← Carolina Clear Tech

Legal & Privacy Brief

2026-04-09

Listen to this brief (17:14)

Download MP3
Show Notes

Show Notes - 2026-04-09

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 9, 2026

Today: LastPass settles 2022 data breach claims for $8.2 million with payments up to $10,000 for documented losses. Bank of America agrees to $72.5 million settlement for allegedly facilitating Jeffrey Epstein's sex trafficking operations. FCC bans all new foreign-made routers from U.S. sale, citing security gaps from Chinese threat actors.

Enforcement Actions

Bank of America Epstein Sex Trafficking Settlement (Case No. 1:25-cv-08520)

Bank of America agreed to pay $72.5 million to settle claims that it facilitated Jeffrey Epstein's sex trafficking enterprise by hosting accounts used for trafficking-related payments. The settlement was reached on March 11, 2026, following mediation with Judge Layn R. Phillips. Plaintiff Jane Doe alleged the bank overlooked red flags including her young age, foreign national status, and lack of legal employment while allowing Epstein to wire tens of thousands of dollars to accounts in her name. The settlement class includes all women and girls sexually abused by Epstein or his associates who received money or something of value in exchange for sexual contact. Fund administrators will distribute proportional payments based on circumstances, severity, type and extent of alleged abuse, nature and duration of relationship with Epstein, and cooperation with government investigations. Bank of America has not admitted wrongdoing. This follows prior Epstein settlements of $290 million against JPMorgan Chase and $75 million against Deutsche Bank.

Italian DPA Sanctions Collection Agency for Unlawful Disclosure (Decision No. 10233368)

The Italian data protection authority (Garante) ruled that a collection agency unlawfully disclosed the existence of a debt to third parties in violation of Articles 5(1)(a) and 6 GDPR. The controller, Sagitter S.p.A., contacted relatives of a data subject to inform them about an unpaid debt and its intention to foreclose on an undivided estate, even though the foreclosure procedure had not started and the notifications were based on mistaken identity. The controller claimed it acted based on legitimate interest under Italian law requiring creditors to notify all co-owners when foreclosing on undivided estates. The DPA rejected this defense, finding that the foreclosure was merely hypothetical at the time of notification, meaning the controller's legitimate interest was not real and present. The DPA ordered the controller to bring its activities into compliance by only notifying actual foreclosure proceedings, not hypothetical future actions.

Litigation Updates

$8.2M LastPass Data Breach Settlement (Case No. 1:22-cv-12047-PBS)

LastPass agreed to pay $8.2 million to resolve claims that it failed to prevent a 2022 data breach that compromised password vaults, usernames, email addresses, and phone numbers. The settlement benefits consumers whose LastPass accounts were compromised in the 2022 breach. Class members can receive a $25 statutory payment if they had an active Consumer Premium Account, Consumer Family Account, or Business Account at the time of the breach. Class members can also receive up to $300 for ordinary losses such as credit monitoring, identity protection, and security services, and up to $10,000 for extraordinary losses such as identity theft and fraud. California residents can receive an additional $100 in statutory damages under the California Consumer Privacy Act if they stored a password or security question in their LastPass vault. The settlement also provides up to $900,000 in reimbursement for cryptocurrency losses allegedly caused by the breach. All benefits will be paid on a pro rata basis depending on the number of claims submitted. The final approval hearing is scheduled for July 14, 2026. LastPass has not admitted wrongdoing.

PHH Mortgage Class Action Over Reverse Mortgage Practices (Case No. 1:26-cv-01584)

Plaintiff Lisa Mattia filed a class action in New York federal court on March 17, 2026, accusing PHH Mortgage Corp. and Onity Group Inc. of fraudulent and predatory practices in connection with reverse mortgage origination and servicing. Mattia claims PHH Mortgage locked borrowers and their heirs into loans with unexplained, undisclosed, and unsubstantiated fees, interest, and penalties. The complaint alleges PHH Mortgage preyed on Mattia's aunt, Lillian O'Keefe, during a period of declining health by inducing her to take out a reverse mortgage. After O'Keefe's death in June 2024, Mattia alleges PHH Mortgage never provided requested mortgage documents or payment history, falsely claimed it had initiated foreclosure proceedings, and hired an unsupervised third-party vendor who illegally entered O'Keefe's home and destroyed personal items. The lawsuit seeks to represent all individuals who obtained reverse mortgages from PHH Mortgage or whose reverse mortgages were serviced by the company. Claims include violations of the Fair Debt Collection Practices Act, Real Estate Settlement Procedures Act, New York General Business Law, New York Real Property Law, trespass, conversion, intentional infliction of emotional distress, and breach of contract.

Procter & Gamble Metamucil Lead Claims Move Forward (Case No. 7:23-cv-10631)

U.S. District Judge Kenneth Karas rejected Procter & Gamble's argument that claims over alleged lead in Metamucil fiber supplements were barred by federal labeling law. The court found that consumers are not challenging compliance with labeling requirements but instead allege the company's marketing is false and misleading due to alleged presence of lead in the products. Testing found that certain Metamucil products exceeded California's Proposition 65 threshold of 0.5 micrograms of lead per serving. Plaintiffs challenge marketing claims such as "#1 Doctor Recommended Brand," arguing that reasonable consumers would interpret such statements to mean the products are safe and endorsed by medical professionals. The complaint alleges the failure to disclose the presence of lead makes those representations misleading. The lawsuit also challenges product-specific claims about appetite control, healthy blood sugar levels, and digestive health for products containing added sugar. While allowing parts of the lawsuit to move forward, the court dismissed some claims for lack of standing, finding that certain plaintiffs could not pursue claims related to products they did not purchase or adequately link to testing results.

Third Circuit Rules Copyright Cannot Block Access to Laws

The U.S. Court of Appeals for the Third Circuit upheld a lower court's ruling that it is fair use to copy and disseminate building codes that have been incorporated into federal and state law, even though those codes are developed by private parties who claim copyright in them. UpCodes created a database of building codes, including the National Electrical Code, that includes codes incorporated by reference into law. ASTM, a private organization that coordinated development of some codes, insisted it retains copyright even after adoption into law and therefore has the right to control how the public accesses and shares them. The Third Circuit found all four fair use factors favored UpCodes. The court held UpCodes's use was "transformative" because it had a separate purpose from ASTM: informing people about the law rather than just best practices. The court found that laws are facts and stand at "the periphery of copyright's core protection," including codes that were "indirectly" incorporated into other codes that were themselves incorporated into law. The court rejected ASTM's argument that harm can be assumed any time materials are posted to the internet for all to access, holding that when a use is transformative, a rightsholder must bring evidence of harm, which will be balanced against the public benefit. The court found that "enhanced public access to the law is a clear and significant public benefit."

Supreme Court Denies Relief to Ohio Congressional Candidate (Ronan v. LaRose)

The Supreme Court declined to intervene on behalf of Sam Ronan, a candidate for Ohio's 15th congressional district, who was removed from the Republican primary ballot based on his past political speech. Ronan, an Air Force veteran, was removed after a voter protested his candidacy, alleging Ronan was "not in fact a Republican." The Franklin County Board of Elections divided two to two on the challenge, and Ohio Secretary of State Frank LaRose broke the tie in favor of removing Ronan from the ballot. Ronan argued his removal violates the First Amendment, but the U.S. Court of Appeals for the 6th Circuit agreed with the district court that although Ronan could change political parties, state law requires him to attest in good faith that he would "support and abide by the principles enunciated by the Republican Party." The 6th Circuit found Ronan had not shown that such a requirement violates the First Amendment. The Supreme Court declined Ronan's emergency request to be reinstated on the ballot.

