1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,506
Total Actions
16
Jurisdictions
$26.6B+
Total Fines Tracked
Marshfield Clinic Health System (Healthcare Provider, WI) reported a HIPAA breach affecting 35,952 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Loving and Living Center, PC dba Awakenings Center (Healthcare Provider, NC) reported a HIPAA breach affecting 17,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.
Motorola Solutions (Health Plan, IL) reported a HIPAA breach affecting 22,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Beverly Hills Oncology Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 57,655 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the CCPA by failing to provide an easy-to-use opt-out mechanism for the sale of personal information and insufficient privacy protections for children. The settlement, subject to court approval, requires Sling TV to implement streamlined opt-out processes across all devices, stop redirecting users to cookie preferences for CCPA opt-outs, and add kid-specific profiles with default opt-out of data sales and targeted advertising. This is the first enforcement action from the DOJ's 2024 investigative sweep of streaming services.
$530K
California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.
$530K
Heartland Health Center (Healthcare Provider, NE) reported a HIPAA breach affecting 43,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Visiting Nurse Association of Texas, LLC (Healthcare Provider, TX) reported a HIPAA breach affecting 28,515 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Conduent Business Services LLC (Business Associate, NJ) reported a HIPAA breach affecting 42,616 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
OB-GYN Associates, Ltd. dba OBGYN Associates (Healthcare Provider, NV) reported a HIPAA breach affecting 62,238 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Space Coast Vascular (Healthcare Provider, FL) reported a HIPAA breach affecting 18,819 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Sierra Vista Hospital & Clinics (Healthcare Provider, NM) reported a HIPAA breach affecting 75,054 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Rockhill Women’s Care (Healthcare Provider, MO) reported a HIPAA breach affecting 70,129 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Susan B. Allen Memorial Hospital (Healthcare Provider, KS) reported a HIPAA breach affecting 11,866 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.
City of St. Joseph, MO Health Department (Healthcare Provider, MO) reported a HIPAA breach affecting 11,538 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
People Encouraging People (Healthcare Provider, MD) reported a HIPAA breach affecting 13,083 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) (Healthcare Provider, FL) reported a HIPAA breach affecting 13,230 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Ennoble Care & Circa Health, LLC (Healthcare Provider, NJ) reported a HIPAA breach affecting 36,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Sturgis Hospital (Health Plan, MI) reported a HIPAA breach affecting 77,771 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Sun Valley Surgery Center (Healthcare Provider, NV) reported a HIPAA breach affecting 27,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
PGA Development, Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 23,899 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The FTC settled allegations against Apitor Technology for violating COPPA by allowing a third party to collect geolocation data from children without parental consent. Apitor must pay a $500,000 suspended fine, delete improperly collected data, and implement measures to comply with COPPA, including obtaining parental consent and notifying parents.
$500K
Teamsters Union 25 Health Services & Insurance Plan (Health Plan, MA) reported a HIPAA breach affecting 19,231 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The FTC released a statement by Chairman Ferguson, joined by Commissioners Holyoak and Meador, regarding the enforcement action against Disney Worldwide Services for alleged violations of the Children's Online Privacy Protection Act (COPPA). The statement addresses the case involving children's privacy protections.
The FTC distributed refunds to consumers who purchased deceptively marketed treatment plans from Golden Sunrise Nutraceutical. The company and its medical director were barred from making unsupported health claims about curing COVID-19, cancer, and Parkinson's disease after a court order in September 2025. Over $40,700 was sent to 578 consumers, with additional claims possible until May 2026.
$103K
Greater Pittsburgh Orthopaedics Associates (Healthcare Provider, PA) reported a HIPAA breach affecting 35,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.
Pacific Imaging Management, LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 13,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Beech Acres Parenting Center (Healthcare Provider, OH) reported a HIPAA breach affecting 19,315 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Massachusetts Attorney General Andrea Joy Campbell announced a $795,000 settlement with Peabody Properties, Inc. for failing to protect personal information and delaying breach notifications after multiple data breaches exposed nearly 14,000 residents' sensitive data. The consent decree requires payment to the Commonwealth and implementation of comprehensive cybersecurity measures.
$795K
Pediatric Otolaryngology Head & Neck Surgery Associates, P.A. (Healthcare Provider, FL) reported a HIPAA breach affecting 43,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
All data sourced from official government enforcement pages.