Federal and state enforcement actions involving unauthorized data sharing violations, tracked from official government sources.
251
Total Actions
$819.7M
Total Fines
15
Jurisdictions
Colorado Attorney General Phil Weiser announced a settlement with Avail Property Management Inc. and PK Management, LLC resolving allegations that the companies denied prospective tenants housing based on criminal history information prohibited under Colorado's Rental Application Fairness Act, including arrests, deferred judgments, and convictions older than five years (some more than 20 years old). The companies, which managed nearly 4,000 rental units across Colorado, relied on a third-party background screening service despite legal prohibitions. Under the settlement, they must change screening practices, review vendor recommendations rather than relying on them automatically, submit to two years of compliance reporting, and pay $300,000.
$300K
Virginia Attorney General Jay Jones announced a landmark $17 billion multistate settlement with Meta joined by 52 states and U.S. territories, resolving claims that Meta deceived the public about addictive design features harming youth mental health and shared Facebook users' private information with third parties before the 2016 election. Virginia is guaranteed $353 million (with an additional $11 million for the data-sharing claims, bringing its total to $364 million). Meta must implement sweeping child-safety reforms on Instagram and Facebook, including age verification, daily time limits, and 'check in breaks,' with implementation and efficacy regularly assessed by an independent auditor.
$353.0M
Attorney General Jones, along with four other states and the FTC, sued Zillow and Redfin for an illegal agreement where Zillow paid Redfin $100 million to exit the multifamily rental advertising market and exclusively display Zillow's listings. The settlement requires the companies to restore competition, pay $2 million, and prohibits future anticompetitive agreements.
$2.0M
New York Attorney General Letitia James, along with four other states and the FTC, settled with Zillow and Redfin after they entered an illegal agreement to stop competing in the multifamily rental advertising market. Zillow paid Redfin $100 million to shut down its advertising business and exclusively display Zillow's listings. The settlement requires the companies to resume competing and pay $2 million.
$2.0M
Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.
$2.0M
Attorney General Jay Jones and a coalition of 21 attorneys general obtained a temporary restraining order blocking the Trump administration from demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers from AAMVA. The lawsuits allege the federal agencies violated federal privacy laws and the Administrative Procedure Act by seeking to acquire the data without guardrails or public notice.
New York Attorney General Letitia James and a coalition of 22 attorneys general plus Pennsylvania secured a temporary restraining order blocking the Trump administration from seizing the names, dates of birth, and Social Security numbers of 17 million commercial drivers nationwide, including nearly 500,000 New Yorkers. The U.S. District Court for the Eastern District of Virginia granted the TRO, preventing the federal government from accessing the data or cutting off access to the critical database.
Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.
$275K
A coalition of 21 attorneys general and the Governor of Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, DHS, and AAMVA to prevent the federal government from obtaining a database of personal information of 17 million commercial driver's license holders. The lawsuits allege the federal government violated federal privacy laws and the Administrative Procedure Act by demanding the data without notice or guardrails, and threatening to withhold $10 million in federal funding if AAMVA refused.
Attorney General Phil Weiser joined a coalition of 22 attorneys general and Pennsylvania in filing two lawsuits against the Trump administration for demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data from being turned over by the August 17 deadline.
New York Attorney General Letitia James and a coalition of 21 other attorneys general and Pennsylvania sued the U.S. Department of Transportation and Department of Homeland Security to block the federal government from seizing the personal data of 17 million commercial drivers from the CDLIS database. The coalition argues the demands violate federal privacy laws and the Constitution, and seeks an injunction to prevent the data transfer.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.
Attorney General Dan Rayfield and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and AAMVA to block demands for a database containing personal information of 17 million commercial drivers. The federal government threatened to withhold $10 million in funding unless the data was turned over, which the coalition argues violates privacy law.
Attorney General Tong and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and DHS to block demands for the personal information of 17 million CDL drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data transfer.
New York Attorney General James announced a multistate settlement with three major egg producers for illegally coordinating to influence a daily egg price index, artificially inflating prices for consumers. The companies will deliver 53 million eggs to food banks and pay $3.3 million, along with adopting compliance measures.
$3.3M
Attorney General Phil Weiser joined a coalition of 43 states and territories announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations that the generic drug manufacturer engaged in conspiracies to artificially inflate and manipulate prices, reduce competition, and unreasonably restrain trade. Sandoz will pay approximately $469 million including previous settlements and agreed to meaningful reforms to ensure fair competition and compliance with antitrust laws.
$400.0M
Attorney General Jennifer Davenport joined a coalition of 23 states and DC in suing the Trump Administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data with other federal agencies, including ICE. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.
Attorney General William Tong joined a coalition of 23 states and the District of Columbia in suing the Trump administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data across federal agencies and potentially private organizations. The lawsuit alleges violations of the Administrative Procedure Act and the Spending Clause, seeking to block the policy.
Oregon Attorney General Dan Rayfield, joined by a coalition of 23 other states, the District of Columbia, and two governors, sued the Trump administration to block a new policy by the Administration for Children and Families (ACF) that would allow federal officials to access private records of millions of TANF recipients. The coalition argues the policy illegally shares sensitive personal data, including Social Security numbers and immigration status, with other federal agencies and private organizations, violating the Administrative Procedure Act and the Spending Clause. The lawsuit seeks to declare the policy illegal and block it from taking effect.
Attorney General Ellison joined a coalition of 23 other states and DC to sue the Trump administration over a policy that would allow the Administration for Children and Families (ACF) to share sensitive TANF recipient data with other federal agencies. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.
The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.
Attorney General Jay Jones joined a coalition of 26 states to sue the Trump administration over unlawful conditions attached to counterterrorism and emergency funding. The conditions would require states to share voter data with DHS and assist in immigration enforcement, which the coalition argues violates the Administrative Procedure Act and the Spending Clause.
Attorney General Phil Weiser joined a bipartisan coalition of 48 states and territories in announcing a $29.6 million settlement with Glenmark Pharmaceuticals. The settlement resolves allegations that Glenmark participated in a widespread conspiracy to inflate prices, reduce competition, and restrain trade for numerous generic prescription drugs. Glenmark also agreed to cooperate in ongoing multistate litigation and implement internal reforms.
$29.6M
Minnesota Attorney General Keith Ellison, along with the FTC and attorneys general of Arizona, Illinois, Michigan, and Wisconsin, settled an antitrust lawsuit against John Deere. The settlement requires Deere to provide farmers and independent repair providers with the same repair resources previously only available to authorized dealers for 10 years, and to pay $1 million in legal costs.
$1.0M
Attorney General Ellison, as part of a bipartisan coalition of nine attorneys general, announced a $7 million settlement with property management company LivCor, LLC. The settlement resolves allegations that LivCor used RealPage's revenue management system to illegally share and gather confidential pricing information with competing landlords, enabling them to keep rental prices artificially high. LivCor must cease using such software, refrain from sharing competitively sensitive information, establish an antitrust compliance program, and cooperate in ongoing litigation against RealPage.
$7.0M
Colorado Attorney General Phil Weiser, as part of a bipartisan coalition of nine attorneys general, announced a $7 million settlement with LivCor, LLC for its role in an algorithmic rent-fixing scheme. LivCor allegedly used RealPage's revenue management software to share and gather confidential pricing information with competing landlords, artificially inflating rental prices. The settlement requires LivCor to cease using such software, pay $7 million in penalties, and cooperate in ongoing litigation against RealPage.
$7.0M
The FTC alleged that Cox Media Group (CMG), MindSift LLC, and 1010 Digital Works LLC deceived customers by falsely claiming to offer an AI-powered 'Active Listening' service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. In reality, the service did not use voice data and consumers had not consented. The companies agreed to pay a total of $930,000 and are prohibited from making misrepresentations about their services, voice data collection, and consumer consent.
