← Carolina Clear Tech

Legal & Privacy Brief

2026-06-09

Listen to this brief (13:42)

Download MP3
Show Notes

Show Notes - 2026-06-09

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - June 9, 2026

Today: Duke University Health System settles patient portal privacy breach for $3.74 million. WhatsApp asks federal court to hold NSO Group in contempt for violating permanent injunction barring spyware attacks on its platform. Trump administration issues executive order targeting cyber risks from frontier AI models, establishing voluntary early-access framework and directing DOJ to prioritize AI-enabled fraud prosecutions.

Enforcement Actions

Duke University Health System Privacy Breach Settlement

Duke University Health System agreed to pay $3.74 million to settle a class action over a privacy breach affecting patients who logged into the MyChart patient portal or MyDuke Health app. The settlement provides compensation to class members whose protected health information was potentially exposed through the breach.

WhatsApp Files Contempt Motion Against NSO Group

WhatsApp filed a federal court motion seeking to hold NSO Group in contempt for violating an October permanent injunction that bars the spyware manufacturer from targeting WhatsApp users. Meta detected spearfishing attacks using social engineering to trick users into clicking malicious links after users reported suspicious activity. The permanent injunction followed a jury verdict awarding WhatsApp $167 million (later reduced to $4.4 million) for NSO's targeting of 1,400 WhatsApp users with zero-click attacks in 2019. NSO previously argued the injunction would force the company out of business and harm law enforcement operations.

Litigation Updates

Florida AG Sues OpenAI Over ChatGPT Safety Claims

Florida Attorney General James Uthmeier filed a lawsuit against OpenAI and CEO Sam Altman alleging ChatGPT encourages violence, harms children, and was deceptively marketed as safe for public use. The complaint alleges the AI chatbot poses safety hazards despite public safety representations.

Trump DOJ Attorneys Referred for Discipline in Anti-Trans Lawfare Case

Trump-appointed federal judge Mary McElroy referred Department of Justice attorneys for professional discipline after they misrepresented facts, withheld information from two federal courts, and deployed procedural tactics to shield investigative methods from judicial review in a case targeting Rhode Island Hospital for medical records of transgender minors. McElroy's May 14 order blocked the DOJ subpoena and noted the government "misrepresented and withheld information to both this Court and the United States District Court for the Northern District of Texas" in an effort to avoid Rhode Island jurisdiction in favor of a Texas court "DOJ deems friendly to its political positions." The referral cites Local Rule 210(b) for further disciplinary proceedings.

Supreme Court Denies Review in AR-15 Hat First Amendment Case

The Supreme Court declined to review C.S. v. McCrumb, a case in which a third-grade student was barred from wearing a baseball cap featuring an AR-15 image and the words "Come and Take It" during a school Hat Day. School officials cited concern about student reactions following a shooting at a high school 50 miles away. The U.S. Court of Appeals for the 6th Circuit upheld a district court ruling in favor of school officials, finding they had a reasonable forecast of substantial disruption under Tinker v. Des Moines Independent School District.

7th Circuit Upholds Ban on Media Access to Indiana Executions

The U.S. Court of Appeals for the 7th Circuit upheld an Indiana law prohibiting media witnesses at state executions, ruling the First Amendment does not guarantee special press access to executions. A group of news outlets including the Associated Press had argued for a limited right of access based on Supreme Court precedent allowing media access to certain governmental proceedings. The majority panel found executions do not resemble court proceedings and therefore fall outside the scope of First Amendment access rights.

Regulatory Guidance

Trump Executive Order on AI Innovation and Cybersecurity

President Trump issued an executive order on June 2, 2026 targeting cyber risks from frontier AI models. The order directs Treasury, NSA, CISA, and NIST to develop a classified benchmarking process to assess advanced cyber capabilities of AI models and determine when a model qualifies as a "covered frontier model." Key provisions include a voluntary early-access framework allowing AI developers to provide the federal government access to covered frontier models for up to 30 days before release to trusted partners, expansion of AI-enabled cybersecurity tools for federal agencies and critical infrastructure operators, establishment of an AI cybersecurity clearinghouse to coordinate vulnerability scanning and patch distribution, and DOJ prioritization of identity theft and wire fraud prosecutions involving AI. The order does not authorize mandatory licensing, preclearance, or permitting requirements for AI model development or release.

