Travis v. Assured Imaging LLC

District Court, D. Arizona·Decided May 10, 2021·No. 4:20-cv-00390·Unknown

Opinion

WO

Angela T Travis, et al., No. CV-20-00390-TUC-JCH

Plaintiffs, ORDER

v.

Assured Imaging LLC,

Defendant. Defendant Assured Imaging, LLC (“Defendant” or “Assured”) moves to dismiss Plaintiffs’ Amended Class Action Complaint. (Assured Imaging, LLC’s Mot. to Dismiss, Doc. 12.) The motion is fully briefed. (Pls’ Resp. and Opp’n to Def.’s Mot. to Dismiss, Doc. 13; Assured Imagining, LLC’s Reply Br. in Supp. of Mot. to Dismiss, Doc. 14.) For the reasons set forth below, the Court will grant Assured’s motion to dismiss without prejudice. a. Factual Background This case arises from a ransomware1 attack. (Doc. 9 at ¶ 9.) On or about May 15,

1 Plaintiffs allege that a ransomware attack is a type of malicious software that blocks access to a computer system or data, usually by encrypting it, until the victim pays a fee to the attacker. (First Am. Class Action Comp., Doc. 9 at 8, ¶ 34.) They allege ransomware attacks are often the final piece of a multiphase coordinated cyber-attack contending that “[o]nce cyberthieves have plundered the target’s systems using [malicious software], the cybercriminals unleash their ransomware virus, locking down the target’s systems for a ransom.” Id. at ¶ 35. 2020, a cyberattack launched from an Assured employee’s email inbox allowed malignant software to infect Assured’s computer networks. (Doc. 9 at ¶ 36.) From May 15 to May 17, 2020, Assured was unaware that its system was compromised and the cyberthieves exfiltrated patient and other data from Assured’s system. Id. at ¶ 37. On May 19, 2020, Defendant realized that its computer system was compromised when the nonparty actors launched a targeted ransomware attack. Id. at ¶ 38. The ransomware attack disrupted Assured’s computer network, leaving patient data stored on its network encrypted and inaccessible for multiple days. Id. at ¶¶ 41, 42. In August of 2020, Assured notified potentially affected persons and governmental agencies of the ransomware attack through a Notice of Data Incident or a Notice of Data Breach. Id. at ¶ 44; Docs 9-1 through 9-4. The Notice of Data Incident states in part: What Happened? On May 19, 2020, Assured learned that its electronic medical records system had become encrypted due to “ransomware” deployed by an unknown actor. Because the impacted systems contained patient information, Assured worked quickly to (1) restore access to the patient information so it could continue to care for patients without disruption and (2) investigate what happened and whether this incident resulted in any unauthorized access to, or theft of, patient information by the unknown actor. Assured conducted an extensive investigation, with the assistance of third-party computer forensic specialists to determine the nature and scope of the incident. On July 1, 2020, the investigation confirmed Assured systems were accessible by an unknown actor between May 15, 2020 and May 17, 2020, and certain, limited data was exfiltrated from our systems. The investigation was unable to determine the full extent of information that was accessed by the unknown actor. In an abundance of caution, Assured performed a comprehensive review of all information stored in our systems at the time of the incident to identify the individuals whose information may have been accessible to the unknown actor. We then worked to determine the identities and contact information for potentially impacted individuals.

What information Was Involved. The following types of patient information were present in the electronic medical records system and therefore potentially accessed and acquired by the unknown actor during this incident: full name, address, date of birth, patient ID, facility, treating clinician, medical history, service performed, and assessment of the service performed, including any recommendations on future testing. We are unaware that any of the information was misused by the unknown actor and Assured is providing this notice in an abundance of caution.

Free access — add to your briefcase to read the full text and ask questions with AI

Travis v. Assured Imaging LLC, (D. Ariz. 2021).

Travis v. Assured Imaging LLC (Travis v. Assured Imaging LLC) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Warth v. Seldin
422 U.S. 490 (Supreme Court, 1975)
Pennsylvania v. New Jersey
426 U.S. 660 (Supreme Court, 1976)
Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Krottner v. Starbucks Corp.
628 F.3d 1139 (Ninth Circuit, 2010)
Michael Henry Ferdik v. Joe Bonzelet, Sheriff
963 F.2d 1258 (Ninth Circuit, 1992)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Cherny v. Emigrant Bank
604 F. Supp. 2d 605 (S.D. New York, 2009)
Shqeirat v. US AIRWAYS, GROUP INC.
515 F. Supp. 2d 984 (D. Minnesota, 2007)
Claridge v. RockYou, Inc.
785 F. Supp. 2d 855 (N.D. California, 2011)
Doe 1 v. AOL LLC
719 F. Supp. 2d 1102 (N.D. California, 2010)
Courthouse News Service v. Michael Planet
750 F.3d 776 (Ninth Circuit, 2014)
Susan B. Anthony List v. Driehaus
134 S. Ct. 2334 (Supreme Court, 2014)
Spokeo, Inc. v. Robins
578 U.S. 330 (Supreme Court, 2016)
White v. Lee
227 F.3d 1214 (Ninth Circuit, 2000)
Zimmerman v. City of Oakland
255 F.3d 734 (Ninth Circuit, 2001)
Medvend, Inc. v. YRC, Inc.
23 F. Supp. 3d 844 (E.D. Michigan, 2014)
In re Adobe Systems, Inc. Privacy Litigation
66 F. Supp. 3d 1197 (N.D. California, 2014)
Warren v. Fox Family Worldwide, Inc.
328 F.3d 1136 (Ninth Circuit, 2003)