In re New Era Enterprises Inc. Data Incident Litigation
In re New Era Enterprises Inc. Data Incident Litigation
Trial Court Opinion
IN THE UNITED STATES DISTRICT COURT February 04, 2026
FOR THE SOUTHERN DISTRICT OF TEXAS Nathan Ochsner, Clerk
HOUSTON DIVISION
§
§
§
IN RE NEW ERA ENTERPRISES INC. § CIVIL ACTION NO. H-25-732
DATA INCIDENT LITIGATION, §
§
§
§
MEMORANDUM AND OPINION
This case is about an alleged breach of confidential health information from several related
insurance companies. The plaintiffs’ complaint, filed on behalf of a putative class, alleges
negligence, negligence per se, breach of an implied contract, and unjust enrichment. The
defendants have moved to dismiss. (Docket Entry No. 41). Based on the complaint, the motion,
the briefs, and the applicable law—and with the benefit of oral argument by able counsel for all
parties—the motion to dismiss is granted in part and denied in part. The rulings and reasons are
set out below.
I. Background
New Era Enterprises, Inc. is a life insurance company that operates New Era Life Insurance
Company, New Era Life Insurance Company of the Midwest, Philadelphia American Life
Insurance Company, and Life of America Insurance Company. (Docket Entry No. 27 ¶ 2). New
Era collects and maintains personally identifiable information and protected health information.
(Id. ¶¶ 3–5). The named plaintiffs, Maria Sanchez, Ernest Williams, Ebony White, Steven Stapp,
and Timothy Kirker, allege that they are current and former customers or employees of New Era:
Sanchez, Williams, White, and Stapp allege that they are current and former customers, (id. ¶¶
152, 162, 176, 190), and Kirker alleges that he was a former employee, (id. ¶ 204).
Between December 9 and 18, 2024, New Era became aware that an unauthorized third
party had accessed certain parts of its information technology network. (Id. ¶ 34). The
unauthorized third party copied files from New Era’s network. (Id.). In February 2025, New Era
sent written notices to the plaintiffs explaining that their information may have been involved in
this data incident. (Id.). The copied files included some combination of names, Social Security
numbers, addresses, dates of birth, health insurance policy numbers, Medicare identification
numbers, and data related to medical treatments and diagnoses. (Id. ¶ 5).
The plaintiffs allege that, as a result of this breach, cybercriminals obtained everything
needed to commit identity theft and wreak havoc on their financial and personal lives. (Id. ¶¶ 13–
15, 64). They allege that that their personal information has already been misused: it has been
posted to the dark web; cybercriminals have attempted to access their financial accounts; and they
have experienced an increase in spam calls and texts. (Id. ¶¶ 170, 184, 198, 212). They allege that
they have been forced to take steps to mitigate the harms of identity theft, have experienced
emotional distress and diminution in the value of their private information, and remain at
substantial risk of future harm. (Id. ¶¶ 152–217).
On February 19, 2025, the plaintiffs sued New Era. (Docket Entry No. 1). They assert
claims of (i) negligence, (ii) negligence per se, (iii) breach of implied contract, and (iv) unjust
enrichment, and seek certification of a nationwide class. (Id. ¶¶ 234–317).
II. The Legal Standards
A. Standing
Article III of the Constitution limits federal courts to deciding “Cases” and
“Controversies.” U.S. CONST. art. III, § 2. This standing limit and requirement “defines with
2
respect to the Judicial Branch the idea of separation of powers on which the Federal Government
is founded.” Allen v. Wright, 468 U.S. 737, 750 (1984).
To establish standing, a plaintiff must meet the “irreducible constitutional minimum” of
Article III, which requires that the plaintiff’s injury be: (1) concrete, particularized, and actual or
imminent; (2) fairly traceable to the defendant’s challenged action; and (3) likely redressable by a
favorable ruling. Lujan v. Defs. of Wildlife, 504 U.S. 555, 560–61 (1992). The party asserting
federal jurisdiction bears the burden of demonstrating standing. See TransUnion LLC v. Ramirez,
594 U.S. 413, 430–31 (2021). When courts assess standing, they “assum[e] that on the merits the
plaintiffs would be successful in their claims.” Polelle v. Fla. Sec’y of State, 131 F.4th 1201, 1211
(11th Cir.) (quoting Culverhouse v. Paulson & Co., 813 F.3d 991, 994 (11th Cir. 2016)), cert.
denied, 146 S. Ct. 298 (2025)
The “concreteness” requirement ensures that the alleged injury is “‘real,’ and not
‘abstract,’” so that the plaintiff has a real stake in the litigation. Spokeo, Inc. v. Robins, 578 U.S.
330, 340 (2016). Injuries are concrete if they have “a close relationship to harms traditionally
recognized as providing a basis for lawsuits in American courts.” TransUnion, 594 U.S. at 425.
“Those include, for example, reputational harms, disclosure of private information, and intrusion
upon seclusion.” Id.
B. Rule 12(b)(6)
Rule 12(b)(6) allows dismissal if a plaintiff fails “to state a claim upon which relief can be
granted.” FED. R. CIV. P. 12(b)(6). Rule 12(b)(6) must be read in conjunction with Rule 8(a),
which requires “a short and plain statement of the claim showing that the pleader is entitled to
relief.” FED. R. CIV. P. 8(a)(2). “[A] complaint must contain sufficient factual matter, accepted as
3
true, to ‘state a claim to relief that is plausible on its face.’” Ashcroft v. Iqbal, 556 U.S. 662, 678,
(2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570 (2007)).
Rule 8 “does not require ‘detailed factual allegations,’ but it demands more than an
unadorned, the-defendant-unlawfully-harmed-me accusation.” Id. (quoting Twombly, 550 U.S. at
555). “A claim has facial plausibility when the plaintiff pleads factual content that allows the court
to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Id. “The
plausibility standard is not akin to a ‘probability requirement,’ but it asks for more than a sheer
possibility that a defendant has acted unlawfully.” Id. (quoting Twombly, 550 U.S. at 556).
“Conversely, when the allegations in a complaint, however true, could not raise a claim of
entitlement to relief, this basic deficiency should be exposed at the point of minimum expenditure
of time and money by the parties and the court.” Eli Lilly & Co. v. Revive Rx, LLC, ___ F. Supp.
3d ___, 2025 WL 3640703, at *5 (S.D. Tex. Dec. 15, 2025) (quoting Cuvillier v. Taylor, 503 F.3d
397, 401 (5th Cir. 2007)).
III. Analysis
New Era moves to dismiss the complaint (1) because the plaintiffs do not have standing to
sue; and (2) because it fails to state a claim. The plaintiffs have standing, but several of their
claims must be dismissed: their request for damages based on emotional harm; their claim of
negligence per se; and their implied-contract claim.
A. Standing
Throughout the complaint, the plaintiffs assert that they will suffer: (i) invasion of privacy;
(ii) theft of their private information; (iii) lost or diminished value of private information; (iv) lost
time and opportunity costs associated with mitigating the consequences of the data breach; (v) loss
of benefit of their bargain with the insurance companies; (vi) lost opportunity costs associated with
4
attempts to mitigate the consequences of the data breach; (vii) nominal damages; and (viii) the
continued and certainly increased risk to their private information that: (a) remains unencrypted
and available for unauthorized third parties to access and abuse; and (b) remains backed up in New
Era’s possession and is subject to further unauthorized disclosures so long as New Era fails to
undertake appropriate and adequate measures to protect the private information. (Docket Entry
No. 27 ¶¶ 7, 116, 157, 265, 278, 302, 315). New Era contends that these injuries are not sufficient
to establish standing.
