MEMORANDUM AND ORDER GRANTING SUMMARY JUDGMENT
Medidata Solutions, Inc. (“Medidata”) commenced this action against Federal- Insurance Company (“Federal”) after Federal denied Medidata’s claim, for insurance coverage. The parties filed cross-motions for summary judgment and the Court ordered additional expert discovery. For the following reasons, Medidata’s motion for summary judgment is GRANTED.
BACKGROUND
A. Medidata
Medidata provides cloud-based services to scientists conducting research in clinical trials. Medidata’s Memorandum of Law in Support of Motion for Summary Judgment (“Pi’s Mem.”) at 3, ECF No. 37. Medidata used Google’s Gmail platfоrm for company emails. Affidavit of Glenn Watt in Support of Medidata’s Motion for Summary Judgment, (“Watt Aff.”) ¶ 2, ECF No. 39. Medi-data email addresses consisted of an employee’s first initial and last name followed by the domain name “mdsol.com” instead of “gmail.com”. Id. ¶3. Email messages sent to Medidata employees were routed through Google computer servers. Id. ¶ 4. Google systems processed 'and stored the email messages. Id. ¶ 4. During processing, Google compared an incoming email address with Medidata employee profiles in order to find a match. Id. ¶ 9. If a match was found, Gmail displayed the sender’s full name, email address, and picture in the “From” field of the message. Id. ¶¶ 8, 10, 11. After processing, the emails were displayed in the Medidata employee’s email account. Id. ¶ ,7. Medidata employees used computers owned by the company to
B. Fraud on Medidata
In the summer of 2014, Medidata notified its finance department of the company’s short-term business plans which included a possible acquisition. Plaintiffs Rule 56.1 Statement (“PL’s 56.1”) ¶36, EOF No. 36. Medidata instructed finance pеrsonnel “to be prepared to assist with significant transactions on an urgent basis.” Id. ¶ 37. In 2014, Alicia Evans (“Evans”) worked in accounts payable at Medi-data. Id. ¶38. Evans was responsible for processing all of Medidata’s travel and entertainment expenses. Joint Exhibit Stipulation (“Joint Ex. Stip.”) Ex. 20, 41:16-21, ECF No. 41. Oii September 16, 2014, Evans received an email purportedly sent from Medidata’s president. Id. Ex. 2; The email message contained the president’s name, email address, and picture in the “From” field. Id. The message to Evans stated that Medidata was close, to .finalizing an acquisition, and that, an attorney named Michael Meyer (“Meyer”) would contact Evans. Id. The email advised Evans that the acquisition was strictly confidential and instructed Evans to devote her full attention to Meyer’s demands. Id. Evans replied: “I will certainly assist in any way I can and will make this a priority.” Id. Ex. 4.
On that same day, Evans received a phone call from a man who held himself out to be Meyer. Id. Ex. 20, 31:10-15. Meyer demanded that Evans process a wire transfer for him.- Id. Meyer told Evans a physical check would not suffice because of time constraints. Id. Ex. 20, 36:5-8. Evans explained to Meyer that she needed an email frоm Medidata’s president requesting the wire transfer. Id. Ex. 20, 34:17-20. Evans also explained she needed approval from Medidata Vice President Ho Chin (“Chin”), and Director of Revenue Josh Schwartz (“Schwartz”). Id.
Chin, Evans, and Schwartz then received a group email purportedly sent from Medidata’s president stating: “I’m currently undergoing a financial operation in which I need you to process and approve a payment on my behalf. I already spoke with Alicia, she will file the wire and I would need you two to sign off.” Id. Ex. 61 The email contained the president of Medidata’s email addrеss in the “From” field and a picture next to his name. Id. In response, Evans logged on to Chase Bank’s online system to initiate a wire transfer. Id. Ex. 20, 13:20-14:16. Evans entered the banking information proyided by Meyer and submitted the wire transfer for approval. Id. Ex. 20, 15:11-23,. 16:17— 17:05. Schwartz and Chin logged on to Chase’s online banking system and approved the wire transfer. Id. Ex, 21,13:20— 14:16; Ex. 19, 59:16-18,' 60:02-04. $4,770,226.00 was wired to a bank account that was .provided by Meyer. Id. Ex. 8.
