Data Breach & Cybersecurity

First Circuit Affirms Data Breach Dismissal on Traceability and Concreteness Grounds

By Arnold D. Lee · September 1, 2026

First Circuit Affirms Data Breach Dismissal on Traceability Grounds

On June 11, 2026, the U.S. Court of Appeals for the First Circuit affirmed the dismissal of a putative class action against Bayamón Medical Center, a Puerto Rico hospital, holding that the named plaintiff lacked Article III standing to pursue claims arising from a 2019 ransomware attack1. The decision, Santos-Pagán v. Bayamón Medical Center, adds to the growing body of appellate case law applying federal standing doctrine to data breach litigation, but its reach is narrower than the outcome might suggest. The panel found that the plaintiff had adequately alleged an injury in fact, in the form of actual misuse of her personal information, and it resolved the appeal on a different element entirely, concluding that she had not plausibly connected that injury to the hospital's data breach. The dismissal rests on traceability, not on any holding about how much risk or harm a data breach plaintiff must allege.

The Bayamón Medical Center Ransomware Attack

Bayamón Medical Center (“BMC”) is a hospital located in Bayamón, Puerto Rico that, like most health care providers, collects and stores patients' personally identifiable information (“PII”) and protected health information (“PHI”), including Social Security numbers, dates of birth, and medical diagnoses. On May 21, 2019, BMC learned that it had been the victim of a ransomware attack in which hackers accessed and encrypted files on its systems. The plaintiff alleged that the PII and PHI of 522,493 BMC patients, including her own, was exposed in that breach2. Two months later, on July 19, 2019, BMC sent a notice letter to affected patients disclosing the breach. The letter explained that hackers had accessed patients' PII and PHI, but that after investigating, BMC had found the information was “simply encrypted” and that there was no indication it had actually been used by an unauthorized person.

Betzaida Santos Pagán, a former BMC patient who received the notice letter, filed a putative class action against BMC in the U.S. District Court for the District of Puerto Rico in May 2020, together with a co-plaintiff whose claims were later dismissed for lack of standing on separate grounds. The complaint, invoking jurisdiction under the Class Action Fairness Act, asserted Puerto Rico law claims for breach of express and implied contract, breach of the covenant of good faith and fair dealing, and negligence. The plaintiffs alleged that BMC's failure to safeguard patient data placed them at ongoing risk of identity theft, required them to spend time and money mitigating that risk, and diminished the value of their personal information.

The litigation proceeded through several rounds of amendment over more than four years. After BMC moved for judgment on the pleadings, arguing the complaint failed to allege a concrete injury, the plaintiffs sought leave to amend in order to invoke federal question jurisdiction by adding a claim under the Stored Communications Act and to plead additional facts about the harms suffered by the co-plaintiff, Minerva Hernández Umpierre. They did not seek to add new factual allegations as to Santos. When BMC again challenged standing, Santos sought leave, nearly five years after the breach, to add newly discovered facts: that after receiving BMC's notice letter, she had discovered an unauthorized cellphone account opened in her name, which cost her roughly $800 to remediate and required her to monitor her credit going forward3. The case was referred to a magistrate judge after the parties failed to respond to a district judge's order asking whether they consented to that referral, a failure the order had specified would be treated as implicit consent under 28 U.S.C. § 636(c)(1). The magistrate judge ultimately dismissed the operative complaint for lack of Article III standing, concluding that Santos had not met her burden of showing that the fraudulent cellphone account was traceable to BMC's cyberattack.

The First Circuit's Two-Part Standing Analysis

On appeal, the First Circuit, in an opinion by Judge Montecalvo joined by Judges Gelpí and Thompson, organized its review around the two standing elements the parties disputed: injury in fact and traceability. Because whether standing exists is a legal question, the court reviewed the district court's dismissal de novo, accepting the complaint's well-pleaded facts as true and drawing reasonable inferences in the plaintiff's favor4. To demonstrate standing, the court explained, a plaintiff must sufficiently plead injury in fact, traceability, and redressability, and the parties' dispute centered on the first two.

On injury in fact, the panel sided with Santos. Relying on its 2023 decision in Webb v. Injured Workers Pharmacy, LLC, the court reiterated that actual misuse of PII may itself constitute an injury in fact5. Because the complaint alleged that unauthorized third parties had used Santos's PII to open a fraudulent cellphone account, causing her to spend time and roughly $800 addressing the resulting damage to her credit, the court found that this was sufficient, standing alone, to establish a concrete and particularized injury. The panel did not reach Santos's alternative theory that the time and money she spent mitigating the fraud were themselves an injury in fact; because she raised that argument for the first time in her reply brief, the court deemed it waived.

