Reading view

There are new articles available, click to refresh the page.

FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices

The Federal Trade Commission, joined by Utah and California, by and through Los Angeles County Counsel, today sued Hims & Hers alleging that the telehealth provider shared consumers’ sensitive health information about medical conditions with third-party advertising platforms despite claiming its services maintain consumers’ privacy and deceives users about its billing and cancellation practices. In...

Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features

I think I missed this one, but you shouldn’t miss it, too. Thorin Klosowski of EFF writes: Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our...

Iowa, 41 other states to receive money from 23andMe settlement

Emery Glover reports: Iowa is now among 42 states that have reached a settlement with the genetics and biotech company, 23andMe. A lawsuit against 23andMe was filed in 2023 after a massive data breach that impacted nearly 7 million people, according to the Iowa Attorney General’s office. The breach reportedly exposed customers’ genetic ancestry information, personal information...

Plaintiffs’ Bar Revs Up Claims Under the Driver’s Privacy Protection Act

“License plate numbers themselves generally are not understood to be “personal information from a motor vehicle record” subject to the DPPA, but private companies using ALPR data may match license plates with DMV records to identify vehicle owners for parking, tolling, collection or enforcement-related notices, creating another use case in which DPPA risk may arise.”...

Memorial Healthcare Services Settles Pixel Litigation

Steve Alder writes: Memorial Healthcare Services, a nonprofit healthcare provider serving patients in Southern California, has agreed to settle a class action lawsuit over its use of pixels and other tracking, web analytics, and advertising technologies on its website. The tools are alleged to have been added to the website without the knowledge or consent...

Veradigm Loses Bid to Toss Suit Over Data Sharing With Google

Christopher Brown reports: Health-technology provider Veradigm Inc. must face a proposed class action alleging it shared patients’ health information with Google LLC without consent in violation of state and federal privacy law. The plaintiffs plausibly alleged that Veradigm disclosed their personal health information, and adequately pleaded claims under the Electronic Communications Privacy Act, the California Invasion of...

Hospital worker suspected of accessing Princess of Wales’s medical records to face prosecution

Russell Myers reports: A hospital worker at the private clinic where the Princess of Wales had abdominal surgery is set to face a criminal prosecution following an investigation into claims that the Princess’ medical records had allegedly been accessed by staff in 2024, it is understood. A total of three trusted employees, who worked at The...

Amazon’s Ring sued over “Familiar Faces” facial recognition feature

Greg Bensinger reports: Amazon was sued on Monday by a Virginia resident over what he said were privacy violations after the company’s Ring doorbell cameras at friends and ​family members’ homes collected and stored images of his face using facial recognition ‌software. The plaintiff, Charles Sigwalt, who is seeking class-action status, sued Amazon in federal...

Texas has sued Meta, WhatsApp over encryption privacy claims

A May 21, 2026 press release from Texas Attorney General Ken Paxton: Attorney General Ken Paxton filed suit against Meta Platforms Inc. and WhatsApp LLC (collectively “WhatsApp”) after the company misled consumers regarding the strength and scope of its privacy protections for its messaging app, WhatsApp. WhatsApp is widely marketed as a secure messaging service...

Privacy Websites break California privacy law at ‘industrial scale,’ survey finds

Tech companies like Google, Facebook and Microsoft are ignoring data controls mandated under California law, researchers say. By: Colin Lecher A new audit has found that websites across the internet may be failing to abide by California privacy law, ignoring a requirement to not track visitors who set a privacy control. The report, from researchers...

Healthcare AI Firm Sued Over Alleged Unlawful Disclosures of Genetic Data

Steve Alder reports: Tempus AI, a publicly traded healthcare artificial intelligence company, is facing multiple class action lawsuits over the alleged unauthorized collection and disclosure of genetic testing results, which were derived from genetic testing by Ambry Genetics Corporation (Ambry Genetics). Tempus AI used Ambry Genetics’ genetic database to train its AI models. Tempus AI...

Judge gives tentative OK to $56 million menstrual app privacy settlement

Margaret Attridge reports: A federal judge Thursday indicated he would grant preliminary approval to a proposed $56 million class action settlement over a lawsuit that accused period tracking app Flo of sharing users’ highly sensitive information with third parties, including Google. “I have to get rid of this thing. No one has gotten paid. This...

Ke: Eldoret hospital to pay Sh525,000 over patient data breach

There seem to be more news stories about data protection out of Kenya recently. This one appeared on CapitalFM: The Office of the Data Protection Commissioner (ODPC) has found St Luke’s Orthopaedic and Trauma Hospital liable for unlawfully disclosing a patient’s sensitive medical information and ordered it to pay Sh525,000 in compensation. In a ruling...

Californians sue over AI tool that records doctor visits

Cyrus Farivar reports: Several Californians sued Sutter Health and MemorialCare this week over allegations that an AI transcription tool was used to record them without their consent, in violation of state and federal law. The proposed class-action lawsuit, filed on Wednesday in federal court in San Francisco, states that, within the past six months, the plaintiffs received...

HK: Medical intern suspended at Princess Margaret Hospital over alleged social media patient data breach Source URL : Medical intern suspended at Princess Margaret Hospital over alleged social media patient data breach

The Standard reports: A medical intern at Princess Margaret Hospital has been suspended after allegedly posting photos containing patients’ information on a personal social media account, the Hospital Authority (HA) announced. The incident came to light after a complaint was filed on Friday, prompting the hospital to launch an immediate investigation. A spokesperson for the...

Platform liability after Russmedia: Italian DPA Fines Platform for Allowing Phone Number in Sex Work Ads Without Consent

Odia Kagan of FoxRothschild writes: The Italian Data Protection Authority (Garante) recently fined online classifieds platform Bakeca S.r.l. after an unknown user published two ads, including an explicit offer for sex work, listing the phone number of a person who had nothing to do with the ads and never consented to their publication. The decision,...
❌