Why Are You Getting This?


You signed up to receive The Privacy Professor Tips, or initiated contact to stay in touch with Rebecca and/or Privacy & Security Brainiacs (PSB) and consented to receive the Tips. Please read our Privacy Notice & Communication Info at the bottom of this message for more information. You may unsubscribe from there as well.


NOTE! For those of you who requested or agreed to receive the Tips over the past 12 months: We recently learned that you did NOT receive any of our Tips during the past 12 months due to an omission in our distribution list settings! So those of you just now receiving the Tips after not receiving them over the months, this is why. We apologize for any confusion this caused.  

Image from FreePik.

School's Back in Session, and Privacy is More at Risk

Faster than students flood the halls when the bell rings, personal data, including the most sensitive of all types, can be stolen from vulnerable academic institutions, as well as directly from the students who attend them. With treasure troves of personal data, much of it belonging to young people with squeaky clean credit histories, schools, colleges and the students themselves have always been big-time targets for cyber criminals. The target is increasingly getting larger because of all the types of digital devices students use and wear, in addition to all the ways that students are now being tracked not only with those devices, but also from the educational institutions and government sites they are required to use and/or that have their student data, as well as all the social media sites that they are voluntarily using.


One of the best things you can do to protect the students in your life is become aware of the security and privacy settings and controls (and gaps in protection) that govern the websites and devices they use, as well as the data collected, stored and shared by their schools. 


When you're curious, ask those entities questions. You get an A+ for following up with them if you get an "I'm not sure. I'll have to look into that" type of response. 

 

Read on to learn more about back-to-school time risks and other threats to your data security and privacy. 

Image from FreePik.

This month we’ve included some great reader questions covering our back-to-school topic, a couple of healthcare and HIPAA topics, the Musk v Apple AI lawsuit, AI-generated imposter websites, and AI-generated voice clones.


Please read to the end where we provide some information about our recent activities and online courses.



We are also now excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for the organizations providing them.


We freely distribute, since 2005, the Privacy Professor Tips monthly publication to help both businesses and individuals, of all ages, to help identify risks throughout their daily lives, and within their own businesses, and to help them know how to prevent security incidents, privacy breaches, and to keep from being a victim of scams.


By sharing this Tips issue with others in your organization, you are also supporting a wide range of regulatory and other legal compliance requirements to sending such awareness communications. Thank you for reading and sharing!

We would love to hear from you!

Did you find the tips we provided useful? Did you like this issue? Do you have questions for us to answer? Please let us know at info@privacysecuritybrainiacs.com.

Rebecca

Image from FreePik.

September Tips of the Month


  • News You May Have Missed
  • Privacy & Security Questions and Tips 
  • Where to Find the Privacy Professor

News You May Have Missed

We are finding more unique news stories to share with you than ever before. We also share news items that we believe are important for most folks to know, but that often do not get much mention in traditional news, or even in security and privacy news outlets.

 

Here are just a few of the 100+ news stories we discovered throughout the past month that provide a wide range of interesting security and privacy related news. These news items demonstrate that such types of risks exist basically anywhere in the world, and that everyone needs awareness.

 

This month we list 50 news items. We are grouping them into four broad categories: The first is for the associated topic of the month, followed by “Of broad interest,” “Privacy in businesses, governments, and other organizations,” and “Laws, legal issues, and lawsuits about or significantly involving privacy and/or security issues.” Many readers will find all the items of interest, but for those of you who prefer one or two specific categories, this will help you find your news items of interest more quickly. Within each category the items are in no particular order. By popular request we are also now including “INSIGHTS” with many of the situations to provide some advice or additional insights.

 

Do you have interesting, unusual, bizarre or odd stories involving security and privacy? Some of the most interesting, bizarre or odd stories are in local news! Or questions about any of the notes we included for the stories we listed this month? Let us know!

Image from FreePik

Specific to Back-to-School

The amount of privacy and data security news in schools, from pre-school through post-graduate universities, is increasing dramatically. Here are 18 representative news reports from this year.

 

1.   Good tips from the Ballwin Police Department on Facebook about removing personal data of students when posting their back-to-school photos.

2.   Good reminder from the James Madison University (JMU) in Virginia about privacy for students 18 and older as they go to college.

3.   In the Philippines, it was also good to see there was also a reminder of what school teachers and staff can and cannot share about students under their Data Privacy Act.

4.   Students have been called to the office — and even arrested — for AI surveillance false alarms. Surveillance systems in American schools increasingly monitor everything students write on school accounts and devices. Thousands of school districts across the country use software like Gaggle and Lightspeed Alert to track kids’ online activities, looking for signs they might hurt themselves or others. With the help of artificial intelligence, technology can dip into online conversations and immediately notify both school officials and law enforcement. However, it has criminalized, and led to imprisonment, of children for careless words. A “teenage girl made an offensive joke while chatting online with her classmates, triggering the school’s surveillance software. Before the morning was even over, the Tennessee eighth grader was under arrest. She was interrogated, strip-searched and spent the night in a jail cell”.

5.    Thousands of school districts’ confidential files and other sensitive documents could have been publicly accessible for months because of a technical glitch in BoardDocs, a software used to manage school board meetings. The “glitch” was reportedly a “misconfiguration,” or an issue with the way the application was “coded and architected.” Here is another report about this from a different news outlet. INSIGHTS: These types of errors are often the result of poor or non-existent coding practices and IT administration practices, and often no, old, or weak security and privacy policies and procedures.

