Fox, Yvonne v. Iowa Health SystemFox, Yvonne v. Iowa Health System
Defendant UnityPoint Health runs a network of hospitals, clinics, home care services, and health insurers throughout Wisconsin, Iowa, and Illinois. In 2017 and 2018, UnityPoint‘s email system was hacked. Plaintiffs, all customers of UnityPoint, say that hackers obtained their private health information and other personal identifying information (such as Social Security numbers) that can be used to commit identity theft. Plaintiffs filed this proposed class action, asserting 14 different claims under Wisconsin, Illinois, and Iowa law. UnityPoint moves to dismiss under
The court will grant the motion only in part. Plaintiffs allegations are sufficient to establish standing under Article III of the Constitution. The court will dismiss some of plaintiffs’ claims for failure to state a claim: (1) Shelly Kitsis and Danielle Duckley‘s claims for negligence and negligence per se because they are barred by the Illinois and Iowa economic loss doctrines; (2) plaintiffs’ claims for invasion of privacy because they do not allege that UnityPoint intentionally released their information; (3) plaintiffs’ common law and statutory misrepresentation claims because plaintiffs have not pleaded reliance or damages; and (4) plaintiffs’ claim under Wisconsin‘s data breach notification statute,
Also before the court is plaintiffs’ notice of supplemental authority, Dkt. 51, and UnityPoint‘s motion for leave to respond to the supplemental authority, Dkt. 52, which plaintiffs oppose. Plaintiffs’ motion is granted; UnityPoint‘s is denied. But the supplemental authority is a district court case from outside this jurisdiction which addresses the issue of standing in data breach cases. There is already binding authority in this jurisdiction on the issue of standing, so the supplemental authority adds little to the analysis. UnityPoint has also its own notice of supplemental authority. Dkt. 54. The court will accept UnityPoint‘s supplemental authority, but it too adds little to the analysis. That case is about standing to sue for violations of the Fair Credit Reporting Act. It did not involve a data breach, or any other allegations that are analogous to this case.
ALLEGATIONS OF FACT
The court draws the following facts from plaintiffs’ amended complaint. Dkt. 22.
A. First data breach
Around November 1, 2017, hackers gained access to UnityPoint employee email accounts and stole the personal health information of more than 16,000 UnityPoint patients. The hackers were “motivated to steal” and “specifically targeted” health information and other sensitive information like Social Security numbers. Id., ¶ 24. UnityPoint discovered the data breach between February 7 and February 15, 2018, but it did not notify the public until two months later, when it sent a letter to those affected by the breach. The letter stated:
[UnityPoint] discovered your protected health information was contained in an impacted email account, including your name and one or more of the following: date of birth, medical record number, treatment information, surgical diagnosis, lab results, medication(s), provider(s), date(s) of service and/or insurance information . . . . The information did not include your Social Security number.
Id., ¶¶ 20-21. UnityPoint knew that this letter was not accurate. On the same day that it sent the letter, it disclosed to the Wisconsin Department of Agriculture, Trade and Consumer Protection that the breach actually did include Social Security numbers.
Fox and Nesheim each received a copy of the letter. Fox called UnityPoint to get more information about what specific health information had been stolen. She spoke to two representatives, but neither was able to give her further information about the breach. Both representatives told her to “take precautions to protect [her] information.” Id., ¶¶ 55, 58. Fox asked if UnityPoint would pay for any “precautions,” and UnityPoint said that it would not. After these conversations, Fox subscribed to an online credit monitoring service so that she could be notified of any future identity theft. Id., ¶ 63.
B. Second data breach
On May 31, 2018, UnityPoint discovered that hackers had again accessed its employee‘s email accounts. This time, hackers stole the private information of about 1.4 million patients. Once again, UnityPoint waited two months before it disclosed the breach to the public. On July 30, it sent a letter to affected class members:
[Stolen information] included your name and one or more of the following information: address, date of birth, Social Security number, driver‘s license number, medical record number, medical information, treatment information, surgical information, diagnosis, lab results,
medication(s), provider(s), date(s) of service and/or insurance information
Id., ¶ 33.
The letter advised recipients to protect themselves against identity theft by monitoring their health information. UnityPoint also offered a complimentary, one-year membership with Experian, which provides identity-theft prevention services. All four plaintiffs received a copy of this letter.
C. Incidents following the data breaches
Since the data breaches, plaintiffs have been victims of attempted identity theft and fraud as well as scam phone calls and emails.
In 2018, Fox noticed an increase in autodialed phone calls and spam emails. From April 13 to July 7, she received about 63 autodialed calls to her landline. Several of these calls came from a number identified as “BC Health Clinics,” and involved a medical scam. Id., ¶ 52. (Plaintiffs do not provide any further detail about the medical scam.) Fox did not receive any scam medical calls before the data breaches.
Nesheim also received more autodialed calls after the data breaches. These calls were so frequent that Nesheim bought a second phone to use for work. In May or June 2018, Nesheim discovered a suspicious charge on his credit card. He canceled his card and asked his bank to issue a new one. Later, in early July, Nesheim was notified that someone had used his private health information to open a new credit card at a different bank. Nesheim is currently working with that bank to ensure that it did not keep open an account in his name. Had Nesheim known about the data breaches as soon as they occurred, he would have “made a timely and informed decision to take action to mitigate the injury.” Id., ¶ 73.
Duckley also received more spam emails and autodialed phone calls after the data breaches. After the second data breach, Duckley became locked out of her pre-existing Experian account due to repeated, unauthorized log-in attempts. When Duckley called Experian to change her password and regain access to the account, Experian told her that the UnityPoint data breach “had undoubtedly been the cause” of the repeated log in attempts. Id., ¶ 76. Had Duckley known about the second data breach as soon as it occurred, she would have “made a timely and informed decision to take action to mitigate the injury.” Id., ¶ 79. Finally, Kitsis, like the other plaintiffs, received more spam emails and autodialed phone calls after the data breaches. Also, her health information is “extraordinarily sensitive,” and the stress caused by the data breach is taking a “significant emotional and physical toll.” Id., ¶ 84.
The threat of identity theft is exacerbated by what hackers refer to as “fullz packages.” Id., ¶ 66. A fullz package is a dossier that compiles information about a victim from a variety of legal and illegal sources. Hackers can take information obtained in one data breach and cross-reference it against information obtained in other hacks and data breaches. So, for example, if a hacker obtains a victim‘s Social Security number and health information from UnityPoint, the hacker can combine it with the same victim‘s Social Security number and phone number from a different data breach. This allows the hacker to compile a full record of information about the individual, which the hacker then sells to others as a package.
The court will discuss additional facts as they become relevant to the analysis.
ANALYSIS
UnityPoint moves to dismiss plaintiffs’ complaint for lack of standing and for
A. Standing
Plaintiffs bear the burden to establish standing to sue in federal court. Lee, 330 F.3d at 468. Standing requires (1) an injury in fact, (2) that is fairly traceable to the challenged conduct of the defendant, and (3) that is likely to be redressed by a favorable judicial decision. See Spokeo, Inc. v. Robins, 136 S. Ct. 1540, 1547 (2016). UnityPoint contends that plaintiffs cannot establish the first two elements.
1. Injury in fact
“To establish injury in fact, a plaintiff must show that he or she suffered an invasion of a legally protected interest that is concrete and particularized and actual or imminent, not conjectural or hypothetical.” Spokeo, 136 S. Ct. at 1548 (quoting Lujan v. Defenders of Wildlife, 504 U.S. 555, 560 (1992) (internal quotation marks omitted)). “Allegations of possible future injury are not sufficient.” Clapper v. Amnesty Int‘l USA, 568 U.S. 398, 409 (2013) (emphasis in original; internal quotations omitted). An injury must be “certainly impending” to constitute an injury in fact. Id.
Plaintiffs have alleged several injuries: lost time due to increased spam calls and emails, time spent dealing with fraud attempts, the threat of future identity theft, and money spent mitigating that threat. Any of these allegations would be sufficient to establish standing; even an “identifiable trifle” can constitute an injury in fact. Craftwood II, Inc. v. Generac Power Sys., Inc., 920 F.3d 479, 481 (7th Cir. 2019) (holding that the time lost reading a junk fax before discarding it is a concrete injury) (quoting United States v. SCRAP, 412 U.S. 669, 689 n.14 (1973)). And the Court of Appeals for the Seventh Circuit has repeatedly held that injuries like plaintiffs’ injuries are sufficient to establish standing in data breach cases. For example, in Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir. 2015), and Lewert v. P.F. Chang‘s China Bistro, Inc., 819 F.3d 963 (7th Cir. 2016), hackers stole customer credit-card data from the defendant business. Some customers experienced fraudulent charges on their cards. Their banks reversed the charges, but even with no monetary loss, the customers suffered an injury in the time spent resolving the fraudulent charges. Lewert, 819 F.3d at 967. The other customers, who did not experience fraudulent charges, still faced the impending risk of future identity theft. Id. at 966. After the data breach, the risk of fraud was more than speculative. “[P]laintiffs ‘should not have to wait until hackers commit identity theft or credit-card fraud in order to give the class standing, because there is an objectively reasonable likelihood that such injury will occur.‘” Lewert, 819 F.3d at 966 (quoting Remijas, 794 F.3d at 693). The risk of future harm was also evident from the statements of the
UnityPoint argues that under Remijas and Lewert, the threat of identity theft is not an injury in fact unless plaintiffs allege that hackers “specifically targeted” personal information and that “a certain percentage of that information [was] used to commit fraud.” Dkt. 28, at 21. But Remijas and Lewert did not create a special test for data breach cases. The ultimate question is the same as any case in which a plaintiff alleges a threat of future injury: whether there is an “objectively reasonable likelihood” that an injury will occur. Remijas, 794 F.3d at 693 (quoting Clapper, 568 U.S. at 410). And in this case, plaintiff have alleged facts sufficient to establish an objectively reasonable likelihood of future identity theft. Personal information, including Social Security numbers, was stolen in the data breaches. The breaches were serious enough that UnityPoint offered identity-theft protection services to the affected customers. And plaintiffs say that thieves used the information to target Fox for a medical scam, open a new credit card in Nesheim‘s name, and attempt to gain access to Duckley‘s Experian account. Even if plaintiffs had not already lost time resolving fraud attempts and answering spam calls, the looming threat of fraud would qualify as an injury in fact.
2. Fairly traceable
UnityPoint says that hackers may have obtained plaintiffs’ information from other sources, and that plaintiffs cannot show that any of their alleged injuries were caused by the UnityPoint data breaches. In the context of standing, the complaint need only allege that “but for” some act or omission of the defendant, the injury would not have occurred. See, e.g., Lac du Flambeau Band of Lake Superior Chippewa Indians v. Norton, 422 F.3d 490, 501 (7th Cir. 2005). If a defendant puts forth evidence that challenges standing as a factual matter, then the burden shifts to the plaintiff to “come forward with competent proof that standing exists.” Laurens v. Volvo Cars of N. Am., LLC, 868 F.3d 622, 626 (7th Cir. 2017) (quoting Apex Digital, Inc. v. Sears, Roebuck & Co., 572 F.3d 440, 444 (7th Cir. 2009)) (internal alterations omitted).
UnityPoint says that it has put forth unrebutted evidence that challenges plaintiffs’ allegations of causation: a declaration from UnityPoint‘s privacy officer that says that no email addresses, passwords, credit card numbers, or “account login information” were stolen in the data breach, Dkt 29, ¶¶ 5-6, and screenshots of Fox‘s personal website that show that her email address and phone number are publicly available, Dkt. 11. This evidence casts doubt on the traceability of some of plaintiffs’ allegations, namely the increases in spam calls and emails (particularly those received by Fox, who published her contact information) and the fraudulent charge on Nesheim‘s credit card (because credit card numbers weren‘t included in the breach). But UnityPoint has not rebutted plaintiffs’ allegations that hackers also stole patient names, addresses, Social Security numbers, dates of birth, and medical records. Plaintiffs have plausibly alleged injuries that can be linked to this information.
Furthermore, UnityPoint‘s evidence does not challenge plaintiffs’ allegations that hackers cross-referenced the data from the breaches and combined it with data from other sources to create “fullz packages.” Id., ¶¶ 66-67. UnityPoint argues that the court is not required to accept these allegations as true in a motion under
In the end, UnityPoint may be correct that some other entity exposed the plaintiffs’ private information and is responsible for the injuries listed in the complaint. But that is an issue of causation that will need to be resolved at trial or summary judgment. At this stage plaintiffs have alleged injuries that are fairly traceable to UnityPoint‘s data breaches.
B. Failure to state a claim
Plaintiffs assert 14 claims: (1) negligence, (2) negligence per se, (3) violation of Wisconsin‘s confidentiality of health records statute, (4) violation of Wisconsin, Illinois, and Iowa‘s breach notification statutes, (5) invasion of privacy, (6) misrepresentation, (7) breach of contract, (8) breach of the covenant of good faith and fair dealing, (9) violation of the Wisconsin Deceptive Trade Practices Act, (10) violation of the Illinois Uniform Deceptive Trade Practices Act, (11) violation of the Illinois Consumer Fraud and Deceptive Business Practices Act, (12) violation of Iowa‘s consumer fraud statute, (13) unjust enrichment, and (14) declaratory relief.
UnityPoint moves to dismiss all 14 claims under
1. Choice of law
Before the court turns to the specific claims, it must consider a preliminary issue: choice of law. The parties agree that Wisconsin law applies to the claims of Fox, Nesheim, and the prospective Wisconsin class members, but they disagree about whether Wisconsin law also applies to the plaintiffs in Illinois and Iowa. Plaintiffs say that Wisconsin law should apply to all plaintiffs. UnityPoint says that Illinois law should apply to Duckley and the prospective Illinois class members, and that Iowa law should apply to Kitsis and the prospective Iowa class members.
