IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION
Tiana McCullar, ) ) Plaintiff, ) ) No. 25 C 6462 v. ) ) Judge Jorge L. Alonso UCM Medical Group Sub, LLC d/b/a ) UChicago Medicine Medical Group ) and Nationwide Recovery Service, Inc., ) ) Defendants. )
MEMORANDUM OPINION AND ORDER
Plaintiff Tiana McCullar brings this putative class action against Defendants UCM Medical Group Sub, LLC (“UCM”) and Nationwide Recovery Service (“NRS”) alleging that Defendants failed to safeguard certain personal information. Defendants move to dismiss. For the reasons stated below, the motions to dismiss are granted in part and denied in part. Background UCM is a healthcare provider and, in its regular course of business, UCM collects personally identifying information and personal health information (“PII/PHI”) from its patients that includes “names, addresses, dates of birth, Social Security numbers, financial account information, and medical information.” R. 1 ¶¶ 1, 21–23. Also, in its regular course of business, UCM shares that information with debt collection agency NRS. Id. McCullar is a patient at UCM and was required to provide UCM with her PII/PHI to receive medical services. Id. ¶ 8. In July 2024, a hacker gained access to the NRS system and obtained PII/PHI information from certain files, including McCullar’s. Id. ¶ 30. NRS learned of the data breach on July 11, 2024, notified UCM on April 8, 2025, and UCM notified McCullar on May 23, 2025. Id. ¶ 32. McCullar brings a putative class action on behalf of (1) a subclass of all UCM patients whose PII/PHI were accessed in the breach and (2) a larger class of all persons who had data in the NRS system and whose PII/PHI were accessed in the data. Id. ¶¶ 53–54. McCullar alleges the following counts: (I) negligence against UCM and NRS; (II) breach of fiduciary duty against
UCM; (III) breach of implied contract against UCM; (IV) unjust enrichment against UCM and NRS; and (V) violation of the Illinois Consumer Fraud Act against UCM. Id. ¶¶ 63–109. Discussion I. Standing The Court begins with standing. To establish standing under Article III of the Constitution, a plaintiff must demonstrate (1) that she suffered an injury-in-fact that is “concrete, particularized, and actual or imminent”; (2) that the injury is “fairly traceable to the defendant”; and (3) that the injury is “likely to be redressable by a favorable judicial decision.” Dinerstein v. Google, LLC, 73 F.4th 502, 511 (7th Cir. 2023). “For a motion to dismiss for lack of standing based on the face of the complaint, the district court must accept as true all material allegations of the complaint,
drawing all reasonable inferences therefrom in the plaintiff’s favor.” Nasir v. United States Dep’t of State, 749 F. Supp. 3d 938, 941 (N.D. Ill. 2024) (citations omitted). Regarding injury-in-fact, Defendants argue that McCullar failed to allege an injury-in-fact because she “does not allege any actual identity theft, fraud, . . . or other misuse of any kind” resulting from the data breach. R. 45-1 at 6. But the Court recently addressed this issue in a similar data-breach case involving sensitive information such as Social Security numbers and where the plaintiffs did not allege “that their information [had] been posted on the dark web, or that there [were] any other indicia of identity theft or fraud.” In re Mondelez Data Breach Litig., 2024 WL 2817489, at *2 (N.D. Ill. June 3, 2024). The Court explained that “a plaintiff who is the victim of a data breach has suffered a harm that has already occurred,” and that “[this] harm satisfies the injury-in-fact requirement by putting [the plaintiff] at a substantial risk of further future harm, because hackers steal personal information for the primary purpose of committing fraud or assuming consumers’ identities.” Id. at *3 (citations omitted). The Court further explained that
“[e]ven if, under TransUnion [v. Ramirez, 594 U.S. 413 (2021)], some ‘separate harm’ is required, the time plaintiffs spent mitigating the risk of [identity] theft is that ‘separate harm.” Id. at *3. Here, as in Mondelez, McCullar alleges loss of sensitive information such as her Social Security number and “lost time and money mitigating the effects of the data breach.” R. 1 ¶ 14. For the same reasons that the Court found that the plaintiffs in Mondelez had sufficiently alleged an injury- in-fact, the Court finds that McCullar has sufficiently alleged an injury-in-fact. Regarding traceability, a plaintiff’s burden is “relatively modest.” Taylor v. Salvation Army Nat’l Corp., 110 F.4th 1017, 1025 (7th Cir. 2024). The plaintiff “need not establish that the defendant’s conduct was the most immediate cause, or even a proximate cause, of the [] injuries.” Id. Rather, traceability requires no more than a “meaningful connection” between the defendant’s
