← All Articles

Perry v. Oswego Health Alleges Hospital Shared Patient Data With Google Without Consent

Tracking Tools Intercepted Medical Searches and Portal Activity

A proposed class action filed in the Northern District of New York alleges that Oswego Health Inc., a HIPAA-covered hospital system, systematically intercepted and disclosed its patients’ protected health information (PHI) and personally identifiable information (PII) to Google via embedded tracking technologies such as DoubleClick and Google Ads without notice or consent. Plaintiffs Eva Perry, Jacqueline Fletcher, and Debra L. Gilmore, all Oswego County residents, allege Oswego’s privacy policy explicitly promised it would not share users’ private information with third parties without express written consent (Compl. ¶12). The complaint frames the disclosures as violations of multiple federal and state privacy laws, including the Electronic Communications Privacy Act (ECPA), the Health Insurance Portability and Accountability Act (HIPAA), and New York’s Deceptive Trade Practices Act, as well as common law claims such as negligence, breach of implied contract, breach of fiduciary duty, breach of confidence, unjust enrichment, constructive bailment, and breach of the implied covenant of good faith and fair dealing. Plaintiffs seek class certification, injunctive relief to halt future disclosures, and damages, including statutory damages of the greater of $100 per day for each day of the violation or $10,000, compensatory, and punitive damages (Compl. ¶292). The amount in controversy for class action jurisdiction exceeds $5,000,000 (Compl. ¶33).

The complaint alleges Oswego Health, a non-profit organization with approximately $233 million in annual revenue, operates web properties that invite patients to search for and share detailed information about their physical and mental health (Compl. ¶2, ¶6). These properties include patient portals where users can access medical records, schedule appointments, and pay bills. However, Oswego allegedly embedded tracking technologies on these sites that surreptitiously collected and transmitted users’ sensitive data—including IP addresses, device identifiers, and medical search queries—to Google without their knowledge or consent (Compl. ¶14-15). The complaint states, “Oswego specifically invites patients to search for and share detailed information about their own physical and mental health via its Web Properties” (Compl. ¶6). Oswego Health, Inc. is identified as a HIPAA-covered entity in the complaint (Compl. ¶32).

The complaint further alleges that Oswego did not obtain express or informed consent from plaintiffs or class members for sharing their private information (Compl. ¶21). The surreptitious collection and divulgence of private information is described as a serious data security and privacy issue by the Federal Trade Commission (FTC) and the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) (Compl. ¶37). The FTC has stated that health information includes anything conveying or enabling inference about a consumer’s health, such as app usage and interaction patterns (Compl. ¶38). The FTC has also warned healthcare companies against using tracking technologies to collect sensitive health information without patient consent, stating, “Don’t use behind-the-scenes tracking technologies that contradict your privacy promises or otherwise harm consumers” (Compl. ¶39).

Oswego’s Web Properties Transmitted Medical Searches and Patient Status to Google

The complaint alleges Oswego embedded tracking technologies on its websites, including patient portals, to collect and share users’ sensitive data with Google without consent. When users searched for medical services (e.g., “Breast Care,” “Urology”), clicked “Bill Pay,” or accessed patient portals, Oswego’s tools transmitted their activity—along with IP addresses, device identifiers, and advertising cookies—to Google for advertising and analytics. For example, the complaint alleges that a user searching for "Breast Care" and selecting a provider had their activity, including the provider’s name and specialty, transmitted to Google via DoubleClick and Google Ads, identifiable by cookies such as IDE (Compl. ¶82-85). Similarly, a user searching for "Urology" services and selecting a provider had their activity transmitted to Google with identifying cookies (Compl. ¶86-89). Oswego linked users' data to IP addresses, device identifiers, email addresses, and Google accounts, creating detailed "data packets" shared with Google for marketing and analytics (Compl. ¶15). The complaint describes how Oswego’s tracking technologies informed Google when a user searched for urology services and selected a provider, identifiable by cookies (Compl. ¶89). Additionally, the technologies transmitted users’ clicks on "Patient Portal" or "Bill Pay" to Google, revealing they are Oswego patients (Compl. ¶90).

Oswego’s privacy policy stated it would not “distribute individually identifiable information to third parties” without express written consent (Compl. ¶12). The complaint alleges this representation was misleading, as Oswego’s practices included sharing such data with third parties like Google. The complaint further alleges Oswego’s privacy policy misrepresented how cookies were used, claiming they stored only “usernames, passwords and other user preferences solely for the convenience of the user” (Compl. ¶105). In reality, the complaint alleges, Oswego’s cookies, such as IDE and DSID, were used for cross-site ad targeting and linking browsing activity to users’ Google accounts (Compl. ¶55-56). The IDE cookie is described as a persistent advertising identifier used for cross-site ad targeting, tracking user interactions post-ad exposure, and delivering personalized ads (Compl. ¶55). The DSID cookie links browsing activity on non-Google sites to a user’s Google account and applies ad personalization settings (Compl. ¶56). Both IDE and DSID cookies constitute personally identifiable information (PII) (Compl. ¶57). Google Ads uses additional third-party cookies, such as 3PSID, 3PAPISID, 3PSIDCC, and NID, to track user behavior across websites and link it to advertising audiences (Compl. ¶59). The 3PSID, 3PAPISID, and 3PSIDCC cookies link browsing activity to a user’s Google account when signed in, while the NID cookie tracks users even when not signed in or without a Google account, assigning a unique browser ID for ad targeting (Compl. ¶60-61). These third-party cookies can also constitute PII when linked to other account data (Compl. ¶62).

The complaint describes Oswego’s tracking technologies as operating invisibly, likening them to a "wiretap" that intercepted users’ communications without their knowledge. The complaint states, “Oswego is, in essence, handing its patients a tapped phone... the software-based wiretaps are quietly intercepting the patients’ communications” (Compl. ¶75). These technologies allegedly captured both the "characteristics" (e.g., IP addresses, cookies) and "content" (e.g., clicked links, medical searches) of users’ communications, transmitting this information to Google (Compl. ¶78). The complaint alleges Oswego’s tracking technologies collected and shared every page visited, character typed, and button clicked on its website with Google (Compl. ¶93). The complaint further alleges Oswego’s tracking technologies transmitted users’ free-text searches (e.g., "cancer") and subsequent clicks to Google, including PII and PHI protected by HIPAA (Compl. ¶91-92).

The complaint alleges Oswego’s cookie banner misled users into believing cookies were used only for internal purposes, omitting third-party disclosures. The banner stated, “This website uses cookies: We use cookies on this site to enhance your experience and improve our marketing efforts” (Compl. ¶98). However, the complaint alleges Oswego’s tracking technologies transmitted users’ private information to Google without notice or authorization, as described in the complaint: “without any notice or authorization, Oswego commands Plaintiffs’ and Class Members’ computing devices to contemporaneously re-direct the Plaintiffs’ and Class Members’ identifiers and the content of their communications to Google” (Compl. ¶80). The complaint asserts that Oswego’s sharing of users’ PII and PHI with Google constitutes an unlawful disclosure, as plaintiffs and class members never consented to such disclosures (Compl. ¶94-95). The complaint further alleges that Oswego deprived plaintiffs and class members of their privacy rights by surreptitiously disclosing their PII and PHI to Google without notice or consent (Compl. ¶96).

HIPAA Violations: Oswego Disclosed PHI Without Proper Safeguards or Consent

The complaint alleges Oswego, as a HIPAA-covered entity, unlawfully disclosed protected health information to Google without proper safeguards or patient authorization, violating the HIPAA Privacy Rule and Security Rule. The HIPAA Privacy Rule prohibits the disclosure of PHI, which includes individually identifiable health information such as IP addresses, URLs, and device identifiers, without patient authorization (Compl. ¶117). The complaint defines PHI as “individually identifiable health information... relates to the past, present, or future physical or mental health or condition of an individual” (Compl. ¶117). The complaint alleges Oswego failed to obtain the required written authorization before disclosing PHI to Google for marketing purposes, as mandated by 45 C.F.R. § 164.508(a)(3) (Compl. ¶116). The complaint states, “Simply put, a covered entity may not sell protected health information to a business associate or other third party for the third party’s own purposes, even if the third party is a business associate” (Compl. ¶123). Additionally, the complaint alleges Oswego violated the HIPAA Security Rule by failing to implement safeguards to protect electronic PHI, such as access controls and security incident procedures (Compl. ¶127). The complaint specifically alleges Oswego failed to review or modify security measures, implement access controls for electronic PHI, and comply with other safeguards outlined in 45 C.F.R. §§ 164.306(a)(1)-(3), 164.308(a)(1), (a)(6)(ii), and 164.312(a)(1) (Compl. ¶127, ¶131).

