Davidson v. Hewlett-Packard Company
- Edward Davila
- 5:16-cv-01928
- U.S. District Court · Northern District of California
- 16
In Davidson v. Hewlett-Packard, Judge Davila granted defendants’ summary-judgment motion, dismissing the privacy claim with prejudice.
Jonathan Marc Davidson and Corinna Davidson’s remaining invasion-of-privacy claims were dismissed with prejudice; the defendants prevailed on the motion for summary judgment.
What happened
In Davidson v. Hewlett-Packard Company, Jonathan Marc Davidson and Corinna Davidson, representing themselves, sued Hewlett-Packard-related companies, health-care companies, and doctors. They sought damages connected to the decision to end Jonathan Davidson’s care at a rehabilitation facility and move him to custodial care at home. The remaining claim concerned alleged invasions of privacy involving Jonathan’s medical information and alleged computer intrusions.
The court found that the plan documents allowed the defendants to share medical information to administer benefits and handle claims and appeals. The plaintiffs also publicly shared information about Jonathan’s condition through a blog and with media members. The court found no evidence that the defendants hacked or accessed the plaintiffs’ electronic devices; the plaintiffs’ allegations were speculative, and their own computer analyst found no evidence linking the defendants to the alleged intrusions.
Judge Davila granted the defendants’ motion for summary judgment. He dismissed with prejudice the invasion-of-privacy claims under the California Constitution and California common law and ordered the file closed, with judgment for the defendants.
The detailed version
- Davidson v. Hewlett-Packard Company · No. 5:16-cv-01928
- Edward Davila
- Sept. 16, 2021
Background
Jonathan Marc Davidson and Corinna Davidson, who represented themselves, sued Hewlett-Packard Company, Hewlett Packard Enterprise Company, United Healthcare Services, Inc., UnitedHealth Group Incorporated, and four doctors. They sought damages related to defendants’ decision to end Jonathan Davidson’s medical care at a skilled-care nursing facility and transfer him to custodial care at home. Jonathan Davidson had amyotrophic lateral sclerosis and required continuous medical care.
The defendants’ motion concerned the plaintiffs’ remaining invasion-of-privacy claim. The court had previously dismissed with prejudice all other claims in the Third Amended Complaint. The remaining claim asserted violations of Article I, Section 1 of the California Constitution and California common law. The plaintiffs also referenced the federal Health Insurance Portability and Accountability Act, but the court noted that statute does not provide a private right to sue.
The privacy claim involved two categories of alleged conduct: sharing and using Jonathan Davidson’s medical information, and intrusions into the plaintiffs’ computers or other electronic devices. The plaintiffs alleged that medical information was shared with personnel and representatives of Hewlett-Packard, United Healthcare, Optum, health-care providers, and others. They also alleged computer intrusions based on events such as flashing screens and pop-up boxes.
Summary-Judgment Standard
Summary judgment is required when the evidence shows there is no genuine dispute about a fact that could affect the result and the moving party is entitled to judgment under the law. Once the moving party meets its initial burden, the opposing party must present admissible evidence creating a genuine factual dispute. The court must draw reasonable inferences for the nonmoving party, but speculation and conclusory statements are not enough. Although courts interpret self-represented parties’ pleadings liberally, those parties must still comply with summary-judgment rules.
California Constitutional Privacy Claim
A California constitutional privacy claim requires a legally protected privacy interest, a reasonable expectation of privacy in the circumstances, and conduct that seriously invaded the protected interest.
The court found that Jonathan Davidson had a legally protected privacy interest in his medical information because medical information is confidential. It found, however, that Corinna Davidson could not assert a constitutional privacy claim based on Jonathan’s medical information merely because he had given her power of attorney. A power of attorney did not give her standing—the legal ability to assert another person’s constitutional claim.
The court then held that the plaintiffs lacked a reasonable expectation of privacy in the medical information at issue. The health-plan documents and privacy notice stated that Hewlett-Packard and United Healthcare could use and share identifiable health information to determine benefit eligibility, pay claims, administer the plan, and conduct related reviews. The court found that the plaintiffs consented to sharing information within and between the relevant organizations and with Jonathan Davidson’s health-care providers for administering benefits and handling appeals. The plaintiffs presented no evidence that defendants shared the information for a purpose other than administering their benefit claims or beyond what was necessary to determine eligibility.
The court also relied on the plaintiffs’ own public disclosures. They had created a publicly accessible blog discussing Jonathan Davidson’s medical condition and had shared information with members of the media and public. The court concluded that these disclosures further showed that the plaintiffs did not maintain a reasonable expectation of privacy in the information they had made public.
The court additionally held that, even if there had been a reasonable expectation of privacy, the disclosures were not sufficiently serious to qualify as an egregious invasion. The information was shared with people the court found necessary to process the plaintiffs’ appeals and determine benefits, and the sharing followed the plaintiffs’ consent.
Regarding the alleged computer intrusions, the court found no record evidence that an intrusion occurred or that any defendant was responsible. The plaintiffs could not identify the responsible person or specifically identify any defendant who engaged in surveillance. Their argument that the events coincided with litigation activity was speculative. The plaintiffs’ computer-forensics analyst found no evidence that defendants caused the problems and identified outdated drivers or user error as possible explanations.
California Common-Law Privacy Claim
The common-law claim was based on alleged public disclosure of private facts and required a public disclosure, a private fact, conduct offensive to a reasonable person, and information that was not a matter of legitimate public concern.
The court held that the medical-information claim failed because the defendants did not publicly disclose the information. The disclosures were limited to people within Hewlett-Packard, United Healthcare, and Optum and to Jonathan Davidson’s treating physicians or their representatives, as permitted by the plan documents and privacy notice. The court also held that the information was not private for purposes of this claim because the plaintiffs had already disclosed detailed information about Jonathan Davidson’s condition and treatment on a public blog and to members of the media and public.
The court reached the same result for the alleged hacking and computer intrusions. It found no record evidence that defendants intruded into or hacked the plaintiffs’ devices, and it held that speculation could not create a genuine factual dispute.
Disposition
The court granted defendants’ motion for summary judgment. It dismissed with prejudice the plaintiffs’ invasion-of-privacy claims under both the California Constitution and California common law, ordered the file closed, and stated that judgment in favor of defendants would follow.
Read the full 16-page opinion on CourtListener, the free public archive maintained by the Free Law Project.