Pandemic Darlings The pandemic economy, in original documents
Home Source documents Consolidated Amended Class Action Complaint — In re Wright & Filippis Data Security Breach Litigation

Consolidated Amended Class Action Complaint — In re Wright & Filippis Data Security Breach Litigation

Date
2023-02-24

Summary

A Consolidated Amended Class Action Complaint filed February 24, 2023 as ECF No. 13 in In re Wright & Filippis, LLC Data Security Breach Litigation, Case No. 2:22-cv-12908-SFC, in the U.S. District Court for the Eastern District of Michigan. Five Michigan plaintiffs sue Wright & Filippis, LLC on behalf of a class, alleging that it failed to safeguard the personal and health information of approximately 877,584 individuals exposed in a ransomware attack from January 26 to January 28, 2022. The complaint states that the company reported the breach on or around November 18, 2022, and alleges that its notice was delayed and incomplete. It asserts jurisdiction under 28 U.S.C. § 1332(d)(2) and seeks damages, restitution and injunctive relief including security improvements and credit monitoring. The 125-page complaint demands a jury trial and ends with a certificate of service.

Summary drafted by a model from the document's text below and checked by script against that text before publication. It is a navigation aid, not a reading of what the document proves. Where AI is used

Full text

Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1056 Filed 02/24/23 Page 1 of 125

IN THE UNITED STATES DISTRICT COURT
FOR THE EASTERN DISTRICT OF MICHIGAN

Case No.: 2:22-cv-12908-SFC
IN RE WRIGHT & FILIPPIS, LLC
DATA SECURITY BREACH
LITIGATION

Hon. Sean F. Cox
CONSOLIDATED AMENDED
CLASS ACTION COMPLAINT
JURY TRIAL DEMANDED

CONSOLIDATED AMENDED COMPLAINT
Plaintiffs Chiquita Braggs, Scott Hamilton, Diane Huff, Shawn Kolka, and
Craig Mejia (“Plaintiffs”), individually and on behalf of all others similarly situated,
bring this action against Defendant Wright & Filippis, LLC (“Defendant” or
“W&F”). Plaintiffs seek to obtain damages, restitution, and injunctive relief for the
Class, as defined below, from W&F. Plaintiffs make the following allegations upon
information and belief, except as to their own actions, the investigation of their
counsel, and the facts that are a matter of public record.
I.
1.

INTRODUCTION

This class action arises out of the recent targeted cyberattack and data

breach on W&F’s network that resulted in unauthorized access to highly sensitive


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1057 Filed 02/24/23 Page 2 of 125

patient and employee data. Plaintiffs bring this class action against W&F for its
failure to secure and safeguard their and approximately 877,584 other individuals’
personally identifiable information (“PII”) and personal health information (“PHI”)
(collectively, “Private Information”). As a result, Plaintiffs and Class Members
suffered ascertainable losses in the form of the loss of the benefit of their bargain,
out-of-pocket expenses, and the value of their time reasonably incurred to remedy
or mitigate the effects of the attack, emotional distress, and the imminent risk of
future harm caused by the compromise of their sensitive personal information.
2.

W&F provides prosthetics, orthotics, and accessibility solutions to

patients; W&F also provides pediatrics and women’s care for patients in addition to
other health care related services.
3.

As a condition of receiving services, W&F’s patients are required to

provide and entrust W&F with sensitive and private information, including PII and
PHI.
4.

W&F discovered that its systems were subject to a cybersecurity attack

culminating in ransomware from January 26 to January 28, 2022, which resulted in
unauthorized access to Private Information (the “Data Breach”).1

“Notice of Privacy Incident”, W&F website, available at
https://www.firsttoserve.com/notice/ (last accessed Feb. 24, 2023) (attached hereto
as Exhibit 1).
2
1


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1058 Filed 02/24/23 Page 3 of 125

5.

On or around November 18, 2022, W&F reported the Data Breach with

the U.S. Department of Health and Human Services Office for Civil Rights as well
as the California Attorney General. It began sending out notification letters to
affected parties around that same time.
6.

W&F’s notice letter2 provided scant detail, particularly considering the

size and scope of the Data Breach and the sensitivity of Plaintiffs’ and Class
Members’ compromised information. W&F’s notice states, in relevant part, that it
“was subject to a cybersecurity attack culminating in ransomware from January 26
to January 28, 2022” and that its “endpoint security detected and terminated the
ransomware shortly after it executed.” See Ex. 2. W&F also stated that, with the
assistance of “third-party experts” it “took immediate steps to secure its systems and
investigate the nature and scope of the Incident.” Id. W&F went on to state that,
“[o]n or about May 2, 2022, Wright & Filippis discovered that the Incident may have
impacted protected health information (“PHI”) or personally identifiable
information (“PII”).” Id.

Sample
WF
Individual
Notification
Letter,
available
at:
https://oag.ca.gov/system/files/WF%20-%20Individual%20Notification%20
Letter%20-%20Patient%20Multistate%20FINAL%2011.11.22_1.pdf (last accessed
Feb. 24, 2023) (attached hereto as Exhibit 2) (W&F’s notice letters had minor
differences based on the state where the individual was located and the individual’s
relationship with W&F, i.e., whether the impacted individual is a current/former
patient or employee of W&F).
3
2


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1059 Filed 02/24/23 Page 4 of 125

7.

W&F’s notice did not disclose how it discovered the cybersecurity

attack, how the ransomware was detected and terminated, the means and
mechanisms of the cybersecurity attack, the reason for its six-month delay in
notifying Plaintiffs and the Class of the Data Breach after learning that Private
Information was impacted, how W&F determined that PHI and PII was “impacted,”
and, importantly, what steps W&F took following the Data Breach to secure its
systems and prevent future cyberattacks.
8.

W&F reported that the scope of information involved includes name,

date of birth, patient number, social security number, driver’s license number or state
ID financial account number, and/or medical health insurance information. See Ex.
2.
9.

The Data Breach was a direct result of W&F’s failure to implement

adequate and reasonable cybersecurity procedures and protocols necessary to protect
individuals’ PII and PHI from the foreseeable thread of a cyberattack.
10.

By taking possession and control of Plaintiffs’ and Class Members’

Private Information for its own pecuniary benefit, W&F assumed a duty to Plaintiffs
and Class Members to implement and maintain reasonable and adequate security
measures to secure, protect, and safeguard Plaintiffs’ and Class Members’ Private
Information against unauthorized access and disclosure. W&F also had a duty to
adequately safeguard this Private Information under industry standards and duties
4


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1060 Filed 02/24/23 Page 5 of 125

imposed by statutes, including HIPAA regulations and Section 5 of the Federal
Trade Commission Act (“FTC Act”). W&F breached that duty by, among other
things, failing to implement and maintain reasonable security procedures and
practices to protect patients’ and other individuals’ Private Information from
unauthorized access and disclosure.
11.

The exposure of a person’s PII and PHI through a data breach ensures

that such person will be at a substantially increased and certainly impending risk of
identity theft crimes compared to the rest of the population, potentially for the rest
of their lives. As a result of the Data Breach, Plaintiffs and Class Members are at
imminent and substantial risk of experiencing various types of misuse of their
Private Information in the coming years, including but not limited to, unauthorized
access to email accounts, tax fraud, and identity theft—including medical identity
theft.
12.

Mitigating that risk, to the extent it is even possible to do so, requires

individuals to devote significant time and money to closely monitor their credit,
financial accounts, health records, and email accounts, and take several additional
prophylactic measures.
13.

There has been no assurance offered by W&F that all impacted Private

Information or copies thereof have been recovered or destroyed.

5


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1061 Filed 02/24/23 Page 6 of 125

14.

As a result of W&F’s inadequate security and breach of its duties and

obligations, the Data Breach occurred, Plaintiffs and over 800,000 Class Members,3
suffered injury and ascertainable losses in the form of the loss of the benefit of their
bargain, out-of-pocket expenses, loss of value of their time reasonably incurred to
remedy or mitigate the effects of the attack, the diminution in value of their personal
information from its exposure, emotional distress, and the present and imminent risk
of fraud and identity theft caused by the compromise of their sensitive personal
information. Plaintiffs’ and Class Members’ sensitive personal information—which
was entrusted to W&F, its officials, and its agents—was compromised and
unlawfully accessed due to the Data Breach.
15.

The injury to Plaintiffs and Class Members was compounded by the

fact that W&F did not notify patients and other individuals that their Private
Information was subject to unauthorized access and exfiltration until November of
2022, nearly six months after the Data Breach was discovered. W&F’s failure to
timely notify the victims of its Data Breach meant that Plaintiffs and Class Members
were unable to take affirmative measures to prevent or mitigate the resulting harm.
16.

Despite having been accessed and exfiltrated by unauthorized criminal

actors, Plaintiffs’ and Class Members’ sensitive and confidential Private Information
U.S.
DHHS
OFFICE
FOR
CIVIL
RIGHTS,
https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 3).
6
3


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1062 Filed 02/24/23 Page 7 of 125

still remains in the possession of W&F. Absent additional safeguards and
independent review and oversight, the information remains vulnerable to further
cyberattacks and theft.
17.

W&F disregarded the rights of Plaintiffs and Class Members by, inter

alia, failing to take adequate and reasonable measures to ensure its data systems
were protected against unauthorized intrusions; failing to disclose that it did not have
adequately robust computer systems and security practices to safeguard PII/PHI of
patients and other individuals; failing to take standard and reasonably available steps
to prevent the Data Breach; failing to properly train its staff and employees on proper
security measures; and failing to provide Plaintiffs and Class Members prompt and
adequate notice of the Data Breach.
18.

In addition, W&F and its employees failed to properly monitor the

computer network and systems that housed the Private Information. Had W&F
properly monitored these electronic systems, it would have discovered the intrusion
sooner or prevented it altogether.
19.

The security of Plaintiffs’ and Class Members’ identities is now at risk

because of W&F’s wrongful conduct as the Private Information that W&F collected
and maintained is now in the hands of data thieves. This present risk will continue
for the course of their lives.

7


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1063 Filed 02/24/23 Page 8 of 125

20.

As a result of the Data Breach, Plaintiffs and Class Members have been

exposed to actual fraud and identity theft as well as a heightened and imminent risk
of fraud and identity theft. Plaintiffs and Class Members must now and in the future
closely monitor their financial accounts to guard against further fraud and identity
theft.
21.

Plaintiffs and Class Members may also incur out of pocket costs for

purchasing credit monitoring services, credit freezes, credit reports, or other
protective measures to deter and detect identity theft.
22.

Plaintiffs and Class Members will also be forced to expend additional

time to review credit reports and monitor their financial accounts and medical
records for fraud or identity theft. Due to the fact that the exposed information
potentially includes Social Security numbers (“SSNs”) and other immutable
personal details, Plaintiffs and Class Members will be at risk of identity theft and
fraud that will persist throughout the rest of their lives.
23.

Plaintiffs bring this action on behalf of themselves and individuals in

the United States whose Private Information was exposed as a result of the Data
Breach, which occurred between January 26-28, 2022, and which W&F only first
publicly acknowledged on or about November 18, 2022. Plaintiffs and Class
Members seek to hold W&F responsible for the harms resulting from the massive
and preventable disclosure of such sensitive and personal information. Plaintiffs
8


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1064 Filed 02/24/23 Page 9 of 125

seek to remedy the harms resulting from the Data Breach on behalf of themselves
and all similarly situated individuals whose Private Information was accessed and
exfiltrated during the Data Breach.
24.

Plaintiffs thus seek remedies including, but not limited to,

compensatory damages, treble damages, punitive damages, reimbursement of outof-pocket costs, and declaratory and injunctive relief including improvements to
W&F’s data security systems, future annual audits, and adequate credit monitoring
services funded by W&F.
II.

THE PARTIES

Plaintiffs
25.

Plaintiff Chiquita Braggs is a resident and citizen of the State of

Michigan. Plaintiff provided her PII and PHI to Wright & Filippis in or around 2020
in order to receive a hand brace.
26.

Plaintiff Scott Hamilton is a resident and citizen of the State of

Michigan. Plaintiff provided his PII and PHI to Wright & Filippis roughly ten years
ago in order to receive a breathing machine from Defendant.
27.

Plaintiff Diane Huff is a resident and citizen of the State of Michigan.

Plaintiff provided her PII and PHI to Wright & Filippis in or around November of
2022 in order to receive knee braces from Defendant.

9


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1065 Filed 02/24/23 Page 10 of 125

28.

Plaintiff Shawn Kolka is a resident and citizen of the State of Michigan.

Plaintiff provided his PII and PHI to Wright & Filippis in or around November of
2021 in order to receive a walker from Defendant.
29.

Plaintiff Craig Mejia is a resident and citizen of the State of Michigan.

Plaintiff Mejia received medical services from Wright & Filippis, providing his PII
and PHI to Wright & Filippis as part of services related to the creation of a molding
for Plaintiff Mejia’s foot.
Defendant
30.

Defendant Wright & Filippis, LLC, is a Michigan limited liability

company with a principal place of business located at 2845 Crooks Road, Rochester
Hills, Michigan 48309 and its principal office address at 7748 Parkcrest Circle,
Clarkston, Michigan 48348.
III.
31.

JURISDICTION AND VENUE

This Court has jurisdiction over Plaintiffs’ claims under 28 U.S.C. §

1332(d)(2), because (a) there are 100 or more Class Members; (b) at least one Class
Member is a citizen of a state that is diverse from W&F—as evidenced by the fact
that Defendant has sent data breach notifications to, inter alia, 4050 Indiana

10


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1066 Filed 02/24/23 Page 11 of 125

residents4, 500 California residents 5, and 50 Montana residents6; and (c) the matter
in controversy exceeds $5,000,000, exclusive of interest and costs.
32.

This Court has personal jurisdiction over the W&F named in this action

because W&F is headquartered in this District and W&F conducts substantial
business in Michigan and this District through its headquarters, offices, parents, and
affiliates.
33.

Venue is proper in this District under 28 U.S.C. §1391(b) because W&F

and/or its parents or affiliates are headquartered in this District and a substantial part
of the events or omissions giving rise to Plaintiffs’ claims occurred in this District.

State of Indiana Department of Justice, Office of the Attorney General,
https://www.in.gov/attorneygeneral/consumer-protection-division/id-theftprevention/files/2022-DB-Year-to-Date-Report-for-Website.pdf (last accessed Feb.
24, 2023) (attached hereto as Exhibit 4).
4

State of California Department of Justice, Office of the Attorney General,
https://oag.ca.gov/ecrime/databreach/reports/sb24-559337 (last accessed Feb. 24,
2023) (attached hereto as Exhibit 5).
5

State of Montana Department of Justice, Office of the Attorney General,
https://dojmt.gov/consumer/databreach/ (last accessed Feb. 24, 2023) (attached
hereto as Exhibit 6).
6

11


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1067 Filed 02/24/23 Page 12 of 125

IV.
A.

FACTUAL ALLEGATIONS

Wright & Filippis’ Business
34.

Since 1944, W&F has provided prosthetics, orthotics, and accessibility

solutions to patients. 7 With over 80 specialists and 20 locations in Michigan alone,
“Wright & Filippis is one of the nation’s largest, family-owned providers of
prosthetics, orthotics, and accessibility solutions.” Id. W&F provides pediatrics and
women’s care in addition to its other health care related services. 8 W&F claims,
“Now more than ever we are reminded of our ongoing commitment to improving
the lives of our patients by helping them get back to their normal day.” Id.
35.

As a condition of providing medical care W&F requires that its

customers entrust it with Private Information. On information and belief, in the
ordinary course of medical care and medical billing, W&F maintains the Private
Information of patients and customers, including but not limited to:
• Name, address, phone number and email address;
• Date of birth;
• Demographic information;
• Social Security number;
About Us, W&F available at https://www.firsttoserve.com/about-us/#ourhistory (last accessed Feb. 24, 2023) (attached hereto as Exhibit 7).
7

Locations, W&F available at https://www.firsttoserve.com/locations/ (last
accessed Feb. 24, 2023) (attached hereto as Exhibit 8).
12
8


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1068 Filed 02/24/23 Page 13 of 125

• Financial information;
• Information relating to individual medical history;
• Information concerning an individual’s doctor, nurse, or other medical
providers;
• Medication information;
• Health insurance information;
• Photo identification;
• Employment information, and;
• Other information that W&F may deem necessary to provide care.
36.

Additionally, W&F may receive Private Information from other

individuals and/or organizations that are part of a patient’s “circle of care,” such as
referring physicians, customers’ other doctors, customers’ health plan(s), close
friends, and/or family Members.
37.

Because of the highly sensitive and personal nature of the information

W&F acquires and stores with respect to patients and other individuals, W&F, upon
information and belief, promises to, among other things: keep customers’ PHI
private; comply with healthcare industry standards related to data security and
Private Information; inform customers and patients of legal duties and comply with
all federal and state laws protecting customers’ and patients’ Private Information;
only use and release customers’ Private Information for reasons that relate to medical
13


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1069 Filed 02/24/23 Page 14 of 125

care and treatment; and provide adequate notice to customers if their Private
Information is disclosed without authorization.
38.

As a HIPAA covered business entity (see infra), W&F is required to

implement adequate safeguards to prevent unauthorized use or disclosure of
Personal Information, including by implementing requirements of the HIPAA
Security Rule and to report any unauthorized use or disclosure of Personal
Information, including incidents that constitute breaches of unsecured protected
health information as in the case of the Data Breach complained of herein.
39.

However, W&F did not maintain adequate security to protect its

systems from infiltration by cybercriminals, and it waited nearly six months to
disclose the Data Breach publicly.
40.

Plaintiffs and Class Members included patients or clients of W&F, and

individuals with a potential or actual employment relationship, and entrusted W&F
with their Private Information.
B. W&F Is a HIPAA Covered Entity
41.

W&F is a HIPAA covered entity that provides healthcare services. As

a regular and necessary part of its business, W&F collects and custodies the highly
sensitive PII of its clients’ patients and health plan Members. W&F is required under
federal and state law to maintain the strictest confidentiality of the patient’s Private
Information that it requires, receives, and collects, and W&F is further required to
14


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1070 Filed 02/24/23 Page 15 of 125

maintain sufficient safeguards to protect that Private Information from being
accessed by unauthorized third parties.
42.

As a HIPAA covered entity, W&F is required to ensure that it will

implement adequate safeguards to prevent unauthorized use or disclosure of Private
Information, including by implementing requirements of the HIPAA Security Rule
and to report any unauthorized use or disclosure of Private Information, including
incidents that constitute breaches of unsecured protected health information as in the
case of the Data Breach complained of herein.
43.

Due to the nature of W&F’s business, which includes providing

prosthetics, orthotics, and pediatric medical devices, W&F would be unable to
engage in its regular business activities without collecting and aggregating Private
Information that it knows and understands to be sensitive and confidential.
44.

By obtaining, collecting, using, and deriving a benefit from Plaintiffs

and Class Members’ Private Information, W&F assumed legal and equitable duties
and knew or should have known that it was responsible for protecting Plaintiffs’ and
Class Members’ Private Information from unauthorized disclosure.
45.

Plaintiffs and Class Members are or were patients whose medical

records and personal information were maintained by, or who received healthrelated or other services from, W&F and directly or indirectly entrusted W&F with
their Private Information.
15


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1071 Filed 02/24/23 Page 16 of 125

46.

