Business
Column: How a legal loophole allows antiabortion prosecutors to obtain women's secret health data
The American legal system has a message for women concerned about their abortion rights: Don’t make the mistake of thinking that your pharmacist is your friend.
Thanks to a gaping loophole in federal healthcare regulations, some of our leading drug store chains turn over customers’ most sensitive private healthcare information to law enforcement agencies, even without a warrant.
That’s the finding of a subcommittee headed by Sen. Ron Wyden (D-Ore.), which learned that all eight of the nation’s largest pharmacy chains have routinely turned over prescription records of thousands of Americans to law enforcement agencies or other government entities secretly without a warrant.
Medical care procured outside a patient’s home state increasingly leaves a digital trail that will easily make its way back to the patient’s domicile.
— Carleen M. Zubrzycki, University of Connecticut
The chains are CVS, Walgreens, Cigna, Optum Rx, Walmart, Kroger, Rite Aid and Amazon. CVS, Kroger and Rite Aid, which have a total of about 11,000 locations nationwide, don’t require store staff to run the requests past company lawyers before complying.
Only Amazon notifies customers that it received a subpoena or warrant for their prescription data.
Wyden’s committee sought briefings from the pharmacy chains after the Supreme Court’s 2022 Dobbs decision overturned nationwide abortion rights.
Since then, Wyden told me by email, “Republican states across the country have criminalized abortion.” That placed privacy “under threat like never before.” He said his goal is to urge “the executive branch to do everything in its power to stop far-right prosecutors and politicians from using women’s private records against them.”
The briefings, Wyden and fellow subcommittee Democrats informed Health and Human Services Secretary Xavier Becerra in a Dec. 12 letter, “made clear that these companies’ privacy practices vary widely, in ways that seriously impact patient privacy.”
None of the pharmacies require a warrant before turning over requested data; all “will turn medical records over in response to a mere subpoena,” which often doesn’t have to be signed by a judge.
That’s a flaw in the Health Insurance Portability and Accountability Act of 1996, or HIPAA, which purports to protect individuals’ health information from disclosure by providers except in narrow circumstances.
CVS spokeswoman Amy Thibault told me by email, “HIPAA does not require law enforcement to obtain a warrant or judge-issued subpoena before they make a lawful request for records containing PHI.” She said that CVS staff “are trained how to appropriately respond to lawful requests from regulatory agencies and law enforcement.”
HIPAA applies to pharmacies as well as physicians and hospitals. What sets them apart, however, is the breadth of their networks— it’s a rare hospital or physician’s practice that maintains a database that can be accessed coast to coast.
Wyden and his colleagues urged Becerra to tighten HIPAA regulations to require pharmacies to “insist on a warrant” before turning over private health data, so that law enforcement agencies have to defend their demands in court.
Some of America’s leading drug store chains turn over customers medical records to law enforcement agencies without even requiring a warrant, exposing women seeking abortions to prosecution by anti-abortion states.
(Senate Finance Committee)
Health and Human Services isn’t the only agency concerned with the misuse of personal data. The Federal Trade Commission on Tuesday charged the data broker Outlogic with selling consumers’ location information extracted from smartphone apps without their permission.
The geolocation data, the FTC said, “could be used to track people’s visits to sensitive locations such as medical and reproductive health clinics, places of religious worship and domestic abuse shelters.” According to a statement by FTC Chair Lina Khan, in at least one contract the company had tracked “Ohio residents who visited specific doctors, including cardiologists, gastroenterologists, or endocrinologists, and then pharmacies or specialty infusion centers.”
The FTC’s legal complaint said the result could include “loss of privacy, exposure to discrimination, physical violence, emotional distress, and other harms.”
In a settlement with Outlogic reached Tuesday, the FTC prohibited the company from selling or sharing any “sensitive location data,” including data involving “locations that provide services to LGBTQ+ people such as bars or service organizations,” “locations of public gatherings of individuals at political or social demonstrations or protests” and data that could be used “to determine the identity or location of a specific individual.”
Outlogic will also have to delete or destroy any such data already collected, and provide consumers with easy ways to refuse permission for their data to be sold and to find out to whom it has already been sold.