6.   Personal information, including names, addresses and social security numbers, from former students in the Lexington-Richland 5 school district in South Carolina was posted in an online forum “used by threat actors,” the district announced on August 18, 2025. The news comes after a district-wide data breach in early June pushed back the start of summer school and temporarily delayed pay for teachers and staff. The breach knocked out web access in the district’s schools that month, the district said. INSIGHTS: Cybercrooks are increasingly targeting education institutions, especially K-12 public schools. Why? The answer is multi-factored. However, a common denominator is that public school budgets are being drastically reduced. Some of the budgets most often slashed are those for IT support, security and privacy, which are too often viewed as “low priority.” Unfortunately, this is also occurring throughout all industries as well. Especially those dealing with high tariffs and higher expenses.

7.   A ransomware attack that compromised the personal data of 37,031 people was confirmed by Mastery Schools, the largest charter school network in Philadelphia. The breach, which occurred in September 2024, exposed a wide range of sensitive information, including Social Security numbers, medical details and student records.

Image from FreePik

8.   BYU–Pathway Worldwide, an education organization supported by the Church of Jesus Christ of Latter-day Saints (LDS Church), had an unauthorized party access over 25,000 students’ data. The university claims that the incident involved a vendor account, whose access was suspended immediately after the organization learned about unauthorized activity on its systems.

9.   Google accused of harming kids by secretly grabbing data from school-provided tech products. According to the lawsuit filed in San Francisco U.S. District Court, almost 70% of U.S. schools use Google's "Workspace for Education" products in classrooms, and a review by this news organization shows numerous Bay Area school districts—including Berryessa Union, Berkeley Unified, and Pleasanton Unified—use the software. Google embeds hidden "tracking" technologies to follow students' online activity across the internet as they use websites and apps, creating a "fingerprint" specific to each child, the lawsuit alleged. Here is another report about this, as well as from here. These are from different news outlets. INSIGHTS: The number of lawsuits being filed for the dramatic increase in such surreptitious digital tracking is also increasing dramatically. Our research shows that many of the organizations' networks where this tracking is taking place didn’t even realize the third parties who were contracted to support IT activities had also implemented these tracking activities. However, the organizations are still accountable and responsible for such tracking, unauthorized data collection and use.

10.   Tennessee’s largest school district sues PowerSchool over data breach. Memphis-Shelby County Schools’ federal lawsuit against the ed tech giant is among the latest that have been filed by over 100 other districts nationwide. The 110,000-student district, which has paid PowerSchool $21 million over the last 12 years for its services, seeks monetary damages to cover expenses incurred from addressing the concerns of students and staff whose personal information was stolen. Damages are also being sought for any costs associated with recovering from the data breach’s impact. INSIGHTS: Reports reveal basic security practices, such as requiring multi-factor authentication, was not being used.  

11.   PowerSchool data breach leads to school extortion attempts. A threat actor has contacted multiple school districts demanding payments related to student and staff data stolen in a December breach. Here’s another report on the PowerSchool breach: PowerSchool Paid Off Hackers After Huge Breach — Now They’re Extorting Districts Millions of students’ and educators’ sensitive records, including Social Security numbers, face new risks as cybergang reneges on ransomware deal.

12.   A politically motivated hacker breached Columbia University's data systems, stealing troves of student documents while briefly shutting down the school's computer systems. The June 24 cyberattack prompted widespread network outages on campus, locking students and staff out of their email accounts, coursework and video conference software for several hours. On the same day, images of President Donald Trump appeared on several public monitors across the Manhattan campus. The data stolen includes bank account and routing numbers, student loan and scholarship disbursements, standardized test scores, grade-point averages, class schedules, home addresses and other contact information

13.   Schools Face an Uphill Battle in Protecting Student Data in the Age of AI. Many school district technology leaders are struggling to establish fundamental student data privacy practices, partly due to a lack of support from the rest of the district, concludes a new report from the nonprofit Consortium for School Networking, a membership organization for district technology leaders.

14.   Ransomware attacks in education jump 23% year over year. The first six months in 2025 saw 130 confirmed and unconfirmed ransomware attacks against colleges and schools.

15.   The Consortium for School Networking (CoSN) provides “results of an extensive survey of district representatives about their privacy expertise and district privacy practices. This one-of-a-kind report, divided into two parts, provides an unprecedented look into how districts are managing the critical task of safeguarding student data.”

16.   Study results show data breach reporting lags in education. The sector takes an average of 4.8 months to report attacks — the highest when compared to business, government and healthcare.

17. Spate of hoax calls about active shooters stir fear at college campuses around the US. On one recent Monday alone, law enforcement responded to calls claiming active shooters at Arkansas, Northern Arizona University, Iowa State, Kansas State, the University of Colorado-Boulder and the University of New Hampshire. More calls were made the next day at the University of Kentucky, West Virginia University and Central Georgia Technical College. INSIGHTS: Such hoax calls are called “swatting.” Familiarize yourself with the characteristics of such hoax threats, which involves protecting your online information. Here is some good advice.

18. Privacy and civil rights groups urge US colleges to end campus surveillance to protect protesters. ““Without immediate action, surveillance tools and the data they amass will be used to supercharge the virulent attacks on campus communities,” says the letter, coordinated by the group Fight for the Future. It was signed by 32 groups, including Amnesty International USA, the Electronic Privacy Information Center and the American-Arab Anti-Discrimination Committee.”

