Curtis M. Smallwood, Appellant, vs. State of Minnesota, Department of Human Services, et al., Respondents
Keith Ellison, Attorney General, Drew D. Bredeson, Assistant Attorney General, St. Paul, Minnesota (for respondents)
Considered and decided by Ross, Presiding Judge; Segal, Chief Judge; and Gaïtas, Judge.
SYLLABUS
- Data that is acquired by an unauthorized person‘s hacking into a government account has not been “disseminated” in violation of
Minnesota Statutes section 13.05 , subdivision 4 (2020). - The state has not waived sovereign immunity for claims under the Minnesota Health Records Act,
Minnesota Statutes sections 144.291-98 (2020).
OPINION
ROSS, Judge
A hacker accessed a Minnesota Department of Human Services email account assigned to a department employee. The department informed Curtis Smallwood, who is civilly committed to the state sex-offender program as a sexually dangerous person, that his private information may have been accessed. Smallwood sued the state for damages under the Minnesota Government Data Practices Act and the Minnesota Health Records Act, contending that “disclosing” his private information caused him emotional and economic harm. The district court dismissed Smallwood‘s civil complaint for failure to state a claim. We affirm in part because the state did not waive its sovereign immunity from exposure to civil liability under the Minnesota Health Records Act. But we reverse in part because Smallwood stated a data practices act claim despite the generalized nature of his allegation of damages.
FACTS
Curtis Smallwood has been civilly committed to the Minnesota Sex Offender Program (MSOP) as a sexually dangerous person since 2011. See In re Civil Commitment of Smallwood, No. A11-1971, 2012 WL 896439, at *1, *3 (Minn. App. March 19, 2012), review denied (Minn. June 27, 2012) (affirming Smallwood‘s civil commitment); In re Civil Commitment of Smallwood, A18-0481, 2018 WL 4401920, at *1 (Minn. App. Sept. 17, 2018) (affirming refusal to grant Smallwood a provisional discharge or transfer). The Minnesota Department of Human Services (DHS) informed him that, in March 2018, a hacker accessed a DHS email account assigned to a DHS employee. The email account
Smallwood filed a civil complaint seeking damages for DHS‘s alleged violations of the Minnesota Government Data Practices Act (MGDPA),
The district court granted DHS‘s motion to dismiss the complaint for failing to state a claim for which relief can be granted. See
Smallwood appeals.
ISSUES
I. Did Smallwood state a claim under the MGDPA?
II. Does sovereign immunity preclude Smallwood‘s HRA claim?
ANALYSIS
Challenging the district court‘s decision to dismiss his MGDPA claim, Smallwood argues that his factual allegations of a violation and his claim for damages satisfy the notice-pleading requirements of
I
Smallwood‘s claim under the MGDPA survives the state‘s motion to dismiss. We review de novo a district court‘s decision to dismiss for failure to state a claim under
Although the district court correctly dismissed the MGDPA claim because Smallwood‘s complaint failed to assert any dissemination of data, we cannot affirm the dismissal of the claim. The complaint‘s allegations do not rest entirely on dissemination because they also implicate a different provision of the statute. The MGDPA does more than prohibit dissemination of private and confidential data, it also requires a governmental entity‘s responsible authority to “establish appropriate security safeguards” to ensure that only appropriate persons access government data.
Although DHS did not address liability under subdivision 5(a)(2) in its brief, it contended at oral argument that determining whether information safeguards are appropriate under the statute is a legal question and that the district court properly denied the claim as a matter of law. The contention rests on one doubtful basis and one erroneous basis: we would have to both infer that the district court denied the claim as a matter of law and also hold that it could rightly do so. This we cannot do.
