Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Researchers find bias in chest X-ray AI classifiers against women, Hispanic and Medicaid patients
A study by the University of Toronto, Vector Institute, and MIT found that AI classifiers trained on public chest X-ray datasets exhibited racial, gender, and socioeconomic bias. Female patients, Hispanic patients, and those with Medicaid insurance were disproportionately affected, with the classifiers often providing incorrect diagnoses for Medicaid patients. The researchers attributed the bias to imbalanced training data and called for rigorous fairness analyses before clinical deployment.
2 source articles · read the reporting →
Kmart's facial recognition system for refund fraud found unlawful by Privacy Commissioner
Kmart Australia deployed facial recognition technology in 28 stores from June 2020 to July 2022, capturing biometric data of every customer entering the stores and those at returns counters to detect refund fraud. The system collected sensitive information without notifying customers or obtaining their consent. The Australian Privacy Commissioner found that Kmart breached the Privacy Act, as the exemption for unlawful activity did not justify the indiscriminate and disproportionate collection of biometric data from thousands of individuals. Kmart has ceased using the system and cooperated with the investigation.
- Company involved
- Kmart Australia Limited
7 source articles · read the reporting →
University of Chicago Medical Center sued over sharing patient data with Google
The University of Chicago Medical Center is accused in a class-action lawsuit of sharing hundreds of thousands of patient medical records with Google without proper de-identification or patient consent. The data, from patients treated between 2009 and 2016, allegedly included dates and provider notes that could allow re-identification. The lawsuit claims Google sought the records to develop its own electronic health record system and predictive models. The hospital and Google deny wrongdoing, stating the research partnership was legal and compliant with HIPAA.
- Company involved
- University of Chicago Medical Center
1 source article · read the reporting →
Arizona Unemployment Applicants Required to Submit Facial Recognition
People applying for unemployment benefits in Arizona must verify their identity via facial recognition software provided by ID.me. If the system fails to match a selfie to a photo ID, applicants can be denied benefits unless they successfully complete a video chat with a referee. A class-action lawsuit filed in June 2021 alleges that the practice violates due process rights and discriminates against people of colour.
- Company involved
- Arizona Department of Economic Security
- AI system involved
- ID.me
1 source article · read the reporting →
Hospital Denies Pain Medication to Patient Based on Narx Score
Elizabeth Amirault, a 34-year-old chronic pain patient, was denied narcotic pain medication during a hospital visit in Fort Wayne, Indiana, in August 2022. A nurse practitioner told her that her Narx Score, generated by Bamboo Health's NarxCare platform, was too high to prescribe opioids. The algorithm uses prescription drug monitoring data to assess risk of misuse, but critics say it can harm patients by cutting off needed care. Amirault believes her score was unfairly high due to her multiple surgeries and doctors.
- AI system involved
- NarxCare
3 source articles · read the reporting →
Thailand halts iris-scan crypto scheme and deletes 1.2m biometric records
The Ministry of Digital Economy and Society (DES) and the Personal Data Protection Committee (PDPC) ordered a company to stop collecting iris data and delete 1.2 million citizen records. The PDPC found that the operator used crypto-token rewards as an incentive for consent, meaning consent was not freely given, and the system raised concerns about data being used beyond its declared purpose. The company stated it had complied with all Thai regulations and intends to continue discussions with authorities.
- Company involved
- The company behind the iris-scan system (not named)
- AI system involved
- Iris-scan system
4 source articles · read the reporting →
Arkansas algorithm slashed home care for disabled people, causing suffering
In Arkansas and other states, algorithms were used to allocate home care hours for disabled and elderly people, replacing nurse judgments. The system assigned hours based on a scoring tool that failed to account for specific disabilities, leading to drastic cuts. Many suffered severe harm, including bed sores, missed meals, and one death. After lawsuits, Arkansas's system was thrown out in 2018, and Idaho's was declared unconstitutional.
- Company involved
- Arkansas state government
1 source article · read the reporting →
DFFH breaches privacy by using ChatGPT in child protection report
A child protection worker at the Department of Families, Fairness and Housing (DFFH) used ChatGPT to draft a Protection Application Report for the Children’s Court, entering sensitive personal information about a child. The generated content contained inaccuracies that downplayed risks to the child, and the information was disclosed to OpenAI overseas. An investigation by the Office of the Victorian Information Commissioner found DFFH failed to ensure accuracy and protect personal information, contravening IPPs 3.1 and 4.1. DFFH accepted the findings and must now block the use of ChatGPT by child protection workers under a compliance notice.
- Company involved
- Department of Families, Fairness and Housing
- AI system involved
- ChatGPT
9 source articles · read the reporting →
Poland's Ministry of Labor profiles unemployed with discriminatory algorithm
In May 2015, Poland's Ministry of Labor and Social Policy introduced an algorithmic system to profile unemployed people into three categories based on their readiness to work, location, and disabilities. The system is accused of being discriminatory and lacking transparency, as it uses default criteria that may lead to social exclusion. A report by the Panoptykon Foundation in October 2015 highlighted these issues and recommended reforms, including granting the right to appeal.
- Company involved
- Ministry of Labor and Social Policy
10 source articles · read the reporting →
Tenant screening software denies housing to disabled Latino man in Connecticut
In 2016, Carmen Arroyo requested to move her disabled son Mikhail into a larger apartment in the same complex. The landlord, WinnResidential, used CoreLogic's CrimSafe tenant screening software, which flagged a dropped retail theft charge against Mikhail as disqualifying. The landlord rejected the application without explanation. Arroyo sued CoreLogic and WinnResidential under the Fair Credit Reporting Act and the Fair Housing Act, alleging that the software disproportionately excludes people of colour. The case was scheduled for trial in August 2021.
- Company involved
- WinnResidential
- AI system involved
- CrimSafe
10 source articles · read the reporting →
Telangana algorithm denied food to thousands of poor families
The Telangana government's algorithmic system Samagra Vedika wrongfully denied subsidised food to thousands of poor families by incorrectly tagging them as ineligible. The system, developed by Posidex Technologies, misidentified individuals across databases, leading to false positives. Affected families, including 67-year-old widow Bismillah Bee, were forced to prove their eligibility, often unsuccessfully. A Supreme Court case ordered re-verification, but many remain excluded.
- Company involved
- Government of Telangana
- AI system involved
- Samagra Vedika
8 source articles · read the reporting →
Illinois DCFS ends unreliable predictive analytics program for child abuse risk
The Illinois Department of Children and Family Services ended its Rapid Safety Feedback program, which used data mining to predict child abuse risk, after the agency's director called the technology unreliable. The system, developed by Eckerd Connects and Mindshare Technology, assigned risk scores to children but failed to flag several high-profile child deaths. The program was also criticised for overwhelming caseworkers with alerts and for potential bias against poor children of colour. DCFS decided not to renew the contract.
- Company involved
- Illinois Department of Children and Family Services
- AI system involved
- Rapid Safety Feedback
10 source articles · read the reporting →
Lawsuit: AI Illegally Recorded Doctor-Patient Encounters - BankInfoSecurity
The system recorded and transcribed patient-doctor conversations without patients' informed consent.
- Company involved
- Sutter Health and MemorialCare
- AI system involved
- Abridge AI platform
1 source article · read the reporting →