Filed 7/24/26 Doe v. Adventist Health System/West CA2/3
NOT TO BE PUBLISHED IN THE OFFICIAL REPORTS
California Rules of Court, rule 8.1115(a), prohibits courts and parties from citing or relying on opinions
not certified for publication or ordered published, except as specified by rule 8.1115(b). This opinion
has not been certified for publication or ordered published for purposes of rule 8.1115.
IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA
SECOND APPELLATE DISTRICT
DIVISION THREE
JAMES DOE et al., B344951
Plaintiffs and Appellants, Los Angeles County
Super. Ct. No.
v. 22STCV36304
ADVENTIST HEALTH SYSTEM/
WEST,
Defendant and Respondent.
APPEAL from an order of the Superior Court of
Los Angeles County, Laura A. Seigle, Judge. Affirmed in part,
reversed in part, and remanded.
Caddell & Chapman, Michael A. Caddell, Cynthia B.
Chapman, Amy E. Tabor; Ahmad, Zavitsanos & Mensing, Foster
C. Johnson, Kelsi White; LippSmith, Graham B. LippSmith,
MaryBeth LippSmith and Jaclyn L. Anderson for Plaintiffs
and Appellants.
Seyfarth Shaw, Kristine Rinella Argentine and Sierra J.
Chinn-Liu for Defendant and Respondent
_________________________
Plaintiffs—four Does who are or were patients of defendant
Adventist Health System/West (Adventist)—brought this
putative class action asserting claims against Adventist for,
among others, violations of the California Invasion of Privacy
Act (CIPA) (Pen. Code, §§ 630 et seq.)1 and the California
Confidentiality of Medical Information Act (CMIA). Plaintiffs
alleged Adventist shared (without their knowledge) their—and
similarly situated patients’—personal information with third
parties through web-based tracking technologies—the Meta Pixel
and/or Google Analytics—installed on Adventist’s websites,
including its public health risk assessment (HRA) website
and its password-protected patient portal. The tools allegedly
tracked site users’ activities, collected their data, and sent
the information—including personally identifiable information,
the contents of users’ communications with Adventist, and
protected health information (PHI)—to Facebook (Meta)
and Google, who shared the data with advertisers.
Plaintiffs sought to certify a class consisting of Adventist
patients with California addresses who—for the period from
November 16, 2017 to April 30, 2024—“used the Adventist
website or patient portal to exchange communications with
Adventist . . . for researching medical conditions or treatments,
finding a physician, making an appointment, or submitting a
health risk assessment form” (general class), and four subclasses.
Only two subclasses are relevant to this appeal: (1) the patient
portal subclass, consisting of all class members “who were
logged into Adventist[’s] . . . patient portal up until May 2023”;
1 Undesignated statutory references are to the Penal Code.
2
and (2) the HRA form subclass, consisting of all class members
“who submitted an online [HRA] form to Adventist.”
The trial court denied plaintiffs’ motion in its entirety.
Plaintiffs appeal from the trial court’s denial of class certification
of the patient portal and HRA form subclasses only. The trial
court concluded, as relevant here, plaintiffs failed to establish:
(1) the patient portal class was ascertainable, (2) common issues
predominated over individual ones for both subclasses, and
(3) the superiority and manageability of a class action. The
court also found plaintiffs had “dropped any attempt to certify
a class” for violations of CIPA under section 632.
The court primarily reasoned that determining whether
the data the tracking technologies sent to third parties contained
the “contents” of users’ communications (CIPA) or users’ “medical
information” (CMIA) would require an individual inquiry into the
information transmitted for each user. The court also reasoned
that plaintiffs had not explained how to ascertain which of the
patients who had logged into the patient portal had engaged in
activities that resulted in transmission of actionable information.
Plaintiffs challenge the rulings, arguing the undisputed record
evidence showed the patient portal class was ascertainable;
the court misunderstood the record, misapplied the definition
of “medical information,” ignored plaintiffs’ theory of liability,
and prematurely determined the merits in finding common issues
did not predominate; and they demonstrated the manageability of
the two subclasses and superiority of a class action to individual
trials. We reverse the court’s denial of class certification of the
HRA form subclass and partially reverse as to the patient portal
subclass.
3
BACKGROUND
1. Background on tracking technologies2
A web browser communicates with a website’s servers to
download and display the website’s content on the user’s screen.
To do so, the web browser sends HTTP (hypertext transfer
protocol) requests to download files from the website’s servers.3
The HTTP request “contains an IP address, which [is] an
identifier assigned to any Internet-connected device,” as well
as “a URL, which represents the address of the file that a
web browser is requesting from a web server,” and the “[u]ser
[a]gent,” which “identifies the details of the operating system
and web browser.” “A URL contains the server’s domain name,
the path of the file located on the server that is being requested,
and a list of query parameters that contain additional
information being sent from a web browser to a web server.”
“Cookies” are “used by web servers to keep track of past
interactions with the web browser.” Cookies can store
“identifiers” “used to identify a specific user account or a specific
device/browser.” “Third-party cookies”—set by a third-party
server—“allow cross-site tracking of a user across different
websites.” On the other hand, “first-party cookies”—set by the
first-party server—“allow same-site tracking of a user on a
particular website.”
2 We glean most of this background from the report of
plaintiffs’ expert Dr. Zubair Shafiq. Quoted material omits
footnote references.
3 The first HTTP request sent “is typically for the Hypertext
Markup Language (HTML) file.” The HTML file contains the
source code or content of a webpage.
4
A “tracking pixel”—such as the Meta Pixel and Google
Analytics—is a piece of code or image “that is used to track
users’ browsing activity on the web.” “When a tracking pixel is
installed on a website by a first party, it allows a third party (i.e.,
a domain that is different from the first-party website that a user
navigates to) to track a user across different websites where the
tracking pixel is installed. Put simply, a tracking pixel allows
a third party to tell that a user visited website A at time A,
website B at time B, and so on.” Tracking pixels “also ghostwrite
first-party cookies on the visited website’s domain to circumvent
third-party cookie blocking.”
A tracking pixel collects “two types of data”—“identifiers”
and “browsing activity”—“in HTTP requests from a user’s web
browser to the tracking pixel’s web server.” “Identifiers” are
collected through cookies stored by the web browser, and “the
combination of IP address and user agent in the transmission
from a user’s web browser to the pixel’s web server.” Identifiers
stored in cookies can include “account identifiers”—“that
uniquely identify the user visiting the website” akin to a driver’s
license number—and “device identifiers”—“that uniquely identify
the user’s device” akin to a vehicle’s license plate number.
The combination of IP address and user agent (or other browser
or device information) “contains sufficiently distinguishing
information” that can be “used as a unique identifier,” known
as “fingerprinting.”
A website may “install tracking pixels from third-party
companies such as Google and Meta to optimize ad campaigns
that they run on Google . . . and Meta.” Thus, “a website may
install and purposefully configure tracking pixels in its HTML
source code to share information about specific actions a user
5
takes on their website with the tracking pixel’s server.” For
example, these tracking technologies can track “events,” such as
when a “button” is clicked, a form is submitted, or a page is
viewed on a website.
Google describes Google Analytics as “ ‘a platform that
collects data from your websites and apps to create reports
that provide insights into your business.’ ” “ ‘Every time a user
visits a webpage, the tracking code will collect pseudonymous
information about how that user interacted with the page.’ ”
Google Analytics “uses both first-party and third-party cookies”
—that store account and device identifiers—“to track users on
and across different websites.” It also has a feature that “allows
Google to link or associate the data with Google accounts of users
who have signed into their Google accounts.” Meta describes
Meta Pixel (formerly called Facebook Pixel) as “a piece of code
on your website that can help you better understand the
effectiveness of your advertising and the actions people take
on your site, like visiting a page or adding an item to their cart.
You’ll also be able to see when customers took an action after
seeing your ad on Facebook and Instagram.” By default, the
Meta Pixel “will track URLs visited, domains visited, and the
devices [users] use.” The Meta Pixel also uses first- and third-
party cookies that store account and device identifiers to track
users across different websites. For example, the Meta Pixel—
through cookies—stores a user’s device identifier and Facebook
account identifier and “collects them on the facebook.com
domain.”
In Adventist’s words, these tracking technologies “cause
different networks (i.e., the Adventist Health server and Google/
Meta servers) to communicate with each other, causing certain
6
categories of data to be transmitted to Google/Meta.” The
“ ‘baseline data’ ” shared consists of first-party cookie identifiers,
URLs, IP addresses—whether complete or partially masked—
and user agent data.
2. Adventist’s use of tracking technologies
Adventist is a nonprofit, faith-based healthcare system
serving communities on the west coast and Hawaii. Between
2017 and 2024, Adventist installed the Meta Pixel and/or Google
Analytics on its websites, including its public-facing website at
adventisthealth.org, its patient portal at myadventisthealth.org,
and its public HRA website at adventisthealthhra.org.
Adventist placed advertisements on Facebook and other
digital platforms, encouraging potential patients to click on a
link where they could, for example, fill out an HRA form. The
ad links also could lead users to Adventist’s website or an ad
campaign landing page where they could, for example, request
an appointment, attend a webinar, or, again, fill out an HRA
form. Adventist used the tracking technologies in connection
with its online marketing efforts “to understand how many users
[we]re clicking on” a particular “ad and getting to [Adventist’s]
site so that [Adventist could] optimize the best performing ads.”
In other words, the tracking pixels enabled Adventist to
determine if an ad campaign was resulting in “conversions”—
users interacting with the website through pageviews, clicks,
form submissions (including HRAs), downloads, etc. Adventist
installed Google Analytics on its patient portal to gain “valuable
insight,” rather than for marketing purposes, however.
a. The patient portal
The patient portal—hosted by Adventist’s business
associate, Cerner—is a password-protected website where, among
7
other things, Adventist patients can access information from
their electronic health record, including test results; exchange
messages with healthcare providers; review treatment
information; schedule appointments; and pay bills. Users can
navigate directly to the patient portal login from their browser
or access it from within the main Adventist website through the
“Patient Login” button. Adventist installed only Google Analytics
on the patient portal, not the Meta Pixel.
Google Analytics normally shares information about
“events” such as, “page views, scrolls, outbound clicks,
site search, form interactions, video engagement, [and] file
downloads.” Adventist was unaware of any modification made
to the type of data Google Analytics collected and transmitted
within the patient portal.4 However, Cerner took security
measures within the patient portal to “configure[ ] [Google
Analytics] to anonymize the IP address[es]” it stored—by
“truncat[ing] the last octet of the IP address”—and “to obfuscate
[portions of] URLs that were provided when a user browses”
the website. To obfuscate the URLs, Cerner used a pattern
recognition software that scanned individual URLs and, if the
URL “matched a pattern that included an identifier or reference
to potential PHI,” that portion of the URL was removed or
replaced with a generic term. For example, if a URL included a
personal or document identification number, Cerner’s software
replaced it with “PERSON_ID” or “DOCUMENT_ID.” Cerner
also “ ‘removed the “query parameter” portion of a URL,
4 Discovery Shafiq reviewed showed Google Analytics was
tracking information inside the patient portal about “Logins,”
“Pageviews,” “Health Record – Results,” “Download/Transmit,”
“Messages,” and others.
8
if present, which reflects searches or other information input
by the user’ ” on the web page.5
In May 2023, Cerner removed Google Analytics.
b. HRA website
Beginning in 2019 or 2020, Adventist partnered with
HealthAware to provide HRAs “through the adventisthealth
hra.org website to the public as a marketing tool to identify
and reach people who may be at an increased risk for certain
health conditions and who would benefit from a medical
evaluation related” to the condition. HRAs could be accessed
directly through the “main website,” through “a specific subpage
of the main website,” or by clicking on an advertisement “on a
third-party website such as Facebook or Google”; they generally
were accessed through ads. When individuals filled out an
HRA form and clicked the link to submit it, they were told if
they were at “low risk,” “moderate risk,” or “high risk” for the
health condition assessed.
Records of the individuals who completed an HRA—
including identifying information the user provided (e.g., name,
date of birth, contact information), which HRA they took
5 The URL “query string” includes “search terms” input by
the user. For example, in the URL “https://www.adventisthealth.
org/site-search/?C=pregnancy” the query string (after the “?”)
shows a search was done at the Adventist website for information
about pregnancy. The following URL has a “path” but no query
string: “https://www.adventisthealth.org/services/cancer-
oncology.” The “path” is “services/cancer-oncology” indicating the
user viewed information about cancer-oncology under “services.”
