Court Rules

Privacy Enforcement Tracker

1,447 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,447

Total Actions

16

Jurisdictions

$26.1B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
NYSettlement

Albany ENT & Allergy Services, P.C.(Albany ENT & Allergy Services)

New York Attorney General Letitia James reached a settlement with Albany ENT & Allergy Services (AENT) over two 2023 ransomware attacks that compromised the medical records of over 200,000 New Yorkers. The OAG found AENT failed to maintain reasonable data security safeguards, inadequately oversaw third-party security vendors, and initially failed to disclose all exposed consumer data to the state. AENT will pay $1 million in penalties (with $500,000 suspended pending $2.25 million in security investments) and implement comprehensive data security measures including encryption, multi-factor authentication, and vendor oversight.

MediumData BreachSecurity FailureHealth Data

$1.0M

FTCConsent DecreeMultistate

Easy Healthcare Corporation(Easy Healthcare)

The FTC charged Easy Healthcare Corporation, operator of the Premom fertility app, with deceiving users by sharing their sensitive health data with third parties for advertising without consent and failing to notify breaches as required by the Health Breach Notification Rule. Under a proposed consent decree, the company will pay a $100,000 civil penalty, be barred from sharing health data for advertising, and must implement privacy and security measures.

MediumUnauthorized Data SharingConsent FailureNotice Failure

$100K

NJSettlement

ATA Consulting LLC(Best Medical Transcription)

ATA Consulting LLC, operating as Best Medical Transcription, settled for $200,000 over a 2016 server misconfiguration that publicly exposed health records of up to 1,654 patients. The settlement includes civil penalties and permanently bars the owner from operating a business in New Jersey. The breach violated HIPAA and the New Jersey Consumer Fraud Act due to inadequate security and failure to promptly notify affected individuals.

MediumHealth DataSecurity FailureBreach Notification Delay

$200K

Explore Enforcement Data