In re Healthcare Interactive, Inc. Data Breach Litigation

District Court, D. Maryland·Decided August 27, 2026·No. 1:25-cv-04034·Unknown

Opinion

IN THE UNITED STATES DISTRICT COURT FOR THE DISTRICT OF MARYLAND * IN RE HEALTHCARE * INTERACTIVE, INC. * DATA BREACH LITIGATION * * Civil Case No.: SAG-25-4034 * * * * * * * * * * * * * * MEMORANDUM OPINION Four plaintiffs brought separate actions against Healthcare Interactive, Inc. (“HCI” or “Defendant”), individually and on behalf of those similarly situated, alleging injuries from HCI’s failure to protect their private information from a data breach of HCI’s computer network. ECF 3. The separate actions were consolidated into the instant case. ECF 4. In the consolidated action, seventeen individuals, bringing suit on behalf of themselves and all others similarly situated (“Plaintiffs”), filed the Consolidated Class Action Complaint on January 30, 2026. ECF 12. The Consolidated Class Action Complaint alleges common law fraud and contract claims, along with a violation of the Maryland Consumer Protection Act,on behalf of all Plaintiffs. Id.It also alleges violations of California consumer protection laws on behalf of Plaintiffs who reside in California. Id.HCI has filed a Motion to Dismiss the Consolidated Class Action Complaint.ECF 22. Plaintiffs oppose the motion, ECF 27, and HCI filed a reply, ECF 28. This Court has reviewed the filings and finds that no hearing is necessary. See Loc. R. 105.6 (D. Md. 2025). For the reasons explained below, the Motion will be granted,and the Consolidated Class Action Complaint will be dismissed without prejudice. I. BACKGROUND The following facts are derived from Plaintiffs’ Consolidated Class Action Complaint, ECF 12, and are assumed to be true for the purpose of the motion to dismiss. HCI is a “Maryland- based technology provider that develops AI-powered software solutions for insurance enrollment and benefits administration.” Id.¶ 2. It “specializes in health and incentive management platforms

that connect and manage healthcare service providers and clients.” Id.HCI collects and stores the private information of “thousands of its current and former clients and its employees.” Id. ¶ 32. The Data Breach On or around July 22, 2025, HCI became aware of suspicious activity related to its computer network. Id. ¶ 39. HCI investigated the incident and discovered a breach of its network system had occurred between July 8, 2025, and July 12, 2025, wherein “an unauthorized actor copied certain files from [HCI’s] computer network.” Id.¶ 40; ECF 12-1 at 1. Plaintiffs allege the breach “compromised the Private Information of 87,565 of [HCI’s] current and former clients and its employees.” ECF 12¶ 6.

HCI sent notice of the breach to potentially affected individuals on December 5, 2025. Id. ¶ 42; ECF 12-1. Six named Plaintiffs allege that they received the notice of data breach. ECF 12 ¶¶ 56, 108, 175, 193, 312, 329. In the notice, HCI stated that it “evaluated the impacted files and determined that protected information was contained within the files that were potentially acquired by the unauthorized actor,” however, HCI was “not aware of any actual or attempted misuse of information within its care.” ECF 12-1 at 1. Potentially affected data includes: Name; date of birth; email address; phone number; mailing address; Social Security number; blood results and/or biometric data; health insurance enrollment data (such as health plans/policies, insurance companies, and member/group ID numbers); medical data (such as medical record numbers, doctors, diagnoses, care, prescription information, and treatment); and health insurance claims data (such as claim numbers, account numbers, explanation of benefits, and billing codes). Id.; ECF 12¶ 6. Inthe notice,HCI also suggested that individuals take measures to protect against possible identity theft. Id. ¶ 45; ECF 12-1 at 2. Plaintiffs’ Injuries Due to the data breach, Plaintiffs allege that their private information “was placed into the hands of cybercriminals—inflicting numerous injuries and significant damages.” Id. ¶ 46. Plaintiffs further allege that they “suffered or are at an increased risk of suffering” the following: a. loss of the opportunity to control how their Private Information is used; b. diminution in value of their Private Information; c. compromise and continuing publication of their Private Information; d. out-of-pocket costs from trying to prevent, detect, and recovery from identity theft and fraud; e. lost opportunity costs and wages from spending time trying to mitigate the fallout of the Data Breach by, inter alia, preventing, detecting, contesting, and recovering from identify theft and fraud; f. delay in receipt of tax refund monies; g. unauthorized use of their stolen Private Information; and h. continued risk to their Private Information—which remains in Defendant’s possession—and is thus as risk for futures breaches so long as Defendant fail to take appropriate measures to protect the Private Information. Id. ¶ 342. The seventeen named Plaintiffs allege the above injuries stemming from the breach. Six named Plaintiffs allege additional, individualized injuries: a. Plaintiff Papcke “has experienced a drastic increase in spam emails, texts, and telephone calls regarding prescription medicine, medical procedures, and doctors, for which she has not inquired.” Id. ¶ 77. b. Plaintiff Levsen experienced a “significant increase in spam emails since the Data Breach occurred which claim that there are open/potential loan applications in his name.” Id. ¶ 161. In response, Plaintiff Levsen “mailed documents to the credit bureaus to freeze his children’s credit and he took approximately half a day off of work to do so. The mailings cost $4.20 for stamps.” Jd. § 160. c. On November 8, 2025, Plaintiff Arevalo “received a notice that his personal information had been found on the dark web.” Jd. § 176. d. In November, 2025, Plaintiff B. Gene Taylor III “received a large package delivered to his home from Amazon containing holiday decorations he did not order. No change was made to his account, nor his wife’s account, and Amazon refused to disclose who had placed the order nor allow them, to return the items.” Jd. J 284. e. Plaintiff Natalie Taylor, the spouse of Plaintiff Taylor III, also received the same Amazon package at their shared home. /d. 301. Further, in the fall of 2025, prior to the package incident, “an unauthorized actor attempted to access Plaintiff [Natalie] Taylor’s Gmail account over 100 times, prompting her to change her password.” /d. f. Plaintiff Owen has experienced “a drastic increase in spam emails, texts, and telephone calls, often taking the form of fake medical alerts and unsolicited inquiries from individuals purporting to be Rocket Mortgage, as a result of the Data Breach.” /d. § 339. Additionally, “on December 20—21, 2025, she received an alert from Aura Credit Monitoring that they fulfilled 11 removal requests of fraudulent inquiries on her credit report.” /d. The fraudulent inquiries were from Instant Data, Address Search.Com., Homeowner’s marketing services, instant data, topacta, VLOOKUP, oldphonebook, America Phonebook, posti, linesharemarketing, and IDM. Jd. The Class Action The seventeen named Plaintiffs seek to represent a class of “[aJll individuals residing in the United States whose Private Information was compromised in the Data Breach discovered by

Free access — add to your briefcase to read the full text and ask questions with AI

In re Healthcare Interactive, Inc. Data Breach Litigation, (D. Md. 2026).

In re Healthcare Interactive, Inc. Data Breach Litigation (In re Healthcare Interactive, Inc. Data Breach Litigation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Lujan v. Defenders of Wildlife
504 U.S. 555 (Supreme Court, 1992)
Doe v. Chao
540 U.S. 614 (Supreme Court, 2004)
Doe v. Obama
631 F.3d 157 (Fourth Circuit, 2011)
Adams v. Bain
697 F.2d 1213 (Fourth Circuit, 1982)
Reilly Ex Rel. Pluemacher v. Ceridian Corp.
664 F.3d 38 (Third Circuit, 2011)
Clapper v. Amnesty International USA
133 S. Ct. 1138 (Supreme Court, 2013)
Kerns v. United States
585 F.3d 187 (Fourth Circuit, 2009)
Hilary Remijas v. Neiman Marcus Group, LLC
794 F.3d 688 (Seventh Circuit, 2015)
Spokeo, Inc. v. Robins
578 U.S. 330 (Supreme Court, 2016)
Richard Beck v. Robert McDonald
848 F.3d 262 (Fourth Circuit, 2017)
Hutton v. Nat'l Bd. of Examiners in Optometry, Inc.
892 F.3d 613 (Fourth Circuit, 2018)
Sierra Club v. U.S. Dep't of the Interior
899 F.3d 260 (Fourth Circuit, 2018)
TransUnion LLC v. Ramirez
594 U.S. 413 (Supreme Court, 2021)
Khan v. Children's National Health System
188 F. Supp. 3d 524 (D. Maryland, 2016)
Chambliss v. CareFirst, Inc.
189 F. Supp. 3d 564 (D. Maryland, 2016)
Jane DiCocco v. Merrick Garland
52 F.4th 588 (Fourth Circuit, 2022)
Brady O'Leary v. TrustedID, Inc.
60 F.4th 240 (Fourth Circuit, 2023)
Thomas Sheppheard v. Patrick Morrisey
143 F.4th 232 (Fourth Circuit, 2025)