(See In re Meta Pixel Healthcare Litigation (N.D.Cal. 2022)
647 F.Supp.3d 778, 795–796 and fn. 10 (Meta Pixel) [examples
of a URL path and query string].)
9
and when, the risk level assigned, whether they wished to
be contacted, and the lead source (how they came to the HRA
website)—were stored in Adventist’s “Salesforce Customer
Relationship Management” (CRM) system. The tracking pixels
installed on the website shared with Google and Meta that an
HRA form had been submitted.
3. Plaintiffs’ class action lawsuit
Plaintiffs are current or former Adventist patients who
interacted with Adventist’s websites, including the patient portal.
Plaintiffs sued Adventist, as individuals and on behalf of a
putative statewide class of Adventist patients or prospective
patients who “exchanged communications” at one of Adventist’s
websites between November 2017 and 2024.6 Plaintiffs alleged
Adventist installed tracking technologies throughout its public
websites and patient portal that acted as “listening and recording
device[s]” permitting Meta7 and Google to “eavesdrop[ ]” on their
and purported class members’ communications with Adventist—
their healthcare provider. Through these tracking technologies,
Adventist allegedly disclosed plaintiffs’ personally identifiable
information and PHI—without their consent—to Meta and
Google. Plaintiffs alleged the tracking technologies transmitted
Adventist website users’ IP addresses, URLs generated from
users’ searches and logins, and users’ personal data input on
the websites. The information shared with Meta and Google
allegedly included, among other things, plaintiffs’ and proposed
class members’ status as Adventist patients, their medical
6 Plaintiffs filed the operative third amended complaint
(TAC) on June 25, 2024.
7 Meta owns Facebook.
10
providers, their actual or potential medical conditions and
treatments, and their “personal identities.”
Plaintiffs alleged Meta/Google used the information
collected from Adventist’s websites to sell targeted advertising
services. In return, Adventist received analytics about its
websites to optimize its marketing efforts and ad placement,
to enhance user experience, and to monitor how many users
engaged with its websites. Plaintiffs alleged they visited
Adventist’s public website and patient portal where they
entered medical information, searched for a doctor, searched
for information about a medical condition and/or its treatment,
filled out an HRA, made appointments, and/or reviewed test
results. Plaintiffs then received advertisements on their
Facebook pages relating to their medical conditions.
Plaintiffs asserted ten separate causes of action against
Adventist, including, among others: one claim for violating CIPA
by using a recording device—the tracking technologies—to record
confidential communications without plaintiffs’ or class members’
consent and transmitting that information to others (§ 632,
subd. (a)) (§ 632(a)), and by “aid[ing]” third parties in the
interception of the “contents” of plaintiffs’ and class members’
communications with Adventist (§ 631, subd. (a)) (§ 631(a)); three
separate claims for violating CMIA by failing to “maintain the
confidentiality of users’ medical information” (Civ. Code, § 56.06),
by negligently failing to “maintain, preserve, and store” plaintiffs’
and class members’ medical information “in a manner that
preserve[d] the confidentiality” of that information (Civ. Code,
§ 56.101), and by disclosing plaintiffs’ and class members’
“sensitive medical information” without their consent (Civ. Code,
§ 56.10); two claims for violating the Unfair Competition Law
11
(Bus. & Prof. Code, § 17200 et seq.) (UCL) based on its violations
of CIPA and CMIA; and a claim for invasion of privacy (Cal.
Const., art. 1, § 1).
4. Class certification motion, opposition, and reply
On June 25, 2024, plaintiffs also filed their motion for class
certification. Both sides submitted reports from their experts,
various declarations, deposition testimony, and other exhibits.8
a. Motion
Plaintiffs proposed the general class—for the period from
November 16, 2017 to April 30, 2024—consist of “all Adventist
Health patients with an address in California who used the
Adventist website or patient portal to exchange communications
with Adventist Health, including researching medical conditions
or treatments, finding a physician, making an appointment,
or submitting a health risk assessment form.”9 (Italics added.)
Plaintiffs also moved to certify four subclasses, including,
a patient portal subclass consisting of “All Class members who
were registered users of Adventist Health’s patient portal up
until March 29, 2024” (italics added), and an HRA form subclass,
8 Plaintiffs’ expert Shafiq’s report summarized his testing
and analysis as showing Adventist “uniformly shared patient
identifiers (e.g., identifiers of accounts or devices used by
patients) alongside content information (e.g., page title and URL)
with third-party companies such as Google and Meta. Therefore,
any patient who used Adventist Health’s website to search for
a doctor, make an appointment, or access the patient portal had
their identifying information together with sensitive health
information shared with third-party companies.”
9 The proposed general class in the TAC included prospective
patients and did not specify the type of communications.
12
consisting of “All Class members who submitted an online [HRA]
form to Adventist Health.” (The two others were the online
appointment and provider search subclasses.)
There was no dispute over the numerosity of the proposed
class and subclasses. Plaintiffs argued the two subclasses at
issue on appeal were ascertainable based on records maintained
by Adventist’s vendors Cerner and HealthAware. Adventist
did not dispute this fact.
Plaintiffs argued Adventist’s liability depended on
common factual and legal questions that predominated over
individual ones. For their CIPA claim, plaintiffs argued those
included whether: Adventist’s tracking pixels acted similarly
to a “bugging device” by “ ‘contemporaneously and invisibly
re-direct[ing] the users’ communications to third parties’ ”;
“the pixels’ workings constitute an interception of a message
in transit in violation of CIPA”; class members had “ ‘a
reasonable expectation of privacy’ ”; and the transmitted
information “included the ‘contents’ of patients’ communications
with Adventist.” For its CMIA claims, plaintiffs argued common
issues included whether “Adventist’s deliberate decision to deploy
the[ ] tracking pixels constituted a ‘disclosure’ of information” or
“negligent storage or maintenance of information”; whether the
disclosed information “included information ‘regarding a patient’s
medical history . . . mental or physical condition, or treatment’ ”
and was protected “ ‘medical information’ ” because it included
“ ‘individually identifiable information . . . sufficient to allow
identification of the individual’ ”; whether Adventist was
authorized to disclose patients’ medical information; and whether
an unauthorized party “ ‘viewed or accessed’ ” the disclosed
information.
13
Plaintiffs argued the factual and legal issues relating to
these questions were common to the patient portal subclass and
HRA form subclass, as well. Plaintiffs asserted Adventist had
admitted Google Analytics was enabled inside the patient portal,
and its standard configuration had not been changed. Plaintiffs
also asserted Shafiq’s investigation revealed that, after a patient
submitted an HRA form, the tracking pixels sent Meta and
Google a “full-string URL[ ]” including a “unique string of
numbers” that would allow anyone to access the HRA report’s
contents.
Finally, plaintiffs argued that a class action was superior
here to allow class members to obtain compensation—through
statutory penalties, and to stop Adventist’s “illegal disclosures
of their sensitive health information.”
b. Opposition
Adventist opposed the motion, primarily arguing several
individual issues predominated. Among other issues, Adventist
argued that, to prove their CIPA and CMIA claims, plaintiffs
would have to present evidence of each individual URL the
tracking pixels sent to Meta and/or Google to show whether
that information constituted the “ ‘content’ ” of a communication
or “medical information” and was individually identifiable.
With respect to the patient portal subclass, Adventist argued
individual URLs sent to Google also would have to be examined
to see what had been obfuscated or masked. Adventist argued
individual inquiry into proposed HRA form subclass members
would be required to determine if individuals were patients
at the time they submitted the form, whether they filled out
the form for others, and whether they accessed the form through
an ad on Google or Facebook, which would affect their reasonable
14
expectation of privacy. Defendants also presented evidence that
the Meta Pixel and Google Analytics transmitted URLs from the
HRA website differently: while Google “likely received” a URL
that included the name of the HRA, the URL transmitted to Meta
said only “hra.adventisthealth.org” or “quiz.adventisthealth.org.”
c. Reply
In their reply—filed after deposing Adventist’s expert
Emily Cohen—plaintiffs argued Cohen’s confirmation that the
tracking technologies “ ‘share[d] at least a baseline of information
consisting of first-party cookie identifiers, page view information,
including URL’s, IP addresses, whether complete or partially
masked, and user agent data’ ” established the “key liability facts
are subject to common proof.” Plaintiffs essentially contended
this baseline data was evidence providing proof common to the
class as to whether the information transmitted was individually
identifiable, conveyed PHI or medical information, or constituted
“contents.” Because the tracking technologies always conveyed
at least the baseline data, plaintiffs argued, whether the tracking
pixel transmitted additional protected information “over the
‘baseline’ ” “only increase[d] the degree of harm suffered by
class members,” and was not relevant to Adventist’s underlying
liability.
Plaintiffs agreed to limit the patient portal subclass to
“All Class members who logged into Adventist’s patient portal
up until May 2023.” (Italics added.) Plaintiffs argued it
was “immaterial what access point patients used” to log into
the patient portal, “as any transmission to Google from the
myadventisthealth.org domain [the patient portal], regardless
of access point, indicate[d] that the individual signed into the
patient portal.” Plaintiffs also argued that, although the URLs
15
sent from the patient portal were partially redacted, they still
contained descriptive “natural language” terms outside of search
parameters that revealed “key information about patients’ health
condition or treatment.” Plaintiffs contended that, because the
class included “only patients who exchanged health-care-related
communications” with Adventist, the court could determine on
a class-wide basis “whether the content” of the communications
was “PHI/medical information.” Plaintiffs also disputed
Adventist’s contentions that the court could not determine the
specific issues affecting the HRA form subclass on a class-wide
basis based on Adventist’s records and/or proposed class
members’ self-reporting.
d. Hearing and trial plan
Before hearing oral argument on plaintiffs’ motion,
the court issued a tentative ruling denying class certification.
The court heard extensive argument on December 19, 2024.
During the hearing—in response to the court’s concerns that
the class included individuals who interfaced with the Adventist
websites for non-health related reasons—plaintiffs’ counsel
proposed to amend the class definition to include patients
who used the Adventist websites to exchange communications
“for” (rather than “including”) researching medical conditions
or treatments, finding a physician, making an appointment,
or submitting an HRA. The court permitted plaintiffs to file
a trial plan and Adventist to file a response before taking
the matter under submission.
Plaintiffs’ trial plan confirmed their modifications of
the general class and patient portal subclass. Plaintiffs also
narrowed the class claims to those under CIPA, “Penal Code
§§ 630 et seq.”; CMIA, “Civil Code §§ 56.101 & 56.10”; and UCL.
16
5. The court’s denial of class certification
On February 14, 2025, the court issued an 18-page order
denying plaintiffs’ motion for class certification in its entirety.
As relevant to this appeal, the court found plaintiffs failed to
establish the patient portal subclass was ascertainable because
they didn’t explain “how to ascertain which patients logged into
the patient portal and engaged in the types of activities that
allegedly resulted in ‘content’ and ‘medical information’ being
transmitted.” The court also found plaintiffs did not show how
common issues predominated on either its CIPA or CMIA claims
for either subclass. The court found that, although plaintiffs
established “medical information may have been revealed by
some of the URLs” transmitted from the patient portal, other
URLs may not have revealed “either ‘content’ under CIPA
or ‘medical information’ under CMIA.” The court also found
“[p]laintiffs did not submit evidence that merely logging into
the patient portal transmits information in violation of CIPA
or CMIA, or that each activity that a logged-in patient can do
within the patient portal transmits information in violation of
CIPA or CMIA.” As for the HRA form subclass, the court found
a person-by-person inquiry would be required to determine
whether Google and Meta “actually followed the links” they
were sent to the completed HRA forms, such as by showing
class members received ads for health issues they disclosed in
HRA forms. Finally, the court found plaintiffs failed to show the
superiority of a class action as they cited no evidence to support
their assertion that “few class members have the time and
resources to pursue their claims on an individual basis,” and
did not address the manageability of the individual questions
17
the court had identified. Plaintiffs filed a timely notice of
appeal.10
DISCUSSION
1. Class certification and standard of review
Section 382 of the Code of Civil Procedure authorizes
a lawsuit to proceed as a class action “when the question is one
of a common or general interest, of many persons, or when the
parties are numerous, and it is impracticable to bring them all
before the court.” “The party advocating class treatment must
demonstrate the existence of an ascertainable and sufficiently
numerous class, a well-defined community of interest, and
substantial benefits from certification that render proceeding
as a class superior to the alternatives. [Citations.] ‘In turn,
the “community of interest requirement embodies three factors:
(1) predominant common questions of law or fact; (2) class
representatives with claims or defenses typical of the class;
and (3) class representatives who can adequately represent
the class.” ’ ” (Brinker Restaurant Corp. v. Superior Court (2012)
53 Cal.4th 1004, 1021 (Brinker).)
The certification question is “ ‘ “essentially a procedural
one that does not ask whether an action is legally or factually
meritorious,” ’ ” and thus, “resolution of disputes over the
merits of a case generally must be postponed until after class
certification has been decided [citation], with the court assuming
for purposes of the certification motion that any claims have
merit.” (Brinker, supra, 53 Cal.4th at p. 1023.) Our Supreme
10 An order denying class certification is appealable under
the “ ‘death knell’ ” doctrine. (See Meinhardt v. City of Sunnyvale
(2024) 16 Cal.5th 643, 656, fn. 8.)
