← Carolina Clear Tech

Legal & Privacy Brief

2026-09-12

Listen to this brief (11:15)

Download MP3
Show Notes

Show Notes - 2026-09-12

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: GEICO will pay $1.65 million to settle claims it failed to investigate inaccurate credit reports sent to LexisNexis. The Supreme Court dismissed an immigration detention case after New York's governor pardoned the petitioner. Florida banned license plate readers from state highways amid growing backlash against Flock Safety's surveillance network.

Enforcement Actions

$1.65M GEICO Credit Reporting Settlement

GEICO agreed to pay $1.65 million to resolve claims it failed to properly investigate and correct inaccurate insurance information reported to LexisNexis Risk Solutions. The settlement addresses violations of the Fair Credit Reporting Act's requirements for furnishers of consumer information to maintain accurate records and investigate disputes.

Highlands Oncology Group Data Breach Settlement

Highlands Oncology Group reached a class action settlement offering up to $4,250 for documented losses, $50 for class members without losses, and three years of medical data monitoring following a data breach affecting patient health information.

Florida DMV Breach Linked to Stolen Police Credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed a data breach after an international cybercriminal organization (ShinyHunters) obtained credentials improperly stored on a Plant City Police Department employee's personal device. The breach was discovered September 4, 2026.

Litigation Updates

Hims & Hers Health Website Tracking Class Action

Hims and Hers Health faces a class action alleging the company used web tracking technologies to gather and disclose consumers' sensitive health information to third parties without consent, raising HIPAA and state privacy law claims.

Venmo Users Sue PayPal Over Financial Data Disclosure

PayPal, operating as Venmo, faces a class action alleging the company shared private user financial transaction data with third parties without obtaining user consent, violating state privacy statutes and the company's own privacy policies.

Ram 2025 Truck Engine Defect Class Action

FCA US faces a class action alleging the company sold 2025 model year Ram 1500 trucks while knowing the vehicles contained a dangerous engine defect, raising product liability and consumer protection claims.

Regulatory Guidance

Florida Bans License Plate Readers on State Highways

Florida's Department of Transportation revoked previous permits for automated license plate reader cameras on state highways and will no longer issue new permits within its jurisdiction. Governor Ron DeSantis stated the use of automated license plate readers has "gotten out of control." The ban applies only to state-level infrastructure; local jurisdictions may continue operating cameras on municipal roads.

California Digital Literacy and Cybersecurity Education Laws (AB 2071, AB 2298)

Governor Newsom signed AB 2071 and AB 2298, requiring California schools to integrate digital wellness into middle and high school health classes and add cybersecurity concepts to recommended curricula. AB 2071 teaches students to identify unhealthy tech habits, protect personal safety, and evaluate digital content including AI-generated media for credibility and bias. AB 2298 adds cybersecurity instruction on safeguarding personal data from online threats.

Privacy Developments

Amazon Ring's "Throw Away the Key Encryption" Falls Short of End-to-End Protection

Amazon introduced "Throw Away the Key Encryption" (TAKE) for Ring cameras, claiming improved privacy by deleting encryption keys after 24 hours. EFF analysis found the system allows Ring to access unencrypted video for 24 hours to process features like smart alerts and video search, making it "barely different from encryption at rest where the server holds the keys." Account recovery keys are stored in cameras by default, and law enforcement could compel mass searches across cameras for specific terms, then seize cameras to decrypt account backups and video content.

AI-Enhanced Business Email Compromise Scams

Microsoft detected a campaign of over one million fraudulent emails in early August targeting accounts payable departments with AI-generated executive impersonation and fake invoices. The campaign impersonated CEOs and ServiceNow, requesting fraudulent payments of nearly $50,000. Microsoft found indicators "consistent with AI-assisted template development" including extensive HTML comments, structured section labeling, and uniform template construction. 88% of targets are American organizations.

Anthropic Detects Russia-Linked Spies Using Claude AI in Hacking Operations

Anthropic detected and disrupted Midnight Blizzard (APT29, attributed to Russia's Foreign Intelligence Service) using its Claude AI tool in cyber-espionage campaigns targeting over 20 government, intelligence, diplomatic and defense organizations. The group compromised hotel Wi-Fi providers, targeted Ukrainian government and military entities, stole proprietary drone software development kits, and used Claude to reverse-engineer drone vision systems and bypass security detections. Anthropic also observed ShinyHunters affiliates using AI to move from stolen developer tokens to full cloud administrative access in three hours.

Policy Changes

Supreme Court Dismisses Immigration Detention Bond Hearing Case (Genalo v. Black)

The Supreme Court dismissed Genalo v. Black, which had been scheduled for October argument on whether noncitizens detained under 8 U.S.C. Section 1226(c) have a right to bond hearings during lengthy detention. The case became moot after New York Governor Kathy Hochul pardoned the petitioner's assault conviction, removing the basis for his mandatory detention. The Solicitor General indicated the Justice Department aims to bring the issue back to the Court in a new petition.

DHS Reduces Nevada Non-Citizen Voter Claims from 16,000 to 185

DHS initially claimed it found 16,000 noncitizens on Nevada's voter rolls but subsequently acknowledged only 185 voter IDs as "confident" matches requiring manual review, a 99% false positive rate. DHS declined to provide Nevada with supporting data for the 185 alleged matches and continues to claim 14,000 voters need additional review and another 6,000 are "higher confidence" matches pending review, despite the massive discrepancy.

Ukrainian Conti Ransomware Member Sentenced to Four Years

Oleksii Lytvynenko, 44, received a four-year U.S. prison sentence for his role as a hacker and developer for the Conti ransomware operation. Conti attacked organizations in 47 U.S. states and 31 countries between 2020 and 2022, extracting over $150 million in ransoms. Forensic evidence showed Lytvynenko continued ransomware operations after Conti's shutdown in 2022.

Compliance Takeaways