The complaint references regulatory guidance from the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), which has warned HIPAA-covered entities about the risks of using online tracking technologies without proper safeguards. In a 2024 bulletin, HHS OCR stated that IP addresses, geographic locations, or other identifiers linked to health data are considered PHI and require consent for disclosure (Compl. ¶43, ¶140). The complaint alleges Oswego’s disclosures of PHI to Google without a Business Associate Agreement (BAA) or patient authorization violated these guidelines. The complaint further alleges that Oswego’s actions exposed patients to risks such as identity theft, financial loss, discrimination, and reputational harm, as detailed in HHS OCR guidance. The complaint quotes HHS OCR, stating, “Such disclosures can reveal incredibly sensitive information about an individual, including diagnoses, frequency of visits to a therapist or other health care professionals, and where an individual seeks medical treatment” (Compl. ¶45). The complaint also notes that the fact that an individual is receiving medical services or is a patient of a particular entity can constitute PHI, stating, “The fact that an individual is receiving medical services or is a patient of a particular entity can be PHI” (Compl. ¶121). Furthermore, the complaint states, “[I]f such information was listed with health condition, health care provision or payment data, such as an indication that the individual was treated at a certain clinic, then this information would be PHI” (Compl. ¶122).

The complaint also asserts that Oswego violated several provisions of New York Public Health Law. Specifically, the complaint alleges Oswego violated New York Public Health Law § 18(6) by disclosing medical information without patient consent (Compl. ¶153), New York Public Health Law § 405.10(a)(6) by failing to obtain patient consent for medical record disclosure (Compl. ¶156), and New York Public Health Law § 405.10(a)(2) by failing to implement safeguards for medical record security (Compl. ¶158). The complaint states that New York law requires hospitals to obtain patient consent before disclosing medical records to outside entities, even for treatment or reimbursement purposes, and to implement safeguards to protect medical record security, including authentication integrity and protection from unwarranted access. The complaint quotes New York Public Health Law § 18(6), stating, “This provision has been interpreted to require hospitals to obtain consent from the patient before disclosing medical records to an outside entity” (Compl. ¶157). The complaint alleges Oswego’s use of tracking technologies without consent violated these New York confidentiality standards (Compl. ¶159).

The complaint alleges Oswego’s HIPAA violations demonstrate wrongdoing and establish its duty to maintain patient privacy (Compl. ¶134). The complaint further alleges Oswego violated HIPAA by implementing tracking technologies in a manner inconsistent with OCR guidance, sharing highly sensitive PHI such as health conditions, treatments, and medications without consent (Compl. ¶137-138). The complaint notes that criminal penalties for HIPAA violations can include fines of up to $250,000 and imprisonment for up to 10 years (42 U.S.C. § 1320(d)(6)(b)(1)) (Compl. ¶AMOUNTS). The complaint also references HHS OCR’s 2024 bulletin on the impermissible use of online tracking technologies by HIPAA-covered entities (Compl. ¶43).

ECPA Claims: Tracking Tools Allegedly Intercepted Electronic Communications

The complaint alleges Oswego violated the Electronic Communications Privacy Act (ECPA) by intentionally intercepting, using, and disclosing electronic communications via its tracking tools. The ECPA prohibits the intentional interception of electronic communications under 18 U.S.C. § 2511(1)(a), the intentional disclosure of intercepted communications under 18 U.S.C. § 2511(1)(c), and the intentional use of intercepted communications under 18 U.S.C. § 2511(1)(d). The complaint alleges Oswego’s tracking technologies, including DoubleClick and Google Ads, constituted “devices” under the ECPA that intercepted users’ electronic communications, such as medical searches and portal logins, and disclosed them to third parties (Compl. ¶298-299). The complaint defines “interception” under the ECPA as the “acquisition of the contents of any wire, electronic, or oral communication through the use of any electronic, mechanical, or other device” (Compl. ¶296). The complaint further alleges Oswego’s actions were undertaken for criminal or tortious purposes, invoking the ECPA’s crime-tort exception (18 U.S.C. § 2511(2)(d)) (Compl. ¶305).

