
Few industries operate under as much scrutiny as cannabis. State rules require operators to track every gram from seed to sale. Operators also retain months of surveillance footage, badge every employee, log every visitor, document waste disposal, and facilitate routine inspections.
Compliance was built into this industry from the start. That compliance framework was designed to prevent the cannabis plant from escaping the tightly controlled supply chain. In the process, regulators also required operators to collect highly sensitive information: patient registrations, physician certifications, scanned driver's licenses, purchase histories, background check files, and fingerprints. Yet the rules often say much less about how to protect that information. The result is an industry that holds pharmacy-grade data but too often protects it with liquor-store-level security.
Three developments in September 2026 illustrate the consequences of that gap.
Recent Cases Expose the Data-Security Gap
On Sept. 8, 2026, Judge Pamela A. Barker of the U.S. District Court for the Northern District of Ohio denied Ohio Medical Alliance LLC's motion to dismiss and instead (in a 52-page decision) held that the plaintiffs had adequately pleaded standing based on specific alleged injuries traceable to the data breach asserted in the six consolidated actions in In re Ohio Marijuana Card Data Breach Litigation, No. 1:25-cv-01765 (N.D. Ohio Sept. 8, 2026).
The litigation arose after a security researcher discovered roughly 957,000 records, amounting to about 323 gigabytes, in a database that the complaint alleges had no encryption and no password protection. The exposed information included driver's licenses, Social Security numbers, medical records, physician certification forms, and mental health evaluations.
The company that ran that database serves medical cannabis patients in six states. No operator in this industry would leave cannabis product in an unlocked room, yet the complaint alleges that nearly a million records containing patient information sat in the digital equivalent of one.
Another class action, In re STIIIZY, Inc. Data Breach Security Litigation, No. 2:25-cv-00490 (C.D. Cal.), has resulted in STIIIZY agreeing to a proposed $2.95 million settlement to resolve claims from an October 2024 incident the cannabis company attributed to a point-of-sale processing vendor. Final approval is scheduled for Oct. 19, 2026. Roughly 380,000 current and former customers received notices that their names, dates of birth, driver's license numbers, photographs, signatures, medical cannabis cards, and transaction histories may have been exposed.
The vendor may have been the point of entry, but STIIIZY is the one funding the $2.95 million settlement, including attorneys' fees, administration costs, credit monitoring, and payments to class members.
Meanwhile, in September 2026 alone, at least nine federal lawsuits were filed in the Eastern District of Louisiana against IDScan.net, an identity verification company that, by its own account, powers ID scanning at more than 1,000 dispensaries and provides medical cannabis card verification in 19 states.
The suits followed investigative reporting that traced a dark-web marketplace calling itself Nexus, which advertised searchable access to what the sellers claimed were more than 153 million driver's license scans and 579,000 medical cards, back to IDScan through timestamps matching real transactions. One researcher's record matched the day a Las Vegas dispensary scanned his license, and records reportedly included infrared and ultraviolet captures alongside the standard scan, the hidden security features that verification hardware reads to catch a counterfeit.
On Sept. 4, 2026, IDScan.net acknowledged in a website notice that an unauthorized third party may have accessed or copied customer information stored in its cloud, including full names and driver's license or other government-issued identification numbers. The FBI has also confirmed it is separately investigating the matter. The company has not confirmed the claimed scale, disclosed a root cause, or said how many people were affected.
Taken together, these developments send a clear message. Plaintiffs' firms are watching the industry, a federal court has allowed a significant data-breach case to move beyond the pleading stage, and litigation now moves faster than many operators' incident response plans.
Cannabis Data Carries Unique Privacy Risks
A stolen credit card can be replaced. A record connecting a person to cannabis use can be permanent, and that information may have serious implications on a person's federal employment and security clearance, Department of Transportation-regulated employment, immigration proceedings, and others. Licensed professionals face another layer of risk: a nurse, teacher, or commercial driver whose medical cannabis registration becomes exposed may face consequences that a nonmedical customer might not.
The U.S. Supreme Court's June 2026 decision in United States v. Hemani, 146 S. Ct. 1677 (2026), limits the government's ability to use 18 U.S.C. § 922(g)(3) to disarm someone based on cannabis use alone, but it did not eliminate the larger concern. Cannabis-use data may still reveal conduct with real legal consequences under federal and state law.
These recent scenarios put personal, sensitive customer data in the headlines. Cannabis operator employee data receives far less attention, even though operators often hold much of the same sensitive information about their workforce.
Cannabis Industry Employee Records Create Parallel Privacy Risks
Cannabis operators carry unusually heavy employee data, and nearly all of it exists because the state rules demand it. State licensing regimes require background checks and fingerprinting for badged employees. Where those checks are obtained through consumer reporting agencies, the resulting reports bring even more obligations under the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq., governing, among other things, how the reports are procured, used, and disposed of.
Many cultivation and processing facilities run biometric timeclocks and access controls, which bring additional privacy considerations into the picture. In Illinois, for example, the Biometric Information Privacy Act, 740 ILCS 14, plainly reaches fingerprint-based employee timekeeping, while a growing number of other states regulate biometric information through standalone biometric laws or broader privacy statutes.
Medical information gathered through the accommodations process must be kept confidential and maintained in separate files under the Americans with Disabilities Act, 42 U.S.C. § 12112(d). A breach of the badging system, for example, can expose the same Social Security numbers and fingerprints as a breach of a patient database itself, and mishandling ADA-protected employee medical files is a legal problem far before any hacker enters the picture.
