ICE Shared Improper Medicaid Data with Palantir: Major Privacy and Compliance Risks Exposed

Table of Contents

In a significant escalation of data-sharing controversies under the Trump administration, new court filings reveal that Immigration and Customs Enforcement (ICE) improperly received and then shared sensitive Medicaid data on millions of individuals with Palantir Technologies. The revelations, detailed in a motion by more than 20 Democratic attorneys general, highlight ongoing risks of function creep, inadequate safeguards, and erosion of trust in healthcare privacy protections.

Background: The Medicaid-ICE Data Sharing Agreement

The dispute stems from a data-sharing agreement between the Centers for Medicare & Medicaid Services (CMS) and ICE, aimed at supporting immigration enforcement by providing location and identifying information on noncitizens. A federal judge in California had previously allowed limited sharing of certain biographical data (such as addresses, dates of birth, and immigration status) for individuals without lawful status, but explicitly barred broader dissemination, including data on U.S. citizens or legal residents.

Despite these restrictions, CMS improperly shared expansive datasets in January 2026—one involving refugees in Minnesota that included U.S. citizens, and another massive file covering millions of people, including lawful residents. ICE was ordered to delete this data, but subsequent filings show repeated failures: the Department of Justice admitted to re-sharing the dataset, and ICE discovered that multiple users still retained copies.

Palantir’s Role and the “Purged” Data Claim

ICE then forwarded this improperly obtained data to Palantir, the data analytics firm known for its work on tools like ELITE (Enhanced Leads Identification and Targeting for Enforcement). ELITE reportedly uses such data to generate real-time maps and dossiers for deportation operations.

Palantir stated that the dataset was purged pursuant to government instructions and emphasized that customers control their own data. However, the incident underscores broader concerns about third-party contractors’ access to sensitive government-held information and the challenges of ensuring complete deletion across systems, including shared platforms like Microsoft Teams.

Privacy Implications: Function Creep and Chilling Effects on Healthcare

Medicaid data is collected under strict privacy expectations for administering healthcare benefits to low-income individuals and families—not for immigration enforcement. Repurposing it represents classic function creep, where data collected for one purpose is redirected to another, often without meaningful consent or transparency.

  • Undermining Patient Trust: Surveys indicate that fears of data sharing with ICE are already deterring immigrants and mixed-status families from seeking care, potentially worsening public health outcomes.
  • Scope of Data: Agreements have referenced access to addresses, phone numbers, SSNs, and even more detailed records in some contexts.
  • Broader Surveillance Ecosystem: This fits into larger administration efforts to consolidate data across agencies, with Palantir playing a central role in analytics.
  • Legal and Oversight Gaps: Repeated violations undermine confidence in the government’s ability to secure the data.

Regulatory and Compliance Takeaways for Organizations

This story serves as a stark reminder for privacy professionals, healthcare entities, and businesses handling sensitive personal data:

  1. Data Minimization and Purpose Limitation: Strictly limit sharing to what is legally required and document purposes.
  2. Vendor Due Diligence: Contracts with analytics firms must include robust audit rights, deletion guarantees, and restrictions on further sharing.
  3. State-Federal Dynamics: Monitor varying state privacy laws and potential blocks on data flows.
  4. Incident Response and Transparency: Prepare for FOIA, discovery, and public scrutiny.
  5. Emerging AI/Analytics Risks: Align practices with frameworks like NIST privacy standards.

A hearing is scheduled for August to clarify the scope of allowable sharing. Organizations should track developments closely.

Looking Ahead

The intersection of healthcare data, immigration enforcement, and powerful analytics platforms like Palantir’s raises profound questions about the balance between security and civil liberties. As data silos erode, individuals’ reasonable expectations of privacy—especially in sensitive domains like medical care—are increasingly at risk.

For Captain Compliance clients navigating this landscape, proactive audits of data-sharing agreements, enhanced vendor controls, and advocacy for stronger purpose limitations will be essential.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.