
San Francisco, CA, October 9, 2026, The U.S. Court of Appeals for the Ninth Circuit issued a published opinion today in Black v. IEC Group, Inc. d/b/a AmeriBen, No. 25-5952. The court held that people who trust a company to keep their sensitive health information private suffer a real, concrete injury when that company discloses the information without their consent. That injury is enough to give them standing to sue in federal court.
The panel of Judges Michael Daly Hawkins, William A. Fletcher, and Eric C. Tung reversed the U.S. District Court for the District of Idaho, which had dismissed the class action lawsuit for lack of standing. The case now returns to the district court for further proceedings.
Judge Tung wrote the opinion and framed the question this way: “If you entrust a company to keep your sensitive health information private, but the company then discloses that information to others without your consent, have you been injured? We hold yes.”
Plaintiffs Melissa and Miles Black receive health insurance through a plan administered by IEC Group, Inc., which does business as AmeriBen. In August 2023, AmeriBen sent each of them a letter saying that an employee had emailed a spreadsheet containing their sensitive health information to one or more plan members.
According to the letter, the information that may have been disclosed included first and last names, unique tracking numbers, provider names, claim numbers, dates of service, and the amounts billed or paid. The plaintiffs allege that AmeriBen promised, including through its Privacy Policy, to keep this information confidential. They also allege that AmeriBen broke that promise.
The district court dismissed the case. It ruled that the plaintiffs had to show an imminent and substantial risk of further harm, beyond the disclosure itself, to establish an injury in fact.
The Ninth Circuit rejected that narrower standard. The court relied on centuries of English and American law and held that unauthorized disclosure of entrusted health information closely resembles a breach of confidence or breach of contract. Courts have long recognized both as grounds for a lawsuit. In the court’s words, “a trust betrayed is the harm.”
The court added that Congress’s judgment in enacting HIPAA confirms that disclosure of this kind of health information is a concrete injury. The court observed that information that might look mundane, such as a provider’s name, dates of service, or amounts billed, “can reveal one’s most private health concerns.” Its examples included a patient seeing a psychiatrist for daily therapy sessions or spending time at a fertility clinic. The court concluded: “Disclosure of such sensitive information resulting from a breach of trust is a harm.”
The opinion also addresses decisions from other circuits. It notes that the Third, Seventh, and Fourth Circuits had not considered a breach of confidentiality based on contractual promises to keep HIPAA-protected health information private, which makes those cases “readily distinguishable.”
This published decision sets binding precedent across the Ninth Circuit. It gives consumers whose confidential health data is mishandled a clear path into federal court, without first having to show identity theft or financial loss.
“Because of this decision, the proverbial door to the courthouse will be opened to millions of people in the United States who entrust their data to healthcare providers, insurers, and other big corporations on the promise that it will be kept confidential,” said Marc Dann of DannLaw.
“For too long, companies that mishandle our most private health information have argued that consumers must wait until they become victims of identity theft before they can seek justice,” said Tom Zimmerman of Zimmerman Law Offices. “The Ninth Circuit rejected that argument and recognized what courts have understood for centuries: when a company betrays the trust you placed in it, that betrayal is itself a harm. We are proud to have secured this important precedent for our clients and for consumers throughout the Ninth Circuit, and we look forward to pursuing this case on remand.”
Jeff Blake of Zimmerman Law Offices, P.C. argued the appeal for the plaintiffs. The plaintiffs are also represented by Tom Zimmerman of Zimmerman Law Offices, P.C.; Marc Dann, Brian Flick, and Marita Ramirez of DannLaw; and Bonner Walsh of Walsh PLLC.
DannLaw is a consumer protection law firm based in Lakewood, Ohio, that represents individuals in class actions and individual cases against corporations that violate consumers’ rights, including in the areas of data privacy, data breach, and consumer financial protection. Led by Marc Dann, the firm’s attorneys litigate in state and federal courts across the country.
Zimmerman Law Offices, P.C. is a Chicago, Illinois-based law firm founded by Tom Zimmerman that represents consumers and other plaintiffs in class action and complex litigation, including data breach and privacy cases, in courts nationwide.
Marc Dann, DannLaw
330-651-3131
md***@*****aw.com
Tom Zimmerman, Zimmerman Law Offices, P.C.
312-440-0020
to*@*********im.com