1. Substantial Risk of Future Harm
The main question presented in New Era’s motion to dismiss is whether the alleged harms
are sufficiently concrete and imminent. A plaintiff does not need to allege a past injury to establish
standing. But to prove standing based on a threat of future harm, plaintiffs must show that the
harm is “certainly impending” or that there is a “substantial risk” of the harm. Clapper v. Amnesty
Int’l USA, 568 U.S. 398, 414 & n.5 (2013). If a “risk” of these harms “hasn’t materialized, the
plaintiff hasn’t yet been injured.” Perez v. McCreary, Veselka, Bragg & Allen, P.C., 45 F.4th 816,
824 (5th Cir. 2022). Courts apply a three-factor test to determine whether a data breach is
sufficiently likely to harm plaintiffs to allow federal courts to adjudicate the case: (1) the data at
issue was compromised as the result of a targeted attack intended to obtain the plaintiffs’ data; (2)
at least some part of the compromised dataset has been misused, even if some plaintiffs’ particular
data has not yet been affected; and (3) the data at issue is more or less likely to subject plaintiffs
to a perpetual risk of identity theft or fraud once it has been exposed. See, e.g., McMorris v. Carlos
Lopez & Assocs., LLC, 995 F.3d 295, 303–05 (2d Cir. 2021); Clemens v. ExecuPharm Inc., 48
F.4th 146, 153–54, 157 (3d Cir. 2022); Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365,
375 (1st Cir. 2023).
5
These factors are important because a plaintiff cannot manufacture standing based on a
data breach without proving a risk of harm. See Clapper, 568 U.S. at 422 (a plaintiff cannot
“manufacture standing by incurring costs in anticipation of non-imminent harm”). In data-breach
cases, the courts of appeals have uniformly agreed that a plaintiff may not recover damages for
“money and time” unless they were spent “to correct an error that itself caused a concrete harm.”
Nelson v. Experian Info. Sols. Inc., 144 F.4th 1350, 1355 (11th Cir. 2025) (emphasis omitted); see,
e.g., Webb, 72 F.4th at 377; McMorris, 995 F.3d at 303; Clemens, 48 F.4th at 155–56; Hutton v.
Nat’l Bd. of Examiners in Optometry, Inc., 892 F.3d 613, 622 (4th Cir. 2018); Galaria v.
Nationwide Mut. Ins. Co., 663 F. App’x 384, 389 (6th Cir. 2016); Lewert v. P.F. Chang’s China
Bistro, Inc., 819 F.3d 963, 966 (7th Cir. 2016); In re U.S. Off. of Pers. Mgmt. Data Sec. Breach
Litig., 928 F.3d 42, 59 (D.C. Cir. 2019). A plaintiff’s response to a data breach is considered an
“additional harm[]” to the risk of concrete harm that itself satisfies standing. Nelson, 144 F.4th at
1355.
As discussed, the plaintiffs have alleged several theories of harm. In this case, a review of
each is not necessary. The plaintiffs can establish standing based on their primary theory of
injury—that there is a substantial risk of future harm. The plaintiffs have adequately alleged all
three McMorris factors.
First, there was “a targeted attack intended to obtain the plaintiffs’ data.” McMorris, 995
F.3d at 301. The notice letter that the plaintiffs received stated that “an authorized person
accessed” New Era’s “IT network . . . and . . . copied some” files containing personal information.
(Docket Entry No. 27 ¶ 34). The letter stated that someone hacked into New Era’s files to steal
the plaintiffs’ data. This intentional act by a malicious hacker suggests a high chance of misuse.
6
Second, “at least some part of the compromised dataset has been misused.” McMorris,
995 F.3d at 301; see OPM, 928 F.3d at 58 (“[A] hacker’s ‘intent’ to use breach victims’ personal
data for identity theft becomes markedly less important where, as here, several victims allege that
they have already suffered identity theft and fraud as a result of the breaches.”). White, Stapp, and
Kirker allege that they received notifications that their private information was posted to the dark
web following the data breach. (Docket Entry No. 27 ¶¶ 184, 198, 212). “That allegation is
critical.” Green-Cooper v. Brinker Int’l, Inc., 73 F.4th 883, 889 (11th Cir. 2023). “The fact that
hackers took [sensitive] data and corresponding personal information from . . . and affirmatively
posted that information for sale on . . . is the misuse” that is needed “for standing purposes . . . .”
Id. at 889–90. It “establishes both a present injury—[sensitive] data and personal information
floating around on the dark web—and a substantial risk of future injury—future misuse of personal
information associated with the hacked [data].” Id. at 890; accord McMorris, 995 F.3d at 302
(explaining that “allegations that the plaintiffs’ PII was available for sale on the Dark Web . . .
provided strong support . . . an Article III injury in fact”).
Third, because the data that New Era maintained included sensitive health and personal
identifying information, there is likely “a perpetual risk of identity theft or fraud once it has been
exposed.” McMorris, 995 F.3d at 302. “Naturally, the dissemination of high-risk information
such as Social Security numbers and dates of birth—especially when accompanied by victims’
names—makes it more likely that those victims will be subject to future identity theft or fraud.”
Id. (citing Attias v. CareFirst, Inc., 865 F.3d 620, 628 (D.C. Cir. 2017)); see In re Equifax Inc.
Customer Data Sec. Breach Litig., 999 F.3d 1247, 1262 (11th Cir. 2021) (“Given the . . . data
stolen, including Social Security numbers, names, and dates of birth, and the unequivocal damage
that can be done with this type of data, we have no hesitation in holding that Plaintiffs adequately
7
alleged that they face a ‘material’ and ‘substantial’ risk of identity theft . . . .”); OPM, 928 F.3d at
60 (even if a breach does not expose every piece of information necessary for immediate financial
fraud, the stolen data itself is sufficient to enable identity theft).
New Era concedes that the McMorris factors are a reformulation of the Clapper standard
for standing. (Docket Entry No. 45 at 3–4). New Era argues that the plaintiffs cannot establish
standing based on their belief that some of their information was sold or posted on the dark web.
(Id. at 3–5). But, at this stage in the litigation, courts must assume that the facts alleged to support
standing are true. Lujan, 504 U.S. at 561. The plaintiffs have plausibly alleged that their specific
information has been misused. Cf. Williams v. Bienville Orthopedic Specialists, LLC, 737 F. Supp.
3d 411, 421 (S.D. Miss. 2024). The complaint alleges, for instance, that “White has received
notice from her Smart Credit monitoring service that her information has been posted to the dark
web.” (Docket Entry No. 27 ¶ 184). This is the allegation that the Eleventh Circuit found sufficient
for standing in Green-Cooper. See 73 F.4th at 889–90.
New Era argues that the plaintiffs cannot establish standing because they have not shown
that the information posted on the dark web was the same information stolen in the data breach.
(Docket Entry No. 41 at 8). New Era relies primarily on a case in which the plaintiff gave “no
timeline of how soon after the breach he started to experience fraudulent activity.” Hemphill v.
Horne, LLP, No. 3:24-CV-178-KHJ-ASH, 2025 WL 837007, at *8 (S.D. Miss. Mar. 10, 2025).
But here, the plaintiffs allege that they are careful about sharing their private information; do not
knowingly transmit it online over unsecured and unencrypted channels; and, at least for White,
Stapp, and Kirker, that they received a message that their data was posted on the dark web shortly
after the New Era data breach. (Docket Entry No. 27 ¶¶ 153–55, 176–88, 190–200, 212). This
temporal proximity is sufficient to create a reasonable inference of traceability. See Hulse v.
