MEMORANDUM OPINION AND ORDER
I. INTRODUCTION
The plaintiff, Beverly T. Peters (“Peters”), brings this class action lawsuit against the defendants, St. Joseph Services Corporation d/b/a St. Joseph Health System, and St. Joseph Regional Health Center (collectively, “St. Joseph”), for damages arising from an intrusion into St. Joseph’s computer network and the resulting data breach. Peters alleges violations of the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq. (“FCRA”), and various state and common law claims sounding in tort and contract. Pursuant to Rule 12(b)(1) of the Federal Rules of Civil Procedure, St. Joseph moves to dismiss the First Amended Class Action. Complaint (the “Complaint”) for lack of standing and, alternatively, for failure to state a claim under Rule 12(b)(6) (Doc. Entry Nos. 26 & 27). St. Joseph has also filed motions to strike and to deny class certification (Doc. Entry Nos. 24 & 25).
This case raises an issue of first impression in this Circuit: whether the heightened risk of future identity theft/fraud posed by a data security breach confers Article III standing on persons whose information may have been accessed.
II. FACTUAL BACKGROUND
St. Joseph is a health care service provider headquartered in Texas. Peters, a resident of Texas and a former St. Joseph patient, gave her personally identifiable information and/or protected health information (collectively, “personal information”) to St. Joseph during the course of purchasing health care services from it. The information, stored on the St. Joseph computer network, included her name, social security number, birthdate, address, medical records and bank account information.
In a letter on February 4, 2014, St. Joseph announced that between December 16, 2013 and December 18, 2013, a security breach of its computer system occurred (the “Data Breach”). It was reported that hackers had infiltrated its computer network and potentially gained access to the personal information of Peters and approximately 405,000 other “[St. Joseph] patients, employees, and some employees’ beneficiaries” (the “Class Members”).
St. Joseph further reported that although it was not aware that any personal information had been misused, it made arrangements to provide potentially affected persons one year of free credit monitoring and identity theft protection. Enrollment in the service was automatic, requiring no action by Peters or the Class Members, and made effective as of the date of the letter. St. Joseph encouraged Peters and the Class Members to take steps to safeguard their personal information by monitoring their credit reports and account statements.
In her 13-count Complaint, Peters alleges that during the Data Breach, the hackers accessed and stole her information from the St. Joseph network, then disseminated it into the public domain where it has been misused by unauthorized and unknown third parties. On one occasion, someone attempted to make a retail purchase on her Discover card, which she previously submitted to St. Joseph in connection with purchasing health care services. Upon receiving a fraud alert from Discover, Peters declined approval for the transaction. The company then closed her account and reissued a new payment card to her. Peters was never charged for the attempted purchase.
It is alleged that on another occasion, someone attempted to access Peters’ Amazon.com account by using her son’s name. Peters claims that the name could only have been obtained from names and next-of-kin information she provided to St. Jo
Peters further complains that as a result of the Data Breach, her email account and mailing address were compromised. Her friends and relatives have received large volumes of spam email from her account and she, herself, has received unsolicited marketing materials and emails targeting the medical conditions recorded in her personal information.
Peters broadly asserts, based on information gleaned from the United States Government Accountability Office (“GAO”) and the Federal Trade Commission (“FTC”), that she and the Class Members are now vulnerable to future attacks by thieves who may seek to commit any number of identity theft-related crimes.
III. CONTENTIONS OF THE PARTIES
St. Joseph moves to dismiss the Complaint, contending that the Court lacks subject matter jurisdiction to hear Peters’ claims because she has not suffered an injury, actual or imminent, that is traceable to St. Joseph’s conduct. Regarding actual injury, St. Joseph argues that Peters has not alleged any unreimbursed cost, damage or loss that is causally connected to the thefi/fraud that she alleges. Regarding threatened injury, St. Joseph contends that Peters’ claim that she and the Class Members face an elevated risk of future identity thefi/fraud that is not “imminent” within the meaning of well-established standing principles. Applying Clapper v. Amnesty Int’l USA, — U.S. -,
Peters contends that St. Joseph’s approach is ill-suited for analyzing standing where, like here, a data breach has given rise to specific incidents of identity theft/ fraud and has “increased the risk of additional real and impending” theft/fraud. As briefed, Peters’ Article III analysis in part turns on the ability of the FCRA to confer standing, based on a private right of action under its provisions.
