DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Plaintiffs Use Privacy Pledge Against Insurer in Data Breach Claim

Posted on March 11, 2016 by Dissent

Armeen Mistry and Matthew Siegel of Cozen O’Connor write about a lawsuit over a data breach in 2014 that I don’t remember ever hearing about before.  Whether plaintiffs will be able to show injury is down the road. For now, they survived a motion to dismiss:

On February 23, an Illinois federal court denied a motion to dismiss a proposed class action based on a “privacy pledge” included with the insurance policy documents provided to the employees of Dillard’s department store.

Lead plaintiff Anne Dolmage alleged that she and other Dillard’s employees received from the insurance company a document entitled “Our Privacy Pledge to You,” which states the company “will not disclose personal information about you, or any current or former insured, except as permitted and/or required by law.” The employees received the privacy pledge along with other materials relating to their applications for health insurance.

In May 2014, plaintiff filed a proposed class action on behalf of all Dillard’s employees and their dependents with policies issued by Combined Insurance Company of America. The complaint alleges that plaintiff and other proposed class members provided the insurer with personal information, including dates of birth and social security numbers. Combined then engaged third-party Enrolltek to perform the insurance enrollment functions and other tasks relating to the class members’ applications. Combined provided the personal information to Enrolltek’s principal, who copied the information to an allegedly unsecure external hard drive. The complaint states that the personal information was “posted online, unsecure and unprotected,” and was “accessible to anyone with an Internet connection.” When Dillard’s employees noticed their personal information was readily available online, they notified the insurance company. According to the complaint, Combined then formally notified the employees that their personal information was “stored on an Internet server by a third party enrollment system vendor since March 2012 without the proper security measures.” Plaintiff and the proposed class allege economic losses, based on false income tax returns, fraudulent cell phone charges, and fraudulent medical expenses incurred in their names.

The original complaint alleged claims under the Fair Credit Reporting Act (“FCRA”), 15 U.S.C. §1681 et seq., and state law claims of negligence, breach of fiduciary duty, breach of express contract, breach of implied contract, unjust enrichment, invasion of privacy, and violation of the Illinois Insurance Code, 215 Ill. Comp. Stat. 5/1001 et seq. On January 21, 2015, the court granted Combined’s motion to dismiss all of plaintiff’s claims, except for the breach of express contract and breach of fiduciary duty claims. Plaintiff then filed an amended complaint in September 2015 alleging only breach of contract, and Combined again moved to dismiss.

In its motion, Combined first argued that its privacy pledge was not included in the health insurance policies the Dillard’s employees received. Instead, Combined argued that it should have been obvious to plaintiff that the pledge was not part of the policy, which specifically stated: “The policy is a legal contract. It is the entire contract between you and us.” Based on this language, Combined argued that plaintiff could not consider outside documents, such as the privacy pledge, as part of the insurance contract. Plaintiff countered that “the policy” is defined as “this policy with any attached application(s), and any riders and endorsements.” Because plaintiff received the pledge along with the policy documents, the court found it reasonable for plaintiff to view the pledge as an endorsement. The court further suggested that Combined could have avoided any confusion by clearly labeling which documents sent with the policy were intended to be incorporated by reference.

Combined also argued that plaintiff failed to include “detailed factual allegations” about the privacy pledge, but the court held that at this stage, plaintiff was not required to plead “detailed factual allegations” in order to survive a motion to dismiss. The court noted that the standard for a motion to dismiss is much lower than the standard for determining standing under Article III. (The debate over standing in data breach litigation has been raging lately, as we have reported here, here, here, and here for example.)

Noting this lower standard for surviving a motion to dismiss, Judge Ruben Castillo stated, “[T]here is no question that Plaintiff will ultimately be required to prove that her damages were caused by Defendant’s actions. But, again, the issue at the pleadings stage is solely whether Plaintiff has stated a plausible claim for relief . . . Given the timeline of events, and the fact that at least 30 other Dillard’s employees allegedly suffered the same type of identity theft, it is certainly plausible that there is a causal link between Defendant’s failure to ensure the confidentiality of the data and the damages alleged” (internal citations omitted).

The case is Dolmage v. Combined Ins. Co. of Am., No. 1:14-cv-3089, pending in the U.S. District Court for the Northern District of Illinois.

SOURCE: JDSupra.


Related:

  • KT Chief to Resign After Cybersecurity Breach Resolution
  • Cyber-Attack On Bectu’s Parent Union Sparks UK National Security Concerns
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
  • A business's cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why?
  • Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)
Category: Breach IncidentsExposureU.S.

Post navigation

← MI: Network security breach reported in West Bloomfield School District, student info exposed
Hackers Claim Breach Of Ku Klux Klan’s Security Company, Staminus (update2) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.