The identifiers that power everyday mobile ad targeting just got treated as a national security threat. US military officials say they have disabled advertising trackers on a range of phones and computers, according to letters released on Friday by Senator Ron Wyden and statements given to Reuters, a development that follows reports that commercially available location data had been used to target American forces in the Middle East. If the Pentagon has decided that advertising IDs on work devices are too dangerous to leave on, law firm owners and medical practice managers should pay attention. You hold confidential relationships that the same data can expose, and you may be buying ads built on the exact data supply chain now under congressional scrutiny.
What the Wyden Letters Confirm About Ad Tracking
The disclosures cover every branch. The US Army, Air Force, Navy, Marine Corps, and Special Operations Command have all disabled advertising tracking across their government-issued devices, including iPhones and Android devices, and Windows computers managed across the federal military enterprise network.
The timelines vary. The Air Force told Wyden it disabled the advertising identifiers on computers and mobile phones two months ago, Special Operations Command said it had recently disabled them on its Windows devices, and the Army said advertising IDs tied to mobile devices had been disabled since earlier this year. The Army added that advertising IDs had been blocked on Windows computers since before 2021, but Android and Apple mobile devices only had them disabled by default since at least February 2026.
Congress is not treating this as finished. Wyden and Representative Pat Harrigan sent a letter to the Pentagon on Friday asking for an investigation into whether the military had properly countered the dangers of the location data trade. Wyden said it was clear the military's efforts "have not been effective at neutralizing this threat." The Pentagon said it would respond to the lawmakers directly.
How Advertising IDs Turn Into Location Surveillance
The mechanism here is the same one behind most location-based ad targeting. Mobile advertising IDs, known in the industry as MAIDs, are unique identifiers attached to individual devices that allow data brokers and ad networks to follow a person's movements across apps and map their physical location with striking precision. These identifiers help companies build detailed profiles of users, and data brokers can then collect, aggregate, and sell that information, potentially making sensitive location data available to buyers.
The supply chain is long and loosely controlled. Location data is collected from smartphones by app developers, sold to data brokers, resold to defense contractors, and then resold again to the government. The US intelligence community and the FBI have confirmed that they buy this data for surveillance and intelligence collection without a warrant. If federal agencies and, reportedly, foreign adversaries can buy it, the same commercial market could in principle be open to other buyers as well, which is exactly why professionals who hold confidential relationships should understand how the trade works.
Why Medical and Legal Locations Are Already Targets
This is not a theoretical risk for healthcare and legal audiences. Wyden's earlier investigations documented exactly this pattern. An anti-abortion organization used cell phone location data shared with online advertising companies to target misinformation at people who had visited Planned Parenthood locations, and the advertising agency involved confirmed the campaign targeted visitors to 600 locations across 48 states.
Swap the clinic for any sensitive destination and the logic holds. A phone that regularly appears at an oncology practice, an addiction treatment center, a bankruptcy attorney's office, or an immigration law firm generates a data trail that brokers can package and sell. Your clients and patients carry that trail with them, and so do your staff. The military's own remaining gap makes the point. Wyden warned that the personal devices of troops and contractors brought onto military bases could still expose service members and facilities to attacks. For a practice, personal phones in the office are the equivalent exposure.
What This Means for Location-Targeted Advertising
If you buy geofenced or location-audience campaigns for patient or client acquisition, the ground is shifting under that tactic. Regulators have already moved against the data sources. The Federal Trade Commission brought an action against the data broker X-Mode Social, which had been selling data collected from phones.
States are moving too, with health data as the leading edge. According to industry reporting, a revised New York Health Information Privacy Act passed both the New York Senate and Assembly in June 2026, is awaiting the governor's signature, and would take effect six months after enactment. Readers should verify the bill's current status against official New York legislative records, since pending legislation can change. As described, it would apply broadly to regulated health information, a category wider than HIPAA's protected health information, reaching businesses in New York or those processing data about New York residents. Location signals that imply a health condition sit squarely in that expanding category. Campaigns that geofence competitor clinics, hospitals, or courthouses may perform today and draw scrutiny tomorrow.
The practical takeaway for growth teams: treat MAID-based location audiences as a depreciating asset. Building acquisition on consented first-party data, search intent, and content means a legal change to one data source is less likely to take your pipeline down with it.
What Law Firms and Medical Practices Should Consider Now
The following are general points to weigh, not legal or compliance advice. Talk with your own counsel about what any law or regulation requires of your practice.
- Consider disabling or resetting advertising IDs on firm-issued phones, tablets, and Windows machines through your mobile device management tool, the same step all five military branches have now taken on their devices.
- Review your bring-your-own-device policy. Many organizations ask staff who handle sensitive matters to zero out advertising IDs and limit app location permissions on personal phones used for work.
- Look at your ad campaigns for location targeting that touches sensitive places: clinics, hospitals, courthouses, treatment centers, places of worship. Document what you find and who approved it.
- Ask your agencies and ad vendors, in writing, whether any audience they sell you is built from MAID or data broker location data, and where that data originates.
- If you serve New York residents or patients, consider reviewing what data you collect that could relate to health information, and raise the pending NYHIPA legislation with your counsel so you understand what may apply to you.
- Brief intake and reception teams. Client-facing Wi-Fi, visitor apps, and lobby tablets also emit identifiers worth reviewing.
The Signal Behind the Story
When the Army, Navy, Air Force, Marine Corps, and Special Operations Command all conclude that advertising identifiers are a liability, the debate about whether this data is sensitive is over. The remaining questions are how fast regulation catches up and who gets caught mid-transition. No one can promise a particular outcome, but practices that reduce their reliance on broker-sourced location data and tighten device settings now may face less disruption as rules and enforcement evolve, while those that wait may find themselves reacting under pressure instead of adapting on their own schedule. The letters released this month were addressed to the Pentagon, but the warning inside them was addressed to everyone.