Plaintiffs allege Oswego intercepted communications containing sensitive information, including medical searches, patient portal activity, and billing interactions, then disclosed them to Google and other third parties without consent. The complaint states that Oswego’s tracking technologies “planted a bug on the web browsers of its Users” and “intercepted” private communications “much like a traditional wiretap” (Compl. ¶74-75). The complaint alleges these interceptions included personally identifiable information (PII) and protected health information (PHI), such as names, email addresses, IP addresses, device identifiers, and medical conditions (Compl. ¶302). The complaint describes how Oswego’s tracking technologies captured both the characteristics and content of patient communications, stating, “Oswego’s tracking captures both the ‘characteristics’ of the communications (e.g., IP addresses, cookies) and the ‘content’ of the communications (e.g., the links clicked, the pages viewed, and the searches performed by the Users)” (Compl. ¶78).

The complaint alleges Oswego’s scheme included false and misleading privacy policies and disguised cookies to track plaintiffs and class members without their knowledge. The complaint states, “Oswego used deceit, including disguised cookies and false and misleading privacy policies, to track Plaintiffs and Class Members” (Compl. ¶314). The complaint further alleges Oswego acted with intent to defraud by invading plaintiffs’ property rights to confidentiality and their computing devices (Compl. ¶316-317). The complaint alleges Oswego willfully facilitated these interceptions without plaintiffs’ knowledge, consent, or express written authorization, as described in the complaint: “Oswego willfully facilitated these interceptions without Plaintiff Perry’s knowledge, consent, or express written authorization” (Compl. ¶218).

Common Law Claims: Negligence, Breach of Contract, and Unjust Enrichment

The complaint includes several common law claims, including negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, constructive bailment, and breach of the implied covenant of good faith and fair dealing. Plaintiffs allege Oswego owed a duty to safeguard their private information and breached that duty by failing to protect it from unauthorized disclosure. The complaint argues Oswego’s failures were reasonably foreseeable to result in harm, including loss of privacy, emotional distress, and ongoing risk of identity theft or discrimination (Compl. ¶327). The complaint alleges Oswego violated its duty to maintain patient privacy by failing to implement reasonable safeguards, stating, “Oswego failed to review or modify its security measures, and failed to implement access controls for electronic PHI” (Compl. ¶127).

In Count II, the complaint alleges Negligence under common law, asserting that Oswego breached its duty to protect plaintiffs’ private information by failing to implement reasonable safeguards. The complaint alleges Oswego’s negligence resulted in the unauthorized disclosure of plaintiffs’ PII and PHI to third parties, causing harm (Compl. ¶2). The complaint states that Oswego’s failures were reasonably foreseeable to result in unauthorized access to plaintiffs’ private information (Compl. ¶323).

In Count III, the complaint alleges Breach of Implied Contract under common law, asserting that Oswego entered into an implied contract with plaintiffs to safeguard their private information. The complaint alleges Oswego breached this contract by disclosing plaintiffs’ private information to third parties without consent (Compl. ¶3). The complaint states that Oswego required private information as a condition of using its web properties and services, creating an implied contract where Oswego agreed to safeguard that information (Compl. ¶331-332). The complaint further alleges Oswego’s privacy policy created a contractual obligation to protect plaintiffs’ private information, which Oswego breached by disclosing it to third parties (Compl. ¶114).

In Count IV, the complaint alleges Breach of Fiduciary Duty under common law, asserting that Oswego, as a healthcare provider, owed a fiduciary obligation to its patients to protect their private information. The complaint alleges Oswego breached this duty by disclosing plaintiffs’ private information to third parties without authorization (Compl. ¶4).

In Count V, the complaint alleges Unjust Enrichment under common law, asserting that Oswego was unjustly enriched by using patients’ private information without authorization or compensation. The complaint alleges Oswego benefited financially from the unauthorized disclosure of plaintiffs’ private information, either through direct compensation from Google or improved advertising efficiencies, while plaintiffs received no compensation for the use of their valuable data (Compl. ¶5). The complaint cites industry reports estimating the value of healthcare data at up to $250 per record on the black market, significantly higher than the $5.40 per record value of payment card records (Compl. ¶199). The complaint further notes that the estimated value of data monetization per user increased from $202 in 2018 to $434 in 2022, reflecting the growing value of personal data (Compl. ¶AMOUNTS). The complaint argues that Oswego’s unauthorized access to plaintiffs’ private information diminished its value, causing harm to plaintiffs, stating, “The unauthorized access to Plaintiffs’ and Class Members’ personal and Private Information has diminished the value of that information” (Compl. ¶206). The complaint also references a 2017 Time Magazine article describing the lucrative market for health data and the privacy risks associated with its collection, stating, “[d]e-identified patient data has become its own small economy: There’s a whole market of brokers who compile the data from providers...” (Compl. ¶201).