8
Acadian Ambulance Serv. Inc., No. 6:24-CV-01011, 2025 WL 1453847, at *10 (W.D. La. May
19, 2025); see also Green-Cooper, 73 F.4th at 890–91 (concluding that proof that the plaintiffs
dined at a Chili’s during the at-risk period was sufficient to establish traceability).
New Era relies on one case in which a court broadly questioned whether even a close
temporal proximity is sufficient to establish traceability because there are many places from which
a plaintiff’s data could be stolen. See, e.g., Williams v. Bienville Orthopaedic Specialists, LLC,
737 F. Supp. 3d 411, 424–25 (S.D. Miss. 2024). This court respectfully disagrees with the opinion
in Williams, which imposes too high a bar on a motion to dismiss. See Hulse, 2025 WL 1453847,
at *10 (disagreeing with the Williams traceability analysis). The plaintiffs have alleged that they
are careful with their data and do not needlessly expose it online. At this stage, the court must
draw the reasonable inference that the data incident, not some other hack, is the reason their
personal data was shortly thereafter available on the dark web; the plaintiffs do not need to
anticipate and negate other potential causes of their injuries at the outset of litigation. See Texas
v. Mayorkas, No. 2:22-CV-094-Z, 2024 WL 455337, at *3 (N.D. Tex. Feb. 6, 2024) (“Plaintiff, at
this stage, is under no obligation to prove its injury actualized or to define and eliminate all possible
factors contributing to it.”).
The complaint adequately alleges each of the McMorris factors and a substantial risk of
injury for the plaintiffs. See Webb, 72 F.4th at 376 (the allegation that “at least some information
stolen in a data breach has already been misused also makes it likely that other portions of the
stolen data will be similarly misused”); McMorris, 995 F.3d at 301 (“[C]ourts have been more
likely to conclude that plaintiffs have established a substantial risk of future injury where they can
show that at least some part of the compromised dataset has been misused—even if plaintiffs’
particular data subject to the same disclosure incident has not yet been affected.”). New Era may
9
again raise standing issues as the record develops, including as to specific injuries for which the
plaintiffs seek redress. See Lujan, 504 U.S. at 561.1
2. Loss of Privacy
New Era argues that the plaintiffs’ alleged injury for loss of privacy is not concrete.
(Docket Entry No. 41 at 9; Docket Entry No. 45 at 10–11). New Era argues that plaintiffs cannot
allege a privacy harm without factual allegations of dissemination and intentional conduct on New
Era’s part.
New Era is correct that one cannot allege a privacy-related harm without showing
dissemination. In TransUnion, the Court held that some plaintiffs had standing because incorrect
information in their credit file was disseminated to third parties, but that other plaintiffs did not
have standing because TransUnion never sent the false credit file to anyone else. 594 U.S. at 417–
18. But here, the plaintiffs allege that their information was disseminated when the hackers stole
it and posted it to the dark web. (Docket Entry No. 27 ¶¶ 41, 167, 184, 198, 212). Courts have
held that this kind of alleged dissemination or public disclosure of private facts is sufficiently
analogous to common-law injuries to support standing. See Bohnak v. Marsh & McLennan
Companies, Inc., 79 F.4th 276, 285 (2d Cir. 2023) (“[T]he core injury here—exposure of Bohnak’s
private PII to unauthorized third parties—bears some relationship to a well-established common-
law analog: public disclosure of private facts.”). Whether the plaintiffs can establish substantial
1 New Era argues that many of the specific damages that the plaintiffs alleged are insufficient to confer
standing. (Docket Entry No. 41 at 7–14). For the most part, these arguments are a subset of the argument
that the plaintiffs did not adequately allege a substantial risk of future harm. Because the plaintiffs have
alleged standing based on a risk of future harm, the court does not need to address in detail some of the
remaining standing arguments that New Era raises. See Cabezas v. Mr. Cooper Grp. Inc., No. 3:23-CV-
2453-N, 2025 WL 2053287, at *7 (N.D. Tex. July 22, 2025) (concluding that “where courts have already
established a risk of future harm, emotional distress and mitigation costs, when coupled with the risk of
harm is a concrete injury sufficient to confer standing” (cleaned up)); Bruno v. Donohoe, 754 F. Supp. 3d
737, 748 (W.D. Tex. 2024) (similar).
10
damages based on this theory of injury is immaterial at this stage. When a concrete interest is
allegedly violated (here, the privacy of personal information), plaintiffs can establish standing
because nominal damages are traditionally appropriate relief. See Uzuegbunam v. Preczewski, 592
U.S. 279, 292–93 (2021) (“[N]ominal damages provide the necessary redress for a completed
violation of a legal right.”). Whether the plaintiffs can prove a tort and recover even nominal
damages for this asserted injury is a merits question under state law that cannot be resolved at this
stage of the litigation.
New Era’s argument that it did not intentionally disclose the plaintiffs’ private information
does not affect the plaintiffs’ standing. A “scienter element does not affect the concreteness of [a
plaintiff’s] injury because it is not ‘essential to the harm’ in the relevant common-law comparator.”
Polelle, 131 F.4th at 1210 n.6 (citation omitted). “Instead, mens rea presents a question of a
defendant’s ‘culpability’ and ‘blameworth[iness].’ Id. (alterations in original) (quoting Morissette
v. United States, 342 U.S. 246, 252 (1952)). In some cases, a “defendant’s mental state may relate
to the degree of injury or causation; some courts have concluded intentional conduct is more likely
to cause a more severe injury than would result in the case of an accident or negligence.” Id.
(citing Raybon v. United States, 867 F.3d 625, 632 (6th Cir. 2017)). “But a defendant’s mental
state does not change the kind of injury a defendant inflicts upon a plaintiff.” Id. The Fifth Circuit
has focused on the kind of injury, not the degree of injury, in determining whether a harm is
sufficiently concrete. See Perez, 45 F.4th at 822. If a defendant exposed or disseminated a
plaintiff’s private information, the plaintiff suffers the same harm whether the defendant did so
“intentionally, unintentionally, in good-faith, or in bad-faith.” Polelle, 131 F.4th at 1210 n.6.
Based on the present record, the plaintiffs have standing to assert privacy-based injuries.
3. Spam Calls and Text Messages
11
Williams, White, and Stapp allege that they have experienced an increase in spam phone
calls and emails since the data breach and have lost time and productivity by screening those spam
calls and emails. (Docket Entry No. 27 ¶¶ 170–71, 184–85, 198–99). New Era argues that these
spam calls and text messages are not fairly traceable to the data breach because the plaintiffs’
contact information was not part of the breach. (Docket Entry No. 41 at 12). The plaintiffs respond
that the data breach enabled cybercriminals to spam them by using “Fullz” packages to link stolen
information to the plaintiffs’ phone numbers, email addresses, and other personal identifiers.
(Docket Entry No. 27 ¶ 126).
Some courts have relied on allegations of “Fullz” packages to find that plaintiffs’ alleged
increase in spam texts after a data breach are traceable to that breach. See Fox v. Iowa Health Sys.,
399 F. Supp. 3d 780, 792 (W.D. Wis. 2019) (concluding that the “allegations plausibly explain[ed]
why, for example, Fox started getting phone calls related to medical scams after the data breach”).