Plaintiffs and the Class Members relied on W&F to implement and

follow adequate data security policies and protocols, to keep their Private
Information confidential and securely maintained, to use such Private Information
solely for business and health care purposes, and to prevent the unauthorized
disclosures of the Private Information. Plaintiffs and Class Members reasonably
expected that W&F would safeguard their highly sensitive information and keep
their Private Information confidential.
47.

As described throughout this Complaint, W&F did not reasonably

protect, secure, or store Plaintiffs’ and the Class’s Sensitive Information prior to,
during, or after the Data Breach, but rather, enacted unreasonable data security
measures that it knew or should have known were insufficient to reasonably protect
the highly sensitive information W&F maintained. Consequently, cybercriminals
circumvented W&F’s security measures, resulting in a significant data breach.
C.

The Data Breach and Notice Letter
48.

According to the notice W&F provided to Plaintiffs and Class

Members, W&F was subject to a cybersecurity attack culminating in ransomware
from January 26 to January 28, 2022. See Ex. 2.
49.

On or about May 2, 2022, W&F discovered that the Incident may have

impacted PHI or PII. See Ex. 2. In response, W&F stated that it “worked diligently
to determine how this incident happened and are taking appropriate measures to
16


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1072 Filed 02/24/23 Page 17 of 125

prevent a similar situation in the future. Since the Incident we have implemented a
series of cybersecurity enhancements, including installation of additional endpoint
detection and response software, resetting all passwords, and rebuilding affected
servers.” Id.
50.

According to W&F’s notice to Plaintiffs and Class Members, the

investigation found the Data Breach,
may have resulted in unauthorized access to or acquisition
of certain files or accounting records that may have
contained one or more of the following data elements: For
current and former patients: name, date of birth, patient
number, social security number, financial account
number, and/or health insurance information. For current
or former employees or job applicants: name, date of birth,
social security number, driver’s license number or state
ID, and in limited instances a financial account number.
Ex. 2.
51.

W&F did not publicly announce the breach until six months later. On

or about November 18, 2022, W&F finally acknowledged the data security incident
to the United States Department of Health and Human Services’ Office for Civil
Rights (“DHHS”). See Ex. 3. On the same day, W&F began notifying the 800,000+
impacted individuals, including Plaintiffs and members of the proposed Class. Id. In
its Notice of Data Breach, W&F admitted that:
Wright & Filippis was subject to a cybersecurity attack
culminating in ransomware from January 26 to January 28,
2022 (the “Incident”). Wright & Filippis’ endpoint security
detected and terminated the ransomware shortly after it
17


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1073 Filed 02/24/23 Page 18 of 125

executed. With assistance from third-party experts, Wright &
Filippis took immediate steps to secure its systems and
investigate the nature and scope of the Incident. On or about
May 2, 2022, Wright & Filippis discovered that the Incident
may have impacted protected health information (“PHI”) or
personally identifiable information (“PII”). We have found
no evidence that your information was misused.
[t]he Incident may have resulted in unauthorized access to or
acquisition of certain files or accounting records that may
have contained one or more of the following data elements:
•

For current and former patients: name, date of
birth, patient number, social security number,
financial account number, and/or health insurance
information.

•

For current or former employees or job applicants:
name, date of birth, social security number, driver’s
license number or state ID, and in limited instances
a financial account number.

Ex. 1.
52.

W&F identified only the following actions it undertook to mitigate and

remediate the harm caused by the Data Breach in its Notice Letter:
As an added precaution, we are also offering complimentary
access to identity monitoring, fraud consultation, and identity
theft restoration services to help mitigate any potential for
harm at no cost to you. Please see below for more
information on enrollment in these services.
Wright & Filippis endeavors to protect the privacy and
security of sensitive information. We have worked diligently
to determine how this incident happened and are taking
appropriate measures to prevent a similar situation in the
future. Since the Incident we have implemented a series of
cybersecurity enhancements, including installation of
18


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1074 Filed 02/24/23 Page 19 of 125

additional endpoint detection and response software,
resetting all passwords, and rebuilding affected servers.
Ex. 2.
53.

As a HIPAA associated business entity that collects, creates, and

maintains significant volumes of Private Information, the targeted attack was a
foreseeable risk of which W&F was aware and knew it had a duty to guard against.
This is particularly true because the targeted attack was a ransomware attack. It is
well-known that healthcare businesses such as Defendant, which collect and store
the confidential and sensitive PII/PHI of hundreds of thousands of individuals, are
frequently targeted by ransomware attacks. Further, Ransomware attacks are highly
preventable through the implementation of reasonable and adequate cybersecurity
safeguards, including proper employee cybersecurity training. In fact, the vast
majority of ransomware incidents are caused by a combination of poor user
practices, lack of cybersecurity training, and weak passwords or access
management. 9
54.

The targeted attack was expressly designed to gain access to and

exfiltrate private and confidential data, including (among other things) the Private
Information of patients, like Plaintiffs and Class Members.

“Most common delivery methods and cybersecurity vulnerabilities causing
ransomware infections according to MSPs worldwide as of 2020.” Statista, available
at
https://www.statista.com/statistics/700965/leading-cause-of-ransomwareinfection/ (last accessed Feb. 24, 2023) (attached hereto as Exhibit 9).
19
9


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1075 Filed 02/24/23 Page 20 of 125

55.

Despite learning that the Data Breach compromised PII and PHI on

May 2, 2022, W&F waited over six months following the completion of its
investigation to notify the impacted individuals of the Data Breach and the need for
them to protect themselves against fraud and identity theft. W&F was, of course, too
late in the discovery and notification of the Data Breach.
56.

Due to W&F’s inadequate security measures and its delayed notice to

victims, Plaintiffs and Class Members now face a present, immediate, and ongoing
risk of fraud and identity theft that they will have to deal with for the rest of their
lives.
57.

Upon information and belief, and based on the type of cyberattack,

along with public news reports, it is plausible and likely that Plaintiffs’ Private
Information was stolen in the Data Breach.
58.

W&F had obligations created by HIPAA, contract, industry standards,

common law, and its own promises and representations made to Plaintiffs and Class
Members to keep their Private Information confidential and to protect it from
unauthorized access and disclosure.
59.

Plaintiffs and Class Members provided their Private Information to

W&F with the reasonable expectation and mutual understanding that W&F would
comply with its obligations to keep such information confidential and secure from
unauthorized access.
20


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1076 Filed 02/24/23 Page 21 of 125

60.

By obtaining, collecting, using, and deriving a benefit from Plaintiffs’

and Class Members’ Private Information, W&F assumed legal and equitable duties
and knew, or should have known, that it was responsible for protecting Plaintiffs’
and Class Members’ Private Information from unauthorized disclosure.
61.

W&F’s data security obligations were particularly important given the

substantial increase in cyberattacks and/or data breaches in the healthcare industry
preceding the date of the breach.
62.

Plaintiffs and the Class Members have taken reasonable steps to

maintain the confidentiality of their personal information. Plaintiffs and Class
Members would not have allowed W&F or anyone in W&F’s position to receive
their Private Information had they known that W&F would fail to implement
industry standard protections for that sensitive information.
63.

As a result of W&F’s negligent and wrongful conduct, Plaintiffs’ and

Class Members’ highly confidential and sensitive Private Information was left
exposed to cybercriminals.
D.

W&F Failed to Comply with FTC Guidelines
64.

W&F was prohibited by the Federal Trade Commission Act (the “FTC

Act”) (15 U.S.C. § 45) from engaging in “unfair or deceptive acts or practices in or
affecting commerce.” The Federal Trade Commission (the “FTC”) has concluded
that a company’s failure to maintain reasonable and appropriate data security for
21


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1077 Filed 02/24/23 Page 22 of 125

consumers’ sensitive personal information is an “unfair practice” in violation of the
FTC Act. See, e.g., FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015).
65.

The FTC has promulgated numerous guides for businesses which

highlight the importance of implementing reasonable data security practices.
According to the FTC, the need for data security should be factored into all business
decision-making.
66.

In 2016, the FTC updated its publication, Protecting Personal

Information: A Guide for Business, which established cyber-security guidelines for
businesses. The guidelines note that businesses should protect the personal customer
information that they keep; properly dispose of personal information that is no longer
needed; encrypt information stored on computer networks; understand their
network’s vulnerabilities; and implement policies to correct any security problems.10
The guidelines also recommend that businesses use an intrusion detection system to
expose a breach as soon as it occurs; monitor all incoming traffic for activity
indicating someone is attempting to hack the system; watch for large amounts of
data being transmitted from the system; and have a response plan ready in the event
of a breach. Id.
67.

The FTC further recommends that companies not maintain PII longer

See ECF No. 1-27, Protecting Personal Information: A Guide for Business,
Federal Trade Commission (2016).

10

22


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1078 Filed 02/24/23 Page 23 of 125

than is needed for authorization of a transaction; limit access to sensitive data;
require complex passwords to be used on networks; use industry-tested methods for
security; monitor for suspicious activity on the network; and verify that third-party
service providers have implemented reasonable security measures.
68.

The FTC has brought enforcement actions against businesses for failing

to adequately and reasonably protect customer data, treating the failure to employ
reasonable and appropriate measures to protect against unauthorized access to
confidential consumer data as an unfair act or practice prohibited by Section 5 of the
Federal Trade Commission Act (“FTCA”), 15 U.S.C. § 45. Orders resulting from
these actions further clarify the measures businesses must take to meet their data
security obligations.
69.

These FTC enforcement actions include actions against healthcare

providers and partners like W&F. See, e.g., In the Matter of Labmd, Inc., A Corp,
2016-2 Trade Cas. (CCH) ¶ 79708, 2016 WL 4128215, at *32 (MSNET July 28,
2016) (“[T]he Commission concludes that LabMD’s data security practices were
unreasonable and constitute an unfair act or practice in violation of Section 5 of the
FTC Act.”)
70.

W&F failed to properly implement basic data security practices.

71.

W&F’s failure to employ reasonable and appropriate measures to

protect against unauthorized access to customers’ Private Information constitutes an
23


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1079 Filed 02/24/23 Page 24 of 125

unfair act or practice prohibited by Section 5 of the FTC Act, 15 U.S.C. § 45.
72.

W&F was at all times fully aware of the obligation to protect the Private

Information of customers and patients. W&F was also aware of the significant
repercussions that would result from its failure to do so.
E.

W&F Failed to Comply with Industry Standards
73.

As shown above, experts studying cyber security routinely identify

healthcare providers as being particularly vulnerable to cyberattacks because of the
value of the Private Information which they collect and maintain.
74.

Several best practices have been identified that at a minimum should be

implemented by healthcare providers like W&F, including but not limited to
educating all employees; strong passwords; multi-layer security, including firewalls,
anti-virus, and anti-malware software; encryption, making data unreadable without
a key; multi-factor authentication; backup data; and limiting which employees can
access sensitive data.
75.

Other best cybersecurity practices that are standard in the healthcare

industry include installing appropriate malware detection software; monitoring and
limiting the network ports; protecting web browsers and email management systems;
setting up network systems such as firewalls, switches and routers; monitoring and
protection of physical security systems; protection against any possible
communication system; training staff regarding critical points.
24


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1080 Filed 02/24/23 Page 25 of 125

76.

W&F failed to meet the minimum standards of any of the following

frameworks: the NIST Cybersecurity Framework Version 1.1 (including without
limitation PR.AC-1, PR.AC-3, PR.AC-4, PR.AC-5, PR.AC-6, PR.AC-7, PR.AT-1,
PR.DS-1, PR.DS-5, PR.PT-1, PR.PT-3, DE.CM-1, DE.CM-4, DE.CM-7, DE.CM8, and RS.CO-2), and the Center for Internet Security’s Critical Security Controls
(CIS CSC), which are all established standards in reasonable cybersecurity
readiness.
77.

These foregoing frameworks are existing and applicable industry

standards in the healthcare industry, and W&F failed to comply with these accepted
standards, thereby opening the door to the cyber incident and causing the Data
Breach.
F.

W&F Violated its HIPAA Obligations to Safeguard the Private Information
71.

W&F is a covered entity under HIPAA (45 C.F.R. § 160.102) and is

required to comply with the HIPAA Privacy Rule and Security Rule, 45 C.F.R. Part
160 and Part 164, Subparts A and E (“Standards for Privacy of Individually
Identifiable Health Information”), and Security Rule (“Security Standards for the
Protection of Electronic Protected Health Information”), 45 C.F.R. Part 160 and Part
164, Subparts A and C.

25


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1081 Filed 02/24/23 Page 26 of 125

72.

W&F is subject to the rules and regulations for safeguarding electronic

forms of medical information pursuant to the Health Information Technology Act
(“HITECH”).11 See 42 U.S.C. §17921, 45 C.F.R. § 160.103.
73.

HIPAA’s Privacy Rule or Standards for Privacy of Individually

Identifiable Health Information establishes national standards for the protection of
health information that is kept or transferred in electronic form.
74.

HIPAA requires “compl[iance] with the applicable standards,

implementation specifications, and requirements” of HIPAA “with respect to
electronic protected health information.” 45 C.F.R. § 164.302.
75.

“Electronic protected health information” is “individually identifiable

health information … that is (i) transmitted by electronic media; maintained in
electronic media.” 45 C.F.R. § 160.103.
76.

HIPAA’s Security Rule requires W&F to do the following:
a. Ensure the confidentiality, integrity, and availability of all electronic
protected health information the covered entity or business associate
creates, receives, maintains, or transmits;
b. Protect against any reasonably anticipated threats or hazards to the
security or integrity of such information;

HIPAA and HITECH work in tandem to provide guidelines and rules for
maintaining protected health information. HITECH references and incorporates
HIPAA.
26

11


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1082 Filed 02/24/23 Page 27 of 125

c. Protect against any reasonably anticipated uses or disclosures of such
information that are not permitted; and
d. Ensure compliance by its workforce.
71.

HIPAA also requires W&F to “review and modify the security

measures implemented . . . as needed to continue provision of reasonable and
appropriate protection of electronic protected health information.” 45 C.F.R. §
164.306(e). Additionally, W&F is required under HIPAA to “[i]mplement technical
policies and procedures for electronic information systems that maintain electronic
protected health information to allow access only to those persons or software
programs that have been granted access rights.” 45 C.F.R. § 164.312(a)(1).
72.

HIPAA and HITECH also obligated W&F to implement policies and

procedures to prevent, detect, contain, and correct security violations, and to protect
against uses or disclosures of electronic protected health information that are
reasonably anticipated but not permitted by the privacy rules. See 45 C.F.R. §
164.306(a)(1) and § 164.306(a)(3); see also 42 U.S.C. §17902.
73.

The HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400-414, also

requires W&F to provide notice of the Data Breach to each affected individual
“without unreasonable delay and in no case later than 60 days following discovery
of the breach.”12
12

See ECF No. 1-25, Breach Notification Rule, U.S. Dep’t of Health & Human
27


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1083 Filed 02/24/23 Page 28 of 125

74.

HIPAA requires a covered entity to have and apply appropriate

sanctions against members of its workforce who fail to comply with the privacy
policies and procedures of the covered entity or the requirements of 45 C.F.R. Part
164, Subparts D or E. See 45 C.F.R. § 164.530(e).
75.

HIPAA requires a covered entity to mitigate, to the extent practicable,

any harmful effect that is known to the covered entity of a use or disclosure of
protected health information in violation of its policies and procedures or the
requirements of 45 C.F.R. Part 164, Subpart E by the covered entity or its business
associate. See 45 C.F.R. § 164.530(f).
76.

HIPAA also requires the Office of Civil Rights (“OCR”), within the

Department of Health and Human Services (“HHS”), to issue annual guidance
documents on the provisions in the HIPAA Security Rule. See 45 C.F.R. §§ 164.302164.318. For example, “HHS has developed guidance and tools to assist HIPAA
covered entities in identifying and implementing the most cost effective and
appropriate administrative, physical, and technical safeguards to protect the
confidentiality, integrity, and availability of e-PHI and comply with the risk analysis
requirements of the Security Rule.” US Department of Health & Human Services,

Services, https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.
html (emphasis added).
28


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1084 Filed 02/24/23 Page 29 of 125

Security Rule Guidance Material.13 The list of resources includes a link to guidelines
set by the National Institute of Standards and Technology (NIST), which OCR says,
“represent the industry standard for good business practices with respect to standards
for securing e-PHI.” US Department of Health & Human Services, Guidance on Risk
Analysis. 14
78.

Title II of HIPAA contains what are known as the Administrative

Simplification provisions. 42 U.S.C. §§ 1301, et seq. These provisions require,
among other things, that the Department of Health and Human Services (“HHS”)
create rules to streamline the standards for handling PII like the data W&F left
unguarded. The HHS subsequently promulgated multiple regulations under
authority of the Administrative Simplification provisions of HIPAA. These rules
include 45 C.F.R. § 164.306(a)(1-4); 45 C.F.R. § 164.312(a)(1); 45 C.F.R. §
164.308(a)(1)(i); 45 C.F.R. § 164.308(a)(1)(ii)(D), and 45 C.F.R. § 164.530(b).
79.

A Data Breach such as the one W&F experienced, is considered a

breach under the HIPAA Rules because there is an access of PHI not permitted under
the HIPAA Privacy Rule:

See
http://www.hhs.gov/hipaa/for-professionals/security/guidance/index.
html (last visited Feb. 24, 2023) (attached hereto as Exhibit 10).

13

https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidancerisk-analysis/index.html (last visited Feb. 24, 2023) (attached hereto as Exhibit 11).
29

14


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1085 Filed 02/24/23 Page 30 of 125

A breach under the HIPAA Rules is defined as, “...the
acquisition, access, use, or disclosure of PHI in a manner
not permitted under the [HIPAA Privacy Rule] which
compromises the security or privacy of the PHI.” See 45
C.F.R. 164.40
80.

The Data Breach resulted from a combination of insufficiencies that

demonstrate W&F failed to comply with safeguards mandated by HIPAA
regulations.
G.

W&F Breached its Duty to Safeguard Plaintiffs’ and Class Members’
Private Information
81.

In addition to its obligations under federal and state laws, W&F owed

a duty to Plaintiffs and Class Members to exercise reasonable care in obtaining,
retaining, securing, safeguarding, deleting, and protecting the Private Information in
its possession from being compromised, lost, stolen, accessed, and misused by
unauthorized persons. W&F owed a duty to Plaintiffs and Class Members to provide
reasonable security, including consistency with industry standards and requirements,
and to ensure that its computer systems, networks, and protocols adequately
protected the Private Information of Class Members.
82.

W&F owed a duty to Plaintiffs and Class Members to create and

implement reasonable data security practices and procedures to protect the Private
Information in its possession, including adequately training its employees and others
who accessed Private Information within its computer systems on how to adequately
protect Private Information.
30


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1086 Filed 02/24/23 Page 31 of 125

83.

W&F owed a duty to Plaintiffs and Class Members to implement

processes that would detect a compromise of Private Information in a timely manner.
84.

W&F owed a duty to Plaintiffs and Class Members to act upon data

security warnings and alerts in a timely fashion.
85.

W&F owed a duty to Plaintiffs and Class Members to disclose in a

timely and accurate manner when and how the Data Breach occurred.
86.

W&F owed a duty of care to Plaintiffs and Class Members because they

were foreseeable and probable victims of any inadequate data security practices.
87.

W&F owes a legal duty to secure consumers’ PII and PHI and to timely

notify consumers of a data breach.
88.

