399 F.Supp.3d 780
W.D. Wis.2019Background
- Plaintiffs (four UnityPoint customers from WI, IL, IA) allege two employee-email hacks in 2017–2018 exposed personal and health data (including Social Security numbers) of tens of thousands; UnityPoint delayed public notice in each instance.
- Plaintiffs allege resulting harms: increased spam/robocalls, attempted identity theft and fraud (one alleged new credit account, attempted Experian login), mitigation costs (credit monitoring, new phone), and emotional distress.
- Plaintiffs sued as a proposed class asserting 14 claims under Wisconsin, Illinois, and Iowa law (negligence, negligence per se, invasion of privacy, statutory and common-law fraud/misrepresentation, breach of contract, unjust enrichment, state data-breach notification claims, declaratory relief, etc.).
- UnityPoint moved to dismiss for lack of Article III standing and for failure to state claims under Rules 12(b)(1) and 12(b)(6); the court considered choice-of-law for nonforum plaintiffs.
- The court found plaintiffs have standing (concrete injuries and traceability sufficiently pleaded) but dismissed several claims: invasion of privacy, misrepresentation/consumer-fraud theories, Illinois/Iowa negligence (economic-loss doctrine), Wisconsin data-breach notification statute (no private right), and declaratory relief; other claims (breach of contract, breach of covenant, unjust enrichment; Wisconsin negligence and Wis. confidentiality-of-health-records for WI plaintiffs) survive.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Standing — injury in fact | Risk of identity theft, mitigation costs, lost time and spam constitute concrete injuries; risk is objectively reasonable given data taken | Plaintiffs lack imminent injury; harms may come from other sources | Plaintiffs have standing; allegations and some specific fraud attempts suffice to show concrete injury and traceability at pleading stage |
| Causation / traceability | Breaches (including SSNs) and fullz theory plausibly explain subsequent spam/fraud; UnityPoint’s delays increased risk | UnityPoint submits evidence disputing linkage for some harms (e.g., Fox’s contact info publicly posted; no CC numbers stolen) | At Rule 12 stage, plaintiffs plausibly allege harms fairly traceable to UnityPoint; factual disputes reserved for later stages |
| Economic-loss doctrine (IL & IA) | Plaintiffs assert negligence/negligence per se despite contractual relationship and nonphysical harms | UnityPoint: pure economic losses from service contract are barred by doctrine | Economic-loss doctrine bars negligence and negligence-per-se claims for Illinois and Iowa plaintiffs; dismissed as to Duckley and Kitsis |
| Invasion-of-privacy claims | Plaintiff: reckless/negligent disclosure by UnityPoint supports claim | UnityPoint: publication-based privacy torts require intentional publication | Dismissed — Wisconsin, Illinois (and likely Iowa) require intentional publication for publicity-based privacy claims; negligent third-party theft insufficient |
| Misrepresentation & consumer-fraud claims | Plaintiffs allege inaccurate breach notices and privacy-policy promises caused reliance/damages | UnityPoint: plaintiffs fail to plead reliance or damages causally linked to statements; Rule 9(b) applies | Dismissed — plaintiffs failed to plead reliance or actual damages tied to alleged misrepresentations; UDTPA claim also fails for lack of likelihood of future harm |
| Data-breach notification statutes | Plaintiffs claim statutory violations for delayed notice across states | UnityPoint: statute violations do not automatically create private remedies or show damages | Dismissed: Wisconsin statute contains no private right; Illinois/Iowa statutory claims dismissed for failure to allege damages caused by timing of notice |
| Contract, covenant, unjust enrichment | Plaintiffs: privacy policy incorporated into service contract; breach caused damages; alternative unjust enrichment | UnityPoint: policy not contractual, no breach, no damages, or contract precludes unjust enrichment | Survive: breach of contract, covenant of good faith and fair dealing, and unjust enrichment claims proceed (including Wisconsin-specific claims for Fox and Nesheim) |
| Declaratory relief | Plaintiffs seek declaration and injunctive relief even if other claims fail | UnityPoint opposes separate declaratory claim | Dismissed as discretionary; redundant given other remedies and dismissed statutory claims |
Key Cases Cited
- Lee v. City of Chicago, 330 F.3d 456 (7th Cir.) (standing/jurisdictional principles for pleadings)
- Spokeo, Inc. v. Robins, 136 S. Ct. 1540 (2016) (concrete-injury requirement for Article III standing)
- Clapper v. Amnesty Int’l USA, 568 U.S. 398 (2013) (imminence/‘certainly impending’ standard for future injury)
- Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir.) (data-breach standing — risk and mitigation costs can be concrete injury)
- Lewert v. P.F. Chang’s China Bistro, Inc., 819 F.3d 963 (7th Cir.) (similar holding on standing in breach cases)
- Dieffenbach v. Barnes & Noble, Inc., 887 F.3d 826 (7th Cir.) (pleading damages separate from standing)