Others have found sufficient allegations of a sudden, rapid uptick in spam calls after plaintiffs’
contact information was leaked. See, e.g., Baldwin v. Nat’l W. Life Ins. Co., No. 2:21-CV-04066-
WJE, 2021 WL 4206736, at *4 (W.D. Mo. Sept. 15, 2021). Courts also note that traceability is
not as demanding as causation; “[e]ven if the data accessed in the Data Breaches did not provide
all the information necessary to inflict these harms, they very well could have been enough to aid
therein.” Mednax Servs., Inc., Customer Data Sec. Breach Litig., 603 F. Supp. 3d 1183, 1206
(S.D. Fla. 2022); see, e.g., Solomon v. ECL Grp., LLC, No. 1:22-CV-526, 2023 WL 1359662, at
*4 (M.D.N.C. Jan. 31, 2023).
Several courts have doubted the concreteness and traceability of spam text messages and
calls, finding that “an increase in spam email and text as a time-based injury [is] insufficient to
constitute a concrete injury.” Hulse, 2025 WL 1453847, at *8. Other courts have noted that
12
“[s]pam calls, texts, and e-mails have become very common in this digitized world,” Hemphill,
2025 WL 837007, at *8 (quoting McCombs v. Delta Grp. Elecs., Inc., 676 F. Supp. 3d 1064, 1074
(D.N.M. 2023)); In re ESO Sols., Inc. Breach Litig., No. 1:23-CV-1557-RP, 2024 WL 4456703,
at *5 (W.D. Tex. July 30, 2024); In re Sci. Applications Int’l Corp. (SAIC) Backup Tape Data
Theft Litig., 45 F. Supp. 3d 14, 33 (D.D.C. 2014), finding that more factual allegations of injury
were required. The Hemphill and ESO courts needed “more,” Hemphill, 2025 WL 837007, at *8;
In re ESO Sols., 2024 WL 4456703, at *5, and the McCombs and SIAC courts needed factual
allegations that contact information was stolen and “detail[s of] the content or frequency of the
spam communications,” McCombs, 676 F. Supp. 3d at 1074; SAIC, 45 F. Supp. 3d at 33.
Under these principles, the plaintiffs have pleaded enough facts to show standing to assert
injuries based on the increased spam calls and messages after the data breach. Repeated spam
calls and messages can constitute concrete harm. See Perez, 45 F.4th at 826 n.6 (explaining that
“unwanted communications can inflict a concrete injury analogous to a nuisance or a public
nuisance”). And the plaintiffs have adequately alleged that their injuries are traceable to the data
breach. Although the plaintiffs’ contact information was not included in the breach, the plaintiffs
explain, through their discussion of “Fullz” packages, how the breach allows cybercriminals to
contact them more easily. See Fox, 399 F. Supp. 3d at 792. In addition, the plaintiffs allege that
they experienced “a significant increase in the number of spam emails and telephone calls.”
(Docket Entry No. 27 ¶ 170). They allege that the increase was close in “time proximity” to the
data breach and something that they have “never experienced . . . prior to now.” (Id.). Although
spam calls and emails are relatively common today, Hemphill, 2025 WL 837007, at *8, the
plaintiffs allege that the post-breach frequency of spam calls, emails, and texts was significantly
greater and a noticeable deviation from their usual experience. These allegations are sufficient to
13
create a reasonable inference that the increase is fairly traceable to New Era’s alleged role in
allowing the data breach.
The plaintiffs have standing to assert an injury based on an increase in spam calls and
emails and text messages after the breach.
B. Failure to State a Claim
New Era moves to dismiss the complaint for failure to state a claim. It argues: (1) that the
plaintiffs cannot prove damages to support their claims; (2) that the economic-loss rule bars the
plaintiffs’ tort claims; (3) that the plaintiffs have not adequately alleged a claim for negligence per
se; (4) that the plaintiffs have not adequately alleged a breach of an implied contract; and (5) that
the plaintiffs have not adequately alleged a claim for unjust enrichment.
1. Damages
“To support a claim for negligence, a plaintiff must establish (1) a legal duty owed by
Defendant to plaintiff; (2) a breach of that duty, and (3) damages proximately caused by the
breach.” Bruno v. Donohoe, 754 F. Supp. 3d 737, 748 (W.D. Tex. 2024). To state a claim for
breach of contract, implied or express, a plaintiff must also establish damages because of a breach.
Smith Int’l, Inc. v. Egle Grp., LLC, 490 F.3d 380, 387 (5th Cir. 2007). New Era argues that the
plaintiffs’ damages theories are not cognizable under Texas law or are inadequately pleaded.
Specifically, New Era argues that the plaintiffs: (1) cannot recover damages based on speculative
risks of future harm; (2) cannot recover for the diminution of the value of their personal
information; (3) cannot recover for the lost time spent responding to the data breach; (4) have not
adequately alleged emotional harm; and (5) cannot recover on a theory that they overpaid for
insurance services. The court addresses the first four arguments and leaves New Era’s fifth for its
discussion of the merits of the plaintiffs’ implied-contract claim.
14
i. Risk of Future Harm
Texas courts have not squarely addressed whether parties can recover damages for the risk
of harm posed by data breaches. Section 919 of the Restatement (Second) of Torts states that
“[o]ne whose legally protected interests have been endangered by the tortious conduct of another
is entitled to recover for expenditures reasonably made or harm suffered in a reasonable effort to
avert the harm threatened.” RESTATEMENT (SECOND) OF TORTS § 919(1) (AM. L. INST. 1979). This
principle extends to those who, by “lack of reasonable care . . . foreseeably . . . permit[] the
improper conduct of . . . a third party.” RESTATEMENT (THIRD) OF TORTS: PHYS. & EMOT.
HARM § 19 (AM. L. INST. 2010). Under this principle, a company that fails to reasonably protect
confidential or sensitive information can be liable for reasonable expenses required to mitigate the
risk of harm caused by a data breach. See RESTATEMENT (THIRD) OF TORTS: LIAB. FOR ECON.
HARM § 6 (AM. L. INST. 2020) (“An actor who, in the course of his or her business . . . performs a
service for the benefit of others is subject to liability for pecuniary loss caused to them by their
reliance upon the service, if the actor fails to exercise reasonable care in performing it.”).
Texas case law includes some examples of the Section 919 principle in practice. A Texas
court allowed recovery for reasonable expenses and attorneys’ fees necessary to avert the risk of
the loss of title to property caused by a defendant’s tortious conduct. Donnelly v. Young, 471
S.W.2d 888, 890, 897 (Tex. Civ. App.—Fort Worth 1971, writ ref’d n.r.e.); see also Moore v.
Kyles, No. 05-92-00238-CV, 1992 WL 368034, at *4 (Tex. App.—Dallas Dec. 14, 1992, no pet.)
(applying Section 919(1) to allow recovery of expenses incurred in a bankruptcy court to avert the
damage caused by fraud and conspiracy). In other cases, the Texas Supreme Court has cautioned
that the risk of future harm may be too low to permit compensatory damages, such as when people
who have only been exposed to asbestos sue for emotional damages based on the risk of contracting
15
future illnesses. See, e.g., Temple-Inland Forest Prods. Corp. v. Carter, 993 S.W.2d 88, 93 (Tex.
1999). But the Texas Supreme Court made clear that the viability of a plaintiff’s claim depends
on the “circumstances” and the “types of fears” of future harm at issue. Id. at 95.
Courts in the Fifth Circuit have allowed plaintiffs to pursue negligence claims if they allege
a sufficient risk of future injury to establish standing, as the plaintiffs have done here. See, e.g.,
Hawkins v. Scout Energy Mgmt., LLC, No. 3:24-CV-01545-N, 2025 WL 2244327, at *5, *8 (N.D.
