Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
Health Information Privacy Reform Act Advanced by HELP Committee
The Health Information Privacy Reform Act, which extends HIPAA-like protections to health data collected by non-regulated entities such as fitness trackers and health apps, has been unanimously advanced by the Senate HELP Committee with a 22-0 vote. The legislation addresses significant privacy gaps by requiring HHS to establish privacy, security, and breach notification standards for consumer hea
ICE Is Buying Access to Credit Card Records
U.S. Immigration and Customs Enforcement (ICE) is purchasing access to consumer credit card application data through third-party data brokers, bypassing traditional warrant requirements. This practice raises significant privacy concerns as personal financial information originally provided for credit purposes is being repurposed for immigration enforcement without explicit consumer consent.
AIPoison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have identified multiple illegal services on underground forums selling unauthorized access to AI models, including 'Poison Claude,' which claims to offer discounted access to Anthropic's language models. These services pose significant security risks as operators can intercept and view all customer prompts, creating potential data exposure and intellectual property theft
Privacy Concerns Raised Over Government Demand for Hospital Emergency Room Data
The U.S. Consumer Product Safety Commission (CPSC) is requesting digital patient data from over 100 hospitals through contractor Konza Health to modernize its National Electronic Injury Surveillance System (NEISS), transitioning from manual to automated data collection. The initiative has raised significant privacy concerns as hospitals report being asked to provide identifiable patient informatio
Some Claude Chats Are Searchable on Google
Private Claude AI chat conversations containing sensitive information, including medical billing data, cryptocurrency wallet keys, and personal addresses, have been indexed and made searchable on Google. The exposure stems from user-controlled sharing settings, with Anthropic stating that shared conversation links become publicly accessible content that may be archived by third-party services, pos
AIFree HIPAA Security Risk Assessment
HIPAA security risk assessments are mandatory evaluations that help healthcare organizations identify threats to protected health information (PHI), assess their likelihood and impact, and ensure adequate safeguards are in place. The requirements appear in both the HIPAA Security Rule for electronic PHI and the Breach Notification Rule, though organizations may need to conduct additional privacy r
FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices
The FTC, along with Utah and California, has filed a lawsuit against telehealth company Him & Hers for allegedly sharing sensitive consumer health data with third-party advertising platforms including Meta, Google, TikTok, and others without proper consent, while falsely claiming to maintain privacy. The complaint also alleges deceptive billing practices, including enrolling customers into difficu
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
An American citizen is being prosecuted for providing border officials with a passcode that triggered a wipe feature on his GrapheneOS-equipped phone. The case highlights tensions between device security features and border search authority, as well as constitutional questions about rights at U.S. borders, which the government considers outside normal jurisdiction until entry is authorized.
AIUK Social Media Ban for Minors Has Privacy Experts Worried
The UK government plans to implement a ban prohibiting users under 16 from accessing user-to-user social media platforms, a move that has raised significant concerns among privacy experts. The policy faces technical challenges around age verification mechanisms and potential privacy implications for both minors and adults who must prove their age.
Duke University Health System; Derick Dermatology Settle Class Action Pixel Lawsuits
Duke University Health System and Derick Dermatology have settled separate class action lawsuits alleging unauthorized use of website tracking pixels that transmitted patients' personal health information to third parties like Meta. Duke agreed to a $3.7 million settlement fund while Derick Dermatology agreed to pay up to $1 million, with both organizations denying any wrongdoing despite agreeing
AIMeta to Use Off-Site Business Data for Feed and AI Personalization
Meta announced it will expand the use of off-site business data beyond targeted advertising to personalize user feeds and AI chatbot responses. This represents a significant shift in how Meta leverages third-party business data shared through tracking pixels and integrations. The move raises questions about data privacy and the expanding role of user behavioral data in AI-driven personalization.
AIFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
Security research has revealed that Bright Data, a major web-scraping proxy provider targeting the AI industry, embeds SDKs in free consumer apps that convert users' devices—including always-on smart TVs—into proxy exit nodes without clear disclosure. The company, formerly known as Luminati, operates what it claims is the world's largest residential proxy network by leveraging these consumer devic
HIPAA Security Rule Training Requirements
HIPAA Security Rule training requirements mandate that covered entities and business associates provide comprehensive security awareness training to all workforce members, not just those with direct patient record access. The training must cover electronic Protected Health Information (ePHI) protection, security policies, threat recognition, incident reporting, and the distinctions between HIPAA v
