Citations

Full opinion text

DECISION AND ORDER

ELIZABETH A. WOLFORD, United States District Judge

INTRODUCTION

Those who are entrusted with details about an individual’s health care should guard against even the inadvertent disclosure of that confidential information. Those duties were allegedly breached in this case when hackers secured access to confidential health care information through a cyberattack. Nonetheless, while legal remedies may be pursued by those who were injured, the law only allows for the pursuit of plausible claims — and only by those who have standing based on an alleged legally compensable injury. Not all parties or all claims in this case meet that standard.

This case arises out of a data breach involving Excellus Health Plan, Inc. (“Ex-cellus”), a healthcare provider. Plaintiffs, who allege various claims and injuries arising from the data breach, bring this putative class action against the following eight defendants: Excellus, Lifetime Healthcare, Inc. (“Lifetime”), Lifetime Benefit Solutions, Inc., Genesee Region Home Care Association, Inc. d/b/a Lifetime Care, Genesee Valley Group Health Association d/b/a Lifetime Health Medical Group, Me-dAmerica, Inc., Univera Healthcare, and Blue Cross and Blue Shield Association (“BCBSA”). In their Consolidated Master Complaint (“CMC”), Plaintiffs assert claims under various federal and state laws and seek, inter alia, class certification, injunctive relief, and damages. (Dkt. 99).

Presently before the Court are two motions to dismiss Plaintiffs’ CMC. (Dkt. 107; Dkt. 111). The Exeellus Defendants and BCBSA — i.e., all Defendants — move to dismiss the CMC pursuant to Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6), on the basis that the Court lacks jurisdiction because Plaintiffs lack standing to sue, , and that Plaintiffs have failed to state a claim. (Dkt. 107-1 (“Exeellus Mot.”)); (Dkt. 111-1 (“BCBSA Mot.)). For the reasons that follow, the Court grants'in part and denies in part both motions.

BACKGROUND

I. Factual Background

The following factual allegations are drawn from Plaintiffs’ CMC.

A. The Parties

Exeellus is “the primary healthcare provider in Upstate New York” and a licensee of BCBSA. (CMC at ¶ 37). Exeellus is a subsidiary of Lifetime and a parent company to all other defendants, except Lifetime and BCBSA. (Id. at ¶ 40). Lifetime is “the parent and/or holding company of a $6.6 billion family of companies, known as the Lifetime Healthcare Companies, that finances and delivers health care in New York State, as well as long-term care nationwide.” (Id. at ¶ 42). The following five defendants are affiliate companies of the Lifetime Healthcare Companies, and they are owned and controlled by Lifetime and Exeellus: (1) Lifetime Benefit Solutions, Inc.; (2) Genesee Region Home Care Association, Inc. d/b/a Lifetime Care; (3) Genesee Valley Group Health Association d/b/a Lifetime Health Medical Group; (4) MedAmerica, Inc.; and (5) Univera Healthcare. (Id. at ¶¶ 45-49). The final defendant, BCBSA, “is a federation of 36 health insurance organizations and companies that provides health insurance to over 106 million individuals.” (Id. at ¶ 50). Ex-cellus “cooperates with BCBSA and other independent Blue Cross Blue Shield ... licensees to participate in the BlueCard program. Under the BlueCard program, members of one BCBS licensee may access another BCBS licensee’s provider networks and discounts.” (Id. at ¶ 55). .

Plaintiffs allege three different types of classes. First, Plaintiffs allege “separate statewide classes for the states of California, Florida, Indiana, North Carolina, New Jersey, New York, and Pennsylvania,” defined as “[a]ll citizens of [name of state] whose [personally identifiable information (“PII”)] or [protected health information (“PHI”) ] was compromised by the Excel-lus data breach” (“Statewide Classes”). (Id. at 64). Second, Plaintiffs allege a federal employee class, defined as “[a]ll en-rollees in the Federal Employee Health Benefits Plan whose Personal Information was compromised by the Exeellus data breach” (“Federal Employee Class”). (Id. at 65). Third, Plaintiffs allege a healthcare provider class, defined as “[a]ll healthcare providers and/or medical professionals who submitted PII directly or indirectly to Defendants and whose PII was compromised by the Exeellus data breach” (“Healthcare Provider Class”). (Id. at 66).

B. The Data Breach

On December 23; 2013, hackers gained access to Excellus’s computer network systems, which stored the personal information belonging to millions of individuals. (Id. at ¶¶ 52, 131, 133). During this data breach, the hackers had access to individuals’ names, dates of birth, social security numbers, mailing addresses, telephone numbers, member identification numbers, financial payment information (including credit card numbers), and medical insurance claims information. (Id, at ¶¶ 1-3, 52, 134). The hackers also had access to healthcare providers’ personal information, including medical licenses. (Id. at ¶ 135). The breach continued for 20 months, until at least August 18, 2014; however, the hackers may have had access to the'systems more recently, on May 11, 2015. (Id. at ¶ 133). :

“In the wake of- other high-profile healthcare data breaches ..., Defendants hired cyberseeurity company Mandiant to forensically assess their systems.” (Id. at ¶ 132). On August-4, 2015, Mandiant’s analysis revealed malware on Defendants’ systems. (Id.) On September 9, 2015, Defendants publicly announced that the breach-had occurred and that it affected 10 to 10.5 million people, including past and current Excellus policyholders, - as well as. those who are insured by or receive healthcare services from' Defendants’ affiliates. (Id. at ¶ 138), According to that announcement, Mandiant’s investigation did hot determine that any personal information was removed from Excellus’s systems, and Excel-lus had no evidence that the personal information was used inappropriately.- (Dkt. 107-3, Ex. A). Defendants offered two years of free credit monitoring to adult victims of the breach. (CMC at ¶ 138).

Plaintiffs allege that Defendants had reason to know that their data security was inadequate both before the data breach started and after it was discovered by Defendants. (Id. at ¶¶ 114, 120). For example, in May 2012, the Department of Health and Human Services’ Office for Civil Rights hired KPMG to conduct an audit of Univera (a Defendant and Lifetime affiliate company) in order to review its compliance with the Privacy, Security, and Breach Notification Rules of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)- (Id. at ¶ 115). The audit revealed, inter alia, that Univera’s “Risk Assessment Policies & Procedures failed to identify the risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI.” (Id. at ¶ 117). As another example, in April 2014, the FBI Cyber Division “issued a ‘Private Industry Notification’ that explained how ‘the health care industry is not technically prepared to combat against cyber criminals’ basic cyber intrusion tactics, techniques and procedures (TTPs), much less against more advanced persistent threats (APTs). The health care industry is not as resilient to cyber intrusions compared to-the financial and retail sectors, therefore the possibility of increased cyber intrusions is likely.’ ” (Id. at ¶ 123). This information, along with other data breaches in the health care industry, allegedly “put Defendants on notice that healthcare and health insurance companies were a target of cyberattack, and that these companies had an obligation to implement reasonable safeguards to - keep pace. Defendants, quite simply, failed to heed the clear and unequivocal warning.” (Id at 129).'

