midpage
Projects
Sign in to see your projects.
780 F.Supp.3d 588
W.D. Pa.
2025
Read the full case

Background

  • In December 2022, a Highmark employee fell victim to a phishing email, resulting in a data breach that exposed sensitive personal and health information of Highmark members.
  • The breach included names, contact information, social security numbers, financial and health data, some of which were later found on the dark web or linked to fraudulent activities.
  • Highmark discovered the breach on December 15, 2022, but did not notify affected members until February 2023.
  • Plaintiffs brought a class action against Highmark, alleging failures to safeguard data and seeking damages and injunctive relief under several theories (including negligence, breach of implied contract, unjust enrichment, and others).
  • Highmark moved to dismiss, arguing that plaintiffs lacked standing and failed to state any viable claims.
  • The court granted the motion in part and denied it in part, allowing some claims to proceed and dismissing others.

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Article III Standing (Injury in Fact) Data breach caused actual/imminent harm and loss Harm too speculative, no misuse alleged Plaintiffs pled imminent, concrete injury; standing found
Negligence (Economic Loss Doctrine) Special relationship/duty to safeguard PII/PHI Barred by economic loss doctrine Economic loss doctrine doesn't bar claim; claim survives
Negligence Per Se Violations of statutory duties (FTC Act, HIPAA) No private right of action; duplicative Dismissed; PA law doesn't recognize as independent claim
Breach of Fiduciary Duty Insurer/insured relationship is confidential No fiduciary relationship here Dismissed; no facts pled showing required relationship
Breach of Confidence Failure to safeguard constitutes disclosure No affirmative disclosure alleged Dismissed; theft by third party not "disclosure"
Breach of Implied Contract Privacy policies form implied contract to protect No specific terms/obligations alleged Claim survives; policies and conduct suffice at this stage
Unjust Enrichment Payments included expectation of data security Plaintiffs paid for insurance, not security Claim survives; plausible at pleading stage
Declaratory Judgment Need declaration re: duty and breach Overlaps with substantive claims Survives; not dismissed at motion-to-dismiss stage

Key Cases Cited

  • Ashcroft v. Iqbal, 556 U.S. 662 (plausibility standard for motions to dismiss)
  • Spokeo, Inc. v. Robins, 578 U.S. 330 (requirements for Article III standing)
  • Clemens v. ExecuPharm Inc., 48 F.4th 146 (data breach standing guideposts)
  • TransUnion LLC v. Ramirez, 594 U.S. 413 (concreteness in Article III standing)
  • Dittman v. UPMC, 196 A.3d 1036 (economic loss doctrine and duties re: data protection)
  • Yenchi v. Ameriprise Fin., Inc., 161 A.3d 811 (fiduciary duties in insurer/insured context)
Read the full case

Case Details

Case Name: DOE v. HIGHMARK, INC.
Court Name: District Court, W.D. Pennsylvania
Date Published: Apr 28, 2025
Citations: 780 F.Supp.3d 588; 2:23-cv-00250
Docket Number: 2:23-cv-00250
Court Abbreviation: W.D. Pa.
Log In