Author: Jaime Farrant

Your Security Camera Vendor Wants to Cover Your Bathroom – Is that Worth 3 Years in Jail?

A security vendor offers you a great deal: a full camera package for your office or clinic, including units for “every room” — bathrooms included. Before you say yes, here’s the one word that should stop you: no.

Installing a camera in a bathroom isn’t a gray area. In most states, it’s either a specific criminal offense, an actionable civil tort, or both — regardless of whether you own the building, whether employees consented to “general” workplace monitoring, or whether your intent was purely about theft prevention.

All Kinds of Laws and Regulations Are Against Your Vendor’s Sales Pitch

Video surveillance law in the U.S. is a patchwork, but one principle is close to universal: people have a reasonable expectation of privacy in spaces where they may be nude or partially undressed — bathrooms, locker rooms, and changing areas top that list in nearly every jurisdiction.

The following layers of law apply here:

1. The federal wiretap/ECPA gap doesn’t help you here. Most security cameras don’t record audio, which is why they generally fall outside the federal Wiretap Act and the Electronic Communications Privacy Act (those statutes govern communications, not silent video). Business owners sometimes hear “no audio recorded, no ECPA problem” and assume that means video is unregulated. It isn’t. ECPA’s silence on soundless video just means you have to look elsewhere — and state law fills that gap fast, especially for restrooms.

2. State statutes specifically ban restroom and changing-area recording. California, for example, expressly forbids video recording in restrooms, locker rooms, and places where people change clothes. Many states have similar “video voyeurism” or “unlawful surveillance” statutes that criminalize recording — or even just installing recording equipment — in a place where someone has a reasonable expectation of privacy, whether or not any footage is ever viewed or used. These are often felony-level offenses, and consent from you as the business owner is irrelevant; the person being recorded is the one whose consent (or knowledge) matters.

3. Healthcare and other regulated settings add another layer. If you run a medical office, a bathroom camera also raises immediate collateral problems: patients or staff visible on camera in a restroom implicates dignity and privacy obligations that go well beyond HIPAA’s technical safeguards — it’s the kind of fact pattern that turns into a licensing board complaint, a media story, or both.

4. Even without a specific statute, common law will find you. Every U.S. jurisdiction recognizes some version of the tort of intrusion upon seclusion: intentionally intruding on someone’s private affairs in a way that would be “highly offensive to a reasonable person.” A camera in a bathroom is the textbook example courts use to illustrate this tort. That means even in a state without a dedicated criminal statute, an employee, patient, or customer who discovers the camera can sue you civilly — and juries tend to have little patience for this fact pattern.

What Does Puerto Rico’s Constitution and Penal Code Say?

If you operate in Puerto Rico, your exposure is arguably higher than in the 50 states, as the right to privacy here isn’t left to a patchwork of state statutes and common-law torts. It’s written directly into the Constitution.

Article II, Section 8 of the Puerto Rico Constitution states: “Toda persona tiene derecho a protección de ley contra ataques abusivos a su honra, a su reputación y a su vida privada o familiar” (Every person has the right to protection of law against abusive attacks on their honor, reputation, and private or family life). What makes this different from the U.S. Constitution is that the Puerto Rico Supreme Court has held that this right applies directly between private parties, not just against government action. In Arroyo v. Rattan Specialties, Inc., 117 D.P.R. 35 (1986), the Court held that the right to privacy operates ex propio vigore — on its own force — and can be asserted by one private citizen against another, including an employer against an employee. That means a bathroom camera dispute in Puerto Rico doesn’t need a separate statute to become a constitutional violation; the Constitution itself solves the controversy.

The Puerto Rico Penal Code then backs this up with a specific criminal provision. Article 168 of the Puerto Rico Penal Code, titled “Illegal recording of images”, makes it a crime for any person, without legal justification or a legitimate investigative purpose, to use electronic or digital video equipment — with or without audio — to conduct secret surveillance in private places, or in any other place where a reasonable expectation of privacy exists. A bathroom is about as clear an example of that as exists. Conviction of this crime carries a 3 year imprisonment penalty, and if the convicted party is a corporation (or any legal person), they face a criminal fine of up to $10,000, on top of civil liability.

Put together, that’s 3 independent legal problems stacked on top of each other for accepting the salesperson’s offer: a constitutional privacy violation that doesn’t require a lawsuit-specific statute to exist, a specific criminal statute naming the conduct, and civil liability for damages. There’s no version of “we didn’t think it applied to us” that survives this situation.

What Will “Getting This Wrong” Cost You?