Tex. Aug. 5, 2025); Cabezas v. Mr. Cooper Grp. Inc., No. 3:23-CV-2453-N, 2025 WL 2053287,
at *7, *11 (N.D. Tex. July 22, 2025); Castillo v. Berry Bros Gen. Contractors Inc., No. 6:24-CV-
01723, 2025 WL 1062091, at *5 (W.D. La. Apr. 8, 2025); Hulse, 2025 WL 1453847, at *7, *11–
12; Smith v. Am. Pain & Wellness, PLLC, 747 F. Supp. 3d 989, 1002–04 (E.D. Tex. 2024); Bruno,
754 F. Supp. 3d at 749. These conclusions track the Restatement and Texas case law. The
plaintiffs have adequately alleged damages based on their risk of future harm.
ii. Diminution in Value of Personal Information
The plaintiffs allege “that consumers can actually sell their non-public information directly
to a data broker who, in turn, aggregates the information and provides it to marketers or app
developers” and that “[c]onsumers who agree to provide their web browsing history to the Nielsen
Corporation can receive up to $50.00 a year.” (Docket Entry No. 27 ¶¶ 139–40). They allege that
the value of their information “has been damaged and diminished by its compromise and
unauthorized release” because the information “is now readily available, and the rarity of the Data
has been lost, thereby causing additional loss of value.” (Id. ¶ 141).2
2 New Era argues that a diminution in the value of one’s personal information is not concrete for the purpose
of standing. But the basis of the injury is economic, and monetary harm is a prototypical concrete injury.
TransUnion, 594 U.S. at 417. This court assumes that state law recognizes personal information as a
commodity and property interest for purposes of standing. See Polelle, 131 F.4th at 1211 (explaining that
courts must accept, for the purpose of standing, the plaintiff’s interpretation of the laws on which the
complaint relies).
16
New Era argues that loss of value for personally identifiable information is not cognizable.
Courts are split on the issue. There is a “growing trend across courts . . . to recognize the lost
property value of this information.” In re Marriott Int’l, Inc., Customer Data Sec. Breach Litig.,
440 F. Supp. 3d 447, 461 (D. Md. 2020); accord In re Mednax, 603 F. Supp. 3d at 1204; Klein v.
Facebook, Inc., 580 F. Supp. 3d 743, 803–04 (N.D. Cal. 2022). Texas courts have been skeptical
of these claims. See In re ESO Sols., 2024 WL 4456703, at *6 (collecting cases). But neither the
Texas Supreme Court nor the Fifth Circuit have addressed the issue directly. Cf. Somer v.
OakBend Med. Ctr., No. 01-24-00187-CV, 2025 WL 2446015, at *13–15 (Tex. App.—Houston
[1st Dist.] Aug. 26, 2025) (holding that government immunity barred the plaintiffs’ suit arising out
of a data breach of a hospital because the diminished value of their personal information is a
financial, not a personal, injury under the Tort Claims Act’s waiver).
In the absence of controlling precedent, the cases recognizing a diminution in the value of
one’s personally identifiable information are more persuasive. The Texas legislature has defined
“property” broadly to include “any matter or thing capable of private ownership.” TEX. TAX
CODE § 1.04(1). Texas law also recognizes property rights in, and has provided specific remedies
for misuses of, individuals’ name, image, and likeness. TEX. PROP. CODE § 26.013(a)(3). Texas
courts would likely recognize a property interest in personal data, which is similar to a person’s
name, image, and likeness and is capable of ownership and commoditization.
The complaint alleges that personally identifiable information has market value, which the
data breach diminished by making the information readily accessible on the dark web. New Era
cites cases finding similar allegations insufficient because the plaintiffs did not allege that they
will attempt to sell, or have in the past sold, their personally identifiable information. See In re
ESO Sols., 2024 WL 4456703, at *6–7; Hawkins, 2025 WL 2244327, at *4. This logic is
17
unpersuasive because in other contexts plaintiffs may recover the lost value of their damaged
property without showing that they plan to sell it. For example, to recover damages for trespass
to chattel, a plaintiff need only show harm to his interest in the quality or value of the chattel. See
Cranor v. 5 Star Nutrition, L.L.C., 998 F.3d 686, 692–93 (5th Cir. 2021) (citing RESTATEMENT
(SECOND) OF TORTS § 218(c) & cmt. e). Similarly, if a bailee negligently damages property in his
care, a plaintiff can establish damages simply by showing the reduction in the value of the bailed
property. See, e.g., Whitley v. Kinsel Motor Co., 94 S.W.2d 202, 202 (Tex. Civ. App.—San
Antonio 1936) (holding that the value of damages for a car crashed in a bailee’s custody is the
change in the market value). These principles apply to the allegations by some of the plaintiffs
that New Era’s negligence caused their personal information to be posted on the dark web, (Docket
Entry No. 27 ¶ 184, 212), and diminished the market value of their property (their personally
identifiable information), (id. ¶ 141).
New Era’s argument may prove persuasive at the summary-judgment stage or at trial, when
the plaintiffs must produce evidence that their personally identifiable information has lost value.
A factfinder might not find that the plaintiffs have been harmed because they cannot show that
they would sell their data soon or that they can only do so at a diminished price. But at this stage
in the litigation, the court must take the plaintiffs’ allegations as true. Iqbal, 556 U.S. at 678. The
plaintiffs have sufficiently alleged a diminution in the market value of their personally identifiable
information.
iii. Lost Time Damages
The plaintiffs repeatedly allege that they have suffered the “lost time and opportunity costs
associated with attempting to mitigate the actual consequences of the Data Breach.” (Docket Entry
18
No. 27 ¶ 7). New Era argues that Texas law does not recognize a tort for wasting another’s time.
(Docket Entry No. 41 at 18).
New Era argues that there is not a “tort that makes a person liable for wasting another’s
time,” Perez, 45 F.4th 825, and that “[l]ost time alone does not establish compensable damages,”
Smallman v. MGM Resorts Int’l, 638 F. Supp. 3d 1175, 1192 (D. Nev. 2022). But under Texas
law, plaintiffs may “estimate[] the value of wasted time” as a measure of damages, so long as they
introduce “evidence about the value of that time—either the quantity or the cost of it.” MBM Fin.
Corp. v. Woodlands Operating Co., L.P., 292 S.W.3d 660, 664 (Tex. 2009); see, e.g., Success
Motivation Inst., Inc. v. Lawlis, 503 S.W.2d 864, 868 (Tex. Civ. App.—Houston [1st Dist.] 1973,
writ ref’d n.r.e.) (upholding a jury award of $20,000 for “lost and wasted time and energy in
pursuing the distributorship venture” that was “directly traceable to wrongful acts” of the
appellant). The plaintiffs’ allegations of wasted time are downstream of the material risk of harm
they faced because of New Era’s alleged role in allowing the data breach. The plaintiffs have
alleged a claim for damages for this lost time. See, e.g., Cabezas, 2025 WL 2053287, at *7;
Hawkins, 2025 WL 2244327, at *5; Bruno, 754 F. Supp. 3d at 749; Smith, 747 F. Supp. 3d at 1002;
see Webb, 72 F.4th at 377 (“[T]ime spent responding to a data breach can constitute a concrete
injury sufficient to confer standing, at least when that time would otherwise have been put to
profitable use.”).