Of Broad Interest…

Image from FreePik

19.   Chicago area ice cream shop owner secretly filmed women, girls in bathroom. The man was put in jail and charged with two counts of child pornography and two counts of unauthorized video recording. The police “were told about what appeared to be a fake wall electrical outlet in the shop’s restroom. An undercover Addison police officer went to the shop and saw what appeared to be an outlet in the shop’s bathroom with a small black lens in one of the receptacles. Police then obtained a search warrant and removed the phony outlet and found a camera inside.”

20.   Moving? Watch for rental scams. "Looking for apartments or houses online is convenient, but that’s where many rental scams start. If you think you’ve found the perfect price in a great location, know how to spot a rental scam — before you commit to a rental." INSIGHTS: Three great tips are in this short article.

21.   Victoria’s Secret shuts down website following unspecified cyberattack. The news came on the heels of Germany-based Adidas being hit by a cyberattack the previous week, as well as French luxury brand Dior reporting a cybersecurity incident two weeks earlier, when the Google Threat Intelligence Group warned that the threat actor, presumed to be the ransomware group Scattered Spider, was going to expand its activities into North America.

22.   How Des Moines police are using social media to find wanted criminals "The Des Moines Police Department has started a bi-weekly social media series called Wanted Wednesday to help generate awareness and tips on people with active arrests warrants or to help identify people who allegedly have committed felony crimes." INSIGHTS: There are safety benefits to these social media series. However, there are concerns that some of the accusations for those who have committed crimes may be wrong and cause harm to the falsely accused. The police should establish some guardrails to help protect against unfounded accusations made publicly.

23.   Apple Intelligence Is Gambling on Privacy as a Killer Feature. Many new Apple Intelligence features happen on your device rather than in the cloud. While it may not be flashy, the privacy-centric approach could be a competitive advantage. INSIGHTS: Pushing processing to edge devices such as this can provide huge privacy protections for face and age identification uses, and other types of uses that currently require end-users to upload sensitive personal information. Processing on the device could eliminate uploading such personal data, and putting at risk as it is sent through the internet and shared with unlimited, and unknown, third parties, whose own systems often have many security and privacy vulnerabilities.

24.   This AI-driven Phantom Hacker Scam is draining retirement funds, and according to the FBI, no one is safe. A three-phase phishing scam utilizes a team of impostors, and so far has drained an estimated $1 billion from the savings accounts of seniors.

Image from FreePik

25.   Houlton, Maine employees made regular use of the controversial surveillance system security cameras that the town installed last year, searching them thousands of times for details about people and vehicles. The data revealed that a handful of staff from various town departments — including police, public works, recreation, code enforcement and civic center — used the 25-plus cameras, often turning them on or searching them outside traditional work hours and even in the middle of the night. Collected between Jan. 1, 2024, and Dec. 31, 2024, the data from the cameras’ digital access logs also raise new questions about whether the town’s use of them violated a Maine law that sharply limits the use of facial surveillance technology.

26.   After Trump's DOGE action, 300 million people's Social Security data is at risk because DOGE officials uploaded sensitive information to a cloud account not subject to oversight and with weak security controls, and in some cases, no security controls, according to a whistleblower. INSIGHTS: Anytime individuals are given access to data for purposes beyond those for which the data was originally collected, significant risks are created. These risks are multiplied when the individuals have no security or privacy background, expertise or training, and when that data is stored on unsecure systems.

27.   Scammers Employ AI to Build Fake Versions of Real Websites. An example is a scam that developed following Joann Fabrics’ bankruptcy earlier this year. Days after that announcement, a host of bogus websites appeared designed to look almost identical to the retailer’s actual site. These sites offered enticing discounts, with the goal of stealing visitors credit card information and data. INSIGHTS: See a related question and answer further down in the Questions and Answers section.

28.   Futurism Scientists created an entire social network where every user is a bot and something wild happened. They simulated a social media platform that was populated entirely by AI chatbots, powered by OpenAI's GPT-4o large language model, to see if there was anything we could do to stop social media from turning into outraged and hate-filled echo chambers. "With or without intervention, social media platforms may be doomed to devolve into a highly polarized breeding ground for extremist thinking."

Image from FreePik

29.   A man seeking to make a dietary change consulted ChatGPT and later developed "bromism," a rare "toxidrome." The 60-year-old had bromism, a syndrome brought about by chronic overexposure to the chemical compound bromide or its close cousin bromine. In this case, the man had been consuming sodium bromide that he had purchased online after ChatGPT told him chloride can be swapped for bromide, so he swapped all the sodium chloride in his diet with sodium bromide. After three months of consuming sodium bromide instead of table salt, the man reported to the emergency department with concerns that his neighbor was poisoning him. INSIGHTS: This is another example of how AI can be very harmful when individuals blindly trust the AI output. Always remember that no AI exists that is 100% correct, and that the AI tools people use often are trained on the questions and data individuals use to ask the AI questions.

30.   Reddit is rolling out age verification in the UK. The platform may also soon start checking if users are human or AI. INSIGHTS: This is another example of an application that could significantly increase privacy protections by pushing this human or AI user check to the edge device instead of performing it at the platform.

31.   A bizarre new Linux malware can be found hiding in cute animal photos. That cute panda pic? It's actually a cryptominer.

