|

AmeriBen Data Breach Lawsuit, Ninth Circuit Revives Health Privacy Case After Dismissal

A federal appeals court has revived a proposed data breach lawsuit against health plan administrator AmeriBen after two customers alleged that their private health information was disclosed without authorization. On October 9, 2026, the Ninth Circuit ruled that the alleged disclosure was enough to establish an injury for purposes of suing in federal court, even without allegations of identity theft or financial loss.

The case, Black v. IEC Group, Inc., involves Miles Black and Melissa Black, whose health insurance benefits were administered by IEC Group, Inc., doing business as AmeriBen. They said information about their medical care was exposed after an employee emailed a spreadsheet to one or more other health plan members.

The ruling reverses the earlier dismissal and sends the case back to the U.S. District Court for the District of Idaho. It does not award compensation, establish that AmeriBen is liable or approve a settlement, and it creates no claim form for other people who received an AmeriBen breach notice.

Quick Facts: Black v. IEC Group, Inc. (AmeriBen)

DetailVerified information
Appellate courtU.S. Court of Appeals for the Ninth Circuit
Appellate case numberNo. 25-5952
District courtU.S. District Court for the District of Idaho
District court case numberNo. 1:23-cv-00384-AKB
PlaintiffsMiles Black and Melissa Black, on behalf of a putative class
DefendantIEC Group, Inc., doing business as AmeriBen (a benefits and third-party administrator)
Main issueWhether the alleged unauthorized disclosure of confidential health information establishes Article III standing
Decision dateOctober 9, 2026
OutcomeDismissal reversed; case remanded for further proceedings
People reportedly affectedAbout 74,000 to 75,000, per HHS OCR reporting and contemporaneous coverage
Class statusPutative class action; no class certified
Official settlement websiteNone. No settlement exists.
Claim form linkNone
Claim deadlineNone
Official opinionNinth Circuit published opinion (PDF)
Check for new filingsPACER, appellate case No. 25-5952

What Happened in the AmeriBen Health Information Disclosure?

According to the court’s opinion, an AmeriBen employee emailed a spreadsheet containing a claims report to one or more health plan members in December 2022. AmeriBen identified the problem in 2023 and sent Miles and Melissa Black notification letters in August 2023, saying some of their information may have been disclosed to unauthorized recipients. AmeriBen also reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR). It said it had no reason to believe the information would be misused, and some notices offered credit monitoring.

The information that may have been exposed included:

  • First and last names
  • Unique tracking or case numbers
  • Employer codes
  • Health care provider names
  • Insurance claim numbers
  • Dates of medical services
  • Amounts billed or paid for care

The district court’s description says the spreadsheet did not include Social Security numbers or financial account credentials.

The plaintiffs alleged they entrusted this information to AmeriBen on the understanding it would remain confidential, and that AmeriBen’s express and implied promises, including its privacy policy, required it to protect the information. They alleged harms including increased risk of harm, mitigation efforts and emotional distress.

The lawsuit asserts state-law claims: negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty and unjust enrichment. It also seeks declaratory and injunctive relief and brings a claim under Florida’s Deceptive and Unfair Trade Practices Act. These are allegations, not findings that AmeriBen committed every alleged violation.

Why the Ninth Circuit Reversed the Dismissal

The district court dismissed the case in August 2025. It concluded the Blacks had not shown an injury sufficient for standing under Article III of the U.S. Constitution. It reasoned that the disclosed information did not create a credible risk of fraud or identity theft and that the plaintiffs’ other alleged harms were speculative.

The Ninth Circuit disagreed after reviewing the complaint.

Unauthorized Disclosure as a Concrete Injury

The appeals court focused on the alleged breach of confidentiality. The plaintiffs said AmeriBen received sensitive information through its role administering their benefits and promised to keep it private.

The panel concluded the alleged harm resembles a traditional claim for breach of confidence. That comparison matters because the Supreme Court has told federal courts to ask whether an alleged injury has a close relationship to harms traditionally recognized in American or English courts. The court also discussed breach of contract: the plaintiffs alleged AmeriBen’s confidentiality promises were part of the relationship under which they supplied their information. The panel found these allegations sufficient to establish standing at this stage. The court indicated that such disclosures can support standing even when the data does not include the most sensitive identifiers and even if some of it might appear “mundane.”

Identity Theft Was Not Required

The Ninth Circuit did not require the Blacks to show someone had already used their information for fraud. That is an important point for health data breach cases: a disclosure can allegedly harm confidentiality interests even without a resulting financial loss.

The decision does not mean every data breach establishes standing. The court focused on these allegations: sensitive health information, an alleged confidential relationship and promises to protect the information. Standing must also be assessed for each claim.

HIPAA Helped the Analysis but Created No New Lawsuit

The opinion discussed the Health Insurance Portability and Accountability Act (HIPAA). The court reasoned that Congress’s decision to protect individually identifiable health information supports treating the alleged disclosure as a concrete injury. But the opinion recognized that HIPAA gives individuals no private right to sue under the statute. The Blacks’ case proceeds on state-law claims, and HIPAA’s protections were used only as part of the standing analysis.

Which Laws and Court Precedents Matter?

Article III Standing

Under Lujan v. Defenders of Wildlife, 504 U.S. 555 (1992), a plaintiff must show a concrete, particularized injury, a causal link to the defendant’s conduct and a likelihood that relief will redress it. At the pleading stage, a plaintiff only has to allege facts that plausibly show standing.

  • Spokeo, Inc. v. Robins, 578 U.S. 330 (2016): the injury must be concrete, not merely a technical violation.
  • TransUnion LLC v. Ramirez, 594 U.S. 413 (2021): courts look for a close relationship to a harm traditionally recognized in American courts, and the Supreme Court listed disclosure of private information among such harms.
  • Krottner v. Starbucks Corp., 628 F.3d 1139 (9th Cir. 2010): an earlier Ninth Circuit decision recognizing that certain data exposure can create a concrete injury without proof of actual identity theft.
  • In re Zappos.com, Inc., 888 F.3d 1020 (9th Cir. 2018): another Ninth Circuit data breach standing decision.
AmeriBen Data Breach Lawsuit, Ninth Circuit Revives Health Privacy Case After Dismissal

HIPAA Privacy, Security and Breach Notification Rules

HIPAA, with its regulations at 45 C.F.R. Parts 160 and 164, protects individually identifiable health information held by covered entities such as health plans and their business associates. The Breach Notification Rule (45 C.F.R. §§ 164.400 to 164.414) generally requires notice to affected individuals without unreasonable delay and within 60 days of discovery, notice to HHS and, for large breaches, notice to the media. HHS OCR can impose civil penalties under 42 U.S.C. § 1320d-5, and state attorneys general can bring HIPAA-based actions under the same section. Wrongful disclosure can also carry criminal penalties under 42 U.S.C. § 1320d-6. None of these gives a private plaintiff a right to sue directly.

Federal Class Action Rules

Federal courts handle many proposed class actions under the Class Action Fairness Act, 28 U.S.C. § 1332(d). A class can be certified only if Federal Rule of Civil Procedure 23 is met, including numerosity, commonality, typicality and adequacy. A named plaintiff must have standing of their own.

Rules 12(b)(1) and 12(b)(6)

Rule 12(b)(1) lets a defendant challenge subject-matter jurisdiction, which is where standing arises, and the district court dismissed on this ground. Rule 12(b)(6) lets a defendant argue a complaint fails to state a claim. AmeriBen may raise that argument again on remand, because the Ninth Circuit’s ruling did not decide whether the claims are legally sufficient.