W&F breached its obligations to Plaintiffs and Class Members and/or

was otherwise negligent and reckless because it failed to properly maintain and
safeguard its computer systems and data. W&F’s unlawful conduct includes, but is
not limited to, the following acts and/or omissions:
a.
b.
c.
d.
e.
f.

Failing to maintain an adequate data security system to reduce
the risk of data breaches and cyber-attacks;
Failing to adequately protect customers’ Private Information;
Failing to properly monitor its own data security systems for
existing intrusions;
Failing to ensure that its vendors with access to its computer
systems and data employed reasonable security procedures;
Failing to detect unauthorized ingress into its systems;
Failing to implement and monitor reasonable network
segmentation to detect unauthorized travel within its systems,
including to and from areas containing the most sensitive data;
31


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1087 Filed 02/24/23 Page 32 of 125

g.
h.
i.
j.

k.
l.

m.
n.

o.
p.

q.

Failing to detect unauthorized exfiltration of the most sensitive
data on its systems;
Failing to train its employees in the proper handling of emails
containing Private Information and maintain adequate email
security practices;
Failing to ensure the confidentiality and integrity of electronic
PHI it created, received, maintained, and/or transmitted, in
violation of 45 C.F.R. § 164.306(a)(1);
Failing to implement technical policies and procedures for
electronic information systems that maintain electronic PHI to
allow access only to those persons or software programs that
have been granted access rights in violation of 45 C.F.R. §
164.312(a)(1);
Failing to implement policies and procedures to prevent, detect,
contain, and correct security violations in violation of 45 C.F.R.
§ 164.308(a)(1)(i);
Failing to implement procedures to review records of
information system activity regularly, such as audit logs, access
reports, and security incident tracking reports in violation of 45
C.F.R. § 164.308(a)(1)(ii)(D);
Failing to protect against reasonably anticipated threats or
hazards to the security or integrity of electronic PHI in violation
of 45 C.F.R. § 164.306(a)(2);
Failing to protect against reasonably anticipated uses or
disclosures of electronic PHI that are not permitted under the
privacy rules regarding individually identifiable health
information in violation of 45 C.F.R. § 164.306(a)(3);
Failing to ensure compliance with HIPAA security standard rules
by its workforces in violation of 45 C.F.R. § 164.306(a)(4);
Failing to train all members of its workforces effectively on the
policies and procedures regarding PHI as necessary and
appropriate for the members of its workforces to carry out their
functions and to maintain security of PHI, in violation of 45
C.F.R. § 164.530(b);
Failing to render the electronic PHI it maintained unusable,
unreadable, or indecipherable to unauthorized individuals, as it
had not encrypted the electronic PHI as specified in the HIPAA
Security Rule by “the use of an algorithmic process to transform
data into a form in which there is a low probability of assigning
32


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1088 Filed 02/24/23 Page 33 of 125

r.
s.
t.
89.

meaning without use of a confidential process or key” (45 CFR
§ 164.304’s definition of “encryption”);
Failing to comply with FTC guidelines for cybersecurity, in
violation of Section 5 of the FTC Act;
Failing to adhere to industry standards for cybersecurity as
discussed above; and
Otherwise breaching its duties and obligations to protect
Plaintiffs’ and Class Members’ Private Information.

W&F negligently and unlawfully failed to safeguard Plaintiffs’ and

Class Members’ Private Information by allowing cyberthieves to access its computer
network and systems which contained unsecured and unencrypted Private
Information.
90.

Had W&F remedied the deficiencies in its information storage and

security systems, followed industry guidelines, and adopted security measures
recommended by experts in the field, W&F could have prevented intrusion into its
information storage and security systems and, ultimately, the theft of Plaintiffs’ and
Class Members’ confidential PII.
91.

However, due to W&F’s failures, Plaintiffs and Class Members now

face an increased risk of fraud and identity theft. In addition, Plaintiffs and the Class
Members also lost the benefit of the bargain they made with W&F.
H.

W&F Knew or Should Have Known that Criminals Target Private
Information
77.

W&F’s data security obligations were particularly important given the

substantial increase in cyberattacks and/or data breaches in the healthcare industry
33


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1089 Filed 02/24/23 Page 34 of 125

and other industries holding significant amounts of PII and PHI preceding the date
of the breach.
78.

At all relevant times, W&F knew, or should have known, its patients’,

Plaintiffs’, and all other Class Members’ Private Information was a target for
malicious actors. Despite such knowledge, W&F failed to implement and maintain
reasonable and appropriate data privacy and security measures to protect Plaintiffs’
and Class Members’ Private Information from cyber-attacks that W&F should have
anticipated and guarded against.
79.

The targeted attack was expressly designed to gain access to and

exfiltrate private and confidential data, including (among other things) the Private
Information of patients and/or plan Members, like Plaintiffs and Class Members.
80.

Cyber criminals seek out PHI at a greater rate than other sources of

personal information. In a 2022 report, the healthcare compliance company Protenus
found that there were 905 medical data breaches in 2021, leaving over 50 million
patient records exposed for 700 of the 2021 incidents. This is an increase from the
758 medical data breaches that Protenus compiled in 2020.15
81.

The healthcare sector suffered about 337 breaches in the first half of

2022 alone, according to Fortified Health Security’s mid-year report released in July.
2022 Breach Barometer, PROTENUS, see https://blog.protenus.com/keytakeaways-from-the-2022-breach-barometer (last visited Feb. 24, 2023) (attached
hereto as Exhibit 12).
34

15


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1090 Filed 02/24/23 Page 35 of 125

The percentage of healthcare breaches attributed to malicious activity rose more than
5 percentage points in the first six months of 2022 to account for nearly 80 percent
of all reported incidents. 16
82.

Further, a 2022 report released by IBM Security states that for 12

consecutive years the healthcare industry has had the highest average cost of a data
breach and as of 2022 healthcare data breach costs have hit a new record high.17
83.

Private Information is a valuable property right. 18 The value of Private

Information as a commodity is measurable.19 “Firms are now able to attain
significant market valuations by employing business models predicated on the
Jill McKeon, Health Sector Suffered 337 Healthcare Data Breaches in First
Half of Year, Cybersecurity News (July 19, 2022), available at:
https://healthitsecurity.com/news/health-sector-suffered-337-healthcare-databreaches-in-first-half-of-year (last visited Feb. 24, 2023) (attached hereto as Exhibit
13).
16

Cost of a Data Breach Report 2022, IBM Security, available:
https://www.ibm.com/downloads/cas/3R8N1DZJ (last visited Feb. 24, 2023)
(attached hereto as Exhibit 14).

17

See Marc van Lieshout, The Value of Personal Data, 457 IFIP ADVANCES IN
INFORMATION AND COMMUNICATION TECHNOLOGY 26 (May 2015),
https://www.researchgate.net/publication/283668023_The_Value_of_Personal_Dat
a (“The value of [personal] information is well understood by marketers who try to
collect as much data about personal conducts and preferences as possible[.]”) (last
visited Feb. 24, 2023) (attached hereto as Exhibit 15).
18

See Robert Lowes, Stolen EHR [Electronic Health Record] Charts Sell for
(Apr.
28,
2014),
$50
Each
on
Black
Market,
MEDSCAPE
http://www.medscape.com/viewarticle/824192 (last visited Feb. 24, 2023) (attached
hereto as Exhibit 16).
35
19


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1091 Filed 02/24/23 Page 36 of 125

successful use of personal data within the existing legal and regulatory
frameworks.”20 American companies are estimated to have spent over $19 billion on
acquiring personal data of consumers in 2018.21 Private Information is so valuable
to identity thieves that once Private Information has been disclosed, criminals often
trade it on the “cyber black-market,” or the “dark web,” for many years.
84.

As a result of its real value and the recent large-scale data breaches,

identity thieves and cyber criminals have openly posted credit card numbers, SSNs,
Private Information, and other sensitive information directly on various Internet
websites, making the information publicly available. This information from various
breaches, including the information exposed in the Data Breach, can be aggregated
and become more valuable to thieves and more damaging to victims.
85.

According to an FBI publication, “[r]ansomware is a type of malicious

software, or malware, that prevents you from accessing your computer files,
systems, or networks and demands you pay a ransom for their return. Ransomware
attacks can cause costly disruptions to operations and the loss of critical information
20

Exploring the Economics of Personal Data: A Survey of Methodologies for
Measuring Monetary Value, OECD 4 (Apr. 2, 2013), https://www.oecdilibrary.org/science-and-technology/exploring-the-economics-of-personaldata_5k486qtxldmq-en (last visited Feb. 24, 2023) (attached hereto as Exhibit 17).

21

U.S. Firms to Spend Nearly $19.2 Billion on Third-Party Audience Data and
Data-Use Solutions in 2018, Up 17.5% from 2017, INTERACTIVE ADVERTISING
BUREAU (Dec. 5, 2018), https://www.iab.com/news/2018-state-of-data-report/ (last
visited Feb. 24, 2023) (attached hereto as Exhibit 18).
36


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1092 Filed 02/24/23 Page 37 of 125

and data.” This publication also explains that “[t]he FBI does not support paying a
ransom in response to a ransomware attack. Paying a ransom doesn’t guarantee you
or your organization will get any data back. It also encourages perpetrators to target
more victims and offers an incentive for others to get involved in this type of illegal
activity.”22
86.

PHI is particularly valuable and has been referred to as a “treasure trove

for criminals.”23 A cybercriminal who steals a person’s PHI can end up with as many
as “seven to 10 personal identifying characteristics of an individual.” Ex. 19. A study
by Experian found that the “average total cost” of medical identity theft is “about
$20,000” per incident, and that a majority of victims of medical identity theft were
forced to pay out-of-pocket costs for healthcare they did not receive in order to
restore coverage.24

See https://www.fbi.gov/how-we-can-help-you/safety-resources/scams-andsafety/common-scams-and-crimes/ransomware (last visited Feb. 24, 2023) (attached
hereto as Exhibit 19).

22

See Andrew Steger, What Happens to Stolen Healthcare Data?, HEALTHTECH
MAGAZINE (Oct. 30, 2019), https://healthtechmagazine.net/article/2019/10/whathappens-stolen-healthcare-data-perfcon (quoting Tom Kellermann, Chief
Cybersecurity Officer, Carbon Black, stating “Health information is a treasure trove
for criminals.”) (last visited Feb. 24, 2023) (attached hereto as Exhibit 20).
23

See ECF No. 1-7, Elinor Mills, Study: Medical identity theft is costly for
victims, CNET (Mar. 3, 2010).
37

24


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1093 Filed 02/24/23 Page 38 of 125

87.

All-inclusive health insurance dossiers containing sensitive health

insurance information, names, addresses, telephone numbers, email addresses,
SSNs, and bank account information, complete with account and routing numbers,
can fetch up to $1,200 to $1,300 each on the black market.25 According to a report
released by the FBI Cyber Division, criminals can sell healthcare records for 50
times the price of a stolen Social Security or credit card number. 26
88.

According to an article in the HIPAA Journal posted on October 14,

2022, cybercriminals hack into medical practices for their “highly prized” medical
records. “[T]he number of data breaches reported by HIPAA-regulated entities
continues to increase every year. 2021 saw 714 data breaches of 500 or more records
reported to the [HHS’ Office for Civil Rights] OCR – an 11% increase from the
previous year. Almost three-quarters of those breaches were classified as hacking/IT
incidents.”

Adam Greenberg, Health insurance credentials fetch high prices in the online
black
market,
SC
MAGAZINE
(July
16,
2013),
https://www.scmagazine.com/news/breach/health-insurance-credentials-fetchhigh-prices-in-the-online-black-market (last visited Feb. 24, 2023) (attached hereto
as Exhibit 21).

25

26

See Health Care Systems and Medical Devices at Risk for Increased Cyber
Intrusions for Financial Gain, FBI CYBER DIVISION (Apr. 8, 2014),
https://www.illuminweb.com/wp-content/uploads/ill-mo-uploads/103/2418/healthsystems-cyber-intrusions.pdf (last visited Feb. 24, 2023) (attached hereto as Exhibit
22).
38


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1094 Filed 02/24/23 Page 39 of 125

89.

Healthcare organizations are easy targets because “even relatively

small healthcare providers may store the records of hundreds of thousands of
patients. The stored data is highly detailed, including demographic data, Social
Security numbers, financial information, health insurance information, and medical
and clinical data, and that information can be easily monetized.”
90.

The HIPAA Journal article goes on to explain that patient records, like

those stolen from W&F, are “often processed and packaged with other illegally
obtained data to create full record sets (fullz) that contain extensive information on
individuals, often in intimate detail.” The record sets are then sold on dark web sites
to other criminals and “allows an identity kit to be created, which can then be sold
for considerable profit to identity thieves or other criminals to support an extensive
range of criminal activities.”
91.

Criminals can use stolen Private Information to extort a financial

payment by “leveraging details specific to a disease or terminal illness.” See Ex. 7.
Quoting Carbon Black’s Chief Cybersecurity Officer, one recent article explained:
“Traditional criminals understand the power of coercion and extortion…By having
healthcare information—specifically, regarding a sexually transmitted disease or
terminal illness—that information can be used to extort or coerce someone to do
what you want them to do.” Id.

39


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1095 Filed 02/24/23 Page 40 of 125

92.

Consumers place a high value on the privacy of that data. Researchers

shed light on how much consumers value their data privacy—and the amount is
considerable. Indeed, studies confirm that “when privacy information is made more
salient and accessible, some consumers are willing to pay a premium to purchase
from privacy protective websites.”27
93.

Given these facts, any company that transacts business with a consumer

and then compromises the privacy of consumers’ Private Information has thus
deprived that consumer of the full monetary value of the consumer’s transaction with
the company.
94.

Indeed, cyberattacks against the healthcare industry have been common

for over ten years with the Federal Bureau of Investigation (“FBI”) warning as early
as 2011 that cybercriminals were “advancing their abilities to attack a system
remotely” and “[o]nce a system is compromised, cyber criminals will use their
accesses to obtain PII.” The FBI further warned that that “the increasing
sophistication of cyber criminals will no doubt lead to an escalation in
cybercrime.”28
Janice Y. Tsai et al., The Effect of Online Privacy Information on Purchasing
Behavior, An Experimental Study, 22(2) INFORMATION SYSTEMS RESEARCH 254
(June 2011), available at: https://www.guanotronic.com/~serge/papers/weis07.pdf
(last visited Feb. 24, 2023) (attached hereto as Exhibit 23).
27

Gordon M. Snow, Statement before the House Financial Services Committee,
Subcommittee on Financial Institutions and Consumer Credit, FBI (Sept. 14, 2011),
40

28


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1096 Filed 02/24/23 Page 41 of 125

95.

Cyberattacks have become so notorious that the FBI and U.S. Secret

Service have issued a warning to potential targets, so they are aware of, and prepared
for, a potential attack. As one report explained, entities like and hospitals are
attractive to ransomware criminals because they often have lesser IT defenses and a
high incentive to regain access to their data quickly. 29
96.

In fact, according to the cybersecurity firm Mimecast, 90% of

healthcare organizations experienced cyberattacks in the past year. 30
97.

W&F was on notice that the FBI has recently been concerned about

data security in the healthcare industry. In August 2014, after a cyberattack on
Community Health Systems, Inc., the FBI warned companies within the healthcare
industry that hackers were targeting them. The warning stated that “[t]he FBI has
observed malicious actors targeting healthcare related systems, perhaps for the

https://archives.fbi.gov/archives/news/testimony/cyber-security-threats-to-thefinancial-sector (last visited Feb. 24, 2023) (attached hereto as Exhibit 24).
29
Ransomware Attacks on Hospitals Put Patients at Risk (May 18, 2022)
https://www.pewtrusts.org/en/research-and-analysis/blogs/stateline/2022/05/18/
ransomware-attacks-on-hospitals-put-patients-at-risk (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 25).
See Maria Henriquez, Iowa City Hospital Suffers Phishing Attack, Security
Magazine (Nov. 23, 2020), https://www.securitymagazine.com/articles/93988iowa-city-hospital-suffers-phishing-attack (last accessed Feb. 24, 2023) (attached
hereto as Exhibit 26).
30

41


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1097 Filed 02/24/23 Page 42 of 125

purpose of obtaining the Protected Healthcare Information (PHI) and/or Personally
Identifiable Information (PII).”31
98.

The American Medical Association (“AMA”) has also warned

healthcare companies about the importance of protecting their patients’ confidential
information:
Cybersecurity is not just a technical issue; it’s a patient safety
issue. AMA research has revealed that 83% of physicians work
in a practice that has experienced some kind of cyberattack.
Unfortunately, practices are learning that cyberattacks not only
threaten the privacy and security of patients’ health and financial
information, but also patient access to care.32
99.

As implied by the above AMA quote, stolen Private Information can be

used to interrupt important medical services. This is an imminent and certainly
impending risk for Plaintiffs and Class Members.
100. W&F was on notice that the federal government has been concerned
about healthcare company data encryption practices. W&F knew its employees

Jim Finkle, FBI Warns Healthcare Firms that they are Targeted by Hackers,
REUTERS (Aug. 2014), https://www.reuters.com/article/us-cybersecurity-healthcarefbi/fbi-warns-healthcare-firms-they-are-targeted-by-hackers-idUSKBN0GK24
U20140820 (last visited Feb. 24, 2023) (attached hereto as Exhibit 27).

31

Andis Robeznieks, Cybersecurity: Ransomware attacks shut down clinics,
hospitals, AM. MED. ASS’N (Oct. 4, 2019), https://www.ama-assn.org/practicemanagement/sustainability/cybersecurity-ransomeware-attacks-shut-down-clinicshospitals (last visited Feb. 24, 2023) (attached hereto as Exhibit 28).
42

32


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1098 Filed 02/24/23 Page 43 of 125

accessed and utilized protected health information in the regular course of their
duties, yet it appears that information was not encrypted.
101. The OCR urges the use of encryption of data containing sensitive
personal information. As far back as 2014, the Department fined two healthcare
companies approximately two million dollars for failing to encrypt laptops
containing sensitive personal information. In announcing the fines, Susan
McAndrew, formerly OCR’s deputy director of health information privacy, stated in
2014 that “[o]ur message to these organizations is simple: encryption is your best
defense against these incidents.”33
102. As a HIPAA covered business associate, W&F should have known
about its data security vulnerabilities and implemented enhanced and adequate
protection, particularly given the nature of the Private Information stored in its
unprotected files.
I.

Cyberattacks and Data Breaches Cause Disruption and Put Consumers at
an Increased Risk of Fraud and Identity Theft

“Stolen Laptops Lead to Important HIPAA Settlements,” U.S. Dep’t of Health
and Human Services (Apr. 22, 2014), available at https://wayback.archiveit.org/3926/20170127085330/https://www.hhs.gov/about/news/2014/04/22/stolenlaptops-lead-to-important-hipaa-settlements.html (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 29).

33

43


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1099 Filed 02/24/23 Page 44 of 125

103. Cyberattacks and data breaches at healthcare companies like W&F are
especially problematic because they can negatively impact the overall daily lives of
individuals affected by the attack.
104. Researchers have found that among medical service providers that
experience a data security incident, the death rate among patients increased in the
months and years after the attack. 34
105. Researchers have further found that at medical service providers that
experienced a data security incident, the incident was associated with deterioration
in timeliness and patient outcomes, generally.35
106. The United States Government Accountability Office released a report
in 2007 regarding data breaches (“GAO Report”) in which it noted that victims of
identity theft will face “substantial costs and time to repair the damage to their good
name and credit record.” 36
See Nsikan Akpan, Ransomware and Data Breaches Linked to Uptick in Fatal
Heart Attacks, PBS (Oct. 24, 2019), https://www.pbs.org/newshour
/science/ransomware-and-other-data-breaches-linked-to-uptick-in-fatal-heartattacks (last visited Feb. 24, 2023) (attached hereto as Exhibit 30).
34

See Sung J. Choi et al., Data Breach Remediation Efforts and Their
Implications for Hospital Quality, 54 Health Services Research 971, 971-980
(2019). Available at https://onlinelibrary.wiley.com/doi/full/10.1111/14756773.13203 (last visited Feb. 24, 2023).

35

See U.S. Gov. Accounting Office, GAO-07-737, Personal Information: Data
Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited;
However, the Full Extent Is Unknown (2007). Available at
44

36


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1100 Filed 02/24/23 Page 45 of 125

107. That is because any victim of a data breach is exposed to serious
ramifications regardless of the nature of the data. Indeed, the reason criminals steal
personally identifiable information is to monetize it. They do this by selling the
spoils of their cyberattacks on the black market to identity thieves who desire to
extort and harass victims, take over victims’ identities in order to engage in illegal
financial transactions under the victims’ names. Because a person’s identity is akin
to a puzzle, the more accurate pieces of data an identity thief obtains about a person,
the easier it is for the thief to take on the victim’s identity, or otherwise harass or
track the victim. For example, armed with just a name and date of birth, a data thief
can utilize a hacking technique referred to as “social engineering” to obtain even
more information about a victim’s identity, such as a person’s login credentials or
Social Security number. Social engineering is a form of hacking whereby a data thief
uses previously acquired information to manipulate individuals into disclosing
additional confidential or personal information through means such as spam phone
calls and text messages or phishing emails.
108. Theft of Private Information is serious. The FTC warns consumers that
identity thieves use Private Information to exhaust financial accounts, receive
medical treatment, start new utility accounts, and incur charges and credit in a

https://www.gao.gov/new.items/d07737.pdf (last visited Feb. 24, 2023) (attached
hereto as Exhibit 31).
45


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1101 Filed 02/24/23 Page 46 of 125

person’s name.
109. The FTC recommends that identity theft victims take several steps to
protect their personal and financial information after a data breach, including
contacting one of the credit bureaus to place a fraud alert (and consider an extended
fraud alert that lasts for 7 years if someone steals their identity), reviewing their
credit reports, contacting companies to remove fraudulent charges from their
accounts, placing a credit freeze on their credit, and correcting their credit reports.37
110. Identity thieves use stolen personal information such as Social Security
numbers for a variety of crimes, including credit card fraud, phone or utilities fraud,
and bank/finance fraud. According to Experian, one of the largest credit reporting
companies in the world, “[t]he research shows that personal information is valuable
to identity thieves, and if they can get access to it, they will use it” to among other
things: open a new credit card or loan, change a billing address so the victim no
longer receives bills, open new utilities, obtain a mobile phone, open a bank account
and write bad checks, use a debit card number to withdraw funds, obtain a new
driver’s license or ID, and/or use the victim’s information in the event of arrest or
court action.

See
IdentityTheft.gov,
Federal
Trade
Commission,
https://www.identitytheft.gov/Steps (last accessed Feb. 24, 2023) (attached hereto
as Exhibit 32).
37

46


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1102 Filed 02/24/23 Page 47 of 125

111. Identity thieves can also use the victim’s name and Social Security
number to obtain government benefits; or file a fraudulent tax return using the
victim’s information. In addition, identity thieves may obtain a job using the victim’s
Social Security number, and/or rent a house or receive medical services in the
victim’s name.
112. Moreover, theft of Private Information is also gravely serious because
Private Information is an extremely valuable property right. 38
113. Theft of PHI, in particular, is gravely serious: “[a] thief may use your
name or health insurance numbers to see a doctor, get prescription drugs, file claims
with your insurance provider, or get other care. If the thief’s health information is
mixed with yours, your treatment, insurance and payment records, and credit report
may be affected.”39
114. Drug manufacturers, medical device manufacturers, pharmacies,
hospitals and other healthcare service providers often purchase Private Information

See, e.g., John T. Soma, et al, Corporate Privacy Trend: The “Value” of
Personally Identifiable Information (“PII”) Equals the “Value" of Financial Assets,
15 Rich. J.L. & Tech. 11, at *3-4 (2009) (“PII, which companies obtain at little cost,
has quantifiable value that is rapidly reaching a level comparable to the value of
traditional financial assets.”) (citations omitted) (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 33).

38

See
Federal
Trade
Commission,
Medical
Identity
Theft,
http://www.consumer.ftc.gov/articles/0171-medical-identity-theft (last accessed
Feb. 24, 2023) (attached hereto as Exhibit 34).
47
39


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1103 Filed 02/24/23 Page 48 of 125

on the black market for the purpose of target-marketing their products and services
to the physical maladies of the data breach victims themselves. Insurance companies
purchase and use wrongfully disclosed PHI to adjust their insureds’ medical
insurance premiums.
115. Each year, identity theft causes tens of billions of dollars of losses to
victims in the United States. For example, with the Private Information stolen in the
Data Breach, which includes Social Security numbers, identity thieves can open
financial accounts, commit medical fraud, apply for credit, file fraudulent tax
returns, commit crimes, create false driver’s licenses and other forms of
identification and sell them to other criminals or undocumented immigrants, steal
government benefits, give breach victims’ names to police during arrests, and many
other harmful forms of identity theft. These criminal activities have and will result
in devastating financial and personal losses to Plaintiffs and Class Members.
116. Private Information is such a valuable commodity to identity thieves
that once the information has been compromised, criminals often trade the
information on the “cyber black-market” for years.
117. There is a strong probability that entire batches of stolen information
have been dumped on the black market and are yet to be dumped on the black market,
meaning Plaintiffs and Class Members are at an increased risk of fraud and identity
theft for many years into the future.
48


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1104 Filed 02/24/23 Page 49 of 125

118. For example, it is believed that certain highly sensitive personal
information compromised in the 2017 Experian data breach was being used, three
years later, by identity thieves to apply for COVID-19-related unemployment
benefits.
119. Cyber criminals may not use the information right away. According to
the U.S. Government Accountability Office, which conducted a study regarding data
breaches:
[I]n some cases, stolen data may be held for up to a year or more before
being used to commit identity theft. Further, once stolen data have been
sold or posted on the Web, fraudulent use of that information may
continue for years. As a result, studies that attempt to measure the harm
resulting from data breaches cannot necessarily rule out all future
harm.40
120. Social security numbers are particularly sensitive pieces of personal
information. As the Consumer Federation of America explains:
Social Security number: This is the most dangerous type of personal
information in the hands of identity thieves because it can open the gate to
serious fraud, from obtaining credit in your name to impersonating you to get
medical services, government benefits, your tax refund, employment—even
using your identity in bankruptcy and other legal matters. It’s hard to change
your Social Security number and it’s not a good idea because it is connected
to your lift in so many ways. 41
40

See supra.

See, e.g., Christine DiGangi, 5 Ways an Identity Thief Can Use Your Social
Security Number, Nov. 2, 2017, https://blog.credit.com/2017/11/5-things-anidentity-thief-can-do-with-your-social-security-number-108597/ (emphasis added)
(last accessed Feb. 24, 2023) (attached hereto as Exhibit 35).

41

49


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1105 Filed 02/24/23 Page 50 of 125

121. For instance, with a stolen Social Security number, which is only one
subset of the Private Information compromised in the Data Breach, someone can
open financial accounts, get medical care, file fraudulent tax returns, commit crimes,
and steal benefits. Id.
122. The Social Security Administration has warned that identity thieves can
use an individual’s Social Security number to apply for additional credit lines. Id.
Such fraud may go undetected until debt collection calls commence months, or even
years, later. Stolen Social Security Numbers also make it possible for thieves to file
fraudulent tax returns, file for unemployment benefits, or apply for a job using a
false identity. Id. at 4. Each of these fraudulent activities is difficult to detect. An
individual may not know that his or her Social Security Number was used to file for
unemployment benefits until law enforcement notifies the individual’s employer of
the suspected fraud. Fraudulent tax returns are typically discovered only when an
individual’s authentic tax return is rejected.
123. An individual cannot obtain a new Social Security number without
significant paperwork and evidence of actual misuse. Even then, a new Social
Security number may not be effective, as “[t]he credit bureaus and banks are able to
link the new number very quickly to the old number, so all of that old bad

50


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1106 Filed 02/24/23 Page 51 of 125

information is quickly inherited into the new Social Security number.” 42
124. This was a financially motivated Data Breach, as the only reason the
cybercriminals go through the trouble of running a targeted cyberattack against
companies like W&F is to get information that they can monetize by selling on the
black market for use in the kinds of criminal activity described herein. This data
demands a much higher price on the black market. Martin Walter, senior director at
cybersecurity firm RedSeal, explained, “[c]ompared to credit card information,
personally identifiable information and Social Security Numbers are worth more
than 10x on the black market.”
125. Indeed, a social security number, date of birth, and full name can sell
for $60 to $80 on the digital black market.43 “[I]f there is reason to believe that your
personal information has been stolen, you should assume that it can end up for sale
on the dark web.” 44
Brian Naylor, Victims of Social Security Number Theft Find It’s Hard to
Bounce Back, NPR (Feb. 9, 2015), http://www.npr.org/2015/02/09/384875839/datastolen-by-anthem-s-hackers-has-millions-worrying-about-identity-theft
(last accessed Feb. 24, 2023) (attached hereto as Exhibit 36).

42

Michael Kan, Here’s How Much Your Identity Goes for on the Dark Web,
Nov. 15, 2017, https://www.pcmag.com/news/heres-how-much-your-identity-goesfor-on-the-dark-web (last accessed Feb. 24, 2023) (attached hereto as Exhibit 37).

43

Dark Web Monitoring: What You Should Know, Consumer Federation of
America, Mar. 19, 2019, https://consumerfed.org/consumer_info/dark-webmonitoring-what-you-should-know/ (last accessed Feb. 24, 2023) (attached hereto
as Exhibit 38).
51

44


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1107 Filed 02/24/23 Page 52 of 125

126. The medical information, PHI, which was exposed is also highly
valuable. PHI can sell for as much as $363 according to the Infosec Institute.45
127. These risks are both certainly impending and substantial. As the FTC
has reported, if hackers get access to PII, they will use it. Id.
128. Identity theft is not an easy problem to solve. In a survey, the Identity
Theft Resource Center found that most victims of identity crimes need more than a
month to resolve issues stemming from identity theft and some need over a year. 46
129. Theft of SSNs also creates a particularly alarming situation for victims
because those numbers cannot easily be replaced. In order to obtain a new number,
a breach victim has to demonstrate ongoing harm from misuse of her SSN, and a
new SSN will not be provided until after the victim has suffered the harm.
130. Due to the highly sensitive nature of SSNs, theft of SSNs in
combination with other PII (e.g., name, address, date of birth) is akin to having a
master key to the gates of fraudulent activity. TIME quotes data security researcher

Center for Internet Security, Data Breaches: In the Healthcare Sector,
available at: https://www.cisecurity.org/blog/data-breaches-in-the-healthcaresector/ (last accessed Feb. 24, 2023) (attached hereto as Exhibit 39).

45

46

2021 Consumer Aftermath Report: How Identity Crimes Impact Victims, their
Families, Friends, and Workplaces, IDENTITY THEFT RESOURCE CENTER (2021),
https://www.idtheftcenter.org/identity-theft-aftermath-study/ (last accessed Feb. 24,
2023) (attached hereto as Exhibit 40).
52


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1108 Filed 02/24/23 Page 53 of 125

Tom Stickley, who is employed by companies to find flaws in their computer
systems, as stating, “If I have your name and your Social Security number and you
haven’t gotten a credit freeze yet, you’re easy pickings.” 47
131. Theft of PII is even more serious when it includes theft of PHI. PHI is
particularly valuable because criminals can use it to target victims with frauds and
scams that take advantage of the victim’s medical conditions or victim settlements.
It can be used to create fake insurance claims, allowing for the purchase and resale
of medical equipment, or gain access to prescriptions for illegal use or resale.
132. Medical identity theft is one of the most common, most expensive, and
most difficult-to-prevent forms of identity theft. Medical identify theft can result in
inaccuracies in medical records and costly false claims. It can also have lifethreatening consequences. If a victim’s health information is mixed with other
records, it can lead to misdiagnosis or mistreatment. According to Kaiser Health
News, “medical-related identity theft accounted for 43 percent of all identity thefts
reported in the United States in 2013,” which is more than identity thefts involving
banking and finance, the government and the military, or education. 48 “Medical

Patrick Lucas Austin, 'It Is Absurd.' Data Breaches Show it's Time to Rethink
How We Use Social Security Numbers, Experts Say, TIME (Aug. 5, 2019, 3:39 PM),
https://time.com/5643643/capital-one-equifax-data-breach-social-security/
(last
accessed Feb. 24, 2023) (attached hereto as Exhibit 41).
47

48

Michael Ollove, “The Rise of Medical Identity Theft in Healthcare,” Kaiser
53


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1109 Filed 02/24/23 Page 54 of 125

identity theft is a growing and dangerous crime that leaves its victims with little to
no recourse for recovery,” reported Pam Dixon, executive director of World Privacy
Forum. Id. “Victims often experience financial repercussions and worse yet, they
frequently discover erroneous information has been added to their personal medical
files due to the thief’s activities.” Id.
133. Data breaches involving medical information “typically leave[] a trail
of falsified information in medical records that can plague victims’ medical and
financial lives for years.”49 It “is also more difficult to detect, taking almost twice as
long as normal identity theft.” 50 In warning consumers on the dangers of medical
identity theft, the FTC states that an identity thief may use Private Information “to
see a doctor, get prescription drugs, buy medical devices, submit claims with your
insurance provider, or get other medical care.” 51 The FTC also warns, “If the thief’s
health information is mixed with yours, it could affect the medical care you’re able
to get or the health insurance benefits you’re able to use. It could also hurt your
Health News, Feb. 7, 2014, https://khn.org/news/rise-of-indentity-theft/ (last
accessed Feb. 24, 2023) (attached hereto as Exhibit 42).
Pam Dixon and John Emerson, The Geography of Medical Identity Theft,
WORLD
PRIVACY
FORUM
6
(Dec.
12,
2017),
https://www.worldprivacyforum.org/2017/12/new-report-the-geography-ofmedical-identity-theft/ (last accessed Feb. 24, 2023) (attached hereto as Exhibit 43).
49

50

See supra.

51

See supra.
54


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1110 Filed 02/24/23 Page 55 of 125

credit.”52
134. A report published by the World Privacy Forum and presented at the
US FTC Workshop on Informational Injury describes what medical identity theft
victims may experience:

52

•

Changes to their health care records, most often the addition of
falsified information, through improper billing activity or activity by
imposters. These changes can affect the healthcare a person receives
if the errors are not caught and corrected.

•

Significant bills for medical goods and services not sought nor
received.

•

Issues with insurance, co-pays, and insurance caps.

•

Long-term credit problems based on problems with debt collectors
reporting debt due to identity theft.

•

Serious life consequences resulting from the crime; for example,
victims have been falsely accused of being drug users based on
falsified entries to their medical files; victims have had their children
removed from them due to medical activities of the imposter; victims
have been denied jobs due to incorrect information placed in their
health files due to the crime.

•

As a result of improper and/or fraudulent medical debt reporting,
victims may not qualify for mortgage or other loans and may
experience other financial impacts.

•

Phantom medical debt collection based on medical billing or other
identity information.

Id.
55


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1111 Filed 02/24/23 Page 56 of 125

•

Sales of medical debt arising from identity theft can perpetuate a
victim’s debt collection and credit problems, through no fault of their
own.53

135. There may also be a time lag between when sensitive personal
information is stolen, when it is used, and when a person discovers it has been used.
Fraud and identity theft resulting from the Data Breach may go undetected until debt
collection calls commence months, or even years, later. An individual may not know
that his or her Social Security Number was used to file for unemployment benefits
until law enforcement notifies the individual’s employer of the suspected fraud.
Fraudulent tax returns are typically discovered only when an individual’s authentic
tax return is rejected.
136. For example, on average it takes approximately three months for
consumers to discover their identity has been stolen and used, and it takes some
individuals up to three years to learn that information.54
137. Cybercriminals can post stolen Private Information on the cyber blackmarket for years following a data breach, thereby making such information publicly
available.

53

See supra.

John W. Coffey, Difficulties in Determining Data Breach Impacts, 17
JOURNAL OF SYSTEMICS, CYBERNETICS AND INFORMATICS 9 (2019),
http://www.iiisci.org/journal/pdv/sci/pdfs/IP069LL19.pdf (last accessed Feb. 24,
2023) (attached hereto as Exhibit 44).
56
54


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1112 Filed 02/24/23 Page 57 of 125

138. Approximately 21% of victims do not realize their identify has been
compromised until more than two years after it has happened. 55 This gives thieves
ample time to seek multiple treatments under the victim’s name. Forty percent of
consumers found out they were a victim of medical identity theft only when they
received collection letters from creditors for expenses that were incurred in their
names.56
139. Identity theft victims must spend countless hours and large amounts of
money repairing the impact to their credit as well as protecting themselves in the
future.57
140. It is within this context that Plaintiffs and all other Class Members must
now live with the knowledge that their Private Information is forever in cyberspace
and was taken by people willing to use the information for any number of improper

See
Medical
ID
Theft
Checklist,
available
at:
https://www.identityforce.com/blog/medical-id-theft-checklist-2 (last accessed Feb.
24, 2023) (attached hereto as Exhibit 45).
55

Experian, The Potential Damages and Consequences of Medical Identify
Theft and Healthcare Data Breaches (“Potential Damages”), available at:
https://www.experian.com/assets/data-breach/white-papers/consequences-medicalid-theft-healthcare.pdf (last accessed Feb. 24, 2023) (attached hereto as Exhibit 46).

56

“Guide for Assisting Identity Theft Victims,” Federal Trade Commission, 4
(Sept. 2013), http://www.consumer.ftc.gov/articles/pdf-0119-guide-assisting-idtheft-victims.pdf (last accessed Feb. 24, 2023) (attached hereto as Exhibit 47).

57

57


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1113 Filed 02/24/23 Page 58 of 125

purposes and scams, including making the information available for sale on the black
market.
141. A study by the Identity Theft Resource Center shows the multitude of
harms caused by fraudulent use of personal and financial information.

