Full Opinion

Filed 7/24/26; Certified for Publication 8/24/26 (order attached) IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA SECOND APPELLATE DISTRICT DIVISION THREE JAMES DOE et al., B344951 Plaintiffs and Appellants, Los Angeles County Super. Ct. No. v. 22STCV36304 ADVENTIST HEALTH SYSTEM/ WEST, Defendant and Respondent. APPEAL from an order of the Superior Court of Los Angeles County, Laura A. Seigle, Judge. Affirmed in part, reversed in part, and remanded. Caddell & Chapman, Michael A. Caddell, Cynthia B. Chapman, Amy E. Tabor; Ahmad, Zavitsanos & Mensing, Foster C. Johnson, Kelsi White; LippSmith, Graham B. LippSmith, MaryBeth LippSmith and Jaclyn L. Anderson for Plaintiffs and Appellants. Seyfarth Shaw, Kristine Rinella Argentine and Sierra J. Chinn-Liu for Defendant and Respondent _________________________ Plaintiffs—four Does who are or were patients of defendant Adventist Health System/West (Adventist)—brought this putative class action asserting claims against Adventist for, among others, violations of the California Invasion of Privacy Act (CIPA) (Pen. Code, §§ 630 et seq.) 1 and the California Confidentiality of Medical Information Act (CMIA). Plaintiffs alleged Adventist shared (without their knowledge) their—and similarly situated patients’—personal information with third parties through web-based tracking technologies—the Meta Pixel and/or Google Analytics—installed on Adventist’s websites, including its public health risk assessment (HRA) website and its password-protected patient portal. The tools allegedly tracked site users’ activities, collected their data, and sent the information—including personally identifiable information, the contents of users’ communications with Adventist, and protected health information (PHI)—to Facebook (Meta) and Google, who shared the data with advertisers. Plaintiffs sought to certify a class consisting of Adventist patients with California addresses who—for the period from November 16, 2017 to April 30, 2024—“used the Adventist website or patient portal to exchange communications with Adventist . . . for researching medical conditions or treatments, finding a physician, making an appointment, or submitting a health risk assessment form” (general class), and four subclasses. Only two subclasses are relevant to this appeal: (1) the patient portal subclass, consisting of all class members “who were logged into Adventist[’s] . . . patient portal up until May 2023”; 1 Undesignated statutory references are to the Penal Code. 2 and (2) the HRA form subclass, consisting of all class members “who submitted an online [HRA] form to Adventist.” The trial court denied plaintiffs’ motion in its entirety. Plaintiffs appeal from the trial court’s denial of class certification of the patient portal and HRA form subclasses only. The trial court concluded, as relevant here, plaintiffs failed to establish: (1) the patient portal class was ascertainable, (2) common issues predominated over individual ones for both subclasses, and (3) the superiority and manageability of a class action. The court also found plaintiffs had “dropped any attempt to certify a class” for violations of CIPA under section 632. The court primarily reasoned that determining whether the data the tracking technologies sent to third parties contained the “contents” of users’ communications (CIPA) or users’ “medical information” (CMIA) would require an individual inquiry into the information transmitted for each user. The court also reasoned that plaintiffs had not explained how to ascertain which of the patients who had logged into the patient portal had engaged in activities that resulted in transmission of actionable information. Plaintiffs challenge the rulings, arguing the undisputed record evidence showed the patient portal class was ascertainable; the court misunderstood the record, misapplied the definition of “medical information,” ignored plaintiffs’ theory of liability, and prematurely determined the merits in finding common issues did not predominate; and they demonstrated the manageability of the two subclasses and superiority of a class action to individual trials. We reverse the court’s denial of class certification of the HRA form subclass and partially reverse as to the patient portal subclass. 3 BACKGROUND 1. Background on tracking technologies 2 A web browser communicates with a website’s servers to download and display the website’s content on the user’s screen. To do so, the web browser sends HTTP (hypertext transfer protocol) requests to download files from the website’s servers. 