conduct and the plaintiff’s injuries. Id. (citations omitted). Here, McCullar alleges that her injuries stem from NRS’s failure to implement adequate data protection and the fact that UCM shared her data with a vendor such as NRS that lacked adequate data protection. R. 1 ¶ 74. These allegations establish a logical and meaningful connection between McCullar’s injuries and Defendants’ conduct. As such, the Court finds that McCullar has sufficiently alleged traceability. Regarding redressability, McCullar alleges “lost time and money mitigating the effects of the data breach,” R. 1 ¶ 14, which can be redressed by monetary damages. She also alleges that her PII/PHI “remains in Defendants’ possession” and is at “continued risk,” id. at ¶ 77, which can be redressed by injunctive relief. For the reasons stated above, the Court finds that McCullar has standing. See Florence v. Ord. Express, Inc., 674 F. Supp. 3d 472, 482 (N.D. Ill. 2023) (“Plaintiffs have alleged an imminent threat of identity theft and fraud due to the exposure of their social security and driver’s license numbers. Based on the substantial risk of harm, Plaintiffs allege that they have spent time and
money on credit monitoring and identity-theft insurance. . . . In sum, Plaintiffs have demonstrated actual and imminent concrete harms by alleging loss of privacy and mitigation costs based on the substantial risk of identity theft and fraud. These harms are traceable to the data breach, which [the defendant] failed to prevent, and redressable by this Court.”). II. Abstention Under the Colorado River doctrine, “a federal court may stay or dismiss a suit in federal court when a concurrent state court case is underway, but only under exceptional circumstances.” Freed v. J.P. Morgan Chase Bank, N.A., 756 F.3d 1013, 1018 (7th Cir. 2014). “To determine whether a stay is appropriate, [courts] conduct a two-part analysis. Id. First, courts “determine whether the state and federal court actions are parallel.” Id. Second, if the actions are parallel,
Free access — add to your briefcase to read the full text and ask questions with AI
IN THE UNITED STATES DISTRICT COURT FOR THE NORTHERN DISTRICT OF ILLINOIS EASTERN DIVISION
Tiana McCullar, ) ) Plaintiff, ) ) No. 25 C 6462 v. ) ) Judge Jorge L. Alonso UCM Medical Group Sub, LLC d/b/a ) UChicago Medicine Medical Group ) and Nationwide Recovery Service, Inc., ) ) Defendants. )
MEMORANDUM OPINION AND ORDER
Plaintiff Tiana McCullar brings this putative class action against Defendants UCM Medical Group Sub, LLC (“UCM”) and Nationwide Recovery Service (“NRS”) alleging that Defendants failed to safeguard certain personal information. Defendants move to dismiss. For the reasons stated below, the motions to dismiss are granted in part and denied in part. Background UCM is a healthcare provider and, in its regular course of business, UCM collects personally identifying information and personal health information (“PII/PHI”) from its patients that includes “names, addresses, dates of birth, Social Security numbers, financial account information, and medical information.” R. 1 ¶¶ 1, 21–23. Also, in its regular course of business, UCM shares that information with debt collection agency NRS. Id. McCullar is a patient at UCM and was required to provide UCM with her PII/PHI to receive medical services. Id. ¶ 8. In July 2024, a hacker gained access to the NRS system and obtained PII/PHI information from certain files, including McCullar’s. Id. ¶ 30. NRS learned of the data breach on July 11, 2024, notified UCM on April 8, 2025, and UCM notified McCullar on May 23, 2025. Id. ¶ 32. McCullar brings a putative class action on behalf of (1) a subclass of all UCM patients whose PII/PHI were accessed in the breach and (2) a larger class of all persons who had data in the NRS system and whose PII/PHI were accessed in the data. Id. ¶¶ 53–54. McCullar alleges the following counts: (I) negligence against UCM and NRS; (II) breach of fiduciary duty against
UCM; (III) breach of implied contract against UCM; (IV) unjust enrichment against UCM and NRS; and (V) violation of the Illinois Consumer Fraud Act against UCM. Id. ¶¶ 63–109. Discussion I. Standing The Court begins with standing. To establish standing under Article III of the Constitution, a plaintiff must demonstrate (1) that she suffered an injury-in-fact that is “concrete, particularized, and actual or imminent”; (2) that the injury is “fairly traceable to the defendant”; and (3) that the injury is “likely to be redressable by a favorable judicial decision.” Dinerstein v. Google, LLC, 73 F.4th 502, 511 (7th Cir. 2023). “For a motion to dismiss for lack of standing based on the face of the complaint, the district court must accept as true all material allegations of the complaint,
drawing all reasonable inferences therefrom in the plaintiff’s favor.” Nasir v. United States Dep’t of State, 749 F. Supp. 3d 938, 941 (N.D. Ill. 2024) (citations omitted). Regarding injury-in-fact, Defendants argue that McCullar failed to allege an injury-in-fact because she “does not allege any actual identity theft, fraud, . . . or other misuse of any kind” resulting from the data breach. R. 45-1 at 6. But the Court recently addressed this issue in a similar data-breach case involving sensitive information such as Social Security numbers and where the plaintiffs did not allege “that their information [had] been posted on the dark web, or that there [were] any other indicia of identity theft or fraud.” In re Mondelez Data Breach Litig., 2024 WL 2817489, at *2 (N.D. Ill. June 3, 2024). The Court explained that “a plaintiff who is the victim of a data breach has suffered a harm that has already occurred,” and that “[this] harm satisfies the injury-in-fact requirement by putting [the plaintiff] at a substantial risk of further future harm, because hackers steal personal information for the primary purpose of committing fraud or assuming consumers’ identities.” Id. at *3 (citations omitted). The Court further explained that
“[e]ven if, under TransUnion [v. Ramirez, 594 U.S. 413 (2021)], some ‘separate harm’ is required, the time plaintiffs spent mitigating the risk of [identity] theft is that ‘separate harm.” Id. at *3. Here, as in Mondelez, McCullar alleges loss of sensitive information such as her Social Security number and “lost time and money mitigating the effects of the data breach.” R. 1 ¶ 14. For the same reasons that the Court found that the plaintiffs in Mondelez had sufficiently alleged an injury- in-fact, the Court finds that McCullar has sufficiently alleged an injury-in-fact. Regarding traceability, a plaintiff’s burden is “relatively modest.” Taylor v. Salvation Army Nat’l Corp., 110 F.4th 1017, 1025 (7th Cir. 2024). The plaintiff “need not establish that the defendant’s conduct was the most immediate cause, or even a proximate cause, of the [] injuries.” Id. Rather, traceability requires no more than a “meaningful connection” between the defendant’s
conduct and the plaintiff’s injuries. Id. (citations omitted). Here, McCullar alleges that her injuries stem from NRS’s failure to implement adequate data protection and the fact that UCM shared her data with a vendor such as NRS that lacked adequate data protection. R. 1 ¶ 74. These allegations establish a logical and meaningful connection between McCullar’s injuries and Defendants’ conduct. As such, the Court finds that McCullar has sufficiently alleged traceability. Regarding redressability, McCullar alleges “lost time and money mitigating the effects of the data breach,” R. 1 ¶ 14, which can be redressed by monetary damages. She also alleges that her PII/PHI “remains in Defendants’ possession” and is at “continued risk,” id. at ¶ 77, which can be redressed by injunctive relief. For the reasons stated above, the Court finds that McCullar has standing. See Florence v. Ord. Express, Inc., 674 F. Supp. 3d 472, 482 (N.D. Ill. 2023) (“Plaintiffs have alleged an imminent threat of identity theft and fraud due to the exposure of their social security and driver’s license numbers. Based on the substantial risk of harm, Plaintiffs allege that they have spent time and
money on credit monitoring and identity-theft insurance. . . . In sum, Plaintiffs have demonstrated actual and imminent concrete harms by alleging loss of privacy and mitigation costs based on the substantial risk of identity theft and fraud. These harms are traceable to the data breach, which [the defendant] failed to prevent, and redressable by this Court.”). II. Abstention Under the Colorado River doctrine, “a federal court may stay or dismiss a suit in federal court when a concurrent state court case is underway, but only under exceptional circumstances.” Freed v. J.P. Morgan Chase Bank, N.A., 756 F.3d 1013, 1018 (7th Cir. 2014). “To determine whether a stay is appropriate, [courts] conduct a two-part analysis. Id. First, courts “determine whether the state and federal court actions are parallel.” Id. Second, if the actions are parallel,
