Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • U.S., Allies Offer Salt Typhoon Update Amid Lingering ‘Information Gap’
    • Cassidy, Hassan Seek Data Breach ‘Transparency’ From Aflac
    • D. Ariz.: Patients failed to explain how HIPAA and Arizona statutes established public policy imposing duty on hospital
    • Google Finds Support From Cybersecurity Advocates in Epic Games Case
    • Identity Theft Seen as Risk From Age-Verification Requirements
    • SI Wireless Urges Court to Grant Mandamus in ‘Rip-and-Replace’ Case
    • Software Supply Chain Security Tool Offered by CISA
    • Wireless Carrier Faces Heat Over Outage Blamed on Cyber Incident
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, D. Ariz.: Patients failed to explain how HIPAA and Arizona statutes established public policy imposing duty on hospital, (Aug 27, 2025)

    Law Firms Mentioned:Chestnut Cambronne PA | Polsinelli PC
    Organizations Mentioned:Chestnut Cambronne, PA | Polsinelli, PC | Yuma Regional Medical Center

    By Jeffrey H. Brochin, J.D.

    Patients whose personal information was stolen and posted on the dark web failed to show that the Hospital owed them a duty to safeguard against bad actors, which was not the same as a duty not to disclose.

    A federal District Court in Arizona has gran ...

    By Jeffrey H. Brochin, J.D.

    Patients whose personal information was stolen and posted on the dark web failed to show that the Hospital owed them a duty to safeguard against bad actors, which was not the same as a duty not to disclose.

    A federal District Court in Arizona has granted the Motion to Dismiss filed by Yuma Regional Medical Center (Yuma Regional or Hospital) in a putative class action lawsuit brought by 14 patients whose personal information was stolen in a ransomware cyberattack. Although the Patients alleged that the Hospital owed them a legal duty to safeguard and protect their information from unauthorized access or disclosure based on an “assumed responsibility” and under “common law”, and asserted that the Federal Trade Commission Act (FTCA), HIPAA regulations, a physician’s Hippocratic Oath, Arizona Revised Statute § 12-2292(A), and Yuma Regional’s own policies provided such legal duties, the court concluded that they did not, (Johnson v. Yuma Regional Medical Center, No. 2:22-cv-01061-SM (D. Ariz. Aug. 13, 2025)).

    Files of 700,000 patients extracted. In April 2022, cybercriminals breached Yuma Regional’s data security systems, gaining unrestricted access to its files for the next few days, and were able to extract highly sensitive files containing data on an estimated 700,000 of its patients. Yuma Regional discovered the breach four days later, and on June 9, 2022, notified its patients of the breach and provided assurances that Yuma Regional was strengthening its system, enhancing its protocols, and offering its patients free credit monitoring and identity theft protection services for an unknown duration.

    After the breach, some of the Patients received word that their information wound up on the dark web, and they filed suit against Yuma Regional. Their first Complaint was dismissed, and their First Amended Complaint asserted claims for: (1) Negligence; (2) Breach of Implied Contract/Implied Duty of Good Faith and Fair Dealing; (3) Unjust Enrichment; (4) Breach of Fiduciary Duty; and (5) Consumer Fraud, Ariz. Rev. Stat. § 44-1521. Presently before the court was Yuma Regional’s Motion to Dismiss.

    Negligence claim. The court focused on the element of negligence requiring that a cognizable duty be owed by the Hospital, which was subsequently breached. The Patients alleged that a duty to safeguard and protect their information from unauthorized access or disclosure was based on an “assumed responsibility” and under “common law” pursuant to: the Federal Trade Commission Act (FTCA), HIPAA regulations, a physician’s Hippocratic Oath, Arizona Revised Statute § 12-2292(A), and Yuma Regional’s policies. Yuma Regional countered that none of those provided a basis to establish a legal duty to the Patients, and the court agreed.

