IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND * IN RE HEALTHCARE * INTERACTIVE, INC. * DATA BREACH LITIGATION * * Civil Case No.: SAG-25-4034 * * * * * * * * * * * * * * MEMORANDUM OPINION Four plaintiffs brought separate actions against Healthcare Interactive, Inc. (“HCI” or “Defendant”), individually and on behalf of those similarly situated, alleging injuries from HCI’s failure to protect their private information from a data breach of HCI’s computer network. ECF 3. The separate actions were consolidated into the instant case. ECF 4. In the consolidated action, seventeen individuals, bringing suit on behalf of themselves and all others similarly situated (“Plaintiffs”), filed the Consolidated Class Action Complaint on January 30, 2026. ECF 12. The Consolidated Class Action Complaint alleges common law fraud and contract claims, along with a violation of the Maryland Consumer Protection Act,on behalf of all Plaintiffs. Id.It also alleges violations of California consumer protection laws on behalf of Plaintiffs who reside in California. Id.HCI has filed a Motion to Dismiss the Consolidated Class Action Complaint.ECF 22. Plaintiffs oppose the motion, ECF 27, and HCI filed a reply, ECF 28. This Court has reviewed the filings and finds that no hearing is necessary. See Loc. R. 105.6 (D. Md. 2025). For the reasons explained below, the Motion will be granted,and the Consolidated Class Action Complaint will be dismissed without prejudice. I. BACKGROUND The following facts are derived from Plaintiffs’ Consolidated Class Action Complaint, ECF 12, and are assumed to be true for the purpose of the motion to dismiss. HCI is a “Maryland- based technology provider that develops AI-powered software solutions for insurance enrollment and benefits administration.” Id.¶ 2. It “specializes in health and incentive management platforms
that connect and manage healthcare service providers and clients.” Id.HCI collects and stores the private information of “thousands of its current and former clients and its employees.” Id. ¶ 32. The Data Breach On or around July 22, 2025, HCI became aware of suspicious activity related to its computer network. Id. ¶ 39. HCI investigated the incident and discovered a breach of its network system had occurred between July 8, 2025, and July 12, 2025, wherein “an unauthorized actor copied certain files from [HCI’s] computer network.” Id.¶ 40; ECF 12-1 at 1. Plaintiffs allege the breach “compromised the Private Information of 87,565 of [HCI’s] current and former clients and its employees.” ECF 12¶ 6.
HCI sent notice of the breach to potentially affected individuals on December 5, 2025. Id. ¶ 42; ECF 12-1. Six named Plaintiffs allege that they received the notice of data breach. ECF 12 ¶¶ 56, 108, 175, 193, 312, 329. In the notice, HCI stated that it “evaluated the impacted files and determined that protected information was contained within the files that were potentially acquired by the unauthorized actor,” however, HCI was “not aware of any actual or attempted misuse of information within its care.” ECF 12-1 at 1. Potentially affected data includes: Name; date of birth; email address; phone number; mailing address; Social Security number; blood results and/or biometric data; health insurance enrollment data (such as health plans/policies, insurance companies, and member/group ID numbers); medical data (such as medical record numbers, doctors, diagnoses, care, prescription information, and treatment); and health insurance claims data (such as claim numbers, account numbers, explanation of benefits, and billing codes). Id.; ECF 12¶ 6. Inthe notice,HCI also suggested that individuals take measures to protect against possible identity theft. Id. ¶ 45; ECF 12-1 at 2. Plaintiffs’ Injuries Due to the data breach, Plaintiffs allege that their private information “was placed into the hands of cybercriminals—inflicting numerous injuries and significant damages.” Id. ¶ 46. Plaintiffs further allege that they “suffered or are at an increased risk of suffering” the following: a. loss of the opportunity to control how their Private Information is used; b. diminution in value of their Private Information; c. compromise and continuing publication of their Private Information; d. out-of-pocket costs from trying to prevent, detect, and recovery from identity theft and fraud; e. lost opportunity costs and wages from spending time trying to mitigate the fallout of the Data Breach by, inter alia, preventing, detecting, contesting, and recovering from identify theft and fraud; f. delay in receipt of tax refund monies; g. unauthorized use of their stolen Private Information; and h. continued risk to their Private Information—which remains in Defendant’s possession—and is thus as risk for futures breaches so long as Defendant fail to take appropriate measures to protect the Private Information. Id. ¶ 342. The seventeen named Plaintiffs allege the above injuries stemming from the breach. Six named Plaintiffs allege additional, individualized injuries: a. Plaintiff Papcke “has experienced a drastic increase in spam emails, texts, and telephone calls regarding prescription medicine, medical procedures, and doctors, for which she has not inquired.” Id. ¶ 77. b. Plaintiff Levsen experienced a “significant increase in spam emails since the Data Breach occurred which claim that there are open/potential loan applications in his name.” Id. ¶ 161. In response, Plaintiff Levsen “mailed documents to the credit bureaus to freeze his children’s credit and he took approximately half a day off of work to do so. The mailings cost $4.20 for stamps.” Jd. § 160. c. On November 8, 2025, Plaintiff Arevalo “received a notice that his personal information had been found on the dark web.” Jd. § 176. d. In November, 2025, Plaintiff B. Gene Taylor III “received a large package delivered to his home from Amazon containing holiday decorations he did not order. No change was made to his account, nor his wife’s account, and Amazon refused to disclose who had placed the order nor allow them, to return the items.” Jd. J 284. e. Plaintiff Natalie Taylor, the spouse of Plaintiff Taylor III, also received the same Amazon package at their shared home. /d. 301. Further, in the fall of 2025, prior to the package incident, “an unauthorized actor attempted to access Plaintiff [Natalie] Taylor’s Gmail account over 100 times, prompting her to change her password.” /d. f. Plaintiff Owen has experienced “a drastic increase in spam emails, texts, and telephone calls, often taking the form of fake medical alerts and unsolicited inquiries from individuals purporting to be Rocket Mortgage, as a result of the Data Breach.” /d. § 339. Additionally, “on December 20—21, 2025, she received an alert from Aura Credit Monitoring that they fulfilled 11 removal requests of fraudulent inquiries on her credit report.” /d. The fraudulent inquiries were from Instant Data, Address Search.Com., Homeowner’s marketing services, instant data, topacta, VLOOKUP, oldphonebook, America Phonebook, posti, linesharemarketing, and IDM. Jd. The Class Action The seventeen named Plaintiffs seek to represent a class of “[aJll individuals residing in the United States whose Private Information was compromised in the Data Breach discovered by
Defendant in July 2025, including all those individuals who received notice of the breach” (the “Nationwide Class”). /d. § 373. Additionally, three named Plaintiffs, who reside in California, seek to represent a subclass of “[a]ll individuals residing in California whose Private Information was compromised in the Data Breach discovered by Defendant in July 2025, including all those individuals who received notice of the breach” (the “California Subclass”). Id. § 374. The Nationwide Class asserts six claims: negligence (Count I), breach of implied contract (Count IT), unjust enrichment (Count IIT), breach of fiduciary duty (Count IV), invasion of privacy (Count V), and violations of the Maryland Consumer Protection Act (Count X). The California Subclass asserts additional violations of California consumer protection laws: the California Unfair Competition Law (Count VJ), California Consumer Privacy Act (Count VID), California Customer Records Act (Count VIII), and the Confidentiality of Medical Information Act (Count IX). The classes seek declaratory relief, injunctive relief, and monetary damages, including compensatory, exemplary, punitive, and statutory damages. /d. at 84-85. HCI has now filed a motion to dismiss the Consolidated Class Action Complaint under Federal Rules of Civil Procedure 12(b)(1) and 12(b)(6). ECF 27. HCI’s Motion is based upon two grounds. First, HCI argues that the Court should dismiss Plaintiffs’ claims because they have failed to allege an injury-in-fact and lack standing. Second, HCI asserts that the Court should dismiss Plaintiffs’ claims for failure to state a claim upon which relief can be granted. HCI’s Rule 12(b)(1) Motion will be granted for lack of standing. As a result, the Court will find moot and not address HCI’s alternative argument to dismiss under Rule 12(b)(6).
