Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Wednesday, June 17, 2026 · 11:48 AM EDT

Key developments

EURASIAN TIMES

Section 702 lapses after failed renewal

FISA Section 702 expired on June 12 for the first time after Congress failed to agree on renewal, EurAsian Times reported. The authority permits warrantless collection of foreign communications and can compel U.S. providers including Google, Microsoft, Apple, Meta, Amazon, AT&T and Verizon to assist; critics say Americans’ communications are swept in through incidental collection and FBI “backdoor” searches. Existing annual court authorization may allow collection to continue for now, but the House is not scheduled to return until June 23, leaving compliance and legal challenges unresolved.

Why it matters

A core U.S. foreign-intelligence surveillance program that affects Americans’ communications is now operating in legal limbo.

Sources & driving stories

EURASIAN TIMES · Sumit Ahlawat

EurAsian Times coverage
PATIENT PROTECT

iRhythm discloses patient data theft

iRhythm Holdings disclosed that unauthorized actors accessed third-party-hosted business applications and stole patient personal and health information, Patient Protect reported. BeyondMachines reported the incident was detected June 8 after social engineering, followed by a June 9 ransom demand and June 10 breach confirmation; clinical systems and medical devices were isolated from the compromised business environment. iRhythm notified affected individuals, retained external cybersecurity experts and reported the incident under applicable regulatory requirements, but did not disclose the number of affected people.

Why it matters

The incident highlights PHI exposure through vendor-hosted business systems rather than core clinical infrastructure.

Sources & driving stories

CLASS ACTION U

Columbus Regional settles tracking-pixel lawsuits

Columbus Regional Health agreed to a class action settlement over allegations that tracking tools on its websites and patient platforms transmitted private patient interactions to third-party technology companies, Class Action U reported. The litigation cited Meta Pixel and tools linked to Google, Microsoft, Adobe, DoubleClick and Marchex, and alleged collection of IP addresses, device types, search terms, button clicks and medical-service page views. The settlement covers about 20,763 eligible Indiana class members, offering $25.50 cash payments and one year of CyEx Privacy Shield Pro; final approval is scheduled for July 22, 2026, with claims due September 19.

Why it matters

Healthcare tracking-pixel litigation is continuing to produce concrete settlements, consumer payments and remediation obligations.

Sources & driving stories

Worth noting

WORTH NOTING

Canada privacy bill toughens enforcement

MLex’s Mike Swift reported that Bill C-26 would create a Digital Safety and Data Protection Commission, authorize fines up to C$25 million or 5% of global revenue, add AI and children’s data rules, and create a private right of action.

WORTH NOTING

Federal privacy preemption bill aired

Finnegan’s Lynn Parker Dupree analyzed the SECURE Data Act after a June 2026 hearing, noting its broad state-law preemption, consumer access/correction/deletion/portability rights, opt-outs for targeted advertising and sale, and lack of a consumer private right of action.

WORTH NOTING

Shadow AI visibility gap widens

Teramind’s new report, summarized by Eagle Tribune, says 69% of C-suite leaders prioritize AI speed over security, 67% of enterprise AI use occurs through unmanaged personal accounts on corporate devices, and 86% of organizations lack visibility into AI data flows.

Still unclear

OPEN QUESTION

Will Section 702’s lapse trigger provider challenges?

Existing FISA court authorization may keep collection going, but the statutory lapse creates uncertainty for compelled companies and could invite litigation before Congress returns.

OPEN QUESTION

Is privacy-law divergence accelerating?

Canada’s proposed stronger enforcement model and the U.S. SECURE Data Act’s preemption-focused framework point in different directions on penalties, private lawsuits and state-level authority.