The Kelly Benefits data breach lawsuit is actually more than a dozen proposed class actions, now consolidated in the U.S. District Court for the District of Maryland as In re Kelly Benefits Data Breach Litigation. The plaintiffs allege that Kelly & Associates Insurance Group, doing business as Kelly Benefits, failed to protect the personal and medical data of 553,660 people from a December 2024 network intrusion and then took roughly four months to start telling victims. The consolidated case is currently stayed.1PACER Monitor. In Re Kelly Benefits Data Breach Litigation
What Happened in the Breach
Intruders were inside Kelly Benefits’ network from December 12 through December 17, 2024, and copied files during that five-day window.2Milberg. Kelly Benefits Data Breach Lawsuit The company says it detected suspicious activity on December 17 and brought in third-party forensics specialists.3The HIPAA Journal. Kelly Benefits Data Breach No ransomware group has publicly claimed the attack.4SC World. Over 260K Compromised in Kelly Benefits Breach
The stolen files contained names, Social Security numbers, dates of birth, tax identification numbers, medical information, health insurance details, financial account information, and in some cases home addresses and government-issued ID numbers.5Paubox. Kelly Benefits Data Breach Impacts Over Half a Million Customers
The reported victim count climbed sharply over several months. Kelly Benefits first told the Maine Attorney General on April 9, 2025 that 32,234 people were affected. On April 21 it revised that number to 263,893, and on May 2 to 413,032.6The HIPAA E Tool. Kelly Benefits Breach Skyrockets to Over 400K An amended disclosure dated July 1, 2025 put the confirmed total at 553,660.7ClaimDepot. Kelly & Associates Data Breach
Who Was Affected
Kelly Benefits administers employee benefits for other companies, so the exposed data belonged mostly to workers at its client organizations rather than to Kelly Benefits’ own customers. The HIPAA Journal identified 45 client organizations tied to the breach, plus Lincoln National Corporation, which reported the incident independently.3The HIPAA Journal. Kelly Benefits Data Breach
The affected clients include major insurers such as United Healthcare, Aetna Life Insurance Company, CareFirst BlueCross BlueShield, Guardian Life Insurance Company, Humana Insurance ACE, Mutual of Omaha Insurance Company, and OneAmerica Financial Partners. Affected employers include Wawa, Mission BBQ Management, FutureCare Health and Management, The Bozzuto Group, Tessco Technologies, ThompsonGas, Virtua Health, and Liquidity Services, among others.3The HIPAA Journal. Kelly Benefits Data Breach
What the Lawsuits Allege
At least 13 proposed class actions were filed in the District of Maryland and later consolidated into In re Kelly Benefits Data Breach Litigation, assigned to Judge Stephanie A. Gallagher.8CourtListener. In Re Kelly Benefits Data Breach Litigation6The HIPAA E Tool. Kelly Benefits Breach Skyrockets to Over 400K
Security Failures
The most detailed complaint, filed by plaintiff Carolyn Gale, alleges that Kelly Benefits stored sensitive data, including information protected by HIPAA, in unencrypted form. It also claims the company lacked multi-factor authentication, strong password requirements, layered defenses such as firewalls and anti-malware software, network port monitoring, email and browser protections, and a functional incident response plan. The complaint says these shortcomings fell below the NIST Cybersecurity Framework and the Center for Internet Security’s Critical Security Controls, and it points to the five days intruders spent inside the network before detection to challenge the company’s post-breach statement that it would “continue to review its already robust security policies.”9U.S. District Court for the District of Maryland. Gale v. Kelly & Associates Insurance Group Complaint
Delayed Notice
Kelly Benefits finished matching affected individuals to their employers and carriers on March 3, 2025, but the first notification letters did not go out until April 9, with broader rolling mailings beginning May 2.3The HIPAA Journal. Kelly Benefits Data Breach One complaint puts the gap between the breach and the first victim notices at 118 days and alleges Kelly Benefits never posted a breach notice on its own website.10Privacy Daily. Class Action Says Insurance Groups Negligence Prompted Data Breach The company reported the breach to the California and Maine Attorneys General on May 2, 2025.11SecurityWeek. Kelly Benefits Data Breach Impact Grows to 400,000 Individuals
Legal Claims
The consolidated complaints share a common set of legal theories:
- Negligence, based on the alleged failure to implement reasonable cybersecurity, train employees, and monitor the network and vendors.
- Breach of contract, based on Kelly Benefits’ privacy policy promising “reasonable care” and limited access to authorized personnel.
- Violations of HIPAA provisions covering access controls, security management, and workforce training.
- Violations of the FTC Act and state consumer protection statutes.
- Violation of Maryland’s data breach notification statute, Md. Commercial Law § 14-3504(b)(3), pleaded specifically in the Parks complaint.2Milberg. Kelly Benefits Data Breach Lawsuit
What Plaintiffs Are Seeking
The lawsuits ask for monetary damages and injunctive relief that would force Kelly Benefits to overhaul its data security. The Gale complaint specifically requests lifetime credit monitoring and identity theft protection, well beyond the 12 months of IDX monitoring Kelly Benefits offered in its notification letters.9U.S. District Court for the District of Maryland. Gale v. Kelly & Associates Insurance Group Complaint5Paubox. Kelly Benefits Data Breach Impacts Over Half a Million Customers
Where the Case Stands
The consolidated litigation is pending but paused. Judge Gallagher issued a Memorandum Opinion on December 10, 2025, and on April 9, 2026 granted a consent motion to stay all proceedings. The parties were directed to file a joint status report by June 26, 2026.1PACER Monitor. In Re Kelly Benefits Data Breach Litigation No class has been certified, and no settlement has been publicly announced. No state or federal regulatory enforcement actions or fines against Kelly Benefits have been reported.
What Affected People Can Do Now
If you received a notification letter, Kelly Benefits offered 12 months of free credit monitoring and identity theft protection through IDX, which includes fraud resolution help and insurance for identity-related losses. The letters also recommended watching for phishing attempts and considering a credit freeze.5Paubox. Kelly Benefits Data Breach Impacts Over Half a Million Customers Because the case is stayed and no class has been certified, there is no settlement claim form to fill out yet. Keep any notification letter you received; it is the document that ties you to the case if a class is later certified or a settlement is reached.