Doe v. Adventist Health System/West
CourtCalifornia Court of Appeal
Date FiledAugust 24, 2026
DocketB344951
StatusPublished
📰 News Coverage: Read the LAWS.com news report on this case
Full Opinion
Filed 7/24/26; Certified for Publication 8/24/26 (order attached)
IN THE COURT OF APPEAL OF THE STATE OF CALIFORNIA
SECOND APPELLATE DISTRICT
DIVISION THREE
JAMES DOE et al., B344951
Plaintiffs and Appellants, Los Angeles County
Super. Ct. No.
v. 22STCV36304
ADVENTIST HEALTH SYSTEM/
WEST,
Defendant and Respondent.
APPEAL from an order of the Superior Court of
Los Angeles County, Laura A. Seigle, Judge. Affirmed in part,
reversed in part, and remanded.
Caddell & Chapman, Michael A. Caddell, Cynthia B.
Chapman, Amy E. Tabor; Ahmad, Zavitsanos & Mensing, Foster
C. Johnson, Kelsi White; LippSmith, Graham B. LippSmith,
MaryBeth LippSmith and Jaclyn L. Anderson for Plaintiffs
and Appellants.
Seyfarth Shaw, Kristine Rinella Argentine and Sierra J.
Chinn-Liu for Defendant and Respondent
_________________________
Plaintiffs—four Does who are or were patients of defendant
Adventist Health System/West (Adventist)—brought this
putative class action asserting claims against Adventist for,
among others, violations of the California Invasion of Privacy
Act (CIPA) (Pen. Code, §§ 630 et seq.) 1 and the California
Confidentiality of Medical Information Act (CMIA). Plaintiffs
alleged Adventist shared (without their knowledge) their—and
similarly situated patients’—personal information with third
parties through web-based tracking technologies—the Meta Pixel
and/or Google Analytics—installed on Adventist’s websites,
including its public health risk assessment (HRA) website
and its password-protected patient portal. The tools allegedly
tracked site users’ activities, collected their data, and sent
the information—including personally identifiable information,
the contents of users’ communications with Adventist, and
protected health information (PHI)—to Facebook (Meta)
and Google, who shared the data with advertisers.
Plaintiffs sought to certify a class consisting of Adventist
patients with California addresses who—for the period from
November 16, 2017 to April 30, 2024—“used the Adventist
website or patient portal to exchange communications with
Adventist . . . for researching medical conditions or treatments,
finding a physician, making an appointment, or submitting a
health risk assessment form” (general class), and four subclasses.
Only two subclasses are relevant to this appeal: (1) the patient
portal subclass, consisting of all class members “who were
logged into Adventist[’s] . . . patient portal up until May 2023”;
1 Undesignated statutory references are to the Penal Code.
2
and (2) the HRA form subclass, consisting of all class members
“who submitted an online [HRA] form to Adventist.”
The trial court denied plaintiffs’ motion in its entirety.
Plaintiffs appeal from the trial court’s denial of class certification
of the patient portal and HRA form subclasses only. The trial
court concluded, as relevant here, plaintiffs failed to establish:
(1) the patient portal class was ascertainable, (2) common issues
predominated over individual ones for both subclasses, and
(3) the superiority and manageability of a class action. The
court also found plaintiffs had “dropped any attempt to certify
a class” for violations of CIPA under section 632.
The court primarily reasoned that determining whether
the data the tracking technologies sent to third parties contained
the “contents” of users’ communications (CIPA) or users’ “medical
information” (CMIA) would require an individual inquiry into the
information transmitted for each user. The court also reasoned
that plaintiffs had not explained how to ascertain which of the
patients who had logged into the patient portal had engaged in
activities that resulted in transmission of actionable information.
Plaintiffs challenge the rulings, arguing the undisputed record
evidence showed the patient portal class was ascertainable;
the court misunderstood the record, misapplied the definition
of “medical information,” ignored plaintiffs’ theory of liability,
and prematurely determined the merits in finding common issues
did not predominate; and they demonstrated the manageability of
the two subclasses and superiority of a class action to individual
trials. We reverse the court’s denial of class certification of the
HRA form subclass and partially reverse as to the patient portal
subclass.
