Michigan Supreme Court Ruling Exposes More Businesses to Consumer Protection Claims
Originally Published: Aug. 13, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
A Livonia medical device distributor spent years building its marketing around a simple promise: encrypted systems, HIPAA-compliant handling, and secure data storage for every customer record it touched. The claims sat on the homepage, in sales decks, and in contracts. For most of that time, the company assumed its state pharmacy and medical device licenses gave it broad cover under Michigan law if a customer ever complained about how its systems worked. That assumption is no longer safe.
On July 31, 2026, the Michigan Supreme Court ruled in Attorney General v. Eli Lilly and Company that operating in a regulated industry does not automatically shield a business from claims under the Michigan Consumer Protection Act. The decision overturned two precedents that had stood for more than 25 years, and it changes the legal exposure facing manufacturers, health care providers, financial services firms, and any business that makes consumer-facing claims about how it handles data and security.
Executive Summary
The Michigan Supreme Court overturned Smith v. Globe Life Insurance Co. (1999) and Liss v. Lewiston-Richards, Inc. (2007), ruling that the Michigan Consumer Protection Act's regulated-industry exemption applies only when the specific conduct at issue was authorized by a regulator, not simply because a business operates in a licensed field. The 4-3 decision arose from Attorney General Dana Nessel's investigation into Eli Lilly's insulin pricing and now exposes a far broader set of Michigan businesses to consumer protection claims, particularly around pricing, marketing, and representations about data security and privacy. Companies that describe their security posture, compliance status, or data handling practices to customers should review those claims now, before a breach, audit, or complaint puts them in front of the Attorney General or a plaintiff's attorney.
What the Michigan Supreme Court Decided
The case traces back to January 2022, when Attorney General Dana Nessel opened an investigation into Eli Lilly and Company's insulin pricing practices. Nessel's office sought civil investigative subpoenas from the Ingham County Circuit Court, but Eli Lilly argued the investigation was barred entirely.
The company pointed to Section 4(1)(a) of the Michigan Consumer Protection Act, codified at MCL 445.904(1)(a), which exempts a transaction or conduct "specifically authorized" under laws administered by a state or federal regulatory board or officer.
Eli Lilly relied on two prior Michigan Supreme Court rulings to make its case. In Smith v. Globe Life Insurance Co., 460 Mich 446 (1999), and Liss v. Lewiston-Richards, Inc., 478 Mich 203 (2007), the court had read that exemption broadly: if a business's general line of activity was authorized or licensed by a regulator, the entire business was shielded from Michigan Consumer Protection Act claims, regardless of whether the specific practice being challenged had anything to do with that authorization. Because the Food and Drug Administration approved Lilly's insulin as safe and effective, and Lilly held a Michigan pharmacy license, the company argued its pricing decisions were automatically covered.
The Ingham County Circuit Court agreed and dismissed the case. A Court of Appeals panel affirmed, holding it was bound by Smith and Liss. The Attorney General's office then took the unusual step of filing a declaratory judgment action specifically asking the Supreme Court to reconsider those two precedents, and the court agreed to hear the case a second time after initial arguments in October 2024.
In its July 31 ruling, a majority of the court held that Smith and Liss had misread the statute. The correct test, the court found, is whether the specific transaction or conduct being challenged was specifically authorized by a regulator, not whether the business generally operates in a regulated field. FDA approval of a drug's safety and effectiveness says nothing about how that drug is priced. A pharmacy license says nothing about pricing terms either. Under the narrower reading, general licensure no longer functions as a blanket shield.
Free Download
AI Business Tips E-Book
When implemented incorrectly, any technology with access to sensitive data can create security risks. Because AI systems rely on large volumes of proprietary data, companies must prioritize security from the outset when evaluating AI implementation or selecting AI solutions. When used responsibly and securely, AI can streamline operations, help solve critical business challenges, and build client trust. Understanding real examples and their impact can help you make informed decisions about adopting AI.
Why This Reaches Far Beyond Pharmaceutical Pricing
Attorneys who tracked the case, including the litigation team at Varnum LLP, identified a wide range of industries that had relied on the old, broader exemption and now face new exposure. Health care companies, financial services firms handling mortgages, insurance, and banking, automotive dealers and lenders, real estate and homebuilding businesses, retailers and grocers, gaming operators, and any company with consumer-facing pricing, marketing, or advertising practices are all named as sectors likely to see increased scrutiny.
The Michigan Chamber of Commerce estimated more than 80 regulated industries and professions had built compliance programs around the assumption that general licensure provided cover.
That assumption is gone. Businesses can no longer point to a state license or federal approval and expect a Michigan Consumer Protection Act claim to be dismissed at the threshold. Instead, they need to show the specific practice being challenged, not just the general business activity, was authorized by a regulator. General permits and licenses won't satisfy that standard.
