Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

REACH, Inc

REACH, Inc (Healthcare Provider, AK) reported a HIPAA breach affecting 1,195 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

VirMedice, LLC

VirMedice, LLC (Business Associate, AZ) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Physicians to Children & Adolescents

Physicians to Children & Adolescents (Healthcare Provider, KY) reported a HIPAA breach affecting 9,536 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Southwest Urology

Southwest Urology (Healthcare Provider, OH) reported a HIPAA breach affecting 1,310 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Fairbanks Urology

Fairbanks Urology (Healthcare Provider, AK) reported a HIPAA breach affecting 1,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Saint Mary’s Home of Erie

Saint Mary’s Home of Erie (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Michael R. Schwartz, MD Inc.

Michael R. Schwartz, MD Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 9,080 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
CTSettlementMultistate

TFG Holding, Inc.(TFG Holding)

Connecticut Attorney General secured a $1 million multistate settlement with TFG Holding, Inc. for deceptive VIP membership program marketing and billing practices. The company must improve disclosures, obtain explicit consent, provide easy cancellation, and offer restitution to affected consumers.

HighConsent FailureOpt-Out FailureNotice Failure

$1.0M

HHSEnforcement Action

Legacy Health, LLC

Legacy Health, LLC (Business Associate, TX) reported a HIPAA breach affecting 6,547 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Express Canna Cards, LLC

Express Canna Cards, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
NYSettlement

Wojeski & Company

New York Attorney General Letitia James settled with public accounting firm Wojeski & Company over two data breaches in 2023 and 2024 that exposed personal information of over 4,700 New York residents, including social security numbers and medical benefits. The firm failed to implement adequate data security measures, did not encrypt sensitive data, and delayed notifying affected consumers of the breaches for over a year. Wojeski must pay $60,000 in penalties and implement enhanced cybersecurity measures including encryption, incident response plans, and employee training.

LowData BreachSecurity FailureBreach Notification Delay

$60K

HHSEnforcement Action

North Atlantic States Carpenters Health Benefits Fund

North Atlantic States Carpenters Health Benefits Fund (Health Plan, MA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Modernizing Medicine, Inc.

Modernizing Medicine, Inc. (Business Associate, FL) reported a HIPAA breach affecting 198,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Heartland Health Center

Heartland Health Center (Healthcare Provider, NE) reported a HIPAA breach affecting 43,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

River City Eye Care, LLC

River City Eye Care, LLC (Healthcare Provider, OR) reported a HIPAA breach affecting 6,588 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Coalesce, LLC dba Benefitelect

Coalesce, LLC dba Benefitelect (Business Associate, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

U.S. Department of Education(Department of Education)

Connecticut Attorney General William Tong joined 18 other attorneys general in filing a comment letter opposing a U.S. Department of Education proposal to expand data collection on race, admissions, and student performance from colleges and universities. The coalition argues the proposal is unreasonably burdensome, unlikely to yield quality data, and could be misused to target lawful diversity, equity, and inclusion initiatives, raising student privacy concerns.

LowStudent Data
CAGuidanceMultistate

U.S. Department of Education

California Attorney General Rob Bonta led a coalition of 18 attorneys general in submitting a comment letter opposing the U.S. Department of Education's proposal to collect extensive student data on race, admissions, and financial aid. The coalition argues the data collection is burdensome, unlikely to yield quality data, and may be misused to target lawful diversity, equity, and inclusion efforts.

LowStudent Data
NYSettlement

American Family Mutual Insurance Company/Midvale Indemnity Company; Farmers Insurance; Hagerty Insurance Agency; The Hartford Insurance Group; Infinity Insurance Company; Liberty Mutual Insurance; Metromile; State Auto Mutual Insurance Company

New York Attorney General Letitia James secured $14.2 million in settlements from eight car insurance companies for failing to implement reasonable data security controls, leading to data breaches that exposed over 825,000 New Yorkers' personal information including driver's license numbers and dates of birth. Hackers exploited vulnerabilities in the companies' online quoting tools to steal the data, which was later used to file fraudulent unemployment claims during the COVID-19 pandemic. The settlements require the companies to pay penalties and implement enhanced cybersecurity measures including data inventory maintenance, multifactor authentication, and improved threat response procedures.

CriticalData BreachSecurity Failure

$14.2M

FLEnforcement Action

Roku, Inc.(Roku)

Florida Attorney General James Uthmeier filed a civil enforcement action against Roku, Inc. for violating the Florida Digital Bill of Rights (FDBOR) and Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The complaint alleges Roku collected, sold, and enabled reidentification of children’s sensitive personal data, including viewing habits and voice recordings, without parental consent or meaningful notice to consumers. The state seeks civil penalties, injunctive relief, and requirements for Roku to implement transparent disclosures, lawful parental controls, and cease unauthorized processing of children’s data.

LowChildren's DataConsent FailureUnauthorized Data Sharing
NYSettlement

American Family Mutual Insurance Company/Midvale Indemnity Company, Farmers Insurance, Hagerty Insurance Agency, The Hartford Insurance Group, Infinity Insurance Company, Liberty Mutual Insurance, Metromile, State Auto Mutual Insurance Company(American Family)

New York Attorney General Letitia James secured $14.2 million in settlements from eight car insurance companies for failing to protect consumers' personal information. The companies' inadequate cybersecurity allowed hackers to steal driver's license numbers and other data through online quoting tools, impacting over 825,000 New Yorkers. The settlements require the companies to pay penalties and implement enhanced data security measures.

CriticalSecurity FailureData Breach

$14.2M

HHSEnforcement Action

Visiting Nurse Association of Texas, LLC

Visiting Nurse Association of Texas, LLC (Healthcare Provider, TX) reported a HIPAA breach affecting 28,515 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
TXSettlement

Austin Diagnostic Clinic

Texas Attorney General Ken Paxton secured a settlement agreement with Austin Diagnostic Clinic to end its policy of restricting parental access to children’s electronic health records. The agreement requires the clinic to provide parents with full, real-time access to their children’s medical information except where restricted by state or federal law, and the AG will monitor compliance.

LowChildren's DataHealth Data
HHSEnforcement Action

Conduent Business Services LLC

Conduent Business Services LLC (Business Associate, NJ) reported a HIPAA breach affecting 42,616 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wellpoint, Inc.

Wellpoint, Inc. (Business Associate, IN) reported a HIPAA breach affecting 579 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

OB-GYN Associates, Ltd. dba OBGYN Associates

OB-GYN Associates, Ltd. dba OBGYN Associates (Healthcare Provider, NV) reported a HIPAA breach affecting 62,238 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cardiovascular Medicine Associates (doing business as MyCardiologist)

Cardiovascular Medicine Associates (doing business as MyCardiologist) (Healthcare Provider, FL) reported a HIPAA breach affecting 2,248 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Space Coast Vascular

Space Coast Vascular (Healthcare Provider, FL) reported a HIPAA breach affecting 18,819 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
TXInvestigation

TP-Link Systems Inc.(TP-Link)

The Texas Attorney General opened an investigation into TP-Link Systems Inc. for potentially allowing the Chinese government to access Texans' consumer data through back doors in networking equipment. The investigation will examine whether TP Link violated Texas privacy law by misleading consumers about its independence and improperly collecting or disclosing data. This follows a prior privacy notice violation issued to the company.

LowUnauthorized Data SharingNotice FailureSecurity Failure
HHSEnforcement Action

Sierra Vista Hospital & Clinics

Sierra Vista Hospital & Clinics (Healthcare Provider, NM) reported a HIPAA breach affecting 75,054 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data