Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

The Carpenter Health Network

The Carpenter Health Network (Healthcare Provider, LA) reported a HIPAA breach affecting 878 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXEnforcement Action

TP-Link, Alibaba, CapCut

Texas Attorney General Ken Paxton has issued notices to several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA's requirements to disclose data processing, allow opt-outs, and enable data deletion within 30 days, or face further legal action.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
TXEnforcement Action

TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party (“CCP”) aligned companies(TP-Link, Alibaba, CapCut)

Texas Attorney General Ken Paxton announced legal action against several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies have been given 30 days to comply with requirements to disclose data processing, allow consumers to opt out of data collection, and enable data deletion. Failure to comply will result in further legal action to protect Texans' privacy rights and prevent data from being accessed by the Chinese Communist Party.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
TXEnforcement Action

TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party ("CCP") aligned companies(TP-Link, Alibaba, CapCut)

Texas Attorney General Ken Paxton has notified several Chinese companies, including TP-Link, Alibaba, and CapCut, that they are violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA requirements to disclose data processing, allow consumer opt-outs, and enable data deletion within 30 days. Failure to comply will result in further legal action.

LowNotice FailureOpt-Out FailureUnauthorized Data Sharing
HHSEnforcement Action

SunLink Health Systems, Inc.

SunLink Health Systems, Inc. (Healthcare Provider, GA) reported a HIPAA breach affecting 2,856 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAAdministrative Order

Todd Snyder, Inc.(Todd Snyder)

The California Privacy Protection Agency (CPPA) settled with Todd Snyder, Inc. for violating the California Consumer Privacy Act (CCPA) by failing to process opt-out requests, requiring excessive information for privacy requests, and improperly verifying identities for opt-outs. The company must pay a $345,178 fine and overhaul its privacy practices, including configuring opt-out mechanisms and providing employee training.

MediumOpt-Out Failure

$345K

HHSEnforcement Action

Minnesota Orthodontics and Dentofacial Orthopedics, P.A.

Minnesota Orthodontics and Dentofacial Orthopedics, P.A. (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Monongalia Health System, Inc.

Monongalia Health System, Inc. (Healthcare Provider, WV) reported a HIPAA breach affecting 4,895 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

CardioVascular Health Clinic

CardioVascular Health Clinic (Healthcare Provider, OK) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Absolute Dental Group, LLC

Absolute Dental Group, LLC (Business Associate, NV) reported a HIPAA breach affecting 1,223,635 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sonrisas Dental Health

Sonrisas Dental Health (Healthcare Provider, CA) reported a HIPAA breach affecting 15,644 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Anesthesia Associates of Morristown, P.A.

Anesthesia Associates of Morristown, P.A. (Healthcare Provider, NJ) reported a HIPAA breach affecting 34,675 individuals. Breach type: Improper Disposal. Location of breached information: Paper/Films.

MediumData BreachHealth Data
HHSEnforcement Action

DermCare Management

DermCare Management (Business Associate, FL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement Action

Planet Zaza of East Haven(Planet Zaza)

Attorney General William Tong obtained a $4.93 million judgment against Planet Zaza of East Haven and its owner for persistent illegal cannabis sales in violation of a court order. The court imposed penalties of $5,000 per day for each day of violation and $25,000 per day for violating the temporary injunction, totaling $4.93 million.

High

$4.9M

CANew Law

California Privacy Protection Agency

On May 1, 2025, the CPPA Board voted to support four California bills that expand privacy protections, including restrictions on location data, neural data protections, data broker disclosure requirements, and teleconference meeting provisions. The Board also took a 'support if amended' position on an AI security bill. This is a legislative support action, not an enforcement action.

Low
HHSEnforcement Action

Berkeley Research Group, LLC

Berkeley Research Group, LLC (Business Associate, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Family Christian Health Center

Family Christian Health Center (Healthcare Provider, IL) reported a HIPAA breach affecting 12,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Canby Clinic

Canby Clinic (Healthcare Provider, OR) reported a HIPAA breach affecting 549 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Physician Wound Solutions, LLC dba Apollo Medical Supply

Physician Wound Solutions, LLC dba Apollo Medical Supply (Healthcare Provider, FL) reported a HIPAA breach affecting 3,561 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) and the UK Information Commissioner's Office (UK ICO) signed a declaration of cooperation to coordinate international privacy and data protection efforts. The agreement facilitates joint research, sharing of best practices, and mutual collaboration on privacy enforcement across jurisdictions.

Low
HHSEnforcement Action

Ascension Health

Ascension Health (Healthcare Provider, MO) reported a HIPAA breach affecting 437,329 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) opened a public comment period for proposed Delete Request and Opt-out Platform (DROP) regulations, which will allow California residents to delete their personal information held by CPPA-registered data brokers in a single request. The comment period runs from April 25 to June 10, 2025, with a hybrid public hearing on June 10.

LowData Broker Non-Compliance
HHSEnforcement Action

Carlton County Public Health and Human Services

Carlton County Public Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 3,502 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Maximus, Inc.

Maximus, Inc. (Business Associate, VA) reported a HIPAA breach affecting 4,955 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Palo Verde Hospital

Palo Verde Hospital (Healthcare Provider, CA) reported a HIPAA breach affecting 594 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cache Valley Ear Nose & Throat

Cache Valley Ear Nose & Throat (Healthcare Provider, UT) reported a HIPAA breach affecting 26,469 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Brainard Surgery Center LLC

Brainard Surgery Center LLC (Healthcare Provider, OH) reported a HIPAA breach affecting 1,820 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Drug and Alcohol Treatment Services, Inc.

Drug and Alcohol Treatment Services, Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 22,215 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Orthopaedic Specialists of Connecticut

Orthopaedic Specialists of Connecticut (Healthcare Provider, CT) reported a HIPAA breach affecting 22,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Icon Family Healthcare LLC

Icon Family Healthcare LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 1,800 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing

Explore Enforcement Data