Because Wisconsin is the forum state, the court applies Wisconsin‘s choice-of-law rules. Auto-Owners Ins. Co. v. Websolv Computing, Inc., 580 F.3d 543, 547 (7th Cir. 2009). Under Wisconsin law, choice-of-law decisions are made on an issue-by-issue basis. BB Syndication Servs., Inc. v. First Am. Title Ins. Co., 780 F.3d 825, 829 (7th Cir. 2015). If the laws of the competing states are the same on a given issue, then the court applies Wisconsin law on that issue. Id. But if the states disagree on a given issue, then there are two tests that Wisconsin courts apply to determine which law applies. Beloit Liquidating Tr. v. Grade, 2004 WI 39, ¶ 24, 270 Wis. 2d 356, 677 N.W.2d 298. The relationship between the two tests is not entirely clear, but in this case they lead to the same result.
The first test requires the court to consider “whether the contacts of one state to the facts of the case are so obviously limited and minimal that application of that state‘s law constitutes officious intermeddling.” Drinkwater v. Am. Family Mut. Ins. Co., 2006 WI 56, ¶ 41, 290 Wis. 2d 642, 714 N.W.2d 568 (quoting Beloit Liquidating, 2004 WI 39, ¶ 24). An alternative version of this test, which applies to contract claims, requires the court to apply Wisconsin law “unless it becomes clear that nonforum contacts are of the greater significance.” Id., ¶ 40. Both versions lead to the same conclusion. UnityPoint (an Iowa corporation) provided services to the Illinois and Iowa plaintiffs in their home states. Those plaintiffs, and their claims against UnityPoint, have no connection to the state of Wisconsin, except that they were lumped into this lawsuit with the Wisconsin plaintiffs. But they do have significant connections to the plaintiffs’ home states, where the plaintiffs lived, received services, and allegedly suffered injuries as a result of UnityPoint‘s actions. The application of Iowa and Illinois law to this case would not constitute any officious intermeddling with Wisconsin.
The second test requires the court to consider five factors to determine which state‘s laws apply: (1) predictability of results; (2) maintenance of interstate and international order; (3) simplification of the judicial task; (4) advancement of the forum‘s governmental interests; and (5) application of the better rule of law. Beloit Liquidating, 2004 WI 39, ¶ 25. The importance of each factor will vary depending upon the specific facts of the case. Id.
In this case, these factors weigh in favor of applying the laws of the nonforum states to the nonforum plaintiffs. The predictability factor deals with the parties’ expectations, Drinkwater, 2006 WI 56, ¶ 46, and UnityPoint could not have predicted that Wisconsin law would apply to its business with customers in Illinois or Iowa. Likewise, it would interfere with interstate order to supplant the laws of the nonforum states with Wisconsin law. See Heath v. Zellmer, 35 Wis. 2d 578, 151 N.W.2d 664, 672 (1967) (“[F]or a state that is only minimally concerned with a transaction or tort to thrust its law upon the parties would be disruptive of the comity between states.“). Plaintiffs say that Wisconsin has a governmental interest in applying Wisconsin law, but they do not explain why this interest would extend to UnityPoint customers who do not reside in, or have any connection with, the state of Wisconsin. And it‘s not clear that any state has a “better” rule of law; this factor requires the court to consider which law “most adequately does justice to the parties and has the greatest likelihood of being applicable with justness in the future.” Beloit Liquidating, 2004 WI 39, ¶ 31. It‘s not clear that this is true for any of the states in question. Only one factor weighs in favor of applying Wisconsin law to all plaintiffs: it would be
Plaintiffs argue that UnityPoint has not identified any conflict between the laws of Wisconsin, Illinois, and Iowa. But as plaintiffs point out (and extensively briefed), all three states recognize different versions of the economic loss doctrine. Dkt. 39, at 22-24. And, as the court will explain below, small variations exist between the states on other issues. Where these variations exist, the court will apply the laws of the nonforum states to the nonforum plaintiffs.
2. Economic loss doctrine
UnityPoint contends that in Illinois and Iowa the economic loss doctrine bars plaintiffs’ claims for negligence, negligence per se, misrepresentation, and invasion of privacy. (Wisconsin also follows the economic loss doctrine, but the parties agree that Wisconsin‘s version of the rule does not apply to contracts for services.) The court agrees that the economic loss doctrine applies to the claims for negligence and negligence per se, and it will dismiss those claims for plaintiffs Duckley and Kitsis. The court will dismiss the misrepresentation and invasion-of-privacy claims on other grounds (discussed below), so it need not decide whether the economic loss doctrine applies to them.
The economic loss doctrine bars a plaintiff from using a tort claim to recover purely economic losses arising from a contractual relationship. In re Michaels Stores Pin Pad Litig., 830 F. Supp. 2d 518, 528 (N.D. Ill. 2011) (applying Illinois law); Nebraska Innkeepers, Inc. v. Pittsburgh-Des Moines Corp., 345 N.W.2d 124, 128 (Iowa 1984). The rationale is that “tort law affords a remedy for losses occasioned by personal injuries or damage to one‘s property, but contract law and the Uniform Commercial Code offer the appropriate remedy for economic losses occasioned by diminished commercial expectations not coupled with injury to person or property.” In re Illinois Bell Switching Station Litig., 641 N.E.2d 440, 444 (Illinois 1994). See also Annett Holdings, Inc. v. Kum & Go, L.C., 801 N.W.2d 499, 503 (Iowa 2011) (the rule is intended to avoid the “tortification of contract law“). The economic loss doctrine has been applied to dismiss negligence claims in several data breach cases across the country, including claims brought under Illinois and Iowa law. See In re Target Corp. Data Sec. Breach Litig., 66 F. Supp. 3d 1154, 1171-76 (D. Minn. 2014) (collecting cases).
Plaintiffs say that Iowa recently abandoned the doctrine when it adopted the Restatement (Third) of Torts. They rely on an unpublished federal district court case that predicts that Iowa courts will stop using the economic loss rule in the future. See Cont‘l W. Ins. Co. v. Cont‘l Fire Sprinkler Co., No. 4:10-CV-00584-TJS, 2013 WL 12092291, at *1 (S.D. Iowa Mar. 27, 2013). But more recently, the Iowa Supreme Court revisited the economic loss doctrine and described its continued applicability (subject to exceptions that do not apply here). St. Malachy Roman Catholic Congregation of Geneseo v. Ingram, 841 N.W.2d 338, 351 (Iowa 2013). Because the Iowa Supreme Court says that it still follows the doctrine, the court will apply it to Kitsis‘s Iowa claims as well as Duckley‘s Illinois‘s claims.
Plaintiffs give three reasons why the doctrine should not apply in this case, but none of them are persuasive. First, plaintiffs say that they have suffered the following non-economic damages: drained phone batteries from an increase in spam calls; lost time; loss in the value of their
Second, plaintiffs cite Cmty. Bank of Trenton v. Schnuck Markets, Inc., 887 F.3d 803, 812 (7th Cir. 2018) (applying Illinois and Missouri law), for the proposition that the economic loss doctrine applies only in cases where the parties have negotiated and established contractual remedies for the underlying harm. But the Trenton court did not hold that—it concluded that the doctrine applied even though the plaintiffs in that case did not have any direct contract with the defendant. Id. at 814. Instead, both parties had contracts with the same third parties, and because they had the opportunity to negotiate remedies as part of those contracts, the economic loss doctrine barred the introduction of new remedies under a theory of tort. The same logic applies here: the plaintiffs had a contract with UnityPoint for health services, and the parties had an opportunity to include a remedy for data breaches as part of their contract but chose not to.
Third, plaintiffs say that the doctrine does not apply to Duckley or the proposed Illinois class because UnityPoint had a preexisting duty to protect patient health records under federal law. (Although neither party identifies the federal law in question, plaintiffs are presumably referring to the Health Insurance Portability and Accountability Act.) Plaintiffs argue that Illinois has an exception to the economic loss doctrine for duties that exist independent of any contract. See Congregation of the Passion v. Touche Ross & Co., 636 N.E.2d 503, 515 (Illinois 1994). But this exception applies only in professional malpractice cases, such as claims for legal malpractice, in which the defendant is a member of a skilled profession and has a duty of reasonable professional competence. Michaels Stores, 830 F. Supp. 2d at 529-30; see also Trenton, 887 F.3d at 817 (adopting the Michaels Stores court‘s interpretation of Illinois law). It does not apply simply because UnityPoint violated a federal statute.
3. Negligence under Wisconsin law
UnityPoint contends that Fox and Nesheim‘s claims for negligence and negligence per se must be dismissed because plaintiffs have failed to allege “actual damages.” But
4. Wisconsin confidentiality of health records statute
Wisconsin Statute § 146.82(1) says that patient health care records may be released only with the informed consent or authorization of the patient, or to persons otherwise designated by the statute. Any person who negligently violates the statute “shall be liable to any person injured as a result of the violation for actual damages to that person, exemplary damages of not more than $1,000 and costs and reasonable actual attorney fees.”
5. Invasion of privacy
The court will dismiss plaintiffs’ claims for invasion of privacy because plaintiffs have not alleged that UnityPoint intentionally disclosed their private information. None of the plaintiffs’ home states recognize a claim for invasion of privacy for negligent or reckless behavior that results in a third party‘s disclosure of plaintiffs’ private information
The parties focus on Wisconsin law, so the court will start there. In Wisconsin, torts related to the invasion of privacy are codified under
Section 995.50 does not specify whether the first element of this claim requires intentional disclosure by the defendant. But
Plaintiffs nonetheless say that
Second, plaintiffs say that in Pachowitz, 2003 WI App 120, ¶ 29, the court held a defendant liable for reckless disclosure of private information. But there was no dispute in that case that the defendant intentionally disclosed the plaintiff‘s private information. Rather, the issue was whether the defendant acted “recklessly as to whether the information was of legitimate public interest” when he decided to share it with others. Id. ¶¶ 28-30.2 Plaintiffs’ invasion-of-privacy claims likewise fail under Illinois and Iowa law. In Illinois, there is no common law duty to safeguard personal information from third-party disclosure. Trenton, 887 F.3d at 816 (citing Cooney v. Chicago Public Schools, 943 N.E.2d 23, 29-29 (Ill. App. Ct. 2010)). Plaintiffs cite Ainsworth v. Century Supply Co., 693 N.E.2d 510, 515 (Ill. App. Ct. 1998), but the cited passage refers to the standard for applying punitive damages under Illinois law. Nothing in that case says that a defendant can be held liable for recklessly allowing a third party to invade one‘s privacy.
Plaintiffs say that Iowa courts have not decided whether an invasion-of-privacy claim requires the defendant to intentionally publish private information, but that “one would expect Iowa law to follow the same approach as Wisconsin and Illinois.”3 Dkt. 39, at 31. The court agrees with this assessment, but unfortunately for plaintiffs, neither Wisconsin or Illinois allows claims for negligent or reckless publication of private information. So the court will dismiss all the invasion-of-privacy claims.
6. Fraud and misrepresentation claims
Plaintiffs assert five claims related to alleged misrepresentations made by UnityPoint: (1) common law misrepresentation, (2) violation of the Wisconsin Deceptive Trade Practices Act, (3) violation of the Illinois Consumer Fraud and Deceptive Business Practices Act, (4) violation of the Iowa Consumer Fraud Act, and (5) violation of the Illinois Uniform Deceptive Trade Practices Act. UnityPoint says that all five claims are subject to heightened3
pleading standards under
The court need not decide the pleading standard issue because even under
a. Common law misrepresentation and consumer fraud statutes
The court starts with plaintiffs’ claim for misrepresentation, together with claims for violation of the
In Wisconsin, a claim for intentional or negligent misrepresentation requires plaintiffs to prove that (1) the defendant made a representation of fact; (2) that was untrue; and (3) that plaintiffs relied on it to their damage. Ollerman v. O‘Rourke Co., Inc., 94 Wis. 2d 17, 25, 288 N.W. 2d 95, 99 (1980). Plaintiffs must also prove reliance to prevail on a misrepresentation claim under Illinois or Iowa law.4
A claim under the
Plaintiffs say that the
With that legal background, the court turns to plaintiffs’ allegations. Plaintiffs allege that UnityPoint made two different sets of misrepresentations. First, plaintiffs say that UnityPoint intentionally misrepresented the scope of the breaches by telling customers that the first data breach did not include Social Security numbers and that the second breach did not affect its electronic medical record system. Plaintiffs say that they “believed the statements to be true and relied on them to their detriment,”
Second, plaintiffs allege that UnityPoint‘s privacy policy misrepresented that health care records were “stored in a secure database” that could be accessed by only a few computer technicians. Id., ¶¶ 117, 156. Again, plaintiffs have not alleged facts showing that they relied on these statements or that the statements caused them damage. None of the plaintiffs say that the privacy policy was a factor in their decision to choose UnityPoint as a healthcare provider, or that they were even aware of the policy before the data breach. Plaintiffs alleged facts showing that UnityPoint violated the privacy policy, as discussed below, but that is unrelated to whether the alleged misrepresentations themselves caused damages.
Because the alleged facts fail to show any reliance by plaintiffs, or any link between the alleged misrepresentations and the damages suffered by plaintiffs, the court will dismiss plaintiffs’ claims for misrepresentation and violation of the consumer fraud statutes.
b. Illinois Uniform Deceptive Trade Practices Act
Duckley contends that UnityPoint‘s misrepresentations about its security procedures violate the
In this case, Duckley says that UnityPoint has shown a repeated pattern of dishonesty by misrepresenting the scope of its breaches, exaggerating the actions it took in response to the first breach, and continuing to represent that it keeps patient health information in a secure database. In short, UnityPoint “has a history of making empty promises to patients that it will secure their [information] without actually doing so.” Dkt. 39, at 27. But even if UnityPoint continues to make similar misrepresentations in the future, Duckley does not explain how this creates a likelihood of future damage to her. She argues that UnityPoint‘s misrepresentations leave her unaware about the full scope of the data breaches and whether her data is protected from future unauthorized access. But these arguments go to the risk of harm that Duckley faces from the data
7. Breach notification statutes
Plaintiffs assert claims for violations of Wisconsin‘s, Illinois‘s, and Iowa‘s data breach notification statutes. The court will dismiss all three claims. The Wisconsin statute does not create a private right of action, and plaintiffs have not alleged facts showing that they suffered damages as a result of UnityPoint‘s violation of the Illinois and Iowa statutes.
