Website tracking technologies have become a significant source of privacy litigation, especially when they are deployed on healthcare websites, patient portals, assessment forms, and other pages involving sensitive information. A recently published California appellate decision illustrates how these cases may proceed when plaintiffs allege that tracking pixels transmitted information to third parties.
In Doe v. Adventist Health System/West (Cal. Ct. App., July 24, 2026, No. B344951), certified for publication on August 24, 2026, the California Court of Appeal considered claims involving the California Invasion of Privacy Act (“CIPA”), the California Confidentiality of Medical Information Act (“CMIA”), Meta Pixel, and Google Analytics.
The court reversed the denial of class certification for the HRA-form subclass and for the surviving claims of the patient-portal subclass, including the CIPA section 631 claim. It affirmed the denial of certification for the patient-portal CMIA claims and the finding that the plaintiffs forfeited certification of their CIPA section 632 claim. The matter was remanded for further proceedings. The court did not determine that Adventist violated CIPA or CMIA; it addressed whether specified issues could be resolved through evidence common to the proposed class members.