Federal courts are courts of limited jurisdiction, and must dismiss a case if, “at any time,” it is determined that subject matter jurisdiction is lacking. FED. R. CIV. P. 12(b)(1), 12(h)(3); see Stockman v. Fed. Election Comm’n,
When evaluating jurisdiction, “a [federal] court is free to weigh the evidence and satisfy itself as to the existence of its power to hear the case.” MDPhysicians & Assoc., Inc. v. State Bd. of Ins.,
V. ANALYSIS AND DISCUSSION
Because the parties are non-diverse, subject matter jurisdiction turns on the viability of the federal claims raised in this suit. These claims appear in counts 1 and 2 of the Complaint. The Court must first determine whether Article III standing exists with respect to these claims before reaching the remaining state and common law claims, which fall within the Court’s supplemental jurisdiction. Cf. Daimler-Chrysler Corp. v. Cuno,
In counts 1 and 2, Peters alleges willful and negligent violations of the FCRA. The FCRA imposes restrictions on any person, as that term is defined by the statute, who “regularly ... assembles] or evaluates] consumer credit information ... for the purpose of furnishing consumer reports to third parties.” 15 U.S.C. § 1681a(b), (f). Any person who willfully or negligently “fails to comply with any requirement imposed under [the FCRA] with respect to any consumer is liable to that consumer.” Id. §§ 1681n(a); 1681o. Peters alleges that St. Joseph violated the following FCRA provisions: 15 U.S.C. § 1681(b),
A. Article III Standing
Article III of the Constitution limits the jurisdiction of federal courts to actual “Cases” and “Controversies.” U.S. Const. art. III, § 2. “ ‘One element of the case-or-controversy requirement’ is that plaintiffs ‘must establish that they have standing to sue.’” Clapper,
Regarding the first prong, the Supreme Court has repeatedly stated that “[although imminence is ... a somewhat elastic concept,” it is not so elastic that it reaches allegations of “possible future injury.” Clapper,
The second prong requires a “causal connection between the injury and the conduct complained of — in other words, the injury must be traceable to the defendant and not the result of the independent action of a third party.” S. Christian Leadership Conference v. Supreme Court of State of La.,
B. Imminent Injury
Peters argues that the increased risk she faces of future identity theft/fraud constitutes “imminent” injury. The Court cannot agree that she faces a “certainly impending” or “substantial” risk of identity theft/fraud as Article III requires, and her Complaint makes the point all too clearly. There, she cites reports from the GAO and FTC to lend credibility to her fear that savvy thieves could potentially use her personal information to: drain her bank account(s); make charges on her credit card(s) or on new cards fraudulently opened in her name; obtain false identification cards; perpetrate tax, medical and insurance fraud; or develop phishing schemes over the internet. Peters further raises the possibility that fraudulent use of her personal information could go undetected for long periods of time — even “years into the future” — and thus cause “significant harm to [her] credit rating and finances.”