In Count VI, the complaint alleges Breach of Confidence under common law, asserting that Oswego violated its duty to maintain the confidentiality of patients’ private information by disclosing it to third parties without consent (Compl. ¶6).

In Count VII, the complaint alleges Constructive Bailment under common law, asserting that Oswego, as a bailee of plaintiffs’ private information, failed to safeguard it as required by law. The complaint alleges Oswego’s failure to protect plaintiffs’ private information constituted a breach of its bailment obligations (Compl. ¶7).

In Count VIII, the complaint alleges a violation of the Implied Covenant of Good Faith and Fair Dealing under common law, asserting that Oswego violated its obligation to act in good faith by handling plaintiffs’ private information in a manner that was inconsistent with their reasonable expectations (Compl. ¶8).

In Count XVII, the complaint alleges Breach of Reasonable Expectation of Privacy under common law, asserting that Oswego violated plaintiffs’ reasonable expectation that their private information would remain confidential and not be disclosed to third parties for commercial purposes. The complaint cites a statistic that 92% of Americans believe internet companies should be required to obtain consent before selling or sharing consumer data, stating, “92% of Americans believe that Internet companies... should be required to obtain consent before selling or sharing consumer data” (Compl. ¶164). The complaint alleges plaintiffs had a reasonable expectation that their PII and PHI would remain private and not be shared for commercial purposes (Compl. ¶161). The complaint further alleges plaintiffs would not have used Oswego’s web properties if they knew their data would be shared with third parties like Google (Compl. ¶162).

Additional Causes of Action: Deceptive Trade Practices, FTC Guidelines, and AMA Code of Ethics

The complaint also includes claims under New York’s Deceptive Trade Practices Act (NY GBL § 349), alleging Oswego engaged in deceptive acts and practices by misrepresenting its data-sharing practices in its privacy policy. In Count IX, the complaint alleges Oswego’s privacy policy falsely stated it would not share users’ private information with third parties without consent, while actively sharing such data with Google and other third parties (Compl. ¶9). The complaint further alleges Oswego’s misrepresentations regarding the use of cookies constituted deceptive trade practices (Compl. ¶105). The complaint quotes Oswego’s privacy policy, which stated, “The Oswego Health site may store files called ‘cookies’ on the user’s computer that contain usernames, passwords and other user preferences solely for the convenience of the user” (Compl. ¶105). The complaint alleges this statement was misleading, as Oswego’s cookies were used for cross-site ad targeting and linking browsing activity to users’ Google accounts.

In Count X, the complaint alleges Oswego violated the HIPAA Privacy Rule (45 C.F.R. §§ 160.103, 164.502, 164.508(a)(3), 164.514(b)(2)(i); 42 U.S.C. § 1320(d)(6)) by disclosing PHI and PII to third parties without authorization. The complaint alleges Oswego’s disclosures included IP addresses, URLs, and device identifiers linked to health data, which constitute PHI under HIPAA (Compl. ¶10). The complaint states that the fact that an individual is receiving medical services or is a patient of a particular entity can constitute PHI (Compl. ¶121). The complaint further alleges Oswego violated HIPAA by failing to obtain written authorization before using or disclosing PHI for marketing purposes, as required by 45 C.F.R. § 164.508(a)(3) (Compl. ¶123). The complaint alleges Oswego disclosed PHI to Google for marketing without the required written authorization, stating, “Oswego provided Plaintiffs’ and Class Members’ PII and PHI to third parties in violation of the Privacy Rule and its own Privacy Policy” (Compl. ¶124).

In Count XI, the complaint alleges Oswego violated the HIPAA Security Rule (45 C.F.R. §§ 164.306(a)(1)-(3), 164.308(a)(1), (a)(6)(ii), 164.312(a)(1), 164.530(c)) by failing to implement safeguards for electronic PHI. The complaint alleges Oswego failed to comply with requirements for confidentiality, security policies, incident response, and threat protection (Compl. ¶11). The complaint specifically alleges Oswego failed to implement access controls for electronic PHI, as required by 45 C.F.R. § 164.312(a)(1) (Compl. ¶127).

