Get tomorrow's brief in your inbox
Today: The Fourth Circuit established a procedural framework for pre-discovery class certification challenges in Oliver v. Navy Federal Credit Union (2026 WL 346144), replacing the improper use of Rule 12(f) motions with a combined Rule 23(c)(1)(A) and 23(d)(1)(D) approach that draws de novo appellate review. The Centers for Medicare and Medicaid Services issued a proposed rule that would strip Medicare and Medicaid funding from hospitals providing gender-affirming care to minors, drawing opposition from EPIC on patient privacy and federal coercion grounds. Multiple California localities have terminated or suspended contracts with Flock Safety after federal agencies, including ICE, accessed automated license plate reader data in violation of California law prohibiting disclosure to out-of-state and federal agencies.
Oliver v. Navy Federal Credit Union - Fourth Circuit Class Certification Framework (4th Cir. 2026 WL 346144)
The Fourth Circuit ruled February 9, 2026, establishing the proper procedural mechanism for pre-discovery class certification challenges. Nine mortgage applicants alleging racial discrimination by Navy Federal Credit Union in residential mortgage lending brought two proposed classes: one under Rule 23(b)(2) for declaratory and injunctive relief, and one under Rule 23(b)(3) for damages. The district court had dismissed both class allegations using Rule 12(f) motions to strike. The Fourth Circuit held that Rule 12(f) is the wrong vehicle for class challenges at any stage, directing instead that defendants use a motion to deny class certification under Rule 23(c)(1)(A) coupled with a motion to strike under Rule 23(d)(1)(D). The court found pre-discovery denials of certification are legal determinations reviewed de novo on appeal, not for abuse of discretion, vacated the Rule 23(b)(2) class denial (the complaint adequately alleged those elements), and affirmed denial of the Rule 23(b)(3) damages class for failure to sufficiently allege predominance and superiority.
EPIC Comments on CMS NPRM: Medicare/Medicaid Funding Prohibition for Gender-Affirming Care in Hospitals
The Electronic Privacy Information Center submitted formal comments urging the Centers for Medicare and Medicaid Services to withdraw its notice of proposed rulemaking that would prohibit Medicare and Medicaid reimbursement for any hospital providing gender-affirming care to minors. Because most hospitals cannot operate without CMS reimbursement, the rule functions as an effective nationwide ban on the procedure in hospital settings. EPIC's opposition centers on patient privacy rights under HIPAA, the scope of CMS authority as a payer versus a clinical standards body, and the constitutional implications of using funding conditions as coercive levers over medical practice. The NPRM is currently in its public comment period.
California ALPR Networks: Unauthorized Federal Agency Access and Flock Safety Contract Terminations
Multiple California localities have moved to terminate or suspend automated license plate reader contracts with Flock Safety following revelations that federal agencies, including ICE, accessed ALPR data in violation of California law (Cal. Vehicle Code sec. 2413) prohibiting disclosure of ALPR data to out-of-state or federal agencies. Mountain View Police shut down all Flock cameras after confirming unauthorized federal access to the network. Los Altos Hills and Santa Cruz terminated Flock contracts outright over ICE concerns. East Palo Alto and Santa Clara County are reconsidering their contracts. California Attorney General data shows at least 75 California law enforcement agencies shared ALPR records out-of-state as recently as 2023, and San Francisco police documented 19 searches related to ICE in a recent reporting period. In San Jose, police conducted more than 261,000 warrantless ALPR searches over approximately 14 months, nearly 700 searches per day, with no suspicion requirement before querying databases containing up to one year of location records representing hundreds of millions of entries. SIREN and CAIR California, represented by the Electronic Frontier Foundation and the ACLU of Northern California, filed suit to stop San Jose's warrantless ALPR access.
EFF "Selling Safety" Report: Accountability Framework for Police Surveillance Procurement
The Electronic Frontier Foundation, the Center for Just Journalism, and IPVM published "Selling Safety," a guide for journalists and policymakers analyzing how police surveillance vendors construct claims of effectiveness and how those unsubstantiated claims propagate into procurement decisions and media coverage. The report documents that ALPR providers, facial recognition vendors, and similar law enforcement technology companies routinely substitute marketing for evidence, and that lawmakers frequently accept vendor-generated effectiveness metrics without independent verification. EFF maintains an Atlas of Surveillance at atlasofsurveillance.org mapping technology deployment across U.S. jurisdictions and a Street-Level Surveillance hub at sls.eff.org providing accountability resources by technology type.
Fourth Circuit class action defense: Defendants in the Fourth Circuit should replace Rule 12(f) motions to strike class allegations with Rule 23(c)(1)(A) motions to deny certification, coupled with Rule 23(d)(1)(D) motions to strike if certification is denied. Pre-discovery certification denials receive de novo appellate review under Oliver v. Navy Federal Credit Union (2026 WL 346144). Assess all pending Fourth Circuit class matters for procedural alignment.
CMS NPRM comment deadline: Healthcare organizations should submit comments to CMS on the gender-affirming care funding NPRM before the comment period closes. Monitor the docket for finalization timing. If finalized, facilities that provide these services will need to either modify programs or lose Medicare and Medicaid certification, requiring board-level policy decisions and contingency planning.
Surveillance vendor data access audits: Any contract with a surveillance technology vendor, including ALPR, body camera, facial recognition, or access control providers, should be reviewed for provisions governing federal or out-of-state agency data access. California law expressly prohibits ALPR data disclosure to federal agencies, and violations are documented across at least 75 agencies. Non-compliant contract terms expose organizations to civil liability and regulatory action under state privacy law.
Warrantless government data access exposure: Organizations that aggregate location data, movement records, or behavioral data through third-party systems should evaluate their current exposure to warrantless government requests. The San Jose ALPR litigation illustrates that mass data collection without warrant requirements is under active legal challenge. Establish documented data minimization and retention policies before litigation or regulatory inquiry forces the issue.
LLM deployment security posture: Research highlighted by Schneier on Security identifies remote timing side-channel attacks against inference-optimized language model deployments. Organizations running customer-facing or internally hosted LLM services should monitor published research on speculative sampling and parallel decoding timing vulnerabilities as these techniques develop from academic proof-of-concept toward operational exploitation.