On September 18, 2014, Meyer contacted Evans requesting a second wire transfer. Id. Ex. 20, 42:02-10. Evans initiated the second wire transfer and Schwartz approved it. Id. Ex. 21, 40:24-41:20. However, Chin thought the email address in the “Reply To” field seemed suspicious. Id. Ex. 19, 46:08-24. Chin spoke with Evans about his suspicions and Evans composed a new email to Medidata’s president inquiring about the wire transfers. Id. Ex. 20, 50:04-20. Medidata’s president told. Evans and Chin that he liad not requested the wire transfers. Id. Medidata employees then realized that the company had been defrauded. Id. Ex. 19, 63:09-64:18. Medi-data contacted the FBI and hired outside counsel to conduct an investigation. Id. The investigations revealed that an unknown actor altered the emails that were sent to Chin, Evans, and Schwartz to ap
C. Medidata Insurance Policy
Medidata held a $5,000,000 insurance policy with Federal called “Federal Executive Protection”. Id. Ex. 1. The Policy contained a “Crime Coverage Section” addressing loss caused by various criminal acts, including Forgery Coverage Insuring, Computer Fraud Coverage, and Funds Transfer Fraud Coverage. Id.
1.Computer Fraud Coverage
The Policy’s, “Computer Fraud Coverage”, protected the “direct loss of Money, Securities or Property sustained by an Organization resulting from Computer Fraud committed by a Third Party.” Id. The Policy defined “Organization” as “any organization designated in Item 4 of the Declarations for this coverage section.” Id. Item 4, in turn, lists “Medidаt[a] Solutions, Inc., and its subsidiaries” as a covered Organization. Id. The Policy defined “Third Party” as “a natural person other than: (a) an Employee; or (b) a natural person acting in collusion with an Employee.” Id.
The Policy defined “Computer Fraud” as: “[T]he unlawful taking or the fraudulently induced transfer of Money, Securities or Property resulting from a Computer Violation.” Id. A “Computer Violation” included both “the fraudulent: (a) entry of Data - into ... a Computer System; [and] (b) change to Data elements or program logic of a Computer System, which is kept in machine readable format ... directed against an Organization.” Id. The Policy defined “Data” broadly to include any “representation of information.” Id. The Policy defined “Computer System” as “a computer and all input, output, processing, storage, off-line media library and communication facilities which are connected to such computer, provided that such computer and facilities are: (a) owned and operated by an Organization; (b)' leased and operated by an Organization; or (c) utilized by an Organization.” Id.
2.Funds Transfer Fraud Coverage
The Policy’s Funds Transfer Fraud Coverage protectеd “direct loss of Money or Securities sustained by an Organization resulting from Funds Transfer Fraud committed by a Third Party.” Id. The.Policy defined “Funds Transfer Fraud” as: “fraudulent electronic ... instructions ... purportedly issued by an Organization, and issued to a financial institution directing such institution to transfer, pay or deliver Money or Securities from any account maintained by such Organization at such institution, without such Organization’s knowledge or consent,” Id.
3.Forgery Coverage
The Policy’s Forgery Coverage protected “direct loss sustained by an Organization resulting from Forgery or alteration of a Financial Instrument committed by a Third Party”. Id. “Fоrgery” is defined as “the signing of the name of another natural person ... with the intent to deceive .,.. Mechanically or electronically produced or reproduced signatures shall be treated the same as hand-written signatures.” Id.
Jp. Claim For Coverage
On September 25, 2014, Medidata submitted a claim to Federal requesting coverage of the fraud under three clauses. Id. Ex. 11. Federal assigned regional claims technician Michael Maillet (“Maillet”) to investigate the fraud on Medidata. Id. Ex. 12.
On December 24, 2014, Federal denied Medidata’s claim for coverage. Id. Federal denied coverage under the computer fraud clause, because there had been no “fraudulent entry of Data into Medidata’s computer system.” Id. at 4. As support, Federal
Federal denied coverage under the funds- transfer fraud clause because the wire transfer had been authorized by Med-idata employees and thus was made with the knowledge and consent of Medidata. Id.