The plaintiffs bear the burden of proving that their lost time would otherwise have been
spent on profitable or productive activities that warrant compensable damages. New Era has not
moved to dismiss on the theory that Texas law requires proof of an economic, as opposed to leisure,
opportunity cost. Factual issues of the plaintiffs’ proof, and the legal issues that might accompany
their specific proof of damages, are still open.
19
The plaintiffs’ alleged damages based on lost time survive New Era’s motion to dismiss.
iv. Emotional Distress
New Era argues that the plaintiffs have not alleged sufficiently severe mental anguish to
recover for emotional distress under Texas law. (Docket Entry No. 41 at 19). The plaintiffs briefly
respond with cases suggesting that they can recover for emotional distress. (Docket Entry No. 44
at 10–11, 17). New Era’s argument is persuasive. The cases the plaintiffs cite do recognize that
emotional distress can be a concrete injury for the purpose of standing. See, e.g., Hawkins, 2025
WL 2244327, at *5; In re ESO Sols., 2024 WL 4456703, at *6; Hulse, 2025 WL 1453847, at *8.
The court agrees that the plaintiffs have standing to pursue damages based on emotional distress.
But New Era argues that Texas substantive law does not permit recovery on the alleged facts. The
court agrees with New Era’s reading of Texas law.
“Without intent or malice on the defendant’s part, serious bodily injury to the plaintiff, or
a special relationship between the two parties,” Texas courts “permit recovery for mental anguish
in only a few types of cases involving injuries of such a shocking and disturbing nature that mental
anguish is a highly foreseeable result,” such as in “suits for wrongful death and actions by
bystanders for a close family member’s serious injury.” City of Tyler v. Likes, 962 S.W.2d 489,
496 (Tex. 1997) (internal citations omitted); see Motor Exp., Inc. v. Rodriguez, 925 S.W.2d 638,
639 (Tex. 1996) (listing examples of cases in which “a claimant who is not physically injured by
the defendant’s breach of a duty may recover mental anguish damages”). Even when plaintiffs
may recover for mental anguish, “it is necessary to offer proof of more than mere worry, anxiety,
vexation or anger.” Grp. Hosp. Servs., Inc. v. Daniel, 704 S.W.2d 870, 878 (Tex. App.—Corpus
Christi-Edinburg 1985, no pet.). Mental anguish “implies a relatively high degree of mental pain
and distress,” such as “mental sensation of pain resulting from such painful emotions as grief,
20
severe disappointment, indignation, wounded pride, shame, despair and/or public humiliation.”
Id. (quoting Trevino v. Southwestern Bell Telephone Co., 582 S.W.2d 582 (Tex. Civ. App.—
Corpus Christi 1979, writ ref’d n.r.e.)).
The plaintiffs allege “stress, anxiety, and concern due to the loss of [their] privacy and
concern over the impact of cybercriminals accessing and misusing” their private information.
(Docket Entry No. 27 ¶¶ 173, 187, 201, 215; see also id. ¶ 158). These allegations are insufficient
to state a claim for emotional distress under Texas law. Nor does it appear that the alleged torts,
which sound in simple negligence and contract, provide a remedy for mental anguish.
The plaintiffs’ payer for damages based on emotional distress is dismissed, without
prejudice. The plaintiffs have one more opportunity to plead, consistent with Rule 11, that they
have suffered emotional damages for which Texas law would permit recovery.
2. Economic-Loss Rule
New Era argues that because the plaintiffs alleged a breach of an implied contract and
because they alleged purely economic injuries, Texas’s economic-loss rule bars their claims for
negligence and negligence per se. (Docket Entry No. 41 at 20).
Under the economic-loss rule, when damage allegedly resulting from the defendant’s
tortious conduct is limited to the loss of a contractual benefit, the action in tort is barred. See
Chapman Custom Homes, Inc. v. Dallas Plumbing Co., 445 S.W.3d 716, 718 (Tex. 2014) (per
curiam); Formosa Plastics Corp. USA v. Presidio Eng’rs & Contractors, Inc., 960 S.W.2d 41, 47
(Tex. 1998); Sw. Bell Tel. Co. v. DeLanney, 809 S.W.2d 493, 494–95 (Tex. 1991). But “the
economic loss rule does not preclude recovery in tort when the defendant, in performing a contract,
breaches a legal duty owed to the plaintiff that is independent of the contractual undertaking and
that results in damage to the plaintiff above and beyond the mere economic loss of the contractual
21
benefit itself.” ConocoPhillips Co. v. Koopmann, 542 S.W.3d 643, 664–65 (Tex. App.—Corpus
Christi–Edinburg 2016), aff’d on other grounds, 547 S.W.3d 858 (Tex. 2018). “Accompanying
every contract is a common-law duty to perform with care, skill, reasonable expedience and
faithfulness the thing agreed to be done, and a negligent failure to observe any of these conditions
is a tort, as well as a breach of the contract.” DeLanney, 809 S.W.2d at 494 (quoting Montgomery
Ward & Co. v. Scharrenbeck, 204 S.W.2d 508, 510 (Tex. 1947)).
The relevant questions are whether “the defendant’s conduct” gives “rise to liability only
because it breaches the parties’ agreement,” id., and whether the plaintiffs assert damages “above
and beyond the mere economic loss of the contractual benefit itself,” Koopmann, 542 S.W.3d at
665. The plaintiffs’ allegations meet this test. First, the plaintiffs allege that New Era breached
its duties under the FTC Act, the Gramm-Leach-Bliley Act, and the common law to prevent
foreseeable harm. (Docket Entry No. 27 ¶¶ 38, 240–45). The plaintiffs’ claims depend on duties
independent of the parties’ alleged contractual relationship. See, e.g., Hawkins, 2025 WL
2244327, at *9; Cabezas, 2025 WL 2053287, at *11. Second, the plaintiffs seek damages for their
mitigation costs, lost time, and violations of their privacy. (Docket Entry No. 27 ¶¶ 7, 14, 158–
59, 170–71, 173–74, 184–85, 187–88, 198–99, 201–02, 212–13, 215–16, 265–66). The plaintiffs
allege harm separate from and in addition to the value of the parties’ contracts. See, e.g., Hawkins,
2025 WL 2244327, at *9; Cabezas, 2025 WL 2053287, at *11; In re Solara Med. Supplies, LLC
Customer Data Sec. Breach Litig., 613 F. Supp. 3d 1284, 1295–96 (S.D. Cal. 2020). The
economic-loss rule does not bar the plaintiffs’ damages in tort.
New Era argues in reply that if the plaintiffs’ “claim for breach of implied contract survives,
its negligence claims cannot.” (Docket Entry No. 45 at 14). But the plaintiffs are permitted to
plead in the alternative. FED. R. CIV. P. 8(d)(3). The alleged inconsistency between the plaintiffs’
22
contract claims and tort claims need not be resolved at this early stage of the litigation. See
Occidental Petro. Corp. v. Wells Fargo Bank, N.A., 573 F.Supp.3d 1161, 1171 (S.D. Tex. 2021)
(holding that “it is premature to resolve” the economic-loss rule “argument at the motion to dismiss
stage” because the plaintiff “is entitled to plead alternative theories for relief, and will face the
economic-loss rule if and when it recovers, depending on the basis of recovery”).
3. Negligence Per Se
The plaintiffs have alleged claims of negligence per se based on breaches of the FTC Act
and the Gramm-Leach-Bliley Act. (Docket Entry No. 27 ¶¶ 89–110). New Era argues that the
plaintiffs’ negligence per se claims should be dismissed because Texas law governs each of their
negligence per se claims and because Texas law does not permit negligence per se claims based
on those statutes. (Docket Entry No. 41 at 14–15, 21–22).