3
BACKGROUND
1. Background on tracking technologies 2
A web browser communicates with a website’s servers to
download and display the website’s content on the user’s screen.
To do so, the web browser sends HTTP (hypertext transfer
protocol) requests to download files from the website’s servers. 3
The HTTP request “contains an IP address, which [is] an
identifier assigned to any Internet-connected device,” as well
as “a URL, which represents the address of the file that a
web browser is requesting from a web server,” and the “[u]ser
[a]gent,” which “identifies the details of the operating system
and web browser.” “A URL contains the server’s domain name,
the path of the file located on the server that is being requested,
and a list of query parameters that contain additional
information being sent from a web browser to a web server.”
“Cookies” are “used by web servers to keep track of past
interactions with the web browser.” Cookies can store
“identifiers” “used to identify a specific user account or a specific
device/browser.” “Third-party cookies”—set by a third-party
server—“allow cross-site tracking of a user across different
websites.” On the other hand, “first-party cookies”—set by the
first-party server—“allow same-site tracking of a user on a
particular website.”
2 We glean most of this background from the report of
plaintiffs’ expert Dr. Zubair Shafiq. Quoted material omits
footnote references.
3 The first HTTP request sent “is typically for the Hypertext
Markup Language (HTML) file.” The HTML file contains the
source code or content of a webpage.
4
A “tracking pixel”—such as the Meta Pixel and Google
Analytics—is a piece of code or image “that is used to track
users’ browsing activity on the web.” “When a tracking pixel is
installed on a website by a first party, it allows a third party (i.e.,
a domain that is different from the first-party website that a user
navigates to) to track a user across different websites where the
tracking pixel is installed. Put simply, a tracking pixel allows
a third party to tell that a user visited website A at time A,
website B at time B, and so on.” Tracking pixels “also ghostwrite
first-party cookies on the visited website’s domain to circumvent
third-party cookie blocking.”
A tracking pixel collects “two types of data”—“identifiers”
and “browsing activity”—“in HTTP requests from a user’s web
browser to the tracking pixel’s web server.” “Identifiers” are
collected through cookies stored by the web browser, and “the
combination of IP address and user agent in the transmission
from a user’s web browser to the pixel’s web server.” Identifiers
stored in cookies can include “account identifiers”—“that
uniquely identify the user visiting the website” akin to a driver’s
license number—and “device identifiers”—“that uniquely identify
the user’s device” akin to a vehicle’s license plate number.
The combination of IP address and user agent (or other browser
or device information) “contains sufficiently distinguishing
information” that can be “used as a unique identifier,” known
as “fingerprinting.”
A website may “install tracking pixels from third-party
companies such as Google and Meta to optimize ad campaigns
that they run on Google . . . and Meta.” Thus, “a website may
install and purposefully configure tracking pixels in its HTML
source code to share information about specific actions a user
5
takes on their website with the tracking pixel’s server.” For
example, these tracking technologies can track “events,” such as
when a “button” is clicked, a form is submitted, or a page is
viewed on a website.
Google describes Google Analytics as “ ‘a platform that
collects data from your websites and apps to create reports
that provide insights into your business.’ ” “ ‘Every time a user
visits a webpage, the tracking code will collect pseudonymous
information about how that user interacted with the page.’ ”
Google Analytics “uses both first-party and third-party cookies”
—that store account and device identifiers—“to track users on
and across different websites.” It also has a feature that “allows
Google to link or associate the data with Google accounts of users
who have signed into their Google accounts.” Meta describes
Meta Pixel (formerly called Facebook Pixel) as “a piece of code
on your website that can help you better understand the
effectiveness of your advertising and the actions people take
on your site, like visiting a page or adding an item to their cart.
You’ll also be able to see when customers took an action after
seeing your ad on Facebook and Instagram.” By default, the
Meta Pixel “will track URLs visited, domains visited, and the
devices [users] use.” The Meta Pixel also uses first- and third-
party cookies that store account and device identifiers to track
users across different websites. For example, the Meta Pixel—
through cookies—stores a user’s device identifier and Facebook
account identifier and “collects them on the facebook.com
domain.”
