Alert
September 29, 2026

ND Ill. Dismisses FCA Cybersecurity Claim Premised on Regulatory Noncompliance, Finding Lack of Materiality

Quick Summary

The U.S. District Court for the Northern District of Illinois dismissed without prejudice an FCA case alleging that Archer Daniels Midland made false statements about its cybersecurity and data protection practices while receiving federal contracts and grants. The court found that the Relator failed to plausibly allege that the government considered ADM’s cybersecurity practices in specific payment decisions, emphasizing that a regulatory requirement is not material under the FCA merely because compliance is a condition of payment. The decision underscores that cybersecurity-based FCA claims require allegations that link regulatory noncompliance to specific affirmative representations and show materiality, including under an implied certification theory. Despite the dismissal, cybersecurity-related FCA exposure remains a risk when compliance with cybersecurity requirements may affect government payment decisions.

This summary was produced using artificial intelligence and reviewed by a human editor.

In 2021, the U.S. Department of Justice (DOJ) launched its Civil Cyber-Fraud Initiative, which uses the False Claims Act (FCA) to combat cybersecurity-related fraud committed by government contractors and grant recipients. The initiative’s primary goal is to shield US information from cybersecurity attacks by holding accountable entities and individuals who “knowingly provid[e] deficient cybersecurity products or services, knowingly misrepresent[] their cybersecurity practices or protocols, or knowingly violat[e] obligations to monitor and report cybersecurity incidents and breaches.” The DOJ’s focus on leveraging the FCA to investigate potential violations of these cybersecurity requirements has continued under the current administration. As of June 24, 2026, the DOJ has recovered more than $73.5 million in at least 15 cybersecurity-related FCA settlements, plus an additional $2 million recovered in a 16th settlement with Honeywell Aerospace Inc. earlier this month. A recent dismissal of an FCA case in the U.S. District Court for the Northern District of Illinois, however, highlights the high materiality bar that the DOJ (and private qui tam relators under the FCA) face when pleading FCA violations, particularly when the alleged fraud rests on regulatory noncompliance rather than affirmative misrepresentations.

The Allegations

In United States ex rel. Mark Pannek v. Archer Daniels Midland Company, Mark Pannek (the “Relator”), a former Archer Daniels Midland (ADM) employee, sued ADM under the FCA, 31 U.S. Code Section 3729 and the following, alleging that ADM made false statements and certifications “about its cybersecurity and data protection practices” while receiving more than $1 billion in federal contracts and grants “related to food commodities and biofuel processing” from the U.S. Department of Agriculture and U.S. Department of Energy. The DOJ declined to intervene in the action, and the Relator chose to continue litigating the case, despite the DOJ’s determination.

The Relator’s amended complaint alleged that certain of ADM’s federal grants and contracts — including a Climate-Smart Commodities grant, grants for ADM’s Advanced Biofuel Program and for COVID-19 relief, Department of Energy grants, ADM’s registration with the System for Award Management, and more than 250 government contracts — included express or implied representations about the company’s compliance with federal cybersecurity and data protection requirements.

The Relator alleged that, “while receiving government funds,” ADM maintained “sensitive information on a centralized data repository with no encryption,” failed to limit access or maintain access logs, sent unencrypted data “to external systems, inadequately screen[ed] third-party service providers, and us[ed] banned telecommunications equipment.” The Relator alleged that this conduct violated multiple federal regulations and standards, including Controlled Unclassified Information regulations, National Institute of Standards and Technology guidelines, Federal Acquisition Regulation requirements, “and other data safeguarding requirements.” The Relator contended that any statement made by ADM that it “complied with all federal regulations or otherwise protected sensitive data was [therefore] false.”

ADM moved to dismiss under Rule 12(b)(6) and Rule 9(b), arguing that the Relator failed “to plead any element of the alleged fraud with sufficient particularity” and that it was “not bound by many of the cybersecurity regulations and standards” cited in the complaint.

The Court’s Decision

U.S. District Judge Sunil R. Harjani of the Northern District of Illinois granted ADM’s motion to dismiss, finding that the Relator failed to demonstrate that any statements related to ADM’s cybersecurity practices were material to the government and that some of the alleged misstatements were “not pled with sufficient particularity.” The court dismissed the complaint without prejudice, permitting the Relator an opportunity to replead.

Materiality: The Dispositive Ground

The court found that the Relator’s “broad allegations about the importance of cybersecurity to the agencies administer[ing] ADM’s contracts and grants” were insufficient to meet the materiality standard for an FCA claim. The court reasoned that the Relator did “not plausibly allege[] that the government attache[d] weight to ADM’s data security practices” in making its specific payment decisions. Citing Universal Health Services, Inc. v. United States, 579 U.S. 176, 194 (2016), the court emphasized that a misrepresentation is not “material merely because the [g]overnment designates compliance with a […] regulatory […] requirement as a condition of payment.” The court found that the Relator’s “conclusory claim that the government would have changed its funding decision” if it had been aware of the noncompliance was insufficient without any “allegations that the government relied on [ADM’s] cybersecurity practices […] in making its payment determinations.”

