Full text
C.M. v. BetterHelp, Inc.
[6] 7 UNITED STATES DISTRICT COURT 8 NORTHERN DISTRICT OF CALIFORNIA
[9] 10 Case No. 23-cv-01033-RS
IN RE BETTERHELP, INC. DATA
11 DISCLOSURE CASES ORDER GRANTING IN PART AND
DENYING IN PART MOTION TO
12 DISMISS CONSOLIDATED CLASS
ACTION COMPLAINT
[14] 15 These putative class actions—now consolidated—arose following the announcement by 16 the Federal Trade Commission (“FTC”) of an investigation into the business practices of 17 defendant BetterHelp, Inc., which resulted in the entry of a consent decree. BetterHelp operates an 18 online counseling service that matches users with therapists and then facilitates counseling via its 19 websites and apps. BetterHelp offers its service under several names, each of which has its own 20 website and app. 21 The primary website and app, named “BetterHelp,” serves general audiences and has been 22 in operation since 2013. In more recent years, BetterHelp has started several additional websites 23 aimed at serving specific groups, such as Christians, couples, teens, and the LGBTQ community. 24 The Consolidated Complaint adopts allegations from the FTC complaint that BetterHelp, 25 “delegated most decision-making authority over its use of Facebook’s advertising services to a 26 Junior Marketing Analyst who was a recent college graduate, had never worked in marketing, and 27 had no experience and little training in safeguarding consumers’ health information when using 1 blanche to decide which Visitors’ and Users’ health information to upload to Facebook and how to 2 use that information.” Consolidated Complaint, para. 71. 3 Despite having numerous privacy assurances on its website and in its interactive forms, 4 BetterHelp allegedly failed to keep its customers’ information confidential. 5 Among other things, BetterHelp allegedly disclosed the email addresses of thousands of its 6 customers and potential customers to various third parties for advertising purposes and the third 7 parties’ own purposes, thereby revealing to the third parties that the customers were seeking 8 and/or receiving mental health treatment through BetterHelp’s websites. See Consolidated 9 Complaint paras. 62-69. 10 BetterHelp now seeks dismissal of the Consolidated Complaint. In its motion, BetterHelp 11 characterizes the Consolidated Complaint as alleging nothing more than that “that BetterHelp, like 12 nearly all companies that use websites or mobile applications, used third-party tracking 13 technologies to operationalize and market its services.” BetterHelp then insists its use of these 14 technologies to collect a limited amount of anonymized data from its users was disclosed in 15 BetterHelp’s privacy policy and was in no way unlawful or harmful. 16 BetterHelp’s criticism of the complaint as a “grab-bag” and a “scattershot approach” has 17 some merit, as not all of the fifteen claims for relief are adequately pleaded, and at least some of 18 them do not appear well-suited for these factual circumstances. BetterHelp’s insistence that it did 19 nothing wrong and that there can be no viable claim here, however, is not tenable, at least at the 20 pleading stage. The complaint will be dismissed, with leave to amend, as set out below.
[27] 1 A. Standing issues 2 1. Standing to Seek Injunctive and Declaratory Relief 3 BetterHelp argues plaintiffs lack standing to pursue injunctive and declaratory relief 4 because they fail to show “a sufficient likelihood that [they] will again be wronged in a similar 5 way” by BetterHelp absent injunctive relief. See Williams v. Apple, Inc., 449 F. Supp. 3d 892 , 906 6 (N.D. Cal. 2020) (quotation omitted). BetterHelp insists the complaint does not suggest plaintiffs’ 7 previously collected and disclosed information will be disclosed by BetterHelp again, and because 8 they do not allege they are still using BetterHelp, there is nothing to suggest that more information 9 will be collected from them and disclosed in the future. 10 Plaintiffs respond that some of them are still receiving targeted ads, which indicates third 11 parties continue to use the information that was collected. Plaintiffs have not shown, however, that 12 any risk of ongoing or future harm from third parties’ continued use of the information supports 13 standing to seek injunctive or declaratory relief against any ongoing or future wrongdoing by 14 BetterHelp. The claims for injunctive and declaratory relief therefore must be dismissed. Plaintiffs 15 will be permitted leave to amend in the event they can in good faith assert a claim to such relief 16 against BetterHelp, arising from some right or duty on its part to control the conduct of third 17 parties. Any amended claims for such relief must also include a sufficient factual basis to show the 18 requisite ongoing or future harm exists notwithstanding the existence of the injunctive relief 19 obtained by the FTC.
