← Carolina Clear Tech

Legal & Privacy Brief

2026-02-17

Listen to this brief (12:20)

Download MP3
Show Notes

Show Notes - 2026-02-17

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 17, 2026

Today: The Fourth Circuit established a procedural framework for pre-discovery class certification challenges in Oliver v. Navy Federal Credit Union (2026 WL 346144), replacing the improper use of Rule 12(f) motions with a combined Rule 23(c)(1)(A) and 23(d)(1)(D) approach that draws de novo appellate review. The Centers for Medicare and Medicaid Services issued a proposed rule that would strip Medicare and Medicaid funding from hospitals providing gender-affirming care to minors, drawing opposition from EPIC on patient privacy and federal coercion grounds. Multiple California localities have terminated or suspended contracts with Flock Safety after federal agencies, including ICE, accessed automated license plate reader data in violation of California law prohibiting disclosure to out-of-state and federal agencies.


Litigation Updates

Oliver v. Navy Federal Credit Union - Fourth Circuit Class Certification Framework (4th Cir. 2026 WL 346144)

The Fourth Circuit ruled February 9, 2026, establishing the proper procedural mechanism for pre-discovery class certification challenges. Nine mortgage applicants alleging racial discrimination by Navy Federal Credit Union in residential mortgage lending brought two proposed classes: one under Rule 23(b)(2) for declaratory and injunctive relief, and one under Rule 23(b)(3) for damages. The district court had dismissed both class allegations using Rule 12(f) motions to strike. The Fourth Circuit held that Rule 12(f) is the wrong vehicle for class challenges at any stage, directing instead that defendants use a motion to deny class certification under Rule 23(c)(1)(A) coupled with a motion to strike under Rule 23(d)(1)(D). The court found pre-discovery denials of certification are legal determinations reviewed de novo on appeal, not for abuse of discretion, vacated the Rule 23(b)(2) class denial (the complaint adequately alleged those elements), and affirmed denial of the Rule 23(b)(3) damages class for failure to sufficiently allege predominance and superiority.


Regulatory Guidance

EPIC Comments on CMS NPRM: Medicare/Medicaid Funding Prohibition for Gender-Affirming Care in Hospitals

The Electronic Privacy Information Center submitted formal comments urging the Centers for Medicare and Medicaid Services to withdraw its notice of proposed rulemaking that would prohibit Medicare and Medicaid reimbursement for any hospital providing gender-affirming care to minors. Because most hospitals cannot operate without CMS reimbursement, the rule functions as an effective nationwide ban on the procedure in hospital settings. EPIC's opposition centers on patient privacy rights under HIPAA, the scope of CMS authority as a payer versus a clinical standards body, and the constitutional implications of using funding conditions as coercive levers over medical practice. The NPRM is currently in its public comment period.


Privacy Developments

California ALPR Networks: Unauthorized Federal Agency Access and Flock Safety Contract Terminations

Multiple California localities have moved to terminate or suspend automated license plate reader contracts with Flock Safety following revelations that federal agencies, including ICE, accessed ALPR data in violation of California law (Cal. Vehicle Code sec. 2413) prohibiting disclosure of ALPR data to out-of-state or federal agencies. Mountain View Police shut down all Flock cameras after confirming unauthorized federal access to the network. Los Altos Hills and Santa Cruz terminated Flock contracts outright over ICE concerns. East Palo Alto and Santa Clara County are reconsidering their contracts. California Attorney General data shows at least 75 California law enforcement agencies shared ALPR records out-of-state as recently as 2023, and San Francisco police documented 19 searches related to ICE in a recent reporting period. In San Jose, police conducted more than 261,000 warrantless ALPR searches over approximately 14 months, nearly 700 searches per day, with no suspicion requirement before querying databases containing up to one year of location records representing hundreds of millions of entries. SIREN and CAIR California, represented by the Electronic Frontier Foundation and the ACLU of Northern California, filed suit to stop San Jose's warrantless ALPR access.


Policy Changes

EFF "Selling Safety" Report: Accountability Framework for Police Surveillance Procurement

The Electronic Frontier Foundation, the Center for Just Journalism, and IPVM published "Selling Safety," a guide for journalists and policymakers analyzing how police surveillance vendors construct claims of effectiveness and how those unsubstantiated claims propagate into procurement decisions and media coverage. The report documents that ALPR providers, facial recognition vendors, and similar law enforcement technology companies routinely substitute marketing for evidence, and that lawmakers frequently accept vendor-generated effectiveness metrics without independent verification. EFF maintains an Atlas of Surveillance at atlasofsurveillance.org mapping technology deployment across U.S. jurisdictions and a Street-Level Surveillance hub at sls.eff.org providing accountability resources by technology type.


Compliance Takeaways