C. Plaintiffs’ Alleged Injuries

Plaintiffs allege that the data breach caused them various types of injuries, both present and future. The following present injuries from the breach are alleged in the CMC. Four plaintiffs allege that false tax returns were filed in their names using their personal information, or that their personal information was accessed through the IRS portal. (Id. at ¶¶ 12,19-20,24,29). Three plaintiffs allege that they- are the victims of identity theft. (Id. at ¶¶ 18, 21, 22), Twelve plaintiffs have experienced fraudulent credit or debit card charges. (Id. at ¶¶ 21-28, 31-32, 34-35). Five plaintiffs allege that they'spent money in order to remediate the breach or protect from future identity theft; this included purchasing additional credit monitoring services. (Id. at ¶¶ 20-23, 34). Three plaintiffs had delays in the receipt of their tax returns. (Id. at ¶¶ 19-20, 29). All plaintiffs spent time and effort to freeze their credit, place fraud alerts on their accounts, monitor credit reports and bank statements, and/or report identity theft to the relevant authorities. (Id. at ¶¶ 17-35). All plaintiffs allege anxiety and fear of identity theft as a result of the data breach. (Id. at ¶ 12). Plaintiffs also allege a risk of future, certainly impending harm as a result of the breach. (See, e.g., id. at ¶¶ 13,19-35).

The Excellus Defendants differentiate the alleged injuries on the basis that four plaintiffs do not allege any specific instances in which their personal information was misused (id. at ¶¶ 17, 30, 33, 36), while the remaining sixteen plaintiffs allege some type of misuse of their personal information (id. at ¶¶ 18-29, 31-32, 34-35),

D. Plaintiffs’ Causes of Action

Based on their factual allegations, Plaintiffs allege ten causes of action, as follows: (1) negligence; (2) negligence per se\ (3) breach of contract; (4) breach of the implied covenant of good faith and fair dealing; (5) third-party beneficiary breach of contract for the Federal Employee Class; (6) negligent misrepresentation;- (7) unjust enrichment; (8) violations of state consumer protection laws; (9) violation of the California Customer Records Act, Cal. Civ. Code § 1798.80;- and- (10) violations of state insurance personal privacy statutes.

II. Procedural History

Following the data breach, several potential victims filed lawsuits alleging various resulting, injuries. (Dkt. 9-2 at 3). The earliest of such lawsuits was filed on September 18, 2015. (Dkt. 1). On November 5, 2015, the Court issued an order consolidating additional lawsuits, pursuant to Federal Rule of Civil Procedure 42(a)(2), and transferred the case to the undersigned. (Dkt. 27 at 4-5). On November 10, 2015, the, Court entered an order directing that any subsequently-filed lawsuit arising out of the same facts or involving the same claims be consolidated into the lead action. (Dkt. 28). On January 25, 2016, the Court appointed interim lead counsel and directed Plaintiffs to file a consolidated master complaint. (Dkt. 80).

On April 15, 2016, Plaintiffs — twenty in all, from seven different states — filed the CMC. (Dkt. 99). On May 3Í, 2016, the Excellus Defendants filed a motion to dismiss. (Dkt. 107). On June 17, 2016, BCBSA filed a motion to dismiss. (Dkt. 111). Plaintiffs responded in opposition to the Excel-lus Defendants’ motion to dismiss on July 7, 2016 (Dkt. 122-3 (“PI. Excellus Opp.”)), and to BCBSA’s motion to dismiss on July 14, 2016 (Dkt. 129 (“PI. BCBSA Opp.”)). On’ August 8, 2016, the Excellus Defend dants and BCBSA each filed a reply in further support of their respective motions to dismiss. (Dkt. 133 (“Excellus Reply”); Dkt. 134 (“BCBSA Reply”)). Oral argument was held before the undersigned on September 8, 2016, at which time the Court reserved decision. (Dkt. 139).

MOTION TO DISMISS FOR LACK OF STANDING

The Court first considers the issue of standing. The Excellus Defendants raise two sets of standing arguments. First, the Exeellus Defendants argue that those Plaintiffs “who do not allege that they have suffered any misuse of their personally identifiable information” — the “non-misuse” Plaintiffs — have not alleged injury-in-fact. (Exeellus Mot. at 5-9). Second, 'the Exeellus Defendants argue that the “misuse” Plaintiffs have not alleged facts establishing that their injuries are fairly traceable to the Exeellus cyberattack. (Id. at 9-12). BCBSA incorporates the Exeellus Defendants’ argument that Plaintiff Nina Mottern (the sole named Plaintiff in the Federal Employee class (CMC at ¶ 23)) has not pleaded injury in fact, and it additionally argues that Mottem’s allegation that she experienced fraudulent charges on her credit card is not fairly traceable to the Exeellus cyberattack. (BCBSA Mot. at 17 (quoting CMC at IT 23)).

I. Fed. R. Civ. P. 12(b)(1)

“A case is properly dismissed for lack of subject matter jurisdiction under Rule 12(b)(1) when the district court lacks the statutory or constitutional power to adjudicate it.” Makarova v. United States, 201 F.3d 110, 113 (2d Cir. 2000). To survive a motion to dismiss under Rule 12(b)(1), Plaintiffs must establish subject matter jurisdiction. Id. “A plaintiff asserting subject matter jurisdiction has the burden of proving by a preponderance of the evidence that it exists.” Id. “In resolving a motion to dismiss for lack of subject matter jurisdiction under Rule 12(b)(1), a district court ... may refer to evidence outside the pleadings.” Id.

II. General Principles of Article III Standing

“Article III of the Constitution limits federal courts’ jurisdiction to certain ‘Cases’ and ‘Controversies.’” Clapper v. Amnesty Int’l USA, 133 U.S. 1138, 133 S.Ct. 1138, 1146, 185 L.Ed.2d 264 (2013). One aspect of this case-or-controversy requirement “is that plaintiffs must establish that they have standing to sue.” Id. (quotation omitted). “The party invoking federal jurisdiction bears the burden of establishing standing.” Id. at 1148 (quotation omitted).

[T]he irreducible constitutional minimum of standing contains three elements. First, the plaintiff must have suffered an “injury in fact” — an invasion of a legally protected interest which is (a) concrete and particularized ... and (b) actual or imminent, not conjectural or hypothetical .... Second, there must be a causal connection between the injury and the conduct complained of — the injury has to be fairly ... traceable to the challenged action of the defendant, and riot ... the result of the independent action of some third party not before the court .... Third, it must be likely, as opposed to merely speculative, that the injury will be' redressed by a favorable decision.

