Privacy
Privacy Under Siege: Census Ban, AI Data Access, and Medicare Fraud
From a quiet ban on census privacy tools to a landmark ruling on AI chats, this edition covers five critical privacy developments.
Commerce Department Bans Differential Privacy for Census, Drawing Criticism
A June 2025 memo from the Commerce Department quietly banned privacy techniques used in the 2020 Census, including differential privacy, which added noise to block-level data to protect identities. The policy change was made without public posting or expert input, and aligns with a push by right-wing groups like America First Legal and the Center for Renewing America, who claim the techniques unfairly benefit Democrats. Statisticians and former Census Bureau chief scientist John Abowd said those claims are based on misinformation, adding that the ban is driven by a desire to obtain block-level citizenship data without protections. The memo identifies two alternative methods: coarsening, which aggregates data to county level, and suppression, which halts publication of certain data points. Critics warn that data sets like the Quarterly Workforce Indicators would shrink to 10% of their current size under suppression, and tools like OnTheMap, used for emergency management and evacuation routes, would be severely affected. Beth Jarosz of Georgetown University said the change would reduce visibility into the lives of disadvantaged and historically marginalized groups, and that local chambers of commerce, workforce development agencies, and emergency responders will feel the loss.
Right-Wing Groups Just Got a Big Win on the Census →
Court Ruling Confirms AI Chat Histories Can Be Seized Under Stored Communications Act
In United States v. Kim, Judge Lorna Schofield of the U.S. District Court for the Southern District of New York ruled that AI conversation histories are subject to government access under the Stored Communications Act (SCA). The defendant, Kim, sought to quash a search warrant served on OpenAI in connection with a securities fraud criminal proceeding, but the court held that he had no right to do so; his only remedy is to later attempt to suppress the evidence. The SCA, enacted in 1986, allows the government to compel providers to disclose communications upon a warrant, and a provider’s ability to object is limited to arguing that the request is unduly burdensome, which was deemed irrelevant in this case. The decision treats AI conversations with large language models as equivalent to emails or cloud storage under the SCA. The law regarding whether such conversations are covered by work product or attorney-client privilege remains unsettled and varies by judge and jurisdiction. The Kim case demonstrates that the government can readily obtain AI conversations under the SCA, underscoring privacy risks for users of chatbots.
Surprise, Surprise: More Evidence That What You Say To Your Chatbot Isn’t Always Private →
Why Your Data Appears on Broker Sites Even If You’re Careful
Data broker profiles are built from public records such as property deeds, voter registration rolls, court filings, and professional licenses, as well as commercial sign-up data from loyalty programs, warranty registrations, and real estate transactions. These sources are publicly accessible under many U.S. state laws, and brokers buy, scrape, or license them without requiring hacking or password breaches. The consequences can be severe: data broker InfoUSA reportedly sold a list of 19,000 verified elderly sweepstakes players to scammers, who stole more than $100 million. Epsilon Data Management agreed to pay $150 million to resolve a criminal charge tied to elder fraud, and two former Epsilon employees were sentenced for selling targeted lists to a fraudster who defrauded 218,000 victims of over $23.7 million. Even individuals who avoid loyalty cards and sweepstakes can have their information appear through property records, vehicle registrations, and court filings. Steps to reduce exposure include searching your name on people-search sites, replacing easy-to-guess security answers with made-up ones, being selective with loyalty programs, and using a data removal service that contacts brokers and handles recurring removals.
Why careful people still end up on data broker sites →
First American Faces Class Action Over DataTree Property Database
Four residents filed a class action complaint against First American Financial in a California federal court, accusing the title insurance company of violating state consumer laws through its DataTree product. DataTree is a nationwide property-intelligence platform that allows free and paid subscribers to access homeowners’ information, including mortgage data, lien and tax data, foreclosure status, telephone numbers, and email addresses. The company offers a free 7-day trial and a subscription plan using search credits. The plaintiffs stated they never consented to their data being used for sales purposes. The lawsuit alleges that First American used plaintiffs’ names and identity attributes in a commercial sales funnel, not merely as a passive republication of public information. Homeowners attached redacted screenshots of their property profiles on DataTree and accused First American of violating right of publicity laws in Alabama, California, Illinois, and Nevada. They seek to certify classes of members who were identified in DataTree between one and four years before the suit was filed. An attorney for the plaintiffs declined to comment, and a First American spokesperson did not respond to a request for comment.
First American sued by homeowners over its property database →
International Criminal Networks Scam Medicare Billions Using AI Voice Bots and Hacked Data
International criminal networks are stealing billions of taxpayer dollars from Medicare and Medicaid through high-tech scams involving hacked patient data and AI voice bots. Scammers hack sensitive patient data and sell it on the dark web, or use it to bill for fake medical equipment or services. AI voice bots posing as U.S. healthcare workers coax information from seniors over the phone, often from Europe or Asia. One Philippines-based outfit trained AIs to speak like elderly Americans when insurance companies called about suspicious claims. Synthetic identities built from breached data are used to establish fraudulent coverage or fabricate consent, according to a March 2026 report by cybersecurity company Pindrop to CMS. Ibrahim Khaldoon Hilmi was arrested in Cyprus and Turkey and handed over to U.S. agents for allegedly running a $3.74375 billion Medicare fraud scheme involving a medical device scam; he faces federal charges in Florida. A Russian mob ‘phantom catheter’ scam attempted to bill $10 billion using stolen patient data of over one million Americans, triggering 400,000 complaints. In January, Kazakh national Anuar Abdrakhmanov was charged in Chicago federal court with conspiracy to commit money laundering in a scheme that billed $666 million. In June, Herbert Leon Kimble was arrested at a casino in the Philippines for orchestrating an attempted $1.2 billion Medicare fraud scheme using a Philippine call center. The scams relied on U.S.-based bank tellers who overlooked shady transactions, and crypto is heavily used for laundering. 1.3 million Americans were issued new Medicare beneficiary numbers in a fraud prevention effort in spring 2025.