3 The HTTP request “contains an IP address, which [is] an identifier assigned to any Internet-connected device,” as well as “a URL, which represents the address of the file that a web browser is requesting from a web server,” and the “[u]ser [a]gent,” which “identifies the details of the operating system and web browser.” “A URL contains the server’s domain name, the path of the file located on the server that is being requested, and a list of query parameters that contain additional information being sent from a web browser to a web server.” “Cookies” are “used by web servers to keep track of past interactions with the web browser.” Cookies can store “identifiers” “used to identify a specific user account or a specific device/browser.” “Third-party cookies”—set by a third-party server—“allow cross-site tracking of a user across different websites.” On the other hand, “first-party cookies”—set by the first-party server—“allow same-site tracking of a user on a particular website.” 2 We glean most of this background from the report of plaintiffs’ expert Dr. Zubair Shafiq. Quoted material omits footnote references. 3 The first HTTP request sent “is typically for the Hypertext Markup Language (HTML) file.” The HTML file contains the source code or content of a webpage. 4 A “tracking pixel”—such as the Meta Pixel and Google Analytics—is a piece of code or image “that is used to track users’ browsing activity on the web.” “When a tracking pixel is installed on a website by a first party, it allows a third party (i.e., a domain that is different from the first-party website that a user navigates to) to track a user across different websites where the tracking pixel is installed. Put simply, a tracking pixel allows a third party to tell that a user visited website A at time A, website B at time B, and so on.” Tracking pixels “also ghostwrite first-party cookies on the visited website’s domain to circumvent third-party cookie blocking.” A tracking pixel collects “two types of data”—“identifiers” and “browsing activity”—“in HTTP requests from a user’s web browser to the tracking pixel’s web server.” “Identifiers” are collected through cookies stored by the web browser, and “the combination of IP address and user agent in the transmission from a user’s web browser to the pixel’s web server.” Identifiers stored in cookies can include “account identifiers”—“that uniquely identify the user visiting the website” akin to a driver’s license number—and “device identifiers”—“that uniquely identify the user’s device” akin to a vehicle’s license plate number. The combination of IP address and user agent (or other browser or device information) “contains sufficiently distinguishing information” that can be “used as a unique identifier,” known as “fingerprinting.” A website may “install tracking pixels from third-party companies such as Google and Meta to optimize ad campaigns that they run on Google . . . and Meta.” Thus, “a website may install and purposefully configure tracking pixels in its HTML source code to share information about specific actions a user 5 takes on their website with the tracking pixel’s server.” For example, these tracking technologies can track “events,” such as when a “button” is clicked, a form is submitted, or a page is viewed on a website. Google describes Google Analytics as “ ‘a platform that collects data from your websites and apps to create reports that provide insights into your business.’ ” “ ‘Every time a user visits a webpage, the tracking code will collect pseudonymous information about how that user interacted with the page.’ ” Google Analytics “uses both first-party and third-party cookies” —that store account and device identifiers—“to track users on and across different websites.” It also has a feature that “allows Google to link or associate the data with Google accounts of users who have signed into their Google accounts.” Meta describes Meta Pixel (formerly called Facebook Pixel) as “a piece of code on your website that can help you better understand the effectiveness of your advertising and the actions people take on your site, like visiting a page or adding an item to their cart. You’ll also be able to see when customers took an action after seeing your ad on Facebook and Instagram.” By default, the Meta Pixel “will track URLs visited, domains visited, and the devices [users] use.” The Meta Pixel also uses first- and third- party cookies that store account and device identifiers to track users across different websites. For example, the Meta Pixel— through cookies—stores a user’s device identifier and Facebook account identifier and “collects them on the facebook.com domain.” In Adventist’s words, these tracking technologies “cause different networks (i.e., the Adventist Health server and Google/ Meta servers) to communicate with each other, causing certain 6 categories of data to be transmitted to Google/Meta.” The “ ‘baseline data’ ” shared consists of first-party cookie identifiers, URLs, IP