142. Victims of the Data Breach, like Plaintiffs and Class Members, must
spend many hours and large amounts of money protecting themselves from the
current and future negative impacts to their privacy and credit because of the Data
Breach. Id.
143. As a direct and proximate result of the Data Breach, Plaintiffs and Class
Members have had their Private Information exposed, have suffered harm as a result,
and have been placed at an imminent, immediate, and continuing increased risk of
58


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1114 Filed 02/24/23 Page 59 of 125

harm from fraud and identity theft. Plaintiffs and Class Members must now take the
time and effort (and spend the money) to mitigate the actual and potential impact of
the Data Breach on their everyday lives, including purchasing identity theft and
credit monitoring services every year for the rest of their lives, placing “freezes” and
“alerts” with credit reporting agencies, contacting their financial institutions and
healthcare providers, closing or modifying financial accounts, and closely reviewing
and monitoring bank accounts, credit reports, and health insurance account
information for unauthorized activity for years to come.
144. Plaintiffs and Class Members have suffered or will suffer actual harms
for which they are entitled to compensation, including but not limited to the
following:
a. Actual identity theft, including fraudulent credit inquiries and
cards being opened in their names;
b. Trespass, damage to, and theft of their personal property, including
Private Information;
c. Improper disclosure of their Private Information;
d. The imminent and certainly impending injury flowing from actual
and potential future fraud and identity theft posed by their Private
Information being in the hands of criminals and having already been
misused;
59


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1115 Filed 02/24/23 Page 60 of 125

e. The imminent and certainly impending risk of having their
confidential medical information used against them by spam callers
to defraud them;
f. Damages flowing from W&F’s untimely (and in some cases, nonexistent) and inadequate notification of the Data Breach;
g. Loss of privacy suffered as a result of the Data Breach;
h. Ascertainable losses in the form of out-of-pocket expenses and the
value of their time reasonably expended to remedy or mitigate the
effects of the Data Breach;
i. Ascertainable losses in the form of deprivation of the value of
patients’ personal information for which there is a well-established
and quantifiable national and international market;
j. The loss of use of and access to their credit, accounts, and/or funds;
k. Damage to their credit due to fraudulent use of their Private
Information; and
l. Increased cost of borrowing, insurance, deposits, and other items
which are adversely affected by a reduced credit score.
145. Moreover, Plaintiffs and Class Members have an interest in ensuring
that their Private Information, which remains in the possession of W&F, is protected
from further public disclosure by the implementation of better employee training and
60


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1116 Filed 02/24/23 Page 61 of 125

industry standard and statutorily compliant security measures and safeguards. W&F
has shown itself to be wholly incapable of protecting Plaintiffs’ and Class Members’
Private Information.
146. Plaintiffs and Class Members also have an interest in ensuring that their
personal information that was provided to W&F is removed from W&F’s
unencrypted files.
147. W&F itself acknowledged the harm caused by the Data Breach because
it offered Plaintiffs and Class Members the inadequate 12 months of identity theft
protection and credit monitoring services. This limited identity theft monitoring is,
however, inadequate to protect Plaintiffs and Class Members from a lifetime of
identity theft risk.
148. W&F further acknowledged, in its letter to Plaintiffs and Class
Members, that, in response to the Data Breach, W&F has “implemented a series of
cybersecurity enhancements, including installation of additional endpoint detection
and response software, resetting all passwords and rebuilding affected servers.” See
Ex. 2.
149. The notice further acknowledged that the Data Breach would cause
inconvenience to affected individuals by providing numerous “steps” for Class
Members to take in an attempt to mitigate the harm caused by the Data Breach, and
that financial harm would likely occur, stating: “Out of an abundance of caution, and
61


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1117 Filed 02/24/23 Page 62 of 125

in accordance with applicable law, we are providing this notice to you so that you
can take steps to minimize the risk that your information will be misused. Id. The
attached sheet describes steps you can take to protect your identity, credit, and
personal information.”
150. At W&F’s suggestion, Plaintiffs are trying to mitigate the damage that
W&F has caused them. Given the kind of Private Information W&F made accessible
to hackers, however, Plaintiffs are certain to incur additional damages. Because
identity thieves have their Private Information, Plaintiffs and all Class Members will
need to have identity theft monitoring protection for the rest of their lives. Some may
even need to go through the long and arduous process of getting a new Social
Security number, with all the loss of credit and employment difficulties that come
with a new number.58 None of this should have happened.
151. Because of the value of its collected and stored data, the medical
industry has experienced disproportionally higher numbers of data theft events than
other industries. For this reason, W&F knew or should have known about these
dangers and strengthened its data security accordingly. W&F was put on notice of

Will a New Social Security Number Affect Your Credit?, LEXINGTON LAW
(Nov. 16, 2015), https://www.lexingtonlaw.com/blog/credit-101/will-a-new-socialsecurity-number-affect-your-credit.html (last accessed Feb. 24, 2023) (attached
hereto as Exhibit 48).

58

62


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1118 Filed 02/24/23 Page 63 of 125

the substantial and foreseeable risk of harm from a data breach, yet it failed to
properly prepare for that risk.
J.

The Data Breach Was Foreseeable and Preventable
152. Data security breaches have dominated the headlines for the last two

decades. And it doesn’t take an IT industry expert to know it. The general public can
tell you the names of some of the biggest cybersecurity breaches: Target,59 Yahoo,60
Marriott International, 61 Chipotle, Chili’s, Arby’s,62 and others. 63
Michael Kassner, Anatomy of the Target Data Breach: Missed Opportunities
and
Lessons
Learned,
ZDNET
(Feb.
2,
2015),
https://www.zdnet.com/article/anatomy-of-the-target-data-breach-missedopportunities-and-lessons-learned/ (last accessed Feb. 24, 2023) (attached hereto as
Exhibit 49).
59

Martyn Williams, Inside the Russian Hack of Yahoo: How They Did It,
CSOONLINE.COM (Oct. 4, 2017), https://www.csoonline.com/article/3180762/
inside-the-russian-hack-of-yahoo-how-they-did-it.html (last accessed Feb. 24,
2023) (attached hereto as Exhibit 50).
60

Patrick Nohe, The Marriot Data Breach: Full Autopsy, THE SSL STORE:
HASHEDOUT (Mar. 22, 2019), https://www.thesslstore.com/blog/autopsying-themarriott-data-breach-this-is-why-insurance-matters/ (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 51).
61

Alfred Ng, FBI Nabs Alleged Hackers in Theft of 15M Credit Cards from
Chipotle, Others, CNET (Aug. 1, 2018), https://www.cnet.com/news/fbi-nabsalleged-hackers-in-theft-of-15m-credit-cards-from-chipotle-others/?ftag=CMG-0110aaa1b (last accessed Feb. 24, 2023) (attached hereto as Exhibit 52).
62

See, e.g., Taylor Armerding, The 18 Biggest Data Breaches of the 21st
Century, CSO ONLINE (Dec. 20, 2018), https://www.csoonline.com
/article/2130877/the-biggest-data-breaches-of-the-21st-century.html (last accessed
Feb. 24, 2023) (attached hereto as Exhibit 53).
63
63


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1119 Filed 02/24/23 Page 64 of 125

153. Companies providing services to the healthcare industry, such as W&F,
have been prime targets for cyberattacks. As early as August 2014, the FBI
specifically warned companies within the healthcare industry that hackers were
targeting them. The warning stated that “[t]he FBI has observed malicious actors
targeting healthcare related systems, perhaps for the purpose of obtaining the
Protected Healthcare Information (PHI) and/or Personally Identifiable Information
(PII).” 64
154. W&F should certainly have been aware, and indeed was aware, that it
was at risk for a data breach that could expose the Private Information that it
collected and maintained.
155. W&F was clearly aware of the risks it was taking and the harm that
could result from inadequate data security, and it could have prevented this Data
Breach.
156. Data disclosures and data breaches are preventable.65 As Lucy
Thompson wrote in the Data Breach and Encryption Handbook, “In almost all cases,
the data breaches that occurred could have been prevented by proper planning and

64

See supra.

Lucy L. Thompson, “Despite the Alarming Trends, Data Breaches Are
Preventable,” in DATA BREACH AND ENCRYPTION HANDBOOK (Lucy Thompson, ed.,
2012).

65

64


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1120 Filed 02/24/23 Page 65 of 125

the correct design and implementation of appropriate security solutions.” Id. She
added that “[o]rganizations that collect, use, store, and share sensitive personal data
must accept responsibility for protecting the information and ensuring that it is not
compromised[.]” Id.
157. “Most of the reported data breaches are a result of lax security and the
failure to create or enforce appropriate security policies, rules, and procedures …
Appropriate information security controls, including encryption, must be
implemented and enforced in a rigorous and disciplined manner so that a data breach
never occurs.” Id.
158. In a Data Breach like this, many failures laid the groundwork for the
Breach. The FTC has published guidelines that establish reasonable data security
practices for businesses. The FTC guidelines emphasize the importance of having a
data security plan, regularly assessing risks to computer systems, and implementing
safeguards to control such risks. 66 The guidelines establish that businesses should
protect the confidential information that they keep; properly dispose of personal
information that is no longer needed; encrypt information stored on computer
networks; understand their network’s vulnerabilities; and implement policies for

FTC, Protecting Personal Information: A Guide for Business,
https://www.ftc.gov/system/files/documents/plain-language/pdf-0136_protetingpersonal-information.pdf. (last accessed Feb. 24, 2023) (attached hereto as Exhibit
54).
65

66


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1121 Filed 02/24/23 Page 66 of 125

installing vendor-approved patches to correct security problems. The guidelines also
recommended that businesses utilize an intrusion detection system to expose a
breach as soon as it occurs; monitor all incoming traffic for activity indicating
hacking attempts; watch for large amounts of data being transmitted from the
system; and have a response plan ready in the event of a breach.
159. Upon information and belief, W&F failed to maintain many reasonable
and necessary industry standards necessary to prevent a data breach, including the
FTC’s guidelines. Upon information and belief, W&F also failed to meet the
minimum standards of any of the following frameworks: the NIST Cybersecurity
Framework, NIST Special Publications 800-53, 53A, or 800-171; the Federal Risk
and Authorization Management Program (FEDRAMP); or the Center for Internet
Security’s Critical Security Controls (CIS CSC), which are well respected
authorities in reasonable cybersecurity readiness.
160. As explained by the Federal Bureau of Investigation, “[p]revention is
the most effective defense against ransomware and it is critical to take precautions
for protection.”67

See How to Protect Your Networks from RANSOMWARE, at 3, available at
https://www.fbi.gov/file-repository/ransomware-prevention-and-response-forcisos.pdf/view. (last accessed Feb. 24, 2023) (attached hereto as Exhibit 55).
66

67


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1122 Filed 02/24/23 Page 67 of 125

161. To prevent and detect ransomware attacks, including the ransomware
attack that resulted in the Data Breach, W&F could and should have implemented,
as recommended by the Federal Bureau of Investigation, the following measures:
• Implement an awareness and training program. Because end users
are targets, employees and individuals should be aware of the threat
of ransomware and how it is delivered.
• Enable strong spam filters to prevent phishing emails from reaching
the end users and authenticate inbound email using technologies like
Sender Policy Framework (SPF), Domain Message Authentication
Reporting and Conformance (DMARC), and DomainKeys
Identified Mail (DKIM) to prevent email spoofing.
• Scan all incoming and outgoing emails to detect threats and filter
executable files from reaching end users.
• Configure firewalls to block access to known malicious IP
addresses.
• Patch operating systems, software, and firmware on devices.
Consider using a centralized patch management system.
• Set anti-virus and anti-malware programs to conduct regular scans
automatically.
• Manage the use of privileged accounts based on the principle of least
privilege: no users should be assigned administrative access unless
absolutely needed; and those with a need for administrator accounts
should only use them when necessary.
• Configure access controls—including file, directory, and network
share permissions—with least privilege in mind. If a user only needs
to read specific files, the user should not have write access to those
files, directories, or shares.

67


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1123 Filed 02/24/23 Page 68 of 125

• Disable macro scripts from office files transmitted via email.
Consider using Office Viewer software to open Microsoft Office
files transmitted via email instead of full office suite applications.
• Implement Software Restriction Policies (SRP) or other controls to
prevent programs from executing from common ransomware
locations, such as temporary folders supporting popular Internet
browsers or compression/decompression programs, including the
AppData/LocalAppData folder.
• Consider disabling Remote Desktop protocol (RDP) if it is not being
used.
• Use application whitelisting, which only allows systems to execute
programs known and permitted by security policy.
• Execute operating system environments or specific programs in a
virtualized environment.
• Categorize data based on organizational value and implement
physical and logical separation of networks and data for different
organizational units.68
162. The threat continues. In August 2022, the Consumer Finance Protection
Bureau (CFPB) published a circular on data security. The CFPB noted that
“[w]idespread data breaches and cyberattacks have resulted in significant harms to
consumers, including monetary loss, identity theft, significant time and money spent
dealing with the impacts of the breach, and other forms of financial distress,” and
the circular concluded that the provision of insufficient security for consumers’ data

68

Id. at 3-4.
68


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1124 Filed 02/24/23 Page 69 of 125

can violate the prohibition on “unfair acts or practices” in the Consumer Finance
Protection Act (CFPA).
163.

Further, to prevent and detect ransomware attacks, W&F could and

should have implemented, as recommended by the United States Cybersecurity &
Infrastructure Security Agency, the following measures:
• Update and patch your computer. Ensure your applications and
operating systems (OSs) have been updated with the latest patches.
Vulnerable applications and OSs are the target of most ransomware
attacks[.]
• Use caution with links and when entering website addresses. Be
careful when clicking directly on links in emails, even if the sender
appears to be someone you know. Attempt to independently verify
website addresses (e.g., contact your organization’s helpdesk,
search the internet for the sender organization’s website or the topic
mentioned in the email). Pay attention to the website addresses you
click on, as well as those you enter yourself. Malicious website
addresses often appear almost identical to legitimate sites, often
using a slight variation in spelling or a different domain (e.g., .com
instead of .net)[.]
• Open email attachments with caution. Be wary of opening email
attachments, even from senders you think you know, particularly
when attachments are compressed files or ZIP files.
• Keep your personal information safe. Check a website’s security
to ensure the information you submit is encrypted before you
provide it[.]
• Verify email senders. If you are unsure whether or not an email is
legitimate, try to verify the email’s legitimacy by contacting the
sender directly. Do not click on any links in the email. If possible,
use a previous (legitimate) email to ensure the contact information
you have for the sender is authentic before you contact them.
69


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1125 Filed 02/24/23 Page 70 of 125

• Inform yourself. Keep yourself informed about recent
cybersecurity threats and up to date on ransomware techniques. You
can find information about known phishing attacks on the AntiPhishing Working Group website. You may also want to sign up for
CISA product notifications, which will alert you when a new Alert,
Analysis Report, Bulletin, Current Activity, or Tip has been
published.
• Use and maintain preventative software programs. Install
antivirus software, firewalls, and email filters—and keep them
updated—to reduce malicious network traffic[.]69
164.

In addition, to prevent and detect ransomware attacks, W&F could and

should have implemented, as recommended by the Microsoft Threat Protection
Intelligence Team, the following measures:
• Secure internet-facing assets
-

Apply latest security updates
Use threat and vulnerability management
Perform regular audit; remove privileged credentials

• Thoroughly investigate and remediate alerts
-

Prioritize and treat commodity malware infections as
potential full compromise;

• Include IT Pros in security discussions
-

Ensure collaboration among [security operations],
[security admins], and [information technology] admins to
configure servers and other endpoints securely;

See Security Tip (ST19-001) Protecting Against Ransomware (original
release date Apr. 11, 2019), previously available at https://uscert.cisa.gov/ncas/tips/ST19-001.
70
69


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1126 Filed 02/24/23 Page 71 of 125

• Build credential hygiene
-

Use [multifactor authentication] or [network level
authentication] and use strong, randomized, just-in-time
local admin passwords
• Apply principle of least-privilege
-

Monitor for adversarial activities
Hunt for brute force attempts
Monitor for cleanup of Event Logs
Analyze logon events

• Harden infrastructure
-

165.

Use Windows Defender Firewall
Enable tamper protection
Enable cloud-delivered protection
Turn on attack surface reduction rules and [Antimalware
Scan Interface] for Office [Visual Basic for
Applications].70

Given that W&F was storing the Private Information of more than

800,000 individuals, W&F could and should have implemented all of the above
measures to prevent and detect ransomware attacks. These are basic, common-sense
email security measures that every business, not only healthcare businesses, should
be doing. W&F, with its heightened standard of care should be doing even more.

See Human-operated ransomware attacks: A preventable disaster (Mar 5,
2020), available at https://www.microsoft.com/security/blog/2020/03/05/humanoperated-ransomware-attacks-a-preventable-disaster/ (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 56).
70

71


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1127 Filed 02/24/23 Page 72 of 125

166. Specifically, among other failures, W&F had far too much confidential
unencrypted information held on its systems. Such Private Information should have
been segregated into an encrypted system. 71 Indeed, the United States Department
of Health and Human Services’ Office for Civil Rights urges the use of encryption
of data containing sensitive personal information, stating “[o]ur message to these
organizations is simple: encryption is your best defense against these incidents.” 72
167. Charged with handling sensitive Private Information, including
healthcare information, Defendant knew, or should have known, the importance of
safeguarding its patients’ Private Information that was entrusted to it and of the
foreseeable consequences if its data security systems were breached. This includes
the significant costs that would be imposed on its patients after a breach. W&F
failed, however, to take adequate cybersecurity measures to prevent the Data Breach
from occurring.
168. With respect to training, Defendant specifically failed to:
•

Implement a variety of anti-ransomware training tools, in
combination, such as computer-based training, classroom

See, e.g., Adnan Raja, How to Safeguard Your Business Data with Encryption,
Aug. 14, 2018, https://digitalguardian.com/blog/how-safeguard-your-business-dataencryption. (last accessed Feb. 24, 2023) (attached hereto as Exhibit 57).

71

“Stolen Laptops Lead to Important HIPAA Settlements,” U.S. Dep’t of Health
and Human Services (Apr. 22, 2014), available at https://wayback.archiveit.org/3926/20170127085330/https://www.hhs.gov/about/news/2014/04/22/stolenlaptops-lead-to-important-hipaa-settlements.html (last accessed Feb. 24, 2023)
(attached hereto as Exhibit 58).
72

72


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1128 Filed 02/24/23 Page 73 of 125

training, monthly newsletters, posters, login alerts, email
alerts, and team-based discussions;
•

Perform regular training at defined intervals such as biannual training and/or monthly security updates; and

•

Craft and tailor different approaches to different employees
based on their base knowledge about technology and
cybersecurity.

169. The Private Information was also maintained on W&F’s computer
system in a condition vulnerable to cyberattacks, such as through the infiltration of
Defendant’s systems through ransomware attacks. The mechanism of the
cyberattack and the potential for improper disclosure of Plaintiffs’ and Class
Members’ Private Information was a known risk to W&F, and thus W&F was on
notice that failing to take reasonable steps necessary to secure the Private
Information from those risks left it in a vulnerable position.
170. In sum, this Data Breach could have readily been prevented through the
use of industry standard network segmentation and encryption of all confidential
information.
171. Plaintiffs and Class Members entrusted their Private Information to
W&F as a condition of receiving healthcare related services. Plaintiffs and Class
Members understood and expected that W&F or anyone in W&F’s position would
safeguard their Private Information against cyberattacks, delete or destroy Private
73


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1129 Filed 02/24/23 Page 74 of 125

Information that W&F was no longer required to maintain, and timely and accurately
notify them if their Private Information was compromised.
K. The Monetary Value of Privacy Protections and Private Information
172. The fact that Plaintiffs’ and Class Members’ Private Information was
stolen means that Class Members’ information is likely for sale by cybercriminals
and will be misused in additional instances in the future. Indeed, there is already
evidence that Plaintiffs’ Private Information is on the dark web.
173. At all relevant times, Defendant was well aware that the Private
Information it collects from Plaintiffs and Class Members is highly sensitive and of
significant value to those who would use it for wrongful purposes.
174. As discussed above, Private Information is a valuable commodity to
identity thieves. As the FTC recognizes, identity thieves can use this information to
commit an array of crimes including identify theft, and medical and financial fraud.73
175. At an FTC public workshop in 2001, then-Commissioner Orson
Swindle described the value of a consumer’s personal information:
The use of third party information from public records,
information aggregators and even competitors for
marketing has become a major facilitator of our retail
economy. Even [Federal Reserve] Chairman [Alan]
Greenspan suggested here some time ago that it’s
See ECF No. 1-14, Federal Trade Commission, Warning Signs of Identity
Theft (Sept. 2018).