    Regarding the FTCA, HIPAA and Arizona Revised Statute § 12-2292, the court found that none of those statutes declared a public policy sufficient to create a tort duty. For a statute to create a civil duty, it must be designed to protect the class of persons, in which the patient was included, against the risk of the type of harm which has in fact occurred as result of the violation, but a statute cannot be the basis of a public policy duty if it does not require or prohibit certain conduct. Furthermore, a public policy-based tort duty does not arise from the existence of an entire statutory scheme that implicitly seeks to protect the public at large from general types of harm.

    Disclosure versus ‘bad actors’. The court noted that Arizona Revised Statute § 12-2292 relates to evidence in the courts and civil proceedings, while Section 12-2292(A) provides that medical and payment records are confidential and privileged and may only be disclosed as authorized by state or federal law or written authorization signed by the patient. In other words, the statute governed some sort of affirmative disclosure, but not the risk that a patient’s information might be stolen and then disclosed by bad actors. Accordingly, the statutes could not be the basis for asserting a duty that was allegedly breached.

    As to the Hippocratic Oath, that doctrine governs the patient-physician relationship but not the patient-hospital relationship, and neither HIPAA nor the FTCA establish any tort duty.

    No implied contract liability. The next turned to the Patients’ Breach of Implied Contract claim. The court observed that contract terms cannot be vaguely pleaded, and that here, the vague reference to Yuma Regional being “committed to protecting” the Patients’ information fails to provide any basis to infer how Yuma Regional would fulfill its commitment to protect the information. The court could not be left to “guess” how a party failed to perform its contractual obligations, and the Patients did not plead any facts in support of a contractual duty to prevent a data breach all together or that Yuma Regional promised to do anything beyond what it was already obligated to do under HIPAA or the FTCA. Accordingly, the Breach of Implied Contract claim was dismissed.

    Similarly, the Breach of Fiduciary Duty claim was dismissed because Arizona does not recognize that hospitals--as opposed to physicians--owe a fiduciary duty to patients. In addition, the court found the FAC’s allegations on that claim to be conclusory and related only to the physician-patient relationship, but not the hospital-patient or -customer relationship. That claim was therefore dismissed for failure to state a claim.

    ACFA claim. Under the Arizona Consumer Fraud Act (ACFA) it is unlawful for any person to use or employ “any deception, deceptive or unfair act or practice, fraud, false pretense, false promise, misrepresentation, or concealment, suppression or omission of any material fact with intent that others rely on such concealment, suppression or omission, in connection with the sale or advertisement of any merchandise.” To state a claim under the ACFA, the Patients needed to show (1) a false promise or misrepresentation made in connection with the sale or advertisement of ‘merchandise,’ and (2) consequent and proximate injury resulting from the misrepresentation.

    Here, the Patients’ issue lay not with Yuma Regionals commitment to protecting the information as a matter of objective fact, but rather its adequacy in effectuating that commitment. Therefore, a theory premised on an affirmative and deceptive misrepresentation did not support the Patents’ ACFA claim.

    But at its core, the Patients’ ACFA claim was really premised on Yuma Regional omitting facts pertaining to how it would protect its patients’ confidential information. Because the Patients specifically identified Yuma Regional’s Notice of Privacy Practices that allegedly omitted information about its inadequate data security systems, and, they alleged that relied on those omissions, in accepting those allegations as true, the court found that those allegations sufficiently raised a plausible inference that if the Patients were aware of Yuma Regional’s privacy practices they would have acted differently had Yuma Regional disclosed the alleged security deficiencies. Therefore, the court denied Yuma Regional’s Motion to Dismiss on that claim.

    The case is No. 2:22-cv-01061-SM.

    Judge: Brnovich, S.

    Attorneys: Bryan L. Bleichner (Chestnut Cambronne PA) for Brittney Johnson. John Spencer Craiger (Polsinelli PC) for Yuma Regional Medical Center.

    Cases: CaseDecisions FederalLegislation CyberPrivacyFeed GCNNews HIPAANews DataBreach ArizonaNews DataPrivacy DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use