In Adventist’s words, these tracking technologies “cause
different networks (i.e., the Adventist Health server and Google/
Meta servers) to communicate with each other, causing certain
6
categories of data to be transmitted to Google/Meta.” The
“ ‘baseline data’ ” shared consists of first-party cookie identifiers,
URLs, IP addresses—whether complete or partially masked—
and user agent data.
2. Adventist’s use of tracking technologies
Adventist is a nonprofit, faith-based healthcare system
serving communities on the west coast and Hawaii. Between
2017 and 2024, Adventist installed the Meta Pixel and/or Google
Analytics on its websites, including its public-facing website at
adventisthealth.org, its patient portal at myadventisthealth.org,
and its public HRA website at adventisthealthhra.org.
Adventist placed advertisements on Facebook and other
digital platforms, encouraging potential patients to click on a
link where they could, for example, fill out an HRA form. The
ad links also could lead users to Adventist’s website or an ad
campaign landing page where they could, for example, request
an appointment, attend a webinar, or, again, fill out an HRA
form. Adventist used the tracking technologies in connection
with its online marketing efforts “to understand how many users
[we]re clicking on” a particular “ad and getting to [Adventist’s]
site so that [Adventist could] optimize the best performing ads.”
In other words, the tracking pixels enabled Adventist to
determine if an ad campaign was resulting in “conversions”—
users interacting with the website through pageviews, clicks,
form submissions (including HRAs), downloads, etc. Adventist
installed Google Analytics on its patient portal to gain “valuable
insight,” rather than for marketing purposes, however.
a. The patient portal
The patient portal—hosted by Adventist’s business
associate, Cerner—is a password-protected website where, among
7
other things, Adventist patients can access information from
their electronic health record, including test results; exchange
messages with healthcare providers; review treatment
information; schedule appointments; and pay bills. Users can
navigate directly to the patient portal login from their browser
or access it from within the main Adventist website through the
“Patient Login” button. Adventist installed only Google Analytics
on the patient portal, not the Meta Pixel.
Google Analytics normally shares information about
“events” such as, “page views, scrolls, outbound clicks,
site search, form interactions, video engagement, [and] file
downloads.” Adventist was unaware of any modification made
to the type of data Google Analytics collected and transmitted
within the patient portal. 4 However, Cerner took security
measures within the patient portal to “configure[ ] [Google
Analytics] to anonymize the IP address[es]” it stored—by
“truncat[ing] the last octet of the IP address”—and “to obfuscate
[portions of] URLs that were provided when a user browses”
the website. To obfuscate the URLs, Cerner used a pattern
recognition software that scanned individual URLs and, if the
URL “matched a pattern that included an identifier or reference
to potential PHI,” that portion of the URL was removed or
replaced with a generic term. For example, if a URL included a
personal or document identification number, Cerner’s software
replaced it with “PERSON_ID” or “DOCUMENT_ID.” Cerner
also “ ‘removed the “query parameter” portion of a URL,
4 Discovery Shafiq reviewed showed Google Analytics was
tracking information inside the patient portal about “Logins,”
“Pageviews,” “Health Record – Results,” “Download/Transmit,”
“Messages,” and others.
8
if present, which reflects searches or other information input
by the user’ ” on the web page. 5
In May 2023, Cerner removed Google Analytics.
b. HRA website
Beginning in 2019 or 2020, Adventist partnered with
HealthAware to provide HRAs “through the adventisthealth
hra.org website to the public as a marketing tool to identify
and reach people who may be at an increased risk for certain
health conditions and who would benefit from a medical
evaluation related” to the condition. HRAs could be accessed
directly through the “main website,” through “a specific subpage
of the main website,” or by clicking on an advertisement “on a
third-party website such as Facebook or Google”; they generally
were accessed through ads. When individuals filled out an
HRA form and clicked the link to submit it, they were told if
they were at “low risk,” “moderate risk,” or “high risk” for the
health condition assessed.
Records of the individuals who completed an HRA—
including identifying information the user provided (e.g., name,
date of birth, contact information), which HRA they took
5 The URL “query string” includes “search terms” input by
the user. For example, in the URL “https://www.adventisthealth.
org/site-search/?C=pregnancy” the query string (after the “?”)
shows a search was done at the Adventist website for information
about pregnancy. The following URL has a “path” but no query
string: “https://www.adventisthealth.org/services/cancer-
oncology.” The “path” is “services/cancer-oncology” indicating the
user viewed information about cancer-oncology under “services.”
