The Ohio Court of Appeals has ruled that the City of Columbus can be held liable for a cyberattack that compromised personal information of city employees and citizens. The decision, made on September 24, 2026, reverses a lower court's dismissal of claims brought by several plaintiffs, including city employees and a citizen who had interacted with the city. This ruling is significant as it addresses the responsibilities of municipal governments in safeguarding sensitive data and sets a precedent for future cases involving data breaches.

The case, Doe v. Columbus, involves a group of plaintiffs, including five city employees and one non-employee, who filed claims against the city after a cyberattack in July 2024. The plaintiffs allege that their personally identifiable information (PII) was compromised due to the city's failure to maintain adequate cybersecurity measures. The plaintiffs sought damages for negligence, breach of contract, invasion of privacy, and other claims. The case was filed in the Franklin County Court of Common Pleas, which initially granted the city's motion to dismiss based on political-subdivision immunity.

The plaintiffs, identified as John Doe Nos. 1 through 5 and Jane Doe, argued that the city had a duty to protect their personal information and failed to implement necessary security protocols. They claimed that the city’s Department of Technology did not adequately train employees on cybersecurity, leading to the breach. The plaintiffs also highlighted that the city had a unified IT system that contained sensitive information about employees and citizens, which was targeted by cybercriminals.

The cyberattack occurred on July 19, 2024, when hackers infiltrated the city’s IT infrastructure. The city acknowledged the breach publicly on July 29, 2024, stating that it had taken steps to limit exposure. However, by August 8, 2024, some of the stolen data was reportedly available on the Dark Web. The plaintiffs claimed they suffered actual injuries, including financial losses and threats to their safety, as a result of the breach.

In its ruling, the Ohio Court of Appeals, led by Judge Boggs, determined that the trial court erred in granting the city's motion to dismiss based on political-subdivision immunity. The court stated, “The activities at issue in this litigation—the operation of a city-wide IT infrastructure—are Proprietary Activities as defined by [R.C.] 2744.01(G)(1).” This means that the city could be held liable for negligence related to its IT operations.

The court explained that political subdivisions like the City of Columbus are generally immune from tort liability, but there are exceptions. One such exception applies when a political subdivision is negligent in performing proprietary functions. The court found that the operation of the city’s IT system, which includes cybersecurity measures, is a proprietary function, and therefore the city could be held liable for any negligence in that area.

Judge Boggs noted that the trial court had incorrectly classified the city’s IT operations as a governmental function, which would have entitled the city to immunity. Instead, the court emphasized that the specific activity leading to the plaintiffs’ injuries—namely, the maintenance and protection of the IT system—should be viewed as a proprietary function. The court stated, “We cannot conclude, based solely on the allegations in the consolidated complaint, that either the city’s maintenance and operation of its IT infrastructure or the security safeguards it employed to protect PII stored within that system is an activity performed for the common benefit of all citizens of the state.”

The impact of this ruling is significant for both the City of Columbus and other municipalities across Ohio. It establishes that cities can be held accountable for data breaches if they fail to implement adequate cybersecurity measures. This decision may encourage cities to invest more in data protection and cybersecurity training to avoid similar lawsuits in the future.

Moreover, the ruling may set a precedent for other cases involving municipal liability in data breaches, as it clarifies the distinction between governmental and proprietary functions in the context of cybersecurity. As more municipalities face cyber threats, this ruling could lead to increased scrutiny of their cybersecurity practices and policies.

Looking ahead, the City of Columbus may choose to appeal the decision to the Ohio Supreme Court. The outcome of this case could have far-reaching implications for how cities across Ohio handle personal data and the legal responsibilities they hold in protecting that information. The court's decision also highlights the growing importance of cybersecurity in the public sector, as cities must now navigate the complexities of data protection while serving their communities.