Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency announced approval of regulations implementing the Delete Act, which will allow consumers to submit a single delete request to multiple data brokers via a new state-hosted platform (DROP). Data brokers must retrieve and process these requests every 45 days starting August 2026, deleting all associated personal data unless a legal exemption applies.

LowData Broker Non-ComplianceOpt-Out FailureRecord Retention
HHSEnforcement Action

West Suburban Eye Surgery Center LLC

West Suburban Eye Surgery Center LLC (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Morton Drug Company

Morton Drug Company (Healthcare Provider, WI) reported a HIPAA breach affecting 40,051 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Steven J. Pearlman MD PC

Steven J. Pearlman MD PC (Healthcare Provider, NY) reported a HIPAA breach affecting 10,182 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Healthcare Therapy Services, Inc.

Healthcare Therapy Services, Inc. (Healthcare Provider, IN) reported a HIPAA breach affecting 15,027 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Marshfield Clinic Health System

Marshfield Clinic Health System (Healthcare Provider, WI) reported a HIPAA breach affecting 35,952 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Loving and Living Center, PC dba Awakenings Center

Loving and Living Center, PC dba Awakenings Center (Healthcare Provider, NC) reported a HIPAA breach affecting 17,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
CTSettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

Connecticut Attorney General William Tong, along with California and New York Attorneys General, settled with Illuminate Education, Inc. for failing to protect student data in a breach that exposed personal information of millions of students. The settlement, the first under Connecticut's Student Data Privacy Law, requires Illuminate to pay $5.1 million and implement enhanced cybersecurity measures.

HighData BreachSecurity FailureStudent Data

$5.1M

NYSettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.

HighData BreachStudent DataSecurity Failure

$5.1M

CTEnforcement Action

Altice/Optimum Online(Altice)

Connecticut Attorney General William Tong filed an expanded complaint against Altice/Optimum Online for deceptive advertising and hidden 'Network Enhancement' fees that collected at least $39.1 million from consumers. The company allegedly misled customers with 'price for life' deals while burying fees in fine print and targeting Spanish speakers with English-only disclosures. The complaint seeks penalties and disgorgement under the Connecticut Unfair Trade Practices Act.

LowNotice Failure
CASettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.

HighData BreachStudent DataHealth Data

$5.1M

HHSEnforcement Action

The Chase Group Employee Benefit Plan

The Chase Group Employee Benefit Plan (Health Plan, NM) reported a HIPAA breach affecting 817 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Archer Health

Archer Health (Healthcare Provider, CA) reported a HIPAA breach affecting 4,285 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) announced its new public-facing name, CalPrivacy, and launched eight privacy tips to help Californians protect their personal data. The agency also announced the upcoming Delete Request and Opt-Out Platform (DROP) for consumers to delete data from data brokers in a single step, launching in January 2026.

Low
HHSEnforcement Action

Motorola Solutions

Motorola Solutions (Health Plan, IL) reported a HIPAA breach affecting 22,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tampa Bay Treatment Associates

Tampa Bay Treatment Associates (Healthcare Provider, FL) reported a HIPAA breach affecting 3,682 individuals. Breach type: Theft. Location of breached information: Electronic Medical Record.

LowData BreachHealth Data
HHSEnforcement Action

Denton MHMR Center

Denton MHMR Center (Healthcare Provider, TX) reported a HIPAA breach affecting 108,967 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Incyte Pathology, P.S.

Incyte Pathology, P.S. (Healthcare Provider, WA) reported a HIPAA breach affecting 629 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
CAGuidance

California healthcare providers, service plans, and contractors(Healthcare Providers)

California Attorney General Rob Bonta issued an informational bulletin summarizing new responsibilities under SB 81, which expands protections for immigrants' medical information by designating immigration status as protected data under the Confidentiality of Medical Information Act (CMIA) and restricts immigration enforcement access to non-public areas of healthcare facilities.

LowHealth Data
HHSEnforcement Action

Expert MRI

Expert MRI (Healthcare Provider, CA) reported a HIPAA breach affecting 209,560 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Judson Center

Judson Center (Healthcare Provider, MI) reported a HIPAA breach affecting 976 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tri Century Eye Care PC

Tri Century Eye Care PC (Healthcare Provider, PA) reported a HIPAA breach affecting 200,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Beverly Hills Oncology Medical Group

Beverly Hills Oncology Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 57,655 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
TXSettlement

Google

Texas Attorney General Ken Paxton secured a $1.375 billion settlement with Google for unlawfully tracking Texans' geolocation data, incognito browsing activity, and biometric identifiers without consent. This is the largest single-state privacy settlement against Google, significantly larger than multistate settlements. The agreement resolves two major privacy enforcement actions brought by Texas.

CriticalGeolocation DataConsent FailureBiometric Data

$1.4B

CAEnforcement ActionMultistate

U.S. Department of Justice(Department of Justice)

California Attorney General Rob Bonta joined 15 attorneys general in filing an amicus brief to limit a U.S. DOJ subpoena seeking medical records of transgender youth from Children's Hospital of Philadelphia, arguing it violates patient privacy and could intimidate providers of gender-affirming care.

LowHealth DataChildren's Data
CTInvestigation

Food Distributors and Grocery Retailers(Food Distributors and Retailers)

Connecticut Attorney General William Tong is expanding an inquiry into high grocery prices by sending letters to major food distributors and retailers. The inquiry found no evidence of price gouging at the retail level but will now investigate the supply chain for potential unfair profiteering. The AG also cited factors like tariffs and SNAP cuts that contribute to high prices.

Low
CASettlement

Sling TV LLC and Dish Media Sales LLC(Sling TV)

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the CCPA by failing to provide an easy-to-use opt-out mechanism for the sale of personal information and insufficient privacy protections for children. The settlement, subject to court approval, requires Sling TV to implement streamlined opt-out processes across all devices, stop redirecting users to cookie preferences for CCPA opt-outs, and add kid-specific profiles with default opt-out of data sales and targeted advertising. This is the first enforcement action from the DOJ's 2024 investigative sweep of streaming services.

MediumOpt-Out FailureChildren's DataConsent Failure

$530K

CASettlement

Sling TV LLC(Sling TV)

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

MediumOpt-Out FailureChildren's Data

$530K

HHSEnforcement Action

Hale Makua Health Services

Hale Makua Health Services (Healthcare Provider, HI) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXInvestigation

Lorex Technology Inc.

Texas Attorney General Ken Paxton opened an investigation into Lorex Technology Inc. for allegedly deceptively selling security cameras with components from CCP-linked Dahua, posing privacy and national security risks. The investigation will determine if Lorex misrepresented the cameras as secure and safe for residential use despite known supply chain vulnerabilities and federal restrictions on Dahua products.

LowSecurity Failure

Explore Enforcement Data