Clemens v. Execupharm, Inc.

CourtDistrict Court, E.D. Pennsylvania
DecidedFebruary 25, 2021
Docket2:20-cv-03383
StatusUnknown

This text of Clemens v. Execupharm, Inc. (Clemens v. Execupharm, Inc.) is published on Counsel Stack Legal Research, covering District Court, E.D. Pennsylvania primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
Clemens v. Execupharm, Inc., (E.D. Pa. 2021).

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE EASTERN DISTRICT OF PENNSYLVANIA JENNIFER CLEMENS, individually and on behalf of all others similarly situated, Plaintiff, CIVIL ACTION NO. 20-3383 v. EXECUPHARM, INC. and PAREXEL INTERNATIONAL CORP., Defendants. PAPPERT, J. February 25, 2021 MEMORANDUM Jennifer Clemens, individually and on behalf of a purported class, sued ExecuPharm, Inc. and parent Parexel International Corporation over a data breach at ExecuPharm. Defendants moved to dismiss the Complaint pursuant to Federal Rule of Civil Procedure 12(b)(6), and the Court subsequently requested supplemental briefing from the Parties as to whether Clemens has standing to bring her claims. Having considered the supplemental briefing and for the reasons that follow, Clemens lacks standing and the Court does not have subject matter jurisdiction to address her claims. I A i Clemens worked at ExecuPharm from February to November of 2016 and provided the company “significant amounts of her personal and financial information” as a “condition of her employment.” (Compl. ¶¶ 56–57, 59, ECF No. 1.) She signed an employment agreement “[a]s a further condition of her employment.” (Id. at ¶ 58.) In it, ExecuPharm agreed to “take appropriate measures to protect the confidentiality and security of all personal information.” (Id.) Although Clemens left the company years ago, ExecuPharm retained her sensitive personal information until at least March 13, 2020. (Id. at ¶ 59.) On that date, ExecuPharm’s server was hacked by the CLOP

ransomware group. (Id. at ¶¶ 1, 11, 14, 31.) CLOP organized a successful email phishing scheme to obtain server access and encrypt data by installing malware. (Id. at ¶ 13.) It accessed thousands of individuals’ sensitive information, including full names, home addresses, social security numbers, taxpayer IDs, credit card and bank information, beneficiary information and, in some cases, passport copies. (Id. at ¶¶ 1–2, 4.) It then demanded a ransom from ExecuPharm in exchange for data decryption tools and threatened to release the data if the ransom was not timely paid. (Id. at ¶ 13.) On April 26, CLOP made at least some of the information it stole available for download on the “dark web.” (Id. at ¶¶ 2, 15, 29). “[T]he download links contained nearly 123,000 files and 162 gigabytes of data,

including nearly 19,000 files of correspondence involving ExecuPharm and Paraxel; more than 80,600 e-mail correspondences; financial, accounting, user documents of ExecuPharm’s employees and managers; and a complete backup file of ExecuPharm’s document management system.” (Id. at ¶ 29.) Clemens alleges she learned in an email from ExecuPharm on March 20 that her information was accessed during CLOP’s data breach and ExecuPharm “confirm[ed]” in an April 26 email “that her family’s most sensitive personal and financial [information] was ‘shared on the dark web.’” (Id. at ¶¶ 60, 64.) In making these allegations, Clemens appears to rely on the ExecuPharm communications she quotes elsewhere in the Complaint, which do not state she specifically was a victim of the data breach. According to the Complaint, ExecuPharm’s March 20 email stated: Unfortunately, we now believe sensitive information has been accessed, including social security number, banking information (copy of a personal check for direct deposit), driver’s license, date of birth, home address, spouse’s name, beneficiary information (including social security numbers) and payroll tax forms (such as W-2 and W-4). For some employees, copies of passports also were accessed.

