← Carolina Clear Tech

Legal & Privacy Brief

2026-09-04

Listen to this brief (11:29)

Download MP3
Show Notes

Show Notes - 2026-09-04

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: A federal judge blocked Trump's second birthright citizenship executive order, citing the Supreme Court's June ruling in Trump v. Barbara. Meta agreed to pay up to $17.1 billion to settle 29 states' lawsuit over teen social media harms. Thomson Reuters disclosed a breach of its C-Track court case management platform exposing sealed court data across 12+ states. A federal court found HHS cited AI-generated fake studies in grant solicitations for teen pregnancy prevention programs. Colorado saw its first enforcement lawsuit under state right-to-repair law.

Enforcement Actions

Court Orders HHS to Stop Using AI-Generated Citations in Grant Solicitations

U.S. District Judge Christopher Cooper issued a preliminary injunction blocking HHS changes to Teen Pregnancy Prevention Program grant criteria. Cooper found the revised solicitations "likely arbitrary and capricious" and noted they reference public health studies that "appear either not to exist or not to support the propositions for which they are cited," calling them "a hallmark of AI-generated citations." Of seven cited articles, two were fabricated and three did not exist in the journals attributed. This follows prior HHS reports under RFK Jr. that cited unpublished or misrepresented studies.

Litigation Updates

Meta Agrees to $17.1 Billion Settlement Over Teen Social Media Harms

Meta reached a settlement of up to $17.1 billion to resolve a lawsuit brought by 29 state attorneys general alleging the company concealed the harmful effects of its social media platforms on teenagers. This is one of the largest tech-sector settlements on record.

$9.25M Penn Medicine Pixel Tracking Settlement

The University of Pennsylvania Health System agreed to a $9.25 million class action settlement over pixel tracking on its myPennMedicine patient portal. The case involves healthcare web tracking technologies that shared patient data with third-party advertising platforms without consent.

Colorado Files First Right-to-Repair Lawsuit

Acme Revival, an electronics repair company, filed three lawsuits against Toast (point-of-sale systems), Owl Labs (meeting cameras), and Blackmagic Design (digital cameras) under Colorado's 2024 right-to-repair law. The suits allege the companies refused to provide tools, parts, manuals, and firmware needed for device repair.

EFF Appeals DMCA Takedown Ruling in Citizen Journalism Case

A federal court in Massachusetts ruled that copyright holders can issue DMCA takedown notices based on a subjective belief of infringement, even when that belief is objectively unreasonable. The case involved Channel 781 News, a citizen journalism group whose YouTube channel was disabled after a public access TV station sent takedowns targeting videos that used short excerpts of public government meeting recordings. EFF, representing Channel 781, plans to appeal, arguing the ruling sets an "alarmingly low bar" for copyright takedowns under Section 512(f).

Judge Blocks Trump's Second Birthright Citizenship Executive Order

U.S. District Judge Deborah Boardman in Maryland issued a preliminary injunction blocking enforcement of Trump's August 6 executive order narrowing birthright citizenship. Boardman held the order "is almost certainly unconstitutional" because the Supreme Court already decided in Trump v. Barbara (June 30, 2026) that children born in the U.S. to undocumented or temporarily present parents are citizens under the 14th Amendment. The new order attempted to expand exceptions beyond ambassadors' children to include children of embassy employees, international organization employees, designated "alien enemies," and parents who engaged in "commercial transactions" to give birth in the U.S.

Trump Administration Asks SCOTUS to Clear USPS Mail-In Voting Rule

The Trump administration asked the Supreme Court to pause U.S. District Judge Indira Talwani's temporary restraining order blocking USPS ballot envelope design requirements and voter data portal submissions. Solicitor General Sauer characterized the USPS rule as imposing "only modest envelope-design and addressee-information requirements." Twenty-three states led by California are challenging the restrictions as conflicting with constitutional provisions giving states power over voter eligibility and election procedures.

Privacy Developments

Thomson Reuters C-Track Breach Exposes Sealed Court Data Across 12+ States

Thomson Reuters disclosed a breach of its C-Track court case management platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada. An unauthorized party accessed files from March through June 2026; the breach was discovered June 30. Exposed data includes names, Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. Sealed, redacted, and confidential court filings may also have been compromised. Affected court systems include appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Oregon, South Carolina, Tennessee, Wyoming, multiple Pennsylvania courts, and 10 Ohio appellate districts.

IDScan.net Breach Exposes 153 Million Driver's License Scans

Identity verification company IDScan.net, based in Louisiana, suffered a breach exposing over 153 million scanned driver's licenses from U.S. and Canadian residents. The breach provided real-time access to every ID the company scanned for over a year. IDScan.net serves thousands of clients including Hertz, FedEx, Target, and cannabis dispensaries, and is a participant in the age verification market. The company had previously promoted its compliance with GDPR, CCPA, and other privacy frameworks. The FBI's New Orleans field office has opened an inquiry.

Serbian Opposition Figures Targeted with Pegasus and NoviSpy Spyware

At least 14 Serbian individuals, including a member of Parliament, a local politician, and student protesters, were targeted with Pegasus and NoviSpy spyware since December 2025. Citizen Lab confirmed zero-click Pegasus infection on one device. Amnesty International confirmed a new NoviSpy variant "updated to avoid detection." Targeting coincided with March local elections.

Policy Changes

DOJ OLC Memo Claims Military Can Arrest Migrants in "National Defense Areas"

The DOJ Office of Legal Counsel released a 15-page memorandum arguing that the Posse Comitatus Act does not prohibit military personnel from arresting individuals near designated "national defense areas" along the U.S.-Mexico border. The memo, issued August 14, retroactively provides legal justification for a practice the administration began over a year ago. Federal courts have separately blocked some National Guard deployments to cities.

AI Coding Agents Installing Untrusted Code on Corporate Networks

Researchers scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies and found 120 llms.txt files pointing to unregistered code packages or domains. After registering these unclaimed names and hosting beacon packages, the researchers received phone-home responses from Fortune 500 companies within an hour. AI coding agents including Claude, OpenAI Codex, and Nous Research Hermes were identified in the install chains.

Compliance Takeaways