$930K
Texas Attorney General Ken Paxton launched an investigation into Meta regarding its Meta AI Glasses, alleging unlawful collection of facial biometric data, deceptive privacy representations, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses’ always-on recording mode lacks proper notice, subcontractors access private user content including intimate moments, and Meta plans to deploy facial recognition technology to collect unsuspecting individuals’ facial geometry. The AG issued a Civil Investigative Demand to determine if Meta violated Texas law by deceptively misrepresenting its data use practices.
Texas Attorney General Ken Paxton launched an investigation into Meta's Meta AI Glasses over allegations of unlawful facial biometric data collection, deceptive privacy practices, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses' always-on recording mode lacks proper user notice, planned facial recognition features would collect data without consent, and private user videos are accessed by third-party annotators in Kenya. The AG issued a Civil Investigative Demand to Meta to determine violations of Texas privacy laws.
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
$12.8M
Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.
The FTC settled charges with data broker Kochava, Inc. and its subsidiary Collective Data Solutions (CDS) over allegations that they sold precise location data from hundreds of millions of mobile devices without consumer consent, enabling tracking of visits to sensitive locations like reproductive health clinics and places of worship. The settlement prohibits the companies from selling or sharing sensitive location data without affirmative express consumer consent, and imposes compliance requirements including a sensitive location data program, supplier consent assessments, incident reporting, and data retention schedules. No monetary penalty was imposed.
CalPrivacy and the California Attorney General secured a $12.75 million settlement from General Motors for data sharing practices from connected vehicles. The settlement includes injunctive terms to change business practices.
$12.8M
The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.
Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.
The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.
$1.1M
Attorney General Raoul secured a court order preventing the U.S. Department of Agriculture from collecting SNAP applicants' and recipients' personal data without an agreed-upon protocol that restricts sharing with unrelated entities like the Department of Homeland Security. The court found that the USDA's proposed protocol would violate federal law by allowing data use for immigration enforcement, contrary to the intended purpose of SNAP.
Massachusetts Attorney General Andrea Campbell secured a preliminary injunction from the U.S. District Court blocking the Trump Administration's USDA from cutting off SNAP funding to states that refuse to turn over personal data of SNAP applicants and recipients. The court found USDA's proposed data protocol unlawful because it allowed sharing data with entities unrelated to federal benefits administration.
California Attorney General Rob Bonta secured a second preliminary injunction from the U.S. District Court for the Northern District of California blocking the Trump Administration's demand that states turn over personal data of SNAP applicants and recipients. The court found the USDA's proposed data protocol would allow sharing of state data with entities unrelated to federal benefits administration, violating federal law.
Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.
Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Texas Attorney General Ken Paxton filed a lawsuit against Shein US Services LLC for selling toxic products and exposing consumers' personal data to the Chinese Communist Party. The lawsuit seeks monetary penalties under the Texas Deceptive Trade Practices Act. This action is part of a broader effort to protect Texans from health risks and CCP influence.
Texas Attorney General Ken Paxton filed a lawsuit against PDD Holdings, Inc. and WhaleCo Inc., doing business as Temu, for deceptive marketing and unlawful covert harvesting of Texans’ personal data that was exposed to the Chinese Communist Party. The suit alleges Temu functions as a 'trojan horse' e-commerce app that bypasses security protocols to create a backdoor into users’ private data, which is stored on servers in China. The lawsuit seeks monetary relief under the Texas Deceptive Trade Practices Act, including up to $10,000 per violation and up to $250,000 per violation targeting consumers aged 65 or older.
Texas Attorney General Ken Paxton filed a lawsuit against Temu (PDD Holdings, Inc. and WhaleCo Inc.) for deceptive marketing practices and illegally harvesting Texans' personal data, which was then exposed to the Chinese Communist Party. The suit seeks monetary damages under the Texas Deceptive Trade Practices Act, with potential penalties of up to $10,000 per violation and higher for seniors. This is part of a broader effort to hold CCP-aligned companies accountable.
Texas Attorney General Ken Paxton filed a lawsuit against TP-Link Systems Inc. for deceptively marketing its networking devices and enabling the Chinese Communist Party to access American consumers' devices. The lawsuit alleges that TP Link's products have been used by PRC state-sponsored hackers and that the company is subject to Chinese laws requiring data disclosure. This is part of a coordinated effort to hold China-aligned companies accountable under Texas law.
