Built From Primary Records · Sources Named on Every Story · Corrections Noted On-Page · Editorial Policy

Why Health Website Privacy Claims Keep Landing in California

A striking share of the country’s website-tracking privacy litigation is filed in California, and the reason is not that Californians browse differently. It is that this state kept a 1967 wiretapping statute on the books, wrote a consumer privacy act that treats health information as a special category, and combined them into something no other state quite has. A current attorney investigation into the telehealth company LifeMD is drawn along exactly that state line.

Table of Contents

What is being looked at

Attorneys are investigating potential cases against LifeMD, Inc. for alleged privacy violations in California, including its Rex MD and ShapiroMD brands. The question under review is whether the intake questionnaires on those sites passed a visitor’s own answers — weight-loss goals, medical symptoms, treatment inquiries — to third-party advertising networks before that visitor accepted the Terms, Privacy Policy, Notice of Privacy Practices and telehealth consent, and before any account existed.

Nothing has been established. No complaint has been filed, no class has been certified, no court or regulator has found anything, and LifeMD has had no pleading to answer. The published criteria and a free case review are on the LifeMD data privacy investigation page. What makes it worth explaining here is less the company than the legal geography.

Advertisement

The four statutes doing the work

  • The California Invasion of Privacy Act (CIPA), Penal Code sections 630 and following — a wiretap statute with statutory damages attached.
  • The California Consumer Privacy Act, as amended by the California Privacy Rights Act — which classifies health information, and inferences drawn about health, as sensitive personal information with rights over how it is shared.
  • The Confidentiality of Medical Information Act (CMIA) — which reaches medical information held by entities outside the traditional federal health-privacy perimeter.
  • The Unfair Competition Law — the general vehicle that carries the others.

Most states have none of this. A visitor in a state without a statutory-damages privacy law who wants to sue over a tracking pixel has to prove they lost something, and in the ordinary case they cannot. The claim dies not because the conduct was different but because the state code was.

A 1967 wiretap law, applied to web pages

CIPA was written for telephone lines. Its core prohibition is on a third party listening in on, or recording, a confidential communication without the consent of all parties — California being a two-party consent state, which is why call-recording notices exist here.

The theory plaintiffs have built on it is that a web page is a communication between a visitor and a site, and that advertising or analytics code embedded in the page is a third party listening to it. Whether that fits a statute drafted around telephone handsets is genuinely contested, and courts have divided. What is not contested is the consequence if it does fit: CIPA carries statutory damages, so a plaintiff who lost no money still has a claim with a number attached to it.

That single feature explains the filing patterns. Multiply a per-violation figure by a class and the case becomes economically worth bringing, which is why California became the venue of choice for a category of harm that is real but nearly impossible to price the ordinary way.

Why the state line matters at all

People are often surprised that a review would be limited by geography when the website is the same website everywhere. Two things fix it in place.

  • The statute is California’s. CIPA protects communications with a California nexus, which in practice means where the person was when they used the site — not where the company is.
  • Physical presence, not just residency. Being in the state at the time of the visit is a threshold fact, which is why these criteria always specify location rather than mailing address.

It also means the same conduct produces a claim for a person in Fresno and nothing at all for the identical person in Reno — an outcome that looks arbitrary and is simply federalism working as designed.

The specific allegation in this review turns on sequence, and the sequence is worth understanding because it is how nearly every online health intake is built.

A visitor picks a topic, clicks “Get Started,” and begins answering questions. Only later does a screen ask them to tick a box agreeing to the terms and the privacy notices, and only after that do they create an account or pay. Advertising and analytics tags, meanwhile, generally load with the page — before there is any consent state to consult.

So the group with the weakest consent record is not the customers. It is the people who answered a few questions and closed the tab. They are also the hardest group to ever notify, because they are in no account database, which is why they are usually absent from the settlement classes these cases produce. The review under discussion is aimed specifically at Californians in that position: people who visited on or before June 14, 2026, answered at least one question on a topic such as weight loss, men’s health, women’s health, cardiovascular health, mental health, prescriptions and refills or primary care, and never accepted the terms, created an account or made a purchase.

