← Carolina Clear Tech

Legal & Privacy Brief

2026-03-12

Listen to this brief (23:11)

Download MP3
Show Notes

Show Notes - 2026-03-12

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 12, 2026

Today: Bell Ambulance disclosed a data breach affecting 235,000 patients after Medusa ransomware stole Social Security numbers and medical records. Meta disrupted an Iranian influence operation using fake Instagram personas to target U.S. users with political messaging. A DOGE contractor allegedly exfiltrated Social Security databases containing 500 million Americans' records on a thumb drive, expecting a presidential pardon if caught.

Enforcement Actions

Bell Ambulance Data Breach (Medusa Ransomware)

Bell Ambulance, Wisconsin's largest ambulance provider, disclosed a cyberattack affecting 237,830 individuals. The breach was discovered on February 13, 2025, when the Medusa ransomware gang infiltrated systems and exfiltrated 219 GB of data including Social Security numbers, driver's license numbers, financial accounts, medical information, and health insurance information. The attackers demanded a $400,000 ransom. Victims were notified beginning in April 2025, with additional affected individuals identified throughout the fall.

Meta Disrupts Iranian Influence Operation on Instagram

Meta removed approximately 300 accounts and pages across Facebook and Instagram that were part of an Iranian influence operation using sophisticated fake personas. The network used accounts posing as journalists, commentators, a political scientist, a women's rights activist, and a satirical cartoonist, utilizing AI-generated profile photos. The operation targeted English-speaking audiences in the U.S. with content critical of Israel and U.S. policy in the Middle East. The network began on X in 2024 before expanding to Meta platforms in summer 2025 and was disrupted late last year. Approximately 41,000 accounts followed the fake Instagram personas.

Meta Scam Ad Removal (159 Million Ads in 2025)

Meta reported removing 159 million scam ads in 2025 and 10.9 million Facebook and Instagram accounts associated with criminal scam centers, amid congressional calls for investigation into the company's facilitation of and profiting from fraudulent advertising. A Reuters investigation cited internal documents projecting about 10% of Meta's 2024 revenue (approximately $16 billion) would come from ads linked to scams and banned goods. Meta disputes this figure. The company worked with Royal Thai Police, FBI, and Britain's National Crime Agency during a Bangkok operation targeting scam centers, disabling more than 150,000 accounts tied to scam networks and contributing to 21 arrests. Meta's director of global threat disruption stated that 92% of the 159 million scam ads removed in 2025 were detected automatically before anyone reported them.

Litigation Updates

AAA Underinsured Motorist Claims Settlement ($4.15M)

AAA agreed to a $4.15 million settlement in Smith v. Interinsurance Exchange of the Automobile Club, Case No. 1:22-cv-00447-WJ-JMR, in the U.S. District Court for the District of New Mexico. Plaintiffs claimed AAA wrongfully reduced underinsured motorist claims by offsetting the amount paid by the at-fault driver, violating New Mexico law. The settlement benefits consumers who had an underinsured motorist claim reduced between January 1, 2010, and May 4, 2022, or who purchased New Mexico automobile insurance with UM/UIM coverage during that period. Class members with offset claims can receive up to $25,000, subject to pro rata reduction based on claims filed. Class members who purchased UM/UIM coverage will receive partial premium refunds.

Amazon Hypoallergenic Body Wash Class Action

Plaintiff Sequoia King filed a class action complaint against Amazon.com Services and Amazon.com on February 6, 2026, in the U.S. District Court for the Southern District of New York (King v. Amazon.com Services LLC, et al., Case No. 1:26-cv-01062). King alleges Amazon falsely advertises its Amazon Basics Hypoallergenic Body Wash for Sensitive Skin as containing no allergens when the product contains fragrance chemicals, which are common causes of skin allergies. The complaint alleges violations of New York General Business Law Sections 349 and 350. King seeks to represent anyone who bought the product in New York and is seeking class certification, damages, fees, costs, and a jury trial.

Depop "Junk Fee" Class Action (California)

Plaintiff Linsey Dinh filed a class action complaint against Depop Inc. on February 6, 2026, in the U.S. District Court for the Northern District of California (Dinh v. Depop Inc., Case No. 3:26-cv-01173-VC). The complaint alleges Depop engages in "drip pricing" by failing to include a mandatory "marketplace" fee in advertised prices, only disclosing the fee at checkout. Dinh was charged a $1.55 marketplace fee at checkout on a $17.00 item in January 2025. The lawsuit alleges violations of California's Consumers Legal Remedies Act, Unfair Competition Law, False Advertising Law, California's Honest Pricing Law, and unjust enrichment. The plaintiff seeks to represent a nationwide class of consumers charged the marketplace fee without prior disclosure and is seeking certification, damages, restitution, declaratory relief, injunctive relief, and fees.

Crock-Pot Nonstick Coating Defect Class Action

Plaintiff Robert Ventullo filed a class action lawsuit against Newell Brands Inc. and Sunbeam Products Inc. in the U.S. District Court for the District of Massachusetts (Ventullo v. Newell Brands Inc., et al., Case No. 1:26-cv-10027). The complaint alleges Crock-Pot slow cookers are falsely advertised as "easy-to-clean" despite a defect causing the nonstick coating to detach, bubble, flake, chip, and peel off. Ventullo claims the defect stems from excess mica in the Teflon coating, preventing proper adhesion to ceramic materials. The plaintiff seeks to represent a nationwide class and Massachusetts class of consumers who purchased a Crock-Pot slow cooker within the statute of limitations period. Claims include breach of express and implied warranty, fraud, breach of contract, unjust enrichment, and violations of the Magnuson-Moss Warranty Act and Massachusetts consumer protection law.