18
Court has recognized that, when “evidence or legal issues
germane to the certification question bear as well on aspects
of the merits, a court may properly evaluate them.” (Id.
at pp. 1023–1024.) However, “[s]uch inquiries are closely
circumscribed.” (Id. at p. 1024.) “[A]ny ‘peek’ a court takes
into the merits at the certification stage must ‘be limited to
those aspects of the merits that affect the decisions essential’
to class certification.” (Ibid.)
“ ‘The decision to certify a class rests squarely within the
discretion of the trial court, and we afford that decision great
deference on appeal, reversing only for a manifest abuse of
discretion: “Because trial courts are ideally situated to evaluate
the efficiencies and practicalities of permitting group action, they
are afforded great discretion in granting or denying certification.”
[Citation.] A certification order generally will not be disturbed
unless (1) it is unsupported by substantial evidence, (2) it rests on
improper criteria, or (3) it rests on erroneous legal assumptions.’ ”
(Brinker, supra, 53 Cal.4th at p. 1022.) Therefore, “ ‘[u]nlike the
general rule compelling a reviewing court to scrutinize the result
below, not the trial court’s rationale, we analyze the propriety
of an order denying class certification based solely on the lower
court’s stated reason for the decision.’ [Citation.]” (Leeds v. City
of Los Angeles (2025) 115 Cal.App.5th 537, 545–546 (Leeds).)
“ ‘Under this standard, an order based upon improper
criteria or incorrect assumptions calls for reversal “ ‘even though
there may be substantial evidence to support the court’s
order.’ ” ’ ” (Noel v. Thrifty Payless, Inc. (2019) 7 Cal.5th 955,
968 (Noel); see also Ayala v. Antelope Valley Newspapers, Inc.
(2014) 59 Cal.4th 522, 537 [“[a] certification decision is reviewed
for abuse of discretion, but when the supporting reasoning
19
reveals the court based its decision on erroneous legal
assumptions about the relevant questions, that decision
cannot stand”]; Cochran v. Schwan’s Home Service, Inc.
(2014) 228 Cal.App.4th 1137, 1143, quoting Knapp v. AT&T
Wireless Services, Inc. (2011) 195 Cal.App.4th 932, 939 (Knapp)
[“ ‘A trial court’s decision that rests on an error of law is an
abuse of discretion.’ ”].)
2. Ascertainability of the patient portal subclass11
A class is ascertainable “when it is defined ‘in terms of
objective characteristics and common transactional facts’ that
make ‘the ultimate identification of class members possible
when that identification becomes necessary.’ ” (Noel, supra,
7 Cal.5th at p. 980.) “[T]his standard . . . include[es] class
definitions that are ‘sufficient to allow a member of [the class]
to identify himself or herself as having a right to recover based
on the [class] description.’ ” (Ibid.)
Plaintiffs defined the patient portal subclass as “All Class
members who were logged into Adventist Health’s patient portal
up until May 2023.” Plaintiffs ultimately defined the general
class—i.e., all class members—as, “For the period November 16,
2017 to April 30, 2024, all Adventist Health patients with an
address in California who used the Adventist website or patient
portal to exchange communications with Adventist Health for
[1] researching medical conditions or treatments, [2] finding a
physician, [3] making an appointment, or [4] submitting a health
risk assessment form.” The initial class definition, however,
encompassed patients “who used the Adventist website or
11 The court found the HRA form subclass members were
ascertainable based on Adventist’s and/or its vendor’s records.
20
patient portal to exchange communications with Adventist
Health, including” the four above activities. (Italics added.)
Plaintiffs’ counsel suggested the revised definition during
the hearing on plaintiffs’ motion and—in plaintiffs’ trial plan—
proposed the court certify the general class as revised.
Accordingly, as Adventist asserts, the patient portal
subclass definition incorporated the revised definition of
the general class. Substituting “[a]ll Class members” with
plaintiffs’ definition of the general class, the patient portal
subclass definition is: All Adventist patients with an address
in California who logged into the patient portal up until May
2023 to exchange communications with Adventist for researching
medical conditions or treatments, finding a physician, making
an appointment, or submitting a health risk assessment form.
The court found plaintiffs did not establish the members
of the general class were ascertainable. The court noted
plaintiffs “propose[d] that [Adventist] generate a list of all
California patients and then ‘patients could identify themselves
as having used the website or patient portal to research medical
conditions or treatments, find a physician, make an appointment,
or submit a health risk assessment form.’ ” Plaintiffs argued
patients would “be able to figure out from the class definition
whether they are part of the class and they can ‘self-report.’ ”
The court found “[i]t [wa]s not so simple,” in part because the
class definition “d[id] not clearly tell putative class member[s]
how to self-report.” The court then concluded the patient portal
subclass had “a similar problem.” Plaintiffs had argued patient
portal subclass members were ascertainable because Adventist
had “information of all registered patient portal users in its
records.” The court found “being a registered user of the patient
21
portal does not mean a patient engaged in activity on the patient
portal that resulted in information, let alon[e] ‘content’ and
‘medical information,’ being transmitted to third parties.” The
court continued, “Plaintiffs do not explain how to ascertain which
patients logged into the patient portal and engaged in the types
of activities that allegedly resulted in ‘content’ and ‘medical
information’ being transmitted, as discussed below,” referring
to its predominance analysis.
Plaintiffs argue the record shows the patient portal
subclass is ascertainable through Adventist’s or its provider
Cerner’s records. As plaintiffs note, the evidence shows
Adventist could create a report of the patient identification
numbers (ID) that created a portal account and the number
of times the patient ID “accessed the portal.” Accordingly,
plaintiffs demonstrated patients who logged into the patient
portal during the subclass period were readily identifiable.
However, as the court implied12 and Adventist argues,
plaintiffs did not demonstrate how to identify patients who
logged into the patient portal and engaged in one of the four
enumerated activities. A patient’s options within the patient
portal were not limited to researching medical conditions
or treatments, finding a physician, making an appointment,
and submitting an HRA. Within the patient portal, patients
also could view lab, radiology, and other results; view their
12 As we noted, the court found the general class definition
did “not clearly tell putative class member[s] how to self-report.”
We can infer the court found the patient portal—which had a
“similar problem”—also did not clearly tell members how to self-
report, in part, because it necessarily subsumed the definition
of the class.
22
health record; download a document; send or receive messages;
pay a bill; and other activities.
Plaintiffs argue Adventist never disputed the patient portal
subclass was ascertainable. In opposing plaintiffs’ motion—
before plaintiffs modified the class definition—Adventist did
not dispute that it could identify patients who had logged into
the patient portal. But in response to plaintiffs’ trial plan,
Adventist argued the “revised general class definition creates
serious impediments to certification of their Patient Portal
Subclass. Specifically, a patient who merely logs in to the patient
portal and does nothing else is not a class member.” (Boldface
omitted.) Adventist specifically noted plaintiffs’ revised class
definition included “only those Adventist Health patients who
used the Adventist Health websites (and the patient portal)
for only four specific things”—researching medical conditions
or treatments, finding a physician, making an appointment, or
submitting a HRA form. Adventist asserted that, as a result,
“not all patient portal users fall within the class; rather, only
those who used the patient portal for identified purposes fall
within the revised class definition.” Adventist argued this
definition raised “additional individual questions about,”
among other things, “what each patient portal user was doing
on the patient portal website” and “whether the actions taken
using the portal fall within one of these four specific categories.”
Plaintiffs argue patients identified as having logged into
the patient portal “could easily recall if they had ever once used
the Patient Portal for any of the purposes for which it was
designed.” Patients may be able to recall what actions they took
within the patient portal, but plaintiffs have not explained how
patients could determine—as Adventist notes—if, for example,
23
their messaging a doctor, downloading a health record, or paying
a bill counted as “researching medical conditions or treatments,”
“finding a physician,” “making an appointment,” or none of those
things.
Nevertheless, as the court itself acknowledged, any
interactions a patient had within the patient portal—unlike
on Adventist’s general website—necessarily would have related
to the patient’s health care. It does not appear that plaintiffs
intended to limit the patient portal subclass only to those
patients who engaged in one of the four specified activities—
especially when, as we discuss below, plaintiffs contend the
baseline information transmitted when a patient logged into the
patient portal transmitted “contents” and “medical information”
to Google. Indeed, plaintiffs’ counsel suggested the revision to
the general class definition to address the court’s stated concerns
about “the general website.” Counsel explained, “I think there’s
one word change that could be made in the proposed class
definition for the general website. [¶] . . . [¶] . . . Strike the word
‘including.’ ” (Italics added.) The court responded, “Oh, replace it
with like about: to exchange communications about researching
medical, finding a physician, making an appointment. [¶] . . .
[¶] . . . So that would eliminate my concern about like you’re
just going on to find the address.” Counsel continued, “Yes,
Your Honor, and we acknowledge that that class would require
self-identification anyway . . . . So that one change would we
think solve the court’s concern with respect or at least address
the court’s concern with respect to the general website.” (Italics
added.)
24
Accordingly, when discussing plaintiffs’ proposed revision
to the general class definition, both plaintiffs’ counsel and
the court had patients’ interactions with the general website
—rather than the authenticated patient portal—in mind.
Critically, earlier in the hearing the court had “agree[d] . . .
the patient portal is people who were patients who are engaging
in the website because of their medical conditions,” not “just some
person on the website looking around the website for whatever
reason.”13 In any event, the posture of this case has changed.
Plaintiffs no longer seek to certify a general class of patients
who used the general Adventist website. For the remaining
patient portal and HRA form subclasses, the enumeration of
specific health-related activities simply is unnecessary to weed
out patients who used the website for non-health-care-related
activities. The patient portal subclass includes only California
patients who logged into the patient portal, and the HRA form
subclass includes only California patients who submitted an
HRA form. Neither subclass raises the concerns the court
had that led plaintiffs’ counsel to revise the class definition.
13 Plaintiffs’ expert Shafiq also stated the class definition
was “limited to patients who interacted with Adventist Health’s
website in specific ways (submitting a health risk assessment,
searching for a medical condition, searching for a physician,
booking an appointment with a provider, or logging into the
patient portal) that involve exchanging health-care-related
information with Adventist.” (Italics added.) In other words,
Shafiq understood that logging into the patient portal itself was
one of the ways in which purported class members could interact
with Adventist’s websites to exchange health-care-related
information.
25
In essence, plaintiffs’ appeal has rendered their post-hearing
revision to the general class moot.
And as we discussed, Adventist and/or its provider Cerner
have records identifying patients who logged into the patient
portal during the relevant period. If some small number of
patients who logged into the portal never used the portal, or
never used it for themselves, “ ‘those [persons] can be eliminated
from the class at that time.’ ” (Nicodemus v. Saint Francis
Memorial Hospital (2016) 3 Cal.App.5th 1200, 1213–1214
(Nicodemus) [data set of all patients’ attorneys’ requests for
patient records attaching release authorizations that may
have included some requests made after litigation began or
for nonlitigation reasons (and thus outside the proposed class)
was sufficient to demonstrate ascertainability].) Moreover,
Adventist did not dispute that the patient portal class was
ascertainable before plaintiffs revised the general class definition.
As plaintiffs note, the court also found they did “not explain
how to ascertain which patients logged into the patient portal
and engaged in the types of activities that allegedly resulted
in ‘content’ and ‘medical information’ being transmitted.”