In Count XII, the complaint alleges Oswego violated New York Public Health Law § 18(6) by disclosing medical information without patient consent (Compl. ¶12). The complaint quotes the statute’s interpretation, stating, “This provision has been interpreted to require hospitals to obtain consent from the patient before disclosing medical records to an outside entity” (Compl. ¶157).

In Count XIII, the complaint alleges Oswego violated New York Public Health Law § 405.10(a)(6) by failing to obtain patient consent for medical record disclosure (Compl. ¶13).

In Count XIV, the complaint alleges Oswego violated New York Public Health Law § 405.10(a)(2) by failing to implement safeguards for medical record security (Compl. ¶14).

In Count XV, the complaint alleges Oswego violated FTC Data Security Guidelines by failing to implement reasonable data security practices to protect plaintiffs’ private information. The complaint cites FTC guidance warning healthcare companies against using tracking technologies to collect sensitive health information without patient consent. The complaint quotes the FTC, stating, “Don’t use behind-the-scenes tracking technologies that contradict your privacy promises or otherwise harm consumers” (Compl. ¶39). The complaint alleges Oswego failed to follow FTC guidelines, such as protecting personal information, encrypting data, and correcting security problems (Compl. ¶149). The complaint also references FTC enforcement actions against other healthcare companies for similar violations, including a $1.5 million penalty imposed on GoodRx for sharing PHI with advertising companies, a $7.8 million settlement with BetterHelp for sharing customer health data with Facebook and Snapchat, and a $100,000 civil penalty ordered against Easy Healthcare for violating the Health Breach Notification Rule (Compl. ¶41). The complaint further references a July 20, 2023, joint warning from the FTC and HHS to approximately 130 healthcare providers about unauthorized disclosures via tracking technologies (Compl. ¶42).

In Count XVI, the complaint alleges Oswego violated the American Medical Association (AMA) Code of Medical Ethics by disclosing patient data to third parties for commercial purposes without de-identification or consent. The complaint cites AMA Opinions 3.1.1, 3.2.4, and 3.3.2, which emphasize the importance of protecting patient confidentiality and obtaining consent for the use of patient data (Compl. ¶145-147). The complaint alleges Oswego’s unauthorized disclosures violated these ethical standards, stating, “Oswego violated the AMA Code of Medical Ethics by disclosing Plaintiffs’ and Class Members’ private information to third parties without de-identification or consent” (Compl. ¶145).

In Count XVIII, the complaint alleges Breach of Privacy Policy, asserting that Oswego’s misrepresentations regarding its data-sharing practices constituted both a breach of contract and a deceptive trade practice. The complaint alleges Oswego’s privacy policy created a contractual obligation to safeguard plaintiffs’ private information, which Oswego breached by disclosing it to third parties without consent (Compl. ¶18). The complaint quotes Oswego’s privacy policy, which stated, “The Oswego Health site may store files called ‘cookies’ on the user’s computer that contain usernames, passwords and other user preferences solely for the convenience of the user” (Compl. ¶105). The complaint alleges this statement was misleading, as Oswego’s cookies were used for cross-site ad targeting and linking browsing activity to users’ Google accounts. The complaint further alleges Oswego’s privacy policy misrepresented its data-sharing practices, stating, “Oswego’s Privacy Policy states that third-party vendors are not authorized to use PII for purposes other than the contracted services” (Compl. ¶104).

Class Action Seeks Relief for Affected Patients

The complaint defines the proposed class as all Oswego patients who visited Oswego’s web properties and whose private information was disclosed to a third party without their authorization or consent (Compl. ¶264). The complaint states, “All Oswego patients who visited Oswego’s Web Properties and whose Private Information was disclosed to a third party without their authorization or consent” (Compl. ¶264). A subclass is defined by specific actions, such as accessing patient portals, paying bills, or searching for medical services (Compl. ¶265). Plaintiffs allege common questions of law and fact predominate, including whether Oswego had a duty to protect plaintiffs’ private information, whether Oswego breached that duty, and whether Oswego violated its privacy policy and applicable laws (Compl. ¶269). The complaint states, “Whether and to what extent Defendant had a duty to protect Plaintiffs’ and Class Members’ Private Information” is a common question of law and fact (Compl. ¶269(a)). The complaint further alleges that class-wide injunctive relief is necessary to prevent ongoing harm, stating, “Unless a Class-wide injunction is issued, Defendant may continue in its failure to properly secure the Private Information of Class Members” (Compl. ¶277).

