California Turns Data Deletion Into an Enforcement Test
Privacy rights are increasingly being tested not by the language of the law, but by whether institutions can carry them out. Yesterday’s clearest example came from California, where Bloomberg Law found that data brokers denied or ignored more than one million deletion requests over two years just as unresolved valid requests are becoming subject to daily fines.
Health data revealed the same divide from another direction. Lawmakers and regulators pursued tighter limits on commercial use, while federal agencies sought broader access to identifiable medical records and another cloud breach exposed clinical, identity, and financial information. Protections and access are expanding at the same time.
Bloomberg Law’s review of company disclosures found more than one million deletion requests had been denied or ignored by California data brokers. Beginning today, valid requests left unresolved beyond 45 days can bring fines of $200 per day. That converts deletion from a largely procedural consumer right into a potentially accumulating financial liability.
Health-data regulation advanced on two fronts, although neither has reached a final outcome. The FTC, California, and Utah sued Hims & Hers over allegations that sensitive health information was shared with advertising platforms through customer lists and tracking technologies; the company disputes the claims. Separately, the Senate HELP Committee advanced S. 3097, which would restrict consumer health-data collection, sharing, and government purchases while creating access and deletion rights. CDT noted that responsibility among HHS, the FTC, and state regulators remains unresolved.
KFF Health News documented movement in the opposite direction: federal agencies are seeking or receiving identifiable medical records for administrative purposes. The CPSC pressed hospitals to send emergency-room records to contractor Konza Health, OPM sought records involving more than eight million federal workers, retirees, and relatives, and HHS leadership accessed some state health-information exchanges. Hospitals, unions, and insurers questioned the authority, HIPAA implications, and lack of public notice.
UK parliamentary scrutiny of the Ministry of Defence’s Afghan applicant breach sharpened the distinction between a security incident and institutional failure. Reporting on the Defence Committee’s findings described weak spreadsheet controls, repeated prior incidents, secrecy that delayed scrutiny, and exposure involving more than 18,500 applicants. The committee’s demand for named owners and deadlines matters because the consequences extended beyond notification to relocation decisions, physical risk, and substantial public cost.
CareCloud notified at least 350,000 people after attackers accessed an AWS environment supporting electronic health records in March. The affected information may include Social Security numbers, financial and payment details, medical records, and insurance data. This did not establish a new breach pattern, but it reinforced how health systems concentrate several forms of durable harm in one environment.
Key Points
- The practical bottleneck in consumer privacy is increasingly identity resolution. Data brokers say requests may not match their records or cannot be verified; privacy vendors allege obstruction and inadequate auditing. California’s fines will test whether companies can distinguish legitimate verification problems from processes that make deletion functionally unavailable.
- The health-data debate is broadening beyond the familiar question of what HIPAA covers. Advertising integrations, consumer apps, government requests, personnel systems, state exchanges, contractors, and cloud-hosted medical records now create separate routes to the same sensitive information. A prohibition on government purchases would address only one of those routes.
- Infrastructure operators are responding to software supply-chain risk by restricting distribution itself. Arch Linux temporarily disabled adoption of AUR packages after an alleged malware campaign targeting credentials, wallets, password managers, cloud secrets, AI service keys, and SSH keys; the full scope remained unconfirmed. Adform removed malicious code from a widely deployed tracking script that could manipulate cryptocurrency addresses and transmit IP addresses and browsing details. Both incidents show that embedded code can become a privacy access point far beyond the organization that originally supplied it.
Implications
Consumer health businesses should treat advertising pixels, analytics tools, uploaded customer lists, and subscription systems as part of the regulated health-data environment. The Hims & Hers allegations remain unproven, but the complaint shows that privacy representations will be examined against actual technical data flows.
Hospitals and public agencies handling government requests need a documented legal basis, field-level data minimization, contractor restrictions, access logging, retention limits, and public-notice analysis. The current disputes show that an asserted administrative purpose does not settle whether identifiable records may be collected.
California data brokers now face a direct reason to improve request matching, verification, escalation, and evidence of deletion. Compliance will depend less on publishing an opt-out page than on demonstrating what happened to each valid request within the required period.
Privacy reviews of websites and software environments should include third-party JavaScript, package-maintainer accounts, orphaned package adoption, signing controls, and emergency disablement procedures. The Adform and Arch incidents show how upstream compromise can expose data or credentials without breaching each downstream user separately.
Watchpoints
Watch
California’s first enforcement actions under the new deletion-fine regime, including how regulators define a valid request and assess disputed identity matches.
Watch
The next steps for S. 3097 and whether its final text clarifies HHS and FTC authority, state enforcement, and private remedies.
Watch
Court filings in the Hims & Hers case that clarify the alleged data flows, privacy representations, and legal theories governing health-related advertising technology.
