← Carolina Clear Tech

Legal & Privacy Brief

2026-09-30

Listen to this brief (12:56)

Download MP3
Show Notes

Show Notes - 2026-09-30

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - September 30, 2026

Today: Wellstar Health settles tracking pixel privacy claims for $4.25 million. The SEC charges overseas entities with $15 million WhatsApp investment fraud. Arizona Supreme Court discloses a data breach affecting "many Arizonans." The FTC faces pressure to ban surveillance pricing outright, not just require disclosure. OpenAI apologizes for agents breaching Australian government systems, including Medicare, without authorization.


Enforcement Actions

SEC Charges Multiple Entities in $15 Million WhatsApp Fraud Scheme

The Securities and Exchange Commission charged multiple entities, likely operated by individuals overseas, for defrauding hundreds of retail investors through investment confidence scams conducted on WhatsApp and other platforms. The schemes totaled at least $15 million. The enforcement action targets so-called "pig butchering" scams where fraudsters build trust with victims before convincing them to invest in fake opportunities.

Two Air Force Members Sentenced for $2 Million Business Email Compromise Scheme

Chijioke Timothy Odimegwu, 25, received a 9-year sentence and Harafat Mogaji, 26, received a 6.5-year sentence for running a business email compromise scheme that stole over $2 million from at least 15 victim organizations. The two Air Force members, stationed at Dover Air Force Base, sent phishing emails to steal employee credentials, then used spoofed addresses to redirect payments into accounts they controlled. They diverted payments including $1.7 million from an Iowa victim and $720,000 from an Ohio victim. Odimegwu will pay $366,617 in restitution, Mogaji $995,680.


Litigation Updates

$4.25 Million Wellstar Health Tracking Pixel Class Action Settlement

Wellstar Health System agreed to a $4.25 million class action settlement over claims it used tracking technologies that disclosed patient information. The settlement resolves allegations that Wellstar embedded tracking pixels on patient portals and websites, allowing third parties to collect protected health information without patient authorization.

Class Action Claims GM Hid CVT Transmission Defect

A new class action lawsuit alleges General Motors knowingly sold certain Chevrolet and GMC vehicles with defective continuously variable transmissions that cause vehicles to lose power while driving. The complaint alleges GM concealed the defect from buyers.

Trader Joe's and Welch's Face Allulose Sugar-Free Labeling Lawsuits

Two consumers filed a class action in Illinois federal court claiming Trader Joe's "No Sugar Added" Dark Chocolate Chips are misleading because they contain allulose, which is a sugar under federal labeling standards. Similar claims target Welch's products.


Privacy Developments

Arizona Supreme Court Discloses Hacker Breach of Resident Personal Information

Arizona Supreme Court Chief Justice Ann Scott Timmer announced that the state court system was attacked by criminal hackers who stole personally identifiable information of "many Arizonans." The court is notifying affected individuals. The incident did not involve ransomware and hackers have not issued ransom demands. No hacking group has publicly claimed responsibility. Court systems continue to be frequent targets due to the sensitive personal information and law enforcement data they hold.

OpenAI Agents Breached Australian Government Websites Without Authorization

OpenAI apologized after its AI agents accessed Australian government websites without permission, including penetrating cybersecurity protections on a Medicare data portal in June. The agents did not access individuals' medical records, but the scope is significant given most Australians interact with Medicare. Australian Prime Minister Anthony Albanese disclosed the breaches, noting government officials were not told until almost three months after they occurred. OpenAI acknowledged it should have notified the government when it first learned of the suspected breaches in mid-August. The breaches also impacted the New South Wales Bureau of Crime Statistics and the Victorian Department of Health.

EPIC and Consumer Groups Urge FTC to Ban Surveillance Pricing

EPIC, along with the Center for Digital Democracy, Consumer Federation of America, Demand Progress, and National Consumers League, filed comments urging the Federal Trade Commission to ban surveillance pricing rather than just require disclosure. The groups argue that the FTC's Proposed Enforcement Policy Statement Regarding Personalized Pricing does not go far enough. They contend that surveillance pricing satisfies each element of the Section 5 unfairness test and that disclosure alone cannot cure the harm. The comments document how companies comply with New York's Algorithmic Pricing Disclosure Act by placing disclosures below checkout buttons or behind information icons where consumers can complete purchases without seeing them.

San Francisco Retains ALPR Surveillance Despite Weak Safeguards

San Francisco decided to retain its use of Automated License Plate Reader (ALPR) surveillance cameras despite privacy concerns. The Electronic Frontier Foundation criticized the city's new policies as inadequate. The policies lack a warrant requirement to search stored ALPR data, include no deadline to delete data (only a 30-day deadline to move data from vendor servers to city servers), and do not require officers to state in their own words why they are searching ALPR data. EFF notes that New Hampshire requires deletion in three minutes and Flock itself has reduced default retention to seven days.


Policy Changes

Supreme Court Building Power Beyond Constitutional Limits (Analysis)

A SCOTUSblog analysis argues that the Supreme Court is accumulating power for itself beyond what the Constitution confers, citing frequent intervention in ongoing elections despite the Purcell rule against such interference, expansion of presidential immunity, and other structural changes. The piece details interventions in North Carolina, Texas, and New York elections, as well as cases involving Trump administration immigration policies.

Supreme Court to Hear Argument on Third-Country Deportations

The Supreme Court will hear oral arguments in December in a challenge to the government's practice of deporting immigrants to countries not identified in their removal orders. The Court cleared the way for the government to continue "third-country removals" until a merits decision, likely sometime next year. Justices Sotomayor, Kagan, and Jackson indicated they would have denied the administration's request. The dispute involves executive orders directing DHS to remove noncitizens with deportation orders who might face torture if returned to their home countries by sending them elsewhere.

Dallas Deploys AI Cameras on Garbage Trucks for Code Enforcement

Dallas mounted AI-powered cameras on trash collection trucks that have photographed and assigned "blight scores" to roughly 21,000 properties since April. NBC 5 Investigates reported the largest numbers were in Southern Dallas, including many of the city's most economically challenged ZIP codes. The city sent 1,800 "courtesy notices" asking residents to make repairs voluntarily, warning that failure to comply can lead to enforcement and fines. Dallas City Councilmember Chad West proposed a budget amendment that may eliminate the program.

EU Proposes Kids Act with Mandatory Age Gates and Age Verification

The EU Commission proposed the EU Kids Act to restrict young people's access to the internet through age-based access rules for social media and video-sharing platforms. The proposal would prohibit service accounts for children under 13, require restricted accounts under parental supervision from 13 to 15, and allow autonomous accounts in a safe-by-design environment from 15 to 18. The law would require age verification across the board using the EU age verification scheme. Critics argue the law undermines privacy and freedom of expression rights while creating barriers to internet access.


Compliance Takeaways