Negron v. Ascension Health

District Court, E.D. Missouri·Decided September 23, 2025·No. 4:24-cv-00669·Unknown

Opinion

UNITED STATES DISTRICT COURT EASTERN DISTRICT OF MISSOURI EASTERN DIVISION

ANGEL JOEL GUSMAN NEGRON, et al., ) ) Plaintiffs, ) ) Case No. 4:24-CV-00669-JAR vs. ) ) ASCENSION HEALTH, et al., ) ) Defendants. )

MEMORANDUM AND ORDER This matter is before the Court on Defendant’s motion to dismiss Plaintiffs’ claims in this putative class action arising from a healthcare system data breach. For the reasons set forth below, the motion will be granted in part and denied in part. BACKGROUND Defendant Ascension Health and two affiliated companies1 (collectively, Ascension) comprise a Missouri-based Catholic non-profit healthcare system of 140 hospitals serving 19 states. Plaintiffs were Ascension patients on May 8, 2024, when its technology network suffered a ransomware attack wherein hackers copied electronic files containing patients’ protected health information (PHI) and personally identifiable information (PII). The next day, Ascension posted a notice to its website disclosing a cybersecurity event and describing its response, involving investigation and remediation with expert third-party assistance.

1 The three related Defendants in this case are Ascension Health, its sister company Ascension Health-IS Inc. d/b/a Ascension Technologies, and their parent company Ascension Health Alliance. Ascension summarily contends that the Alliance and Technologies entities should be dismissed from the complaint. But Plaintiffs plead all allegations as to all Defendants. Their respective roles in the events of this case is a matter properly reserved for discovery. To the extent Ascension’s argument could be construed as a motion to dismiss these defendants, it will be denied. On May 14, 2024, Plaintiffs filed this putative class action asserting claims of negligence (Count I), negligence per se (Count II), breach of implied covenant of good faith and fair dealing (Count III), and unjust enrichment (Count IV) and seeking various forms of injunctive relief and monetary damages. In October 2024, Plaintiffs filed an amended complaint asserting seven claims on behalf of a nationwide class and 11 state law claims specific to seven state subclasses.

The proposed nationwide class consists of: All United States residents whose Personal Information was compromised in the Data Breach discovered by Ascension in May 2024, including all those individuals who receive notice of the breach. The seven proposed subclasses consist of residents of Arkansas, Florida, Illinois, Indiana, Michigan, Oklahoma, and Wisconsin, respectively. Plaintiffs assert the following counts: Nationwide Class I. Negligence II. Negligence per se III. Breach of Express Contract IV. Breach of Implied Contract V. Unjust Enrichment (in the alternative to breach of implied contract) VI. Invasion of Privacy VII. Missouri Merchandising Practices Act, Mo. Rev. Stat. § 407.010 Sub-classes VIII. Arkansas Deceptive Trade Practices Act, Ark. Code §§ 4-88-101 IX. Florida Deceptive and Unfair Trade Practices Act, Fla. Stat. §§ 501.201 X. Illinois Personal Information Protection Act, 815 Il. Comp. Stat. § 530/1 XI. Illinois Consumer Fraud and Deceptive Business Practices Act, 815 Il. Comp. Stat. § 505 XII. Oklahoma Consumer Protection Act, Okla. Stat. tit. 15 § 751 XIII. Wisconsin Breach of Confidentiality of Health Records Act, Wis. Stat. § 146.81 XIV. Wisconsin Deceptive Trade Practices Act, Wis. Stat. § 100.18 XV. Wisconsin Notice of Unauthorized Acquisition of Personal Information Act, Wis. Stat. § 134.98(2) XVI. Michigan Identity Theft Protection Act, Mich. Comp. Laws § 445.72 XVII. Michigan Consumer Protection Act, Mich. Comp. Laws § 445.903 XVIII. Indiana Deceptive Consumer Sales Act, Ind. Code §§ 24-5-0.5-0.1 Common Facts The central facts in the complaint common to all counts can be summarized as follows. In connection with the provision of medical services, Ascension creates and stores patients’ medical records containing PHI and PII. The Health Insurance Portability and Accountability Act (HIPAA) requires regulated entities like Ascension to maintain appropriate administrative,

Free access — add to your briefcase to read the full text and ask questions with AI

Negron v. Ascension Health, (E.D. Mo. 2025).

Negron v. Ascension Health (Negron v. Ascension Health) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
E-Shops Corp. v. U.S. Bank National Ass'n
678 F.3d 659 (Eighth Circuit, 2012)
U.S. Bank, N.A. v. Integrity Land Title Corp.
929 N.E.2d 742 (Indiana Supreme Court, 2010)
Lowdermilk v. Vescovo Building & Realty Co.
91 S.W.3d 617 (Missouri Court of Appeals, 2003)
Sherman v. Sea Ray Boats, Inc
649 N.W.2d 783 (Michigan Court of Appeals, 2002)
Y.G. v. Jewish Hospital of St. Louis
795 S.W.2d 488 (Missouri Court of Appeals, 1990)
Sofka v. Thal
662 S.W.2d 502 (Supreme Court of Missouri, 1983)
Emerson Electric Co. v. Marsh & McClennan Companies
362 S.W.3d 7 (Supreme Court of Missouri, 2012)
Shelby E. Watson v. Wells Fargo Home Mortgage, Inc.
438 S.W.3d 404 (Supreme Court of Missouri, 2014)
Kacie Nickel v. Stephens College
480 S.W.3d 390 (Missouri Court of Appeals, 2015)
Spokeo, Inc. v. Robins
578 U.S. 330 (Supreme Court, 2016)
Matthew Carlsen v. GameStop, Inc.
833 F.3d 903 (Eighth Circuit, 2016)
Richard Torti, Sr. v. John Hancock Life Insurance Co
868 F.3d 666 (Eighth Circuit, 2017)
Matthew Kuhns v. Scottrade, Inc.
868 F.3d 711 (Eighth Circuit, 2017)
Melissa Alleruzzo v. SuperValu, Inc.
870 F.3d 763 (Eighth Circuit, 2017)