a. Wisconsin‘s notification statue
Under Wisconsin law, a statute provides a private right of action only if there is a clear indication of the legislature‘s intent to create such a right. Grube v. Daun, 210 Wis. 2d 681, 563 N.W.2d 523, 526 (1997). “[T]he general rule is that a statute which does not purport to establish a civil liability, but merely makes provision to secure the safety or welfare of the public as an entity, is not subject to a construction establishing a civil liability.” Id. at 689 (quoting McNeill v. Jacobson, 55 Wis. 2d 254, 198 N.W.2d 611, 614 (1972)). An implied right of action is created only when (1) the language or the form of the statute indicates the legislature‘s intent to create a private right of action, and (2) the statute establishes private civil liability rather than merely providing for protection of the public. Miller Aviation v. Milwaukee Cty. Bd. of Supervisors, 273 F.3d 722, 729 (7th Cir. 2001) (citing Grube, 563 N.W.2d at 526).
b. Illinois and Iowa data breach statutes
Unlike the Wisconsin statute, the
The only courts to have interpreted the
Both Illinois and Iowa require a company to notify its customers of a data breach “without unreasonable delay,”
8. Contract claims
Plaintiffs assert claims for breach of contract and breach of the covenant of good faith and fair dealing. The court will allow plaintiffs to proceed on both claims.
To state a claim for breach of contract, plaintiffs must allege: “(1) the existence of a valid and enforceable contract; (2) substantial performance by the plaintiff; (3) a breach by the defendant; and (4) resultant damages.” Reger Dev., LLC v. Nat‘l City Bank, 592 F.3d 759, 764 (7th Cir. 2010). Plaintiffs say that the data breaches were caused when UnityPoint breached its privacy policy. UnityPoint says that the privacy policy is not a contract, that it did not breach the policy, and that there are no damages. As already explained above, plaintiffs have adequately alleged that they were damaged by the data breach. So at this point the court need consider only the other two disputed elements.
UnityPoint makes three arguments for why its privacy policy is not an enforceable contract. None are persuasive. First, it says that plaintiffs bought health services, not privacy services, and that there was no separate consideration for the terms of the privacy policy. But plaintiffs do not claim that the privacy policy is a wholly independent contract. Rather, they contend that the policy was incorporated into their contract for health services, and that because they gave consideration for the contract for health services, they do not need to show independent consideration for the privacy policy. Dkt. 39, at 29 (citing Dolmage v. Combined Ins. Co. of Am., No. 14 C 3809, 2016 WL 754731, at *9 (N.D. Ill. Feb. 23, 2016)). UnityPoint does not respond to this argument. Plaintiffs’ allegation that UnityPoint gave each customer a written copy of its privacy policy is sufficient for the court to reasonably infer that the parties intended to incorporate the policy into their contract for health services.
Second, UnityPoint argues that its privacy policy is merely a statement of preexisting legal obligations. The parties agree that one cannot form a contract by simply promising to follow the law, see, e.g., Johnson v. Maki & Assocs., Inc., 682 N.E.2d 1196, 1199 (Ill. App. Ct. 1997), but plaintiffs argue that the privacy policy includes promises that go beyond state and federal regulations. Because UnityPoint does not explain which laws or regulations its privacy policy is meant to enforce, the court declines to dismiss the contract claim on this ground.
Third, UnityPoint argues that the policy is a nonbinding promise because it has a clause that allows UnityPoint to change the terms of the policy and add new provisions. Dkt. 28-1, at 6. UnityPoint cites First Wisconsin Nat. Bank of Milwaukee v. Oby, 52 Wis. 2d 1, 188 N.W.2d 454, 457 (1971), which states that a promise is not a contract if “performance depends solely upon [the promisor‘s] option or discretion, as where the promisor is free to perform or to withdraw from the agreement at will.” But unlike the contract at issue in Oby, which did not require the parties to perform any actions, the terms of the privacy policy require UnityPoint to “follow the terms of the [policy] currently in effect.” Dkt. 28-1, at 6. Furthermore, unlike the contract in Oby, which allowed one of the parties to unilaterally cancel the entire contract, the modification clause allows UnityPoint to modify only the terms of the privacy policy. It does not allow UnityPoint to modify or withdraw from the overall contract for medical services. Neither party provides authority that explains whether Oby applies to contracts that allow a party to modify a contract only in part. The parties may raise the issue at summary judgment, but for now, the court concludes that plaintiffs have sufficiently alleged that the policy is a binding contract.
UnityPoint says that even if the policy is binding, plaintiffs have not alleged any breach of the policy. But plaintiffs plausibly allege that UnityPoint breached its promise to store patient information in a “secure database” when it sent patient health information in employee email attachments. And in any event, the allegations in the complaint allow the court to reasonably infer that the data breach occurred because UnityPoint did not follow the procedures laid out in its privacy policy. Plaintiffs have pleaded sufficient facts to survive a motion to dismiss.
