Data breach cases are often brought as class actions because large numbers of people can potentially be affected. But the potential for injury is not enough to create constitutional standing. Before a putative data breach class action can make it to the class certification stage, the named plaintiffs in the case must show that they have standing to pursue the case for themselves, which boils down to a showing that they were injured as a result of the breach.
The ruling follows on the heels of two other district court rulings holding that standing was not satisfied in the data breach context, Polanco v. Omnicell, Inc., 2013 WL 6823265 (D.N.J. 2013); Barnes & Noble Pin Pad Litigation, 2013 WL 4759588, (N.D. Ill. 2013).
SAIC is an information technology company that was handling data for Tricare, a government agency that provides insurance coverage and health care to active-duty service members and their families.
Plaintiffs alleged that tapes containing personal and medical information for 4.7 million members of the U.S. military and their families were stolen from the parked car of an SAIC employee. The breach victims sued Tricare and SAIC, among others, asserting numerous causes of action (some of which were creative), including increased risk of identity theft, costs related to mitigating future harm, the loss of privacy, failure to adequately protect data and a violation of the right to truthful personal information.
The court granted the defendants’ motions to dismiss the claims all of the plaintiffs who lacked an actual injury traceable to the data breach on the ground that they lacked standing. Only two plaintiffs pled sufficient injury to confer standing.
The court held that plaintiffs lacked standing because the “degree by with the risk of harm has increased is irrelevant — instead, the question is whether the harm is certainly impending.” The court also found that costs incurred to prevent future injury did not create standing. The court also rejected the invasion of privacy claim of most plaintiffs because they did not allege that their personal information had been viewed or exposed in a way that would facilitate access to the data.
The plaintiffs’ claims that were based on alleged legal violations were also found to be deficient: “Standing . . . does not merely require a showing that the law has been violated, or that a statute will reward litigants in general upon a showing of a violation," the court ruled. "Rather, standing demands some form of injury — some showing that the legal violation harmed you in particular, and that you are therefore an appropriate advocate in the federal courts.”
The court also dismissed the plaintiffs’ claim based on deprivation of their “right to truthful information about the security of their PII/PHI,” holding that no independent harm has flowed from that alleged deprivation.
Significantly, as the courts did in Omnicell and Barnes & Noble, the SAIC court relied in large part on the U.S. Supreme Court’s decision in Clapper v. Amnesty International, 133 S. Ct. 1138 (2013), a case outside of the data breach context, decided under the Foreign Intelligence Surveillance Act (“FISA”). In Clapper, the court relied on well-settled precedent to hold that “allegations of possible future injury are not sufficient” to confer constitutional standing.
At its Spring meeting Thursday and Friday in Washington, D.C., the Judicial Conference's Committee on Rules of Practice and Procedure (aka, the Standing Committee) approved a revised package of amendments, which were recommended by its Advisory Committee on Rules of Civil Procedure in a May 2 report.
The amendments include significant changes from the original proposals, reflecting feedback from three public hearings that drew more than 120 witnesses and 2,356 written comments. The Standing Committee members were effusive in their praise for the open, transparent process that the Rules Committee and its two subcommittees have followed after the 2010 Civil Litigation Conference, held at Duke University's law school, sponsored and organized by the advisory committee.
Among other amendments approved was a new form of Rule 37(e), changes to Rule 1 and a controversial reworking of Rule 26(b)(1). The original multi-layered proposal for a new Rule 37(e) was scrapped in favor of a simplified rule limited to electronically stored information. An ill-fated attempt to reduce presumptive limits on certain discovery devices was abandoned and a sharply re-focused Rule 26(b)(1) was approved to emphasize that discovery must be both relevant and proportional to the needs of the case.
The next stop is a review by the Judicial Conference in September. If approved, the U.S. Supreme Court will be asked to review and vote on whether to send the amendments to Congress. If that occurs before May 2015, the individual rules will become effective in December 2015, unless Congress disapproves.
Scope of Discovery
A core recommendation is to move the listed proportionality "factors" from later in Rule 26 into the definition of scope of discovery set out in Rule 26(b)(1). The Rules Committee is convinced that the change “will not limit proportional discovery,” but will have an impact only at the margins, where unlimited discovery is inappropriate.
It was explained that there is no intent to change the burden of proof involved. As is the practice when a party claims that “undue burden” bars a discovery request, courts will seek the information relevant to the assessment of proportionality from both parties, with the ultimate responsibility to decide whether the request is proportional resting with the court.
However, the Rules Committee has adjusted the order of factors listed in the rule so that “the amount in controversy” is secondary to the importance of “discovery in resolving the issues.” The rule will also require consideration of the “relative access” of the parties to the information.
A member asked whether revised Rule 26(b)(1) was intended to guide assessment of what ESI “should have been preserved” under revised Rule 37(e), which is discussed below. The response was that the assessment of whether “reasonable steps” had been undertaken might involve actions taken before a complaint was filed and that under those circumstances, reliance on the common law on the topic was deemed more appropriate.
Cooperation
The Standing Committee also approved the explicit acknowledgment of responsibility by both courts and parties for securing the goals of Rule 1 (the “just, speedy, and inexpensive determination of every action”) by an amendment to the text. The Committee Note also acknowledges the role of cooperation in the effort, but will clarify that there is no intention to create a right to sanctions for failures to cooperate.
Failure to Preserve
The recommended replacement for Rule 37(e) garnered considerable scrutiny by members of the Standing Committee, given that the revised proposal differs dramatically from the original proposal. U.S. Judge David Campbell (D. Ariz.)—chairman of the Rules Committee—led a thorough discussion by describing the background to the revised proposal and then dealing with a series of difficult hypotheticals testing the application of the rule.
Blame it on Target. Or Edward Snowden. But in case you haven't noticed, legal technology conversations lately aren't exactly obsessed with predictive coding right now. Instead, firms—and everyday citizens—are more likely to be discussing data breaches, cybercrimes, and concerns about confidential client information.
But according to a new survey by LexisNexis' Legal & Professional division, while law firms may be talking—they aren't doing very much about it. The company reports that 89 percent of the 300 legal professionals in 40 states and in 15 practice areas who were recently polled said their firms send confidential information to clients via unencrypted email—relying on a disclaimer at the bottom of the correspondence to serve as protection.
So what are the ramifications? How are law firms, corporate counsel and vendors responding to these sometimes contradictory technology challenges? We can get some clues from last week's Computer and Enterprise Investigations Conference, annually presented by Guidance Software.
For starters, the company has always thrown a broad cloth around its offerings. Founded in 1997, Guidance has targeted both electronic data discovery and other "digital investigations," and today offers a line of seven software under the "EnCase" brand (and a line of Tableau forensics products). The company says its EnCase Enterprise platform "is used by more than half of the Fortune 500," by the likes of Allstate, Ford, General Electric, Pfizer and Viacom, to name a few.
It's easy to see that Guidance, and its CEIC conference, covers a wide range of disciplines, including digital forensics, cybersecurity, e-discovery and litigation support, compliance and risk management, information and law enforcement.
Guidance President and CEO Victor Limongelli kicked off the 2014 four-day CEIC event with the opening keynote on May 19, explaining how the company has decided to transition to a "platform" approach for its EnCase suite of products. The concept is to move from a "closed" (self-contained) system to a more collaborative environment, where third parties can plug applications into the EnCase platform and, in effect, customize the operation to meet the specific needs of their organizations.
Perhaps Guidance is also reacting to yet another strong legal industry trend: bring your own devices. About a year ago, Guidance launched its EnCase App Central store (think Apple Inc.'s App Store). It offers apps from third-party developers that can be integrated into the EnCase platform, Limongelli explained. To date, more than 30,000 downloads from the EnCase App Central store, he told the audience.
"It's all about apps," observed San Francisco's Albert Barsocchini, director of strategic consulting at Minnesota-based NightOwl Discovery. He served as an associate general counsel at Guidance for eight years (2003-11). "EnCase is no longer closed," he said. Now, EnCase products are a foundation, and organizations can build systems on top of that foundation, said Barsocchini.
But don't think the company is throwing out its babies with the bath water. "With recent attention on data breaches, including Target Corp. and the controversy about Edward Snowden's disclosure of government documents, I expected to see cybersecurity take center stage," observed Boston's David Horrigan, an analyst and counsel at 451 Research.
Guidance has traditionally had three focus areas—forensics, cybersecurity and e-discovery," he said. "What surprised me was Limongelli’s strong focus on e-discovery, said Horrigan. "The keynote highlighted Guidance's new e-discovery offerings, including Linked Review, which we expect to be Guidance's answer to predictive coding," Horrigan noted.
U.S. law firms may be worried about the security risks of sharing confidential information online, but a new surveyby LexisNexis' legal and professional division reveals that they are not doing much about it.
Unencrypted email remains by far the most prominent way that law firms share privileged communications with their clients, with 89 percent of respondents reporting that it is the firm's primary method of distributing information.
In March, the company canvassed about 300 legal professionals in 40 states across 15 different practice areas. Results show that although respondents were aware of the risks, and wary of them, the most common method of securing documents and protecting privilege was the use of a confidentiality statement at the bottom of an email, with 77 percent of firms reporting this was their primary line of defense.
“There’s clearly a disconnect between expressed security concerns and measures law firms employ to protect their clients and themselves,” said Christopher Anderson, a senior product manager at LexisNexis, in a statement. “Relying on a mere statement of confidentiality when sharing privileged communications by email is a weak measure—and further it might protect the law firm but affords very little protection for the client,” he said.
A minority of law firms go a step further to protect their information, with 22 percent saying they use email encryption,14 percent using a password to protect documents and 13 percent employing a secure file-sharing site. At the reverse end of the spectrum, 4 percent of respondents said they take no measures at all to protect private information. “Law firms need to perform their due diligence, stay abreast of technology and ultimately protect their clients’ interest online just as they do in providing legal counsel,” said Anderson.
Attorney Marlisse Silver Sweeney is a freelance writer based in Vancouver. Twitter: @MarlisseSS.
This spring, about 25 practitioners participated in an informal roundtable at the new Supreme Court of Singapore for an informal benchmarking discussion. It was organized by the non-profit organization, Electronic Discovery Institute, and made possible with the assistance of the court's Senior Assistant Registrar and CIO Zee Kin Yeong. Yeong previously served as a partner in Rajah & Tann (IT and intellectual property) and started his career as a deputy public prosecutor and state counsel with the Attorney-General's Chambers, where he prosecuted inter alia computer and white collar crimes. In his current position, Yeong's position mirrors that of a federal magistrate judge in the U.S.
Others participating at the April 10th gathering were assistant registrars included Lee Siew Hui Jacqueline; James Elisha Lee Han Leong; Miyapan Ramu; and Jean Chan Lay Koon. The two-hour session also drew lawyers from accounting firms; plaintiff, defense, and corporate counsel. U.S. participants included UBS' Wayne Matus, managing director, and Jamie Brown, global discovery counsel.
Yeong kicked off the event with a historical perspective on e-discovery in Singapore. In 2009, the Singapore Supreme Court launched its first Practice Directive to deal with the growing volume of electronic evidence in litigation, he said. “We always focused on a set of directions that would guide the profession on how to handle electronic requests … to provide a framework and put in place standards for the profession. To ensure that the profession has the skills and the tools to handle electronic documents in an efficient and cost effective manner.”
In 2012, the court responded to concerns that the 2009 Practice Directive was too technical and returned for a revision, 2012 Practice Directive, the current version. Not by coincidence, it focuses on points similar to those that have emerged in the U.S. federal courts: from metadata to proportionality of costs. The Practice Directive includes a checklist of issues for good faith collaboration that is similar to the Cooperation Proclamation lead by The Sedona Conference. The 2012 edition also moved the directive to a mandatory opt-in framework, explained Yeong. “What is the meaning of an opt-in framework? Whether a case has 1 million or 5 thousand documents, [litigants] must consider using it.”
Yeong identified discovery trends in the Singapore Court System. The court has recently seen the PD as a frequently-used tool in litigation against large entities—as a method of getting discovery materials and forensic images in an employment matter. Litigants also have used the PD to obtain documents from large technology companies that relate to intellectual property disputes. He also identified a trend of young enterprising lawyers using the PD to limit the scope of request—a focus on proportionality.
Unlike the mandatory "Brady" and "Giglio" disclosures required in the U.S., there is no corollary criminal PD for exchange of discovery in Singapore, he said. The 2011 amendments to Singapore Criminal Procedure account for limited discovery, but nothing like those in the U.S., said Yeong. Even so, the deputy public prosecutor is considering new developments now, he noted.
Matus clarified that unlike Singapore, the U.S. is made up of an amalgam of state and local jurisdictions—it's not just the federal courts that we see in headline-making opinions. He responded to Yeong’s observations with five significant U.S. trends.
1. Discovery data volumes and costs are massive compared to those in Singapore, observed Matus. A matter might have 40 terabytes of data and hundreds of people reviewing information, he said. With hundreds of cases, costs can be many millions of dollars. "The proliferation of data is changing things."
2. In Singapore, the use of search terms is becoming more common, but the use of search terms in the U.S. is changing, he said. “Search terms are dying.” Litigants are replacing search terms with advanced search and analytics as a result of search term inefficiency. “Search terms might find five documents that are not relevant for every one document that is.”
3. There is an increased mandate for cooperation in the U.S. “Judges don’t have time. There is a need for early judicial involvement to force parties to cooperate,” said Matus. The trend of lawyers receiving sanctions is very real, he said—a concept that troubled may of the participants E-discovery is becoming a case within a case, he said, and the argument is not about the merits of a case, but whether a document existed or not.