{"id":2947,"date":"2026-05-19T16:59:50","date_gmt":"2026-05-19T20:59:50","guid":{"rendered":"https:\/\/blogs.duanemorris.com\/classactiondefense\/?p=2947"},"modified":"2026-05-19T16:59:51","modified_gmt":"2026-05-19T20:59:51","slug":"california-supreme-court-rules-that-a-smash-and-grab-hardware-theft-with-no-access-to-sensitive-records-does-not-automatically-result-in-multi-million-or-billion-dollar-liability-under-california-pr","status":"publish","type":"post","link":"https:\/\/blogs.duanemorris.com\/classactiondefense\/2026\/05\/19\/california-supreme-court-rules-that-a-smash-and-grab-hardware-theft-with-no-access-to-sensitive-records-does-not-automatically-result-in-multi-million-or-billion-dollar-liability-under-california-pr\/","title":{"rendered":"California Supreme Court Rules That A Smash-And-Grab Hardware Theft, With No Access To Sensitive Records, Does Not Automatically Result In Multi-Million Or Billion Dollar Liability Under California Privacy Laws"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full is-resized\"><a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/Confidential.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"533\" src=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/Confidential.jpg\" alt=\"\" class=\"wp-image-2948\" style=\"aspect-ratio:1.5009445058274227;width:173px;height:auto\" srcset=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/Confidential.jpg 800w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/Confidential-300x200.jpg 300w, https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/Confidential-768x512.jpg 768w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>By <\/strong><strong>Gerald L. Maatman, Jr., Jennifer A. Riley, Ryan T. Garippo, and Jamar D. Davis<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Duane Morris Takeaways:\u00a0<\/em><\/strong><em>On May 14, 2026, in J.M. v. Illuminate Education, Inc., No. S286699, 2026 Cal. LEXIS 2657 (May 14, 2026),\u00a0the California Supreme Court <a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/05\/4eb0e762-6ef9-495f-a808-54e3ab6b8a94.pdf\">held <\/a>that the California Court of Appeal decision to deny a demurrer was improper for an incorrect application of privacy laws.\u00a0 This decision emphasizes why defendants should confirm whether a plaintiff sufficiently pled a cause of action that aligns with the remedies that he or she seeks to recover.\u00a0 Further, the opinion clarifies that injury under the Confidentiality of Medical Information Act, Cal. Civ. Code \u00a7 56, et seq. (\u201cCMIA\u201d) depends on whether the company subjects medical information to a substantial risk of unauthorized use or access, not whether the unauthorized user actually views sensitive data.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Case Background<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Illuminate Education, Inc. (\u201cIlluminate\u201d) is a technology company that helps educators determine the academic progression of an individual student, as well as their areas of potential improvement.&nbsp; The company uses data from individual students, including medical data, to make these determinations.&nbsp; Illuminate provided its services to the Ventura County Office of Education, under which Plaintiff (a minor) was a student.&nbsp; Plaintiff provided his medical information to the Ventura County Office of Education, which then provided Plaintiff\u2019s health data to Illuminate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2022, Illuminate became aware of suspicious activity related to its systems.&nbsp; Illuminate promptly initiated an investigation.&nbsp; The investigation confirmed an unauthorized user gained access to Illuminate\u2019s records, including students\u2019 medical information.&nbsp; Illuminate sent a notice to the guardians of the affected students, including Plaintiff, informing them of the scope of the potential disclosure.&nbsp; The notice made it clear that Illuminate found no evidence that the unauthorized user (or users) was successful in actual or attempted misuse of the data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After the breach, Plaintiff alleges that he received several mail solicitations at an address provided to only the Ventura County Office of Education.&nbsp; As a result, Plaintiff filed a class action lawsuit alleging that Illuminate, as health care provider, negligently managed the students\u2019 medical records under the CMIA and failed to expediently disclose the data breach to those affected under the Customer Records Act, Cal. Civ. Code \u00a7 1798.80, <em>et seq<\/em>. (\u201cCRA\u201d).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The trial court sustained Illuminate\u2019s demurrer, without leave to amend, after Plaintiff twice failed to cure deficiencies in his pleadings. The Court of Appeal reversed that decision, holding that the trial court abused its discretion by sustaining the demurrer, because Plaintiff may have been able to cure the defects in his complaint if a different legal analysis was applied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Following that decision, the California Supreme Court set out to resolve the disagreement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The California Supreme Court\u2019s Decision<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The California Supreme Court\u2019s analysis hinges on its statutory interpretation, involving the plain reading of the statutes and their legislative histories.