Data-Breach Standing in the First Circuit: Actual Misuse Can Be Injury-in-Fact, but Traceability Requires Plausible, Nonconclusory Facts Linking the Misuse to the Breach
I. Introduction
In Santos-Pagan v. Bayamon Medical Center, the United States Court of Appeals for the First Circuit affirmed the dismissal of a putative class action arising from a ransomware attack on a Puerto Rico hospital, Bayamón Medical Center (“BMC”). The named plaintiff, Betzaida Santos Pagán (“Santos”), alleged that a breach exposed patients’ personally identifiable information (“PII”) and protected health information (“PHI”), and that she later discovered an unauthorized cellphone account opened in her name, requiring time and money to repair her credit.
The decisive issue on appeal was Article III standing—specifically whether Santos plausibly pleaded (1) an injury in fact and (2) traceability (a causal connection between the injury and BMC’s breach). Although the First Circuit agreed Santos adequately alleged an injury in fact (actual misuse), it held she failed to plausibly allege that the misuse was fairly traceable to BMC’s data breach.
II. Summary of the Opinion
- Injury in fact: The court held Santos plausibly alleged a concrete injury because she alleged actual misuse of her PII—an unauthorized cellphone account—plus mitigation costs (including an alleged ~$800 to repair her credit score).
- Traceability: The court held Santos failed to plausibly allege that the fraudulent cellphone account was fairly traceable to BMC’s breach, because the complaint lacked factual content supporting a reasonable inference that the fraud stemmed from the breach rather than some other source.
- Result: No Article III standing; dismissal affirmed. The court did not reach other jurisdictional disputes because standing was dispositive.
III. Analysis
A. Precedents Cited
1. Foundational standing requirements
-
Kerin v. Titeflex Corp. and Blum v. Holder
The opinion uses these cases to restate that Article III standing is essential to the case-or-controversy requirement and to frame the three-element standing test (injury in fact, traceability, redressability). Kerin also supplies the appellate standard: de novo review and crediting well-pleaded facts at the pre-discovery dismissal stage.
-
Katz v. Pershing, LLC
Cited for the proposition that standing is reviewed de novo, reinforcing that the appellate court independently evaluates whether the pleaded facts satisfy Article III.
-
Lujan v. Defs. of Wildlife
The central source for the “fairly traceable” requirement and the admonition that standing fails where injury results from “independent action of some third party not before the court.” The court leans on Lujan to explain why, in data-breach cases, a plaintiff must plead facts permitting a plausible inference that third-party fraud is causally connected to the defendant’s breach—not merely temporally or rhetorically associated with it.
2. Traceability versus proximate cause
-
Lexmark Int'l, Inc. v. Static Control Components, Inc.
Cited for the proposition that standing’s traceability requirement is not “proximate causation,” but still requires a non-speculative causal connection. The court uses Lexmark to emphasize the traceability standard is lighter than merits causation, yet not so light that conclusory assertions suffice.
-
Conservation L. Found., Inc. v. Acad. Express, LLC
Cited for a modern First Circuit articulation of traceability: a “causal connection between the injury and the conduct complained of.” It helps the court situate its analysis as an application of plausibility pleading to the traceability element.
3. First Circuit data-breach standing guidance
-
Webb v. Injured Workers Pharmacy, LLC
This is the key comparator. The court reiterates Webb’s holding that “actual misuse of PII may constitute an injury in fact.” More importantly, the court explains why traceability was plausible in Webb but not here:
- Temporal connection: In Webb, the alleged fraudulent tax filing occurred close enough in time to the breach to support an “obvious temporal connection.”
- Plausible exclusivity / careful handling allegations: In Webb, the plaintiff alleged careful practices (not transmitting unencrypted PII, securing documents), supporting an inference the breach was the likely source of the misused PII.
- Contextual pleading: The Webb complaint tied the misuse to the breach with supporting factual context, not a bare conclusion.
In Santos-Pagan, the court treats Webb as a roadmap: it does not impose a formal checklist, but it makes clear that some comparable factual content is typically needed to push traceability from “possible” to “plausible.”
4. Pleading standards and waiver doctrine
-
Ruiz v. Bally Total Fitness Holding Corp.
Cited to underscore that even on a plaintiff-friendly motion-to-dismiss posture, courts need not credit “bald assertions” or “unsupportable conclusions.” This principle is pivotal to rejecting the complaint’s conclusory linkage between the breach and the unauthorized cellphone account.
-
Braintree Lab'ys, Inc. v. Citigroup Glob. Mkts. Inc.
Used to deem waived Santos’s underdeveloped request (hinted at in briefing) to reverse the “with prejudice” aspect to allow yet another amendment. The case reinforces that appellate courts will not entertain cursory arguments or late-developed positions.
B. Legal Reasoning
1. Injury in fact: “Actual misuse” clears the concreteness hurdle
The court accepts that a pleaded instance of actual misuse—here, a fraudulent cellphone account—can be a concrete, particularized injury. Relying on Webb v. Injured Workers Pharmacy, LLC, it concludes Santos’s allegation of actual misuse, plus alleged mitigation expenditures, is enough to satisfy injury in fact at the pleading stage.
