Griffey v. Magellan Health Incorporated

District Court, D. Arizona·Decided June 2, 2022·No. 2:20-cv-01282·Unknown

Opinion

WO

Chris Griffey, et al., No. CV-20-01282-PHX-MTL

Plaintiffs, ORDER

v.

Magellan Health Incorporated,

Defendant. Magellan Health, Inc.’s (“Magellan’s”) computer systems were hacked and a data breach occurred. The personally identifiable information (“PII”) and protected health information (“PHI”) of Magellan employees, Magellan contractors, and Magellan- administered health care benefit plan participants was stolen. Plaintiffs, in their individual capacities and as putative class representatives, assert several claims against Magellan arising from the data breach. The Court previously granted a motion to dismiss with leave to amend. (Doc. 39.) Magellan has filed a Motion to Dismiss (Doc. 41, the “Motion”) the Second Amended Consolidated Class Action Complaint (Doc. 40, the “Second Amended Complaint”) arguing that (1) Plaintiffs have not alleged a cognizable loss on their negligence and consumer protection claims and (2) Plaintiffs’ unjust enrichment claims and their various state law claims do not adequately allege “how Magellan’s data security was inadequate.” (Doc. 41 at 2.) The Motion (Doc. 41) will be granted in part and denied in part.1

1 Both parties have submitted legal memoranda, and oral argument would not have aided the Court’s decisional process. See Partridge v. Reich, 141 F.3d 920, 926 (9th Cir. 1998); The factual background has been previously summarized by this Court. See Griffey v. Magellan Health Inc., No. CV-20-01282-PHX-MTL, 2021 WL 4427065, at *1–2 (D. Ariz. Sept. 27, 2021). It will not be repeated here except where necessary or where new facts have been alleged. For example, the Second Amended Complaint asserts in greater detail why the data security that Magellan employed to protect Plaintiffs’ PII and PHI was inadequate. (Doc. 40 ¶¶ 58–65; 77–96.) Plaintiffs allege that Magellan failed to implement cybersecurity safeguards outlined by the Department of Health and Human Services’ Office for Civil Rights, the Federal Bureau of Investigation, the United States Cybersecurity & Infrastructure Security Agency, the Microsoft Threat Protection Intelligence Team, the University of Illinois Chicago, and the Center for Internet Security. (See id. ¶¶ 83–96.) These security safeguards include, but are not limited to: encrypting PII and PHI, educating and training employees, “correcting the configuration of software and network devices” (Id. ¶ 84), enabling strong spam filters, scanning incoming and outgoing emails, patching operating systems, configuring firewalls, “[s]et[ting] anti-virus and anti-malware programs to conduct regular scans automatically” (Id. ¶ 88), managing privileged accounts, “configur[ing] access controls . . . with least privilege in mind” (Id.), and “[d]isabl[ing] macro scripts from office files transmitted via email” (Id.). (See id. ¶¶ 77–96.) Additionally, Plaintiffs allege that Magellan “fail[ed] to monitor ingress and ingress network traffic; maintain an inventory of public facing [i]ps; monitor elevated privileges; equip its server with anti-virus or anti-malware; and employ basic file integrity monitoring.” (Id. ¶ 91.) The Second Amended Complaint posits that “the occurrence of the Data Breach indicates that Defendant failed to adequately implement one or more of the above measures to prevent ransomware attacks.” (Id.) Plaintiffs also allege that Magellan “failed to meet the minimum standards of the following cybersecurity frameworks: the NIST Cybersecurity Framework Version 1.1 (including without limitation PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-5, see also LRCiv 7.2(f); Fed. R. Civ. P. 78(b). PR.AC-6, PR.AC-7, PR.AT-1, PR.DS-1, PR.DS-5, PR.PT-1, PR.PT-3, DE.CM-1, DE.CM-4, DE.CM-7, DE.CM-8, and RS.CO-2), and the Center for Internet Security’s Critical Security Controls . . . which are established standards in reasonable cybersecurity readiness.” (Id. ¶ 96.) The Second Amended Complaint also alleges that Magellan has not provided an adequate credit monitoring service since the data breach. (See id. ¶¶ 5, 9, 11, 15, 26–27, 99.) Plaintiffs allege that the service that Magellan offers does not provide alerts for or monitor whether a Plaintiff’s personal information appears on the dark web or service and credit applications. (Id. ¶ 5.) They also allege that it does not provide alerts or monitor for a USPS address change verification or fake personal information connected to a person’s identity. (Id.) Additionally, they allege that it does not offer “identity theft monitoring and protection.” (Id. ¶¶ 9, 11.) Finally, Plaintiffs allege that the services offered by Magellan “fail[ed] to provide for the fact that victims of Data Breaches and other unauthorized disclosures commonly face multiple years of ongoing identity theft and financial fraud.” (Id. ¶ 104.) A complaint must contain “a short and plain statement of the claim showing that the pleader is entitled to relief” such that the defendant is given “fair notice of what the . . . claim is and the grounds upon which it rests.” Bell Atl. Corp. v. Twombly, 550 U.S. 545, 555 (2007) (quoting Fed. R. Civ. P. 8(a)(2); Conley v. Gibson, 355 U.S. 41, 47 (1957)). A complaint does not suffice “if it tenders ‘naked assertion[s]’ devoid of ‘further factual enhancement.’” Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (quoting Twombly, 550 U.S. at 556). Dismissal under Rule 12(b)(6) “can be based on the lack of a cognizable legal theory or the absence of sufficient facts alleged under a cognizable legal theory.” Balistreri v. Pacifica Police Dep’t, 901 F.2d 696, 699 (9th Cir. 1988). A complaint, however, should not be dismissed “unless it appears beyond doubt that the plaintiff can prove no set of facts in support of the claim that would entitle it to relief.” Williamson v. Gen. Dynamics Corp., 208 F.3d 1144, 1149 (9th Cir. 2000). The Court must accept material allegations in a complaint as true and construe them in the light most favorable to Plaintiffs. North Star Int’l v. Arizona Corp. Comm’n, 720 F.2d 578, 580 (9th Cir. 1983). “Indeed, factual challenges to a plaintiff’s complaint have no bearing on the legal sufficiency of the allegations under Rule 12(b)(6).” See Lee v. City of Los Angeles, 250 F.3d 668, 688 (9th Cir. 2001). Review of a Rule 12(b)(6) motion is “limited to the content of the complaint.” North Star Int’l, 720 F.2d at 581. A. Negligence “‘To establish a defendant’s liability for a negligence claim, a plaintiff must prove: (1) a duty requiring the defendant to conform to a certain standard of care; (2) breach of that standard; (3) a causal connection between the breach and the resulting injury; and (4) actual damages.’” CVS Pharmacy, Inc. v. Bostwick, 251 Ariz. 511, 517 (2021) (quoting Quiroz v. ALCOA Inc., 243 Ariz. 560, 563–64 (2018)). As before, Plaintiffs Culberson, Rayam, Leather, Williams, Ranson, Flanders, and Lewis allege that “[Magellan] had a duty of care to use reasonable means to secure and safeguard its computer property—and Class Members’ PII and PHI held within it—to prevent disclosure of the information, and to safeguard the information from theft.” (Doc. 40 ¶ 142.) They also allege that this “duty included a responsibility to implement processes by