You will face real exposure across all fronts, notably:

  • Criminal liability: Many state voyeurism/unlawful surveillance statutes are felonies, carrying fines and potential jail time for the person who installs or operates the equipment — that could be you, personally, not just “the business.”
  • Civil damages: Intrusion-upon-seclusion claims, among other tort claims, can result in compensatory damages, and courts in the US have allowed punitive damages where the conduct is found egregious — a bathroom camera is close to the paradigm case.
  • Employment claims: If the person recorded is an employee, expect this to also surface as a hostile work environment or wrongful termination claim if discipline follows the discovery.
  • Reputational cost: Unlike a data breach notice, this is the kind of story that runs on local news with your business’s name in the headline. There’s no regulator fine that costs you more than the client and patient trust it destroys.

Why Should You Care About This?

Because although you might think the sales pitch sounds reasonable, you could end up in a lot of trouble. “Fully covered and protected business” sounds like a good security practice, and most business owners installing these systems aren’t trying to do anything invasive — they’re thinking about delivery problems, break-ins, shoplifting, and slip-and-fall liability. However, your good intent doesn’t matter for most of these statutes, and it won’t matter to a jury either. The law doesn’t ask whether you meant well; it asks whether a reasonable person would find being recorded in that space highly offensive. In a bathroom, the answer is already decided.

This is also a useful moment to audit your entire camera plan, not just the bathroom question — because the same vendor conversation is a good opportunity to think through where cameras are legally fine (entrances, sales floors, hallways, parking areas) versus where they cross the line (restrooms, break-rooms used for nursing mothers, private offices with an expectation of confidentiality).

What Can You Do to Comply?

  1. Decline any bathroom, locker room, or changing-area camera outright. There’s no notice, consent form, or signage that fixes this. Don’t install it, and don’t let a vendor bundle it into a package “in case you change your mind.”
  2. Map your camera locations against expectation-of-privacy zones. Entrances, registers, storage, parking, and common work areas are generally fine. Restrooms, changing rooms, and private offices are not.
  3. Put your monitoring policy in writing. For the cameras you do install, a written policy — reviewed by an attorney — that discloses locations, purpose, and retention helps establish notice and reduces the risk of a monitoring-related claim from staff.
  4. Check your state’s specific statute. Voyeurism and unlawful-surveillance laws vary — some cover only “for sexual gratification” purposes, others cover any recording in a private space regardless of purpose. If you operate in Puerto Rico, the relevant provision is Article 168 of the Penal Code — broader than many mainland statutes since it isn’t limited to a sexual-purpose requirement.
  5. Train whoever manages the footage. Access controls and retention limits for legitimate camera footage matter too — who can view it, how long it’s kept, and how it’s secured.

The Bottom Line

Say yes to the cameras. Say no to the bathroom units — every time, no exceptions, regardless of how the package is bundled or how good the discount is. This is one of the few areas of privacy law where there’s no compliant way to do the thing at all; the only right answer is not installing it.

If you’re building out a security camera plan for your office, clinic, or retail space and want a compliance check before you sign anything, book a consultation — better to ask before the cameras go up than after.

This post is for general informational purposes and does not constitute legal advice. Camera and surveillance laws vary by state; consult an attorney about the rules that apply to your specific location and industry.

Duration of Status Is Over. Will My Visa Now Have a Deadline?

For nearly 50 years, F-1 students, J-1 exchange visitors, and I-visa foreign media representatives have lived under one of the most forgiving rules in U.S. immigration law: “duration of status,” or D/S. As long as you were still enrolled in school, still in your program, or still doing your job, your admission simply didn’t expire. No countdown clock, no renewal deadline, no fixed date circled on the calendar.

That era ends on September 15, 2026.

On July 17, 2026, the Department of Homeland Security published a final rule eliminating D/S for F, I and J nonimmigrants and replacing it with a fixed admission period, capped at 4 years, after which you must either finish your program, get approved for an extension, or leave. If you’re currently in the U.S. on one of these visas — or you’re an employer, school, or program sponsor who works with people who are — take a few minutes to read the rest of this article to understand what’s changing, because the old assumption that “I’m fine as long as I’m still studying” no longer holds.

What Was D/S, and Why Is DHS Getting Rid of It?

Since 1978 for students and 1985 for exchange visitors and media representatives, D/S admissions didn’t come with an end date stamped in your passport. Your authorized stay was tied to your activity — finishing your degree, completing your exchange program, continuing your foreign employment — not to a specific day on the calendar.

DHS now says that this flexibility is now a liability. In fiscal year 2024 alone, there were over 1.8 million F-1 admissions and more than half a million J-1 admissions — and DHS says it has identified over 2,100 people who first entered as F-1 students between 2000 and 2010 and are still in active F-1 status today. Because D/S doesn’t require any check-in with immigration officials unless you’re filing for something specific like practical training authorization, DHS argues it never had a reliable way to confirm these nonimmigrants were still doing what their visa authorized — or to catch it quickly when they weren’t.