addresses—whether complete or partially masked— and user agent data. 2. Adventist’s use of tracking technologies Adventist is a nonprofit, faith-based healthcare system serving communities on the west coast and Hawaii. Between 2017 and 2024, Adventist installed the Meta Pixel and/or Google Analytics on its websites, including its public-facing website at adventisthealth.org, its patient portal at myadventisthealth.org, and its public HRA website at adventisthealthhra.org. Adventist placed advertisements on Facebook and other digital platforms, encouraging potential patients to click on a link where they could, for example, fill out an HRA form. The ad links also could lead users to Adventist’s website or an ad campaign landing page where they could, for example, request an appointment, attend a webinar, or, again, fill out an HRA form. Adventist used the tracking technologies in connection with its online marketing efforts “to understand how many users [we]re clicking on” a particular “ad and getting to [Adventist’s] site so that [Adventist could] optimize the best performing ads.” In other words, the tracking pixels enabled Adventist to determine if an ad campaign was resulting in “conversions”— users interacting with the website through pageviews, clicks, form submissions (including HRAs), downloads, etc. Adventist installed Google Analytics on its patient portal to gain “valuable insight,” rather than for marketing purposes, however. a. The patient portal The patient portal—hosted by Adventist’s business associate, Cerner—is a password-protected website where, among 7 other things, Adventist patients can access information from their electronic health record, including test results; exchange messages with healthcare providers; review treatment information; schedule appointments; and pay bills. Users can navigate directly to the patient portal login from their browser or access it from within the main Adventist website through the “Patient Login” button. Adventist installed only Google Analytics on the patient portal, not the Meta Pixel. Google Analytics normally shares information about “events” such as, “page views, scrolls, outbound clicks, site search, form interactions, video engagement, [and] file downloads.” Adventist was unaware of any modification made to the type of data Google Analytics collected and transmitted within the patient portal. 4 However, Cerner took security measures within the patient portal to “configure[ ] [Google Analytics] to anonymize the IP address[es]” it stored—by “truncat[ing] the last octet of the IP address”—and “to obfuscate [portions of] URLs that were provided when a user browses” the website. To obfuscate the URLs, Cerner used a pattern recognition software that scanned individual URLs and, if the URL “matched a pattern that included an identifier or reference to potential PHI,” that portion of the URL was removed or replaced with a generic term. For example, if a URL included a personal or document identification number, Cerner’s software replaced it with “PERSON_ID” or “DOCUMENT_ID.” Cerner also “ ‘removed the “query parameter” portion of a URL, 4 Discovery Shafiq reviewed showed Google Analytics was tracking information inside the patient portal about “Logins,” “Pageviews,” “Health Record – Results,” “Download/Transmit,” “Messages,” and others. 8 if present, which reflects searches or other information input by the user’ ” on the web page. 5 In May 2023, Cerner removed Google Analytics. b. HRA website Beginning in 2019 or 2020, Adventist partnered with HealthAware to provide HRAs “through the adventisthealth hra.org website to the public as a marketing tool to identify and reach people who may be at an increased risk for certain health conditions and who would benefit from a medical evaluation related” to the condition. HRAs could be accessed directly through the “main website,” through “a specific subpage of the main website,” or by clicking on an advertisement “on a third-party website such as Facebook or Google”; they generally were accessed through ads. When individuals filled out an HRA form and clicked the link to submit it, they were told if they were at “low risk,” “moderate risk,” or “high risk” for the health condition assessed. Records of the individuals who completed an HRA— including identifying information the user provided (e.g., name, date of birth, contact information), which HRA they took 5 The URL “query string” includes “search terms” input by the user. For example, in the URL “https://www.adventisthealth. org/site-search/?C=pregnancy” the query string (after the “?”) shows a search was done at the Adventist website for information about pregnancy. The following URL has a “path” but no query string: “https://www.adventisthealth.org/services/cancer- oncology.” The “path” is “services/cancer-oncology” indicating the user viewed information about cancer-oncology under “services.” (See In re Meta Pixel Healthcare Litigation (N.D.Cal. 2022) 647 F.Supp.3d 778, 795–796 and fn. 10 (Meta Pixel) [examples of a URL path and query string].) 