Stryker has filed a motion to dismiss a consolidated class-action lawsuit stemming from the March 11 cyberattack that disrupted its business operations.
Eight current and former Stryker employees sued the medical device maker within 48 hours of the company’s announcement of the attack, alleging their personally identifiable information — including Social Security numbers, financial account data, and driver’s license information — had been compromised. In U.S. District Court for the Western District of Michigan, plaintiffs assert seven claims under Michigan law, including negligence, breach of implied contract, and intrusion upon seclusion.
Stryker’s June 22 motion argues the case should be dismissed on two primary grounds. First, the company says its own investigation, conducted with independent experts, found no evidence that any of the eight plaintiffs’ personally identifiable information was accessed, according to court records viewed by Becker’s. Chief Information Security Officer Juan Pablo Calderon stated under penalty of perjury that Stryker has not notified any plaintiff that their data was compromised, a legal requirement had any personally identifiable information been accessed. The only plaintiff data found in potentially exposed files were the business email addresses of two plaintiffs, which Stryker argues does not constitute personally identifiable information under Michigan law.
Second, Stryker contends that plaintiffs lack Article III standing because any alleged injuries are not traceable to the cyberattack. The company’s forensic expert identified that each plaintiff’s information had appeared in multiple prior data breaches — two plaintiffs in at least 20 each — predating the Stryker incident.
Plaintiffs attributed the March hack to Handala, an Iranian nation-state cybercriminal group. Stryker, which develops products and services used in surgical and medical care, is incorporated in Michigan and operates globally.
Editor’s note: Becker’s reached out to Stryker for comment and will update the story if the company responds.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.