Lujan v. Defs. of Wildlife, 504 U.S. 555, 560-61, 112 S.Ct. 2130, 119 L.Ed.2d 351 (1992) (internal quotation marks, citations, and brackets omitted).

In a class action, the Court considers the injuries of the named plaintiffs, not unnamed class members. That is, class action plaintiffs “must allege and show that they personally have been injured, not that injury has been suffered by other, unidentified members of the class to which they belong and which they purport to represent.” Warth v. Seldin, 422 U.S. 490, 502, 95 S.Ct. 2197, 45 L.Ed.2d 343 (1975). “[I]f none of the named plaintiffs purporting to represent a. class establishes the requisite of a case or controversy with the defendants, none may seek relief on behalf of himself or any other member of the class.” O’Shea v. Littleton, 414 U.S. 488, 494, 94 S.Ct. 669, 88 L.Ed.2d 674 (1974).

III. Injury in Fact

As discussed, the first standing element is injury in fact. An injury in fact is “an invasion of a legally protected interest which is- (a) concrete and particularized and (b) actual or imminent, not conjectural or hypothetical.” Lujan, 504 U.S. at 560, 112 S.Ct. 2130 (citations and internal quotation marks omitted).

The Excellus Defendants argue that Plaintiffs who have not alleged any actual misuse of their data — the so-called “non-misuse” Plaintiffs: Matthew Fero, Dwayne Church, Therese Boomershine, and Brenda Caltagarone — have not alleged an injury in fact. (Excellus Mot. - at 5-9). The Excellus Defendants argue that the following alleged injuries are insufficient for standing: increased risk of identity theft, mitigation efforts, overpayment for insurance, and violation of state statutes. (Id.).

Plaintiffs argue that they each have alleged an injury-in-fact sufficient to support Article III standing. (PI. Excellus Opp. at 4-13). Without differentiating, as the Ex-cellus Defendants do, between those who have suffered misuse and those who have not, Plaintiffs claim that they have standing based on alleged present injuries caused by the breach: they have suffered from fraudulent tax returns; unauthorized access to tax information; identity theft; and fraudulent credit or debit charges. (Id. at 7). Some Plaintiffs allege “monetary impacts,” such as spending money to remediate or protect from fraudulent activity and experiencing delays in receipt of federal tax returns; Plaintiffs contend that those monetary, impacts constitute injury-in-fact. (Id.). And, Plaintiffs argue that spending time to deal with the consequences of the breach — including acts such as freezing or monitoring credit and bank statements, reporting identity theft; and completing police reports — also constitutes injury in fact. (Id. at 7-8). All Plaintiffs allege that the breach caused them to suffer anxiety and fear, which, according to them, constitutes injury-in-fact. (Id. at 8).

A. CMC’s Allegations Regarding The Non-Misuse Plaintiffs

The CMC alleges that Fero, a citizen of New York, received a letter from Excellus notifying him that his PII and PHI, along with the PII and PHI of his wife and two children, may have been compromised in the data breach. (CMC at ¶ 17). He subsequently enrolled himself and his wife in the two-year credit monitoring service offered through Kroll, although he could not enroll his minor children. (Id.). The CMC further alleges that, “[a]s a result of the data breach, the Personal Information of Mr. Fero arid his family has been compromised, and he has spent time attempting to ensure that his family is protected from future acts of identity theft or fraud stemming from this data breach.” (Id.).

The CMC alleges that Church, a citizen of California, received a letter from Excel-lus notifying him that his PII and PHI may have been compromised in the data breach. (Id. at ¶30). He then enrolled in Kroll’s two-year credit monitoring service and ordered a copy of his most recent credit report. (Id.). The CMC alleges that, “[a]s a result of the data breaeh, Mr. Church’s Personal Information ■ has been compromised, and he has been forced to spend time attempting to .protect himself from future incidents of identity theft and fraud.” (Id.).

The CMC alleges that Boomershine, a citizen of Indiana, received a letter from Lifetime Healthcare Companies notifying her that her PII and PHI may have been compromised in the data breach. (Id. at ¶33). She subsequently (1) enrolled in Kroll’s two-year credit monitoring service; (2) implemented credit freézes • with the three major reporting bureaus; (3) ordered copies of her most recent credit report; (4) filed a police report with the Roanoke Police Department; (5) filed an identity theft report with the FTC; and (6) purchased additional credit monitoring services through Credit Karma. (Id.). The CMC further alleges that her “Personal Information has been compromised, and she has spent significant time attempting to protect herself from identity theft and fraud.” (Id.).

The CMC alleges that Caltagarone, a citizen of Pennsylvania, “is unsure how or why her information was compromised in the Excellus data breach, but she believes her employer, Cenclear, obtains services from one of the Defendants.” (Id. at ¶ 36). She received a letter from Lifetime Healthcare Companies notifying her that her PII and PHI may have been compromised in the data breach. (Id.). The CMC also alleges that her “Personal Information has been compromised” as a result of the data breach. (Id.).

B. Increased Risk of Future Identity Theft

1. Parties’ Arguments

The Excellus Defendants argue that the four non-misuse Plaintiffs’ allegations that they suffer an “imminent and certain impending injury flowing from fraud and identity theft posed by their PII and PHI being placed in the hands of unknown third parties,” (CMC at ¶ 167(e)), is conclu-sory and not “certainly impending,” as required to meet the standard for risk of future harm to support Article III standing. (Excellus Mot; at 5). The Excellus Defendants argue that the fact that other Plaintiffs have alleged misuse of their personal information does not elevate the non-misuse Plaintiffs’ risk of harm to the ■ level of “certainly impending.” (Id. at 6).'

Plaintiffs argue that they ,have standing based on “a real risk,of future, certainly impending harm,. and/or the substantial risk that harm will occur as a result of this breach,” which is sufficient to support Article III standing. (PI. Excellus Opp. at 8). Plaintiffs, point to decisions by “several courts of appeals [that] , have determined the substantial risks of future harm posed by a data breach that compromises PII constitutes injury in fact .’’.(Id. at 9). Plaintiffs further assert that the cases on which Defendants rely in support of their argument that Plaintiffs’ risk of harm is not ■“certainly impending” are distinguishable. (Id. at 11-12).

