Answers · HIPAA & Tracking
What is a wiretapping (CIPA) claim against a website?
Last reviewed: · Strategic AI Architects Data Desk · reviewed by Mike Moore
A wiretapping claim under the California Invasion of Privacy Act alleges that a website "intercepted" a visitor's communications in transit — a chat widget transcript, a session-replay recording of keystrokes and mouse movement, or a tracking pixel routing page activity to Meta or Google — and shared them with a third party without the all-party consent California Penal Code section 631 requires, entitling the plaintiff to $5,000 per violation in statutory damages under section 637.2 with no proof of actual harm (current statutory text, verified live August 17, 2026).
The qualifier, stated plainly: this area of law is genuinely unsettled. Courts are split on whether a marketing pixel is an "interception" at all, decisions conflict within the same district, and a November 2025 California federal ruling called the case law a "total mess." Saying the risk is either fake or certain would both be wrong; what is certain is the volume of demand letters and filings, and the per-violation number they cite.
The statutes a website claim is built from
| Provision | What it prohibits | How it's used against a website |
|---|---|---|
| Penal Code §631 | Wiretapping — reading or learning the contents of a communication in transit without all-party consent | Chat widgets, session replay, pixels sending form/page activity to a third party |
| Penal Code §638.51 | Installing a pen register / trap-and-trace device without a court order | The newer wave: trackers collecting IP addresses and device identifiers framed as 'pen registers' |
| Penal Code §637.2 | — (the remedy) | $5,000 per violation or 3× actual damages, no actual harm required |
The legislative fix has not arrived. Senate Bill 690, which businesses hoped would carve routine commercial tracking out of CIPA, stalled in the Assembly in July 2025 (Duane Morris client alert, July 2025), and its July 2, 2026 amendment dropped sections 631 and 632 from the bill entirely — so the wiretap claims that carry most website suits remain privately enforceable (Alston & Bird, July 2026). Law-firm trackers through 2025-2026 describe pre-consent firing — the tag that loads before the banner is answered — as the dominant fact pattern (Loeb & Loeb, "The Millisecond Problem," April 2026).
For a health or Medicare agency, CIPA sits on top of the health-specific frameworks, not instead of them: the same pixel can draw a HIPAA/FTC analysis on a quote form and a CIPA theory on any page. The practical defense is the same either way — consent that actually blocks the tag before it fires, not a banner displayed next to a tag that already fired.
Sources
- California Legislative Information. Penal Code §631 (wiretapping) and §637.2 (civil remedy, $5,000 per violation), current statutory text. Verified live 2026-08-17. leginfo.legislature.ca.gov.
- Duane Morris LLP. "California SB 690 Stalls in Assembly — CIPA Liability Remains at Least Through 2026," July 2025. duanemorris.com.
- Alston & Bird. "California SB 690 Reform Advances as CIPA Claims Persist," July 2026 — the July 2, 2026 amendment narrowing SB 690 to the pen-register provisions. alston.com.
- Loeb & Loeb LLP. "The Millisecond Problem: How Pre-Consent Tracking Is Driving CIPA Lawsuits in 2026," April 2026. loeb.com.
- Covington & Burling, Inside Class Actions. "Website Wiretapping Roundup: 2025 Decisions and Developments," January 27, 2026 — the split rulings, including the November 2025 'total mess' decision. insideclassactions.com.
This page is sourced information, not legal advice. For a compliance decision about your agency, talk to counsel who knows your state and your book of business.
Related questions
My agency isn't in California — can I still get a CIPA demand letter?
Yes. CIPA is a California statute, but the plaintiff's location is what plaintiffs' firms plead, not the defendant's. A visitor who accessed your site from California can attempt a claim against an agency based anywhere, which is why these demand letters reach businesses in every state.
Do these claims usually win?
The candid answer is that courts are split and the law is unsettled. Some courts have let pixel and session-replay claims past motions to dismiss; others have rejected the theory outright — a November 2025 California federal decision described the state of CIPA case law on tracking as a 'total mess.' Most matters resolve as demand-letter settlements priced below the cost of defense, which is exactly why the volume persists.
Is this a health-data law like HIPAA?
No — and that is what makes it dangerous for agencies that assume they're safe because HIPAA doesn't apply to them. CIPA asks whether a communication was intercepted without consent, on any page. Health context can make a claim more sympathetic, but the statute is not limited to health information.
Want to know where your own site stands? Run the free Audit — a live AEO audit plus a HIPAA tracking scan — or browse all answers.