Whether Adventist violated CIPA or CMIA by transmitting the
contents of patients communications or their medical information
are merits questions that plaintiffs were not required to answer
to demonstrate ascertainability. In turn, whether Adventist’s
liability under those statutes is subject to common proof relates
to the court’s predominance inquiry, which we discuss below.
Accordingly, we conclude plaintiffs demonstrated the patient
portal subclass members are ascertainable.
26
3. The court’s predominance inquiry
“The ‘ultimate question’ the element of predominance
presents is whether ‘the issues which may be jointly tried, when
compared with those requiring separate adjudication, are so
numerous or substantial that the maintenance of a class action
would be advantageous to the judicial process and to the
litigants.’ [Citations.]” (Brinker, supra, 53 Cal.4th at p. 1021.)
“A court must examine the allegations of the complaint and
supporting declarations [citation] and consider whether
the legal and factual issues they present are such that their
resolution in a single class proceeding would be both desirable
and feasible.” (Id. at pp. 1021–1022; see also Walsh v. IKON
Office Solutions, Inc. (2007) 148 Cal.App.4th 1440, 1450
(Walsh) [“In examining whether common issues of law or fact
predominate, the court must consider the plaintiff’s legal
theory of liability.”].)
“ ‘As a general rule if the defendant’s liability can be
determined by facts common to all members of the class, a class
will be certified even if the members must individually prove
their damages.’ ” (Brinker, supra, 53 Cal.4th at p. 1022.)
The “pertinent questions” under the predominance inquiry are:
“(1) What elements must be proven to establish the defendant’s
liability, and (2) Are these elements susceptible of common
proof?” (Downey v. Public Storage, Inc. (2020) 44 Cal.App.5th
1103, 1113 (Downey).) Moreover, “ ‘[T]he possibility that a
defendant may be able to defeat the showing of an element
of a cause of action “ ‘as to a few individual class members[,]
does not transform the common question into a multitude
of individual ones.’ ” [Citation.]’ ” (Nicodemus, supra,
3 Cal.App.5th at p. 1219.)
27
Plaintiffs’ trial plan stated it was seeking class certification
of their (1) CIPA claim, which alleged in the TAC that Adventist
had violated two provisions of CIPA: section 631(a), known as
the “wiretapping provision” and section 632(a), known as the
“recording provision”—which the court found plaintiffs had
abandoned (see Meta Pixel, supra, 647 F.Supp.3d at p. 798);14
(2) CMIA claims, alleging Adventist violated Civil Code sections
56.10 and 56.101; and (3) UCL claims based on Adventist’s
alleged violations of CIPA and CMIA.15
In essence, the trial court found that—although plaintiffs
had established the existence of several issues subject to common
proof—due to variations in the actual information shared
with Google and/or Meta through the URLs and other data
transmitted by the pixels, plaintiffs failed to meet their burden
to show Adventist’s liability under CIPA or CMIA could be
determined based on evidence common to all class members.
(See Duran v. U.S. Bank National Assn. (2014) 59 Cal.4th 1, 28
(Duran) [“class treatment is not appropriate ‘if every member
of the alleged class would be required to litigate numerous
and substantial questions determining his individual right to
recover following the “class judgment” ’ on common issues”].)
We first state the applicable law and then review the court’s
predominance analysis as to the two subclasses.
a. Applicable law
The wiretapping provision of CIPA, as relevant here,
imposes statutory penalties on anyone “who willfully and without
14 We discuss that finding at the end of the Discussion
section.
15 Accordingly, we need not separately address that claim.
28
the consent of all parties to the communication,” “reads or
attempts to read, or to learn the contents or meaning of any
message, report, or communication while the same is in transit
or passing over any wire, line, or cable, or is being sent from, or
received at any place within this state; or who uses, or attempts
to use, in any manner, or for any purpose, or to communicate
in any way, any information so obtained, or who aids, agrees
with, employs, or conspires with any person or persons to
unlawfully do, or permit, or cause to be done any of the acts
or things mentioned above in this section.” (§ 631(a).) Plaintiffs
alleged Adventist aided and abetted Meta and Google’s violation
of the “ ‘eavesdropping’ ” and “use” clauses of section 631(a). (See
Rodriguez v. Ford Motor Co. (S.D.Cal. 2024) 722 F.Supp.3d 1104,
1112–1114, 1116, 1122–1224 [to state a claim for “aiding and
abetting” under section 631(a), plaintiff must allege the third
party “ ‘violated one of the first three clauses of section 631(a),
and that [d]efendant aided, agreed with, employed, or conspired
with that person or entity to commit those unlawful acts’ ”].)
The court’s predominance analysis focused on whether
plaintiffs had demonstrated common evidence could be used
to determine whether the URLs shared with Google and/or
Meta included the “contents” of patients’ communications with
Adventist. CIPA does not define “contents.” A similar provision
in the federal Wiretap Act, however, broadly defines “ ‘contents’ ”
to “include[ ] any information concerning the substance, purport,
or meaning of that communication.” (18 U.S.C. § 2510(8);
see Meta Pixel, supra, 647 F.Supp.3d at p. 798 [analysis for
a violation of CIPA “ ‘is the same as that under the federal
Wiretap Act’ ”]; 18 U.S.C. § 2511(1)(a)–(e).) According to the
Ninth Circuit, the “ ‘contents’ ” of an online communication
29
“refers to the intended message conveyed by the communication,
and does not include record information regarding the
characteristics of the message that is generated in the course
of the communication.” (In re Zynga Privacy Litigation (9th Cir.
2014) 750 F.3d 1098, 1106–1107 (Zynga).) In Zynga, the Ninth
Circuit explained a URL that included “only basic identification
and address information” did not constitute “the contents of
a communication,” but a URL that contained “a search term
or similar communication made by the user” may constitute
“contents.” (Id. at pp. 1108–1109; see id. at pp. 1102–1103,
1107 [granting motion to dismiss where alleged information
transmitted—user’s Facebook ID and address of webpage user
was viewing when user clicked link to a gaming application—
was not “ ‘contents’ ” but record information].)
Since Zynga, other federal district courts within California
have considered whether URLs shared or intercepted by tracking
technologies constitute the “contents” of a communication.
In Meta Pixel, supra, 647 F.Supp.3d at pp. 785, 795–796, 798
the trial court—in deciding a motion for preliminary injunction—
found alleged transmissions of patients’ log-in communications
with their health care provider MedStar Health System’s patient
portal “likely constitute[d] ‘contents’ ” under the Wiretap Act
and CIPA. Plaintiffs there alleged that, when they “press[ed]
the login button” to enter their patient portal, the information
was sent to Meta through a transmission that included the
“patient’s identity in the form of cookies, IP address, and User-
Agent identifiers,” “[c]ontent of the button (‘Log in’),” “[c]ontents
of the page from which the patient clicked to log in to the patient
portal,” and “[c]ontent of the page the patient will land as a result
of clicking ‘Log in’ to the patient portal.” (Id. at p. 785.) The
30
court found the patient portal “log-in buttons” and the descriptive
URLs, which included both “the ‘path’ and the ‘query string,’ ”
were “ ‘contents’ ” because “they concern[ed] the substance of
a communication.” (Id. at pp. 795–796 [also explaining “contact
information provided as part of a sign-up process constitutes
‘content’ because this information is the subject of the
communication”].)
Federal district courts have “ ‘employ[ed] a contextual
“case-specific” analysis hinging on “how much information would
be revealed” by the information’s tracking and disclosure.’ ”
(Cousin v. Sharp Healthcare (S.D.Cal. 2023) 702 F.Supp.3d 967,
976 (Cousin II), quoting Hammerling v. Google, LLC (N.D.Cal.
2022) 615 F.Supp.3d 1069, 1092–1093.) “ ‘Generally, customer
information such as a person’s name, address, and subscriber
number or identity is record information, but it may be contents
when it is part of the substance of the message conveyed to the
recipient. [Citations.] Similarly, URLs are record information
when they only reveal a general webpage address and basic
identification information, but when they reproduce a person’s
personal search engine queries, they are contents.’ ” (Ibid.
[denying motion to dismiss where alleged data included “personal
search queries—such as specialty healthcare providers and
treatments for medical conditions—and therefore plausibly
conveyed content: their PHI”]; see also In re Google RTB
Consumer Privacy Litigation (N.D.Cal. 2022) 606 F.Supp.3d 935,
949 (Google RTB) [finding redirected electronic communications
allegedly comprised of “ ‘content categories of the site or app,’ ”
“ ‘[content] categories that describe [the] current section of the
site or app,’ ” the “ ‘URL of the page where the impression will be
shown,’ ” “ ‘referrer URL that caused navigation to the current
31
page,’ ” and a “ ‘list of keywords about [the] site or app,’ ” among
other items, constituted “content”].)
CMIA in turn prohibits a health care provider from
disclosing “medical information regarding a patient . . . without
first obtaining authorization.” (Civ. Code, § 56.10, subd. (a).)
CMIA defines “medical information” as “any individually
identifiable information . . . regarding a patient’s medical history,
. . . mental or physical condition, or treatment. ‘Individually
identifiable’ means that the medical information includes
or contains any element of personal identifying information
sufficient to allow identification of the individual, such as the
person’s name, address, electronic mail address, telephone
number, or social security number, or other information that,
alone or in combination with other publicly available information,
reveals the identity of the individual.” (Civ. Code, § 56.05, subd.
(j)(1), former subd. (j) (2024–2025), former subd. (i) (2022–2023),
and former subd. (j) (2014–2021).) The definition of “medical
information” “does not encompass demographic or numeric
information that does not reveal medical history, diagnosis,
or care.” (Eisenhower Medical Center v. Superior Court (2014)
226 Cal.App.4th 430, 435 (Eisenhower).)
b. HRA form subclass
i. The court made a merits determination in
implicitly deciding plaintiffs could not establish
by common proof that Adventist transmitted
the contents of communications or medical
information of patients who submitted
HRA forms under CIPA or CMIA
As plaintiffs note, in assessing the predominance prong
for the HRA form subclass, the court discussed the evidence
32
relating to plaintiffs’ CIPA and CMIA claims together. The court
noted plaintiffs’ motion asserted—citing Shafiq’s report—the
tracking code Adventist employed on the HRA forms caused
Google and Meta to be notified when an HRA form had been
completed and transmitted “ ‘full-string URLs’ . . . that ‘included
a unique string of numbers that would allow anyone . . . to access
the HRA reports’ contents.’ ” The court noted the cited portions
of Shafiq’s report stated Adventist shared information “ ‘about
specific events such as “HRA Report Accessed” ’ and URLs such
as ‘https://quiz.adventisthealth.org/v3/c6c2ecf4-abec-4222-843a-
65e83697f7b0/report/a2d7dfd4-c6fe-4c53-8d41-eacf4e4e87a0.’ ”16
Shafiq noted “anyone can go” to that URL “to access the contents
of the report.”
When “clicked” the two example HRA URLs in Shafiq’s
report indeed link directly to reports that assess the user’s risk
factors for the specified health condition based on information
the user input into the HRA form. (See footnote 16.) The reports
thus refer to that user-provided information. For example, the
WeightAware report recommended the individual lose weight
and indicated, among other things, that the individual had
high blood pressure and cholesterol or was taking medication
for those conditions, had sleep apnea and asthma, and exercised
a moderate amount. Similarly, the HeartAware report accessed
from a second link included the individual’s age, sex, and weight,
and noted the person had cholesterol outside the recommended
16 This link is to a “WeightAware” report—an HRA for
weight loss. Shafiq’s report also included the following link
to a “HeartAware” report—an HRA for cardiovascular risk:
https://quiz.adventisthealth.org/v3/64d7e7c0-d719-4d61-be6d-
a2a3f50cebbe/report/8f3a968d-1615-4857-a52b-ebde3074886b.
33
range, had a family history of early cardiovascular disease,
and exercised a moderate amount, among other information.
The court found it was “questionable whether the fact that
a person filled out an HRA reveals the contents of a patient’s
communications with [Adventist] or anything about the patient’s
physical or mental condition or treatment. On the other hand,
the actual HRAs likely contain both contents of patients’
communications and their medical information.” This difference
between a URL/event data indicating a patient had submitted
an HRA form, and the completed HRA form or results report
itself, is the only reasoning the court expressed for finding
plaintiffs failed to demonstrate common issues predominated
for the HRA form subclass on their CIPA claim.