“Unless and until these conjectures come true,” Reilly,
The future injuries alleged in this case fail for the same reasons the injuries in Lujan and Clapper were rejected by the Supreme Court. In Lujan, the plaintiffs, environmental conservationist organizations, sought to enjoin the funding of government activities that threatened the habitats of certain animal species. The Court held that standing could not be established
In Clapper, the Court addressed whether attorneys and human rights, labor, legal and media organizations had standing to challenge a provision of the Foreign Intelligence Surveillance Act of 1978 (“FISA”). The provision authorized the Government to acquire foreign intelligence information from communications of non-U.S. persons located abroad. The plaintiffs claimed that they faced harm stemming from a reasonable fear that persons with whom they exchanged foreign intelligence information — i.e., colleagues, clients, sources, and other individuals located abroad— would be likely targets of FISA-sanctioned surveillance. They alleged that the challenged provision would compromise their ability to “locate witnesses, cultivate resources, obtain information, and communicate confidential information to their clients.” Clapper,
The plaintiffs asserted that “there [was] an objectively reasonable likelihood that their communication with their foreign contacts will be intercepted under [FISA] at some point in the future.” Id. at 1147. The Second Circuit accepted the argument, but the Supreme Court rejected it. The Court determined that the “objectively reasonable likelihood” standard was “inconsistent” with the long-standing requirement that threatened injury must be “certainly impending” to satisfy Article III. Id. at 1147-48 (citing cases).
Under Clapper, Peters must at least plausibly establish a “certainly impending” or “substantial” risk that she will be victimized. The allegation that risk has been increased does not transform that assertion into a cognizable injury. In fact, as one district court has observed, “Clapper seems rather plainly to reject the premise ... that any marginal increase in risk is sufficient to confer standing.” Strautins v. Trustwave Holdings, Inc.,
It is worth noting that the Court also held that the alleged injuries were not fairly traceable to the challenged provision. In this regard, the Court rejected the argument that the plaintiffs were “suffering present injury because the risk of ... surveillance already ha[d] forced them to take costly and burdensome measures to protect the confidentiality of their international communications.” Clapper,
The Court recognizes that before Clapper, a split existed among the Third, Seventh and Ninth circuit courts over whether the increased risk of harm stemming from a data security breach constitutes imminent injury under Article III. The Seventh and Ninth Circuits held that such a risk was sufficient to confer standing. Krottner,
Arguably, Clapper has resolved the circuit split.
The incidents identified by Peters as evidence of actual identity theft/fraud fail to meet the causation and redressability elements of the standing test. Peters essentially argues that her injuries are traceable to the FCRA because they stem from St. Joseph’s failure to comply with the requirements of the statute. She contends that as a result of this failure, acts of identity theft/fraud were (and continue to be) perpetrated against her, albeit by unknown third parties, for which St. Joseph should be held responsible: the attempted charge to her credit card; the attempted access to her Amazon.com account; the telephone solicitations she has received from medical products and services companies; the spam email sent from her account; and the physical and electronic materials she has received targeting her recorded medical conditions.
Although it is alleged that St. Joseph’s failures “proximately caused” these injuries, the allegation is conelusory and fails to account for the sufficient break in causation caused by opportunistic third parties. The injuries, to the extent that they meet the first prong, are “the result of the independent action of a third party” and therefore not cognizable under Article III. S. Christian Leadership Conference,
Even if the above injuries were traceable to St. Joseph’s alleged failures under the FCRA, it is not likely that a favorable decision from this Court would redress the harm she has experienced. St. Joseph argues that Peters has not alleged any quantifiable damage or loss she has suffered as a result of the Data Breach. The Court agrees.
• Moreover, some of Peters’ injuries have already been remedied. Discover never charged her for the fraudulent purchase identified in the Complaint and closed her account to prevent future fraud. Upon discovery that her Yahoo email account had been compromised, Peters changed her password. The Complaint contains no allegations that her email contacts continue to receive voluminous spam email from her account since she took this proactive measure.
Finally, a ruling from the Court would not prevent medical products and services companies from contacting Peters or otherwise disgorge them of her personal information. Certainly, the Court can neither “control [n]or ... predict” the “unfettered choices” made by these companies, who are not before the Court and are independent of St. Joseph in any event. Lujan,
Peters has not made the requisite demonstration of injury, traceability and re-dressability for her alleged injuries. Lacking viability, her federal claims are dismissed with prejudice.
VI. CONCLUSION
Based on the foregoing analysis and discussion, the Court GRANTS St. Joseph’s Rule 12(b)(1) motion to dismiss for want of subject matter (federal question) jurisdiction and dismisses the Complaint without leave to amend. The Court expresses no
It is so ORDERED.
Notes
. The issue was presented to the Texas Court of Appeals in Bliss & Glennon, Inc. v. Ashley,
. The Court expresses no opinion as to the viability of Peters' claims under Rule 12(b)(6) since its 12(b)(1) ruling is dispositive. See Ramming v. United States,
. Peters defines the Class Members as follows:
All Texas residents who were sent a letter or other communication by St. Joseph notifying them that their personally identifiable information and/or protected health information was maintained on a St. Joseph Health System computer system server that was breached by hackers between December 16, 2013 and December 18, 2013, inclusive.
. The argument conflates Article III standing and statutory standing, which are separate and distinct jurisdictional issues. The Article III question asks whether a party has brought a claim — any claim, statutory or otherwise— that the Constitution recognizes. As discussed below, the injury must satisfy Article Ill’s "case or controversy” requirement. The statutory question, by contrast, asks whether a party has the right to sue under a specific statute. The injury must satisfy the statute’s requirements for bringing a cause of action. Article III standing is mandatory for every claim, and therefore an antecedent inquiry to any claim of statutory standing.
. 15 U.S.C. § 1681(b) states:
(b) Reasonable procedures
It is the purpose of this subchapter to require that consumer reporting agencies adopt reasonable procedures for meeting the needs of commerce for consumer credit, personnel, insurance, and other information in a manner which is fair and equitable to the consumer, with regard to the confidentiality, accuracy, relevancy, and proper utilization of such information in accordance with the requirements of this sub-chapter.
. 15 U.S.C. § 1681a(d)(3) states:
(3) Restriction on sharing of medical information
Except for information or any communication of information disclosed as provided in section 1681b(g)(3) of this title, the exclusions in paragraph (2) [narrowing definition of "consumer report”] shall not apply with respect to information disclosed to any person related by common ownership or affiliated by corporate control, if the information is—
(A) medical information;
(B) an individualized list or description based on the payment transactions of the consumer for medical products or services; or
(C) an aggregate list of identified consumers based on payment transactions for medical products or services.
. 15 U.S.C. § 1681b(a), (g) state in relevant part;
(g) Protection of medical information
(1) Limitation on consumer reporting agencies
A consumer reporting agency shall not furnish for employment purposes, or in connection with a credit or insurance transaction, a consumer report that contains medical information (other than medical contact information treated in the manner required under section 605(a)(6) of this title) about a consum-er____
. 15 U.S.C. § 1681c(a)(6) states in relevant part:
(а) Information excluded from consumer reports
Except as authorized under subsection (b) of this section, no consumer reporting agency may make any consumer report containing any of the following items of information:
(б) The name, address, and telephone number of any medical information furnisher that has notified the agency of its status____
. To reach its conclusion in Pisciotta, the Seventh Circuit drew analogies from Second, Fourth, Sixth and Ninth Circuit cases addressing defective medical device, toxic substance and environmental injury claims. Pisciotta,
. The Court notes that since Clapper, intra-circuit splits have developed among district courts in the Seventh and Ninth Circuits. In the Seventh Circuit, at least two courts have ruled that Clapper abrogated Pisciotta while one court disagrees. Compare Strautins,
In the Ninth Circuit, one district court has determined that "the possibility of future harm is insufficient to establish standing.” Yunker v. Pandora Media, Inc., No. 11-CV-03113-JSW,
Other courts that have applied Clapper in the data breach context include district courts in the District of Columbia, the Southern District of Ohio, and the District of New Jersey. These courts have rejected the "increased risk” theory of standing. See In re Sci. Applications Int’l Corp. (SAIC) Backup Tape Data Theft Litig.,
. The court notes that St. Joseph also cites as a pleading defect Peters’ failure to allege any "unreimbursed cost” she incurred in mitigation of the Data Breach. The observation implies that such an allegation would meet the injury test. As discussed in Part V.B., voluntary mitigation expenses are not valid Article III injuries. Clapper,
