California SB 690 and CIPA: What Health Websites Face
California SB 690 ends private CIPA pen register suits over website tracking from 2027, but wiretap claims stay. Here is what health websites face.
California SB 690 takes away private lawsuits under the pen register and trap and trace section of the California Invasion of Privacy Act (CIPA), Penal Code §638.51, over website and app tracking, and leaves those claims to the Attorney General; private CIPA wiretap claims under §631 are not changed. Governor Newsom signed it on September 30, 2026 as Chapter 976, it takes effect on January 1, 2027, and it reaches pending claims in suits commenced within two years before its operative date. For health websites, CIPA risk from tracking narrows; it does not end. Curve Compliance helps with server-side conversions that send each platform a fixed list of fields, detection of PHI-like patterns before data reaches an ad platform, consent management, and a BAA on every plan.
Book a call. Curve's team will review what your website sends to Meta, Google and TikTok with you, then set up server-side conversions and consent management under a BAA on every plan. Book a call with Curve.
What SB 690 changes
SB 690 amends one section of the Penal Code, §637.2, the section that lets people sue over CIPA violations. The chaptered text adds a new subdivision (d)(1): "An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General." The Legislative Counsel's Digest says the bill "would instead authorize only the Attorney General to bring that action."
Section 638.51 says a person "may not install or use a pen register or a trap and trace device without first obtaining a court order." Section 638.50 defines a pen register as "a device or process that records or decodes dialing, routing, addressing, or signaling information" and defines a trap and trace device in similar terms. Both definitions carry the same limit: "but not the contents of a communication." That carve-out explains what SB 690 leaves behind.
In his signing message, the Governor wrote that the bill "eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for violations of the pen register and trap-and-trace statute arising from conduct occurring on an internet website, online application, or mobile application." He said it addresses "the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site."
What SB 690 does not change
The new subdivision (d) names only Section 638.51. The rest of §637.2 as amended still reads: "Except as provided in subdivision (d), a person who has been injured by a violation of this chapter may bring an action against the person who committed the violation" for the greater of "Five thousand dollars ($5,000) per violation" or three times actual damages. A plaintiff still does not need to have "suffered, or be threatened with, actual damages." So private suits under CIPA's other sections keep that remedy.
| Penal Code section | What the statute covers | Private suits over website or app conduct after SB 690 |
|---|---|---|
| §631, wiretapping | Trying "to learn the contents or meaning of any message, report, or communication while the same is in transit" without "the consent of all parties to the communication" | Not changed. Private suits stay open under §637.2(a). |
| §632, eavesdropping and recording | Using a device to "eavesdrop upon or record the confidential communication" without the consent of all parties | Not changed. |
| §632.7, recording calls | Recording a call that involves a cellular or cordless phone "without the consent of all of the parties to a communication" | Not changed. |
| §638.51, pen register and trap and trace | Using "a pen register or a trap and trace device without first obtaining a court order" | Only the Attorney General may sue a private actor over website or app conduct (§637.2(d)(1)). |
SB 690 is "An act to amend Section 637.2 of the Penal Code," so HIPAA is untouched. The HHS tracking bulletin still says regulated entities "are not permitted to use tracking technologies in a manner that would result in impermissible disclosures" of PHI, apart from the part HHS says a court vacated on June 20, 2024 (annotated here). For other California laws, see our CMIA and CCPA guide.
When SB 690 takes effect, and which cases it reaches
The bill text shows it was approved by the Governor and filed with the Secretary of State on September 30, 2026. Its status page lists it as "Non-Urgency." Under Article IV, section 8 of the California Constitution, a statute enacted at a regular session "shall go into effect on January 1 next following a 90-day period from the date of enactment of the statute." For a bill enacted on September 30, 2026, that is January 1, 2027. Until then, the current §637.2 on leginfo has no Attorney General limit.
The new subdivision (d)(2) makes the change reach back. The amendments "apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation" (SB 690). The bill gives no calendar date for that window. The only claims these amendments limit are §638.51 claims against a private actor over website or app conduct.
