Federal health officials improperly handed the personal data of millions of Medicaid enrollees to Immigration and Customs Enforcement, which then passed the records to the analytics firm Palantir, according to court filings reported by NPR on July 17, 2026. The disclosures surfaced in a federal lawsuit led by California and 20 state attorneys general seeking to block ICE from using Medicaid data for immigration enforcement. For the millions of Americans whose names and addresses were in that dataset, the case is a stark reminder that even government-held health data can travel far beyond where it was meant to go.
What the court filings revealed
The Centers for Medicare & Medicaid Services (CMS) first improperly shared a dataset containing millions of names with ICE in January 2026, according to the filings. In a court document submitted last week, the Justice Department acknowledged that CMS then inadvertently reshared the same dataset a second time, saying the error happened during an effort to transfer data from states not party to the lawsuit.
From there, the records moved again. Palantir operates an app called ELITE that ICE agents use to display the addresses of noncitizens who may be targeted for deportation. In a declaration, California deputy attorney general Anna Rich described how, when the states asked what officials had done to ensure the data was purged, the government said the files had been shared over a Microsoft Teams chat and later deleted from that chat. Rich included a redacted discovery transcript that appears to show ICE personnel asking Palantir to delete the file.
The suit, led by California, asks a federal court to stop health officials from sharing Medicaid data further and to bar the administration from using it for immigration enforcement or what the plaintiffs call "population surveillance."
Why this matters beyond immigration
It is tempting to file this story under immigration policy and move on. That would miss the wider lesson. The data at the center of the case is ordinary health-program enrollment information — names, addresses, and program details of people who signed up for Medicaid. The same categories of data sit in employer HR systems, insurance databases, pharmacy records, and countless vendor apps.
When sensitive records are copied into a chat tool, forwarded to a contractor, and then "deleted" with no independent verification, the trail becomes almost impossible to audit. That is not a problem unique to one agency. It is the everyday failure mode of modern data handling: information is easy to duplicate, hard to recall, and rarely tracked once it leaves the system that created it.
The privacy rights you actually have
If you are a Medicaid enrollee, your health information is generally protected under the Health Insurance Portability and Accountability Act (HIPAA). HIPAA gives you the right to see who has accessed your records, to request an accounting of certain disclosures, and to file a complaint if you believe your data was mishandled. The U.S. Department of Health and Human Services explains these individual rights and its complaint process on its official site at hhs.gov/hipaa.
Those rights have limits. HIPAA contains carve-outs for law enforcement and national security, and litigation like the California case is precisely how courts test where those limits fall. Filing a HIPAA complaint will not, by itself, undo a disclosure that has already happened. But it creates a record, and a pattern of complaints can trigger the kind of oversight that changes agency behavior.
Where a data-privacy expert comes in
This is where professional guidance is worth the call. A qualified data-privacy or information-security consultant can help you in ways a headline cannot. First, they can assess your personal exposure: which databases hold your information, and what a realistic risk looks like for you specifically. Second, they can walk you through the practical steps — freezing credit, enabling breach alerts, tightening the settings on the apps and portals that already hold your data — that reduce harm if your records are exposed.
For organizations, the case is a live checklist. Any business that moves personal data through consumer chat tools, hands files to outside contractors, or relies on a vendor's promise to "delete" a file should treat this story as a warning. A security professional can build a data map, set retention rules, require verified deletion instead of a screenshot, and put contracts in place that make a vendor legally accountable for what it does with your customers' information. Consulting an expert before a regulator or a plaintiff's lawyer comes knocking is far cheaper than doing it after.
What to do this week
You do not need to wait for the lawsuit to resolve to act. Three steps are worth taking now.
Request an accounting of disclosures from your health plan or Medicaid office to learn who has received your information. Set up free credit monitoring and consider a credit freeze, which blocks new accounts being opened in your name. And if you believe your data was shared improperly, document what you know and file a complaint with HHS — or speak with a privacy attorney or data-security consultant about your options.
The Medicaid-to-Palantir episode is not the last of its kind. Data flows faster than the rules meant to govern it, and "we deleted it from the chat" is not the safeguard anyone should rely on. Knowing your rights, and knowing when to bring in an expert, is the difference between being a passive data point and being in control of your own information.
This article is for general information and does not constitute legal advice. For guidance on your specific situation, consult a qualified privacy attorney or data-security professional.

Daniel Miller