Texas law does not recognize a negligence per se claim for breaches of the FTC Act or
Gramm-Leach-Bliley Act. “Negligence per se is a common-law doctrine that allows courts to rely
on a penal statute to define a reasonably prudent person’s standard of care.” Reeder v. Daniel, 61
S.W.3d 359, 361–62 (Tex. 2001). “But it is well established that [even] criminal statutes do not
always represent a standard for civil liability.” Id. “Courts ‘must consider whether recognizing
such an accompanying civil action would be inconsistent with legislative intent’ in ‘determining
whether a penal statute provides the basis for a civil cause of action.’” Eli Lilly, 2025 WL 3640703,
at *8 (quoting Reliable Ambulance Serv., Inc. v. Mercy Hosp. of Laredo, No. 04-02-00188-CV,
2003 WL 21972724, at *3 (Tex. App.—San Antonio Aug. 20, 2003, pet. denied)). “Reeder
directed Texas courts to assess how the legislature has regulated the area, whether it enacted
separate criminal and civil schemes relating to the conduct, whether the legislature considered and
rejected a private right of action, and whether courts in other jurisdictions have recognized a similar
23
cause of action.” Id. (citing Reeder, 61 S.W.3d at 363–64); see, e.g., Reliable, 2003 WL 21972724,
at *6 (concluding that violations of the federal anti-kickback statute could not support “a common
law cause of action by a competitor for damages and injunctive relief”); Eli Lilly, 2025 WL
3640703, at *11 (holding that Texas courts likely would not allow a tort claim based on violations
of the Texas FDCA).
Although the plaintiffs identify numerous cases that have allowed negligence per se claims
based on violations of the FTC Act and the GLBA, Texas courts applying Texas law have
consistently rejected negligence per se claims based on the FTC Act and similar statutes that do
not include private rights of action but include government-enforcement schemes. See, e.g., Smith,
747 F. Supp. 3d at 1004 (FTC Act); Bruno, 754 F. Supp. 3d at 748 n.3 (same); In re ESO, 2024
WL 4456703, at *11 (same); Lowman v. Enter. Fin. Grp., Inc., No. 3:24-CV-02752-L, 2025 WL
2778380, at *3 (N.D. Tex. Sept. 30, 2025) (same); see also Hall v. Phenix Investigations, Inc., No.
3:14-CV-0665-D, 2014 WL 5697856, at *9 (N.D. Tex. Nov. 5, 2014) (holding that there is no
private right of action under the GLBA); Haynes v. Am.’s Car-Mart, Inc., No. 5:24-CV-00067-
RWS-JBB, 2024 WL 4729491, at *9 (E.D. Tex. Sept. 23, 2024) (same), report and
recommendation adopted, No. 5:24-CV-67-RWS-JBB, 2024 WL 4533301 (E.D. Tex. Oct. 21,
2024). The plaintiffs cannot state a claim of negligence per se based on violations of the FTC Act
and the GLBA under Texas law.
These statutes may come into play, because federal law may provide “evidence of the
relevant standard of care.” Century Next Bank v. JPMorgan Chase Bank, No. CV H-25-2461,
2026 WL 179558, at *5 (S.D. Tex. Jan. 23, 2026). “Experts routinely opine on the standard of
care,” and “references to statutes and administrative regulations is one method of establishing a
standard of care.” Texas Health Harris Methodist Hosp. Sw. Fort Worth v. Davis, No. 02-23-
24
00055-CV, 2024 WL 3611269, at *19 (Tex. App.—Fort Worth Aug. 1, 2024, pet. denied) (mem.
op) (quoting Doe v. Kerrville I.S.D., SA-21-CV-00369-XR, 2023 WL 5313889, at *6 (W.D. Tex.
Aug. 16, 2023)); Hernandez v. Nueces Cnty. Med. Soc’y Cmty. Blood Bank, 779 S.W.2d 867, 871
(Tex. App.—Corpus Christi–Edinburg 1989, no pet.) (explaining that “[i]t is well-established that
state health regulations, national standards, and organizational bylaws are admissible to define the
standard of care customarily offered”). The FTC Act and the GLBA “may speak to the relevant
standard of care,” but “they cannot show an automatic breach of duty to establish negligence per
se.” In re ESO, 2024 WL 4456703, at *11.
Second, although Texas law would not recognize the plaintiffs’ negligence per se claims,
“a law other than Texas law may apply.” Cabezas, 2025 WL 2053287, at *12; Hawkins, 2025 WL
2244327, at *10. A federal court applies the choice-of-law rules of the state in which it sits.
Klaxon Co. v. Stentor Elec. Mfg. Co., 313 U.S. 487, 496 (1941). Texas courts apply the law of the
state with the most significant relationship to the particular substantive issue. Taylor v. U.S. Bank
Nat. Ass’n, No. 4:12-cv-03550, 2015 WL 507526, at *5 (S.D. Tex. Feb. 6, 2015). Relevant factors
are: 1) the place where the injury occurred; 2) the place where the conduct causing the injury
occurred; 3) the domicile, residence, nationality, place of incorporation and place of business of
the parties, and 4) the place where the relationship, if any, between the parties is centered.
RESTATEMENT (SECOND) OF CONFLICT OF LAWS § 145(2) (AM. L. INST. 1971).
“Courts have specifically recognized that ‘[t]he data breach context raises unique problems
in choice-of-law analysis’ because it is not always clear where the breach occurred and where the
harm from the breach can be said to have accrued.” Tjahjono v. Westinghouse Air Brake Techs.
Corp., No. 2:23-CV-531, 2024 WL 1287085, at *5 (W.D. Pa. Mar. 26, 2024) (alterations in
original) (quoting In re Mednax, 603 F. Supp. 3d at 1199). Data is no longer “stored on local
25
servers or mainframes,” but perhaps in the “cloud,” meaning that the location of the breach or
injury is not “readily determined.” In re Mednax, 603 F. Supp. 3d at 1199. “A substantial number
of cases addressing the issue in the context of data breach cases have accordingly held that it is
inappropriate to decide which law applies at the motion to dismiss stage.” Tjahjono, 2024 WL
1287085, at *5; see, e.g., In re Am. Med. Collection Agency, Inc. Customer Data Sec. Breach
Litig., No. 19-md-2904, 2021 WL 5937742, at *13–14 (D.N.J. Dec. 16, 2021); Carr v. Oklahoma
Student Loan Auth., 699 F. Supp. 3d 1241, 1246–47 (W.D. Okla. 2023).
It is not clear whether these factual issues are material to the choice-of-law analysis. Some
courts have recognized that the location of breached servers would not alter the conflicts analysis.
See, e.g., In re MOVEit Customer Data Sec. Breach Litig., No. 23-MD-3083-ADB-PGL, 2025 WL
2176590, at *5 (D. Mass. July 31, 2025). In any event, the parties did not spend much time briefing
the choice-of-law issue, which offers another reason to defer resolving the question at this stage.
See id. at *6 (collecting cases that defer choice-of-law questions due to limited briefing).
The plaintiffs’ claims for negligence per se are not viable under Texas law, but their claims
are not dismissed with prejudice because the laws of other states may apply and may allow them.
