In re: Netgain Technology, LLC Consumer Data Breach Litigation
- Susan Nelson
- 0:21-cv-01210
- U.S. District Court · District of Minnesota
- 38
In Netgain Data Breach Litigation, Judge Nelson granted in part and denied in part Netgain’s dismissal motion, allowing negligence claims to proceed while dismissing others.
The seven plaintiffs and proposed classes may continue their negligence and declaratory-relief claims at this stage. The negligence-per-se claim and Minnesota Health Records Act claim were subject to the granted portion of Netgain’s motion, while the withdrawn California claims were addressed as moot. Netgain Technology, LLC remains the defendant in the surviving claims.
What happened
In re: Netgain Technology, LLC Consumer Data Breach Litigation concerns a ransomware attack that allegedly exposed sensitive personal and health information stored by Netgain Technology, LLC. Seven plaintiffs sued Netgain for themselves and proposed classes, claiming negligence, negligence per se, violations of the Minnesota Health Records Act, and other relief. Netgain argued that the plaintiffs lacked constitutional standing and had not adequately stated their claims.
The court held that the plaintiffs adequately alleged an injury because their information was stolen and they faced a substantial risk of future harm. It also found that Mark Kalling alleged present identity-theft-related harm traceable to the breach, giving at least one plaintiff standing. The court further found that the negligence claim was adequately pleaded, but the negligence-per-se and Minnesota Health Records Act claims were not. The California and Minnesota statutory claims were withdrawn, making the motion as to those claims moot.
Judge Susan Richard Nelson granted in part and denied in part Netgain’s motion to dismiss. The motion was granted as to Counts II and V, denied as to Counts I and VI, and denied as moot as to Counts III and IV. The order allowed the negligence and declaratory-relief claims to proceed at this stage.
The detailed version
- In re: Netgain Technology, LLC Consumer Data Breach Litigation · No. 0:21-cv-01210
- Susan Nelson
- June 2, 2022
Background
Netgain Technology, LLC provides cloud-based information-technology and cybersecurity services and stores sensitive information for its clients. The plaintiffs alleged that a ransomware attack in fall 2020 allowed cybercriminals to access and export data from at least 15 clients, including names, Social Security numbers, dates of birth, driver’s-license numbers, medical information, and other sensitive data. They alleged that Netgain paid a ransom in exchange for assurances that the information would be deleted and not disclosed.
Seven individuals brought the consolidated action for themselves and proposed nationwide, California, and Minnesota classes. Their amended complaint asserted negligence, negligence per se, violations of the Minnesota Health Records Act, and requests for declaratory and injunctive relief. The plaintiffs also initially asserted claims under the California Consumer Privacy Act and California Unfair Competition Law, but later withdrew those claims.
Netgain moved to dismiss under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). Rule 12(b)(1) addresses the court’s jurisdiction, including whether a plaintiff has constitutional standing. Rule 12(b)(6) tests whether the complaint states a legally sufficient claim, assuming well-pleaded factual allegations are true.
Standing
The court denied Netgain’s Rule 12(b)(1) motion. It concluded that the plaintiffs adequately alleged an injury in fact because the complaint alleged that their personally identifiable information and personal health information were stolen. The court also found that the alleged theft created a substantial risk of future harm, including identity theft, particularly because the stolen information included identifying and medical information and some plaintiffs took steps to monitor their credit or accounts.
The court separately found that Mark Kalling alleged a present injury. He alleged that his information was stolen, that he received at least four notifications of credit-card fraud, and that he spent more than 30 hours mitigating damage to his credit. The court found those allegations sufficient to establish an injury fairly traceable to the data breach. Because one named plaintiff’s standing was enough for the putative class action to proceed, the court denied the jurisdictional portion of Netgain’s motion.
Negligence claim
The court denied the motion to dismiss the negligence claim. It held that the economic-loss doctrine did not bar the claim under Minnesota or Wisconsin law because Netgain provided services; under South Carolina law because the plaintiffs were not in contractual privity with Netgain; or under California and Nevada law because the alleged loss of time, exposure of sensitive information, and risk of identity theft went beyond purely economic loss.
The court also found that the plaintiffs plausibly alleged that Netgain owed them a duty to protect their information. Under the laws of California, Minnesota, Nevada, South Carolina, and Wisconsin, the court determined at the pleading stage that Netgain’s control over sensitive information, its cybersecurity business, and the foreseeable risk of harm from inadequate security supported a duty of care.
The court further held that the plaintiffs adequately alleged cognizable damages, including time spent monitoring credit, reviewing financial accounts, responding to the breach, and mitigating alleged identity-theft-related harm. The court emphasized that the case was at the pleading stage and that the plaintiffs did not need to assign a specific monetary value to their damages at that point.
Negligence per se
The court granted the motion as to Count II, the negligence-per-se claim. The plaintiffs based that claim in part on Section 5 of the Federal Trade Commission Act. The court held that the complaint’s allegation that the plaintiffs belonged to the class the statute protected was conclusory and did not explain why they were members of that protected group. It also held that the Federal Trade Commission Act does not create a private right of action. The court therefore dismissed the negligence-per-se claim.
Minnesota Health Records Act claim
The court granted the motion as to Count V, the Minnesota Health Records Act claim. The statute requires an unauthorized release or intentional unauthorized access in the circumstances alleged. Relying on Minnesota Supreme Court precedent, the court held that a person must affirmatively release a record, meaning set it free or make it available for use. The court found that Netgain did not affirmatively release the records; instead, the cybercriminals allegedly stole or extracted them. The court dismissed this claim on that basis and did not reach Netgain’s alternative arguments.
Declaratory and injunctive relief
The court denied the motion as to Count VI. Netgain argued that the plaintiffs sought only a ruling duplicating their other claims and that injunctive relief was unavailable because other legal remedies existed and no ongoing irreparable injury was shown. The court found those arguments premature because the plaintiffs alleged that Netgain continued to provide inadequate data security and that they and the proposed class continued to suffer injury.
The court denied the motion as moot as to Counts III and IV because the plaintiffs had withdrawn their California Consumer Privacy Act and California Unfair Competition Law claims.
Disposition
Judge Susan Richard Nelson ordered that Netgain’s Motion to Dismiss be granted in part and denied in part: granted as to Counts II and V; denied as to Counts I and VI; and denied as moot as to Counts III and IV. The opinion does not state that any dismissal was with or without prejudice.
Read the full 38-page opinion on CourtListener, the free public archive maintained by the Free Law Project.