73

74


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1130 Filed 02/24/23 Page 75 of 125

something on the order of the life blood, the free flow of
information.74
176. Commissioner Swindle’s 2001 remarks are even more relevant today,
as consumers’ personal data functions as a “new form of currency” that supports a
$26 Billion per year online advertising industry in the United States. 75
177. The FTC has also recognized that consumer data is a new (and
valuable) form of currency. In an FTC roundtable presentation, another former
Commissioner, Pamela Jones Harbour, underscored this point:
Most consumers cannot begin to comprehend the types
and amount of information collected by businesses, or why
their information may be commercially valuable. Data is
currency. The larger the data set, the greater potential for
analysis—and profit.76
178. Recognizing the high value that consumers place on their Private
Information, many companies now offer consumers an opportunity to sell this
information. See ECF No. 1-16. The idea is to give consumers more power and
control over the type of information that they share and who ultimately receives that
See ECF No. 1-15, Public Workshop: The Information Marketplace: Merging
and Exchanging Consumer Data, FED. TRADE COMM’N Tr. at 8:2-8 (Mar. 13, 2001).

74

See ECF No. 1-16, Julia Angwin & Emily Steel, Web’s Hot New Commodity:
Privacy, The Wall Street Journal (Feb. 28, 2011).
76
See ECF No. 1-17, Statement of FTC Commissioner Pamela Jones Harbour—
Remarks Before FTC Exploring Privacy Roundtable, FED. TRADE COMM’N (Dec. 7,
2009).
75

75


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1131 Filed 02/24/23 Page 76 of 125

information. And, by making the transaction transparent, consumers will make a
profit from their Private Information. This business has created a new market for the
sale and purchase of this valuable data.
179. Consumers place a high value not only on their Private Information, but
also on the privacy of that data. Researchers have begun to shed light on how much
consumers value their data privacy, and the amount is considerable. Indeed, studies
confirm that the average direct financial loss for victims of identity theft in 2014 was
$1,349.77
180. As discussed above, the value of Plaintiffs’ and Class Members’ Private
Information on the black market is substantial.
181. Medical identity theft can result in inaccuracies in medical records and
costly false claims. It can also have life-threatening consequences. If a victim’s
health information is mixed with other records, it can lead to misdiagnosis or
mistreatment.
182. The ramifications of W&F’s failure to keep its patients’ Private
Information secure are long-lasting and severe. Once Private Information is stolen,
fraudulent use of that information and damage to victims may continue for years.

See ECF No. 1-18, U.S. Dep’t of Justice, Victims of Identity Theft, OFFICE OF
JUSTICE PROGRAMS: BUREAU OF JUSTICE STATISTICS 1 (Nov. 13, 2017).
77

76


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1132 Filed 02/24/23 Page 77 of 125

183. Victims may not realize their identity has been compromised until long
after it has happened. 78 This gives thieves ample time to seek multiple treatments
under the victim’s name. Forty percent of consumers found out they were a victim
of medical identity theft only when they received collection letters from creditors
for expenses that were incurred in their names.79
184. Breaches are particularly serious in healthcare industries, with
healthcare related data among the most private and personally consequential, as set
forth above.80
185. At all relevant times, Defendant was well-aware, or reasonably should
have been aware, that the Private Information it maintains is highly sensitive and
could be used for wrongful purposes by third parties, such as identity theft and fraud.
186. Had Defendant remedied the deficiencies in its security systems,
followed industry guidelines, and adopted security measures recommended by
experts in the field, Defendant would have prevented the ransomware attack into its
systems and, ultimately, the theft of its patients’ Private Information.

78

2012.

See ECF No. 1-21, Survey on Medical Identity Theft, Ponemon Institute, June

See ECF No. 1-22, The Potential Damages and Consequences of Medical
Identify Theft and Healthcare Data Breaches, EXPERIAN, (Apr. 2010).
79

80

See supra.
77


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1133 Filed 02/24/23 Page 78 of 125

187. Information about, or related to, an individual for which there is a
possibility of logical association with other information is of great value to hackers
and thieves. Indeed, “there is significant evidence demonstrating that technological
advances and the ability to combine disparate pieces of data can lead to identification
of a consumer, computer or device even if the individual pieces of data do not
constitute PII.” 81 For example, different PII and PHI elements from various sources
may be able to be linked in order to identify an individual, or access additional
information about or relating to the individual.82 Based upon information and belief,
the unauthorized parties utilized the Private Information they obtained through the
Data Breach to obtain additional information from Plaintiffs and Class Members that
was misused.
188. In addition, as technology advances, computer programs may scan the
Internet with wider scope to create a mosaic of information that may be used to link
information to an individual in ways that were not previously possible. This is known
as the “mosaic effect.”

See ECF No. 1-21, Protecting Consumer Privacy in an Era of Rapid Change:
A Proposed Framework for Businesses and Policymakers, Preliminary FTC Staff
Report, FED. TRADE COMM’N 35-38 (Dec. 2010).

81

See id. (evaluating privacy framework for entities collecting or using
consumer data with can be “reasonably linked to a specific consumer, computer, or
other device”).
78

82


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1134 Filed 02/24/23 Page 79 of 125

189. Names and dates of birth, combined with contact information like
telephone numbers and email addresses, are very valuable to hackers and identity
thieves as it allows them to access users’ other accounts. Thus, even if payment card
information was not involved in the Data Breach, the unauthorized parties could use
Plaintiffs’ and Class Members’ Private Information to access accounts, including,
but not limited to email accounts and financial accounts, to engage in the fraudulent
activity identified by Plaintiffs.
190. Given these facts, any healthcare or other type of entity that transacts
business with patients or customers and then compromises the privacy of its patients’
or customers’ Private Information has thus deprived them of the full monetary value
of the transaction with the entity.
191. Acknowledging the damage to Plaintiffs and Class Members,
Defendant instructed patients like Plaintiffs to “review the statements you receive
from your health insurer” and call the insurer “immediately” if fraudulent charges
appear. Plaintiffs and Class Members now face an impending, substantial risk of
identity theft and medical insurance fraud.
192. In short, the Private Information exposed is of great value to hackers
and cyber criminals and the data compromised in the Data Breach can be used in a
variety of unlawful manners, including opening new credit and financial accounts in
users’ names.
79


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1135 Filed 02/24/23 Page 80 of 125

L. The Data Breach’s Impact on Plaintiffs and Class Members
193. W&F received Plaintiffs’ PII/PHI in connection with providing certain
devices to them. In requesting and maintaining Plaintiffs’ PII/PHI for business
purposes, W&F expressly and impliedly promised, and undertook a duty, to act
reasonably in its handling of Plaintiffs’ PII/PHI. W&F, however, did not take proper
care of Plaintiffs’ PII/PHI, leading to its exposure to and exfiltration by
cybercriminals as a direct result of W&F inadequate data security measures.
194. On or around November 18, 2022, W&F sent Plaintiffs notice
concerning the Data Breach. The letter stated that W&F experienced a cybersecurity
attack and that the incident may have resulted in unauthorized access to Plaintiffs’
PII/PHI stored on W&F’s systems. The notice stated that the compromised
information that was present on the impacted files included one or more of the
following data elements: name, date of birth, patient number, social security number,
financial account number, and/or health insurance information. The notice further
encouraged Plaintiffs “to remain vigilant and consider taking steps to avoid identity
theft, obtain additional information, and protect your personal information.” W&F
also offered identity theft protection services through IDX, but only for a period of
one year.
195. W&F’s conduct, which allowed the Data Breach to occur, caused
Plaintiffs significant injuries and harm, including but not limited to, the following—
80


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1136 Filed 02/24/23 Page 81 of 125

Plaintiffs immediately devoted (and must continue to devote) time, energy, and
money to: closely monitoring their medical statements, bills, records, and credit and
financial accounts; changing login and password information on any sensitive
account even more frequently than they already do; more carefully screening and
scrutinizing phone calls, emails, and other communications to ensure that they are
not being targeted in a social engineering or spear phishing attack; searching for
suitable identity theft protection and credit monitoring services and paying for such
services to protect themselves; and placing fraud alerts and/or credit freezes on their
credit file. Plaintiffs have taken or will be forced to take these measures in order to
mitigate their potential damages as a result of the Breach.
196. Once PII or PHI is exposed, there is virtually no way to ensure that the
exposed information has been fully recovered or contained against future misuse.
For this reason, Plaintiffs will need to maintain these heightened measures for years,
and possibly their entire lives. Consumer victims of data breaches are more likely to
become victims of identity fraud.83
197. Plaintiffs greatly value their privacy, especially while receiving
medical services and/or devices. Plaintiffs and Class Members did not receive the
full benefit of their bargain when paying for medical services, and instead received

See ECF No. 1-31, 2014 LexisNexis True Cost of Fraud Study, LEXISNEXIS
(Aug. 2014).
81
83


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1137 Filed 02/24/23 Page 82 of 125

services that were of a diminished value to those described in their agreements with
their respective healthcare institutions that had made agreements with W&F for the
benefit and protection of Plaintiffs and Class Members and their respective Private
Information. Plaintiffs and Class Members were damaged in an amount at least equal
to the difference in the value between the services they thought they paid for (which
would have included adequate data security protection) and the services they
actually received.
198. They would not have obtained medical services and/or devices from
W&F, or paid the amount they did to receive such, had they known that W&F would
negligently fail to adequately protect their PII/PHI. Indeed, Plaintiffs paid W&F for
medical devices with the expectation that W&F would keep their PII/PHI secure and
inaccessible from unauthorized parties. Plaintiffs and Class Members would not
have obtained services from their medical providers had they known that Defendant
failed to properly train its employees, lacked safety controls over its computer
network, and did not have proper data security practices to safeguard their Private
Information from criminal theft and misuse.
199. Plaintiffs and Class Members have lost confidence in their medical
provider, W&F, as a result of the Data Breach.
200.

As a direct result of Defendant’s intentional, willful, reckless, and

negligent conduct which resulted in the Data Breach, unauthorized parties were able
82


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1138 Filed 02/24/23 Page 83 of 125

to access, acquire, view, publicize, and/or otherwise commit the identity theft and
misuse of Plaintiffs’ and Class members’ Private Information as detailed above, and
Plaintiffs and members of the Class are at a heightened and increased substantial risk
of suffering identity theft and fraud.
201. Plaintiffs are also at a continued risk of harm because their PII/PHI
remains in W&F systems, which have already been shown to be susceptible to
compromise and attack and are subject to further attack so long as W&F fails to
undertake the necessary and appropriate data security measures to protect the PII
and PHI in its possession.
202. As a result of the Data Breach, and in addition to the time Plaintiffs
have spent and anticipate spending to mitigate the impact of the Data Breach on their
lives, Plaintiffs have also suffered emotional distress from the public release of their
PII and PHI, which they believed would be protected from unauthorized access and
disclosure. The emotional distress they have experienced includes anxiety and stress
resulting from the unauthorized bad actors viewing, selling, and misusing their PII
and PHI for the purposes of identity theft and fraud.
203. Additionally, Plaintiffs have suffered damage to and diminution in the
value of their highly sensitive and confidential PII/PHI—a form of property that
Plaintiffs entrusted to W&F and which was compromised as a result of the Data

83


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1139 Filed 02/24/23 Page 84 of 125

Breach W&F failed to prevent. Plaintiffs have also suffered a violation of their
privacy rights as a result of W&F’s unauthorized disclosure of their PHI/PII.
204. The risks associated with identity theft are serious. While some identity
theft victims can resolve their problems quickly, others spend hundreds to thousands
of dollars and many days repairing damage to their good name and credit record.
Some consumers victimized by identity theft may lose out on job opportunities, or
be denied loans for education, housing or cars because of negative information on
their credit reports. In rare cases, they may even be arrested for crimes they did not
commit.
205. Some of the injuries and risks associated with the loss of Private
Information have already manifested themselves in Plaintiffs and other Class
Members’ lives. Each Class Member received a cryptically written notice letter from
Defendant stating that their Private Information was released, and that they should
remain vigilant for fraudulent activity, with no other explanation of where this
Private Information could have gone, or who might have access to it.
206. In addition to a remedy for the economic harm, Plaintiffs and Class
Members maintain an undeniable interest in ensuring that their Private Information
remains secure and is not subject to further misappropriation and theft.
M. Plaintiffs’ Experiences
Plaintiff Braggs
84


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1140 Filed 02/24/23 Page 85 of 125

207. Subsequent to the Data Breach, and in addition to the injuries alleged
above, Plaintiff Braggs also experienced actual identity theft and fraud, including a
credit card account that was applied for and opened in her name. Additionally,
Plaintiff Braggs has already been notified by IDX credit monitoring services that her
information compromised in the Data Breach is now being sold on the dark web.
208. Plaintiff Braggs spent approximately two days responding to these
incidents of identity theft and fraud, and continues to spend at least an hour a day
monitoring her accounts for additional fraudulent activity as a result of the Data
Breach. The time spent dealing with these incidents resulting from the Data Breach
is time Plaintiff Braggs otherwise would have spent on other activities, such as work
and/or recreation. Moreover, the time Plaintiff lost was spent at W&F’s direction.
Indeed, in the notice letter Plaintiff received, W&F directed Plaintiff to spend time
mitigating her losses by reviewing her accounts and credit reports for unauthorized
activity.
209. Plaintiff plans on taking additional time-consuming, necessary steps to
help mitigate the harm caused by the Data Breach, including continually reviewing
Plaintiff’s accounts for any unauthorized activity.
Plaintiff Hamilton
210. Subsequent to the Data Breach, and in addition to the injuries alleged
above, Plaintiff Hamilton also experienced actual identity theft and fraud, including
85


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1141 Filed 02/24/23 Page 86 of 125

an Amazon purchase that was made in his name using his credit card. Additionally,
on or around December 1, 2022, he experienced a hard inquiry on his credit report
through Wells Fargo that he did not sign up for. IDX and Experian credit monitoring
services have also notified him that his information compromised in the Data Breach
is now being sold on the dark web.
211. Plaintiff Hamilton has spent approximately three hours thus far
responding to these incidents of identity theft and fraud, or otherwise as a result of
the Data Breach. The time spent dealing with these incidents resulting from the Data
Breach is time Plaintiff Hamilton otherwise would have spent on other activities,
such as work and/or recreation. Moreover, the time Plaintiff lost was spent at W&F’s
direction. Indeed, in the notice letter Plaintiff received, W&F directed Plaintiff to
spend time mitigating his losses by reviewing his accounts and credit reports for
unauthorized activity.
212. Plaintiff plans on taking additional time-consuming, necessary steps to
help mitigate the harm caused by the Data Breach, including continually reviewing
Plaintiff’s accounts for any unauthorized activity.
Plaintiff Huff
213. Subsequent to the Data Breach, and in addition to the injuries alleged
above, Plaintiff Huff also experienced actual identity theft and fraud, including a
business banking account that was opened in her name, for which account she never
86


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1142 Filed 02/24/23 Page 87 of 125

applied for. Plaintiff has also experienced unauthorized charges in the amount of
roughly $450 through her Robinhood account, an unauthorized login attempt
through her cell phone, and was locked out of both her Robinhood and cell phone
accounts as a result.
214. Plaintiff Huff has spent in excess of two days responding to these
incidents of identity theft and fraud, or otherwise as a result of the Data Breach. The
time spent dealing with these incidents resulting from the Data Breach is time
Plaintiff Huff otherwise would have spent on other activities, such as work and/or
recreation. Moreover, the time Plaintiff lost was spent at W&F’s direction. Indeed,
in the notice letter Plaintiff received, W&F directed Plaintiff to spend time
mitigating her losses by reviewing her accounts and credit reports for unauthorized
activity.
215. Plaintiff plans on taking additional time-consuming, necessary steps to
help mitigate the harm caused by the Data Breach, including continually reviewing
Plaintiff’s accounts for any unauthorized activity.
Plaintiff Kolka
216. Subsequent to the Data Breach, and in addition to the injuries alleged
above, Plaintiff Kolka also experienced actual identity theft and fraud, including a
credit card that was opened in his name, negatively impacting his credit score and
resulting in the denial of a car loan for which he recently applied.
87


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1143 Filed 02/24/23 Page 88 of 125

217. Plaintiff Kolka has spent approximately three hours responding to this
incident of identity theft, or otherwise as a result of the Data Breach. The time spent
dealing with this incident resulting from the Data Breach is time Plaintiff Kolka
otherwise would have spent on other activities, such as work and/or recreation.
Moreover, the time Plaintiff lost was spent at W&F’s direction. Indeed, in the notice
letter Plaintiff received, W&F directed Plaintiff to spend time mitigating his losses
by reviewing his accounts and credit reports for unauthorized activity.
218. Plaintiff plans on taking additional time-consuming, necessary steps to
help mitigate the harm caused by the Data Breach, including continually reviewing
Plaintiff’s accounts for any unauthorized activity.
Plaintiff Mejia
219. Subsequent to the Data Breach, and in addition to the injuries alleged
above, Plaintiff Mejia has also experienced receipt of a substantial number of calls
that do not appear to have any proper purpose.
220. Plaintiff Mejia has spent approximately two hours, as of the filing of
this amended complaint, responding to fraudulent calls and otherwise working to
stay apprised of any fraudulent activity concerning his PII/PHI that may be taking
place as a result of the Data Breach. The time spent dealing with these incidents
resulting from the Data Breach is time Plaintiff Mejia otherwise would have spent
on other activities, such as work and/or recreation. Moreover, the time Plaintiff
88


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1144 Filed 02/24/23 Page 89 of 125

Mejia lost was spent at W&F’s direction. Indeed, in the notice letter Plaintiff Mejia
received, W&F directed him to spend time mitigating his losses by reviewing his
accounts and credit reports for unauthorized activity.
221. Plaintiff Mejia plans on taking additional time-consuming, necessary
steps to help mitigate the harm caused by the Data Breach, including continually
reviewing his accounts for any unauthorized activity.

89


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1145 Filed 02/24/23 Page 90 of 125

CLASS ACTION ALLEGATIONS
222. Plaintiffs bring this action on behalf of themselves and on behalf of all
other persons similarly situated (“the Class”).
223. Plaintiffs propose the following Class definitions, subject to
amendment as appropriate:
Nationwide Class
All individuals residing in the United States whose Private
Information was compromised as a result of the Data Breach,
including all individuals who were sent the Notice of Data
Privacy Incident on or around November 18, 2022.
In addition, or in the alternative, Plaintiffs propose the following state class:
Michigan Class
All individuals residing in Michigan whose Private Information
was compromised as a result of the Data Breach, including all
individuals in Michigan who were sent the Notice of Data
Privacy Incident on or around November 18, 2022.
224. Excluded from the Class are W&F’s officers and directors; any entity
in which W&F has a controlling interest; and the affiliates, legal representatives,
attorneys, successors, heirs, and assigns of W&F. Excluded also from the Class are
members of the judiciary to whom this case is assigned, their families and members
of their staff.
225. Plaintiffs reserve the right to amend or modify the Class or Class
definitions as this case progresses.
90


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1146 Filed 02/24/23 Page 91 of 125

226. Numerosity, Fed. R. Civ. P. 23(a)(1): The Members of the Class are
so numerous that joinder of all of them is impracticable. While the exact number of
Class Members is unknown to Plaintiffs at this time, based on information and belief,
the Class consists hundreds of thousands of individuals, including at least 800,000
individuals who were or are patients of W&F whose sensitive data was compromised
in Data Breach.
227. Commonality, Fed. R. Civ. P. 23(a)(2): There are questions of law and
fact common to the Class, which predominate over any questions affecting only
individual Class Members. These common questions of law and fact include,
without limitation:
a.