courts “carefully weigh[] ten-non-exclusive factors.” Id. But if the actions are not parallel, the doctrine “does not apply and the court need not address the second part of the analysis.” Id. “The lawsuits need not be identical to be considered parallel.” TruServ Corp. v. Flegles, Inc., 419 F.3d 584, 592 (7th Cir. 2005). Lawsuits are considered parallel “if substantially the same parties are litigating substantially the same issues simultaneously in two fora.” Id. (citations omitted). “The question is not whether the suits are formally symmetrical, but whether there is a substantial likelihood that the state court litigation will dispose of all claims presented in the federal case.” Id. (citations omitted). “Any doubt regarding the parallel nature of the state court suit should be resolved in favor of exercising jurisdiction.” Id. (citations omitted). UCM argues that the Court should stay this case pursuant to Colorado River because there is a parallel case in Illinois state court. R. 48-1 at 6. Critically, the Illinois case involves the same data breach but names only UCM as a defendant and the case thus does not involve NRS. R. 59 at 6. Because the Illinois case does not involve NRS, there is not a substantial likelihood that the
Illinois case will dispose of all claims presented here. Indeed, it is almost certain that the Illinois case will not dispose of the claims against NRS. For this reason, the Court finds that the cases are not parallel and declines to stay this case. III. Stating a Claim A Rule 12(b)(6) motion “tests whether the complaint states a claim on which relief may be granted.” Richards v. Mitcheff, 696 F.3d 635, 637 (7th Cir. 2012). A complaint must provide “a short and plain statement of the claim” and must “contain sufficient factual matter, accepted as true, to state a claim to relief that is plausible on its face.” Ashcroft v. Iqbal, 556 U.S. 662, 677–78 (2009) (citations omitted). Facial plausibility exists when the plaintiff pleads factual content that “allows the court to draw the reasonable inference that the defendant is liable for the misconduct
alleged.” Id. at 678. In deciding a motion to dismiss, the Court “accept[s] the well-pleaded facts in the complaint as true and draw[s] reasonable inferences in the plaintiff’s favor.” Esco v. City of Chicago, 107 F.4th 673, 678 (7th Cir. 2024). 1. Negligence To state a claim for negligence under Illinois law, “a plaintiff must allege facts showing that (1) the defendant owed a duty of care to the plaintiff, (2) the defendant breached that duty, and (3) the breach was the proximate cause of plaintiff’s injuries.” Flores v. Aon Corp., 2023 IL App (1st) 230140, ¶ 23. Regarding the duty of care, “the vast majority of district courts in this Circuit to have considered the issue have found that there is a duty under Illinois law to safeguard personal information in the data breach context.” In re Lurie Children’s Hosp. Data Sec. Litig., 2025 WL 2754760, at *9 (N.D. Ill. Sept. 27, 2025) (collecting cases). The Court finds, consistent with its
position in Mondelez, 2024 WL 2817489 at *4, that there is a duty under Illinois law to safeguard personal information. This duty extends to a particular defendant when “a plaintiff and a defendant [stand] in such a relationship to one another that the law imposed upon the defendant an obligation of reasonable conduct for the benefit of the plaintiff.” Daniel v. Chicago Transit Auth., 2020 IL App (1st) 190479, ¶ 20. “In considering this question, courts often examine four factors: (1) the reasonable foreseeability of the injury, (2) the likelihood of the injury, (3) the magnitude of the burden of guarding against the injury, and (4) the consequences of placing that burden on the defendant.” Id. (citations omitted). The Court finds that in today’s climate, the risk of an attempted data breach is reasonably foreseeable and absent reasonable security measures, the likelihood of a
data breach and subsequent injury is high. Although there may be significant costs to maintaining reasonable security measures given the breadth and complexity of today’s hackers, the consequences of placing that burden on UCM and NRS are minimal given that UCM and NRS are already obligated under statute and by industry standard to maintain reasonable security measures. The Court thus finds that the duty of care extends to both UCM and NRS. Regarding breach and proximate cause by NRS, McCullar alleges that NRS “fail[ed] to exercise reasonable care” because it “failed to design, adopt, implement, control, direct, oversee, manage, monitor, and audit appropriate data security processes, controls, policies, procedures, protocols, and software and hardware systems to safeguard and protect PII/PHI entrusted to them—including Plaintiff’s and Class members’ PII/PHI,” and that “but for” these failures, her “PII/PHI would not have been compromised.” R. 1 ¶ 74, 76. NRS does not dispute proximate cause but, as to breach, NRS argues that these are “conclusory allegations [that] are insufficient to state a negligence claim,” R. 45-1 at 10, and that McCullar “identifies no lacking safeguards, no
