Background graphic
Health Law Bulletins

Class certification warranted for hospital’s alleged use of tracking-pixel software in violation of privacy statutes

August 28, 2026

Doe v. Adventist Health System/West (July 24, 2026, B344951) __ Cal.App.5th __ [2026 WL 2474859]

Patients sued Adventist Health System/West, alleging its websites used Meta Pixel and Google Analytics tracking software to transmit personally identifiable information, patient communications, and protected health information without their consent. Plaintiffs asserted claims under the California Invasion of Privacy Act (CIPA) and the Confidentiality of Medical Information Act (CMIA), plus a common-law invasion of privacy claim. They sought class certification of subclasses for users of Adventist’s health risk assessment (HRA) form and patient portal. The trial court denied class certification, finding that predominance of common issues was lacking and that class treatment would not be superior. The court also ruled the patient portal subclass was not ascertainable. Plaintiffs appealed.

The Court of Appeal reversed on the HRA subclass and partially reversed on the patient portal subclass. The court held the patient portal subclass was ascertainable because Adventist and its portal provider maintained login records, and whether data transmissions violated CIPA or CMIA is a merits question rather than an ascertainability question. On predominance for the HRA subclass (limited to patients who submitted forms), plaintiffs showed that patient submissions uniformly generated full-string URL report links transmitted by tracking technology back to Meta and Google. Determining whether those transmissions violated the statutes by transferring “content” was subject to common proof, rather than individual inquiry, by adopting the federal Wiretap Act’s definition of “contents.” Applying J.M. v. Illuminate Education, Inc. (2026) 19 Cal.5th 705, the court decided that the HRA reports “undoubtedly” contained “medical information” because they contained information “regarding” patients’ medical history, condition, or treatment. The court further held that whether third-party algorithmic processing of transmitted data constitutes unauthorized “viewing” or “access” to medical information—an element required to state a CMIA violation—presents a common merits question susceptible to classwide resolution.

For the patient portal subclass, the court reversed on the CIPA wiretapping theory (uniform login data could commonly prove transmission of communication contents), but affirmed denial of CMIA certification because the URL descriptors generated by individual portal activity varied by patient, raising individual issues as to whether each transmission contained “medical information.” Finally, the court concluded the HRA subclass and the remaining claims for the patient portal subclass satisfied the superiority and manageability requirements, and that class certification was the most efficient means of adjudicating the common questions.

Related Attorneys

Class certification warranted for hospital’s alleged use of tracking-pixel software in violation of privacy statutes

H. Thomas Watson

Partner Los Angeles
Class certification warranted for hospital’s alleged use of tracking-pixel software in violation of privacy statutes

Peder K. Batalden

Partner Los Angeles
Class certification warranted for hospital’s alleged use of tracking-pixel software in violation of privacy statutes

Lacey L. Estudillo

Counsel San Francisco

Put Our Proven Appellate Expertise to Work for You.

For over 60 years, we've preserved judgments, reversed errors, and reduced awards in some of California’s most high-profile appellate cases.

Explore our practices Explore Careers
Horvitz