Becerra hasn’t responded to the committee’s letter, but his agency did launch a rule-making procedure in April aimed at prohibiting the disclosure of personal information about a person’s reproductive healthcare by a provider, including a pharmacy, in a state where the healthcare is legal, but sought for an investigation or prosecution in a state where it’s banned.
But the Health and Human Services initiative is still only a proposal, not a rule. Several factors have made it more urgent.
The so-called interoperability of medical data is generally reckoned to be a good thing. Pharmacists should have access to the full range of a customer’s prescriptions, for example, so they can watch out for dangerous interactions among medicines that may have been missed by doctors, especially if one patient is treated by multiple physicians.
Those checks have been made even easier by the growth of national drug chains, which have supplanted the mom-and-pop drugstores that used to be common in America. Now one database can provide patient information to thousands of affiliated pharmacists coast to coast.
But the Supreme Court’s overturning of abortion rights in 2022 converted that boon into a potential peril by turning judgments about medical procedures over to the states.
“There are now categories of care in which states have taken dramatically different approaches to whether that care should be available,” says Carmel Shachar, an expert on health law and policy at Harvard Law School. Abortion is the most evident area, but divergences in state law increasingly apply to gender-affirming care and substance abuse treatment.
Those divergences, Shachar told me, make the relevant medical records especially sensitive to the point where they need to be protected from law enforcement.
But expansive databases may make that difficult — a prosecutor in antiabortion Texas might be prevented by a medical shield law from accessing data about a Texan’s legal treatment in Massachusetts, but theoretically could subpoena it from a pharmarcy chain’s branch in Texas.
The challenge goes beyond simply shielding direct evidence of a legal abortion — such as a prescription for mifepristone — from prying law enforcement eyes in an antiabortion state.
“There’s a perception that abortions or gender-affirming care exist on their own islands separate from other medical care,” Shachar says. “But somebody who is medically literate can read between the lines of a medical record to see if an abortion happened.”
For instance, consider if a medical record showed that a woman was pregnant and records show a bit later that she’s begun to take chemotherapy treatment for cancer that would be incompatible with pregnancy.
“That might be suggestive that she was pregnant and is no longer pregnant, with no baby to show for it,” Shachar says. “How much of a medical record you need to protect to truly protect the privacy of people who have had abortions or gender-affirming care is murky.”
Placing a legal moat around medical records of an out-of-state abortion may be difficult. “Medical care procured outside a patient’s home state increasingly leaves a digital trail that will easily make its way back to the patient’s domicile,” observed Carleen M. Zubrzycki of the University of Connecticut in a 2022 law review paper.
When any such patient “receives any subsequent medical care — abortion-related or not — in her state of residence,” she wrote, “the odds are high that her home-state providers will access and incorporate her entire medical record into their own records.” That would undermine the efforts of safe-haven states to protect visiting patients by providing “slam-dunk evidence that could be used in out-of-state litigation to punish abortions.”
The determination of antiabortion activist politicians to narrow women’s reproductive healthcare options is explicit and persistent.
On July 7, 2022 — just two weeks after the Supreme Court handed down the Dobbs decision — a dozen right-wing Texas state legislators warned the Dallas law firm Sidley Austin that it might face criminal charges for having “decided to reimburse the travel costs of employees who leave Texas to murder their unborn children” — i.e., who leave Texas to obtain legal abortions elsewhere.
Last February, the attorneys general of 20 red states, led by Missouri Atty. Gen. Andrew Bailey, sent threatening letters to CVS, Walgreens, Rite Aid, Albertsons, Walmart, Kroger and Costco warning them that federal law prohibited them from using the mail to distribute drugs for medication abortion, such as mifepristone.
The letters cited the antique and long-discredited 1873 statute known as the Comstock Act after its bluenosed progenitor. The law’s applicability to abortion rights has long been dismissed by legal scholars. But it was at the core of a ruling by U.S. District Judge Matthew Kacsmaryk of Texas invalidating the Food and Drug Administration’s approval of mifepristone.
The FDA’s rules on mifepristone, which allow the drug to be taken by patients outside a hospital or doctor’s office, are currently before the Supreme Court.
The quest by antiabortion prosecutors for data pertaining to out-of-state medical procedures is destined to grow. The proportion of patients traveling out of their home states to obtain abortions has doubled over the last three years to 20% in the first six months of 2023 from 10% in the same period in 2020, according to the Guttmacher Institute.
The rate is especially high in safe-haven states bordered by antiabortion states, such as Illinois, where out-of-state patients increased in early 2023 to 18,870 from 5,570 three years earlier. New Mexico and Colorado experienced sharp increases for the same reason. In California, where abortions increased by 15,200 in the statistical period, only 16% of the increase was due to out-of-state patients — presumably because abortion is legal in the nearby states of Nevada, Oregon and Washington.
What is becoming clear as state legislators take advantage of the Supreme Court’s evisceration of medical privacy rights in the Dobbs decision, is that the stakes are destined to become magnified in the absence of federal action. People suffering from infectious diseases linked to what legislators disdain as immoral behavior such as HIV or hepatitis C might face increased discrimination or limits on access to public healthcare programs, for example.
“In terms of states diverging in what medical care is allowed or isn’t allowed,” Shachar says, “abortion and gender-affirming care might be the tip of the iceberg.”
Business
How our AI bots are ignoring their programming and giving hackers superpowers
Welcome to the age of AI hacking, in which the right prompts make amateurs into master hackers.
A group of cybercriminals recently used off-the-shelf artificial intelligence chatbots to steal data on nearly 200 million taxpayers. The bots provided the code and ready-to-execute plans to bypass firewalls.
Although they were explicitly programmed to refuse to help hackers, the bots were duped into abetting the cybercrime.
According to a recent report from Israeli cybersecurity firm Gambit Security, hackers last month used Claude, the chatbot from Anthropic, to steal 150 gigabytes of data from Mexican government agencies.
Claude initially refused to cooperate with the hacking attempts and even denied requests to cover the hackers’ digital tracks, the experts who discovered the breach said. The group pummelled the bot with more than 1,000 prompts to bypass the safeguards and convince Claude they were allowed to test the system for vulnerabilities.
AI companies have been trying to create unbreakable chains on their AI models to restrain them from helping do things such as generating child sexual content or aiding in sourcing and creating weapons. They hire entire teams to try to break their own chatbots before someone else does.
But in this case, hackers continuously prompted Claude in creative ways and were able to “jailbreak” the chatbot to assist them. When they encountered problems with Claude, the hackers used OpenAI’s ChatGPT for data analysis and to learn which credentials were required to move through the system undetected.
The group used AI to find and exploit vulnerabilities, bypass defences, create backdoors and analyze data along the way to gain control of the systems before they stole 195 million identities from nine Mexican government systems, including tax records, vehicle registration as well as birth and property details.
AI “doesn’t sleep,” Curtis Simpson, chief executive of Gambit Security, said in a blog post. “It collapses the cost of sophistication to near zero.”
“No amount of prevention investment would have made this attack impossible,” he said.
Anthropic did not respond to a request for comment. It told Bloomberg that it had banned the accounts involved and disrupted their activity after an investigation.
OpenAI said it is aware of the attack campaign carried out using Anthropic’s models against the Mexican government agencies.
“We also identified other attempts by the adversary to use our models for activities that violate our usage policies; our models refused to comply with these attempts,” an OpenAI spokesperson said in a statement. “We have banned the accounts used by this adversary and value the outreach from Gambit Security.”
Instances of generative AI-assisted hacking are on the rise, and the threat of cyberattacks from bots acting on their own is no longer science fiction. With AI doing their bidding, novices can cause damage in moments, while experienced hackers can launch many more sophisticated attacks with much less effort.
Earlier this year, Amazon discovered that a low-skilled hacker used commercially available AI to breach 600 firewalls. Another took control of thousands of DJI robot vacuums with help from Claude, and was able to access live video feed, audio and floor plans of strangers.
“The kinds of things we’re seeing today are only the early signs of the kinds of things that AIs will be able to do in a few years,” said Nikola Jurkovic, an expert working on reducing risks from advanced AI. “So we need to urgently prepare.”
Late last year, Anthropic warned that society has reached an “inflection point” in AI use in cybersecurity after disrupting what the company said was a Chinese state-sponsored espionage campaign that used Claude to infiltrate 30 global targets, including financial institutions and government agencies.
Generative AI also has been used to extort companies, create realistic online profiles by North Korean operatives to secure jobs in U.S. Fortune 500 companies, run romance scams and operate a network of Russian propaganda accounts.
Over the last few years, AI models have gone from being able to manage tasks lasting only a few seconds to today’s AI agents working autonomously for many hours. AI’s capability to complete long tasks is doubling every seven months.
“We just don’t actually know what is the upper limit of AI’s capability, because no one’s made benchmarks that are difficult enough so the AI can’t do them,” said Jurkovic, who works at METR, a nonprofit that measures AI system capabilities to cause catastrophic harm to society.
So far, the most common use of AI for hacking has been social engineering. Large language models are used to write convincing emails to dupe people out of their money, causing an eight-fold increase in complaints from older Americans as they lost $4.9 billion in online fraud in 2025.
“The messages used to elicit a click from the target can now be generated on a per-user basis more efficiently and with fewer tell-tale signs of phishing,” such as grammatical and spelling errors, said Cliff Neuman, an associate professor of computer science at USC.
AI companies have been responding using AI to detect attacks, audit code and patch vulnerabilities.
“Ultimately, the big imbalance stems from the need of the good-actors to be secure all the time, and of the bad-actors to be right only once,” Neuman said.
The stakes around AI are rising as it infiltrates every aspect of the economy. Many are concerned that there is insufficient understanding of how to ensure it cannot be misused by bad actors or nudged to go rogue.
Even those at the top of the industry have warned users about the potential misuse of AI.
Dario Amodei, the CEO of Anthropic, has long advocated that the AI systems being built are unpredictable and difficult to control. These AIs have shown behaviors as varied as deception and blackmail, to scheming and cheating by hacking software.
Still, major AI companies — OpenAI, Anthropic, xAI, and Google — signed contracts with the U.S. government to use their AIs in military operations.
This last week, the Pentagon directed federal agencies to phase out Claude after the company refused to back down on its demand that it wouldn’t allow its AI to be used for mass domestic surveillance and fully autonomous weapons.
“The AI systems of today are nowhere near reliable enough to make fully autonomous weapons,” Amodei told CBS News.
Business
iPic movie theater chain files for bankruptcy
The iPic dine-in movie theater chain has filed for Chapter 11 bankruptcy protection and intends to pursue a sale of its assets, citing the difficult post-pandemic theatrical market.
The Boca Raton, Fla.-based company has 13 locations across the U.S., including in Pasadena and Westwood, according to a Feb. 25 filing in U.S. Bankruptcy Court in the Southern District of Florida, West Palm Beach division.
As part of the bankruptcy process, the Pasadena and Westwood theaters will be permanently closed, according to WARN Act notices filed with the state of California’s Employment Development Department.
The company came to its conclusion after “exploring a range of possible alternatives,” iPic Chief Executive Patrick Quinn said in a statement.
“We are committed to continuing our business operations with minimal impact throughout the process and will endeavor to serve our customers with the high standard of care they have come to expect from us,” he said.
The company will keep its current management to maintain day-to-day operations while it goes through the bankruptcy process, iPic said in the statement. The last day of employment for workers in its Pasadena and Westwood locations is April 28, according to a state WARN Act notice. The chain has 1,300 full- and part-time employees, with 193 workers in California.
The theatrical business, including the exhibition industry, still has not recovered from the pandemic’s effect on consumer behavior. Last year, overall box office revenue in the U.S. and Canada totaled about $8.8 billion, up just 1.6% compared with 2024. Even more troubling is that industry revenue in 2025 was down 22.1% compared with pre-pandemic 2019’s totals.
IPic noted those trends in its bankruptcy filing, describing the changes in consumer behavior as “lasting” and blaming the rise of streaming for “fundamentally” altering the movie theater business.
“These industry shifts have directly reduced box office revenues and related ancillary revenues, including food and beverage sales,” the company stated in its bankruptcy filing.
IPic also attributed its decision to rising rents and labor costs.
The company estimated it owed about $141,000 in taxes and about $2.7 million in total unsecured claims. The company’s assets were valued at about $155.3 million, the majority of which coming from theater equipment and furniture. Its liabilities totaled $113.9 million.
The chain had previously filed for bankruptcy protection in 2019.
Business
Startup Varda Space Industries snags former Mattel plant in El Segundo
In an expansion of its business of processing pharmaceuticals in Earth’s orbit, Varda Space Industries is renting a large El Segundo plant where toy manufacturer Mattel used to design Hot Wheels and Barbie dolls.
The plant in El Segundo’s aerospace corridor will be an extension of Varda Space Industries’ headquarters in a much smaller building on nearby Aviation Boulevard.
Varda will occupy a 205,443-square-foot industrial and office campus at 2031 E. Mariposa Ave., which will give it additional capacity to manufacture spacecraft at scale, the company said.
Originally built in the 1940s as an aircraft facility, the complex has a history as part of aerospace and defense industries that have long shaped the South Bay and is near a host of major defense and space contractors. It is also close to Los Angeles Air Force Base, headquarters to the Space Systems Command.
Workers test AstroForge’s Odin asteroid probe, which was lost in space after launch this year.
(Varda Space Industries)
Varda is one of a new generation of aerospace startups that have flourished in Southern California and the South Bay over the last several years, particularly in El Segundo, often with ties to SpaceX.
Elon Musk’s company, founded in 2002 in El Segundo, has revolutionized the industry with reusable rockets that have radically lowered the cost of lifting payloads into space. Though it has moved its headquarters to Texas, SpaceX retains large-scale operations in Hawthorne.
Varda co-founder and Chief Executive Will Bruey is a former SpaceX avionics engineer, and the company’s spacecraft are launched on SpaceX’s workhorse Falcon 9 rockets from Vandenberg Space Force Base in Santa Barbara County.
Varda makes automated labs that look like cylindrical desktop speakers, which it sends into orbit in capsules and satellite platforms it also builds. There, in microgravity, the miniature labs grow molecular crystals that are purer than those produced in Earth’s gravity for use in pharmaceuticals.
It has contracts with drug companies and also the military, which tests technology at hypersonic speeds as the capsules return to Earth.
Its fifth capsule was launched in November and returned to Earth in late January; its next mission is set in the coming weeks. Varda has more than 10 missions scheduled on Falcon 9s through 2028.
For the last several decades, the Mariposa Avenue property served as the research and development center for Mattel Toys. El Segundo has also long been a center for the toy industry as companies like to set up shop in the shadow of Mattel.
The Mattel facility “has always been an exceptional property with a legacy tied to aerospace innovation, and leasing to Varda Space Industries feels like a natural continuation of that story,” said Michael Woods, a partner at GPI Cos., which owns the property.
“We are proud to support a company that is genuinely pushing the boundaries of what’s possible, and are excited to watch Varda grow and thrive here in El Segundo,” Woods said.
As one of the country’s most active hubs of aerospace and defense innovation, El Segundo has seen its industrial property vacancy fall to 3.4% on demand from space companies, government contractors and technology startups, real estate brokerage CBRE said.
Successful startups often have to leave the neighborhood when they want to expand, real estate broker Bob Haley of CBRE said. The 9-acre Mattel facility was big enough to keep Varda in the city.
Last year, Varda subleased about 55,000 square feet of lab space from alternative protein company Beyond Meat at 888 Douglas St. in El Segundo, which it started moving into in June.
Varda will get the keys to its new building in December and spend four to eight months building production and assembly facilities as it ramps up operations. By the end of next year, it expects to have constructed 10 more spacecraft.
In the future, Varda could consolidate offices there, given its size. Currently, though, the plan is to retain all properties, creating a campus of three buildings within a mile of one another that are served by the company’s transportation services, Chief Operating Officer Jonathan Barr said.
“We already have Varda-branded shuttles running up and down Aviation Boulevard,” he said.
-
World1 week agoExclusive: DeepSeek withholds latest AI model from US chipmakers including Nvidia, sources say
-
Massachusetts1 week agoMother and daughter injured in Taunton house explosion
-
Wisconsin3 days agoSetting sail on iceboats across a frozen lake in Wisconsin
-
Maryland4 days agoAM showers Sunday in Maryland
-
Florida4 days agoFlorida man rescued after being stuck in shoulder-deep mud for days
-
Denver, CO1 week ago10 acres charred, 5 injured in Thornton grass fire, evacuation orders lifted
-
Massachusetts2 days agoMassachusetts man awaits word from family in Iran after attacks
-
Oregon6 days ago2026 OSAA Oregon Wrestling State Championship Results And Brackets – FloWrestling