Key developments
Supreme Court extends privacy to geofence data
NBC Bay Area reported that the U.S. Supreme Court ruled Monday that constitutional privacy protections apply to cellphone location information, in a 6-3 decision written by Justice Elena Kagan. The case arose from a 2019 Virginia bank robbery investigation where police used a Google geofence warrant to identify Okello Chatrie, then obtained a home search warrant and found nearly $100,000 in cash. The Court remanded the case without deciding whether the specific geofence warrant satisfied the Fourth Amendment.
Why it matters
The ruling limits law enforcement reliance on broad location-data sweeps and narrows the third-party doctrine for smartphone-derived data.
Sources & driving stories
NBC BAY AREA
NBC Bay Area coverageSLATE · Cullen Seltzer
Slate coverageAmazon fined over identity-theft record denials
BleepingComputer's Sergiu Gatlan reported that the FTC said Amazon will pay a $2.25 million civil penalty to settle allegations it blocked identity theft victims from accessing fraudulent transaction records. The FTC alleged Amazon customer service agents denied requests on privacy or security grounds, missed the Fair Credit Reporting Act's 30-day deadline, and refused some law-enforcement requests made on victims' behalf. The proposed order requires timely record access and notice to consumers who requested records since April 2024 but did not receive them.
Why it matters
The case highlights privacy being used as a rationale to deny fraud victims access to data they are legally entitled to obtain.
Sources & driving stories
BLEEPINGCOMPUTER · Sergiu Gatlan
BleepingComputer coverageMedtronic notifies patients after April breach
Healthtech Security reported that Medtronic is notifying patients after unauthorized access to corporate IT systems from April 13 to April 19, 2026. The incident has not yet appeared on the HHS Office for Civil Rights breach portal, but state portals list more than 297,000 affected people in Texas, 63,500 in Massachusetts, and 8,700 in Vermont. Medtronic said it has no evidence affected information was publicly posted and found no impact to product security, patient safety, manufacturing, or distribution; it is offering 24 months of credit monitoring, identity theft restoration, and dark web monitoring.
Why it matters
The breach involves large-scale health-related personal data exposure at a major medical technology company, with state reporting already showing hundreds of thousands affected.
Sources & driving stories
HEALTHTECH SECURITY
Healthtech Security coverageWorth noting
WORTH NOTING
Apple email aliases may expose users
Android Authority's Taylor Kerns reported that 404 Media found an Apple Hide My Email vulnerability that EasyOptOuts said could reveal a user's real email address within minutes, despite Apple having been notified more than a year earlier.
WORTH NOTING
Huntsville breach litigation begins
AL.com's Savannah Tryens-Fernandes reported a proposed class action alleging Huntsville Hospital patients' names, dates of birth, medical records, and financial information were compromised through Cerner systems, with detection in January 2025 but patient notification beginning in June 2026.
WORTH NOTING
Iowa porn age checks start
The Des Moines Register's William Morris reported that Iowa's House File 846 took effect July 1, requiring age verification for websites with at least one-third pornographic content and raising privacy concerns around ID, financial-document, or third-party verification.
Still unclear
OPEN QUESTION
How specific must geofence warrants become?
The Supreme Court recognized privacy interests in location history but left lower courts to decide how probable cause and particularity apply to specific geofence demands.
OPEN QUESTION
Can age verification avoid new privacy risks?
Iowa and other states are pushing online age checks that may require sensitive identity data, making retention limits, vendor practices, and enforcement rules central to privacy outcomes.
