Articles Posted in Class-Action

Every data incident in 2026 produces the same playbook. A plaintiffs’ firm files a class action. The complaint pleads breach of contract. It pleads invasion of privacy. It pleads a federal statutory claim. And, almost always, it pleads negligence.

The negligence count usually says some version of the same thing. The defendant owed a duty to safeguard the plaintiff’s personal information, the defendant breached that duty by allowing the data to be exposed or transmitted, and the plaintiff suffered damages including diminished data value, anxiety, lost time, and lost benefit of the bargain.

Illinois law has a problem with this count. Two problems, actually.

The first problem is that there is no freestanding common law duty in Illinois to safeguard another person’s data. The second problem is that even if there were such a duty, Illinois’s economic loss doctrine, known as the Moorman doctrine, would bar recovery for the kinds of damages plaintiffs typically plead.

Both problems are dispositive at the motion to dismiss stage when the defense is built carefully.

The duty problem is settled by the Seventh Circuit. In Community Bank of Trenton v. Schnuck Markets, Inc., the court held that the Illinois Supreme Court has not recognized an independent common law duty to safeguard personal information. The court applied that holding to a data breach class action and dismissed the negligence claim. The Illinois Appellate Court reached the same conclusion in Cooney v. Chicago Public Schools, where the court rejected an attempt to use HIPAA, the federal medical privacy statute, as the source of a state law duty to safeguard data.

These holdings are not technicalities. They are reflections of how the duty element works in Illinois negligence law. A duty does not arise from a vague feeling that information should be protected. A duty arises from a relationship recognized by law, a statute that creates a private cause of action, or a common law rule the Illinois Supreme Court has actually adopted. When none of those exists, there is no duty, and there is no negligence.

Plaintiffs sometimes argue that the physician patient relationship, the merchant customer relationship, or the employer employee relationship is enough. Federal courts in Illinois have rejected those arguments in the data context. In Doe v. Genesis Health System, decided in 2025, the Central District of Illinois applied Community Bank and Cooney directly to a healthcare website tracking case and dismissed the negligence count. The court explained that the relationship based theory does not change the rule. If the Illinois Supreme Court has not recognized the duty, a federal court sitting in diversity will not invent it.

The second problem is the Moorman doctrine.

Moorman Manufacturing Co. v. National Tank Co. is one of the most cited cases in Illinois law. The Illinois Supreme Court held in 1982 that a plaintiff cannot recover in negligence for purely economic loss. Economic loss means losses that are not personal injury and are not damage to other property. Diminished data value is economic loss. Lost benefit of the bargain is economic loss. Lost time is economic loss. Anxiety and emotional distress are not personal injuries in this context. Each of those theories runs into the Moorman bar.

The reason this matters is that data class action complaints almost always allege economic loss as the principal damage theory. Without economic loss damages, the negligence count loses most of its monetary value. Without an actual breach of contract or a separate statutory cause of action, the case shrinks dramatically.

Three points are worth highlighting for any Illinois business defending a data related lawsuit. Continue reading ›

A new wave of class action lawsuits is sweeping into the Northern District of Illinois. The defendants are not telecom companies. They are healthcare practices, retailers, fintech companies, telehealth platforms, employers running candidate portals, and any business with a website that uses analytics or advertising tools.

The legal theory is the same in almost every case. The plaintiff alleges that a tracking pixel, often the Meta pixel, the TikTok pixel, or the Google tag, captured information the user typed into the defendant’s website and quietly transmitted that information to a third party advertising platform. The plaintiff then alleges that this transmission violated the federal Electronic Communications Privacy Act, also known as the Wiretap Act, 18 U.S.C. section 2511.

The financial pressure of these cases is enormous. The Wiretap Act allows statutory damages of the greater of $100 per day or $10,000 per plaintiff, plus attorney fees. Multiplied across a putative class of website visitors, the demand letter is designed to force a settlement. That math is the plaintiffs’ bar’s business model.

There is a powerful defense to most of these cases. It is called the party exception, and Illinois federal courts are increasingly willing to enforce it.

The party exception is not buried in a regulatory annex. It is in the statute itself. 18 U.S.C. section 2511(2)(d) provides that the prohibition on intercepting electronic communications does not apply where one of the parties to the communication has consented, or where the defendant is itself a party to the communication. When a customer or patient fills out a form on your website, the customer’s communication is being directed at you. You are not eavesdropping on someone else. You are the recipient.

That sounds obvious. It is also dispositive in most pixel cases when the defense is properly pleaded.

