• Skip to primary navigation
  • Skip to main content

HRMorning

  • FREE RESOURCES
  • PREMIUM CONTENT
  • HR DEEP DIVES
  • PODCASTS
    • VOICES OF HR
    • WOMEN’S LEADERSHIP TODAY
  • LOGIN
  • SIGN UP FREE
  • Employment Law
  • Benefits
  • Recruiting
  • HR Technology
  • Payroll
  • Management
  • Women’s Leadership
  • More
    • Talent Management
    • Performance Management
    • Leadership & Strategy
    • Compensation
    • Policy & Procedures
    • Wellness
    • Staff Departure
    • HR Career & Self-Care
    • Health Care
    • Retirement Plans
  • Employment Law

Data breach, but no identity theft: Can employee still sue?

Tom D'Agostino
By: Tom D'Agostino
  • Share on

About the Author

Tom D’Agostino is an attorney and legal editor who has more than 30 years of experience writing about employment law, disability law and education law trends. He earned his B.A. degree from Ramapo College of New Jersey and his J.D. from the Duquesne University School of Law. D’Agostino, who is a member of the Pennsylvania bar, is a past member of the American Bar Association’s Section of Individual Rights and Responsibilities and the Pennsylvania Bar Association’s Legal Services to Persons with Disabilities Committee. He has provided technical assistance in the production of segments for television’s ABC World News and 20/20, and he has been quoted in periodicals including USA Today. He is also a past contributing author of Legal Rights of Persons with Disabilities: An Analysis of Federal Law, which is a comprehensive two-volume treatise addressing the legal rights of people with disabilities. Tom is passionate about baseball and authentic Italian food. When not writing, he enjoys spending time with family.

Show Less
Last Updated: September 20, 2022
5 minute engagement
New Ruling Backs Ex-Employee

An important new decision from a federal appeals court says a former employee can proceed with claims against her old employer based on a data breach – even though the breach did not lead to identity theft or fraud against her.

“In an increasingly digitized world,” the court advised, “an employer’s duty to protect its employees’ sensitive information has significantly broadened.”

That admonition may understandably strike fear in the hearts of employers that have been less than diligent about safeguarding private employee information. It reflects a stark reality: It’s more important than ever to have robust safeguards in place to protect the confidentiality of personal information employers collect from their employees.

This case involves Jennifer Clemens, who used to work for ExecuPharm, Inc. ExecuPharm is a subsidiary of a global pharmaceutical company called Parexel International.

As a condition of employment ExecuPharm required Clemens to provide it with a variety of highly sensitive and personal information. This information included her Social Security number, bank and financial account numbers, insurance and tax information, and her passport.

In return, Clemens’ employment agreement said the company would “take appropriate measures to protect the confidentiality and security” of the information she gave it.

After Clemens left the company, a hacking group used a phishing attack to steal sensitive information relating to a number of its current and former employees – and Clemens was one of them.

The hacking group held the information for ransom before posting it to the Dark Web, making it available to others.

ExecuPharm provided periodic updates to affected individuals, and it also provided a year of credit-monitoring services.

No identity theft, but …

In addition, Clemens took other steps. She placed fraud alerts on her credit reports, and she transferred her money to a new bank. She also paid for additional credit-monitoring services for herself and her family. She also says the ordeal caused her to suffer emotional distress and incur related costs for therapy.

She sued ExecuPharm and Parexel, asserting negligence and breach of contract against them.

A lower court ruled against her, granting a defense motion to dismiss the suit. It said the suit could not go on because Clemens only alleged an increased risk of identity theft, which was not enough. Her risk of future harm was speculative, the lower court said, because she had not experienced actual identity theft or fraud. In legal terms, it explained, she did not have “standing” to proceed with the suit.

On appeal, the U.S. Court of Appeals for the Third Circuit (Delaware, New Jersey and Pennsylvania) disagreed and revived the suit.

To show “standing,” the appeals court explained, Clemens had to demonstrate that she suffered a concrete injury that was actual or imminent. She further had to show the employer caused the injury and that the requested relief would set things right.

No harm no foul? No way

Allegations of future injury are good enough, the court explained, if there is a substantial risk that the harm will occur. That is the case here, the court said. It said Clemens presently faces a substantial risk of identity theft or fraud because her personal information is on the Dark Web.

In addition, the harm Clemens alleges is sufficiently concrete, the court added. Her costs associated with mitigation efforts and therapy are concrete, it noted.

In addition, Clemens alleged facts showing her injury is traceable to the employer’s conduct, the reviewing court added. And her alleged injury can be made right by the court via a monetary award.

In essence, the court decided that Clemens – and others like her – cannot be forced to wait until they actually experience identity theft before they sue for a data breach. It is enough to show a substantial risk of further harm, it decided.

The case was sent back to the lower court for further proceedings.

The decision gives employees in similar cases potent ammunition to support the argument that in data breach cases, they should be able to recover damages even if the breach does not lead to identity theft. Essentially, it says that the problems caused by a significant breach alone are enough to support a claim for damages.

It is not the only federal appeals court ruling to reach a similar conclusion on this issue. At least one other federal appeals court has ruled that a substantial risk of future identity theft is sufficient to file suit.

