Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled June 23, 2022

Patterson v. Medical Review Institute of America, LLC

Judge
Maxine Chesney
Docket
3:22-cv-00413
Court
U.S. District Court · Northern District of California
Pages
6
Civil ProcedureMotion to Dismiss
In one sentence

Patterson v. Medical Review Institute of America, LLC: Judge Chesney granted the motion, dismissed the complaint for lack of standing, and allowed amendment.

Who this affects

Albert Patterson’s individual lawsuit and proposed class claims were dismissed for lack of subject-matter jurisdiction, subject to his opportunity to amend; MRIoA prevailed on its standing challenge.

What happened

In Patterson v. Medical Review Institute of America, LLC, Albert Patterson sued after MRIoA notified him that hackers had accessed personal health, identifying, and financial information during a data breach. He brought nine claims, including negligence, privacy violations, and breach of contract.

MRIoA argued that Patterson lacked constitutional standing because he had not shown a real injury, and also asked the court to dismiss his claims or transfer the case. The court found that the information involved was not sensitive enough to create a credible risk of fraud or identity theft, and that Patterson had not shown a sufficient injury from lost time, anxiety, reduced information value, or loss of privacy.

Judge Chesney granted MRIoA’s motion and dismissed the complaint for lack of subject-matter jurisdiction, but allowed Patterson to file an amended complaint by July 14, 2022. The court did not decide MRIoA’s alternative arguments that the claims were inadequately pleaded or that the case should be transferred.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Patterson v. Medical Review Institute of America, LLC · No. 3:22-cv-00413
Judge
Maxine Chesney
Date
June 23, 2022

Background

Albert Patterson alleged that Medical Review Institute of America, LLC (MRIoA) acquired, collected, and stored customers’ personal health information, personally identifying information, and financial information to facilitate clinical peer review of health-care services. Patterson alleged that MRIoA sent him a January 7, 2022 letter stating that his information had been involved in a data breach discovered after hackers infiltrated MRIoA’s network.

Patterson asserted nine claims: negligence; violation of California’s Confidentiality of Medical Information Act; invasion of privacy; breach of confidence; violation of California’s Information Practices Act of 1977; breach of implied contract; breach of the implied covenant of good faith and fair dealing; unfair business practices; and unjust enrichment. Several claims were brought for a proposed nationwide class, while others were brought for a proposed California subclass.

Motion and standing analysis

MRIoA moved to dismiss under Federal Rule of Civil Procedure 12(b)(1) for lack of subject-matter jurisdiction, moved under Rule 12(b)(6) for failure to state a claim, or alternatively requested transfer to the District of Utah. MRIoA argued that Patterson lacked Article III standing because he had not alleged a legally sufficient injury. The court explained that standing requires an injury that is concrete and particularized and actual or imminent, that the injury be fairly traceable to the defendant’s conduct, and that a favorable decision likely would redress it.

MRIoA identified five possible injury theories: increased risk of fraud and identity theft, lost time, anxiety, reduced value of personal information, and loss of privacy. In opposition, Patterson relied only on time he lost because of the data breach.

The court rejected the fraud-and-identity-theft theory. MRIoA submitted undisputed evidence that the information about Patterson potentially exposed in the breach was not sufficiently sensitive to create a credible future risk. The information consisted of Patterson’s name, a date, the title “Advisory,” references to him as the insured and patient, a 60-minute review time, and a total amount to be billed of $327.000.

The court also rejected the theories based on lost time and anxiety. Because Patterson had not shown a credible threat of future identity theft, the court held that he could not create standing by taking steps to protect himself from a hypothetical future harm.

The court found that Patterson had not shown an injury based on reduced information value. Although he alleged that a market for personal information existed on the dark web, he did not allege that he planned to sell his information or that the breach prevented him from doing so. The court also noted that there was no indication of a market for the relatively innocuous information involved in this breach.

Finally, the court rejected the loss-of-privacy theory. Patterson did not allege that an unauthorized person actually viewed or misused his information. MRIoA submitted evidence that the hackers demanded ransom in exchange for returning the data and returned the data after MRIoA paid. On that record, the court found no cognizable privacy injury.

Ruling

The court held that Patterson had not met his burden of showing a cognizable injury in fact and therefore lacked Article III standing. It granted MRIoA’s motion and dismissed the complaint for lack of subject-matter jurisdiction. The court gave Patterson leave to amend and set July 14, 2022, as the deadline for an amended complaint.

Because the court dismissed the case for lack of standing, it did not reach MRIoA’s alternative arguments that Patterson had failed to state a claim or that the case should be transferred to the District of Utah. The court vacated the scheduled hearing and continued the case-management conference to October 14, 2022.

The authoritative version

Read the full 6-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.