The Northern District of Illinois has issued a series of decisions applying this exact logic. In Kurowski v. Rush System for Health, the court held that Rush, not Facebook or Google or a downstream ad platform, was the intended recipient of the patient communications submitted through Rush’s website and patient portal. Sloan v. Anker Innovations Ltd. went further, holding that even where a defendant later uploads information to a third party server, the defendant remains a party to the original communication, not a non party interceptor. The Zak v. Bose Corp. line of cases rejected the plaintiffs’ bar’s relabeling tactic of recasting the website operator as a redirector of someone else’s data flow. And in Doe v. Genesis Health System, the court explained the principle in plain language. The communications could not have occurred without the plaintiff communicating with the defendant as the intended recipient and party.

What this means in practice is that when a plaintiff sues your business for embedding analytics on your own website that collected information the plaintiff voluntarily submitted to your business, you have a real defense at the motion to dismiss stage. The defense does not require discovery. It does not require expert testimony. It requires careful pleading and an early motion that frames the issue correctly. Continue reading ›

If you operate a healthcare practice, a telehealth platform, a behavioral health clinic, a fertility center, an addiction treatment facility, a dental or optometry chain, or any consumer facing business that handles sensitive information online, you have probably heard about the new generation of class action lawsuits over tracking pixels.

The lawsuits target businesses that embed third party tools like the Meta pixel, the TikTok pixel, or Google Analytics on their websites. The complaints allege that the tools captured information about a user’s interactions and transmitted that information to advertising platforms without consent.

In most of these cases, the defendant has a strong defense built into the federal Wiretap Act itself. When a user submits information to your website, you are a party to the communication, and 18 U.S.C. section 2511(2)(d) excludes parties from liability under the statute.

Plaintiffs know about that defense, so they have a workaround. They invoke the same subsection’s other clause, the so called crime tort exception. It provides that the party exception does not apply if the communication was intercepted for the purpose of committing any criminal or tortious act. Plaintiffs typically plead a HIPAA violation, an invasion of privacy claim, or both, as the predicate.

The question is whether this workaround survives.

That question is now actively splitting the federal courts in Illinois. The split is real, current, and important enough that one judge has already certified it for interlocutory appeal.

In the defense friendly camp, Doe v. Genesis Health System, decided by the United States District Court for the Central District of Illinois in 2025, held the answer is no. The court read the statute carefully and concluded that the defendant must have intercepted the communication for the purpose of committing a crime or a tort. Marketing and advertising purposes, the court held, do not satisfy that standard, because lawful commercial activity, even when it ultimately runs afoul of HIPAA’s regulatory scheme, is not the same as acting in order to commit a crime or tort. The Seventh Circuit articulated a similar principle years earlier in Thomas v. Pearl and again in Desnick v. American Broadcasting Cos. The recorder must intend to break the law or commit a tort. That intent is the heart of the carve out.

Doe 1 v. Chestnut Health Systems, Inc., decided in 2025, took the same path and dismissed a complaint that recited criminal or tortious purpose in conclusory terms. The court held that a conclusory recital will not do.

In the plaintiff friendly camp, Stein v. Edward-Elmhurst Health, decided in 2025, went the other way. The court held that a HIPAA violating disclosure can satisfy the carve out even when the defendant’s overall purpose was lawful commercial advertising. The same court later denied reconsideration but explicitly certified the question for interlocutory appeal, finding substantial ground for difference of opinion. That certification is itself a tell. When a federal trial court is comfortable enough with the strength of the opposing view to permit an immediate appeal, the law is genuinely unsettled.

What does this mean for Illinois businesses? Three things. Continue reading ›

Based on our research and experience, the best defenses to a class action generally revolve around the requirements of typicality and adequacy of the class representative (Danis v. USN Communications, Inc., 189 F.R.D. 391 (1999)). The presence of even an arguable defense peculiar to the named plaintiff or a small subset of the plaintiff class may destroy the required typicality of the class as well as bring into question the adequacy of the named plaintiff’s representation. This fear arises from the possibility that the named plaintiff could become distracted by the presence of an individual defense, which could compromise the representation of the rest of the class (Al Haj v. Pfizer Inc., — F.R.D. —- (2020)), (Lipton v. Chattem, Inc., 289 F.R.D. 456 (2013)), (CE Design Ltd. v. King Architectural Metals, Inc., 637 F.3d 721 (2011)).

A defense unique to a proposed class representative does not need to be a sure bet to defeat the adequacy required for class certification; it only needs to be arguable and substantial (Al Haj v. Pfizer Inc., — F.R.D. —- (2020)). Similarly, defenses that are specific to the named representative may defeat the requirements of typicality or adequacy of the representative (Danis v. USN Communications, Inc., 189 F.R.D. 391 (1999)). However, these defenses need to be “unique, arguable and likely to usurp a significant portion of the litigant’s time and energy” (Danis v. USN Communications, Inc., 189 F.R.D. 391 (1999)).

