← Carolina Clear Tech

Legal & Privacy Brief

2026-07-24

Listen to this brief (10:29)

Download MP3
Show Notes

Show Notes - 2026-07-24

Stories Covered

CVEs Referenced

CVE-2025-66376

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - July 24, 2026

Today: Aidvantage settles TCPA robocall claims for $3 million. Russian hackers exploit Zimbra webmail zero-click vulnerabilities to compromise NATO and Ukrainian targets. State Department imposes visa restrictions on cybercrime networks, while ICE's illegal Medicaid data sharing extends to Palantir contractor access.

Enforcement Actions

ICE Illegally Shared Medicaid Data with Palantir Contractor

ICE obtained Medicaid data from the Centers for Medicare and Medicaid Services without legal authorization in January 2026, targeting home addresses and ethnicities of millions to locate migrants for deportation. Court filings revealed ICE then shared this data with Palantir Technologies, which operates the ELITE app used to track noncitizen addresses. The data-sharing agreement violated HIPAA Privacy Rule protections. Democratic attorneys general from more than 20 states filed suit challenging the agreement.

U.S. Data Access Demands in African Health Agreements Raise Sovereignty Concerns

State Department negotiations conditioned more than $1 billion in global health aid to African nations on access to citizens' health data. Uganda's December 10 agreement grants the U.S. direct, real-time access to nine national health data systems for seven years, including electronic medical records, lab data, and community health worker systems. The agreements lack standard data protection language limiting collection scope and use, increasing exposure and commercialization risks. Zambia, Zimbabwe, and Ghana rejected initial deals.

State Department Imposes Visa Restrictions on Cyber Scammers

Secretary of State Marco Rubio announced visa restrictions for individuals involved in cybercrime networks and their immediate family members on July 23, targeting those responsible for cyberscams and sextortion. The policy implements President Trump's March executive order on cybercrime and fraud. The restrictions focus on Chinese transnational criminal groups operating scam centers in Southeast Asia, which cost Americans $10 billion in 2024 according to government estimates.

Litigation Updates

$3 Million Aidvantage TCPA Class Action Settlement

Aidvantage settled Telephone Consumer Protection Act class action claims for $3 million. The settlement covers recipients of unsolicited robocalls from the student loan servicer. No case number or jurisdictional details were provided in the announcement.

Nissan Class Action Alleges Failure to Protect Employee Data in Oracle Breach

A new class action lawsuit alleges Nissan North America failed to protect current and former employee personal information in a data breach involving Oracle systems. The complaint does not specify the breach date, scope of compromised records, or jurisdictional venue.

Google Faces Class Certification Bid Over Tax Data Tracking

Consumers are seeking federal court certification of nationwide and state classes in a privacy lawsuit alleging Google collected confidential tax return information without consent. Plaintiffs claim Google tracked tax data through its services. The motion for class certification is pending.

Judge Grants Summary Judgment to Amazon in Audible Auto-Enrollment Case

Amazon and Audible won summary judgment in a proposed class action alleging deceptive enrollment of consumers in paid Audible memberships after they obtained free audiobooks through Amazon. The court found no deceptive practices in the enrollment process.

Trump Petitions Supreme Court for Reconsideration in E. Jean Carroll Case

President Trump's petition for reconsideration of the Supreme Court's decision upholding the $5 million E. Jean Carroll verdict has been distributed to the justices for potential action on August 17. The petition challenges the 2nd Circuit's decision allowing testimony from other women alleging assault and the 2005 Access Hollywood tape. The Supreme Court has not granted a petition for reconsideration since 2018.

Privacy Developments

Russian Hackers Exploit Zimbra Webmail with Zero-Click Phishing

Federal agencies in the U.S., U.K., Europe, Australia, and New Zealand warned Thursday that Russian state-aligned group Laundry Bear has compromised governmental and commercial organizations through zero-click phishing targeting Zimbra Collaboration Suite webmail. The campaign exploits CVE-2025-66376, patched in November 2025, hiding malicious JavaScript in emails from compromised accounts that executes immediately upon opening. Hackers exfiltrated 90 days of emails, passwords, contact lists, two-factor authentication tokens, and passcodes. Targets include defense, transportation, and financial sectors in NATO states, Ukraine, CIS countries, and Africa.

Origin Energy Confirms Customer Data Breach in Australia

Australian energy company Origin Energy, serving nearly 5 million customers, confirmed Thursday that customer data was compromised in a security incident. Compromised data may include account information, last four digits of credit card numbers, last three digits of bank account numbers, names, addresses, and dates of birth. The company is working with independent cyber experts and authorities to determine the total number of impacted customers.

FAA Drone Waivers Enable Expansion of Aerial Surveillance

Over 1,000 public safety agencies received Federal Aviation Administration Part 91 waivers for drone-as-first-responder programs between April 2025 and February 2026, more than all waivers issued in the previous seven years combined. The waivers permit Beyond Visual Line of Sight autonomous drone operations using AI-based flight automation. Drone footage can be integrated with automated license plate reader networks and stored indefinitely. Deployments frequently occur for low-risk calls involving unhoused people, mental health concerns, and noise complaints.

Policy Changes

FTC Proposes Policy Limiting AI Chatbot Editorial Discretion

The FTC announced a proposed policy statement on July 1 titled "Suppression of Accuracy in Artificial Intelligence Systems," declaring AI developers "likely" commit false advertising when they steer model outputs toward objectives users don't expect. The policy requires "clear and conspicuous" disclosures when AI systems prioritize objectives other than pure accuracy. The proposal does not identify specific false advertisements or deceived consumers and does not address Supreme Court precedent in Brown v. Entertainment Merchants Association or Moody v. NetChoice protecting editorial discretion as First Amendment expression.

Senate Democrats Reintroduce Supreme Court Term Limits Bill

Senator Sheldon Whitehouse reintroduced legislation setting 18-year staggered term limits for new Supreme Court justices, with only the nine most junior justices ruling on cases. The bill is unlikely to pass while Republicans control the House, Senate, and White House. Whitehouse stated the bill aims to keep term limits "top of mind for the American public" rather than achieve immediate legislative outcomes.

OLC Opinion Interprets TikTok Ban Exceptions for Government Use

The Office of Legal Counsel issued an opinion permitting the Trump administration to use TikTok on government devices despite Senator Josh Hawley's law banning "the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited." The OLC concluded that ByteDance's 19.9% stake in the current joint venture does not constitute "ownership" under the statute and users' continued use of the same app does not make it a "successor application."

Compliance Takeaways