Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled Mar. 31, 2025

Malinowski v. International Business Machines Corporation

Judge
Nelson Roman
Docket
7:23-cv-08421
Court
U.S. District Court · Southern District of New York
Pages
13
Civil ProcedureMotion to Dismiss
In one sentence

In Malinowski v. International Business Machines Corporation, Judge Román dismissed all claims without prejudice because the complaint did not adequately show standing.

Who this affects

The named plaintiffs and proposed class members may amend their claims, while the defendants received dismissal of the claims without prejudice.

What happened

In Malinowski v. International Business Machines Corporation, patients sued International Business Machines Corporation and Johnson & Johnson Health Care Systems, Inc. after an unauthorized third party accessed information from the Janssen CarePath program. They alleged injuries including fraudulent accounts and charges, publication of personal information, and increased spam.

The court granted the defendants’ motion to dismiss under Rule 12(b)(6). It ruled that the plaintiffs had not adequately alleged that their injuries were traceable to the data breach, so they lacked the required constitutional standing. The court dismissed all eight claims without prejudice.

Judge Nelson S. Román allowed the plaintiffs to file an amended complaint by May 15, 2025. The order states that the claims would be deemed dismissed with prejudice if the plaintiffs did not amend within the allowed period.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Malinowski v. International Business Machines Corporation · No. 7:23-cv-08421
Judge
Nelson Roman
Date
Mar. 31, 2025

Background

The plaintiffs brought a consolidated class action complaint against International Business Machines Corporation and Johnson & Johnson Health Care Systems, Inc. The complaint alleged that Johnson & Johnson Health Care Systems owned and operated Janssen CarePath, a patient-support program, while IBM managed the platform as a service provider. According to the complaint, IBM discovered on August 2, 2023, that an unauthorized third party had accessed information belonging to the plaintiffs and approximately 631,000 other patients.

The allegedly accessed information included names, contact information, dates of birth, health-insurance information, and information about medications and medical conditions. The plaintiffs alleged that, after the breach, they experienced unauthorized store and credit-card accounts, fraudulent charges, publication of personal information on the dark web, emails referring to their health insurers and medical conditions, and increased spam messages and calls.

The complaint asserted negligence, negligence per se, breach of implied contract, breach of fiduciary duty, breach of a third-party-beneficiary contract, unjust enrichment, violations of the Florida Unfair and Deceptive Trade Practices Act, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act.

Motion and Legal Standard

The defendants moved to dismiss the consolidated complaint under Federal Rule of Civil Procedure 12(b)(6), which allows dismissal when a complaint does not allege enough facts to make a claim legally plausible. The court also analyzed Article III standing, a constitutional requirement that a plaintiff show an actual or imminent injury, a connection between that injury and the defendant’s conduct, and a likelihood that a court decision could remedy the injury.

Court’s Analysis

The court limited its discussion to standing. It held that the complaint did not adequately allege traceability—the required causal connection between the plaintiffs’ injuries and the defendants’ conduct. The plaintiffs alleged that various adverse events occurred after the data breach and attributed those events to the defendants, but the court found that timing and attribution alone showed only correlation, not a plausible causal connection.

The court also noted that the plaintiffs did not allege sufficient facts showing that the information needed to open the unauthorized accounts was contained in the CarePath database and was among the information exposed in the breach. The court concluded that the complaint, as currently written, did not establish Article III standing.

Disposition

The court granted the defendants’ motion to dismiss all eight claims without prejudice. The plaintiffs were granted leave to file an amended complaint by May 15, 2025. The order stated that, if they did not file an amended complaint within that period, the claims dismissed without prejudice would be deemed dismissed with prejudice. The clerk was directed to terminate the motion at ECF No. 50.

The authoritative version

Read the full 13-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.