Why health websites still face CIPA claims
For website and app conduct, SB 690 removes private suits built on routing and addressing information. It leaves the theories built on what a visitor says, searches or types. On a health website that is the sensitive part: a search for a condition, the page about a treatment, the answers on an intake form, a chat message, a recorded call.
The Washington Supreme Court's Baker opinion, filed October 8, 2026, describes the kind of tracking these suits target. As alleged there, when a visitor searched a hospital site for a condition, Pixel "records and relays the content of this search to Meta." The plaintiffs also pointed out that "courts have denied motions to dismiss claims alleging that conduct similar to SCH's actions here violate the federal wiretap act or California's privacy act." For a running list of how pixel cases have ended, see pixel settlements to date and healthcare pixel lawsuits in 2026.
More change may come: the Governor's signing message says "CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants" and urges "the Legislature to take this on next year." Tools that capture what visitors type sit closest to §631's words about "the contents or meaning" of a communication; see our guides on session replay and chat widgets.
Washington's Baker ruling: what it decided and what it did not
On October 8, 2026, the Washington Supreme Court ruled in Baker v. Seattle Children's Hospital, No. 104590-5. It held that RCW 9.73.030(1)(a) "excludes searches and clicks that generate an automated response from SCH's website," and it affirmed dismissal of the claim under the Washington privacy act. That statute protects communications "between two or more individuals," and each search or click involved one individual and "a fully automated system."
Three limits matter. The court wrote: "We therefore limit our review to the plaintiffs' activities on SCH's public website." The plaintiffs did not appeal their other claims, and the opinion "does not address the sufficiency of those claims." Justice González concurred only in the result and added: "A message to a member of a care team is not before us, nor is the application of our privacy act to a system that does more than return stored content." The majority also said California's privacy act "likewise differs significantly" from Washington's, so Baker does not decide CIPA cases (opinion). Washington's health data law is a separate matter (MHMDA checklist).
Video pages and the VPPA: Salazar v. Paramount Global
A federal law, the Video Privacy Protection Act (VPPA), is also before the U.S. Supreme Court. The docket for No. 25-459 shows "Petition GRANTED" on January 26, 2026 and "SET FOR ARGUMENT on Wednesday, October 14, 2026." Its latest entry, dated August 20, 2026, records the lower court record arriving. As of October 10, 2026, the case has not been argued or decided.
The question presented is whether the VPPA's phrase "goods or services from a video tape service provider" "refers to all of a video tape service provider's goods or services or only to its audiovisual goods or services." Health brands that post videos on pages carrying an ad pixel should follow the ruling.
What to review on a health website before January 2027
- List every tag on your pages. Run the free Curve Compliance scanner; it lists the tracking scripts on a page with a risk level for each.
- Start with pages that carry health context. Condition pages, site search, booking, intake forms, chat and portal sign-in.
- Check what each tag sends. Page URLs, search terms, form fields and button text. SB 690 does not reach §631 claims about contents.
- Ask before tags fire. Apply each visitor's consent choice before tags run, and record it.
- Mask what visitors type. Replay and chat tools should mask form fields and free text.
- Check call recording. Section 632.7 bars recording calls that involve a cell or cordless phone without the consent of all parties.
- Get a BAA from every vendor that receives PHI. HHS says regulated entities "must ensure that all tracking technology vendors have signed a BAA" (HHS bulletin).
How Curve Compliance helps
Curve Compliance replaces browser ad pixels with one script and sends conversions server-side from Curve's servers to Meta, Google Ads, TikTok, Microsoft Advertising and LinkedIn. Each platform receives only a fixed list of fields. Contact identifiers are off by default and SHA-256 hashed when enabled, and events can use neutral names. Curve detects PHI-like patterns, such as condition names, form answers and emails in URLs, before data reaches an ad platform, and flags them so they can be stopped at the source. Event Logs show what Curve sent to each platform and what the platform accepted. See moving from pixels to server-side.
