Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.Procedural orderFiled May 25, 2023

Becker v. LISI, LLC

Judge
Jon Tigar
Docket
4:21-cv-03295
Court
U.S. District Court · Northern District of California
Pages
12
Class ActionCivil Procedure
In one sentence

In Becker v. LISI, LLC, Judge Tigar denied Becker’s second request to preliminarily approve a class settlement, without prejudice.

Who this affects

The ruling affects Matthew Becker, LISI, LLC, AmWins Group, Inc., and the proposed settlement class members whose personally identifying information was compromised in the July 2020 data breach. The proposed settlement was not preliminarily approved.

What happened

Becker v. LISI, LLC is a proposed class action over a 2020 data breach involving customers’ personally identifying information. Becker proposed a settlement for about 500 affected people that included identity-protection services, reimbursement for certain losses and time, and a possible payment of up to $200,000.

The court found that Becker’s second request still did not provide enough information to evaluate the settlement. In particular, the request did not adequately estimate the class’s possible recovery, explain the expected claims rate, justify provisions allowing defendants to keep unclaimed amounts, or provide all required information about comparable settlements.

Judge Tigar denied the request without prejudice because the court could not determine whether the settlement was fair, reasonable, adequate, and within the range of possible approval. The court said Becker could submit a revised request within 90 days.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Becker v. LISI, LLC · No. 4:21-cv-03295
Judge
Jon Tigar
Date
May 25, 2023

Background

This proposed class action arose from a data breach that Defendants LISI, LLC and AmWins Group, Inc. announced in July 2020. The breach involved an employee’s hacked email account and the forwarding of emails containing affected individuals’ personally identifying information, including names, Social Security numbers, dates of birth, and insurance information, to an unauthorized third party.

Matthew Becker alleged that Defendants failed to adequately protect the information. He asserted claims for negligence, breach of confidence, injunctive and declaratory relief, and violation of California’s Unfair Competition Law. He sought to represent all individuals whose information was compromised in the breach.

The proposed settlement class consisted of people residing in the United States whose information was compromised. The opinion notes that the proposed class size was unclear: the settlement materials stated 553 people, another filing suggested 491, and the court used an estimate of 500 for purposes of the order.

Proposed Settlement

The proposed agreement would provide class members with access to IDX identity-protection services for 24 months. Class members could also seek reimbursement for certain breach-related out-of-pocket expenses, including fraud or identity-theft losses, professional fees, credit-related costs, and other listed expenses. They could seek compensation for up to three hours of time at $25 per hour. Defendants would pay up to $1,500 per claimant, subject to a total cap of $200,000, with claims reduced proportionally if they exceeded that cap. Any amount below the cap would remain with Defendants.

The agreement also described cybersecurity actions Defendants had taken after the breach, including multi-factor authentication, tighter rules for email forwarding, employee retraining, annual training, and centralized security oversight. The agreement released claims related to the breach and the conduct alleged or that could have been alleged in the action. It also provided that Defendants would not oppose a request for up to $75,000 in attorney’s fees and costs or a service award of up to $2,000 for Becker.

Court’s Analysis

The court explained that preliminary approval is an initial review of a proposed class settlement. At this stage, the court must determine whether it will likely be able to find that the settlement is fair, reasonable, and adequate, certify the settlement class if necessary, and direct reasonable notice to affected class members. The settlement must fall within the range of possible approval and must not show obvious deficiencies or improper preferential treatment.

The court had previously denied Becker’s first request without prejudice and identified problems with the submission. The second request addressed some issues but still did not comply with several sections of the Northern District of California’s Procedural Guidelines.

First, the court found that the second request did not adequately explain the class’s potential recovery if Becker fully prevailed on each claim or justify the discount reflected in the settlement. Becker relied on an estimate of the black-market value of Social Security numbers, placing the potential recovery at $2 to $25 per person and $12,500 for the class at the highest estimate. The court found that Becker did not explain why that method was the best measure of the claims’ value, particularly because the complaint alleged other forms of harm, including identity theft, fraud, mitigation expenses, lost time, privacy losses, and economic and noneconomic harm. The court also required more information about the value of the described cybersecurity actions if they were intended to constitute relief for the class.

Second, the court found that the request did not provide all required support for its estimated 4 percent claims rate. Although the proposed claims administrator had compared five data-breach settlements, the submission did not identify those examples or explain why they were selected.

Third, the court found that the proposed settlement’s reversion provisions were not adequately addressed. A reversion occurs when money designated for class members may remain with or return to the defendant. The agreement allowed Defendants to retain unclaimed amounts, and the estimated claims rate could leave at least $170,000 of the $200,000 reimbursement cap unpaid. The court also could not determine whether unused identity-protection codes would create another reversion. The second request did not explain why a reversionary settlement was appropriate in this case.

Fourth, the court found that the submission did not provide all information required about six comparable data-breach settlements. The comparison omitted, among other things, the claims released, notice methods, average recovery, attorney’s fees and costs, and information about whether class members used any non-monetary relief.

Disposition

The court stated that it could not make a preliminary determination that the proposed settlement was fair, reasonable, and adequate or that it fell within the range of possible approval. It therefore denied Becker’s second motion for preliminary approval without prejudice. The court stated that Becker may submit a revised motion within 90 days of the order.

The authoritative version

Read the full 12-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.