Key developments
ICE Medicaid data reached Palantir app
New court filings reported by WLRN’s Jude Joffe-Block say ICE shared improperly obtained Medicaid data with Palantir, whose ELITE app displays addresses of noncitizens who may be subject to deportation. The January 7 dataset included data on millions of people beyond what a federal court had allowed, and Justice Department filings said a later search found copies still held by about six ICE users after deletion efforts. The disclosure came as DOJ asked U.S. District Judge Vince Chhabria to expand permitted Medicaid data sharing, while more than 20 Democratic attorneys general argued repeated violations undermine assurances that healthcare data remains private.
Why it matters
The filings connect health-benefits data, immigration enforcement, and a major surveillance contractor despite prior court limits and deletion orders.
Sources & driving stories
WLRN · Jude Joffe-Block
WLRN coverage23andMe reaches $18 million breach settlement
A coalition of 42 U.S. attorneys general reached an $18 million settlement with 23andMe over the 2023 credential-stuffing breach that exposed genetic and profile data tied to more than six million people. Reporting by Infosecurity Magazine and Tech Times says the settlement requires new security governance, continuing risk assessments, privacy-law compliance, and continued options for consumers to delete genetic samples and personal data. The breach began with roughly 14,000 compromised accounts, then expanded through the DNA Relatives feature to expose ancestry, ethnicity, health predisposition, family-tree, location, and profile data.
Why it matters
Genetic data cannot be reset like passwords or payment cards, making security mandates and post-bankruptcy data controls especially consequential.
Sources & driving stories
INFOSECURITY MAGAZINE
Infosecurity Magazine coverageTECH TIMES
Tech Times coverageLawmakers advance warrant limits for surveillance data
The New American’s Michael Tennant reports that Rep. Keith Self introduced the PRIVACY Act, cosponsored by Reps. Eli Crane and Andrew Clyde, to require a warrant before federal law enforcement accesses data from state and local mass-surveillance systems. Covered technologies include automated license-plate readers, Flock-style surveillance cameras, long-range microphones, and related location-tracking tools, with proposed 30-day retention limits and restrictions on federal funding. Separately, Cowboy State Daily’s Clair McFarland reports Wyoming lawmakers are preparing Sept. 28-29 hearings on bills that would treat personal data as property and limit law-enforcement access to biometric or geolocation data.
Why it matters
The proposals show privacy legislation moving from broad consumer data rights toward specific limits on police access to networked cameras, biometrics, and location data.
Sources & driving stories
THE NEW AMERICAN · Michael Tennant
The New American coverageCOWBOY STATE DAILY · Clair McFarland
Cowboy State Daily coverageWorth noting
WORTH NOTING
Healthcare records draw ransomware markets
DigitalShield reports TrendAI found ransomware accounts for 36.3% of detected underground-market activity tied to healthcare, with growing targeting of electronic health-record and digital medical-record platform providers.
WORTH NOTING
Ecopetrol reports account-data theft
Yahoo Finance reports Colombia’s Ecopetrol said a cyberattack stole data tied to about 3,300 user accounts across cloud-based file storage at 15 subsidiaries, while the attacker made extortion demands.
WORTH NOTING
Fidelity settlement claims deadline nears
Yahoo Finance reports Fidelity customers have until July 27, 2026, to claim from a $2.5 million breach settlement covering potential exposure of names, Social Security numbers, financial account information, and driver’s license information.
Still unclear
OPEN QUESTION
Can ICE prove every Medicaid copy is deleted?
DOJ filings cite technical difficulty locating every variation of the improperly shared dataset, even as the government seeks broader access to Medicaid data for immigration enforcement.
OPEN QUESTION
Will genetic breach settlements change security baselines?
The 23andMe case pairs long-lived genetic exposure with bankruptcy-limited compensation, making enforceable governance and deletion rights a key test for direct-to-consumer genetics firms.