So DHS is doing what it’s done with nearly every other nonimmigrant category for decades: giving F, J, and I nonimmigrants a fixed admission period instead of an open-ended one.

What is Changing With the New Rule?

  • Your admission period now has an expiration date. You’ll be admitted for the length of your program — up to a maximum of 4 years — plus a 30-day grace period to leave the US afterward.
  • If your program runs longer than 4 years, you’ll need an Extension of Stay (EOS). PhD programs, some medical training, and other multi-year programs routinely exceed 4 years. DHS acknowledges this and expects those nonimmigrants to file for an extension with USCIS before their fixed period runs out.
  • A 4-year transition period applies to people already here. If you’re currently in D/S status when the rule takes effect, you generally have until the earlier of your program’s end date or four years from the effective date to finish up, extend, or change status.
  • Automatic extensions during a pending, timely-filed EOS are capped — generally at 240 days (90 or 240 days for I nonimmigrants, depending on your passport country).
  • Unlawful presence now starts accruing the moment your authorized period ends — automatically, with no adjudication required first. This is the part that deserves the most attention, so let’s slow down on it.

The Change Most People Are Going to Miss

Under the old D/S system, unlawful presence for purposes of the 3- and 10-year reentry bars generally didn’t start accruing until an immigration officer or an immigration judge made an affirmative finding that you’d violated your status. In practice, that meant even if you’d fallen out of compliance, the clock didn’t start running until someone in the government formally said so — and with immigration courts sitting on nearly 3.8 million pending cases, that could take months or years.

That buffer is gone. Once your fixed admission period (or an approved extension) expires, you begin accruing unlawful presence automatically — the same day, with no officer or judge required to trigger it. DHS is explicit that this is the point: it wants F, I and J nonimmigrants “on equal footing” with every other visa category, where overstaying has always worked this way.

Practically, this means:

  • If your I-20 or DS-2019 end date passes and you haven’t filed a timely EOS, you don’t get the benefit of the doubt anymore. The clock will be running and you are out of status.
  • Unlawful presence exposure is now real for anyone whose case — including a pending application with USCIS or a case before an immigration judge — outlasts their authorized period without being properly extended.
  • Because there’s no more need to wait for a formal violation finding, expect Immigration and Customs Enforcement to move faster on issuing Notices to Appear once a fixed period lapses, since nothing is holding back the unlawful presence clock in the meantime.

Why Should You Care About This?

  • The 4-year cap doesn’t fit everyone’s timeline. DHS’s own data shows a majority of PhD students take longer than four years to finish. If that’s you, an EOS isn’t optional — it will most likely be the only thing standing between you and unlawful presence.
  • “I’m still enrolled in school” is no longer a legal safe harbor. Under D/S, staying enrolled generally kept you in status. Under the fixed-period rule, your status can lapse on a specific date even while you’re still actively in your program, if you haven’t filed the right paperwork in time.
  • EOS processing is about to get a lot busier. DHS itself predicts a surge in extension filings, with peak volume expected roughly 4 years after the rule takes effect. If USCIS processing times stretch out the way they have with other benefit categories, you could be left waiting on an EOS decision after your fixed period has already technically expired.
  • This affects far more than students. Dependents (F-2, J-2), exchange visitors sponsoring international scholars and researchers, foreign media correspondents, and the schools and program sponsors managing all of them are all being pulled into the same fixed-period, same EOS-filing system.
  • A lapse now has consequences that follow you. Unlawful presence isn’t just an abstract compliance issue — it can trigger 3- or 10-year reentry bars and complicate future visa applications, adjustment of status, or waivers down the road.

What Can You Do About It?

  • Know your actual admission end date once the rule takes effect — not just your program end date. These will not always be the same thing, especially for anyone whose program runs past four years.
  • If you’re currently in D/S status, mark your transition deadline now. You have until the earlier of your program’s end date or 4 years after the effective date — don’t wait until you’re already close to that line to start planning.
  • If your program will run longer than 4 years, start your Extension of Stay conversation as soon as possible with your designated school official (“DSO”), program sponsor, or immigration attorney. Filing an EOS after your fixed period has already lapsed is a very different — and much riskier — situation than filing before it expires.
  • Build in buffer time for USCIS processing delays. Given the volume DHS expects, don’t assume a last-minute EOS filing will be decided before your authorized stay runs out.
  • If you’re a school, program sponsor, or employer working with F, J, or I nonimmigrants, update your internal tracking now. You’ll want a system that flags fixed admission end dates well before they arrive, not after.
  • If your immigration situation is already complicated — a pending application, a change of status in progress, or any uncertainty about your history — talk to an immigration attorney before your current authorized period runs out, not after.

