Website tracking technologies have become a significant source of privacy litigation, especially when they are deployed on healthcare websites, patient portals, assessment forms, and other pages involving sensitive information. A recently published California appellate decision illustrates how these cases may proceed when plaintiffs allege that tracking pixels transmitted information to third parties.
In Doe v. Adventist Health System/West (Cal. Ct. App., July 24, 2026, No. B344951), certified for publication on August 24, 2026, the California Court of Appeal considered claims involving the California Invasion of Privacy Act (“CIPA”), the California Confidentiality of Medical Information Act (“CMIA”), Meta Pixel, and Google Analytics.
The court reversed the denial of class certification for the HRA-form subclass and for the surviving claims of the patient-portal subclass, including the CIPA section 631 claim. It affirmed the denial of certification for the patient-portal CMIA claims and the finding that the plaintiffs forfeited certification of their CIPA section 632 claim. The matter was remanded for further proceedings. The court did not determine that Adventist violated CIPA or CMIA; it addressed whether specified issues could be resolved through evidence common to the proposed class members.
What Were the Allegations Against Adventist Health?
The plaintiffs were current or former patients of Adventist Health System/West. They alleged that Adventist installed Meta Pixel and Google Analytics on several websites, including its public-facing website, an online health-risk-assessment website, and a password-protected patient portal.
According to the plaintiffs, these technologies tracked website activity and transmitted information to Meta and Google without adequate knowledge or consent. The allegedly transmitted data included identifiers, internet protocol addresses, URLs, page titles, browser information, search terms, form-submission events, and other information concerning users’ interactions with Adventist’s websites.
The patient portal allowed users to access test results, exchange messages with healthcare providers, review treatment information, schedule appointments, and perform other account-related activities. Adventist installed Google Analytics—but not Meta Pixel—inside the patient portal.
Adventist also offered online health risk assessments (“HRAs”) designed to evaluate a person’s potential risk for particular medical conditions. The plaintiffs alleged that both Meta Pixel and Google Analytics were used in connection with the HRA website and that URLs associated with completed assessments could lead to reports containing assessment results.
The lawsuit asserted several causes of action, including claims under CIPA Penal Code sections 631 and 632, CMIA, California’s Unfair Competition Law, and the California Constitution’s privacy provision.
How Do Tracking Pixels Collect Website Information?
The Court of Appeal provided a detailed explanation of tracking-pixel technology. When a person visits a website, the browser sends requests containing information needed to retrieve and display the requested page. Those requests may include an IP address, URL, browser or device information, and cookies that identify an account or device.
A tracking pixel is code that allows a third party to receive information about a person’s activities on a website. Depending on its configuration, a pixel may record page views, clicks, search terms, form submissions, downloads, or other events. Cookies and similar identifiers may also allow the third party to associate website activity with a particular device or account.
Not every URL necessarily reveals the contents of a communication. A URL containing only basic addressing or routing information may be treated differently from a URL containing a search term, medical condition, form response, or other information entered or selected by the user. The plaintiffs’ experts contended that Adventist’s tracking code operated consistently across users and transmitted baseline information that included identifiers, page-view information, URLs, IP addresses, and browser data. Adventist disputed whether the evidence established that actionable information was uniformly transmitted.
Why Did the Trial Court Deny Class Certification?
The plaintiffs sought certification of several proposed classes and subclasses. Two were central to the appeal:
- A patient-portal subclass consisting of qualifying California patients who logged into the portal during the relevant period; and
- An HRA-form subclass consisting of qualifying patients who submitted an online health risk assessment.
The trial court denied certification. It concluded, among other things, that the patient-portal subclass was not sufficiently ascertainable and that individual questions would predominate because the transmitted URLs and information could vary among users.
The trial court also found that the plaintiffs had not adequately demonstrated that a class action would be superior or manageable. In addition, it concluded that the plaintiffs had abandoned their class-certification request concerning the CIPA section 632 recording claim because their motion and reply did not substantively address that provision.
What Did the Court of Appeal Decide?
The Patient-Portal Subclass Was Ascertainable
The appellate court concluded that records maintained by Adventist or its service provider could identify patients who logged into the portal. Whether those patients ultimately could prove that actionable information was transmitted involved the merits of their claims—not whether the proposed subclass could be identified.
This distinction is important. At class certification, a court determines whether the proposed class satisfies procedural requirements. It ordinarily does not decide whether the plaintiffs will ultimately prove liability.
The CIPA Claim Could Be Evaluated Through Common Evidence
CIPA Penal Code section 631 addresses specified forms of unauthorized interception, use, and disclosure of communications. The plaintiffs alleged that Adventist aided Meta and Google in intercepting or using the contents of their communications.
The appellate court explained that “contents” generally concerns the substance, purport, or meaning of a communication, rather than basic record or addressing information. Under the authorities discussed in the opinion, a URL containing only identification or address information may not constitute contents, while a URL containing a user’s search term or similar message may qualify.
For the HRA-form subclass, the plaintiffs presented a theory that common technical evidence could establish whether the website uniformly transmitted URLs linking to completed assessment reports. The Court of Appeal concluded that this issue was susceptible to common proof. It expressly declined to decide whether the plaintiffs’ evidence would ultimately establish that the transmissions occurred as alleged.
For the patient-portal subclass, the court concluded that the plaintiffs had presented a common theory concerning the baseline information transmitted when patients logged into the portal. The act of submitting login credentials could arguably communicate that the user was a verified patient seeking access to a private account. Thus, whether the transmitted login-related information constituted the contents of a communication could be evaluated through common evidence.
