Extending Learned Hand's Negligence Formula to Information Security Breaches
Michael L. Rustad, Thomas H. Koenig · The Knowledge Bank (The Ohio State University) · 2007
Negligent security policy is at the heart of recent data theft disasters involving identity fraud and the misappropriation of electronic information.Several statutes already give the state attorneys general or federal officials the right to seek penalties against any company that fails to disclose security breaches when consumer data has been compromised.However, no state or federal security breach notification statutes give the victims of data theft a private cause of action for data theft.At present, the combination of the economic loss rule, present injury requirements, and the lack of a judicially created duty to secure data, presents an insurmountable barrier to individual recovery for negligent data handling.Companies use contractual devices such as "hold harmless" clauses and indemnification to shift the costs of data theft to users.This article argues that Learned Hand's famous risk/utility test should be extended to create a duty to secure computer systems applicable against companies that hold sensitive personal information.The victims of negligent information security should be allowed to recover damages from the data handlers whose failure to implement reasonable security enables data theft.This negligent enablement theory of tort liability will create the necessary policy incentives for companies to develop comprehensive security solutions that will prevent data intrusions.