Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Apex Custom Software

Apex Custom Software (Business Associate, TX) reported a HIPAA breach affecting 1,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Holdrege Memorial Homes, Inc.

Holdrege Memorial Homes, Inc. (Healthcare Provider, NE) reported a HIPAA breach affecting 1,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Treatment Solutions

Community Treatment Solutions (Healthcare Provider, NJ) reported a HIPAA breach affecting 950 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

Multiple Connecticut retailers and wholesalers(Connecticut Retailers and Wholesalers)

Connecticut Attorney General William Tong announced a coordinated multi-state enforcement action against the sale of bootleg, flavored disposable e-cigarettes. Civil investigative demands were served on 12 Connecticut smoke shops, convenience stores, and two wholesalers for selling illegally imported, non-FDA authorized nicotine products designed to appeal to youth. Nine other states announced parallel investigations or litigation targeting distributors and retailers of these products.

Low
FTCConsent Decree

GoDaddy Inc.(GoDaddy)

The FTC settled charges against GoDaddy for failing to implement adequate data security measures for its web hosting services, which led to multiple breaches and misled customers about its security protections. The proposed order requires GoDaddy to establish a comprehensive information security program and hire an independent assessor for regular reviews.

LowSecurity Failure
TXEnforcement Action

Aylo Global Entertainment

Texas Attorney General Ken Paxton defended House Bill 1181 at the U.S. Supreme Court, which requires online pornography sites to verify users' ages to protect children from harmful content. The law was challenged by pornography distributors, but Texas won at the Fifth Circuit and is now defending its constitutionality. Texas has also sued Aylo Global Entertainment for non-compliance, leading to Pornhub's shutdown in Texas.

LowChildren's Data
FTCSettlement

Mobilewalla Inc.(Mobilewalla)

The FTC finalized an order banning Mobilewalla Inc. from selling sensitive location data after alleging the company sold such data without verifying consumer consent. The order prohibits Mobilewalla from collecting data from ad exchanges for non-auction purposes, misrepresenting data practices, and using location data from sensitive locations like health clinics and places of worship.

LowConsent FailureGeolocation Data
FTCConsent Decree

IntelliVision Technologies Corp.(IntelliVision Technologies)

The FTC finalized an order against IntelliVision Technologies Corp. for making deceptive claims about its facial recognition software's accuracy and lack of bias. The company must now back up any claims with competent testing and is prohibited from misrepresenting the software's performance. No monetary penalty was imposed.

LowBiometric DataAI/Automated Decisions
TXEnforcement Action

Allstate and Arity(Allstate)

Texas Attorney General Ken Paxton filed a lawsuit against Allstate and its subsidiary Arity for unlawfully collecting, using, and selling driving data from over 45 million consumers without consent. The data, which includes precise geolocation information, was used to justify insurance premium increases. This action alleges violations of the Texas Data Privacy and Security Act (TDPSA).

LowNotice FailureConsent FailureUnauthorized Data Sharing
HHSEnforcement Action

Samaritan Counseling Center of the Fox Valley

Samaritan Counseling Center of the Fox Valley (Healthcare Provider, WI) reported a HIPAA breach affecting 956 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
TXEnforcement Action

TikTok

Texas Attorney General Ken Paxton filed a lawsuit against TikTok for deceptively promoting its app as safe for children despite the prevalence of inappropriate and explicit content. The action alleges violations of the SCOPE Act, which protects children's online privacy, and follows a previous lawsuit regarding data privacy issues.

LowChildren's Data
HHSEnforcement Action

BayMark Health Services, Inc.

BayMark Health Services, Inc. (Business Associate, TX) reported a HIPAA breach affecting 3,170 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

Greystar Real Estate Partners LLC, Blackstone's LivCor LLC, Camden Property Trust, Cushman & Wakefield Inc, Pinnacle Property Management Services LLC, Willow Bridge Property Company LLC, Cortland Management LLC(Greystar, LivCor, Camden, Cushman & Wakefield, Pinnacle Property Management, Willow Bridge, Cortland)

The U.S. Department of Justice and ten states filed an amended complaint against six major landlords for using algorithmic pricing and sharing competitively sensitive information to suppress competition and raise rents. Cortland Management LLC agreed to a consent decree requiring it to cease these practices, cooperate with the investigation, and submit to court-monitored oversight. The landlords collectively manage over 1.3 million rental units across the United States.