9 and when, the risk level assigned, whether they wished to be contacted, and the lead source (how they came to the HRA website)—were stored in Adventist’s “Salesforce Customer Relationship Management” (CRM) system. The tracking pixels installed on the website shared with Google and Meta that an HRA form had been submitted. 3. Plaintiffs’ class action lawsuit Plaintiffs are current or former Adventist patients who interacted with Adventist’s websites, including the patient portal. Plaintiffs sued Adventist, as individuals and on behalf of a putative statewide class of Adventist patients or prospective patients who “exchanged communications” at one of Adventist’s websites between November 2017 and 2024.6 Plaintiffs alleged Adventist installed tracking technologies throughout its public websites and patient portal that acted as “listening and recording device[s]” permitting Meta 7 and Google to “eavesdrop[ ]” on their and purported class members’ communications with Adventist— their healthcare provider. Through these tracking technologies, Adventist allegedly disclosed plaintiffs’ personally identifiable information and PHI—without their consent—to Meta and Google. Plaintiffs alleged the tracking technologies transmitted Adventist website users’ IP addresses, URLs generated from users’ searches and logins, and users’ personal data input on the websites. The information shared with Meta and Google allegedly included, among other things, plaintiffs’ and proposed class members’ status as Adventist patients, their medical 6 Plaintiffs filed the operative third amended complaint (TAC) on June 25, 2024. 7 Meta owns Facebook. 10 providers, their actual or potential medical conditions and treatments, and their “personal identities.” Plaintiffs alleged Meta/Google used the information collected from Adventist’s websites to sell targeted advertising services. In return, Adventist received analytics about its websites to optimize its marketing efforts and ad placement, to enhance user experience, and to monitor how many users engaged with its websites. Plaintiffs alleged they visited Adventist’s public website and patient portal where they entered medical information, searched for a doctor, searched for information about a medical condition and/or its treatment, filled out an HRA, made appointments, and/or reviewed test results. Plaintiffs then received advertisements on their Facebook pages relating to their medical conditions. Plaintiffs asserted ten separate causes of action against Adventist, including, among others: one claim for violating CIPA by using a recording device—the tracking technologies—to record confidential communications without plaintiffs’ or class members’ consent and transmitting that information to others (§ 632, subd. (a)) (§ 632(a)), and by “aid[ing]” third parties in the interception of the “contents” of plaintiffs’ and class members’ communications with Adventist (§ 631, subd. (a)) (§ 631(a)); three separate claims for violating CMIA by failing to “maintain the confidentiality of users’ medical information” (Civ. Code, § 56.06), by negligently failing to “maintain, preserve, and store” plaintiffs’ and class members’ medical information “in a manner that preserve[d] the confidentiality” of that information (Civ. Code, § 56.101), and by disclosing plaintiffs’ and class members’ “sensitive medical information” without their consent (Civ. Code, § 56.10); two claims for violating the Unfair Competition Law 11 (Bus. & Prof. Code, § 17200 et seq.) (UCL) based on its violations of CIPA and CMIA; and a claim for invasion of privacy (Cal. Const., art. 1, § 1). 4. Class certification motion, opposition, and reply On June 25, 2024, plaintiffs also filed their motion for class certification. Both sides submitted reports from their experts, various declarations, deposition testimony, and other exhibits. 8 a. Motion Plaintiffs proposed the general class—for the period from November 16, 2017 to April 30, 2024—consist of “all Adventist Health patients with an address in California who used the Adventist website or patient portal to exchange communications with Adventist Health, including researching medical conditions or treatments, finding a physician, making an appointment, or submitting a health risk assessment form.” 9 (Italics added.) Plaintiffs also moved to certify four subclasses, including, a patient portal subclass consisting of “All Class members who were registered users of Adventist Health’s patient portal up until March 29, 2024” (italics added), and an HRA form subclass, 8 Plaintiffs’ expert Shafiq’s report summarized his testing and analysis as showing Adventist “uniformly shared patient identifiers (e.g., identifiers of accounts or devices used by patients) alongside content information (e.g., page title and URL) with third-party companies such as Google and Meta. Therefore, any patient who used Adventist Health’s website to search for a doctor, make an appointment, or access the patient portal had their identifying information together with sensitive health information shared with third-party companies.” 