Allen v. Blackbaud Inc

District Court, D. South Carolina·Decided October 19, 2021·No. 3:20-cv-02930·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF SOUTH CAROLINA COLUMBIA DIVISION

) ) ) Case No.: 3:20-mn-02972-JMC IN RE: BLACKBAUD, INC., ) CUSTOMER DATA BREACH ) MDL No. 2972 LITIGATION ) ) ORDER AND OPINION ) ) ____________________________________)

THIS DOCUMENT RELATES TO: ALL ACTIONS:

This matter is before the court on Defendant Blackbaud, Inc.’s (“Blackbaud”) Motion to Dismiss four (4) of Plaintiffs’ common law claims pursuant to Federal Rule of Civil Procedure 12(b)(6). (ECF No. 124.) For the reasons set forth below, the court GRANTS IN PART and DENIES IN PART Blackbaud’s Motion. (Id.) I. RELEVANT BACKGROUND Blackbaud is a publicly traded cloud software company incorporated in Delaware and headquartered in Charleston, South Carolina. (ECF No. 77 at 110–11 ¶ 419, 112 ¶ 424.) The company provides data collection and maintenance software solutions for administration, fundraising, marketing, and analytics to social good entities such as non-profit organizations, foundations, educational institutions, faith communities, and healthcare organizations (“Social Good Entities”). (Id. at 4 ¶ 4, 114 ¶ 430.) Blackbaud’s services include collecting and storing Personally Identifiable Information (“PII”) and Protected Health Information (“PHI”) from its customers’ donors, patients, students, and congregants. (Id. at 3 ¶ 2, 114 ¶ 429.) In this action, Plaintiffs represent a putative class of individuals whose data was provided to Blackbaud’s customers and managed by Blackbaud. (Id. at 6 ¶ 12.) Thus, Plaintiffs are patrons of Blackbaud’s customers rather than direct customers of Blackbaud. (ECF Nos. 92-1 at 9; 109 at 7–8.) Plaintiffs assert that, from February 7, 2020 to May 20, 2020, cybercriminals orchestrated a two-part ransomware attack on Blackbaud’s systems (“Ransomware Attack”). (ECF No. 77 at 11–12 ¶ 25.) Cybercriminals first infiltrated Blackbaud’s computer networks, copied Plaintiffs’ data, and held it for ransom. (Id. at 11 ¶ 25, 137 ¶ 496; ECF No. 92-1 at 7.) When the Ransomware

Attack was discovered in May 2020, the cybercriminals then attempted but failed to block Blackbaud from accessing its own systems. (Id.) Blackbaud ultimately paid the ransom in an undisclosed amount of Bitcoin in exchange for a commitment that any data previously accessed by the cybercriminals was permanently destroyed. (ECF Nos. 77 at 9 ¶ 20, 138 ¶ 499; 92-1 at 7.) Plaintiffs maintain that the Ransomware Attack resulted from Blackbaud’s “deficient security program[.]” (ECF No. 77 at 117–18 ¶ 439.) They assert that Blackbaud failed to comply with industry and regulatory standards by neglecting to implement security measures to mitigate the risk of unauthorized access, utilizing outdated servers, storing obsolete data, and maintaining unencrypted data fields. (Id. at 117–18 ¶ 439, 134 ¶ 486, 136 ¶ 491, 142 ¶ 510.)

Plaintiffs further allege that after the Ransomware Attack, Blackbaud launched a narrow internal investigation into the attack that analyzed a limited number of Blackbaud systems and did not address the full scope of the attack. (Id. at 143 ¶ 514.) Plaintiffs contend that Blackbaud failed to provide them with timely and adequate notice of the Ransomware Attack and the extent of the resulting data breach. (Id. at 130–31 ¶ 473.) They claim that they did not receive notice of the Ransomware Attack “until July of 2020 at the earliest[.]” (Id. at 156 ¶ 555.) Plaintiffs allege that they subsequently received notices of the Ransomware Attack from various Blackbaud customers at different points in time from July 2020 to January 2021. (See, e.g., id. at 25 ¶ 63, 29 ¶ 82, 32 ¶ 93, 109 ¶ 414.) Plaintiffs maintain that although Blackbaud initially represented that sensitive information such as SSNs and bank account numbers were not compromised in the Ransomware Attack, Blackbaud informed certain customers in September and October 2020 that SSNs and other sensitive data were in fact stolen in the breach. (Id. at 141–42 ¶ 509.) Additionally, on September 29, 2020, Blackbaud filed a Form 8-K with the Securities and Exchange Commission stating that SSNs, bank account information, usernames, and passwords may have been exfiltrated

