Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


A Lawsuit Arising from a Data Breach is Dismissed for Failure to Allege a Concrete Injury

info@josefelgueroso.com

Versión en español

2021-07-01

A federal judge in Arizona has dismissed a lawsuit arising from a data breach because the plaintiffs failed to allege a concrete injury. The plaintiffs had received medical services from the defendant company and sued it based on several claims related to the data breach, including negligence and breach of contract.



Source: Chameleon Design

Facts

Unknown hackers used the email inbox of an employee of Assured Imaging to launch malware that infected the company's computer networks. As a result, patient data and other data were exfiltrated and data was encrypted with ransomware for several days.

The company's notice of data breach indicated that a malicious actor had exfiltrated an unknown amount of data. It added that the company reviewed the data potentially exfiltrated and notified the individuals who were potentially impacted. The potentially-accessed data included names, addresses, and details about the medical care the plaintiffs received.

The plaintiffs' allegations included emotional distress, anxiety, expenses related to credit monitoring, risk of identity theft, loss of value of private information, overpaying for inadequate data security, and facing the risk of becoming the targets of future attacks.

The Judge's Decision

The judge had to decide whether the plaintiffs had standing. Standing is the right of a party to bring a legal action.

Plaintiffs must prove that if the facts they allege in the complaint are true, they have standing. To have standing to bring a lawsuit in federal court, plaintiffs must prove the following:

  • the alleged injury is concrete, actual or imminent, and not hypothetical;
  • the injury is causally connected to the defendant's action; and
  • a favorable decision of the court is likely to redress the injury.

Cases related to standing in data breaches

The judge reviewed recent judgments related to injuries arising from data breaches. In a case involving a stolen laptop that contained the personal information of tens of thousands of Starbucks employees, a federal court of appeals found that the plaintiffs adequately alleged injury, because the stolen information included names, addresses, and Social Security Numbers. In a case involving a data breach at online retailer Zappos.com, the same court of appeals held that the plaintiffs had adequately alleged injury, because the email accounts of two of the plaintiffs had been taken over and used to send advertisements to people in their address books.

On the other hand, in a case involving a data breach at Uber in which hackers obtained names, email addresses, phone numbers, and driver's license numbers, the district court found that the plaintiffs had not sufficiently alleged injury. The court indicated that the fact that hackers had accessed basic information did not create a risk of fraud or identity theft. In another case involving a data breach at clothing retailer Brooks Brothers, the district court held that the plaintiffs had failed to allege injury because the hackers had not accessed addresses or Social Security numbers.

Regarding other claims of injury by the plaintiffs, the judge noted that no court has found that the loss of value of personal information or overpaying for data security are sufficient injuries to grant standing.

The Plaintiffs' allegations

Assured Imaging's data breach notice indicated that unknown hackers had potentially accessed personal information, but the company did not know whether the hackers had used that information. The potentially-accessed data included full names, addresses, dates of birth, patient identification numbers, facilities, treating clinicians, medical histories, services performed, and assessments of the services performed, including any recommendations on future testing.

The judge observed that the plaintiffs had not alleged that hackers had used their personal information to take over their email accounts or identities. Similarly, the judge viewed the information potentially accessed as insufficient to create an impending risk of identity theft or fraud.

As a result, the judge held that the plaintiffs had not alleged injuries that would grant them standing, and dismissed the lawsuit. The judge granted the plaintiffs the opportunity to amend their complaint, but indicated that further passage of time without harm would undermine their claims of injury.

Sources

Angela T Travis, et al., v. Assured Imaging LLC (United States District Court for the District of Arizona, 2021)