Finally, Federаl rejected Medidata’s claim for Forgery Coverage because the emails did not contain an actual signature and did not meet the Policy’s definition of a Financial Instrument. Id. Federal also based its denial of both the Forgery Coverage and the Computer Fraud Coverage claims on the belief that the emails did not directly cause Medidata’s loss, because no loss would have taken place if Medidata employees had not acted on the instructions contained in those emails. Id. .
On January 13, 2015, Medidata sent a letter responding to the dеnial and setting forth the basis for coverage under the Policy. Id. Ex. 14. Federal replied on January 30, 2015, reasserting its denial of coverage for the claim. Id. Ex. 15.
DISCUSSION
Summary judgment is appropriate where “the pleadings, depositions, answers to interrogatories and admissions on file, together with affidavits, if any, show that there is no genuine issue as to any material fact and that the moving party is entitled to judgment as a matter of law.” Celotex Corp. v. Catrett,
The burden lies with the moving .party to demonstrate the absence of any genuine issue of material fact and all inferences and ambiguities are to be resolved in favor of the nonmoving party; See Celotex Corp.,
Under New. York law, insurance policies are interpreted according to general rules of contract interpretation. Olin
A. Computer Fraud Coverage
Medidata argues that the Policy’s Computer Fraud clause covers the company’s loss in 2014, because a thief fraudulently entered and changed data in Medi-data’s computer system. Pl.’s Mem. at 14-20. Specifically; Medidata asserts that the address in the “From” field of the spoofed emails constituted data which was entered by the thief posing as Medidata’s president. Id. at 14. Also, a thief entered a computer code which caused Gmail to “change” the hacker’s email address to the Medidata president’s email address. Id. at 19-20.
- Federal argues that Medidata’s loss in 2014 is not covered by the Computer Fraud clause, because the emails did not require access to Medidata’s computer system, a manipulatiоn of those computers, or input of fraudulent'information. Federal’S Memorandum of Law in Support of Summary Judgment (“Defs Mem.”) at 9-12, ECF No. 34. The Court has reviewed .the Policy and concludes that, as a matter of law, the unambiguous language of. the Computer Fraud clause provides coverage for the theft from Medidata.
Under Medidata’s policy, a computer violation occurs upon the “the fraudulent: (a) entry of Data into or deletion of Data from a Computer System” or “(b) change to Data elements-or program logic of a Computer System, which is kept in machine readable format.” The New York Court of Appeals shed light on. these phrases in Universal, which involved a health insurance company that was defrauded by healthcare providers who entered claims for reimbursement of services that were never rendered.
Here, the fraud on Medidata falls within the kind of. “deceitful and dishonest access” imagined by the New York Court of Appeals. Id. It is undisputed that the theft occurred by way of email spoofing.
Federal’s reading of Universal is over-broad. In this case, Federal focuses on the thiefs construction of the spoofed emails and computer code before sending them to Gmail, arguing that, as a result, there was no entry or change of data to Medidata’s computer system. Def s Mem. at 9-12. Under this logic, Universal would require that a thief hack into a company’s -computer system and execute a bank transfer on their own in order to-trigger insurance coverage. Hоwever, this reading of Universal incorrectly limits the coverage of the policy in this case. It is true that the Court of Appeals in Universal peppered its opinion with references to hacking as the example for a covered violation. See e.g., id. at 681,
Federal’s reliance on Pestmaster Servs., Inc. v. Travelers Cas. & Sur. Co. of Am., is also misplaced. The court in Pestmaster, held that a corporation’s computer fraud insurance policy did not cover a theft by the company’s payroll administrator, because the administrator was authorized to withdraw funds from the corporation’s bank account, notwithstanding the fact that he later misappropriated the payroll funds. No. 13-CV-5039 (JFW),
In challenging causation, Federal contends that “there is no direct nexus” between the spoofed emails and the fraudulent wire transfer. Defs Mem. at 13-15. According to Federal, the spoofed emails “did not create, authorize, or release a wire transfer” because Medidata employees received telephone calls from the thief and took other steps in apрroving the fraudulent transfer. Id. at 16. As support, Federal cites to the Fifth Circuit’s decision in Apache Corp. v. Great American Ins. Co. denying coverage of a similarly worded computer fraud provision.
