Frechette v. Health Recovery Services, Inc.

District Court, S.D. Ohio·Decided August 29, 2023·No. 2:19-cv-04453·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE SOUTHERN DISTRICT OF OHIO EASTERN DIVISION

TIANA FRECHETTE, et al., : : Plaintiffs, : Case No. 2:19-cv-4453 : v. : Chief Judge Algenon L. Marbley : HEALTH RECOVERY SERVICES, INC., : Magistrate Judge Jolson : Defendant. :

OPINION & ORDER This matter is before the Court on Plaintiffs’ Motion for Class Certification. (ECF No. 60). This case involves a dispute between the parties arising from unauthorized third-party access (the “breach”) to Defendant’s computer storage systems, which contained Plaintiffs’ personal and medical information. (ECF No. 38 ¶ 1). For the following reasons, Plaintiffs’ Motion is DENIED. I. BACKGROUND A. Factual Background Defendant Health Recovery Services (“HRS”) is a non-profit that provides services to those suffering from mental illness or substance abuse issues, including Plaintiffs and their putative class. (ECF No. 38 ¶¶ 2–5). Plaintiff Tiana Frechette was a patient of HRS at the time of the breach. (Id. ¶ 2). Minors J.F. and C.F., represented in this lawsuit by their mother and guardian, Jane Doe, were also patients of HRS at the time of breach. (Id. ¶¶ 3–4). On February 5, 2019, HRS discovered that an unauthorized IP address remotely had accessed its computer network since November 14, 2018. (Id. ¶¶ 1, 30). On the network, HRS stored the personal and medical information of its clients, including Plaintiffs and the class they seek to represent. (Id. ¶¶ 1, 6). HRS sent notice of this data breach on April 4, 2019, two months after it was discovered. (Id. ¶ 30). Specifically, HRS sent out 20,845 data breach notification letters containing the following language: On March 15, 2019, our third-party forensic expert determined that this unauthorized access to our network occurred from November 14, 2018 until its discovery on February 5, 2019. While the forensic expert has indicated to us that they do not believe that any of HRS’ patient information was ever in fact accessed, they were unable to definitively rule out that possibility.

While our investigation is ongoing, we have no evidence that the unknown third party accessed or acquired protected health information stored on the HRS server. Nevertheless, we confirmed this server stored files and a software application which may have contained your (your minor’s) name, address, phone number, (and) date of birth, (and Social Security number). If you (your minor) were a patient of HRS after 2014, the information stored in the files and software application also included your (your minor’s) medical information, health insurance information, diagnosis, and treatment information. Out of an abundance of caution, we are providing notice of this incident to you given we cannot rule out unauthorized access to this information occurred.

(ECF No. 60-1 at 4–5; ECF No. 62-3 at 1). According to HRS, not all of the 20,845 people to whom it sent the data breach notification letter (the “notification letters”) were patients. (ECF No. 66 at 14). As HRS’s Chief Financial Officer Regina Smith stated in her deposition, that number “could have included people that [HRS had] never seen, never talked to, had no record, never patients.” (Regina Smith Deposition, ECF No. 62-2 at 25:23–26:1). Plaintiffs allege that HRS failed “to maintain reasonable and adequate procedures to protect and secure the Personal Information,” “to timely discover the unauthorized access,” and “to provide Plaintiffs and the Data Breach Class members with timely information regarding the unauthorized access.” (ECF No. 28 ¶ 33). Plaintiffs state that their personal and medical information was “compromised,” “misappropriated,” “access[ed],” and “stolen” through the breach. (Id. ¶¶ 30, 31, 39, 40). HRS’s alleged failures “resulted in financial injuries to Plaintiffs and [the class] and has placed [them] at grave risk of identity theft and other possible fraud and abuse.” (Id. ¶ 33). Those alleged injuries stem from invasion of privacy; out-of-pocket costs for protective and reactive measures such as credit monitoring; and mental and emotional distress from having highly sensitive health information disclosed. (Id. ¶¶ 40–46, 49–52). According to HRS, there is no evidence that anyone’s information was accessed by the interloper. (ECF No.

66 at 4). Instead, it argues, the unauthorized access was only to a dummy server containing “pseudo-client” information on it to test its new system. (Regina Smith Declaration, ECF No. 66- 1 ¶¶ 16–17; ECF No. 66 at 1). HRS represents that it sent letters to every individual with information in HRS’s entire computer system notifying them of the data security incident merely out of an abundance of caution. (Smith Declaration ¶ 18; ECF No. 66 at 4). B. Procedural Background On October 6, 2019, Plaintiffs filed their original Complaint. (ECF No. 1). It was superseded on January 6, 2020, by Plaintiffs’ First Amended Complaint (ECF No. 6), which HRS moved to dismiss (ECF No. 9). This Court issued an Opinion, granting dismissal on six of

ten counts in the First Amended Complaint for failure to state a claim—but preserving four counts for breach of implied contract, unjust enrichment, and willful and negligent violations of the Fair Credit Reporting Act (“FCRA”). (ECF No. 23). Those are the only counts alleged in the Second Amended Complaint, which Plaintiffs filed on February 17, 2021. (ECF No. 38). This is the operative Complaint in this case. The factual allegations largely track those in the First Amended Complaint. This Court issued another Opinion, granting dismissal on two of the four counts in the Second Amended Complaint for failure to state a claim—this time preserving only two counts for breach of implied contract and unjust enrichment. (ECF No. 44). On January 9, 2023, Plaintiffs filed their Motion for Class Certification. (ECF No. 60). In their Motion, Plaintiffs seek an order from this Court to allow the case to proceed as a class action pursuant to Rule 23 of the Federal Rules of Civil Procedure. Specifically, Plaintiffs argue that this case satisfies the requirements of Rule 23(a) and should be certified under Rule 23(b)(3). Plaintiffs request the following class definition:

All HRS patients whose personal information or medical information was compromised as a result of the data breach first disclosed by Defendant Health Recovery Services, Inc. on April 5, 2019.

(ECF No. 60-1 at 6). Plaintiffs’ Motion is ripe for this Court’s consideration. II. STANDARD OF REVIEW A plaintiff seeking class certification bears the burden of establishing compliance with all four requirements of Rule 23(a), referred to by the shorthand of “(1) numerosity, (2) commonality, (3) typicality, and (4) adequacy.” Fed. R. Civ. P. 23(a); Alkire v. Irving, 330 F.3d 802, 820 (6th Cir. 2003). Additionally, even though Rule 23 has no express ascertainability requirement, the Sixth Circuit has held that it is implicitly required for class certification. Cole v. City of Memphis, 839 F.3d 530, 541 (6th Cir. 2016); see also Carrera v. Bayer Corp., 727 F.3d 300 (3d Cir. 2013). Ascertainability is met where the “class description [is] sufficiently definite so that it is administratively feasible for the court to determine whether a particular individual is a member.” Cole, 839 F.3d at 541 (quoting Young v. Nationwide Mut. Ins.

Free access — add to your briefcase to read the full text and ask questions with AI

Frechette v. Health Recovery Services, Inc., (S.D. Ohio 2023).

Frechette v. Health Recovery Services, Inc. (Frechette v. Health Recovery Services, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Eisen v. Carlisle & Jacquelin
417 U.S. 156 (Supreme Court, 1974)
General Telephone Co. of Southwest v. Falcon
457 U.S. 147 (Supreme Court, 1982)
Wal-Mart Stores, Inc. v. Dukes
131 S. Ct. 2541 (Supreme Court, 2011)
In Re American Medical Systems, Inc. Pfizer, Inc.
75 F.3d 1069 (Sixth Circuit, 1996)
Lloyd D. Alkire v. Judge Jane Irving
330 F.3d 802 (Sixth Circuit, 2003)
Gabriel Carrera v. Bayer Corp
727 F.3d 300 (Third Circuit, 2013)
Dino Rikos v. The Procter & Gamble Co.
799 F.3d 497 (Sixth Circuit, 2015)
Lakendus Cole v. City of Memphis
839 F.3d 530 (Sixth Circuit, 2016)
Young v. Nationwide Mutual Insurance
693 F.3d 532 (Sixth Circuit, 2012)