* * *
Case No. 2:25-cv-01123-GMN-BNW
ENTERPRISES DATA BREACH ORDER
Before this Court is Defendant Effortless Office Enterprises, LLC’s (“Effortless”) motion to dismiss. ECF No. 43. Plaintiffs responded at ECF No. 47, and Effortless replied at ECF No. 55. For the reasons discussed below, this Court recommends that Effortless’s motion be granted in part and denied in part. A. Facts and Procedural History Plaintiffs bring this putative class action individually and on behalf of a nationwide class of all individuals residing in the United States whose private information may have been compromised in a data breach suffered by Defendant Effortless. ECF No. 36 at 3. Effortless provided IT and cloud services to Defendant Nevada Heart & Vascular Center, LLP (“NHVC”). Id. An unauthorized actor accessed personal information stored on an Effortless computer network between May 9, 2024, and July 23, 2024. Id. at 12. Nearly a year later, on May 12, 2025, NHVC learned that some of its data was impacted as a result of this breach. Id. On or about June 13, 2025, Effortless began notifying individuals potentially impacted by the Effortless breach, including Plaintiffs. Id. at 11. Plaintiffs allege that they were required to provide their personally identifiable information (“PII”) and personal health information (“PHI”), such as their full names, addresses, dates of birth, social security numbers, medical information, and health insurance information, to NHVC1, which provided this information to Effortless. Id. at 36, 38, 40, 42, 43. NHVC subsequently provided this information to Effortless. Id. at 36, 38, 40, 43. All Plaintiffs allege that they diligently protect their private information and that they are not aware of ever being a part of a data breach involving their medical records. Id. at 36, 38, 40, 42, 43. All Plaintiffs also allege that they have taken multiple steps to avoid identity theft, including increasingly reviewing their credit monitoring service, setting up notices and reports, and carefully reviewing all their accounts. Id. at 37, 39, 41, 43, 44. They allege that they have already spent many hours of valuable time dealing with the data breach and that they anticipate spending considerable time and money on an ongoing basis trying to mitigate and address harms caused by the breach. Id. at 37, 39, 41, 43, 44. Plaintiffs allege that they are presently at risk and will continue to be at increased risk of identity theft and fraud for their lifetimes. Id. at 38, 40–43, 45. Plaintiffs allege that they have suffered actual injuries from having their private information compromised because of the breach, including damage to and diminution in the value of their private information, violation of privacy rights; and present, imminent, and impending injury from the increased risk of identity theft and fraud. Id. at 37, 39–41, 43–44. Plaintiffs also allege that they have experienced significant worry, anxiety, and emotional distress regarding the disclosure of their private information. Id. at 38, 40–41, 43, 45. Plaintiff Laurana Faith Smith adds that she experienced a fraudulent login attempt on her Microsoft Xbox account originating from out of the state following the data breach, although Xbox support was able to resolve the issue. Id. at 37. Plaintiff Nguyen adds that she received notification from a commercially available product that her Social Security Number was found on the dark web following the data breach. Id. at 40. Plaintiff Richard Obringer alleges that he also experienced a significant increase in spam text messages, telephone calls, and emails since the breach occurred. Id. at 41. Plaintiff Carden states that an unauthorized third party purchased an
1 One of the plaintiffs, Josephine Margaret Russo, was not a patient of NHVC but was rather a patient at Saint Rose Hospital. ECF No. 36 at 42. Saint Rose Hospital was also a client of iPhone on his Costco Visa card on July 17, 2025, and that following the data breach, an unauthorized third party opened several accounts using his email address. Id. at 45. He also alleges that he experienced a significant increase in spam text messages and emails following the data breach. Id. After several cases arising out of the same data breach were filed, the cases were consolidated. See ECF No. 30 (consolidating 2:25-cv-01134-GMN-EJY, 2:25-cv-01135-GMN- BNW, 2:25-cv-01142-GMN-MDC, 2:25-cv-01145-GMN-EJY, 2:25-cv-01149-GMN-MDC, 2:25-cv-01486-GMN-EJY under 2:25-cv-01123). Plaintiffs then filed a superseding consolidated complaint against both NHVC and Effortless alleging four causes of action: (1) negligence/negligence per se; (2) breach of third-party beneficiary contract as to Defendant effortless; (3) invasion of privacy/intrusion upon seclusion as to both Defendants; and (4) unjust enrichment. ECF No. 36 at 49–59. Defendant NHVC moves to dismiss the claims against it under R. See generally ECF No. 46. B. Parties’ Arguments Defendant Effortless moves to dismiss Plaintiffs’ complaint under Rule 12(b)(6) for failure to state a claim for which relief can be granted. ECF No. 43 at 1. Effortless argues that Plaintiffs fail to adequately allege facts to establish all the elements of their negligence/negligence per se claim, breach of third-party beneficiary claim, invasion of privacy claim, and unjust enrichment claim. Id. at 3. Plaintiffs respond that their allegations are sufficient to establish all elements required for each cause of action. ECF No. 47 at 5, 18, 20–21. Rule 12(b)(6) of the Federal Rules of Civil Procedure mandates that a court dismiss a cause of action that fails to state a claim upon which relief can be granted. Fed. R. Civ. P. 12(b)(6); see also North Star Int’l v. Ariz. Corp. Comm’n, 720 F.2d 578, 581 (9th Cir. 1983). When considering a motion to dismiss under Rule 12(b)(6), dismissal is appropriate only when the complaint does not give the defendant a fair notice of a legally cognizable claim and the grounds on which it rests. See Bell Atl. Corp. v. Twombly, 550 U.S. 544, 555 (2007). In allegations as true and construe them in the light most favorable to the plaintiff. See NL Indus., Inc. v. Kaplan, 792 F.2d 896, 898 (9th Cir. 1986). The court, however, is not required to accept as true allegations that are merely conclusory, unwarranted deductions of fact, or unreasonable inferences. See Sprewell v. Golden State Warriors, 266 F.3d 979, 988 (9th Cir. 2001). A formulaic recitation of a cause of action with conclusory allegations is not sufficient; a plaintiff must plead facts showing that a violation is plausible, not just possible. Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009) (citing Twombly, 550 U.S. at 555). “A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. A court may not look beyond the complaint to a plaintiff’s moving papers, such as a memorandum in opposition to a defendant’s motion to dismiss. Schneider v. Cal. Dep’t. of Corr., 151 F.3d 1194, 1197 n.1 (9th Cir. 1998). If a court grants a motion to dismiss for failure to state a claim, leave to amend “shall be freely given when justice so requires.” Fed. R. Civ. P. 15(a)(2). Leave to amend should be granted unless it is clear that the deficiencies in the complaint cannot be cured by amendment. DeSoto v. Yellow Freight Sys., Inc., 957 F.2d 655, 659 (9th Cir. 1992). A. Negligence/Negligence Per Se Under Nevada law, a negligence claim requires four elements: “(1) the existence of a duty of care, (2) breach of that duty, (3) legal causation, and (3) damages.” Sanchez ex rel. Sanchez v. Walmart Stores, Inc., 125 Nev. 818, 824, 221 P.3d 1276, 1280 (2009) (internal citation omitted). Effortless moves to dismiss Plaintiffs’ negligence/negligence per se claim because Plaintiffs fail to sufficiently allege that they suffered “cognizable harm” to establish the damages element. ECF No. 43 at 5. Effortless contends that none of the categories of alleged harm— increased risk of fraud, identity theft, and misuse of PII; lost time, diminished value of private information; loss of benefit of the bargain; and increased anxiety—are sufficient to satisfy the damages element of their claims because each one is supported by vague and conclusory 1. Increased Risk of Fraud, Identity Theft, and Misuse of PII Plaintiffs’ complaint alleges that they suffered present, imminent, and impending injury arising from the increased risk of identity theft, fraud, and increased risk of PII. ECF No 36 at 54, 57. The Court has found that “alleged injuries that stem from a danger of future harm are insufficient to support a negligence action. Pruchnicki v. Envision Healthcare Corp., 439 F. Supp. 3d 1226, 1232 (D. Nev. 2020), aff’d 845 F. App'x 613 (9th Cir. 2021). However, the Court in Smallman v. MGM Resorts Int’l found that where plaintiffs have already alleged that their stolen PII has been posted on the dark web, it is “evident that the PII stolen [] will provide further ammo for hackers to commit identity fraud or threat in the future.” 638 F. Supp. 3d. 1175, 1191 (D. Nev. 2022) (internal citation omitted). In coming to its conclusion, the Court pointed to the Seventh Circuit’s reasoning that, “[p]resumably, the purpose of the hack is, sooner or later, to make fraudulent charges or assume those consumers’ identities”. Id. (citing Remijas v. Neiman Marcus Grp., LLC. 794 F.3d 688, 693 (7th Cir. 2015). Here, Plaintiffs allege fraudulent login attempts, increases in spam text messages, telephone calls, and emails (many of which regarded health insurance); notifications that PII has been found on the dark web, and even an unauthorized purchase on a credit card following the data breach. ECF No. 36 at 37–38, 40–41, 45. Plaintiffs connect these incidents with the data breach by stating that “upon information and belief” the alleged injuries were the direct result of the breach. Id. at 38, 40–41, 45. Plaintiff Russo is the only plaintiff that does not allege a specific incident in which her personal information was used nefariously. Although Defendants argue that Plaintiffs’ allegations lack adequate detail, detailed factual allegations are not required at the pleading stage. Fed. R. Civ. P. 8(a) (2); Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009). Following the Court’s logic in Smallman, this Court finds that, because all Plaintiffs (except for Plaintiff Russo) allege specific facts to show their PII has been stolen and accessed by bad actors, they sufficiently plead likelihood of future harm. As Plaintiff Russo does not sufficiently plead likelihood of future harm, this Court recommends that her negligence/negligence per se claim be dismissed to the extent she alleges damages solely on 2. Lost Time Plaintiffs’ complaint alleges that they suffered the harm of lost time and expense associated with the data breach. ECF No. 36 at 54, 57. The Court has previously found that a plaintiff’s lost time, without an accompanying expenditure, is insufficient to constitute a cognizable injury. Pruchnicki v. Envision Healthcare Corp., 439 F. Supp. 3d 1226, 1233 (D. Nev. 2020), aff’d 845 F. App'x 613 (9th Cir. 2021) (holding that “tangible out-of-pocket expenses are required for lost time monitoring credit to be cognizable as damages”). Plaintiffs Smith, Obringer, Russo, and Carden allege that they have spent valuable time monitoring credit reports and reviewing financial statements for signs of identity theft, but none of them allege concrete out-of- pocket expenses. Accordingly, these Plaintiffs fail to sufficiently allege damages related to lost time and this Court recommends the dismissal of their negligence/negligence per se claim to the extent they allege damages solely on lost time with leave to amend. Plaintiff Nugyen, on the other hand, alleges that she paid $29.99 per month for a credit monitoring product. ECF No. 36 at 39. Effortless argues that Plaintiff Nguyen’s allegation is insufficiently pled she fails to specify whether she purchased this service after or as a result of the data breach. ECF No. 43 at 11. This Court disagrees. The complaint states that “as a result [of the breach], [Nguyen] has taken multiple steps to avoid identity theft…[a]dditionally, she has enrolled in Experian credit monitoring for which she pays $29.99 per month.” ECF No. 36 at 39. Because Plaintiff Nguyen plausibly alleges that she paid out-of-pocket for a credit monitoring product in connection with the data breach, she has sufficiently pled allegations to support lost time damages. See Ashcroft v. Iqbal, 556 U.S. 662, 678 (2009). 3. Diminished Value of Private Information Plaintiffs’ complaint alleges that the value of their private information has been either lost or diminished as a result of the data breach. ECF No. 36 at 53, 57. “Diminution in value of personal information can be a viable theory of damages.” Pruchnicki v. Envision Healthcare Corp., 439 F. Supp 3d 1226, 1234 (D. Nev. 2020), aff’d 845 Fed. App'x 13 (9th Cir. 2021). Effortless contends that to obtain damages under this theory, Plaintiffs must establish that there is market is impaired. Id.; see Svenson v. Google, Inc., No. 13-cv-04080-BLF, 2016 WL 8943391, at *9 (N.D. Cal. Dec. 21, 2016). Under Effortless’s formulation of the test, Plaintiffs are required to prove they intended to sell their own PII. Pruchnicki, 439 F. Supp 3d at 1235 (examining whether there were specific allegations that plaintiff was “unable to sell” her own PII while assessing any diminution in value of the PII). But this pleading requirement is not supported by Ninth Circuit precedent, and other district courts in the Ninth Circuit have rejected it. See In re Anthem, No. 15-MD-02617-LHK, 2016 WL 3029783, at *15 (N.D. Cal. May 27, 2016) (“The statements…appear to require a plaintiff to allege that there was either an economic market for their PII or that it would be harder to sell their own PII, not both.”) (emphasis in the original); Svenson, 2015 WL 1503429, at *5 (“The Ninth Circuit’s holding [in its May 2014 Facebook Privacy Litig. decision] does not require [this] type of explication…”) (emphasis in the original). Here, Plaintiffs allege that “[a] sophisticated black market exists on the dark web where criminals can buy or sell…personal and medical information like the Private Information at issue here.” ECF No. 36 at 27. They allege that criminals monetize data by “selling the stolen information on the Internet black market to other criminals who then utilize the information to commit a variety of identity theft related crimes.” Id. Moreover, some Plaintiffs, like Plaintiff Nguyen, specifically allege that their information has been found on the dark web following the data breach. Id. at 40. Accordingly, Plaintiffs sufficiently allege facts to support that there was an economic market for their stolen information. This Court finds that Plaintiffs have stated a cognizable theory of damages for diminution of value. 