II. LEGAL STANDARDS A. Rule 12(b)(1) Standard When a Rule 12(b)(1) motion contests the factual basis for subject matter jurisdiction, the burden of proving subject matter jurisdiction rests with the plaintiff. Richmond, Fredericksburg & Potomac R.R. Co. v. United States, 945 F.2d 765, 768 (4th Cir. 1991). A challenge to jurisdiction
may be either facial, i.e., the complaint fails to allege facts upon which subject matter jurisdiction can be based, or factual, i.e., jurisdictional allegations of the complaint are not true. Adams v. Bain, 697 F.2d 1213, 1219 (4th Cir. 1982); see also Kerns v. United States, 585 F.3d 187, 192 (4th Cir. 2009) (same); Richmond, Fredericksburg & Potomac R.R. Co., 945 F.2d at 768 (same). In determining whether jurisdiction exists, the district court regards the pleadings’ allegations as mere evidence and may consider evidence outside the pleadings without converting the proceeding to one for summary judgment. Richmond, Fredericksburg & Potomac R.R. Co., 945 F.2d at 768. B. Standing for a Class Action Complaint Article III of the U.S. Constitution limits the jurisdiction of federal courts to “Cases” and
“Controversies.” U.S. Const. art. III, § 2. “One element of the case-or-controversy requirement is that plaintiffs must establish that they have standing to sue.” Clapper v. Amnesty Int’l USA, 568 U.S. 398, 408 (2013) (internal citations and quotation marks omitted). To invoke federal jurisdiction, a plaintiff bears the burden of establishing the minimum requirements of Article III standing. Lujan v. Defs. of Wildlife, 504 U.S. 555, 561 (1992). “[T]he procedural posture of the case dictates the plaintiff’s burden as to standing.” Beck v. McDonald, 848 F.3d 262, 270 (4th Cir. 2017) (citing Lujan, 504 U.S. at 561). “At the pleading stage, general factual allegations of injury resulting from the defendant’s conduct may suffice, for on a motion to dismiss we presume that general allegations embrace those specific facts that are necessary to support the claim.” Id. (quoting Lujan, 504 U.S. at 561) (internal quotation marks omitted). In a class action, “[e]very class member must have Article III standing in order to recover individual damages.” TransUnion LLC v. Ramirez, 594 U.S. 413, 431 (2021). The Court analyzes standing based on the allegations of personal injury made by the named plaintiffs. Beck, 848 F.3d
at 269 (citing Doe v. Obama, 631 F.3d 157, 160 (4th Cir. 2011)). “Without a sufficient allegation of harm to the named plaintiff in particular, plaintiffs cannot meet their burden of establishing standing.” Id. at 270 (quoting Doe, 631 F.3d at 160) (internal quotation marks omitted). III. DISCUSSION To invoke federal jurisdiction, Plaintiffs must establish the three “irreducible” minimum requirements of Article III standing: (1) injury in fact, (2) causation, and (3) redressability. Lujan, 504 U.S. at 560. At issue here arethe first two elements, injury in fact and causation. “To establish injury in fact, a plaintiff must show that he or she suffered ‘an invasion of a legally protected interest’ that is ‘concrete and particularized’ and ‘actual or imminent, not
conjectural or hypothetical.’” Spokeo, Inc. v. Robins, 578 U.S. 330, 339 (2016) (quoting Lujan, 504 U.S. at 560). A “‘threatened rather than actual injury can satisfy Article III standing requirements,’” but “not all threatened injuries constitute an injury-in-fact.” Beck, 848 F.3d at 271 (quoting Friends of the Earth, Inc. v. Gaston Copper Recycling Corp., 204 F.3d 149, 160 (4th Cir. 2000)). “Although ‘imminence’ is concededly a somewhat elastic concept, it cannot be stretched beyond its purpose, which is to ensure that the alleged injury is not too speculative for Article III purposes.” Id. (quoting Lujan, 504 U.S. at 564–65 n.2) (internal quotation marks omitted). Ultimately, a “threatened injury must be certainly impending to constitute injury in fact.” Clapper, 568 U.S. at 409 (internal citations and quotation marks omitted) (emphasis in original). The causation prong of standing requires that a plaintiff’s alleged injury be “fairly ... traceable to the challenged action of the defendant, and not ... the result of the independent action of some third party not before the court.” Rouse v. Fader, 171 F.4th 272, 280 (4th Cir. 2026) (quoting Lujan, 504 U.S. at 560) (internal quotations omitted). However, causation “does not require that a defendant’s actions ‘be the sole or even immediate cause of [a plaintiff’s] injury.’”
Sheppheard v. Morrisey, 143 F.4th 232, 243 (4th Cir. 2025) (quoting Sierra Club v. U.S. Dep’t of the Interior, 899 F.3d 260, 284 (4th Cir. 2018)). The Article III causation burden is “‘relatively modest,’ especially at the ‘motion-to-dismiss stage,’” Lowy v. Daniel Def., LLC, 167 F.4th 175, 195–96 (4th Cir. 2026) (quoting DiCocco v. Garland, 52 F.4th 588, 592 (4th Cir. 2022)), but a “highly attenuated chain of possibilities” will not support standing. Clapper, 568 U.S. at 410. The Fourth Circuit has specifically addressed standing requirements in data breach suits. It has held that “an alleged injury in an identity theft case is constitutionally sufficient under two recognized circumstances: (1) through actual injury of identity theft; or (2) a threatened injury based on substantial risk of future identity theft that is sufficiently imminent.” In re Marriott Int’l,
Inc., Customer Data Sec. Breach Litig., No. 19-MD-2879, 2020 WL 6290670, at *4 (D. Md. Oct. 27, 2020) (citing Hutton v. Nat’l Bd. of Exam’rs in Optometry, Inc., 892 F.3d 613, 622 (4th Cir. 2018)); see also Beck v. McDonald, 848 F.3d 262, 274 (4th Cir. 2017). An individual “being subjected to a data breach isn’t in and of itself sufficient to establish Article III standing without a nonspeculative, increased risk of identity theft.” O’Leary v. TrustedID, Inc., 60 F.4th 240, 244 (4th Cir. 2023). Rather, standing in data breach cases is usually found in cases that include “allegations indicating that some of the stolen data had already been misused, that there was a clear intent to use the plaintiffs’ personal data for fraudulent purposes, or both.” Burger v. Healthcare Mgmt. Sols., LLC, No. CV 23-1215, 2024 WL 473735, at *5 (D. Md. Feb. 7, 2024) (quoting Khan v. Children’s Nat’l Health Sys., 188 F. Supp. 3d 524, 531 (D. Md. 2016)) (internal quotations omitted). Two Fourth Circuit cases illustrate this standard. In Beck vy. McDonald, the court held that plaintiffs in two consolidated appeals whose personal information was compromised in data breaches had not shown an Article III injury based on an alleged “increased risk of future identity theft and the cost of measures to protect against it.” 848 F.3d 262, 267 (4th Cir. 2017). In the first consolidated case, the defendant’s laptop containing plaintiffs’ private information was stolen by an unauthorized user, and in the second, the defendant’s record boxes containing plaintiffs’ health and private data were lost or stolen. /d. at 267—268. The court found that the threat of identity theft and misuse of the personal information was merely speculative because, “even after extensive discovery,” there was “no evidence” that the information had been “accessed or misused or that [the plaintiffs had] suffered identity theft.” /d. at 274. There was also no evidence that the thief even stole the laptop or record boxes with the intent to steal private information. /d. Even though plaintiffs’ private information was stolen, the Fourth Circuit held that “the mere theft of these items, without more, cannot confer Article II] standing.” /d. at 275. On the other hand, in Hutton vy. Nat’l Bd. Of Examiners in Optometry, Inc., the Fourth Circuit held that the plaintiffs had standing where they were “victims of identity theft traceable to the defendant’s data breach.” O Leary, 60 F 4th at 244 (citing Hutton, 892 F.3d at 621-22). There, the named plaintiffs had already suffered identity theft and credit card fraud such that there was “no need to speculate on whether substantial harm will befall” them. Hutton, 892 F.3d at 622. Specifically, the named plaintiffs alleged that they: (1) “received an unsolicited Chase Amazon Visa credit card that was applied for using her social security number and her maiden name (the name that she had provided to the NBEO in 1998);” (2) “learned that someone had applied for a
