Cybersecurity Policy Report, W.D. Mo.: Court trims data-breach suit against women’s health provider, (Apr 21, 2026)
Law Firms Mentioned:Kopelowitz Ostrow P.A. | Lathrop GPM LLP
Organizations Mentioned:Lathrop GPM, LLP | Mid America Physician Services, LLC | O.S and F.C.
By Martin A. Steinberg, J.D.
Provider allegedly failed to protect the patients’ sensitive information during a November 2024 data breach, exposing them to identity theft risks and other harm.
The federal court in Kansas City granted in part and denied in part Mid America Physician Services, LLC’s motion to dismiss a putative class action arising from a November 2024 data breach affecting the patients’ personal, financial, and medical information. The court dismissed without prejudice the patients’ negligence, negligence per se, invasion-of-privacy, breach-of-fiduciary-duty, and Missouri Merchandising Practices Act claims, holding that Missouri law does not recognize the broad data-security duty the patients urged, that HIPAA and the FTC Act cannot support negligence per se, and that the fiduciary-duty and MMPA theories were inadequately pleaded. But the court allowed the implied-contract, unjust-enrichment, and declaratory-and-injunctive-relief claims to proceed, finding the complaint sufficiently alleged an implied promise to safeguard patient information and a plausible cost-savings theory of unjust enrichment at the pleading stage (O.S. and F.C. v. Mid America Physician Services, LLC, No. 4:25-cv-00685-RK (W.D. Mo. April 13, 2026)).
Background. Mid America Physician Services, LLC, a Kansas-based provider of obstetrics and gynecological care, serves patients through facilities in Kansas near the Kansas City metropolitan area, including patients from both Kansas and Missouri. The named plaintiffs are current and former patients from both states who brought this putative class action after a data breach.
According to the complaint, the patients were required to provide the provider with sensitive personal information to receive medical services, including names, addresses, Social Security numbers, financial account and payment card information, medical information, and health insurance information, all of which the provider stored on its computer systems and networks. On or about November 14, 2024, the provider discovered a network incident affecting its IT systems. Its investigation concluded in early May 2025, and about two months later, in July 2025, the provider notified affected individuals through website postings and mailed notices that their information had been exposed.
Plaintiffs allege that the breach caused actual and threatened harms, including identity theft, risk of future fraud, loss of privacy, mitigation expenses, time spent monitoring accounts, and credit-related injury, and they contend that the breach resulted from the provider’s failure to implement reasonable cybersecurity protections. They assert eight claims: negligence, negligence per se, breach of implied contract, unjust enrichment, invasion of privacy, breach of fiduciary duty, violation of the Missouri Merchandising Practices Act, and declaratory and injunctive relief.
Negligence claim. The court held that Missouri law did not impose on the provider the duty of care that the patients asserted in this data-breach case. Although the patients argued that healthcare providers collecting sensitive personal data should owe a duty to use reasonable cybersecurity measures, the court found that theory too broad under Missouri law. Relying on Community Bank of Trenton v. Schnuck Markets, Inc., 887 F.3d 803 (7th Cir. 2018), and related authority, the court concluded Missouri would not recognize a general common-law duty to safeguard patient data based solely on its collection and storage.
The court further held that generalized allegations about the prevalence of cybercrime and attacks on healthcare providers were insufficient to render the breach foreseeable in the legally required sense. Because the patients did not allege facts showing the provider knew or should have known a cyberattack on its systems was sufficiently foreseeable, the court dismissed the negligence claim.
Negligence per se claim. The court dismissed the patients’ negligence per se claim, which was based on alleged violations of Section 5 of the FTC Act and HIPAA. The court held that under Missouri law, negligence per se cannot rest on statutes that do not provide a private cause of action. Citing recent Missouri authority on HIPAA and Eighth Circuit authority on the FTC Act, the court concluded that neither statute can support a negligence-per-se theory here. It therefore granted the provider’s motion to dismiss Count 2.
Breach of implied contract claim. The court held that the patients plausibly stated a claim for breach of an implied contract, and therefore denied dismissal of Count 3. Addressing mutual assent, the court concluded that the patients adequately alleged a meeting of the minds by asserting that the provider received their confidential and personal information as a required part of providing medical treatment, maintained privacy policies governing that information, and implicitly promised confidentiality and protection in exchange for the patients’ disclosure of that information.
The court emphasized that whether such an implied contract ultimately existed is a factual question not suitable for resolution on a motion to dismiss. On breach, the court found that the patients’ allegations were sufficiently specific because the patients identified concrete deficiencies, including the alleged failure to use industry-standard network segmentation, to encrypt all private information, to maintain proper record retention and destruction practices, and to implement multi-factor authentication. Those allegations, the court held, plausibly suggested more than a mere possibility of misconduct, allowing the implied-contract claim to proceed.
Unjust enrichment claim. The court declined to dismiss the unjust-enrichment claim. It held that the patients plausibly alleged that the provider received a benefit through payments for medical services, that part of those payments was expected to support reasonable data security, and that the provider was unjustly enriched by saving money through allegedly inadequate, cheaper security measures.
Invasion of privacy. The court dismissed the invasion-of-privacy claim because the patients did not oppose dismissal and expressly agreed that Count 5 could be dismissed without prejudice.
Breach-of-fiduciary-duty claim. The court dismissed the patients’ breach-of-fiduciary-duty claim. It acknowledged that Missouri law recognizes a physician’s fiduciary duty of confidentiality arising from the patient-physician relationship and that the provider effectively conceded such a relationship existed at least as to medical information. But the court held that the patients still failed to plead a breach because they did not allege that the provider itself disclosed their private information to unauthorized third parties. The court distinguished cases involving disclosure by a hospital’s own employees or the direct release of patient records, explaining that the alleged exposure here resulted from third-party cybercriminals rather than from affirmative disclosure by the provider. Because the patients cited no Missouri authority extending fiduciary-duty liability to those circumstances, the court granted dismissal of Count 6.
Violation of MMPA claim. The court dismissed the patients’ Missouri Merchandising Practices Act claim. Relying on Kuhns v. Scottrade, Inc., 868 F.3d 711 (8th Cir. 2017), the court held that the provider did not sell data-security services as merchandise but instead maintained security measures to induce patients to provide information to obtain medical care. The court rejected the patients’ effort to distinguish Kuhns, finding no persuasive reason why this case differed materially and noting Missouri authority describing the keeping of confidential medical records as incidental to providing medical treatment. The court therefore granted dismissal of Count 7.
Declaratory judgment and injunctive relief. The court allowed the patients’ request for declaratory and injunctive relief to proceed because some substantive claims survived dismissal, namely the implied-contract and unjust-enrichment claims.
The case is No. 4:25-cv-00685-RK.
Judge: Ketchmark, R.
Attorneys: Jeffrey M. Ostrow (Kopelowitz Ostrow P.A.) for O.S and F.C. Kathleen Fisher Enyeart (Lathrop GPM LLP) for Mid America Physician Services, LLC.
Companies: O.S and F.C.; Mid America Physician Services, LLC
Cases: CaseDecisions ConfidentialityNews CyberPrivacyFeed EHRNews HIPAANews DataPrivacy DataSecurity DataBreach LitigationEnforcement MissouriNews