Why Are You Getting This?


You signed up to receive The Privacy Professor Tips, or initiated contact to stay in touch with Rebecca and/or Privacy & Security Brainiacs (PSB) and consented to receive the Tips. Please read our Privacy Notice & Communication Info at the bottom of this message for more information. You may unsubscribe from there as well.  

You Can't Have Freedom If You Don't Have Privacy

In the United States we are celebrating Independence Day on July 4th. This is when we also acknowledge the sacrifices made, by all parts of society, to win and to maintain our freedoms. Such sacrifices are also made in other countries throughout the world, and the lessons apply everywhere.


Those of us passionate about the importance of freedom, in a society increasingly enveloping all citizens and residents within technologies that can be quite useful, but also quite invasive, believe privacy does not have to be one of the sacrifices we make. Whether the tradeoff is for safety, convenience, entertainment, or some other benefit, there are ways to achieve that end without sacrificing privacy.


We can have privacy if the will and dedication to privacy exists. Those establishing such potentially privacy-invasive practices and products must actively demonstrate their dedication to privacy protections.

 

As Supreme Court Justice Louis Brandais famously wrote in 1928:



"The makers of our Constitution understood the need to secure conditions favorable to the pursuit of happiness, and the protections guaranteed by this are much broader in scope, and include the right to life and an inviolate personality -- the right to be left alone -- the most comprehensive of rights and the right most valued by civilized men. The principle underlying the Fourth and Fifth Amendments is protection against invasions of the sanctities of a man's home and privacies of life."


If you celebrate Independence Day on July 4th, or any other day of freedom wherever in the world you are, think about how your freedoms, and those of your family and friends, are supported and realized through your privacy. And how important rights to privacy are to your, and everyone’s, life, liberty, and freedom.


Read on to learn more about the trade-offs between privacy and other initiatives that often require, or simply result in, privacy invasions. Along with a  many other important issues that involve collecting huge amounts of our personal data without consent from us that are facing us today. For example, physical safety tools, online surveillance technologies, and artificial intelligence (AI) tools sucking up huge amounts of personal data.

 

We had over a dozen readers tell us they really like the “NOTEs” we included with news items, and also providing a longer list of news items. Voices spoken are voices heard! So, we are providing more of those in this issue. We also have received several “thanks” messages for the healthcare and HIPAA questions and answers; from both those working in the industry, as well as those who are patients and insureds…which is everyone. We will be sure to include at least two healthcare security and privacy topics going forward, starting with this issue.


Also, please read to the end where we provide some information about some brand-new online courses we will soon be offering. We are also now excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for the organizations providing them. See more at the end.

We freely distribute, since 2005, the Privacy Professor Tips monthly publication to help both businesses and individuals, of all ages, to help identify risks throughout their daily lives, and to help them know how to prevent security incidents, privacy breaches, and to keep from being a victim of scams. Thank you for reading!


We would love to hear from you!

Did you find the tips we provided useful? Did you like this issue? Do you have questions for us to answer? Please let us know at info@privacysecuritybrainiacs.com.

Rebecca

Image from Freepik

July Tips of the Month


  • News You May Have Missed
  • Privacy & Security Questions and Tips 
  • Where to Find the Privacy Professor

News You May Have Missed

We are finding more unique news stories to share with you than ever before. We also share news items that we believe are important for most folks to know, but that often do not get much mention in traditional news, or even in security and privacy news outlets.

 

Here are just a few of the 100+ news stories we discovered throughout the past month that provide a wide range of interesting security and privacy related news. These news items demonstrate that such types of risks exist basically anywhere in the world, and that everyone needs awareness.

 

This month we list 51 news items. We are also trying something new. We are grouping them into three broad categories: “Of broad interest,” “Privacy in businesses, governments, and other organizations,” and “Laws, legal issues, and lawsuits about or significantly involving privacy and/or security issues.” Many readers will find all the items of interest, but for those of you who prefer one or two specific categories, this will help you find your news items of interest more quickly. Within each category the items are in no particular order. And by popular request are also now including a “NOTE” with most of the situations to provide some advice or additional insights.

 

Do you have interesting, unusual, bizarre or odd stories involving security and privacy? Some of the most interesting, bizarre or odd stories are in local news! Or questions about any of the notes we included for the stories we listed this month? Let us know!

Image from Pexels

Of Broad Interest…

1.   Lucille Ball Found Out She Was Pregnant When Her Medical Records Were Leaked During Radio Broadcast. A broadcaster had "been tipped off by a medical lab informant before the Arnazes themselves had learned the news," according to a new book. NOTE: This was long before the HIPAA Privacy Rule went into effect in 2003, and the HIPAA Security Rule in 2005. What is interesting is how much additional health information was included in this June 2025 article; HIPAA covers protected health information (PHI) for 50 years after death. Perhaps it was provided in the book, and the source was not Lucille Ball’s healthcare provider. This is an excellent HIPAA compliance use case!


2.   Minnesota Shooting Renews Calls For Online Privacy Laws. Police found in the murder’s notebook information on 45 Minnesota state and federal officials, along with their home addresses, and a large amount of other personal data from 11 “people search” websites such as Intelius, Spokeo and TruePeopleSearch.com, that offer users the ability to look up the addresses, phone numbers and other personal information about generally anyone for a small fee. NOTE: Even if you request such sites to remove your personal data, which most will do, they continue collecting personal data about all people possible, so your profile will be rebuilt in most cases. You will need to regularly remove your personal information on each site.


3.   After 12 Years of Failed Attempts, the Man Who Lost His Hard Drive Containing $742M in Bitcoin Finally Ends His Search. A Newport man’s quest to recover $742 million in Bitcoin from a landfill has captivated the world for over a decade. Legal battles, high-tech plans, and a lost fortune buried under tons of waste make this a tale like no other. Now, a documentary brings his relentless journey to light. NOTE: If any of you watch this documentary, please let us know your review! There are many data security and privacy practices and issues involved with this situation.

Image from Pexels

4.   Indianola, Iowa, Police Officer Charged With Stalking Woman. “Keller continuously contacted the woman and drove by her house. The complaint, filed by a Carlisle police sergeant, says Keller let himself into the victim's house on Sunday which scared her.” NOTE: Another use case for privacy and security safeguards. Individuals abusing their access to personal data is increasing throughout the U.S. as well as in other parts of the world. This highlights the need for all organizations that possess or access personal data to have strong safeguards to prevent unauthorized access to personal data, and also to monitor those with access with regard to the days, times and frequencies they are doing so.


5.   Fraudulent Text Messages Target Recipients With False Claims of Unpaid Tolls or Traffic Violations. The Iowa Department of Transportation (IA DoT) is warning consumers of recent text scams that are occurring in Iowa and across the country. See an image of one of these messages below. Here is a short video the IA DoT made about it. NOTE: These text messages are occurring throughout all the U.S. states and territories.  Similar text messages are also being sent in other countries. Let your friends and family members know about this if you think they could be susceptible to this scam. Stay informed, and stay alert!

Image source: The Iowa Department of Transportation.

6.   Amazon Would Like You To Hand Over Your Palm Print, Please. What to know about the tech giant’s growing biometric business. NOTE: Be aware that any type of data can be compromised (stolen, used in unauthorized ways, etc.).  Biometric data is extremely valuable to hackers, criminals, and other types of entities. Why? Because unlike a password, it cannot be changed. So your biometric data can be used forever by others for reasons that you may not want, or in ways that could harm you. Always confirm the strongest security and privacy protections possible are used by organizations collecting this data.


7.   Barbie Maker Mattel And OpenAI Partner To Develop AI-Powered Toys. However, there are significant privacy, security and safety concerns about the use of AI in toys.  NOTE: AI toys collect and analyze data about children's interactions. Be sure to check for how this information will be used and protected. And consider the impacts for how personal data collected, such as voice recordings and interactions, could be compromised and misused. Then decide if you want to take these risks with a child’s information, and impacts it may have on them.


8.   Meta Found A New Way To Violate Your Privacy. “Here’s what you can do. Even hardened digital privacy veterans said they were stunned by Meta’s tactics.” “Researchers found that apps from Meta and Yandex, a technology company that originated in Russia, circumvented privacy protections in Android devices in ways that allowed their apps to secretly track people as they browsed the web.” NOTE: The best way to help prevent these circumventions is using a privacy browser, such as DuckDuckGo or Brave, to name a couple of options.


9.   Meta AI Users Confide On Sex, God And Trump. Some Don’t Know It’s Public. Some People Are Unwittingly Posting Their Private And Sometimes Mortifying Conversations With The Meta AI Chatbot To The World. “We’ve seen a lot of examples of people sending very, very personal information to AI therapist chatbots or saying very intimate things to chatbots in other settings,” said Calli Schroeder, a senior counsel at the Electronic Privacy Information Center. “I think many people assume there’s some baseline level of confidentiality there. There’s not. Everything you submit to an AI system at bare minimum goes to the company that’s hosting the AI.” "The company’s share button doesn’t explicitly tell users where their conversations with Meta AI will be posted and what other people will be able to see — a fact that appeared to confuse some users about the new app." "There's no way to disable Meta AI from either Facebook or Instagram in either the browser version or the app version." NOTE: If you are using, or thinking of using, Meta AI, please be aware of this!


Image from Pexels

10.   Police In Britain Use Controversial AI Tool That Looks At People’s Sex Lives And Beliefs. Senior MPs and privacy campaigners have expressed alarm at the deployment of Palantir’s AI-powered crime-fighting software with access to sensitive personal information. “The system is already in use by the Bedfordshire force, with a similar one understood to be under development by Leicestershire Police. It could be used to target “persons suspected of having committed or being about to commit a criminal offence.”” “The police memo states that Nectar will “require and be used to access” 11 different types of “special category information” held on an unspecified number of individuals. This information includes “race”, “political opinions”, “sex life”, “religion”, “philosophical beliefs”, “trade union membership” and “health”. It is understood that as many as 80 separate data sources, ranging from traffic camera data to intelligence files, are available to be processed by the software.” NOTE: Besides including this information about suspects, it will also include information on victims of crime, witnesses, and vulnerable individuals including children. This data, as described and shown in the memo image below, contains very sensitive personal data. And the associated individuals are not consenting to have this vast array of personal data used. How will this information be secured? Who will have access to it? So many others. This activity should have a strict security and privacy program surrounding the use. The harms to those whose information is involved from misuse of the personal data could be significant, last for a lifetime, and also put individuals at physical risk of harm. 


Source: An internal police memo obtained by The iNews Paper (in the link provided) and Liberty Investigates

11.   AI of Murdered Chris Pelkey Makes His Own Impact Statement at Sentencing (a court 1st), with Judge. NOTE: This is another privacy after death issue. Should AI be used to have a dead person say something they really did not say? Could this have been handled in a way that would be authentic to what the deceased actually had said while he was alive about these types of situations? From a privacy perspective, this is something that people should include within their will, and indicate specific individuals who they allow to make such statements on their behalf. Or, to prohibit the creation of such AI representations if they don’t believe they will convey their true beliefs and feelings.


12.   Airlines Don’t Want You to Know They Sold Your Flight Data to DHS. A contract obtained by 404 Media shows that an airline-owned data broker forbids the feds from revealing it sold them detailed passenger data. “A data broker owned by the country’s major airlines, including Delta, American Airlines, and United, collected US travelers’ domestic flight records, sold access to them to Customs and Border Protection (CBP), and then as part of the contract told CBP to not reveal where the data came from, according to internal CBP documents obtained by 404 Media. The data includes passenger names, their full flight itineraries, and financial details. CBP, a part of the Department of Homeland Security (DHS), says it needs this data to support state and local police to track people of interest’s air travel across the country.” NOTE: This is an example of how organizations can and are collecting personal data by default without consent through the use of data brokers.


13.   Visitors To Colorado Historic Sites Urged To Report “Negative” Information About America, Per Order. Signage asking for visitor feedback went up recently at the Amache and Sand Creek Massacre historic sites, triggering concerns that difficult history could be sanitized. NOTE: In addition to concerns about changing the details of history, there are also concerns about what seems like a request to actively surveil others and report those who do not convey historical facts that are not “happy” stories about America

Image from Pexels

14.   Hackers Force 100-Year-Old German Napkin Manufacturer Into Insolvency. “On May 19th, all the printers at the facility began printing ransom notes. All systems, including PCs and laptops, were paralyzed. Fasana could not execute orders of over €250,000 on May 20th alone, according to a report by Kölner Stadt-Anzeiger, a daily newspaper published in Cologne. Production has been halted entirely, employees did not receive their May salaries on time, and massive revenue losses, accumulating to €2 million (USD $2,347,307.64) over two weeks, have pushed the company overboard. It has filed for insolvency. The company, which was acquired by Powerparc in March, is now looking for another buyer.” NOTE: This is an example of how poor security practices and/or insider mistakes, or malicious activities, can literally shut down the business forever.


15.   Fraudulent Text Messages Target Recipients With False Claims of Unpaid Tolls or Traffic Violations. “The Iowa DOT does not send out fee collection reminders via text and will never text customers asking for private or financial information. Any payment requests from the Iowa DOT are made through personal transaction, via physical mail, or through an online transaction initiated by the customer. In addition, the Iowa DOT does not collect tolls on any of their roads or bridges.” NOTE: These same types of text scams are occurring throughout all the U.S. states and territories, as well as within other countries.


16.   Scanning Technology Is Coming To Detect Child Porn. “Police Have A New Tool To Find Sexually Explicit Images Of Children. Experts say it can be useful but may also be ripe for abuse. "A common technology used by law enforcement agencies now says it can help fight fire with fire, by using new software to speed up the identification of child exploitation images from accused people’s phones and computers." "There’s also a risk of errors in using technology to hunt for child abuse images. Many internet companies scan users’ online photos, videos and messages to identify sexual abuse imagery. Those scans are considered essential in fighting child exploitation, but at times they have flagged innocent parents as child abusers."” NOTE: In addition to errors, the increasing use of deepfakes to create porn images of people of all ages, and send them to people who then have them on their computing devices, sometimes in spam filters or in unread emails, texts, etc., also creates an additional risk of false accusations.


17.   16 Billion Password Data Breach Hits Apple, Google, Facebook And More. “Currently, nearly all major platforms have been affected by the breach, including Apple accounts (formerly Apple IDs), Gmail, Facebook accounts and GitHub as well as instant messaging platforms like Telegram and both commercial and government platform portals.” NOTE: Most people have accounts on at least one of these platforms. Read this article for some good advice to keep the crooks who now have your information from using it to commit identity theft, or do other crimes, using your personal data.


18.   AI System Resorts To Blackmail If Told It Will Be Removed. “Anthropic says testing of its new system revealed it is sometimes willing to pursue "extremely harmful actions" such as attempting to blackmail engineers who say they will remove it.” NOTE: Ask AI product manufacturers and/or retailers if the AI has been programmed and thoroughly tested to keep from “going rogue” and doing this and similar actions.


19.   An Experimental New Dating Site Matches Singles Based on Their Browser Histories. Browser Dating users upload their 5,000 most recent searches, which are turned into a “browsing personality profile" by AI. “The site scans up to 5,000 recent browser searches or goes back as far as search history is stored, which could be several years.” NOTE: Do you want to send your browsing data history to an unknown entity, who will then monetize and share it with an unlimited number of other entities for their own personal gain?


20.   These Iowans Learned Their Mom's Fertility Doctor Is Their Father. Now They Want Justice. “A collection of health issues drove Bright [one of the Iowans] to take a DNA test with 23andMe, and later Ancestry.com.” Her research led her to the University of Iowa, “the incubator for the world’s first sperm bank and a pioneer for innovation in fertility care.” In a news photo, “Bright saw her face” on one of the sperm bank leader’s face; who turned out to be her biological father. NOTE: Many issues in this article highlight how privacy rights often must be balanced with relatives whose health risks must also be considered. 