Image from FreePik

32.   Fourteen arrested in phishing attack investigations. Thirteen people have been arrested in Romania on suspicion of making fraudulent tax repayment claims using personal data that was stolen in sophisticated phishing attacks.

Privacy In Businesses, Governments, And Other Organizations…

33.   TThe U.S. Department of Government Efficiency (DOGE) uploaded an enormous Social Security database to an unsecured cloud in June, risking the private information of hundreds of millions of Americans, per a new whistleblower complaint. The file is a treasure trove for bad actors, says the complaint, filed by the Social Security Administration’s Chief Data Officer. The database contains the identifying details of more than 300 million Americans — and includes all the information in someone’s Social Security application, name, date of birth, parents’ names, addresses, etc. “Americans may be susceptible to widespread identity theft, may lose vital healthcare and food benefits,” the complaint says, “and the government may be responsible for re-issuing every American a new Social Security Number at great cost.”

Image from Pexels

34.   What we know about the Social Security Administration listing thousands of living immigrants as dead: The affected individuals newly added to the Social Security Administration’s “Death Master File” are in the country legally. Additionally, DHS and the Treasury Department signed a deal allowing the IRS to share immigrants’ tax data with Immigration and Customs Enforcement for the purpose of identifying and deporting people illegally in the U.S. The agreement will allow ICE to submit names and addresses of immigrants inside the U.S. illegally to the IRS for cross-verification against tax records. Advocates say the Treasury-DHS information-sharing agreement violates privacy laws and diminishes the privacy of all Americans.

35.   Erasing personal data from the devices you discard is a booming business. A recent report found that stolen devices and drives are a more common method of data loss than either ransomware or stolen credentials. Nonetheless, there’s often less diligence around data security when it comes time to dispose of electronic devices and IT equipment. That reality has motivated the IT Asset Disposition (ITAD) industry to not only invest in developing more robust data-erasure tools and standardized processes but also to certify their work to customers.

36.   Federal investigators demanded details on transgender patients from at least 1 hospital. When the U.S. Justice Department sought information from doctors and clinics that provide gender-affirming care for young transgender patients, officials weren’t just asking for policies. They also demanded information about individual patients. “The subpoena sent to Children’s Hospital of Philadelphia on June 11 was included in a legal filing Monday in challenges from the states of Minnesota, Oregon and Washington to the administration’s attempts to bar the treatment for patients under age 19. The 18-page document demanded an expansive list of documents be provided. Among them: Documents to identify “by name, date of birth, social security number, address and parent/guardian information” patients who were prescribed puberty blockers or hormone therapy. The requests also covered personnel files for various categories of hospital employees, information about patient intake procedures and about which insurance billing codes the hospital used for gender-affirming care.”

37.   A third of cyberattacks still target small businesses, many of which still underestimate how long it will take and how much it will cost to recover from the attack.

38.   A hacker used AI to automate an 'unprecedented' cybercrime spree. Anthropic said it caught a hacker using its chatbot, Claude, to identify, hack and extort at least 17 companies. The operation began with the hacker convincing Claude Code, Anthropic’s chatbot that specializes in creating computer programming based on simple requests, to identify companies vulnerable to attack. Claude then created malicious software to actually steal sensitive information from the companies. Next, it organized the hacked files and analyzed them to both help determine what was sensitive and could be used to extort the victim companies. The chatbot then analyzed the companies’ hacked financial documents to help determine a realistic amount of bitcoin to demand in exchange for the hacker’s promise not to publish that material. It also wrote suggested extortion emails.

39.   ESET says it has discovered “the first known AI-powered ransomware,” which the company has named PromptLock. It uses OpenAI's gpt-oss:20b model, which the company released earlier this month as one of two open-source models, meaning a user can freely use and modify the code. It can also run on high-end desktop PCs or laptops with a 16GB GPU. 

40.   License plate camera company Flock Safety halts cooperation with federal agencies. The company has installed more than 4,000 license plate-detecting cameras nationwide to aid law enforcement. It has halted operations with federal agencies because of ongoing concerns among officials in Illinois and elsewhere. Flock Safety's cameras capture billions of photos of license plates each month. The company has programs with Customs and Border Protection and Homeland Security Investigations for sharing the data.

Image from Washington State Transportation Commission.

41.   Nevada closed state offices on August 24, 2025, as a cyberattack disrupted its IT systems. The Nevada government is now working with local, tribal, and federal agencies to investigate and respond to the attack. The Governor's office is warning residents to be cautious of unsolicited calls or emails asking for sensitive information.

42.   Deloitte’s report for the Australia Department of Employment and Workplace Relations on welfare compliance systems, which cost taxpayers $439,000, contained at least half a dozen references to academic works that do not exist. “The welfare academic who discovered the incorrect references, Chris Rudge, has found the report also contains an apparently invented quote from the decision in a leading robo-debt case, Deanna Amato v Commonwealth.”

43.   Microsoft is probing if Chinese hackers learned SharePoint flaws through alerts. Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched. The tech giant is probing if a leak from the Microsoft Active Protections Program (MAPP) led to the widespread exploitation of vulnerabilities in its SharePoint software globally.

Laws, Legal Issues, And Lawsuits About Or Significantly Involving Privacy And/Or Security Issues…

Image from FreePik.

