California Narrows Website Tracking Lawsuits (10/01/2026)
- › California's SB 690, signed September 30, ends private pen register and trap and trace claims under CIPA for tracking on websites and apps, effective January 1, 2027.
- › The law reaches pending claims filed within two years of that date, but wiretapping claims under Section 631 and other theories remain available.
- › The SEC's Division of Examinations published a handbook walking registrants through an exam from risk assessment to the closing letter.
- › OCR issued guidance on when state Medicaid agencies can use protected substance use disorder records to confirm exemptions from work requirements.
- › A California law firm reported a breach affecting patients of a hospital client, a reminder that outside counsel holds health data too.
California’s website tracking lawsuits became their own small industry: a plaintiff visits a site, a tracking pixel fires, and a demand letter follows claiming the pixel was an illegal pen register under a decades-old wiretapping law. SB 690 closes the most common version of that claim, and it reaches back to some suits already on file. It does not end the litigation, though, and the compliance work on your tags and consent banners remains just as necessary.
Top 5 Critical Compliance Alerts
1. California’s SB 690 Ends Pen Register Claims Over Website Tracking
Governor Newsom signed SB 690 on September 30, ending the private right of action against private businesses for alleged violations of California Invasion of Privacy Act Section 638.51, the pen register and trap and trace provision, arising from conduct on websites and mobile applications, per Fox Rothschild. It takes effect January 1, 2027, and applies to pending claims in actions filed within two years before that date. Claims under Section 631 for interception of communications are untouched, and plaintiffs are already shifting to federal wiretap law, California’s computer fraud statute, unfair competition, and common law privacy theories.
Operator Note: Treat this as relief on one theory and not as permission. Keep an accurate inventory of the tags on your site, what they send and to whom, and make sure your consent banner does what it says before a plaintiff tests the other theories.
2. The SEC Publishes an Exam Handbook
The SEC’s Division of Examinations published “The SEC Exam Handbook: A Practical Guide on Process and Engagement,” replacing its earlier brochure with a stage-by-stage account of an exam from risk assessment through the disposition letter, per the SEC. Division Director Keith Cassidy said the aim is to make the process “more consistent and predictable.”
Operator Note: Registered advisers and broker-dealers should walk through the handbook’s stages now and decide who owns each one, so the first request of the next exam does not start that conversation.
3. OCR Explains When SUD Records Can Confirm Medicaid Work Exemptions
The HHS Office for Civil Rights issued guidance on when state Medicaid agencies can use substance use disorder records protected under 42 CFR Part 2 to verify that adults aged 19 to 64 are exempt from Medicaid community engagement requirements of roughly 80 hours a month, per the HIPAA Journal. OCR Director Paula Stannard said the aim is to let states use information they already hold “while continuing to protect the confidentiality of SUD patient records.”
4. A Law Firm Breach Reaches a Hospital’s Patients
Buchalter, a California law firm, reported that an unauthorized third party accessed limited patient data belonging to its client Arrowhead Regional Medical Center in Colton, discovered on August 28, and Ohio’s Saber Healthcare reported a server breach affecting more than 3,000 people, per the HIPAA Journal.
Operator Note: Outside counsel often holds patient data for litigation and investigations, and it sits outside your own controls. Confirm your law firms are covered by business associate agreements where required and ask what security review they have passed.
5. CPAP Medical Supplies Settles Its Breach Suit for Up to $500,000
CPAP Medical Supplies and Services of Jacksonville agreed to pay up to $500,000 to resolve litigation over a December 2024 breach affecting 90,133 patients and employees, with two years of medical data monitoring and up to $5,000 in documented losses per person, per the HIPAA Journal.
Additional Compliance Alerts
Regulatory Updates
- The European Commission proposes an EU KIDS Act: The September 17 proposal would set a harmonized framework for how children use online services. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.