2. Discussion

In 2013, the Supreme Court considered whether future injury satisfies the injury-in-fact requirement for standing in Clapper, a case in which the plaintiffs— consisting of attorneys and human rights, labor, legal, and media organizations— challenged the constitutionality of government surveillance of suspected terrorists under the Foreign Intelligence Surveillance Act. Clapper, 133 S.Ct. at 1145-46. The Supreme Court ruled that “[tjhreatened injury must be certainly impending to constitute injury in fact, and allegations of possible future injury are not sufficient.” Id. at 1147 (brackets, emphasis, and quotation marks omitted). Applying that rule, the Supreme Court concluded that the plaintiffs’ “theory of future injury [wa]s too speculative to satisfy the well-established requirement that threatened injury must be ‘certainly impending,’ ” id. at 1143; that is, the theory of standing “relie[d] bn a highly attenuated chain of possibilities” and was only “speculative whether the Government [would] imminently target communications to which [the plaintiffs-were] parties,” id. at 1148. Yet the Supreme Court also stated in a footnote that it has not always required “plaintiffs to demonstrate that it is literally certain that the harms they identify" will Come about.” Id. at 1150 n.5. The Supreme Court explained that it has, in some instances, found “standing based on a ‘substantial risk’ that the harm will occur, which may prompt plaintiffs to reasonably incur costs to mitigate or avoid that harm.” Id.; see also Spokeo, Inc. v. Robins, — U.S —, 136 S.Ct. 1540, 1549, 194 L.Ed.2d 635 (2016) (citing Clapper for the proposition that “the risk of real harm” may “satisfy the requirement of concreteness” for. the injury in fact requirement).

Before and after Clapper, courts have split over whether increased risk of identity theft is sufficient for standing' in a data breach case. The Second Circuit has hot yet addressed the issue, although it is poised to do so. See Whalen v. Michael Stores, Inc., 153 F.Supp.3d 577, 579 n.2 (E.D.N.Y. 2015), appeal docketed, 2d Cir. 16-260, 16-352., Other circuit courts to have considered the issue have reached different results: the Sixth, Seventh, and Ninth Circuits have found standing based on increased risk of identity theft, while the Third and Fourth Circuits have found such injury too speculative to warrant standing.

Before Clapper, in Krottner v. Starbucks Corp., 628 F.3d 1139 (9th Cir. 2010), the Ninth Circuit found that data breach victims had standing based bn increased risk of identity theft. Id. at ’1143-43. In that case, a laptop containing the names, addresses,' and' social security numbers of 97,000 Starbucks employees was stolen. Id. at 1140. .Starbucks notified those employees of the theft ahd offered credit monitoring services, even though there had been “no indication-that the private information ha[d] been misused.” Id. at 1140-41. One named plaintiff alleged that someone used his Social Security number to attempt to open a bank account following the theft of the laptop. Id. at 1141. The Ninth Circuit, noting that “the. possibility of future injury may be sufficient to confer standing on plaintiffs,” held that the increased risk of identity theft was an injury in fact because the plaintiffs had alleged “a credible threat of real and immediate harm stemming from the theft of the laptop.” Id. at 1142-43. - - ■ • • ■

In another pre-Clapper decision, Reilly v. Ceridian Corp., 664 F.3d 38 (3d Cir. 2011), the Third Circuit reached a different result, holding that plaintiffs’ alleged injuries from increased risk of identity theft were insufficient'for standing. Id. át 43. In that case, hackers “potentially gained access” to personal information belonging to 27,000 people that was stored on a'computer system of a payroll processing company, but “whether the hacker, read, copied, or understood” the personal information-was unclear. Id. at 40, The Third Circuit reasoned that the plaintiffs — victims of- that data breach — would have injuries only “if the hacker, read, copied, and understood the hacked information, and if the hacker attempts to use the information, and if he does so successfully.” Id. at 43 (emphasis in original). The Third Circuit distinguished Starbucks Corpit reasoned that the threatened harms were more imminent than in the case before it, where there was “no evidence that the intrusion was intentional or malicious. [The plaintiffs] ha[d] alleged no misuse, and therefore, no injury. Indeed, no identifiable taking occurred; ■all that is known is that'a firewall was penetrated.” Id. at 44.

After Clapper, the Fourth Circuit concluded that the plaintiffs’ alleged injury of increased risk of identity theft was too speculative to constitute an injury-in-fact. Beck v. McDonald, 848 F.3d 262, 273-74 (4th Cir.2017). In Beck, two cases were consolidated for appeal; one case arose out of the theft of a laptop containing unencrypted personal information, while the other arose out of the theft of four boxes -of pathology reports containing personal information. Id. at 266-69. The Fourth Circuit concluded that plaintiffs’ allegations of standing based on threatened injury of future identity theft was too speculative to constitute an injury-in-fact, reasoning that the plaintiffs had made no claim either that the data thief intentionally targeted the personal information or that any instances of misuse had occurred as a result of the da,ta breach. Id. at 273-75. The Fourth Circuit also reasoned that, even after discovery, no evidence demonstrated that the plaintiffs’ information has been misused or that they have suffered identity theft. Id. at 274-75.

Both before and after Clapper, the Seventh Circuit has concluded that risk of identity theft is sufficient for standing. In a pre-Clapper case, Pisciotta v. Old National Bancorp, 499 F.3d 629 (7th Cir. 2007), the plaintiffs had brought a class action against a bank, alleging that it failed to adequately secure their personal information, and as a result, a hacker stole that information. Id. at 631. The Seventh Circuit concluded that “the injury-in-fact requirement can be satisfied by a threat of future harm or by an act which harms the plaintiff only by increasing the risk of future harm that the plaintiff would have otherwise faced, absent the defendant’s actions.” Id. at 634 & n.3.

Post-Clapper, the Seventh Circuit found that risk‘of identity theft is sufficient for standing in two data breach cases. The first was Remijas v. Neiman Marcus Group, LLC, 794 F.3d 688 (7th Cir. 2015). That case arose from a data breach in which hackers used malware to collect data associated with 350,000 Neiman Marcus store credit cards. In the months after the data breach, more than 9,200 customers found fraudulent charges on their Neiman Marcus credit cards. Id. at 690. The complaint alleged that the hackers had actually stolen and misused the store credit card data; as a result, the Seventh Circuit concluded that “the Neiman Marcus customers, should not have to wait until hackers commit identity theft or credit-card fraud in order to give the class standing, because there is an ‘objectively reasonable likelihood’ that such an injury will occur.” Id. at 693. The Seventh Circuit explained:

At this stage in the litigation, it is plausible to infer that the plaintiffs have shown a substantial risk of harm from the Neiman Marcus data breach. Why else would hackers break into a store’s database and steal consumers’ private information? Presumably, the purpose of the hack is, sooner or later, to make fraudulent charges or assume those consumers’ identities.

Id. Thus, the Seventh Circuit found injuries sufficient for standing based on future injuries — the increased risk of fraudulent charges and the increased risk of identity theft — as well as the time and money spent resolving fraudulent charges and in protecting against future charges. Id. at 691-94.

The séeond postr-Clapper case was Lewert v. P.F. Chang’s China Bistro, Inc., 819 F.3d 963 (7th Cir. 2016), in which the Seventh Circuit followed Remijas.- There, the Seventh Circuit found that customers of P.F. Chang’s restaurant whose credit and debit card data had been stolen in a data breach had “the same kind of future injuries as the Remijas plaintiffs did: the increased risk of fraudulent charges and identity theft they face[d] because their data ha[d] already been stolen.” Id. at 967. The Seventh Circuit stated that whether the plaintiffs’ data was exposed in the breach — something that P.F Chang’s disputed — was immaterial at the pleading stage. Id. at 968.

