Mealey's Data Privacy

  • June 23, 2025

    Initial Approval Given To Settlement Of Data Breach Suit Against Health Care Firm

    BALTIMORE — Extending an existing stay on discovery and other proceedings in a consolidated lawsuit over a health care provider’s 2023 data breach, a Maryland federal judge granted the plaintiffs’ motion for preliminary approval of a $1.35 million settlement of negligence, contractual and other claims against the firm.

  • June 20, 2025

    Judge Says HHS Lacked Authority To Enact New HIPAA Privacy Rule

    AMARILLO, Texas — Granting a doctor’s summary judgment motion, a Texas federal judge concluded that the U.S. Department of Health and Human Services violated the Administrative Procedure Act (APA) in enacting a new privacy rule, supplementing the Health Insurance Portability and Accountability Act of 1996 (HIPAA), that prohibits medical providers from disclosing information related to reproductive health care (RHC) in particular circumstances, leading the judge to vacate the new rule.

  • June 19, 2025

    Data Interception Claims Over Hard Rock Café’s Website Are Dismissed

    SACRAMENTO, Calif. — A California federal judge found that a user of Hard Rock Café International (USA) Inc.’s website did not sufficiently allege that the contents of her communications from her website visits were intercepted by the company or shared with Meta Platforms Inc., leading her to grant Hard Rock’s motion to dismiss a complaint against it for violation of the California Invasion of Privacy Act (CIPA).

  • June 19, 2025

    $7.5 Million Settlement Of Digital Pharmacy Data Breach Class Action Approved

    OAKLAND, Calif. — Almost seven months after preliminarily approving a $7.5 million settlement of a class action over a 2023 data breach experienced by PostMeds Inc., a California federal judge made his approval final, granting a motion by the plaintiffs in the consolidated lawsuit, while also giving his thumbs up to requests for attorney fees, costs and service awards.

  • June 18, 2025

    Meta Must Provide Privacy Plaintiffs With Analyses Of Users’ Time On Facebook

    SAN FRANCISCO — A putative class of Facebook users who sued Meta Platforms Inc. over the purported sharing of their protected health information (PHI) via its pixel tool are entitled to certain analyses and reports correlating users’ time spent on the social network with Meta’s revenue, a California federal magistrate judge ruled, finding the requested info relevant to the plaintiffs’ proposed damages theory.

  • June 18, 2025

    Chrome Users Again Denied Class Certification In Google Data Collection Suit

    OAKLAND, Calif. — Two and a half years after a California federal judge declined to certify a class of Chrome browser users in their privacy suit against Google LLC, the judge handed another defeat to the plaintiffs as she found that individualized issues regarding each class member’s knowledge of, and consent to, Google’s data collection practices would predominate over common questions.

  • June 18, 2025

    N.M. Panel: Policy Term ‘For A Security Breach’ Is Ambiguous; Coverage Triggered

    ALBUQUERQUE, N.M. — A New Mexico appeals court affirmed a lower court’s summary judgment ruling that a cyber insurance policy covered an underlying third-party claim seeking payment for invoices that a now insolvent health insurer mistakenly wired to a fraudulent bank account, finding that the policy term “for a security breach” is ambiguous and must be construed in favor of the insured and the “loss of money” policy exclusions do not apply.

  • June 18, 2025

    HHS Federal Workers File Class Suit Over Erroneous Record Sharing, Firings

    WASHINGTON, D.C. — Seven employees of the U.S. Department of Health and Human Services (HHS) and its subcomponents filed a class complaint in a federal court in the District of Columbia alleging that “hopelessly error-ridden” personnel records were wrongly turned over to U.S. DOGE Service, the U.S. Office of Personnel Management (OPM) and the Office of Management and Budget (OMB) without being verified and were incorrectly used to fire 10,000 workers in violation of the Privacy Act.

  • June 17, 2025

    States Ask Bankruptcy Court To Find 23andMe Can’t Sell Users’ Genetic Data

    ST. LOUIS — Missouri federal bankruptcy court issued a summons to 23andMe Holding Co. in a declaratory judgment adversary proceeding brought by a group of U.S. states and the National Association of Attorneys General (NAAG) to prevent the financially troubled DNA-testing company from selling the genetic data of millions of its users as part of its bankruptcy process without their consent.

  • June 16, 2025

    RNC May Intervene In Suits Over ‘Integrity Of Elections’ Executive Order

    WASHINGTON, D.C. — A District of Columbia federal judge partly granted a motion by the Republican National Committee to intervene in three consolidated suits in which the Democratic National Committee (DNC) and others challenge several provisions of President Donald J. Trump’s recent executive order (EO) on “Preserving and Protecting the Integrity of American Elections.”

  • June 16, 2025

    Supreme Court Will Consider Pregnancy Center’s Jurisdictional Question

    WASHINGTON, D.C. — The U.S. Supreme Court on June 16 granted certiorari to an anti-abortion pregnancy center on its question of whether constitutional challenges to an investigative subpoena demanding the names of donors must first be adjudicated by a state court before they are ripe for federal court review.

  • June 13, 2025

    Initial OK Given To $6.3M Settlement Of Apnea Supply Firm Data Breach Suit

    INDIANAPOLIS — Preliminarily approving an agreement providing more than $6.3 million to settle a class action over data breaches experienced by a sleep apnea supply firm, an Indiana federal judge held that the parties “will likely be able to certify and approve a settlement class under Federal Rule of Civil Procedure 23.”

  • June 12, 2025

    DOGE Enjoined From Further Access To OPM Records By Federal Judge

    NEW YORK — In a 99-page ruling, a New York federal judge granted a preliminary injunction motion filed by two labor unions and a group of federal employees to halt any further access of U.S. Office of Personnel Management (OPM) computer systems and records by U.S. Department of Government Efficiency (DOGE) agents, who have not been sufficiently vetted, credentialed or trained per the Privacy Act.

  • June 12, 2025

    Data Breach Class Action Against Biotech Firm Settles For $7.5 Million

    CENTRAL ISLIP, N.Y. — Four months after preliminarily approving a $7.5 million settlement of a consolidated class action over a 2023 data breach experienced by a biotech firm, a New York federal magistrate judge granted final approval to the settlement, which provides for up to $10,000 in out-of-pocket reimbursements for class members.

  • June 12, 2025

    Class Action Alleges Insurer Intentionally Disclosed Driver’s License Numbers

    NEW YORK — A class action complaint for violation of the Driver’s Privacy Protection Act (DPPA) was brought against Lemonade Inc. in a New York federal court on June 9, alleging that the insurer knowingly and intentionally obtained, used and disclosed class members’ driver’s license numbers and other personal information on its online quoting platform that was ultimately accessed by cybercriminals.

  • June 11, 2025

    Revised, Reduced Attorney Fees Award In CPK Data Breach Suit Approved

    SANTA ANA, Calif. — After an initial attorney fees award of $800,000 was rejected and remanded by the Ninth Circuit U.S. Court of Appeals in a consolidated class action over a data breach experienced by California Pizza Kitchen Inc. (CPK), a California federal judge on June 10 approved a revised fees and costs request, which reduces the original award by more than $500,000.

  • June 11, 2025

    Some Privacy Claims Over Google’s Collection Of Health Data May Proceed

    SAN FRANCISCO — A group of anonymous plaintiffs suing Google LLC over the alleged collection and sharing of users’ health-related data saw most of their privacy and related claims survive the tech company’s second dismissal motion, with a California federal judge finding that in the second amended consolidated complaint (SAC) the plaintiffs corrected defects that led to their previous complaint being completely dismissed.

  • June 10, 2025

    Magistrate Approves $7.25M Settlement Of Patreon Privacy Violation Claims

    SAN FRANCISCO — A California federal magistrate judge granted a motion for final approval of a $7.25 million settlement to resolve claims that Patreon Inc. illegally shared its users’ video-viewing data with social media company Meta Platforms Inc., including more than $2.1 million in attorney fees, and rejected as invalid more than 900 opt-outs filed on behalf of class members by a third-party “recovery company.”

  • June 10, 2025

    1 Plaintiff, 1 Claim Remain In Marsh & McLennan Data Breach Class Action

    NEW YORK — After two dismissal rulings, discovery, an appeal, a class representative substitution and choice-of-law disputes, a 4-year-old putative class action over a 2021 data breach experienced by Marsh & McLennan Cos. Inc. has just a single remaining claim for breach of implied contract in a second amended complaint (SAC) that was filed at the direction of a New York federal judge after the most recent ruling.

  • June 10, 2025

    Emotional Distress Claim Over Hacked Apple Account Again Survives Dismissal

    SAN JOSE, Calif. — A user of Apple Inc. devices and iCloud service sufficiently alleged that the company’s failure to rectify flaws in its recovery key reset process contributed to permitting hackers to gain access to his personal data and files, a California federal judge found, denying the tech company’s motion to dismiss a claim for intentional infliction of emotional distress.

  • June 09, 2025

    Split U.S. Supreme Court Resumes DOGE Access To SSA Records

    WASHINGTON, D.C. — A U.S. Supreme Court majority on June 6 concluded that the Social Security Administration (SSA) must again provide access to agency records to a Department of Government Efficiency (DOGE) SSA team, staying a preliminary injunction issued in April by a federal judge in Maryland.

  • June 06, 2025

    4th Circuit Again Decertifies Marriott Data Breach Classes Without Another Remand

    RICHMOND, Va. — Almost two years after it decertified several classes for claims against Marriott International Inc. and its information technology provider related to a massive data breach, a Fourth Circuit U.S. Court of Appeals panel again decertified the same classes, finding them to be barred under a class action waiver that was part of the hotel chain’s contract with customers.

  • June 05, 2025

    Mass. High Court: Police Review Of Indictee’s GPS Data Didn’t Violate Privacy

    BOSTON — Law enforcement’s use of GPS data, from a man being monitored pursuant to a pretrial release agreement, to connect him with a subsequent crime did not violate his constitutional rights, a unanimous Massachusetts Supreme Judicial Court held June 4, because the man had no expectation of privacy in the data collection to which he had consented.

  • June 05, 2025

    $525,000 Settlement Of Data Breach Suit Against Property Manager Gets Initial OK

    NEW ORLEANS — A proposed agreement that would settle putative class claims brought by a former tenant against a property manager over a 2021 data breach that he says exposed his personally identifiable information (PII) received preliminary approval from a Louisiana federal judge, who deemed the $525,000 settlement fund to be “within the range of what is reasonable.”

  • June 04, 2025

    Wiretapping, Data-Sharing Claims Against Eyewear Website Dismissed For 2nd Time

    DALLAS — Almost eight months after a Texas federal judge dismissed a putative class action alleging that an eyewear retailer’s website was sharing customers’ private health information (PHI) with Meta Platforms Inc., the judge dismissed an amended complaint, finding that the plaintiffs still failed to allege that any PHI, in the form of eyewear prescriptions, was among the data that was shared.

Can't find the article you're looking for? Click here to search the Mealey's Data Privacy archive.