9 The proposed general class in the TAC included prospective patients and did not specify the type of communications. 12 consisting of “All Class members who submitted an online [HRA] form to Adventist Health.” (The two others were the online appointment and provider search subclasses.) There was no dispute over the numerosity of the proposed class and subclasses. Plaintiffs argued the two subclasses at issue on appeal were ascertainable based on records maintained by Adventist’s vendors Cerner and HealthAware. Adventist did not dispute this fact. Plaintiffs argued Adventist’s liability depended on common factual and legal questions that predominated over individual ones. For their CIPA claim, plaintiffs argued those included whether: Adventist’s tracking pixels acted similarly to a “bugging device” by “ ‘contemporaneously and invisibly re-direct[ing] the users’ communications to third parties’ ”; “the pixels’ workings constitute an interception of a message in transit in violation of CIPA”; class members had “ ‘a reasonable expectation of privacy’ ”; and the transmitted information “included the ‘contents’ of patients’ communications with Adventist.” For its CMIA claims, plaintiffs argued common issues included whether “Adventist’s deliberate decision to deploy the[ ] tracking pixels constituted a ‘disclosure’ of information” or “negligent storage or maintenance of information”; whether the disclosed information “included information ‘regarding a patient’s medical history . . . mental or physical condition, or treatment’ ” and was protected “ ‘medical information’ ” because it included “ ‘individually identifiable information . . . sufficient to allow identification of the individual’ ”; whether Adventist was authorized to disclose patients’ medical information; and whether an unauthorized party “ ‘viewed or accessed’ ” the disclosed information. 13 Plaintiffs argued the factual and legal issues relating to these questions were common to the patient portal subclass and HRA form subclass, as well. Plaintiffs asserted Adventist had admitted Google Analytics was enabled inside the patient portal, and its standard configuration had not been changed. Plaintiffs also asserted Shafiq’s investigation revealed that, after a patient submitted an HRA form, the tracking pixels sent Meta and Google a “full-string URL[ ]” including a “unique string of numbers” that would allow anyone to access the HRA report’s contents. Finally, plaintiffs argued that a class action was superior here to allow class members to obtain compensation—through statutory penalties, and to stop Adventist’s “illegal disclosures of their sensitive health information.” b. Opposition Adventist opposed the motion, primarily arguing several individual issues predominated. Among other issues, Adventist argued that, to prove their CIPA and CMIA claims, plaintiffs would have to present evidence of each individual URL the tracking pixels sent to Meta and/or Google to show whether that information constituted the “ ‘content’ ” of a communication or “medical information” and was individually identifiable. With respect to the patient portal subclass, Adventist argued individual URLs sent to Google also would have to be examined to see what had been obfuscated or masked. Adventist argued individual inquiry into proposed HRA form subclass members would be required to determine if individuals were patients at the time they submitted the form, whether they filled out the form for others, and whether they accessed the form through an ad on Google or Facebook, which would affect their reasonable 14 expectation of privacy. Defendants also presented evidence that the Meta Pixel and Google Analytics transmitted URLs from the HRA website differently: while Google “likely received” a URL that included the name of the HRA, the URL transmitted to Meta said only “hra.adventisthealth.org” or “quiz.adventisthealth.org.” c. Reply In their reply—filed after deposing Adventist’s expert Emily Cohen—plaintiffs argued Cohen’s confirmation that the tracking technologies “ ‘share[d] at least a baseline of information consisting of first-party cookie identifiers, page view information, including URL’s, IP addresses, whether