In Galaria v. Nationwide Mutual Insurance Co., 663 Fed.Appx. 384 (6th Cir. 2016), the Sixth Circuit found post-(tapper that plaintiffs had standing in a case arising out of the theft of their personal information from the computer network of Nationwide Mutual Insurance Company. Id. at 386-86; The Sixth Circuit held that the plaintiffs’ allegations that “the theft of their personal data places them at a continuing, increasing risk of fraud and identity theft” were sufficient for standing at the pleading stage of the litigation. Id. at 388. The Sixth Circuit reasoned that speculation about the possibility of future injury was unnecessary when the data had already been stolen and was in the possession of criminals:

Indeed, Nationwide seems to recognize the severity of the risk, given its offer to provide credit-monitoring and identity-theft protection for a full year. Where a data breach targets personal information, a reasonable inference can be drawn that the hackers will use the victims’ data for the fraudulent' purposes alleged in [pjlaintiffs’ complaints.

Id. at 388. The Sixth Circuit distinguished the Third Circuit’s decision in Reilly on the grounds that, unlike in that case, the plaintiffs had alleged an “identifiable taking,” that is, the intentional theft of their data. Id.' at 389-90. On that point, the Court stated that at the pleading stage, it was required to “accept as true [pjlaintiffs’ allegations about the nature of the breach and the data stolen, and construe the complaints in [pjlaintiffs’ favor.” Id. at 389-90 n.3.

Like circuit courts, district courts have also reached different conclusions regarding standing based on increased risk of identity theft. One case, on which the Ex-cellus Defendants rely, is In re Science Applications International Corp. (SAIC) Backup Tape Data Theft Litigation, 45 F.Supp.3d 14 (D.D.C. 2014). That case arose out of the theft of data tapes containing personal information of military members and their families. Id. at 20. Most plaintiffs alleged injury based on increased risk of identity theft alone; some of those plaintiffs additionally alleged injury based on the time or money spent monitoring their credit or communicating with banks regarding the theft. Id. at 21. The In re SAIC court, relying on Reilly, concluded that neither the increased risk of identity theft, nor the costs of credit monitoring or other preventative measures, constituted an injury in fact for standing purposes. Id. at 26-28.

Like In re SAIC, other district courts have found no standing and “dismiss[edj suits where the plaintiffs, even where they alleged that their personal data had been stolen or accessed, did not allege actual misuse of the data.” Khan v. Children’s Nat’l Health Sys., 188 F.Supp.3d. 524, 531 (D. Md. 2016); see In re Zappos.com, Inc., 108 F.Supp.3d 949, 958-59 (D. Nev. 2015) (finding no standing where last four digits of customers’ credit card were stolen, but plaintiffs had not alleged any unauthorized purchases or other misuse); Whalen, 153 F.Supp.3d at 583 (finding no standing based on increased risk of future harm where plaintiff alleged that “fraudulent use of cards might not- be apparent for years” and did not allege any out of pocket costs resulting from data breach); see also In re SuperValu, Inc., No. 14-MD-2586 ADM/ TNL, 2016 WL 81792, at *5 (D. Minn. Jan. 7, 2016) (finding that an allegation of a single unauthorized charge on a credit card.in the almost a year and a half following a data breach was not traceable to the breach and did not support an inference that the plaintiffs’ credit card information was at substantial risk of misuse because of the breach), appeal docketed, 8th Cir. 16-2528; Peters v. St. Joseph Servs. Corp., 74 F.Supp.3d 847, 854 (S.D. Tex. 2015) (finding injury based on increased risk of future identity theft too speculative because plaintiff “cannot describe how she will be injured without beginning the explanation with the word ‘if’ (quotation and alterations omitted)).

By contrast, in cases where district courts have found standing, the plaintiffs set forth “allegations indicating that some of the stolen data had already been misused, that there was a clear intent to use the plaintiffs’ personal data for fraudulent purposes, or both.” Khan, 188 F.Supp.3d at 531; see Welborn v. Internal Revenue Serv., No. CV 15-1352 (RMC), 218 F.Supp.3d 64, 77, 2016 WL 6495399, at *7 (D.D.C. Nov. 2, 2016) (finding that plaintiffs who alleged that “they ha[d] suffered actual identity theft when someone filed false tax returns (and claimed fraudulent, refunds) in their names” .sufficiently pleaded injury-in-fact, whereas “allegations that they face[d] an increased risk of future harm [did] not satisfy Article III”), appeal docketed, D.C. Cir. 16-5365; In re Target Corp. Data Sec. Breach Litig., 66 F.Supp.3d 1154, 1157-59 (D. Minn. 2014) (finding standing based on “unlawful charges, restricted or blocked access to bank accounts, inability to pay other bills, and late payment charges or new card fees” suffered by the,, plaintiffs in case arising out of theft, of credit and debit card and personal information belonging to Target customers); In re Adobe Sys., Inc. Privacy Litig. (Adobe), 66 F.Supp.3d 1197, 1214-16 (N.D. Cal. 2014) (finding standing where hackers deliberately targeted Adobe’s servers to steal the plaintiffs’ credit card information and posted some of the stolen data on websites used by hackers); In re Sony Gaming Networks & Customer Data Sec. Breach Litig., 996 F.Supp.2d 942, 955-58, 962-63 (S.D. Cal. 2014) (finding “allegations that [the plaintiffs’] Personal Information was collected by Sony and then wrongfully disclosed as a result of the intrusion sufficient to establish Article III standing”).

In Khan, 188 F.Supp.3d at 531, the district court rationalized the different outcomes, finding the differences could be explained not because courts had applied different, legal standards, but rather because of variations in the factual circumstances: ,

In the absence of specific incidents of the use of stolen data for identity fraud purposes, district courts have generally found that the increased risk of identity theft does not confer standing_ In fact, the only post-Clapper cases cited by [Plaintiff] or uncovered by this [c]ourt in which data breach victims were found to have standing all included allegations indicating that some of the stolen, data .had already been misused, that there was a clear intent to use the plaintiffs’ personal data for fraudulent purposes, or both.

Id. at 531. Thus, the Khan court concluded that, “in the data breach context, plaintiffs have properly alleged an injury in fact arising from increased risk of identity theft if they put forth facts that provide either (1) actual examples of the use of the fruits of the data breach for identity theft, even if involving other victims; or (2) a clear indication that the data breach was for the purpose of using the plaintiffs’ personal data to engage in identity fraud.” Id. at 532. Based on that framework, the Khan court concluded that the plaintiff lacked standing to sue because she had not alleged misuse of her data, and the circumstances of the data breach did hot clearly indicate that the hackers’ purpose was to use personal data to engage in identity fraud. Id.