4. Loss of Benefit of the Bargain Plaintiffs’ complaint alleges that they suffered loss of the benefit of the bargain because they provided their private information in order to obtain services from Defendants and expected that they were, in part, paying to protect the private information they provided. ECF No. 36 at 36. They further allege that because Defendants failed to provide the expected data security, Plaintiffs lost the benefit of the bargain. Id. at 36, 54. Effortless argues that Plaintiffs fail to sufficiently subsumed within the cost of goods provided by Defendant NHVC. ECF No. 43 at 14. Defendants also argue Plaintiffs hey also failed to demonstrate any actual loss resulting from the data breach. Id. Courts are divided on the level of detailed factual allegation required in data breach cases to show that data security was part of the bargain. Smallman v. MGM Resorts Int’l, 638 F. Supp. 3d. 1175, 1189 (D. Nev. 2022). Some out-of-district courts in the Ninth Circuit accept more general allegations that security was expected and was thus a part of the bargain. See In re Anthem, Inc. Data Breach Litig., 162 F. Supp. 3d 953, 992, 995 (N.D. Cal. 2016) (adopting a “loss of benefit of the bargain” theory for plaintiffs who alleged they had contracted for “reasonable and adequate security measures” that Anthem failed to deliver, causing plaintiffs to overpay for health insurance); In re Intel Corp. CPU Mktg, Sales Pracs. and Prods. Liab. Litig., No. 3:18-md-2828-SI, 2020 WL 1495304, at *8 (D. Or. Mar. 27, 2020) (holding that more general factual allegations about the plaintiffs’ expectations for data security and the contours of the parties’ bargain are sufficient at the pleading stage), aff’d No. 22-35652, 2023 WL 7211394 (9th Cir. Nov. 2, 2023). Other cases have required more specific factual allegations showing how data security was a part of the bargain or how much of the money was spent on data security. See e.g., Gardiner v. Walmart, Inc., No. 20-cv-04618, 2021 WL 4992539, at *5 (N.D. Cal. July 28, 2021) (holding that plaintiff’s allegations did not support his benefit of the bargain theory where defendant’s privacy policy did not discuss pricing or charges for data security). This District has previously relied upon the line of cases that accept more general factual allegations about the plaintiff’s expectations for data security. See Smallman, 638 F. Supp. 3d. at 1190. Following this line of cases, and based on the arguments presented, this Court finds that Plaintiffs sufficiently pled their benefit of the bargain theory of damages because Plaintiffs allege that they “as patients of Defendant Effortless Office’s clients, understood and expected that they were, in part, paying for services and data security to protect the Private Information they were required to provide”. ECF No. 36 at 36. 5. Increased Anxiety Plaintiffs’ complaint alleges that they have suffered anxiety and emotional harm due to the disclosure of their private information to cybercriminals. ECF No. 36 at 54. Under Nevada law, “in the absence of physical impact, proof of serious emotional distress causing physical injury or illness must be presented”. Pruchnicki v. Envision Healthcare Corp., 845 F. App'x 613 (9th Cir. 2021) (citing Olivero v. Lowe, 116 Nev. 395, 399, 995 P.2d 1023, 1026 (2000) (internal quotation marks omitted). Here, Plaintiffs only assert that they suffered anxiety and emotional harm “due to their Private Information’s disclosure to cybercriminals.” ECF No. 36 at 54. Because Plaintiffs have not asserted the existence of any physical injury or illness, they fail to establish cognizable harm to warrant damages for anxiety and emotional distress. This Court recommends the dismissal of Plaintiffs’ negligence/negligence per se claim to the extent they allege damages solely on anxiety and emotional distress with leave to amend. B. Breach of Third-Party Beneficiary Contract To state a claim for breach of contract under Nevada law, the plaintiff must allege: (1) the existence of a valid agreement between the plaintiff and the defendant; (2) a breach by the defendant