[20] 21 2. Statutory Standing for UCL, FAL, and CLRA Claims (Counts IX, X, and XV) 22 “To establish standing to bring a claim under these statutes [the Unfair Competition Law 23 (“UCL”), False Advertising Law (“FAL”), and Consumers Legal Remedy Act (“CLRA”)], 24 plaintiffs must meet an economic injury-in-fact requirement . . . .” Reid v. Johnson & Johnson,
[25] 780 F.3d 952, 958 (9th Cir. 2015) (emphasis added). Although some cases support the notion that 26 taking of personal information without consent can constitute economic injury, “[t]he weight of 27 the authority in the district and the state . . . points in the opposite direction: that the ‘mere 1 misappropriation of personal information’ does not establish compensable damages.” Katz-Lacabe 2 v. Oracle Am., Inc., 668 F. Supp. 3d 928 , 943. (N.D. Cal. 2023). While Katz-Lacabe addressed 3 only the UCL, its reasoning equally dooms the FAL and CLRA claims. Because plaintiffs contend 4 their economic injury lies in the taking and unauthorized dissemination of their personal 5 information, they lack statutory standing to pursue these claims, and they must be dismissed. 6 Plaintiffs will be permitted to amend to assert any other basis they may have to support the 7 requisite economic injury.1
[8] 9 B. Other pleading adequacy issues 10 1. Common Law and Constitutional Privacy (Counts II and XI) 11 Count II is a common law claim for invasion of privacy. Count XI, brought on behalf of 12 the four California Plaintiffs and a California sub-class alleges violation of the right of privacy 13 enshrined in the California Constitution. 14 “The right to privacy in the California Constitution sets standards similar to the common 15 law tort of intrusion.” Hernandez v. Hillsides, Inc., 211 P.3d 1063, 1073 (Cal. 2009). Because of 16 this similarity, “courts consider the claims together and ask whether: (1) there exists a reasonable 17 expectation of privacy, and (2) the intrusion was highly offensive.” In re Facebook, Inc. Internet 18 Tracking Litig., 956 F.3d 589, 601 (9th Cir. 2020). 19 As to both the constitutional and common law claim, BetterHelp’s primary argument is 20 that the element of an “intrusion” on privacy is lacking, because the plaintiffs all voluntarily 21 provided the information in dispute. While BetterHelp’s contention that the label does not quite 22 “fit” the wrongdoing is somewhat persuasive, where a defendant has disseminated a plaintiff’s 23 private information without consent or authority to do so, even if the defendant came by the
[25] 1 BetterHelp’s additional challenges to the adequacy of the pleading of the UCL and FAL claims 26 would not independently support dismissal. As to the CLRA claim, plaintiffs failed to respond to BetterHelp’s point that no pre-suit demand was alleged, as required by the statute. Any amended 27 CLRA claim should address that issue. 1 information lawfully, it impacts privacy in substantially the same way as where the defendant 2 comes by the information wrongfully. In either situation, the loss of privacy—the intrusion on the 3 plaintiff’s seclusion—arises when the information reaches someone who is not supposed to have 4 it. 5 BetterHelp’s further argument that plaintiffs fail to plead any “highly offensive” or 6 “egregious” conduct sufficient to state a claim for invasion of privacy is unpersuasive. The 7 allegations are that BetterHelp collected information from its clients and prospective clients 8 regarding the highly personal issue of their interest in seeking counseling or therapy, with 9 assurances that the information would not be shared, and then turned around and shared that 10 information. There is no basis to conclude as a matter of law that such alleged conduct is neither 11 highly offensive nor egregious. 12 Finally, although it is far from clear that damages are available under the constitutional 13 claim, it does not materially expand the scope of potential liability or the factual issues presented 14 in this action. While it must be dismissed to the extent it seeks injunctive relief for the reasons 15 discussed at the outset, it will not be dismissed at this juncture on the additional grounds that 16 damages are unavailable or that it is otherwise duplicative of the common law claim.
[17] 18 2. The CMIA (Count XII) 19 California’s Confidentiality of Medical Information Act (“CMIA”) prohibits the 20 unauthorized disclosure and negligent maintenance or preservation of medical information by a 21 provider of healthcare. Cal. Civ. Code § 56.101 . BetterHelp argues plaintiffs’ claim fails because 22 (1) BetterHelp is not a “provider of healthcare”; (2) BetterHelp did not disclose plaintiffs’ 23 “medical information”; and (3) no third party improperly viewed their “medical information.” See 24 Sutter Health v. Super. Ct., 174 Cal. Rptr. 3d 653, 661 (Cal. Ct. App. 2014). 25 BetterHelp has shown it does not meet any applicable statutory definition of “provider of 26 health care.” Plaintiffs invoke the definitions in Cal. Civ. Code §§ 56.06 (a), (b), (d), and 56.13. 27 Section 56.06(a) does not apply because there are no allegations that BetterHelp is “organized for 1 the purpose of maintaining medical information.” Section 56.06(b) does not apply because 2 BetterHelp does not “offer software or hardware to consumers . . . designed to maintain medical 3 information.” 4 While the Section 56.06(d) definition of a “mental health digital service,” might very well 5 apply now, it did not become effective until January 1, 2023, well after the complained-of conduct 6 occurred. Plaintiffs have not rebutted BetterHelp’s argument that it cannot be applied 7 retroactively. 8 Finally, Section 56.13 does not apply because plaintiffs do not allege that BetterHelp 9 received any medical information through a CMIA authorization or from a provider of health care 10 for one of the purposes set out in the statute. Accordingly, even if the allegations could be 11 construed to support a claim that BetterHelp disclosed “medical information” that was viewed by 12 others within the meaning of the statute, dismissal of this claim for relief is warranted. Plaintiffs 13 may amend if they have a good faith basis to present facts placing BetterHelp within the statutory 14 definitions.