(See In re Meta Pixel Healthcare Litigation (N.D.Cal. 2022)
647 F.Supp.3d 778, 795–796 and fn. 10 (Meta Pixel) [examples
of a URL path and query string].)
9
and when, the risk level assigned, whether they wished to
be contacted, and the lead source (how they came to the HRA
website)—were stored in Adventist’s “Salesforce Customer
Relationship Management” (CRM) system. The tracking pixels
installed on the website shared with Google and Meta that an
HRA form had been submitted.
3. Plaintiffs’ class action lawsuit
Plaintiffs are current or former Adventist patients who
interacted with Adventist’s websites, including the patient portal.
Plaintiffs sued Adventist, as individuals and on behalf of a
putative statewide class of Adventist patients or prospective
patients who “exchanged communications” at one of Adventist’s
websites between November 2017 and 2024.6 Plaintiffs alleged
Adventist installed tracking technologies throughout its public
websites and patient portal that acted as “listening and recording
device[s]” permitting Meta 7 and Google to “eavesdrop[ ]” on their
and purported class members’ communications with Adventist—
their healthcare provider. Through these tracking technologies,
Adventist allegedly disclosed plaintiffs’ personally identifiable
information and PHI—without their consent—to Meta and
Google. Plaintiffs alleged the tracking technologies transmitted
Adventist website users’ IP addresses, URLs generated from
users’ searches and logins, and users’ personal data input on
the websites. The information shared with Meta and Google
allegedly included, among other things, plaintiffs’ and proposed
class members’ status as Adventist patients, their medical
6 Plaintiffs filed the operative third amended complaint
(TAC) on June 25, 2024.
7 Meta owns Facebook.
10
providers, their actual or potential medical conditions and
treatments, and their “personal identities.”
Plaintiffs alleged Meta/Google used the information
collected from Adventist’s websites to sell targeted advertising
services. In return, Adventist received analytics about its
websites to optimize its marketing efforts and ad placement,
to enhance user experience, and to monitor how many users
engaged with its websites. Plaintiffs alleged they visited
Adventist’s public website and patient portal where they
entered medical information, searched for a doctor, searched
for information about a medical condition and/or its treatment,
filled out an HRA, made appointments, and/or reviewed test
results. Plaintiffs then received advertisements on their
Facebook pages relating to their medical conditions.
Plaintiffs asserted ten separate causes of action against
Adventist, including, among others: one claim for violating CIPA
by using a recording device—the tracking technologies—to record
confidential communications without plaintiffs’ or class members’
consent and transmitting that information to others (§ 632,
subd. (a)) (§ 632(a)), and by “aid[ing]” third parties in the
interception of the “contents” of plaintiffs’ and class members’
communications with Adventist (§ 631, subd. (a)) (§ 631(a)); three
separate claims for violating CMIA by failing to “maintain the
confidentiality of users’ medical information” (Civ. Code, § 56.06),
by negligently failing to “maintain, preserve, and store” plaintiffs’
and class members’ medical information “in a manner that
preserve[d] the confidentiality” of that information (Civ. Code,
§ 56.101), and by disclosing plaintiffs’ and class members’
“sensitive medical information” without their consent (Civ. Code,
§ 56.10); two claims for violating the Unfair Competition Law
11
(Bus. & Prof. Code, § 17200 et seq.) (UCL) based on its violations
of CIPA and CMIA; and a claim for invasion of privacy (Cal.
Const., art. 1, § 1).
4. Class certification motion, opposition, and reply
On June 25, 2024, plaintiffs also filed their motion for class
certification. Both sides submitted reports from their experts,
various declarations, deposition testimony, and other exhibits. 8
a. Motion
Plaintiffs proposed the general class—for the period from
November 16, 2017 to April 30, 2024—consist of “all Adventist
Health patients with an address in California who used the
Adventist website or patient portal to exchange communications
with Adventist Health, including researching medical conditions
or treatments, finding a physician, making an appointment,
or submitting a health risk assessment form.” 9 (Italics added.)
Plaintiffs also moved to certify four subclasses, including,
a patient portal subclass consisting of “All Class members who
were registered users of Adventist Health’s patient portal up
until March 29, 2024” (italics added), and an HRA form subclass,
8 Plaintiffs’ expert Shafiq’s report summarized his testing
and analysis as showing Adventist “uniformly shared patient
identifiers (e.g., identifiers of accounts or devices used by
patients) alongside content information (e.g., page title and URL)
with third-party companies such as Google and Meta. Therefore,
any patient who used Adventist Health’s website to search for
a doctor, make an appointment, or access the patient portal had
their identifying information together with sensitive health
information shared with third-party companies.”
9 The proposed general class in the TAC included prospective
patients and did not specify the type of communications.
12
consisting of “All Class members who submitted an online [HRA]
form to Adventist Health.” (The two others were the online
appointment and provider search subclasses.)
There was no dispute over the numerosity of the proposed
class and subclasses. Plaintiffs argued the two subclasses at
issue on appeal were ascertainable based on records maintained
by Adventist’s vendors Cerner and HealthAware. Adventist
did not dispute this fact.
Plaintiffs argued Adventist’s liability depended on
common factual and legal questions that predominated over
individual ones. For their CIPA claim, plaintiffs argued those
included whether: Adventist’s tracking pixels acted similarly
to a “bugging device” by “ ‘contemporaneously and invisibly
re-direct[ing] the users’ communications to third parties’ ”;
“the pixels’ workings constitute an interception of a message
in transit in violation of CIPA”; class members had “ ‘a
reasonable expectation of privacy’ ”; and the transmitted
information “included the ‘contents’ of patients’ communications
with Adventist.” For its CMIA claims, plaintiffs argued common
issues included whether “Adventist’s deliberate decision to deploy
the[ ] tracking pixels constituted a ‘disclosure’ of information” or
“negligent storage or maintenance of information”; whether the
disclosed information “included information ‘regarding a patient’s
medical history . . . mental or physical condition, or treatment’ ”
and was protected “ ‘medical information’ ” because it included
“ ‘individually identifiable information . . . sufficient to allow
identification of the individual’ ”; whether Adventist was
authorized to disclose patients’ medical information; and whether
an unauthorized party “ ‘viewed or accessed’ ” the disclosed
information.
13
Plaintiffs argued the factual and legal issues relating to
these questions were common to the patient portal subclass and
HRA form subclass, as well. Plaintiffs asserted Adventist had
admitted Google Analytics was enabled inside the patient portal,
and its standard configuration had not been changed. Plaintiffs
also asserted Shafiq’s investigation revealed that, after a patient
submitted an HRA form, the tracking pixels sent Meta and
Google a “full-string URL[ ]” including a “unique string of
numbers” that would allow anyone to access the HRA report’s
contents.
Finally, plaintiffs argued that a class action was superior
here to allow class members to obtain compensation—through
statutory penalties, and to stop Adventist’s “illegal disclosures
of their sensitive health information.”
b. Opposition
Adventist opposed the motion, primarily arguing several
individual issues predominated. Among other issues, Adventist
argued that, to prove their CIPA and CMIA claims, plaintiffs
would have to present evidence of each individual URL the
tracking pixels sent to Meta and/or Google to show whether
that information constituted the “ ‘content’ ” of a communication
or “medical information” and was individually identifiable.
With respect to the patient portal subclass, Adventist argued
individual URLs sent to Google also would have to be examined
to see what had been obfuscated or masked. Adventist argued
individual inquiry into proposed HRA form subclass members
would be required to determine if individuals were patients
at the time they submitted the form, whether they filled out
the form for others, and whether they accessed the form through
an ad on Google or Facebook, which would affect their reasonable
14
expectation of privacy. Defendants also presented evidence that
the Meta Pixel and Google Analytics transmitted URLs from the
HRA website differently: while Google “likely received” a URL
that included the name of the HRA, the URL transmitted to Meta
said only “hra.adventisthealth.org” or “quiz.adventisthealth.org.”