Communications Workers of America Local 1180 Security Benefits Fund (Health Plan, NY) reported a HIPAA breach affecting 18,550 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.
The Federal Trade Commission (FTC) sent warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans’ Data from Foreign Adversaries Act (PADFAA). PADFAA prohibits data brokers from selling or providing sensitive personal data about Americans to foreign adversaries such as China, Russia, Iran, and North Korea. The letters warn that violations could result in civil penalties of up to $53,088 per violation and urge companies to review their business practices for compliance.
The FTC issued warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA), which bans the sale or disclosure of sensitive personal data to foreign adversaries like China, Russia, Iran, and North Korea. The letters cite instances where recipients offered data on Armed Forces members, which is protected under PADFAA. Non-compliance could result in civil penalties up to $53,088 per violation.
The Florida Attorney General's Office launched the CHINA Prevention Unit and issued a subpoena to Shein for deceptive trade practices and data privacy violations. The unit focuses on combating threats from foreign adversaries like the Chinese Communist Party to consumer data and economic security. This action is part of broader efforts to audit and hold accountable companies with ties to China.
Health and Hospital Corporation of Marion County (Healthcare Provider, IN) reported a HIPAA breach affecting 792 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email, Laptop.
Lincoln National Corporation d/b/a/ Lincoln Financial (Health Plan, IN) reported a HIPAA breach affecting 998 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
A bipartisan coalition of 35 state attorneys general led by New York Attorney General Letitia James sent a demand letter to xAI on January 26, 2026, requiring the company to address its Grok chatbot’s creation and sharing of nonconsensual intimate images, including child sexual abuse material. The AGs demand that xAI implement safeguards to prevent Grok from generating such content, delete existing harmful content, suspend offending users, and give X users control over whether their content can be edited by Grok. No monetary penalty has been imposed as this is a pre-enforcement demand for action.
Minnesota Department of Human Services (Health Plan, MN) reported a HIPAA breach affecting 303,965 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
California Attorney General Rob Bonta, alongside attorneys general from New York, Colorado, Illinois, and Minnesota, filed a motion for preliminary injunction to continue blocking the Trump Administration's unlawful freeze of $10 billion in federal funding for child care and family assistance programs and to prevent broad data requests for personally identifiable information of millions of residents. The funding freeze targets five Democratic-led states without evidence of fraud, and the data requests are part of the challenged unlawful actions. A temporary restraining order was previously granted blocking these measures.
Privacy enforcement action where the FTC settled with General Motors and OnStar for collecting and selling consumers' geolocation and driving behavior data without adequate notice or consent. The order prohibits sharing data with consumer reporting agencies and requires transparency and consumer choice measures.
TMG Health, Inc. (Business Associate, TX) reported a HIPAA breach affecting 2,076 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
Massachusetts Attorney General Andrea Campbell filed a motion to enforce a preliminary injunction against the Trump Administration's demands for personal data of SNAP recipients. The court previously blocked such demands, but the administration renewed its request, threatening to withhold funding. The AG seeks to ensure compliance with federal privacy laws and protect SNAP recipients' sensitive information.
Illinois Department of Human Services (Health Plan, IL) reported a HIPAA breach affecting 705,017 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
California Attorney General Rob Bonta, on behalf of a multistate coalition, filed a motion in U.S. District Court to enforce a preliminary injunction that blocks the Trump Administration from demanding personal and sensitive information about Supplemental Nutrition Assistance Program (SNAP) recipients. The Administration has renewed its demand, threatening to withhold administrative funding from states that do not comply, which the AG argues violates the existing court order and federal law protecting the confidentiality of SNAP applicant data.