21.   Computer-Vision Research Is Hiding Its Role In Creating ‘Big Brother’ Technologies. Technologies that can interpret imagery have many potential applications. An innovative study of papers and patents in the field suggests one use case that overrides the others: human surveillance. NOTE: You may be asked to pay for this report.


22.   From Menu to Malware: How Innocent Scans Lead to Quishing Attacks. Public places become ideal locations for malicious code drops. Cafés, libraries, gyms, event spaces—all host QR codes daily. Because the codes often live on replaceable media like stickers or printouts, it's easy for a malicious actor to swap them.

Image from U.S. National Park Service

23.   Meta Is Reportedly Planning to Release New AI Smart Glasses With Oakley and Prada. "The glasses will be able to take photos and videos, make calls and send text messages through voice commands, livestream content, and play music, just like the Ray-Ban Metas. They will also have AI capabilities, so users can ask questions through a "Hey Meta" voice command." NOTE: These create some significant security risks; e.g., creating a pathway into businesses if the glasses are digitally connected to your network. Also privacy risks; e.g., capturing sensitive and personal visual and audio information unbeknownst to those in the vicinity, violating HIPAA, GLBA, IL BIPA, GDPR, and a page-long list of other laws and regulations. Businesses need rules and policies for the use of these and other smart devices within their full digital ecosystem.




Privacy In Businesses, Governments, And Other Organizations…

24.   DoD Employee Prints Hundreds of Classified Documents and Gets Sentenced to Prison. The now ex-employee “routinely printed documents to which he had access, often at the end of the work day… 256 individual documents totaling more than 3400 pages were printed since his hire” in mid-2023. NOTE: For workforce members with access to highly sensitive information, having policies in place to do daily, possibly random, bag checks for such information when leaving the premises could have identified this physical documentation exfiltration.


25.   AI Use at Work Has Nearly Doubled in Two Years. The use of AI at work is accelerating. In the past two years, the percentage of U.S. employees who say they have used AI in their role a few times a year or more has nearly doubled, from 21% to 40%. Frequent AI use (a few times a week or more) has also nearly doubled, from 11% to 19% since Gallup’s first measure in 2023. Daily use has doubled in the past 12 months alone, from 4% to 8%. NOTE: There are significant privacy and legal risks if such use involves personal data and intellectual property.


26.   AI Agents Are Getting Better at Writing Code—and Hacking It as Well. One of the best bug-hunters in the world is an AI tool called Xbow, just one of many signs of the coming age of cybersecurity automation. NOTE: While AI can be a useful tool to *help* find vulnerabilities, it is necessary to also have humans be bug hunters as well, since many vulnerabilities require knowledge of the context of the environment within which the application is running to find as many vulnerabilities as possible.


27.   From Malware To Deepfakes, Generative AI Is Transforming Attacks. Generative AI is even helping hackers trick open-source developers into using malicious code, according to Gartner. NOTE: Make sure your IT developers and contracted development workforce members have had training to spot and not fall for these types of techniques.


28.   FDA Playbook Engineers Safety Into Medical Device Manufacturing. "The FDA includes detailed examples of risk assessment matrices, threat modeling tools, and response planning templates...meant to guide organizations in both assessing potential vulnerabilities and responding to incidents quickly and effectively." NOTE: Let your workforce members, family and friends who fill such roles know about this risk.


29.   Scattered Spider Swarms Insurance Sector with Targeted Cyber Attacks, Google Warns. The notorious threat group known for targeting major retailers and employing advanced social engineering techniques, has reportedly shifted its focus to the U.S. insurance industry. NOTE: Make sure your workforce members have had training to spot and not fall for these types of techniques.

Image from Freepik

30.   Employers Are Drowning In AI-Generated Job Applications, With LinkedIn Now Processing 11,000 Submissions Per Minute—A 45 Percent Surge From Last Year, According To New Data Reported By The New York Times. “Fraud poses an increasing threat. In January, the Justice Department announced indictments in a scheme to place North Korean nationals in remote IT roles at US companies. Research firm Gartner says that fake identity cases are growing rapidly, with the company estimating that by 2028, about 1 in 4 job applicants could be fraudulent.  As we have previously reported, security researchers have also discovered that AI systems can hide invisible text in applications, potentially allowing candidates to game screening systems using prompt injections in ways human reviewers can't detect.” NOTE: Let your workforce members, family and friends who fill such hiring roles know about this risk.


31.   Beware Of Fake SonicWall VPN App That Steals Users' Credentials. A good reminder not to download apps from non-vendor sites. “Users would visit the spoofed sites, and then download what they believed to be the most recent version of the SonicWall VPN app. But in reality, they got a fake NetExtender that, when executed, stole all their information related to the VPN configuration — username, password, domain, and more — and sent it to an attacker-controlled remote server.” NOTE: This could happen to any service or product vendor. Let your workforce members, family and friends who fill such roles know about this risk.


32.   Israel–Iran Conflict Escalates in Cyberspace: Banks and Crypto Hit, Internet Cut. “On the same day, major U.S. cybersecurity groups—including the IT‑ISAC and Food & Ag‑ISAC—issued advisories warning that Iranian-affiliated threat actors may retaliate globally, targeting American companies across sectors like energy, finance, healthcare, and logistics. The alerts urge CISOs to elevate monitoring and reinforce incident response protocols in light of heightened geopolitical risk.” NOTE: Share this news with your IT security areas to make sure they are aware of the heightened risks, and can take appropriate actions to defend against them.


33.   Backpack Betrayal: Missile Defense Employee Busted Smuggling Classified Documents. “An employee of the Missile Defense Agency, allegedly sanitized classified documents by snipping away details she considered sensitive and then placed them into her backpack to walk them out of a secure facility.” NOTE: Could a similar situation happen at your organization? What controls and safeguards do you have in places to stop such situations?


34.   Trump Executive Order Alters Biden-Era Cybersecurity Regulations. The “SUSTAINING SELECT EFFORTS TO STRENGTHEN THE NATION’S CYBERSECURITY AND AMENDING EXECUTIVE ORDER 13694 AND EXECUTIVE ORDER 14144” is located here. The “Fact Sheet: President Donald J. Trump Reprioritizes Cybersecurity Efforts to Protect America” is located here.


35.   ‘It’s a Heist’: Real Federal Auditors Are Horrified by DOGE. WIRED talked to actual federal auditors about how government auditing works—and how DOGE is doing the opposite. “Two federal auditors with years of experience, who have both worked on financial and technical audits for the government, say that DOGE’s actions are the furthest thing from what an actual audit looks like. Both asked to speak on the condition of anonymity because they weren’t permitted to speak to the press.” NOTE: Rebecca was an IT Auditor early in her career, and has maintained her Certified Information Systems Auditor (CISA) certification since then through doing hundreds of audits, include some in U.S. government agencies. Just from verifiable and objective news reports concerning the methods, she agrees that many factors, such as timing and quotes from DOGE, do not support long-held and updated certified IT audit standards, which creates significant privacy and data security problems.


36.   Edward “Big Balls” Coristine’s placement at the SSA comes after a White House official told WIRED on Tuesday that the 19-year-old had resigned from his position in government. “A 19-year-old high school graduate who worked at Musk’s Neuralink for several months, Coristine has gone by the handle “Big Balls” online and joined the government with no prior experience. He has also founded a company called Tesla.Sexy LLC in 2021 and worked for a startup known for hiring black hat hackers; he was reportedly fired after being suspected of leaking internal information.”


37.   Trump Administration Gives Personal Data Of Immigrant Medicaid Enrollees to Deportation Officials. “Health Secretary Robert F. Kennedy Jr. ordered the dataset handed over to the Department of Homeland Security (DHS), the emails show. Officials at the Centers for Medicare and Medicaid Services were given just 54 minutes on Tuesday to comply with the directive. The dataset includes the information of people living in California, Illinois, Washington state and Washington, D.C.” NOTE: Despite the article heading, the health data of *all* those enrolled in Medicare and Medicaid in California, Illinois, Washington state and Washington, D.C. were given to DHS.

Image from Pexels

Laws, Legal Issues, And Lawsuits About Or Significantly Involving Privacy And/Or Security Issues…

38.   Iowa Supreme Court Upholds 2023 Law, Says Police Can Now Search Trash Without Warrants. NOTE: See the Questions and Answers section below for a reader question we are answering about this news item.


39.   Texas Judge Throws Out Biden Rule Protecting Medical Privacy on Abortion. The HIPAA decision seemed like it had opened the floodgates for law enforcement to use patient records to investigate any type of reproductive care. NOTE: However, given the June 27, 2025 ruling by the U.S. Supreme Court that individual judges lack the authority to grant nationwide injunctions, and per our legal expert’s analysis, the Texas judge’s ruling does not change the HIPAA law protecting reproductive data, a subset of all types of PHI, outside of Texas. Nor does it change other state laws where privacy laws are in place that provide such protections.


40.   23andMe Customers Did Not Expect Their DNA Data Would Be Sold, Lawsuit Claims. The genetic-testing company, which collected DNA data from users, is for sale in bankruptcy court. Now, 27 states and the District of Columbia oppose selling the data without express consent. NOTE: See the Questions and Answers section below for a reader question we are answering about this news item.


41.   Credit Union’s Lawsuit Against Fiserv Is A Test For Cybersecurity Liability. The credit union claims that Fiserv's online banking platform was so riddled with vulnerabilities it exposed its members to possible identity theft.


42.   Please Do Your Best Not to Appear in the “AI Hallucination Database.” “As illustrated by the ever-increasing number of cases in which lawyers, many of whom are quite intelligent themselves, have gotten in trouble for submitting the legal work of certain alleged artificial intelligences to courts around the world…According to the database, these cases are being reported almost every day at this point.” NOTE: As of June 28, there were 161 cases from around the world listed, and associated penalties, as applied. The highest to date shown is USD $31,100. We suggest showing this to your legal counsel and/or business management.


43.   New York Passes Novel Law Requiring Safeguards for AI Companions. Scheduled to come into effect on November 5, 2025, the law requires operators of AI companions to implement safety measures to detect and address users’ expression of suicidal ideation or self-harm and to regularly disclose to users that they are not communicating with a human.

Image from Freepik

44.   Health Tech Startup Alleges Doximity Used Prompt Injection to Steal AI Trade Secrets. “The complaint, filed on June 20 by Quinn Emanuel, alleges that Doximity engineers posed as doctors to manipulate OpenEvidence’s generative AI system into revealing proprietary code.” NOTE: If your organization, in any industry, codes, maintains or uses AI systems, this would be a good article to show to your IT area that is responsible for such systems.


45.   Supreme Court Upholds Texas Law Aimed At Blocking Minors From Seeing Online Porn. “The group said the law puts an unfair free-speech burden on adults by requiring them to submit personal information that could be vulnerable to hacking or tracking. It agreed, though, that children under 18 shouldn’t be seeing porn.” NOTE: We also agree children should not be viewing porn. However, our research shows that the age verification tools being used have significant vulnerabilities throughout the full online data cycle through which personal data is transmitted, creating significant risks that personal data from children, and adults, using these systems can easily be collected and used for identity theft and other types of crimes.


46.   In Lawsuit Over Teen’s Death, Judge Rejects Arguments That AI Chatbots Have Free Speech Rights. “The developers behind Character.AI are seeking to dismiss a lawsuit alleging the company’s chatbots pushed a teenage boy to kill himself.” NOTE: Expect to see many more of these types of lawsuits claiming AI rights to emerge in the coming years.


47.   U.S. Supreme Court Rules In Favor Of Texas Death Row Inmate Pushing For DNA Evidence Tests. Ruben Gutierrez is challenging the constitutionality of a state law that restricts death row inmates from seeking tests that he says will prove he’s not a murderer.


48.   NC Pathology Lab Patient Drops Data Breach Class Action. A North Carolina woman walked away Thursday from a putative class action that alleged a pathology practice failed to safeguard 235,000 patients' private data.


49.   A Federal Judge On June 6 Allowed Some Claims To Survive In A Class Action That Accuses Google Of Deliberately Tracking, Collecting And Monetizing Third-Party Private Health Information From Health Care Websites For Advertising Purposes.


50.   Cops Who Attended ‘Stop The Steal’ Rally Ask US Supreme Court To Keep Their Names Out Of The News. Using “John Doe” pseudonyms, they sued over whether the investigation into their activities should be made public. The Washington State Supreme Court ruled in February that they can be identified and that they haven’t shown that public release of their names violates their right to privacy. The state supreme court denied reconsideration earlier this month and lawyers for the four officers submitted a petition to the U.S. Supreme Court, asking that the names remain protected during their legal challenge.


51.   Tesla Moves To Block City Of Austin From Releasing Robotaxi Information. “It has asked a federal judge to prohibit NHTSA [National Highway Traffic Safety Administration] from releasing data about crashes related to the use of Full Self Driving and Autopilot systems. Also, it is pressuring the city of Austin not to disclose information about the robotaxi trial.”

Image from Pexels

Check out our Privacy & Security Brainiacs blog page for more unique security and privacy news items. Have you run across any surprising, odd, offbeat or bizarre security and/or privacy news? Please let us know! We may include it in an upcoming issue.

Privacy & Security Questions and Tips

Rebecca answers hot-topic questions from Tips readers

July 2025

We continue to receive a wide variety of questions about security and privacy. Questions about current hot topics in society, and increasingly more about healthcare privacy and security. Thank you for sending them in! This month in addition to our Question of the Month we’ve included five additional questions.

 

Are the answers interesting and/or useful to you? Please let us know! Keep your questions coming!

Image from Freepik.

Question of the Month:



Q1: Do you have any recommendations for actions the general public, businesses, and other organizations should take for the new law that was recently passed in Iowa about law enforcement not needing to obtain consent to search trash placed for pickup by garbage trucks?

A1:


Great question! Here is the article referenced by the reader: Iowa Supreme Court upholds 2023 law, says police can now search trash without warrants. While this is specific to Iowa, these same types of laws also exist in many other states, and in many other countries throughout the world.

 

While the majority of current privacy considerations and discussions deal with digital contexts, we must never forget about the centuries’ old physical situations, for they still, and will always, exist, along with the associated privacy risks.

 

Shift this scenario to your business's disposal activities.

 

Do you have protections in place to keep all types of dumpster divers and trash trollers from accessing personal data, intellectual property, and other confidential information?

 

Below is an excerpt from the previously referenced article, but I encourage you to read the full article for more context.

 

"Iowa Supreme Court upholds 2023 law, says police can now search trash without warrants. In 2021, a divided Supreme Court found the Iowa Constitution protects a residents' privacy interest in their garbage, even when out on the curb, breaking with federal courts in their interpretation of the corresponding parts of the U.S. Constitution. In response, Iowa legislators passed a 2023 law stating that Iowans have "no reasonable expectation of privacy in garbage placed outside of the person’s residence for waste collection in a publicly accessible area." In 2023, under the auspices of that law, Des Moines police followed up on a tip about suspected drug trafficking to search the trash of Charles Amble and John Mandracchia, finding evidence that resulted in drug charges. The two men challenged the constitutionality of the 2023 law, and the district court sided with them, holding that the Legislature cannot supersede the Iowa Supreme Court's interpretation of the state Constitution."

(Somewhat) Quick Hits:


Here are five more questions, most of which we are answering at a comparatively high level. We provide more in-depth information and associated details about these topics in separate blog posts, videos on our YouTube channel, in infographics and e-books, LinkedIn posts to our business page, and within our online training and awareness courses.

Image from FreePik

Q2: Isn’t the 23andMe data covered by HIPAA?


A2:


HIPAA establishes security, privacy, breach notice and other obligations for healthcare covered entities (CEs) and their business associates (BAs). CEs include healthcare providers (hospitals, clinics, doctors, etc.), healthcare plans (health insurers, health insurance plans funded by employers, etc.), and healthcare clearinghouses (billing services, repricing companies, community health management information systems, community health information systems, etc.).