during the Ransomware Attack. (Id. at 12 ¶ 26, 143 ¶ 512.) After the Ransomware Attack was made public, putative class actions arising out of the intrusion into Blackbaud’s systems and subsequent data breach were filed in state and federal courts across the country. (ECF No. 1 at 1.) On December 15, 2020, the Judicial Panel on Multidistrict Litigation consolidated all federal litigation related to the Ransomware Attack into this multidistrict litigation (“MDL”) for coordinated pretrial proceedings.1 (Id. at 3.) On April 2, 2021, thirty-four (34) named Plaintiffs2 from twenty (20) states filed a Consolidated Class Action Complaint (“CCAC”) alleging that their PII and/or PHI was compromised during the Ransomware Attack. (ECF No. 77.) 3 They assert six (6) claims on behalf

of a putative nationwide class as well as ninety-one (91) statutory claims on behalf of putative state subclasses. (Id. at 173 ¶ 627 – 424 ¶ 1815.) To facilitate the efficient resolution of the litigation, the court ordered various phases of motions practice to address jurisdictional issues, certain statutory claims, and specific common law claims. (ECF Nos. 23 at 2; 78 at 1.) This phase addresses the common law claims. Blackbaud

1 As of October 19, 2021, this MDL is comprised of twenty-nine (29) member cases. 2 The named Plaintiffs are identified in paragraphs 45 through 418 of the CCAC. (See ECF No. 77 at 20 ¶ 45 – 110 ¶ 418.) Since the CCAC was filed, Plaintiff Rosalie Simkins voluntarily dismissed her individual claims on September 17, 2021. See Simkins v. Blackbaud, Inc., No. 3:21- cv-00431-JMC (ECF No. 72). 3 The CCAC supersedes all other complaints in this MDL filed on behalf of Blackbaud’s customer’s patrons against Blackbaud. (ECF Nos. 23 at 4; 77.) filed the instant Motion to Dismiss pursuant to Rule 12(b)(6) on July 9, 2021, contending that Plaintiffs’ negligence, negligence per se, gross negligence, and unjust enrichment claims should be dismissed for failure to state a claim. (ECF No. 124.) Plaintiffs filed a Response on August 9, 2021. (ECF No. 142.) The court held a hearing on the Motion to Dismiss on September 2, 2021. (ECF No. 147.)

II. LEGAL STANDARD A. Applicable Law 1. Choice of Law: Negligence, Negligence Per Se, and Gross Negligence The parties have stipulated to the application of South Carolina choice of law principles. (ECF No. 93.) For tort claims, South Carolina uses the lex loci delicti analysis of the First Restatement of Conflict of Laws. The goals of the First Restatement were to “reduce forum shopping and increase predictability and uniformity” of result. See Yasamine J. Christopherson, Conflicted About Conflicts? A Simple Introduction to Conflicts of Laws, 21 S.C. LAW. 30, Sept. 2009, at 31. Under the traditional or “vested-rights” rule, “the cause of action was considered to

be created in the state of the tort, and the capacity to sue or immunity or defense was considered part and parcel of those rights.” 29 A.L.R.3d 603 (1970); see also Trahan v. E.R. Squibb & Sons, Inc., 567 F. Supp. 505, 508 (M.D. Tenn. 1983) (“The lex loci doctrine is derived from the vested right approach which holds that a plaintiff's cause of action ‘owes its creation to the law of the jurisdiction where the injury occurred and depends for its existence and extent solely on such law.’”) (quoting Winters v. Maxey, 481 S.W.2d 755, 756 (Tenn. 1972)).

Free access — add to your briefcase to read the full text and ask questions with AI

Allen v. Blackbaud Inc, (D.S.C. 2021).

Allen v. Blackbaud Inc (Allen v. Blackbaud Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Aziz v. Alcolac, Inc.
658 F.3d 388 (Fourth Circuit, 2011)
Brown v. Brown
739 N.W.2d 313 (Michigan Supreme Court, 2007)
Francis v. Giacomelli
588 F.3d 186 (Fourth Circuit, 2009)
Kleckley v. Northwestern National Casualty Co.
526 S.E.2d 218 (Supreme Court of South Carolina, 2000)
Huggins v. Citibank, N.A.
585 S.E.2d 275 (Supreme Court of South Carolina, 2003)
Vaughan v. Town of Lyman
635 S.E.2d 631 (Supreme Court of South Carolina, 2006)
Hollins Ex Rel. Hollins v. Richland County School District One
427 S.E.2d 654 (Supreme Court of South Carolina, 1993)
Madison Ex Rel. Bryant v. Babcock Center
638 S.E.2d 650 (Supreme Court of South Carolina, 2006)
Doe v. Marion
645 S.E.2d 245 (Supreme Court of South Carolina, 2007)
Citizens for Lee County, Inc. v. Lee County
416 S.E.2d 641 (Supreme Court of South Carolina, 1992)
Bishop v. South Carolina Department of Mental Health
502 S.E.2d 78 (Supreme Court of South Carolina, 1998)
Rogers v. South Carolina Department of Parole & Community Corrections
464 S.E.2d 330 (Supreme Court of South Carolina, 1995)
Whisenant v. James Island Corporation
281 S.E.2d 794 (Supreme Court of South Carolina, 1981)