Exact Sciences Laboratories LLC (Healthcare Provider, WI) reported a HIPAA breach affecting 2,658 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 780 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
CareOregon (Health Plan, OR) reported a HIPAA breach affecting 5,473 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
Riverland Community Health (Healthcare Provider, MN) reported a HIPAA breach affecting 940 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
York Hospital (Healthcare Provider, ME) reported a HIPAA breach affecting 1,259 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
TapestryHealth (Healthcare Provider, CT) reported a HIPAA breach affecting 6,494 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
Anesthesiology & Pain Consultants, LLC (Healthcare Provider, LA) reported a HIPAA breach affecting 538 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other Portable Electronic Device.
Texas Attorney General Ken Paxton filed a lawsuit against Sony, Samsung, LG, Hisense, and TCL Technology Group for using Automated Content Recognition (ACR) technology to collect Texans' viewing data without proper consent. A temporary restraining order was secured against Hisense to halt all data collection and sharing. The AG issued a consumer alert with instructions to disable ACR on smart TVs.
Texas Attorney General Ken Paxton obtained a temporary restraining order against Hisense, a Chinese smart TV manufacturer, to halt its collection of Texans' personal data through Automated Content Recognition technology without consent. The technology captures every sound and image on the TVs every 500 milliseconds and sells the data, with access granted to the Chinese Communist Party. The TRO prohibits Hisense from collecting, using, selling, sharing, disclosing, or transferring ACR data about Texans while the case continues.
FPMCM LLC (Business Associate, TN) reported a HIPAA breach affecting 2,072 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Texas Attorney General Ken Paxton has filed lawsuits against five major TV manufacturers—Sony, Samsung, LG, Hisense, and TCL—for unlawfully collecting Texans' viewing data using Automated Content Recognition (ACR) technology without their knowledge or consent. The ACR software captures screenshots of TV displays every 500 milliseconds and transmits the data to the companies, which then sell it for targeted advertising. The AG's office alleges these practices violate Texas privacy laws and seeks to enjoin the companies from continuing the surveillance.
Texas Attorney General Ken Paxton filed a lawsuit against five major TV manufacturers—Sony, Samsung, LG, Hisense, and TCL—for illegally collecting consumers' viewing data through Automated Content Recognition (ACR) technology without knowledge or consent. The companies capture screenshots and monitor TV usage in real-time, then sell the data for targeted advertising, risking sensitive information. The suit seeks to halt these invasive practices and protect Texans' privacy.
OCAT, LLC dba Evoke Wellness at Hilliard (Healthcare Provider, OH) reported a HIPAA breach affecting 1,629 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Heart of Texas Behavioral Health Network (Healthcare Provider, TX) reported a HIPAA breach affecting 1,309 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
ConvenientMD LLC (Healthcare Provider, NH) reported a HIPAA breach affecting 1,332 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Florida Attorney General James Uthmeier issued an investigative subpoena to TP-Link Systems Inc. as part of a consumer protection investigation into the company’s cybersecurity practices, supply-chain infrastructure, and handling of U.S. consumer data, including allegations of unauthorized data sharing with the Chinese Communist Party. The probe will determine if TP-Link misled customers about foreign government access to their personal data, which would violate the Florida Deceptive and Unfair Trade Practices Act, with no findings of wrongdoing yet.
California Attorney General Rob Bonta co-led a coalition of 18 attorneys general in submitting a comment letter opposing the Department of Homeland Security's expansion of the Systematic Alien Verification for Entitlements (SAVE) program to include U.S.-born citizens. The coalition argues the expansion violates the Privacy Act of 1974, creates a massive surveillance database, increases data breach risks, and will lead to inaccurate verifications and denial of benefits.
Henry Ford Health (Healthcare Provider, MI) reported a HIPAA breach affecting 1,984 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Desktop Computer.
Connecticut Attorney General William Tong joined a bipartisan coalition of nine states in a $7 million settlement with Greystar Management Services LLC, the largest U.S. landlord, for anticompetitive algorithmic pricing practices. Greystar shared competitively sensitive data with competitors via RealPage's algorithms and discussed pricing strategies, leading to inflated rents. The consent decree prohibits such conduct, requires monitoring if using uncertified algorithms, and bars participation in RealPage competitor meetings.
