This article was originally published on Crafting Your Home. A human contributor also wrote and edited the post.
A California-led lawsuit says the federal government mishandled sensitive Medicaid information after ICE shared a large dataset with Palantir, raising new questions about privacy, immigration enforcement and the security of health records.
SAN FRANCISCO. A fight over medical privacy and immigration enforcement has intensified after California officials accused federal agencies of mishandling Medicaid data that was supposed to be protected under a court order.
The dispute centers on millions of Medicaid records that federal immigration officials shared with Palantir, a data analytics company used by government agencies. The disclosure became public through a federal lawsuit led by California Attorney General Rob Bonta and more than 20 other Democratic attorneys general challenging the Trump administration’s efforts to expand access to Medicaid information for immigration enforcement.
The states argue that the data transfer shows the federal government cannot be trusted to safeguard sensitive health information. Federal officials, however, have argued that limited Medicaid data access is necessary for immigration enforcement efforts involving people who are not lawfully present in the United States.
The legal battle now raises a broader question affecting millions of Medicaid recipients: How much personal health information should the government be allowed to access, and what protections should exist before that information is shared?
A Court Fight Over Medicaid Data and Immigration Enforcement

The case, filed in federal court in California, challenges an agreement between the Centers for Medicare & Medicaid Services (CMS) and Immigration and Customs Enforcement (ICE). The agreement allows ICE to obtain certain Medicaid information for immigration enforcement purposes. The lawsuit is being heard in the U.S. District Court for the Northern District of California by Judge Vince Chhabria.
In December, Chhabria allowed federal officials to access limited Medicaid information from states involved in the lawsuit. That information included details such as addresses, dates of birth and immigration status for certain individuals without lawful immigration status. But the court’s order placed limits on how that information could be used.
The latest controversy began after state officials argued that federal agencies went beyond those restrictions. According to a filing submitted July 16 by the coalition of attorneys general, ICE shared Medicaid information with Palantir, the technology company that operates a mapping application known as ELITE.
Government agencies use the tool to organize and analyze information. The states argue that transferring the data to another contractor violated the court’s restrictions.
What Data Was Shared With Palantir?
According to court documents, one dataset transferred on January 7 contained records involving millions of individuals. The states said the information included people who were not necessarily undocumented immigrants, including some individuals who were legally present in the United States.
A separate dataset involving refugees resettled in Minnesota was also improperly included, according to court filings. The disclosure created concerns because Medicaid records contain highly sensitive personal information.
Although Medicaid is primarily a healthcare program, eligibility records can include information connected to identity, residency and personal circumstances. California officials argued that people may avoid seeking healthcare if they fear their information could later be used for immigration enforcement. That concern, they said, could affect public health by discouraging eligible residents from enrolling in programs or seeking medical care.
Palantir Says the Information Was Deleted
Palantir responded that the company did not independently collect or maintain the information.
A company spokesperson told NPR that government customers control their own data and that Palantir’s role is to help agencies integrate and analyze information rather than store it for its own purposes. The company said the dataset was deleted at the government’s request. The Department of Homeland Security did not immediately provide a public response regarding the transfer.
Federal officials have maintained that the government must have appropriate tools to enforce immigration laws. The administration has argued that access to certain government records can help locate individuals who may be subject to removal proceedings.
Court Records Reveal Additional Data Handling Problems
The dispute grew more complicated after the Justice Department acknowledged another transfer involving the same dataset. According to court filings, CMS accidentally shared the improperly obtained information again while providing records involving states that were not part of the original lawsuit.
An ICE official, Alberto Briseno, stated in a declaration that personnel deleted the file after discovering the mistake and that the information was not used for immigration enforcement.
However, a follow-up review found that six additional users still had copies of the same dataset.
The discovery intensified criticism from state officials, who argued the repeated mistakes demonstrate why stronger safeguards are necessary. California officials said the problem was not simply whether information was shared once, but whether agencies could reliably track where sensitive records went after distribution.
Why California Officials Say the Data Is Not Safe
The attorneys general involved in the lawsuit argue that the mistakes weaken the federal government’s argument for expanding access to Medicaid information. The Justice Department has asked Judge Chhabria to broaden access rules so ICE can receive Medicaid data involving a wider group of noncitizens. The proposal could potentially include people who are not U.S. citizens, legal permanent residents, or individuals with certain protected immigration statuses.
The states argue that recent disclosures prove the government has not established enough safeguards. In their court filing, officials said each additional data-sharing error makes it more difficult to reassure Medicaid recipients and healthcare providers that private information will remain protected.
The concern extends beyond immigration policy. Health officials worry that if people believe their medical information could be shared with enforcement agencies, some may avoid applying for healthcare coverage or delay seeking treatment.
How the Government Plans to Address the Problem
Court records show officials attempted to confirm that Palantir and other contractors removed the improperly shared data. California Deputy Attorney General Anna Rich described efforts to verify deletion, including asking whether files shared through Microsoft Teams had been removed.
A redacted transcript included in court filings appeared to show ICE personnel asking Palantir to delete the information. However, state officials argued that relying on deletion requests after a violation occurs does not solve the underlying concern. They want stricter controls before information is shared.
A Growing National Debate Over Government Data
The California lawsuit reflects a larger debate happening across the country. Government agencies increasingly rely on large technology systems to manage information, identify patterns, and enforce policies.
Supporters argue data-sharing tools can improve efficiency and help agencies carry out legal responsibilities. Critics argue that sensitive personal information requires stronger limits, especially when health records are involved.
The Medicaid dispute highlights the challenge of balancing government enforcement priorities with privacy protections.
Medicaid serves millions of Americans, including low-income families, older adults, people with disabilities, and other vulnerable populations. For those individuals, trust in the system can determine whether they seek medical care or avoid it.
What Happens Next in the Federal Case
Judge Chhabria is expected to hold a hearing in August to determine the future limits on Medicaid data sharing between CMS and ICE. For now, a temporary pause on CMS-ICE data sharing for enforcement purposes remains in place.
The California-led coalition of states is asking the court to strengthen restrictions and require clearer safeguards before any future transfers occur. The federal government is pushing for broader access, arguing that immigration enforcement requires reliable information.
The outcome could affect not only this lawsuit but also how government agencies across the country handle sensitive personal data. At the center of the case is a question that reaches far beyond one database. When personal health information enters the government system, who ultimately controls where it goes, and who gets to decide how it is used?