misconfigured controls, or deficient practices as to NRS,” R. 60 at 8. But when deciding a motion to dismiss, the Court is required to accept the well-pled facts in the complaint as true and draw reasonable inferences in the plaintiff’s favor. It’s possible that discovery will reveal that NRS had reasonably sufficient safeguards in place and that, even so, the hackers managed to penetrate NRS’s database. This, however, is an issue of fact. At this stage, drawing all reasonable inferences in McCullar’s favor, the Court finds that it is plausible that NRS lacked reasonably sufficient safeguards on its database. Regarding breach and proximate caused by UCM, McCullar alleges that UCM “fail[ed] to exercise reasonable care” because it shared Plaintiff’s PII/PHI with NRS and that “but for” UCM sharing the data, her “PII/PHI would not have been compromised.” R. 1 ¶ 74, 76. UCM argues
that it was NRS who breached by not having sufficient safeguards and NRS who caused the harm. R. 48-1 at 15. McCullar responds that UCM breached and caused the harm because it failed to sufficiently “oversee[] NRS’s data-security practices.” R. 57 at 15. The Court addressed a similar issue in Mondelez where the company Mondelez collected data from its employees, turned that data over to law firm Bryan Cave, and then Bryan Cave’s system was hacked. Mondelez, 2024 WL 2817489, at *6. Regarding the plaintiff’s theory that Mondelez had caused the harm by providing the data to Bryan Cave, the Court explained that “[n]either side cites cases in which courts have directly addressed the viability of such a theory in a similar context, much less approved or rejected it.” Mondelez, 2024 WL 2817489 at *6. The same remains true here. The Court finds, as it found in Mondelez, that “[t]o the extent that there is little precedent to guide the parties and the Court as to [McCullar’s] precise legal theory, there is all the more reason to develop the facts first, rather than to hastily proceed to a dispositive ruling.” Id. See also McGary v. City of Portland, 386 F.3d 1259, 1270 (9th Cir. 2004) (“Rule 12(b)(6)
dismissals are especially disfavored in cases where the complaint sets forth a novel legal theory that can best be assessed after factual development.”) (citations omitted). For these reasons, the Court finds that McCullar may proceed on her negligence claims against UCM and NRS. 2. Breach of Fiduciary Duty To state a claim for breach of fiduciary duty under Illinois law, a plaintiff must allege facts showing “the existence of a fiduciary duty, a breach of that duty, and damages proximately caused by the breach.” Alonso v. Weiss, 932 F.3d 995, 1001 (7th Cir. 2019). Although it is “well-settled in Illinois . . . that a fiduciary relationship arises between doctor and patient,” San Roman v. Children’s Heart Ctr., Ltd., 2010 IL App (1st) 091217, ¶ 14, it remains unclear whether that duty
extends to a healthcare facility such as UCM. Cf. Lurie, 2025 WL 2754760 at *11 (“The Court finds that Plaintiffs improperly use the fiduciary duty a treating physician owes their patients to bootstrap into Illinois law a fiduciary duty owed to patients by the healthcare facility at which their treating physician practices.”) with Doe v. Fertility Centers of Illinois, S.C., 2022 WL 972295, at *5 (N.D. Ill. Mar. 31, 2022) (finding that “Doe’s fiduciary duty claim against FCI survives”); see also Nutty v. Jewish Hosp., 571 F. Supp. 1050, 1052 (S.D. Ill. 1983) (“While physicians clearly have a fiduciary relationship with their patients, the relationship between a hospital and a patient is more difficult to categorize.”). Ultimately, based on the allegations here, the Court cannot conclude that the fiduciary duty owed by physicians to their patients extends to UCM and to the administrative staff in charge of maintaining patient information or disseminating that information to third parties such as NRS. See Doe v. Genesis Health Sys., 2024 WL 3890164, at *13 (C.D. Ill. Aug. 21, 2024) (“Plaintiff
fails to support that any court in Illinois has found that a healthcare facility has a fiduciary duty in relation to patients’ private information.”); Jezek v. CareCredit, LLC, 2011 WL 2837492, at *3 (N.D. Ill. July 18, 2011) (“Plaintiffs cite no authority to show that in the context of the physician- patient relationship, transactions outside of medical treatment . . . are subject to the fiduciary relationship.”). For this reason, the Court dismisses McCullar’s claim against UCM for breach of fiduciary duty. 3. Breach of Implied Contract To state a claim for breach of an implied contract under Illinois law, a plaintiff must allege “all the elements of an express contract, but unlike an express contract or other contracts, its terms are inferred from the conduct of the parties.” Gociman v. Loyola Univ. of Chicago, 41 F.4th 873,