The complaint seeks class certification, injunctive relief to halt future disclosures, and damages, including statutory damages under the ECPA, which provides for damages of the greater of $100 per day for each day of the violation or $10,000 (Compl. ¶292). The complaint states, “statutory damages of whichever is the greater of $100 a day for each day of the violation or $10,000” (Compl. ¶292). Plaintiffs also seek compensatory and punitive damages, as well as disgorgement of profits derived from the unauthorized use of their private information. The complaint alleges over 50,000 individuals were affected by Oswego’s improper disclosure of PII and PHI (Compl. ¶268). The complaint notes that the industry-wide data monetization estimate for 2022 was $200 billion, reflecting the significant value of personal data (Compl. ¶AMOUNTS). The complaint also references the black-market value of healthcare data, which is estimated at $250 per record, compared to $5.40 per record for payment card data (Compl. ¶199).

Plaintiffs further seek to toll the statute of limitations under the “delayed discovery” rule, arguing they were unaware of the interception and disclosure of their data until recently (Compl. ¶262). The complaint states that Oswego’s tracking technologies operated invisibly, and plaintiffs had no reason to suspect their private information was being intercepted and shared with third parties. The complaint alleges Oswego’s headquarters are located at 110 W. Sixth St., Oswego, NY 13126 (Compl. ¶282).

The complaint provides detailed accounts of the named plaintiffs’ experiences with Oswego’s tracking technologies. Plaintiff Eva Perry alleges Oswego and Google intercepted her communications containing private information, including her IP address, device identifiers, location, patient status, medical services, treatments, and providers, without her consent (Compl. ¶217-219). The complaint states Perry began receiving targeted ads related to her medical conditions after the disclosure (Compl. ¶222). Plaintiff Jacqueline Fletcher similarly alleges Oswego and Google intercepted her communications containing private information without consent, and she began receiving targeted ads related to her medical conditions (Compl. ¶235-240). Plaintiff Debra L. Gilmore alleges Oswego and Google intercepted her communications containing private information without consent, and she suffered damages including invasion of privacy, violation of confidentiality, loss of benefit of the bargain, diminution of value, statutory damages, and ongoing risk (Compl. ¶253-259). The complaint states Gilmore continues to use Oswego’s website and portal for medical care and seeks protection of her future private information (Compl. ¶261).

The allegations described here are taken from the filing and remain unproven; no responsive pleading is reflected in the source document.

David Brunk is a civil litigation attorney. He can be reached at david@newmanbrunk.com.

From the Complaint Public Court Record

1 IN THE UNITED STATES DISTRICT COURT NORTHERN DISTRICT OF NEW YORK CLASS ACTION COMPLAINT Pla intiffs Eva Perry, Jacqueline Fletcher, and Debra L. Gilmore, through their attorneys, bring this class action lawsuit in their individual capacities and on behalf of all others similarly situated against Oswego Health, Inc. (“Oswego” or “Defendant”). Plaintiffs allege the following based on their personal knowledge, their counsel’s investigation, certain facts in the public record, and, where indicated, upon information and good faith belief. INTRODUCTION 1.Defendant Oswego is a regional healthcare system which serves Oswego County, New York, and the surrounding areas through its hospital, multiple urgent care centers, laboratory and imaging facilities, and multi-specialty medical group of over 100 physicians and medical providers. Oswego offers a broad range of primary and specialty care services, including cardiology, orthopedics, gastroenterology, ENT, general surgery, pulmonology, urology, and Plaintiffs, v. OSWEGO HEALTH, INC., Defendant. JURY TRIAL DEMANDED Case No. EVA PERRY, JACQUELINE FLETCHER, and DEBRA L. GILMORE, on behalf of themselves and all others similarly situated, 5:26-cv-1294 (BKS/CBF)

2 bariatrics, and it provides both hospital-based and outpatient care across the region. 1 2. Oswego generates approximately $233 million dollars in annual revenue. 3. As part of the medical services it provides, Oswego owns, operates, controls, and maintains a website, https://www.oswegohealth.org/ (the “Website”). The Website allows current and potential Oswego patients, inter alia, to search for and view medical providers and services, hospital and office locations, and various wellness resources. 4. Oswego also operates, controls, and maintains two web-based patient portals (the “Portals”). Oswego’s patient Portals allow Oswego patients, inter alia, to remotely access their medical records, review their test results, schedule a

Questions about this topic: david@newmanbrunk.com

Practice areas