$7.0M
Marrs Ear, Nose & Throat, PA (Healthcare Provider, FL) reported a HIPAA breach affecting 6,376 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
West Suburban Eye Surgery Center LLC (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Incyte Pathology, P.S. (Healthcare Provider, WA) reported a HIPAA breach affecting 629 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Better Vision Eyecare, LLC (Healthcare Provider, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Legacy Health, LLC (Business Associate, TX) reported a HIPAA breach affecting 6,547 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Express Canna Cards, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
New York Attorney General Letitia James settled with public accounting firm Wojeski & Company over two data breaches in 2023 and 2024 that exposed personal information of over 4,700 New York residents, including social security numbers and medical benefits. The firm failed to implement adequate data security measures, did not encrypt sensitive data, and delayed notifying affected consumers of the breaches for over a year. Wojeski must pay $60,000 in penalties and implement enhanced cybersecurity measures including encryption, incident response plans, and employee training.
$60K
Florida Attorney General James Uthmeier filed a civil enforcement action against Roku, Inc. for violating the Florida Digital Bill of Rights (FDBOR) and Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The complaint alleges Roku collected, sold, and enabled reidentification of children’s sensitive personal data, including viewing habits and voice recordings, without parental consent or meaningful notice to consumers. The state seeks civil penalties, injunctive relief, and requirements for Roku to implement transparent disclosures, lawful parental controls, and cease unauthorized processing of children’s data.
The Texas Attorney General opened an investigation into TP-Link Systems Inc. for potentially allowing the Chinese government to access Texans' consumer data through back doors in networking equipment. The investigation will examine whether TP Link violated Texas privacy law by misleading consumers about its independence and improperly collecting or disclosing data. This follows a prior privacy notice violation issued to the company.
Harris County Hospital District d/b/a Harris Health (Healthcare Provider, TX) reported a HIPAA breach affecting 5,357 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
California Attorney General Rob Bonta filed a lawsuit against the City of El Cajon for unlawfully sharing Automated License Plate Reader (ALPR) data with over 100 out-of-state law enforcement agencies, violating state law that restricts such data to California public agencies. The AG is seeking a court order to halt the sharing and compel compliance with state privacy protections.
Florida Health Sciences Center, Inc (Healthcare Provider, FL) reported a HIPAA breach affecting 896 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
Arizona Health Care Cost Containment System- State Medicaid Agency (Health Plan, AZ) reported a HIPAA breach affecting 3,177 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Weekend Health, LLC (Business Associate, NY) reported a HIPAA breach affecting 1,643 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
The California Privacy Protection Agency (CPPA) settled with Tractor Supply Company for $1.35 million over violations of the California Consumer Privacy Act (CCPA). The violations included failing to maintain a proper privacy policy, not notifying job applicants of their rights, lacking an effective opt-out mechanism, and sharing personal information without adequate contracts. Tractor Supply must pay the fine and implement remedial measures such as scanning digital properties and annual compliance certification.
$1.4M
Blue Shield of California (Business Associate, CA) reported a HIPAA breach affecting 607 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
Gainwell Technologies LLC (Business Associate, TX) reported a HIPAA breach affecting 912 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
VIVA Health (Health Plan, AL) reported a HIPAA breach affecting 4,945 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
A coalition of 21 state attorneys general led by New York Attorney General Letitia James obtained a temporary restraining order from the District Court for the Northern District of California blocking the USDA from demanding personally identifiable information of all SNAP recipients, including Social Security numbers, home addresses, and immigration statuses. The lawsuit argued that the USDA’s demand violated federal and state laws prohibiting disclosure of SNAP data except in narrow circumstances, and that the data would be used for immigration enforcement against recipients. The order also prohibits the USDA from withholding SNAP funding from plaintiff states that refuse to comply with the data demand.
New York Attorney General Letitia James and a coalition of 20 other states sued the U.S. Department of Agriculture to stop its demand for personal information of SNAP recipients for immigration enforcement. The District Court issued a temporary restraining order blocking USDA's demand and preventing funding cuts, citing violations of laws protecting SNAP data confidentiality.
Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) (Healthcare Provider, FL) reported a HIPAA breach affecting 13,230 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.