It’s important to note that the assertion of individual defenses does not necessarily defeat a plaintiff’s ability to represent a class adequately (P.J.’s Concrete Pumping Service, Inc. v. Nextel West Corp., 345 Ill.App.3d 992 (2004)), (Walczak v. Onyx Acceptance Corp., 365 Ill.App.3d 664 (2006)). A class action, in which a defendant is alleged to have acted wrongfully in the same basic manner as to the entire class, is not necessarily defeated merely because certain defenses may be urged against individual class members (735 ILCS 5/2-801).

Moreover, defenses that are unique to a named plaintiff are relevant to the inquiry into whether plaintiff’s claims are typical but are not necessarily dispositive of the issue (Sebo v. Rubenstein, 188 F.R.D. 310 (1999)). In many instances when a unique defense exists a class is defeated but the court is not required to deny certification for speculative reasons; the certification decision always remains within the sound discretion of the court (Danis v. USN Communications, Inc., 189 F.R.D. 391 (1999)).

Lastly, it’s worth noting that while the merits are not typically before the appellate court when reviewing the district court’s certification of the class, the claim of the class representative may be subject to a defense that makes it an inappropriate representative of the class because other class members may not be subject to the same defense, or perhaps to any defense (CE Design Ltd. v. King Architectural Metals, Inc., 637 F.3d 721 (2011)).

Continue reading ›

When facing a class action lawsuit, the stakes are incredibly high. The complexity of these cases requires a legal team with specialized expertise and a track record of success. DiTommaso Lubin stands out as a premier choice for several compelling reasons:

Extensive Experience in Class Action Defense

DiTommaso Lubin’s legal team has extensive experience in defending class action lawsuits across various industries. Our attorneys are well-versed in the intricate procedural and substantive aspects of class action law, ensuring that every angle of your case is meticulously analyzed and strategically addressed.

In a world where consumer lawsuits and class actions seem to be on the rise, businesses are constantly seeking effective strategies to defend themselves against potential legal challenges. One strategy that often flies under the radar but can be a game-changer is product recalls. While recalls are typically viewed as an admission of fault, they can actually serve as a powerful defense strategy, potentially short-circuiting class action lawsuits before they gain traction. In this blog, we’ll explore how recalls can be a great defense strategy for businesses.

1. Swift Action and Responsibility

One of the primary reasons recalls can be an effective defense strategy is the swift action and responsibility they demonstrate. When a company identifies a potential safety issue with one of its products and voluntarily recalls it, they are taking proactive steps to protect their consumers. This responsible and proactive approach can help build goodwill with customers and regulators.

By recalling a product quickly, a company can show that they prioritize safety over profit, which can make it challenging for plaintiffs to argue that the company was negligent or intentionally harmed consumers. Instead of facing a drawn-out legal battle, the company can focus on rectifying the issue and rebuilding trust.

2. Mitigation of Damages

Recalls also allow companies to mitigate potential damages, which can be a significant factor in deterring class action lawsuits. When a company recalls a product, they can take it off the market, preventing further harm to consumers and limiting potential damages. This swift action can reduce the overall number of affected consumers and the associated financial impact.

In a class action lawsuit, plaintiffs often seek damages for medical bills, lost wages, pain and suffering, and other related costs. By recalling the product early, a company can argue that they took reasonable steps to prevent these damages from occurring or escalating. Continue reading ›

The Telephone Consumer Protection Act (TCPA) imposes liability for calling or texting cellular phone numbers using an Automatic Telephone Dialing System (ATDS) without sufficient prior express consent. The TCPA defines an ATDS as “equipment which has the capacity (A) to store or produce telephone numbers to be called, using a random or sequential number generator; and (B) to dial such numbers.” The TCPA creates a private cause of action and allows a plaintiff to recover statutory penalties of $500 per call or text in violation, or up to $1,500 for a knowing or willful violation. These statutory penalties have made the TCPA a useful tool for class-action plaintiffs’ attorneys seeking to hold companies liable for calls and texts over a four year statute of limitations period.

The Ninth Circuit has traditionally taken an expansive approach when defining what does and doesn’t qualify as an ATDS, extending the definition to virtually any kind of auto-dialer. Last year however, in Facebook, Inc. v. Duguid, the U.S. Supreme Court struck down the Ninth Circuit’s expansive approach to defining an ATDS, generally holding that an auto-dialer is not an ATDS if the numbers being dialed are from an existing list of specific numbers, such as from a database. Since Duguid, many TCPA defendants have argued that the definition of an ATDS requires that the random or sequential number generator be used to generate telephone numbers. Many TCPA defense attorneys also remained concerned that more liberal circuits, such as the Ninth and Second Circuits, might undermine Duguid’s conservative, defense-friendly ruling.

