Skip the navigation
)
News

Most claims dismissed in Hannaford data breach suit

Without damages, there's no case, judge rules

May 13, 2009 04:27 PM ET

Computerworld - All but one of the legal claims filed against Hannaford Bros. -- the Maine-based retailer that suffered a security breach exposing some four million credit and debit cards -- has been dismissed.

U.S. District Court Judge Brock Hornby threw out the civil claims against the grocer for its alleged failure to protect card holder data and to notify customers of the breach in a timely fashion. In dismissing the claims, Hornby ruled that without any actual and substantial loss of money or property, consumers could not seek damages.

The only complaint he allowed to stand was from a woman who said she had not been reimbursed by her bank for fraudulent charges on her bank account following the Hannaford breach.

In a 39-page opinion, Hornby wrote that consumers with no fraudulent charges posted to their accounts could not seek damages under Maine law; neither could those who might have had fraudulent charges on their accounts that were later reversed.

The breach at Scarborough, Maine-based Hannaford affected customers at the company's supermarkets in New England and New York, at its Sweetbay stores in Florida and at some independently owned retail stores in the Northeast that carry Hannaford products. The intrusion began in late 2007 but was not discovered until March 2008 when it was publicly disclosed.

The company was hit with class-action lawsuits from multiple states that were consolidated into one suit last summer. The complaints included breach of implied contract, breach of implied warranty, negligence and violation of Maine's Unfair Trade Practices Act.

Hornby said three of the claims against Hannaford were valid under current Maine law. When a person uses a debit or a credit card in a grocery transaction, Hannaford should use reasonable care in protecting the card data, he wrote in the decision. Similarly, Hannaford's apparent delay in disclosing the data breach constituted an unfair trade practice under Maine law, he said.

"A jury could find that, if Hannaford had disclosed the security breach immediately upon learning of it from Visa, customers would not have purchased groceries at its stores with plastic," till the problem was fixed, he said.

Peter Murray, lead counsel for the plaintiffs and a partner at Murray, Plumb & Murray, in Portland, Maine, said no decision has been made on how to proceed. One option would be to pursue the lawsuit on behalf of individuals whose fraudulent charges may not have been reversed he said. Another would be to appeal the decision.

From a legal standpoint, it shouldn't matter whether the fraudulent charges were reversed, or whether it cost money for someone to reinstate previously authorized credit or account numbers, Murray said. "We believe that they have all suffered actual damage," he said. "We don't believe there is any legal distinction between the ways fraudulent charges impacted the consumer."

The Hannaford opinion is similar to < href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=Security&articleId=9032778">several others involving data breaches in recent years. In August 2007, the U.S. Court of Appeals for the Seventh Circuit threw out a a proposed class-action lawsuit against Evansville, Ind.-based Old National Bancorp (ONB) involving a 2005 data-breach incident.

In June 2007, a U.S. District Court judge in Ohio dismissed class-action claims against Litton Loan Servicing LP over a breach involving personal data. In that case, the judge said that without actual identity theft occurring, the plaintiffs suffered only anticipated injury and therefore did not need to be compensated. In 2005, a federal judge threw out a lawsuit against TriWest Healthcare Alliance in Phoenix saying it was unclear whether any of the 500,000 records that were stolen had actually been accessed or used by thieves.

Read more about DRM and Legal Issues in Computerworld's DRM and Legal Issues Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

DRM and Legal Issues White Papers
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Establishing a Strategy for Database Security is No Longer Optional
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
All DRM and Legal Issues White Papers
DRM and Legal Issues Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
All DRM and Legal Issues Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs