Patterson v. Medical Review Institute of America, LLC

District Court, N.D. California·Decided August 26, 2022·No. 3:22-cv-00413·Unknown

Opinion

1 2 3 4 IN THE UNITED STATES DISTRICT COURT 5 FOR THE NORTHERN DISTRICT OF CALIFORNIA 6 7 ALBERT PATTERSON, Case No. 22-cv-00413-MMC

8 Plaintiff, ORDER GRANTING DEFENDANT'S 9 v. MOTION TO DISMISS PLAINTIFF'S FIRST AMENDED COMPLAINT OR 10 MEDICAL REVIEW INSTITUTE OF TRANSFER; DISMISSING FIRST AMERICA, LLC, AMENDED COMPLAINT WITHOUT 11 FURTHER LEAVE TO AMEND; Defendant. VACATING HEARING 12

13 14 Before the Court is defendant Medical Review Institute of America, LLC’s 15 (“MRIoA”) Motion, filed July 28, 2022, “to Dismiss Plaintiff’s First Amended Complaint 16 Pursuant to F.R.C.P. 12(b)(1), 12(b)(6), or Transfer the Case Pursuant to 28 U.S.C. 17 § 1404(a).” Plaintiff Albert Patterson (“Patterson”) has filed opposition, to which MRIoA 18 has replied. Having read and considered the papers filed in support of and in opposition 19 to the motion, the Court deems the matter suitable for determination on the parties’ 20 respective written submissions, VACATES the hearing scheduled for September 2, 2022, 21 and rules as follows. 22 In his operative complaint, the First Amended Complaint (“FAC”), Patterson 23 alleges MRIoA is an entity that “acquired, collected[,] and stored” customers’ “personal 24 health information [“PHI”]” and “personally identifiable information [“PII”]” to “facilitate 25 clinical peer review of healthcare services.” (See FAC ¶¶ 1, 5.) Patterson further alleges 26 he received a letter from MRIoA, dated January 7, 2022, “informing him that his PHI/PII 27 and/or financial information was involved” in a data breach whereby hackers “infiltrated” 1 FAC ¶¶ 2, 20.) 2 Based on said allegations, Patterson asserts the following seven claims for relief: 3 (1) “Negligence”; (2) “Confidentiality of Medical Information Act (Cal. Civ. Code § 56, et 4 seq.)”; (3) “Invasion of Privacy”; (4) “Breach of Confidence”; (5) “Breach of Implied 5 Contract”; (6) “Unfair Business Practices (Cal. Bus. & Prof. Code § 17200, et seq.)”; and 6 (7) “Unjust Enrichment.”1 7 On May 31, 2022, MRIoA filed a motion seeking an order dismissing the instant 8 action or, in the alternative, transferring it to the District of Utah, on the grounds that 9 (1) Patterson lacks Article III standing, (2) Patterson had failed to allege facts sufficient to 10 support any of his claims for relief, and (3) the District of Utah is a more convenient 11 forum. By order filed June 23, 2022, the Court, finding Patterson had not met his burden 12 to show he has suffered a cognizable injury, dismissed Patterson’s initial complaint for 13 lack of Article III standing and afforded Patterson leave to amend. (See Doc. No. 23 14 (“June 23 Order”).) On July 14, 2022, Patterson filed his FAC. 15 By the instant motion, MRIoA again seeks an order dismissing, or in the alternative 16 transferring, the instant action, on the same grounds asserted in its earlier motion to 17 dismiss. The Court first turns to the question of standing. 18 A district court has subject matter jurisdiction only where the plaintiff has 19 “[s]tanding to sue” under Article III of the Constitution. See Spokeo, Inc. v. Robins, 578 20 U.S. 330, 337-38 (2016). To satisfy Article III’s standing requirements, (1) “the plaintiff 21 must have suffered an injury in fact” that is “concrete and particularized” and “actual or 22 imminent, not conjectural or hypothetical,” (2) the injury must be “fairly traceable” to the 23