State Law Claims and State Breach Notification Statutes

The plaintiffs’ claims arise under state law, including negligence, contract and Florida’s Deceptive and Unfair Trade Practices Act, Fla. Stat. § 501.201 et seq. States also have data breach notification laws, such as Idaho’s, found at Idaho Code § 28-51-104 and following. These statutes generally require notice to affected residents and are often enforced by state attorneys general. Which state’s law applies to each claim is a question for the district court.

What the Ruling Means for Other Health Data Breach Lawsuits

The decision may matter in future cases involving unauthorized disclosure of sensitive health information, especially within the Ninth Circuit, which covers California, Idaho, Washington, Oregon, Arizona, Nevada, Montana, Alaska and Hawaii. It gives plaintiffs a route to establish standing by alleging that a company disclosed confidential health information in breach of a trusted relationship, without first proving identity theft or a measurable financial loss.

It is not a blanket ruling that every privacy complaint survives dismissal. The nature of the information, the confidentiality relationship and the actual allegations still matter.

For other data breach matters, see our coverage of the DentaQuest data breach lawsuit, the Mortgage Investors Group $925,000 data breach settlement and the Mental Health Association $300,000 data breach settlement. Those involve different facts and defendants, and the AmeriBen ruling does not decide their outcomes.

Key Dates in the AmeriBen Data Breach Litigation

DateEvent
December 2022Alleged unauthorized email of a claims spreadsheet
July 2023AmeriBen reportedly identified the possible exposure
August 2023Notification letters sent; incident reported to HHS OCR
August 25, 2023Original complaint filed in the District of Idaho
July 30, 2024District court issued an earlier dismissal order
August 21, 2025District court dismissed the amended complaint with prejudice
October 9, 2026Ninth Circuit reversed the dismissal and remanded

What Happens Next in Black v. IEC Group?

The case returns to the District of Idaho rather than ending with a payment or settlement. Possible next steps:

  1. Possible further review. AmeriBen could ask the Ninth Circuit for rehearing or rehearing en banc, generally within 14 days of judgment under Federal Rule of Appellate Procedure 40, and the appellate mandate normally issues after that window closes. A petition for Supreme Court review is also possible. Check the docket for any such filing.
  2. Proceedings in the district court. The case can continue after the standing dismissal was reversed.
  3. Remaining legal issues. AmeriBen may renew motions to dismiss on the merits, and the ruling resolved neither liability nor damages.
  4. Class certification. The plaintiffs sued for themselves and others similarly situated, but the appellate opinion does not certify a class.
  5. Discovery and possible settlement talks. These are possible steps, not confirmed developments.

No settlement amount, payment date, claims administrator or deadline has been set.

Can You File a Claim in the AmeriBen Data Breach Lawsuit?

No. The October 9, 2026 decision created no public claim form or settlement process. The case is a proposed class action, not a court-approved settlement, and the ruling does not entitle everyone who received a notice to compensation. No action is needed to “join” at this stage.

If you received an AmeriBen notice:

  • Keep the notice. It may list the information that was potentially disclosed.
  • Save records. Keep health-plan correspondence and any documented costs or losses you believe relate to the disclosure.
  • Monitor your accounts. Review Explanation of Benefits statements and credit reports, and consider a fraud alert if you wish.
  • Watch the docket. The district court docket is where later orders, class-certification filings or settlement news will appear.
  • Avoid scams. Do not pay anyone for a nonexistent claim form.
  • Document real harm. If you suffered identity theft or another concrete loss, document it and consider consulting a qualified attorney, because limitation periods keep running.

Frequently Asked Questions

Did the Ninth Circuit rule that AmeriBen was liable?

No. It held only that the plaintiffs alleged enough injury for standing. Liability, damages and class certification remain undecided.

Does the ruling mean affected customers will receive money?

No. The court awarded no damages and approved no settlement. No claim form or payment deadline exists.

Do plaintiffs have to prove identity theft to sue?

Not necessarily. Here the court found that alleged unauthorized disclosure of confidential health information was enough for standing at the pleading stage. It does not guarantee that every data breach claim qualifies.