LowSurveillance PricingUnauthorized Data Sharing
HHSEnforcement Action

Eastern Idaho Public Health

Eastern Idaho Public Health (Healthcare Provider, ID) reported a HIPAA breach affecting 759 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

North Los Angeles County Regional Center

North Los Angeles County Regional Center (Business Associate, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

DentaQuest

DentaQuest (Health Plan, WI) reported a HIPAA breach affecting 868 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Ingham County Medical Care Facility, d/b/a Dobie Road

Ingham County Medical Care Facility, d/b/a Dobie Road (Healthcare Provider, MI) reported a HIPAA breach affecting 3,078 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataSecurity Failure
CTGuidance

Businesses subject to CTDPA(N/A)

Attorney General William Tong announced that starting January 1, 2025, businesses covered by the Connecticut Data Privacy Act must honor global opt-out preference signals, allowing consumers to opt out of targeted advertising and data sales via tools like Global Privacy Control. The advisory explains requirements, notes exemptions for HIPAA-covered entities, and provides resources for compliance.

LowOpt-Out Failure
HHSEnforcement Action

Omaha Surgical Center

Omaha Surgical Center (Healthcare Provider, NE) reported a HIPAA breach affecting 1,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Dragonfly Health

Dragonfly Health (Business Associate, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Polaris Endeavors

Polaris Endeavors (Healthcare Provider, FL) reported a HIPAA breach affecting 4,552 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Khalil Foundation (DBA Khalil Center)

Khalil Foundation (DBA Khalil Center) (Healthcare Provider, IL) reported a HIPAA breach affecting 1,153 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
FTCConsent Decree

Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC(Marriott)

The FTC finalized an order against Marriott International and Starwood Hotels for failing to implement reasonable data security, which led to three data breaches affecting over 344 million customers. The companies must implement a comprehensive security program, delete unnecessary personal information, allow U.S. customers to request deletion, and restore stolen loyalty points. They are also prohibited from misrepresenting their data security practices.

LowSecurity Failure
HHSEnforcement Action

Effortless Office Enterprises, LLC

Effortless Office Enterprises, LLC (Business Associate, NV) reported a HIPAA breach affecting 3,112 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

HealthEquity, Inc.

HealthEquity, Inc. (Business Associate, UT) reported a HIPAA breach affecting 1,549 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPASettlement

PayDae, Inc. (Infillion) and The Data Group, LLC(Infillion and Data Group)

The California Privacy Protection Agency (CPPA) settled with two data brokers, PayDae, Inc. (Infillion) and The Data Group, LLC, for failing to register as required by Senate Bill 362 (the Delete Act). Infillion paid $54,200 and The Data Group paid $46,600, and both agreed to injunctive terms to ensure future compliance with registration requirements.

LowData Broker Non-Compliance
HHSEnforcement Action

California Correctional Health Care Services

California Correctional Health Care Services (Healthcare Provider, CA) reported a HIPAA breach affecting 1,416 individuals. Breach type: Loss. Location of breached information: Paper/Films.

LowData BreachHealth Data
HHSEnforcement Action

Kitsap Mental Health Services

Kitsap Mental Health Services (Healthcare Provider, WA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXInvestigation

Character.AI, Reddit, Instagram, Discord, and 14 other companies

Texas Attorney General Ken Paxton launched investigations into Character.AI and 14 other companies, including Reddit, Instagram, and Discord, over potential violations of children’s privacy and safety laws. The investigations focus on compliance with the SCOPE Act and Texas Data Privacy and Security Act (TDPSA), which require parental consent for sharing minors’ data and mandate notice and consent requirements for children’s personal information. No fines or remedies have been imposed as the investigations are ongoing.

LowChildren's DataConsent FailureNotice Failure
CTEnforcement ActionMultistate

Firearms Industry

Connecticut Attorney General William Tong announced a multistate coalition of 16 attorneys general to use civil enforcement against irresponsible members of the firearms industry. The coalition will enforce state consumer protection and liability laws to reduce gun violence, with past actions including lawsuits against Glock for machine gun conversions and ghost gun dealers.

Low

Explore Enforcement Data