[15] 16 3. The CIPA (Count VIII) 17 Section 631 of the California Invasion of Privacy Act (“CIPA”) makes actionable “three 18 distinct” “patterns of conduct: [1] intentional wiretapping, [2] willfully attempting to learn the 19 contents or meaning of a communication in transit over a wire, and [3] attempting to use or 20 communicate information obtained as a result of engaging in either of the previous two activities.” 21 Tavernetti v. Super. Ct., 583 P.2d 737, 741 (Cal. 1978). It also imposes liability upon “anyone 22 ‘who aids, agrees with, employs, or conspires with any person or persons to unlawfully do, or 23 permit, or cause to be done any of the’ . . . three bases for liability.” Mastel v. Miniclip SA, 549 F. 24 Supp. 3d 1129, 1134 (E.D. Cal. 2021) (quoting Cal. Penal Code § 631 (a)). 25 BetterHelp asserts, and plaintiffs do not contend otherwise, that any liability here is for 26 “aiding and abetting,” as BetterHelp cannot “eavesdrop” on its own communications with the 27 plaintiffs. BetterHelp then argues it cannot be liable for aiding and abetting where the third parties 1 were acting as its own vendors for purposes of collecting and analyzing user data, and to the extent 2 the third parties may have used the information for their own purposes, BetterHelp lacked 3 knowledge or involvement in such conduct. These arguments are insufficient to defeat the claim, 4 particularly at the pleading stage, where the allegations are that BetterHelp allegedly participated 5 in the conduct of the third parties in intercepting the information. 6 BetterHelp’s further arguments that CIPA does not, or should not, apply to internet 7 communications, and as to whether communications were intercepted “in transit” or not, are not 8 persuasive. Its contention that CIPA cannot be applied to non-California plaintiffs may be 9 addressed at the class certification stage, but does not support dismissal now, particularly because 10 the claim would survive as to the California subclass in any event.
[11] 12 4. The ECPA (Count VII) 13 The Electronic Communications Privacy Act (“ECPA”) is a federal counterpart to CIPA, 14 and prohibits the intentional “interception” of electronic communications, 18 U.S.C. § 2511 (1)(a). 15 Unlike CIPA, however, ECPA is a one-party consent statute, pursuant to 18 U.S.C. § 2511 (2)(d). 16 BetterHelp’s choice to deploy the tracking on its websites, means “one of the parties to the 17 communication”—BetterHelp—gave “prior consent to such interception.” Id.; see also Rodriguez 18 v. Google LLC, No. 20-cv-04688-RS, 2021 WL 2026726 , at *6 (N.D. Cal. May 21, 2021); In re 19 Yahoo Mail Litig., 7 F. Supp. 3d 1016, 1026 (N.D. Cal. 2014) (“[T]he consent of one party is a 20 complete defense to a Wiretap Act claim.”). 21 Plaintiffs invoke the crime-tort exception, which requires them to plead sufficient facts to 22 show that “the primary motivation or a determining factor in the interceptor's actions has been to 23 injure plaintiffs tortiously.” The plaintiffs in Katz-Lacabe failed to qualify for the exception 24 because the defendant’s “purpose has plainly not been to perpetuate torts on millions of Internet 25 users, but to make money.” Rodriguez, 2021 WL 2026726 at *6 n.8 (citing In re Google Inc. 26 Gmail Litigation, No. 13-MD-02430-LHK, 2014 WL 1102660 , at *18 n.13 (N.D. Cal. Mar. 18, 27 2014)). 1 Here, while the third-party interceptors presumably were only trying to make money, 2 BetterHelp itself arguably was committing the tort/crime of disclosing its customer’s sensitive 3 mental health-related information in violation of HIPAA. This distinction from Katz-Lacabe, 4 which did not implicate HIPAA, is sufficient to permit the claim to go forward.
