How ICE and Palantir Turned Medicaid Records Into Deportation Leads

Court filings reveal CMS improperly sent Medicaid data on millions to ICE in January 2026, which then shared it with Palantir for its ELITE deportation tool. The breach violated judicial limits, included U.S. citizens, and sparked fresh skepticism about data controls despite purge claims. Democratic states say trust is shattered.
How ICE and Palantir Turned Medicaid Records Into Deportation Leads
Written by Emma Rogers

Federal immigration agents got their hands on Medicaid data they had no business seeing. Then they passed it to Palantir. Court records unsealed this month lay bare the chain of errors. And the skepticism runs deep.

More than 20 Democratic attorneys general filed a motion July 17 detailing how the Centers for Medicare and Medicaid Services sent a dataset on millions of people to Immigration and Customs Enforcement in January. The transfer violated court limits. ICE turned around and fed the information to Palantir Technologies. The data analytics company runs an internal app called ELITE that agents use to pull up addresses of people targeted for deportation. Short. Simple. And according to the plaintiffs, entirely out of bounds.

The revelations surfaced inside a lawsuit brought last year against the Trump administration’s data-sharing pact between CMS and ICE. U.S. District Judge Vince Chhabria, an Obama appointee in California, had ruled in December that officials could share narrow slices of Medicaid information on noncitizens without lawful status. Home addresses. Dates of birth. Immigration status. Nothing more. Yet the January handoff swept far wider. It captured U.S. citizens. Lawful residents. Mixed-status households. One early file even pulled in refugee data from Minnesota that wrongly included citizens.

Officials discovered the overreach. ICE said it deleted the files and swore they went unused for enforcement. But fresh searches turned up copies still sitting on employees’ systems. Half a dozen users, according to declarations from ICE section chief Alberto Briseno. Technological hurdles complicated full erasure. The Justice Department admitted CMS had inadvertently reshared the same expansive dataset while trying to add information from states not part of the suit. Each misstep, the Democratic attorneys general argued, chipped away at any claim that the government could handle sensitive health records responsibly.

“Defendants produced documents confirming that Medicaid data from Plaintiff States had been shared with employees or contractors of Palantir,” the motion stated. The implications stretch beyond one breach. Medicaid files carry names, addresses, and eligibility details tied to health services that millions of Americans, including citizens, rely on. Feeding those into tools built for enforcement risks chilling enrollment, especially among immigrant families wary of any government link to deportation.

Palantir pushed back in a statement to NPR. “Our customers control their own data and manage access to that data. When Palantir employees are granted access to a customer’s dataset, it is solely to help integrate and analyze that data — which is what our software does — not to store it or use it for our own purposes. Palantir can confirm that the dataset in question was purged pursuant to government instruction.” Clean words. Yet the episode revives long-standing questions about how far private contractors embed themselves in federal surveillance operations.

ELITE, short for Enhanced Leads Identification and Targeting for Enforcement, populates maps with potential targets. It compiles dossiers. It assigns confidence scores to addresses. Earlier reporting from EFF and 404 Media had already flagged the tool’s appetite for health department records alongside commercial and public datasets. The July filings supplied the first concrete proof that Medicaid information had actually flowed into it despite judicial guardrails.

But this didn’t start in January. Last summer the administration moved unilaterally to grant ICE access to Medicaid records for the express purpose of locating people to arrest and remove. The pact with CMS followed. Similar arrangements surfaced with the IRS. Critics saw a pattern. Health data. Tax data. All repurposed for immigration enforcement on a scale not seen before. States sued to block it, arguing the moves violated privacy statutes baked into Medicaid law and threatened the program’s core promise of confidentiality.

Judge Chhabria paused the broader sharing in May after the first improper transfers came to light. He scheduled further hearings, including one set for August to hash out exactly which categories of noncitizens remain eligible. The Democratic attorneys general used the latest motion to warn that repeated violations and sloppy deletion efforts had destroyed trust. Why should states or enrollees believe safeguards would hold next time?

Privacy advocates piled on. The Electronic Frontier Foundation noted in January that pairing Medicaid addresses with mapping and analytics created precisely the kind of dragnet feared by civil liberties groups. Once data leaves secure health channels and enters contractor ecosystems, control evaporates. Copies multiply. Audit trails fade. And the incentive to exploit every scrap of location information only grows as deportation targets multiply under current policy.

ICE and the Justice Department counter that deletions happened. No enforcement actions relied on the tainted files. They want the court to expand access anyway, claiming the narrow categories approved last December don’t capture enough actionable leads. The plaintiffs fire back that the government’s own inability to corral the data it demanded proves the opposite. Confidence in compliance? Eroded. Ability to assure patients their records stay private? Gone.

Techdirt framed the affair bluntly on the day the story broke wider. Its coverage highlighted the “maximum awfulness” of the administration’s approach and expressed deep doubt that any “belated purge” had truly scrubbed the information from Palantir’s systems or derivative models. Once analysts at the company touch a dataset, the piece suggested, traces tend to linger in ways paper deletion orders rarely erase.

Recent coverage adds texture. Medical Daily reported two days ago on the dual disclosures: first the CMS-to-ICE transfer of millions of names, then the handoff to Palantir for ELITE. It noted the Minnesota refugee file as a stark example of mission creep that pulled in citizens alongside noncitizens. The BMJ placed the story in a global context, connecting U.S. health-data feeding into deportation tools with similar debates overseas about medical records and enforcement.

Congressional voices have stirred. Rep. Rob Menendez called the episode a “massive privacy breach” and urged strict guardrails to keep taxpayer-funded health data from being weaponized. On X, reactions split along familiar lines. Some users decried government overreach and questioned why ICE had Medicaid access at all. Others dismissed concerns as obstacles to legitimate enforcement. The volume of posts spiked this week, many linking back to the NPR account that first synthesized the court motion.

At root sits a tension that predates this administration. Government agencies collect vast stores of personal information for narrow statutory reasons. Health programs protect it fiercely to encourage participation. Immigration enforcement seeks every locational advantage available. When those missions collide inside contractor platforms that specialize in fusing disparate datasets, the safeguards built for one purpose rarely survive contact with the other.

Palantir’s business model thrives on exactly this fusion. Its government contracts have ballooned in recent years. Defense. Intelligence. Now domestic enforcement. Supporters praise the efficiency such tools deliver. Detractors warn that efficiency without strict oversight invites mission creep and permanent expansion of surveillance capacity. The Medicaid episode hands the critics fresh ammunition.

Deletion claims only heighten the stakes. Briseno’s declaration admitted practical difficulties in guaranteeing every variant of the file had been hunted down. Microsoft Teams chats. Local downloads. Cached copies. The modern data environment laughs at old-school purge orders. And once Palantir’s algorithms ingest even a subset of addresses, those signals can inform future models in ways impossible to audit from outside.

Judge Chhabria faces a thicket. Expand access and risk more leaks. Keep it narrow and invite appeals that could land the case before a Supreme Court widely expected to favor executive latitude on immigration. The Democratic states have made clear they will fight any broadening until the government proves it can handle the data without repeated blunders.

Meanwhile millions of Medicaid recipients remain in the dark about whose hands their information reached. Citizens who share addresses with noncitizen family members. Legal residents whose eligibility records traveled anyway. The breach doesn’t discriminate. It simply widens the pool of people who now must wonder whether signing up for health coverage painted a brighter target on their door.

The story continues to unfold. An August hearing looms. Further filings will likely surface. Yet the core facts already speak volumes. A system designed to deliver medical care to low-income Americans became, through error and ambition, raw material for deportation analytics. The distance between those two purposes used to feel wider. Technology and policy choices have narrowed it considerably. Whether courts or Congress widen it again will shape privacy expectations for years ahead.

And the skepticism lingers. About deletions. About controls. About assurances that this time the rules will stick. In an era when data moves at light speed and enforcement appetites grow, trust has become the scarcest resource of all.

Subscribe for Updates

InfoSecPro Newsletter

News and updates in information security.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us