Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTSettlementMultistate

Laboratory Corporation of America

Connecticut Attorney General William Tong led a 44-attorney-general coalition settlement with Laboratory Corporation of America over the 2019 AMCA breach, which potentially exposed personal information of more than 27.5 million people, including 10.2 million Labcorp patients. Labcorp will pay $2,287,455 and implement enhanced vendor-risk management, information-security, and oversight measures.

HighData BreachSecurity FailureHealth Data

$2.3M

CTSettlementMultistate

Abbott Laboratories

Connecticut joined 39 other states and the federal government in a $384 million False Claims Act settlement with Abbott Laboratories over allegations that the company failed to manufacture powder infant formula and nutritional therapy products in compliance with federal and state requirements at its Sturgis, Michigan, and Casa Grande, Arizona facilities. Abbott allegedly manufactured formula in conditions that risked microorganism contamination and failed to disclose contamination test results to the FDA during 2019 and 2022 inspections. The settlement resolves claims that Abbott caused false claims to be submitted to the WIC program and state Medicaid programs between January 1, 2018, and December 31, 2022.

CriticalSecurity FailureNotice FailureRecord Retention

$384.2M

CTSettlementMultistate

Comstar, LLC(Comstar)

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

MediumData BreachSecurity FailureHealth Data

$515K

CTEnforcement Action

Prospect Medical Holdings

Connecticut filed a statement of interest in the bankruptcy of Prospect Medical Holdings, alleging years of mismanagement that harmed patients and led to a ransomware attack compromising the data of 212,369 residents. The state seeks to ensure a responsible transition of hospitals and hold Prospect accountable for its misconduct.

LowData BreachSecurity Failure
CTSettlementMultistate

Enzo Biochem, Inc.(Enzo Biochem)

Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.

HighSecurity FailureHealth Data

$4.5M

Explore Enforcement Data