780 F.Supp.3d 588
W.D. Pa.2025Background
- In December 2022, a Highmark employee fell victim to a phishing email, resulting in a data breach that exposed sensitive personal and health information of Highmark members.
- The breach included names, contact information, social security numbers, financial and health data, some of which were later found on the dark web or linked to fraudulent activities.
- Highmark discovered the breach on December 15, 2022, but did not notify affected members until February 2023.
- Plaintiffs brought a class action against Highmark, alleging failures to safeguard data and seeking damages and injunctive relief under several theories (including negligence, breach of implied contract, unjust enrichment, and others).
- Highmark moved to dismiss, arguing that plaintiffs lacked standing and failed to state any viable claims.
- The court granted the motion in part and denied it in part, allowing some claims to proceed and dismissing others.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Article III Standing (Injury in Fact) | Data breach caused actual/imminent harm and loss | Harm too speculative, no misuse alleged | Plaintiffs pled imminent, concrete injury; standing found |
| Negligence (Economic Loss Doctrine) | Special relationship/duty to safeguard PII/PHI | Barred by economic loss doctrine | Economic loss doctrine doesn't bar claim; claim survives |
| Negligence Per Se | Violations of statutory duties (FTC Act, HIPAA) | No private right of action; duplicative | Dismissed; PA law doesn't recognize as independent claim |
| Breach of Fiduciary Duty | Insurer/insured relationship is confidential | No fiduciary relationship here | Dismissed; no facts pled showing required relationship |
| Breach of Confidence | Failure to safeguard constitutes disclosure | No affirmative disclosure alleged | Dismissed; theft by third party not "disclosure" |
| Breach of Implied Contract | Privacy policies form implied contract to protect | No specific terms/obligations alleged | Claim survives; policies and conduct suffice at this stage |
| Unjust Enrichment | Payments included expectation of data security | Plaintiffs paid for insurance, not security | Claim survives; plausible at pleading stage |
| Declaratory Judgment | Need declaration re: duty and breach | Overlaps with substantive claims | Survives; not dismissed at motion-to-dismiss stage |
Key Cases Cited
- Ashcroft v. Iqbal, 556 U.S. 662 (plausibility standard for motions to dismiss)
- Spokeo, Inc. v. Robins, 578 U.S. 330 (requirements for Article III standing)
- Clemens v. ExecuPharm Inc., 48 F.4th 146 (data breach standing guideposts)
- TransUnion LLC v. Ramirez, 594 U.S. 413 (concreteness in Article III standing)
- Dittman v. UPMC, 196 A.3d 1036 (economic loss doctrine and duties re: data protection)
- Yenchi v. Ameriprise Fin., Inc., 161 A.3d 811 (fiduciary duties in insurer/insured context)