But plaintiffs alleged that every submission of an HRA
questionnaire resulted in the transmission of a URL that linked
directly to an HRA report. And whether the transmission
of those URLs linking to completed reports—rather than
transmission of the reports themselves—is the transmission
of “contents” under CIPA or medical information under CMIA,
is a merits question. (See Linder v. Thrifty Oil Co. (2000) 23
Cal.4th 429, 439–440 (Linder) [question of class certification
is “essentially a procedural one that does not ask whether an
action is legally or factually meritorious”]; see also Sav-On Drug
Stores, Inc. v. Superior Court (2004) 34 Cal.4th 319, 327 (Sav-On)
[“focus in a certification dispute is on what type of questions—
common or individual—are likely to arise in the action, rather
than on the merits of the case”].) Plaintiffs presented evidence
that this merits question could be answered—one way or
the other—with common proof. They presented evidence that
the tracking technologies were installed on the HRA portion of
34
the Adventist website and where patients filled out HRA forms;
the tracking technologies uniformly shared “a baseline of
information” that included URLs, along with first-party cookie
identifiers, IP addresses, and user agent data; and after a user
submitted an HRA form, a URL was generated providing the user
with a report of the results. In other words plaintiffs’ evidence
allegedly would show that patients who submitted HRA forms
would have received a report of their results through a URL link,
and the tracking technologies uniformly would have shared that
URL link with Google and/or Meta regardless of the specific HRA
submitted. And arguably the results report for any submitted
HRA—as in the examples above—likely would contain the
“contents” of patients’ communications and their medical
information.
Adventist nevertheless argues plaintiffs “presented no
evidence that links to particular HRA results were uniformly
transmitted,” and Shafiq’s report did not show the tracking pixels
actually shared the HRA results URL with Google and/or Meta.
Shafiq stated—under penalty of perjury—that his “testing and
analysis” showed Adventist installed tracking pixels from Google
and Meta on the HRA section of its website, including where
the patient fills out the HRA form. Anne Dinapoli Block—a
representative from Adventist’s marketing firm BPD—testified
Google Tag Manager containers that included tracking pixels
for Google and Meta were “on the HRAs.” And Shafiq’s report
included the two URL examples noted above.
Shafiq also stated he tested how Adventist “installs
tracking pixels from third party companies while interacting with
the website in the form of assessments, surveys, and quizzes.”
He filled out three different HRAs and a cancer genetic risk
35
survey and, after submitting them, received a final report
for each that he “could view, print, or email.” Shafiq stated
his “testing showed Adventist did share the full-string URL
on the HRA portion of its website with both Google and Meta.”
Moreover, Shafiq opined the “tracking pixel source code on
Adventist Health’s website operates deterministically, meaning
it consistently executes in the same manner, always sharing
identifiers and content information with third parties such
as Google or Meta.” Shafiq further explained, “[s]uch code is
designed to behave uniformly for all users, meaning it will
execute the same way and share identical types of information
for every patient accessing Adventist Health’s website.” He
concluded Adventist’s website “uniformly installed tracking
pixels from third-party companies such as Google and Meta
over the class period.” And Adventist’s expert Cohen testified
she was unaware of any instances where the tracking pixels
installed on the “various Adventist websites” did not “share
at least a baseline of information,” including URLs.
Adventist asserts Shafiq’s report showed tracking
technologies only on “the homepage/disclaimer page for one
particular HRA,” but the report did not show “Google or Meta
tracking pixels being used on an HRA results page.” Adventist
notes its manager of marketing automation, Crystal Long,
“testified that, to the extent they were used at all, tracking pixels
would be on the initial disclaimer pages.” Long testified it
was her “understanding” that there was a pixel on the initial
disclaimer page but that pixel did not record if someone
completed an assessment, “[s]o the person could have left the
[HRA] and never checked the box and never proceeded, but
they’re thinking that somebody took that HRA because they
36
got to that page.” She recalled that issue “led to a discrepancy
between the number of people who visited the [HRA] page and
the number that actually completed it.” She did not testify that
pixels were not firing on the pages or events that came up when
a person checked the disclaimer box and completed the HRA
form, however. Adventist also asserts Shafiq “fail[ed] to show—
through DevTools, historical Google Analytics data, or otherwise”
—that the HRA results URL was transmitted to a third party.
Whether plaintiffs can prove Adventist in fact transmitted
URL links to HRA reports to Google and/or Meta also is a merits
question. At this stage, however, plaintiffs had to demonstrate
the claim was subject to common proof, not that they likely would
prevail on the claim. (Downey, supra, 44 Cal.App.5th at p. 1113
[predominance inquiry asks if the elements of the claim are
“susceptible of common proof”].) We conclude the evidence
plaintiffs presented was sufficient to demonstrate this issue—
whether Adventist uniformly shared URL links to patient HRA
reports with Google and/or Meta—could be answered through
common proof rather than individual inquiry. We offer no
opinion as to whether the evidence plaintiffs ultimately produce
will be sufficient to prove that is what happened.17 In any event,
17 Discovery is ongoing. After the certification hearing,
in January 2025, the court granted plaintiffs’ motion to compel
Adventist to produce certain Google Analytic logs it had provided
to its expert Cohen, which Shafiq would use for further statistical
analysis. At the certification hearing, plaintiffs’ counsel noted
the pending motion to compel and argued that, with those data
logs, Shafiq could “do a probability analysis . . . to identify the
likelihood that an individual class member will have transmitted
protected health information at least once during the class
period.”
37
the court did not deny certification of the HRA form subclass
for failing to satisfy the predominance prong on the ground
plaintiffs failed to show Adventist—through tracking
technologies—uniformly shared URL links to patients’ HRA
reports with Meta and/or Google. (See Leeds, supra, 115
Cal.App.5th at pp. 545–546 [appellate court analyzes denial
of class certification “ ‘based solely on the lower court’s stated
reason for the decision’ ”]; Knapp, supra, 195 Cal.App.4th at
p. 939 [“We may only consider the reasons stated by the trial
court and must ignore any unexpressed reason that might
support the ruling.”].)
Adventist also contends the court correctly found “there
is significant variability within the URLs and event data that
are allegedly transferred to Google and/or Meta” with respect to
the HRA form subclass. In its discussion of the predominance
prong for plaintiffs’ CIPA and CMIA claims as to the general
class, the court referred to—in addition to “ ‘ “HRA Report
Accessed” ’ ”—other “ ‘specific events’ ” and “page URLs” from
the HRA website that Shafiq’s report stated Adventist tracked
and transmitted, such as “ ‘ “HRA Disclaimer Agree,” ’ ”
“ ‘ “HRA Email Sign Up,” ’ ” “ ‘patient-assessment-report,’ ”
“ ‘https://hraadventisthealth.org,’ ” and “ ‘https://quiz.adventist
health.org.’ ” The court noted Shafiq didn’t state whether the
referenced “events” “contain[ed] patient search terms” and
didn’t differentiate between URLs and page titles that included
“user-inputted search terms” and those that did not. The court
found the noted events “appear[ed] to be records of page views
or buttons/links that a patient clicked” and thus were “not
‘content.’ ” The court also found the noted URLs and events
38
“provide[d] no information on their face about a patient’s
medical history, mental or physical condition, or treatment.”
The proposed HRA form subclass, however, includes only
patients who submitted HRA forms. The fact that Adventist
transmitted different URLs or event data depending on whether
a patient visited an HRA page, clicked on an HRA “quiz,” or
accessed an HRA report after submitting an HRA form thus
did not create individualized issues of proof—patients who
viewed but did not submit an HRA form or who only visited an
HRA page would not be part of the subclass. Only individuals
who submitted an HRA form would have received a URL link to
the report with the results. And as plaintiffs assert, all patients
who submitted an HRA form would have “proceeded through
[the] entire workflow” of multiple page view events. Moreover,
determining whether the sharing of a URL that links directly
to an HRA report can itself constitute the transmission of the
“contents” of a communication or of medical information would
not require review of each individual URL. Nor did the court
conclude the URLs that Adventist shared when patients
submitted HRA forms were too varied to determine by common
proof whether they constituted the contents of a communication
or medical information. As we now discuss, the court found
proof of plaintiffs’ CMIA claim for the HRA form subclass would
require individualized inquiry based on an entirely different
reason.
39
ii. Plaintiffs presented evidence that the question
of whether Google and/or Meta viewed or
accessed submitted HRA forms and/or reports
under the CMIA was subject to common proof
As the court noted, “Liability under CMIA requires a
showing ‘that the confidential nature of the plaintiff’s medical
information was breached as a result of the health care provider’s
negligence’ or affirmative conduct.” (Quoting Regents of
University of California v. Superior Court (2013) 220 Cal.App.4th
549, 564, 570, disapproved of on another ground in J.M. v.
Illuminate Education, Inc. (2026) 19 Cal.5th 705, 723 (J.M.).)
Undoubtedly, the reports generated in response to a patient’s
submitted HRA form—as we described above—contained
information “regarding” that patient’s medical history, condition,
or treatment. (Civ. Code, § 56.05, subd. (j)(1) [defining “medical
information”].) Plaintiffs also presented evidence that the
tracking technologies on the Adventist websites transmitted
identifiers including—at a minimum—first-party cookie
identifiers, IP addresses, and user agent data from which Google
and/or Meta could identify the specific user.18 (Ibid. [“medical
information” is “any individually identifiable information”
regarding a patient’s medical history, etc.].) And, as we
discussed, plaintiffs presented evidence that whether Adventist
transmitted URL links to its patients’ HRA reports is subject
to common proof.
18 Adventist argues that whether Adventist transferred
“identifying information . . . for any particular user” to Google
and/or Meta is a “significant individualized issue.” The court’s
order, however, did not find plaintiffs failed to show common
issues predominated on this question. Without getting into too
40
In essentially finding Adventist’s liability under CMIA
was not susceptible to class-wide proof for the HRA form
subclass, the court noted the “quiz” URL plaintiffs cited from
Shafiq’s report—“containing a [unique] string of numbers
and letters”—“does not, on its face, reveal medical information.
Rather[,] it provides access to medication information.” In Vigil
v. Muir Medical Group IPA, Inc. (2022) 84 Cal.App.5th 197, 213
(Vigil),19 the appellate court held “a breach of confidentiality
under the CMIA requires a showing that an unauthorized party
viewed the confidential information.” (Italics added.) Thus, an
unauthorized party’s possession of or access to the confidential
information would be insufficient to show a breach. (Id. at
pp. 217–219.) The court in Vigil also agreed “breach of
confidentiality under the CMIA is an individualized issue.” (Id.
at p. 219; id. at p. 220 [concluding “each class member would
have to show that his or her medical information was viewed by
an unauthorized party to recover under the CMIA” under Civil
much technical detail, Shafiq explained Google and/or Meta could
determine a user’s identity through “[d]eterministic matching . . .
based on identifiers such as email address, phone number, and
device identifiers,” or “[p]robabilistic matching (also known as
fingerprinting),” which “relies on statistical analysis of multiple
signals.” Shafiq opined the “IP address, user agent, and device
properties from the patient’s browser” that Adventist shared
through the tracking technologies contained a sufficient amount
of data “bits” to enable Google/Meta to “reasonably identi[f]y
an individual”—“even when the patients are not account holders”
—through “identity services” using deterministic and/or
probabilistic matching.
19 As we discuss, Vigil was disapproved of in J.M., supra, 19
Cal.5th at p. 723.
41
Code §§ 56.36, subd. (b) and 56.101, subd. (a)].)20 Following Vigil,
the court here found plaintiffs would have to show Google
and/or Meta actually viewed the contents of the HRAs to show
Adventist’s disclosure of the link violated CMIA.21
After this matter was submitted for decision, our high
court rejected the Vigil “rule that no breach of confidentiality
has occurred until medical information is actually viewed by
an unauthorized person.” (J.M., supra, 19 Cal.5th at p. 721.)
The court held “the primary inquiry with regard to breach
of confidentiality is whether the information is exposed to a
significant risk of unauthorized access or use.” (Id. at p. 723.)
The court disapproved Vigil to the extent it held otherwise.22
(Ibid.)
20 Vigil involved a data breach where a former employee of
a medical group, before her employment ended, “downloaded
copies of information for over 5,400 patients that included
insurance and clinical information.” (Vigil, supra, 84 Cal.App.5th
at pp. 205–206.) The named plaintiff had argued “the case could
be decided on a classwide basis because there was evidence
that [the former employee] downloaded, retained, and viewed
a patient spreadsheet.” (Id. at p. 207.)