complete or partially masked, and user agent data’ ” established the “key liability facts are subject to common proof.” Plaintiffs essentially contended this baseline data was evidence providing proof common to the class as to whether the information transmitted was individually identifiable, conveyed PHI or medical information, or constituted “contents.” Because the tracking technologies always conveyed at least the baseline data, plaintiffs argued, whether the tracking pixel transmitted additional protected information “over the ‘baseline’ ” “only increase[d] the degree of harm suffered by class members,” and was not relevant to Adventist’s underlying liability. Plaintiffs agreed to limit the patient portal subclass to “All Class members who logged into Adventist’s patient portal up until May 2023.” (Italics added.) Plaintiffs argued it was “immaterial what access point patients used” to log into the patient portal, “as any transmission to Google from the myadventisthealth.org domain [the patient portal], regardless of access point, indicate[d] that the individual signed into the patient portal.” Plaintiffs also argued that, although the URLs 15 sent from the patient portal were partially redacted, they still contained descriptive “natural language” terms outside of search parameters that revealed “key information about patients’ health condition or treatment.” Plaintiffs contended that, because the class included “only patients who exchanged health-care-related communications” with Adventist, the court could determine on a class-wide basis “whether the content” of the communications was “PHI/medical information.” Plaintiffs also disputed Adventist’s contentions that the court could not determine the specific issues affecting the HRA form subclass on a class-wide basis based on Adventist’s records and/or proposed class members’ self-reporting. d. Hearing and trial plan Before hearing oral argument on plaintiffs’ motion, the court issued a tentative ruling denying class certification. The court heard extensive argument on December 19, 2024. During the hearing—in response to the court’s concerns that the class included individuals who interfaced with the Adventist websites for non-health related reasons—plaintiffs’ counsel proposed to amend the class definition to include patients who used the Adventist websites to exchange communications “for” (rather than “including”) researching medical conditions or treatments, finding a physician, making an appointment, or submitting an HRA. The court permitted plaintiffs to file a trial plan and Adventist to file a response before taking the matter under submission. Plaintiffs’ trial plan confirmed their modifications of the general class and patient portal subclass. Plaintiffs also narrowed the class claims to those under CIPA, “Penal Code §§ 630 et seq.”; CMIA, “Civil Code §§ 56.101 & 56.10”; and UCL. 16 5. The court’s denial of class certification On February 14, 2025, the court issued an 18-page order denying plaintiffs’ motion for class certification in its entirety. As relevant to this appeal, the court found plaintiffs failed to establish the patient portal subclass was ascertainable because they didn’t explain “how to ascertain which patients logged into the patient portal and engaged in the types of activities that allegedly resulted in ‘content’ and ‘medical information’ being transmitted.” The court also found plaintiffs did not show how common issues predominated on either its CIPA or CMIA claims for either subclass. The court found that, although plaintiffs established “medical information may have been revealed by some of the URLs” transmitted from the patient portal, other URLs may not have revealed “either ‘content’ under CIPA or ‘medical information’ under CMIA.” The court also found “[p]laintiffs did not submit evidence that merely logging into the patient portal transmits information in violation of CIPA or CMIA, or that each activity that a logged-in patient can do within the patient portal transmits information in violation of CIPA or CMIA.” As for the HRA form subclass, the court found a person-by-person inquiry would be required to determine whether Google and Meta “actually followed the links” they were sent to the completed HRA forms, such as by showing class members received ads for health issues they disclosed in HRA forms. Finally, the court found plaintiffs failed to show the superiority of a class action as they cited no evidence to support their assertion that “few class members have the time and resources to pursue their claims on an individual basis,” and did not address the manageability of the individual questions 17 the court had identified. Plaintiffs filed a timely notice of appeal. 