Again, the appellate court did not hold that the transmissions actually violated CIPA. It held that the trial court’s stated reasons did not support denying class certification of the section 631 claim.
The CMIA Analysis Differed Between the Subclasses
The CMIA outcome differed between the two subclasses. For the HRA-form subclass, the appellate court concluded that common evidence could address whether Meta and Google viewed or accessed HRA reports and whether the information was exposed to a significant risk of unauthorized access or use.
The plaintiffs argued that Meta’s and Google’s automated systems processed and assimilated all information made available to them. The appellate court held that whether such processing amounted to viewing or accessing the HRA report information was a common merits question under CMIA. It did not decide that automated processing satisfied CMIA.
The court also considered J.M. v. Illuminate Education, Inc. (2026) 19 Cal.5th 705, which the California Supreme Court decided after the appeal had been submitted. J.M. rejected a categorical rule requiring proof that an unauthorized person actually viewed medical information. Instead, the primary CMIA inquiry is whether the information was exposed to a significant risk of unauthorized access or use. The Court of Appeal concluded that J.M. did not alter the disposition and stated that the parties could raise related issues on remand.
The court reached a different result for the patient-portal CMIA claims.
Some portal URLs allegedly contained descriptive terms relating to radiology, medical conditions, or treatment. Other URLs may have revealed only that a user downloaded an unspecified document, accessed a health record, scheduled an appointment, or sent a message.
Because those variations could affect whether the information qualified as “medical information” under CMIA, the appellate court affirmed the denial of certification for the patient-portal CMIA claim. It also explained that identifying someone merely as a patient does not necessarily constitute medical information under CMIA, even though patient status may receive protection under other legal frameworks, including HIPAA.
The result illustrates why businesses should not assume that HIPAA, CMIA, CIPA, and the California Consumer Privacy Act use identical definitions or impose interchangeable duties.
Class Treatment Was Superior and Manageable
The Court of Appeal concluded that the plaintiffs sufficiently demonstrated the superiority of class treatment because the technical and expert costs of litigating an individual tracking-pixel claim would exceed an individual claimant’s potential recovery. In the aggregate, however, the alleged statutory privacy claims could create substantial exposure.
The court found that the common issues identified for the HRA-form subclass and the patient-portal CIPA claim did not create the unmanageable individualized proceedings contemplated by the trial court.
The plaintiffs did not succeed on every issue. The appellate court agreed that they had forfeited class certification of their CIPA section 632 claim because their motion and reply did not adequately identify the claim, discuss its elements, or support it with legal authority. Attempting to raise the issue more fully in a later trial plan was insufficient.
What Did the Decision Not Establish?
The decision should be read carefully. It did not hold that:
- Every tracking pixel violates CIPA;
- Meta Pixel or Google Analytics is inherently unlawful;
- Every URL constitutes the contents of a communication;
- Every transmission from a healthcare website contains medical information;
- Adventist lacked valid consent;
- Meta or Google unlawfully accessed patient information; or
- The plaintiffs will prevail at trial.
Instead, the court decided that specified liability questions could be evaluated using evidence common to members of the proposed subclasses. Adventist may still dispute the plaintiffs’ factual allegations, statutory interpretations, expert opinions, causation theories, consent arguments, and other issues on remand.
What Should Businesses Learn from This Case?
The decision has implications beyond hospitals. Any organization operating a website that collects health, financial, employment, identity-verification, insurance, or other sensitive information should evaluate its tracking technologies.
Businesses should consider the following measures:
- Map tracking tools by page and user state. Identify every pixel, analytics script, cookie, advertising tag, chatbot, and session-replay tool operating on public pages, authenticated pages, portals, and post-submission screens.
- Observe real data flows. Test network traffic during representative sessions and document the cookies, identifiers, URLs, query strings, page titles, event names, and other fields transmitted to each third party.
- Isolate sensitive workflows. Avoid deploying unnecessary advertising or analytics code on patient portals, account dashboards, assessment forms, payment pages, and other sensitive interfaces.
- Remove sensitive details from URLs and event labels. Medical conditions, report identifiers, search terms, form responses, and account information should not appear in URL paths, query parameters, page titles, or event names unless operationally necessary and appropriately protected.
- Confirm consent before transmission. When consent is relied upon, verify that the user receives appropriate notice and manifests legally sufficient consent before the relevant tracking technology activates.
- Restrict vendor access and secondary use. Determine whether each vendor acts solely as a service provider or may independently use transmitted information for advertising, profiling, model development, or other purposes, and align contractual restrictions with the system’s actual operation.
- Preserve configuration and consent history. Maintain historical website versions, consent records, vendor agreements, tag configurations, privacy notices, and technical logs showing what operated during each relevant period.
The law governing CIPA and website tracking remains unsettled. Nevertheless, Doe v. Adventist Health demonstrates that technical evidence concerning uniform website configurations, automated data processing, and common data flows may support class treatment even when the parties dispute whether the underlying transmissions were unlawful.
Our law firm provides legal counsel regarding internet law, data privacy, cybersecurity, website tracking, CIPA compliance, and technology-related disputes. Businesses that use pixels, analytics platforms, chat technologies, or other website-monitoring tools should consult qualified counsel regarding their specific systems and practices. This article is provided for informational purposes only and does not constitute legal advice.
Internet Lawyer Blog

