Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
ORSettlementMultistate

Abbott Laboratories

Abbott Laboratories agreed to pay more than $384 million — including $977,558 to Oregon — to resolve allegations that it sold powder infant formula and nutritional therapy products made in unsafe manufacturing conditions to Medicaid and food assistance programs such as WIC between January 2018 and December 2022. Investigators found Abbott failed to maintain manufacturing equipment and control water at its Sturgis, Michigan, and Casa Grande, Arizona, facilities, and withheld test results showing contamination during FDA inspections in 2019 and 2022. The settlement was negotiated by the National Association of Medicaid Fraud Control Units on behalf of the federal government and 39 states.

CriticalSecurity FailureNotice Failure

$384.2M

CTSettlementMultistate

Abbott Laboratories

Connecticut joined 39 other states and the federal government in a $384 million False Claims Act settlement with Abbott Laboratories over allegations that the company failed to manufacture powder infant formula and nutritional therapy products in compliance with federal and state requirements at its Sturgis, Michigan, and Casa Grande, Arizona facilities. Abbott allegedly manufactured formula in conditions that risked microorganism contamination and failed to disclose contamination test results to the FDA during 2019 and 2022 inspections. The settlement resolves claims that Abbott caused false claims to be submitted to the WIC program and state Medicaid programs between January 1, 2018, and December 31, 2022.

CriticalSecurity FailureNotice FailureRecord Retention

$384.2M

NYSettlement

Thirty Madison, Inc.

New York Attorney General Letitia James secured $400,000 from Thirty Madison, Inc., an online medication provider, for misleading consumers about auto-renewing subscriptions and making cancellation difficult. The company failed to clearly disclose subscription terms and non-refundable fees, and required multiple steps to cancel. The settlement requires payment, refunds to eligible subscribers, and changes to subscription practices.

MediumNotice FailureConsent FailureDark Patterns

$400K

MNSettlement

Stevens Community Medical Center

Minnesota Attorney General Keith Ellison reached a settlement with Stevens Community Medical Center (SCMC) over allegations that SCMC improperly calculated discounts required for uninsured patients with household incomes under $125,000, violating the Minnesota Hospital Agreement and state law. As a result, some uninsured patients were billed up to 20.5% more than allowed. SCMC must provide up to $1,412,776.25 in refunds or medical-debt reductions to potentially eligible patients.

HighNotice Failure

$1.4M

TXInvestigation

American Academy of Pediatrics

Texas Attorney General Ken Paxton launched an investigation into the American Academy of Pediatrics (AAP) over concerns that the organization may be promoting and recommending childhood vaccines for financial gain. The AAP has been issued a Civil Investigative Demand to determine the basis of its vaccine recommendations and whether they are influenced by financial incentives from pharmaceutical donors.

LowNotice Failure
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
FTCSettlement

Vanilla Chip LLC

The FTC finalized a settlement with Vanilla Chip LLC (doing business as TruHeight) and its principals over allegations that they deceptively advertised height-enhancing supplements for children and teenagers without competent and reliable scientific evidence. The FTC also alleged that TruHeight used fake social media bot profiles and relied on reviews written by employees, vendors, or consumers who received free products or discounts for 5-star reviews. Under the final order, TruHeight must pay $750,000 and is barred from making unsupported health claims or misrepresenting reviews.

MediumNotice Failure

$750K

MNSettlement

Omega Dental Care

Minnesota Attorney General Keith Ellison reached a settlement with Annelle Soberay and Omega Dental Care, a defunct dental clinic that shut down in late 2024 without providing advance notice or transitional care to patients. The settlement allows consumers to obtain refunds from the Consumer Protection Restitution Account for fees paid for services that were never provided.

LowNotice FailureConsent Failure
FTCEnforcement ActionMultistate

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

LowConsent FailureNotice FailureChildren's Data
COSettlementMultistate

GS Labs

Colorado Attorney General Phil Weiser and a bipartisan coalition of 18 attorneys general announced a $4.87 million settlement with GS Labs, a former COVID-19 rapid testing business. The company was found to have violated the Colorado Consumer Protection Act by falsely advertising test results with no wait times, same day appointments, and no out-of-pocket expenses, while overcharging consumers and insurance providers.

HighNotice FailureConsent Failure

$4.9M

MNSettlementMultistate

GS Labs

Attorney General Ellison announced a $4.87 million multistate settlement with GS Labs for overcharging patients, charging unlawful administrative fees, and failing to deliver timely COVID-19 test results. The settlement includes $3.63 million in restitution to affected consumers and $1.25 million to the multistate group, along with injunctive relief if GS Labs resumes operations.

MediumNotice FailureConsent Failure
FLInvestigation

Contec and Epsimed

Florida Attorney General James Uthmeier issued subpoenas to Contec, a Chinese medical device manufacturer, and Epsimed, a Miami-based reseller, over allegations that their patient monitors contain backdoors and automatically transmit patient data to China without consent. The companies are accused of violating Florida's Deceptive and Unfair Trade Practices Act by omitting material security vulnerabilities andmaking false representations about FDA approval and product quality. The AG may seek damages, civil penalties, and injunctive relief in future enforcement.