In this case, the four non-misuse plaintiffs — Fero, Church, Boomershine, and Caltagarone — have alleged increased risk of harm, unaccompanied by any concrete misuse of their stolen personal information. (CMC at ¶¶ 17, 30, 33, 36). While they all allege that their personal information was compromised as a result of the data breach, (see, e.g., id. at ¶ 17), none allege any;facts indicating that the-hackers have misused their personal information since the data breach occurred, or that any other suspicious activity has occurred in the three years since the data breach began. This undercuts their assertion that the asserted harm of future identity theft is “certainly impending.” These plaintiffs’ claims of injuries do not meet the definition of injury in fact. Their alleged injuries are neither concrete, nor actual and imminent because the alleged injuries rely on a chain of possibilities about the actions of independent actors: these Plaintiffs may suffer some actual harm if the hacker, has the information in a format that is understandable and accessible, and if the hacker intends to commit crimes by misusing it or transmitting it to someone who (joes, and if the hacker (or other party) can successfully misuse the information. See Clapper, 133 S.Ct. at 1150 (“We decline to abandon our usual reluctance to endorse standing theories that rest on speculation about the decisions of.independent actors.”).

And, as the Excellus Defendants point out, Maridiant’s investigation of the data breach “did not identify evidence of the collection, staging, or exfiltr ation of patidnt data. Although" Mandiant did" not find evidence of the collection, staging or exfiltration of patient data, Mandiant was unable to rule out the possibility the attacker accessed patient data based on the available log data.” (Dkt. 123); see also Makarova, 201 F.3d at 113 (explaining that, in ruling on . a 12(b)(1) motion, a court may consider materials outside the pleadings). Thus, even though Plaintiffs allege that their personal information was actually stolen (CMC at ¶ 167(a)), the fact that Mandiant’s investigation did not reveal collection or exfiltration of that data suggests there is not a clear indication from the circumstanc.es of the data breach that the cyber attackers breached Excellus’s networks in order to use these four Plaintiffs’ personal information to commit identity fraud against, them. See Khan, 188 F.Supp.3d at 532. Accordingly, the Court finds the alleged harm of increased risk of identity fraud too speculative to support standing for these four plaintiffs.

C. Alternative Bases for Standing

As an initial matter, the Court notes that Plaintiffs have not responded to. the Excellus Defendants’ arguments that the four non-misuse plaintiffs .lack standing based on their alleged mitigation efforts, overpayment for health insurance, diminution in value of personal information, and violations of state statutes. (See generally PI. Excellus Opp.). Some “courts in this circuit have held that a plaintiffs failure to respond to contentions raised, in a motion to dismiss constitutes an abandonment of the applicable claims.” Bond v. City of N.Y., No. 14-CV-2431(RRM) (VVP), 2015 WL 5719706, at *8 (E.D.N.Y. Sept. 28, 2015) (citing McLeod v. Verizon New York, 995 F.Supp.2d 134, 143-44 (E.D.N.Y. 2014) (collecting cases)). Even if Plaintiffs had responded to the Excellus Defendants’ arguments regarding these bases for standing, as discusspd below, the Court finds these alternative bases insufficient.'

1. Mitigation Efforts

The Excellus Defendants argue that alleged mitigation efforts by the non-misuse Plaintiffs — that is, Boomershine’s purchase of additional credit monitoring services (CMC at ¶ 33), and Boomershine, Fero, and Church having “spent time” to protect themselves (id. at-¶¶ 17, 30, 33)— are insufficient to establish standing. (Ex-cellus Mot. At 7). The Court agrees.

In Clapper, the Supreme Court held that plaintiffs “cannot manufacture standing merely by inflicting harm on themselves based on their fears of hypothetical future harm that is not certainly impending.” 133 S.Ct. at 1151. The Supreme Court thus rejected the argument that the cost of measures taken to protect plaintiffs’ confidentiality of communications against surveillance could confer standing, reasoning that, “[i]f the law were otherwise, an enterprising plaintiff would be able to secure a lower standard for Article III standing simply by making an expenditure based on a nonparanoid fear.” Id.

This rule from Clapper has been applied in the data breach context, such that courts have concluded that mitigation efforts following a data breach do not confer standing where the alleged harm is not imminent. See Beck, 848 F.3d at 277-78 (“[T]hese self-imposed harms cannot confer standing.”); Remijas, 794 F.3d at 694 (concluding, based on Clapper, that “Mitigation expenses do not qualify as actual injuries where the harm is not'imminent”); Reilly, 664 F.3d at 46 (concluding that “alleged time and money expenditures to monitor ... financial information do not establish standing, because costs incurred to watch- for a speculative chain of future events based on hypothetical future criminal acts are no ‘more ‘actual’ injuries than the alleged’ ‘increased risk of injury’ ”); In re SuperValu, Inc., 2016 WL 81792, at *7 (stating thát “the cost to mitigate the risk of future harm does not constitute an injury in fact unless the future harm being mitigated against is itself imminent”); Whalen, 153 F.Supp.3d at 581 (rejecting argument that mitigation expenses confér standing).

Having concluded that the increased risk of identity theft is not imminent for these four plaintiffs, the non-misuse plaintiffs’ mitigation efforts against that future harm cannot confer standing.

2. Overpayment Allegations

The Excellus Defendants ; argue that Plaintiffs cannot establish injury-in-fact based on their alleged overpayment for health insurance. (Excellus Mot. at 7-8). The Court agrees. ,“[A] number of courts have rejected an ‘overpayment’ theory of damages as an injury-in-fact for standing purposes.” In re Cmty. Health Sys., Inc., No. 15-CV-222-KOB, 2016 WL 4732630, at *8 (N.D. Ala. Sept. 12, 2016); see Khan, 188 F.Supp.3d at 533 (finding no standing based on overpayment allegations where plaintiff did “not allege any facts showing that she overpaid for ... services or that she would have sought those services from another provider had she been aware of the hospital’s allegedly lax data security”); Carlsen v. GameStop, Inc., 112 F.Supp.3d 855, 861 (D. Minn. 2015) (finding no standing based on overpayment theory and stating that “[cjourts have generally found ‘overpayment’ theories insufficient to establish injury, even in situations involving highly sensitive [personal information]”); In re Zappos.com, Inc., 108 F.Supp.3d at 962 n.5 (finding no standing based on “diminished value of the services provided by Zappos” because plaintiffs failed to “allege facts showing how the price they paid for [Zappos’s] goods incorporated some particular sum that was understood by both parties to be allocated towards the protection of customer data”); In re SAIC, 45 F.Supp.3d at 30 (rejecting overpayment theory, stating, “[t]o the extent that Plaintiffs claim that some indeterminate part of their premiums went toward paying for security measures, such a claim is too flimsy to support standing.”); see Lewert, 819 F.3d at 968 (expressing, in dicta, skepticism about plaintiffs’ argument that “the cost of their meals is an injury because they would not have dined at P.F. Chang’s had they known of its poor data security”); see also Remijas, 794 F.3d 688, 696 (7th Cir. 2015) (refraining “from deciding whether the overpayment for Neiman Marcus products ... might suffice as injuries under Article III” but acknowledging that the court was. “dubious” that the overpayment theory alone would have sufficed for standing).

