Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
TXInvestigation

Meta AI Studio and Character.AI(Meta and Character.AI)

Texas Attorney General Ken Paxton has opened an investigation into Meta AI Studio and Character.AI for deceptive practices in marketing AI chatbots as mental health services to children. The platforms are accused of impersonating licensed professionals, fabricating qualifications, and exploiting user data for advertising without proper disclosure. Civil Investigative Demands have been issued to examine violations of Texas consumer protection laws and the SCOPE Act.

LowChildren's DataUnauthorized Data SharingNotice Failure
HHSEnforcement Action

Lake City Cancer Care, LLC

Lake City Cancer Care, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 9,980 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Anaheim

Welcome Dentistry-Anaheim (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mower County Health and Human Services

Mower County Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Los Angeles

Welcome Dentistry-Los Angeles (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

UnitedHealthcare

UnitedHealthcare (Health Plan, CT) reported a HIPAA breach affecting 3,215 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Laurel Cancer Care, LLC

Laurel Cancer Care, LLC (Healthcare Provider, MS) reported a HIPAA breach affecting 1,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Zelis Healthcare LLC

Zelis Healthcare LLC (Business Associate, MA) reported a HIPAA breach affecting 4,289 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Dr. Doug's Pediatric Dentistry

Dr. Doug's Pediatric Dentistry (Healthcare Provider, UT) reported a HIPAA breach affecting 3,590 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Altos Inc

Altos Inc (Business Associate, CA) reported a HIPAA breach affecting 1,634 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

PROVAIL

PROVAIL (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Friesen Group

Friesen Group (Healthcare Provider, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Center for Disability Services, Inc.

Center for Disability Services, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 3,343 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CPPAEnforcement Action

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) filed a petition in Superior Court to enforce a subpoena against Tractor Supply Company for alleged CCPA violations, including failure to honor consumers' right to opt-out of the sale and sharing of personal information. This is the CPPA's first judicial action to enforce an investigative subpoena, and the agency is seeking court assistance to compel the company's compliance.

LowOpt-Out Failure
HHSEnforcement Action

South Coast Pediatrics

South Coast Pediatrics (Healthcare Provider, CA) reported a HIPAA breach affecting 7,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Precision Edodontics of Raleigh

Precision Edodontics of Raleigh (Healthcare Provider, NC) reported a HIPAA breach affecting 4,022 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
FLEnforcement Action

WebGroup Czech Republic, a.s.; NKL Associates, s.r.o.; Sonesta Technologies, s.r.o.; Sonesta Media, s.r.o.; Sonesta Technologies, Inc.; GGW Group, s.r.o.; GTFlix TV, s.r.o.; GGW Group, LLC; Traffic F, s.r.o.(WebGroup Czech Republic, NKL Associates, Sonesta Technologies, Sonesta Media, GGW Group, GTFlix TV, Traffic F)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3, which requires age verification to prevent minors from accessing harmful content. The companies, including XVideos.com and XNXX.com, have failed to implement age verification since the law took effect on January 1, 2025. The lawsuit seeks to enforce HB 3 and the Florida Deceptive and Unfair Trade Practices Act to protect children from exposure to explicit material.

LowChildren's Data
FLEnforcement Action

Webgroup Czech Republic, NKL Associates, Sonesta Technologies, Inc., GGW Group, Traffic F(WebGroup Czech Republic)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3 by not implementing age verification to prevent minors from accessing harmful content. The companies have ignored prior warnings and are accused of unfair business practices. The suit seeks to compel compliance with state law.

LowChildren's Data
HHSEnforcement Action

Genoa Community Hospital/LTC

Genoa Community Hospital/LTC (Healthcare Provider, NE) reported a HIPAA breach affecting 2,544 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Western Montana Clinic PC

Western Montana Clinic PC (Healthcare Provider, MT) reported a HIPAA breach affecting 8,255 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Central Maine Healthcare

Central Maine Healthcare (Healthcare Provider, ME) reported a HIPAA breach affecting 7,223 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Vail Summit Orthopaedics

Vail Summit Orthopaedics (Healthcare Provider, CO) reported a HIPAA breach affecting 5,044 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

David A. Nover, M.D., P.C.

David A. Nover, M.D., P.C. (Healthcare Provider, PA) reported a HIPAA breach affecting 4,703 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Berkshire Health Systems, Inc.

Berkshire Health Systems, Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 1,421 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong, leading a coalition of 22 states, filed a lawsuit against the U.S. Department of Agriculture for demanding that states disclose sensitive personal data of SNAP recipients. The demand violates federal privacy laws and the Constitution, and threatens to withhold critical funding. The lawsuit seeks to block USDA from conditioning SNAP administrative funds on data disclosure.

LowUnauthorized Data Sharing
HHSEnforcement Action

University of Miami

University of Miami (Healthcare Provider, FL) reported a HIPAA breach affecting 2,928 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

PhyNet Dermatology, LLC

PhyNet Dermatology, LLC (Business Associate, TN) reported a HIPAA breach affecting 1,308 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Center at Cordera

The Center at Cordera (Healthcare Provider, CO) reported a HIPAA breach affecting 6,057 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAFine

Accurate Append, Inc.(Accurate Append)

The California Privacy Protection Agency (CPPA) ordered Accurate Append, Inc. to pay a $55,400 fine for failing to register as a data broker under the Delete Act by the January 31, 2024 deadline. The company registered only after being contacted during an enforcement sweep and agreed to injunctive terms, including paying attorney fees for future non-compliance.

LowData Broker Non-Compliance

$55K

HHSEnforcement Action

Compass Counseling Services, LLC

Compass Counseling Services, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,440 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data