PrivacySignal
Enforcement

Family says woman violated HIPAA, ‘weaponized’ info

DataBreaches.net · · International · Enforcement

A civil lawsuit filed in West Virginia alleges that a medical administrator named Sarah Gross repeatedly accessed a family's private health records without authorization over several years, then used that information against them in a personal family dispute. The plaintiffs, unnamed in the complaint, are suing Gross and West Virginia University Medical Corporation.

Why this matters: This is what insider access abuse actually looks like. Not a hacker, not a foreign actor — just someone with a login and a personal grudge. Medical records contain some of the most sensitive information people have, and healthcare workers routinely have access to far more than they need. When that access gets used as a weapon in a private dispute, the damage is personal and lasting. The employer here faces real questions too. Years of unauthorized access should not go undetected. If it does, the institution is part of the problem.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
The Guardian — Tech · · International

US schools and police warn about viral ‘Cat in the Hat’ trend after teens’ arrests

A social media trend using distorted or AI-generated images of the Cat in the Hat character has spread across the US, with some posts used to make threats against schools and students. Several teenagers have been arrested or charged in connection with the posts, prompting warnings from schools and law enforcement.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
WIRED — AI · · International

Meta Sued Over Training Data for Its AI and Face-Recognition Systems

A proposed class action lawsuit claims Meta scraped photos from Facebook and Instagram without permission to train its AI image-generation tools and develop an unreleased facial recognition feature called NameTag.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
The Guardian — Tech · · International

New Mexico lawyer fined for using AI-generated brief containing fabricated testimony

The New Mexico Supreme Court fined and held defense attorney Stephen Aarons in contempt after he submitted an appeal brief in a murder case that contained fabricated police testimony and invented witnesses generated by ChatGPT. Aarons said he used the AI tool to build what he described as a bulletproof summary, but did not verify the filing's accuracy before submitting it.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
EFF — Deeplinks · · International

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon introduced a new encryption feature for Ring cameras called Throw Away the Key Encryption, which shifts some control over video access toward users. Critics argue the approach still leaves Amazon holding temporary encryption keys, stopping well short of true end-to-end privacy protection.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
Information Commissioner's Office · · UK

ICO statement on its investigation into Police Scotland

The UK's Information Commissioner's Office has issued a statement regarding an investigation it opened into Police Scotland. No further details about the investigation's findings or scope are available from this disclosure.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →