Related Links

Related Stories

  • Lawsuits fly over T-Mobile Sidekick cloud data loss
    T-Mobile has reportedly been hit by two class action lawsuits alleging that the cellular carrier misled consumers into believing that their data was secure after data was lost in the cloud
  • Heartland breach generates storm of lawsuits
    Embarrassment over the massive data breach suffered by Heartland Payment Systems has turned out to be only the start of the firm's problems. The company, which announced the potential compromise of an as-yet undisclosed number of card records, is now on the receiving end of lawsuits from at least eight banks and credit unions.
  • ChoicePoint settles class action suit for $10m
    Data broker ChoicePoint has agreed to pay $10 million to settle a class-action lawsuit brought against it over the three-year old data breach which exposed 163 000 personal information records.
  • Information Security: Read All About It
    Ill news travels quick and far, or so the saying goes. But how well is security-related news covered in the press, and what are people writing about? Danny Bradbury investigates
    Members' Content
  • Comment: Compliance trends on the horizon
    Cheryl Klein of GRC Consulting believes that a focus on automation is the single best way to keep compliance costs manageable, especially for medium and smaller-sized businesses

News

Aetna boots data breach class action suit

12 March 2010

Health insurer Aetna has succeeded in having a class-action lawsuit over an alleged security breach dismissed.

The case, bought by Cornelius Allison, stemmed from an alleged security breach of the Aetna online job application database. The breach, which was announced by Aetna last May, caused it to send notification letters to 65 000 current and former employees telling them that personal information may have been exposed.

 

Allison, who worked for the company as an office assistant from 1998 until May 2005, applied for a customer service position at Aetna using its website. He uploaded his personal information and his resume.

According to the complaint filed in the lawsuit, Allison became aware last May of a breach in the job application website, when applicants reported receiving phishing emails from Aetna asking for additional personal information in response to job enquiries.

 

Aetna argued in the case that Allison's claim was invalid, because it merely speculated that there may have been material damage. "Courts have recognized that allegations of 'increased risk of harm' and related costs for preventative measures are not legally cognizable injuries." In short, Allison could not prove that any harm had been done.

The case was dismissed even though Allison contended that he had incurred out-of-pocket expenses, lost time, and an increased risk of identity theft. "Plaintiffs alleged injury or an increased risk of identity theft is far too speculative," the judge said in a decision. "Plaintiff's allegation that his personal information was even accessed is conjecture. Plaintiff never received the phishing email. In addition, defendants letter stated that they were unable to verify whether plaintiff's information was even accessed."

Allison had also admitted that only email addresses had been accessible in the breach, the court said. "At best, plaintiff has alleged a mere possibility of an increased risk of identity theft, which is insufficient for purposes of standing, and he certainly has not asserted a credible threat of identity theft."

The decision carries particular significance for future data breach cases bought by victims who cannot prove that their identities have been stolen.

Aetna's job application website contained the email addresses of 450 000 job applicants, along with the social security numbers of current and former employees. The social security numbers, telephone numbers for addresses, and employment histories of those who had been offered jobs by Aetna were also in the system.

 

This article is featured in:
Compliance and Policy Data Loss Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.