Dobson v. SimonMed Imaging LLC

District Court, D. Arizona·Decided August 22, 2025·No. 2:25-cv-00527·Unknown

Opinion

WO

Star Do bson, ) No. CV-25-00527-PHX-SPL ) ) No. CV-25-00548-PHX-SPL (cons.) Plaintiff, ) No. CV-25-00601-PHX-SPL (cons.) vs. ) ) ORDER ) SimonMed Imaging LLC, ) ) Defendant. ) ) )

Before the Court is Defendant SimonMed Imaging, LLC’s (“SimonMed’s”) Motion to Dismiss (Doc. 17), Plaintiff’s Response (Doc. 19), and Defendant’s Reply (Doc. 22). The Court now rules as follows.1 This is a putative class action lawsuit brought pursuant to the Class Action Fairness Act (“CAFA”), 28 U.S.C. § 1332(d)(2). (Doc. 13 ¶ 19). Plaintiff Star Dobson, as well as consolidated plaintiffs Andree Guest, Albert Dumas, Rosemary Hamermaster, and other putative class members (collectively, “Plaintiffs”) are current and former patients at Defendant SimonMed, a healthcare provider that employs approximately 200 radiologists across 11 states. (Id. ¶¶ 27–28). SimonMed collects and electronically files private information from its patients, including names, dates of birth, addresses, passport

