Coast Studio
Book a Consultation
  • Methodology
  • Growth LabsEcommerce & DTC Scale Regulated MarketsHealth, Fintech & Legal
  • Creative
  • Case Studies
  • Blog
  • About
  • Methodology
  • Growth Labs
  • Regulated Markets
  • Creative
  • Case Studies
  • Blog
  • About
  • Book Consultation →
Home / Blog / What Is CIPA & the Demand Letters?

HIPAA Tracking · Q&A

What Is CIPA, and Why Are Health Brands Getting Demand Letters?

Last updated: August 10, 2026 ยท By Jason Garrett, Founder, Coast Studio. Not legal advice. Full legal landscape: The State of HIPAA Tracking.

CIPA is California's wiretapping statute, and plaintiff firms have turned it into a mass-demand-letter machine aimed at tracking pixels. For many health brands, a CIPA letter is the first sign anyone outside marketing noticed their pixel.

How a 1960s wiretap law hits a pixel

CIPA bars intercepting a communication without consent. Plaintiff firms argue that a third-party pixel — Meta's, TikTok's, a session recorder — "intercepts" a visitor's interaction with your site in real time and ships it to the vendor. On a health site, the intercepted interaction reveals a condition, which raises the stakes. The theory does not need a data breach or actual harm; the interception itself is the claim.

Why the letters come in waves

The letters are cheap to send and easy to template. A firm scans sites for known trackers, identifies health context, and mails demands at volume, betting that many recipients settle rather than litigate. CIPA demand letters have become their own cottage industry, and health brands are prime targets because the health context strengthens the claim.

What to do if you get one

  1. Send it to counsel immediately. Do not respond directly, and do not ignore it.
  2. Preserve evidence, then audit what your pixels actually transmit — the letter is often a template, but your exposure is specific. See our pixel-audit checklist.
  3. Fix the root cause. Move to server-side, scrubbed tracking and consent gating so the interception theory has nothing to grab.

FAQ

Is a CIPA letter a lawsuit? Not yet. It is a demand, usually seeking a settlement. But it can become a suit, and it signals a real exposure worth fixing.

Does a cookie consent banner defeat CIPA? A true opt-in gate that blocks trackers until consent is the strongest defense. A banner that fires tags on load does little.

We're not in California. Does CIPA reach us? It reaches interactions with California residents. As with MHMDA, the user's location drives exposure, not yours.

Related

  • The State of HIPAA-Compliant Marketing Tracking
  • Is the Meta Pixel HIPAA Compliant?
  • Healthcare Pixel Audit Checklist
  • Does MHMDA Apply to My Marketing?
JG

Jason Garrett

Founder & CEO of Coast Studio, a performance marketing agency for regulated industries — health & wellness, healthtech, fintech, and legal. Jason writes about privacy-compliant tracking and paid acquisition for publications including Ours Privacy and Curve. Not legal advice — validate decisions about your stack with your privacy counsel.

Connect on LinkedIn →

Sorting out your exposure?

Coast Studio runs compliance-first paid media for regulated health brands — we map your legal exposure and build tracking that holds up. Not legal advice.

Book a Consultation
Coast Studio

© 2026 Left Coast Agency, LLC.

AboutJason GarrettBlogPrivacyTermsContact
Google Partner