Here, as the Excellus Defendants rightly point out, the CMC lacks any factual allegations that would support the claim that Plaintiffs paid a specific amount of money for data security. (See CMC at ¶ 167(h) (claiming “overpayment for health insurance ..., in that a portion of the price for insurance or other services paid by Plaintiffs and Class Members to Defendants was for the costs of Defendants to take reasonable and adequate security measures .... ”). Accordingly, Plaintiffs’ alleged overpayment is not a basis for standing.

3. Diminution in Value

The Excellus Defendants argue that Plaintiffs’ allegation that they have suffered a diminution in value of their personal information does not support standing because Plaintiffs have not alleged any facts showing that the breach deprived them of any value. (Excellus Mot. at 8-9). Courts have rejected allegations that the diminution in value of personal information can support standing. See Welborn, 2016 WL 6495399, at *8 (“Courts have routinely rejected the proposition that an individual’s personal identifying information has an independent monetary value.”); Khan, 188 F.Supp.3d at 533 (rejecting standing based on diminution in value theory because plaintiff did not “explain how the hackers’ possession of that information has diminished its value, nor does she assert that she-would ever-actually sell her own personal information”); Whalen, 153 F.Supp.3d at 582 (“[W]ithout allegations about how her cancelled credit card information lost value, [plaintiff] does not have standing on this ground.”); In re SAIC, 45 F.Supp.3d at 30 (“As to the value of their personal and medical information, Plaintiffs do not contend that they intended to sell this information on the cyber black market in the first place, so it is uncertain how they were injured by this alleged loss. Even if the service members did intend to sell their own data — something'no one alleges — it is unclear whether or how the data has been devalued by the breach.”). Although Plaintiffs’ CMC alleges that the information compromised in the Excellus data breach commands a high price on the black market- (CMC at ¶ 162), the CMC lacks factual allegations to support the proposition that their personal information was made less valuable to them as a result of the breach, or that the data breach negatively impacted the value of their data such that Plaintiffs could not use or sell it. Thus, because Plaintiffs have not alleged any facts regarding how the data breach has led to a diminution in the value of their personal information, there can be no standing on this basis.

4. Violation of State Statutes

Finally, the Excellus Defendants argue that the asserted violations of various state statutes do not confer standing in federal court. (Excellus Mot. at 9). The Court agrees. See Spokeo, 136 S.Ct. at 1549 (“Article III standing requires a concrete injury even in the context of a statutory violation,”); Hollingsworth v. Perry, — U.S. -, 133 S.Ct. 2652, 2667, 186 L.Ed.2d 768 (2013) (“[Standing in federal court is a question of federal law, not state law. And no matter its reasons, the fact that a State thinks a private party should have standing to seek relief for a generalized grievance cannot override our settled law to the contrary.”); see also Khan, 188 F.Supp.3d at 534 (concluding, in a data breach case, that violations of state statutes and common law cannot establish Article III standing).

D. Conclusion

Based on the foregoing, the Court grants the Excellus Defendants’ motion to dismiss the four non-misuse plaintiffs (Fero, Church, Boomershine, and Calta-garone) for lack of standing on the .basis that they have not alleged an injury-in-fact. The Court dismisses these plaintiffs’ claims without prejudice, as the Court’s conclusion would not necessarily bar these plaintiffs from -asserting ,a claim in the event that they suffered an actual misuse. Nonetheless, because there is no information before the Court that these plaintiffs could presently replead their claims, to allege actual misuse, the Court declines to grant leave to replead.

IV. Causation

The second element . of stand: ing — causation—requires “a causal connection between the injury and the conduct complained of,” Lujan, 504 U.S. at 560, 112 S.Ct. 2130. The harm alleged must be “fairly ... trace[able] to the challenged action of the defendant, and not injury that results from the independent action of some third party not before the court.” Simon v. E. Ky, Welfare Rights Org., 426 U.S. 26, 41-42, 96 S.Ct. 1917, 48 L.Ed.2d 450 (1976). While a plaintiffs injury must be “fairly traceable” to a defendant’s actions, the causal connection element of standing “does not create an onerous standard. For example,, it is a standard lower than that-of proximate, causation. ... A defendant’s conduct that injures a plaintiff but does so only indirectly, after intervening conduct by another person, may suffice for Article III standing.” Carter v. HealthPort Techs., LLC, 822 F.3d 47, 55-56 (2d Cir. 2016) (citations omitted).

A. The Parties’ Arguments

The Excellus Defendants argue that the “misuse” Plaintiffs “have not pleaded any facts to tie their particular allegations of misuse to the Excellus cyberattack as opposed to any other possible source.” • (Ex-cellus Mot. at 10). The Excellus Defendants also argue that the alleged forms of misuse — phishing emails, fraudulent charges on credit or debit cards, tax fraud, and identity theft — are fairly common and could have been the result of the actions of some third -party not before the Court or another data breach of recent years. (Id.). To that end, the Excellus Defendants, citing In re SAIC, 45 F.Supp.3d at 27, report the statistic that identity theft affects 3.3% of the population. (Id.). The Excellus Defendants also argue that the alleged harms of phishing emails and fraudulent charges are not traceable when Plaintiffs have not alleged that they provided email addresses or payment card information to Excellus. (Id. at 10-11).

Plaintiffs respond to the Excellus Defendants’ argument stating, “[t]raceability does, not require plaintiffs to rule out every possible alternative cause at the pleading stage,” and that several courts have rejected similar arguments that-an injury cannot be fairly traceable if it is a common injury. (PI. Excellus Opp, at 25-26). According to Plaintiffs, in the data breach context, “no court” has accepted a traceability argument like the one advanced by the Excel-lus Defendants. (Id. at 25-26).

