Star Health Data Breach Case: Refuses To Quash Criminal Proceedings Against Himanshu Pathak
The on Monday declined to interfere with the criminal proceedings initiated against cybersecurity researcher Himanshu Pathak for allegedly accessing and downloading sensitive customer data from without authorisation. A bench of Chief Justice Surya Kant, Justice Joymalya Bagchi, and Justice V. Mohana dismissed Pathak’s challenging a order that refused to quash the case. However, the Court made permanent the granted on , allowing Pathak to raise all his defences before the trial court.
The decision underscores the fine line between legitimate and potential criminal overreach, particularly when personal data is involved. The observed that the factual disputes—including Pathak’s intent, the extent of data downloaded, and the nature of his communications with Star Health—could not be resolved at the stage under .
Background of the Dispute
Star Health’s complaint alleges that Pathak unlawfully accessed and downloaded approximately 8,000 files containing customers’ personal, health, and financial information. The insurer further claims that Pathak subsequently sought to pressure the company by referring to the possible publication of the data while offering cybersecurity services. Pathak, on the other hand, maintains that he discovered critical vulnerabilities in Star Health’s systems, reported them to the company and the cybersecurity platform ‘’, and sought corrective action without any intention to misuse the information.
The case gained attention as it raises questions about the legal boundaries of and . Pathak’s defence points to a separate FIR filed by , which was later closed by the police after investigators found that Pathak had informed the company about security vulnerabilities and leakage of sensitive data. That closure report, according to Pathak’s counsel, supports his claim of research.
Arguments Before the Apex Court
Pathak’s Defence: A in Cybersecurity
, appearing for Pathak, argued that his client had acted as a “” by identifying vulnerabilities and reporting them. He emphasised that Pathak had previously reported security flaws to organisations such as , , and , all of which acknowledged the reports and took corrective action. Bhushan submitted that the downloaded material was used solely to demonstrate the extent of the vulnerability to Star Health and was never published or supplied to unauthorised parties.
“The entire exercise was most . There was no intention, in fact, the proposal for business. Otherwise, we wouldn't have reported it to and to the company itself,” Bhushan argued. He also highlighted that the Policybazaar case was closed after investigation, indicating a pattern of .
Star Health’s Position: Beyond a Routine Disclosure
, representing Star Health, countered by drawing the Court’s attention to the communications between Pathak and the insurer. One email, cited by Muralidhar, referred to plans to publish articles about the security issues through national and international publications after the vulnerabilities were fixed. Star Health characterised this as an implied threat, not a standard disclosure process.
Muralidhar also pointed to subsequent emails in which Pathak allegedly proposed charging $65,000 for an and $3,000 per month for maintenance. He argued that the combination of downloading thousands of customer files, referencing publication, and demanding payment supported the prosecution’s case and could not be dismissed at the threshold. “This is not an ordinary person you're dealing with,” he submitted.
Court’s Key Observations
The bench focused on the alleged downloading of 8,000 files and questioned whether such a volume was necessary to demonstrate a security weakness. The judges drew a clear distinction between notifying a company that its system is vulnerable and actually removing sensitive information from its database.
“The moment sensitive personal information is removed from a company's database, the privacy interests of the individuals whose information is contained in that data are implicated,” the Court observed. This statement reflects a growing judicial concern over data privacy, especially after the landmark Puttaswamy judgment recognising the right to privacy as a fundamental right under .
The Court also questioned whether a cybersecurity researcher could independently access and download data merely because the objective was to demonstrate a vulnerability. It noted that even if a person believes another entity is acting improperly, that does not authorise the person to obtain private information and use its possession as leverage.
Ultimately, the bench held that the competing accounts—Pathak’s claim of research versus Star Health’s allegations of and —involved factual questions that must be assessed during trial. “In the facts and circumstances of the case, we are not inclined to entertain these . The same stand dismissed with liberty to the petitioner to raise all the contentions before the Trial Court at an appropriate stage,” the order stated.
Legal Analysis: Limits of
The ’s refusal to quash the proceedings reaffirms the limited scope of . The to prevent is not meant to adjudicate disputed facts. As the bench indicated, issues such as whether Pathak’s conduct was , whether downloading data was necessary, and whether his communications amounted to require evidence and cross-examination.
This approach is consistent with the principle laid down in State of Haryana v. Bhajan Lal (), where the held that FIRs can be quashed only in exceptional circumstances where the allegations do not disclose any offence. Here, the allegations—unauthorised access, downloading, and pressure through publication threats— disclose offences under the , and possibly the .
The case also highlights the tension between cybersecurity research and data protection. While is encouraged, the law does not grant a blanket immunity to researchers who access and remove personal data without authorisation. The upcoming , may provide clearer guidelines, but currently, the legal framework remains case-specific.
Impact on Legal Practice and Cybersecurity
For legal practitioners, this judgment serves as a reminder of the importance of factual pleadings at the investigation stage. Defence lawyers must be prepared to demonstrate not just the absence of criminal intent but also the proportionality of the researcher’s actions. The closure of the Policybazaar case may be a persuasive precedent, but each case turns on its own facts.
Cybersecurity professionals and companies should take note of the Court’s emphasis on privacy. Even well-intentioned research can attract criminal liability if personal data is removed from a system without authorisation. The safest practice is to report vulnerabilities without downloading data, or to do so only under a formal with clear terms.
The has left the door open for Pathak to prove his bona fides before the trial court. His defence will likely rely on the Policybazaar closure report and acknowledgements from other organisations. However, Star Health’s metadata records may provide forensic evidence of the extent of access, which could strengthen its case.
Conclusion
The ’s refusal to quash the criminal proceedings against Himanshu Pathak does not prejudge his guilt or innocence. It simply recognises that the dispute requires a full trial. The case will now proceed before the , where the court will examine the evidence, including the emails, metadata, and the parties’ conduct.
For the legal community, this case underscores the evolving intersection of cybersecurity, data privacy, and criminal law. As digital vulnerabilities become more common, courts will increasingly be called upon to balance the interests of security researchers, companies, and individuals whose data is at stake. Until a clear statutory framework emerges, each case will likely set its own precedent.