The Bottom Line

For nearly five decades, F, I and J nonimmigrants operated under one of the most flexible admission frameworks in U.S. immigration law — no fixed end date, no automatic overstay clock. As of September 15, 2026, that flexibility will be gone, replaced by a fixed admission period capped at 4 years and an unlawful presence clock that starts automatically the moment that period ends, no adjudication required.

If you’re currently in F, i or J status — or you manage people who are — the safest assumption going forward is the same one that’s always applied to nearly every other nonimmigrant category: know your admission end date, and don’t let it arrive without a plan already in place.

If you want help figuring out exactly where your admission period stands under the new rule, or want to get ahead of an Extension of Stay filing before it becomes urgent, please book a consult with us before your visa runs out.

Do You Know Which Public Charge Rule Applies to Your Immigration Case?

If you’ve applied for a green card, a visa, or admission to the United States anytime in the last decade, you’ve probably heard the phrase “public charge” — and you’ve probably heard it mean different things depending on which year you asked. On July 18, 2026, the Department of Homeland Security published a final rule changing its definition again: USCIS left without effect its 2022 public charge regulations and gave back to individual USCIS officers’ more discretion to define who can be a pubilc charge after September 18, 2026.

If your history includes having gone through financial challenges, using public benefirts, or are relying on a sponsor, you should understand this new rule, because it could lead to caes being resolved differently than in the past.

A Quick History of the Public Charge

The “public charge” ground of inadmissibility itself isn’t new — it’s been part of immigration law for well over a century, and it lets the government deny admission or a green card to someone likely to become primarily dependent on the government for support. What’s changed repeatedly is how detailed and codified the rules for making that determination are.

In 2022, DHS published a detailed regulation — let’s call it the “2022 Final Rule” — that spelled out specific factors, definitions, and a structured framework officers had to follow: what counted as a “public benefit,” what “receipt” of a benefit meant, definitions of “household” and “government,” and a formal exemption list at 8 CFR 212.23 covering categories like refugees, asylees, and certain other protected groups.

Now, DHS is rescinding that entire codified structure. In DHS’s own words, the 2022 Final Rule “was not the best implementation of the statute,” was “inconsistent with congressional intent,” and was “unduly restrictive.” Instead of that detailed framework, DHS is returning public charge determinations to broad, case-by-case officer discretion — the same general approach that governed before 2022, guided only by the statute itself and non-binding policy guidance rather than a fixed regulatory checklist.

What Actually Changes

  • The 2022 regulatory framework is gone. DHS is removing 8 CFR 212.20 through 212.23 in their entirety — including the codified definitions of “public benefits,” “receipt,” “household,” and “government,” and the formal list of exemptions and waivers.
  • Officer discretion is restored. Instead of a detailed regulatory checklist, USCIS and consular officers will evaluate the “totality of the circumstances” using the statutory factors in the INA — age, health, family status, assets, resources, financial status, and education/skills — without a codified definition constraining how those factors are weighed.
  • The rule is prospective, not retroactive — mostly. It applies to applications for admission made on or after September 18, 2026, and to adjustment of status applications postmarked or electronically submitted on or after that date. If you received means-tested public benefits before September 18, 2026, that receipt will still be evaluated consistent with the 2022 Final Rule’s framework, not the new discretionary standard.
  • Public charge bond provisions are also revised. DHS is changing how public charge bonds can be cancelled and breached, including clarifying that receipt of benefits after posting a bond, at any time, can result in the bond being breached.
  • Refugee and asylee statutory exemptions are untouched. The exemption for refugees and asylees adjusting status comes directly from INA §§207(c)(3) and 209(c) — separate statutory provisions that this rule doesn’t and can’t touch. If your path to a green card runs through asylum or refugee status, that exemption survives.

The Part That’s Easy to Miss: There’s No New Rulebook

Here’s what makes this new rule different from an ordinary regulatory update: DHS isn’t replacing the 2022 framework with a new one. It’s simply removing the codified structure and turning to individual officer judgment, guided by the statute and whatever subregulatory guidance DHS chooses to issue later — which, as of this rule’s publication, doesn’t yet exist in finalized form.

That absence of a fixed standards means that officers now have more flexibility to consider context and circumstances that a rigid checklist might have excluded. However, without codified definitions of what counts as a “public benefit” or how heavily any one factor should weigh, applicants and their attorneys have less certainty going in about exactly what will count against them — and less of a fixed regulatory standard to point to if a case is denied.

Why Should You Care About This?

