Dittman v. UPMC, 649 Pa. 496, 196 A.3d 1036 (Pa. 2018)

Facts

  • UPMC required employees, as a condition of employment, to provide sensitive personal and financial information (including Social Security numbers and bank information).
  • UPMC stored this information on internet-accessible computer systems.
  • In 2014, hackers accessed UPMC’s systems and stole personal data of roughly 62,000 current and former employees.
  • Employees alleged the stolen data was used to file fraudulent tax returns, causing financial losses and risk of identity theft.
  • Employees filed a putative class action asserting, among other claims, negligence and breach of implied contract, alleging UPMC failed to implement reasonable security measures (e.g., encryption, adequate firewalls, and authentication protocols).
  • The trial court dismissed the negligence claim on preliminary objections, concluding UPMC owed no duty to protect against third-party criminal acts and that the economic loss doctrine barred purely economic damages.
  • The Superior Court affirmed.
  • The Pennsylvania Supreme Court granted review to address duty and the economic loss doctrine in the data-breach context.

Issues

  1. Whether an employer owes a common-law duty to exercise reasonable care to safeguard employees’ sensitive personal information stored on an internet-accessible computer system.
  2. Whether Pennsylvania’s economic loss doctrine bars a negligence claim seeking only pecuniary damages from a data breach when the alleged duty arises under common law independent of any contract.

Decision

  • The court held that an employer owes a duty to exercise reasonable care to safeguard employees’ sensitive personal information stored on an internet-accessible system.
  • The court held the economic loss doctrine did not bar the negligence claim because the alleged duty sounded in common law and was independent of contractual obligations.
  • The Superior Court judgment was vacated, the trial court order was reversed, and the case was remanded for further proceedings on the negligence claim.
  • Because the case was at the pleading stage, the court did not decide breach, causation, or the amount of damages.
  • A party engaging in affirmative conduct that creates a foreseeable, unreasonable risk of harm owes a duty of reasonable care to protect others from that risk.
  • An employer that affirmatively collects and stores employees’ sensitive personal and financial information on internet-accessible systems has a common-law duty to use reasonable care to protect that information.
  • The presence of third-party criminal conduct does not negate duty where the defendant’s own conduct is alleged to have created the risk of harm.
  • Under Pennsylvania’s economic loss doctrine, purely pecuniary damages may be recoverable in negligence when the defendant breached a common-law duty that exists independently of any contractual duty.
  • Recognizing a duty to protect employee data does not make the employer an insurer; plaintiffs must still prove breach, causation (factual and legal), and damages.

Conclusion

Pennsylvania’s high court reinstated employees’ negligence claim arising from a data breach, recognizing an employer’s common-law duty to reasonably secure employee data and holding that the economic loss doctrine does not bar purely economic damages when the claimed duty is independent of contract.