and (3) damages as a result of the breach. Med. Providers Fin. Corp. II v. New Life Centers, L.L.C., 818 F. Supp 2d 1271, 1274 (D. Nev. 2011). To show the existence of a valid agreement, a plaintiff must show that there was: (1) offer and acceptance, (2) meeting of the minds, and (3) consideration. May v. Anderson, 121 Nev. 668, 672, 119 P.3d 1254, 1257 (2005). Effortless argues that Plaintiffs failed to adequately allege that there was consideration and a meeting of the minds such that a valid agreement was formed. ECF No. 43 at 15. Effortless argues that Plaintiffs cannot establish that there was valid consideration to establish a contract because Plaintiffs do not allege that they paid for cybersecurity measures when they provided their information to NHVC.2 Id. at 16. Plaintiffs allege that they are third-party beneficiaries to the contract between Effortless and its clients rather than a party to the contract. In turn, this Court construes Effortless’s argument to be that because Plaintiffs do not sufficiently allege that they paid Effortless’s clients for data protection, they do not sufficiently allege that the clients themselves gave consideration for the enforcement of the contracts. To the extent Effortless makes this argument, this Court agrees. Although Plaintiffs allege that, “Defendant Effortless Office entered into contracts to provide IT services to its clients” this allegation is conclusory and does not clearly allege payment or any consideration in exchange for data protection. Effortless also argues that Plaintiffs do not establish a meeting of the minds because they fail to allege that Effortless provided or made any assurances in their contracts with their clients that it would provide data security services in connection with the health care services provided to Plaintiffs. ECF No. 16. This argument appears to question Plaintiffs’ status as third party beneficiaries. To assert third-party beneficiary status, as Plaintiffs do here, “there must clearly appear a promissory intent to benefit the third party…and ultimately it must be shown that the third party’s reliance thereon is foreseeable.” Elizabeth E. v. ADT Sec. Sys. West. Inc., 108 Nev. 889, 839 P.2d 1308, 1311 (Nev. 1992). Although the complaint does not specifically allege that data security services would be connected to health care services, it does allege Effortless contractually agreed to receive and protect its clients’ customers’ private information. ECF No. 36 at 54. Plaintiffs provided their private information to Effortless’s clients with the expectation that their information would be protected. Id. at 55. As the collection and protection of customers’ private information was the “direct and primary objective of the contracting parties”, Plaintiffs, as customers of Effortless’s clients, relied on that protection. Id. at 54–55. Accordingly, Plaintiffs sufficiently allege third party beneficiary status by alleging that there was a promissory intent to benefit them (protection of their private information) and that they foreseeably relied on that benefit. Nevertheless, because Plaintiffs failed to clearly allege there was consideration to support the existence of a valid agreement between the plaintiff and the defendant, Plaintiffs’ breach of third-party beneficiary contract claim fails. Because it is unclear that amendment would be futile, this Court recommends that this claim be dismissed with leave to amend. Because leave to amend is recommended, this Court also addresses the damages element of Plaintiffs’ claim to guide amendment. As with the negligence/negligence per se claim, Effortless argues that Plaintiffs fail to establish cognizable harm to establish damages. ECF No. 43 at 5. For the reasons discussed in Section III(A) (3), this Court finds that all Plaintiffs sufficiently allege that they suffered diminution in value of their PII and loss of benefit of the bargain. This Court also finds that Plaintiffs Smith, Nguyen Obringer and Carden sufficiently plead facts to support increased risk of fraud, identity theft, and misuse of PII and that Plaintiff Nguyen sufficiently alleges damages as to lost time. Plaintiffs Smith, Russo, Obringer, and Carden fail to sufficiently plead damages as to lost time. Plaintiff Russo fails to plead increased risk of fraud, identity theft and misuse of PII. C. Invasion of Privacy: Intrusion Upon Seclusion To state a claim for intrusion upon seclusion under Nevada law, a plaintiff must allege: “(1) an intentional intrusion (physical or otherwise); (2) on the solitude or seclusion of another; (3) that would be highly offensive to a reasonable person.” People for the Ethical Treatment of Animals v. Bobby Berosini, Ltd., 111 Nev. 615, 630, 895 P.2d 1269, 1279 (1995). Courts considering whether a particular action is “highly offensive” under Nevada law should consider “the degree of intrusion, the context, conduct and circumstances surround the intrusion as well as the intruder’s motives and objectives, the setting into which he intrudes, and the expectations of those whose privacy is invaded.” People for the Ethical Treatment of Animals, 111 Nev. at 630, 895 P.2d at 1282. The Court has previously found that an allegation that a plaintiff’s sensitive PII is in the hands of a notorious cybercriminal gang is sufficient to plead the “highly offensive” element. Smith v. Findlay Auto., Inc., No. 2:24-cv-01226-RFB-EJY, 2025 WL 973859, at *7 (D. Nev. Mar. 21, 2025). Effortless argues that Plaintiffs’ invasion of privacy/intrusion upon seclusion claim must be dismissed because Plaintiffs fail to establish that Effortless’s conduct was highly offensive as Plaintiffs do not allege that any information has actually been sold or published on the dark web. Russo allege actual harm that suggests that Plaintiffs’ PII has been published and/or sold and is being used by bad actors. See supra Section III(A)(1). Plaintiff Nguyen even specifically alleges that she was notified her PII had been found on the dark web. ECF No. 36 at 39. Because all Plaintiffs (except Plaintiff Russo) allege facts to suggest that their PII has been bought/sold or otherwise found on the dark web, this Court finds they sufficiently plead the “highly offensive” element under Smith. The invasion of privacy claim for intrusion upon seclusion should be dismissed as to Plaintiff Russo only. Because it is unclear that amendment would be futile, Plaintiff Russo should be granted leave to amend. D. Unjust Enrichment A claim for unjust enrichment in Nevada requires (1) a benefit conferred on the defendant by the plaintiff; (2) appreciation of the benefit by the defendant; and (3) acceptance and retention of the benefit by the defendant under circumstances such that it would be inequitable for him to retain it without payment. Leasepartners Corp. v. Robert L. Brooks Tr., 113 Nev. 747, 755, 942 P.2d 182, 187 (1997). “An action based on a theory of unjust enrichment is not available when there is an express, written contract, because no agreement can be implied when there is an express agreement.” Id. Effortless argues that Plaintiffs’ unjust enrichment claim must be dismissed because Plaintiffs have already made a breach of third-party beneficiary contract claim, and a claim for unjust enrichment cannot survive dismissal if the breach of contract claim survives. ECF No. 43 at 19. While it is true that a claim for unjust enrichment cannot succeed if a breach of contract claim succeeds at the summary judgment stage, at the pleading stage, both claims can survive dismissal. See e.g. In re Data Breach Sec. Litig. Against Caesar’s Ent., Inc., No. 2:23-cv-01447- ART-BNW, 2025 WL 2393024. At *6 (D. Nev. Aug. 15, 2025) (denying defendant’s motion to dismiss as to both plaintiffs’ breach of contract and unjust enrichment claims); compare with Gen. Elec. Capital Corp. v. Mendoza, No. 2:09-cv-839-JCM(GWF), 2010 WL 1665274, at *2 (D. Nev. Apr. 21, 2010) (denying summary judgment for plaintiffs unjust enrichment where their claim for ] Effortless also argues that Plaintiffs cannot pursue an unjust enrichment claim because plaintiffs cannot pursue equitable remedies unless they can show they lack an adequate remedy at law. ECF No. 43 at 19 (citing Sonner v. Premier Nutrition Corp., 971 F.3d 834, 844 (9th Cir. 2020)). Unlike the plaintiff in Sonner, Plaintiffs here allege that they face ongoing harms tncluding the risk of fraud and identity theft and that a judgment for monetary damages will not end this ongoing harm. ECF No. 36 at 58. Since Plaintiffs sufficiently allege that they do not have a full and adequate remedy at law, their unjust enrichment claim is not precluded under Sonner. IV. CONCLUSION IT IS ORDERED that Plaintiff Smith’s, Russo’s, Obringer’s, and Carden’s negligence/negligence per se claim should be DISMISSED to the extent they allege damages solely on lost time with leave to amend. IT IS FURTHER ORDERED that Plaintiffs’ negligence per se claim should be DISMISSED to the extent they allege damages solely anxiety and emotional distress with leave to amend. IT IS FURTHER ORDERED that Plaintiffs’ breach of third-party beneficiary contract be DISMISSED with leave to amend. IT IS FURTHER ORDERED that Plaintiffs’ invasion of privacy claim be DISMISSED only as to Plaintiff Russo with leave to amend. IT IS FURTHERED ORDERED that Plaintiffs may have until September 16, 2026, to file an amended complaint. DATED: August 18, 2026 (LA ge lepine bala BR A°WEKSLER UNITED STATES MAGISTRATE JUDGE