Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Wakefield & Associates, LLC

Wakefield & Associates, LLC (Business Associate, TN) reported a HIPAA breach affecting 31,751 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTSettlementMultistate

Comstar, LLC(Comstar)

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

MediumData BreachSecurity FailureHealth Data

$515K

HHSEnforcement Action

Clinic Service Corporation

Clinic Service Corporation (Business Associate, CO) reported a HIPAA breach affecting 82,331 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
MASettlementMultistate

Comstar, LLC(Comstar)

Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.

MediumData BreachHealth DataSecurity Failure

$515K

HHSEnforcement Action

Pecan Tree Dental, PLLC

Pecan Tree Dental, PLLC (Healthcare Provider, TX) reported a HIPAA breach affecting 13,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Jefferson-Blount-St. Clair Mental Health Authority

Jefferson-Blount-St. Clair Mental Health Authority (Healthcare Provider, AL) reported a HIPAA breach affecting 30,434 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

360 Dental PC

360 Dental PC (Healthcare Provider, PA) reported a HIPAA breach affecting 11,273 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NJSettlement

Apple Inc.

New Jersey Attorney General Matthew Platkin announced a settlement with Apple Inc. over allegations of widespread merchandise pricing violations at 11 Apple stores statewide, including failure to display required pricing information and refund policies. Apple agreed to pay a $150,000 civil penalty, the largest-ever under New Jersey's Merchandise Pricing Act, and implement revised business practices to ensure clear pricing and refund policy disclosures. The settlement resolves violations of the New Jersey Consumer Fraud Act and the 2017 consent order previously entered into by Apple.

Medium

$150K

HHSEnforcement Action

Avosina Healthcare Solutions

Avosina Healthcare Solutions (Business Associate, VA) reported a HIPAA breach affecting 44,425 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Central Ozarks Medical Center

Central Ozarks Medical Center (Healthcare Provider, MO) reported a HIPAA breach affecting 11,818 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mid Michigan Medical Billing Service, Inc.

Mid Michigan Medical Billing Service, Inc. (Business Associate, MI) reported a HIPAA breach affecting 28,185 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NYSettlement

OrthopedicsNY, LLP(OrthopedicsNY)

New York Attorney General Letitia James secured a $500,000 settlement with orthopedics practice OrthopedicsNY, LLP for failing to implement adequate data security measures, leading to a 2023 cyberattack that exposed personal and health information of approximately 656,000 patients and employees. The settlement requires OrthopedicsNY to pay the penalty, fund one year of free credit monitoring for affected individuals, and adopt enhanced data security practices including multifactor authentication, encryption, and annual risk assessments.

MediumData BreachSecurity FailureHealth Data

$500K

HHSEnforcement Action

AllerVie Health

AllerVie Health (Healthcare Provider, TX) reported a HIPAA breach affecting 80,521 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Artemis Healthcare Inc.

Artemis Healthcare Inc. (Healthcare Provider, TN) reported a HIPAA breach affecting 45,867 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Medical Center, LLP

Medical Center, LLP (Healthcare Provider, GA) reported a HIPAA breach affecting 32,090 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

North East Medical Services

North East Medical Services (Healthcare Provider, CA) reported a HIPAA breach affecting 91,513 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Excellent Home Care Services, LLC

Excellent Home Care Services, LLC (Healthcare Provider, NY) reported a HIPAA breach affecting 16,278 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

West Texas Health, PLLC

West Texas Health, PLLC (Business Associate, TX) reported a HIPAA breach affecting 73,720 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTInvestigationMultistate

Affirm, Afterpay, Klarna, PayPal, Sezzle, Zip(Affirm)

Connecticut Attorney General William Tong led a multistate coalition in sending inquiry letters to six major BNPL providers—Affirm, Afterpay, Klarna, PayPal, Sezzle, and Zip—seeking detailed information on their pricing, fees, disclosures, and consumer assessment practices to evaluate compliance with consumer protection laws, following the rescission of federal Truth in Lending Act rules for BNPL.

MediumNotice Failure
HHSEnforcement Action

Spindletop Center

Spindletop Center (Healthcare Provider, TX) reported a HIPAA breach affecting 88,863 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
ORSettlement

Grocery Delivery E-Service USA, Inc., doing business as HelloFresh(HelloFresh)

Consumer protection and advertising enforcement action. Oregon Attorney General secured a settlement with meal-kit company HelloFresh for misleading consumers with deceptive 'free meal,' 'free shipping,' and 'free gift' offers that required hundreds of dollars in purchases to obtain. The company must pay $106,000 and implement comprehensive advertising reforms.

MediumDark PatternsNotice Failure

$106K

HHSEnforcement Action

Davies, McFarland & Carroll LLC

Davies, McFarland & Carroll LLC (Business Associate, PA) reported a HIPAA breach affecting 54,712 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Millcreek Pediatrics

Millcreek Pediatrics (Healthcare Provider, DE) reported a HIPAA breach affecting 14,095 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

NS Support, LLC

NS Support, LLC (Healthcare Provider, ID) reported a HIPAA breach affecting 92,845 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

NAHGA Claim Services

NAHGA Claim Services (Health Plan, ME) reported a HIPAA breach affecting 26,906 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Anchorage Neighborhood Health Center

Anchorage Neighborhood Health Center (Healthcare Provider, AK) reported a HIPAA breach affecting 70,555 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Personic Management Company LLC

Personic Management Company LLC (Business Associate, VA) reported a HIPAA breach affecting 10,929 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Morton Drug Company

Morton Drug Company (Healthcare Provider, WI) reported a HIPAA breach affecting 40,051 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Steven J. Pearlman MD PC

Steven J. Pearlman MD PC (Healthcare Provider, NY) reported a HIPAA breach affecting 10,182 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Healthcare Therapy Services, Inc.

Healthcare Therapy Services, Inc. (Healthcare Provider, IN) reported a HIPAA breach affecting 15,027 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data