Abdale v. North Shore-Long Island Jewish Health System, Inc.

49 Misc. 3d 1027, 19 N.Y.S.3d 850
New York Supreme Court·Decided August 14, 2015·Published·Cited by 10 cases

Opinion

OPINION OF THE COURT

Robert J. McDonald, J.

Plaintiffs commenced the within action on behalf of themselves and others similarly situated on February 5, 2013 to recover damages for, among other things, defendants’ “failure to adequately protect the confidential personal and medical [1031] information of their current and former patients, conduct that ultimately resulted in identity and medical identity data breaches.” Plaintiffs are 13 patients, or relatives of patients, who allegedly received medical services at medical facilities owned or operated by defendants North Shore-Long Island Jewish Health System, Inc. (Health System), North Shore-Long Island Jewish Medical Care, PLLC (Medical Care), North Shore-LIJ Network, Inc. (Network) and North Shore University Hospital (NSUH). Plaintiffs allege that defendants Health System, Medical Care and NSUH each operate under the corporate umbrella of defendant Network; and that defendants Network, Health System and Medical Care owns, operates, manages, maintains and secures defendant NSUH. The complaint refers to all four defendants collectively as North-Shore LIJ.

Plaintiffs allege that at the time they received medical treatment they provided personal information to the defendants, and that on or before fall 2010 and continuing at least through 2012, medical record face sheets and unencrypted computer network data were stolen from defendants North-Shore LIJ. It is also alleged that patients’ physical (hard copy) hospital face sheets were unsecured and were stolen from inside the premises of the defendants’ facilities, including NSUH. These face sheets consist of cover sheets containing information about each patient, including their full name, their spouse’s full name if married, date of birth, address, telephone number, medical record number, Social Security number, insurance information, and current medical information and history. Plaintiffs allege that the stolen data contains private, personal information, including but not limited to protected health information as defined by HIPAA, Social Security numbers, medical information and other information of hundreds of patients. Plaintiffs allege that as a result of the defendants’ failure to implement and follow basic security procedures, their personal information is now in the hands of thieves, and that they face a substantial increased risk of identity theft. Each of the 13 plaintiffs allege that they have experienced repeated instances of identity theft since said data breach and that as a consequence of said breach, plaintiffs, as well as current and former patients, have had to spend and will continue to spend significant time and money in the future to protect themselves. In addition, plaintiff Peterman alleges that as a result of the data breach her credit rating was substantially damaged; plaintiff Vetere alleges that as a result of the data breach her [1032] income tax refund for 2010 was fraudulently claimed and sent to a third party; and plaintiff Akins alleges that identity thieves fraudulently filed state and federal income tax returns for 2011, causing him substantial financial losses.

The complaint alleges that Health System through its Patients’ Bill of Rights, and website, advised patients that it, and each of its owned and sponsored article 28 not-for-profit corporations are required by law to follow HIPAA regulations and protect the privacy of health information that may reveal a patient’s identity. The complaint further alleges that patients were also advised that they have a right to be notified of any breaches of “Unsecured Protected Health” information as soon as possible, but in any event no later than 60 days following the discovery of the breaches.

Plaintiffs allege that on January 26, 2012, Clincy M. Robinson was arrested and charged with identity theft in the first degree (one count) and criminal possession of computer related materials (two counts), scheme to defraud in the first degree (two counts) and unlawful possession of personal information in the third degree (one count). Mr. Robinson was charged with being in possession of 25 face sheets from NSUH, data that is maintained on the computer network of NSUH, and being in possession of computer data consisting of personal identifying information for over 900 individuals, without authorization, and it is alleged that he pleaded guilty to these charges and was sentenced on December 13, 2012 in the District Court of Nassau County.

Plaintiffs also allege that on June 1, 2012, Dennis Messias was arrested and charged with identity theft in the first degree (four counts), grand larceny in the third degree, and scheme to defraud in the first degree, in connection with the theft and unauthorized use of patients’ personal information from the premises of NSUH.

Plaintiffs allege that the defendants were aware of these thefts and security breaches and that they failed to notify their patients within 60 days of the breach; that defendants failed to notify the Secretary of the U.S. Department of Health and Human Services of said security breaches in the year in which they discovered said breaches; and that defendants failed to maintain a written log of security breaches since 2007, on an annual basis.

The complaint alleges 11 causes of action for (1) negligence per se based upon violations of General Business Law § 899-aa; [1033] (2) negligence per se based on violations of Public Health Law § 18; (3) negligence per se based upon violations of General Business Law § 399-dd (4); (4) negligence per se based on violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub L 104-191, 110 US Stat 1936); (5) negligence per se based on violations of the Health Information Technology for Economic and Clinical Health Act (HITECH) (42 USC §§ 17921-17953, as added by Pub L 111-5, division A, tit XIII, § 13001 et seq., 123 US Stat 226); (6) violations of General Business Law § 349; (7) breach of contract; (8) breach of fiduciary duty; (9) negligence; (10) breach of the implied covenant of good faith and fair dealing; and (11) misrepresentation.

Free access — add to your briefcase to read the full text and ask questions with AI

Abdale v. North Shore-Long Island Jewish Health System, Inc., 49 Misc. 3d 1027, 19 N.Y.S.3d 850 (N.Y. Super. Ct. 2015).

49 Misc. 3d 1027 (Abdale v. North Shore-Long Island Jewish Health System, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Untitled Case
S.D. New York, 2026
Total Asset Recovery Servs. LLC v. Metlife, Inc.
2024 NY Slip Op 33840(U) (New York Supreme Court, New York County, 2024)
Total Asset Recovery Servs. LLC v. Metlife, Inc.
2020 NY Slip Op 07480 (Appellate Division of the Supreme Court of New York, 2020)
In re Equifax, Inc.
362 F. Supp. 3d 1295 (N.D. Georgia, 2019)
Fero v. Excellus Health Plain, Inc.
236 F. Supp. 3d 735 (W.D. New York, 2017)