What information was involved?

Per the notices and court filings, names, tracking or claim numbers, provider information, dates of service and amounts billed or paid. The district court’s description says it did not include Social Security numbers or direct financial account credentials.

How many people were affected?

Reporting based on HHS OCR data puts the number at roughly 74,000 to 75,000 people. Check HHS OCR’s breach portal for the official figure.

Can patients sue AmeriBen directly under HIPAA?

No. HIPAA has no private right of action, as the Ninth Circuit noted. The lawsuit relies on state-law claims, and HIPAA was relevant only to the standing analysis.

Was this a certified class action?

No. It remains a putative class action, subject to class-certification requirements.

What are the case numbers?

The appeal is No. 25-5952 in the Ninth Circuit, and the district court case is No. 1:23-cv-00384-AKB in the District of Idaho.

When will the case be resolved?

No date has been set. The case goes back to the district court, and the decision sets no settlement deadline or trial date.

What should people who received a notice do?

Keep the notice, monitor statements and credit reports, and watch the docket. Consult a lawyer if you experienced actual harm.

Disclaimer: This article provides general legal information and is not legal advice. AllAboutLawyer.com is an independent legal information website, not a law firm. Allegations in a lawsuit are not findings of fact, and the court’s opinion controls. Verify the current docket status and consult qualified counsel about your own situation.

About the author: Researched and written by Israr Ahmad, legal content researcher at AllAboutLawyer.com. Coverage focuses on court filings, official government announcements, settlement documents and legal developments affecting consumers.

Sources

  1. U.S. Court of Appeals for the Ninth Circuit, Black v. IEC Group, Inc., No. 25-5952, published opinion filed October 9, 2026. https://cdn.ca9.uscourts.gov/datastore/opinions/2026/10/09/25-5952.pdf
  2. U.S. District Court, District of Idaho, Black v. IEC Group, Inc., No. 1:23-cv-00384-AKB, dismissal order, August 21, 2025. https://law.justia.com/cases/federal/district-courts/idaho/iddce/1%3A2023cv00384/52833/46/
  3. PACER, Public Access to Court Electronic Records. https://pacer.uscourts.gov/
  4. HHS Office for Civil Rights, breach portal and HIPAA Breach Notification Rule. https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
  5. HIPAA, 42 U.S.C. §§ 1320d-5 and 1320d-6. https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title42-section1320d-6&num=0&edition=prelim
  6. 45 C.F.R. Parts 160 and 164 (HIPAA Privacy, Security and Breach Notification Rules). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C
  7. Federal Rules of Civil Procedure 12 and 23. https://www.law.cornell.edu/rules/frcp
  8. Federal Rule of Appellate Procedure 40. https://www.law.cornell.edu/rules/frap/rule_40
  9. 28 U.S.C. § 1332(d) (Class Action Fairness Act). https://www.law.cornell.edu/uscode/text/28/1332
  10. Idaho Code § 28-51-104 et seq. (breach notification). https://legislature.idaho.gov/statutesrules/idstat/title28/t28ch51/
  11. Fla. Stat. § 501.201 et seq. (Florida Deceptive and Unfair Trade Practices Act). http://www.leg.state.fl.us/statutes/
  12. Lujan v. Defenders of Wildlife, 504 U.S. 555 (1992).
  13. Spokeo, Inc. v. Robins, 578 U.S. 330 (2016).
  14. TransUnion LLC v. Ramirez, 594 U.S. 413 (2021).
  15. Krottner v. Starbucks Corp., 628 F.3d 1139 (9th Cir. 2010).
  16. In re Zappos.com, Inc., 888 F.3d 1020 (9th Cir. 2018).

Researched and written by Israr Ahmad, Legal Content Researcher at AllAboutLawyer.com.

Last updated: October 10, 2026

About the Author

Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.

Leave a Reply

Your email address will not be published. Required fields are marked *