4. Breach of Implied Contract
A breach of an implied-contract claim requires that the plaintiff show an enforceable
contract, including: (1) an offer, (2) an acceptance, (3) a meeting of the minds, (4) mutual consent,
and (5) execution and delivery. Plotkin v. Joekel, 304 S.W.3d 455, 476 (Tex. App.—Houston [1st
Dist.] 2009, pet. denied). The difference between express contracts and implied contracts is the
evidence used to prove the meeting of minds to form a legal agreement. Id. at 476–77; see
Southwell v. Univ. of the Incarnate Word, 974 S.W.2d 351, 354–55 (Tex. App.—San Antonio
1998, pet. denied). The parties’ objective actions, not their subjective state of minds, control the
26
analysis. Lindsey Constr., Inc. v. AutoNation Fin. Servs., LLC, 541 S.W.3d 355, 363 (Tex. App.—
Houston [14th Dist.] 2017, no pet.).
The plaintiffs rely on two theories of contract formation: (1) an agreement to adhere to the
terms of New Era’s privacy policy; and (2) an implied agreement based on the sensitive nature of
the data given to New Era. (Docket Entry No. 27 ¶¶ 284–304). New Era argues that the plaintiffs
lack standing to sue for breach of the implied contract and that no such contract exists as a matter
of Texas law. (Docket Entry No. 41 at 10–11, 22–25). If the plaintiffs’ allegations are sufficient,
then they have standing to pursue their contract claims. See TransUnion, 594 U.S. at 417
(explaining that economic harms are sufficient to confer standing). The implied-contract claim is
appropriately addressed on the merits. And on the merits, the plaintiffs’ implied-contract claim
fails.
The plaintiffs allege that they were customers or employees of New Era and had purchased
policies (or had employment contracts) with them. (Docket Entry No. 27 ¶ 4, 29, 30). In other
words, the plaintiffs have or had an express contract with New Era. Under Texas law, “there can
be no implied contract where the subject matter is covered by a valid express contract.” Morales
v. Dalworth Oil Co., 698 S.W.2d 772, 774 (Tex. App.—Forth Worth 1985, writ ref’d n.r.e.); see
1 WILLISTON ON CONTRACTS § 4:21 (4th ed. 2025) (“There can be no implied in fact if there is an
express contract covering the subject matter involved.”). To facilitate New Era’s performance
under the parties’ contracts, the plaintiffs provided New Era with personal and confidential
information. (Docket Entry No. 27 ¶ 30). If the plaintiffs wanted New Era, as a condition of the
contract, to provide a level of cybersecurity to their information, then they should have added such
a term to the agreement. Arguing that an implied-in-fact contract exists between these parties is
an attempt “to change the parties’ express agreement.” Iiitec Ltd. v. Weatherford Tech. Holdings,
27
LLC, No. CV H-19-3386, 2021 WL 2635380, at *13 (S.D. Tex. June 25, 2021). The mere
provision of sensitive data in exchange for services is insufficient to create an implied-in-fact
contract when the plaintiffs provided that data under an express contract that excludes the term
that they hope to imply. Cf. In re Mednax, 603 F. Supp. 3d at 1221 (declining to imply a contract
based on allegations that the plaintiffs merely “provided their personal information as required to
receive healthcare services from Defendants”).
New Era’s privacy policy does not change the analysis. Multiple documents can form a
single contract, or one document may incorporate by reference the promises made in another
document. Polyflow, LLC v. Specialty RTP, LLC, No. 4:15-CV-02817, 2016 WL 6909383, at *6
(S.D. Tex. May 17, 2016). But there is no allegation that the plaintiffs’ insurance agreements with
New Era incorporated by reference the privacy policy. Nor are there allegations that the privacy
policy was furnished to the plaintiffs during negotiations over the insurance policies or
employment contracts, such that all the documents should be part of the same agreement. See
Mobil Expl. & Producing U.S., Inc. v. Dover Energy Expl., L.L.C., 56 S.W.3d 772, 777 (Tex.
App.—Houston [14th Dist.] 2001, no pet.) (“A court may determine, as a matter of law, that
multiple documents, even if they are executed at different times and do not reference each other,
comprise a single, unified contract.”). Without more, New Era’s privacy policy does not create
enforceable contractual obligations. Compare Day & Zimmermann, Inc. v. Hatridge, 831 S.W.2d
65, 69 (Tex. App.—Texarkana 1992, writ denied) (explaining that “a statement of company policy,
unaccompanied by an express agreement, does not create contractual rights”), with Fort Worth
Transp. Auth. v. Thomas, 303 S.W.3d 850, 859 (Tex. App.—Fort Worth 2009, pet denied) (“The
CBA and the Operator Handbook related to the same transaction, and their terms do not clearly
prevent them from being considered together.”).
28
The plaintiffs have not stated a breach of contract claim against New Era. The court grants
New Era’s motion to dismiss this claim, without prejudice, and grants the plaintiffs leave to amend
their complaint to attempt to state a contract, misrepresentation, or fraud claim under Texas law.
Failure to sufficiently allege this claim in the amended complaint will result in a dismissal of that
claim with prejudice.
5. Unjust Enrichment
Under Texas law, unjust enrichment “is an equitable concept that arises in situations in
which another person has ‘wrongfully secured a benefit or has passively received one in which it
would be unconscionable to retain.’” Houle v. Casillas, 594 S.W.3d 524, 554 (Tex. App.—El
Paso 2019, no pet.) (quoting Eun Bok Lee v. Ho Chang Lee, 411 S.W.3d 95, 111–12 (Tex. App.—
Houston [1st Dist.] 2013, no pet.)). New Era argues that the plaintiffs’ unjust enrichment claim
fails because they “do not allege that Defendant did anything that was fraudulent or that involved
duress or undue advantage.” (Docket Entry No. 41 at 25).
Texas law “recognizes two theories or species of unjust enrichment: one for passive receipt
of a benefit that would be unconscionable to retain, and another for wrongfully securing a benefit.”
Digital Drilling Data Sys., LLC v. Petrolink Servs., Inc., 965 F.3d 365, 379 (5th Cir. 2020); see In
re KP Eng’g, L.P., 63 F.4th 452, 457 (5th Cir. 2023) (“If a plaintiff’s unjust enrichment claim is
based on passive receipt of a benefit that would be unconscionable to retain, then the plaintiff does
not need to plead or prove that the defendant acted wrongfully.”). The existence of fraud, duress,
or the taking of undue advantage is not an element of unjust enrichment, “even though the doctrine
is typically found to apply under one of those scenarios.” Walker v. Walker, 631 S.W.3d 259, 266
(Tex. App.—Houston [14th Dist.] 2020, no pet.) (cleaned up). A claim for unjust enrichment
29
“does not depend on the existence of a wrong” and instead arises when a party retains benefits
under circumstances where it would be unjust to retain them. /d. (citation omitted).
New Era does not move to dismiss the plaintiffs’ unjust-enrichment claim on any other
ground. New Era’s motion to dismiss the plaintiffs’ unjust-enrichment claim is denied.
IV. Conclusion
New Era’s motion to dismiss, (Docket Entry No. 41), is granted in part and denied in part.
The plaintiffs’ allegations of emotional harm are dismissed, without prejudice. The plaintiffs’
claims of negligence per se are dismissed, without prejudice, subject to this court’s later ruling on
choice-of-law issues. The plaintiffs’ claims for implied breach of contract are dismissed, without
prejudice. The plaintiffs are granted leave to amend their complaint within 14 days of the issuance
of this Memorandum and Opinion.
SIGNED on February 4, 2026, at Houston, Texas.
LW Cnt
Lee H. Rosenthal
Senior United States District Judge
30
Case-law data current through December 31, 2025. Source: CourtListener bulk data.