On March 30, a three-judge panel of the U.S. Court of Appeals for the Fifth Circuit heard oral argument in Rand v. Eyemart Express LLC — an appeal that could shape the legal landscape for businesses that deploy tracking technologies on their websites.
The plaintiffs had brought a now-dismissed proposed class action in the U.S. District Court for the Northern District of Texas, claiming that Eyemart Express incorporated tracking technology from Meta Platforms Inc. on its website, which collected protected health information without the plaintiffs' consent.
At oral argument, the panel pressed both sides with pointed questions about the sufficiency of the plaintiffs' pleadings, the nature of the information at issue and whether dismissal at the motion to dismiss stage was appropriate.
The outcome could affect companies across multiple industries, particularly those that operate health-adjacent or retail websites and use third-party analytics tools.
Background: The District Court Dismissal
The case arises from allegations that Eyemart, a retail eyewear company selling both prescription and nonprescription glasses, installed the Meta Pixel on its website.
According to the plaintiffs, the Meta Pixel tracks predetermined user interaction "events," such as clicking buttons, adding items to a cart or searching for store locations, and then transmits data about these interactions to Meta. The plaintiffs alleged that because they all had Facebook accounts, a user identification cookie stored on their devices allowed Meta to link the tracked interactions to specific individuals.
Five named plaintiffs brought suit on behalf of themselves and a putative class. Three of the original plaintiffs alleged that they visited the Eyemart website to browse for prescription eyewear or to find eye doctors.
After the district court dismissed the first complaint for failure to state a claim, two additional plaintiffs were added in an amended complaint and alleged that they actually purchased prescription eyewear through the website, entering their prescription information as part of the checkout process. Eyemart moved to dismiss the amended complaint without leave to replead again.
The plaintiffs asserted claims for violation of the federal Electronic Communications Privacy Act, the Missouri Wiretap Act, the Illinois Eavesdropping Statute, breach of contract, breach of implied contract and intrusion upon seclusion. All of the claims rested on the theory that Eyemart unlawfully shared the plaintiffs' private health information, or PHI, with Meta.
The district court, in its May 2025 opinion by U.S. District Judge David C. Godbey of the Northern District of Texas, granted Eyemart's motion to dismiss and dismissed all claims with prejudice. The court's analysis proceeded in two parts.
First, as to the three original plaintiffs — the browsing plaintiffs — the court held that they had failed to plead any facts showing they shared PHI with Eyemart in the first place. The court found that a user's subjective intent for visiting the website, including whether to purchase prescription eyewear or nonprescription sunglasses, did not constitute the sharing of PHI, and that disclosing one's location to find a nearby Eyemart store gave no new information to Meta beyond what the plaintiffs had already shared through their Facebook accounts.
Second, as to the purchasing plaintiffs, the district court stated that these plaintiffs had plausibly established they shared PHI with Eyemart by entering prescription information. However, the court found they had not sufficiently alleged that any of that PHI was actually transmitted to Meta through the Pixel. The court examined the screenshots and figures attached to the amended complaint, which showed the specific metadata sent to Meta when an "AddToCart event" was triggered, and found that the transmitted data included only the item name, product ID, price, frame material and fulfillment entity.
Notably, the court found that because Eyemart's frames "appear to be versatile and available for prescription lenses, sunglass lenses, or fashion lenses, information about the frames or the styles customers browse does not convincingly share any PHI." Prescription information was conspicuously absent. The plaintiffs failed to plead that "the prescription information is captured by the Pixel."
The court concluded that the exhibits attached to the complaint contradicted the plaintiffs' conclusory allegations that PHI had been shared with Meta.
Because the district court found no plausible allegation that PHI was transmitted to Meta, all derivative claims also failed. The Electronic Communications Privacy Act and Missouri Wiretap Act are one-party consent statutes, meaning that Eyemart, as a party to the communications on its own website, could not be liable unless it intercepted the communications for the purpose of committing a crime or tort.
The plaintiffs invoked the "crime-tort exception," arguing that any sharing of PHI with Meta would violate the Health Insurance Portability and Accountability Act. But without plausible allegations of PHI disclosure, the exception did not apply.
The Illinois Eavesdropping Statute claim similarly failed because the Illinois plaintiff failed to plead facts to show he shared any PHI; therefore, he could not show that any private conversation was intercepted. The breach of contract, implied contract and intrusion upon seclusion claims were likewise dismissed for lack of a factual predicate.
The Fifth Circuit Oral Argument: A Skeptical Panel
U.S. Circuit Judges Catharina Haynes, Stephen A. Higginson and James C. Ho sat on the panel for the Fifth Circuit. The oral argument featured active questioning from the panel on several key issues.
Much of the argument centered on the line between browsing and PHI disclosure. Judge Higginson asked the plaintiffs' counsel whether "browsing is not disclosing" as a general proposition. The judge pressed the plaintiff's position further, but posed, "If your contention is that browsing does disclose private information, would every single case similar to this one have to go to discovery?"
The plaintiffs' counsel resisted a blanket concession, emphasizing that one plaintiff had used the website's scheduling feature to find an eye exam and that cumulative tracking across multiple visits could reveal health-related information. Judge Ho asked Eyemart's counsel whether the fact that a person is seeking medical care constitutes PHI, and Eyemart's counsel stated that, at least "in context, that does constitute PHI."
