Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Marshfield Clinic Health System

Marshfield Clinic Health System (Healthcare Provider, WI) reported a HIPAA breach affecting 35,952 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Loving and Living Center, PC dba Awakenings Center

Loving and Living Center, PC dba Awakenings Center (Healthcare Provider, NC) reported a HIPAA breach affecting 17,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Motorola Solutions

Motorola Solutions (Health Plan, IL) reported a HIPAA breach affecting 22,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Beverly Hills Oncology Medical Group

Beverly Hills Oncology Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 57,655 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CASettlement

Sling TV LLC and Dish Media Sales LLC(Sling TV)

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the CCPA by failing to provide an easy-to-use opt-out mechanism for the sale of personal information and insufficient privacy protections for children. The settlement, subject to court approval, requires Sling TV to implement streamlined opt-out processes across all devices, stop redirecting users to cookie preferences for CCPA opt-outs, and add kid-specific profiles with default opt-out of data sales and targeted advertising. This is the first enforcement action from the DOJ's 2024 investigative sweep of streaming services.

MediumOpt-Out FailureChildren's DataConsent Failure

$530K

CASettlement

Sling TV LLC(Sling TV)

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

MediumOpt-Out FailureChildren's Data

$530K

HHSEnforcement Action

Heartland Health Center

Heartland Health Center (Healthcare Provider, NE) reported a HIPAA breach affecting 43,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Visiting Nurse Association of Texas, LLC

Visiting Nurse Association of Texas, LLC (Healthcare Provider, TX) reported a HIPAA breach affecting 28,515 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Conduent Business Services LLC

Conduent Business Services LLC (Business Associate, NJ) reported a HIPAA breach affecting 42,616 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

OB-GYN Associates, Ltd. dba OBGYN Associates

OB-GYN Associates, Ltd. dba OBGYN Associates (Healthcare Provider, NV) reported a HIPAA breach affecting 62,238 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Space Coast Vascular

Space Coast Vascular (Healthcare Provider, FL) reported a HIPAA breach affecting 18,819 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sierra Vista Hospital & Clinics

Sierra Vista Hospital & Clinics (Healthcare Provider, NM) reported a HIPAA breach affecting 75,054 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Rockhill Women’s Care

Rockhill Women’s Care (Healthcare Provider, MO) reported a HIPAA breach affecting 70,129 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Susan B. Allen Memorial Hospital

Susan B. Allen Memorial Hospital (Healthcare Provider, KS) reported a HIPAA breach affecting 11,866 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

City of St. Joseph, MO Health Department

City of St. Joseph, MO Health Department (Healthcare Provider, MO) reported a HIPAA breach affecting 11,538 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

People Encouraging People

People Encouraging People (Healthcare Provider, MD) reported a HIPAA breach affecting 13,083 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”)

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) (Healthcare Provider, FL) reported a HIPAA breach affecting 13,230 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Ennoble Care & Circa Health, LLC

Ennoble Care & Circa Health, LLC (Healthcare Provider, NJ) reported a HIPAA breach affecting 36,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sturgis Hospital

Sturgis Hospital (Health Plan, MI) reported a HIPAA breach affecting 77,771 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sun Valley Surgery Center

Sun Valley Surgery Center (Healthcare Provider, NV) reported a HIPAA breach affecting 27,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

PGA Development, Inc.

PGA Development, Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 23,899 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
FTCConsent Decree

Apitor Technology

The FTC settled allegations against Apitor Technology for violating COPPA by allowing a third party to collect geolocation data from children without parental consent. Apitor must pay a $500,000 suspended fine, delete improperly collected data, and implement measures to comply with COPPA, including obtaining parental consent and notifying parents.

MediumChildren's DataGeolocation DataNotice Failure

$500K

HHSEnforcement Action

Teamsters Union 25 Health Services & Insurance Plan

Teamsters Union 25 Health Services & Insurance Plan (Health Plan, MA) reported a HIPAA breach affecting 19,231 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
FTCEnforcement Action

Disney Worldwide Services(Disney)

The FTC released a statement by Chairman Ferguson, joined by Commissioners Holyoak and Meador, regarding the enforcement action against Disney Worldwide Services for alleged violations of the Children's Online Privacy Protection Act (COPPA). The statement addresses the case involving children's privacy protections.

MediumChildren's Data
FTCSettlement

Golden Sunrise Nutraceutical, Inc.(Golden Sunrise Nutraceutical)

The FTC distributed refunds to consumers who purchased deceptively marketed treatment plans from Golden Sunrise Nutraceutical. The company and its medical director were barred from making unsupported health claims about curing COVID-19, cancer, and Parkinson's disease after a court order in September 2025. Over $40,700 was sent to 578 consumers, with additional claims possible until May 2026.

MediumSecurity Failure

$103K

HHSEnforcement Action

Greater Pittsburgh Orthopaedics Associates

Greater Pittsburgh Orthopaedics Associates (Healthcare Provider, PA) reported a HIPAA breach affecting 35,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Pacific Imaging Management, LLC

Pacific Imaging Management, LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 13,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Beech Acres Parenting Center

Beech Acres Parenting Center (Healthcare Provider, OH) reported a HIPAA breach affecting 19,315 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
MAConsent Decree

Peabody Properties, Inc.(Peabody Properties)

Massachusetts Attorney General Andrea Joy Campbell announced a $795,000 settlement with Peabody Properties, Inc. for failing to protect personal information and delaying breach notifications after multiple data breaches exposed nearly 14,000 residents' sensitive data. The consent decree requires payment to the Commonwealth and implementation of comprehensive cybersecurity measures.

MediumSecurity FailureBreach Notification Delay

$795K

HHSEnforcement Action

Pediatric Otolaryngology Head & Neck Surgery Associates, P.A.

Pediatric Otolaryngology Head & Neck Surgery Associates, P.A. (Healthcare Provider, FL) reported a HIPAA breach affecting 43,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data