10 DISCUSSION 1. Class certification and standard of review Section 382 of the Code of Civil Procedure authorizes a lawsuit to proceed as a class action “when the question is one of a common or general interest, of many persons, or when the parties are numerous, and it is impracticable to bring them all before the court.” “The party advocating class treatment must demonstrate the existence of an ascertainable and sufficiently numerous class, a well-defined community of interest, and substantial benefits from certification that render proceeding as a class superior to the alternatives. [Citations.] ‘In turn, the “community of interest requirement embodies three factors: (1) predominant common questions of law or fact; (2) class representatives with claims or defenses typical of the class; and (3) class representatives who can adequately represent the class.” ’ ” (Brinker Restaurant Corp. v. Superior Court (2012) 53 Cal.4th 1004, 1021 (Brinker).) The certification question is “ ‘ “essentially a procedural one that does not ask whether an action is legally or factually meritorious,” ’ ” and thus, “resolution of disputes over the merits of a case generally must be postponed until after class certification has been decided [citation], with the court assuming for purposes of the certification motion that any claims have merit.” (Brinker, supra, 53 Cal.4th at p. 1023.) Our Supreme 10 An order denying class certification is appealable under the “ ‘death knell’ ” doctrine. (See Meinhardt v. City of Sunnyvale (2024) 16 Cal.5th 643, 656, fn. 8.) 18 Court has recognized that, when “evidence or legal issues germane to the certification question bear as well on aspects of the merits, a court may properly evaluate them.” (Id. at pp. 1023–1024.) However, “[s]uch inquiries are closely circumscribed.” (Id. at p. 1024.) “[A]ny ‘peek’ a court takes into the merits at the certification stage must ‘be limited to those aspects of the merits that affect the decisions essential’ to class certification.” (Ibid.) “ ‘The decision to certify a class rests squarely within the discretion of the trial court, and we afford that decision great deference on appeal, reversing only for a manifest abuse of discretion: “Because trial courts are ideally situated to evaluate the efficiencies and practicalities of permitting group action, they are afforded great discretion in granting or denying certification.” [Citation.] A certification order generally will not be disturbed unless (1) it is unsupported by substantial evidence, (2) it rests on improper criteria, or (3) it rests on erroneous legal assumptions.’ ” (Brinker, supra, 53 Cal.4th at p. 1022.) Therefore, “ ‘[u]nlike the general rule compelling a reviewing court to scrutinize the result below, not the trial court’s rationale, we analyze the propriety of an order denying class certification based solely on the lower court’s stated reason for the decision.’ [Citation.]” (Leeds v. City of Los Angeles (2025) 115 Cal.App.5th 537, 545–546 (Leeds).) “ ‘Under this standard, an order based upon improper criteria or incorrect assumptions calls for reversal “ ‘even though there may be substantial evidence to support the court’s order.’ ” ’ ” (Noel v. Thrifty Payless, Inc. (2019) 7 Cal.5th 955, 968 (Noel); see also Ayala v. Antelope Valley Newspapers, Inc. (2014) 59 Cal.4th 522, 537 [“[a] certification decision is reviewed for abuse of discretion, but when the supporting reasoning 19 reveals the court based its decision on erroneous legal assumptions about the relevant questions, that decision cannot stand”]; Cochran v. Schwan’s Home Service, Inc. (2014) 228 Cal.App.4th 1137, 1143, quoting Knapp v. AT&T Wireless Services, Inc. (2011) 195 Cal.App.4th 932, 939 (Knapp) [“ ‘A trial court’s decision that rests on an error of law is an abuse of discretion.’ ”].) 2. Ascertainability of the patient portal subclass 11 A class is ascertainable “when it is defined ‘in terms of objective characteristics and common transactional facts’ that make ‘the ultimate identification of class members possible when that identification becomes necessary.’ ” (Noel, supra, 7 Cal.5th at p. 980.) “[T]his standard . . . include[es] class definitions that are ‘sufficient to allow a member of [the class] to identify himself or herself as having a right to recover based on the [class] description.’ ” (Ibid.) Plaintiffs defined the patient portal subclass as “All Class members who were logged into Adventist Health’s patient portal up until May 2023.” Plaintiffs ultimately defined the general class—i.e., all class members—as, “For the period November 16, 2017 to April 30, 2024, all Adventist Health patients with an address in California who used the Adventist website or patient portal to exchange communications with Adventist Health for [1] researching medical conditions or treatments, [2] finding a physician, [3] making an appointment, or [4] submitting a health risk assessment form.” The initial class definition, however, encompassed patients “who used the Adventist website or 11 The court found the HRA form subclass members were ascertainable based on Adventist’s and/or its vendor’s records. 