The California Court of Appeal recently issued a ruling in the case Doe v. Adventist Health System/West (Docket B344951), which centers on allegations that the healthcare provider unlawfully shared patient information through tracking technologies. This decision affects current and former patients of Adventist Health System and raises important questions about privacy rights in the digital age.
The plaintiffs in this case, referred to as "Doe" and three other unnamed individuals, filed a class action lawsuit against Adventist Health System/West. They claim that the healthcare provider violated the California Invasion of Privacy Act (CIPA) and the California Confidentiality of Medical Information Act (CMIA) by sharing their personal information with third parties without consent. This information was allegedly collected through tracking technologies, specifically the Meta Pixel and Google Analytics, which were installed on Adventist's websites.
The dispute began when the plaintiffs alleged that Adventist Health System shared sensitive data, including personally identifiable information and protected health information (PHI), with companies like Facebook (Meta) and Google. The plaintiffs sought to certify a class of individuals who interacted with Adventist's websites between November 2017 and April 2024, particularly focusing on two subclasses: those who used the patient portal and those who submitted health risk assessment forms.
The case made its way through the legal system, eventually reaching the California Court of Appeal after the trial court denied the plaintiffs' motion for class certification. The trial court concluded that the plaintiffs failed to demonstrate that the subclasses were ascertainable and that common issues predominated over individual ones.
In its ruling, the California Court of Appeal affirmed in part and reversed in part the trial court's decision. The court ruled that the denial of class certification for the health risk assessment (HRA) subclass was incorrect and sent the case back to the lower court for further proceedings. However, the court upheld the trial court's decision regarding the patient portal subclass, stating that the plaintiffs did not adequately show how to ascertain which patients logged into the portal and engaged in activities that resulted in the transmission of actionable information.
The court stated, "Plaintiffs did not explain how to ascertain which patients logged into the patient portal and engaged in the types of activities that allegedly resulted in 'content' and 'medical information' being transmitted."
The ruling was delivered by an unspecified judge in the California Court of Appeal. The court's decision highlights the complexities involved in class action lawsuits, particularly those dealing with privacy issues in the digital realm. The court emphasized that while the plaintiffs provided sufficient evidence to support the HRA subclass, they did not meet the necessary criteria for the patient portal subclass.
This ruling has significant implications for patient privacy rights and the use of tracking technologies by healthcare providers. As digital health services become more prevalent, the case underscores the importance of ensuring that patient data is handled with care and that individuals are informed about how their information may be used.
The decision may set a precedent for future cases involving similar allegations against healthcare providers and other organizations that utilize tracking technologies. It raises questions about the extent to which companies must go to protect patient privacy and comply with existing laws.
Looking ahead, the plaintiffs may seek to appeal the court's ruling regarding the patient portal subclass. However, the court's decision on the HRA subclass allows that part of the case to proceed, potentially leading to further developments in the ongoing litigation. The case serves as a reminder of the evolving landscape of privacy rights and the legal responsibilities of organizations in the digital age.