Chase credit card using her social security number and former married name;” and (3) “received an alert that her credit score had decreased eleven points due to a credit application that was fraudulently filed with Chase, using her address, social security number, and mother’s maiden name.” /d. In contrast to Beck, this information sufficed to allege that the plaintiffs’ “data ha[d] been stolen, accessed, and used in a fraudulent manner.” /d. In Hutton, the Fourth Circuit also found that the plaintiffs had satisfied the causation prong of standing because the complaint “contained sufficient allegations that the [defendant] was a plausible source of the [p]laintiffs’ personal information” that had been fraudulently used. /d. at 623. To reach this conclusion, the court looked to factual allegations that fraudulent credit cards were applied for using the former surnames of two plaintiffs who had provided the defendant with those names years earlier; a plaintiff “was informed by a credit monitoring service of an effort to open a fraudulent credit card account in her name, using personal information she had previously provided to [the defendant]” years earlier; and “other national optometry organizations do not gather or store Social Security numbers, or have investigated and confirmed that their databases have not been breached.” /d. at 623. Thus, the court reasoned, the plaintiffs plausibly alleged that, “amongst the group of optometrists, the [defendant] is the only common source that collected and continued to store social security numbers that were required to open a credit card account, and also stored outdated personal information ... during the relevant time periods.” /d. A. Actual Injury Plaintiffs argue that injury in fact exists here because they have suffered the following actual injuries: (1) identity theft and attempted fraud, (2) emotional distress, and (3) diminution in the value of their private information. ECF 27 at 4-10, 12-15. These, Plaintiffs contend, “are causally connected to Defendant’s actions resulting in the Data Breach.” /d. at 17. The Court finds
that these allegations in Plaintiffs’ Consolidated Class Action Complaint are more akin to Beck than to Hutton because Plaintiffs fail to allege specific misuse of their private information or traceability of any harm from the breach of HCI’s systems. “Actual misuse is the keystone of Article III injury in Fourth Circuit data breach case law.” Capiau v. Ascendum Mach., Inc., No. 24-CV-00142, 2024 WL 3747191, at *4 (W.D.N.C. Aug. 9,
2024) (collecting cases). “One way for a data breach plaintiff to establish actual misuse—and thus Article III injury—is to credibly plead ‘that their data [has] been used in a fraudulent manner’ as a consequence of the breach.” Id. (quoting Stamat v. Grandizio Wilkins Little & Matthews, LLP, No. CV 22-00747, 2022 WL 3919685, at *5 (D. Md. Aug. 31, 2022)); see also Hutton, 892 F.3d at 622. Of the seventeen named Plaintiffs, eleven clearly fail to allege actual misuse of their private information: Plaintiffs Paige, Cruz, Nussbaum, Breet, Harrison, Maestas, Robinson, E.T., R.T., R.T., and Quednow. These named Plaintiffs allege only general and speculative harms from the breach, and do not allege that their private information has actually been used in a fraudulent
manner.Specifically, theyallege in a conclusory manner that they have suffered actual injury from the “exposure, theft, and dissemination of [their] Private Information on the dark web,” ECF 12¶¶ 62, 80, 97, 114, 131, 148, 164, 182, 199, 216, 233, 250, 267, 284, 301, 318, 335, and “in the form of damages to and diminution in the value of [their] Private information,” id. ¶¶ 63, 81, 98, 115, 132, 149, 165, 183, 200, 217, 234, 251, 268, 285, 302, 319, 336. Even accepting as true the contentions that named Plaintiffs’ private information was stolen in the breach,1 these allegations provide no information regarding how or where their private information has been published, or
1 Again, only six of the named Plaintiffs received notice from HCI that their data was potentially acquired by the bad actor. ECF 12 ¶¶ 56, 108, 175, 193, 312, 329. whether they have suffered actual or attempted identity theft and fraud as a result. These general allegations are insufficient to establish standing.See Beck, 848 F.3d at 275 (finding that the “mere theft” of the plaintiff’s personal information “without more, cannot confer Article III standing”). The remaining six named Plaintiffs—Plaintiffs Papcke, Levsen, Taylor III, Taylor, Arevalo, and Owen—allege more specific injuries that present a closer case. These injuries include
one or more of the following: increased spam communications, receiving notice that their information was published on the dark web, receiving (but not being charged for) a package of holiday decorations, receiving notice from a credit monitoring agency, and unauthorized attempts to access their email accounts. ECF 12 ¶¶ 77, 160, 161, 176, 284, 301, 339. However, these allegations are not sufficient for the Court to find that Plaintiffs have met their standing burden at this time. Plaintiffs do not provide enough information for the Court to determine that these injuries stem from actual misuse of Plaintiffs’ information that is causally connected to HCI’s breach. Plaintiffs do not connect the information that they provided to HCI to these alleged incidents, and only two of these six named Plaintiffs allege that they received notice
that they were potentially affected by the breach from HCI. Id. ¶¶ 175, 329. For example, Plaintiff Arevalo’s allegation that “his personal information had been found on the dark web,” ECF 12 ¶ 176, provides no detail regarding what kind of information was found and whether that same information had been in HCI’s possession before the breach. And Plaintiff Owen’s allegation that Aura Credit Monitoring “fulfilled 11 removal requests of fraudulent inquiries on her credit report,” id. ¶ 339, does not specify if those removal requests were submitted prior to the breach of HCI’s systems.Absent additional detail regarding the timing, substance, and severity of these events, and their connection to the HCI breach, these allegations are insufficient to establish standing. Further, in regard to the allegations of increased spam calls and emails, courts within the Fourth Circuit generally find generic allegations of increased spam calls and emails insufficient for injury in fact. See, e.g., Stuart v. Kyocera AVX Components Corp., 769 F. Supp. 3d 476, 489 (D.S.C. 2025) (rejecting standing based on increased spam calls where “Plaintiffs provide[d] no factual support—including the dates or substance of the alleged calls or emails—to sufficiently
allege an injury in fact”); Burger, 2024 WL 473735, at *6 (D. Md. 2024) (finding a “generic allegation of increased spam calls and emails, if an injury at all, fails to plausibly show that [plaintiff’s] alleged injuries were the result of Defendant’s conduct”) (internal quotation marks omitted). Spam communications can only rise to an injury in fact when they “support the inference” that Plaintiffs’ personal information “has been mis-used as a consequence of the ... breach.” Capiau, 2024 WL 3747191, at *4. This can occur when the substance of the spam communication is specific enough to the breach. Id. (finding injury in fact where the plaintiff experienced “increased receipt of spam, including from actors impersonating [the defendant’s] CEO” because
“[a]ctual mis-use—not receipt of spam—constitutes the concrete injury”). It can also occur when the spam calls are paired with an independent, concrete injury in fact, such as actual or attempted identity theft or fraud. See Farley v. Eye Care Leaders Holdings, LLC, No. 22-CV-468, 2023 WL 1353558, at *4 (M.D.N.C. Jan. 31, 2023) (rising to injury-in-fact where spam emails and texts were accompanied by the plaintiff’s email being hacked and her credit score unexpectedly fluctuating dramatically); Solomon v. ECL Grp., LLC, No. 22-CV-526, 2023 WL 1359662, at *4 (M.D.N.C. Jan. 31, 2023) (finding injury-in-fact where the “spam calls were so frequent that [plaintiff] changed her phone numbers”). Plaintiffs’ generic allegations of increased spam calls and emails fail to do either, and therefore, cannot create standing. Plaintiffs’ othertwoallegedactual injuries fare no better.First, Plaintiffs allege emotional distress from the breach, which has manifested in “[a]nxiety, sleep disruption, stress, fear, and frustration.” ECF 12 ¶¶ 61, 79, 96, 113, 130, 147, 181, 198, 215, 232, 249, 266, 283, 300, 317, 334. Specific emotional injuries may suffice for Article III standing purposes. See TransUnion LLC, 594 U.S. at 436 n.7. However, “bare assertions of emotional injury are insufficient to confer
Article III standing.” Beck, 848 F.3d at 273 (citing Doe v. Chao, 540 U.S. 614, 624–25 (2004)) (rejecting the plaintiffs’ claim that “emotional upset” and “fear [of] identity theft and financial fraud” resulting from the data breaches were “adverse effects” sufficient to confer Article III standing). Here, in the absence of any concrete or actual injuries, Plaintiffs allege nothing more than bare assertions of emotional harm that do not confer standing. Finally, Plaintiffs allege “[a]ctual injury in the form of damages to and diminution in the value of [their] Private information.” ECF 12 ¶¶ 63, 81, 98, 115, 132, 149, 165, 183, 200, 217, 234, 251, 268, 285, 302, 319, 336. Plaintiffs do not have standing based on this harm because the Consolidated Class Action Complaint “fails to allege any facts explaining how Plaintiffs actually
lost value because of the disclosure of their” personal information. Stuart, 769 F. Supp. 3d at488. For example, Plaintiffs do not allege that “they have attempted to sell their personal information or that, if they have, the data breach forced them to accept a decreased price for that information.” Chambliss v. Carefirst, Inc., 189 F. Supp. 3d 564, 572 (D. Md. 2016). Accordingly, Plaintiffs have not pleadedstanding based on the diminution in value of their private information. B. Imminent, FutureInjury In addition to actual injuries, Plaintiffs can establish standing based on a “substantial risk” that harm will occur in the future. Beck, 848 F.3d at 275. Plaintiffs allege two forms of imminent, future harms: increased risk of identity theft and fraud, and mitigation expenses they will incur to prevent identity theft and fraud. To establish standing based on these harms, Plaintiffs must allege information that “suffice[s] to push the threatened injury of future identity theft beyond the speculative to the sufficiently imminent.” Id. at 274. For example, a substantial risk exists if the plaintiff alleges that “the data thief intentionally targeted the personal information compromised in the data breaches” or “at least one named plaintiff alleged misuse or access of that personal
information by the thief.” Id. (collecting cases). Plaintiffs first allege that they will suffer “[i]mminent and impending injury arising from the substantially increased risk of fraud, misuse, and identity theft,” ECF 12 ¶¶ 64, 82, 99, 116, 133, 150, 166, 184, 201, 218, 235, 252, 269, 286, 303, 320, 337. They allege, without any facts to support their contentions, that their private information “will be published imminently ... by cybercriminals on the Dark Web.” Id. ¶ 49. This bare allegation does not suffice to establish standing based on a “substantial risk” that harm will occur. The Fourth Circuit has been clear that the “mere theft of [personal data], without more, cannot confer Article III standing.” Beck, 848 F.3d at 275. Therefore, Plaintiffs fail to meet their standing burden in regard to this imminent
injury. Next, Plaintiffs allege injury from the time and money they will spend to mitigate their injuries from the breach. Named Plaintiffs “anticipate[] spending considerable amounts of time and money to try and mitigate [their] injuries” ECF ¶¶ 65, 83, 100, 117, 134, 151, 167, 185, 202, 219, 253, 270, 287, 304, 321, 338. Where concrete injury is imminent, a plaintiff’s voluntary mitigation efforts are cognizable as Article III harms. See Stamat, 2022 WL 3919685, at *7; Beck, 848 F.3d at 276–77 (citing Remijas v. Neiman Marcus Grp., LLC, 794 F.3d 688, 694 (7th Cir. 2015); Reilly v. Ceridian Corp., 664 F.3d 38, 46 (3d Cir. 2011)). However, in the absence of concrete injury, as is the case here, Plaintiffs cannot manufacture standing by voluntarily incurring remedial and preventative costs. Beck, 848 F.3d at 276–77 (citing Clapper, 568 U.S. at 415). It is not out of the realm of possibility that the named Plaintiffs, or other individuals in the proposed class, have suffered some concrete harm as a result of the breach of HCI’s systems, if there has been actual misuse of their private information. But the Consolidated Class Action
Complaint fails to provide sufficient information about such harms and their connection to the HCI breach to confer standing at this time. As such, Plaintiffs’ claims will be dismissed without prejudicefor lack of standing. IV. CONCLUSION For the reasons stated above, HCI’s Motion to Dismiss, ECF 22, is granted. A separate Order follows, which will afford Plaintiffs thirty days to seek leave to amend their Consolidated Class Action Complaint.
Dated: August 27, 2026 /s/ Stephanie A. Gallagher United States District Judge