Kurowski v. Rush System for Health

District Court, N.D. Illinois·Decided December 11, 2023·No. 1:22-cv-05380·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION

MARGUERITE KUROWSKI and ) BRENDA McCLENDON, on behalf ) of themselves and all others ) similarly situated, ) ) Plaintiffs, ) ) vs. ) Case No. 22 C 5380 ) RUSH SYSTEM FOR HEALTH ) d/b/a Rush University ) System for Health, ) ) Defendant. )

MEMORANDUM OPINION AND ORDER

MATTHEW F. KENNELLY, District Judge: This is a putative class action brought by Marguerite Kurowski and Brenda McClendon (collectively Kurowski) against Rush University System for Health. Kurowski filed the case in federal court pursuant to the Class Action Fairness Act, 28 U.S.C. § 1332(d). In general terms, Kurowski's claims arise from her contention that Rush has violated her and other patients' privacy interests by surreptitiously intercepting and transmitting to third parties information that includes patients' personally identifiable patient and health data. The Court has issued two previous decisions on motions to dismiss filed by Rush. In the first decision, which concerned Kurowski's original complaint, the Court dismissed all but one of Kurowski's claims, leaving standing only a claim for injunctive relief under the Illinois Deceptive Trade Practices Act (DTPA), 815 ILCS 510/3. See Kurowski v. Rush Sys. for Health, No. 22 C 5380, 2023 WL 2349606 (N.D. Ill. Mar. 3, 2023) (Kurowski I). Kurowski then filed an amended complaint in which she reasserted (with some additional allegations) the claims the Court had dismissed, as well as several new claims. In the Court's second decision, which concerned the amended

complaint, the Court dismissed all but two of Kurowski's claims, including, this time, her DTPA claim. The Court left standing two newly asserted claims, one for breach of contract and one under the Illinois Eavesdropping Act. See Kurowski v. Rush Sys. for Health, No. 22 C 5380, 2023 WL 4707184 (N.D. Ill. July 24, 2023) (Kurowski II). Kurowski has now moved for leave to file a second amended complaint. In this iteration of her complaint, she has reasserted three of her previously dismissed claims and attempts to address the deficiencies noted by the Court in its earlier rulings. Rush opposes Kurowski's motion. The Court addresses the motion in this opinion. Discussion The Court assumes familiarity with Kurowski's allegations as summarized in its

earlier decisions and discusses them here only to the extent needed to provide background and context for the motion for leave to amend. Kurowski alleges that as a Rush patient, she has used and continues to use Rush's web properties to obtain information related to her health care. This includes Rush's patient portal MyChart, which Kurowski uses to exchange with her health care providers communications about appointments, test results, prescription refills, and other treatment. The MyChart patient portal is a software system designed and licensed to Rush by Epic Software Systems. As deployed by Rush, it is available only to patients, and it is password-protected. Kurowski alleges that the MyChart system, with Rush's knowledge and agreement, secretly deploys "custom analytics scripts"—for example, Google Analytics. Proposed 2d Am. Compl. ¶ 31. This source code, Kurowski alleges, allows for contemporaneous unauthorized interception and transmission of personally identifiable

patient data, and redirection and disclosure of "the precise content of patient communications with Rush" whenever a Rush patient uses a Rush web property, including MyChart. Id. ¶ 32. Kurowski alleges that the data transmitted to third parties, including Facebook, Google, and Bidtellect, includes patient IP addresses, patient cookie identifiers, device identifiers, account numbers, URLs, other unique identifying numbers or codes, and browser fingerprints, all of which can be used to direct targeted advertising to patients. Id. ¶¶ 35, 40. She also alleges that patient communications within the MyChart portal are, or were, shared with at least Facebook, Google, and Bidtellect. Id. ¶¶ 38-39. Kurowski alleges that Rush did all of this without her knowledge or authorization and that it derived a benefit from doing so. See, e.g., id. ¶¶

45, 60, 152. Kurowski previously asserted, and asserts again in her proposed second amended complaint, claims under the federal Wiretap Act, as amended by the Electronic Communications Privacy Act of 1986, 18 U.S.C. § 2511(1)(a), (c)-(d); the DTPA; and under Illinois common law for breach of an implied duty of confidentiality. The Court previously dismissed each of these claims in Kurowski I and/or Kurowski II. The Court will discuss the details of these claims in this opinion only to the extent needed to explain any changes, whether in Kurowski's claim, in the Court's ruling, or in both. 1. Wiretap Act claim Under the Wiretap Act, "any person who—(a) intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept, any wire, oral, or electronic communication" commits an offense and may be subject to a civil

penalty. 18 U.S.C. §§ 2511(1), (4) & (5). This is also true for any person who intentionally discloses or uses, or endeavors to disclose or use, the contents of an intercepted communication. Id. § 2511(1)(c), (d). Section 2511(2)(d) provides an exception when the person intercepting or causing an interception of a communication "is a party to the communication or where one of the parties to the communication has given prior consent to such interception." Id. § 2511(2)(d). The Court has ruled that Rush is "a party to the communication[s]" at issue. But this "party exception" does not permit a party that intercepts or causes interception to escape liability if the "communication is intercepted for the purpose of committing any tortious or criminal act in violation of the Constitution or laws of the

United States or of any State." Id. Kurowski contends that this exception to the party exception applies here. In the previous versions of her complaint, Kurowski contended—and she contends now—that Rush had violated a provision of the Health Insurance Portability and Accountability Act, specifically 42 U.S.C. § 1320d-6(a)(3). This provision imposes a criminal penalty for knowingly "disclosing individually identifiable health information" (again, IIHI) to a third party. HIPAA defines IIHI as any information, including demographic information collected from an individual, that—(A) is created or received by a health care provider . . . (B) relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, and (i) identifies the individual; or (ii) with respect to which there is a reasonable basis to believe that the information can be used to identify the individual.

Id. § 1320d(6) (emphasis added). In addressing the original version of Kurowski's complaint, the Court found that she had alleged only that IP addresses, cookie identifiers, device identifiers, account numbers, URLs, and browser fingerprints were transmitted to third parties like Facebook, Google, and Bidtellect. The Court found no basis in the complaint to support a plausible inference that such information (at least without more) constituted IIHI within the meaning of HIPAA.

Free access — add to your briefcase to read the full text and ask questions with AI

Kurowski v. Rush System for Health, (N.D. Ill. 2023).

Kurowski v. Rush System for Health (Kurowski v. Rush System for Health) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related