&nbsp; Generally, this analysis fell into three distinct categories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>First<\/em><\/strong>, Justice Goodwin Liu, writing for the California Supreme Court, reasoned that Plaintiff failed to establish a valid claim under CMIA because he could not allege that Illuminate was a \u201cprovider of health care\u201d under California Civil Code section 56.06.&nbsp; Relying on the text of section 56.06, the Supreme Court explained there are two ways for a business to qualify as a \u201cprovider of health care\u201d: (1) a covered business maintains medical records to make the information available to either an individual or a health care provider upon request of the individual or provider; or (2) a covered business makes medical information available for an individual or a health care provider upon request to allow an individual to manage their information, or to help diagnose or treat the individual.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Supreme Court also confirmed this interpretation by relying on the legislative history of the statutes.&nbsp; The Supreme Court observed that the legislative history confirmed that the legislature was concerned with&nbsp; situations where diabetics used a data platform to record glucose levels, or where people with hypertension used platforms to track their blood pressure.&nbsp; Relying on the legislative history, the Supreme Court observed that Plaintiff never alleged that Illuminate created a repository of student records that allowed the students to create their own records, or to access and share those records at their discretion.&nbsp; Instead, Plaintiff asserted that Illuminate stored medical information to help educators monitor, evaluate, and address student needs.&nbsp; As a result, Illuminate was not a \u201cprovider of health care,\u201d because it did not make medical records available upon request of the individual or provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Supreme Court also quickly addressed Plaintiff\u2019s inability to satisfy the alternative method for determining whether Illuminate is a \u201cprovider of health care\u201d because Plaintiff never alleged that Illuminate \u201cprovides medical information to health care providers or individuals for diagnosis and treatment of an individual.\u201d&nbsp; <em>Illuminate Education<\/em>, 2026 Cal. LEXIS 2657, at *12.&nbsp; As a result, and after quickly dispensing with a few other arguments, the Supreme Court concluded that Illuminate was not a \u201cprovider of health care\u201d under the CMIA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Second<\/em><\/strong>, in addition to analyzing whether Illuminate was a \u201cprovider of health care,\u201d the Supreme Court also determined whether Plaintiff had alleged sufficient injury to state a claim under the CMIA.&nbsp; The Supreme Court disagreed with Illuminate\u2019s argument that injury requires an unauthorized person to view medical data, and ruled that a plaintiff alleges injury by claiming that the medical information was exposed to \u201ca significant risk of unauthorized access or use.\u201d&nbsp; <em>Id.<\/em> at *29.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CMIA requires covered entities to \u201cpreserve[] the confidentiality\u201d of medical information.\u00a0 Cal. Civ. Code \u00a7 56.101(a).\u00a0 The Supreme Court stated that \u201cconfidentiality\u201d requires \u201ckeeping information private or secret\u201d and clarified that this obligation applies regardless of whether an unauthorized party actually views the data.\u00a0<em>Illuminate Education<\/em>, 2026 Cal. LEXIS 2657, at *26. (\u201c[W]e reject the rule that no breach of confidentiality has occurred until medical information is actually viewed by an unauthorized person.\u201d).\u00a0 Instead, the determination of whether a covered entity failed to preserve the confidentiality of data depends on a factor-based analysis that considers the \u201cform, duration, and extent of the data breach, as well as any mitigation efforts by the covered entity.\u201d <em>Id.<\/em> at *30. Thus, a plaintiff need not allege that his or her data was \u201cactually viewed\u201d by a third party, because that person is \u201cunlikely to know what an unauthorized party has done with their data unless they suffer actual damage\u201d and instead \u201c[a]ll relevant circumstances must be considered\u201d when determining whether confidentiality was breached.\u00a0 <em>Id.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Third<\/em><\/strong>, for the CRA claim, the Supreme Court ruled that Plaintiff did not state a cause of action against Illuminate because Plaintiff was not a customer within the meaning of the statute.\u00a0 To bring suit under the CRA, a plaintiff must establish that he or she is a \u201ccustomer\u201d within the meaning of the statute.\u00a0 <em>Boorstein v. CBS Interactive, Inc.<\/em>, 222 Cal. App. 4th 456, 467 (2013).\u00a0 A customer is \u201can individual who provides personal information to a business for the purpose of purchasing or leasing a product or obtaining a service from the business.&#8221; Cal. Civ. Code \u00a7 1798.80(c).\u00a0 Here, the Supreme Court found that Plaintiff never alleged that he provided any personal information to Illuminate to purchase or lease a product, or obtain a service from Illuminate.\u00a0 The Supreme Court observed that the Ventura County Office of Education purchased Illuminate\u2019s services and provided the student information, not Plaintiff. Moreover, the Supreme Court disregarded Plaintiff\u2019s argument that he was the \u201cultimate\u201d customer of Illuminate because the CRA \u201cdoes not authorize suit by all consumers or beneficiaries; it authorizes a civil action for an injured \u2019customer.\u2019\u201d <em>Id.<\/em> at *32.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the end, the Supreme Court reversed the judgment of the Court of Appeal and remanded the matter for further proceedings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Implications For Companies<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This decision emphasizes the importance of ensuring that a plaintiff has sufficiently pled all causes of action asserted.&nbsp; When the CMIA or CRA are involved, companies must consider whether they are, in fact, a covered entity in order to determine whether they are subject to the statutes\u2019 reach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Further,&nbsp; to assert injury under the CMIA for a data breach claim, the analysis hinges on the risk of unauthorized use, not what an unauthorized user is able to do with the data.&nbsp; Thus, it is imperative that companies take all reasonable steps to retain the confidentiality of sensitive records, making an extra effort to ensure that hardware is secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For CRA claims, companies need to pay special attention to which entities solicit or contract for their services as attention to these details can potentially thwart a potential CRA claim.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In short, organizations that use such medical data, and operate in California, should take note of this decision because it impacts their defenses both positively and negatively going forward.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Gerald L. Maatman, Jr., Jennifer A. Riley, Ryan T. Garippo, and Jamar D. Davis Duane Morris Takeaways:\u00a0On May 14, 2026, in J.M. v. Illuminate Education, Inc., No. S286699, 2026 Cal. LEXIS 2657 (May 14, 2026),\u00a0the California Supreme Court held that the California Court of Appeal decision to deny a demurrer was improper for an &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blogs.duanemorris.com\/classactiondefense\/2026\/05\/19\/california-supreme-court-rules-that-a-smash-and-grab-hardware-theft-with-no-access-to-sensitive-records-does-not-automatically-result-in-multi-million-or-billion-dollar-liability-under-california-pr\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;California Supreme Court Rules That A Smash-And-Grab Hardware Theft, With No Access To Sensitive Records, Does Not Automatically Result In Multi-Million Or Billion Dollar Liability Under California Privacy Laws&#8221;<\/span><\/a><\/p>\n","protected":false},"author":575,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[123],"tags":[],"ppma_author":[7,9,127,161],"class_list":["post-2947","post","type-post","status-publish","format-standard","hentry","category-state-class-actions"],"authors":[{"term_id":7,"user_id":575,"is_guest":0,"slug":"gmaatman","display_name":"Gerald L. Maatman, Jr.","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2022\/09\/maatmangerald-100x100.jpg","author_category":"","last_name":"Maatman Jr.","first_name":"Gerald L.","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/geraldmaatman.html","description":"<a href=\"https:\/\/www.duanemorris.com\/attorneys\/geraldmaatman.html\">Read Gerald's bio.<\/a>"},{"term_id":9,"user_id":576,"is_guest":0,"slug":"jariley","display_name":"Jennifer A. Riley","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2023\/08\/rileyjennifer-100x100.jpg","author_category":"","last_name":"Riley","first_name":"Jennifer A.","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/jenniferriley.html","description":"<a href=\"https:\/\/www.duanemorris.com\/attorneys\/jenniferriley.html\">Read Jennifer's bio.<\/a>"},{"term_id":127,"user_id":692,"is_guest":0,"slug":"rgarippo","display_name":"Ryan Garippo","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2024\/09\/garipporyan-100x100.jpg","author_category":"","last_name":"Garippo","first_name":"Ryan","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/ryangarippo.html","description":"<A HREF=\"https:\/\/www.duanemorris.com\/attorneys\/ryangarippo.html\">Read Ryan's Bio<\/a>"},{"term_id":161,"user_id":767,"is_guest":0,"slug":"jddavis","display_name":"Jamar D. Davis","avatar_url":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-content\/uploads\/sites\/56\/2026\/04\/davisjamar-100x100.jpg","author_category":"1","last_name":"Davis","first_name":"Jamar D.","job_title":"","user_url":"https:\/\/www.duanemorris.com\/attorneys\/jamardavis.html","description":"<a href=\"https:\/\/www.duanemorris.com\/attorneys\/jamardavis.html\r\n\">Read Jamar's bio.<\/a>"}],"_links":{"self":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/2947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/users\/575"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/comments?post=2947"}],"version-history":[{"count":0,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/posts\/2947\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/media?parent=2947"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/categories?post=2947"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/tags?post=2947"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.duanemorris.com\/classactiondefense\/wp-json\/wp\/v2\/ppma_author?post=2947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}