Crosby v. OneTouchPoint Inc

District Court, E.D. Wisconsin·Decided September 23, 2024·No. 2:22-cv-00882·Unknown

Opinion

UNITED STATES DISTRICT COURT EASTERN DISTRICT OF WISCONSIN

RICHARD DUSTERHOFT, et al,

Plaintiffs, v. Case No. 22-cv-0882-bhl

ONETOUCHPOINT CORP,

Defendant. ______________________________________________________________________________

ORDER GRANTING IN PART AND DENYING IN PART DEFENDANT’S MOTION TO DISMISS ______________________________________________________________________________ This putative class action stems from an April 2022 data breach in which hackers gained access to Defendant OneTouchPoint Corp. (OneTouchPoint)’s computer systems. Plaintiffs have filed fifteen lawsuits against OneTouchPoint, alleging that their personal information was exposed as a result of the data breach. In a September 29, 2022 order, the Court consolidated the actions and appointed interim co-lead counsel, who, with OneTouchPoint’s consent, filed a Consolidated and Amended Class Action Complaint (Consolidated Complaint). (See ECF Nos. 12 & 15.) After the parties spent more than a year attempting a settlement, on November 20, 2023, OneTouchPoint filed a motion to dismiss, contending that Plaintiffs lack standing to pursue their claims and, even if they have standing, they fail to state actionable claims. (ECF Nos. 55 & 55-1.) The Court will grant OneTouchPoint’s motion but only in part. With respect to standing, the Court is skeptical that all of the named Plaintiffs have in fact suffered sufficiently concrete injuries to support standing, but under binding Seventh Circuit law, the Consolidated Complaint sufficiently alleges injury at the pleading stage for all but one Plaintiff (Dusterhoft). The Court agrees with OneTouchPoint, however, that Plaintiffs’ claims for injunctive and declaratory relief are unlikely to be redressed by a favorable decision and that portion of the motion to dismiss will be granted. The Court also agrees with OneTouchPoint that Plaintiffs have failed to support at least some of their substantive claims with plausible factual allegations sufficient to maintain those claims, and those claims will be dismissed. Plaintiffs have adequately alleged several of their other claims, however, and OneTouchPoint’s motion will be denied as to those causes of action, which include their common-law claims for negligence, negligence per se, and unjust enrichment, as well as statutory claims under Wisconsin, Georgia, and South Carolina law. BACKGROUND1 This litigation arises from an April 27, 2022 data breach at OneTouchPoint. (ECF No. 15 ¶5.) OneTouchPoint is a mailing and printing services vendor in the healthcare sector. (Id. ¶2.) Plaintiffs include patients of OneTouchPoint’s clients whose personal information was compromised in the data breach, along with two former OneTouchPoint employees whose information was similarly compromised. (Id. ¶¶43, 208, 278.) Plaintiffs’ proposed class includes the approximately 2.6 million individuals whose personal information was exposed during the breach. (Id. ¶¶1, 22.) OneTouchPoint is a Delaware corporation headquartered in Hartland, Wisconsin. (Id. ¶33.) It provides services including brand management, marketing, printing, and supply chain logistics to healthcare providers. (Id. ¶37.) In order to provide its services, OneTouchPoint requires its clients to provide information about their patients, including personally identifiable information (PII) and personal health information (PHI). (Id. ¶¶1, 3.) The information OneTouchPoint collects and maintains includes names, addresses, Social Security numbers (SSNs), member IDs, dates of birth, health insurance information, and other medical information provided during health assessments. (Id. ¶¶3, 39.) On April 28, 2022, OneTouchPoint detected encrypted files on some of its computer systems. (Id. ¶4.) A subsequent investigation revealed that an unauthorized party had accessed some of its servers on April 27, 2022. (Id. ¶5.) Less than six weeks later, on June 3, 2022, OneTouchPoint provided written notice of the breach to its clients. (Id. ¶6.) The notice letter stated that “the impacted systems contained information related to individuals provided by [OneTouchPoint’s] customers,” but OneTouchPoint could not confirm what personal information was accessed by the perpetrator. (Id. ¶7.) OneTouchPoint initially reported that the breach impacted 1,073,316 individuals’ data, but that number later rose to more than 2.6 million. (Id. ¶9.) The affected individuals include patients of nearly 40 health insurance companies and healthcare service providers. (Id. ¶60.)

Free access — add to your briefcase to read the full text and ask questions with AI

Crosby v. OneTouchPoint Inc, (E.D. Wis. 2024).

Crosby v. OneTouchPoint Inc (Crosby v. OneTouchPoint Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Schilling v. Rogers
363 U.S. 666 (Supreme Court, 1960)
Warth v. Seldin
422 U.S. 490 (Supreme Court, 1975)
City of Los Angeles v. Lyons
461 U.S. 95 (Supreme Court, 1983)
Papasan v. Allain
478 U.S. 265 (Supreme Court, 1986)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Wilton v. Seven Falls Co.
515 U.S. 277 (Supreme Court, 1995)
Raines v. Byrd
521 U.S. 811 (Supreme Court, 1997)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Davis v. Federal Election Commission
554 U.S. 724 (Supreme Court, 2008)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Virgil Jean v. William E. Dugan
20 F.3d 255 (Seventh Circuit, 1994)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Parks v. MacRo-dynamics, Inc.
591 P.2d 1005 (Court of Appeals of Arizona, 1979)
Auto-Owners Insurance v. Websolv Computing, Inc.
580 F.3d 543 (Seventh Circuit, 2009)
Zastrow v. Journal Communications, Inc.
2006 WI 72 (Wisconsin Supreme Court, 2006)
Merrill Lynch, Pierce, Fenner & Smith, Inc. v. Boeck
377 N.W.2d 605 (Wisconsin Supreme Court, 1985)