21 As plaintiffs note, whether a third party “actually viewed
the information” is not an element under CIPA. (See § 631(a)
[CIPA is violated when a party “reads or attempts to read,
or to learn the contents or meaning of any message, report,
or communication” in transit]; see also footnote 22.)
22 As we discuss, the J.M. decision does not affect our
disposition. If plaintiffs’ proffered theory of proof would enable
a factfinder to determine on a class-wide basis whether Google
and/or Meta viewed or accessed the HRA report links—as we
conclude it does below—it also would enable a factfinder to
42
Not having the benefit of J.M., however, on appeal,
plaintiffs have argued the trial court ignored their proposed
theory of how they commonly could prove “whether third
parties viewed or accessed HRA Subclass members’ medical
information.” Plaintiffs assert they will present evidence at
trial—through their expert Dr. Jennifer Golbeck’s testimony—
that Meta and Google “used sophisticated computer algorithms
to process and analyze the data received from tracking pixel
transmissions.” As plaintiffs note, in her report, Golbeck
summarized her analysis as showing “that Facebook and
Google routinely collect, analyze[ ], and exploit users’ data
for advertising purposes, including the data of Adventist’s
patients.”23 As “Golbeck’s testimony will apply to the entire
Subclass,” plaintiffs contend this element “is a common issue
supporting predominance.” To the extent that this evidence
would satisfy an actual “viewing” or “accessing” requirement,
it would necessarily demonstrate exposure to a significant risk
of unauthorized access.
Adventist argues plaintiffs never argued Meta’s and
Google’s algorithmic processing of data constituted “ ‘viewing’ ”
of that information for purposes of CMIA. Adventist
acknowledges plaintiffs mentioned their algorithm theory
determine if the information in the HRA report links was
“exposed to a significant risk of unauthorized access or use.”
(J.M., supra, 19 Cal.5th at p. 723.) To the extent J.M. raises new
issues, however, the parties may raise them in the trial court
on remand.
23 The court denied Adventist’s motion to strike Golbeck’s
report and opinions.
43
in a footnote but essentially contends that, because a footnote
was insufficient to “advance their ‘algorithmic processing’ theory
at . . . trial,” plaintiffs forfeited the argument.
We disagree. In their motion, plaintiffs argued that
whether Adventist violated CMIA depended on questions
common to the class, including whether “the disclosed
information was ‘viewed or accessed’ by an unauthorized party.”
Plaintiffs provided their support for that statement—as they did
for other common questions their motion identified for this cause
of action—in a footnote. Plaintiffs asserted their expert Golbeck
“will testify that Facebook and Google have sophisticated systems
for processing and analyzing the data and building profiles used
to serve targeted advertising. [Citing ¶¶ 35–77 of Golbeck’s
report.] How these algorithms work and whether processing
by computer algorithm constitutes being ‘viewed or otherwise
accessed’ for CMIA purposes present common questions.”
Plaintiffs filed Golbeck’s report with their motion as a supporting
exhibit. Plaintiffs also cited to Cousin II in support of this
theory. In that case, the district court denied defendant’s motion
to dismiss the plaintiffs’ CMIA claim where the plaintiffs had
“plead[ed] information regarding Meta’s business model and
how it uses the information for targeted advertising.” (Cousin II,
supra, 702 F.Supp.3d at p. 975.) The court explained “whether
the alleged use by Meta of the information, through perhaps
algorithms, amounts to viewing or accessing under CMIA is
a question the Court cannot answer on Defendant’s motion to
dismiss. It is sufficiently plausible at this time that Plaintiffs’
information was ‘viewed or otherwise accessed’ as contemplated
by CMIA.” (Ibid.)
44
Adventist relies on Holden v. City of San Diego (2019) 43
Cal.App.5th 404. There, the court found a plaintiff was precluded
from raising a legal issue on appeal—that the defendant city
had failed to comply with a statute—where he had raised that
issue “only in a footnote in his opening [trial court] brief” without
substantive legal analysis. (Id. at p. 419.) Holden is inapposite.
There, the plaintiff’s footnote stated the city had ignored a
statutory requirement without quoting the relevant language
from the statute or providing any legal analysis that the city
was required to comply with the statute and failed to do so.
(Ibid.) The plaintiff also failed to provide any substantive
analysis of the issue in his opening brief on appeal, again
referring to a footnote. (Ibid.) Here, however, plaintiffs’ motion
contended up front that common issues existed as to Adventist’s
liability under CMIA and set forth those common questions in a
bullet-pointed list. From our reading of the motion, counsel made
a style choice to use footnotes to describe the common evidence
plaintiffs would present to answer those questions rather than
interrupt the flow of that list. And, unlike the plaintiff in
Holden, plaintiffs’ opening and reply briefs on appeal
substantively address their algorithm theory. We find no
forfeiture.24
The court did not mention plaintiffs’ algorithm theory of
proof in finding they failed to show common issues predominated.
It thus did not determine if this element of plaintiffs’ CMIA claim
—whether Google and/or Meta viewed or accessed the HRA
24 Moreover, in opposition to plaintiffs’ certification motion,
Adventist never argued plaintiffs’ algorithm theory would not
enable a factfinder to answer the viewing/accessing question
on a class-wide basis for the HRA form subclass.
45
report links—could be determined on a class-wide basis under
the theory plaintiffs proposed. (See Brinker, supra, 53 Cal.4th at
p. 1021 [answer to question of predominance “hinges on ‘whether
the theory of recovery advanced by the proponents of certification
is, as an analytical matter, likely to prove amenable to class
treatment’ ”]; Walsh, supra, 148 Cal.App.4th at p. 1450 [court
must consider plaintiffs’ theory of liability to determine if
common issues predominate].) This was error. As plaintiffs
argue, the theory they advanced through Golbeck’s report
was that “Google’s and Facebook’s sophisticated algorithms
automatically processed the transmitted data.” Accordingly,
“[t]he trial court’s ‘actual clicks’ theory b[ore] no relationship to
Plaintiffs’ algorithmic processing theory . . . and therefore cannot
support denial of certification.” They argue “[i]t is a class-wide
merits issue whether the algorithmic processing that Plaintiffs
will show Facebook and Google performed satisfies this element
as ‘viewing’ or ‘accessing.’ ” (Citing the district court’s holding
in Cousin II, supra, 702 F.Supp.3d at p. 975, stated above.)
We agree and conclude plaintiffs presented sufficient
evidence to demonstrate their algorithm theory of proof would
enable a factfinder to determine on a class-wide basis whether
Google and/or Meta viewed or accessed the HRA report links.
In plaintiffs’ words, Golbeck’s report explained how Google
and Facebook process, analyze, and assimilate users’ data
they receive to provide targeted advertising. We have reviewed
Golbeck’s report. She explained companies like Meta/Facebook
and Google use machine learning systems to analyze all available
user data to develop predictive models to develop targeted
advertising. “[B]ecause a machine learning system constructs
its predictive model from all data made available, all the data
46
made available is necessarily used by that system, regardless of
what degree of predictive weight a resulting model places on any
given data point.” Golbeck opined “it is reasonable to state that
all data available to [a] model in operation is used by that model,
and it is not usually feasible (and not part of the usual parlance
of those working with machine learning) to discuss the
relationship between a particular piece of data and the
predictions made by the model.”
As we understand their theory, plaintiffs contend they
can show Meta’s and/or Google’s sophisticated data processing
systems/computer algorithms, as a matter of course, would have
“accessed” or “viewed” the data within the actual HRA reports
—i.e., patients’ medical information—through the URL links
Adventist transmitted. That data then necessarily would have
been used in some way by the predictive models those systems
created to develop targeted advertising. Such an analysis would
show on a class-wide basis whether or not Adventist’s alleged
transmission of URL links to patients’ HRA reports resulted
in a breach of the “confidential nature” of patients’ medical
information. Defendants argued below and on appeal that
what Adventist allegedly transmitted was the URL, not the
report itself, and the URL does not reveal medical information.
But whether a third-party’s computer system’s assimilation of
data—as plaintiffs’ expert described—amounts to the viewing
or accessing of that data under the CMIA is a merits question
common to the HRA form subclass. Accordingly, we conclude
plaintiffs met their burden in the trial court to show whether
unauthorized parties viewed or accessed HRA form subclass
members’ medical information can be determined based on
common proof.
47
In summary, we conclude the court’s reasoning did not
support its finding that plaintiffs did not show common issues
predominated on their CIPA and CMIA claims as to the HRA
form subclass.
c. The patient portal subclass
i. Plaintiffs demonstrated their CIPA –
wiretapping claim was subject to common proof
Plaintiffs’ ultimate theory was that the baseline
information the tracking pixels uniformly shared whenever
patients interacted with an Adventist website—the first-party
cookie identifiers, page view information, URLs (whether
partially obfuscated or not), IP addresses (whether complete
or partially masked), and user agent data—was evidence
applicable class-wide to prove plaintiffs’ CIPA (and CMIA) claim,
demonstrating common issues predominated. Plaintiffs relied
on their expert Shafiq’s reports to show the question of whether
this information included the “contents” of Adventist’s patients’
communications was subject to common proof. Those reports,
which the court examined, included Shafiq’s analysis of the data
transmitted to Google and/or Meta from both Adventist’s public
websites and the patient portal, however.
Shafiq stated Adventist “shared at least the following types
of sensitive information about patient activity . . . alongside the
patient identifiers:” “Page URL that includes search terms” and
“Page title that includes search terms.” Shafiq gave examples of
URLs from Adventist’s public website that included query strings
with search terms such as “pregnancy,” “breast . . . cancer,”
and the name of a provider combined with the search term
“mental . . . health” or “radiation . . . oncology.” Another page
URL example showed a search at “doctors.adventisthealth.org”
48
that included a query string with the search terms “surgical”
and “abortion.”
The trial court noted those URL examples included search
terms. The court also referred to Shafiq’s finding that Adventist
shared “Page title that includes search terms such as ‘surgical
abortion – Find a Physician or Provider/Adventist Health’
and ‘MyAdventistHealth Patient Portal/Adventist Health.’ ”25
The court noted the first page title example appeared to contain
search terms but the second did not. The court concluded page
titles like the example “ ‘MyAdventistHealth Patient Portal’ ”
“merely identif[ied] the page” and were “not ‘a person’s personal
search engine queries’ that [could] be content.” (Quoting
Cousin II, supra, 702 F.Supp.3d at p. 976.) The court further
noted Shafiq’s report referred to Adventist having tracked
and transmitted “ ‘specific events’ ”—again, from Adventist’s
public website—“ ‘such as “HRA Report Accessed,” “Online
Scheduling Confirmation,” ’ ” “ ‘patient-assessment-report,’ ”
“ ‘Knee Webinar Thank-You,’ . . . ‘Lodi Ortho Thank-You,’ . . .
‘Adventist Health All Contact Button Clicks,’ [and] ‘Heart
Webinar Pageview,’ ” but he did not “say these events contain
patient search terms.” As we mentioned, the court found
they appeared to be “records of page views or buttons/links
that a patient clicked” and “[a]s such,” were “not ‘content.’ ”
The court noted that although Shafiq gave examples of
URLs “containing patients’ search terms,” his report “define[d]
‘content information’ as including page titles.” “Navigating to
25 The page title “MyAdventistHealth Patient Portal” appears
to be the page where a patient can log into the portal, not
necessarily the page within the patient portal after the patient
has logged in.
49
a webpage without entering search terms,” the court reasoned,
“does not transmit ‘contents,’ even if information about that
webpage (i.e., record data) is transmitted.” (Citing Zynga, supra,
750 F.3d at pp. 1108–1109.) Accordingly, because one patient’s
transmitted information might contain “search terms” that
“could be content,” while another patient’s transmitted
information might consist of a “webpage or event information”
that could be merely “record information,” the court found
plaintiffs failed to show common issues predominated relating
to this element of proof.
