Doe v. Regents of the University of California

United States District Court for the Northern District of California

Doe v. Regents of the University of California

Trial Court Opinion

1 2 3 4 UNITED STATES DISTRICT COURT 5 NORTHERN DISTRICT OF CALIFORNIA 6 7 JANE DOE, Case No. 23-cv-00598-WHO

8 Plaintiff, ORDER DENYING MOTION TO 9 v. DISMISS

10 REGENTS OF THE UNIVERSITY OF Re: Dkt. No. 34 CALIFORNIA, 11 Defendant.

12 Defendant, doing business as UCSF Medical Center (“UCSF”), moves to dismiss the 13 express breach of contract claim from plaintiff’s Amended Complaint (“AC”).1 I dismissed the 14 breach of contract claim with leave to amend in my May 2023 Order because plaintiff Jane Doe 15 had not adequately alleged that she had received or otherwise sufficiently assented to UCSF’s 16 Health Notice of Privacy Practices Act or Website Privacy Statement to state a breach of express 17 contact claim. May 2023 Order at 9-10.2 She has now, and UCSF’s motion is DENIED. 18 In the AC, plaintiff alleges three sources for her breach of express contract claim: Terms 19 and Conditions for UCSF MyChart (“MyChart Terms and Conditions”), AC ¶¶ 25-31; (2) UCSF 20 website Terms of Use, which incorporate by reference the Privacy Policy Statement, AC ¶¶ 33-40; 21 and (3) UCSF Notice of Privacy Practices, which UCSF provides to each patient. AC ¶¶ 41-47. 22 UCSF argues that plaintiff has failed to adequately allege: (1) the source of the contractual duties; 23 24 1 The procedural and factual background of this action was discussed in my May 8, 2023 Order 25 Granting in Part and Denying in Part defendant’s prior motion to dismiss. May 2023 Order, Dkt. No. 18. Plaintiff’s claims for invasion of privacy and violation of specific provisions of 26 California’s Confidentiality of Medical Information Act were not dismissed and remain. Id. at 5- 9. 27 1 (2) the consideration and mutual assent for the identified contractual duties; (3) that the contractual 2 duties promise anything beyond what UCSF is required to do under other laws; and (4) damages 3 available as a matter of contract law. Each of UCSF’s challenges fail. 4 Plaintiff has clearly alleged the bases for the contractual duties she alleges UCSF has 5 breached, as well as how those contractual provisions were communicated to plaintiff. See AC ¶¶ 6 25-47; 154-164. In particular, she points to the disclosure on the MyChart login page, that “BY 7 USING UCSF MYCHART OR BY CLICKING ‘I ACCEPT’ BELOW, YOU SIGNIFY YOUR 8 AGREEMENT TO THESE TERMS AND CONDITIONS. IF YOU DO NOT AGREE TO 9 THESE TERMS AND CONDITIONS, you are not able to use the UCSF MyChart.” AC ¶ 29. 10 Those terms and conditions promise to “afford the same degree of confidentiality to medical 11 information stored on UCSF MyChart as is given to health information stored by UCSF 12 Health in any other medium.” Id. ¶ 30 (emphasis in original). She then identifies additional 13 sources of those promises, including the “Terms of Use” and “Website Privacy Statement” that 14 plaintiff alleges are hyperlinked on UCSF’s website as well as in emails UCSF sent to plaintiff 15 and others. Id. ¶ 33. Finally, she alleges that each UCSF patient is provided a separate copy of 16 the “Notice of Privacy Practice.” Id. ¶ 41.3 17 UCSF does not discuss the contents of these documents or challenge whether the 18 documents identified contain express or incorporated promises governing how patient information 19 will be protected, not shared with third parties absent written consent, etc. Instead, UCSF argues 20 that plaintiff fails to allege acceptance, mutual consent, and consideration for her identified 21 contractual promises. But she has adequately alleged that she entered into these contracts to 22 receive treatment and services from UCSF. AC ¶ 152. She plausibly alleges that UCSF uses the 23 MyChart patient portal and its website to provide patient services, and notes where plaintiff had to 24 25 3 These added allegations bring this case within the lines of authority I distinguished in the May 26 2023 Order at 9 (discussing In re Solara Medical Supplies, LLC Customer Data Security Breach Litigation,