Traceability was where the complaint failed. The First Circuit explained that traceability does not demand proximate causation, but requires only that the plaintiff's injury be fairly traceable to the defendant's conduct6, which in turn requires a causal connection between the injury and the conduct complained of7; an injury caused by the “independent action of some third party not before the court” does not satisfy the requirement8. Applying that standard, the court identified three specific gaps in Santos's pleading. First, the complaint provided no plausible basis to infer a temporal connection between the data breach and the opening of the fraudulent cellphone account: it never alleged when the account was opened, and the record suggested Santos did not even discover the account until sometime after September 2023, more than four years after the breach. Second, unlike the plaintiff in Webb, Santos never alleged that she generally protected her PII, avoided transmitting it over unsecured channels, or stored it securely, allegations that in Webb had supported an inference that the misused information came from the breach rather than some other source. Third, the complaint never alleged what type of information a fraudster would need to open a cellphone account, or whether that information matched what BMC held or what was exposed in the breach. Taken together, the court concluded, these gaps left only a conclusory assertion that the fraudulent account was linked to the breach, the kind of “bald assertion” a court need not credit even under the generous pleading standard applicable to a motion to dismiss9.

Measuring Santos-Pagán Against Webb

The decision is notable less for breaking new doctrinal ground than for showing, with real precision, how the First Circuit's own recent precedent cuts both ways. In Webb v. Injured Workers Pharmacy, decided in 2023, the same court reversed a dismissal and found standing where a plaintiff alleged that her PII was used to file a fraudulent tax return roughly one year after the breach, a gap the court there called an “obvious temporal connection,” combined with allegations that she was careful with her personal information and had never transmitted it through unsecured channels. Santos-Pagán makes clear that Webb was not simply a low bar cleared by any allegation of downstream misuse. Rather, the panel read Webb as resting on three mutually reinforcing allegations, an obvious temporal connection between the breach and the fraudulent tax return, an allegation that the plaintiff's PII was being used by an unauthorized individual, and allegations that she was careful about sharing her PII and stored documents containing it in a secure location. Santos supplied the second of the three. Like the Webb plaintiff, she alleged that her PII had been used by unauthorized third parties, but, as the panel put it, the similarities to Webb ended there. She pleaded neither the timing nor the safeguarding allegations, and the court identified a further gap peculiar to her own complaint, which never alleged whether the information a fraudster would need to open a cellphone account was the kind of information she gave BMC or that the breach exposed. The court was careful to add that it was not requiring that particular combination in every complaint; it held only that Santos's attempt to clear the traceability hurdle by analogy to Webb failed.

Traceability Is Not the Same Question as Injury in Fact

Because the panel resolved the case on traceability, it had no occasion to address the question that dominates most discussion of data breach standing: whether the risk of future identity theft that follows the exposure of sensitive information is concrete enough to support a suit for damages. The Supreme Court's decisions in Clapper v. Amnesty International USA and TransUnion LLC v. Ramirez are the usual reference points for that question, with TransUnion holding that the mere risk of future harm, without more, cannot support standing to seek damages10, and Clapper holding that standing cannot rest on a speculative chain of possibilities11. The Santos-Pagán panel cited neither decision. Both address concreteness and imminence, which are components of injury in fact, and the panel had already concluded that Santos satisfied that element. The First Circuit's position on injury in fact remains what it was after Webb, which held that a data breach plaintiff plausibly alleged a concrete injury based on the material risk of future misuse of her exposed information together with a present harm caused by exposure to that risk12. Nothing in Santos-Pagán disturbs that holding. What the decision adds is that a plaintiff who clears the injury-in-fact threshold must still plead facts connecting the injury to the defendant's breach. That requirement carries particular force in the ransomware context. BMC's own notification letter told patients that their information had been accessed and encrypted but that there was no indication it had actually been used by an unauthorized person, a disclosure that, standing alone, gave the plaintiff little to work with when a fraud incident later surfaced.

The timing of the underlying litigation also underscores a practical reality: ransomware attacks and follow-on litigation frequently unfold over years, and the passage of time between breach and alleged harm can itself work against plaintiffs. The U.S. Department of Health and Human Services Office for Civil Rights maintains a public portal cataloguing every reported breach of unsecured protected health information affecting 500 or more individuals13. As those cases accumulate, the traceability question the First Circuit addressed in Santos-Pagán, whether a later-discovered instance of fraud can plausibly be pinned on a specific, sometimes years-old, breach, will only become more common and more consequential.

Practical Implications for Companies Facing Post-Breach Litigation

Santos-Pagán is a useful point of reference for companies facing data breach class actions, provided it is read for what it decided rather than for what it might be stretched to say.

First, companies and their counsel should read putative class complaints closely rather than resting on a general argument that data breach plaintiffs lack standing. What defeated this plaintiff was the combination of an undated fraud incident, no allegation that she generally safeguarded her information, and no allegation connecting the type of information misused to the type exposed in the breach. Those observations are not a checklist, and the panel said as much. Whether any of them matters in a given case will depend on what else the complaint alleges and on how the plaintiff frames her theory of standing.

