LinkedIn’s Insight Tag Creates Legal Entanglements–Doe v. LinkedIn

This opinion is an offshoot of the multitudinous Meta Pixel cases. LinkedIn offered its own tracking technology called the Insight Tag. Prior blog post. In this case, two healthcare entities, Covered California and Nevada Health Link, installed the Insight Tag, which alleged sent consumers’ sensitive health information to LinkedIn. The lawsuit over these implementations leads to a partially split ruling.

Consumer Consent

LinkedIn’s own disclosures may be sufficient (see LB v. LinkedIn in my prior post), but its partners’ disclosures are not. Covered California’s disclosures expressly say “no personal information is sold or distributed,” and Nevada Health Link’s disclosures do not mention sharing data with third parties.

Furthermore, “Courts have often found a lack of consent when the type of data collected, though conceivably included in the disclosure, falls outside the plaintiffs’ reasonable expectations.” LinkedIn capturing consumers’  “medication and dosage” would be outside such expectaions. The complaint against Covered California was not specific enough about its data captures, but that can be fixed in an amended complaint.

LinkedIn’s Intent to Intercept

Johnson alleges that LinkedIn intentionally intercepted her and class members’ communications regarding their medical care through the Insight Tag, which Johnson alleges LinkedIn designed to collect all interactions with the Nevada Health Link website. Johnson also alleges that the issue of health information being shared via tracking technology is so well known in the technology industry that LinkedIn should have known its Insight Tag was likely collecting personal health information. Finally, Johnson alleges that LinkedIn monetized the intercepted personal health information in the form of targeted advertising, which is most of LinkedIn’s revenue. Though the inference of intent may be relatively weak in light of LinkedIn’s policies to the contrary and the absence of specific facts concerning how LinkedIn uses the data it allegedly receives from the Insight Tag, the Court finds these allegations sufficient to survive a motion to dismiss

So…the court says LinkedIn has sufficient “intent” to intercept sensitive consumer data even if its contract with customers restricted such efforts, because LinkedIn should have known data leakages would occur? That doesn’t sound like “intent” to me. See the Pharmatrak case from 2003…

LinkedIn argued that the Nevada Health Link is a government agency, so it should be entitled to the presumption of regularity, i.e., that it followed its own policies and the LinkedIn agreement. The court says that presumption, if it applies at all, is more of an evidentiary burden, not a legal matter that supports motions to dismiss. Plus, Johnson alleged a wrongful data collection of their data, regardless of the entities’ general policies.

Intrusion Upon Seclusion

LinkedIn fails to provide any support for its argument that the “amount” of information disclosed, the public availability of the website, or the optional nature of some forms are relevant to the degree of intrusion or otherwise cause the context, circumstances, and setting factors to tip in LinkedIn’s favor. For purposes of the motion to dismiss, the Court finds Johnson’s allegations that LinkedIn’s unauthorized interception of information regarding her medication and dosage was “highly offensive” conduct sufficient.

Based on my unscientific review of the Pixel cases, it seems like the lawsuits against healthcare entities frequently survive motions to dismiss. It will be an entirely different matter for plaintiffs to win the cases and defend those rulings on appeal.

Case Citation: Doe v. LinkedIn Corp., 2026 WL 2199526 (N.D. Cal. July 30, 2026)

More Posts on the Pixel Cases and Related Claims