613 F. Supp. 3d 1284

(S.D. Cal. May 7, 2020) and In re Yahoo! Inc. Customer Data 27 Security Breach Litigation, No. 16-MD-02752-LHK,

2017 WL 3727318

, at *44 (N.D. Cal. Aug. 1 agree to the terms of use for the portal and website. Id. ¶¶ 29, 33. That is sufficient.4 2 UCSF may be right that plaintiff’s breach of contract claim might fail if she sought only to 3 require UCSF to comply with other legal duties imposed under HIPAA or the CMIA. But she 4 identifies UCSF privacy and data sharing promises that extend beyond UCSF’s duties under 5 HIPAA and CMIA, including that “disclosures of ‘health information’ for ‘marketing purposes . . . 6 are strictly limited and require your written authorization.’” AC ¶ 45; id. ¶ 46 (“Under the heading 7 ‘Other Uses and Disclosures of Health Information’ UC Regents promises that ‘[o]ther ways [it] 8 share[s] and use[s] [a patient’s] health information not covered by this Notice will be made only 9 with [the patient’s] written authorization.’”); see also In re Anthem, Inc. Data Breach Litig., No. 10 15-MD-02617-LHK,

2016 WL 3029783

, at *12 (N.D. Cal. May 27, 2016 (denying motion to 11 dismiss breach of contract claim based on allegations that defendants violated “their commitment 12 to maintain the confidentiality and security of [PII]” and “by failing to comply with their own 13 policies and applicable laws, regulations and industry standards for data security and protecting 14 the confidentiality” of PII); In re: Premera Blue Cross Customer Data Sec. Breach Litig., No. 15 3:15-MD-2633-SI,

2017 WL 539578

, at *15 (D. Or. Feb. 9, 2017) (denying motion to dismiss, 16 where privacy policy “goes beyond merely confirming Premera’s obligations under HIPAA and 17 thus the fact that HIPAA does not provide a private right of action does not preclude the Court 18 from implying this proposed term.”). 19 Finally, plaintiff has sufficiently alleged damage from the type of breach asserted here. 20 See In re Facebook, Inc., Consumer Priv. User Profile Litig.,

402 F. Supp. 3d 767

, 802 (N.D. Cal. 21 2019) (“the detriment the plaintiffs suffered was an invasion of their privacy. Perhaps some of the 22 individual plaintiffs suffered a harm from this privacy invasion that can be measured by 23 compensatory damages. [] Perhaps others did not, but under California law even those plaintiffs 24 4 UCSF argues that “at best” plaintiff has alleged UCSF uses a “browsewrap” type of agreement 25 that cannot give rise to an enforceable contract under California law. Reply at 4, citing Sellers v. JustAnswer LLC,

73 Cal. App. 5th 444

, 463 (2021), reh'g denied (Jan. 18, 2022), review denied 26 (Apr. 13, 2022). However, plaintiff’s complaint does not center on mere browsing of UCSF’s website, but the use of it by entering her data into the patient portal. See e.g., AC ¶¶ 71-73. 27 Moreover, the language relied on by plaintiff is more akin to “clickwrap” or “sign-in” agreements 1 may recover nominal damages.” (citations omitted)). 2 In light of the foregoing, UCSF’s motion to dismiss is DENIED. 3 IT IS SO ORDERED. 4 || Dated: August 22, 2023

6 ® William H. Orrick 7 United States District Judge 8 9 10 11 12

15 16

= 17

Z 18 19 20 21 22 23 24 25 26 27 28

Reference

Status
Unknown