Federal also cites to the Ninth Circuit’s decision in Taylor & Lieberman v. Federal Ins. Co., denying coverage of a computer fraud provision. (“Taylor I”),
Accordingly, Medidata has demonstrated that its losses were a direct cause of a computer violation.
B. Funds Transfer Fraud Coverage
Medidata argues that it was improperly denied coverage under the Funds Transfer Fraud clause because the theft in 2014 “(1) caused a direct loss of money; (2) by fraudulent electronic instructions purportedly issued by Medidata; (3) issued to a financial institution; (4) to deliver money from Medidata’s accounts; (5) without Medidata’s knowledge or consent.” Pi’s Mem. at 20. Federal challenges the last of the requisite elements, arguing that the bank wire transfer in 2014 was voluntary and with Medidata’s knowledge and consent, Defs Mem. at 21-24. Federal also argues that, because Medidatа employees voluntarily transferred the money, it was actually issued by Medidata instead of “purportedly issued” as the Policy demands. Id. at 24-25. The Court finds that the unambiguous language of the Policy covers the theft from Medidata in 20Í4.
The Policy defines Funds Transfer Fraud' as: “fraudulent electronic \:. instructions .... purportedly' issued by an Organization, and issued, to a financial institution directing such institution to transfer, pay or deliver Money or Securities from any account maintained by such Organization at such institution, without such Organization’s knowledge or consent.”
C. Forgery Coverage
The theft from Medidata in 2014 does not trigger coverage under the Forgery clause,' because the Policy requires a “direct loss resulting from Forgery or alteration of a Financial Instrument committed by a Third Party.” Joint Ex. Stip., Ex. 1. The parties vehemently dispute whether the spoofed emails containing Medidata’s president’s name constitute a forgery. See Pi’s Mem. at 18; Defs Mem. at 17. However, the Court need not resolve the mattеr. Even if the emails contained a forgery, the absence of a financial instrument proves fatal to Medidata’s claim for coverage. In a strained reading of the Policy, Medidata argues that a forgery itself triggers coverage even in the absence of a financial instrument. Medidata’s Memorandum of law in Further Support of Summary Judgment (“Pi’s Reply”) at 20, ECF No. 62. However, “[t]he entire contract must be reviewed and particular words should be considered, not as if isolated from the context, but in the light of the obligation as a whole and the intention of the partiеs as manifested thereby. Form should not prevail over substance and a sensible meaning of words should be sought.” Riverside S. Planning Corp. v. CRP/Extell Riverside, L.P.,
CONCLUSION
Fpr the foregoing reasons, Medidata’s motion for summary judgment is GRANTED and Federal’s motion for. summary judgment is DENIED.
SO ORDERED.
Notes
. The trial court noted "the perpetrators enrolled new members in the ... plan with the person’s cooperation, in return for which the member received a kickback from the provider. In some cases, the provider used the member’s personal information without that person’s knowledge. In either event, the provider itself did not enroll in the plan. Instead, they were able to submit claims after obtaining a National Provider Identifier (NPI) from [the agency of the U.S. Department of Health and Human Service tasked with overseeing this market]. In some cases, the NPI was obtained for a fictitious provider, in other cases it was fraudulently taken from a legitimate provider.”
. A court in this district defined “.Spoofing” as "the practice of disguising a commercial email to make the e-mail appear to come from an address from which it actually did not originate. Spoofing involves placing in the “From” or "Reply-to” lines, or in other portions of e-mail messages, an .e-mail address other than the actual sender’s address, without the consent or authorization of the user of the e-mail address whose address is spoofed.” Karvaly v. eBay, Inc.,
. The Appellate Division appeared to have a similar concern when it found that the language of the policy "was intended to apply to wrongful acts in manipulation of the computer system, i.e., by hackers, and did not provide coverage for fraudulent content consisting of claims by bona fide doctors and other health care providers authorized to use the system for reimbursement for health care services that were not provided.”
