LRLossReserves.com
Back to The WireGeneral Liability

California Pixel Ruling Widens Hospital Privacy IBNR

California's citable Doe ruling shifts hospital pixel reserving from known response costs to a class-scale liability inventory. The immediate control is to model users, sessions, transmissions, and coverage aggregation separately before liability is decided.

On August 24, 2026, the California Court of Appeal certified Doe v. Adventist Health System/West for publication, making its class-certification analysis citable. The court revived certification bids for users who submitted Adventist’s online health risk assessment and partially revived one for patients who logged into a portal that allegedly sent data through Meta Pixel or Google Analytics. A September 3 California Supreme Court filing, No. S298399, puts further review on the watch list.

The court did not find that Adventist violated the California Invasion of Privacy Act (CIPA) or the Confidentiality of Medical Information Act (CMIA), and it awarded no damages. It sent certification issues back to the trial court. The distinction inside the ruling matters: class treatment can proceed on the health-risk-assessment theories and the patient-portal CIPA wiretapping theory, but the court affirmed denial of certification for the portal subclass’s CMIA theory.

Who it affects

The direct audience is California hospital systems, academic medical centers, public hospitals, and provider captives that deployed third-party analytics on risk assessments or authenticated portals. The issue also reaches systems outside California when California patients used their sites. Finance teams accustomed to hospital liability IBNR need to separate this exposure from medical malpractice because the potential claim count comes from digital activity, not encounters or occupied beds.

The reserve mechanism

The immediate lever is frequency. A first estimate may capture forensic work, notice expense, and several named plaintiffs while omitting the larger incurred but not reported (IBNR) population. Before selecting a count, inventory deployment dates, domains, logged-in and public pages, transmitted fields, consent versions, unique users, sessions, and vendor configurations. Run separate scenarios in which the reserve unit is a user, a session, or a transmission. The opinion did not choose among them.

Severity then multiplies that uncertainty. Penal Code section 637.2 authorizes the greater of $5,000 per CIPA violation or three times actual damages, without requiring actual damages as a prerequisite. That is a statutory-damage input, not a payable estimate here. Model it separately from defense and remediation costs, with low, central, and stress assumptions for both class size and violation count.

The tail should remain open after tracking code is removed. Certification, common-proof discovery, liability, appeals, and coverage allocation can each delay reliable case estimates. That process-driven lag resembles the defense-cost tail in other hospital liability litigation. It also supports the warning from actuary.info’s third-party cyber analysis against blending response costs with slower privacy claims.

What this means for your next review

Put three reconciliations on the agenda: users to sessions to transmissions; forensic costs to third-party liability; and gross exposure to each cyber, privacy, general liability, captive, and excess layer. Test whether “claim” and “occurrence” aggregate by event, user, or transmission, whether defense erodes the retention or limit, and whether any privacy exclusion leaves the loss fully net retained. That exclusion test belongs beside the broader 2026 casualty treaty review. Directionally, keep third-party privacy IBNR open through the remand. Removing the code ends new exposure, not the reporting tail.

Sources