Aponte v. Northeast Radiology, P.C.
- Vincent Briccetti
- 7:21-cv-05883
- U.S. District Court · Southern District of New York
- 10
In Aponte v. Northeast Radiology, Judge Briccetti dismissed the case because plaintiffs did not show a concrete injury giving them standing to sue.
The ruling affected Jose Aponte II and Lisa Rosenberg and the proposed class of similarly situated persons whose electronic health information was allegedly stored in defendants’ system. The court dismissed the case for lack of standing and did not decide the merits of the asserted claims.
What happened
Aponte v. Northeast Radiology, P.C. involved Jose Aponte II and Lisa Rosenberg’s proposed class action over alleged failures to protect patients’ electronic health information. They claimed unauthorized users accessed a system containing medical and identifying information.
The plaintiffs said they faced future identity theft, had to monitor their accounts, paid or would pay for protection services, received less than they had bargained for, and experienced an invasion of privacy. They asserted claims including negligence, breach of contract, violation of New York law, and intrusion upon seclusion.
The court ruled that the plaintiffs had not shown a concrete injury or a sufficiently imminent risk of harm, so they lacked standing to sue. Judge Vincent L. Briccetti granted the motion to dismiss under Rule 12(b)(1), dismissed the case, and did not decide whether the complaint stated valid claims under Rule 12(b)(6).
The detailed version
- Aponte v. Northeast Radiology, P.C. · No. 7:21-cv-05883
- Vincent Briccetti
- May 16, 2022
Background
Jose Aponte II and Lisa Rosenberg brought a proposed class action against Northeast Radiology, P.C. and Alliance HealthCare Services, Inc. The plaintiffs alleged that unauthorized individuals accessed defendants’ Picture Archiving and Communications System between April 14, 2019, and January 7, 2020. According to the amended complaint, the system contained approximately 62 million images associated with 300,000 patients, and file names could display electronic protected health information, including names, birth dates, patient identification numbers, examination dates, and study descriptions. The plaintiffs alleged that the system lacked basic security features, including encryption and passwords.
The plaintiffs alleged that they faced an ongoing and imminent risk of identity theft and fraud because electronic health information cannot be canceled like a credit card. They also alleged that they would need to monitor accounts, obtain credit or identity-theft monitoring, and spend time preventing or reducing possible future losses. In addition, they claimed they would not have used defendants’ services if they had known about the security practices and that the alleged security failures caused an intrusion upon their seclusion.
The amended complaint asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, violation of New York General Business Law Section 349, and intrusion upon seclusion. Defendants moved to dismiss under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). Rule 12(b)(1) concerns the court’s subject-matter jurisdiction; Rule 12(b)(6) concerns whether a complaint states a legally sufficient claim.
Standing analysis
The court addressed the Rule 12(b)(1) motion first. To establish constitutional standing, a plaintiff must show an injury in fact that is concrete and particularized, actual or imminent, fairly traceable to the defendant’s conduct, and likely to be remedied by a favorable decision.
The court held that the plaintiffs had not alleged an injury in fact. First, they did not allege that anyone had misused or attempted to misuse their information. They also did not allege that they belonged to the group of 29 patients whose information defendants had determined was accessed. The court found that the allegation that an unauthorized user could have viewed or downloaded the plaintiffs’ information was too remote and speculative to establish a substantial or imminent risk of identity theft.
Second, the court held that the plaintiffs’ account-monitoring efforts and related expenses did not establish an injury because those steps were based on a speculative future threat. Third, the court rejected the alleged benefit-of-the-bargain injury. The plaintiffs had not alleged concrete harm from the breach, and the court reasoned that the alleged loss of privacy was insufficient without misuse or attempted misuse of the data.
Fourth, the court rejected the intrusion-upon-seclusion theory as a basis for standing. Although intrusion upon seclusion can resemble a traditionally recognized legal harm, the plaintiffs alleged that unauthorized third parties—not defendants—accessed the data. The court therefore concluded that the plaintiffs had not identified a sufficiently close common-law comparison for the injury they alleged.
Finally, the court explained that alleged violations of the Health Insurance Portability and Accountability Act, the Federal Trade Commission Act, and New York and Connecticut law could not establish standing without a concrete injury. Allegations of a legal violation alone were not enough, and the request for statutory damages did not independently create standing.
Disposition
The court concluded that the plaintiffs had not shown that they suffered or would imminently suffer an injury in fact. It held that they therefore lacked standing, leaving the court without subject-matter jurisdiction. Judge Vincent L. Briccetti granted the motion to dismiss under Rule 12(b)(1), instructed the Clerk to close the case, and expressly did not reach defendants’ Rule 12(b)(6) motion concerning whether the plaintiffs had stated valid claims.
Read the full 10-page opinion on CourtListener, the free public archive maintained by the Free Law Project.