SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Standards, Regulations & LegislationColumnsSecurity & the Law

Court Decision Sheds Light on Duty to Protect Personal Information

By Lessing E. Gold, Contributing writer
Security Law
June 24, 2024

Confidentiality has now become very important in the conduct of security companies. Although the following case does not involve an alarm company, it is worth noting. In the case, the plaintiff brought a class action against a law firm alleging that it failed to safeguard their data properly, leading to a data breach that exposed their personal identifiable information (PII) and protected health information (PHI).

The plaintiffs sought injunctive relief and monetary damages arising from the firm’s alleged negligence, breach of confidence, breach of implied contract and breach of implied covenant of good faith and fair dealing.

The claim arose from a data breach that purportedly exposed the PII and the PHI of one of the plaintiffs to criminal cyber hackers. The complaint alleged that the defendant law firm failed to safeguard plaintiffs’ data properly. The defendant filed a motion to dismiss.

The plaintiff alleged that she and the other class members provided their PHI and PII to defendant law firm in order to establish attorney-client relationships. On an unspecified date, a cyberattack targeting the defendant’s network servers was purportedly launched by hackers. The attack enabled hackers to gain access to the PII and PHI of plaintiff and approximately 12,000 other individuals.

In discussing the matter, the court indicated that with respect to the injunction to prevent future harm, the plaintiff failed to allege an imminent injury sufficient to confer standing for the injunctive remedies sought. As for monetary relief, the court found that the allegation concerning the existence of actual misuse of plaintiff’s PII or that of other victims of the data breach were tenuous.

The court pointed out, however, that while the plaintiff provided little detail as to the nature of the “actual identity theft,” it would accept the facts as pled and accordingly concluded that the complaint did set forth a sufficient basis for standing with respect to plaintiff’s claims for monetary relief. 

 As to the claim for negligence, the court indicated that to establish a complaint for negligence, the plaintiff must demonstrate that the defendant owed the plaintiff a duty of reasonable care, that the defendant breached this duty, that damage resulted, and there was a causal relation between the breach of the duty and the damage.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →

The court pointed out that while plaintiff’s theory of breach is quite vague, allegations that defendant failed to encrypt plaintiff’s data effectively, store plaintiff’s data, or learn of the breach and waited for more than one month to notify plaintiff of the data breach, are sufficient to satisfy the plausibility standard.

The court further pointed out that the defendant did not substantially address the existence of a duty in its motion to dismiss. In this case, the plaintiff failed to allege a breach and cognizable damages. Therefore the court did not elaborate on the question of duty, but noted that other sessions of the court found a duty to protect PII from foreseeable cyberattacks in the data breach context.

The court therefore allowed the defendant’s motion to dismiss with respect to injunctive remedies, but otherwise denied its motion to dismiss. Consequently, the matter will go to trial.

KEYWORDS: cybersecurity identity theft

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Lessing E. Gold of Mitchell, Silberberg & Knupp is counsel to the California Alarm Association and a contributing legal columnist. He can be reached at sdm@bnpmedia.com.

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    Exclusives
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Exclusives
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Annual Industry Forecast
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings

Related Articles

  • cyber 3 responsive default

    Federal Agencies’ Cybersecurity Failures Leaving Americans’ Personal Information at Risk

    See More
  • Security Law

    No Device? No Excuse: Court Upholds Duty to Defend

    See More
  • Plaintiff’s Duty to Insure Against Loss Releases Alarm

    See More

Related Products

See More Products
  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

  • surveillance.jpg

    Surveillance, Privacy and Public Space

  • s and the law.jpg

    Surveillance and the Law: Language, Power and Privacy

See More Products

Events

View AllSubmit An Event
  • September 25, 2025

    Cloud or On-Premise: Navigating Access Control and Cybersecurity Choices

    ON DEMAND: Security technology is rapidly evolving — and so are the threats. In this webinar, we'll examine the advantages and trade-offs of cloud-based and on-premise solutions, offering clarity for integrators, consultants and end users.
View AllSubmit An Event
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing