Get tomorrow's brief in your inbox
Today: LifeStance Health and Mount Sinai Medical Center reach class action settlements totaling $3.2 million over privacy violations. SafePal, Trezor, and Coinkite hardware wallet breaches expose nearly 40,000 crypto holders to physical threats, while Heights Finance leaks financial data for 750,000 customers. California courts break media advertising models by allowing age discrimination claims under the Unruh Act, and a federal judge blocks TikTok, YouTube, and Meta from obtaining preliminary injunction against California's SB 976 addictive feeds law.
$3.02 Million LifeStance Health Group Website Tracking Settlement
LifeStance Health Group agreed to a $3.03 million class action settlement over claims it violated patients' privacy rights by using tracking pixels on its website. The settlement addresses allegations that the mental health services provider improperly shared patient data with third parties through website analytics tools without adequate consent.
$220,000 Mount Sinai Medical Center Data Breach Settlement
Mount Sinai Medical Center of Florida reached a $220,000 class action settlement over a data privacy breach. The settlement provides cash payments and medical data monitoring services to affected patients whose protected health information was compromised.
Shopify Class Action Survives Motion to Dismiss
A California federal judge rejected Shopify's bid to dismiss a proposed class action alleging the company secretly collected consumers' personal and payment information through its checkout platform without consent. The court found sufficient allegations that Shopify violated California privacy law by gathering data beyond what was necessary for transaction processing.
Federal Court Allows California Age Discrimination Claims Against Tech Platforms
A federal district court in San Jose denied preliminary injunctions from Meta, YouTube, and TikTok seeking to block California's SB 976, the "Protecting Our Kids from Social Media Addiction Act." The law defines algorithmic recommendation systems as "addictive feeds" and requires parental consent for minors, with default one-hour daily limits. The court ruled that blocking speech (content moderation) is First Amendment protected, but algorithmic recommendation is not, relying on language from the Supreme Court's Moody v. NetChoice footnote that declined to address the constitutional status of recommendation algorithms.
California Appeals Court Extends Unruh Act to Media Advertising
Another California court followed the Liapes v. Facebook precedent, allowing Unruh Act age discrimination claims to proceed against Google for not serving certain ads to users based on age. The Copia Institute filed an amicus brief arguing the decision violates First Amendment protections for editorial discretion and Section 230 protections for platform intermediation of third-party content. The decision creates conflict with California laws requiring platforms to restrict certain content based on age.
Supreme Court Denies Trump Rehearing in Carroll Case
The Supreme Court denied President Trump's petition for rehearing in Trump v. Carroll, leaving intact a $5 million verdict for sexual assault and defamation. Trump had argued that evidence including testimony from other women and the Access Hollywood tape should have been excluded. A separate petition regarding an $83 million award in a related Carroll case remains pending, raising questions about whether presidential statements constitute protected official acts.
MyDr Healthcare Breach Exposes 19 Million in Poland
Polish authorities are investigating a cyberattack on MyDr, a healthcare software provider, that potentially exposed data belonging to 19 million people and 12,000 medical facilities. Hackers obtained unauthorized access to historical data through April 2024. Poland's e-Health Center is replacing digital certificates used by medical systems to connect to the P1 nationwide electronic health platform as a precautionary measure, though no evidence suggests the certificates were compromised.
SafePal Crypto Wallet Breach Affects 40,000 Customers
SafePal confirmed a data breach affecting 40,000 customers who placed orders between March 2, 2025 and April 11, 2026. Stolen information includes names, email addresses, shipping addresses, phone numbers, and purchase details. The breach resulted from a flaw in an order-tracking plugin that allowed unauthorized access to customer order information. This is the third hardware wallet manufacturer breach in the past month, following similar incidents at Trezor and Coinkite. CertiK reports a 33 percent year-over-year increase in cryptocurrency "wrench attacks" (violent, in-person robberies), with 52 incidents and $124 million in losses in the first half of 2026.
Heights Finance Breach Exposes 750,000 Financial Records
Debt consolidation lender Heights Finance disclosed a May 7 breach of a cloud-based platform that exposed financial information and Social Security numbers for 734,828 customers. Stolen data includes banking information (account numbers, routing numbers), government IDs (Social Security numbers, tax IDs, driver's license numbers), and customer service interaction records. The company operates across 11 states including Alabama, Tennessee, Georgia, Texas, and South Carolina.
Unlimited Technology Systems Breach Affects 3.8 Million Patients
More than 3.8 million patients are being notified that their personal and protected health information may have been exposed in a data breach at Unlimited Technology Systems, a healthcare technology provider. Limited details are available about the scope or cause of the breach.
Flock Safety Implements Access Controls After Stalking Incidents
Following a Washington Post report documenting 46 cases of police officers improperly using Flock Safety's license plate camera network to stalk women, CEO Garrett Langley announced new security measures. Changes include recommended 7-day data retention (previously 30 days), new offense filtering, mandatory audit assistance, proactive lockouts, required case codes, and mandatory multi-factor authentication. However, the 7-day retention period is only "recommended," not required. Flock's network adds approximately 20 billion license plate images monthly.
White House Deputizes Private Companies for Offensive Cyber Operations
On August 12, 2026, President Trump issued a National Security Presidential Memorandum establishing a program allowing vetted U.S. companies to conduct government-authorized offensive cyber operations against foreign transnational criminal organizations. The program permits two operation types: Cyber Surveillance Operations (covert unauthorized access for intelligence collection) and Cyber Effects Operations (manipulation, disruption, or destruction of information systems). Participating Companies must receive written government approval for each operation and act under DOJ and DHS supervision. The memorandum requires compliance with the Computer Fraud and Abuse Act and tracks the CFAA's exemption for "lawfully authorized investigative, protective, or intelligence activity" under 18 U.S.C. § 1030(f). DOJ and DHS must establish operating procedures by October 12, 2026.
Department of Justice OLC Opinion on Posse Comitatus Act
The DOJ Office of Legal Counsel issued a memorandum stating the Posse Comitatus Act does not prevent military personnel from making arrests near designated "national defense areas" such as portions of the U.S.-Mexico border. This represents a significant expansion of permissible military involvement in domestic law enforcement.
Healthcare website operators: Audit all tracking pixels, analytics scripts, and third-party tools immediately. The LifeStance settlement demonstrates regulators and plaintiffs are targeting HIPAA-covered entities for unauthorized data sharing through website technologies.
Financial services using cloud platforms: Conduct access control audits and implement multi-factor authentication by September 30, 2026. The Heights Finance breach shows cloud platform vulnerabilities remain a critical risk vector for sensitive financial data.
California platforms with recommendation algorithms: Begin implementing age verification, parental consent workflows, and time-limit controls for SB 976 compliance. The federal court's denial of preliminary injunctions signals the law will take effect as written.
Law enforcement agencies with ALPR systems: Establish mandatory audit trails and independent oversight mechanisms immediately. Document all searches with required case codes and implement automated alerts for unusual access patterns following the Flock Safety stalking incidents.
Companies handling cryptocurrency customer data: Enhance physical security guidance for customers and prepare incident response plans for "wrench attack" risks. The 33 percent increase in violent crypto theft incidents requires heightened security awareness programs.