← Carolina Clear Tech

Legal & Privacy Brief

2026-09-02

Listen to this brief (11:57)

Download MP3
Show Notes

Show Notes - 2026-09-02

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - September 2, 2026

Today: The Trump administration faces a lawsuit over its illegal plan to build a master citizenship database that threatens voter access ahead of the midterms. Meta agrees to a $17 billion settlement with 52 state AGs embedding age estimation technology and severe restrictions on teen users. A federal judge rules the Department of Defense unlawfully retaliated against Anthropic for refusing to allow its AI technology to be used for mass surveillance of US persons.

Enforcement Actions

CRST Expedited Minimum Wage Settlement

CRST Expedited agreed to pay $14.5 million to settle claims it violated California labor laws by failing to pay truck drivers minimum wage and other compensation. The settlement resolves allegations that the company misclassified drivers and failed to comply with state wage and hour requirements.

Cone Health Pixel Tracking Settlement

Cone Health agreed to a $1.76 million settlement to resolve claims it used pixel tracking technology to collect and share patient information without consent. The settlement addresses allegations that the healthcare provider embedded third-party tracking pixels on patient portals and public-facing websites, transmitting protected health information to technology companies without authorization.

Nutex Health Data Breach and Extortion

Healthcare facilities operator Nutex disclosed that hackers stole patient and employee data during an August cyberattack and are now extorting the company with threats to publish the information externally. Nutex operates 27 hospital and outpatient facilities in 12 states and earned $427.2 million in the first half of 2026. The Gentlemen ransomware gang claimed responsibility for the attack. A class action complaint has been filed in Texas on behalf of individuals whose personally identifiable information and protected health information was accessed.

Litigation Updates

Saks TCPA Class Action

Saks.com faces a class action lawsuit alleging it violated federal law by sending unsolicited telemarketing text messages to consumers. The complaint alleges violations of the Telephone Consumer Protection Act, which requires prior express written consent before sending marketing texts.

American Express Credit Reporting Lawsuit

American Express National Bank faces a credit reporting lawsuit alleging it continued reporting two settled accounts as unpaid charged-off debts after accepting full settlement payments from the plaintiff. The complaint alleges violations of the Fair Credit Reporting Act.

Regulatory Guidance

White House Cyber Surveillance and Disruption Program

The White House unveiled a program to authorize private-sector companies to conduct cyber surveillance and disruption operations against foreign cyber-enabled criminal organizations (CE-TCOs). The program defines CE-TCOs as foreign groups conducting cyber-enabled crime against the US government, US persons, or US interests, and not wholly operated under a foreign government's direction. The memorandum presumes a foreign group is not state-connected unless clear intelligence establishes such a connection. Critical legal complications include surveillance protections for US persons and difficulty accurately targeting foreign criminal organizations.

FSB Warning on AI Cyber Risk to Financial System

The Financial Stability Board warned G20 ministers and central bank governors that cyber risk from frontier AI poses the "most immediate concern" to the global financial system. FSB chair Andrew Bailey called on financial institutions and technology providers to prepare for severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies. The FSB stressed the importance of robust response and recovery capabilities, including the ability to restore critical systems and data from "bare metal" following a significant cyber incident.

Privacy Developments

EPIC Sues to Block Trump Citizenship Database

EPIC filed a lawsuit in the US District Court for the District of Maryland challenging the Trump administration's plan to build a master database of US citizens for voter eligibility verification. The March 31, 2026 executive order directed DHS, the Social Security Administration, and the State Department to create "State Citizenship Lists" of confirmed citizens in all 50 states. The complaint alleges violations of the Social Security Act, the Privacy Act, the Administrative Procedure Act, and the constitutional separation of powers. The administration is compelling states to cross-reference voter rolls with the federal lists within 60 days, despite DHS acknowledging the lists will contain widespread inaccuracies. The administration is threatening to investigate and prosecute states and election officials who "issue Federal ballots to individuals not eligible to vote."

Meta $17 Billion Settlement Embeds Age Verification Technology

Meta reached a $17 billion settlement with 52 state attorneys general that embeds age assurance technology and age gates into Facebook and Instagram. Within one year, Meta must apply age assurance methods to each user in the settling states. The settlement places severe restrictions on teen users (ages 13-15) that can only be modified by parents and only in exchange for giving parents extensive information about their online community and usage. The settlement requires Meta to collect, analyze, and retain more information about teen users. The settlement empowers state AGs to enforce Meta's content restrictions on "age inappropriate content."

Comcast Xfinity WiFi Motion Detection Feature

Comcast added motion detection as a feature to its Xfinity wireless routers, sending push notifications to users when motion is detected near connected devices. Comcast's support page states that information generated by WiFi Motion may be shared with third parties without further notice in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena.

LG and Samsung Smart Monitors Use ACR Tracking

LG and Samsung smart monitors use the same ad-serving operating systems as their smart TVs, including automatic content recognition (ACR) technology that tracks user activity. LG monitors have installed McAfee pop-up ads onto connected computers through an app called LG Monitor App Installer, distributed via Windows Update under the cover of driver updates.

Policy Changes

California A.B. 1709 Regulates Addictive Social Media Design

The California Legislature passed A.B. 1709, which prohibits social media platforms from making addictive design features available to users under 16 years old. The bill originally proposed a complete ban on youth social media access but was amended to preserve youth access while regulating platform design. EPIC worked with lawmakers to amend the bill to focus on prohibiting addictive design features rather than age-gating access.

Compliance Takeaways