Court Rules

Privacy Enforcement Tracker

1,338 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,338

Total Actions

14

Jurisdictions

$50.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

The Center at Cordera

The Center at Cordera (Healthcare Provider, CO) reported a HIPAA breach affecting 6,057 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAFine

Accurate Append, Inc.(Accurate Append)

The California Privacy Protection Agency (CPPA) ordered Accurate Append, Inc. to pay a $55,400 fine for failing to register as a data broker under the Delete Act by the January 31, 2024 deadline. The company registered only after being contacted during an enforcement sweep and agreed to injunctive terms, including paying attorney fees for future non-compliance.

LowData Broker Non-Compliance

$55K

HHSEnforcement Action

Compass Counseling Services, LLC

Compass Counseling Services, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,440 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NJWarning Letter

auto dealerships(Auto Dealerships)

The New Jersey Division of Consumer Affairs sent warning letters to over 3,000 auto dealerships reminding them of the state's data deletion law, which requires dealerships to offer to delete personal data from vehicles when accepting them for resale or lease. Failure to comply can result in fines of $500 for first offenses and $1,000 for subsequent offenses, aimed at preventing unauthorized access to sensitive consumer information stored in vehicle infotainment systems.

LowSecurity Failure
HHSEnforcement Action

Doctors’ Memorial Hospital

Doctors’ Memorial Hospital (Healthcare Provider, FL) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Nova Recovery Center, LLC d/b/a Nova Recovery Center

Nova Recovery Center, LLC d/b/a Nova Recovery Center (Healthcare Provider, TX) reported a HIPAA breach affecting 6,242 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Blue Shield of California

Blue Shield of California (Health Plan, CA) reported a HIPAA breach affecting 783 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Laptop, Network Server, Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Kettering Adventist Healthcare

Kettering Adventist Healthcare (Healthcare Provider, OH) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

OrthoAtlanta LLC

OrthoAtlanta LLC (Business Associate, GA) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Equilibria Mental Health Services

Equilibria Mental Health Services (Healthcare Provider, PA) reported a HIPAA breach affecting 3,232 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Brien Center for Mental Health and Substance Abuse Services

The Brien Center for Mental Health and Substance Abuse Services (Healthcare Provider, MA) reported a HIPAA breach affecting 5,427 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Human Development Services of Westchester

Human Development Services of Westchester (Healthcare Provider, NY) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Oregon Specialty Group

Oregon Specialty Group (Healthcare Provider, OR) reported a HIPAA breach affecting 3,337 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTSettlement

Capulet Entertainment

Connecticut Attorney General settled with Capulet Entertainment over the failed Capulet Fest 2024, which was abruptly relocated and partially cancelled, leaving ticketholders without refunds. The settlement provides up to $50,000 in consumer refunds and imposes future requirements including performance bonds and contractor commitments.

Low
HHSEnforcement Action

Mid South Rehab Services Inc.

Mid South Rehab Services Inc. (Healthcare Provider, MS) reported a HIPAA breach affecting 1,316 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC)

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC) (Healthcare Provider, VA) reported a HIPAA breach affecting 2,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Regency Oaks

Regency Oaks (Healthcare Provider, FL) reported a HIPAA breach affecting 2,008 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Square of Seminole

Freedom Square of Seminole (Healthcare Provider, FL) reported a HIPAA breach affecting 3,473 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Picis Clinical Solutions, Inc. d/b/a Medstreaming

Picis Clinical Solutions, Inc. d/b/a Medstreaming (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Plaza Senior Living

Freedom Plaza Senior Living (Healthcare Provider, FL) reported a HIPAA breach affecting 4,847 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Covenant Health

Covenant Health (Business Associate, MA) reported a HIPAA breach affecting 7,864 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FLInvestigation

Robinhood Crypto, LLC.(Robinhood)

Florida Attorney General James Uthmeier launched an investigation into Robinhood Crypto, LLC for allegedly deceptive practices regarding trading costs. The AG issued a subpoena seeking internal documents to determine if Robinhood violated Florida's Deceptive and Unfair Practices Act by falsely claiming to offer the lowest crypto trading costs. Robinhood must respond by July 31, 2025.

Low
HHSEnforcement Action

Mountain Laurel Dermatology

Mountain Laurel Dermatology (Healthcare Provider, NC) reported a HIPAA breach affecting 3,324 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Naper Grove Vision Care

Naper Grove Vision Care (Healthcare Provider, IL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre (Healthcare Provider, GA) reported a HIPAA breach affecting 1,714 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTSettlement

TicketNetwork, Inc.(TicketNetwork)

Connecticut Attorney General William Tong announced a settlement with TicketNetwork, Inc. for violating the Connecticut Data Privacy Act by maintaining an unreadable privacy notice and non-functional consumer rights mechanisms. TicketNetwork agreed to comply with CTDPA requirements, maintain metrics for consumer rights requests, report to the AG, and pay $85,000.

LowNotice FailureOpt-Out Failure

$85K

HHSEnforcement Action

Complete Care Rehab LLC

Complete Care Rehab LLC (Healthcare Provider, MI) reported a HIPAA breach affecting 4,764 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

K&E Advanced Dentisrty

K&E Advanced Dentisrty (Healthcare Provider, OH) reported a HIPAA breach affecting 1,700 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

City of Franklin

City of Franklin (Healthcare Provider, WI) reported a HIPAA breach affecting 3,233 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Urology Associates of Charleston

Urology Associates of Charleston (Healthcare Provider, SC) reported a HIPAA breach affecting 2,060 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data