49 Misc. 3d 1027
N.Y. Sup. Ct.2015Background
- Plaintiffs (13 patients or relatives) allege North Shore–LIJ entities failed to safeguard patient face sheets and unencrypted network data, resulting in thefts and identity/medical identity fraud between 2010–2012.
- At least two individuals were criminally charged after being found in possession of patient face sheets and electronic data; one allegedly held data for over 900 people.
- Plaintiffs claim defendants promised to comply with HIPAA and other privacy obligations, but delayed or failed to notify patients and regulators of breaches within statutory timelines.
- The complaint pleads 11 causes of action (negligence, negligence per se based on several statutes, GBL § 349, breach of contract, breach of fiduciary duty, breach of implied covenant, misrepresentation).
- Defendants removed under CAFA to federal court; the case was remanded to state court. Defendants moved to dismiss under CPLR 3211(a)(7).
- The court dismissed most statutory and contract-based claims for lack of a private right of action or insufficient pleading, but allowed negligence claims to proceed against NSUH and Health System (dismissed as to Network and Medical Care).
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Whether plaintiffs may pursue negligence per se under NY Gen. Bus. Law § 899-aa | Statute’s notice requirements were violated; plaintiffs seek damages for increased identity-theft risk | No express private right; enforcement reserved to Attorney General; private suit not implied | Dismissed — no private right of action under § 899-aa |
| Whether plaintiffs can sue under Public Health Law § 18 for disclosure of records | Theft = disclosure of medical records causing harm | Statute does not create private cause of action; theft by third party is not defendant disclosure | Dismissed — no private right and no actionable disclosure |
| Whether HIPAA/HITECH/GBL § 399-ddd create private causes of action | Regulatory privacy/security duties were breached | Those federal statutes/regulatory schemes do not confer private right; state statute enforcement vested in AG | Dismissed — no private right under HIPAA/HITECH/§399-ddd |
| Viability of common-law claims (negligence, breach of contract/fiduciary, GBL § 349, fraud, implied covenant) | Privacy policies and representations created duties and inducements to rely; negligent security caused identity theft and damages | Pleading is conclusory, group/collective pleading insufficient, economic-loss and pleading particularity bars, no specific contract terms or individualized fraud allegations | Negligence claim survives as to NSUH and Health System; all other common-law claims dismissed; negligence dismissed as to Network and Medical Care |
Key Cases Cited
- Leon v. Martinez, 84 N.Y.2d 83 (pleading construed liberally on motion to dismiss)
- Goshen v. Mutual Life Ins. Co. of N.Y., 98 N.Y.2d 314 (GBL § 349 injury and consumer-oriented requirement)
- Sheehy v. Big Flats Community Day, 73 N.Y.2d 629 (three-factor test for implied private right of action)
- Carrier v. Salvation Army, 88 N.Y.2d 298 (implied private right of action requires clear legislative intent)
- Mark G. v. Sabol, 93 N.Y.2d 710 (declining implied private right when statute provides enforcement mechanism)
- Cruz v. TD Bank, N.A., 22 N.Y.3d 61 (statutory enforcement provisions preclude judicially implied remedies)
- Oswego Laborers' Local 214 Pension Fund v. Marine Midland Bank, 85 N.Y.2d 20 (elements of a GBL § 349 claim)
