Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC)

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC) (Healthcare Provider, VA) reported a HIPAA breach affecting 2,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Regency Oaks

Regency Oaks (Healthcare Provider, FL) reported a HIPAA breach affecting 2,008 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Square of Seminole

Freedom Square of Seminole (Healthcare Provider, FL) reported a HIPAA breach affecting 3,473 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Picis Clinical Solutions, Inc. d/b/a Medstreaming

Picis Clinical Solutions, Inc. d/b/a Medstreaming (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Anne Arundel Dermatology

Anne Arundel Dermatology (Healthcare Provider, MD) reported a HIPAA breach affecting 1,905,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Plaza Senior Living

Freedom Plaza Senior Living (Healthcare Provider, FL) reported a HIPAA breach affecting 4,847 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Covenant Health

Covenant Health (Business Associate, MA) reported a HIPAA breach affecting 7,864 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FLInvestigation

Robinhood Crypto, LLC.(Robinhood)

Florida Attorney General James Uthmeier launched an investigation into Robinhood Crypto, LLC for allegedly deceptive practices regarding trading costs. The AG issued a subpoena seeking internal documents to determine if Robinhood violated Florida's Deceptive and Unfair Practices Act by falsely claiming to offer the lowest crypto trading costs. Robinhood must respond by July 31, 2025.

Low
HHSEnforcement Action

Mountain Laurel Dermatology

Mountain Laurel Dermatology (Healthcare Provider, NC) reported a HIPAA breach affecting 3,324 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
MASettlement

Earnest Operations LLC(Earnest)

Massachusetts Attorney General settled with Earnest Operations LLC for $2.5 million over allegations that the student loan lender's use of AI underwriting models led to disparate impact on Black, Hispanic, and non-citizen applicants. The company failed to test its AI models for bias, used discriminatory variables like Cohort Default Rate, and sent inaccurate adverse action notices. Earnest must pay the fine, discontinue problematic practices, and implement compliance measures.

HighAI/Automated DecisionsNotice Failure

$2.5M

HHSEnforcement Action

Naper Grove Vision Care

Naper Grove Vision Care (Healthcare Provider, IL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Florida Lung, Asthma & Sleep Specialists (FLASS)

Florida Lung, Asthma & Sleep Specialists (FLASS) (Healthcare Provider, FL) reported a HIPAA breach affecting 10,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre (Healthcare Provider, GA) reported a HIPAA breach affecting 1,714 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTSettlement

TicketNetwork, Inc.(TicketNetwork)

Connecticut Attorney General William Tong announced a settlement with TicketNetwork, Inc. for violating the Connecticut Data Privacy Act by maintaining an unreadable privacy notice and non-functional consumer rights mechanisms. TicketNetwork agreed to comply with CTDPA requirements, maintain metrics for consumer rights requests, report to the AG, and pay $85,000.

LowNotice FailureOpt-Out Failure

$85K

HHSEnforcement Action

Complete Care Rehab LLC

Complete Care Rehab LLC (Healthcare Provider, MI) reported a HIPAA breach affecting 4,764 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

K&E Advanced Dentisrty

K&E Advanced Dentisrty (Healthcare Provider, OH) reported a HIPAA breach affecting 1,700 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

City of Franklin

City of Franklin (Healthcare Provider, WI) reported a HIPAA breach affecting 3,233 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Arbor Associates, Inc.

Arbor Associates, Inc. (Business Associate, MI) reported a HIPAA breach affecting 17,040 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cierant Corporation

Cierant Corporation (Business Associate, CT) reported a HIPAA breach affecting 232,506 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Urology Associates of Charleston

Urology Associates of Charleston (Healthcare Provider, SC) reported a HIPAA breach affecting 2,060 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Zumpano Patricios, P.A.

Zumpano Patricios, P.A. (Business Associate, FL) reported a HIPAA breach affecting 279,275 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Radiology Associates of Richmond, Inc.

Radiology Associates of Richmond, Inc. (Healthcare Provider, VA) reported a HIPAA breach affecting 1,419,091 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
CASettlement

Healthline Media LLC(Healthline)

California Attorney General Rob Bonta announced a $1.55 million settlement with Healthline Media LLC for CCPA violations. Healthline failed to honor opt-out requests, shared consumer data including health-related article titles with third parties, and used deceptive privacy practices. The settlement includes injunctive relief and a compliance program.

HighOpt-Out FailureUnauthorized Data SharingHealth Data

$1.6M

HHSEnforcement Action

Clinical Practices of the University of Pennsylvania

Clinical Practices of the University of Pennsylvania (Healthcare Provider, PA) reported a HIPAA breach affecting 1,432 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Texas Center for Infectious Disease Associates

Texas Center for Infectious Disease Associates (Healthcare Provider, TX) reported a HIPAA breach affecting 19,481 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Centers for Medicare & Medicaid Services

Centers for Medicare & Medicaid Services (Health Plan, MD) reported a HIPAA breach affecting 107,154 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

California Cancer Associates for Research and Excellence – San Diego

California Cancer Associates for Research and Excellence – San Diego (Healthcare Provider, CA) reported a HIPAA breach affecting 638 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Denali Biomedical

Denali Biomedical (Healthcare Provider, AK) reported a HIPAA breach affecting 2,413 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
TXEnforcement Action

Aylo Global Entertainment(Aylo)

The Supreme Court upheld a Texas law requiring pornography websites to implement age-verification measures to protect children from explicit content. Attorney General Ken Paxton is enforcing the law with fines for violations and has sued Aylo Global Entertainment for non-compliance.

LowChildren's Data
HHSEnforcement Action

PET Imaging of Dallas Northeast

PET Imaging of Dallas Northeast (Healthcare Provider, TX) reported a HIPAA breach affecting 1,935 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data