The federal case filed in a California courtroom

California is not only a source of causes of action; it is where the federal government chose to bring its own telehealth privacy case. On July 29, 2026 the Federal Trade Commission, joined by the State of Utah and Los Angeles County, sued Hims & Hers Health in the U.S. District Court for the Northern District of California, alleging among other things that the company shared sensitive health information with advertising platforms including Meta and Snap while marketing itself as private, and that it charged customers before provider consultations and made subscriptions hard to cancel. The claims run under Section 5 of the FTC Act and the Restore Online Shoppers’ Confidence Act. Hims & Hers denies wrongdoing and the case is unresolved.

📨 Get Free California Guides Alerts

Free · No spam · Unsubscribe anytime

It does not involve LifeMD, and it is a government enforcement action rather than a class claim. Its relevance to Californians is that a county and a state attorney general’s office are named alongside a federal agency — a reminder that consumer privacy enforcement here runs through several offices at once, and that Los Angeles County in particular has been an active participant.

A Nevada case that already closed

LifeMD has already been through one privacy case, and it is finished. In W.M.F. & Matthew Marden v. LifeMD, Inc., in Clark County, Nevada, users alleged that tracking technologies on the lifemd.com and rexmd.com websites potentially disclosed identifiable health information to third parties including Meta, Google and TikTok. LifeMD denied the allegations. The parties settled with no admission of liability: claims closed September 22, 2025, final approval was entered September 30, 2025, and distribution of $10 in cash or a $25 voucher began January 21, 2026. The record is at LifeMD & RexMD Privacy Settlement Closed: Payment Status.

That class covered members and purchasers nationwide. Because the California review is aimed at people who never became either, missing the 2025 claim deadline does not by itself rule a Californian out of it.

The short clock nobody mentions

An investigation with no complaint has no court deadline, which reads to most people as no urgency. The statute of limitations does not work that way. It runs from the conduct, not from the filing, and it keeps running while everyone waits to see whether a case materialises. California privacy claims of this kind can carry notably short periods.

The practical consequence is unglamorous: the useful step is preserving the evidence that dates the visit — browser history, a bookmark, a retargeting ad, an abandoned-intake or “finish your visit” email. The marketing follow-up is often the cleanest proof that someone started a questionnaire at all.

Questions people ask

Why do so many website privacy lawsuits get filed in California?

Because California supplies statutory damages through the California Invasion of Privacy Act, so a claim can proceed without proving financial loss, and because the CCPA as amended by the CPRA treats health information and inferences about health as sensitive personal information. Most states offer neither.

What is CIPA?

The California Invasion of Privacy Act, enacted in 1967 as a telephone wiretapping statute. Plaintiffs have applied its prohibition on a third party listening in on a communication to advertising and analytics code embedded in web pages, arguing the tag is the uninvited third party to a communication between the visitor and the site. Courts have divided on the theory.

Does the California investigation into LifeMD mean the company did something wrong?

No. It is an attorney investigation, not a filed case. No complaint has been filed against LifeMD on these allegations, no class has been certified, and no court or regulator has made any finding. Nothing has been proven.

Who may qualify for the LifeMD review in California?

California residents who were in California on or before June 14, 2026 when they visited LifeMD, Rex MD or ShapiroMD, clicked “Get Started” on a topic such as weight loss, men’s health, women’s health, cardiovascular health, mental health, prescriptions and refills or primary care and answered at least one question, never checked the box agreeing to the terms, never created an account and never made a purchase, and who are not already represented by a lawyer.

Is there a deadline?

There is no claim form and no court deadline, because nothing has been filed. Statutes of limitations run independently of any filing, and California privacy claims of this kind can carry short periods, which is why these reviews are described as time-sensitive.

This article is general information about California privacy law and a publicly announced attorney investigation. It is not legal advice and does not create an attorney-client relationship. No complaint has been filed against LifeMD on the allegations described, no class has been certified, and nothing has been proven. California News Now is not a law firm and is not affiliated with any company named here. Attorney advertising may appear on linked pages.


You Might Also Like

Owed money from a settlement? Check what is open at OpenClassActions.com. Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.