Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Duke University Health System; Derick Dermatology Settle Class Action Pixel Lawsuits
Duke University Health System and Derick Dermatology have settled separate class action lawsuits alleging unauthorized use of website tracking pixels that transmitted patients' personal health information to third parties like Meta. Duke agreed to a $3.7 million settlement fund while Derick Dermatology agreed to pay up to $1 million, with both organizations denying any wrongdoing despite agreeing
AIMeta to Use Off-Site Business Data for Feed and AI Personalization
Meta announced it will expand the use of off-site business data beyond targeted advertising to personalize user feeds and AI chatbot responses. This represents a significant shift in how Meta leverages third-party business data shared through tracking pixels and integrations. The move raises questions about data privacy and the expanding role of user behavioral data in AI-driven personalization.
AIFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
Security research has revealed that Bright Data, a major web-scraping proxy provider targeting the AI industry, embeds SDKs in free consumer apps that convert users' devices—including always-on smart TVs—into proxy exit nodes without clear disclosure. The company, formerly known as Luminati, operates what it claims is the world's largest residential proxy network by leveraging these consumer devic
HIPAA Security Rule Training Requirements
HIPAA Security Rule training requirements mandate that covered entities and business associates provide comprehensive security awareness training to all workforce members, not just those with direct patient record access. The training must cover electronic Protected Health Information (ePHI) protection, security policies, threat recognition, incident reporting, and the distinctions between HIPAA v
