October 13, 2009

Data breach decision may go to Maine's high court

Judge seeks opinion on whether consumers can seek restitution for inconvenience of changing credit cards after a data breach

A federal judge in Maine is asking the state's Supreme Court to clarify whether consumers can seek restitution from merchants for the time and effort involved in changing payment cards and bank accounts after a data breach.

The case involves Hannaford Bros. which last year disclosed that unknown intruders had broken into its network and stolen data on more than 4.2 million credit and debit cards from its stores in New England, New York and Florida. The disclosure resulted in several lawsuits against the Maine-based retailer by consumers and banks seeking to recoup the costs associated with blocking and issuing new cards.

[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and newsletter, both from InfoWorld. ]

This May, U.S. District Court Judge Brock Hornby threw out almost all of the civil claims against the grocer that had been filed by consumers. The lawsuits had alleged that Hannaford had failed to protect card holder data and to notify customers of the breach in a timely fashion. In dismissing the claims, Hornby ruled that without any actual and substantial loss of money or property, consumers could not seek damages.

The only complaint he allowed to stand was from a woman who said she had not been reimbursed by her bank for fraudulent charges on her bank account after the Hannaford breach.

At the time, Hornby wrote that consumers with no fraudulent charges posted to their accounts could not seek damages under Maine law. Neither could those who might have had fraudulent charges on their accounts that were later reversed.

This week, however, Hornby reversed that decision. He asked the Law Court, the highest court in Maine, to weigh in on the question of whether the time and effort spent in mitigating the fallout from a data breach constituted a cognizable injury under Maine law.

The question stemmed from a motion filed by the plaintiffs in the case asking Hornby to reconsider his earlier ruling. In all, the plaintiffs had asked the judge to clarify four questions with the state Supreme Court. Horny dismissed three of those requests but agreed to clarify one question.

"Whether time and effort spent mitigating or averting harm from actionable conduct...is alone sufficient to recover damages is uncertain under Maine law," wrote in a 16-page ruling. As a result, the Maine Supreme Court should be given the opportunity to determine whether such damages constitute a cognizable injury under Maine law, he wrote.

The Maine Supreme Court's ruling on the matter could have a significant impact on how other courts view the same issue going forward. Most courts have tended to dismiss a vast majority of the consumer class-action lawsuits brought in the wake of a data breach involving the compromise of credit and debit card data.

In most cases, courts have held that since consumers are compensated for any loss by the card-issuing bank they have little reason to seek other damages from the breached entity. They have also tended to reject the idea that consumers must be compensated for damages that they could suffer in the future as a result of a data breach.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.