Court Rules

Privacy Enforcement Tracker

1,338 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,338

Total Actions

14

Jurisdictions

$50.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
TXInvestigation

Meta Platforms, Inc. and Character Technologies, Inc.

Texas Attorney General Ken Paxton opened an investigation into Meta and Character.AI via Civil Investigative Demands, alleging deceptive trade practices including misrepresenting AI chatbots as confidential mental health tools while harvesting user data for targeted advertising. The probe assesses potential violations of Texas consumer protection laws and the SCOPE Act, particularly regarding privacy misrepresentations, concealment of data usage, and harms to children. This builds on prior investigations into Character.AI for SCOPE Act compliance.

LowChildren's DataNotice FailureConsent Failure
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong is seeking a preliminary injunction to block the U.S. Department of Agriculture from forcing states to share private data of SNAP participants, including social security numbers and shopping history. USDA is threatening to cut off administrative funding if states do not comply, which AG Tong argues violates federal privacy laws and the Constitution.

LowUnauthorized Data Sharing
HHSEnforcement Action

Bevel Health Medical Group

Bevel Health Medical Group (Healthcare Provider, PA) reported a HIPAA breach affecting 510 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
TXInvestigation

Meta AI Studio and Character.AI(Meta and Character.AI)

Texas Attorney General Ken Paxton has opened an investigation into Meta AI Studio and Character.AI for deceptive practices in marketing AI chatbots as mental health services to children. The platforms are accused of impersonating licensed professionals, fabricating qualifications, and exploiting user data for advertising without proper disclosure. Civil Investigative Demands have been issued to examine violations of Texas consumer protection laws and the SCOPE Act.

LowChildren's DataUnauthorized Data SharingNotice Failure
HHSEnforcement Action

Lake City Cancer Care, LLC

Lake City Cancer Care, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 9,980 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Anaheim

Welcome Dentistry-Anaheim (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mower County Health and Human Services

Mower County Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Los Angeles

Welcome Dentistry-Los Angeles (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

UnitedHealthcare

UnitedHealthcare (Health Plan, CT) reported a HIPAA breach affecting 3,215 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Laurel Cancer Care, LLC

Laurel Cancer Care, LLC (Healthcare Provider, MS) reported a HIPAA breach affecting 1,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Zelis Healthcare LLC

Zelis Healthcare LLC (Business Associate, MA) reported a HIPAA breach affecting 4,289 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Dr. Doug's Pediatric Dentistry

Dr. Doug's Pediatric Dentistry (Healthcare Provider, UT) reported a HIPAA breach affecting 3,590 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Altos Inc

Altos Inc (Business Associate, CA) reported a HIPAA breach affecting 1,634 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

PROVAIL

PROVAIL (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Friesen Group

Friesen Group (Healthcare Provider, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Center for Disability Services, Inc.

Center for Disability Services, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 3,343 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CPPAEnforcement Action

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) filed a petition in Superior Court to enforce a subpoena against Tractor Supply Company for alleged CCPA violations, including failure to honor consumers' right to opt-out of the sale and sharing of personal information. This is the CPPA's first judicial action to enforce an investigative subpoena, and the agency is seeking court assistance to compel the company's compliance.

LowOpt-Out Failure
HHSEnforcement Action

South Coast Pediatrics

South Coast Pediatrics (Healthcare Provider, CA) reported a HIPAA breach affecting 7,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Precision Edodontics of Raleigh

Precision Edodontics of Raleigh (Healthcare Provider, NC) reported a HIPAA breach affecting 4,022 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
FLEnforcement Action

WebGroup Czech Republic, a.s.; NKL Associates, s.r.o.; Sonesta Technologies, s.r.o.; Sonesta Media, s.r.o.; Sonesta Technologies, Inc.; GGW Group, s.r.o.; GTFlix TV, s.r.o.; GGW Group, LLC; Traffic F, s.r.o.(WebGroup Czech Republic, NKL Associates, Sonesta Technologies, Sonesta Media, GGW Group, GTFlix TV, Traffic F)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3, which requires age verification to prevent minors from accessing harmful content. The companies, including XVideos.com and XNXX.com, have failed to implement age verification since the law took effect on January 1, 2025. The lawsuit seeks to enforce HB 3 and the Florida Deceptive and Unfair Trade Practices Act to protect children from exposure to explicit material.

LowChildren's Data
FLEnforcement Action

Webgroup Czech Republic, NKL Associates, Sonesta Technologies, Inc., GGW Group, Traffic F(WebGroup Czech Republic)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3 by not implementing age verification to prevent minors from accessing harmful content. The companies have ignored prior warnings and are accused of unfair business practices. The suit seeks to compel compliance with state law.

LowChildren's Data
HHSEnforcement Action

Genoa Community Hospital/LTC

Genoa Community Hospital/LTC (Healthcare Provider, NE) reported a HIPAA breach affecting 2,544 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Western Montana Clinic PC

Western Montana Clinic PC (Healthcare Provider, MT) reported a HIPAA breach affecting 8,255 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Central Maine Healthcare

Central Maine Healthcare (Healthcare Provider, ME) reported a HIPAA breach affecting 7,223 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Vail Summit Orthopaedics

Vail Summit Orthopaedics (Healthcare Provider, CO) reported a HIPAA breach affecting 5,044 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

David A. Nover, M.D., P.C.

David A. Nover, M.D., P.C. (Healthcare Provider, PA) reported a HIPAA breach affecting 4,703 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Berkshire Health Systems, Inc.

Berkshire Health Systems, Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 1,421 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong, leading a coalition of 22 states, filed a lawsuit against the U.S. Department of Agriculture for demanding that states disclose sensitive personal data of SNAP recipients. The demand violates federal privacy laws and the Constitution, and threatens to withhold critical funding. The lawsuit seeks to block USDA from conditioning SNAP administrative funds on data disclosure.

LowUnauthorized Data Sharing
HHSEnforcement Action

University of Miami

University of Miami (Healthcare Provider, FL) reported a HIPAA breach affecting 2,928 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

PhyNet Dermatology, LLC

PhyNet Dermatology, LLC (Business Associate, TN) reported a HIPAA breach affecting 1,308 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data