Plaintiffs do not dispute this reasoning as applied to the
variety of transmissions from Adventist’s public website with
respect to the general class. Plaintiffs contend, however, that
the court’s reasoning—that their CIPA claim was not susceptible
to common proof because some URLs contained patient search
terms and others did not—did not apply to the patient portal
subclass because no “query strings” were transmitted from the
patient portal. In reasoning plaintiffs failed to show common
issues predominated for the patient portal subclass, the court
noted one example URL transmitted from within the patient
portal included the words “/health-record/radiology”26 revealing—
as Adventist’s expert confirmed—that the patient had requested
26 The full page URL in the patient portal for this example
was “https://patientportal.myadventisthealthportal.org/
person/dS7xf9Kt4in8df5/health-record/radiology/15999379949/
download.” Before sharing the full page URL, Cerner would
have substituted the identifying number strings with
“PERSON_ID” and “DOCUMENT_ID.” One such example is:
“/person/PERSON_ID/health-record/radiology/types/common/
DOCUMENT_ID/download.”
50
a radiology report. The court noted such a URL may have
revealed the patient’s medical information—and thus we can
infer also arguably conveyed the “contents” of the patient’s
communication. The court, however, noted other URLs that
reflected the “patient’s activity in the patient portal caused a
‘Download/Transmit’ or ‘Health Record – Results’ event,” “may
not reveal . . . ‘content’ under CIPA” (or “ ‘medical information’
under CMIA”). The court reasoned “ ‘Download/Transmit’ and
‘Health Record – Results’ appear[ed] not to contain patient
search terms.”27
As plaintiffs note, unlike the public website, none of
the URLs transmitted from the patient portal included patient
search terms because all query strings were removed. Nor would
any Page search terms (such as the surgical abortion example
above) have been included, as Cerner’s security software would
have removed any terms revealing health information within
search parameters. Accordingly, as no patient portal URLs
contained user search terms or query strings, plaintiffs argue
there would be no need to examine the individual URLs for
search terms to determine if they transmitted “contents,” as the
court had reasoned was required for the public website. Rather,
plaintiffs contend that whether Adventist’s uniform transmission
of URLs from the portal with path information, “including
descriptive natural language terms like ‘Health Record – Results’
27 These descriptive terms reflected the tabs or buttons within
the patient portal that logged-in patients could “click.” Others
included “lab results,” “radiology,” “medications,” “procedures,”
“health record,” “messages,” “appointments,” “documents,” and
“view results.”
51
and ‘Radiology,’ ” satisfies the “contents” element of CIPA “is a
merits question, and it is a common one.”
First, we do not interpret the court’s reference to “events”
not containing “search terms” to mean the court mistakenly
believed some URLs in the patient portal had “query strings” and
some did not, as plaintiffs seem to contend. Rather, the court
was comparing the “radiology” example—which showed the
patient had downloaded a radiology record through inclusion of
the substantive term “radiology”—with the other two examples
that generally described the patient’s activity—having instigated
an unknown “download” or viewed some type of “results” within
the patient’s health record. Critically, the court did not state
the “radiology” example included user search terms while the
“download/transmit” example did not. Rather, we understand
the court to have reasoned that, without a user search term,
specific document accessed, or other similar user communication,
the descriptor “download/transmit” likely did not convey the
contents of the patient’s communications whereas “radiology”
might. (Cf. Cousin II, supra, 702 F.Supp.3d at pp. 975–976
[alleging data collected included “specialty healthcare providers”
and “treatments for medical conditions” was sufficient to show
“ ‘contents of communications’ ” to state a claim under CIPA].)
We do not disagree that the different descriptive terms within
the patient portal URLs seem to convey different levels of
information—despite uniformly not including query strings.
Nevertheless, those descriptive terms—as we noted—
denote the activity choice the patient made within the patient’s
personalized portal. Presumably, a URL that included the
descriptive term “health record” or “messages” indicated the
patient had accessed her electronic health record or sent or read
52
a message to or from a provider, just as the term “radiology”
that appeared in the example above showed a patient checked
a radiology result. In the context of an authenticated patient
portal, therefore, the description of the chosen page visited,
or activity performed within the portal, arguably is not “basic
identification [or] address information” that constitutes merely
“record information.” (Zynga, supra, 750 F.3d at pp. 1107,
1109.)28 For purposes of determining whether the URLs
transmitted from the patient portal conveyed “contents” under
CIPA, it thus would not seem to matter whether the descriptive
term assigned to the chosen activity was more specific like
“radiology” or more generic like “download,” as any term arguably
would convey the “purport” of the patient’s communications with
Adventist—to message a provider, download a health record,
28 For Adventist’s public website, in contrast, the URL
arguably would need to include specific terms to disclose that the
patient was exchanging health-care-related communications with
Adventist and not simply browsing the website. For the patient
portal subclass, however, the information Adventist allegedly
transmitted did not show the patient simply navigated to the
patient portal login page, but that the patient actually had logged
into the portal and took a specific action. (Compare, e.g., Zynga,
supra, 750 F.3d at pp. 1108–1109 [address of website visited
was not the “contents of a communication”] with Google RTB,
supra, 606 F.Supp.3d at p. 949 [finding alleged transmission of
“ ‘content categories’ ” of website, categories that describe current
section of the website, and other information, all disclosed
“content”].) Again, the court agreed that patients who logged
into the patient portal only would be engaging in activities
related to their health care with Adventist.
53
view a test result, etc.29 (See 18 U.S.C.§ 2510(8).) Whether
plaintiffs successfully can establish those URLs—despite having
generic descriptive terms—satisfy CIPA’s contents element is
a merits question, however. (See Brinker, supra, 53 Cal.4th at
p. 1023 [certification question does not ask whether action is
legally or factually meritorious].)
In any event, plaintiffs argue—as they did below—that
the baseline information the tracking technologies universally
transmitted when a patient logged into the patient portal is
common evidence that will show Adventist transmitted the
“contents” of the subclass members’ communications in violation
of CIPA. They argue that “simply logging into the portal
disclosed the individual’s status as [Adventist’s] patient” and
thus transmitted content. (See Nienaber v. Overlake Hosp.
Medical Center (W.D.Wash. 2024) 733 F.Supp.3d 1072, 1081
(Nienaber) [“transmission of information submitted to a private
patient portal—such as a user clicking on the ‘log in’ button on
that webpage—reveals patient status”].) Plaintiffs presented
evidence through Shafiq’s report that, along with the URL path
showing the user logged into the patient portal, the tracking
technologies transmitted the “partially masked IP address,
29 Griffith v. TikTok, Inc. (C.D.Cal., Sept. 9, 2024, No. 5:23-cv-
00964-SB-E) 2024 WL 4308813, relied on by Adventist, is thus
distinguishable. The alleged CIPA violations there were based
on the TikTok pixel having transmitted the contents of purported
class members’ communications from various websites. (Id. at
*1–2, 4.) The viability of plaintiffs’ CIPA claims thus would
depend on the nature of each website, each plaintiff’s activity
on the various websites, and how each different website
implemented the software. (Id. at *4.)
54
user agent, and cookies containing identifiers,” which were
sufficient to enable Google to identify the individual patient.30
Plaintiffs assert that—“[a]t the merits stage”—their expert
will use Google Analytics logs—that were produced after class
certification briefing had completed—“to show that descriptive,
full-string URLs were disclosed to Google uniformly for all”
patient portal subclass members. (See footnote 17.)
The court found plaintiffs “did not submit evidence that
merely logging into the patient portal transmits information
in violation of CIPA or CMIA.” This was a premature
determination of the merits of plaintiffs’ theory of proof, at least
for the CIPA claim. (Sav-On, supra, 34 Cal.4th at p. 327; Linder,
supra, 23 Cal.4th at pp. 439–440.) Sharing a URL path along
with patient identifiers that indicated a patient had logged into
the Adventist patient portal arguably transmitted the “contents”
of the patient’s communication. Arguably, the “purport” of—or
the “intended message conveyed by”—entering login credentials
on the patient portal page and hitting the “login” button is to tell
Adventist the user is a verified patient who wants to log into his
or her personal patient portal. (See Meta Pixel, supra, 647
F.Supp.3d at p. 795 [construing “log-in buttons” to patient portal
as “ ‘contents’ ”].) Because plaintiffs presented evidence showing
the tracking technologies transmitted the same baseline
information discussed above for all subclass members, we
conclude they met their burden to show the contents element of
their CIPA claim was subject to common proof. (See Downey,
30 Again, the court did not find plaintiffs failed to show
common evidence was available to determine whether the
information transmitted could enable Google to identify
the individual. (See footnote 18.)
55
supra, 44 Cal.App.5th at p. 1113.) As this was the only element
the court discussed in its predominance analysis of the CIPA
cause of action for the patient portal subclass, the denial of class
certification on this ground is unsupported. (See Leeds, supra,
115 Cal.App.5th at pp. 545–546; Knapp, supra, 195 Cal.App.4th
at p. 939.)
ii. Substantial evidence supported the court’s
finding that plaintiffs failed to show their
CMIA claim was subject to common proof
for the patient portal subclass
We cannot say the same for plaintiffs’ CMIA claim. The
trial court found plaintiffs failed to show common proof could
establish whether the URLs transmitted from the patient portal
disclosed plaintiffs’ medical information under CMIA based on
essentially the same reasons as its analysis of plaintiffs’ evidence
of “contents” under CIPA. Plaintiffs argue that, because the
patient portal was “dedicated solely to communications regarding
patients’ medical treatment,” whether the URLs transmitted
from the patient portal disclosed patients’ medical information
is a common question. They contend the differences in the
specificity of the URLs’ descriptive terms thus would not require
examination of each individual URL because all the descriptive
terms—even the most generic ones—arguably would “regard,
concern, and relate to the medical treatments that the patients
have received or plan to receive from [Adventist].”
Although patients engaged only in health-related activities
within the patient portal, we cannot conclude the variation
in the descriptive URLs would not raise individual issues for
the “medical information” element of CMIA, as we did for the
“contents” element of CIPA. While more generic descriptive
56
terms still indicated the choice the patient made within
the portal—and thus, whether a patient’s choice of activity
constituted “contents” could be answered with common evidence
—we agree with the trial court that those same descriptive terms
did not uniformly convey “medical information.”
For purposes of showing Adventist transmitted “medical
information” under CMIA, the variations in the descriptive terms
used to describe patients’ activities within the portal thus raised
individual issues. As the trial court found, a URL revealing that
a patient downloaded a “radiology” report may have constituted
the disclosure of medical information—that a patient underwent
an imaging test or procedure arguably discloses information
“regarding” the patient’s medical history, condition, or treatment.
But a URL revealing that a patient “download[ed]” an
unspecified document, viewed something in the patient’s health
record, or generally made an appointment or sent a message—
without more—would not seem to convey information regarding
the patient’s medical history, mental or physical condition, or
treatment.31 (See Eisenhower, supra, 226 Cal.App.4th at p. 435
31 This is in contrast to Frasco v. Flo Health, Inc. (N.D.Cal.
2025) 349 F.R.D. 557, on which plaintiffs rely. There, a court
certified a class of users of a menstruation and ovulation tracker
app whose personal information about menstruation, ovulation,
pregnancy goals, and the like, allegedly was shared with Google
and Meta. (Id. at p. 569.) The descriptive terms of the custom
events transmitted there, however, all revealed a user’s personal
health information, such as “PREGNANCY_WEEK_CHOSEN”
or entries relating to a user’s goals—such as “ ‘Track my cycle,’ ”
“ ‘Get Pregnant,’ ” or “ ‘Track pregnancy’ ”—that all new users
were required to input. (Id. at pp. 572–573.) The naming
conventions of the events within the patient portal here
57
[rejecting plaintiffs’ interpretation of CMIA that would mean
“release by a health care provider of personal identification would
be sufficient whether or not there was a release of substantive
information regarding that person’s medical condition, history,
or treatment” (italics added)]; cf., e.g., Doe v. Regents of
University of California (N.D.Cal. 2023) 672 F.Supp.3d 813,
818–819 [denying motion to dismiss CMIA claim where plaintiff
alleged she entered “information relating to her heart issues
and high blood pressure” in her patient portal that defendant
disclosed to Meta and that she began receiving advertisements
on Facebook for high blood pressure medication].)
While we agree that whether or not the descriptive URLs
disclosed medical information is a merits determination,
plaintiffs did not demonstrate that merits determination
is subject to common proof. Moreover, that the baseline
information transmitted when patients logged into the patient
portal arguably revealed subclass members’ patient status
does not also translate into class-wide evidence to prove their
medical information was disclosed. Plaintiffs correctly note
patient status is PHI under HIPAA.32 (Meta Pixel, supra, 647
F.Supp.3d at p. 793; Nienaber, supra, 733 F.Supp.3d at p. 1081.)