TCPA plaintiffs’ attorneys seized on a particular quirk in footnote 7 of the Duguid opinion where the Supreme Court addressed an argument concerning the overlapping of the “storing and producing functions” of an ATDS. In addressing a situation where an autodialer might not both store and produce numbers, the Supreme Court wrote: “For instance, an autodialer might use a random number generator to determine the order in which to pick phone numbers from a pre-produced list. It would then store those numbers to be dialed at a later time.” Plaintiffs’ attorneys have argued that companies that maintain customer contact lists and select which customers to contact on a given day using a random or sequential number generator are therefore using an ATDS. Continue reading ›

The U.S. Food and Drug Administration recently published a proposed rule that, if implemented, would update the labeling standards that food products must meet in order to be labeled as “healthy.” The FDA first established a definition for “healthy” in 1994, and at that time nutrition science and federal dietary guidance focused more on the individual nutrients contained in food. According to the FDA, the proposed rule would “align the definition of ‘healthy’ with current nutrition science, the updated Nutrition Facts label and the current Dietary Guidelines for Americans,” with the goal of assisting consumers to increase their consumption of under-consumed dietary components.

The proposed rule would achieve this goal by requiring “healthy” foods to contain a minimum quantity of at least one of the specified food groups or subgroups recommended by the Dietary Guidelines such as fruits and vegetables, while limiting over-consumed ingredients that may lead to negative health consequences such as sodium or added sugars. The FDA’s proposed framework for the updated definition of “healthy” focuses on ensuring that foods labeled as healthy can qualify to bear the title by helping consumers to build a diet consistent with current dietary recommendations. Continue reading ›

Facing a recently filed putative class action lawsuit over the labeling and marketing of its toddler formula, baby formula manufacturer Gerber has asked a federal judge in Chicago to dismiss the suit arguing that reasonable parents buying its toddler formula couldn’t possibly be misled by the claims on its Good Start Grow products. The motion comes on the heels of the dismissal of a second class action lawsuit involving Gerber’s formula by a Virginia federal judge earlier in the month.

In her complaint, plaintiff Melissa Garza alleges that Gerber makes a toddler formula that is marketed as nutritional, but which actually contains added sugars and less protein than cow’s milk. Garza alleges that Gerber’s Good Start GentlePro Infant Formula and Good Start Grow Toddler Drink are marketed nearly identically without disclosing that the toddler formula has added sugar, less protein and more carbohydrates than whole cow’s milk.

The complaint alleges that Gerber’s failure to adequately distinguish the two products and disclose that its toddler formula is inconsistent with expert advice constitute violations of the Illinois Consumer Fraud and Deceptive Business Practices Act, the consumer fraud acts of other states and the federal Magnuson Moss Warranty Act and has unjustly enriched Gerber. Garza seeks to represent herself and a class of individuals in Illinois, Iowa, Arkansas, Wyoming, North Dakota, and Utah who purchased Gerber’s toddler formula.

The toddler formula, which the complaint refers to as a “transition formula” (a term Gerber takes issue with in its motion to dismiss), contains nearly the same ingredients as Gerber’s infant formula and is fortified with vitamins D and E as well as iron. However, Garza alleges that a global consensus of pediatric health organizations, including the American Academy of Pediatrics (AAP) Committee on Nutrition and the relevant Sub-Committee of the World Health Organization (WHO) have advised that transition formula is not recommended and that toddlers can meet all nutritional needs from whole cow’s milk, water and healthy foods. Continue reading ›

In today’s society, license agreements are everywhere. With the advent of Software as a Service (SaaS) and web-based services, click-wrap or clickthrough agreements—agreements where the licensee agrees to the terms of the license agreement by clicking a button or ticking a box—are commonplace. The software and online services industries depend on such agreements. Recently however, a federal district court judge out of the Northern District of California issued a potentially industry-shaking ruling invalidating amendments to such click-wrap agreements unless a user is required to manifest assent to such amendments through something more than mere continued use of the service.

The defendant in the suit is Dropbox and the plaintiff is a user of Dropbox’s online file storage service. The plaintiff, who filed the suit pro se, alleged that he suffered injury as a result of a 2012 data breach which the plaintiff alleged involved the compromise of his Dropbox account. In response to the complaint, Dropbox moved to compel arbitration arguing that its amended terms of service (TOS) required the claim to be resolved through binding arbitration instead of a lawsuit. Continue reading ›

Contact Information