Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Escambia Community Clinics, Inc. dba Community Health Northwest Florida

Escambia Community Clinics, Inc. dba Community Health Northwest Florida (Healthcare Provider, FL) reported a HIPAA breach affecting 143,969 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

University Diagnostic Medical Imaging, PC

University Diagnostic Medical Imaging, PC (Healthcare Provider, NY) reported a HIPAA breach affecting 138,080 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Asheville Eye Associates, PLLC

Asheville Eye Associates, PLLC (Healthcare Provider, NC) reported a HIPAA breach affecting 204,984 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Allegheny Health Network Home Medical Equipment LLC and Allegheny Health Network Home Infusion LLC

Allegheny Health Network Home Medical Equipment LLC and Allegheny Health Network Home Infusion LLC (Healthcare Provider, PA) reported a HIPAA breach affecting 292,773 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
FTCConsent Decree

General Motors LLC, General Motors Holdings LLC, and OnStar LLC(General Motors)

The FTC alleged that General Motors and its OnStar subsidiary collected and sold drivers' precise geolocation and driving behavior data (e.g., hard braking, speeding) to consumer reporting agencies without adequately notifying consumers or obtaining their affirmative consent. A proposed consent order bans the companies from disclosing this sensitive data to consumer reporting agencies for five years and requires them to implement clearer consent mechanisms, data access/deletion processes, and opt-out options.

HighGeolocation DataConsent FailureUnauthorized Data Sharing
HHSEnforcement Action

Mid America Physician Services

Mid America Physician Services (Healthcare Provider, KS) reported a HIPAA breach affecting 104,513 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Newport Harbor Pathology Medical Group, Inc.

Newport Harbor Pathology Medical Group, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 119,341 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTSettlement

Stone Academy

Connecticut Attorney General William Tong announced a $5 million preliminary settlement with Stone Academy and its owners for unfair and deceptive conduct. The for-profit nursing school failed to deliver promised education, lacking textbooks, experienced teachers, and clinical training, and abruptly closed in February 2023. The settlement provides cash payments to harmed students, bars the owner from higher education employment for five years, and includes measures to help students complete their education.

HighNotice FailureConsent Failure

$5.0M

HHSEnforcement Action

Medusind Inc.

Medusind Inc. (Business Associate, FL) reported a HIPAA breach affecting 701,475 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tycon Medical Systems, Inc.

Tycon Medical Systems, Inc. (Healthcare Provider, VA) reported a HIPAA breach affecting 112,847 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Richmond University Medical Center

Richmond University Medical Center (Healthcare Provider, NY) reported a HIPAA breach affecting 674,033 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Regional Care, Inc.

Regional Care, Inc. (Healthcare Clearing House, NE) reported a HIPAA breach affecting 225,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Summit Medical Group, PLLC

Summit Medical Group, PLLC (Healthcare Provider, TN) reported a HIPAA breach affecting 464,159 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
TXInvestigation

Character.AI

Texas Attorney General Ken Paxton has launched investigations into Character.AI and fourteen other companies, including Reddit, Instagram, and Discord, for potential violations of the SCOPE Act and TDPSA regarding children's privacy and safety. The investigations focus on unauthorized sharing of minors' data and lack of parental controls. No penalties have been imposed yet as the investigations are ongoing.

HighChildren's DataConsent FailureNotice Failure
HHSEnforcement Action

Atrium Health

Atrium Health (Healthcare Provider, NC) reported a HIPAA breach affecting 585,959 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

HighData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

American Addiction Centers, Inc.

American Addiction Centers, Inc. (Business Associate, TN) reported a HIPAA breach affecting 410,747 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Texas Tech University Health Sciences Center

Texas Tech University Health Sciences Center (Healthcare Provider, TX) reported a HIPAA breach affecting 650,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Texas Tech University Health Sciences Center El Paso

Texas Tech University Health Sciences Center El Paso (Healthcare Provider, TX) reported a HIPAA breach affecting 815,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Rocky Mountain Gastroenterology Associates PLLC

Rocky Mountain Gastroenterology Associates PLLC (Healthcare Provider, CO) reported a HIPAA breach affecting 366,491 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Great Plains Regional Medical Center

Great Plains Regional Medical Center (Healthcare Provider, OK) reported a HIPAA breach affecting 133,149 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Rockford Gastroenterology Associates

Rockford Gastroenterology Associates (Healthcare Provider, IL) reported a HIPAA breach affecting 147,253 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

RRCA Accounts Management Inc.

RRCA Accounts Management Inc. (Business Associate, IL) reported a HIPAA breach affecting 115,837 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.

HighData BreachHealth DataSecurity Failure
CTEnforcement Action

Vision Solar

The Connecticut Attorney General obtained a $5 million stipulated judgment against Vision Solar for alleged deceptive sales practices, including high-pressure tactics, misrepresentations, and performing unpermitted work. Although the company is bankrupt and cannot pay, the judgment establishes binding operational standards for solar companies in Connecticut regarding disclosures, contracting, permitting, and use of licensed contractors.

HighConsent FailureNotice Failure

$5.0M

TXSettlementMultistate

Marriott International, Inc.(Marriott)

Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.

HighData BreachSecurity Failure

$3.5M

HHSEnforcement Action

Ciox Health LLC, d/b/a Datavant Group

Ciox Health LLC, d/b/a Datavant Group (Business Associate, AZ) reported a HIPAA breach affecting 320,702 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Omni Family Health

Omni Family Health (Healthcare Provider, CA) reported a HIPAA breach affecting 468,344 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

ATSG, Inc

ATSG, Inc (Business Associate, NY) reported a HIPAA breach affecting 909,469 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Muskogee City County Enhanced 911 Trust Authority

Muskogee City County Enhanced 911 Trust Authority (Business Associate, OK) reported a HIPAA breach affecting 180,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTSettlementMultistate

Enzo Biochem, Inc. and Enzo Clinical Labs, Inc.(Enzo Biochem)

Connecticut Attorney General announced a $1.73 million settlement with Enzo Clinical Labs for overbilling the state Medicaid program. The lab billed Medicaid full prices while offering discounted rates to other payers, violating the state False Claims Act. The settlement resolves both an audit repayment and claims from a whistleblower investigation.

High

$1.7M

FTCConsent Decree

Verkada

Verkada, a security camera company, failed to secure customer data, leading to a hacker accessing over 150,000 cameras and sensitive health information. The company also violated the CAN-SPAM Act by sending spam emails without proper opt-out mechanisms. To settle, Verkada will pay $2.95 million and implement a comprehensive security program with audits.

HighSecurity FailureOpt-Out FailureNotice Failure

$3.0M

Explore Enforcement Data