Reported / Citable
Background
Rice Medical, a Texas critical-access hospital, licensed financial-administration software under a 2010 hosting agreement with NextGen. QuadraMed later acquired NextGen’s rights and obligations under that agreement. The agreement broadly required arbitration of disputes arising from or relating to its subject matter.
Rice Medical alleged that an August 2023 cyberattack on defendants’ systems left it without access to its software and caused permanent loss of financial records. It sued QuadraMed and Harris under Texas law for fraud by nondisclosure, gross negligence, and conversion, and separately asserted a contract claim against QuadraMed. Rice Medical sought leave to expand its allegations against Harris; QuadraMed moved to compel arbitration, while Harris moved to dismiss and alternatively sought arbitration.
The Court’s Holding
Magistrate Judge Yvonne Y. Ho granted Rice Medical leave to amend. The proposed amended complaint plausibly alleged that Harris voluntarily made partial disclosures about the breach while withholding material information about ransom negotiations and its decision not to pay. It also plausibly alleged that Harris, by exercising control over Rice Medical’s data and relevant systems, owed a duty to safeguard that data.
The court concluded that neither the economic loss rule nor Texas conversion law required dismissal at the pleading stage. The relationship and any risk-allocation arrangement between Harris and QuadraMed were insufficiently developed to apply the economic loss rule, and Rice Medical’s electronic financial records could potentially support conversion under the merger exception. The court recommended denying Harris’s motion to dismiss, compelled Rice Medical to arbitrate its claims against QuadraMed under the hosting agreement, and denied Harris’s alternative arbitration request because Harris did not establish a basis for a nonsignatory to enforce the clause.
Key Takeaways
- A broad clause covering disputes “arising from or relating to” a hosting agreement encompassed claims tied to a data breach and lost customer data.
- A nonsignatory cannot compel arbitration merely by pointing to related allegations; Harris did not establish the close relationship required for intertwined-claims estoppel.
- At the pleading stage, allegations that a company controlled and inadequately protected retained data can support Texas-law negligence and fraud-by-nondisclosure claims.
Why It Matters
The ruling separates contractual and noncontractual defendants in a data-breach dispute. Rice Medical’s claims against the contractual successor, QuadraMed, must proceed in arbitration, but its tort claims against Harris remain in court unless further factual development establishes a basis for dismissal or arbitration.
The decision also reflects a willingness to allow claims over lost electronic business records to proceed where the records could have been converted had they existed in paper form.