Summary
The United States District Court for the Western District of Missouri considers Mid America Physician Services, LLC’s Rule 12(b)(6) motion to dismiss a putative class action arising from a November 2024 data breach. The court grants the motion in part, dismissing without prejudice claims for negligence, negligence per se, invasion of privacy, breach of fiduciary duty, and violation of the Missouri Merchandising Practices Act. Claims for breach of implied contract, unjust enrichment, and declaratory and injunctive relief remain.
Topics
Practice areas
Questions Presented
- Whether plaintiffs plausibly pleaded a Missouri negligence claim based on MAPS's alleged failure to safeguard information from a third-party cyberattack.
- Whether alleged violations of Section 5 of the FTC Act and HIPAA could support a Missouri negligence per se claim.
- Whether plaintiffs plausibly pleaded formation and breach of an implied contract requiring MAPS to safeguard their private information.
- Whether plaintiffs plausibly pleaded unjust enrichment under a cost-savings theory.
- Whether plaintiffs plausibly pleaded invasion of privacy and breach of fiduciary duty claims arising from the data breach.
- Whether plaintiffs stated a claim under the Missouri Merchandising Practices Act based on MAPS's collection and alleged failure to protect private information.
- Whether plaintiffs could maintain a claim for declaratory and injunctive relief while substantive claims remained.
Holdings
- Under Missouri law, a generalized threat environment of cyber-hacking and data breaches, without additional facts showing that the particular attack was foreseeable to MAPS, does not establish a common-law duty for a medical provider to protect patient information from criminal acts of third parties. Plaintiffs therefore failed to state a negligence claim.
- Alleged violations of HIPAA and Section 5 of the FTC Act cannot support a Missouri negligence per se claim because neither statute provides a private cause of action.
- Plaintiffs plausibly pleaded a breach-of-implied-contract claim by alleging that MAPS received their confidential information as a condition of providing medical services, impliedly promised confidentiality and reasonable protection, and failed to implement specific security measures.
- Plaintiffs plausibly pleaded unjust enrichment under a cost-savings theory by alleging that they paid for medical services, a portion of which was intended to fund reasonable data security, and that MAPS retained savings from using allegedly inadequate security measures.
- Although Missouri recognizes a physician-patient fiduciary duty of confidentiality, plaintiffs failed to state a breach-of-fiduciary-duty claim because they did not allege that MAPS disclosed their private information to unauthorized third parties.
- Plaintiffs failed to state a Missouri Merchandising Practices Act claim because MAPS sold medical services, not data-security services, and plaintiffs did not establish the required relationship between the alleged unlawful conduct and the sale of merchandise.
- The claim for declaratory and injunctive relief was not dismissed because plaintiffs retained substantive claims for breach of implied contract and unjust enrichment.
Key quotations
“To survive a motion to dismiss pursuant to rule 12(b)(6) of the Federal Rules of Civil Procedure, “a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim for relief that is plausible on its face.’”” (Legal Standard)
“The Court is persuaded that the Missouri Supreme Court would not recognize a general or “data privacy” duty of care for the reasons explained by the Seventh Circuit in Community Bank of Trenton” (Discussion § I)
“The Court is persuaded that Plaintiffs allege more than what had been alleged in Kuhns.” (Discussion § III)
Factual background
MAPS, a Kansas-based medical provider serving patients from Kansas and Missouri, collected and stored plaintiffs' medical, personal, financial, Social Security, and health-insurance information as part of providing medical services. MAPS discovered a network incident or data breach on or about November 14, 2024, completed its investigation in early May 2025, and notified affected individuals in July 2025. Plaintiffs alleged risks of fraud and identity theft, monitoring and mitigation expenses, loss of privacy, credit damage, and other injuries, asserting that MAPS failed to implement adequate cybersecurity safeguards.
Procedural history
Plaintiffs filed a putative class action asserting eight claims arising from a November 2024 data breach involving medical, personal, financial, and health-insurance information. The Court considered MAPS's motion to dismiss the Second Amended Complaint and granted it in part and denied it in part. Counts 1, 2, 5, 6, and 7 were dismissed without prejudice; Counts 3, 4, and 8 remained.