883 (7th Cir. 2022). An implied contract “is one in which a contractual duty is imposed by a promissory expression which may be inferred from the facts and circumstances and the expressions on the part of the promisor which show an intention to be bound.” Id. (citations omitted). Plaintiff alleges that on UCM’s website, UCM tells patients that “[p]rotecting the privacy of your health information is important” and that it “respect[s] the privacy of your medical information.” R. 1 ¶ 24. Also, as alleged, UCM’s website contains a privacy policy which describes how PII/PHI may be used and disclosed by UCM. Id. ¶ 25. In similar contexts, courts have found that “even general commitments to protecting personal information in a defendant’s privacy policy can support an inference of an implied promise.” Lurie, 2025 WL 2754760 at *12 (“Indeed, an implied contract can be implied simply from the nature of Plaintiffs’ relationship with Lurie: since Plaintiffs were required to provide Lurie with their PII and PHI to receive services, they could reasonably expect that Lurie, in turn, would keep this information private and protect it from unauthorized disclosures.”) (citations omitted); see also Mondelez, 2024 WL 2817489 at *7 (“The
existence of a Privacy Policy . . . demonstrates Mondelez’s commitment to protecting personal information generally, and it is one of the circumstances that might support an inference of an implicit promise to protect [] personal information.”) (citations omitted). As such, the Court finds that McCullar may proceed on her claim for breach of implied contract. 4. Unjust Enrichment To state a claim for unjust enrichment under Illinois law, a plaintiff must allege “that the defendant has unjustly retained a benefit to the plaintiff’s detriment, and that defendant’s retention of the benefit violates the fundamental principles of justice, equity, and good conscience.” Guerrero v. Howard Bank, 74 F.4th 816, 823–24 (7th Cir. 2023) (citations omitted). Here, UCM contends that McCullar failed to allege “a benefit unjustly retained by UCM.” R. 48-1 at 12. The
Court agrees. Any monetary benefit that McCullar conferred upon UCM was for healthcare services, and the McCullar does not allege that there was any separate outlay for data security. See Perdue v. Hy-Vee, Inc., 455 F. Supp. 3d 749, 766 (C.D. Ill. 2020) (“Plaintiffs have not alleged that any specific portion of their payments went toward data protection; rather, they state that their payments were for food and gas. Additionally, Plaintiffs have not alleged a benefit conferred in exchange for protection of their personal information.”); Irwin v. Jimmy John’s Franchise, LLC, 175 F. Supp. 3d 1064, 1072 (C.D. Ill. 2016) (“[The plaintiff] paid for food products. She did not pay for a side order of data security and protection.”). For this reason, the Court dismisses McCullar’s claims against UCM and NRS for unjust enrichment. 5. Illinois Consumer Fraud Act To state a claim for violation of the Illinois Consumer Fraud and Deceptive Business Practices Act (“ICFA”), a plaintiff must allege “(1) a deceptive or unfair act or practice by the defendant; (2) the defendant’s intent that the plaintiff rely on the deceptive or unfair practice; and (3) the unfair or deceptive practice occurred during a course of conduct involving trade or commerce.” Siegel v. Shell Oil Co., 612 F.3d 932, 934 (7th Cir. 2010). Applied in the context of data security, a plaintiff must “actually identify a deceptive guarantee about data security in order to state an ICFA claim.” Cmty. Bank of Trenton v. Schnuck Markets, Inc., 887 F.3d 803, 824 (7th Cir. 2018). Here, there are no allegations that UCM made a deceptive guarantee about data security, let alone that UCM intended that McCullar rely on a deceptive guarantee. Simply put, the facts of the case do not fit this claim. As such, the Court dismisses McCullar’s claim against UCM for violation of ICFA. Conclusion For the foregoing reasons, Defendants motions [45] [48] to dismiss are granted in part and denied in part. The Court dismisses Plaintiffs claims for breach of fiduciary duty, unjust enrichment, and for violation of the Illinois Consumer Fraud Act. Plaintiff may proceed, however, on her claims for negligence against UCM and NRS and on her claim for breach of implied contract against UCM. Defendants shall answer the complaint within fourteen days. The parties shall continue with discovery under supervision of the Magistrate Judge.
SO ORDERED. ENTERED: August 18, 2026
HON. JORGE L. ALONSO United States District Judge
1]