Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong is seeking a preliminary injunction to block the U.S. Department of Agriculture from forcing states to share private data of SNAP participants, including social security numbers and shopping history. USDA is threatening to cut off administrative funding if states do not comply, which AG Tong argues violates federal privacy laws and the Constitution.

LowUnauthorized Data Sharing
HHSEnforcement Action

Bevel Health Medical Group

Bevel Health Medical Group (Healthcare Provider, PA) reported a HIPAA breach affecting 510 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
TXInvestigation

Meta AI Studio and Character.AI(Meta and Character.AI)

Texas Attorney General Ken Paxton has opened an investigation into Meta AI Studio and Character.AI for deceptive practices in marketing AI chatbots as mental health services to children. The platforms are accused of impersonating licensed professionals, fabricating qualifications, and exploiting user data for advertising without proper disclosure. Civil Investigative Demands have been issued to examine violations of Texas consumer protection laws and the SCOPE Act.

LowChildren's DataUnauthorized Data SharingNotice Failure
HHSEnforcement Action

Lake City Cancer Care, LLC

Lake City Cancer Care, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 9,980 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Anaheim

Welcome Dentistry-Anaheim (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mower County Health and Human Services

Mower County Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alert Medical Alarms

Alert Medical Alarms (Healthcare Provider, PA) reported a HIPAA breach affecting 39,218 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

CPAP Medical Supplies and Services Inc.

CPAP Medical Supplies and Services Inc. (Healthcare Provider, FL) reported a HIPAA breach affecting 90,133 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Los Angeles

Welcome Dentistry-Los Angeles (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

UnitedHealthcare

UnitedHealthcare (Health Plan, CT) reported a HIPAA breach affecting 3,215 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Laurel Cancer Care, LLC

Laurel Cancer Care, LLC (Healthcare Provider, MS) reported a HIPAA breach affecting 1,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Zelis Healthcare LLC

Zelis Healthcare LLC (Business Associate, MA) reported a HIPAA breach affecting 4,289 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Dr. Doug's Pediatric Dentistry

Dr. Doug's Pediatric Dentistry (Healthcare Provider, UT) reported a HIPAA breach affecting 3,590 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Altos Inc

Altos Inc (Business Associate, CA) reported a HIPAA breach affecting 1,634 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mission City Community Network, Inc.

Mission City Community Network, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 11,016 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

PROVAIL

PROVAIL (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Aflac Incorporated (“Aflac”)

Aflac Incorporated (“Aflac”) (Health Plan, GA) reported a HIPAA breach affecting 13,924,906 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Friesen Group

Friesen Group (Healthcare Provider, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Center for Disability Services, Inc.

Center for Disability Services, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 3,343 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CPPAEnforcement Action

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) filed a petition in Superior Court to enforce a subpoena against Tractor Supply Company for alleged CCPA violations, including failure to honor consumers' right to opt-out of the sale and sharing of personal information. This is the CPPA's first judicial action to enforce an investigative subpoena, and the agency is seeking court assistance to compel the company's compliance.

LowOpt-Out Failure
HHSEnforcement Action

South Coast Pediatrics

South Coast Pediatrics (Healthcare Provider, CA) reported a HIPAA breach affecting 7,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Oglethorpe, Inc.

Oglethorpe, Inc. (Healthcare Provider, FL) reported a HIPAA breach affecting 92,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Precision Edodontics of Raleigh

Precision Edodontics of Raleigh (Healthcare Provider, NC) reported a HIPAA breach affecting 4,022 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
FLEnforcement Action

WebGroup Czech Republic, a.s.; NKL Associates, s.r.o.; Sonesta Technologies, s.r.o.; Sonesta Media, s.r.o.; Sonesta Technologies, Inc.; GGW Group, s.r.o.; GTFlix TV, s.r.o.; GGW Group, LLC; Traffic F, s.r.o.(WebGroup Czech Republic, NKL Associates, Sonesta Technologies, Sonesta Media, GGW Group, GTFlix TV, Traffic F)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3, which requires age verification to prevent minors from accessing harmful content. The companies, including XVideos.com and XNXX.com, have failed to implement age verification since the law took effect on January 1, 2025. The lawsuit seeks to enforce HB 3 and the Florida Deceptive and Unfair Trade Practices Act to protect children from exposure to explicit material.

LowChildren's Data
FLEnforcement Action

Webgroup Czech Republic, NKL Associates, Sonesta Technologies, Inc., GGW Group, Traffic F(WebGroup Czech Republic)

Florida Attorney General James Uthmeier filed a lawsuit against multiple online pornography websites for violating HB 3 by not implementing age verification to prevent minors from accessing harmful content. The companies have ignored prior warnings and are accused of unfair business practices. The suit seeks to compel compliance with state law.

LowChildren's Data
HHSEnforcement Action

MDLand International Corporation

MDLand International Corporation (Business Associate, NY) reported a HIPAA breach affecting 22,586 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Genoa Community Hospital/LTC

Genoa Community Hospital/LTC (Healthcare Provider, NE) reported a HIPAA breach affecting 2,544 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Langdon & Company, LLP Certified Public Accountants

Langdon & Company, LLP Certified Public Accountants (Business Associate, NC) reported a HIPAA breach affecting 46,061 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
FTCSettlement

Frank Romero

The FTC is returning over $672,000 to consumers who were deceived by Frank Romero, operator of Trend Deploy, for violating the Mail Order Rule. The court order required Romero to pay the FTC, and the FTC is now distributing refunds to 9,419 affected consumers.

MediumConsent FailureNotice Failure

$672K

HHSEnforcement Action

DaVita Inc.

DaVita Inc. (Healthcare Provider, CO) reported a HIPAA breach affecting 2,689,826 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure

Explore Enforcement Data