ICE Shared Medicaid Data with Palantir, Court Filings Reveal
New court filings in the ongoing federal lawsuit State of California v. U.S. Department of Health and Human Services reveal that U.S. Immigration and Customs Enforcement (ICE) shared Medicaid data it was not authorized to possess with the data analytics firm Palantir Technologies, according to NPR. The data — originally obtained by ICE through an improper transfer from the Centers for Medicare and Medicaid Services (CMS) in January 2026 — included information on millions of people, including U.S. citizens and lawful permanent residents.
Background of the Legal Battle
The case, filed on July 1, 2025, by California Attorney General Rob Bonta and more than 20 Democratic state attorneys general, challenges the Trump administration’s mass transfer of Medicaid data to ICE for immigration enforcement. In December 2025, U.S. District Judge Vince Chhabria ruled that CMS could share only limited information about noncitizens not lawfully residing in the United States — specifically addresses, birth dates, and immigration status. The January transfer, which included data on millions of people far beyond what the court authorized, violated that order.
As 404 Media first reported in January, the data feeds into Palantir’s “ELITE” (Enhanced Leads Identification & Targeting for Enforcement) application, which provides ICE agents with maps of potential deportation targets, dossiers on individuals, and address “confidence scores” based on HHS and other government data.
How the Data Was Shared
According to a declaration filed by California Deputy Attorney General Anna Rich, when plaintiffs asked what federal officials had done to ensure Palantir and other contractors had purged the data, defendants responded that the data had been shared over a Microsoft Teams chat and subsequently deleted from the chat. Rich shared in her declaration a document turned over in discovery showing a redacted transcript of what appears to be ICE personnel asking Palantir to delete the file.
ICE Section Chief Alberto Briseno wrote in a declaration that ICE personnel deleted the file after it was discovered and that it was not used for law enforcement purposes. However, a broader search the next day revealed that half a dozen users still retained copies of the January 7 dataset. Briseno acknowledged that the searches had “highlighted technological difficulties of making a representation that every possible variation of the file has been searched for and located,” adding that “ICE will continue to make good faith efforts to delete any copies that may be found in the future.”
Repeated Compliance Failures
The Palantir revelation is not an isolated incident. In July 2026, CMS inadvertently reshared the same January dataset with ICE during an effort to share data from states not involved in the lawsuit. Judge Chhabria temporarily paused all CMS-ICE data sharing in late May 2026 after federal officials admitted to the improper January transfer.
Despite these compliance failures, the Department of Justice is asking the court to expand the order to allow ICE to receive data on a broader category of noncitizens — potentially including all immigrants who are not legal permanent residents, citizens, or holders of another form of permanent status.
Privacy Implications
The improper sharing of data on U.S. citizens and lawful permanent residents represents a significant privacy breach affecting potentially millions of individuals who enrolled in Medicaid for healthcare, not knowing their data would be used for immigration enforcement. As the Electronic Frontier Foundation has warned, the consolidation of government records into a single searchable, AI-driven interface raises profound privacy concerns.
In their motion filed July 16, the Democratic attorneys general wrote: “Each successive revelation of a violation of the Order makes it more difficult for Plaintiff States to have confidence in Defendants’ ability to maintain and secure this data in compliance with the Order, and more difficult for Plaintiff States to communicate assurances to Medicaid providers, enrollees (and their counsel), and the public at large about the privacy and confidentiality of their healthcare data.”
Palantir’s Expanding Role
The revelations come amid Palantir’s deepening involvement in immigration enforcement infrastructure. In February 2026, the Department of Homeland Security awarded Palantir a $1 billion contract to build “ImmigrationOS,” an AI-powered system for identifying immigrants for deportation. The company, co-founded by Peter Thiel and valued at approximately $315 billion, has a long history of providing surveillance and data analytics technology to government agencies.
What’s Next
Judge Chhabria has scheduled a hearing for August 2026 to further clarify his order and address the compliance failures. The court will also consider the DOJ’s request to expand data access — a request that faces significant headwinds given the government’s demonstrated inability to properly manage the data already obtained.
As Chhabria warned during an April 30 hearing: “If the federal government cannot be sufficiently careful then it can’t use the information, ok?”
The case represents a critical test of how the government can aggregate and repurpose data collected for one purpose — healthcare — for another — immigration enforcement — with potential implications for privacy law and the limits of government surveillance.