Patient status is not “medical information” protected under
do not universally convey the same type of personal or
specific information.
32 The Health Insurance Portability and Accountability Act
(HIPAA) (42 U.S.C. § 1320 et seq.). See 45 C.F.R. § 160.103
(2026) (defining PHI under HIPAA as “individually identifiable
health information” that is “[t]ransmitted by electronic media”;
“[m]aintained in electronic media”; or “[t]ransmitted or
maintained in any other form or medium”).
58
CMIA, however. (Eisenhower, supra, 226 Cal.App.4th at pp. 435–
436 [fact individual “may have been a patient at a hospital at
some time” or was identified as “a patient is not in itself medical
information” under CMIA]; see also id. at pp. 436–437 [noting
“the definition of ‘individually identifiable health information’
under federal law differs markedly from that in the CMIA”].)
We also reject plaintiffs’ contention that the court did not
apply CMIA’s definition of medical information. In its discussion
of whether common issues predominated on the CMIA claim for
the general class, the court quoted the definition from the Civil
Code. The court noted Shafiq’s report’s references to “ ‘sensitive
information’ ” included more than “medical information” as
defined by CMIA. The court expressly found that, “[b]ecause
Shafiq’s analysis aggregate[d] different types of information—
such as URLs that may or may not convey medical information,
page titles that may or may not include descriptive or generic
search terms or no search terms, and page views and events
with generic names that may not convey medical information—
into the category of ‘sensitive information,’ his reports do not
support Plaintiffs’ conclusion of a common question concerning
whether the transmissions violate CMIA.” The court had no need
to repeat CMIA’s definitions or the above findings when it
analyzed the descriptive terms included in the URLs transmitted
from the patient portal and concluded those terms did not
universally constitute “ ‘medical information’ under CMIA.”
Accordingly, we conclude substantial evidence supported the
trial court’s reasoning that plaintiffs failed to demonstrate
common proof was available to determine whether Adventist
disclosed the subclass members’ “medical information.”
59
4. The superiority and manageability of the subclasses
The court also denied plaintiffs’ motion for class
certification on superiority and manageability grounds. Courts
generally consider four factors in determining if a class action
would be superior to individual suits: (1) the interest of each
purported class member in personally controlling his or her
own case; (2) any difficulties “ ‘likely to be encountered in
managing a class action’ ”; (3) the “ ‘nature and extent of any
litigation by individual class members already in progress
involving the same controversy’ ”; and (4) the “ ‘desirability of
consolidating all claims in a single action before a single court.’ ”
(Basurco v. 21st Century Ins. Co. (2003) 108 Cal.App.4th 110,
121.) “In certifying a class action, the court must also conclude
that litigation of individual issues, including those arising from
affirmative defenses, can be managed fairly and efficiently.”
(Duran, supra, 59 Cal.4th at pp. 28–29; id. at pp. 32–33 [trial
court failed to manage individual issues raised by defendant’s
affirmative defense properly].)
The court found plaintiffs did not show the superiority
of a class action because they (1) cited “no evidence” in support
of their assertion that “few class members have the time and
resources to pursue their claims on an individual basis” and
(2) did not “state the value of the individual claims.”
In their reply, plaintiffs asserted they were seeking
statutory damages under CIPA and CMIA. At the hearing,
plaintiffs’ counsel clarified that the CIPA and CMIA claims
were worth $2,500 and $5,000 in statutory damages, respectively,
for each plaintiff. For plaintiffs’ other claims, counsel stated
their damages expert—in other tracking pixel cases—had
estimated the value of the disclosed information to be about
60
“$200 a class member.” Plaintiffs’ post-hearing trial plan also
stated that plaintiffs sought $5,000 in statutory damages under
CIPA (Pen. Code, § 637.2), $2,500 in statutory damages under
CMIA (Civ. Code, § 56.36), and estimated damages under the
UCL “to be in the range of $200.”
We aren’t sure what other evidence plaintiffs could have
presented to demonstrate few Adventist patients would have
“the time and resources to pursue their claims on an individual
basis.” With at most $7,700 (plus attorney fees) at stake, it is
hard to imagine how the average person could afford to pursue
these claims individually. For example, the cost to hire expert
witnesses to develop the technical evidence necessary to prove
these claims alone would exceed any one individual’s expected
recovery.33 As a class action, however, the alleged damages
in the aggregate would consist of millions of dollars.
“Generally, a class suit is appropriate ‘when numerous
parties suffer injury of insufficient size to warrant individual
action and when denial of class relief would result in unjust
advantage to the wrongdoer.’ ” (Linder, supra, 23 Cal.4th
at p. 435.) That is the case here. Absent a class action, each
individual proposed class member—whether the HRA form or
patient portal subclass—effectively would be unable to seek
redress for Adventist’s alleged privacy violations. As plaintiffs
argued, a class action is “not only the best, but realistically the
only, way to compensate Class members and hold Adventist
accountable for” its alleged disclosures of its patients’ information
to Meta and Google. Moreover, given the cost of litigation would
33 Shafiq was paid $500 per hour, and Golbeck was paid
$550 per hour.
61
far exceed any one individual’s recovery, it is unlikely individual
class members would have an interest in controlling their own
cases. Nor does Adventist contend any of its patients has ongoing
litigation against it involving these same claims. Finally, given
the common issues we have discussed, we agree with plaintiffs
that “it would be grossly inefficient for the courts to hear
the same liability facts in a deluge of individual actions.”
Accordingly, we conclude plaintiffs sufficiently demonstrated
the superiority of class action treatment for the HRA form
and patient portal subclasses.
As for the manageability question, the court primarily
was looking at that issue through the lens of the general class.
As to the two relevant subclasses, the court found plaintiffs failed
to “address” the manageability of the individual questions that
we have concluded plaintiffs established can be determined
through common proof. For the HRA form subclass, the court
stated that plaintiffs did not discuss, for example, “whether there
is a way to identify the URLs containing links to HRAs that third
parties actually clicked on to view the HRAs.” As we discussed,
plaintiffs presented a common theory of proof that would not
require a showing of “ ‘actual clicks’ ” on individual URLs to
establish Google and/or Meta viewed or accessed the linked
HRA reports under the CMIA. The issue the court identified
thus would not create a manageability problem. (Leeds, supra,
115 Cal.App.5th at pp. 545–546 [appellate court considers only
stated reason].)
As for the patient portal subclass, the court stated
plaintiffs, for example, did not discuss “whether some kind of
statistical analysis could show the percentage of patients’ activity
in the patient portal that resulted in URLs containing medical
62
information being sent to third parties.” The court also noted—
again, as an example—plaintiffs’ trial plan stated common issues
which included “ ‘Whether the baseline information transmitted
by Google Analytics and the Facebook Meta Pixel constitutes
“contents” under CIPA,’ and ‘Whether the baseline data
constitutes “medical information” under [CMIA].’ ” The court
noted, however, that—as it had found—“some of that ‘baseline
data’ (such as page view information and URLs) may or may not
be ‘contents’ or ‘medical information’ depending on whether the
data reveals patient’s search terms, the descriptive quality of
the search terms, and other characteristics. The trial plan does
not explain how analyzing the different types of ‘baseline data’
. . . can be handled to determine which class members had their
‘contents’ or ‘medical information’ transmitted to a third party.”
As we have discussed, although this may have been
an issue for the general class, it is not one for the patient portal
subclass. Under plaintiffs’ theory of proof, the baseline data
transmitted when any patient logged into the patient portal
included the contents of the patient’s communication with
Adventist. As we explained, that some URLs conveyed more
specific terms to describe patients’ activities within the patient
portal would not affect plaintiffs’ contention that all patients
who logged into the patient portal had the contents of their
communications transmitted to a third party. Arguably, then,
no statistical analysis would be necessary to analyze the terms
in the URLs, as under plaintiffs’ theory, they did not raise an
issue requiring individual proof. And as plaintiffs failed to
demonstrate their CMIA claim was subject to common proof
for the patient portal subclass, we need not determine whether
63
plaintiffs could manage individualized issues relating to that
claim for that subclass.
In sum, we conclude the record does not support finding
the HRA form subclass, and the patient portal subclass for
plaintiffs’ CIPA claim, raised individual issues that cannot be
managed.
5. The trial court did not abuse its discretion in finding
plaintiffs forfeited certification of their CIPA –
recording claim
As the trial court noted, plaintiffs’ CIPA claim in their
TAC alleged Adventist violated section 632(a) when it “used a
recording device to record confidential communications . . . and
then transmitted such information to others, such as Facebook.”
The court however, found plaintiffs had “dropped any attempt to
certify a class for alleged violations of section 632.” In so finding,
the court noted “[n]either [p]laintiffs’ motion nor reply brief
mentions section 632.” The court acknowledged plaintiffs’ trial
plan—filed after the hearing by permission—“list[ed] section 632
issues to be decided in the trial,” but found “asserting those
issues after the hearing without briefing or citations to the
evidence is too late.” We agree.
Plaintiffs contend the court erred. They assert their
motion’s arguments about their CIPA claims “encompass[ed] both
[s]ections 631 and 632.” They note a key distinction between
sections 631 and 632 is that section 632 “requires a showing that
the communications were ‘confidential.’ ” They argue their list
of common issues for their CIPA claim included “[w]hether Class
members had a ‘reasonable expectation of privacy.’ ” They argue
that issue was relevant only to their section 632 claim and they
discussed it substantively, citing to discussion in Meta Pixel that
64
related to a section 632 CIPA claim. (Citing Meta Pixel, supra,
647 F.Supp.3d at p. 799.) Plaintiffs also contend Adventist
“understood” plaintiffs had addressed section 632 in their motion
because Adventist cited a case for the proposition that “ ‘[i]n
a case involving alleged violations of CIPA, “individualized
inquiries into the reasonableness of each class member’s
individual expectation of confidentiality . . . [we]re unavoidable”
and, therefore such claims were “not capable of being resolved
on a class-wide basis.” ’ ” (Citing Adventist’s citation of Mendell
v. Am. Med. Response, Inc. (S.D.Cal., Mar. 23, 2021, No. 19-cv-
01277-BAS-KSC) 2021 WL 1102423, plaintiffs added italics.)
Plaintiffs bore the burden on their motion for class
certification. That burden included providing citation to the law
on the claims for which they were seeking certification and
substantive discussion of each of the elements. Plaintiffs never
mentioned section 632(a) in their moving or reply papers, as
the court found. Although they briefly mentioned the issue of
a “reasonable expectation of privacy” in their discussion of their
CIPA claim—for which they cited only section 631—plaintiffs
never set forth all of the elements they would be required to
prove under section 632(a). Nor do we find plaintiffs’ brief
mention of a “reasonable expectation of privacy” constituted a
substantive discussion of the issue. Moreover, Adventist cited
Mendell in discussing the issue of whether class members had
a reasonable expectation of privacy “for purposes of an invasion
of privacy claim,” not a section 632 claim. After all, plaintiffs
originally had pursued an invasion of privacy claim against
Adventist, alleged as the fifth cause of action in their TAC.
Finally, we do not find plaintiffs’ belated citation to
section 632 in their trial plan’s list of common questions—
65
or Adventist’s response to the trial plan—cures their failure
to cite and properly discuss section 632 in their moving and
reply papers.34 Accordingly, the trial court did not clearly abuse
its discretion in not considering plaintiffs’ section 632(a) claim
for class certification.
34 Adventist’s response to plaintiffs’ trial plan noted plaintiffs’
plan’s proposed common question—“ ‘Whether Class members’
communications with Adventist were confidential’ ”—was
“a specific element of a Section 632 CIPA claim.” Adventist
again cited to Mendell. We do not read Adventist’s response
to plaintiffs’ trial plan’s mention of an element of a section 632
CIPA claim as somehow agreeing that plaintiffs’ motion raised
the claim.
66
DISPOSITION
We affirm the court’s order finding plaintiffs forfeited their
section 632(a) claim and denying class certification of their CMIA
claims for the patient portal subclass. We reverse the court’s
order denying class certification for the HRA form subclass
and the surviving claims for the patient portal subclass and
remand the matter for further proceedings.
The parties are to bear their own costs on appeal.
NOT TO BE PUBLISHED IN THE OFFICIAL REPORTS
EGERTON, Acting P. J.
We concur:
ADAMS, J.
HANASONO, J.
67