As for plaintiffs’ claim for breach of the covenant of good faith and fair dealing, UnityPoint says only the court should dismiss it as duplicative of the breach of contract claim. But this claim may be pleaded as an alternative to the breach of contract claim. See Maryland Staffing Servs., Inc. v. Manpower, Inc., 936 F. Supp. 1494, 1509 (E.D. Wis. 1996) (finding that despite overlap, common law breach of contract and good faith and fair dealing claims could be pleaded in the alternative). Because that is UnityPoint‘s only argument for dismissing this claim, the court will allow the claim to proceed.
9. Unjust enrichment
As an alternative to the contract claims, plaintiffs assert a claim for unjust enrichment. The elements of this claim are: (1) a benefit conferred by plaintiffs to the defendant; (2) defendant‘s knowledge of the benefit; and (3) it would be inequitable for defendant to retain the benefit without paying its value. Admiral Ins. Co. v. Paper Converting Mach. Co., 2012 WI 30, 339 Wis. 2d 291, 811 N.W.2d 351.
UnityPoint says that plaintiffs do not state a claim for unjust enrichment because they received the medical services that they paid for. But plaintiffs allege that privacy protection was part of the services that they paid for, and because UnityPoint was negligent in its privacy practices, they did not provide the full benefit of that bargain. These allegations are sufficient at the pleading stage to state a claim.
UnityPoint also says that plaintiffs cannot bring a claim for unjust
10. Declaratory relief
Plaintiffs final claim is for declaratory relief stating that UnityPoint violated state law, and in particular the
As explained above, the court is already dismissing plaintiffs’ claims under the
C. Leave to amend
Plaintiffs ask for leave to amend their complaint to cure any deficiencies that lead to claims being dismissed. The court will deny the request because amendment in this case would be futile.
Many of the dismissed claims failed because of legal barriers, not because plaintiffs failed to plead pertinent facts. The Illinois and Iowa negligence claims are barred by the economic loss doctrine,
Only the misrepresentation claims and claims for delayed notification of the breach failed due to pleading deficiencies—plaintiffs did not plead actual damages caused by UnityPoint‘s communications or reliance on those communications. But it‘s hard to see how plaintiffs can cure these deficiencies. Their alleged injuries all stem from the data breach itself and hackers’ potential use of information gathered in the data breach. Whatever statements UnityPoint made about its data security practices or the scope of the data breaches, those statements had no effect on the degree of harm caused by breaches. The hackers had plaintiffs’ information either way.
If plaintiffs can show cause why their amendments would not be futile, then they may file a separate motion for leave to amend. But they will need to point to specific information that was unavailable
D. Conclusion
The court will dismiss plaintiffs’ claims for invasion of privacy, misrepresentation, violation of the consumer fraud statutes,
All plaintiffs may proceed on their claims for breach of contract, breach of the covenant of good faith and fair dealing, and unjust enrichment. Fox and Nesheim may also proceed on their claims for violation of the Wisconsin confidentiality of health care records statute,
ORDER
IT IS ORDERED that:
- Defendant UnityPoint System‘s motion to dismiss, Dkt. 27, is GRANTED in part:
- Plaintiff Danielle Duckley‘s claims for negligence, negligence per se, violation of the
Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505/2 , violation of theIllinois Uniform Deceptive Trade Practices Act, 815 ILCS 510/2 , and violation of theIllinois data breach notification statute, 815 ILCS 530/45 , are DISMISSED. - Plaintiff Shelly Kitsis‘s claims for negligence, negligence per se, violation of the
Iowa Consumer Fraud Act, I.C. § 714H , and violation of theIowa data breach notification statute, I.C. § 715C.2 , are DISMISSED. - Plaintiff Yvonne Fox and Grant Nesheim‘s claims for violation of the
Wisconsin Deceptive Trade Practices Act, Wis. Stat. § 100.18 , and violation of theWisconsin data breach notification statute, Wis. Stat. § 134.98(3)(a) are DISMISSED. - Plaintiffs’ claims for misrepresentation, invasion of privacy, and declaratory relief are DISMISSED.
- The motion is denied in all other regards.
- Plaintiff Danielle Duckley‘s claims for negligence, negligence per se, violation of the
- Plaintiffs’ motion to submit supplemental authority, Dkt. 51, is GRANTED.
- Defendant‘s motion for leave to respond to the supplemental authority, Dkt. 52, is DENIED.
- Defendant‘s motion to submit supplemental authority, Dkt. 53, is GRANTED.
Entered July 24, 2019.
BY THE COURT:
/s/
JAMES D. PETERSON
District Judge