Whether W&F unlawfully used, maintained, lost, or disclosed
Plaintiffs’ and Class Members’ Private Information;

b.

Whether W&F failed to implement and maintain reasonable
security procedures and practices appropriate to the nature and
scope of the information compromised in the Data Breach;

c.

Whether W&F’s data security systems prior to and during the
Data Breach complied with applicable data security laws and
regulations including, e.g., HIPAA;

d.

Whether W&F’s data security systems prior to and during the
Data Breach were consistent with industry standards;

e.

Whether W&F owed a duty to Class Members to safeguard their
Private Information;

91


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1147 Filed 02/24/23 Page 92 of 125

f.

Whether W&F breached the duty to Class Members to safeguard
their Private Information;

g.

Whether W&F knew or should have known that its data security
systems and monitoring processes were deficient;

h.

Whether W&F should have discovered the Data Breach sooner;

i.

Whether Plaintiffs and Class Members suffered legally
cognizable damages as a result of W&F’s misconduct;

j.

Whether W&F’s conduct was negligent;

k.

Whether W&F breached implied contracts with Plaintiffs and
Class Members;

l.

Whether W&F were unjustly enriched by unlawfully retaining a
benefit conferred upon them by Plaintiffs and Class Members;

m.

Whether W&F failed to provide notice of the Data Breach in a
timely manner, and;

n.

Whether Plaintiffs and Class Members are entitled to damages,
civil penalties, punitive damages, treble damages, and/or
injunctive relief.

228. Typicality, Fed. R. Civ. P. 23(a)(3): Plaintiffs’ claims are typical of
those of other Class Members because Plaintiffs’ information, like that of every
other Class Member, was compromised in the Data Breach.

92


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1148 Filed 02/24/23 Page 93 of 125

229. Adequacy, Fed. R. Civ. P. 23(a)(4): Plaintiffs will fairly and
adequately represent and protect the interests of the Members of the Class. Plaintiffs’
Counsel are competent and experienced in litigating class actions.
230. Predominance, Fed. R. Civ. P. 23(b)(3): W&F has engaged in a
common course of conduct toward Plaintiffs and Class Members, in that all the
Plaintiffs’ and Class Members’ data was stored on the same computer system and
unlawfully accessed in the same way. The common issues arising from W&F’s
conduct affecting Class Members set out above predominate over any individualized
issues. Adjudication of these common issues in a single action has important and
desirable advantages of judicial economy.
231. Superiority, Fed. R. Civ. P. 23(b)(3): A class action is superior to
other available methods for the fair and efficient adjudication of the controversy.
Class treatment of common questions of law and fact is superior to multiple
individual actions or piecemeal litigation. Absent a class action, most Class
Members would likely find that the cost of litigating their individual claims is
prohibitively high and would therefore have no effective remedy. The prosecution
of separate actions by individual Class Members would create a risk of inconsistent
or varying adjudications with respect to individual Class Members, which would
establish incompatible standards of conduct for W&F. In contrast, the conduct of
this action as a Class action presents far fewer management difficulties, conserves
93


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1149 Filed 02/24/23 Page 94 of 125

judicial resources and the parties’ resources, and protects the rights of each Class
Member.
232. W&F has acted on grounds that apply generally to the Class as a whole,
so that Class certification, injunctive relief, and corresponding declaratory relief are
appropriate on a Class-wide basis.
233. Likewise, particular issues are appropriate for certification because
such claims present only particular, common issues, the resolution of which would
advance the disposition of this matter and the parties’ interests therein. Such
particular issues include, but are not limited to:
a. Whether W&F failed to timely and adequately notify the public of
the Data Breach;
b. Whether W&F owed a legal duty to Plaintiffs and the Class to
exercise due care in collecting, storing, and safeguarding their
Private Information;
c. Whether W&F’s security measures to protect its data systems were
reasonable in light of best practices recommended by data security
experts;
d. Whether W&F’s failure to institute adequate protective security
measures amounted to negligence;

94


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1150 Filed 02/24/23 Page 95 of 125

e. Whether W&F failed to take commercially reasonable steps to
safeguard consumer Private Information; and
f. Whether adherence to FTC data security recommendations, and
measures recommended by data security experts would have
reasonably prevented the Data Breach.
234. Finally, all members of the proposed Class are readily ascertainable.
W&F has access to Class Members’ names and addresses affected by the Data
Breach. Class Members have already been preliminarily identified and sent notice
of the Data Breach by W&F.
CAUSES OF ACTION
FIRST COUNT
Negligence
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
235. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
236. W&F required customers, including Plaintiffs and Class Members, to
submit non-public Private Information in the ordinary course of healthcare services.
237. By collecting and storing this data in its computer system and network,
and sharing it and using it for commercial gain, W&F owed a duty of care to use
reasonable means to secure and safeguard its computer system—and Class
Members’ Private Information held within it—to prevent disclosure of the
95


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1151 Filed 02/24/23 Page 96 of 125

information, and to safeguard the information from theft. W&F’s duty included a
responsibility to implement processes by which it could detect a breach of its
security systems in a reasonably expeditious period of time and to give prompt notice
to those affected in the case of a data breach.
238. W&F owed a duty of care to Plaintiffs and Class Members to provide
data security consistent with industry standards and other requirements discussed
herein, and to ensure that its systems and networks, and the personnel responsible
for them, adequately protected the Private Information.
239. Plaintiffs and the Class are a well-defined, foreseeable, and probable
group of patients that W&F was aware, or should have been aware, could be injured
by inadequate data security measures.
240. W&F owed numerous duties to Plaintiffs and the Class, including the
following:
• to exercise reasonable care in obtaining, retaining, securing,
safeguarding, deleting and protecting Private Information in its
possession;
• to protect Private Information using reasonable and adequate security
procedures and systems that are compliant with industry-standard
practices; and
• to implement processes to quickly detect a data breach and to timely act
on warnings about data breaches.

96


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1152 Filed 02/24/23 Page 97 of 125

241. A large depository of highly valuable health care information is a
foreseeable target for cybercriminals looking to steal and profit from that sensitive
information. W&F knew or should have known that, given its repository of a host of
Private Information for hundreds of thousands of patients posed a significant risk of
being targeted for a data breach. Thus, W&F had a duty to reasonably safeguard its
patients’ data by implementing reasonable data security measures to protect against
data breaches. The foreseeable harm to Plaintiffs and the Class of inadequate data
security created a duty to act reasonably and safeguard the Private Information.
242. W&F’s duty of care to use reasonable security measures also arose as
a result of the special relationship that existed between W&F and patients, which is
recognized by laws and regulations including but not limited to HIPAA, as well as
common law. W&F was in a superior position to ensure that their systems were
sufficient to protect against the foreseeable risk of harm to Class Members from a
data breach.
243. W&F’s duty to use reasonable security measures under HIPAA
required W&F to “reasonably protect” confidential data from “any intentional or
unintentional use or disclosure” and to “have in place appropriate administrative,
technical, and physical safeguards to protect the privacy of protected health
information.” 45 C.F.R. § 164.530(c)(1). Some or all of the medical information at

97


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1153 Filed 02/24/23 Page 98 of 125

issue in this case constitutes “protected health information” within the meaning of
HIPAA.
244. In addition, W&F has a duty to employ reasonable security measures
under Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, which
prohibits “unfair . . . practices in or affecting commerce,” including, as interpreted
and enforced by the FTC, the unfair practice of failing to use reasonable measures
to protect confidential data.
245. W&F’s duty to use reasonable care in protecting confidential data arose
not only as a result of the statutes and regulations described above, but also because
W&F is bound by industry standards to protect confidential Private Information.
246. W&F breached its duties, and thus was negligent, by failing to use
reasonable measures to protect Class Members’ Private Information. The specific
negligent acts and omissions committed by W&F includes, but is not limited to, the
following:
a. Failing to adopt, implement, and maintain adequate security
measures to safeguard Class Members’ Private Information;
b. Failing to adequately monitor the security of their networks and
systems;
c. Failing to ensure that their email system had plans in place to
maintain reasonable data security safeguards;
98


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1154 Filed 02/24/23 Page 99 of 125

d. Failing to have in place mitigation policies and procedures;
e. Allowing unauthorized access to Class Members’ Private
Information;
f.

Failing to detect in a timely manner that Class Members’ Private
Information had been compromised; and

g.

Failing to timely notify Class Members about the Data Breach so
that they could take appropriate steps to mitigate the potential for
identity theft and other damages.

247. It was foreseeable that W&F’s failure to use reasonable measures to
protect Class Members’ Private Information would result in injury to Class
Members. Furthermore, the breach of security was reasonably foreseeable given the
known high frequency of cyberattacks and data breaches in the healthcare industry.
248. W&F’s conduct was grossly negligent and departed from reasonable
standards of care, including but not limited to, failing to adequately protect the
Private Information and failing to provide Plaintiffs and Class Members with timely
notice that their sensitive Private Information had been compromised.
249. Neither Plaintiffs nor Class Members contributed to the Data Breach
and subsequent misuse of their Private Information as described in this Complaint.
250. As a direct and proximate result of Defendant’s conduct, Plaintiffs and
Class Members suffered damages as alleged above.
99


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1155 Filed 02/24/23 Page 100 of 125

251. Plaintiffs and Class Members are entitled to compensatory and
consequential damages suffered as a result of the Data Breach.
252. Plaintiffs and Class Members are also entitled to injunctive relief
requiring W&F to, e.g., (i) strengthen their data security systems and monitoring
procedures; (ii) submit to future annual audits of those systems and monitoring
procedures; and (iii) continue to provide adequate credit monitoring to all Class
Members.
SECOND COUNT
Negligence Per Se
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
253. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
254. Pursuant to the Federal Trade Commission Act, 15 U.S.C. § 45, W&F
has a duty to provide fair and adequate computer systems and data security practices
to safeguard Plaintiffs’ and Class Members’ Private Information.
255. Pursuant to HIPAA, 42 U.S.C. § 1302d, et seq., W&F had a duty to
implement reasonable safeguards to protect Plaintiffs’ and Class Members’ Private
Information.
256. Pursuant to HIPAA, W&F had a duty to render the electronic PHI it
maintained unusable, unreadable, or indecipherable to unauthorized individuals, as
specified in the HIPAA Security Rule by “the use of an algorithmic process to
100


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1156 Filed 02/24/23 Page 101 of 125

transform data into a form in which there is a low probability of assigning meaning
without use of a confidential process or key.” See definition of encryption at 45
C.F.R. § 164.304.
257. W&F breached its duties to Plaintiffs and Class Members under the
Federal Trade Commission Act and HIPAA by failing to provide fair, reasonable, or
adequate computer systems and data security practices to safeguard Plaintiffs’ and
Class Members’ Private Information.
258. W&F’s failure to comply with applicable laws and regulations
constitutes negligence per se.
259. But for W&F’s wrongful and negligent breach of its duties owed to
Plaintiffs and Class Members, Plaintiffs and Class Members would not have been
injured.
260. The injury and harm suffered by Plaintiffs and Class Members was the
reasonably foreseeable result of W&F’s breach of its duties. W&F knew or should
have known that it was failing to meet its duties, and that W&F’s breach would cause
Plaintiffs and Class Members to experience the foreseeable harms associated with
the exposure of their Private Information.
261. As a direct and proximate result of W&F’s negligent conduct, Plaintiffs
and Class Members have suffered injury and are entitled to compensatory,
consequential, and punitive damages in an amount to be proven at trial.
101


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1157 Filed 02/24/23 Page 102 of 125

THIRD COUNT
Breach of Implied Contract
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
262. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
263. Plaintiffs and the Class Members entered into implied contracts with
W&F under which W&F agreed to safeguard and protect such information and to
timely and accurately notify Plaintiffs and Class Members that their information had
been breached and compromised.
264. Plaintiffs and the Class were required to and delivered their Private
Information to W&F as part of the process of obtaining services provided by W&F.
Plaintiffs and Class Members paid money, or money was paid on their behalf, to
W&F in exchange for services.
265. W&F solicited, offered, and invited Class Members to provide their
Private Information as part of W&F’s regular business practices. Plaintiffs and Class
Members accepted W&F’s offers and provided their Private Information to W&F.
266. W&F accepted possession of Plaintiffs’ and Class Members’ Private
Information for the purpose of providing services or Plaintiffs and Class Members.
267. In accepting such information and payment for services, Plaintiffs and
the other Class Members entered into an implied contract with W&F whereby W&F
102


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1158 Filed 02/24/23 Page 103 of 125

became obligated to reasonably safeguard Plaintiffs’ and the other Class Members’
Private Information.
268. In delivering their Private Information to W&F and paying for
healthcare services, Plaintiffs and Class Members intended and understood that
W&F would adequately safeguard the data as part of that service.
269. Upon information and belief, in its written policies, W&F expressly and
impliedly promised to Plaintiffs and Class Members that they would only disclose
protected information and other Private Information under certain circumstances,
none of which related to a Data Breach as occurred in this matter.
270. The implied promise of confidentiality includes consideration beyond
those pre-existing general duties owed under HIPAA or other state of federal
regulations. The additional consideration included implied promises to take adequate
steps to comply with specific industry data security standards and FTC guidelines
on data security.
271. The implied promises include but are not limited to: (1) taking steps to
ensure that any agents who are granted access to Private Information also protect the
confidentiality of that data; (2) taking steps to ensure that the information that is
placed in the control of its agents is restricted and limited to achieve an authorized
medical purpose; (3) restricting access to qualified and trained agents; (4) designing
and implementing appropriate retention policies to protect the information against
103


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1159 Filed 02/24/23 Page 104 of 125

criminal data breaches; (5) applying or requiring proper encryption; (6)
implementing multifactor authentication for access; and (7) taking other steps to
protect against foreseeable data breaches.
272. Plaintiffs and the Class Members would not have entrusted their Private
Information to W&F in the absence of such an implied contract.
273. Had W&F disclosed to Plaintiffs and the Class that they did not have
adequate computer systems and security practices to secure sensitive data, Plaintiffs
and the other Class Members would not have provided their Sensitive Information
to W&F.
274. W&F recognized that Plaintiffs’ and Class Member’s Private
Information is highly sensitive and must be protected, and that this protection was
of material importance as part of the bargain to Plaintiffs and the other Class
Members.
275. Plaintiffs and the other Class Members fully performed their
obligations under the implied contracts with W&F.
276. W&F breached the implied contract with Plaintiffs and the other Class
Members by failing to take reasonable measures to safeguard their Private
Information as described herein.

104


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1160 Filed 02/24/23 Page 105 of 125

277. As a direct and proximate result of W&F’s conduct, Plaintiffs and the
other Class Members suffered and will continue to suffer damages in an amount to
be proven at trial.
FOURTH COUNT
Unjust Enrichment
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
278. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
279. This count is pleaded in the alternative to Count 3 (breach of implied
contract).
280. Upon information and belief, W&F funds its data security measures
entirely from its general revenue, including payments made by or on behalf of
Plaintiffs and the Class Members.
281. As such, a portion of the payments made by or on behalf of Plaintiffs
and the Class Members is to be used to provide a reasonable level of data security,
and the amount of the portion of each payment made that is allocated to data security
is known to W&F.
282. Plaintiffs and Class Members conferred a monetary benefit on W&F.
Specifically, they purchased goods and services from W&F and/or its agents and in
so doing provided W&F with their Private Information. In exchange, Plaintiffs and
Class Members should have received from W&F the goods and services that were
105


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1161 Filed 02/24/23 Page 106 of 125

the subject of the transaction and have their Private Information protected with
adequate data security.
283. W&F knew that Plaintiffs and Class Members conferred a benefit
which W&F accepted. W&F profited from these transactions and used the Private
Information of Plaintiffs and Class Members for business purposes.
284. Plaintiffs and Class Members conferred a monetary benefit on W&F,
by paying W&F as part of rendering medical services, a portion of which was to
have been used for data security measures to secure Plaintiffs’ and Class Members’
Personal Information, and by providing W&F with their valuable Personal
Information.
285. W&F was enriched by saving the costs it reasonably should have
expended on data security measures to secure Plaintiffs’ and Class Members’
Personal Information. Instead of providing a reasonable level of security that would
have prevented the Data Breach, W&F instead calculated to avoid its data security
obligations at the expense of Plaintiffs and Class Members by utilizing cheaper,
ineffective security measures. Plaintiffs and Class Members, on the other hand,
suffered as a direct and proximate result of W&F’s failure to provide the requisite
security.
286. Under the principles of equity and good conscience, W&F should not
be permitted to retain the money belonging to Plaintiffs and Class Members, because
106


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1162 Filed 02/24/23 Page 107 of 125

W&F failed to implement appropriate data management and security measures that
are mandated by industry standards.
287. W&F acquired the monetary benefit and Personal Information through
inequitable means in that it failed to disclose the inadequate security practices
previously alleged.
288. If Plaintiffs and Class Members knew that W&F had not secured their
Personal Information, they would not have agreed to provide their Personal
Information to W&F.
289. Plaintiffs and Class Members have no adequate remedy at law.
290. As a direct and proximate result of W&F’s conduct, Plaintiffs and Class
Members have suffered and will suffer injury, including but not limited to: (i) actual
identity theft; (ii) the loss of the opportunity to control how their PII is used; (iii) the
compromise, publication, and/or theft of their Personal Information; (iv) out-ofpocket expenses associated with the prevention, detection, and recovery from
identity theft, and/or unauthorized use of their Private Information; (v) lost
opportunity costs associated with effort expended and the loss of productivity
addressing and attempting to mitigate the actual and future consequences of the Data
Breach, including but not limited to efforts spent researching how to prevent, detect,
contest, and recover from identity theft; (vi) the continued risk to their Private
Information, which remains in W&F’s possession and is subject to further
107


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1163 Filed 02/24/23 Page 108 of 125

unauthorized disclosures so long as W&F fail to undertake appropriate and adequate
measures to protect Private Information in their continued possession; and (vii)
future costs in terms of time, effort, and money that will be expended to prevent,
detect, contest, and repair the impact of the Private Information compromised as a
result of the Data Breach for the remainder of the lives of Plaintiffs and Class
Members.
291. As a direct and proximate result of W&F’s conduct, Plaintiffs and Class
Members have suffered and will continue to suffer other forms of injury and/or harm.
292. W&F should be compelled to disgorge into a common fund or
constructive trust, for the benefit of Plaintiffs and Class Members, proceeds that they
unjustly received from them. In the alternative, W&F should be compelled to refund
the amounts that Plaintiffs and Class Members overpaid for W&F’s services.
FIFTH COUNT
Breach of Fiduciary Duty
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
293. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
294. In light of the special relationship between W&F and Plaintiffs and
Class Members, W&F became a fiduciary by undertaking a guardianship of the
Private Information to act primarily for Plaintiffs and Class Members, (1) for the
safeguarding of Plaintiffs’ and Class Members’ Private Information; (2) to timely
108