Supreme Court Summary Reversal on Qualified Immunity (Zorn v. Linton)

The Supreme Court summarily reversed a Second Circuit decision that would have allowed a civil rights suit to proceed to trial over a police officer's use of force at a protest. Shela Linton was one of approximately 200 people who staged a sit-in at the Vermont state capitol on the day of the governor's inauguration, demonstrating for universal healthcare. When Linton refused to leave, Sergeant Jacob Zorn used a "rear wristlock" pain compliance technique, grabbing her arm, wrenching it behind her back, and snapping her wrist until she screamed and rose to her feet. Linton left with permanent damage to her left wrist and shoulder and has been diagnosed with post-traumatic stress disorder, depression, and anxiety. The Second Circuit held that Linton's case should go to a jury to decide whether Zorn violated her Fourth Amendment right against excessive force. The Supreme Court summarily reversed, holding that Zorn was entitled to qualified immunity because his conduct had not violated clearly established law. The summary reversal is part of a pattern of the court using its shadow docket to quickly reverse lower court decisions in favor of government defendants.

Federal Judge Blocks Trump Public Broadcasting Defunding (District Court for DC)

U.S. District Court for DC Judge Randolph Moss issued a permanent injunction blocking President Trump's executive order defunding PBS and NPR, ruling it violated the First Amendment. The executive order resulted in Congress obliterating the entire Corporation for Public Broadcasting (CPB) budget of $1.1 billion for fiscal years 2026 and 2027. With no money left to function, the CPB voted to dissolve itself in January. The executive order immediately cut millions of dollars in funding from the Education Department to PBS for children's programming, forcing the system to lay off one-third of the PBS Kids staff. Judge Moss wrote: "The Federal Defendants fail to cite a single case in which a court has ever upheld a statute or executive action that bars a particular person or entity from participating in any federally funded activity based on that person or entity's past speech. Perhaps that is because neither Congress nor any prior Administration has ever attempted something so extreme, or perhaps it is because any prior effort to do so has failed. But the most obvious reason is that any such individual ban, based on past speech, would almost certainly constitute the type of retaliation that the First Amendment prohibits." The ruling comes too late to save much of U.S. public media, with mass layoffs and program cancellations already completed.

Federal Judge Rules Border Officers Violated Warrantless Arrest Order

Judge Jennifer L. Thurston of the Federal District Court for the Eastern District of California found on Wednesday that U.S. Customs and Border Protection officials violated a previous order regarding warrantless arrests and ordered agents operating in her judicial district to fully document their reasons for making any future stops. Judge Thurston had previously found that immigration operations in Kern County, California, appeared to have been based on racial profiling, with agents making arrests when people they stopped could not produce proof of citizenship on the spot. Last year, she restricted the agency from continuing to carry out random immigration sweeps in the region, citing a "pattern and practice of agents performing detentive stops without reasonable suspicion." The new ruling found that border agents violated that order when they carried out an immigration sweep last year in a Home Depot parking lot in Sacramento. The court found that surveillance showing two out of 20 individuals in a location were noncitizens (roughly 10%) does little to demonstrate that the location is used "predominantly" by noncitizens and reveals little more than that the location is "frequented by illegal immigrants, but also by many legal residents." The court ordered the government to provide individualized reasonable suspicion for future stops.

Regulatory Guidance

FCC Bans New Foreign-Made Routers from U.S. Sale

The FCC issued an update to its Covered List on March 23, effectively banning all new routers produced in foreign countries from obtaining regulatory approval necessary for U.S. sale unless they are specifically given an exception by the Department of Defense or DHS. The Commission cited "security gaps in foreign-made routers" leading to widespread cyberattacks as justification, mentioning high-profile attacks by Chinese advanced persistent threat actors Volt, Flax, and Salt Typhoon. Previously, the FCC changed the Covered List to ban hardware by specific vendors such as Huawei and Hytera in 2021. This new blanket ban affects importation and sale of almost all new consumer routers. It does not affect consumer routers produced in the United States, like Starlink in Texas. The ban does not distinguish between companies with a track-record of producing vulnerable products and those without. The announcement quoted an Executive Branch determination that foreign produced routers introduce "a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense." The ban does not address the growing number of connected devices involved in attacks it aims to address, such as Android TV boxes preloaded with malware that fuel the Kimwolf and BADBOX 2 fraud and residential proxy botnets.

HHS Amends ACIP Charter to Expand Secretary Control Over Panel Members

HHS Secretary Robert F. Kennedy Jr. amended the Advisory Committee on Immunization Practices (ACIP) charter to expand his authority over panel member selection and appointment. The amended charter changes language from "shall be selected by the Secretary" to "shall be selected and appointed by the HHS Secretary," enshrining Kennedy's ability to unilaterally install ACIP members. The membership criteria were also dramatically changed. Currently, ACIP members "shall be selected from authorities who are knowledgeable in the fields of immunization practices and public health, have expertise in the use of vaccines and other immunobiologic agents in clinical practice or preventive medicine, have expertise with clinical or laboratory vaccine research, or have expertise in assessment of vaccine efficacy and safety." The renewal notice did not mention these criteria, but instead discussed members having a "geographic balance" and a "balance of specialty areas" spanning a much larger swath of medical and scientific fields: "biostatistics, toxicology, immunology, epidemiology, pediatrics, internal medicine, family medicine, nursing, consumer issues, state and local health department perspective, academic perspective, public health perspective, etc." These changes follow a preliminary injunction on vaccine schedule changes ACIP recommended last year, with courts finding the changes violated the Administrative Procedure Act by not being based on evidence and being arbitrary or unsupported by fact.

State Department Directs Embassies to Use X for Counter-Propaganda Operations

Secretary of State Marco Rubio signed a cable directing U.S. embassies and consulates worldwide to launch coordinated campaigns countering foreign propaganda and explicitly endorsing Elon Musk's X as an "innovative" tool for the effort. The cable admits this is psychological operations work and instructs diplomatic offices to coordinate with "the Department of War's Psychological Operations," the military unit more commonly known as MISO (Military Information Support Operations, formerly Psyop), which is part of the Pentagon. The cable instructs embassies and consulates to pursue five goals: countering hostile messaging, expanding access to information, exposing adversary behavior, elevating local voices who support American interests, and promoting "telling America's story." Embassies are told to recruit local influencers, academics, and community leaders abroad to carry counter-propaganda messaging, an approach designed to make American-funded narratives feel locally organic rather than centrally directed. The cable states: "These campaigns seek to shift blame to the United States, sow division among allies, promote alternative worldviews antithetical to America's interests, and even undermine American economic interests and political freedoms. Using digital platforms, state-controlled media, and influence operations, they pose a direct threat to US national security and fuel hostility toward American interests."

Privacy Developments

Eurail Data Breach Impacts 308,777 (Passport Numbers Leaked)

European train travel company Eurail B.V. notified U.S. regulators this week about a data breach impacting 308,777 people. The company filed breach notices in several states warning about an incident that occurred on December 26, 2025. Hackers breached Eurail systems and copied data that was later offered for sale on the dark web with a sample dataset published on Telegram. The breach notification letters say names and passport numbers were stolen during the attack. In February, a hacker claimed the attack and said they stole 1.3 TB of data that included source code, database backups, and Zendesk support tickets. The hacker claimed Eurail declined to negotiate with them, prompting them to go public with the theft. The attack had significant downstream effects, impacting a separate traveling program called DiscoverEU, which warned participants that their names, ages, passport information, photocopies of their passports, address, bank account number, and some health data was likely included in the breach. The company urged customers to be wary of contact asking for personal information and to change passwords associated with their Rail Planner app.

LAPD Files Exposed in Los Angeles City Attorney Breach

The Los Angeles Police Department announced on Tuesday that hackers gained access to a Los Angeles City Attorney's Office digital storage system containing sensitive police documents. The LAPD described the documents as materials that had been turned over in discovery from previously resolved or settled LAPD civil litigation cases. The hack did not breach any LAPD systems or networks. A spokesperson for the LA City Attorney's Office said it became aware of the breach on March 20. The hackers accessed a "third-party tool used by the City Attorney's Office to transfer discovery to opposing counsel and litigants." The office is working with law enforcement and external forensic specialists to investigate the incident. Social media posts allegedly featuring information about the stolen material revealed there were 7.7 terabytes of data available for download and more than 337,000 files accessed. The stolen materials included records containing witness names, medical information, unredacted criminal complaints, and investigative files. Under California law, police records are generally considered confidential.

Minnesota National Guard Deployed After County Cyberattack

Minnesota Governor Tim Walz issued an executive order on Tuesday deploying the Minnesota National Guard to Winona County after a cyberattack on Monday disrupted "vital emergency and critical services." The cyberattack on critical systems caused "significant disruptions," and county officials have been working with the FBI, the state's Information Technology Services, and other law enforcement agencies to recover. Walz wrote: "Unfortunately, the scale and complexity of this incident has exceeded both internal and commercial response capabilities. As a result, Winona County has requested cyber protection support from the Minnesota National Guard to help address this incident and make sure that vital municipal services continue without interruption." The executive order opens up funding, equipment, and other resources to help the county recover. Winona County, home to about 50,000 people, previously said it was dealing with a ransomware attack in January. Walz' executive order does not say if the two incidents are connected. Walz previously activated the state's national guard in response to a ransomware attack last year on the city of St. Paul.

Policy Changes

Colorado Right to Repair Law Under Threat from Tech Lobbyists

Tech companies like Cisco and IBM have pushed Colorado lawmakers to sign off on SB26-090, the Exempt Critical Infrastructure from Right to Repair law, which would neuter protections covering wheelchairs, agricultural farming equipment, and consumer electronics. Colorado's right to repair laws, which first appeared in 2022, make it easier for consumers to afford repairs and gain easier access to parts, manuals, and tools. Tech companies claim the bill is necessary to protect public safety, but the definition of "critical infrastructure" is so large and vague as to render all protections meaningless. Gay Gordon-Byrne, executive director at the Repair Association, testified: "I can point out at least five problems with the bill as drafted. The definition of critical infrastructure is completely inadequate. The definition that has been proposed in this bill is not even a definition." While tech company lobbyists have convinced the Colorado Labor and Technology committee to advance the bill, it still needs approval by the Colorado Senate and House. While eight states have now passed right to repair laws, none have actually enforced them despite numerous, ongoing infractions across countless industries.

TikTok Removes Covert Networks Ahead of Hungary Vote

TikTok said it removed covert networks attempting to sway the result of Hungary's parliamentary elections ahead of voting. The company said the networks used fake accounts to post and amplify political content aimed at Hungarian users, including material critical of opposition leader Péter Magyar and his Tisza Party as well as content targeting Prime Minister Viktor Orbán's ruling Fidesz. TikTok said it also removed hundreds of impersonating accounts and thousands of videos that violated its election policies. TikTok told The Record it had since December banned more than 300 accounts for impersonating Hungarian election candidates and elected officials. It said it had also taken action against six covert influence networks, the majority of which spread narratives favorable to the Fidesz political party, with some smaller networks targeting Hungarian audiences with narratives critical of Fidesz and Orbán. Hungarian fact-checkers detailed false narratives about Magyar appearing on fake websites impersonating legitimate sources, including claims he plans a "coup" if defeated and that his party would reinstate compulsory military service. Fact-checking outlet Lakmusz said the activity showed similarities to earlier influence operations that researchers have linked to Russian actors, including coordinated messaging and the use of deceptive online infrastructure.

Compliance Takeaways