DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

2024 Year in Review: Data Breach Litigation

Posted on April 9, 2025 by Dissent

Seen at Wilmer Hale:

One of the main risks for a company in the event of a data breach is the threat of litigation. Data breach litigation continued to proliferate in 2024, as it has in prior years.

In the past year, plaintiffs continued to seek relief following data breaches under state common-law doctrines, and the Alabama Supreme Court joined the other state courts of last resort who have addressed data-breach litigation in published decisions.  Federal data breach plaintiffs contended with standing issues in the wake of the Supreme Court’s decision in TransUnion LLC v. Ramirez, and an apparent circuit split between the Tenth and Eleventh Circuits deepened when the Third Circuit weighed in.  The District of New Jersey also provided further guidance to companies on the scope of the attorney-client privilege when responding to data breaches.

This post examines these trends.

Common-Law Claims For Traditional Data Breaches

More traditional common-law claims (e.g., negligence, breach of contract) based on data breaches were common in 2024, as in prior years.  In many instances, such claims survived a motion to dismiss.1

One notable exception is the Alabama Supreme Court’s decision in Griggs v. NHS Management.2 In Griggs, the court rejected claims for negligence, negligence per se, invasion of privacy, unjust enrichment, breach of confidence, and breach of fiduciary duty related to a data breach suffered by NHS, a provider of administrative services for nursing homes and physical rehabilitation facilities in Alabama, Arkansas, Florida, and Missouri.3 The court established a high bar for making out invasion of privacy, breach of confidence, and unjust enrichment claims in the traditional data breach litigation context involving hacking by a third-party.

Read more at WilmerHale.

Category: Commentaries and AnalysesLegislation

Post navigation

← E-ZPass toll payment texts return in massive phishing wave
Fall River schools chief: No insurance for cyberattack; says computer system remains down →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack
  • Sweden under cyberattack: Prime minister sounds the alarm
  • Former CIA Analyst Sentenced to Over Three Years in Prison for Unlawfully Transmitting Top Secret National Defense Information
  • FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe
  • AI tools collect and store data about you from all your devices – here’s how to be aware of what you’re revealing
  • 23andMe Privacy Ombudsman Urges User Consent Pre-Data Sale

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.