Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Thursday, June 25, 2026 · 11:48 AM EDT

Key developments

HEALTHCARE IT NEWS

Healthcare patient-data breach reports widen

Healthcare IT News' Andrea Fox reported that One Medical Seniors, formerly Iora Health, said an unauthorized party accessed third-party file-storage systems from June 8 to June 11; the incident was discovered June 13 and involved archived demographic and clinical records on legacy systems, while clinics, services and the EMR were not affected. Potentially affected Iora patients were in Atlanta, Denver, Houston, Phoenix, Tucson, Seattle, Massachusetts and North Carolina; Fox also noted an unverified ShinyHunters extortion claim. Separately, Morningstar reported Schubert Jonckheer & Kolbe's investigation of Xsolis after a Jan. 20-22 phishing intrusion potentially exposed or copied data for about 1.4 million people, including names, birth dates, Social Security numbers, insurance data and treatment information.

Why it matters

The reports underscore how healthcare privacy exposure is increasingly concentrated in legacy archives, third-party storage and vendor systems outside core clinical platforms.

Sources & driving stories

HEALTHCARE IT NEWS · Andrea Fox

Healthcare IT News coverage
REUTERS

Sixth Circuit blocks Michigan voter-roll demand

Reuters reported that a 2-1 Sixth U.S. Circuit Court of Appeals panel upheld an order preventing the Justice Department from obtaining Michigan's unredacted qualified voter file. Judge Andre Mathis, joined by Judge R. Guy Cole, said DOJ letters to Secretary of State Jocelyn Benson did not state the legally required basis and purpose; Judge John B. Nalbandian dissented. Reuters noted DOJ has sought voter lists containing sensitive identifiers from nearly all states, at least 17 Republican-led states voluntarily shared data, and DOJ has sued 30 states plus the District of Columbia.

Why it matters

The ruling constrains a federal push to aggregate sensitive voter identifiers and may shape parallel voter-roll privacy fights across states.

Sources & driving stories

LEXOLOGY

Vermont enacts health and genetic privacy laws

Lexology contributors Libbie Canter, Elizabeth Brim and Clare Mathias reported that Vermont recently enacted H.639 and S.71 to regulate health-related information. H.639 covers direct-to-consumer genetic testing companies and service providers, requiring consent for non-primary uses, easier revocation, deletion and sample-destruction workflows, and warrant/probable-cause or express-consent limits for government disclosures; it takes effect July 1, 2026. S.71 expands consumer health data protections, covers reproductive, gender-affirming and sexual health data, treats biometric and neural data as sensitive, restricts certain geofencing near healthcare facilities, requires consent before selling consumer health data, and takes effect Jan. 1, 2028 with Vermont Attorney General-only enforcement.

Why it matters

The package adds another state-level privacy framework for health, genetic, biometric and neural data outside traditional HIPAA coverage.

Sources & driving stories

LEXOLOGY · Libbie Canter, Elizabeth Brim, Clare Mathias

Lexology coverage

Worth noting

WORTH NOTING

Tata confirms 630GB data leak

Mbtmag reported Tata Electronics confirmed a breach after World Leaks posted more than 630GB and 204,000 files, including employee information and potentially Apple- and Tesla-linked manufacturing or product specifications.

WORTH NOTING

Deflock maps Flock ALPR cameras

BGR reported that a new open-source tool maps Flock automated license plate reader locations and can help users plan routes around them, against a backdrop of Flock estimates of 20 billion plate reads per month across 49 states.

WORTH NOTING

Resolution targets medication wastewater surveillance

Rep. Brittany Pettersen introduced a June 24 resolution to prohibit government monitoring of groundwater, surface water, wastewater or drinking water for reproductive-health medications, citing reports on EPA discussions and Texas wastewater-testing legislation.

Still unclear

OPEN QUESTION

Will voter-data demands survive elsewhere?

The Sixth Circuit ruling turned partly on statutory demand defects, while DOJ has broader suits pending against states and could test revised requests or different legal theories.

OPEN QUESTION

Who owns inherited health-data risk?

The One Medical incident involved third-party legacy file storage, while Xsolis involved vendor-held patient data, putting pressure on M&A diligence, vendor oversight and archive governance.