The notion that the district court implicitly denied the appropriate-safeguard claim as a matter of law is doubtful because it framed DHS‘s argument for dismissal as challenging the dissemination claim specifically. The district court not only did not include
But even if we infer from the district court‘s dismissal of the complaint entirely that it implicitly rejected the appropriate-safeguard claim as a matter of law, we reject DHS‘s position that the district court could do so appropriately. This is because whether DHS‘s safeguards were “appropriate” in this case is not subject to dismissal for failure to state a claim. The statute neither defines “appropriate” nor presents any specific elements of what qualifies as an appropriate safeguard or what would fail as an inappropriate one. This is not surprising given the nature of the adjective. “Appropriate” is akin to “reasonable,” being a nearly synonymous, relative term with meaning only in the context of its case-by-case circumstances. The legislature frequently demonstrates that it treats both terms as situational. See, e.g.,
Likewise courts customarily treat the terms as dependent on the circumstances and determined as a matter of fact, not as a matter of law. See, e.g., King‘s Cove Marina, LLC v. Lambert Com. Constr. LLC, 958 N.W.2d 310, 321 (Minn. 2021) (“Reasonableness is a question of fact for the district court to resolve as the fact-finder.” (quotation omitted)); Kolstad v. Fairway Foods, Inc., 457 N.W.2d 728, 735-36 (Minn. App. 1990) (“Thus, it is incumbent upon the fact-finder to examine carefully . . . the appropriateness of hours spent and the hourly rate requested.“); W. Nat‘l. Ins. Co. v. Thompson, 797 N.W.2d 201, 208 (Minn. 2011) (“[W]e conclude that whether a request for an examination under oath and the refusal of such a request are reasonable are questions of fact. . . .“); Costilla v. State, 571 N.W.2d 587, 596 (Minn. App. 1997), review denied (Minn. Jan. 28, 1998) (observing that “a question of fact exists as to the . . . appropriateness of the state‘s actions“); Nicollet Restoration, Inc. v. City of St. Paul, 533 N.W.2d 845, 848 (Minn. 1995) (“Ordinarily, the reasonableness of reliance is a fact question for the jury.“). Given the plain meaning of the term and the manner in which the legislature and courts commonly apply it, we hold that the question of whether the state has established “appropriate” safeguards to prevent
We offer no opinion about whether, in some cases, the circumstances might present a clear picture demonstrating that the evidence could not, as a matter of law, support a factual finding of inappropriateness. But at most, the question of appropriateness might then remain a matter for summary judgment on developed, undisputed facts. The facts of the claim in this case are not developed at the early stage of the rule 12 dismissal. Under rule 12 we answer only whether the complaint states a claim for legal relief. And we hold that Smallwood‘s complaint alleges facts that could establish a statutory violation under
We turn to whether Smallwood‘s complaint sufficiently asserted a claim for damages. The district court concluded that it did not. It reached this conclusion two months before, and therefore without the insight provided by, the supreme court‘s decision in Halva, 953 N.W.2d at 498. We think Halva controls and requires reversal.
A person who “suffers any damage” resulting from a responsible authority‘s or government entity‘s violating “any provision” of the MGDPA is entitled to damages.
The supreme court‘s analysis in Halva informs our reasoning, as it held sufficient a complaint with a damages claim no more robust or precise than Smallwood‘s. The complaint in Halva, like the complaint here, was “sparse with details and [did] not contain a direct causal statement explaining how those violations caused [the plaintiff] harm.” 953 N.W.2d at 503. But also like the complaint here, the Halva complaint “sufficiently identified the facts that gave rise to [the plaintiff‘s] claim” because it “list[ed] a number of facts that could support a finding of a Data Practices Act violation.” Id. Although the Halva complaint‘s claim for damages asserted only that the plaintiff is “entitled to an award of any actual damages plus exemplary damages for each . . . violation of the Data Practices Act,” id. at 502 (alterations omitted), the court held that the “complaint provide[d] the factual nexus for [the] alleged damages” and was therefore “sufficient under our normal pleading standard,” id. at 503. Smallwood‘s complaint describes his purported emotional distress in vague and conclusory terms, but the Halva court reminded us that, “[u]nder our law, the pleading of broad general statements that may be conclusory is permitted.” Id. (quoting Barton v. Moore, 558 N.W.2d 746, 749 (Minn. 1997)). Because Smallwood identified an MGDPA violation and alleged resulting damages sufficient to put DHS on notice of his legal claim, the claim in part survives DHS‘s motion to dismiss for failure to state a claim.