Second, companies should recognize that breach notification letters can become important evidence in later standing disputes. BMC's notice letter, which disclosed that data had been encrypted but stated there was no indication of actual misuse, effectively left plaintiffs to prove misuse and its connection to the breach from scratch, without help from the company's own investigation. Drafting accurate, carefully worded notification letters, without overstating either the scope of exposure or the confidence with which misuse can be ruled out, remains important not only for regulatory compliance but for shaping the standing landscape in any litigation that follows.

Third, defense counsel should anticipate that plaintiffs will respond to Santos-Pagán by front-loading their complaints with the kind of allegations that supported standing in Webb: specific dates linking alleged fraud to the breach, assertions about how carefully the plaintiff safeguarded personal information, and factual detail connecting the type of information misused to the type exposed. Companies should expect complaints to become more detailed rather than assuming this decision forecloses viable claims outright; the decision addresses pleading sufficiency, not the ultimate merits of a well-supported traceability theory.

Fourth, companies should not overread Santos-Pagán as establishing a bright-line rule requiring a particular time gap or a particular set of pleaded facts. The First Circuit was explicit that it was not holding that every complaint like Santos's requires the allegations catalogued in its opinion; it held only that her attempt to clear standing's traceability hurdle with Webb failed.14 Practitioners should treat the decision as a fact-intensive application of the traceability requirement rather than a categorical shield, and should continue to develop the full range of standing arguments available under Webb and controlling Supreme Court precedent.

Finally, given how long this litigation took to resolve, seven years from breach to final appellate decision, companies should plan for post-breach litigation risk to persist well beyond the immediate aftermath of an incident, including by preserving investigative records and maintaining institutional knowledge of a breach's technical scope, which may prove critical to standing and merits arguments raised years later.

Conclusion

Santos-Pagán v. Bayamón Medical Center is a reminder that Article III standing has more than one element, and that traceability was the decisive one here. By affirming dismissal notwithstanding the plaintiff's allegation of actual identity theft, the court made clear that pleading both a breach and a later fraud incident is not the same as pleading facts that connect them. It was equally clear that it was deciding this complaint rather than writing a rule for every complaint, and it left the First Circuit's injury-in-fact case law where Webb had placed it. For companies facing the aftermath of a data breach, the decision is worth reading closely and worth citing carefully.

This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.


  1. Santos-Pagán v. Bayamón Medical Center, No. 24-2018 (1st Cir. June 11, 2026); 1st Cir. slip op.↩︎

  2. Santos-Pagán, No. 24-2018, slip op. at 3-4; 1st Cir. slip op.↩︎

  3. Santos-Pagán, No. 24-2018, slip op. at 6-7; 1st Cir. slip op.↩︎

  4. Kerin v. Titeflex Corp., 770 F.3d 978, 981 (1st Cir. 2014); Justia↩︎

  5. Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365, 373 (1st Cir. 2023); Justia↩︎

  6. Lexmark Int'l, Inc. v. Static Control Components, Inc., 572 U.S. 118, 134 n.6 (2014); Justia↩︎

  7. Conservation L. Found., Inc. v. Acad. Express, LLC, 129 F.4th 78, 90 (1st Cir. 2025) (quoting Lujan v. Defs. of Wildlife, 504 U.S. 555, 560 (1992)); Justia↩︎

  8. Lujan v. Defs. of Wildlife, 504 U.S. 555, 560 (1992); Justia↩︎

  9. Ruiz v. Bally Total Fitness Holding Corp., 496 F.3d 1, 4 (1st Cir. 2007); OpenJurist↩︎

  10. TransUnion LLC v. Ramirez, 594 U.S. 413 (2021); Justia↩︎

  11. Clapper v. Amnesty Int'l USA, 568 U.S. 398 (2013); Justia↩︎

  12. Webb v. Injured Workers Pharmacy, LLC, 72 F.4th 365, 375 (1st Cir. 2023); Justia↩︎

  13. U.S. Dep't of Health & Human Servs., Office for Civil Rights, Breach Portal: Notice to the Secretary of HHS Breach of Unsecured Protected Health Information; HHS Office for Civil Rights↩︎

  14. Santos-Pagán, No. 24-2018, slip op. at 14 n.7 (“we do not hold that every complaint like Santos's requires allegations listed in the parenthetical numbers above. We simply hold that her attempt to clear standing's traceability hurdle with Webb fails”); 1st Cir. slip op.↩︎

This article was written by Arnold D. Lee, an attorney in the Phoenix office of Spencer Fane. For more information, visit spencerfane.com.

The views expressed are those of the author alone and do not represent the views of Spencer Fane LLP or its clients. This article is for general informational purposes only and is not legal advice.