UK Mandates Device-Level Nudity Detection for Child Protection

The United Kingdom gave Apple, Google, and other tech companies three months to implement device-level controls that detect and block nude images of children on smartphones and tablets. Prime Minister Keir Starmer announced the measure at London Tech Week. The rules apply to existing and new devices and require activation of built-in features or implementation of technical solutions across all apps, cameras, and services. The Home Office stated there will be no data collection, monitoring, or reporting. Adults will require age verification to access nude content. If tech firms fail to comply, the government will introduce legislation with potential fines and criminal liability for executives. More than 90% of child sex abuse reports in 2024 featured self-generated content.

Russia Expands SORM Digital Surveillance System

Russia's Ministry of Digital Development published new regulations expanding the technical standards governing SORM (System for Operative Investigative Activities), the platform that gives Russian security and intelligence agencies access to telephone calls, internet traffic, and electronic communications. The updated rules specify how information must be searched, processed, and transmitted, and expand searchable data to include full names, passport information, tax identification numbers, addresses, usernames, domains, URLs, corporate records, device identifiers, and geographic coordinates. The regulations require telecommunications providers and "information dissemination organizers" to deploy specialized hardware, storage systems, and dedicated communications infrastructure. Non-compliance triggers licensing problems, regulatory scrutiny, and administrative sanctions.

Privacy Developments

noyb Launches CRIF Class Action Over Credit Scoring GDPR Violations

Austrian privacy advocacy organization noyb filed an injunction and class action for damages against CRIF GmbH, one of Austria's largest credit reference agencies, alleging the company maintains an unlawful "shadow registry" containing names, dates of birth, and addresses of nearly all adults in Austria. CRIF assigns credit scores between 250 and 700, but for 90% of individuals the score is based solely on age, gender, and address without any financial information. noyb alleges CRIF violates GDPR by collecting data from address brokers authorized only for marketing purposes, failing to inform data subjects about processing, and relying on invalid legitimate interest claims rather than consent. CRIF's clients include mobile operators (Magenta, Drei), banks (Erste Bank, Santander), energy suppliers (Verbund), online retailers (Zalando), and payment processors (Klarna).

Meta Removes Facial Recognition Code From Smart Glasses App

Meta removed facial recognition technology code from its Meta AI companion app for smart glasses following a WIRED investigation and public outcry. The June 5 app update removed code designed to convert face images into biometric signatures to identify strangers in public, including "Person recognized" alerts and machine learning models for detecting, digitizing, and storing biometric signatures. EFF's Threat Lab verified the presence of the FRT system through static analysis before Meta's removal. Meta has not confirmed whether it will reintroduce the system or disclosed what it did with data collected during internal testing.

Policy Changes

Supreme Court Petition Campaigns Targeting Obergefell

A SCOTUSblog analysis noted that while the Supreme Court denied review in Davis v. Ermold (a county clerk's challenge to Obergefell v. Hodges with poor facts and no institutional backing), future well-orchestrated campaigns analogous to Dobbs could challenge the 2015 same-sex marriage decision. Support for same-sex marriage fell from 71% in 2022-2023 to 65% in 2026, primarily due to declining Republican support. Unlike Davis, which had only two supporting briefs (National Organization for Marriage and Claremont Institute), a future case with strong facts, no procedural hurdles, and new legal arguments could pose a credible threat to Obergefell precedent.

Armenia Election Withstands Russia-Linked Disinformation Campaign

Armenian Prime Minister Nikol Pashinyan's pro-European Civil Contract party won nearly 50% of the vote in parliamentary elections despite an eight-month Russia-linked disinformation campaign (Matryoshka) that fabricated news reports, manipulated videos, and deployed bot networks accusing Pashinyan of corruption and crimes. The operation, part of Russia's broader Doppelganger influence campaign, cloned legitimate media outlets and amplified false narratives warning Armenia could face Ukraine-like consequences for strengthening ties with Europe. False bomb threats from foreign numbers and email addresses also disrupted polling stations. The European Union deployed a civilian mission to Armenia to help counter foreign disinformation.

Compliance Takeaways