20 patient portal to exchange communications with Adventist Health, including” the four above activities. (Italics added.) Plaintiffs’ counsel suggested the revised definition during the hearing on plaintiffs’ motion and—in plaintiffs’ trial plan— proposed the court certify the general class as revised. Accordingly, as Adventist asserts, the patient portal subclass definition incorporated the revised definition of the general class. Substituting “[a]ll Class members” with plaintiffs’ definition of the general class, the patient portal subclass definition is: All Adventist patients with an address in California who logged into the patient portal up until May 2023 to exchange communications with Adventist for researching medical conditions or treatments, finding a physician, making an appointment, or submitting a health risk assessment form. The court found plaintiffs did not establish the members of the general class were ascertainable. The court noted plaintiffs “propose[d] that [Adventist] generate a list of all California patients and then ‘patients could identify themselves as having used the website or patient portal to research medical conditions or treatments, find a physician, make an appointment, or submit a health risk assessment form.’ ” Plaintiffs argued patients would “be able to figure out from the class definition whether they are part of the class and they can ‘self-report.’ ” The court found “[i]t [wa]s not so simple,” in part because the class definition “d[id] not clearly tell putative class member[s] how to self-report.” The court then concluded the patient portal subclass had “a similar problem.” Plaintiffs had argued patient portal subclass members were ascertainable because Adventist had “information of all registered patient portal users in its records.” The court found “being a registered user of the patient 21 portal does not mean a patient engaged in activity on the patient portal that resulted in information, let alon[e] ‘content’ and ‘medical information,’ being transmitted to third parties.” The court continued, “Plaintiffs do not explain how to ascertain which patients logged into the patient portal and engaged in the types of activities that allegedly resulted in ‘content’ and ‘medical information’ being transmitted, as discussed below,” referring to its predominance analysis. Plaintiffs argue the record shows the patient portal subclass is ascertainable through Adventist’s or its provider Cerner’s records. As plaintiffs note, the evidence shows Adventist could create a report of the patient identification numbers (ID) that created a portal account and the number of times the patient ID “accessed the portal.” Accordingly, plaintiffs demonstrated patients who logged into the patient portal during the subclass period were readily identifiable. However, as the court implied 12 and Adventist argues, plaintiffs did not demonstrate how to identify patients who logged into the patient portal and engaged in one of the four enumerated activities. A patient’s options within the patient portal were not limited to researching medical conditions or treatments, finding a physician, making an appointment, and submitting an HRA. Within the patient portal, patients also could view lab, radiology, and other results; view their 12 As we noted, the court found the general class definition did “not clearly tell putative class member[s] how to self-report.” We can infer the court found the patient portal—which had a “similar problem”—also did not clearly tell members how to self- report, in part, because it necessarily subsumed the definition of the class. 22 health record; download a document; send or receive messages; pay a bill; and other activities. Plaintiffs argue Adventist never disputed the patient portal subclass was ascertainable. In opposing plaintiffs’ motion— before plaintiffs modified the class definition—Adventist did not dispute that it could identify patients who had logged into the patient portal. But in response to plaintiffs’ trial plan, Adventist argued the “revised general class definition creates serious impediments to certification of their Patient Portal Subclass. Specifically, a patient who merely logs in to the patient portal and does nothing else is not a class member.” (Boldface omitted.) Adventist specifically noted plaintiffs’ revised class definition included “only those Adventist Health patients who used the Adventist Health websites (and the patient portal) for only four specific th