Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

AmerisourceBergen Specialty Group, LLC

AmerisourceBergen Specialty Group, LLC (Healthcare Provider, PA) reported a HIPAA breach affecting 3,102 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FTCConsent Decree

Blackbaud Inc.(Blackbaud)

The FTC finalized a consent order against Blackbaud Inc. for alleged security failures that led to a data breach exposing personal data of millions of consumers. Blackbaud must delete unnecessary data, implement a security program, and not misrepresent its policies. No monetary penalty was imposed.

LowSecurity FailureData BreachNotice Failure
HHSEnforcement Action

Pope & Conner Consulting, Inc.

Pope & Conner Consulting, Inc. (Business Associate, WI) reported a HIPAA breach affecting 1,035 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Kenneth Young Center

Kenneth Young Center (Healthcare Provider, IL) reported a HIPAA breach affecting 6,842 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FTCSettlement

InMarket Media(InMarket)

The FTC settled with InMarket Media for unlawfully collecting and using consumers' precise location data without adequate notice and consent. The order prohibits InMarket from selling or sharing precise location data, requires deletion of collected data, and mandates consumer consent mechanisms and privacy programs.

LowNotice FailureConsent FailureGeolocation Data
HHSEnforcement Action

AMERICAN RENAL MANAGEMENT

AMERICAN RENAL MANAGEMENT (Business Associate, TN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXSettlement

Multi Media, LLC(Multi Media)

Texas Attorney General Ken Paxton announced a settlement with Multi Media, LLC, operator of Chaturbate, for violating Texas age verification law HB 1181. The company agreed to implement an age verification service on its website to prevent minors from accessing adult content. No monetary penalty was imposed in this settlement.

LowChildren's Data
HHSEnforcement Action

Therapeutic Health Services

Therapeutic Health Services (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Empath-Stratum Inc. doing business as Empath Health

Empath-Stratum Inc. doing business as Empath Health (Healthcare Provider, FL) reported a HIPAA breach affecting 5,545 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cumberland Heights Foundation, Inc.

Cumberland Heights Foundation, Inc. (Healthcare Provider, TN) reported a HIPAA breach affecting 5,078 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
FTCSettlement

X-Mode Social and Outlogic(X-Mode)

The FTC finalized an order against data broker X-Mode and its successor Outlogic for selling precise location data that could track visits to sensitive locations like medical clinics and places of worship. The order bans them from sharing or selling sensitive location data and requires them to delete collected data, implement privacy programs, and ensure downstream compliance.

LowGeolocation DataUnauthorized Data SharingData Broker Non-Compliance
HHSEnforcement Action

UNC Hospitals

UNC Hospitals (Healthcare Provider, NC) reported a HIPAA breach affecting 3,142 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

Apple Inc.(Apple)

Connecticut, along with the U.S. Department of Justice and 15 other states, has filed a civil antitrust lawsuit against Apple Inc. for monopolizing smartphone markets in violation of the Sherman Act. The complaint alleges Apple engages in anticompetitive conduct such as blocking innovative apps, suppressing cloud streaming services, and limiting interoperability to maintain its monopoly and impose high costs on consumers and developers. The plaintiffs seek equitable relief to restore competition.

Low
CTEnforcement Action

Connecticut Office of the Attorney General and Department of Consumer Protection

The Connecticut Attorney General and Consumer Protection Commissioner announced a public service announcement to warn about illegal, unsafe cannabis edibles that mimic kid-friendly snacks. The agencies highlighted ongoing enforcement actions against retailers selling unregulated delta-8 THC products, with four judgments secured totaling $40,000, and ten pending actions. The PSA aims to protect children from accidental ingestion of potent, untested products.

Low

$40K

CTEnforcement ActionMultistate

Meta Platforms, Inc.(Meta)

Connecticut Attorney General William Tong joined a bipartisan coalition of 41 attorneys general in sending a letter to Meta Platforms, Inc. to address the rising number of Facebook and Instagram account takeovers by scammers. The coalition criticizes Meta's inadequate security measures and calls for improved protections including multi-factor authentication, increased staffing for response, and stronger enforcement against scammers. The letter urges Meta to take immediate action to safeguard user accounts from hijacking and fraud.

LowSecurity Failure
ILEnforcement ActionMultistate

Meta Platforms Inc.(Meta)

A bipartisan coalition of 41 attorneys general, led by Illinois Attorney General Kwame Raoul, sent a letter to Meta Platforms Inc. calling for improved data security practices to protect users from account takeovers by scammers. The coalition cites a dramatic increase in account takeover complaints and urges Meta to increase staffing, implement multi-factor authentication, and take stronger enforcement actions against scammers.

LowSecurity Failure
CTEnforcement ActionMultistate

MV Realty

Connecticut Attorney General William Tong announced legislative action to ban 40-year exclusive real estate listing agreements following an investigation into MV Realty that uncovered nearly 400 deceptive contracts. The company targeted lower-income homeowners with small cash payments for long-term liens, imposing steep penalties for cancellation or independent sales, and often failed to provide proper disclosure or copies of agreements.