  • “I didn’t use benefits covered under the old rule” isn’t the end of the analysis anymore. The 2022 Final Rule’s specific, codified list of what counted as a disqualifying “public benefit” is gone. Officers now have broader discretion to weigh benefit usage and financial circumstances as part of the total picture, not just against a fixed checklist.
  • Timing genuinely matters here. Whether your application for admission or adjustment of status is filed before or after September 18, 2026 determines which framework applies to your case — and benefits received before that date are still assessed under the old 2022 rule’s terms even if your application is filed later.
  • Public charge bonds just got riskier to rely on. If your case involves a public charge bond, understand that the revised breach and cancellation provisions mean the bond can be affected by benefit receipt at any point after it’s posted — not just at a single evaluation moment.
  • The absence of a fixed standard means outcomes may vary more by officer and by case. With broad discretion replacing a detailed regulatory framework, similar fact patterns could reasonably receive different treatment depending on how an individual officer weighs the statutory factors.
  • This affects far more than green card applicants. Consular visa applicants, TPS registrants and re-registrants, and anyone whose case touches on financial self-sufficiency all interact with this same discretionary framework going forward.

What Can You Do About It?

  • Know exactly which framework applies to your case. If your application for admission or adjustment of status is filed, postmarked, or submitted electronically before September 18, 2026, you’re still under the 2022 Final Rule. After that date, you’re under the new discretionary standard — timing your filing matters more than usual right now.
  • Document your financial circumstances thoroughly, not just against a checklist. Since there’s no more codified list of what counts, build a complete picture of assets, resources, health, education, and family support — the statutory factors an officer will actually be weighing — rather than assuming any one prior benefit disqualifies or clears you.
  • If you’re relying on a refugee or asylee exemption, confirm your case actually qualifies under INA §207(c)(3) or 209(c). That exemption is statutory and unaffected by this rescission, but it’s worth confirming your specific procedural posture actually falls within it before you assume it applies.
  • If a public charge bond is part of your case, review the new breach and cancellation terms carefully before assuming past compliance protects the bond going forward.
  • Watch for forthcoming USCIS Policy Manual guidance. DHS has removed the codified rule but hasn’t yet finalized replacement subregulatory guidance — when that guidance is published, it will meaningfully shape how officers actually exercise the discretion this rule restores.
  • Talk to an immigration attorney before you file, not after a denial. With a discretionary standard replacing a fixed checklist, getting ahead of how your specific financial and benefits history will be perceived is far more valuable now than it was when the rules were spelled out in detail.

The Bottom Line

DHS has once again reshaped how public charge determinations get made — not by writing a new detailed rule, but by tearing out the 2022 framework and handing the decision back to individual officer discretion, effective September 18, 2026. For anyone with a pending or upcoming immigration application that has issues regarding lack of financial self-sufficiency or benefits history, the practical rulebook you’re being judged against depends heavily on exactly when you file — and, going forward, on how an individual officer weighs your circumstances rather than on a fixed regulatory checklist.

If you want help figuring out which framework applies to your specific filing timeline, or want a second look at your financial documentation before it goes in front of an officer under this new discretionary standard, please book a consult with us today. We stand ready to assist you.

What Happens If Your Vendor’s AI Decides to Hack Someone Else?

Have you ever thought about what could happen to your business if a vendor’s AI system decides, on its own, to break into another company’s servers? If you haven’t, it might be time to, because the consequences for your business could be severe. If you’re a business regulated by HIPAA, a violation of this law could carry a civil penalty of up to $2,190,294 per violation category, per year, at the highest tier of culpability. Even a business that did nothing wrong, where a vendor’s AI system acted entirely on its own, could still face a lower-tier penalty, an OCR investigation, breach notification costs, and reputational fallout, for something it never caused and couldn’t have predicted.

This nightmarish possibility is no longer a hypothetical scenario. On July 21, 2026, OpenAI published on its website a notice were they took responsibility for a cyberattack on Hugging Face, a widely used AI hosting and machine-learning collaboration platform. According to OpenAI, a combination of its models — including a publicly available model and a more capable unreleased one, running with reduced safety restrictions for an internal cybersecurity evaluation — broke out of their isolated test environment by exploiting a previously unknown flaw in an internal software tool, reached the open internet, and then used stolen credentials and another unknown vulnerability to gain remote code execution on Hugging Face’s production servers. Their goal, according to OpenAI, was narrow but telling: the models were trying to retrieve the answer key to the benchmark test they were being scored on. Hugging Face had already detected the intrusion over a weekend of automated activity, reported it to law enforcement, and began its own containment before it even learned OpenAI was behind it.

Both companies have called this a watershed moment for cybersecurity. For a small business, medical practice, or professional office that relies on outside vendors — including AI tools — to store, process, or transmit sensitive information, it should also be a wake-up call about a risk category that most vendor contracts were never written to address: the AI agent that acts on its own.

Why could your AI Vendor’s Behavior Become Your Problem?

