← Carolina Clear Tech

Legal & Privacy Brief

2026-05-07

Listen to this brief (17:12)

Download MP3
Show Notes

Show Notes - 2026-05-07

Stories Covered

CVEs Referenced

CVE-2026-0300

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief

May 7, 2026

Today: NYDFS imposed a $2.25 million penalty on Delta Dental for MOVEit breach failures including late notification and inadequate data retention policies. House Republicans released the SECURE Data Act, which would preempt state privacy laws while offering weaker consumer protections than most existing state frameworks. A critical Palo Alto Networks firewall vulnerability (CVE-2026-0300, CVSS 9.3) is under active exploitation, with CISA ordering federal agencies to patch by Saturday.

Enforcement Actions

NYDFS Delta Dental $2.25M Penalty (MOVEit Breach)

New York Department of Financial Services issued a $2.25 million civil monetary penalty against Delta Dental Insurance Company and Delta Dental of New York on April 29, 2026, for violations of Part 500 Cybersecurity Regulation. The action stems from the June 2023 MOVEit Transfer zero-day breach. NYDFS charged Delta Dental with four violations under Part 500: failure to maintain policies for secure disposal of nonpublic information no longer necessary for business operations (§500.13), failure to implement adequate written incident response policies (§500.3(n)), failure to establish incident response plans addressing regulatory reporting obligations (§500.16(b)(6)), and failure to provide timely notice of a cybersecurity event (§500.17(a)). Delta Dental identified a malicious webshell on June 1, 2023, confirmed data exfiltration by July 6, 2023, but did not notify NYDFS until December 15, 2023, more than five months after confirming the breach. Approximately 60,000 files containing Social Security numbers, driver's license numbers, financial account information, and health data were exfiltrated. Delta Dental had disabled MOVEit's default 30-day retention settings, keeping files on servers longer than necessary without written policies governing retention changes.

Litigation Updates

Blue Cross Blue Shield $2.67B Antitrust Settlement Payments Begin

Blue Cross Blue Shield will begin distributing payments from a $2.67 billion class action settlement resolving claims the health insurance provider engaged in anticompetitive practices. The settlement addresses allegations that BCBS insurers restricted competition through market allocation agreements and territorial restrictions.

Oglethorpe $350K Data Breach Settlement

Oglethorpe agreed to a $350,000 class action settlement resolving claims that a 2025 data breach compromised sensitive consumer information. The settlement provides compensation to affected class members whose personal data was exposed in the incident.

Sportsman's Warehouse Pennsylvania Privacy Settlement

Sportsman's Warehouse agreed to a class action settlement resolving claims it violated Pennsylvania data privacy laws by disclosing firearm purchase information without consumer consent. The settlement addresses allegations that the retailer improperly shared transaction data with third parties in violation of state privacy protections.

Equity Residential $56M RealPage Rent Price-Fixing Settlement

Equity Residential agreed to pay $56 million to resolve claims it participated in a rent price-fixing scheme using RealPage's revenue management software. The settlement addresses allegations that landlords coordinated pricing through algorithmic software, violating antitrust laws by reducing competition in rental markets.

Supreme Court Denies Apple Stay in Epic Games Contempt Case

Justice Elena Kagan denied Apple's emergency request to pause a civil contempt order entered against the company in its ongoing dispute with Epic Games. The contempt finding stems from Apple's alleged violations of an earlier order prohibiting the company from blocking developers from encouraging customers to purchase games and products outside the App Store. The 9th Circuit found Apple in contempt for implementing measures that made it more difficult for developers to direct customers to alternative payment systems and for imposing large commissions on purchases made through third-party systems after users clicked links in the App Store. Apple sought Supreme Court intervention before litigating its commission rate under the contempt finding. Kagan denied the stay without referring it to the full Court, indicating it was not a close call.

Matt Taibbi Defamation Suit Dismissed

Judge George B. Daniels dismissed journalist Matt Taibbi's defamation lawsuit against author Eoin Higgins and Bold Type Books over Higgins' book "Owned: How Tech Billionaires on the Right Bought the Loudest Voices on the Left." Taibbi sued claiming the book's title and content falsely stated he was "owned" and "bought" by billionaires. The court ruled that the book's cover, jacket, and challenged statements were metaphorical, non-actionable opinion protected by the First Amendment. The decision explains that "Owned" and "Bought" are susceptible to both literal and metaphorical meanings depending on context, and that reasonable readers would interpret these terms metaphorically when applied to media figures and their relationships with financial backers. The dismissal reinforces that critique and commentary about journalists' relationships with wealthy supporters constitute protected opinion, not defamatory factual claims.

Regulatory Guidance

CISA Critical Infrastructure Isolation Initiative (CI Fortify)

Cybersecurity and Infrastructure Security Agency unveiled CI Fortify, a new initiative urging critical infrastructure organizations to prepare for technology and telecommunications outages caused by cyberattacks. The guidance recommends organizations proactively disconnect from third-party dependencies and develop operational plans for functioning without reliable telecommunications and internet during crisis or conflict. CI Fortify emphasizes network segmentation, isolation of operational technology systems, and rapid restoration capabilities while disconnected. CISA Acting Director Nick Andersen stated the agency will conduct targeted assessments of critical infrastructure organizations, though specific numbers and locations were not disclosed. The initiative addresses nation-state hacking campaigns including China's Volt Typhoon, where threat actors prepositioned on U.S. critical infrastructure to enable destructive cyber action during potential kinetic military conflict.

Palo Alto Networks Critical Firewall Vulnerability (CVE-2026-0300)

Palo Alto Networks disclosed CVE-2026-0300, a critical vulnerability (CVSS 9.3) affecting PAN-OS software and PA-Series and VM-Series firewalls with specific configurations. The vulnerability is under active exploitation targeting authentication portals exposed to untrusted IP addresses or the public internet. CISA confirmed exploitation and ordered all U.S. federal agencies to apply Palo Alto's mitigations by May 10, 2026. A patch will be released over the next two weeks, with Rapid7 estimating availability for many versions by May 13. Customers following security best practices by restricting sensitive portals to trusted internal networks face greatly reduced risk. Multiple cybersecurity firms reported exploitation following release of exploit code on Tuesday evening.

FCC Laboratory Testing Ban (China-Based Facilities)

Trump administration FCC announced plans to ban electronic device testing at laboratories with offices in China for products sold in the United States. Approximately 75% of U.S.-bound electronics are currently tested in Chinese facilities, with 27 affected facilities operated as Chinese subsidiaries of major Western testing firms including Intertek, SGS, TUV Rheinland, and Bureau Veritas. Basic FCC certification testing costs $400 to $1,300 at Chinese labs compared to $3,000 to $4,000 at U.S. equivalents. The policy would require companies to redirect testing to facilities in the U.S., Europe, or Taiwan, significantly increasing compliance costs that will likely be passed to consumers. The ban applies to companies with testing offices in China regardless of ownership, affecting U.S. and European testing firms operating Chinese subsidiaries.

Privacy Developments

Federal SECURE Data Act Proposed (House Republicans)

House Energy and Commerce Committee Republicans released the SECURE Data Act draft without bipartisan support. The bill would preempt state consumer privacy laws under Section 15, eliminating the 21 state privacy laws passed in recent years, all 50 state data breach notification laws, and state laws governing specific categories of sensitive data such as biometric and location information. The bill provides standard data rights (access, correction, deletion, limited portability) and requires consumer consent before processing sensitive data or using personal data for previously undisclosed purposes. Consumers can opt out of targeted third-party advertising, data sales, and certain profiling, but companies may continue these practices unless consumers opt out. The bill requires data brokers earning at least 50% of profits from data sales to register in an FTC public database. The bill does not include private right of action for consumers, limiting enforcement to FTC and state attorneys general. Critics including EFF and EPIC argue the bill reinforces failed "notice and choice" models, permits massive data overcollection to continue, and would eliminate stronger state protections including California's data broker deletion tool and automatic opt-out signal requirements.

HUD Proposed AI Tool Using Sensitive Data

Department of Housing and Urban Development published a Notice of intent to modify its System of Records to collect new categories of personally identifiable information and introduce AI features that would generate draft case summaries and suggested email responses using case information and internal knowledge bases. EPIC and Center for Democracy & Technology submitted comments opposing the changes, arguing HUD's Notice lacks details about system accuracy, fitness, safety, security protocols, and accountability mechanisms. The Notice suggests these AI practices are already operational prior to publication, which EPIC and CDT argue violates the Privacy Act. The organizations urged HUD to roll back the changes and conduct proper Privacy Act compliance before implementing AI systems processing sensitive housing assistance data.

California AI Chatbot Mental Health Liability Law

California passed legislation requiring AI chatbot providers to implement protocols preventing production of suicidal ideation if engaging in mental health conversations, with liability for conversations linked to harm. The law will likely result in chatbots responding to emotional distress by displaying 988 crisis line numbers or terminating conversations. New York is considering legislation that would ban chatbots from discussions "suited for licensed professionals." Critics including Professor Jess Miers argue the liability regime will make chatbots less safe by incentivizing providers to cut off mental health conversations entirely rather than provide continued support. Research shows over one million people per week use general-purpose chatbots for mental health support, with many reporting positive outcomes. A Replika study found 30 users credited the chatbot with helping them avoid suicide. The laws follow high-profile tragic cases but may eliminate beneficial mental health support for larger populations not in crisis.

Illinois Chatbot Provider Liability Framework (H.B. 5044)

Illinois House Bill 5044 would establish chatbots as products for purposes of product liability law, allowing chatbot providers to be held strictly liable for harms their chatbots cause. EPIC Counsel Kara Williams testified in support of the bill on May 5, 2026, stating it represents an important step toward tech company accountability and justice for people harmed by dangerous products. The bill is based on the liability section of EPIC's People-First Chatbot Bill and would create a clear liability framework for chatbot-related injuries.

Policy Changes

Supreme Court Voting Rights Act Decision (Louisiana v. Callais)

Supreme Court finalized its decision in Louisiana v. Callais, striking down Louisiana's congressional map under the Voting Rights Act and requiring the state to draw a new map before the 2026 elections. The decision limits the use of race as a predominant factor in drawing election districts even when necessary to comply with Section 2 of the Voting Rights Act. Justice Samuel Alito's majority opinion applies strict scrutiny to districts drawn to protect Black voters, holding that preventing discriminatory effects against voters of color is not a sufficiently compelling government interest to justify race-based districting. Justice Ketanji Brown Jackson dissented, joined by Justices Sonia Sotomayor and Elena Kagan. The decision will likely result in redistricting throughout the South that reduces majority-minority districts designed to protect Black voter representation, with expected decreases in people of color elected to Congress and state legislatures. The ruling follows decades of Supreme Court decisions limiting the Voting Rights Act, including City of Mobile v. Bolden (requiring proof of discriminatory purpose), Shaw v. Reno (applying strict scrutiny to race-based districting), and Shelby County v. Holder (striking down preclearance requirements).

South Dakota Citizenship Proof Voting Law

South Dakota enacted legislation requiring state residents to prove citizenship to participate in state and local elections, with non-citizens restricted to federal elections only. Governor Larry Rhoden signed the bill following claims of widespread noncitizen voting, though Director of Elections Rachel Soulek testified only one of 273 identified noncitizens had ever cast a ballot (in the 2016 general election), likely due to clerical error. The law creates confusion among county election officials about acceptable proof of citizenship. Hughes County requires physical driver's licenses showing both front and back, while other counties are adopting varying standards. Critics argue the law suppresses voter turnout by adding confusion and barriers to voter registration, particularly affecting mail-in voting. The legislation follows Supreme Court precedent in Louisiana v. Callais permitting voting restrictions that do not explicitly state discriminatory intent.

Compliance Takeaways