c. Reply
In their reply—filed after deposing Adventist’s expert
Emily Cohen—plaintiffs argued Cohen’s confirmation that the
tracking technologies “ ‘share[d] at least a baseline of information
consisting of first-party cookie identifiers, page view information,
including URL’s, IP addresses, whether complete or partially
masked, and user agent data’ ” established the “key liability facts
are subject to common proof.” Plaintiffs essentially contended
this baseline data was evidence providing proof common to the
class as to whether the information transmitted was individually
identifiable, conveyed PHI or medical information, or constituted
“contents.” Because the tracking technologies always conveyed
at least the baseline data, plaintiffs argued, whether the tracking
pixel transmitted additional protected information “over the
‘baseline’ ” “only increase[d] the degree of harm suffered by
class members,” and was not relevant to Adventist’s underlying
liability.
Plaintiffs agreed to limit the patient portal subclass to
“All Class members who logged into Adventist’s patient portal
up until May 2023.” (Italics added.) Plaintiffs argued it
was “immaterial what access point patients used” to log into
the patient portal, “as any transmission to Google from the
myadventisthealth.org domain [the patient portal], regardless
of access point, indicate[d] that the individual signed into the
patient portal.” Plaintiffs also argued that, although the URLs
15
sent from the patient portal were partially redacted, they still
contained descriptive “natural language” terms outside of search
parameters that revealed “key information about patients’ health
condition or treatment.” Plaintiffs contended that, because the
class included “only patients who exchanged health-care-related
communications” with Adventist, the court could determine on
a class-wide basis “whether the content” of the communications
was “PHI/medical information.” Plaintiffs also disputed
Adventist’s contentions that the court could not determine the
specific issues affecting the HRA form subclass on a class-wide
basis based on Adventist’s records and/or proposed class
members’ self-reporting.
d. Hearing and trial plan
Before hearing oral argument on plaintiffs’ motion,
the court issued a tentative ruling denying class certification.
The court heard extensive argument on December 19, 2024.
During the hearing—in response to the court’s concerns that
the class included individuals who interfaced with the Adventist
websites for non-health related reasons—plaintiffs’ counsel
proposed to amend the class definition to include patients
who used the Adventist websites to exchange communications
“for” (rather than “including”) researching medical conditions
or treatments, finding a physician, making an appointment,
or submitting an HRA. The court permitted plaintiffs to file
a trial plan and Adventist to file a response before taking
the matter under submission.
Plaintiffs’ trial plan confirmed their modifications of
the general class and patient portal subclass. Plaintiffs also
narrowed the class claims to those under CIPA, “Penal Code
§§ 630 et seq.”; CMIA, “Civil Code §§ 56.101 & 56.10”; and UCL.
16
5. The court’s denial of class certification
On February 14, 2025, the court issued an 18-page order
denying plaintiffs’ motion for class certification in its entirety.
As relevant to this appeal, the court found plaintiffs failed to
establish the patient portal subclass was ascertainable because
they didn’t explain “how to ascertain which patients logged into
the patient portal and engaged in the types of activities that
allegedly resulted in ‘content’ and ‘medical information’ being
transmitted.” The court also found plaintiffs did not show how
common issues predominated on either its CIPA or CMIA claims
for either subclass. The court found that, although plaintiffs
established “medical information may have been revealed by
some of the URLs” transmitted from the patient portal, other
URLs may not have revealed “either ‘content’ under CIPA
or ‘medical information’ under CMIA.” The court also found
“[p]laintiffs did not submit evidence that merely logging into
the patient portal transmits information in violation of CIPA
or CMIA, or that each activity that a logged-in patient can do
within the patient portal transmits information in violation of
CIPA or CMIA.” As for the HRA form subclass, the court found
a person-by-person inquiry would be required to determine
whether Google and Meta “actually followed the links” they
were sent to the completed HRA forms, such as by showing
class members received ads for health issues they disclosed in
HRA forms. Finally, the court found plaintiffs failed to show the
superiority of a class action as they cited no evidence to support
their assertion that “few class members have the time and
resources to pursue their claims on an individual basis,” and
did not address the manageability of the individual questions
17
the court had identified. Plaintiffs filed a timely notice of
appeal. 10
DISCUSSION
1. Class certification and standard of review
Section 382 of the Code of Civil Procedure authorizes
a lawsuit to proceed as a class action “when the question is one
of a common or general interest, of many persons, or when the
parties are numerous, and it is impracticable to bring them all
before the court.” “The party advocating class treatment must
demonstrate the existence of an ascertainable and sufficiently
numerous class, a well-defined community of interest, and
substantial benefits from certification that render proceeding
as a class superior to the alternatives. [Citations.] ‘In turn,
the “community of interest requirement embodies three factors:
(1) predominant common questions of law or fact; (2) class
representatives with claims or defenses typical of the class;
and (3) class representatives who can adequately represent
the class.” ’ ” (Brinker Restaurant Corp. v. Superior Court (2012)
