Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
TXEnforcement Action

Meta, Google, General Motors, TikTok, and other companies(Meta)

Texas Attorney General Ken Paxton announced a comprehensive privacy enforcement initiative, achieving record settlements with Meta ($1.4B) and Google ($1.375B) for biometric and geolocation data violations, suing General Motors and TikTok, and investigating numerous companies for children's data and AI practices. The AG's office has enforced multiple Texas privacy laws and registered over 200 data brokers.

CriticalBiometric DataGeolocation DataChildren's Data

$2.8B

HHSEnforcement Action

Anne Arundel Dermatology

Anne Arundel Dermatology (Healthcare Provider, MD) reported a HIPAA breach affecting 1,905,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Radiology Associates of Richmond, Inc.

Radiology Associates of Richmond, Inc. (Healthcare Provider, VA) reported a HIPAA breach affecting 1,419,091 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Episource, LLC

Episource, LLC (Business Associate, CA) reported a HIPAA breach affecting 6,725,572 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
TXSettlement

Google

Attorney General Ken Paxton sued Google for unlawfully tracking and collecting Texans' private data, including geolocation, incognito searches, and biometric data. The case resulted in a $1.375 billion settlement, the largest ever against Google for state privacy enforcement, marking a major win for data privacy rights.

CriticalGeolocation DataBiometric Data

$1.4B

HHSEnforcement Action

Absolute Dental Group, LLC

Absolute Dental Group, LLC (Business Associate, NV) reported a HIPAA breach affecting 1,223,635 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Blue Shield of California

Blue Shield of California (Business Associate, CA) reported a HIPAA breach affecting 4,700,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
CTSettlementMultistate

Apotex

Connecticut Attorney General William Tong leads a multistate coalition in a $39.1 million settlement with Apotex for conspiracy to inflate generic drug prices and limit competition. The settlement resolves allegations of widespread price-fixing and requires Apotex to pay compensation to affected consumers, agree to injunctive relief, and implement internal reforms to ensure antitrust compliance.

Critical

$39.1M

HHSEnforcement Action

Southeast Series of Lockton Companies, LLC (Lockton)

Southeast Series of Lockton Companies, LLC (Lockton) (Business Associate, GA) reported a HIPAA breach affecting 1,124,727 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
NYEnforcement ActionMultistate

Elon Musk and DOGE(DOGE)

New York Attorney General Letitia James led a multistate coalition to sue the Trump administration for allowing Elon Musk and DOGE unauthorized access to the Treasury Department's central payment system, exposing Americans' sensitive personal information. A federal court granted a preliminary injunction blocking this access and ordering the destruction of any obtained records.

CriticalUnauthorized Data Sharing
CTEnforcement ActionMultistate

Department of Government Efficiency (DOGE)(DOGE)

Connecticut Attorney General William Tong, leading a coalition of 19 attorneys general, secured a temporary restraining order blocking DOGE and Elon Musk from accessing Treasury Department payment systems containing sensitive personal data. The court found the Trump Administration illegally granted unauthorized access, exposing Americans' bank account details and Social Security numbers. The order mandates destruction of downloaded materials and restricts access to vetted civil servants.

CriticalData BreachUnauthorized Data Sharing
CTEnforcement ActionMultistate

U.S. Department of the Treasury(Treasury)

Connecticut Attorney General William Tong filed a lawsuit against President Trump and the U.S. Treasury Department to stop DOGE's unauthorized access to the Treasury's central payment system, which contains sensitive personal information like bank details and Social Security numbers. The lawsuit seeks an injunction and a declaration that the new policy granting access to Elon Musk and DOGE members is unlawful and jeopardizes data security.

CriticalData BreachSecurity Failure
CTEnforcement ActionMultistate

Treasury Department(U.S. Treasury)

Connecticut Attorney General William Tong joined a coalition of 19 attorneys general in suing President Trump and the U.S. Treasury to stop DOGE's unauthorized access to the Treasury's central payment system and confidential records, calling it the largest data breach in American history. The lawsuit seeks an injunction to block the expanded access policy and a declaration that it is unlawful.

CriticalUnauthorized Data SharingData Breach
HHSEnforcement Action

Community Health Center, Inc.

Community Health Center, Inc. (Healthcare Provider, CT) reported a HIPAA breach affecting 1,060,936 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record, Network Server.

CriticalData BreachHealth DataSecurity Failure
FTCConsent Decree

Cognosphere Pte. Ltd and Cognosphere LLC(Cognosphere)

The FTC settled with Cognosphere, the developer of Genshin Impact, for violating COPPA by collecting children's data without parental consent and for using deceptive loot box practices that misled players about costs and odds. Cognosphere will pay a $20 million fine, be banned from selling loot boxes to teens under 16 without parental consent, and must implement various transparency and data deletion measures.