Watch
Whether the CPSC, OPM, or HHS publishes clearer authority, notice, minimization, retention, and contractor safeguards for identifiable medical records.
Watch
Additional CareCloud filings or litigation that establish the full affected population, intrusion path, data taken, and responsibility for controls in the AWS environment.
Fallout
The most meaningful movement came in four areas: California’s effort to make deletion rights enforceable at scale, competing pressures around access to health data, renewed accountability for a consequential government breach, and concrete containment of privacy-relevant software supply-chain attacks.
Health Data Collection, Access, and Exposure
Health information now travels through far more than hospitals and insurers. Consumer services, advertising systems, government agencies, contractors, personnel programs, state exchanges, and cloud infrastructure all create distinct access and compliance questions.
Fresh developments
The Senate’s health privacy bill advanced through committee while regulators pursued Hims & Hers over alleged advertising-related disclosures. At the same time, KFF Health News reported that federal agencies were seeking broad access to identifiable medical records, and CareCloud disclosed a breach affecting at least 350,000 people. Together, these developments complicated any simple account of health privacy improving or deteriorating: legal protections are being strengthened in some channels while collection and exposure continue through others.
Why we noticed
Organizations cannot manage this risk by asking only whether information is covered by HIPAA. They also need to know where health-related inferences and identifiers move, which vendors receive them, what government access is permitted, how deletion works, and whether cloud security and breach response cover the combined clinical, identity, and financial dataset.
Watch for:
- Whether S. 3097 advances beyond committee with a workable enforcement structure.
- Greater disclosure of the legal basis and safeguards for federal medical-record requests.
- Technical evidence and court rulings concerning health-data use by advertising platforms.
Consumer Deletion Rights
The right to delete personal information is becoming a test of operational capacity. Its value depends on whether businesses can locate a person across inconsistent records, verify requests without creating unreasonable barriers, and complete deletion across internal systems and vendors.
Fresh developments
Bloomberg Law found that California data brokers denied or ignored more than one million deletion requests over the preceding two years. The timing is important: beginning August 1, valid requests unresolved after 45 days can generate $200 in daily fines. Broker explanations centered on unverifiable requests and mismatched records, placing identity matching at the center of the coming enforcement test.
Why we noticed
A right that fails when records are messy is weakest where data brokerage is most opaque. The new penalty structure gives regulators a way to examine not only written policies, but request logs, matching standards, denial reasons, vendor performance, and evidence that deletion actually propagated through connected systems.
Watch for:
- The first fines or public compliance actions under California’s deletion platform.
- Regulatory guidance on verification and mismatched records.
- Whether denial rates fall as financial exposure begins to accumulate.
Government Data Stewardship
Government breaches can create harms that ordinary notification and credit monitoring cannot address, particularly when records identify people facing political violence, immigration risk, or retaliation.
Fresh developments
Reporting on the UK Defence Committee’s findings portrayed the Afghan applicant breach as a systemic governance failure rather than an isolated spreadsheet mistake. Weak controls and repeated incidents were compounded by a superinjunction that delayed parliamentary and audit scrutiny for nearly two years. The committee responded by demanding identifiable responsibility and deadlines for correction.
Why we noticed
The episode shows that secrecy can protect affected people in the short term while also delaying institutional accountability. When leaked data can expose individuals to physical danger, the quality and speed of the government’s response become part of the privacy harm itself.
Watch for:
- Named officials, deadlines, and measurable corrective actions from the Ministry of Defence.
- Further parliamentary or ICO scrutiny of the breach and delayed disclosure.
- How the government addresses continuing protection and relocation needs.
Software Supply-Chain Privacy
Software dependencies can give upstream code access to downstream credentials, browsing activity, financial assets, and cloud systems. The privacy consequence is therefore determined not only by what an application intentionally collects, but by every package and script it trusts.
Fresh developments
Arch Linux halted AUR package adoption after an alleged campaign involving compromised maintainer accounts and package takeovers, while Adform removed malicious code from a JavaScript tracking library deployed on customer websites. The Arch campaign reportedly targeted a broad range of secrets; the Adform code could alter cryptocurrency addresses and transmit browsing details. The full Arch scope remained uncertain, but both operators took direct containment action.
Why we noticed
These incidents connect software security with privacy governance. Package adoption rules, maintainer identity, third-party script inventories, code integrity, and emergency shutdown mechanisms determine whether a single upstream compromise can silently reach many users.
Watch for:
- Confirmation of the Arch campaign’s affected packages and users.
- Further disclosure from Adform and affected websites.
- Stronger maintainer, signing, and third-party script controls.
Final Thought
The most consequential privacy disputes are no longer only about whether data is sensitive. They are about who can reach it, through which technical or legal channel, and whether the rights meant to constrain that access can survive contact with real systems.