LowHealth DataUnauthorized Data SharingConsent Failure
NYEnforcement ActionMultistate

23andMe, Inc.(23andMe)

New York Attorney General Letitia James, joined by 27 other state attorneys general and the District of Columbia, filed a lawsuit against 23andMe to block the company’s planned sale of 15 million customers’ genetic and health data without their consent or knowledge. The coalition argues 23andMe must comply with state laws requiring express informed consent for the sale or transfer of sensitive genetic data. The lawsuit seeks to prevent misuse, exposure in future breaches, and unauthorized use of customers’ private genetic information.

LowConsent FailureHealth DataUnauthorized Data Sharing
FTCSettlement

Cerebral, Inc.(Cerebral)

The FTC settled with telehealth firm Cerebral, Inc. for sharing sensitive consumer mental health data with third parties like LinkedIn, Snapchat, and TikTok for advertising without proper consent, employing sloppy security practices, and misleading consumers about cancellation policies. Cerebral must pay over $7 million (with $2 million due upfront), is permanently banned from using health information for most advertising, must implement a comprehensive privacy program, delete unnecessary data, and provide easy cancellation.

HighUnauthorized Data SharingSecurity FailureNotice Failure

$7.0M

FTCConsent Decree

1Health.io(1Health)

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

LowSecurity FailureOpt-Out FailureNotice Failure

$75K

FTCSettlement

1Health.io

The FTC settled with genetic testing company 1Health.io for failing to secure sensitive genetic and health data, deceiving consumers about data deletion, and unfairly changing its privacy policy without notice or consent. The settlement includes refunds totaling over $49,500 to 2,432 affected consumers.

LowSecurity FailureOpt-Out FailureNotice Failure

$50K

CTSettlementMultistate

Easy Healthcare Corporation(Easy Healthcare)

Connecticut, Oregon, and the District of Columbia reached a $100,000 settlement with Easy Healthcare Corporation, the operator of the Premom ovulation tracking app, for sharing sensitive user health and location data with third parties without appropriate disclosures or user consent. The settlement requires the company to implement comprehensive privacy and security programs, obtain consent before sharing health or location data, and provide users with a method to delete their personal information.

MediumUnauthorized Data SharingNotice FailureHealth Data

$100K

FTCConsent DecreeMultistate

Easy Healthcare Corporation(Easy Healthcare)

The FTC charged Easy Healthcare Corporation, operator of the Premom fertility app, with deceiving users by sharing their sensitive health data with third parties for advertising without consent and failing to notify breaches as required by the Health Breach Notification Rule. Under a proposed consent decree, the company will pay a $100,000 civil penalty, be barred from sharing health data for advertising, and must implement privacy and security measures.

MediumUnauthorized Data SharingConsent FailureNotice Failure

$100K

FTCSettlement

GoodRx Holdings Inc.(GoodRx)

The FTC settled with GoodRx for sharing consumers' sensitive prescription and health information with Facebook, Google, and other third parties for advertising without consent, and for failing to report these unauthorized disclosures as required by the Health Breach Notification Rule. GoodRx will pay a $1.5 million civil penalty and is permanently barred from sharing user health data for advertising.

HighConsent FailureHealth DataNotice Failure

$1.5M

CTSettlement

Lively Hearing Corporation, Widex USA, Inc., Hark Wellness, Inc., Wonder Ear, Inc.(Lively Hearing, Widex USA, Hark Wellness, Wonder Ear)

Connecticut Attorney General William Tong announced settlements with four hearing aid companies for marketing their products as 'FDA-approved' when no such approval exists. The companies will collectively pay $40,000 and cease such marketing practices. The investigation underscores that over-the-counter hearing aids are not FDA-approved and consumers should be wary of such claims.

LowNotice Failure

$40K

CTSettlement

L.A. Vision

Connecticut Attorney General William Tong announced a $678,901 settlement with L.A. Vision and optician Lisa Azinheira for overbilling the state Medicaid program. The providers billed for non-medically necessary vision services and extra eyeglasses for children. In addition to restitution, they must comply with a federal Integrity Agreement requiring audits, training, and compliance measures.

MediumConsent FailureNotice Failure

$679K

FTCSettlement

SkyMed International, Inc.(SkyMed)

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

LowSecurity FailureNotice Failure
FTCConsent Decree

Flo Health, Inc.(Flo Health)

The FTC settled with Flo Health, Inc., developer of a popular fertility-tracking app, alleging it misled users by sharing sensitive health data with third-party analytics providers like Facebook and Google after promising to keep such data private. The proposed consent order requires Flo to obtain user consent before sharing health data, notify affected users, and destroy previously shared data, among other requirements.

LowHealth DataUnauthorized Data SharingNotice Failure
FTCSettlement

Ortho-Clinical Diagnostics, Inc.(Ortho-Clinical Diagnostics)

The FTC settled with Ortho-Clinical Diagnostics, Inc. for misleading consumers about its participation in the EU-U.S. Privacy Shield framework. The company allowed its certification to lapse in 2018 but continued to claim participation. The settlement prohibits such misrepresentations and requires compliance with Privacy Shield obligations for data collected or deletion of such data.

LowNotice Failure

Explore Enforcement Data