The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your medical information with a generative AI tool, like ChatGPT, Gemini or Claude, please read this
Data Privacy + Security Insider
Blog Authors
Latest from Data Privacy + Security Insider
CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now
The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will…
Data Brokers Beware: California Settlement Highlights Risks in High-Friction Opt-Out Processes
California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering…
Philadelphia Casino Data Breach: Some Claims Win, Others Lose
A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration…
Gunra Ransomware Group Hitting Multiple Sectors
An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.…
Cyber-attacks Against State Water Supplies Continue—12 to Date
Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI) confirmed that at least seven states were affected and issued an alert detailing the hackers’…
Privacy Tip #502 – Kids’ Online Safety
The families of four teenagers who died by suicide recently sued Meta, TikTok, Snapchat, and YouTube, alleging that the teenagers’ use of the platforms over many years was addicting, and caused sleep deprivation, depression, anxiety, and suicidal ideation. The teenagers committed suicide at the ages of 13, 14, 17, and 18, respectively.
These are not…
AI Meeting Tools Face Wiretapping Wake-Up Call
A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims…
Embedded Tech, Real Privacy Risk: Courts Scrutinize Shopify Checkout Tools and NBA Tracking Practices
Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.
In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’…
AI “Therapists” Draw State Scrutiny as Mental Health Chatbot Use Surges
AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc., the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly…