The Second Circuit held the line on trans patients' privacy. Providers still need a plan.
A watchful vixen never advertises where her den is. This month, one federal court agreed that a hospital's patient list deserves the same discretion, while another disagreed entirely.
By Katie Delaney · 2026-09-01 · 15 min read
What the Second Circuit actually decided#
On 26 August 2026, a three judge panel at the Second Circuit Court of Appeals denied the Department of Justice's request to pause a lower court order shielding transgender patients' medical records. The panel, which included two judges appointed by President Trump and one appointed by President Biden, gave almost no reasoning, only that the motion was denied, according to Courthouse News, 2026. For the plaintiffs, and for the hospitals holding their charts, that one line order is the difference between a subpoena a court can enforce today and one that stays frozen while the underlying case continues.
The organisations representing the plaintiffs called it exactly that: a rejection of the government's latest attempt to obtain the most private medical information of transgender young people, with the underlying case, not just this one motion, continuing regardless, per Lambda Legal, 2026 and the ACLU, 2026.
The case is Coe v. Blanche, filed on 2 June 2026 in the Southern District of New York by the American Civil Liberties Union, the New York Civil Liberties Union and Lambda Legal, on behalf of three families with transgender youth and two transgender young adults who were minors when they began care. Every plaintiff sued under a pseudonym, and the court provisionally certified a class covering everyone in the same position, so the ruling protects far more patients than the five named on the docket, per the docket, via CourtListener.
US District Judge Katherine Polk Failla granted a temporary restraining order on 24 June 2026, then converted it into a preliminary injunction on 6 July, finding the government's demands likely violate the Fourth and Fifth Amendments as well as New York's own doctor patient confidentiality law. Her order bars the DOJ from seeking, receiving, using, retaining or disseminating identifying or sensitive information about the plaintiffs while the case proceeds, one of the clearest healthcare data privacy protections any federal court has written this year, per the Civil Rights Litigation Clearinghouse.
The subpoenas reach further than one hospital. Federal prosecutors sent grand jury demands to more than twenty New York healthcare facilities, including NYU Langone and Mount Sinai, seeking the identities and treatment histories of patients who received gender-affirming care for gender dysphoria while under eighteen, going back to January 2020. The request grew out of an April 2025 directive asking prosecutors to investigate pharmaceutical “misbranding” tied to puberty blockers and hormone therapy, itself a response to a Trump executive order, signed days into his second term, declaring the government would no longer fund or support gender-affirming care for minors, per The Associated Press via NBC News, 2026 and Courthouse News, 2026.
None of this happened in one afternoon, and every date below marks another test of healthcare data privacy under real legal pressure. The timeline lays out the five dates that matter, from the day the lawsuit was filed to the day the DOJ lost its latest bid to route around the block.
Read plainly, the dates show a pattern the government has repeated in courtroom after courtroom: file a subpoena, get blocked, appeal, get blocked again, try a different theory in a different state. Courthouse News, 2026 counted at least eight federal district courts that had already quashed or narrowed similar demands before the Second Circuit even reached this one. That pattern is why healthcare data privacy has become the single most contested question in trans healthcare marketing this year, and why it will not be settled by one ruling in one circuit.
Why healthcare data privacy still depends on the map#
Here is the complication a same day headline will not tell you: healthcare data privacy protection for trans patients is not one national rule right now, it is a patchwork that changes at the circuit line. The Second Circuit's refusal to lift Judge Failla's order is a win in New York. It is not binding in Texas, Washington, or anywhere else the DOJ decides to try the same request through a different US Attorney's office.
Twelve days earlier, on 14 August 2026, a different panel reached the opposite conclusion. The Ninth Circuit, ruling two to one in QueerDoc, PLLC v. DOJ, reversed a district court that had quashed an administrative HIPAA subpoena against a telehealth provider serving trans patients, holding that a president is entitled to policy preferences and may direct the executive branch to pursue them, and that public opposition to gender-affirming care alone does not prove a subpoena was issued in bad faith. One dissenting judge argued the majority had let policy preference override the statutory limits Congress built into HIPAA, per the Ninth Circuit's opinion, via Justia and Lawdork, 2026.
Put the two rulings side by side and the shape of the fight becomes a number, not just a mood.
Nine rulings against the government, one for it, and the one is an appeals court rather than a single district judge, which is what makes it dangerous. A circuit split invites the Supreme Court, and the DOJ has every incentive to keep filing until it finds a panel that reasons like the Ninth Circuit's rather than the Second's. A subpoena that cannot pick up a scent in one circuit will simply try another, so treat healthcare data privacy for gender-affirming care records as jurisdiction dependent, not settled, and build your patient privacy rights messaging around that honest uncertainty rather than a protection the law has not finished deciding.
Gender-affirming care is healthcare, not a debate#
None of this is a referendum on whether gender-affirming care works. The World Professional Association for Transgender Health's Standards of Care, Version 8, and the Endocrine Society's own clinical practice guideline both treat hormone therapy and related treatment as ordinary, evidence-based medicine, developed the way any specialty guideline is developed: years of clinical research, multidisciplinary review and graded recommendations, not political preference. That clinical baseline sits underneath every record the DOJ is trying to obtain.
None of that clinical detail is a healthcare data privacy risk on its own. The evidence is public, published and meant to be cited. The risk sits one layer down, in whether a specific named person can be tied to it.
That clinical footing matters for healthcare data privacy communication specifically. A provider can state, plainly and without hedging, that the treatment it offers is recommended by the relevant medical societies. What it cannot do is let that same plain statement become the thread a subpoena, a data broker or a hostile actor pulls to identify who is receiving it. The safest den is the one that never advertises exactly who is inside it, and healthcare data privacy in gender-affirming care is best planned as protecting the individual precisely because the underlying care needs no defending at all.
The Second Circuit refused to lift an order blocking federal prosecutors from obtaining sensitive information about young people who received gender-affirming care in New York City.
That post landed within days of the ruling, from the LGBTQ outlet them., and it captures the mood among the clinics, hospital departments and platforms folkfox works with: relief that one court held the line, and no illusion that the fight for patient privacy rights is finished, per them., 2026.
The paid channels a subpoena cannot touch#
Even before this case, gender-affirming care providers had one of the narrowest paid marketing funnels in healthcare. Google's healthcare and medicines policy already restricts online prescribing, dispensing and telehealth advertising to businesses holding LegitScript certification, and its policy on health in personalised advertising bars targeting anyone by inferred or declared medical condition, gender-affirming care included, per Google Ads healthcare and medicines policy and Google, health in personalised advertising.

Meta runs the same logic through its personal attributes rules: an ad cannot assert or imply that the person viewing it has a specific health condition, so copy describing a service in general terms passes review and copy naming the viewer's diagnosis does not, per Meta, personal attributes policy.
Add an active federal subpoena effort aimed at exactly this patient population and the calculus shifts again. A pixel that tracks a visitor from a symptom page to a booking form leaves a track a subpoena can follow just as easily as a clinician's note, so every dollar spent chasing a narrower audience now carries a second question behind the usual one: does this campaign create a healthcare data privacy exposure a grand jury could later ask a court to unseal.
Marketing stacks for regulated healthcare are already a warren of vendors, pixels and subprocessors, and every additional integration is one more room a subpoena's lawyers could ask a court to search. The table below is a plain accounting of which channels still work, and what each one actually requires now.
| Channel | Where it stands | What to do now |
|---|---|---|
| Google Search, brand and condition terms | LegitScript certification required; no personal condition targeting | Certify early, lead with plain clinical language, skip remarketing lists |
| Meta, Instagram | Personal attributes policy blocks condition targeting; broad interest targeting still runs | Speak to the service on offer, never to the viewer's diagnosis |
| Organic search and AEO | No health ad gate applies | Publish clinical, sourced content clinicians and patients can both find |
| Referring physician networks | Governed by provider relationships, not ad policy | Invest here first; it survives every ad policy and subpoena headline |
| Email and patient portals | Governed by HIPAA and consent, not by an ad platform | The highest trust channel folkfox sees; protect it like the record it is |
Read the table the way a fox reads a hedgerow: the safest routes are the ones nobody is watching for a click. Referring physicians and a provider's own patient portal do not run through an ad auction and do not care what a grand jury is doing three states away, which is exactly why they deserve the budget a paid campaign cannot responsibly spend on this population right now.
Where HIPAA compliance healthcare teams still have gaps#
Most HIPAA compliance healthcare programmes were built to survive an insurer audit or a state attorney general inquiry, not a federal grand jury asking a hospital to hand over patient identities wholesale. That gap is where providers, clinic networks and telehealth platforms serving trans patients need to spend the next quarter, and it splits cleanly into four jobs: know what you hold, minimise it, say the true thing about privacy in public, and know who to call the day a subpoena arrives.
List every field your marketing, scheduling and analytics tools store against a real subpoena's likely ask: diagnosis, treatment dates, appointment history, even a form field asking why someone booked.
Data minimisation is a retention schedule, not a slogan. Delete or aggregate identifying marketing data on a fixed clock, so the record a subpoena could reach is thinner every year rather than growing. This one habit does more for healthcare data privacy than any policy page.
Publish a plain language page describing what the practice collects, why, and how long it is kept. A precise, honest account of your own practices invites less scrutiny than an overpromised legal guarantee.