44.   Sex offenders and other criminals could walk free due to 'deepfake' evidence. Police forces across Britain are not equipped to deal with AI-generated deepfakes; it could result in miscarriages of justice. Potential risks are “that innocent people could be wrongly accused of crimes based on AI-generated evidence and those guilty of offences could escape justice by fabricating alibis.” INSIGHTS: Deepfake pictures or audio clips are made using AI to look real. These situations are appearing in other countries as well.

45.   A full Eleventh Circuit ruled that Georgia Department of Corrections officers are not entitled to immunity in the case of a woman who was strip-searched while visiting her husband in prison, saying the search was unreasonable and violated her Fourth Amendment rights.

46.   Cigna faces lawsuit over use of web trackers from Meta and other companies. A California resident is suing three subsidiaries of Cigna and other parties in a state court in Sacramento, California, over allegations that the company's use of website tracking tools violated her privacy. The plaintiff hopes to represent state residents who entered medical information on the insurer's site before January 2015.

47.   Elon Musk’s Lawyers Claim He ‘Does Not Use a Computer’. The claim appeared in a court filing related to Elon Musk’s ongoing lawsuit against Sam Altman and OpenAI. The Tesla and xAI owner has posted about his laptop numerous times in the past year. INSIGHTS: Whatever you post online will generally always be open to scrutiny and used for whatever other reason for which others see the need to use it. Plus, many people will get caught telling a lie under oath. The technically savvy understand this.

48.   Lawyers using AI keep citing fake cases in court. Judges aren’t happy. Failing to vet AI output before using it in court documents could violate attorneys’ duty to provide competent representation, the American Bar Association has said.

Image from FreePik.

49.   California jury rules Meta violated privacy law in case involving period-tracking app. On August 1, a federal jury in San Francisco delivered a historic verdict in a class action lawsuit against Meta Platforms that has the potential to rewrite the rulebook around the use of private data. The social media giant that owns Facebook, the jury found, had violated a California privacy law by using confidential data it had harvested from Flo, the popular women’s health app, to sell advertising. Meta could now be on the hook for billions in dollars in statutory damages under the California Invasion of Privacy Act. The case appears to have been one of the first in which Big Tech has been held liable for misusing consumer health information.

 

50.   Was Google evil? Anibal Rodriguez and 98 million other Google users are suing Google for violating their privacy. Users thought by turning off a Google activity control, “the “Supplemental Web & App Activity,” they had blocked Google’s collection and retention of their private information from apps (PayPal, Spotify, Lyft and millions of others) that use Google services. Instead, the lawsuit claims Google allowed the apps to retain and use that data, tracking users’ interactions on those apps, showing what they read, what they saw, what they did.

Check out our Privacy & Security Brainiacs blog page for more unique security and privacy news items. Have you run across any surprising, odd, offbeat or bizarre security and/or privacy news? Please let us know! We may include it in an upcoming issue.

Privacy & Security Questions and Tips

Rebecca answers hot-topic questions from Tips readers

September 2025

We continue to receive a wide variety of questions about security and privacy. Questions about current hot topics in society, and increasingly more about healthcare privacy and security. Thank you for sending them in! This month in addition to our Question of the Month we’ve included five additional questions.

 

Are the answers interesting and/or useful to you? Please let us know! Keep your questions coming!

Question of the Month:



Q1: What are some indicators that a website was created by AI to look like the impersonated, actual, site?

A1:


Such impersonated websites are being widely created now with the help of AI. This includes for all types of school sites, K-12 and universities. Especially at the beginning of the school year, when students and parents are submitting their financial information to schools to get grants, scholarships and loans. These sites are taking site visitors’ personal data, money, and more by pretending to be educational institutions. Stay aware! Here are some ways to spot impersonated websites.

 

Look at the web address (the URL).

  • Look at the end of the URL. Look for an address that isn’t the same as what you typically see. E.g., if you use a website that ends in .com, but now a message purports to be that same website, but its URL ends in .ru, or something else other than .com, then it may very well be a spoofed website.
  • Look for misspellings within the URL. E.g., instead of PrivacySecurityBrainiacs.com, you see PrivicySecurityBrainiacs.com. See anything different in the second URL? That is not our site!
  • Look for extra, or missing, letters, words and symbols in the URL. E.g., instead of PrivacySecurityBrainiacs.com, you see Privacy_Security_Brainiacs.co. That is not our site!
  • Look for website security indicators. Legitimate websites use HTTPS and most display a padlock icon somewhere in the address bar. Clicking the padlock will reveal the site's security certificate. You can examine it to see if the registered company name is legitimate. CAUTION! Increasingly more fake sites also use HTTPS to appear credible. While it is good to disqualify a site using only HTTP, you cannot confirm that a site is legitimate only based on it having an HTTPS.
  • Don’t trust perfect grammar. AI tools make grammatically correct phishing messages! Just because the writing is professional-looking does not mean it is not a criminal site.
  • Watch out for all numbers in the URL address. This is often an IP address if it looks similar to the following after https// :  123.456.789

Generally all legitimate URL addresses use a domain name, and not an IP address.

 

Verify the URL before clicking it.

