MyChart and Website Tracking Claims in Michigan
Michigan has become an active venue for website-tracking litigation, including a case brought against Blue Cross Blue Shield of Michigan over pixels on its public sites. The claims run on the Michigan Eavesdropping Statute together with the federal Wiretap Act. This page explains why both are pleaded together — the answer is a Michigan court decision that makes the state statute harder to use than its text suggests.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What These Cases Allege
The allegation is that health systems, insurers and other organisations installed third-party tracking technology — pixels, cookies, session-replay tools, chat widgets — on their websites and patient portals, and that this code transmitted identifying information about visitors' activity to outside analytics and advertising companies without adequate notice or consent. In the Michigan case brought against Blue Cross Blue Shield of Michigan, the complaint centres on pixels on public-facing websites capturing information tied to what visitors did there and passing it to third-party vendors. The defendants generally deny that the information was private or that anyone was concretely harmed.
Case Details
Michigan claims of this type are brought under the Michigan Eavesdropping Statute, MCL 750.539a et seq., together with the federal Wiretap Act, 18 U.S.C. § 2510 et seq. Falls v. Blue Cross Blue Shield of Michigan Mutual Insurance Company was filed in the United States District Court for the Eastern District of Michigan. Similar claims are filed in Michigan state courts and in the Western District.
Where Michigan Claims Stand
Michigan is now part of a very large national wave. Roughly 4,000 digital wiretapping cases have been filed across the United States since 2022, targeting website tracking technologies including cookies, pixels, session-replay tools and chat features. Michigan's arrival in that wave is recent, and the case against Blue Cross Blue Shield of Michigan in the Eastern District is the one drawing attention.
The statute is stronger on paper than in practice. The Michigan Eavesdropping Statute, MCL 750.539a and following, reads as though it requires consent from everyone involved in a private conversation. But Michigan courts have held that a participant in a conversation may record it — which, if a website operator is treated as a participant in the exchange with a visitor, removes the obstacle the statute appears to create. That is why complaints in Michigan almost always plead the federal Wiretap Act alongside the state claim rather than relying on state law alone.
No global Michigan settlement exists. These are individual cases against individual organisations, at different stages, with no central claims process. Where a specific case settles, that settlement has its own administrator, class definition and deadline, announced for that case only.
Who These Claims Involve
The claims generally involve Michigan residents who used a health system's, insurer's or provider's website or patient portal during a period when that organisation had third-party tracking code installed, where the activity was identifiable as health-related — looking up a condition, requesting an appointment, using a portal feature.
What matters in practice:
- The specific organisation and period define the class. There is no Michigan-wide group. Each case covers one defendant's website over one defined period, established from that organisation's records rather than from your recollection.
- Insurer websites count, not only hospitals. The prominent Michigan case concerns an insurer's public-facing sites. Tracking claims are not limited to clinical portals.
- Notice usually arrives from the case, not from the company. Most people learn they are in a class when a court-approved notice is sent, which happens well into the litigation.
If you believe you were affected, the useful step is establishing which organisation's site you used and roughly when — that is what determines whether any existing case reaches you.
What These Cases Realistically Pay
Website-tracking settlements have generally landed in the hundreds of thousands to low millions of dollars per defendant, shared among classes that often number in the hundreds of thousands. Divided out, individual payments in resolved cases of this type have commonly been modest — tens of dollars is a normal outcome, with more where documented harm exists.
The number that causes the most confusion is statutory damages. Wiretapping statutes specify per-violation amounts, and advertising quotes them as if each class member collects one. In reality those figures function as a negotiating ceiling; settlements reflect what a defendant can pay and a court will approve.
There is no Michigan figure to quote. Value depends on which organisation, which period, what data and how the participant-recording problem is resolved in that particular case. A firm offering you a number before knowing those things is advertising, not assessing.
How Michigan Got Here
- 1
Michigan's Eavesdropping Statute
MCL 750.539a and following prohibits eavesdropping on private conversations. Its text reads as a broad protection, and it carries criminal as well as civil consequences.
- 2
Michigan courts read in a participant exception
Michigan case law establishes that a participant in a conversation may record it. Applied to websites, where the operator is arguably a participant in its exchange with a visitor, this substantially weakens the state statute as a standalone basis for tracking claims.
- 3
2022 — the national wave begins
Following reporting on tracking pixels transmitting health information to advertising platforms, roughly 4,000 digital wiretapping cases are filed nationwide over the following years, targeting cookies, pixels, session-replay tools and chat features.
