Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCSettlementMultistate

Kars-R-Us.com, Inc.(Kars-R-Us.com)

The FTC and 19 states settled with Kars-R-Us.com, Inc. and its operators for deceptive charity fundraising claims, where only 0.28% of over $45 million raised was used for breast cancer screenings. Operators face permanent fundraising bans and a $3.88 million monetary judgment.

HighNotice Failure

$3.9M

HHSEnforcement Action

Doctors Imaging Group

Doctors Imaging Group (Healthcare Provider, FL) reported a HIPAA breach affecting 171,862 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Medical Associates of Brevard, LLC

Medical Associates of Brevard, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 246,711 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Retina Group of Florida

Retina Group of Florida (Healthcare Provider, FL) reported a HIPAA breach affecting 152,691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
FTCSettlement

Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC(Disney)

The FTC alleges that Disney violated COPPA by failing to properly label children-directed videos on YouTube as 'Made for Kids,' allowing the collection of personal data from children under 13 without parental consent. Disney will pay a $10 million civil penalty and must implement a program to ensure accurate video designations, potentially incorporating age assurance technologies.

HighChildren's DataConsent Failure

$10.0M

HHSEnforcement Action

University of Iowa Health Care

University of Iowa Health Care (Healthcare Provider, IA) reported a HIPAA breach affecting 101,875 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

University of Iowa Community Home Care

University of Iowa Community Home Care (Healthcare Provider, IA) reported a HIPAA breach affecting 109,029 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Vital Imaging Medical Diagnostic Centers, LLC

Vital Imaging Medical Diagnostic Centers, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 260,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Highlands Oncology Group PA

Highlands Oncology Group PA (Healthcare Provider, AR) reported a HIPAA breach affecting 111,766 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alera Group, Inc.

Alera Group, Inc. (Business Associate, IL) reported a HIPAA breach affecting 155,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
NJEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

New Jersey Attorney General Matthew J. Platkin joined a coalition of 20 attorneys general in filing a lawsuit against the U.S. Department of Agriculture (USDA) for demanding that states turn over sensitive personal information of SNAP recipients, including Social Security numbers and addresses. The lawsuit argues that this demand violates federal privacy laws and the Constitution, as the data is protected and should only be used for program administration. The coalition seeks to block USDA from conditioning SNAP funding on compliance with this demand.

HighUnauthorized Data SharingConsent Failure
CTEnforcement Action

MAKECTBETTER LLC(MAKECTBETTER)

Connecticut Attorney General William Tong filed a lawsuit against MAKECTBETTER LLC and individuals for operating a fraudulent scheme selling fake cannabis licenses. The defendants forged state documents and charged businesses up to $50,000 for non-existent licenses. The AG is seeking a $2.5 million prejudgment remedy to freeze the defendants' assets.

High

$2.5M

MAEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Massachusetts Attorney General Andrea Campbell, joined by a coalition of 21 states and Kentucky, filed a lawsuit challenging the U.S. Department of Agriculture's demand that states turn over sensitive personal data of SNAP recipients. The lawsuit argues that this demand violates federal privacy laws and the Spending Clause, threatening the privacy of millions of low-income families and coercing states by threatening funding cuts.

HighUnauthorized Data Sharing
NYEnforcement ActionMultistate

United States Department of Agriculture(USDA)

New York Attorney General Letitia James, joined by 20 other states and Kentucky, filed a lawsuit challenging the Trump administration's policy requiring states to disclose personal information of SNAP recipients to federal agencies. The policy violates privacy laws by demanding sensitive data like Social Security numbers for potential immigration enforcement. The coalition seeks a court injunction to stop the illegal data sharing.

HighUnauthorized Data Sharing
TXSettlement

Meta Platforms, Inc.(Meta)

Texas Attorney General Ken Paxton secured a record-setting $1.4 billion settlement with Meta for unlawfully capturing and using the biometric data of millions of Texans, marking one of the largest privacy settlements in U.S. history.

HighBiometric Data

$1.4B

MASettlement

Earnest Operations LLC(Earnest)

Massachusetts Attorney General settled with Earnest Operations LLC for $2.5 million over allegations that the student loan lender's use of AI underwriting models led to disparate impact on Black, Hispanic, and non-citizen applicants. The company failed to test its AI models for bias, used discriminatory variables like Cohort Default Rate, and sent inaccurate adverse action notices. Earnest must pay the fine, discontinue problematic practices, and implement compliance measures.

HighAI/Automated DecisionsNotice Failure

$2.5M

HHSEnforcement Action

Zumpano Patricios, P.A.

Zumpano Patricios, P.A. (Business Associate, FL) reported a HIPAA breach affecting 279,275 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cierant Corporation

Cierant Corporation (Business Associate, CT) reported a HIPAA breach affecting 232,506 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CASettlement

Healthline Media LLC(Healthline)

California Attorney General Rob Bonta announced a $1.55 million settlement with health information website publisher Healthline Media LLC, resolving allegations that the company violated the CCPA and Unfair Competition Law. Violations included failing to honor consumer opt-out requests, sharing sensitive health data with third parties without required privacy protections, and using deceptive consent banners that did not disable tracking cookies. The settlement imposes injunctive terms, compliance requirements, and a civil penalty, marking the largest CCPA settlement to date.

HighOpt-Out FailureUnauthorized Data SharingHealth Data

$1.6M

HHSEnforcement Action

Centers for Medicare & Medicaid Services

Centers for Medicare & Medicaid Services (Health Plan, MD) reported a HIPAA breach affecting 107,154 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Compumedics USA, Inc.

Compumedics USA, Inc. (Business Associate, NC) reported a HIPAA breach affecting 318,150 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Horizon Healthcare RCM

Horizon Healthcare RCM (Healthcare Clearing House, IN) reported a HIPAA breach affecting 210,901 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Heartland Regional Medical Center d/b/a Mosaic Life Care

Heartland Regional Medical Center d/b/a Mosaic Life Care (Healthcare Provider, MO) reported a HIPAA breach affecting 145,269 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

McLaren Health Care

McLaren Health Care (Healthcare Provider, MI) reported a HIPAA breach affecting 743,131 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mainline Health Systems Inc

Mainline Health Systems Inc (Healthcare Provider, AR) reported a HIPAA breach affecting 101,104 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
FLEnforcement Action

Contec, Epsimed(Contec)

Florida Attorney General James Uthmeier issued subpoenas to Contec and Epsimed for selling medical devices that transmit patient data to China without adequate security. The companies are accused of violating Florida's Deceptive and Unfair Trade Practices Act by misrepresenting FDA approval and concealing cybersecurity vulnerabilities. The AG seeks damages, civil penalties, and injunctive relief to protect consumers.

HighUnauthorized Data SharingHealth DataSecurity Failure
HHSEnforcement Action

Decisely Insurance Services, LLC

Decisely Insurance Services, LLC (Business Associate, GA) reported a HIPAA breach affecting 537,603 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Central Kentucky Radiology

Central Kentucky Radiology (Healthcare Provider, KY) reported a HIPAA breach affecting 166,953 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Southern Connecticut Vascular Center, LLC

Southern Connecticut Vascular Center, LLC (Healthcare Provider, CT) reported a HIPAA breach affecting 154,417 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Renkim Corporation

Renkim Corporation (Business Associate, MI) reported a HIPAA breach affecting 105,518 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure

Explore Enforcement Data