  • Be cautious of shortened URLs. From unexpected and unsolicited texts, emails, comments on social media sites, etc. Shortened URLs are often used by cybercrooks, increasingly more through using AI, to redirect to malicious URLs. Use a URL safety checker first if you ultimately want to visit the site if it is legitimate. There are many such URL safety checkers. A couple we use include URLVoid and Norton Safeweb
  • Don’t click links in texts or emails. Emails and texts can show you legitimate URLs, but hide the actual URL in the associated computer code where you cannot see it. Go directly to the official website instead. E.g., if you get an unsolicited or unexpected email from a well-known URL like Facebook.com, don’t click it. Use a browser and type Facebook.com in the web address bar and contact their customer support to ask if they are sending messages like you received.
  • Hover before clicking. For links in emails, texts, or social media sites, hover your cursor over it without clicking. The destination URL will usually appear, allowing you to inspect the full URL before proceeding.
  • Be extra cautious on small devices. On phones and other type of smaller screens the details are often hard to see clearly. This makes it more likely that targeted victims will click malicious links because something tiny appears to be legitimate.

(Somewhat) Quick Hits:


Here are five more questions, most of which we are answering at a comparatively high level. We provide more in-depth information and associated details about these topics in separate blog posts, videos on our YouTube channel, in infographics and e-books, LinkedIn posts to our business page, and within our online training and awareness courses.

Image from Google Gemini

Q2: Are there any privacy issues related to the Musk lawsuit against Apple?



A2:


Musk is making quite an interesting accusation within his lawsuit. I don’t see any actual evidence that he’s provided to support his claim though.

 

The publicly reported “evidence” that he has provided to support his lawsuit appears to be largely circumstantial. And quite frankly, his claims sound more like sour grapes from someone who thinks he’s “losing” the AI app race. Basically, he’s making the accusation that Grok (Musk’s AI tool) is currently coming in at #5 instead of #1 only because of some “cheating” that Apple is committing. This reminds me of very early in my career when I taught 7th through 12th grade math and computing. Sometimes when the favored “math star” to win a class-observed chalk-board math-solving-race lost, the “star” claimed the loss was because the winner cheated.


Musk’s claim loses quite of bit of credibility given OpenAI is at #1. Last I checked, Microsoft owns 49% of OpenAI. Which means Apple is promoting one of their other competitors to be at #1, but putting Musk’s Grok at #5…for being a competitor? Hmm. It also appears, from various reports, that Musk is highly insulted because Grok is not listed in the Apple "Must-Have Apps" section. Has Musk provided any solid, verifiable evidence of Apply deliberately suppressing or manipulation of rankings? I’ve not seen any. Perhaps if there is evidence it will be shown during the trial. 


From a privacy standpoint, many of my own clients, friends and family have decided not to use Grok because of the reported wholesale use of tweets and associated data from X, and from the prior history of Twitter tweets, to train newer versions of Grok; per multiple reports from PBS, Bloomberg, The Washington Post, and others who were quoting Musk. I support the decisions of my clients, friends and family. I also do not use Grok, and privacy risks are one of the more significant reasons. (Instead, I use 5 other AI tools, and then compare the results, to see discrepancies in the results.)

 

Ultimately, Musk’s Grok may be being bested by the other apps in the Apple store in large part because of his horrible privacy practice of what appears, to those who care about privacy, to be wholesale training use of all the online data, and associated meta data, with no consent from the associated individuals for the data he is using for his own company’s financial gain.


Two key points for AI customers and business leaders:

  • Given Grok is using massive amounts of publicly available data to train Grok, including personal data and clients’ interactions, without obtaining consent from the associated individuals, it is probably best for mitigating privacy risks to avoid using Grok anyway.
  • When a tech vendor is filing a lawsuit simply because they are not “beating” one of their competitors, or it is not “winning” with their product in some other way, it should indicate to an organization that the tech vendor may also be difficult to work with if any problems are encountered when using the tech vendor’s products or services, and/or when discovering any data security and privacy vulnerabilities or breaches.

Q3: The lack of thorough risk assessment is a critical issue in healthcare security. What strategies do you recommend for organizations to ensure their risk assessment practices are both effective and compliant with HIPAA, and other applicable legal requirements?

Image from FreePik

A3:


Great question, Ron! There is so much I could provide to address this question comprehensively. However, that will require a longer blog post, and probably a new course. In the meantime, here are some important considerations.


The HIPAA regulatory text does not explicitly provide detailed instructions for what is expected from an acceptable HIPAA risk assessment (referenced also as “risk analysis” within the regulatory text). However, the associated regulation summaries and preliminary supplementary information preceding the regulatory requirements provide insights within the initial published HIPAA regulation and the subsequent updates. The Department of Health and Human Services (HHS) has also published a huge amount of guidance materials throughout the years about what they consider to be effective and compliant risk assessments. They also have indicated the actions that they consider to be necessary within a compliant risk assessment within their audit findings, breach investigation reports, and HIPAA noncompliance settlements. The National Institute of Standards and Technology (NIST) has also been providing HIPAA compliance direction, in coordination with HHS, within multiple versions of NIST SP 800-66.


Considering all supplemental government guidance documents, coupled with 20 years of helping healthcare covered entities (CEs) and business associates (BAs), of all sizes, with HIPAA compliance, including implementing practical risk management controls appropriate for each business ecosystem, here is an overview of an effective strategy I’ve used many times to help CEs and BAs perform risk assessments:

1)   Make sure you have identified a role (or person, team or department) to be accountable for HIPAA compliance activities, and specifically for HIPAA risk management activities. This role should have entity-wide authority to enlist the assistance of any workforce members when performing a risk assessment. Those fulfilling the role should be a strong leader, and have knowledge and expertise in technical security, physical security, administrative security, operational security, and privacy, in general and as they apply to your specific organization. They can engage outside experts to help also, as necessary to fill knowledge gaps.