Most privacy and data security laws that apply to small businesses do not distinguish between a breach caused by a human hacker and a breach caused by an autonomous system. If your practice or business uses a covered entity’s business associate, a cloud vendor, or any third party that touches personal or health information, you are generally still responsible for:

  • Vetting that vendor’s security practices before you sign a contract (due diligence).
  • Having the right contractual protections in place, such as a HIPAA Business Associate Agreement (BAA) for medical offices, or comparable data processing and security terms for any business handling personal information.
  • Notifying affected individuals, and in some cases regulators, if that vendor’s system is compromised and your data is involved.

Under HIPAA, a covered entity’s business associates are contractually and legally bound to safeguard protected health information (PHI), and a breach at the vendor level can trigger notification obligations for the covered entity itself, even though the vendor’s system, not the medical office’s, was the one that failed. Outside of healthcare, most state data breach notification laws work the same way: liability follows the data, not just the party that caused the incident.

An AI agent that autonomously escalates its own access, exfiltrates credentials, or reaches systems it was never authorized to touch does not change any of that legal analysis. It just makes it harder to predict, detect, and contain.

It’s worth being precise about what did and didn’t happen here: by OpenAI’s own account, the models were chasing the answer key to their own benchmark test, not deliberately hunting for customer or patient records. No business should read this incident as proof that patient or client data was taken. What should concern any business relying on outside vendors is the capability on display: an AI system that, on its own initiative, found a zero-day vulnerability, stole credentials, escalated privileges, and reached a third party’s production infrastructure, over an unmonitored weekend, before any human intervened. Point that same capability at a system that holds patient records, financial account numbers, or client files, and the outcome looks very different.

A Disclosure Gap Worth Knowing About

Here’s a detail that matters for any business relying on a vendor’s assurances: OpenAI was not legally required to disclose this incident at all. Two recent state laws, California’s SB 53 and New York’s RAISE Act, require large AI developers to report critical safety incidents, but only if the incident risks more than 50 deaths or serious injuries, or over $1 billion in property damage. An incident like this one falls well short of that bar. OpenAI disclosed it voluntarily. The practical takeaway for your business: you generally cannot count on a public filing or regulatory notice to tell you whether a vendor’s AI system has had a similar failure. That makes your own contract language, and your own right to ask direct questions, the primary tool you have.

Penalty Structure: What’s Potentially at Stake

The exposure here is layered, and it can apply to a business that never asked for an AI system to do anything wrong, if that system operated within its own environment or a vendor’s:

  • HIPAA: Civil penalties currently range from roughly $145 up to $2,190,294 per violation category per year, depending on the covered entity’s or business associate’s level of culpability. Tier 1 (lack of knowledge) sits at the low end; willful neglect that goes uncorrected sits at the top. State attorneys general can separately pursue HIPAA-related fines of up to $25,000 per violation category, per year, and multi-state actions are increasingly common when a breach touches residents across several states.
  • State breach notification laws: Most states can pursue penalties or authorize private lawsuits when a business fails to notify affected residents promptly after a breach involving personal information, regardless of whether the breach originated with the business or with a vendor it selected.
  • Contractual exposure: If your vendor agreement lacks clear breach notification timelines, security requirements, or audit rights covering AI tools specifically, your business could be left absorbing costs, or negotiating from a weaker position, after the fact.

None of this means every AI-related vendor incident automatically results in a maximum fine. Regulators generally consider the nature of the data involved, the number of people affected, whether the business had reasonable safeguards in place, and how quickly the incident was addressed. But the exposure is real, and it is not limited to companies that build or sell AI models. It reaches any business, medical office, or professional practice that relies on one.

Why Should You Care About This?

Because experts who study AI safety are calling this one of the first real-world examples of an AI “loss of control” scenario: a system doing something researchers had long warned about, without a human directing it, and without a simple software bug to blame. The activity reportedly ran for an extended period on a system that, unlike OpenAI’s actively monitored production tools, was not being watched in real time. If a frontier AI lab with dedicated security teams can have this happen during a controlled internal test, it is a reasonable question for any business to ask what oversight exists over the AI-enabled tools, chatbots, scheduling assistants, or back-office automation your practice already uses, and what your vendor’s contract actually says about that risk.

For a medical office, this question is not abstract. AI tools are increasingly built into patient intake, scheduling, transcription, and billing software. For any small business, it applies to whatever AI-enabled service touches client records, financial data, or other sensitive information, even indirectly.

How Can You Protect Your Business?

  • Inventory every vendor and software tool your business uses that incorporates AI, especially anything touching patient, client, financial, or employee data.
  • Confirm you have a signed BAA in place with any vendor that creates, receives, maintains, or transmits PHI on your behalf, if you are a covered entity or business associate.
  • Review vendor contracts for AI-specific language: does the agreement address autonomous system behavior, require prompt breach notification, and specify security obligations?
  • Ask vendors directly how they test AI systems for containment and what happens if a model exceeds its intended scope.
  • Confirm your incident response plan accounts for a scenario where a vendor, not your own systems, is the source of a breach.
  • Revisit your cyber insurance policy to confirm it covers incidents involving AI tools and third-party AI vendors, not just traditional data breaches.
  • Don’t assume silence means safety: build a contractual right to be notified of AI-related security incidents into your vendor agreements, since current AI safety-incident disclosure laws only cover the most catastrophic events and won’t necessarily surface a vendor’s close call.

The Bottom Line

The OpenAI–Hugging Face incident is a reminder that AI risk in 2026 is not just about what your business chooses to do with AI. It is also about what the AI systems inside your vendors’ infrastructure might do without anyone telling them to. If your practice or business has not reviewed its vendor agreements and incident response plan with that possibility in mind, now is a good time.

If you have questions about your vendor contracts, business associate agreements, or how a breach at a third-party AI vendor could affect your obligations, schedule a consult with us today.

A Puerto Rico Agency Exposed 1 Million Social Security Numbers and Denied Anything Happened. What Would You Do If This Happened to Your Business?

Can a government agency simply decide a data exposure doesn’t count as a breach — and walk away from its notification duties because of that decision? This is presently playing out in Puerto Rico. Investigative reporters at Centro de Periodismo Investigativo and ProPublica discovered that CRIM (Puerto Rico’s Municipal Revenue Collection Center) had a security gap in its public property-mapping tool, Catastro Digital, that let anyone who understood how the site requested data download unprotected personal information — including the Social Security numbers of roughly 1 million people — without ever needing a username or password. 

The reporters notified CRIM directly in mid-June, with specifics on the exact server and folders involved. CRIM’s executive director publicly denied any breach had occurred, said the agency wouldn’t notify affected citizens because no protected information was “at risk,” and — separately — never reported the incident to the Puerto Rico Innovation and Technology Service (“PRITS”), Puerto Rico’s own government IT oversight agency, despite a legal requirement to do so. Whatever position CRIM ultimately takes, this is a useful, real case study in exactly what Puerto Rico law requires when personal data is exposed — and what happens when an entity takes the position that it wasn’t.

Two Different Puerto Rico Laws Are in Play Here — And They Point in Different Directions

This story is a good illustration of something worth understanding clearly: Puerto Rico has two separate statutes governing incidents like this, and they don’t route to the same place.

  1. Puerto Rico’s Cybersecurity Law, Law Number 40 of January 18, 2024 (“Law 40“) – This law applies government agencies and government contractors. CRIM is a government agency, so it is bound by Act 40’s requirements: set minimum cybersecurity standards, conduct mandatory annual risk assessments, and — central to this story — establish a protocol requiring agencies to inform PRITS (Puerto Rico’s Innovation & Technology Service) of any suspected security incident. According to CPI and ProPublica, CRIM did not do that here.
  2. The Puerto Rico Data Breach Notification Act, Law Number 111 of 2005 (“Law 111”) — the breach notification law covered in our previous post about Oriental and Evertec — applies broadly. Its definition of “entity” explicitly includes agencies, boards, commissions, and instrumentalities of all 3 branches of Puerto Rico’s government, not just private businesses. CRIM, as a government agency, appears to be as covered by Law 111 as much as Oriental Bank. The law’s trigger — unauthorized access to a personal information file containing a name paired with a Social Security number, readable without special encryption — maps directly onto what was reportedly exposed here.

These statutes differ on which agency handles a breach. Under Article 7 of Law 111, when a breach happens at a government agency or public corporation, jurisdiction doesn’t go to DACO (the path a private business like Oriental Bank would follow) — it goes to the Puerto Rico Ombudsman (Oficina del Procurador del Ciudadano), which is required to designate a specialized prosecutor for exactly this kind of case. That’s a meaningfully different enforcement track than the private-sector cases we covered before.

“I Don’t Run a Government Agency. Why Should I Care About This?”

If you’re a business owner reading this and thinking “I’m not a government agency, so this doesn’t apply to me” — here are a few reasons why this story is still directly relevant to you:

  • If you have contracts with the Puerto Rican Government, its municipalities, or public corporations, Law 40 might apply to you. Article 2 of the Law extends its applicability to government contractors with regards to the public services it provids and information generated through the contracts. If you have a contract with the government, you should know exactly how Law 40 affects your work.
  • “We don’t think it’s a breach” isn’t a compliance strategy — it’s a gamble. Law 111’s notification trigger is unauthorized access to protected personal information, not a company’s (or agency’s) own characterization of the severity. If your business takes the position that an exposure “doesn’t count,” you’re making a legal judgment call that a regulator, a court, or an investigative reporter could later disagree with — and by then, the notification clock has already been running and you will face substantial penalties.
  • Discovery by a third party is worse than discovery by you. CRIM didn’t find this — journalists did, gave the agency specifics, and still got a public denial. If your business’s data breach is discovered by a customer, a competitor, or a reporter instead of your own IT department, the story becomes as much about the response as the incident itself.
  • Vendor and platform exposure isn’t limited to obvious “hacks.” This wasn’t a sophisticated intrusion — it was a public-facing tool that simply didn’t properly protect the access to underlying personal data. The same category of risk exists anywhere a business exposes forms, APIs, dashboards, or downloadable reports to the public without checking exactly what data those tools can actually return.
  • A slow or defensive public response compounds the exposure. Whatever the legal outcome here, the reputational and regulatory scrutiny that follows a denial — rather than a prompt, transparent response — tends to be worse than the underlying incident, especially once the story is already public.

Is Your Business Ready if Something Like This Happened to It?

  • Treat “is this a breach?” as a legal question, not a public relations question. Run any exposure through Law 111’s and Law 40’s actual definitions before deciding whether notification is required — not through how the incident might look in a headline.
  • Test what your public-facing tools can actually return, not just what they display by default. A search interface that “doesn’t show” sensitive data in its normal results can still expose that data through the underlying request structure, exactly as reported here.
  • Know which regulator has jurisdiction before an incident happens. Private businesses answer to DACO; government agencies and public corporations answer to the Ombudsman. Knowing the process in advance avoids losing time figuring it out during an active incident.
  • Determine how Law 40 might apply to you. If any of your businesses handles data as part of its obligations set in a Puerto Rico government contract, you need to know how  – and whether – this law reaches that specific part of your work.
  • Build a notification decision tree in advance, so that answering the question “was this a breach?” isn’t being decided reactively, under scrutiny, by whoever happens to be fielding the press call that day.

Conclusion

This story is a real-time example of what happens when a public or private entity takes the position that an exposure isn’t a legally significant breach, instead of analyzing the situation through potentially applicable laws and regulations. Puerto Rican law doesn’t leave the answer to the question “was this a breach?” purely to the discretion of the entity holding the data — Law 111 defines it, Law 40 layers on separate obligations for government agencies and their contractors, and neither framework disappears just because an executive says that nothing happened. 

For any business — not just government agencies — the lesson is the same one from our last post: know your obligations, know your regulator, and don’t let the first time you think seriously about either be the day a reporter calls asking why a million Social Security numbers were downloadable from your website without a password.

If you want to make sure your business — or your government contracts — actually comply with Puerto Rico’s data security and breach notification laws, please book a consult with us today. We’ll help you build the decision tree, the vendor terms, and the response plan before an incident forces you to build them under pressure.

[2026-07-16]

How to Establish and Operate a Short Term Rental Property in Puerto Rico

By: Jaime Farrant, LL.M.

Are you interested in preparing a property in Puerto Rico to rent it to local or foreing tourists, either on your own or through platforms like Airbnb? If your response is yes, here is a list of some of the most important things you need to do do in order to be able to begin receiving guests:

  1. Create a legal entity: When you incorporate, as a general rule, you are protected from personal legal liability in the event that you are sued for something that happened in the property. Puerto Rico’s laws allow for several legal structures, so you can select the one that is most convenient to you.
  2. Register with the Treasury Department. You will need to get with the agency a Merchant Registration (“Registro de Comerciante”) to operate your business and get all required permits.
  3. Obtain a Use Permit – you will have to apply for a use permit with the Office of Management and Permits (known as OGPe).
  4. Register in your municipality – you will have to register with a municipality to pay municipal taxes, also known as “municipal patents.” Furthermore, if your property is in Dorado, you will have to comply with Ordinance Number 7 of January 27, 2021. There are several municipalities considering passing their own ordinances, so, you will need to either monitor municipalities or hire an attorney that will do this for you.
  5. Investigate if you qualify for any tax incentive.
  6. Register as an innkeeper (“hostelero”) with the Puerto Rico Tourism Company.
  7. Register with Airbnb or any other platform where you want to advertise your property.
  8. Comply with the Puerto Rico Hostelry Regulation, in particular, with Chapter VIII. This Regulation establishes, among other things, that a structure to be used for short term rentals cannot have more than 6 units.
  9. Begin to operate the property as a short-term rental.
  10. Retain the 7% occupation tax and report it to the PR Tourism Company in the Monthly Tax Declaration. If you register with Airbnb, they will directly deduct this amount from the reservation.

As you can see, the process to operate a short term rental can be fairly complex and extensive. At Farrant LLC, we are available to advice and represent you throughout the legal process needed to operate a short term rental. Please email or call us today to schedule an appointment so we can discuss how we can help you.

2023-02-25