The panel also questioned whether dismissal at the pleading stage was appropriate, or whether the district court should have permitted discovery due to the complexity of the case. Judge Higginson observed that the district court appeared to treat the exemplar figures attached to the complaint as conclusive proof that no PHI was transmitted, without fully grappling with the plaintiffs' broader textual allegations, including that Eyemart "uploads the customer list to Meta" containing "email addresses, purchase information, including what prescription eyewear they purchased."
The argument also surfaced the question of whether Eyemart was a direct interceptor of the communications or merely a procurer of an interception by Meta. The plaintiffs' counsel argued that Meta, not Eyemart, actually captured the data, and therefore, the one-party consent defense should not apply. Eyemart's counsel responded by citing the Fifth Circuit's 2000 decision in Peavy v. WFAA-TV Inc., holding that a private right of action does not exist for mere procurers of an interception versus the interceptors themselves.
Eyemart's counsel also pointed to Meta's own business terms prohibiting the sharing of health-related information.
Finally, the plaintiffs' counsel argued that the district court erred by dismissing the claims of the purchasing plaintiffs with prejudice without giving them leave to amend, since they were first added in the amended complaint and never had an independent chance to replead. Therefore, the district court denying them the ability to amend was an error, the plaintiffs' counsel claimed.
The Broader Trend: A Surge in Pixel Tracking Litigation
Rand v. Eyemart Express is part of a broader wave of privacy litigation targeting businesses for their use of tracking technologies. In 2025 alone, state and federal courts throughout the country dealt with thousands of data privacy dockets. Website tracking litigation has become a major component of this landscape.
Plaintiffs attorneys have increasingly turned to federal and state wiretap statutes — originally enacted to combat telephone surveillance — to challenge routine online business practices such as the use of cookies, pixels, session replay tools and analytics tags.[1]
Some court rulings addressing these claims, like the district court decision here, have turned on whether one- or two-party consent is required under the statute, and whether the plaintiff sufficiently alleged that their protected personal information was shared.
The healthcare sector has been hit particularly hard. In 2025, for example, a consolidated class action against Aspen Dental Management Inc. resulted in an eight-figure settlement.[2] Other healthcare systems have also settled pixel-related lawsuits, including companies allegedly using tracking technologies.
There is a growing number of district courts and state courts weighing in on whether violations of HIPAA through the interception of medical information on third-party websites are sufficient to state federal claims. The number of targeted companies offering pixel technologies has expanded far beyond just Meta, and grows by the day with new theories and new technologies targeted.
But the litigation is not confined to healthcare. Courts have seen wiretapping claims brought against companies across virtually all industries, including retailers, educational and financial institutions, hospitality companies, and a wide range of consumer-facing businesses.
As we have previously discussed, plaintiffs firms are expanding their theories to argue that pixel-based data collection violates other privacy statutes, consumer protection laws and common-law tort principles. The Electronic Communications Privacy Act's crime-tort exception has become a particularly active battleground, with courts splitting over whether commercial motivation for deploying tracking technology is sufficient to trigger the exception, or whether plaintiffs must allege a specific intent to commit a downstream crime or tort.[3]
What This Could Mean for Businesses
An affirmance from a federal appellate court here could provide businesses with a significant defense against pixel-tracking lawsuits. It would reinforce the principle that plaintiffs must plausibly allege not just that a website uses tracking technology, but that the specific data captured and transmitted to a third party includes protected or sensitive information.
It would also validate the district court's approach of scrutinizing the technical exhibits attached to a complaint to determine whether they contradict broader allegations. For companies that use the Meta Pixel or similar tools, an affirmance would mean that so long as the Pixel is configured to capture only nonsensitive metadata, such as product names, prices and materials, the risk of wiretap liability is substantially reduced.
A reversal could leave the floodgates to pixel tracking litigation open. If the appellate court holds that the plaintiffs' allegations were sufficient to survive a motion to dismiss, particularly the theory that an "AddToCart event" for prescription lenses implies the transmission of health information, even without explicit prescription data in the metadata, then businesses would face a much lower bar for plaintiffs to reach discovery.
Discovery in these cases can be expensive and invasive, requiring companies to disclose the inner workings of their tracking configurations, their data-sharing relationships with third-party platforms, and potentially the full scope of information transmitted through server-side tools like Meta's Conversions API.
A reversal on the procedural ground, that the new plaintiffs should have been given leave to amend, would be narrower but still significant, as it would send the case back to the district court and allow the plaintiffs another opportunity to craft more detailed allegations. And if the district court addresses the "direct interceptor" versus "procurer" distinction raised at oral argument, its analysis could have implications well beyond the facts of this case, potentially reshaping how liability is allocated between website operators and the third-party technology providers whose tools they deploy.
Conclusion
Regardless of how the Fifth Circuit rules, Rand v. Eyemart Express underscores the importance of proactive risk management for any company that uses tracking technologies on its website.
Businesses should audit their use of pixels, cookies and analytics tools to understand exactly what data is being collected and transmitted to third parties. Privacy policies and cookie consent mechanisms should be reviewed and updated to ensure clear disclosure.
Companies should consider segmenting website functionality so that tracking tools are not deployed on pages where users may enter sensitive information, such as prescription data, patient portals or appointment scheduling pages. And businesses should evaluate whether their existing terms of service, arbitration clauses and forum selection provisions provide adequate protection in the event of litigation.
The Fifth Circuit's decision in Rand v. Eyemart Express is expected in the coming months.
"Tracking Tech Suit Is a Risk Management Reminder for Cos.," by Harrison Brown and Gabrielle N. Ganze was published in Law360 on May 20, 2026. Reprinted with permission.
