Reported / Citable
Background
Four patients alleged that Adventist Health secretly transmitted information from its public health-risk assessment pages and password-protected patient portal to Meta and Google through tracking technologies. They asserted claims under the California Invasion of Privacy Act (CIPA) and Confidentiality of Medical Information Act (CMIA), contending that identifiers, communications, and health information reached third parties and advertisers.
The patients sought certification of subclasses covering portal users and people who submitted online health-risk assessments. The trial court denied certification, reasoning that identifying affected patients and determining whether each transmission contained protected information would require individualized inquiries. The patients appealed the denial as to the portal and assessment subclasses.
The Court’s Holding
The Second District reversed the denial of certification for the health-risk assessment subclass and for surviving claims involving the patient portal. It concluded that the trial court misunderstood portions of the technical evidence, prematurely resolved merits questions, and failed to evaluate the plaintiffs’ proposed common proof. Class certification asks whether common issues and a workable common methodology predominate, not whether plaintiffs have already proved liability.
The court nevertheless affirmed two parts of the order. Plaintiffs had forfeited a CIPA section 632 confidential-communications theory by not properly presenting it, and the record supported denial of the portal subclass’s CMIA claims. The remand therefore permits certification proceedings on a narrower set of claims rather than approving the entire proposed action.
Key Takeaways
- Website-tracking privacy claims can be suitable for class treatment when common technical evidence identifies uniform transmissions.
- A certification court should test the proposed method of proof without deciding disputed merits prematurely.
- Ascertainability does not necessarily demand user-by-user mini-trials if records and tracking evidence can identify the class.
- Privacy theories must be clearly raised in the certification motion or they may be forfeited.
- The result is a remand for further proceedings, not a determination that Adventist violated CIPA or CMIA.
Why It Matters
California healthcare organizations using pixels, analytics scripts, and advertising tools face substantial class-action exposure when those tools operate on patient-facing pages. The decision emphasizes that the technical uniformity of code and data flows can create common questions even when individual users entered different information.
For privacy litigators, expert reports should map each challenged transmission to statutory elements and a proposed class-identification method. Defendants should distinguish genuine individualized consent or content issues from merits arguments dressed as manageability objections. Healthcare operators should separately audit public assessment tools and authenticated portals, minimize identifiers in outbound requests, and document any consent architecture before litigation arises.