Becker v. LISI, LLC

District Court, N.D. California·Decided May 25, 2023·No. 4:21-cv-03295·Unknown

Opinion

MATTHEW BECKER, Case No. 21-cv-03295-JST

Plaintiff, ORDER DENYING SECOND MOTION v. FOR PRELIMINARY APPROVAL OF CLASS ACTION SETTLEMENT LISI, LLC, et al., Re: ECF No. 42 Defendants.

Before the Court is Plaintiff Matthew Becker’s second motion for preliminary approval of a class action settlement. ECF No. 42. The Court will deny the motion without prejudice. This putative class action arises out of the alleged failure of Defendants LISI, LLC and AmWins Group, Inc. to adequately secure and safeguard their customers’ personally identifiable information (“PII”). ECF No. 1. Plaintiff brings claims on behalf of all individuals whose PII was compromised as a result of the data breach Defendants announced in July 2020. A. Parties and Claims LISI partners with insurance carriers to market and distribute their products to insurance brokers and agencies. AmWins is LISI’s parent company. In July 2020, Becker, who had previously enrolled in a MetLife insurance plan, received a Notice of Data Breach from LISI. The notice indicated that an employee’s email account had been hacked, and that emails containing class members’ PII—including names, Social Security Numbers, dates of birth, and insurance information—had been forwarded from a LISI email account to an unauthorized third party. Becker alleges that Defendants took inadequate steps to protect class members’ PII, and theft. Among other harms, Becker asserts that fraudulent accounts were opened in his name using his Social Security number, and that he was required to purchase a credit and identity theft monitoring product that he would not otherwise have needed to purchase. Becker’s complaint asserts causes of action for (1) negligence, (2) breach of confidence, (3) injunctive and declaratory relief, and (4) violation of California’s Unfair Competition Law, Cal. Bus. & Prof. Code §§ 17200, et seq. B. Key Terms of Proposed Settlement The Settlement Agreement defines the Settlement Class as “all persons residing in the United States whose [PII] was compromised as a result of the Data Security Incident that was announced by Defendants in July 2020.” ECF No. 38-1 ¶¶ 1.35, 4.1. The class is comprised of approximately 500 individuals.1 Defendants agree to provide all class members with access to IDX’s Identity Protection Services for 24 months from the “Effective Date.”2 Id. ¶ 5.2. “This benefit will be provided with the Short Notice as a link with a redeemable code to be used directly with IDX.” Id. Though class members need not submit a claim to access Identity Protection Services, they must enroll by the

1 The exact size of the proposed class is unclear. The Settlement Agreement and notice state that the class is composed of 553 individuals. ECF No. 38-1 ¶ 1.37; id. at 46. Becker’s second motion for preliminary approval suggests that the class is composed of 491 individuals. ECF No. 42-3 (chart stating that 491 class members would be bound by the proposed settlement). For the purposes of this order, the Court assumes a class size of 500.

2 “Effective Date” is not defined in the Settlement Agreement, as the internal cross-reference in its definition is incorrect. ECF No. 38-11 ¶ 1.11 (defining “Effective Date” as “the first date by which all of the events and conditions specified in ¶ 1.12 herein have occurred and been met”); id. ¶ 1.12 (defining “Fee Application”).

The term “Effective Date” is also repeatedly used—without definition—in both the short and long notice. See, e.g., ECF No. 38-1 at 40 (explaining that all class members will be provided credit monitoring services “for a period of 24 months from the Effective Date of the Settlement”); id. at 43 (“[S]ervices will be provided for a period of 24 months from the Effective Date of the Settlement.”). For more information regarding the terms of the settlement, the notices direct class members to the Settlement Agreement, available on the settlement website. However, as noted “Election Deadline,” a term not defined in the Settlement Agreement.3 Id. Class members may also submit claims for out-of-pocket losses reasonably traceable to the data breach, including losses relating to fraud or identity theft; fees associated with lawyers, accountants, or credit repair services; costs associated with freezing or unfreezing credit and post- breach credit monitoring; and breach-related notary, fax, postage, copying, mileage, and long- distance telephone charges. Id. ¶ 5.3. Each class member seeking reimbursement for such out-of- pocket losses must submit receipts or other “not ‘self-prepared’” documentation. Id. Class members can also be reimbursed for up to three hours of time spent addressing issues related to the data breach, compensated at $25 per hour, provided they submit an attestation and brief description of the time associated with each action. While Defendants will not create a fund for payment of class members’ claims for reimbursement of out-of-pocket losses and lost time, Defendants will reimburse each claimant up to $1,500, up to an aggregate cap of $200,000. If the value of claims made exceeds this cap, each will be reduced on a pro rata basis. Id. If claims submitted total less than $200,000, Defendants will keep the difference. The Settlement Agreement also identifies “Non-Monetary Relief” in the form of improvements to Defendants’ cybersecurity practices. Id. ¶ 5.7. “In response to the event, following a password reset across the organization, [LISI] enacted multi-factor authentication and tightened policies and practices with regard to the creation of forwarding rules[,] . . . conducted a re-training of its employees[,] . . . instituted annual employee training[,] . . . [and] has also come under the governance of AmWINS Group, Inc.’s central security team, which has standardized anti-malware protections on all endpoints.”4 Id. 3 The Settlement Agreement states that, “[i]f a Settlement Class Member elects to receive . . . Identity Protection Services, he or she must make that election by the Election Deadline.” ECF No. 38-1 ¶ 5.3. Because the Settlement Agreement and notices indicate that all class members will receive this benefit, the Court understands the phrase “make that election” to mean that class members must enter the redeemable code on the IDX website prior to the Election Deadline. Neither notice explains that a class member who wishes to enroll in Identity Protection Services must do so by any deadline.

Free access — add to your briefcase to read the full text and ask questions with AI

Becker v. LISI, LLC, (N.D. Cal. 2023).

Becker v. LISI, LLC (Becker v. LISI, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Wal-Mart Stores, Inc. v. Dukes
131 S. Ct. 2541 (Supreme Court, 2011)
In Re Bluetooth Headset Products Liability
654 F.3d 935 (Ninth Circuit, 2011)
Fay v. Perles
484 F. Supp. 2d 6 (District of Columbia, 2007)
Hanlon v. Chrysler Corp.
150 F.3d 1011 (Ninth Circuit, 1998)
United States v. Castro-Vazquez
176 F. Supp. 3d 13 (D. Puerto Rico, 2016)
Haralson v. U.S. Aviation Servs. Corp.
383 F. Supp. 3d 959 (N.D. California, 2019)
May v. United States
157 F. 1 (Ninth Circuit, 1907)
Class v. City of Seattle
955 F.2d 1268 (Ninth Circuit, 1992)