1 Because it would not assist in resolution of the instant issues, the Court finds the pending motion is suitable for decision without oral argument. See LRCiv. 7.2(f); Fed. R. Civ. P. 78(b); Partridge v. Reich, 141 F.3d 920, 926 (9th Cir. 1998). information, and Social Security numbers. (Id. ¶¶ 30, 35, 53–54). In February 2025, SimonMed fell victim to a data breach (the “Data Breach”) from the ransomware group Medusa, who claimed to have exfiltrated over 200 gigabytes of data from their systems, including files that contained patients’ and employees’ full names, dates of birth, mailing addresses, telephone numbers, email addresses, driver’s licenses, diagnostic images, passports, identification cards, Social Security numbers, health insurance details, medical records, payroll information, corporate emails, and more. (Id. ¶ 35). The putative plaintiffs allege that SimonMed “did not use reasonable security procedures and practices appropriate to the nature of the sensitive information they were maintaining,” and that the Data Breach was therefore preventable. (Id. ¶¶ 40, 44). Furthermore, they allege that they believe the stolen information has been sold on the dark web since the Data Breach occurred. (Id. ¶ 42). Plaintiffs also allege a number of individualized injuries they believe to be related to the Data Breach. Plaintiff Andree Guest “received notice that data related to her 401K account had been accessed and was required to reset her passwords.” (Id. ¶ 174). Plaintiff Albert Dumas received two unauthorized inquiries to his credit report. (Id. ¶ 185). Rosemary Hamermaster “experienced suspicious spam communications using Private Information compromised in the Data Breach.” (Id. ¶ 196). Plaintiffs’ Consolidated Class Action Complaint asserts claims for (1) negligence (id. ¶¶ 215–49), (2) negligence per se (id. ¶¶ 250–64), (3) breach of implied contract (id. ¶¶ 265–84), (4) breach of fiduciary duty (id. ¶¶ 285–93), and (5) unjust enrichment (id. ¶¶ 294–306). The proposed class consists of “[a]ll individuals residing in the United States whose Private Information was accessed and/or acquired by an unauthorized party as a result of the data breach that occurred at Defendant.” (Id. ¶ 201). To survive a motion to dismiss under Rule 12(b)(6), a complaint must contain “a short and plain statement of the claim showing that the pleader is entitled to relief” so that the defendant is given fair notice of the claim and the grounds upon which it rests. Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007) (quoting Fed. R. Civ. P. 8(a)(2)). A court may dismiss a complaint for failure to state a claim under Rule 12(b)(6) for two reasons: (1) lack of a cognizable legal theory, or (2) insufficient facts alleged under a cognizable legal theory. Balistreri v. Pacifica Police Dep’t, 901 F.2d 696, 699 (9th Cir. 1990). When deciding a motion to dismiss, all allegations of material fact in the complaint are taken as true and construed in the light most favorable to the nonmoving party. Cousins v. Lockyer, 568 F.3d 1063, 1067 (9th Cir. 2009). A. Negligence “To establish a claim for negligence, a plaintiff must prove four elements: (1) a duty requiring the defendant to conform to a certain standard of care; (2) a breach by the defendant of that standard; (3) a causal connection between the defendant’s conduct and the resulting injury; and (4) actual damages.” Gipson v. Kasey, 150 P.3d 228, 230 (Ariz. 2007). In its Motion to Dismiss, SimonMed argues that (1) Plaintiffs have not adequately alleged a duty of care, (2) Plaintiffs have not claimed an actual, cognizable injury resulting from any breach, and (3) Plaintiffs’ allegations of causation are conclusory and insufficient. (Doc. 17 at 6–11). Plaintiffs make two arguments to support their claim that SimonMed had a duty to protect their private information: (1) because of the special provider-patient relationship, which may give rise to a duty in tort, and (2) because of a common-law duty based on the “public policy of preventing wrongful disclosures of Private Information and identity theft.” (Doc. 19 at 11–12); see Quinalty v. FocusIT LLC, No. CV-23-00207-PHX-JJT, 2024 WL 342454, at *3 (D. Ariz. Jan. 30, 2024) (“In Arizona, several special relationships can give rise to a duty, including relationships based on contract, familial relations, or conduct undertaken by the defendant.”); see also Cal-Am Props. Inc. v. Edais Eng’g Inc., 509 P.3d 386, 389 (Ariz. 2022) (“Special relationships that give rise to a duty in negligence include legally recognized common law relationships and those formed by contract, familial relationship, or joint undertaking.”). SimonMed asserts a slightly different argument with respect to duty, arguing that Plaintiffs’ claims are premised not on a special relationship or public policy considerations, but on SimonMed voluntarily undertaking the responsibility to store their private data. (Doc. 17 at 6); see Quinalty, 2024 WL 342454, at *3. If so, as SimonMed argues, their negligence claim must fail, because Arizona requires a showing of physical harm to support a claim based on negligent undertaking. (Doc. 17 at 6). SimonMed is correct that if Plaintiffs are alleging a duty of care based on SimonMed voluntarily undertaking the responsibility to protect their private information, that claim must fail, as they have not alleged any physical harm caused by SimonMed’s negligence. See Cal-Am Props. Inc. v. Edais Eng’g Inc., 253 Ariz. 78, 83 (2022). Regarding the physician-patient special relationship, SimonMed argues that Plaintiffs have not cited “any Arizona authority extending a purported physician-patient duty to the data breach context.” (Doc. 22 at 2). This argument is somewhat persuasive. As the Arizona Court of Appeals has explained, “[t]he physician-patient relationship . . . creates a presumption that physicians will marshal information in their possession, pertinent to a patient’s health, to protect the patient from that risk of harm.” Doe I by & through Fleming & Curti, PLC v. Lenzner Med. Servs., LLC, 570 P.3d 977, 992 (Ariz. Ct. App. 2025) (Eckerstrom, J., dissenting). The question here, then, is whether SimonMed, in the course of its physician-patie

Free access — add to your briefcase to read the full text and ask questions with AI

Dobson v. SimonMed Imaging LLC, (D. Ariz. 2025).

Dobson v. SimonMed Imaging LLC (Dobson v. SimonMed Imaging LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Gipson v. Kasey
150 P.3d 228 (Arizona Supreme Court, 2007)
Ralph and Carolee Thomas v. Montelucia Villas
302 P.3d 617 (Arizona Supreme Court, 2013)
Barmat v. John and Jane Doe Partners AD
747 P.2d 1218 (Arizona Supreme Court, 1987)
Cousins v. Lockyer
568 F.3d 1063 (Ninth Circuit, 2009)
Cook v. Orkin Exterminating Co., Inc.
258 P.3d 149 (Court of Appeals of Arizona, 2011)
Span v. Maricopa
437 P.3d 881 (Court of Appeals of Arizona, 2019)