midpage
Projects
Sign in to see your projects.
399 F.Supp.3d 780
W.D. Wis.
2019
Read the full case

Background

  • Plaintiffs (four UnityPoint customers from WI, IL, IA) allege two employee-email hacks in 2017–2018 exposed personal and health data (including Social Security numbers) of tens of thousands; UnityPoint delayed public notice in each instance.
  • Plaintiffs allege resulting harms: increased spam/robocalls, attempted identity theft and fraud (one alleged new credit account, attempted Experian login), mitigation costs (credit monitoring, new phone), and emotional distress.
  • Plaintiffs sued as a proposed class asserting 14 claims under Wisconsin, Illinois, and Iowa law (negligence, negligence per se, invasion of privacy, statutory and common-law fraud/misrepresentation, breach of contract, unjust enrichment, state data-breach notification claims, declaratory relief, etc.).
  • UnityPoint moved to dismiss for lack of Article III standing and for failure to state claims under Rules 12(b)(1) and 12(b)(6); the court considered choice-of-law for nonforum plaintiffs.
  • The court found plaintiffs have standing (concrete injuries and traceability sufficiently pleaded) but dismissed several claims: invasion of privacy, misrepresentation/consumer-fraud theories, Illinois/Iowa negligence (economic-loss doctrine), Wisconsin data-breach notification statute (no private right), and declaratory relief; other claims (breach of contract, breach of covenant, unjust enrichment; Wisconsin negligence and Wis. confidentiality-of-health-records for WI plaintiffs) survive.

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Standing — injury in fact Risk of identity theft, mitigation costs, lost time and spam constitute concrete injuries; risk is objectively reasonable given data taken Plaintiffs lack imminent injury; harms may come from other sources Plaintiffs have standing; allegations and some specific fraud attempts suffice to show concrete injury and traceability at pleading stage
Causation / traceability Breaches (including SSNs) and fullz theory plausibly explain subsequent spam/fraud; UnityPoint’s delays increased risk UnityPoint submits evidence disputing linkage for some harms (e.g., Fox’s contact info publicly posted; no CC numbers stolen) At Rule 12 stage, plaintiffs plausibly allege harms fairly traceable to UnityPoint; factual disputes reserved for later stages
Economic-loss doctrine (IL & IA) Plaintiffs assert negligence/negligence per se despite contractual relationship and nonphysical harms UnityPoint: pure economic losses from service contract are barred by doctrine Economic-loss doctrine bars negligence and negligence-per-se claims for Illinois and Iowa plaintiffs; dismissed as to Duckley and Kitsis
Invasion-of-privacy claims Plaintiff: reckless/negligent disclosure by UnityPoint supports claim UnityPoint: publication-based privacy torts require intentional publication Dismissed — Wisconsin, Illinois (and likely Iowa) require intentional publication for publicity-based privacy claims; negligent third-party theft insufficient
Misrepresentation & consumer-fraud claims Plaintiffs allege inaccurate breach notices and privacy-policy promises caused reliance/damages UnityPoint: plaintiffs fail to plead reliance or damages causally linked to statements; Rule 9(b) applies Dismissed — plaintiffs failed to plead reliance or actual damages tied to alleged misrepresentations; UDTPA claim also fails for lack of likelihood of future harm
Data-breach notification statutes Plaintiffs claim statutory violations for delayed notice across states UnityPoint: statute violations do not automatically create private remedies or show damages Dismissed: Wisconsin statute contains no private right; Illinois/Iowa statutory claims dismissed for failure to allege damages caused by timing of notice
Contract, covenant, unjust enrichment Plaintiffs: privacy policy incorporated into service contract; breach caused damages; alternative unjust enrichment UnityPoint: policy not contractual, no breach, no damages, or contract precludes unjust enrichment Survive: breach of contract, covenant of good faith and fair dealing, and unjust enrichment claims proceed (including Wisconsin-specific claims for Fox and Nesheim)
Declaratory relief Plaintiffs seek declaration and injunctive relief even if other claims fail UnityPoint opposes separate declaratory claim Dismissed as discretionary; redundant given other remedies and dismissed statutory claims

Key Cases Cited

  • Lee v. City of Chicago, 330 F.3d 456 (7th Cir.) (standing/jurisdictional principles for pleadings)
  • Spokeo, Inc. v. Robins, 136 S. Ct. 1540 (2016) (concrete-injury requirement for Article III standing)
  • Clapper v. Amnesty Int’l USA, 568 U.S. 398 (2013) (imminence/‘certainly impending’ standard for future injury)
  • Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir.) (data-breach standing — risk and mitigation costs can be concrete injury)
  • Lewert v. P.F. Chang’s China Bistro, Inc., 819 F.3d 963 (7th Cir.) (similar holding on standing in breach cases)
  • Dieffenbach v. Barnes & Noble, Inc., 887 F.3d 826 (7th Cir.) (pleading damages separate from standing)
Read the full case

Case Details

Case Name: Fox, Yvonne v. Iowa Health System
Court Name: District Court, W.D. Wisconsin
Date Published: Jul 25, 2019
Citations: 399 F.Supp.3d 780; 3:18-cv-00327
Docket Number: 3:18-cv-00327
Court Abbreviation: W.D. Wis.
Log In
    Fox, Yvonne v. Iowa Health System, 399 F.Supp.3d 780