The Tenth Circuit made clear that federal employment law applies even in an industry with a complicated federal status. In Kenney v. Helix TCS, Inc., 939 F.3d 1106 (10th Cir. 2019), a security guard for a Colorado cannabis company sued for unpaid overtime compensation. The employer argued that the Fair Labor Standards Act (FLSA) should not protect workers in an industry that violates the Controlled Substances Act.
The court rejected that position: Violating one federal statute does not excuse an employer from complying with another. Kenney addressed the FLSA, but its reasoning likely extends beyond wage claims. Federal employment laws applied to cannabis employers throughout the Schedule I era. Now that medical cannabis has been rescheduled to Schedule III, operators should assuredly pay closer attention to federal laws governing employment and data privacy practices.
New Technology Continues to Expand Risk
The tools operators are adopting now increase the risks. Analytics platforms, AI-assisted point-of-sale systems, and marketing automation, for example, further expand the customer-data footprint. Each new tool also adds another vendor relationship. Two of the three recent lawsuits mentioned above involved third-party vendor breaches.
On the employment side, the U.S. Equal Employment Opportunity Commission’s (EEOC) iTutorGroup case offered an early warning. The company programmed its application software to reject applicants at or above a certain age automatically and later paid $365,000 to settle the EEOC's age discrimination lawsuit, EEOC v. iTutorGroup, Inc., No. 1:22-cv-02565 (E.D.N.Y. 2023).
In the employment context, AI does not create a new theory of liability (employers already couldn’t discriminate based on age); it simply applies the existing ones at scale. Title VII of the Civil Rights Act, the Age Discrimination in Employment Act (ADEA), and the ADA still govern employment decisions made with AI tools, and an employer cannot outsource liability or responsibility by using a third-party vendor. Though the EEOC removed much of its AI-specific guidance from its website in January 2025, the existing legal standards remain.
Why Good Data Practices Matter
On April 28, 2026, the Department of Justice's final rescheduling order took effect, placing cannabis covered by qualifying state medical licenses and FDA-approved cannabis products from Schedule I to Schedule III, and on Sept. 9, 2026, the D.C. Circuit denied a motion to stay that order while consolidated legal challenges proceed.
Rescheduling is meaningful, particularly for qualifying medical operators facing Section 280E of the Internal Revenue Code, which denied ordinary business deductions to businesses trafficking in Schedule I or II substances. Federal banking and insurance friction remains real; the Government Accountability Office reported recently that cannabis businesses continue to face meaningful access challenges. Trademark, lending, and coverage questions will be worked out incrementally, category by category.
Rescheduling does not make cannabis an ordinary industry, but it does change the diligence conversation. Lenders, insurers, investors, and acquirers that once stopped at the word “cannabis” now have more reason to look closely. When they do, data governance will be part of that review. They will want to know what data the company holds, where it is stored, who can access it, and how the company handled its last incident. An operator with a documented data governance program can answer those questions, while the one with an unencrypted database in its history may be explaining that failure for years (and with significant financial consequences).
Good data practices do more than reduce risk; they also protect the company's long-term value.
What Operators Should Do Now
For dispensaries specifically, the retail side of the industry, the IDScan case may already be live in their technology. Operators using IDScan.net or a similar verification vendor should ask whether scans from their locations were affected, invoke the contract's notification and cooperation provisions in writing, and preserve the vendor's responses, at minimum.
They should also determine who has the legal duty to notify customers. State breach-notification laws generally place that obligation on the entity that owns or licenses the data, which may be the dispensary depending on the vendor arrangement. Operators should assess the full verification and point-of-sale systems and maintain an incident response plan that assumes a plaintiffs' firm may come knocking before the vendor does. That preparation can determine whether the operator manages the incident proactively or spends the next several months reacting to it in crisis mode.
For other operators, the same work can be done without the pressure of an active incident. The industry already knows how to build and run compliance programs. The task now is to apply that discipline to the data.
Operators should consider these six takeaways:
- Inventory your data. Identify every category of customer and employee information you hold, where it lives, and who can access it, from patient registrations and ID scans to background check files and biometric records. You cannot protect what you have not accounted for, and you certainly cannot answer a diligence questionnaire without it.
- Audit every single one of your vendors, starting with point-of-sale and ID verification. STIIIZY attributed its data breach to a POS vendor, and the IDScan.net lawsuits target a verification provider most operators have yet to really think about. Review what data each vendor touches, what security obligations the contract imposes, who pays when the vendor fails, and the breach notification procedures.
- Encrypt and restrict. The complaint against Ohio Medical Alliance alleges an unencrypted database with no password. Encryption at rest, multi-factor authentication, and role-based access are the data equivalent of the physical locked vault every regulator already requires for its product.
- Stop keeping what you do not need. Set retention periods, purge on schedule, and document everything.
- Update your incident response plan. The first IDScan.net complaints were filed two days after the dark-web listing appeared; a plan that assumes weeks to investigate before anyone notices assumes a world that no longer exists. Get clear on your notification obligations well in advance. Every state has a breach notification statute, each of which runs on its own clock, and medical information frequently triggers stricter requirements.
- Build your diligence file. Keep the written security policies, the vendor contract terms, the training records, and the incident history in one place, maintained with the same care and attention as the way you maintain your license renewal file.
Cannabis companies did not choose this compliance-heavy environment, but successful operators have turned it into a level of discipline that many industries will never match. The data in your systems, much of it collected because regulations require it, deserves the same protection as the product on your shelves.
Plaintiffs' lawyers have already noticed the compliance gap. Operators should close it before they become the next target.




