Employers have not only legal but also reputational incentive to carefully safeguard the privacy of personal information collected from employees.

Questions to ask

Here are some questions to ask and answer with regard to the collection and maintenance of confidential employee information.

  1. Do we really need this information? Before collecting personal information from employees, carefully evaluate whether it is truly needed and how it will be used. In this case, the former employee alleges that the employer required her to provide a significant amount of varied and highly personal information, including even information relating to her child and husband.
  2. Have we properly trained employees relating to securing the personal data of collected information? In this day and age, cybersecurity threats are as real as ever. Proper training of all relevant employees is imperative. Some basics: Require strong passwords; instruct employees not to open email attachments from suspicious sources; and regularly back up all data.
  3. Are adequate security measures in place? These include, for example, firewalls, secure passwords and encryption.
  4. Do we have a response plan ready to go? If the worst happens and a breach occurs, you need to act quickly to minimize the harm. It is not time to formulate a response from scratch. Instead, it is time to put a previously designed plan into action. This plan must include providing timely notice to all affected individuals.
  5. Do our written policies reflect a commitment to safeguard confidential information? A published confidentiality policy makes employees aware of your commitment to safeguard their private information and outlines the scope of your duties in this regard.

Clemens v ExecuPharm, Inc., No. 21-1506 (3d Cir. 9/2/22).

Filed under
  • Employment Law
  • Share on

Get the HRMorning Newsletter

With HRMorning arriving in your inbox, you will never miss critical stories on labor laws, benefits, retention and onboarding strategies.

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form
  • This field is hidden when viewing the form

Free Training & Resources

Webinars

Improve New-Hire Engagement with Digital Onboarding

Webinars

Implementing a Hybrid Work Strategy that Makes Sense for Your Business

Webinars

Go From HR Overwhelm to Expert: How to Level Up Your Career and Become a Strategic Partner

White Papers

Payroll Automation: The Key to Compliance And Efficiency

Provided by Paypro

SPONSORED CONTENT

HR Technology

sponsored content
The Best AI Software for HR Automation

Courtesy of G-P

Talent Management

sponsored content
Powerful Employee Retention Strategies for 2025: How to Keep Your Best People

Courtesy of PEOPLEGURU

Benefits

Health Care

Wellness

sponsored content
Proven Results: 5 Ways Teladoc Health Chronic Condition Management Transforms HR Outcomes

Courtesy of TELADOC HEALTH

Further Reading

  • Employment Law
Flu vaccine misstep costs employer $50K

A Michigan hospital has agreed to pay $50,000 and furnish other relief to settle a lawsuit that accused it of pulling a job offer because t...

  • Employment Law
State AGs warn Fortune 100: Mind your DEI efforts

A mid-July letter signed by the attorneys general of 13 states warns Fortune 100 CEOs that they “will face serious legal consequences” ...

  • Employment Law
Did Toxic Workplace Lead to Birth Defects? Suit Gets New Life

An employer may be responsible for birth defects allegedly caused by its workers’ exposure to toxic chemicals, a state appeals court in I...

  • Employment Law
Cal/OSHA Targets Silica Safety Violations, Cites 9 Employers

California’s Division of Occupational Safety and Health (Cal/OSHA) has cited nine employers for silica health and safety violations in th...

  • Employment Law
  • Retirement Plans
DOL issues new guidance on PLESAs: What HR needs to know

The Department of Labor (DOL) recently issued new federal guidance on pension-linked emergency savings accounts (PLESAs) that employers sho...

  • Employment Law
7 bonus tips you absolutely need when dealing with job accommodation requests

What’s a valid accommodation request under the ADA or similar law? This case shows that the answer might not be as simple as you think...

Get the latest from HRMorning in your inbox PLUS immediately access 10 FREE HR guides.

I WANT MY FREE GUIDES
HR Morning Logo
  • Facebook
  • Linked In
  • ABOUT HRMORNING
  • ADVERTISE WITH US
  • WRITE FOR US
  • CONTACT
  • Employment Law
  • Benefits
  • Recruiting
  • Talent Management
  • Performance Management
  • HR Technology
  • Leadership & Strategy
  • Compensation
  • Policy & Procedures
  • Wellness
  • Staff Departure
  • HR Career & Self-Care
  • Health Care
  • Retirement Plans
  • DEI

HRMorning, part of the Rover Insights Network, provides the latest HR and employment law news for HR professionals in the trenches of small-to-medium-sized businesses. Rather than simply regurgitating the day's headlines, HRMorning delivers actionable insights, helping HR execs understand what HR trends mean to their business.

Powered By Rover Insights
Privacy Policy | Terms of Service
Copyright© 2026 Rover Insights
HRMorning Logo

WELCOME BACK!

Enter your username and password below to log in

Forget Your Username or Password?

Reset Password

Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.

Log In

Why do we need your credit card for a free trial?

We ask for your credit card to allow your subscription to continue should you decide to keep your membership beyond the free trial period.  This prevents any interruption of content access.

Your card will not be charged at any point during your 21 day free trial
and you may cancel at any time during your free trial.

During your free trial, you can cancel at any time with a single click on your “Account” page.  It’s that easy.