Curve's consent management applies the right rule for each visitor's region, records every decision, and holds back tracking and ad forwarding until a visitor's choice allows it. It treats Global Privacy Control as a decline of advertising. Session replay and heatmaps run under the same BAA, with form fields and text inputs masked by default. Curve signs a BAA on every plan (BAA Directory entry), and Curve's team does the setup; most customers are live in about a week.
You get a clear record of what Curve sends to each ad platform. For your own exposure under CIPA or HIPAA, talk to your counsel, and book a call with Curve to see your setup.
Sources, checked October 10, 2026: SB 690, chaptered text; SB 690 status; SB 690 history; Governor's SB 690 signing message; Penal Code §631, §632, §632.7, §637.2, §638.50 and §638.51; California Constitution, art. IV, §8; Baker v. Seattle Children's Hospital, Wash. Sup. Ct. No. 104590-5; Salazar v. Paramount Global, No. 25-459, docket and question presented; and HHS, online tracking technologies.
Frequently Asked Questions
What is California SB 690?
SB 690, Chapter 976 of 2026, amends Penal Code §637.2 so that, once it takes effect, a private plaintiff cannot sue a private actor under CIPA's pen register and trap and trace section, §638.51, over conduct on "an internet website, online application, or mobile application." Only the Attorney General can bring that action (SB 690).
Does SB 690 end CIPA lawsuits over the Meta Pixel?
No. It ends private suits under one section, §638.51, for website and app conduct. Private claims under §631, §632 and §632.7 are not changed, and §637.2 still lets an injured person sue. The Governor's signing message says CIPA "contains other decades-old statutes that are also susceptible to abuse" and asks the Legislature to act next year.
When does SB 690 take effect?
January 1, 2027. It was approved on September 30, 2026 as a non-urgency bill (status), and the California Constitution puts such statutes into effect "on January 1 next following a 90-day period from the date of enactment of the statute."
Does SB 690 apply to lawsuits already filed?
Yes, for pending §638.51 website and app claims in suits filed within the window. The amendments "apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation" (SB 690). It does not reach claims under §631 or other sections.
Can the California Attorney General still sue over website tracking?
Yes. Under the new §637.2(d)(1), a §638.51 action over website or app conduct "may be brought under this section only by the Attorney General" (SB 690). SB 690 does not limit the Attorney General.
Is session replay or chat still a CIPA risk?
SB 690 does not change §631, which covers trying to learn "the contents or meaning" of a communication in transit without the consent of all parties. Curve Compliance masks form fields and text inputs in session replay by default, under the same BAA, and its consent settings can switch California to opt-in, so recordings wait until a visitor accepts.
Did the Washington Supreme Court say hospital pixels are legal?
No. In Baker v. Seattle Children's Hospital (October 8, 2026), the court held only that Washington's privacy act does not cover searches and clicks that get an automated response from a hospital's public website. It did not address the plaintiffs' other claims or patient portal messages.
Does SB 690 change anything under HIPAA?
No. SB 690 amends one section of California's Penal Code. HIPAA is federal law, and the HHS bulletin on tracking technologies still applies, apart from the part a federal court vacated on June 20, 2024. A BAA is a HIPAA contract; CIPA is a separate state law.
Talk to Curve Compliance
Book a call. Curve's team will review what your website sends to Meta, Google and TikTok with you, set up server-side conversions and consent management, and sign a BAA on every plan. Most customers are live in about a week. Book a call with Curve.
Related articles
- GuideCalifornia CPRA and Healthcare Marketing: Lessons from the Healthline $1.55 Million Penalty
- GuideState Attorneys General Are Joining Federal Pixel Cases: California and Utah in the Hims Complaint
- GuideCalifornia CMIA and CCPA: Healthcare Marketing Compliance for Golden State Practices
- GuideHow to Make Facebook Ads HIPAA Compliant and Keep Tracking
Check your own site
See if your website is at risk. Enter your domain to scan it for tracking scripts that can expose patient data.
Stay Compliant. Scale Confidently.
Curve's team sets up HIPAA-compliant ad tracking for you, and most customers are live in about a week.
Book a free tracking audit