Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTCoalitionMultistate

U.S. Department of Health and Human Services (HHS)

Connecticut Attorney General William Tong joined a coalition of 22 attorneys general and Pennsylvania’s governor in a letter urging HHS to keep federal vaccine recommendations grounded in scientific and medical evidence. The letter asks HHS to preserve the ACIP’s role and current vaccine recommendation categories; it is a policy advocacy action, not a privacy enforcement action.

Low
CTSettlementMultistate

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

Connecticut and a coalition of 47 other states and territories announced preliminary court approval of a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to inflate drug prices. The release does not give the date of the court’s preliminary approval, so the event date reflects the press release date.

Low
MNSettlement

Omega Dental Care

Minnesota Attorney General Keith Ellison announced the first round of restitution, issuing 8 refund checks totaling $38,634 to consumers harmed by Omega Dental Care, a defunct Eden Prairie dental clinic owned and operated by Anne Soberay. The refunds, paid from the state's Consumer Protection Restitution Account (CPRA), compensate consumers who paid out of pocket for dental services that were never provided. The refunds follow an earlier settlement between the AG's office and Omega Dental Care and Soberay. Note: this is a consumer protection (non-delivery of services) action, not a privacy enforcement action; no privacy violation types from the taxonomy apply.

Low
MNConsent Decree

Sanford Health and North Memorial Health

The Minnesota Attorney General entered into a 10-year oversight agreement with Sanford Health and North Memorial Health to allow their merger to proceed, conditioned on commitments to invest $600 million in Minnesota hospitals, maintain core services including the Level 1 trauma center at Robbinsdale Hospital, honor collective-bargaining agreements, and maintain charity care and government program participation. The agreement also requires quarterly meetings and annual reporting to the Attorney General for 10 years.

Low
COEnforcement ActionMultistate

U.S. Department of Health and Human Services

Attorney General Weiser joined a coalition of attorneys general in suing to block new unlawful conditions on Title X funding imposed by HHS, which would penalize states and providers that refuse to abandon nondiscrimination initiatives or conform to the administration's ideological vision of family planning. The lawsuit argues the conditions conflict with federal law, violate the Administrative Procedure Act, and are unconstitutionally vague.

Low
CTEnforcement Action

Anthem, ConnectiCare, and UnitedHealthcare

Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.

Low
TXInvestigation

American Academy of Pediatrics

Texas Attorney General Ken Paxton launched an investigation into the American Academy of Pediatrics (AAP) over concerns that the organization may be promoting and recommending childhood vaccines for financial gain. The AAP has been issued a Civil Investigative Demand to determine the basis of its vaccine recommendations and whether they are influenced by financial incentives from pharmaceutical donors.

LowNotice Failure
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
MNInvestigation

Allina Health

The Minnesota Attorney General is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review is conducted under Minnesota's health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest. No enforcement action has been taken; this is a public consultation.

Low
MNSettlement

Omega Dental Care

Minnesota Attorney General Keith Ellison reached a settlement with Annelle Soberay and Omega Dental Care, a defunct dental clinic that shut down in late 2024 without providing advance notice or transitional care to patients. The settlement allows consumers to obtain refunds from the Consumer Protection Restitution Account for fees paid for services that were never provided.

LowNotice FailureConsent Failure
NJAdministrative Order

Woodbury Family Pharmacy

The New Jersey State Board of Pharmacy temporarily suspended the license of pharmacist Nittal K. Lodha and the permit of Woodbury Family Pharmacy for allegedly practicing unsafely, maintaining unsanitary conditions, and interfering with patients' rights to transfer prescriptions to other pharmacies. The suspension was ratified on June 24, 2026.

LowHealth Data
FTCEnforcement ActionMultistate

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

LowConsent FailureNotice FailureChildren's Data
MNInvestigation

Allina Health

The Minnesota Attorney General's Office is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review will assess compliance with state health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest.

Low
FTCEnforcement Action

Amare Global Holdings Inc.

The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.

LowConsent FailureHealth DataChildren's Data
VACoalitionMultistate

Virginia Attorney General Jay Jones joined a bipartisan coalition of 44 state attorneys general in submitting a comment letter supporting a proposed U.S. Department of Labor rule to increase transparency requirements for pharmacy benefit managers (PBMs) servicing employer-funded ERISA health plans. The coalition urged the DOL to clarify that the proposed rule does not preempt existing state PBM transparency laws and to coordinate enforcement with state attorneys general. This action is a policy advocacy comment letter and does not constitute an enforcement action against any specific entity.

Low
HHSEnforcement Action

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

The Center for Advanced Eye Care

The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Option Care Health, Inc.

Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CTGuidance

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

LowData BreachBiometric Data
HHSEnforcement Action

VNS Behavioral Health Inc. (“VNS Health”)

VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

44North

44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Easterseals Northeast Indiana

Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wee Care Pediatrics, LLC

Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cedar Valley Services

Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Resource Corporation of America

Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

VPS Medical PLLC

VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

University Spine Center

University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data