53 Cal.4th 1004, 1021 (Brinker).)
The certification question is “ ‘ “essentially a procedural
one that does not ask whether an action is legally or factually
meritorious,” ’ ” and thus, “resolution of disputes over the
merits of a case generally must be postponed until after class
certification has been decided [citation], with the court assuming
for purposes of the certification motion that any claims have
merit.” (Brinker, supra, 53 Cal.4th at p. 1023.) Our Supreme
10 An order denying class certification is appealable under
the “ ‘death knell’ ” doctrine. (See Meinhardt v. City of Sunnyvale
(2024) 16 Cal.5th 643, 656, fn. 8.)
18
Court has recognized that, when “evidence or legal issues
germane to the certification question bear as well on aspects
of the merits, a court may properly evaluate them.” (Id.
at pp. 1023–1024.) However, “[s]uch inquiries are closely
circumscribed.” (Id. at p. 1024.) “[A]ny ‘peek’ a court takes
into the merits at the certification stage must ‘be limited to
those aspects of the merits that affect the decisions essential’
to class certification.” (Ibid.)
“ ‘The decision to certify a class rests squarely within the
discretion of the trial court, and we afford that decision great
deference on appeal, reversing only for a manifest abuse of
discretion: “Because trial courts are ideally situated to evaluate
the efficiencies and practicalities of permitting group action, they
are afforded great discretion in granting or denying certification.”
[Citation.] A certification order generally will not be disturbed
unless (1) it is unsupported by substantial evidence, (2) it rests on
improper criteria, or (3) it rests on erroneous legal assumptions.’ ”
(Brinker, supra, 53 Cal.4th at p. 1022.) Therefore, “ ‘[u]nlike the
general rule compelling a reviewing court to scrutinize the result
below, not the trial court’s rationale, we analyze the propriety
of an order denying class certification based solely on the lower
court’s stated reason for the decision.’ [Citation.]” (Leeds v. City
of Los Angeles (2025) 115 Cal.App.5th 537, 545–546 (Leeds).)
“ ‘Under this standard, an order based upon improper
criteria or incorrect assumptions calls for reversal “ ‘even though
there may be substantial evidence to support the court’s
order.’ ” ’ ” (Noel v. Thrifty Payless, Inc. (2019) 7 Cal.5th 955,
968 (Noel); see also Ayala v. Antelope Valley Newspapers, Inc.
(2014) 59 Cal.4th 522, 537 [“[a] certification decision is reviewed
for abuse of discretion, but when the supporting reasoning
19
reveals the court based its decision on erroneous legal
assumptions about the relevant questions, that decision
cannot stand”]; Cochran v. Schwan’s Home Service, Inc.
(2014) 228 Cal.App.4th 1137, 1143, quoting Knapp v. AT&T
Wireless Services, Inc. (2011) 195 Cal.App.4th 932, 939 (Knapp)
[“ ‘A trial court’s decision that rests on an error of law is an
abuse of discretion.’ ”].)
2. Ascertainability of the patient portal subclass 11
A class is ascertainable “when it is defined ‘in terms of
objective characteristics and common transactional facts’ that
make ‘the ultimate identification of class members possible
when that identification becomes necessary.’ ” (Noel, supra,
7 Cal.5th at p. 980.) “[T]his standard . . . include[es] class
definitions that are ‘sufficient to allow a member of [the class]
to identify himself or herself as having a right to recover based
on the [class] description.’ ” (Ibid.)