2)   Determine the scope of the risk assessment. Many organizations try to boil the ocean by performing one risk assessment with a scope of the entire organization, all business associates and their subcontractors, remote working areas, etc.  For many organizations with the resources, time, and expertise, this will work satisfactorily. I’ve found over the years that performing several smaller scoped risk assessments works better for many other organizations. I’ve been doing this with many of my clients for years, always with success. Those participating don’t feel as overwhelmed with having too much to do in a short period of time with limited resources. And, they don’t feel like they lack the necessary knowledge about the systems, applications, PHI-involved processes, facilities, offsite locations, computing devices, business associates, etc. that they are assessing.

3)   Then, the leaders accountable for each of the smaller-scoped assessments take all these smaller risk assessment reports and findings and create the comprehensive final risk assessment. They do this utilizing the full report details and results of all the smaller scoped risk assessments, and work together to create the final comprehensive risk assessment. Not only is this a very effective way to accomplish risk assessments, but this process also almost always results in identifying ongoing risk management activities to perform, which also supports the additional HIPAA risk management requirements.


I’m currently helping two different healthcare clients, one a CE, and the other a BA, to perform their risk assessments in this way. It has really helped by having multiple activities being performed for different topics concurrently, and also takes a great amount of pressure off of each of the team leaders.


For example, one client is a healthcare software vendor. They have one team is working on the technology development risk assessment, another team performing the home office facilities risk assessment, and the third risk assessment team working on the remote working operations. After those are completed, we will convene the three teams and assess the combined impacts of all of the assessments to determine overall organizational risk assessment results.


For other clients, they almost always have a smaller-scoped risk assessment being performed at any point in time. The results are then incorporated into the overall organizational risk assessment. This often points to areas where another smaller-scoped risk assessment should be performed.


It is basically a divide and conquer strategy for performing risk assessments that has proven to be quite efficient and valuable throughout the years. This strategy also works for all other regulations, and industries.


Some great resources to use throughout the assessments, especially when clarifications are needed for different risk issues that emerge, include NIST SP 800-66r2, “Implementing the HIPAA Security Rule,” and the just-published on August 27, 2025, NIST SP 800-53r5.2.0, “Security and Privacy Controls for Information Systems and Organizations.”


I’ll include links in upcoming issues of the Monthly Tips to a new blog post, and new course on this topic, when they become available.

Image from FreePik

Q4: Does HIPAA require any protections against workforce members accessing PHI? Or, can all workforce members access all PHI, since they are part of the hospital or clinic?


A4:


HIPAA requires that each of the workforce members, or “insiders,” must only access the protected health information (PHI) for which they have some direct responsibility requiring such access. This is not only to support privacy, but also for information security. Such protections are very important.

 

Consider this; according to the Verizon Business ‘‘2024 Data Breach Investigations Report: Healthcare Snapshot,” insiders were the second leading cause of breaches in the healthcare sector in 2023, exceeded only by ‘‘miscellaneous errors,’’ such as mis-delivery of PHI to unauthorized individuals.

 

Such unauthorized access often occurs through mistakes of workforce members who try to do the right things. That said, there are also malicious insiders who, throughout history, have taken advantage of their authorized access to then steal, sell, and commit a wide variety of other crimes by exploiting that trusted access to PHI. For example, a recent settlement resolved an OCR investigation involving the theft and sale of the PHI of more than 12,000 patients by an employee of a large healthcare system, Montefiore Medical Center. Montefiore had to pay a $4.75 million monetary settlement penalty and follow an HHS-monitored corrective action plan (CAP) for at least two years. In another example, security guards at a large healthcare provider, Yakima Valley Memorial Hospital in Washington, were alleged to have used their login credentials to inappropriately access the full health records of 419 patients. The hospital paid a $240,000 penalty and must follow an HHS-monitored corrective action plan (CAP) for at least two years.

 

CEs and BAs must all implement and maintain strong safeguards to protect not only against external threats but also against insider threats. This includes safeguards that must not allow workforce members to access the PHI of any patients for whom they do not have a direct responsibility or need that supports the patients’ treatment, payment or operations. 

Q5: In what ways, if any, is privacy involved with the U.K. deciding to drop its demand that Apple build a backdoor into its encrypted iCloud services?

 

A5:


It is great that you recognize there are privacy risks for backdoors built into encrypted data. The specific efforts of governments, along with investigators, law enforcement, the military, and others, to compel back doors into encryption has been going on throughout most countries for at least 32 years since the Clipper Chip was being promoted by the US government.

 

What I’ve written about this many times throughout the past four decades is still true; putting backdoors in encryption was and still is a very bad idea for strong, verifiable and compelling reasons.

 

Here are five important and compelling facts that governments and other types of organizational leaders need to know. Strong, verified reasons for why putting backdoors in encryption is a very, very, very, very bad idea.

1.   Backdoors can often be, and have been, exploited accidentally, resulting in great harm. Backdoors in technologies are nothing new, often to allow for easier troubleshooting by the programmers that created the code.

2.   Backdoors will not remain a secret. Backdoors will be discovered and used by the adversaries and crooks that the associated encryption tools were established to protect data from in the first place.

3.   Backdoors created to fight crime will be used to commit crime. Proficient enemies who are looking for vulnerabilities in security technologies know how to exploit the weaknesses when they find them.

