• CASES

    Search by

RX-V inc. v. Pharmacie Lisa Gaudreault et Suzie Desmarais inc.

Executive Summary: Key Legal and Evidentiary Issues

  • Whether an insurer can be compelled, through a Wellington-type application, to defend its insureds in a warranty claim arising from a fraudulent wire transfer.
  • Coverage under the professional liability policy was conceded to be triggered, leaving only the applicability of exclusion clause 3.01(u)(ii) in dispute.
  • The insurer bore the burden of proving that the exclusion applied clearly and unequivocally, eliminating any possibility of coverage.
  • Exclusion clauses must be interpreted restrictively, while coverage provisions receive a broad interpretation favourable to the insured.
  • Ambiguity existed as to whether the claimed damages "flowed from" the breach of informational assets or instead from the accountants' alleged failure to verify banking details.
  • No extrinsic evidence was before the Court regarding the parties' reasonable expectations or comparable policies, which would be required to resolve the ambiguity.

Facts of the case

In July 2024, Pharmacie Lisa Gaudreault et Suzie Desmarais inc. ("Pharmacie") purchased a pill-dispenser verification system from RX-V inc. for a price of $120,896. When the time came to pay, its accountant, Simon Dufresne-Tremblay of the firm Les Services Comptables B.D.G.L. inc. (together, "BDGL"), recommended paying by bank transfer rather than by cheque. Pharmacie agreed and emailed BDGL the documents needed for BDGL to carry out the payment. According to the allegations, a cyber-fraudster managed to replace Pharmacie's instruction email with one containing her own banking coordinates. BDGL used the banking details from the fraudulent email, and the transfer of nearly $121,000 was made into the fraudster's account, from which the funds promptly disappeared. RX-V inc. sued Pharmacie for the balance owed. Pharmacie in turn brought a warranty claim against BDGL, alleging it failed to perform the necessary verifications before transferring the funds, and seeking indemnification for any judgment rendered in favour of RX-V inc. BDGL then turned to its insurer, the Fonds d'assurance de la responsabilité professionnelle de l'Ordre des comptables professionnels agréés du Québec (the "Fonds"), serving it with a forced intervention application and a Wellington-type application to compel it to take up their defence. The Fonds denied coverage and refused to assume the defence.

Policy terms at issue

The Fonds acknowledged that the policy's coverage was triggered, since the alleged fault was committed in the course of providing professional services, but argued the claim fell within exclusion clause 3.01(u)(ii). That clause excludes claims seeking damages flowing from a breach of the right to privacy, or a breach of the confidentiality, integrity, or availability of informational assets, where that breach itself flows from unauthorized access to or use of a computer system, malicious code infecting a computer system, or an act of social engineering. The policy defines "computer system" as including any computer, hardware, or software, and "informational asset" as including computer systems, infrastructure, or equipment, as well as any software, website, application, document, or data. The term "act of social engineering" is not defined in the policy, but the Court understood it to refer to techniques used to manipulate a person into doing things or disclosing confidential information, and it did not appear contested that the term would apply to the fraudster's conduct here.

The court's reasoning and analysis

Justice Patrick Ferland of the Quebec Superior Court set out the principles governing Wellington-type applications: the insurer's duty to defend is autonomous from its duty to indemnify, and it arises from the mere possibility, appearing prima facie from the allegations of the principal action, that the policy covers the acts or omissions alleged. Because the Fonds relied on an exclusion, it bore the burden of proving that coverage was excluded clearly and unequivocally, leaving no possibility that it could be required to indemnify its insured, and exclusion clauses must be interpreted restrictively. The Court found the dispute turned strictly on the interpretation of the exclusion clause. Under the Fonds' reading, the claim sought damages flowing from a breach of the integrity of BDGL's informational assets, which itself flowed from unauthorized access and an act of social engineering. BDGL countered that the exclusion targets only damages whose legal cause is the breach of the informational asset itself, not damages caused by the insured's own fault or negligence, even where that fault occurred following or because of the unauthorized access or social engineering. The Court found the policy's terms were open to more than one interpretation. On BDGL's reading, the deletion of the original email and its replacement with a fraudulent one did not in themselves cause any damage; they were merely the occasion of the damage, or a circumstance increasing the risk that damage would occur, whereas it was BDGL's alleged lack of adequate verification that brought about the loss. The Court noted that this reading appeared consistent with the ordinary meaning of the clause's terms, and observed that had the Fonds wished to exclude all harmful consequences of social engineering or unauthorized access, it could have drafted a broader exclusion. While the Fonds argued that cyber-risks are the subject of specialized coverage with high premiums and that the policy should be read in line with the parties' expectations, the Court held that no evidence was before it comparing similar policies, cyber-risk policies, or establishing the parties' reasonable expectations, and such evidence would be required. In the absence of any evidence allowing it to set aside BDGL's interpretation, the Court could not conclude that the exclusion applied clearly and unequivocally, and there remained a real possibility that the Fonds would be required to indemnify its insured.

Ruling and outcome

The Court concluded that the test for granting the Wellington application was met and allowed the application brought by Les Services Comptables B.D.G.L. inc. and Simon Dufresne-Tremblay, who were the successful parties. It ordered the Fonds to take up their defence in the warranty claim instituted against them by Pharmacie, to assume their defence costs, and to reimburse the fees and professional costs they had incurred to date in their defence, with legal costs. No specific dollar amount for the defence costs, reimbursement, or legal costs was stated in the judgment; the total amount ordered in favour of the successful parties therefore cannot be determined from the decision. The underlying claim in the main action concerns the transfer of approximately $121,000 (a purchase price of $120,896), but the merits of that dispute remain to be decided.

RX-V inc.
Law Firm / Organization
François Crevier Avocat
Lawyer(s)

François Crevier

Pharmacie Lisa Gaudreault et Suzie Desmarais inc.
Lawyer(s)

Vincent Patoine

Les Services Comptables B.D.G.L. inc.
Law Firm / Organization
Gauthier Bédard
Lawyer(s)

Anne-Julie Paquin

Simon Dufresne-Tremblay
Law Firm / Organization
Gauthier Bédard
Lawyer(s)

Anne-Julie Paquin

Fonds d’assurance de la responsabilité professionnelle de l’Ordre des comptables professionnels agréés du Québec
Law Firm / Organization
Norton Rose Fulbright Canada LLP
Lawyer(s)

Kim Bernard

Quebec Superior Court
500-17-136103-259
Insurance law
Not specified/Unspecified
Defendant