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1164 Filed 02/24/23 Page 109 of 125

notify Plaintiffs and Class Members of a Data Breach and disclosure; and (3) to
maintain complete and accurate records of what information (and where) W&F do
store.
295. W&F had a fiduciary duty to act for the benefit of Plaintiffs and Class
Members upon matters within the scope of its relationship with its patients, in
particular, to keep secure their Private Information.
296. W&F breached its fiduciary duty to Plaintiffs and Class Members by
failing to diligently discovery, investigate, and give notice of the Data Breach in a
reasonable and practicable period.
297. W&F breached its fiduciary duty to Plaintiffs and Class Members by
failing to encrypt and otherwise protect the integrity of the systems containing
Plaintiffs’ and Class Members’ Private Information.
298. W&F breached its fiduciary duty owed to Plaintiffs and Class Members
by failing to timely notify and/or warn Plaintiffs and Class Members of the Data
Breach.
299. W&F breached its fiduciary duty to Plaintiffs and Class Members by
otherwise failing to safeguard Plaintiffs’ and Class Members’ Private Information.
300. As a direct and proximate result of W&F’s breach of its fiduciary duty,
Plaintiffs and Class Members have suffered and will suffer injury, including but not
limited to: (i) actual identity theft; (ii) the compromise, publication, and/or theft of
109


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1165 Filed 02/24/23 Page 110 of 125

their Private Information; (iii) out-of-pocket expenses associated with the
prevention, detection, and recovery from identity theft and/or unauthorized use of
their Private Information; (iv) lost opportunity costs associated with effort expended
and the loss of productivity addressing and attempting to mitigate the actual and
future consequences of the Data Breach, including but not limited to efforts spent
researching how to prevent, detect, contest, and recover from identity theft; (v) the
continued risk to their Private Information, which remains in W&F’s possession and
is subject to further unauthorized disclosures so long as W&F fail to undertake
appropriate and adequate measures to protect the Private Information in their
continued possession; (vi) future costs in terms of time, effort, and money that will
be expended as result of the Data Breach for the remainder of the lives of Plaintiffs
and Class Members; and (vii) the diminished value of W&F’s services they received.
301. As a direct and proximate result of W&F’s breach of its fiduciary duty,
Plaintiffs and Class Members have suffered and will continue to suffer other forms
of injury and/or harm, and other economic and non-economic losses.
SIXTH COUNT
VIOLATIONS OF MICHIGAN’S DATA BREACH
PROMPT NOTIFICATION LAW
(MICH. COMP. LAWS ANN. § 445.72(1), et seq.)
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
302. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
110


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1166 Filed 02/24/23 Page 111 of 125

303. Defendant is required to accurately and notify Plaintiffs and Class
Members if it discovers a security breach, or receives notice of a security breach
(where unencrypted and unredacted Personal Information was accessed or acquired
by unauthorized persons), without unreasonable delay under Mich. Comp. Laws
Ann. § 445.72(1).
304. Defendant is a business that owns or licenses computerized data that
includes personal information as defined by Mich. Comp. Laws Ann. § 445.72(1).
305. Plaintiffs and Class Members’ personal information (e.g., Social
Security numbers) includes personal information as covered under Mich. Comp.
Laws Ann. § 445.72(1).
306. Because Defendant discovered a security breach and had notice of a
security breach (where unencrypted and unredacted personal information was
accessed or acquired by unauthorized persons), Defendant had an obligation to
disclose such in a timely and accurate fashion as mandated by Mich. Comp. Laws
Ann. § 445.72(4).
307. Defendant has stated it was aware of the Data Breach in January 2022.
Defendant has also stated that it only became aware that the Data Breach
compromised protected PII and PHI in May 2022. However, Defendant did not
notify Plaintiffs and the Class until November 2022, approximately ten months

111


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1167 Filed 02/24/23 Page 112 of 125

after it first learned of the Data Breach, and six months after its investigation had
confirmed that the Private Information was compromised.
308. As a direct and proximate result of Defendant’s violations of Mich.
Comp. Laws Ann. § 445.72(4), Plaintiffs and Class Members suffered damages as
set forth herein.
309. Plaintiffs and Class Members seek relief under Mich. Comp. Laws
Ann. § 445.72(13), including, but not limited to, a civil fine of up to $250 for each
violation.
COUNT SEVEN
BREACH OF CONFIDENCE
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
310. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
311. Plaintiffs and Class Members have an interest, both equitable and legal,
in the Private Information that was conveyed to, collected by, and maintained by
Defendant and that was ultimately accessed or compromised in the Data Breach.
312. As a healthcare provider, Defendant has a special relationship to its
patients, like Plaintiffs and the Class Members.
313. Because of that special relationship, Defendant was provided with and
stored private and valuable PII and PHI belonging to Plaintiffs and the Class, which
it was required to maintain in confidence.
112


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1168 Filed 02/24/23 Page 113 of 125

314. Plaintiffs and the Class provided Defendant with their Private
Information under both the express and/or implied agreement of Defendant to limit
the use and disclosure of such Private Information.
315. Defendant had a common law duty to maintain the confidentiality of
Plaintiffs’ and Class Members’ Private Information.
316. Defendant owed a duty to Plaintiffs and Class Members to exercise the
utmost care in obtaining, retaining, securing, safeguarding, deleting, and protecting
their Private Information in its possession from being compromised, lost, stolen,
accessed by, misused by, or disclosed to unauthorized persons.
317. Plaintiffs and Class Members have a privacy interest in their personal
and medical matters, and Defendant had a duty not to disclose confidential personal
and medical information and records concerning its patients.
318. As a result of the parties’ relationship of trust, Defendant had
possession and knowledge of the confidential Private Information of Plaintiffs and
Class Members.
319. Plaintiffs’ and the Class’s Private Information is not generally known
to the public and is confidential by nature.
320. Plaintiffs and Class Members did not consent to nor authorize
Defendant to release or disclose their Private Information to an unknown criminal
actor.
113


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1169 Filed 02/24/23 Page 114 of 125

321. Defendant breached the duty of confidence it owed to Plaintiffs and
Class Members when Plaintiffs’ and Class’s Private Information was disclosed to
unknown criminal hackers by way of Defendant’s own acts and omissions, as
alleged herein.
322. Defendant breached its duties of confidence by failing to safeguard
Plaintiffs’ and Class Members’ Private Information, including by, among other
things: (a) mismanaging its system and failing to identify reasonably foreseeable
internal and external risks to the security, confidentiality, and integrity of customer
information that resulted in the unauthorized access and compromise of the Private
Information; (b) mishandling its data security by failing to assess the sufficiency of
its safeguards in place to control these risks; (c) failing to design and implement
information safeguards to control these risks; (d) failing to adequately test and
monitor the effectiveness of the safeguards’ key controls, systems, and procedures;
(e) failing to evaluate and adjust its information security program in light of the
circumstances alleged herein; (f) failing to detect the Breach at the time it began or
within a reasonable time thereafter; (g) failing to follow its own privacy policies and
practices published to its patients; (h) storing PII, PHI and medical
records/information in an unencrypted and vulnerable manner, allowing its
disclosure to hackers; and (i) making an unauthorized and unjustified disclosure and

114


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1170 Filed 02/24/23 Page 115 of 125

release of Plaintiffs’ and the Class Members’ Private Information to a criminal third
party.
323. But for Defendant’s wrongful breach of its duty of confidences owed
to Plaintiffs and Class Members, their privacy, confidences, and Private Information
would not have been compromised.
324. As a direct and proximate result of Defendant’s breach of Plaintiffs’
and the Class’s confidences, Plaintiffs and Class Members have suffered or will
suffer injuries, including: the erosion of the essential and confidential relationship
between Defendant—as a health care services provider—and Plaintiffs and Class
Members as patients; loss of their privacy and confidentiality in their Private
Information; theft of their Private Information; costs associated with the detection
and prevention of identity theft and unauthorized use of the financial accounts; costs
associated with purchasing credit monitoring and identity theft protection services;
lowered credit scores resulting from credit inquiries following fraudulent activities;
costs associated with time spent and the loss of productivity from taking time to
address and attempt to ameliorate, mitigate, and deal with the actual and future
consequences of the Defendant’s Data Breach – including finding fraudulent
charges, cancelling and reissuing cards, enrolling in credit monitoring and identity
theft protection services, freezing and unfreezing accounts, and imposing
withdrawal and purchase limits on compromised accounts; the imminent and
115


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1171 Filed 02/24/23 Page 116 of 125

certainly impending injury flowing from the increased risk of potential fraud and
identity theft posed by their Private Information being placed in the hands of
criminals; damages to and diminution in value of their Private Information entrusted,
directly or indirectly, to Defendant with the mutual understanding that Defendant
would safeguard Plaintiffs’ and Class Members’ data against theft and not allow
access and misuse of their data by others; continued risk of exposure to hackers and
thieves of their Private Information, which remains in Defendant’s possession and
is subject to further breaches so long as Defendant fails to undertake appropriate and
adequate measures to protect Plaintiffs’ and Class Members’ data; loss of personal
time spent carefully reviewing statements from health insurers and providers to
check for charges for services not received, as directed to do by Defendant; and/or
mental anguish accompanying the loss of confidences and disclosure of their
confidential Private Information.
325. Additionally, Defendant received payments from Plaintiffs and Class
Members for services with the understanding that Defendant would uphold its
responsibilities to maintain the confidences of Plaintiffs’ and Class Members’
Private Information.
326. Defendant breached the confidence of Plaintiffs and Class Members
when it made an unauthorized release and disclosure of their confidential Private

116


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1172 Filed 02/24/23 Page 117 of 125

Information and, accordingly, it would be inequitable for Defendant to retain the
benefit at Plaintiffs’ and Class Members’ expense.
327. As a direct and proximate result of Defendant’s breach of confidences,
Plaintiffs and Class Members are entitled to damages, including compensatory,
punitive, and/or nominal damages, and/or disgorgement or restitution, in an amount
to be proven at trial.
COUNT EIGHT
DECLARATORY RELIEF
(On Behalf of Plaintiffs and the Nationwide Class or, Alternatively, the
Michigan Class)
328. Plaintiffs re-allege and incorporate by reference all other paragraphs in
the Complaint as if fully set forth herein.
329. Under the Declaratory Judgment Act, 28 U.S.C. §§ 2201, et seq., this
Court is authorized to enter a judgment declaring the rights and legal relations of the
parties and granting further necessary relief. Furthermore, the Court has broad
authority to restrain acts, such as here, that are tortious and violate the terms of the
federal statutes described in this Complaint.
330. An actual controversy has arisen in the wake of the Data Breach
regarding Defendant’s present and prospective common law and other duties to
reasonably safeguard Plaintiffs’ and Class Members’ Private Information, and
whether Defendant is currently maintaining data security measures adequate to
protect Plaintiffs and Class Members from future data breaches that compromise
117


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1173 Filed 02/24/23 Page 118 of 125

their Private Information. Plaintiffs and the Class remain at imminent risk that
additional compromises of their Private Information will occur in the future.
331. The Court should also issue prospective injunctive relief requiring
Defendant to employ adequate security practices consistent with law and industry
standards to protect consumers’ PII and PHI.
332. Defendant still possesses the Private Information of Plaintiffs and the
Class.
333. Defendant has made no announcement that it has changed its data
storage or security practices relating to the storage of Plaintiffs’ and Class Members’
Private Information.
334. To Plaintiffs’ knowledge, Defendant has made no announcement or
notification that it has remedied the vulnerabilities and negligent data security
practices that led to the Data Breach.
335. If an injunction is not issued, Plaintiffs and the Class will suffer
irreparable injury and lack an adequate legal remedy in the event of another data
breach at W&F. The risk of another such breach is real, immediate, and substantial.
336. The hardship to Plaintiffs and Class Members if an injunction does not
issue exceeds the hardship to Defendant if an injunction is issued. Among other
things, if another data breach occurs at W&F, Plaintiffs and Class Members will
likely continue to be subjected to a heightened, substantial, imminent risk of fraud,
118


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1174 Filed 02/24/23 Page 119 of 125

identify theft, and other harms described herein. On the other hand, the cost to
Defendant of complying with an injunction by employing reasonable prospective
data security measures is relatively minimal, and Defendant has a pre-existing legal
obligation to employ such measures.
337. Issuance of the requested injunction will not disserve the public interest.
To the contrary, such an injunction would benefit the public by preventing another
data breach at W&F, thus eliminating the additional injuries that would result to
Plaintiffs and Class Members, along with other consumers whose Private
Information would be further compromised.
338. Pursuant to its authority under the Declaratory Judgment Act, this Court
should enter a judgment declaring that W&F implement and maintain reasonable
security measures, including but not limited to the following:
a. Engaging third-party security auditors/penetration testers, as well as
internal security personnel, to conduct testing that includes simulated
attacks, penetration tests, and audits on W&F’s systems on a periodic
basis, and ordering W&F to promptly correct any problems or issues
detected by such third-party security auditors;
b. engaging third-party security auditors and internal personnel to run
automated security monitoring;

119


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1175 Filed 02/24/23 Page 120 of 125

c. auditing, testing, and training its security personnel regarding any new
or modified procedures;
d. purging, deleting, and destroying Private Information not necessary for
its provisions of services in a reasonably secure manner;
e. conducting regular database scans and security checks; and
f. routinely and continually conducting internal training and education to
inform internal security personnel how to identify and contain a breach
when it occurs and what to do in response to a breach.
PRAYER FOR RELIEF
WHEREFORE, Plaintiffs pray for judgment as follows:
a) For an Order certifying this action as a Class action and appointing
Plaintiffs as Class Representative and their counsel as Class Counsel;
b) For equitable relief enjoining W&F from engaging in the wrongful
conduct complained of herein pertaining to the misuse and/or
disclosure of Plaintiffs’ and Class Members’ Private Information, and
from refusing to issue prompt, complete and accurate disclosures to
Plaintiffs and Class Members;
c) For equitable relief compelling W&F to utilize appropriate methods
and policies with respect to consumer data collection, storage, and

120


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1176 Filed 02/24/23 Page 121 of 125

safety, and to disclose with specificity the type of Personal Information
compromised during the Data Breach;
d) For equitable relief requiring restitution and disgorgement of the
revenues wrongfully retained as a result of W&F’s wrongful conduct;
e) Ordering W&F to pay for not less than three years of credit monitoring
services for Plaintiffs and the Class;
f) For an award of actual damages, compensatory damages, statutory
damages, and statutory penalties, in an amount to be determined, as
allowable by law;
g) For an award of punitive damages, as allowable by law;
h) For an award of attorneys’ fees and costs, and any other expense,
including expert witness fees;
i) Pre- and post-judgment interest on any amounts awarded; and,
j) Such other and further relief as this court may deem just and proper.
JURY TRIAL DEMANDED
Under Federal Rule of Civil Procedure 38(b), Plaintiffs demand a trial by jury
of any and all issues in this action so triable as of right.

Dated: February 24, 2023

Respectfully submitted,
/s/ E. Powell Miller
E. Powell Miller (P39487)
121


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1177 Filed 02/24/23 Page 122 of 125

Emily E. Hughes (P68724)
THE MILLER LAW FIRM
950 W. University Drive, Suite 300
Rochester, MI 48307
T: (248) 841-2200
epm@millerlawpc.com
eeh@millerlawpc.com
Nicholas A. Migliaccio
Jason S. Rathod
MIGLACCIO & RATHOD LLP
412 H. St. NE, Suite 302
Washington, DC 20002
T: (202) 470-3520
F: (202) 800-2730
nmigliaccio@classlawdc.com
jrathod@classlawdc.com
SHUB LAW FIRM LLC
Jonathan Shub
Benjamin F. Johns
134 Kings Hwy. E., 2nd Floor
Haddonfield, NJ 08033
T: (856) 772-7200
jshub@shublawyers.com
bjohns@shublawyers.com
Kevin J. Stoops (P64371)
SOMMERS SCHWARTZ, PC
One Towne Square, Suite 900
Southfield, MI 48076
T: (248) 355-0300
kstoops@sommerspc.com
LYNCH CARPENTER LLP
Gary F. Lynch
1133 Penn Avenue, 5th Floor
Pittsburgh, PA 15222
T: (412) 253-6307
F: (412) 231-0246
122


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1178 Filed 02/24/23 Page 123 of 125

gary@lcllp.com
Adam G. Taub (P48703)
ADAM TAUB ASSOC.
CONSUMER LAW GROUP
17200 W. Ten Mile Road, Suite 200
Southfield, MI 48075
T: (248) 746-3790
adamgtaub@clgplc.net
MASON LLP
Gary E. Mason
Danielle Lynn Perry
5101 Wisconsin Avenue NW, Ste 305
Washington, DC 20016
T: (202) 429-2290
F: (202) 429-2294
gmason@masonllp.com
dperry@masonllp.com
Gary M. Klinger
MILBERG COLEMAN BRYSON
PHILLIPS GROSSMAN PLLC
227 W. Monroe Street, Suite 2100
Chicago, IL 60606
T: (866) 252-0878
gklinger@milberg.com
Edmund S. Aronowitz (P81474)
ARONOWITZ LAW FIRM PLLC
220 S. Main St, Suite 305
Royal Oak, MI 48067
T: (248) 716-5421
edmund@aronowitzlawfirm.com
WILSHIRE LAW FIRM PLC
Thiago Coelho
Jonas P. Mann
3055 Wilshire Blvd., 12th Floor
Los Angeles, CA 90010
123


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1179 Filed 02/24/23 Page 124 of 125

T: (213) 381-9988
thiago@wilshirelawfirm.com
jmann@wilshirelawfirm.com
Caleb Marker (MI Bar No. P70963)
ZIMMERMAN REED LLP 6420
Wilshire Blvd., Suite 1080 Los
Angeles, CA 90048
Telephone: (877) 500-8780
caleb.marker@zimmreed.com
Brian C. Gudmundson*
Jason P. Johnston*
Michael J. Laird*
Rachel K. Tack*
ZIMMERMAN REED LLP
1100 IDS Center 80 South 8th Street
Minneapolis, MN 55402 Telephone:
(612) 341-0400
brian.gudmundson@zimmreed.com
jason.johnston@zimmreed.com
michael.laird@zimmreed.com
rachel.tack@zimmreed.com
Christopher D. Jennings*
Nathan I. Reiter III
THE JOHNSON FIRM
610 President Clinton Ave., Suite 300
Little Rock, AR 72201
Tel: (501) 372-1300
chris@yourattorney.com
nathan@yourattorney.com

124


Case 2:22-cv-12908-SFC-EAS ECF No. 13, PageID.1180 Filed 02/24/23 Page 125 of 125

CERTIFICATE OF SERVICE
I hereby certify that on February 24, 2023, I electronically filed
the foregoing documents using the Court’s electronic filing system,
which will notify all counsel of record authorized to receive such filings.

/s/ E. Powell Miller
E. Powell Miller (P39487)
THE MILLER LAW FIRM, P.C.
950 W. University Dr., Ste. 300
Rochester, MI 48307
Tel: (248) 841-2200
epm@millerlawpc.com

File and source

File
gov.uscourts.mied.366223.13.0.pdf
Size
1,028,667 bytes
SHA-256
5f84d8508f24a288b355cbe2f1dcc875cee74ecb44a021f91986995a362082a0
Our copy
gov.uscourts.mied.366223.13.0.pdf
Original
www.courtlistener.com
Back to top