Wallace v. Nuvance Health
- Vincent Briccetti
- 7:20-cv-00545
- U.S. District Court · Southern District of New York
- 31
In Wallace v. Health Quest, Judge Briccetti partly granted and partly denied Health Quest’s dismissal motion after a patient-data breach.
The ruling affects the six named plaintiffs—Leah Wallace, Steven Super, Stephen Gyscek, Alexys Williamson, Nicole Digilio, and Chung Suk Crispell—and the proposed class of similarly situated Health Quest patients and customers. It dismisses some claims but allows the remaining claims to proceed.
What happened
Wallace v. Health Quest Systems, Inc. is a proposed class action by six patients whose medical and other sensitive information allegedly was exposed in a phishing-related data breach. They brought claims involving negligence, contracts, unjust enrichment, confidentiality, bailment, and New York consumer-protection laws.
The court ruled that the plaintiffs adequately alleged standing and some legally recognizable damages, including lost value from the services they purchased and certain credit-monitoring expenses. It dismissed the express-contract and New York General Business Law § 899-aa claims, along with negligence and breach-of-confidence claims brought by Stephen Gyscek and Nicole Digilio. The remaining claims were allowed to proceed.
Judge Vincent L. Briccetti granted in part and denied in part Health Quest’s motion to dismiss under Rules 12(b)(1) and 12(b)(6), and directed Health Quest to answer the amended complaint.
The detailed version
- Wallace v. Nuvance Health · No. 7:20-cv-00545
- Vincent Briccetti
- Mar. 23, 2021
Background
Six plaintiffs brought a proposed class action against Health Quest Systems, Inc. They alleged that a 2018 phishing incident allowed unauthorized individuals to access employee emails and attachments containing patients’ sensitive information, potentially including medical records, Social Security numbers, financial information, and health-insurance information. The plaintiffs alleged that information for 28,910 patients may have been compromised and that Health Quest did not notify affected patients until 2019, with a further notice in January 2020.
The amended complaint asserted claims for negligence, breach of implied contract, breach of express contract, unjust enrichment, breach of confidence, bailment, violation of Section 349 of New York’s General Business Law, and violation of General Business Law § 899-aa. Health Quest moved to dismiss under Rule 12(b)(1), which concerns subject-matter jurisdiction, and Rule 12(b)(6), which tests whether a complaint adequately states a claim.
Standing and Damages
The court held that the plaintiffs adequately alleged constitutional standing. Their allegations that unknown third parties accessed sensitive information plausibly showed a substantial risk of identity theft and fraud.
The court separately examined whether the plaintiffs alleged damages supporting their claims. It held that all six plaintiffs plausibly alleged they lost part of the benefit they expected from the healthcare services they purchased because they expected Health Quest to provide adequate data security. Wallace, Super, Williamson, and Crispell also plausibly alleged out-of-pocket expenses for credit-monitoring or identity-protection services.
The court rejected several other alleged damages theories. Attempted fraud, without alleged monetary loss or other harm, was insufficient by itself. Time spent monitoring credit or responding to possible fraud was insufficient standing alone. The risk of future fraud did not establish damages because the plaintiffs did not show that future expenses were reasonably certain to occur. The plaintiffs also did not plausibly allege that their private information lost value because they did not adequately allege a market for their information, how its value declined, or that they could have sold it.
Negligence
The court held that the plaintiffs, other than Gyscek and Digilio, plausibly alleged negligence. They alleged that Health Quest had a duty to safeguard their private information, breached that duty by failing to use reasonable security measures, and caused them to incur qualifying out-of-pocket costs. The court also held that this duty could exist independently of any contract, so New York’s economic-loss rule did not bar the claim at this stage.
Because Gyscek and Digilio did not allege monetary losses resulting from the data breach, the court granted the motion to dismiss their negligence claims.
Contract Claims
The court dismissed the express-contract claim. It held that Health Quest’s privacy notice did not state sufficiently definite promises about the level of data protection or particular security measures. The plaintiffs also relied on language that did not appear in the privacy notice and did not explain where or how Health Quest allegedly made that promise.
The court allowed the implied-contract claim to proceed. The privacy notice, Health Quest’s other notices, and the security measures it said it was implementing supported an inference that Health Quest had undertaken an implied obligation to use reasonable care in protecting patients’ information in exchange for their business. The court also held that the plaintiffs plausibly alleged consideration because they claimed Health Quest promised more than merely complying with existing legal requirements.
Unjust Enrichment
The court denied dismissal of the unjust-enrichment claim. The plaintiffs alleged that they paid Health Quest for healthcare services but did not receive the expected benefit because Health Quest failed to protect their private information. Although an actual contract could bar unjust enrichment, the court allowed both theories because Health Quest disputed whether a contract existed.
Breach of Confidence and Bailment
The court held that the plaintiffs plausibly alleged a breach-of-confidence claim against a healthcare corporation. It concluded that New York law could recognize a duty to keep patients’ information confidential when a healthcare corporation receives that information to provide medical care. The court allowed the claim to proceed for Wallace, Super, Williamson, and Crispell, but dismissed Gyscek’s and Digilio’s claims because they did not adequately allege qualifying monetary damages.
The court denied dismissal of the bailment claim. A bailment involves one party receiving and holding another party’s property for a particular purpose. The plaintiffs plausibly alleged that they entrusted their private information to Health Quest to obtain medical care, that Health Quest agreed to safeguard it, and that Health Quest failed to exercise reasonable care. The court also concluded at this stage that New York law could extend bailment principles to intangible information.
New York Consumer-Protection Claims
The court held that all plaintiffs plausibly stated a claim under General Business Law § 349. Health Quest’s privacy statements were consumer-oriented, and the plaintiffs plausibly alleged that the statements could mislead reasonable consumers about Health Quest’s security practices and promptness in reporting a breach. Their alleged loss of the benefit of the bargain supplied a plausible injury.
The plaintiffs did not oppose dismissal of their claim under General Business Law § 899-aa. The court therefore deemed that claim abandoned and dismissed it.
Disposition
Judge Vincent L. Briccetti granted in part and denied in part Health Quest’s motion to dismiss. The court dismissed the General Business Law § 899-aa and express-contract claims, as well as Gyscek’s and Digilio’s negligence and breach-of-confidence claims. All other claims were allowed to proceed. The court directed Health Quest to answer the amended complaint by April 5, 2021, and terminated the motion.
Read the full 31-page opinion on CourtListener, the free public archive maintained by the Free Law Project.