1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Five Star Home Health, Inc. (Healthcare Provider, OK) reported a HIPAA breach affecting 1,575 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Houston Health Department (Healthcare Provider, TX) reported a HIPAA breach affecting 7,445 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The FTC issued warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA), which bans the sale or disclosure of sensitive personal data to foreign adversaries like China, Russia, Iran, and North Korea. The letters cite instances where recipients offered data on Armed Forces members, which is protected under PADFAA. Non-compliance could result in civil penalties up to $53,088 per violation.
Carolina Foot & Ankle Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Connecticut Attorney General William Tong announced a civil investigative demand into Concierge Apartments management for alleged mismanagement leading to unsafe living conditions, including loss of hot water, ignored work orders, and evacuation orders. The investigation seeks records on tenant complaints, repairs, and documentation of $2 million in repairs promised. The property owner, J.R.K Property Holdings, is a private equity-backed real estate firm with $15 billion in assets.
Adapt Integrated Health Care (Healthcare Provider, OR) reported a HIPAA breach affecting 2,908 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Federal Trade Commission (FTC) sent warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans’ Data from Foreign Adversaries Act (PADFAA). PADFAA prohibits data brokers from selling or providing sensitive personal data about Americans to foreign adversaries such as China, Russia, Iran, and North Korea. The letters warn that violations could result in civil penalties of up to $53,088 per violation and urge companies to review their business practices for compliance.
Marin Cancer Care (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
EDGAR A MARTORELL MD LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 1,107 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Cottage Hospital (Healthcare Provider, NH) reported a HIPAA breach affecting 1,005 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Apex Spine & Neurosurgery, LLC (Healthcare Provider, GA) reported a HIPAA breach affecting 2,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Florida Attorney General's Office launched the CHINA Prevention Unit and issued a subpoena to Shein for deceptive trade practices and data privacy violations. The unit focuses on combating threats from foreign adversaries like the Chinese Communist Party to consumer data and economic security. This action is part of broader efforts to audit and hold accountable companies with ties to China.
Issaqueena Pediatric Dentistry PA (Healthcare Provider, SC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Personalis, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 650 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Antitrust enforcement action where the FTC settled with Express Scripts, a major pharmacy benefit manager, for using anticompetitive rebating practices that artificially inflated insulin prices. The settlement requires ESI to change its business practices to increase transparency and lower patient out-of-pocket costs, potentially saving $7 billion over 10 years.
New Jersey Acting Attorney General Jennifer Davenport, alongside 42 states and territories, filed a multistate complaint against Novartis AG and its subsidiaries Sandoz AG and Sandoz Group AG alleging a conspiracy to fix prices, allocate markets, and rig bids for 31 generic drugs, inflating costs for consumers and public healthcare programs. The complaint also alleges Novartis fraudulently spun off Sandoz to shield itself from liability for prior antitrust violations. This action builds on evidence from three previous multistate generic drug price-fixing complaints.
The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.
Pafford Medical Services (Healthcare Provider, AR) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Mindoula Health, Inc. (Business Associate, MD) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Lincoln National Corporation d/b/a/ Lincoln Financial (Health Plan, IN) reported a HIPAA breach affecting 998 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
Senator Josh Becker introduced SB 923, the Expanding Privacy Rights Act, sponsored by CalPrivacy. The bill would expand the CCPA right to delete to include personal information obtained from third-party sources, and require businesses to provide multiple methods (e.g., webform) for submitting privacy requests.
Health and Hospital Corporation of Marion County (Healthcare Provider, IN) reported a HIPAA breach affecting 792 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email, Laptop.
BAYADA Home Health Care, Inc. (Healthcare Provider, NJ) reported a HIPAA breach affecting 9,526 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Connecticut Attorney General and Consumer Counsel secured a settlement requiring Charter Communications to adhere to consumer protection commitments as it acquires Cox Communications. The agreement, pending PURA approval, includes pricing transparency, service reliability improvements, a $3 million digital access investment, and compliance with the Connecticut Data Privacy Act. It also maintains a Connecticut workforce and office, and prevents cost pass-through to customers.
The Connecticut Attorney General and Consumer Counsel announced a settlement with Charter Communications regarding its proposed acquisition of Cox Communications. The settlement includes consumer protections such as billing transparency, service reliability improvements, a $3 million digital access investment, and other commitments. It is pending approval by the Public Utilities Regulatory Authority.
California Attorney General Rob Bonta announced an investigative sweep targeting businesses that use surveillance pricing, which involves setting individualized prices based on consumer data. The Department of Justice is sending information request letters to companies in the retail, grocery, and hotel sectors to assess compliance with the CCPA's purpose limitation principle. This action seeks to ensure that consumers are not charged different prices without proper disclosure and that businesses adhere to privacy laws.
WindRose Health Network (Healthcare Provider, IN) reported a HIPAA breach affecting 691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
A bipartisan coalition of 35 state attorneys general led by New York Attorney General Letitia James sent a demand letter to xAI on January 26, 2026, requiring the company to address its Grok chatbot’s creation and sharing of nonconsensual intimate images, including child sexual abuse material. The AGs demand that xAI implement safeguards to prevent Grok from generating such content, delete existing harmful content, suspend offending users, and give X users control over whether their content can be edited by Grok. No monetary penalty has been imposed as this is a pre-enforcement demand for action.
The California Privacy Protection Agency (CalPrivacy) announced the launch of the Delete Request and Opt-out Platform (DROP) during Data Privacy Week. DROP allows Californians to submit a single request to delete their personal information from over 500 registered data brokers, as required by the Delete Act. The platform is free and has already seen over 176,000 sign-ups since January 1, 2026.
New Jersey Acting Attorney General Jennifer Davenport and the Division of Consumer Affairs issued general guidance warning sellers against engaging in price gouging during a declared state of emergency ahead of a major winter storm. The guidance cites New Jersey’s price gouging law, which prohibits price increases exceeding 10% of pre-emergency prices for necessary goods and services during the emergency and 30 days after its termination. Violations carry civil penalties up to $10,000 for first offenses and $20,000 for subsequent offenses, with each individual sale counted as a separate violation.
All data sourced from official government enforcement pages.