In sum, Smallwood‘s complaint adequately put DHS on notice of his claim that DHS violated the MGDPA‘s duty to appropriately secure his private and confidential data, which resulted in a breach that caused emotional damages. We do not suggest that the allegations are a model of precision or that the complaint appears to map a clear course of success on the merits. We say only that the complaint passes the minimum notice-pleading requirements to overcome a rule 12 motion to dismiss.
II
Smallwood contends that he sufficiently stated a claim under the HRA and that sovereign immunity does not prevent an HRA claim. We resolve the appeal as to this claim based on sovereign immunity alone.
Sovereign immunity is a judicial creation generally shielding the state from civil liability in all claims except those to which the state has consented to suit. Nieting v. Blondell, 235 N.W.2d 597, 600, 603 (Minn. 1975).
Our de novo review of the HRA under this framework leads us to conclude that the legislature did not intend to waive sovereign immunity to allow state liability for HRA claims. Under the operative liability provision of the HRA, “a person” who “negligently . . . releases a health record in violation of sections 144.291 to 144.297” is liable to the patient for compensatory damages resulting from the unauthorized release.
Smallwood ushers us on a circuitous journey hoping to arrive at state civil liability under the HRA. Leaving the plainly worded directive that a “person” can be liable under the act, Smallwood takes us to another provision of the chapter, observing that “a provider, or a person who receives health records from a provider, may not release a patient‘s health records” unless authorized by the patient or by law.
We do not disagree with the conclusion that DHS operates a qualifying healthcare facility licensed under chapter 144 and that it may not release health records without authorization. But the meandering venture linking a liable “provider” under section 144.293, a “health care facility” under section 144.291, a “hospital” under section 144.50, an “institution” providing institutional care under section 144.50, and a government “department” requiring licensure under section 144.50, is too dizzyingly attenuated for us to say that it plainly, clearly, and unmistakably expresses the legislature‘s intent—beyond doubt—to waive sovereign immunity. We know that, by comparison, the legislature knows how to strike a simple course from violation to state liability in unmistakable terms: the
Similarly unconvincing are Smallwood‘s three other arguments against sovereign-immunity waiver. We briefly address each.
We reject Smallwood‘s contention that state liability derives from
We also reject his argument that the legislature abrogated sovereign immunity by allowing for vicarious liability. The HRA prohibits “[a] provider, or a person who receives health records from a provider” from releasing health records without authorization.
And finally we reject Smallwood‘s related contention based on caselaw. He asserts that Expose v. Thad Wilderson & Associates, P.A. establishes vicarious liability under the HRA. 863 N.W.2d 95, 104-05 (Minn. App. 2015), aff‘d (Minn. Nov. 3, 2016). It does not. We did not discuss vicarious liability in Expose. We held merely that, because the appellant had not consented to a disclosure, the district court improperly concluded that the respondent was entitled to judgment as a matter of law on appellant‘s vicarious-liability allegation. Id. Smallwood‘s contention that vicarious liability is available under Larson v. Northwest Mutual Life Ins. Co. fails for the same reason. 855 N.W.2d 293, 301-02 (Minn. 2014). Although the court said that “under the plain meaning of the [HRA], liability arises only when a person or entity actually discloses a health record” (emphasis added), this was dicta and not binding. Id. at 302; Brink v. Smith Cos. Const., Inc., 703 N.W.2d 871, 876 (Minn. App. 2005), review denied (Minn. Dec. 21, 2005). The “only question before [the
We observe that determining the types of damages to which Smallwood would be entitled if he should prove his claims is premature. We generally review a damages award for an abuse of discretion. See, e.g., Dunn v. Nat‘l Beverage Corp., 745 N.W.2d 549, 555 (Minn. 2008). Because the district court dismissed Smallwood‘s complaint entirely, it did not consider his request for different types of damages. Nor do we.
DECISION
Smallwood alleged facts and damages that could establish a violation of the Minnesota Government Data Practices Act. The district court therefore erroneously dismissed his data-practices claim. The state did not waive its sovereign immunity for claims under Minnesota Health Records Act. The district court therefore correctly dismissed Smallwood‘s health-records claim.
Affirmed in part and reversed in part.