BCBSA argues that Mottern’s injuries cannot be- deemed fairly traceable when she has not alleged that she provided her credit card information to Excellus, or that she paid her premiums to any Defendants directly or by credit card. (BCBSA Mot. at 9). BCBSA also argues that Mottem “alleges no facts demonstrating that the fraudulent charges, or even the cyberat-tack itself, are fairly traceable to any conduct by BCBSA.” (Id.). BCBSA identifies three purported deficiencies in that regard: First, according to BCBSA, Mottern has engaged in impermissible group pleading by lumping BCBSA in with either Ex-cellus or with all Defendants. (Id. at 10). Second, BCBSA argues that Mottern’s allegations are conclusory, as she asserts “ ‘failings’ by Defendants without identifying what limitations, ‘best practices,’ or ‘safeguards’ BCBSA should have employed, and point[s] to no actual misconduct by BCBSA that resulted in injury to Plaintiffs.” (Id.). Third, BCBSA argues that “conclusory statements that BCBSA violated a statute, without more, are insufficient to confer Article III standing.” (Id.).

Plaintiffs respond to BCBSA by arguing that Mottern’s injuries are fairly traceable: the requirement is not onerous and maybe satisfied even when the injury is indirectly traceable due to the intervening conduct by another person. (PL BCBSA Opp. at 4). Plaintiffs maintain- that their allegations concerning BCBSA are sufficient: according to the CMC, BCBSA contracted to ensure that federal employees, like Mot-tern, benefitted from reasonable data security, that BCBSA, as agent .for Excellus, failed to provide that security in certain respects, and .that the failures led to identity theft, fraud, and the imminent risk of future harm. (Id. at 4-5 (citing CMC at ¶¶ 82-95,134,142-45)).

B. “Fairly Traceable” in Data Breach Context

In the data breach context,' courts have rejected 'the argument that plaintiffs’ injuries are not fairly traceable when their information could have been compromised during a different data breach in recent years. See Remijas, 794 F.3d at 696. In Remijas, for example, the Seventh Circuit concluded that “[t]he fact that Target or some other store [besides Neiman Marcus] might have caused • the plaintiffs’ private information to be exposed does nothing to negate the plaintiffs’ standing to sue.” Id. At the pleading stage, the Seventh Circuit found it sufficient that Neiman Marcus admitted that customers’ credit cards had been exposed and that the retailer had notified them that their personal information was at risk. Id, The Seventh Circuit explained that Neiman Marcus’ argument was better raised as a defense in a later stage in the litigation: “If there are'multiple companies that could have exposed the plaintiffs’ private information'to the hackers, then ‘the common law of torts has long shifted the burden of proof to defendants to prove that their negligent actions were not the ‘but-for’ cause of the plaintiffs injury.’ ” Id. (citations and quotations omitted).

Other courts have similarly rejected challenges to standing based on traceability in the data breach context, finding the challenge better suited for a later stage-of the litigation. See Lewert, 819 F.3d at 969 (rejecting the argument that. fraudulent charges could not be- attributed to data breach at P.F. Chang’s, and explaining that the argument that there are potential alternative causes for plaintiffs’ injuries may be pursued at merits phase); In re Zappos.com, Inc., 2016 WL 2637810, at *6 (D.Nev. 2016) (rejecting traceability argument because “[wjhether or not ... [plaintiffs’ allegations suffer from defects that prevent them from ultimately prevailing in the case, the allegations show the conpection between the alleged injury and breach is more than just hypothetical or tenuous”); In re Target Corp., 66 F.Supp.3d at 1159 (“Plaintiffs’ allegations plausibly allege that they suffered injuries that are ‘fairly traceable’ to Target’s conduct. ... This is sufficient at this stage to plead standing. Should discovery fail to bear out Plaintiffs’ allegations, Target may move for summary judgment on the issue.”).

On the other hand, in In re SAIC, 45 F.Supp.3d at 31-33, the court concluded that some of the plaintiffs did not meet the causation requirement because, while they had alleged unauthorized charges on their credit and debit cards or that money was withdrawn, from their bank accounts, none had alleged that credit card, debit card, or bank account information was on the stolen tapes. The district court in In re: Community Health Systems, Inc. similarly found that the “fairly traceable” element exists for purposes of Article III case or controversy standing “when at least one instance of misuse was pled that would have a logical connection to the data stolen.” 2016 WL 4732630 at *12. Thus, as in In re SAIC, the In re: Community Health Systems, Inc. court dismissed, for example, plaintiffs who alleged unauthorized credit card charges but who did not allege that the data breach included credit card information. See id. Similarly relying on In re SAIC, the D.C. district court in Welbom found that a plaintiff who had alleged a potential compromise of her personal information, followed by an instance of fraudulent activity in her financial accounts, such as the removal of funds, could not meet the traceability requirement because “[i]t [wa]s not clear that the type of data obtained from the theft ... was necessarily used in the removal of funds.” 2016 WL 6495399, at *9. That plaintiff thus failed to “put forward facts showing that [her] injuries [could] be traced to the specific data incident of which [she] complained] and not to any previous theft or data loss incident.” Id.

C. Application

The Court finds Defendants’ arguments unpersuasive. The CMC plausibly alleges that the various forms of misuse are “fairly traceable” to the data breach on the Excellus networks. At this early stage of the litigation, Plaintiffs’ allegations are sufficient. They have alleged that the Defendants failed to safeguard their personal information — including names, dates of birth, social security numbers, member identification numbers, home addresses, telephone numbers, and financial information (CMC at ¶ 56) — and, as a direct result, hackers gained access to their personal information. They have also alleged that BCBSA contracted to ensure that federal employees, like Mottern, benefitted from reasonable data security, that BCBSA, as agent for Excellus, failed to provide that security in certain respects, and that the failures led to identity theft, fraud, and the imminent risk of future harm. (Id. at ¶¶ 82-95, 134, 142-45). These alleged chains of events are plausible, and, given that the causation element of standing is not an onerous hurdle, the Court finds that the Plaintiffs have sufficiently alleged this requirement and need not rule out alternative sources of their injuries. Thus, Defendants’ motion to dismiss the remaining Plaintiffs’ claims for lack of the causation aspect of standing is denied.

MOTIONS TO DISMISS FOR FAILURE TO STATE A CLAIM

Defendants further argue that, even if Plaintiffs did have standing, they have failed to state a claim.

I. Rule 12(b)(6) Standard

“To survive a motion to dismiss, a complaint must contain sufficient factual matter, accepted as true, to ‘state a claim to relief that is plausible on its face.’ ” Ashcroft v. Iqbal, 556 U.S. 662, 678, 129 S.Ct. 1937, 173 L.Ed.2d 868 (2009) (quoting Bell Atl. Corp. v. Twombly, 550 U.S. 544, 570, 127 S.Ct. 1955, 167 L.Ed.2d 929 (2007)). “A claim has facial plausibility when the plaintiff pleads factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged. The plausibility standard is not akin to a ‘probability requirement,’ but it asks for more than a sheer possibility that a defendant has acted unlawfully.” Id. (internal citations omitted). Generally, the Court must accept as true all of the allegations contained in the complaint. See id. That rule does not apply to legal conclusions, however: “[t]hreadbare recitals of the elements of a cause of action, supported by mere conclusory statements ... are not entitled to th