4.   Backdoors and other types of weakened security create opportunities for malicious insiders and the authorized unaware. Humans are the weakest link in information security, and trusted insiders present some of the greatest threats to systems and information. 

5.   Backdoors in technology hurt business success and thwart technology advances. If weakened security in commercial products and services is the result of a national policy (as opposed to other causes, such as human error or corporate interests), this government-required weakened security harms the nation economically.

 

I need to revive a long blog from 11 years ago where I expanded upon each of these.

 

In short, backdoors in encryption will not only weaken, but generally destroy, the security of data, significantly infringe upon privacy, violate compliance requirements, and result in breaches.

 

The current reasons being given by lawmakers and law enforcement to weaken encryption to be able to access data often sound noble in the way the statements are presented. However, when digging into the resulting security and privacy risks doing so would create, and the cornucopia of harms that would result to unlimited numbers of individuals and groups, those who value facts and logic have, to date, typically realized that such back doors are not good ideas. Those who persist in making such encryption backdoor demands either do not have a good understanding of how encryption works, based upon their many statements, or they simply do not care about privacy as they are focused only on their own goals.

 

While this decision by the UK is the latest encryption backdoor battle win for privacy, it is really only the next win in a long string of wins throughout the past four decades of continuing to have battles against backdoors in encryption being pursued by not only other countries, but many attempts made here in the U.S. I fully expect there will continue to be many more attempts. There always have been, and as long as governments, law enforcement, and others believe they have a right to surveil the general public through such backdoors, these attempts to compel tech companies to build in backdoors for such entities will continue.

 

The scary reality is that today more tech companies are demonstrating willingness to work with government agencies in what appear to be quid pro quo actions following tax breaks, and possibly other benefits they are receiving that have not been publicly reported.

 

What I know for certain, though, is that this short-term privacy victory is only one battle won within a long privacy and encryption war that will continue for the foreseeable future.

Q6: I've read your information about AI cloning voices. Has this happened in real life?

 

A6:


Yes, it has happened many times throughout the past several years. Here are three examples:

  • In May, 2025, it was widely reported that the phone of Donald Trump’s Chief of Staff, Susie Wiles, was hacked, and an AI cloned voice called the contacts in her phone asking for cash and presidential pardons. The FBI then launched an investigation.
  • In October 2024, criminals cloned the voice of a company director in the United Arab Emirates to successfully orchestrate a $51 million heist.
  • In January, 2023, in what may be the most widely reported voice-cloning case, Jennifer DeStefano’s phone rang with a terrifying call from what sounded like her sobbing 15-year-old daughter, claiming she'd been kidnapped. Jennifer nearly paid scammers thousands of dollars, convinced they were holding her daughter hostage. She later discovered her daughter was safe and that her voice was AI-generated.

 

With current technology, it only takes three seconds of the actual person’s voice to make a clone. So, if someone you know calls and asks you an unexpected or out-of-character question, be very suspicious. Consider telling them you’ll call them back, and then hang up and call the actual person and see if it was truly them who had just called you.

Send us any questions you have. And, keep reading the monthly Privacy Professor Tips!

Check It Out!

We will soon be publishing two new courses! Hopefully we can announce them and point to them in our October Tips. Our clients are telling us our courses contain more valuable information, real-life use cases and examples, and supplemental materials that they continue to use to support their business after training, than any of the other HIPAA security and privacy courses they have seen or used. Check it out!

 

We are also excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for some such organizations. Get in touch with us for the details!

 

See some security and privacy tools to take with you while traveling in our 8-page “Protecting Privacy and Security While Traveling” list.

 

What topics would you like to see us create videos, and more formal online courses, for? Let us know!

 

Have questions about our education offerings? Contact us!

Where to Find The Privacy Professor

Rebecca is happy to be teaching Cybersecurity & Privacy Basics for Engineers and Technical Professionals. Online / Jan 30, 2026 / Course Code: 0105-WEB26. Time: 12:00 PM - 2:00 PM Eastern Time. Check it out!

From https://www.epictraining.ca/online-courses/computer-engineering/cybersecurity-and-privacy-basics-for-engineers-and-technical-professionals/22592/#course-description1

The Privacy Professor | Website

Privacy & Security Brainiacs| Website

Facebook  Twitter  Linkedin  

Permission to Share



If you would like to share, please forward the Tips message in its entirety. You can share excerpts as well, with the following attribution:


Source: Rebecca Herold. September 2025 Privacy Professor Tips

www.privacysecuritybrainiacs.com.


NOTE: Permission for excerpts does not extend to images.


Privacy Notice & Communication Information


You are receiving this Privacy Professor Tips message as a result of:

 

1) subscribing through PrivacyGuidance.com or PrivacySecurityBrainiacs.com or

2) making a request directly to Rebecca Herold or 

3) connecting with Rebecca Herold on LinkedIn


When LinkedIn users invite Rebecca Herold to connect with them, she sends a direct message when accepting their invitation. That message states that in the spirit of networking and in support of the communications that are encouraged by LinkedIn, she will send those asking her to link with them her monthly Tips messages. If they do not want to receive the Tips messages, the new LinkedIn connections are invited to let Rebecca know by responding to that LinkedIn message or contacting her at rebeccaherold@rebeccaherold.com

 

If you wish to unsubscribe, just click the SafeUnsubscribe link below.