(Compl. ¶ 18.) The email appended a pdf of a March 18 letter to former employees, which explained to recipients “[i]f you are receiving this . . . we believe you may be among the group of former employees impacted by this incident.” (Id. at ¶ 16 (emphasis added).) ExecuPharm’s April 26 email stated it had “become aware that the information accessed by the cyberattackers has been shared on the dark web”—it does not appear to have said anything about Clemens’s or her family’s data specifically. (Id. at ¶ 30.) Notwithstanding the apparent inconsistencies in Clemens’s allegations, the Court interprets the Complaint in the light most favorable to her and credits that her information was accessed and posted online. ii After the breach, ExecuPharm offered free identity monitoring services for one year to all potentially affected current and former employees. (Id. at ¶¶ 24, 65.) Clemens took advantage of these services, but also purchased additional services for herself and her family at a cost of $39.99 per month. (Id. at ¶ 71.) Since the breach, Clemens “has spent significant time and effort reviewing her financial accounts, bank records, and credit reports for unauthorized activity and will continue to do so.” (Id. at ¶¶ 61, 67–69.) She has occasionally missed work in order to pursue mitigative measures. (Id. at ¶ 70.) Once, after she changed her family’s bank account numbers, she was delayed from accessing her funds due to a mistake by the bank. (Id. at ¶ 69.) Clemens also says she sought and paid for counseling to cope with stress and anxiety caused by the breach. (Id. at ¶ 72.) She believes that “[g]iven the highly-sensitive nature of the information stolen, the value of [her] [p]ersonal

[i]nformation has been diminished and she remains at substantial and imminent risk of future harm.” (Id. at ¶¶ 73, 97.) But she does not allege she has experienced any identity theft or fraud. See generally (id.). According to Clemens, many breach victims “have already experienced significant harms . . . including, but not limited to, identity theft, financial fraud, tax fraud, medical and healthcare fraud, unauthorized financial accounts or lines of credit opened in their names, and fraudulent payment card purchases.” (Id. at ¶ 81.) Victims other than herself have also spent time, money and effort monitoring their accounts and protecting their information. (Id.) B

Clemens sued ExecuPharm and Parexel on July 10, 2020 seeking relief individually and on behalf of a class of individuals whose personal information was compromised by the breach. (Id. at ¶ 100.) Her Complaint asserts claims of negligence (Count I), negligence per se (Count II), breach of implied contract (Count III) and breach of contract (Count IV) against both Defendants and breach of fiduciary duty (Count V) and breach of confidence (Count VI) against ExecuPharm. See generally (id. at ¶¶ 116– 56). It also seeks a declaratory judgment stating Defendants’ existing data security measures fail to comply with their duties of care and instructing Defendants to implement and maintain industry-standard measures. (Id. at ¶¶ 157–61.) Defendants moved to dismiss the Complaint in full. See (Mot. to Dismiss 1, ECF No. 14). On February 5, 2021, the Court ordered the Parties to provide supplemental briefing addressing whether Clemens has standing to bring her claims. (Suppl.

Briefing Order, ECF No. 24.) In their Supplemental Brief, Defendants argue Clemens has not alleged an injury-in-fact sufficient to establish Article III standing in this Circuit. See generally (Defs.’ Suppl. Brief 2–8, ECF No. 25). Clemens argues she has established standing for all claims, but contends “irrespective of her other claims,” she “plainly” has standing for her contract-based causes of action. See generally (Pl.’s Suppl. Brief 3–10, ECF No. 26). II Article III of the United States Constitution limits the exercise of judicial power to cases and controversies. See Clapper v. Amnesty Int’l USA, 568 U.S. 398, 408 (2013); see also Taliaferro v. Darby Twp. Zoning Bd., 458 F.3d 181, 188 (3d Cir. 2006) (“Absent

Article III standing, a federal court does not have subject matter jurisdiction to address a plaintiff’s claims, and they must be dismissed.”).

Free access — add to your briefcase to read the full text and ask questions with AI

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Raines v. Byrd
521 U.S. 811 (Supreme Court, 1997)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Reilly Ex Rel. Pluemacher v. Ceridian Corp.
664 F.3d 38 (Third Circuit, 2011)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Pisciotta v. Old National Bancorp
499 F.3d 629 (Seventh Circuit, 2007)
Jim Bognet v. Secretary Commonwealth of PA
980 F.3d 336 (Third Circuit, 2020)
Federal Trade Commission v. Wyndham Worldwide Corp.
10 F. Supp. 3d 602 (D. New Jersey, 2014)
Storm v. Paytime, Inc.
90 F. Supp. 3d 359 (M.D. Pennsylvania, 2015)

Cite This Page — Counsel Stack

Bluebook (online)
Clemens v. Execupharm, Inc., Counsel Stack Legal Research, https://law.counselstack.com/opinion/clemens-v-execupharm-inc-paed-2021.