This decision upends decades of settled case law, exposing regulated employers and professionals to duplicative oversight, expanded litigation risk and higher costs,” said Michigan Chamber President & CEO Jim Holcomb. “It creates new opportunities for lawsuit abuse while making it more difficult for businesses to operate with the consistency and predictability they need to invest and grow.”
The Attorney General's office is expected to open more investigations now that the primary procedural defense is gone. Private plaintiffs have the same incentive. Because the narrower exemption applies equally to private claims, Michigan businesses should expect an increase in consumer class actions built on the same theory the Attorney General used against Eli Lilly.
Cybersecurity, Compliance Angle Most Businesses Are Missing
Most coverage of this decision has focused on pricing and marketing claims. For businesses that handle sensitive data, the exposure runs just as deep through security and privacy representations. A company that tells customers its systems are encrypted, that it's HIPAA compliant, that it meets the Payment Card Industry Data Security Standard, or that it follows the Federal Trade Commission's Safeguards Rule is making a consumer-facing claim about specific conduct. Under the old Smith and Liss framework, a business in a regulated industry could often argue that general licensure covered those claims too. That argument is now considerably weaker.
If a breach occurs and it turns out the encryption wasn't applied consistently, the vendor handling patient records was never vetted, or the access controls described in a privacy policy weren't in place, that gap between the claim and the practice is exactly the kind of specific conduct the Michigan Supreme Court said the regulated-industry exemption no longer covers. A business can hold every license and certification relevant to its industry and still face a Michigan Consumer Protection Act claim over a security representation that turned out to be inaccurate.
Vendor relationships raise the same issue. A manufacturer that assures customers its supply chain partners meet defense-grade security standards, or a health care provider that tells patients its billing vendor is fully compliant, is making a claim about specific practices, not just about the industry it operates in. Documentation matters more now than it did before July 31. A business that can produce a security policy, a vendor risk assessment, an access log, or an incident response plan showing it did what it said it would do is in a far stronger position than one relying on the fact that it holds a license.
Reviewing Consumer-Facing Security, Privacy Claims
The first step for most businesses is a plain read of every place security, privacy, or compliance claims show up: websites, contracts, sales materials, privacy policies, and breach notification templates. Each claim should be checked against what the business can document. A claim of encryption should match a configuration setting. A claim of compliance with a given framework should match evidence a business could hand an auditor or a regulator without scrambling to produce it after the fact.
Documenting Vendor Oversight
Businesses that make representations about vendors, whether that's a cloud provider, a billing company, or a subcontractor with access to customer data, need contracts and assessments that back up those representations. A verbal assurance from a vendor isn't the same as a documented review, and after this ruling, the difference is more likely to matter in a dispute.
Preparing for Increased Scrutiny
Businesses should assume the Attorney General's office and plaintiffs' attorneys will look more closely at consumer-facing claims going forward. That means document retention policies, incident response plans, and breach notification procedures should be current and ready to produce, not something a business builds after a subpoena arrives.
Frequently Asked Questions
What did the Michigan Supreme Court decide in the Eli Lilly case?
The court ruled that the Michigan Consumer Protection Act's regulated-industry exemption applies only when the specific conduct being challenged was authorized by a regulator, not simply because the business operates in a regulated field. The decision overturned Smith v. Globe Life Insurance Co. (1999) and Liss v. Lewiston-Richards, Inc. (2007).
Does this ruling only affect pharmaceutical companies?
No. Attorneys tracking the case identified health care, financial services, automotive, real estate, retail, and gaming among the sectors most exposed, along with any business that markets or prices products directly to consumers.
How does this decision affect cybersecurity and data privacy claims?
Claims about encryption, compliance certifications, or data handling practices are specific representations about conduct, not general statements about the industry a business operates in. General licensure no longer functions as a blanket defense if those specific claims turn out to be inaccurate.
Can private individuals sue under the narrower exemption, or is this limited to the Attorney General?
The narrower exemption applies to private claims as well as Attorney General enforcement. Businesses should expect an increase in private consumer litigation built on the same legal theory used in the Eli Lilly case.
What should a business do first in response to this ruling?
Start with a review of every consumer-facing claim about security, privacy, and compliance, and confirm each one is backed by documentation the business could produce during an investigation or lawsuit. Vendor contracts and risk assessments should get the same review.
Need Help Reviewing Your Compliance and Security Documentation?
STACK Cybersecurity helps Michigan businesses assess their security posture, document vendor oversight, and prepare for increased regulatory scrutiny. Email info@stackcyber.com or call (734) 744-5300.