Doe v. Adventist Health System/West CA2/3

California Court of Appeal·Decided July 24, 2026·No. B344951·Unpublished

Opinion

Filed 7/24/26 Doe v. Adventist Health System/West CA2/3 NOT TO BE PUBLISHED IN THE OFFICIAL REPORTS California Rules of Court, rule 8.1115(a), prohibits courts and parties from citing or relying on opinions not certified for publication or ordered published, except as specified by rule 8.1115(b). This opinion has not been certified for publication or ordered published for purposes of rule 8.1115.

IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA

SECOND APPELLATE DISTRICT

DIVISION THREE

JAMES DOE et al., B344951

Plaintiffs and Appellants, Los Angeles County Super. Ct. No. v. 22STCV36304

ADVENTIST HEALTH SYSTEM/ WEST,

Defendant and Respondent.

APPEAL from an order of the Superior Court of Los Angeles County, Laura A. Seigle, Judge. Affirmed in part, reversed in part, and remanded. Caddell & Chapman, Michael A. Caddell, Cynthia B. Chapman, Amy E. Tabor; Ahmad, Zavitsanos & Mensing, Foster C. Johnson, Kelsi White; LippSmith, Graham B. LippSmith, MaryBeth LippSmith and Jaclyn L. Anderson for Plaintiffs and Appellants. Seyfarth Shaw, Kristine Rinella Argentine and Sierra J. Chinn-Liu for Defendant and Respondent _________________________ Plaintiffs—four Does who are or were patients of defendant Adventist Health System/West (Adventist)—brought this putative class action asserting claims against Adventist for, among others, violations of the California Invasion of Privacy Act (CIPA) (Pen. Code, §§ 630 et seq.)1 and the California Confidentiality of Medical Information Act (CMIA). Plaintiffs alleged Adventist shared (without their knowledge) their—and similarly situated patients’—personal information with third parties through web-based tracking technologies—the Meta Pixel and/or Google Analytics—installed on Adventist’s websites, including its public health risk assessment (HRA) website and its password-protected patient portal. The tools allegedly tracked site users’ activities, collected their data, and sent the information—including personally identifiable information, the contents of users’ communications with Adventist, and protected health information (PHI)—to Facebook (Meta) and Google, who shared the data with advertisers. Plaintiffs sought to certify a class consisting of Adventist patients with California addresses who—for the period from November 16, 2017 to April 30, 2024—“used the Adventist website or patient portal to exchange communications with Adventist . . . for researching medical conditions or treatments, finding a physician, making an appointment, or submitting a health risk assessment form” (general class), and four subclasses. Only two subclasses are relevant to this appeal: (1) the patient portal subclass, consisting of all class members “who were logged into Adventist[’s] . . . patient portal up until May 2023”;

1 Undesignated statutory references are to the Penal Code.

2 and (2) the HRA form subclass, consisting of all class members “who submitted an online [HRA] form to Adventist.” The trial court denied plaintiffs’ motion in its entirety. Plaintiffs appeal from the trial court’s denial of class certification of the patient portal and HRA form subclasses only. The trial court concluded, as relevant here, plaintiffs failed to establish: (1) the patient portal class was ascertainable, (2) common issues predominated over individual ones for both subclasses, and (3) the superiority and manageability of a class action. The court also found plaintiffs had “dropped any attempt to certify a class” for violations of CIPA under section 632. The court primarily reasoned that determining whether the data the tracking technologies sent to third parties contained the “contents” of users’ communications (CIPA) or users’ “medical information” (CMIA) would require an individual inquiry into the information transmitted for each user. The court also reasoned that plaintiffs had not explained how to ascertain which of the patients who had logged into the patient portal had engaged in activities that resulted in transmission of actionable information. Plaintiffs challenge the rulings, arguing the undisputed record evidence showed the patient portal class was ascertainable; the court misunderstood the record, misapplied the definition of “medical information,” ignored plaintiffs’ theory of liability, and prematurely determined the merits in finding common issues did not predominate; and they demonstrated the manageability of the two subclasses and superiority of a class action to individual trials. We reverse the court’s denial of class certification of the HRA form subclass and partially reverse as to the patient portal subclass.

