Attias v. Carefirst, Inc.

365 F. Supp. 3d 1
CourtCourt of Appeals for the D.C. Circuit
DecidedJanuary 30, 2019
DocketCase No. 15-cv-00882 (CRC)
StatusPublished
Cited by29 cases

This text of 365 F. Supp. 3d 1 (Attias v. Carefirst, Inc.) is published on Counsel Stack Legal Research, covering Court of Appeals for the D.C. Circuit primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
Attias v. Carefirst, Inc., 365 F. Supp. 3d 1 (D.C. Cir. 2019).

Opinion

CHRISTOPHER R. COOPER, United States District Judge *5I. Background...6

II. Standard of Review...7

III. Jurisdiction...7

IV. Analysis...8

A. Whether plaintiffs have adequately alleged damages for nine of their eleven claims...9

1. Plaintiffs must allege actual damages for nine of their causes of action...9
2. Four theories of actual damages...11

B. Whether the parties' contractual relationship bars plaintiffs' tort claims...17

C. Whether plaintiffs have pled in the alternative an unjust enrichment claim...25

D. Whether plaintiffs have alleged an unlawful trade practice under the D.C. Consumer Protection Procedures Act...25

E. Whether insurance companies are exempt from civil liability for data breaches under the Maryland Consumer Protection Act...26

V. Conclusion...27

In May 2015, the District of Columbia-area health insurer CareFirst announced that it had suffered a data breach that compromised the personal information of millions of its policyholders. Plaintiffs in this putative class action are among those whose data was accessed. They seek compensation for the breach through both tort- and contract-based claims under District of Columbia law, as well as statutory claims under several D.C., Maryland, and Virginia consumer-protection laws.

Common to all of plaintiffs' claims is the assertion that they have been injured by CareFirst's failure to protect their personal information from exposure. The alleged injuries do not, for the most part, involve actual misuse of their personal information. Plaintiffs instead claim that the data breach resulted in an increased risk of identity theft and the need for prophylactic expenditures-on credit monitoring services and the like-to reduce that risk. They also contend that CareFirst's failure to protect their personal information resulted in a contractual injury because they did not receive the full value of the policies they purchased. And they say they have suffered emotional distress in dealing with the breach.

The Court previously dismissed plaintiffs' claims for lack of Article III standing, finding that they had failed to allege a non-speculative injury-in-fact. The D.C. Circuit reversed and remanded. CareFirst now moves to dismiss the operative second amended complaint under Federal Rule of Civil Procedure 12(b)(6) for failure to state a claim.

The Court will grant the motion in large part. After briefly recounting the factual and procedural background, the Court will begin by confirming that it has diversity jurisdiction over the case pursuant to the Class Action Fairness Act, 28 U.S.C. § 1332(d). It will then explain its conclusion that, while plaintiffs' alleged injuries may be enough to establish standing at the pleading stage of the case, they are largely insufficient to satisfy the "actual damages" element of nine of their state-law causes of action. The Court will then move to the interplay between plaintiffs' tort and contract claims, finding that the parties' non-fiduciary contractual relationship independently forecloses tort liability based on the allegations in the complaint. Finally, the Court will address issues specific to plaintiffs'

*6unjust enrichment claim and their claims under the District of Columbia Consumer Protection Procedures Act and the Maryland Consumer Protection Act.

At the end of the day, the Court will dismiss all of plaintiffs' claims except for a breach of contract claim and a Maryland Consumer Protection Act claim brought by the only two plaintiffs (Kurt and Connie Tringler of Maryland) who have plausibly alleged actual misuse of personal information resulting from the data breach. In reaching this outcome, the Court acknowledges the difficulty of applying traditional tort and contract principles in the contemporary context of data security. It also recognizes that courts across the country have divided on a number of important legal issues that frequently arise in data breach litigation. The Court has attempted to illuminate some of these divisions in this opinion.

I. Background

Seven plaintiffs bring this putative class action against CareFirst and certain of its affiliates doing business in the District of Columbia, Maryland, and Virginia. Second Am. Class Action Compl. ("SAC"), ECF No. 9.1 CareFirst operates a group of health insurance companies providing coverage to more than one million individuals in the District of Columbia, Maryland, and Virginia. Id. ¶¶ 5-8, 23. Plaintiffs are residents of the District of Columbia, Maryland, and Virginia, and customers and insureds of CareFirst. Id. ¶¶ 1-4, 25. When customers purchase health insurance through CareFirst, they provide the company certain personal information, including their names, credit card numbers, addresses, and social security numbers. Id. ¶¶ 26-27. CareFirst promises, explicitly or implicitly, to keep this information protected. Id. ¶¶ 28-29. CareFirst allegedly failed to properly encrypt some of the data entrusted to its care, id. ¶ 31, and in June 2014, CareFirst suffered a cyberattack, id. ¶ 33. It learned of the attack in April 2015 and notified its customers, including plaintiffs, the following month. Id. ¶¶ 35-36.

Free access — add to your briefcase to read the full text and ask questions with AI

Related

Cite This Page — Counsel Stack

Bluebook (online)
365 F. Supp. 3d 1, Counsel Stack Legal Research, https://law.counselstack.com/opinion/attias-v-carefirst-inc-cadc-2019.