23andMe is not a HIPAA CE because it is a direct-to-consumer company rather than a traditional healthcare provider, health plan, or healthcare clearinghouse using PHI to support healthcare treatment, payment or operations (TPO). If a HIPAA CE hired 23andMe to use their services or products to support TPO for their organization, then then in that particular situation 23andMe would be a BA and would need to comply with HIPAA. But not in the situations where consumers have purchased products and services directly from 23andMe. So generally, the answer to if 23anMe data is covered by HIPAA is, “no.”


That said, the genetic information 23andMe collects are subject to other state and federal regulations related to genetic data and privacy, as well as other laws outside of the U.S. In addition to genetic data, 23andMe also has a wide range of legal requirements for all the other personal information they also have about each of their customers.

Q3: What is the big deal about other people getting our DNA data? What can they do with it; clone someone? LOL!



A3:


Actually, it is a big deal, because unlike other types of personal identifiers and authentication data that can be changed after breaches, your DNA (and other biometric data) can never be changed. So, once your DNA data is breached, you’re breached for life. And that DNA that is identifying you in increasingly more locations can then be used to authenticate crooks to get into all those accounts and files that require such identification matching.


This is true not only for identity matching and authentication, but also for other purposes.


In 2012, as part of a research study I did for a private client, I purchased a National Geographic DNA Ancestry Kit to determine the associated privacy risks for that product.


My then 12-year-old son with an astute understanding of privacy saw me looking at it and said to me, “Mom! That’s a privacy risk!”


I was so proud and happy to know that he was concerned about my privacy.


Then he followed up his statement with, “Don’t violate my privacy by giving them your DNA!”


I was even more proud he so quickly understood that 50% of his DNA is the same as my DNA, which could be used in many ways that could impact not only my life, but also his life. For example, besides discovering new brothers, sisters and other relatives you may never have thought even existed, DNA could be used by health insurance companies to determine your insurance premium, or to deny you (or your children, siblings, parents, etc.) insurance. Or, to deny you loans and mortgages. Or to deny or accept people to schools and universities. Or, to make you…and your children, siblings, parents, etc.…. suspects for crimes, when the match is significant enough. And likely many more ways as time goes on.


Many different studies show that 36% to 96% of DNA analysis businesses routinely share their customers’ data with other entities such as the FBI and other government agencies, law enforcement, private clients, and more. Generally, all of them will share the data with a court order.


This highlights the fact that when an organization shares an individual’s DNA, they are actually sharing a family tree of DNA when they use these services from a DNA business, a business promotion, service, benefit, prize, or other reason.


There are so many potential privacy, as well as physical safety, harms associated with sharing what is literally a non-replaceable personal identifier.


Harms have already occurred through such sharing, including false arrests and imprisonments, cancelled health insurance, rejected school applications, broken family relationships, and more.


Customers of such DNA analysis businesses should be very concerned, as much as my own middle-school son was.


A breach of one person’s DNA, and other biological data, from a business could have negative repercussions not only to their business, but also for the associated individuals and generations of their relatives; past, present and future. Not to mention the legal violations, lawsuits, etc.

Image from Pexels

Q4: I’m responsible for security, privacy and HIPAA compliance at a healthcare clinic. What are your thoughts on using an in-office shredder to destroy PHI versus using a contracted shredding service? And, what about the disposal of the shredded paper containing PHI?


A4:


An onsite shredder is a great option! The key would be to use a cross-cut shredder that creates tiny enough pieces that it would be virtually impossible to reconstruct into a readable form. Once tiny, pieces of hardcopy imperceptible information are created by the shredder, then you would be able to put them into your regular trash. I recommend that you include within your HIPAA compliance documentation that you confirmed the pieces were not intelligible and would be virtually impossible to reconstruct. I suggest you even take a photo to provide evidence if any auditors or regulators express doubt.

 

I also suggest you ensure that there is no image saved in storage or memory by the shredder device prior to shredding. I’ve seen some shredders that have such capability, and they are typically enabled by default.

Image from FreePik

Q5: I live in the U.S. Recently there was a movie being filmed in my city, at a hospital. Does HIPAA allow movie-makers to enter patient areas of hospitals without prior written authorization?

 

A5:


No. Healthcare providers cannot invite or allow media personnel, including film crews, into treatment or other areas of their facilities where patients’ PHI will be accessible in written, electronic, oral, visual, audio, or other form, or otherwise make PHI accessible to the media, without prior written authorization from each individual who is or will be in the area or whose PHI otherwise will be accessible to the media. There are very limited circumstances where healthcare providers may disclose PHI to members of the media without a prior authorization signed by each of the associated individuals.

 

It is not sufficient for a healthcare provider to request or require media personnel to mask the identities of patients (using techniques such as blurring, pixelation, voice alteration software, etc.) for whom an authorization was not obtained, because HIPAA does not allow media access to the patients’ PHI, absent an authorization, in the first place. Additionally, the healthcare provider must ensure that reasonable safeguards are in place to protect against impermissible disclosures, and to limit incidental disclosures of other PHI that may be in the area but for which an authorization has not been obtained.     

 

There are extremely limited situations in which HIPAA allows CEs to disclose limited PHI to the media without obtaining a HIPAA authorization. For example, when seeking the media’s help to identify or locate the family of an unidentified and incapacitated patient in its care.  

 

HIPAA does not require health care providers to prevent members of the media from entering public areas of their facilities, such as public waiting areas or areas where the public enters or exits the facility. 

 

If CEs use third parties to produce training videos or public relations materials on the provider’s behalf protections must be in place. If patients will be identified by the provider and interviewed by a film crew, or if PHI might be accessible during filming or otherwise disclosed, the CE must enter into a HIPAA BA agreement with the film crew acting as a BA, which obligates the film crew to comply with all applicable HIPAA requirements. 


Q6: I am on the security and privacy team at a small health insurance company in the U.S. I would appreciate you resolving a disagreement at our business office. Our new boss said that under HIPAA a “limited data set” is the same thing as “de-identified PHI.” I’m pretty sure it is not. Am I right?

 

A6:


Janis, you can say with full confidence that under HIPAA, a limited data set (LDS) is *not* the same as de-identified PHI.

 

An LDS is PHI that *excludes* all of the following direct identifiers of the individual or of relatives, employers, or household members of the individual:

1.   Names

2.   Postal address information, other than town or city, State, and zip code

3.   Telephone numbers

4.   Fax numbers

5.   Electronic mail addresses

6.   Social Security numbers

7.   Medical record numbers

8.   Health-plan beneficiary numbers

9.   Account numbers

10. Certificate and license numbers

11. Vehicle identifiers and serial numbers, including license plate numbers

12. Device identifiers and serial numbers

13. Web Universal Resource Locators (URLs)

14. Internet Protocol (IP) address numbers

15. Biometric identifies including fingerprints and voice prints

16. Full-face photographic images and any comparable image

 

Such data can be very useful for health research and other activities. An LDS is *STILL PHI*! And, as such, must still be protected as required by HIPAA, and must only be shared after a Data Use Agreement (DUA) establishing the requirements has been executed with the party receiving the LDS.

 

In stark contrast, de-identified data has all 16 of the items listed above removed, *in addition to* the following:

1.   Dates. Generally, elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date

of death; and all ages over 89 and all elements of dates (including year)

indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older.


2.   Geographic Information. Generally all geographic subdivisions

smaller than a State, including street address, city, county, precinct, zip

code, and their equivalent geocodes, except for the initial three digits of a

zip code.


3.   Any other unique identifying number, characteristic, or code, provided they are not listed as direct identifiers, and the CE does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information.



After PHI is appropriately de-identified so that there is no way to translate it to identify the associated individuals, it is no longer PHI.

 

However, AI is making this simplistic de-identification method harder to accomplish, so simply removing the 19 specific types of items listed previously may not be sufficient to avoid having the data re-identified, based upon the context within which it is used. So the other option under HIPAA, in short, is having a statistician with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information to not be individually identifiable, by applying proven methods to determine that the information cannot be reasonably re-identified. These types of statistical assurances support HIPAA risk management requirements, and will likely need to be used more often in the coming months and years as AI, quantum computing, and other emerging technologies are used more often.

Send us any questions you have. And, keep reading the monthly Privacy Professor Tips!

Check It Out!

A quick reminder that we recently (in May) published our brand new online learning course, HIPAA Basics for Business Associates. Our clients are telling us our courses contain more valuable information, real-life use cases and examples, and supplemental materials that they continue to use to support their business after training, than any of the other HIPAA security and privacy courses they have seen or used. Check it out! We have more courses we will be publishing this month and next as well.

 

In May we published a new HIPAA Basics for Business Associates course. It includes information, guidance and real-life examples not found in other courses. Other courses will be published this month (July).

 

We are also excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for some such organizations. Get in touch with us for the details!

 

See some security and privacy tools to take with you while traveling in our 8-page “Protecting Privacy and Security While Traveling” list.

 

What topics would you like to see us create videos, and more formal online courses, for? Let us know!

 

Have questions about our education offerings? Contact us!

Where to Find The Privacy Professor

From https://www.isaca.org/training-and-events/online-training/virtual-summits/assessing-privacy-risks-and-implementing-governance/agenda

Rebecca delivered a talk at the ISACA, June 18, 2025, Virtual Summit, “Privacy Governance for Third Parties: Tales from the Trenches of Real-Life Experiences.” Available now for viewing!

The Privacy Professor | Website

Privacy & Security Brainiacs| Website

Facebook  Twitter  Linkedin  

Permission to Share



If you would like to share, please forward the Tips message in its entirety. You can share excerpts as well, with the following attribution:


Source: Rebecca Herold. July 2025 Privacy Professor Tips

www.privacysecuritybrainiacs.com.


NOTE: Permission for excerpts does not extend to images.


Privacy Notice & Communication Information


You are receiving this Privacy Professor Tips message as a result of:

 

1) subscribing through PrivacyGuidance.com or PrivacySecurityBrainiacs.com or

2) making a request directly to Rebecca Herold or 

3) connecting with Rebecca Herold on LinkedIn


When LinkedIn users invite Rebecca Herold to connect with them, she sends a direct message when accepting their invitation. That message states that in the spirit of networking and in support of the communications that are encouraged by LinkedIn, she will send those asking her to link with them her monthly Tips messages. If they do not want to receive the Tips messages, the new LinkedIn connections are invited to let Rebecca know by responding to that LinkedIn message or contacting her at rebeccaherold@rebeccaherold.com

 

If you wish to unsubscribe, just click the SafeUnsubscribe link below.