Free access — add to your briefcase to read the full text and ask questions with AI

Griffey v. Magellan Health Incorporated, (D. Ariz. 2022).

Griffey v. Magellan Health Incorporated (Griffey v. Magellan Health Incorporated) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Conley v. Gibson
355 U.S. 41 (Supreme Court, 1957)
Watters v. Wachovia Bank, N. A.
550 U.S. 1 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Lee v. City Of Los Angeles
250 F.3d 668 (Ninth Circuit, 2001)
Vess v. Ciba-Geigy Corp. USA
317 F.3d 1097 (Ninth Circuit, 2003)
United States v. Ciresi
697 F.3d 19 (First Circuit, 2012)
Fink v. Time Warner Cable
714 F.3d 739 (Second Circuit, 2013)
Tamer Salameh v. Tarsadia Hotel
726 F.3d 1124 (Ninth Circuit, 2013)
Zucco Partners, LLC v. Digimarc Corp.
552 F.3d 981 (Ninth Circuit, 2009)
Robertson v. Sixpence Inns of America, Inc.
789 P.2d 1040 (Arizona Supreme Court, 1990)
Kertesz v. Net Transactions, Ltd.
635 F. Supp. 2d 1339 (S.D. Florida, 2009)
Luminous Unit Co. v. Freeman-Sweet Co.
3 F.2d 577 (Seventh Circuit, 1924)