midpage
Projects
Sign in to see your projects.
49 Misc. 3d 1027
N.Y. Sup. Ct.
2015
Read the full case

Background

  • Plaintiffs (13 patients or relatives) allege North Shore–LIJ entities failed to safeguard patient face sheets and unencrypted network data, resulting in thefts and identity/medical identity fraud between 2010–2012.
  • At least two individuals were criminally charged after being found in possession of patient face sheets and electronic data; one allegedly held data for over 900 people.
  • Plaintiffs claim defendants promised to comply with HIPAA and other privacy obligations, but delayed or failed to notify patients and regulators of breaches within statutory timelines.
  • The complaint pleads 11 causes of action (negligence, negligence per se based on several statutes, GBL § 349, breach of contract, breach of fiduciary duty, breach of implied covenant, misrepresentation).
  • Defendants removed under CAFA to federal court; the case was remanded to state court. Defendants moved to dismiss under CPLR 3211(a)(7).
  • The court dismissed most statutory and contract-based claims for lack of a private right of action or insufficient pleading, but allowed negligence claims to proceed against NSUH and Health System (dismissed as to Network and Medical Care).

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Whether plaintiffs may pursue negligence per se under NY Gen. Bus. Law § 899-aa Statute’s notice requirements were violated; plaintiffs seek damages for increased identity-theft risk No express private right; enforcement reserved to Attorney General; private suit not implied Dismissed — no private right of action under § 899-aa
Whether plaintiffs can sue under Public Health Law § 18 for disclosure of records Theft = disclosure of medical records causing harm Statute does not create private cause of action; theft by third party is not defendant disclosure Dismissed — no private right and no actionable disclosure
Whether HIPAA/HITECH/GBL § 399-ddd create private causes of action Regulatory privacy/security duties were breached Those federal statutes/regulatory schemes do not confer private right; state statute enforcement vested in AG Dismissed — no private right under HIPAA/HITECH/§399-ddd
Viability of common-law claims (negligence, breach of contract/fiduciary, GBL § 349, fraud, implied covenant) Privacy policies and representations created duties and inducements to rely; negligent security caused identity theft and damages Pleading is conclusory, group/collective pleading insufficient, economic-loss and pleading particularity bars, no specific contract terms or individualized fraud allegations Negligence claim survives as to NSUH and Health System; all other common-law claims dismissed; negligence dismissed as to Network and Medical Care

Key Cases Cited

  • Leon v. Martinez, 84 N.Y.2d 83 (pleading construed liberally on motion to dismiss)
  • Goshen v. Mutual Life Ins. Co. of N.Y., 98 N.Y.2d 314 (GBL § 349 injury and consumer-oriented requirement)
  • Sheehy v. Big Flats Community Day, 73 N.Y.2d 629 (three-factor test for implied private right of action)
  • Carrier v. Salvation Army, 88 N.Y.2d 298 (implied private right of action requires clear legislative intent)
  • Mark G. v. Sabol, 93 N.Y.2d 710 (declining implied private right when statute provides enforcement mechanism)
  • Cruz v. TD Bank, N.A., 22 N.Y.3d 61 (statutory enforcement provisions preclude judicially implied remedies)
  • Oswego Laborers' Local 214 Pension Fund v. Marine Midland Bank, 85 N.Y.2d 20 (elements of a GBL § 349 claim)
Read the full case

Case Details

Case Name: Abdale v. North Shore-Long Island Jewish Health System, Inc.
Court Name: New York Supreme Court
Date Published: Aug 14, 2015
Citations: 49 Misc. 3d 1027; 19 N.Y.S.3d 850; 2015 NY Slip Op 25274
Court Abbreviation: N.Y. Sup. Ct.
Log In
    Abdale v. North Shore-Long Island Jewish Health System, Inc., 49 Misc. 3d 1027