Gordon Rees Scully Mansukhani New York Partner Brian Middlebrook, alongside New York Associate J. Michael Paulino and Detroit Partner Luke Wolf, successfully secured the dismissal of a data breach putative class action filed in the United States District Court of the Western District of Michigan, Southern Division, against the firm’s client, a Michigan corporation that collects patient survey analytics for healthcare-related organizations.
The plaintiffs in the lawsuit alleged that their personally identified information and/or protected health information were potentially compromised in a cyberattack impacting the firm’s client in or around April 2025. The plaintiffs claimed that they suffered various injuries including the future risk of harm and identity theft, lost or diminished value of their private information, costs associated with the prevention, detection, and recovery from identity theft, lost opportunity costs, invasion of their privacy, loss of the benefit of the bargain, and emotional distress associated with the loss of control over their private information. One plaintiff claimed to have experienced one or more unauthorized attempts of fraudulent charges on her credit card, while two plaintiffs alleged to have experienced an increase in spam calls and texts following the security incident.
These facts presented significant challenges at the motion to dismiss stage, particularly in this case, where the court ultimately held that the plaintiffs sufficiently pled injuries or damages for purposes of Article III standing. However, the GRSM team leveraged the controlling legal authority, coupled with the facts surrounding the incident and nature of information potentially impacted, to persuade the court that the plaintiffs failed to state a valid claim for negligence, negligence per se, breach of confidence, unjust enrichment, and declaratory judgment under Michigan law.
In its order, the court held that, even viewing the allegations in the light most favorable to the plaintiffs, they have not plausibly connected this attempted fraud to the type of compromised data at issue in this case and that more factual content is required to raise their right to relief above sheer speculation. In rejecting the plaintiffs’ claim for breach of confidence, the court held that the plaintiffs’ allegations demonstrate a theft of their private information by a third party, not that GRSM’s client affirmatively disclosed the impacted private information. As for the unjust enrichment claim, the court ruled that the plaintiffs did not plead any facts tending to show that GRSM’s client obtained a benefit from the plaintiffs, rejecting the plaintiffs’ conclusory allegations altogether. Given that the court dismissed the plaintiffs’ remaining claims, the court finally disposed of the declaratory judgment claim, emphasizing that declaratory judgment/injunctive relief is a remedy and not a standalone cause of action.
The dismissal represents a significant victory for the client and other organizations that have fallen victim to malicious third-party cyberattacks and, after complying with applicable legal notification requirements, have been met with putative class action litigation, often multiple such actions arising from the same incident. The result reflects a sustained, long-term litigation strategy that combined aggressive motion practice with a careful review and development of the factual record. The victory further underscores GRSM’s Cyber, Privacy, and Data Security practice and the firm’s ability to handle complex, high-stakes data breach class actions across the country.