1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Florida Attorney General James Uthmeier filed a lawsuit against Snap, Inc., operator of Snapchat, for violating Florida’s HB3 child social media protection law and the Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The suit alleges Snap knowingly allowed children under 13 to create accounts, failed to obtain parental consent for 14-15 year old users, deployed addictive dark pattern design features to children, and deceived parents about platform risks including predator access, drug sales, and harmful content. The legal action seeks to hold Snap accountable for noncompliance with Florida child safety and privacy laws.
Onsite Mammography (Business Associate, MA) reported a HIPAA breach affecting 357,265 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Texas Attorney General Ken Paxton filed a motion to appoint a Consumer Privacy Ombudsman in the Chapter 11 bankruptcy case of 23andMe to protect the sensitive genetic and personal data of Texans. The genetic testing company seeks to sell assets that may include genetic data, health information, and personally identifiable information. The AG's office is also informing Texans of their rights under Texas law to request deletion of their data and genetic samples.
90 Degree Benefits, Inc. – St. Paul (Business Associate, WI) reported a HIPAA breach affecting 1,268 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
The Connecticut Office of the Attorney General released an updated enforcement report on the Connecticut Data Privacy Act (CTDPA) for 2024, summarizing investigations into companies handling connected vehicles, genetic data, palm recognition, teen messaging apps, and facial recognition. The report outlines expanded enforcement priorities around opt-out practices and dark patterns, and includes legislative recommendations to strengthen the CTDPA.
The New Jersey Attorney General filed a lawsuit against Discord, Inc. for deceptive business practices under the Consumer Fraud Act. Discord misrepresented its Safe Direct Messaging and age verification features, failing to protect children from
Florida Attorney General James Uthmeier issued a subpoena to Roblox on April 16, 2025, as part of an investigation into the gaming platform’s child-protection policies and children’s data practices. The subpoena demands documents related to Roblox’s marketing to children, age-verification procedures, chat moderation, and processing of minors’ personal data, following reports of children being exposed to harmful content and predatory actors on the platform. No fines or remedies have been imposed yet, as the investigation is ongoing.
Eight state regulators, including the California Privacy Protection Agency and attorneys general from seven states, formed the bipartisan Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. The group aims to share expertise, resources, and coordinate investigations to protect consumer privacy across jurisdictions.
Recovery Epicenter Foundation (Healthcare Provider, FL) reported a HIPAA breach affecting 800 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.
HEALTH AND WELLNESS OF TEXAS (Healthcare Provider, TX) reported a HIPAA breach affecting 500 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Email.
Magnolia Manor Inc. (Healthcare Provider, GA) reported a HIPAA breach affecting 960 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Bell Ambulance, Inc. (Healthcare Provider, WI) reported a HIPAA breach affecting 237,830 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The City of Long Beach, CA (Healthcare Provider, CA) reported a HIPAA breach affecting 258,191 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
AHS Sherman LLC dba AHS Sherman Medical Center (Healthcare Provider, TX) reported a HIPAA breach affecting 908 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.
Health Care Service Corporation (Health Plan, IL) reported a HIPAA breach affecting 2,944 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
Blue Cross and Blue Shield of Texas (Health Plan, IL) reported a HIPAA breach affecting 12,086 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
Blue Cross and Blue Shield of Oklahoma (Health Plan, IL) reported a HIPAA breach affecting 1,020 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
Blue Cross and Blue Shield of Illinois (Health Plan, IL) reported a HIPAA breach affecting 6,903 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
Parc Provence Memory Care Facility (Healthcare Provider, MO) reported a HIPAA breach affecting 13,954 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Gatesworth Senior Living St. Louis (Healthcare Provider, MO) reported a HIPAA breach affecting 31,124 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Summit Healthcare Medical Associates (Healthcare Provider, AZ) reported a HIPAA breach affecting 1,861 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Endue Software (Business Associate, ME) reported a HIPAA breach affecting 118,028 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Altior Healthcare, LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 1,002 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
The Connecticut Attorney General, leading a multistate task force of 51 attorneys general, issued warning letters to nine phone providers for allegedly routing unlawful robocalls. The providers have received numerous traceback notices for various scam calls, including government impersonations and financial fraud. The task force demands immediate cessation of illegal robocall facilitation or face legal action.
Cabot Medical Care (Healthcare Provider, AR) reported a HIPAA breach affecting 21,467 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Jacksonville Medical Care (Healthcare Provider, AR) reported a HIPAA breach affecting 6,262 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Blue Shield of California (Business Associate, CA) reported a HIPAA breach affecting 4,700,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Kelly & Associates Insurance Group, Inc. (Business Associate, MD) reported a HIPAA breach affecting 553,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Alabama Ophthalmology Associates (Healthcare Provider, AL) reported a HIPAA breach affecting 131,576 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.
Loretto Hospital (Healthcare Provider, IL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
All data sourced from official government enforcement pages.