CriticalChildren's DataDark Patterns

$20.0M

FTCSettlement

COGNOSPHERE LLC(Cognosphere)

The FTC settled with Cognosphere LLC, developer of Genshin Impact, for violating COPPA by collecting personal information from children without parental consent and for deceptive practices regarding in-game loot box purchases. The company will pay $20 million in penalties and is banned from selling loot boxes to children under 16 without verifiable parental consent.

CriticalChildren's DataDark Patterns

$20.0M

NYSettlement

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company(GEICO, Travelers)

GEICO and Travelers were fined $11.3 million for data breaches that exposed personal information of over 120,000 New Yorkers due to inadequate cybersecurity. The breaches involved driver's license numbers being stolen and used in fraudulent unemployment claims. The settlements mandate enhanced security measures and penalties.

CriticalData BreachSecurity Failure

$11.3M

NYSettlement

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)

New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne Harris settled with auto insurers GEICO and Travelers for $11.3 million combined over data breaches that exposed over 120,000 New Yorkers’ personal information, including driver’s license numbers and dates of birth. The breaches stemmed from insufficient data security controls, allowing hackers to steal information and file fraudulent unemployment claims during the COVID-19 pandemic. The settlements require the companies to pay penalties and implement enhanced cybersecurity measures including comprehensive information security programs, data inventories, and improved access controls.

CriticalData BreachSecurity Failure

$11.3M

HHSEnforcement Action

Lubbock County Hospital District

Lubbock County Hospital District (Healthcare Provider, TX) reported a HIPAA breach affecting 1,461,776 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
CTSettlementMultistate

Heritage Pharmaceuticals and Apotex

Attorney General William Tong announced settlements with Heritage Pharmaceuticals and Apotex totaling $49.1 million to resolve allegations of price-fixing conspiracies for generic prescription drugs. The companies agreed to cooperate in ongoing multistate litigation and implement internal reforms to ensure fair competition.

Critical

$49.1M

HHSEnforcement Action

Summit Pathology and Summit Pathology Laboratories, Inc.

Summit Pathology and Summit Pathology Laboratories, Inc. (Healthcare Provider, CO) reported a HIPAA breach affecting 1,813,538 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
CTSettlementMultistate

Marriott International, Inc.(Marriott)

A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.

CriticalSecurity FailureData Breach

$52.0M

NYSettlementMultistate

Marriott International, Inc.(Marriott)

A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.

CriticalData BreachSecurity Failure

$52.0M

NJSettlementMultistate

Marriott International, Inc.(Marriott)

A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.

CriticalData BreachSecurity Failure

$52.0M

FTCSettlement

Invitation Homes

Consumer fraud case where the FTC settled with Invitation Homes for deceiving renters with undisclosed fees and unlawful charges, including hidden fees and unfair security deposit withholdings. The company must pay over $47.2 million in refunds to affected consumers and change its leasing practices.

CriticalNotice Failure

$48.0M

HHSEnforcement Action

Acadian Ambulance Service, Inc.

Acadian Ambulance Service, Inc. (Healthcare Provider, LA) reported a HIPAA breach affecting 2,896,985 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

HealthEquity, Inc.

HealthEquity, Inc. (Business Associate, UT) reported a HIPAA breach affecting 4,300,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
TXSettlement

Meta (formerly known as Facebook)

Texas Attorney General Ken Paxton secured a $1.4 billion settlement with Meta over the company’s decade-long unauthorized capture of Texans’ facial geometry via its Tag Suggestions feature, which used facial recognition software without providing notice or obtaining informed consent. The practices violated Texas’s Capture or Use of Biometric Identifier Act (CUBI) and Deceptive Trade Practices Act, as Meta automatically enabled the feature for all Texans without explaining its functionality or seeking permission. This is the largest privacy settlement ever obtained by a single state attorney general, with Meta required to pay the penalty over five years and cease the unlawful biometric data practices.

CriticalBiometric DataConsent FailureNotice Failure

$1.4B

TXSettlement

Meta

Meta captured facial recognition data from millions of Texans without consent, violating Texas biometric privacy laws. The company agreed to pay $1.4 billion over five years to settle the case. This is the largest privacy settlement obtained by a single state.

CriticalBiometric DataConsent Failure

$1.4B

HHSEnforcement Action

Change Healthcare, Inc.

Change Healthcare, Inc. (Business Associate, MN) reported a HIPAA breach affecting 192,700,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure

Explore Enforcement Data