562 F.Supp.3d 34
D. Ariz.2021Background
- Magellan Health suffered an April 2020 spear-phishing–initiated ransomware attack that exposed employees’, contractors’, and health-plan participants’ PII and PHI. Plaintiffs represent categories who received breach notices, experienced attempted fraud, or incurred out-of-pocket mitigation costs.
- Plaintiffs pleaded negligence, negligence per se, breach of implied contract, unjust enrichment, the Arizona Consumer Fraud Act, and various state consumer-protection claims, alleging Magellan promised and failed to provide adequate data security (including via a privacy policy).
- Magellan moved to dismiss for lack of Article III standing, failure to plead causation or cognizable damages, Rule 9(b) failures on fraud-based claims, and that some state statutes do not apply extraterritorially or to employees/contractors.
- The court found Article III standing satisfied for plaintiffs alleging actual misuse/risk disclosure, but scrutinized proximate causation, cognizable injury, adequacy of pleading about deficient security, and Rule 9(b) particularity.
- The court dismissed negligence (with leave to amend), unjust enrichment, implied-contract, and multiple state consumer-protection claims for failure to state a claim, dismissed negligence per se with prejudice, and gave leave to amend most dismissed counts within 14 days.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Article III standing | Disclosure of PII/PHI and increased risk are concrete injuries | Alleged injuries are speculative/future risks only | Standing satisfied for breach allegations involving actual disclosure/risk; TransUnion recognized disclosure as intangible harm |
| Negligence — causation & damages | Magellan breached duty to secure data causing theft, misuse, out-of-pocket mitigation costs, and diminution in value | Some plaintiffs only allege future risk (speculative); others lack proximate causation or cognizable damages (lost time, diminution, unproven monitoring costs) | Causation plausible for plaintiffs alleging actual misuse/attempted fraud; many alleged damages (future risk, vague time loss, unproven diminution, unjustified monitoring costs) are not cognizable — negligence dismissed with leave to amend; notice-only plaintiffs fail |
| Unjust enrichment / Implied contract (privacy policy/consideration) | Plaintiffs paid fees/provided labor and PII/PHI in exchange for data security; privacy policy created enforceable terms beyond HIPAA | No direct enrichment or impoverishment shown; privacy-policy promises are preexisting legal duties (no new consideration); pleading lacks specificity as to which standards were breached | Claims fail for lack of pleaded inadequacy, connection, and consideration; dismissed with leave to amend |
| Consumer-protection / fraud-based claims & extraterritoriality | Privacy policy statements and omissions support AzCFA, NY §349, UCL, DUTPA, MoMPA, PA CPL, WI DTPA claims | Claims sound in fraud so Rule 9(b) requires particularity; many state statutes require in-state liability-creating conduct or a consumer-merchant relationship; privacy-policy allegations are conclusory | Court applies Rule 9(b) and rejects conclusory “there was a breach, so security was inadequate” theory; multiple state consumer claims dismissed for lack of specificity and extraterritoriality/merchant-consumer issues; leave to amend (VA notice claim also dismissed as notice within one month was reasonable) |
Key Cases Cited
- Bell Atl. Corp. v. Twombly, 550 U.S. 544 (U.S. 2007) (pleading must state plausible claim)
- Ashcroft v. Iqbal, 556 U.S. 662 (U.S. 2009) (pleading standard and disregard of conclusory allegations)
- TransUnion LLC v. Ramirez, 141 S. Ct. 2190 (U.S. 2021) (disclosure of private information can satisfy Article III injury)
- Lujan v. Defenders of Wildlife, 504 U.S. 555 (U.S. 1992) (standing requirements)
- Lexmark Int’l, Inc. v. Static Control Components, Inc., 572 U.S. 118 (U.S. 2014) (proximate causation must be plausibly alleged at pleading stage)
- Krottner v. Starbucks Corp., [citation="406 F. App'x 129"] (9th Cir. 2010) (standing in data-breach context)
- Stollenwerk v. Tri-West Health Care All., [citation="254 F. App'x 664"] (9th Cir. 2007) (theft of data leads to plausible proximate cause of misuse)
- CDT, Inc. v. Addison, Roberts & Ludwig, C.P.A., P.C., 198 Ariz. 173 (Ariz. Ct. App. 2000) (negligence damages must be actual, appreciable, non-speculative)
- Flagstaff Affordable Hous. Ltd. P’ship v. Design Alliance, Inc., 223 Ariz. 320 (Ariz. 2010) (Arizona’s economic-loss doctrine is not to be broadly extended)
- Vess v. Ciba-Geigy Corp. USA, 317 F.3d 1097 (9th Cir. 2003) (Rule 9(b) applies to state-law fraud claims)