Plaintiffs defined the patient portal subclass as “All Class
members who were logged into Adventist Health’s patient portal
up until May 2023.” Plaintiffs ultimately defined the general
class—i.e., all class members—as, “For the period November 16,
2017 to April 30, 2024, all Adventist Health patients with an
address in California who used the Adventist website or patient
portal to exchange communications with Adventist Health for
[1] researching medical conditions or treatments, [2] finding a
physician, [3] making an appointment, or [4] submitting a health
risk assessment form.” The initial class definition, however,
encompassed patients “who used the Adventist website or
11 The court found the HRA form subclass members were
ascertainable based on Adventist’s and/or its vendor’s records.
20
patient portal to exchange communications with Adventist
Health, including” the four above activities. (Italics added.)
Plaintiffs’ counsel suggested the revised definition during
the hearing on plaintiffs’ motion and—in plaintiffs’ trial plan—
proposed the court certify the general class as revised.
Accordingly, as Adventist asserts, the patient portal
subclass definition incorporated the revised definition of
the general class. Substituting “[a]ll Class members” with
plaintiffs’ definition of the general class, the patient portal
subclass definition is: All Adventist patients with an address
in California who logged into the patient portal up until May
2023 to exchange communications with Adventist for researching
medical conditions or treatments, finding a physician, making
an appointment, or submitting a health risk assessment form.
The court found plaintiffs did not establish the members
of the general class were ascertainable. The court noted
plaintiffs “propose[d] that [Adventist] generate a list of all
California patients and then ‘patients could identify themselves
as having used the website or patient portal to research medical
conditions or treatments, find a physician, make an appointment,
or submit a health risk assessment form.’ ” Plaintiffs argued
patients would “be able to figure out from the class definition
whether they are part of the class and they can ‘self-report.’ ”
The court found “[i]t [wa]s not so simple,” in part because the
class definition “d[id] not clearly tell putative class member[s]
how to self-report.” The court then concluded the patient portal
subclass had “a similar problem.” Plaintiffs had argued patient
portal subclass members were ascertainable because Adventist
had “information of all registered patient portal users in its
records.” The court found “being a registered user of the patient
21
portal does not mean a patient engaged in activity on the patient
portal that resulted in information, let alon[e] ‘content’ and
‘medical information,’ being transmitted to third parties.” The
court continued, “Plaintiffs do not explain how to ascertain which
patients logged into the patient portal and engaged in the types
of activities that allegedly resulted in ‘content’ and ‘medical
information’ being transmitted, as discussed below,” referring
to its predominance analysis.
Plaintiffs argue the record shows the patient portal
subclass is ascertainable through Adventist’s or its provider
Cerner’s records. As plaintiffs note, the evidence shows
Adventist could create a report of the patient identification
numbers (ID) that created a portal account and the number
of times the patient ID “accessed the portal.” Accordingly,
plaintiffs demonstrated patients who logged into the patient
portal during the subclass period were readily identifiable.
However, as the court implied 12 and Adventist argues,
plaintiffs did not demonstrate how to identify patients who
logged into the patient portal and engaged in one of the four
enumerated activities. A patient’s options within the patient
portal were not limited to researching medical conditions
or treatments, finding a physician, making an appointment,
and submitting an HRA. Within the patient portal, patients
also could view lab, radiology, and other results; view their
12 As we noted, the court found the general class definition
did “not clearly tell putative class member[s] how to self-report.”
We can infer the court found the patient portal—which had a
“similar problem”—also did not clearly tell members how to self-
report, in part, because it necessarily subsumed the definition
of the class.
22
health record; download a document; send or receive messages;
pay a bill; and other activities.
Plaintiffs argue Adventist never disputed the patient portal
subclass was ascertainable. In opposing plaintiffs’ motion—
before plaintiffs modified the class definition—Adventist did
not dispute that it could identify patients who had logged into
the patient portal. But in response to plaintiffs’ trial plan,
Adventist argued the “revised general class definition creates
serious impediments to certification of their Patient Portal
Subclass. Specifically, a patient who merely logs in to the patient
portal and does nothing else is not a class member.” (Boldface
omitted.) Adventist specifically noted plaintiffs’ revised class
definition included “only those Adventist Health patients who
used the Adventist Health websites (and the patient portal)
for only four specific th