24 1 The First, Third, Fourth, Fifth, and Seventh Claims for Relief are brought on behalf of a “Nationwide Class,” defined as “[a]ll individuals within the United States of 25 America whose PHI/PII and/or financial information was exposed to unauthorized third- parties as a result of the data breach discovered on November 9, 2021.” (See FAC 26 ¶ 29.) The Second and Sixth Claims for Relief are brought on behalf of a “California Subclass,” defined as “[a]ll individuals within the State of California whose PII/PHI was 27 stored by Defendant and/or was exposed to unauthorized third parties as a result of the 1 challenged conduct of the defendant, and (3) “it must be likely . . . that the injury will be 2 redressed by a favorable decision.” See Lujan v. Defs. of Wildlife, 504 U.S. 555, 560-61 3 (1992) (internal quotation, citation, and alteration omitted). “The party invoking federal 4 jurisdiction bears the burden of establishing” the elements of standing, see id. at 561, and 5 a plaintiff who lacks standing may not “seek relief on behalf of himself or any other 6 member of [a] class” he purports to represent, see Warth v. Seldin, 422 U.S. 490, 502 7 (1975) (internal quotation and citation omitted). 8 A defendant seeking dismissal for lack of standing may raise a “facial” or “factual” 9 challenge. See Safe Air for Everyone v. Meyer, 373 F.3d 1035, 1039 (9th Cir. 2004). “In 10 a facial attack, the challenger asserts that the allegations contained in a complaint are 11 insufficient on their face to invoke federal jurisdiction,” whereas, “in a factual attack, the 12 challenger disputes the truth of the allegations that, by themselves, would otherwise 13 invoke federal jurisdiction.” See id. “Once the moving party . . . convert[s] [a] motion to 14 dismiss into a factual motion by presenting affidavits or other evidence properly brought 15 before the court, the party opposing the motion must furnish affidavits or other evidence 16 necessary to satisfy its burden of establishing subject matter jurisdiction.” Savage v. 17 Glendale Union High Sch., 343 F.3d 1036, 1039 n.2 (9th Cir. 2003). 18 Here, MRIoA, raising both facial and factual challenges, contends Patterson has, 19 again, failed to establish a cognizable injury in fact. In his opposition, Patterson relies 20 only on theories of “lost time” and “anxiety” caused by the data breach. (See Opp. at 21 3:23-27, 5:2-3.) Specifically, Patterson alleges that he has spent time “verifying the 22 legitimacy and impact of the [d]ata [b]reach, exploring credit monitoring and identity theft 23 insurance options, self-monitoring his accounts[,] and seeking legal counsel regarding his 24 options for remedying and/or mitigating the effects of the [d]ata [b]reach” (see FAC ¶ 21), 25 and that he has suffered “fear, apprehension, anxiety, and embarrassment” as a result of 26 the breach (see FAC ¶ 23). As set forth below, the Court finds Patterson has not met his 27 burden of showing he has suffered a cognizable injury. 1 remains undisputed by Patterson, that “none of the information about Patterson 2 potentially exposed in the data breach was sufficiently sensitive to create a credible risk 3 of future fraud or identity theft” (see June 23 Order at 3:22-26; see also Leichliter Decl. 4 ¶ 10 (averring the only information regarding Patterson that was “potentially accessed by 5 the attackers . . . consisted of a single one-page document” containing “the date, the title 6 ‘Advisory,’ a reference to ‘Patterson, Albert’ as ‘Insured’ and ‘Patient,’ a Policy number, 7 ‘Review Time 60 minutes[,]’ and ‘Total amount: to be billed $327.00’”)), and, contrary to 8 Patterson’s argument, lost time and anxiety, absent a credible risk, are not “sufficient to 9 establish Article III standing” (see Opp. at 4:12); see also Burns v.

Free access — add to your briefcase to read the full text and ask questions with AI

Patterson v. Medical Review Institute of America, LLC, (N.D. Cal. 2022).

Patterson v. Medical Review Institute of America, LLC (Patterson v. Medical Review Institute of America, LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Warth v. Seldin
422 U.S. 490 (Supreme Court, 1975)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Safe Air for Everyone v. Meyer
373 F.3d 1035 (Ninth Circuit, 2004)