[5] 6 5. The CCPA (Count XIII) 7 The California Consumer Privacy Act (“CCPA”) confers a private right of action for 8 “Personal Information Security Breaches.” Cal. Civ. Code § 1798.150 (emphasis added). 9 BetterHelp insists the facts here do not constitute a “security breach” as that term is commonly 10 understood. The statute, however, allows for statutory damages where “nonencrypted and 11 nonredacted personal information . . . [was] subject to an unauthorized access and exfiltration, 12 theft, or disclosure as a result of the business’s violation of the duty to implement and maintain 13 reasonable security procedures and practices appropriate to the nature of the information to protect 14 the personal information.” Cal. Civ. Code § 1798.150 (a)(1). 15 The information here allegedly was “subject to . . . [a] disclosure as a result of the 16 business’s violation of the duty to implement and maintain reasonable security procedures and 17 practices appropriate to the nature of the information.” It was disclosed because BetterHelp 18 affirmatively allowed the tracking software on its websites—which can reasonably be argued was 19 not an appropriate security procedure or practice, given the nature of the information. This claim 20 may go forward.
[21] 22 6. The CDAFA (Count XIV) 23 The California plaintiffs bring this claim under the Computer Data Access and Fraud Act 24 (“CDAFA”), which “is a state law counterpart to the” federal Computer Fraud and Abuse Act 25 (“CFAA”), and courts routinely analyze them together. Meta Platforms, Inc. v. BrandTotal Ltd.,
[26] 605 F. Supp. 3d 1218 , 1260 (N.D. Cal. 2022). Here, plaintiffs have not advanced a federal CFAA 27 claim. 1 Both the CDAFA and the CFAA were “enacted to prevent intentional intrusion onto 2 someone else’s computer—specifically, computer hacking.” hiQ Labs, Inc. v. LinkedIn Corp., 31
3 F.4th 1180 , 1196 (9th Cir. 2022). BetterHelp argues the CDAFA claim must be dismissed because 4 (1) the statute addresses computer hacking, not data disclosure; (2) plaintiffs fail to allege “loss” or 5 “damage” within the meaning of the statute; and (3) BetterHelp had permission to access the 6 computer systems at issue. 7 In this instance, the allegations of wrongdoing cannot be shoehorned into a violation of this 8 statute. While dismissal will be with leave to amend, plaintiffs should only do so if they can 9 articulate a factual and legal basis for application of this statute under the circumstances.
[10] 11 7. Breach of Confidence (Count V) 12 The common law claim for breach of confidence protects novel ideas that are offered in 13 confidence. See Faris v. Engberg, 158 Cal. Rptr. 704, 712 (Cal. Ct. App. 1979) (“An actionable 14 breach of confidence will arise when an idea, whether or not protectable, is offered to another in 15 confidence.”). It typically arises when a would-be inventor is peddling some new invention, or a 16 writer is shopping an idea for a screenplay, and the like. The alleged facts here simply do not 17 implicate the common law tort. Again, plaintiffs will be given leave to amend, but should 18 carefully consider whether there is a valid basis to do so.
[19] 20 8. Breach of Contract (Counts III and IV) and Negligence (Count I) 21 The Consolidated Complaint alleges, in essence, that plaintiffs entered into contractual 22 relationships with BetterHelp, and that BetterHelp’s various promises of confidentiality were 23 terms of those contracts. The allegations regarding how and when the contracts were formed, and 24 what provisions became express or implied terms of those contracts, are not as specific and clear 25 as they should be, even assuming they might survive dismissal if that was the only issue with the 26 pleading. Any amended complaint, therefore, should specifically and concisely identify the facts 27 showing how the contracts were formed, the alleged contractual terms, and the facts plaintiffs 1 contend establish breach. 2 Because plaintiffs’ relationship with BetterHelp appears to have arisen in contract, it is not 3 clear the alleged circumstances support a negligence claim. Any amended complaint asserting a 4 || count for negligence should specifically and concisely identify the facts supporting a claim for 5 non-economic damages.
[6] 7 9. Unjust Enrichment (Count XIII) 8 BetterHelp’s challenge to the unjust enrichment claim rests on its contention that plaintiffs 9 || cannot pursue such claims and express contract claims simultaneously. Although the claims 10 || ultimately may be incompatible, plaintiffs will not be put to an election at this stage.
[11] 12 The Consolidated Complaint is dismissed to the extent set forth above. Plaintiffs may file 5 13 an amended complaint within 20 days of the date of this order.
[14] 15 || ITISSO ORDERED.
[16] = 17 Dated: July 15, 2024 1g Vil Ldn
RICHARD SEEBORG
19 Chief United States District Judge
[27] *8 CasE No. 23-cv-01033-RS