Agree the escalation path with counsel now: who may accept service, who calls outside counsel, and what nobody on staff may hand over without a court order. A rehearsed response stays calmer than an improvised one.
None of this requires new technology. It requires treating healthcare data privacy as an operational discipline that marketing owns jointly with compliance and counsel, rather than a line in a policy nobody on the growth team has actually read. Saying the true thing about privacy in public is a brand strategy problem before it is a legal one, and it lives in the same content programme that already carries your clinical evidence, as folkfox argued when NHS Wales paused its own gender-affirming surgery list.
Marketing PII fields audited
Every CRM and ad pixel field checked against what a subpoena could ask for.
Records past retention schedule
Target zero identifying marketing records held past their agreed date.
Certified paid channels live
LegitScript certified Google and reviewed Meta accounts, the two channels that can legally run campaigns for this audience.
A subpoena is not something a marketing team can outrun, but it is something a marketing team can stop feeding. Every field you never collect leaves no trail to subpoena, and that quiet discipline earns more patient trust than any privacy badge on a landing page. It is also, as one recent HIPAA compliant marketing raise shows, the same discipline that keeps a healthcare data privacy programme credible after the headlines move on.
Frequently asked questions#
Is transgender status protected under HIPAA?
Yes, in the same way any other health information is. HIPAA's Privacy Rule protects identifiable health information regardless of diagnosis, so records showing gender-affirming care are covered exactly like records showing diabetes or cancer treatment. The 2026 dispute is not about that healthcare data privacy baseline, it is about whether a grand jury subpoena can override it. A separate 2024 rule adding extra reproductive health privacy protections was itself struck down by a Texas court in 2025, a reminder that this area keeps moving, per HHS's HIPAA Privacy Rule guidance and Holland & Knight, 2025.
How should clinics handle DOJ subpoenas gender-affirming care providers are now facing?
Treat every subpoena as a legal event, not a marketing one. Route it straight to counsel before responding, confirm what a validly issued order actually compels versus what it merely requests, and never let front line or marketing staff make that call. Providers within the Second Circuit have stronger footing than those in the Ninth right now, but the safe default everywhere is the same: say nothing and call a lawyer first.
What did the Second Circuit actually decide on 26 August 2026?
It denied the Department of Justice's request to pause a lower court order that blocks the DOJ from seeking, receiving or using identifying health information about transgender patients treated at New York hospitals. The underlying case, Coe v. Blanche, continues; the ruling only means the protection stays in place while it does.
Does the Ninth Circuit's ruling cancel out the Second Circuit's protection?
Not directly. The Ninth Circuit's decision came in a different case, involving a telehealth provider rather than New York hospitals, and it upheld a separate administrative subpoena. The two rulings create a genuine circuit split rather than one cancelling the other, which is exactly why the legal position for gender-affirming care providers nationwide is unsettled rather than resolved.
What is data minimisation, in a healthcare marketing context?
It means keeping only the information needed to serve or reach a patient, for only as long as it is needed, so any given record is as unremarkable as possible if it is ever demanded. For gender-affirming care providers, that includes CRM notes, ad pixel data and form fields, not only clinical charts. It is the single cheapest healthcare data privacy improvement most marketing teams can make.
Can gender-affirming care providers run paid ads on Google or Meta at all?
Yes, within real limits. LegitScript certified providers can advertise on Google without naming a viewer's condition, and Meta allows service focused ads under its personal attributes policy. Neither platform allows targeting someone by inferred diagnosis, so campaigns describe the service rather than the person's health status.
Is gender-affirming care for minors legal everywhere in the United States?
No. Twenty seven states currently limit or ban it, and the Supreme Court ruled in June 2025 that states have the constitutional authority to do so. That is a separate legal question from whether the federal government can subpoena medical records nationwide, which is the dispute this article covers.
Read more on this topic#
Wales paused the surgery list. The access question just got louder
NHS Wales paused gender-affirming surgery referrals on 28 August. What the numbers show, and what providers can still do.
Read the pieceHIPAA compliant marketing just earned its proof of concept
A $15 million raise for a healthcare data privacy platform, and what it proves about privacy first growth.
Read the pieceAny best healthcare marketing agency now has six pixel laws to check
Six state privacy laws now govern health site ad pixels, before any campaign goes live.
Read the pieceGoogle Ads healthcare policy just opened Spain to Rx telehealth ads
What LegitScript certified telehealth providers can now do under Google's healthcare ad policy.
Read the pieceTalk to folkfox about healthcare data privacy before the next subpoena does
Gender-affirming care providers, clinic networks and telehealth platforms that need to reach patients and referring physicians without adding to their legal exposure are exactly who folkfox already works with, on healthcare data privacy and on the growth that survives it.