1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Connections for Kids (Healthcare Provider, ME) reported a HIPAA breach affecting 938 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
The Cooper Health System (Healthcare Provider, NJ) reported a HIPAA breach affecting 57,412 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Connecticut Attorney General William Tong filed a lawsuit against Triggered Brand for selling unapproved 'research grade' GLP-1 weight loss drugs directly to consumers without prescriptions or medical oversight, violating the Connecticut Unfair Trade Practices Act and pharmacy licensing laws. The AG also issued a Civil Investigative Demand to Made In China for similar sales and sent warning letters to weight loss clinics about compounded GLP-1 drugs.
The FTC finalized an order with GoDaddy for failing to implement adequate data security measures and misleading consumers about its security and Privacy Shield compliance. The order prohibits misrepresentations, requires a comprehensive security program, and mandates independent assessments.
The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company allegedly did not implement reasonable security measures, leaving customer websites vulnerable to attacks that could harm both the customers and visitors to those sites. The case resulted in a consent order requiring GoDaddy to improve its security practices.
The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company's security failures left customers' and website visitors' data vulnerable to attacks. The final order requires GoDaddy to implement comprehensive data security measures.
Community Hospital of Anaconda (Healthcare Provider, MT) reported a HIPAA breach affecting 21,243 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Instituto de Ojos de Puerto Rico (Healthcare Provider, ) reported a HIPAA breach affecting 50,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Insulet Corporation (Healthcare Provider, MA) reported a HIPAA breach affecting 841 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
Mercy Surgical Dressing Group, Inc. (Business Associate, PA) reported a HIPAA breach affecting 4,159 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Harbin Clinic, LLC (Healthcare Provider, GA) reported a HIPAA breach affecting 176,149 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Compassion Health Care, Inc. (Healthcare Provider, NC) reported a HIPAA breach affecting 23,282 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Weiser Valley Hospital District dba Weiser Memorial Hospital (Healthcare Provider, ID) reported a HIPAA breach affecting 59,990 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Doctors Hospital at Renaissance, LTD (Healthcare Provider, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
CareNexa, LLC, doing business as Molecular Testing Labs (Healthcare Provider, WA) reported a HIPAA breach affecting 7,711 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Anne Arundel County Department of Health (Healthcare Provider, MD) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
HopeHealth, Inc. (Healthcare Provider, SC) reported a HIPAA breach affecting 5,823 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Hunter Health Clinic (Healthcare Provider, KS) reported a HIPAA breach affecting 28,431 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Union County Children and Youth Services (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
CVS Caremark (Business Associate, RI) reported a HIPAA breach affecting 2,599 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
The California Privacy Protection Agency (CPPA) submitted a letter to the House Energy & Commerce Committee opposing a provision in the Committee's budget reconciliation bill that would impose a 10-year moratorium on enforcement of state artificial intelligence and automated decisionmaking technology (ADMT) laws and regulations. The CPPA argues that the moratorium threatens critical consumer protections approved by California voters under the CCPA, including regulations governing consumers' access and opt-out rights related to businesses' use of ADMT.
Washington Gastroenterology (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Attorney General Ken Paxton sued Google for unlawfully tracking and collecting Texans' private data, including geolocation, incognito searches, and biometric data. The case resulted in a $1.375 billion settlement, the largest ever against Google for state privacy enforcement, marking a major win for data privacy rights.
$1.4B
The California Privacy Protection Agency (CPPA) opened a formal public comment period on modifications to proposed regulations for CCPA updates, cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance companies. The modifications were approved unanimously during the May 1 Board Meeting, and comments are accepted until June 2, 2025.
Blue Cross Blue Shield of Texas (Business Associate, IL) reported a HIPAA breach affecting 593 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
Tri-City Cardiology Consultants, P.C. (Healthcare Provider, AZ) reported a HIPAA breach affecting 22,753 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The California Privacy Protection Agency ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under the Delete Act. The order was issued by default after the company did not contest the allegations, highlighting CPPA's enforcement of data broker registration requirements.
$46K
The California Privacy Protection Agency (CPPA) ordered Jerico Pictures, Inc., doing business as National Public Data, to pay a $46,000 fine for failing to register and pay the annual fee required under California's Delete Act. The order was issued by default after the company did not contest the allegations. This enforcement action highlights the CPPA's efforts to ensure data broker compliance with registration laws.
$46K
Allied Services Division Welfare Fund (Health Plan, IL) reported a HIPAA breach affecting 5,727 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Texas Attorney General Ken Paxton issued a 30-day compliance notice to TP-Link, Alibaba, CapCut, and other CCP-affiliated Chinese companies for violating the Texas Data Privacy and Security Act (TDPSA). The companies are accused of failing to disclose consumer data processing activities, allow opt-out of data collection, and enable consumer data deletion as required by Texas law. If the companies do not comply within 30 days, the Attorney General's office will pursue additional legal action.
All data sourced from official government enforcement pages.