Particularity of the Alleged False Statements

The court stated that the complaint could “be dismissed on materiality alone,” but chose to address “ADM’s remaining arguments” as well, in anticipation of an amended complaint. Applying Rule 9(b)’s requirement that FCA complaints identify the “who, what, when, where, and how” of the alleged fraud, the court found that the Relator’s allegations about three alleged false statements were pled with sufficient particularity because they included alleged details like who signed the grants, when, for what amount, and, crucially, certain cybersecurity precautions that were conditions of the grants.

The court indicated that the Relator’s allegations regarding the remaining government grants failed because the Relator did not identify any affirmative false statement beyond the mere fact of receiving funds. As to ADM’s government contracts, the court found the Relator’s allegations as to certain contracts to be insufficiently pled, as they relied on implied rather than express contractual terms regarding adherence to cybersecurity regulations. The court also rejected the Relator’s implicit certification theory for these grants and contracts, explaining that even under that theory, a relator must identify a specific affirmative representation and plead the materiality of any omission about noncompliance.

Falsity, Scienter, and Applicability of the Cybersecurity Regulations

On falsity, the court found that if ADM did make statements about its cybersecurity compliance, the Relator adequately alleged deficiencies “that would render [those] statements false.” On scienter, the court found that the Relator’s allegations, including reference to a 2019 cybersecurity audit and a 2022 report shared with ADM executive leadership, were sufficient to plead scienter as to statements made after those investigations, though not for statements that predated them.

The court declined to address whether certain regulatory requirements apply to ADM, noting that the Relator’s adequately pled allegations that certain regulations applied to ADM’s contracts and grants must be “accepted as true” at the motion to dismiss stage.

Key Takeaways

The Pannek decision offers several practical lessons for companies, including digital health and medical technology companies, that receive federal contracts or grants and face, or are at risk of facing, FCA claims predicated on cybersecurity noncompliance:

  • Materiality is a powerful threshold defense. The court’s decision reinforces that general allegations about the government’s interest in cybersecurity, or the mere fact that cybersecurity compliance is labeled as a condition of payment, is not sufficient to plead materiality under the FCA. Defendants facing cybersecurity-based FCA claims should scrutinize whether the relators have alleged specific facts demonstrating that the government actually relied on defendants’ cybersecurity representations in making funding decisions.
  • Alleged regulatory noncompliance is not necessarily a false statement, particularly at the pleadings stage. The court reaffirmed the principle applied by the U.S. Court of Appeals for the Seventh Circuit in United States ex rel. Berkowitz v. Automation Aids, Inc., 896 F.3d 834 (2018): Merely alleging a company violated federal regulations while receiving government funds does not, by itself, establish a knowing false statement under the FCA. A relator must identify the specific affirmative representation made by the defendant and tie the alleged regulatory violation to that statement.
  • Implied certification theories require specificity. Even under an implied certification theory, a relator “must identify what affirmative statement the company made” to the government and separately plead the materiality of any omitted information about noncompliance. Allegations that a defendant implicitly certified that it complied with all applicable laws will not suffice.
  • Scienter can be established when leadership is aware of compliance deficiencies. The court’s scienter analysis confirms that internal audits and investigation reports identifying compliance deficiencies, particularly those shared within senior leadership, can be sufficient for a relator to plead the requisite knowledge element for FCA purposes.
  • Potential cybersecurity FCA exposure remains a risk. Despite the dismissal, the court found that the Relator plausibly alleged the applicability of key cybersecurity regulations to ADM’s contracts and grants and allowed the case to proceed to repleading. As the government continues to prioritize cybersecurity compliance, companies should be aware of the possibility of FCA exposure when compliance with cybersecurity requirements may be material to the government’s payment decision and ensure that their cybersecurity programs, contract representations, and internal audit processes are well-documented and defensible.

* * *

The Goodwin Healthcare team will continue to monitor FCA enforcement developments and their potential impact on our clients. For more information on the issues discussed in this alert, please contact the authors or reach out to Goodwin’s Government Investigations, Enforcement & White Collar Defense group, the False Claims Act group, the Data, Privacy & Cybersecurity group, or the Goodwin lawyer whom you typically consult.

Explore more coverage of emerging topics of interest to the healthcare industry on our Health Headlines page.

This informational piece, which may be considered advertising under the ethical rules of certain jurisdictions, is provided on the understanding that it does not constitute the rendering of legal advice or other professional advice by Goodwin or its lawyers. Prior results do not guarantee similar outcomes.