EFF Amicus Brief: Embedding and Copyright Server Test

The Electronic Frontier Foundation filed an amicus brief in the Fifth Circuit urging the court not to make embedding illegal. The case involves Emmerich Newspapers, which wants the Fifth Circuit to reject the server test and hold that entities embedding links to content are responsible for "displaying" it and can be directly liable if the content turns out to be infringing. Under the server test, applied by most U.S. courts for almost two decades, the entity that controls the server hosting copyrighted work can be directly liable for infringement, while those who merely link to it face only secondary liability in limited circumstances. EFF argues that millions of websites embed external content for functions like selecting fonts, streaming music, customer support, and legal compliance. Emmerich also claims that altering a URL violates the Digital Millennium Copyright Act's prohibition on changing copyright management information, which would put link shortener users at risk of statutory penalties.

Privacy Developments

DOGE Contractor Allegedly Exfiltrated Social Security Databases (500 Million Records)

A former DOGE software engineer allegedly walked out of the Social Security Administration with databases containing records on more than 500 million living and dead Americans on a thumb drive and attempted to upload the data to his new employer's systems at a government contractor. The whistleblower complaint alleges the engineer possessed two restricted databases called "Numident" and the "Master Death File," which include Social Security numbers, places and dates of birth, citizenship, race and ethnicity, and parents' names. The engineer allegedly told a colleague who refused to help upload the data that he expected to receive a presidential pardon if his actions were deemed illegal. The engineer had approved access to Social Security data while working at DOGE. The alleged data exfiltration occurred around early January 2026, after the engineer started a job at a government contractor in October 2025.

Stryker Medical Device Manufacturer Cyberattack (Handala Hackers)

Stryker confirmed a cyberattack that caused a "global network disruption" to its Microsoft environment. The company stated it has no indication of ransomware or malware and believes the incident is contained. Employees reported that corporate computers and phones were completely wiped on Wednesday morning, with company servers wiped clean and work apps taken down. The Iran-linked Handala hacking group claimed responsibility, stating the attack was retaliation for a U.S. missile strike on a school in Iran. The group claimed it wiped more than 200,000 systems, servers, and mobile devices while stealing 50 terabytes of company data. When employees attempted to log in, they saw the Handala logo. Stryker is one of the largest medical device manufacturers in the world, reporting more than $25 billion in earnings last year, and holds large contracts with the U.S. Department of Defense.

Certbot and Let's Encrypt IP Address Certificates

Let's Encrypt now issues IP address certificates and six-day certificates to the general public. Certbot 5.3 added support for IP address certificates through the --ip-address flag and --preferred-profile shortlived flag. IP address certificates require Let's Encrypt's "shortlived" profile and are valid for six days. Certbot supports getting IP address certificates through webroot, manual, and standalone plugins, but the nginx and apache plugins do not yet support IP addresses. Organizations should set up automatic renewal with a --deploy-hook that tells webservers to load the most up-to-date certificates from disk.

Policy Changes

Trump Administration Seeks Supreme Court Intervention on Haiti TPS Termination

U.S. Solicitor General D. John Sauer asked the Supreme Court to pause a ruling by U.S. District Judge Ana Reyes that barred the government from ending the Temporary Protected Status (TPS) program for Haitians. On November 28, 2025, then-DHS Secretary Kristi Noem announced that Haiti's TPS designation would end on February 3, 2026, despite acknowledging "escalating violence and gang violence" in Port-au-Prince. Judge Reyes issued a ruling on February 2, 2026, temporarily barring the termination, finding it "substantially likely" that Noem ended the designation "because of hostility to nonwhite immigrants" and that Noem failed to consult with other federal agencies or consider the billions Haitian TPS holders contribute to the economy. As of June 2025, approximately 350,000 Haitian nationals in the United States had temporary protected status. The U.S. Court of Appeals for the D.C. Circuit turned down the government's request to stay Reyes' ruling, distinguishing the case from Supreme Court decisions involving Venezuela TPS cases.

Defense Department Civilian Protection Mission Dissolved

The Trump administration dissolved the Defense Department's Civilian Protection Center of Excellence and civilian harm reduction program. Defense Secretary Pete Hegseth made "lethality" a top priority, forcing out senior adviser Wes J. Bryant and other staff involved in the program. The administration lowered the authorization level for lethal force, broadened target categories, inflated threat assessments, and fired inspectors general. On February 28, 2026, a missile strike on an elementary school in Minab, Iran, killed 165 people, most under age 12, with nearly 100 others wounded. Bellingcat authenticated a video showing a Tomahawk missile strike next to the school, and Iranian state media showed fragments of a U.S.-made Tomahawk at the site. U.N. human rights experts have called for an investigation into whether the attack violated international law.

EFF Report: Government Access to Advertising Surveillance Data

The Electronic Frontier Foundation published a report confirming that the government is using the advertising surveillance infrastructure to obtain consumer data. EFF is explaining the dangers of targeted advertising and location tracking and the latest in the fight for privacy and free speech online. EFF Staff Attorney Lena Cohen discussed how targeted advertising can reveal user location to federal law enforcement. The EFFector newsletter is now available on all major podcast platforms.

Compliance Takeaways