Keffer’s Coverage Claim Rejected by Federal Judge

Keffer Development Services, a Grove City, Pennsylvania, software firm that provides electronic medical record tools under the name Athletic Trainer Software, faced dozens of lawsuits consolidated in Michigan after former University of Michigan football coach Matthew Weiss used his access to the platform to view student-athletes’ private photos and videos. The student-athletes alleged Keffer failed to secure its system. Weiss was indicted in 2025 on charges of hacking into more than 100 colleges, downloading personal data on over 150,000 athletes and using that data to break into social media, email and cloud accounts to obtain intimate images. His criminal and civil cases remain pending.

Keffer turned to its general liability insurer, Hartford Casualty Insurance Company, arguing the policy required it to defend and indemnify the company. Keffer claimed the underlying lawsuits alleged “bodily injury” because the victims suffered emotional distress, humiliation and physical manifestations of stress. It also argued that Weiss’s intrusion into its servers constituted a “personal and advertising injury” under the policy.

U.S. District Judge William S. Stickman IV of the Western District of Pennsylvania rejected both arguments. On the bodily injury theory, he found that allegations of emotional distress fall short of Pennsylvania’s definition, which demands actual physical harm. The judge noted the complaints are “devoid of facts that show any physical impact” and that Weiss’s conduct was directed at the software, not students’ bodies. The policy’s mental anguish coverage applied only if it arose from a physical cause, which was not present. On the personal-and-advertising-injury claim, the judge concluded that even if Weiss’s hacking could be considered an entry onto Keffer’s “premises,” Keffer failed to show Weiss acted on behalf of the property’s owner, landlord or lessor—a policy requirement. He further agreed with Hartford that an information-disclosure exclusion independently barred coverage.

Why General Liability Policies Fail to Cover Cyber Incidents Like This

The Bodily Injury Standard: No Physical Harm, No Coverage

The ruling underscores a critical limitation of many general liability policies: absent physical impact, emotional distress claims—even those accompanied by “physical manifestations of stress and anxiety”—do not meet the bodily injury definition under Pennsylvania law. Keffer’s policy did include mental anguish coverage, but only when arising from an actual physical cause. Because the breach was a digital intrusion with no contact between Weiss and the students, coverage was denied. Policyholders in states with similar physical-harm requirements should take note that ransomware-related sleeplessness or anxiety will not automatically trigger GL bodily injury coverage.

Advertisement

Why the ‘Personal and Advertising Injury’ Theory Failed

Keffer’s fallback was that Weiss’s computer intrusion amounted to a personal and advertising injury through an “entry into” its premises. Judge Stickman found that theory tenable—but Keffer couldn’t satisfy the policy’s further condition: the intruder must act on behalf of the property’s owner, landlord, or lessor. Because Weiss had no such connection, the entry was not covered. This reinforces that standard GL wording is not designed for cyber intrusions; a perpetrator’s unauthorized entry is not the same as an eviction, invasion or other traditional covered offense.

The Information-Disclosure Exclusion: A Separate Bar

Even if the other arguments had prevailed, Hartford pointed to a specific exclusion for claims arising from the disclosure of information. Judge Stickman agreed it independently barred coverage. Such exclusions are common in GL forms and increasingly cited in data-breach disputes. The decision signals that courts will enforce them when the underlying claim is fundamentally about the mishandling or exposure of private data—exactly what the Weiss lawsuits alleged.

Together, the three holdings draw a bright line: a standard GL policy, without bespoke cyber endorsements, is unlikely to respond to data breach suits that hinge on emotional distress or information disclosure. For companies that handle sensitive personal data, the case is a vivid illustration of the coverage gap.

What Companies Can Learn From Keffer’s Denied Claim

For risk managers and insurance buyers evaluating their cyber exposure:

  • Review your GL policy’s bodily injury definition—particularly if business operates in a state like Pennsylvania that requires actual physical harm. As the Keffer case shows, emotional distress claims from a privacy breach alone may not trigger coverage.
  • Check for information-disclosure exclusions. If your policy contains one, it likely forecloses coverage for lawsuits alleging failure to protect private data, even if other coverage arguments exist.
  • Do not rely on ambiguous personal-and-advertising injury coverage for cyber intrusions. The ruling highlights the difficulty of satisfying the “owner, landlord or lessor” condition for hacker entries. A standalone cyber insurance policy or a well-drafted GL endorsement is necessary to fill this gap.

Risk & Opportunity Assessment

Commercial RiskHighKeffer faces uncovered defense costs and potential settlements from multidistrict litigation, demonstrating that companies without dedicated cyber insurance can suffer severe financial fallout when GL policies do not respond.
Competitive RiskLowThe case does not directly alter the competitive position of Keffer or its rivals; the impact is on insurance coverage rather than market share.
Regulatory RiskLowNo regulatory penalty or enforcement action is at issue in the ruling; the litigation is civil, not driven by a regulatory data breach investigation.
Reputation RiskMediumThe underlying data breach involving student-athletes’ intimate images has already caused reputational damage to Keffer. The coverage denial adds financial pressure but does not create new reputational exposure beyond the incident itself.
Technology DisruptionLowThe story centers on insurance contract interpretation, not a technological innovation or disruption; the software platform’s vulnerability is a factual backdrop, not a technology-sector shift.
Commercial OpportunityLowFor insurers, the ruling simply confirms existing policy exclusions and does not create a new revenue opportunity. For policyholders, the opportunity lies in recognizing the need for proper cyber coverage, but that is a risk-management insight rather than a direct commercial gain.