Notably, the court narrows what it decides. It does not resolve whether time-and-money spent to mitigate risk (absent actual misuse) would independently establish injury in fact, because Santos raised that theory only in her reply brief and thus waived it.
2. Traceability: plausibility requires more than “it happened after the notice letter”
The opinion’s core holding is that Santos failed to plausibly plead that the unauthorized cellphone account was “fairly traceable” to BMC’s ransomware incident. The court identifies three principal deficiencies:
-
No plausible temporal linkage pleaded.
Santos alleged only that she discovered the fraudulent account after receiving BMC’s July 19, 2019 notice letter—without alleging when the account was opened or facts supporting proximity to the May 2019 breach. Worse for plausibility, her later motion for leave suggested she discovered the issue after September 2023—years after the breach—undercutting any inference of an “obvious temporal connection” akin to Webb.
-
No allegations narrowing alternative sources of the misused PII.
Unlike Webb, the complaint did not allege facts about Santos’s handling of her own PII (e.g., careful sharing, secure storage) that would make it more plausible the breach—not some other exposure—was the source. The court rejects Santos’s attempt to substitute “reliance on BMC’s promise to safeguard” for allegations that meaningfully reduce other plausible sources.
-
No pleaded fit between the breached data and the fraud’s requirements.
The complaint did not allege that the type of information necessary to open a cellphone account was among the specific PII/PHI BMC maintained and that was exposed. The court treats Santos’s briefing claim—“the only personal data needed” is what she gave BMC—as both (a) outside the complaint and (b) the sort of unsupported assertion courts need not credit under Ruiz v. Bally Total Fitness Holding Corp..
The upshot is doctrinally important: even when actual misuse is alleged (satisfying injury in fact), standing still fails unless the complaint plausibly connects that misuse to the defendant’s breach rather than leaving the causal story to speculation in a world where PII can be obtained from many channels.
3. Jurisdictional sequencing
The court expressly declines to reach disputes about subject matter jurisdiction under CAFA or the Storage Communications Act because Article III standing is a threshold requirement; without standing, federal courts lack power to decide the merits or other jurisdictional theories in the case as presented.
C. Impact
-
Pleading strategy in First Circuit data-breach cases: Plaintiffs cannot rely on conclusory “data breach therefore fraud” allegations. Even where actual misuse is alleged, complaints should plead concrete facts that make the breach a plausible source (timing, type of data taken, and context narrowing alternative sources).
-
Temporal specificity becomes practically critical: The opinion signals that courts will scrutinize the alleged timing of misuse relative to the breach. Vague statements like “after I received the letter” may be insufficient, especially if other filings suggest a multi-year gap.
-
“Webb” as a functional benchmark: The court treats Webb v. Injured Workers Pharmacy, LLC as illustrating what kinds of factual allegations can transform traceability from speculative to plausible. While disclaiming a rigid checklist, the decision likely encourages defendants to litigate traceability aggressively whenever the complaint lacks comparable detail.
-
Limits on curing standing via later-developed theories: The waiver rulings (mitigation-as-injury raised only in reply; cursory amendment request) are a practical warning: standing theories and requests for relief must be developed early and clearly, particularly in appeals from standing dismissals.
-
Class-action implications: Because the named plaintiff must have standing, an inability to plead traceability for the representative’s misuse allegation can end the putative class case at the threshold, regardless of the scale of the breach.
IV. Complex Concepts Simplified
- Article III standing
-
A constitutional requirement that a plaintiff show a real dispute suitable for federal court. It generally requires (1) a real injury, (2) that the defendant caused it in a meaningful way, and (3) that a court can likely redress it.
- Injury in fact
-
A concrete, personal harm that is actual or imminent. In data-breach cases, “actual misuse of PII” (like proven fraud using your information) can qualify.
- Traceability (“fairly traceable”)
-
The requirement that the injury is plausibly connected to the defendant’s conduct. It is not as strict as proving the defendant legally “caused” the harm at trial, but it must be more than speculation—especially where third-party criminals could have gotten the information elsewhere.
- Plausibility pleading
-
At the motion-to-dismiss stage, courts accept well-pleaded facts as true, but they do not accept bare conclusions. The complaint must contain enough factual detail to make the claimed causal connection reasonable.
- Waiver on appeal
-
If an argument is not properly developed in the opening brief, an appellate court may treat it as forfeited—even if it might have mattered.
V. Conclusion
Santos-Pagan v. Bayamon Medical Center sharpens First Circuit data-breach standing doctrine by separating two ideas that plaintiffs sometimes conflate: (1) alleging actual misuse may satisfy injury in fact, but (2) standing still fails unless the complaint pleads nonconclusory facts making it plausible that the misuse is fairly traceable to the defendant’s breach. The decision’s practical message is that data-breach complaints must plead the “bridge” from breach to fraud—timing, data fit, and contextual facts limiting alternative sources—or face dismissal at the courthouse door.