PrivacySignal
Healthcare

EPIC Urges 7th Circuit to Uphold Wiretap Act to Protect Private Communications Containing Sensitive Health Data

EPIC · · US Federal · Healthcare Privacy

EPIC filed an amicus brief in the Seventh Circuit asking the court to treat Edward-Elmhurst Health's use of Meta Pixel on its patient portal as a violation of the federal Wiretap Act. The health system embedded tracking code that automatically sent patient data from its MyChart portal to Meta and other third parties.

Why this matters: When you log into a hospital's patient portal, you expect your information to stay medical. You do not expect it to be quietly handed to Meta. Health systems have been embedding tracking code that does exactly that, often without patients knowing. The Wiretap Act is a serious federal law with real teeth. If courts apply it here, hospitals face meaningful consequences for surveillance-grade data sharing. If they do not, patient portals become one more place where your most sensitive information is harvested and sold.

Who should care: Healthcare professionals · Privacy officers · Compliance · Cybersecurity

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

Healthcare
HIPAA Journal · · US Federal

Fairchild Medical Center & Boone Health Settle Pixel Lawsuits

Fairchild Medical Center and Boone Health have reached settlements over lawsuits alleging that tracking pixels on their websites or patient portals transmitted patient data to third parties without authorization.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
HIPAA Journal · · US Federal

OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions

The HHS Office for Civil Rights has released guidance addressing when states may use substance use disorder records to verify whether Medicaid recipients qualify for exemptions from community engagement requirements. The guidance clarifies the conditions under which such sensitive health records can lawfully be accessed for eligibility purposes.

Who should care: Healthcare professionals · Privacy officers · Compliance · Lawyers

#healthcare#regulation Read original →
Healthcare
HIPAA Journal · · US Federal

Data Breaches Announced by Saber Healthcare & Buchalter

Saber Healthcare, an Ohio-based care provider, and Buchalter, a California law firm, have each announced separate data breaches. Both organizations handle sensitive personal and legal information, making the incidents significant for the individuals they serve.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare Read original →
Healthcare
The Guardian — Privacy · · International

More than 44,000 file legal objections to Palantir NHS platform handling their data

More than 44,000 people in the UK have filed formal legal objections to NHS England's Federated Data Platform, which is built on Palantir technology, demanding it be blocked from processing their personal health data. The campaign has grown alongside broader criticism of Palantir's ties to Israeli military operations and its work supporting ICE deportation efforts in the United States.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai#privacy Read original →
Healthcare
The Guardian — Tech · · International

RFK Jr outlines expansive vision for collecting US health data at Maha event

Health Secretary Robert F. Kennedy Jr. called for broad collection and sharing of Americans' medical and lifestyle data — from doctor visits to exercise habits — to be analyzed by AI and made available to government and independent researchers, framing it as a response to chronic disease.

Who should care: Healthcare professionals · Privacy officers · Compliance · General readers · AI governance · Policy

#healthcare#ai Read original →
Healthcare Critical
HIPAA Journal · · US Federal

Citrix Patches Actively Exploited NetScaler ADC & NetScaler Gateway Vulnerabilities

Citrix has released patches for two critical zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are being actively exploited in the wild. The flaws affect widely used network access and application delivery products common in enterprise and healthcare environments.

Who should care: Healthcare professionals · Privacy officers · Compliance

#healthcare#security Read original →