Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
TXInvestigation

American Academy of Pediatrics

Texas Attorney General Ken Paxton launched an investigation into the American Academy of Pediatrics (AAP) over concerns that the organization may be promoting and recommending childhood vaccines for financial gain. The AAP has been issued a Civil Investigative Demand to determine the basis of its vaccine recommendations and whether they are influenced by financial incentives from pharmaceutical donors.

LowNotice Failure
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
MNInvestigation

Allina Health

The Minnesota Attorney General is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review is conducted under Minnesota's health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest. No enforcement action has been taken; this is a public consultation.

Low
MNSettlement

Omega Dental Care

Minnesota Attorney General Keith Ellison reached a settlement with Annelle Soberay and Omega Dental Care, a defunct dental clinic that shut down in late 2024 without providing advance notice or transitional care to patients. The settlement allows consumers to obtain refunds from the Consumer Protection Restitution Account for fees paid for services that were never provided.

LowNotice FailureConsent Failure
NJAdministrative Order

Woodbury Family Pharmacy

The New Jersey State Board of Pharmacy temporarily suspended the license of pharmacist Nittal K. Lodha and the permit of Woodbury Family Pharmacy for allegedly practicing unsafely, maintaining unsanitary conditions, and interfering with patients' rights to transfer prescriptions to other pharmacies. The suspension was ratified on June 24, 2026.

LowHealth Data
FTCEnforcement ActionMultistate

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

LowConsent FailureNotice FailureChildren's Data
MNInvestigation

Allina Health

The Minnesota Attorney General's Office is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review will assess compliance with state health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest.

Low
FTCEnforcement Action

Amare Global Holdings Inc.

The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.

LowConsent FailureHealth DataChildren's Data
VACoalitionMultistate

Virginia Attorney General Jay Jones joined a bipartisan coalition of 44 state attorneys general in submitting a comment letter supporting a proposed U.S. Department of Labor rule to increase transparency requirements for pharmacy benefit managers (PBMs) servicing employer-funded ERISA health plans. The coalition urged the DOL to clarify that the proposed rule does not preempt existing state PBM transparency laws and to coordinate enforcement with state attorneys general. This action is a policy advocacy comment letter and does not constitute an enforcement action against any specific entity.

Low
HHSEnforcement Action

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

The Center for Advanced Eye Care

The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Option Care Health, Inc.

Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CTGuidance

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

LowData BreachBiometric Data
HHSEnforcement Action

VNS Behavioral Health Inc. (“VNS Health”)

VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

44North

44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Easterseals Northeast Indiana

Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wee Care Pediatrics, LLC

Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cedar Valley Services

Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Resource Corporation of America

Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

VPS Medical PLLC

VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

University Spine Center

University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alexes Hazen MD, PLLC

Alexes Hazen MD, PLLC (Healthcare Provider, NY) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email, Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

First Choice Community Home Care, Inc.

First Choice Community Home Care, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 725 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

BlueCross BlueShield of Tennessee, Inc.

BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 1,670 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Five Star Home Health, Inc.

Five Star Home Health, Inc. (Healthcare Provider, OK) reported a HIPAA breach affecting 1,575 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Houston Health Department

Houston Health Department (Healthcare Provider, TX) reported a HIPAA breach affecting 7,445 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Carolina Foot & Ankle Associates

Carolina Foot & Ankle Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data