- 4
Healthcare providers begin settling elsewhere
Health systems in other states resolve pixel class actions, establishing a pattern: per-defendant settlements in the hundreds of thousands to low millions, distributed across very large classes.
- 5
Michigan enters the map
Falls v. Blue Cross Blue Shield of Michigan is filed in the Eastern District of Michigan, alleging that tracking pixels on public-facing websites collected and transmitted personally identifiable information to third-party vendors without adequate notice or consent, under both the Michigan Eavesdropping Statute and the federal Wiretap Act.
- 6
August 2026 — where it stands
The Michigan litigation is active, with no global settlement and no central claims process. Individual cases proceed on their own timetables against individual defendants.
What to Be Careful About
Health-privacy litigation generates a great deal of advertising, and some of it is inaccurate in ways that cost people money. These are the patterns worth recognising.
"Check if you qualify" pages that only collect your details
Many sites offering a Michigan MyChart eligibility check are lead-generation pages that pass your information to whichever firm pays most, without assessing anything. A genuine assessment asks which provider's portal you used and roughly when, because that is what determines whether any particular case covers you. A page that asks only for a name, email and phone number has not checked anything.
Sites treating the Blue Cross case as an open claim window
The Michigan case against Blue Cross Blue Shield of Michigan is active litigation, not a settlement. There is no claim form, no administrator and no deadline attached to it. Any page inviting you to file a claim against it is describing a process that does not exist. If that case ever settles, notice would come from a court-approved administrator, and joining would not require paying anyone a fee.
Messages asking you to confirm patient-portal credentials
No legitimate settlement administrator and no law firm needs your MyChart username or password. Cases of this kind are proven from the provider's own records and from what the provider's website transmitted, not from anything inside your account. Anyone asking you to log in through a link they sent is after the account, not the claim. If you want to check a notice, go to your provider's own site or the administrator's published address directly.
Common Questions
Is there a Michigan MyChart settlement I can claim from?
No. Michigan website-tracking claims are individual cases against individual organisations, and none of them operates a general claims process for Michigan residents. Where a specific case settles, a court-approved administrator issues notice to that case's class, with its own definition and deadline. There is no statewide fund and nothing to file today.
What is the Michigan Eavesdropping Statute?
MCL 750.539a and following, Michigan's law against eavesdropping on private conversations. It is used in tracking cases on the theory that transmitting a visitor's activity to a third party without consent is an interception of a private communication. Its text is broad, but Michigan courts have held that a participant in a conversation may record it — and if a website operator counts as a participant, that reading substantially narrows the statute in this context.
Then why is the statute used at all?
Because the participant question is genuinely contested when applied to websites, and because pleading state and federal claims together gives a case more than one route. The federal Wiretap Act, 18 U.S.C. § 2510 and following, is pleaded alongside the Michigan statute in these complaints for exactly that reason. Whether the state claim survives is one of the questions the litigation is there to answer.
The case is against an insurer, not a hospital. Does that matter?
It matters mainly because it shows the reach of these claims. Website-tracking litigation is not confined to clinical patient portals; it extends to insurer sites, pharmacy sites and any page where a visitor's activity suggests something about their health. The legal theory is about what the code transmitted and whether the visitor consented, not about what kind of organisation ran the site.
How would I know whether I am in a class?
Court-approved notice is the reliable route: if a class is certified or a settlement is approved, an administrator sends notice to people identified from the defendant's own records. In the meantime, what you can establish yourself is which organisations' sites and portals you used and roughly when. That is the information a lawyer needs to tell you whether any existing case reaches you.
Do I need to prove I was harmed?
It depends on the claim. Statutory claims of this kind are often framed so that the violation itself is the injury, which is why they are brought under wiretapping and consumer-protection statutes rather than as ordinary negligence. Federal courts have nevertheless required plaintiffs to show a concrete injury to get through the courthouse door, and that requirement is where several of these cases have run into trouble. It is a live legal question, not a settled one.
How would I even know if my data was shared?
Usually you would not, which is a large part of why these cases exist. Tracking code runs invisibly in the background of a web page. In practice people find out one of three ways: the provider sends a breach or privacy notice, a court-approved class notice arrives by post or email, or news coverage names a provider they used. If you used MyChart or another patient portal in Michigan and are not sure, checking whether your provider has published a notice is the sensible first step.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.