LowConsent Failure
CTRegulatory Report

Connecticut Office of the Attorney General

The Connecticut Office of the Attorney General released a mandated report on the Connecticut Data Privacy Act (CTDPA), detailing over a dozen notices of violation issued to companies across various industries for deficiencies in privacy disclosures and consumer rights mechanisms. The report highlights common compliance failures and reaffirms the AG's commitment to enforcement and education under the state's consumer privacy law.

LowNotice FailureOpt-Out Failure
CPPASettlement

Key Marketing Advantage, LLC(Key Marketing Advantage)

The California Privacy Protection Agency settled with data broker Key Marketing Advantage, LLC for failing to register and pay fees under the Delete Act. KMA will pay $55,800 and agree to injunctive terms. This is the fifth enforcement action in a sweep against unregistered data brokers.

LowData Broker Non-Compliance

$56K

CPPASettlement

Key Marketing Advantage, LLC(Key Marketing Advantage)

The California Privacy Protection Agency (CPPA) settled with data broker Key Marketing Advantage, LLC for failing to register and pay fees under the Delete Act. KMA will pay $55,800 and comply with injunctive terms, including covering attorney fees for non-compliance. This is the fifth enforcement action in CPPA's sweep against unregistered data brokers.

LowData Broker Non-Compliance

$56K

CTGuidance

CT UCC Statement Service

Connecticut officials, including Attorney General William Tong, warned businesses about a scam by CT UCC Statement Service, which charges $90 for free UCC reports. The company's mailings are designed to look like government documents, but reports are available for free at business.ct.gov. Businesses should verify notices and avoid paying fees for free services.

LowDark Patterns
FTCConsent Decree

X-Mode Social and Outlogic, LLC(X-Mode Social)

The FTC settled with data brokers X-Mode Social and Outlogic for selling precise location data without informed consent and failing to protect sensitive information. The proposed order bans the sale of sensitive location data, requires deletion of collected data, and mandates a comprehensive privacy program. This is the FTC's first action against a data broker for sensitive location data practices.

LowConsent FailureGeolocation DataOpt-Out Failure
FTCGuidance

Website and Online Service Operators Covered by COPPA(COPPA-Covered Operators)

The FTC has proposed amendments to the COPPA Rule to enhance children's privacy protections. Key changes include requiring separate parental consent for targeted advertising, prohibiting conditioning access on data collection, limiting push notifications, strengthening data security and retention requirements, and restricting commercial use in educational technology. The proposal shifts responsibility from parents to companies to safeguard children's data.

LowChildren's DataConsent FailureUnauthorized Data Sharing
FTCConsent Decree

Global Tel*Link Corp.(Global Tel*Link)

The FTC proposed a consent order against Global Tel*Link Corp. for failing to secure sensitive user data, leading to a breach affecting nearly 650,000 consumers, and for delaying notification for about nine months. The order requires the company to implement a comprehensive security program, notify affected users with credit monitoring, and report future breaches promptly.

LowSecurity FailureBreach Notification Delay
NYConsent Decree

Marymount Manhattan College

Marymount Manhattan College suffered a data breach in 2021 affecting 99,097 New Yorkers. The New York Attorney General found that MMC failed to secure its network infrastructure and update security policies. As part of the agreement, MMC must invest $3.5 million over six years to improve data encryption, enable multi-factor authentication, and implement other security measures.

LowSecurity FailureData BreachStudent Data
FTCWarning Letter

Five tax preparation companies(Tax Preparation Companies)

The FTC issued warnings to five tax preparation companies against using or disclosing consumer tax data for unrelated purposes like advertising without explicit consent. The agency cites its penalty offense authority, referencing a previous case against Beneficial Corp, and warns that such practices violate the FTC Act and could incur penalties up to $50,120 per violation. The notices highlight that using tracking technologies for data collection without consent is also prohibited.

LowConsent Failure
FTCConsent Decree

1Health.io(1Health)

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

LowSecurity FailureOpt-Out FailureNotice Failure

$75K

FTCGuidanceMultistate

Federal Trade Commission

Attorney General William Tong of Connecticut led a bipartisan coalition of 30 state attorneys general in submitting comments to the Federal Trade Commission. The comments aim to improve collaboration between the FTC and state AGs to prevent and prosecute unfair and deceptive practices, addressing issues raised by the AMG Capital decision that may limit restitution. The coalition emphasizes the importance of joint efforts for national consumer protection.

Low
CTCoalitionMultistate

The Office of the Attorney General William Tong

Attorney General William Tong of Connecticut joined a bipartisan coalition of 44 attorneys general to issue a letter supporting the G.U.A.R.D. VA Benefits Act. The legislation aims to hold unaccredited and unregulated actors accountable for defrauding veterans applying for VA benefits by requiring proper accreditation and imposing penalties, as unaccredited services waste veterans' money and time and may lead to fraud and identity theft.

Low
CTCoalitionMultistate

The Office of the Attorney General William Tong

Attorney General William Tong of Connecticut joined a multistate coalition of 21 attorneys general in filing an amicus brief to defend the federal government's ability to communicate with social media companies about dangerous online content. The coalition opposes a preliminary injunction that prohibits such communications, arguing it undermines public safety efforts and must be overturned. The brief highlights examples of productive dialogue on issues like election security, public health emergencies, and consumer protection.

Low

Explore Enforcement Data