Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • ELECTRONIC HEALTH RECORDS—N.D. Ill.: Help at Home must face core claims over patient data breach
    • ADMINISTRATION OF FDC ACT—FDA GUIDANCE NOTICES: Protein efficiency ratio rat bioassay studies to demonstrate new infant formula supports quality factor
    • ADMINISTRATION OF MEDICARE/MEDICAID PROGRAMS—DAB DECISIONS: CMS revocation authority for failure to timely report license suspension
    • CIVIL MONEY PENALTIES—DAB DECISIONS: Failure to post machine-readable file listing standard charges lead to imposition of CMP
    • CONTROLLED SUBSTANCES—PROPOSED RULES: Placement of diphenidine in Schedule I
    • DURABLE MEDICAL EQUIPMENT—DAB DECISIONS: CMS properly determined effective date of enrollment of Medicare durable medical equipment supplier
    • ELECTRONIC HEALTH RECORDS—GAO REPORTS: VA has made progress on health information privacy
    • MEDICAL DEVICES NEWS—Cotton Warns FDA About Cyber Vulnerabilities in Chinese-Made Medical Devices
    • STRATEGIC PERSPECTIVES—The Future Ready Lawyer: Experts share insights on making legal AI work
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Health Law Daily Wrap Up, ELECTRONIC HEALTH RECORDS—N.D. Ill.: Help at Home must face core claims over patient data breach, (May 27, 2026)

    Law Firms Mentioned:Polsinelli PC | Strauss Borrelli PLLC
    Organizations Mentioned:HAH Group Holding Co. LLC d/b/a Help at Home | Polsinelli, PC

    By Martin A. Steinberg, J.D.

    The provider must face negligence and implied-contract claims after patients alleged a vendor breach exposed sensitive health and personal data.

    Two patients brought a putative class action against HAH Group Holding, LLC d/b/a Help at Home, after a Ma ...

    By Martin A. Steinberg, J.D.

    The provider must face negligence and implied-contract claims after patients alleged a vendor breach exposed sensitive health and personal data.

    Two patients brought a putative class action against HAH Group Holding, LLC d/b/a Help at Home, after a March 2024 vendor data breach allegedly exposed sensitive personal and health information. The patients asserted claims for negligence, negligence per se, breach of express and implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, and declaratory judgment. The provider moved to dismiss for lack of standing and failure to state a claim. The court held that both patients alleged imminent harm sufficient for forward-looking relief, but only one alleged actual injury sufficient to support damages arising from fraudulent credit card charges, a closed account, and a credit score drop. Applying Illinois law at this stage, the court allowed the negligence and implied-contract claims to proceed but dismissed the remaining claims, limiting damages to the patient alleging actual financial injury (Bernardino v. HAH Group Holding, LLC, No. 1:24-cv-07595 (N.D. Ill. May 19, 2026)).

    Background. The patients alleged that a multistate provider collected and maintained their personal and protected health information, which was exposed when unauthorized actors accessed a vendor’s systems in March 2024. The provider notified affected patients in August 2024 and offered one year of credit monitoring. One patient alleged fraudulent credit card charges, a steep credit-score drop, spam calls and phishing emails, and a belief that her information was for sale on the dark web; the other alleged only fear of future misuse. The patients filed an amended putative class action asserting claims for negligence, negligence per se, breach of express and implied contract, unjust enrichment, breach of fiduciary duty, breach of confidence, and declaratory judgment, and the provider moved to dismiss for lack of standing and failure to state a claim.

    Article III standing. The court held that both patients sufficiently alleged imminent injury for purposes of forward-looking relief. The provider argued that the patients lacked Article III standing because their alleged injuries were too speculative. The court explained that standing requires an injury in fact that is concrete, particularized, and actual or imminent, and that each named patient in a putative class action must show personal injury. The court also distinguished between forward-looking relief and damages: a substantial risk of future harm may support injunctive or declaratory relief, but damages require concrete harm that has already materialized.

    Imminent injury. The court held that, under Seventh Circuit data-breach precedent, the increased risk of identity theft and fraud can support standing for injunctive relief, especially where one patient’s notice letter confirmed that her Social Security number was exposed. The patients alleged that the breach exposed sensitive private information, including Social Security numbers, medical information, financial account numbers, and dates of birth. The court rejected the provider’s causation argument, finding it reasonable to infer that hackers steal sensitive data to commit fraud or identity theft.

    Actual injury. The court held that only one patient alleged actual injury sufficient to support damages. She reported fraudulent credit card charges, a closed account, a drop in her credit score, increased spam calls and phishing emails, and the belief that her information was for sale on the dark web. The court found those allegations sufficiently tied to the breach at the pleading stage because her Social Security number and date of birth were exposed and could plausibly be used to access financial accounts.

    By contrast, the other patient alleged only fear of future misuse, diminished value of her information, anxiety, loss of the benefit of the bargain, and time spent responding to the breach. Because she did not allege publication, misuse, or out-of-pocket costs, those theories did not support damages. Both patients could pursue injunctive and declaratory relief, but only the patient alleging fraudulent charges and related financial harm could seek damages.

    Choice of law. The court declined to conduct a full choice-of-law analysis at the pleading stage, reasoning that nationwide class-action choice-of-law issues required further factual development about the location of the data, conduct, services, and alleged harms. The court also found that the provider had not identified any dispositive conflict among the laws of Illinois, Indiana, and New York, so it applied Illinois law for purposes of the motion to dismiss.

    Negligence claim. The court allowed the negligence claim to proceed. It found that the patients plausibly alleged that the provider owed a common-law duty to safeguard sensitive personal and health information, given its role as a national health-services provider. The court also rejected the provider’s economic-loss-doctrine argument because the alleged data-security duty arose independently of any express contract.

    Negligence per se claim. The court dismissed the negligence per se claim. Although the patients relied on alleged violations of the FTC Act and HIPAA, the court held that those statutes did not create a separate private cause of action for negligence per se under Illinois law. At most, the alleged statutory violations could support the ordinary negligence claim as evidence of breach.

    Breach of express contract claim. The court dismissed the express-contract claim because the patients did not adequately allege that the provider’s privacy policy was itself an enforceable contract or that it was incorporated into any services contract. The complaint did not plead definite contract terms, offer and acceptance, or how the privacy policy became part of the parties’ agreement.

    Breach of implied contract claim. The court allowed the implied-contract claim to proceed by finding it plausible that, by requiring patients to provide sensitive information as a condition of receiving services, the provider impliedly agreed to keep that information private and to protect it from unauthorized disclosure. The court also found the allegations of damages sufficient at the pleading stage, particularly as to the patient who alleged fraudulent credit card charges and a drop in credit score.

    Unjust enrichment claim. The court dismissed the unjust enrichment claim on the ground that providing sensitive information was incidental to the patient-provider relationship and did not confer a separate benefit on the provider. The court also noted that the alleged benefit from the breach flowed to the hackers, not the provider.

    Breach of fiduciary duty claim. The court dismissed the fiduciary-duty claim because Illinois law had not recognized a fiduciary duty between a home-services provider and its patients in this context, and the claim largely duplicated the negligence theory. The court declined to expand Illinois law by recognizing a new fiduciary-duty claim.

    Breach of confidence claim. The court dismissed the breach-of-confidence claim for similar reasons. The patients acknowledged that Illinois courts had not recognized such a claim in the data-breach context, and the court declined to create a novel state-law cause of action.

    Declaratory judgment. The court dismissed the declaratory-judgment count because declaratory relief is a remedy, not an independent cause of action. The dismissal did not foreclose the patients from seeking declaratory relief as a remedy if otherwise supported by the surviving claims.

    The case is No. 1:24-cv-07595.

    Judge: Kendall, V.

    Attorneys: Cassandra P. Miller (Strauss Borrelli PLLC) for Lisa Vaughn Bernardino, Joann Loffler, Jimmy Tavares and Nicole Delia. Mary Clare G. Bonaccorsi (Polsinelli PC) for HAH Group Holding Co. LLC d/b/a Help at Home.

    Companies: HAH Group Holding Co. LLC d/b/a Help at Home

    MainStory: TopStory CaseDecisions CyberPrivacyFeed EHRNews GCNNews HITNews HealthReformNews HomeNews DataSecurity DataBreach IllinoisNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use