Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Highlands Oncology Group PA

Highlands Oncology Group PA (Healthcare Provider, AR) reported a HIPAA breach affecting 111,766 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Western Montana Clinic PC

Western Montana Clinic PC (Healthcare Provider, MT) reported a HIPAA breach affecting 8,255 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Central Maine Healthcare

Central Maine Healthcare (Healthcare Provider, ME) reported a HIPAA breach affecting 7,223 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Vail Summit Orthopaedics

Vail Summit Orthopaedics (Healthcare Provider, CO) reported a HIPAA breach affecting 5,044 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

David A. Nover, M.D., P.C.

David A. Nover, M.D., P.C. (Healthcare Provider, PA) reported a HIPAA breach affecting 4,703 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Berkshire Health Systems, Inc.

Berkshire Health Systems, Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 1,421 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Alera Group, Inc.

Alera Group, Inc. (Business Associate, IL) reported a HIPAA breach affecting 155,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong, leading a coalition of 22 states, filed a lawsuit against the U.S. Department of Agriculture for demanding that states disclose sensitive personal data of SNAP recipients. The demand violates federal privacy laws and the Constitution, and threatens to withhold critical funding. The lawsuit seeks to block USDA from conditioning SNAP administrative funds on data disclosure.

LowUnauthorized Data Sharing
HHSEnforcement Action

University of Miami

University of Miami (Healthcare Provider, FL) reported a HIPAA breach affecting 2,928 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

PhyNet Dermatology, LLC

PhyNet Dermatology, LLC (Business Associate, TN) reported a HIPAA breach affecting 1,308 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Center at Cordera

The Center at Cordera (Healthcare Provider, CO) reported a HIPAA breach affecting 6,057 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAFine

Accurate Append, Inc.(Accurate Append)

The California Privacy Protection Agency (CPPA) ordered Accurate Append, Inc. to pay a $55,400 fine for failing to register as a data broker under the Delete Act by the January 31, 2024 deadline. The company registered only after being contacted during an enforcement sweep and agreed to injunctive terms, including paying attorney fees for future non-compliance.

LowData Broker Non-Compliance

$55K

HHSEnforcement Action

Compass Counseling Services, LLC

Compass Counseling Services, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,440 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NJWarning Letter

auto dealerships(Auto Dealerships)

The New Jersey Division of Consumer Affairs sent warning letters to over 3,000 auto dealerships reminding them of the state's data deletion law, which requires dealerships to offer to delete personal data from vehicles when accepting them for resale or lease. Failure to comply can result in fines of $500 for first offenses and $1,000 for subsequent offenses, aimed at preventing unauthorized access to sensitive consumer information stored in vehicle infotainment systems.

LowSecurity Failure
CAEnforcement ActionMultistate

United States Department of Agriculture (USDA)

New York Attorney General Letitia James joined a multistate coalition of 21 attorneys general and Kentucky in filing a lawsuit against the U.S. Department of Agriculture (USDA) challenging its illegal demand for personally identifiable information of over 40 million SNAP recipients. The coalition alleges the USDA’s requirement that states turn over SNAP recipients’ Social Security numbers, addresses, and immigration statuses violates federal and state laws prohibiting disclosure of SNAP data for non-program purposes, and that the data will be shared across federal agencies for unauthorized immigration enforcement. The coalition seeks a declaratory judgment declaring the policy illegal and a nationwide injunction preventing enforcement of the data demand.

CriticalUnauthorized Data Sharing
CTEnforcement Action

MAKECTBETTER LLC(MAKECTBETTER)

Connecticut Attorney General William Tong filed a lawsuit against MAKECTBETTER LLC and individuals for operating a fraudulent scheme selling fake cannabis licenses. The defendants forged state documents and charged businesses up to $50,000 for non-existent licenses. The AG is seeking a $2.5 million prejudgment remedy to freeze the defendants' assets.

High

$2.5M

NYEnforcement ActionMultistate

United States Department of Agriculture(USDA)

New York Attorney General Letitia James, joined by 20 other states and Kentucky, filed a lawsuit challenging the Trump administration's policy requiring states to disclose personal information of SNAP recipients to federal agencies. The policy violates privacy laws by demanding sensitive data like Social Security numbers for potential immigration enforcement. The coalition seeks a court injunction to stop the illegal data sharing.

HighUnauthorized Data Sharing
MAEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Massachusetts Attorney General Andrea Campbell, joined by a coalition of 21 states and Kentucky, filed a lawsuit challenging the U.S. Department of Agriculture's demand that states turn over sensitive personal data of SNAP recipients. The lawsuit argues that this demand violates federal privacy laws and the Spending Clause, threatening the privacy of millions of low-income families and coercing states by threatening funding cuts.

HighUnauthorized Data Sharing
NJEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

New Jersey Attorney General Matthew J. Platkin joined a coalition of 20 attorneys general in filing a lawsuit against the U.S. Department of Agriculture (USDA) for demanding that states turn over sensitive personal information of SNAP recipients, including Social Security numbers and addresses. The lawsuit argues that this demand violates federal privacy laws and the Constitution, as the data is protected and should only be used for program administration. The coalition seeks to block USDA from conditioning SNAP funding on compliance with this demand.

HighUnauthorized Data SharingConsent Failure
HHSEnforcement Action

Doctors’ Memorial Hospital

Doctors’ Memorial Hospital (Healthcare Provider, FL) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Northwest Denture Center, Inc.

Northwest Denture Center, Inc. (Healthcare Provider, WA) reported a HIPAA breach affecting 19,419 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Nova Recovery Center, LLC d/b/a Nova Recovery Center

Nova Recovery Center, LLC d/b/a Nova Recovery Center (Healthcare Provider, TX) reported a HIPAA breach affecting 6,242 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

McKenzie Memorial Hospital

McKenzie Memorial Hospital (Healthcare Provider, MI) reported a HIPAA breach affecting 58,839 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Gastroenterology Consultants of South Texas

Gastroenterology Consultants of South Texas (Healthcare Provider, TX) reported a HIPAA breach affecting 44,579 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Blue Shield of California

Blue Shield of California (Health Plan, CA) reported a HIPAA breach affecting 783 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Laptop, Network Server, Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Kettering Adventist Healthcare

Kettering Adventist Healthcare (Healthcare Provider, OH) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXSettlement

Meta Platforms, Inc.(Meta)

Texas Attorney General Ken Paxton secured a record-setting $1.4 billion settlement with Meta for unlawfully capturing and using the biometric data of millions of Texans, marking one of the largest privacy settlements in U.S. history.

HighBiometric Data

$1.4B

HHSEnforcement Action

Dr. Michael Bilikas and Associates d.b.a. 32 Pearls

Dr. Michael Bilikas and Associates d.b.a. 32 Pearls (Healthcare Provider, WA) reported a HIPAA breach affecting 23,517 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
TXEnforcement Action

Meta, Google, General Motors, TikTok, and other companies(Meta)

Texas Attorney General Ken Paxton announced a comprehensive privacy enforcement initiative, achieving record settlements with Meta ($1.4B) and Google ($1.375B) for biometric and geolocation data violations, suing General Motors and TikTok, and investigating numerous companies for children's data and AI practices. The AG's office has enforced multiple Texas privacy laws and registered over 200 data brokers.

CriticalBiometric DataGeolocation DataChildren's Data

$2.8B

HHSEnforcement Action

OrthoAtlanta LLC

OrthoAtlanta LLC (Business Associate, GA) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data