Cybersecurity Policy Report, D. Idaho: Health Insurance administrator prevails over its accidental data breach victims, (Aug 26, 2025)
Law Firms Mentioned:Frost Brown Todd LLP | Walsh PLLC
Organizations Mentioned:IEC Group Inc.
By Jeffrey H. Brochin, J.D.
Where information disclosed was not sufficiently sensitive to give hackers the means to commit fraud or identity theft, the patients’ concerns remained purely speculative and failed to establish injury-in-fact for standing purposes.
A federal District Court in Idaho has granted the Motion to Dismiss filed by IEC Group, Inc. (Ameriben) in a putative class action lawsuit brought by patients who claimed injury due to the emailing of a filtered spreadsheet later found to be capable of unfiltering. The spreadsheet did not contain social security numbers, financial access information, nor passwords, and the patients’ claims that such information was nevertheless of value to the black market was hypothetical as opposed to being concrete and particularized as required for injury-in-fact giving rise to Article III standing ( Black v. IEC Group, Inc., No. 1:23-cv-00384-AKB (D. Idaho, Aug. 21, 2025)).
Emailed filtered spreadsheet. In August 2023, Ameriben—who contracts with employers to provide health insurance administrative services—notified patients that a data breach occurred in December 2022 when an Ameriben employee emailed a spreadsheet containing “a claims report” to one or more members. The spreadsheet was filtered to show only the recipient’s personal information, however, in July 2023, Ameriben discovered that the spreadsheet could possibly be unfiltered to display the personal information of other members, including that of the patients. Therefore, on August 14, 2023, Ameriben sent a letter to the patients notifying them of the potential disclosure of their information, explaining how to protect their identity, and advising them of their right to receive one or more free credit reports from each of the major credit report bureaus.
The notice further explained that the personal information potentially disclosed included the patients’ first and last name, the employee’s first and last name, a unique tracking number, provider name, claim number, date of service, and the amount billed or paid. Approximately ten days later, on August 25, 2023, the patients filed their initial Complaint on behalf of themselves and a putative class of similarly situated individuals, alleging among other things, negligence, negligence per se, breach of contract, breach of fiduciary duty, and Florida statutory violations. The court granted Ameriben’s motions to dismiss under Rule 12(b)(1) and (b)(6) of the Federal Rules of Civil Procedure, due to lack of standing and fail to state a claim for relief. Presently before the court was Ameriben’s renewed motions to dismiss as to the First Amended Complaint.
Element of injury-in-fact. Ameriben argued that the patients had no standing to bring their claims because they could not allege any concrete injury in fact. The court noted that although a concrete injury may include tangible or intangible harms, it must nevertheless be real and not abstract. Furthermore, in a suit for damages, a concrete harm demands more than the mere risk of future harm, rather, the patients must make a showing of a “certainly impending” or “substantial risk” of harm. To allege a concrete injury from disclosure of personal information, a patient must show the nature of the information disclosed, the context of the disclosure, and other alleged injuries associated with the disclosure that demonstrate an imminent and substantial injury.
Nature of information disclosed. The court observed that whether a patient establishes that future harm is likely--and therefore a concrete injury---turns on the type of personal information compromised. In data breach cases, courts must examine the nature of the specific information at issue to determine whether privacy interests were implicated at all, otherwise, every data breach would confer standing regardless of whether private information was exposed.
The patients’ Amended Complaint referred to the value of patient information ‘on the black market’, but they did not explain how the specific information at issue here (member identification numbers, health provider, and health insurance information) was conducive to medical identity theft. Although the patient cited to public sources that allude to crimes using confidential information, such as social security numbers, they did not support their assertions regarding the patient information at issue in the instant case. The court found that while a social security number, date of birth, or passwords pose an inherent risk of fraud, a patient’s name, references to a patient being insured, review time, and total amount billed do not raise the same sensitivity concerns. Accordingly, the court ruled that the nature of the compromised information did not give rise to an injury-in-fact.
Context of disclosure. As noted above, the context of an alleged disclosure also shapes the risk of injury, and the court therefore proceeded to next examine the context factor in determining risk of injury. Where a data theft is carried out by an outside hacker for nefarious purposes, a “highly attenuated chain of possibilities” as proffered by the patients does not support an allegation that harm is substantial nor imminent. The instant patients made unsubstantiated claims as to how an independent actor may misuse information, but that speculation did not show a substantial risk of harm as might be the case in a “deliberately targeted” or stolen data scenario. The failure to allege that a data thief intentionally targeted the personal information rendered the risk of future identity theft too speculative.
Here, although the Amended Complaint added details regarding the general risks associated with sharing medical data, the court also weighed Ameriben’s post-disclosure notice, which stated that Ameriben had “no reason to believe that someone has or will misuse your healthcare data.” Although the patients asserted that such patient information is valuable on the black market, they did not allege how the information would be used for nefarious purposes, nor did they explain to whom the patient information was disclosed, why it was likely subject to misuse, or why individuals were likely to share that medical diagnoses with the public.
Based on the foregoing, the court granted Ameriben’s Motion to Dismiss, with prejudice.
The case is No. 1:23-cv-00384-AKB.
Judge: Brailsford, A.
Attorneys: Bonner Charles Walsh (Walsh PLLC) for Miles Black. Darren A. Craig (Frost Brown Todd LLP) for IEC Group Inc.
Companies: IEC Group Inc.
Cases: CaseDecisions FederalLegislation GCNNews GeneralNews CyberPrivacyFeed DataPrivacy DataBreach IdahoNews DataSecurity