3 BACKGROUND 1. Background on tracking technologies2 A web browser communicates with a website’s servers to download and display the website’s content on the user’s screen. To do so, the web browser sends HTTP (hypertext transfer protocol) requests to download files from the website’s servers.3 The HTTP request “contains an IP address, which [is] an identifier assigned to any Internet-connected device,” as well as “a URL, which represents the address of the file that a web browser is requesting from a web server,” and the “[u]ser [a]gent,” which “identifies the details of the operating system and web browser.” “A URL contains the server’s domain name, the path of the file located on the server that is being requested, and a list of query parameters that contain additional information being sent from a web browser to a web server.” “Cookies” are “used by web servers to keep track of past interactions with the web browser.” Cookies can store “identifiers” “used to identify a specific user account or a specific device/browser.” “Third-party cookies”—set by a third-party server—“allow cross-site tracking of a user across different websites.” On the other hand, “first-party cookies”—set by the first-party server—“allow same-site tracking of a user on a particular website.”

2 We glean most of this background from the report of plaintiffs’ expert Dr. Zubair Shafiq. Quoted material omits footnote references. 3 The first HTTP request sent “is typically for the Hypertext Markup Language (HTML) file.” The HTML file contains the source code or content of a webpage.

4 A “tracking pixel”—such as the Meta Pixel and Google Analytics—is a piece of code or image “that is used to track users’ browsing activity on the web.” “When a tracking pixel is installed on a website by a first party, it allows a third party (i.e., a domain that is different from the first-party website that a user navigates to) to track a user across different websites where the tracking pixel is installed. Put simply, a tracking pixel allows a third party to tell that a user visited website A at time A, website B at time B, and so on.” Tracking pixels “also ghostwrite first-party cookies on the visited website’s domain to circumvent third-party cookie blocking.” A tracking pixel collects “two types of data”—“identifiers” and “browsing activity”—“in HTTP requests from a user’s web browser to the tracking pixel’s web server.” “Identifiers” are collected through cookies stored by the web browser, and “the combination of IP address and user agent in the transmission from a user’s web browser to the pixel’s web server.” Identifiers stored in cookies can include “account identifiers”—“that uniquely identify the user visiting the website” akin to a driver’s license number—and “device identifiers”—“that uniquely identify the user’s device” akin to a vehicle’s license plate number. The combination of IP address and user agent (or other browser or device information) “contains sufficiently distinguishing information” that can be “used as a unique identifier,” known as “fingerprinting.” A website may “install tracking pixels from third-party companies such as Google and Meta to optimize ad campaigns that they run on Google . . .

Free access — add to your briefcase to read the full text and ask questions with AI

Doe v. Adventist Health System/West CA2/3, (Cal. Ct. App. 2026).

Doe v. Adventist Health System/West CA2/3 (Doe v. Adventist Health System/West CA2/3) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Brinker Restaurant Corp. v. Superior Court
273 P.3d 513 (California Supreme Court, 2012)
Regents of University v. Superior Court
220 Cal. App. 4th 549 (California Court of Appeal, 2013)
Basurco v. 21st Century Insurance
133 Cal. Rptr. 2d 367 (California Court of Appeal, 2003)
Walsh v. IKON Office Solutions, Inc.
56 Cal. Rptr. 3d 534 (California Court of Appeal, 2007)
Sav-On Drug Stores, Inc. v. Superior Court
96 P.3d 194 (California Supreme Court, 2004)
Linder v. Thrifty Oil Co.
2 P.3d 27 (California Supreme Court, 2000)
Eisenhower Medical Center v. Superior Court
226 Cal. App. 4th 430 (California Court of Appeal, 2014)
Duran v. U.S. Bank National Assn.
325 P.3d 916 (California Supreme Court, 2014)
Ayala v. Antelope Valley Newspapers, Inc.
327 P.3d 165 (California Supreme Court, 2014)
Cochran v. Schwan's Home Service, Inc.
228 Cal. App. 4th 1137 (California Court of Appeal, 2014)
Nicodemus v. Saint Francis Memorial Hospital CA1/4
3 Cal. App. 5th 1200 (California Court of Appeal, 2016)
Noel v. Thrifty Payless, Inc.
445 P.3d 626 (California Supreme Court, 2019)
Knapp v. AT&T Wireless Services, Inc.
195 Cal. App. 4th 932 (California Court of Appeal, 2011)