ParamergeParamerge

Evidence · The claim ledger

Privacy & security8

Every cited claim this site makes in this evidence area, with the sources that ground it. Source keys link back to the full reference lists on the Evidence Registry.

EmpiricalTiered HIPAA penalties run from $145 to $73,011 per violation with an annual cap near $2.19M (2025-adjusted), and disclo…

Tiered HIPAA penalties run from $145 to $73,011 per violation with an annual cap near $2.19M (2025-adjusted), and disclosure to a tool that is not a business associate is itself a violation.

Sources: hipaajournal2026a, hipaajournal2026b

Appears on: /pan-lab

ConceptualProtected health information (PHI) is individually identifiable health information; under the HIPAA Privacy Rule (45 CFR…

Protected health information (PHI) is individually identifiable health information; under the HIPAA Privacy Rule (45 CFR 160.103) its uses and its disclosures are both regulated, so how PHI is used inside a system — not only whether it leaves — is governed.

Sources: u2013

Appears on: /pan-lab

ConceptualPersonally identifiable information (PII) is information that can distinguish or trace an individual's identity, alone o…

Personally identifiable information (PII) is information that can distinguish or trace an individual's identity, alone or combined with other data; NIST SP 800-122 directs organizations to minimize its collection and use and to limit use to the purpose for which it was collected.

Sources: mccallister2010

Appears on: /pan-lab

ConceptualUnder the GDPR (Regulation (EU) 2016/679, Article 5), personal data must be collected for specified purposes and not fur…

Under the GDPR (Regulation (EU) 2016/679, Article 5), personal data must be collected for specified purposes and not further processed in a way incompatible with them (purpose limitation), and kept adequate, relevant, and limited to what is necessary (data minimisation).

Sources: europeanparliamentandcouncil2016

Appears on: /pan-lab

ConceptualThe volume's school social work chapter names function creep, a term it takes from Koops (2021), as the long-term risk t…

The volume's school social work chapter names function creep, a term it takes from Koops (2021), as the long-term risk that data collected for a beneficial purpose such as identifying mental health needs is later repurposed for an entirely different function; it names student discipline and sharing with external law-enforcement agencies as its examples. The chapter's stated concern is the absence of specific, renewed consent for the new use and the erosion of trust that follows, not the volume of data held. It offers this as a risk argument and reports no incidence rate.

Sources: huang2026a

Appears on: /pan-lab

EmpiricalIn a school communication-monitoring deployment the flagged-content archive is itself the exposure pathway. Every flag w…

In a school communication-monitoring deployment the flagged-content archive is itself the exposure pathway. Every flag writes a durable record of a student's most sensitive writing, including disclosures of sexual orientation, and the investigative record already in this registry documents that archive being released unredacted through links that required no login, students who risked being outed after writing about sexual orientation or gender identity, and a district that discontinued the vendor in 2023 following an outing incident. The volume's LGBTQIA+ chapter supplies the mechanism that record instantiates: a store built to protect people is also the means by which they can be exposed, which is why practitioners are documented deliberately omitting sexual-orientation and gender-identity data from client information systems even at a cost to record completeness. This claim states institutional exposure only - what the record holds and which hand-offs it can travel along - and never a per-student outcome. Students sit outside these dynamics by construction and nothing about them is computed on any diagram.

Sources: downey2026, bryanandlurye2025, associatedpress2025

Appears on: /domains/cases/gaggle-school-monitoring, /pan-lab

EmpiricalThe LGBTQIA+ chapter documents a governance trade-off practitioners already make: social work professionals intentionall…

The LGBTQIA+ chapter documents a governance trade-off practitioners already make: social work professionals intentionally omit sexual-orientation and gender-identity data from client information systems to protect people from exposure, forced outing or violence. The chapter frames this as a considered deviation from data-completeness norms rather than a recording error, reports it from the literature it reviews, and gives no prevalence figure.

Sources: downey2026

Appears on: /pan-lab, /practice/data-minimization

ConceptualMinimisation carries a cost the protective case usually leaves out: a record deliberately kept thinner is also a record …

Minimisation carries a cost the protective case usually leaves out: a record deliberately kept thinner is also a record that supports less verification, so minimising trades exposure against the evidence the correction loop itself runs on. The duty that travels with it is purpose limitation — consent obtained for one purpose does not cover reuse of that data to train a model for another — which is how the data-protection regulation states the two together. Direction only: none of these sources measures the size of either cost.

Sources: downey2026, an2026a, europeanparliamentandcouncil2016

Appears on: /pan-lab, /practice/data-minimization