Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

United of Omaha Life Insurance Company

United of Omaha Life Insurance Company (Health Plan, NE) reported a HIPAA breach affecting 107,894 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
CASettlement

Blackbaud

Blackbaud, a software company, suffered a data breach in 2020 due to inadequate security measures and made misleading statements about the breach and its security practices. California Attorney General Rob Bonta secured a $6.75 million settlement requiring Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

HighData BreachSecurity FailureBreach Notification Delay

$6.8M

HHSEnforcement Action

Signature Performance, Inc.

Signature Performance, Inc. (Business Associate, NE) reported a HIPAA breach affecting 130,228 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Panorama Eyecare

Panorama Eyecare (Healthcare Provider, CO) reported a HIPAA breach affecting 377,911 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

AmerisourceBergen Specialty Group, LLC

AmerisourceBergen Specialty Group, LLC (Healthcare Provider, PA) reported a HIPAA breach affecting 252,214 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tri-City Healthcare District

Tri-City Healthcare District (Healthcare Provider, CA) reported a HIPAA breach affecting 108,149 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Watson Clinic

Watson Clinic (Healthcare Provider, FL) reported a HIPAA breach affecting 280,278 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Medical Express Ambulance Inc. D/B/A Medex Ambulance

Medical Express Ambulance Inc. D/B/A Medex Ambulance (Healthcare Provider, IL) reported a HIPAA breach affecting 121,190 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

United Seating and Mobility, L.L.C., d/b/a Numotion

United Seating and Mobility, L.L.C., d/b/a Numotion (Healthcare Provider, TN) reported a HIPAA breach affecting 602,265 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Kootenai Health

Kootenai Health (Healthcare Provider, ID) reported a HIPAA breach affecting 464,088 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

NorthBay Healthcare Corporation

NorthBay Healthcare Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 569,012 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Delta Health System

Delta Health System (Healthcare Provider, MS) reported a HIPAA breach affecting 216,532 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
NYSettlementMultistate

Morgan Stanley Smith Barney LLC(Morgan Stanley)

Morgan Stanley failed to properly decommission computer devices containing unencrypted customer data, leading to the sale of devices with personal information at auction and missing servers with potential data. A multistate coalition secured a $6.5 million settlement requiring Morgan Stanley to implement enhanced data security measures.

HighSecurity FailureData Breach

$6.5M

NJSettlementMultistate

Morgan Stanley Smith Barney, LLC(Morgan Stanley)

New Jersey Attorney General Matthew Platkin announced a multistate settlement where Morgan Stanley will pay $1.27 million to NJ over data security incidents that compromised personal information of over 755,000 NJ residents and millions nationwide. The incidents involved improper decommissioning of devices and a software flaw, leading to unauthorized access. The settlement requires Morgan Stanley to strengthen its data security and disposal procedures.

HighSecurity FailureData Breach

$1.3M

FTCConsent Decree

Ring LLC(Ring)

The FTC charged Ring LLC with allowing employees to access private customer videos without consent and failing to secure user accounts, leading to hackers controlling cameras. Under a proposed consent order, Ring must pay $5.8 million in refunds, delete unlawfully accessed data, and implement a privacy and security program.

HighConsent FailureNotice FailureSecurity Failure

$5.8M

NJSettlementMultistate

EyeMed Vision Care

EyeMed Vision Care suffered a data breach in June 2020 due to poor security practices, including shared passwords, exposing personal and medical information of approximately 2.1 million individuals. The multistate settlement imposes a $2.5 million penalty and requires EyeMed to implement enhanced security measures and comply with privacy laws.

HighData BreachSecurity FailureHealth Data

$2.5M

NJSettlementMultistate

Wawa Inc.(Wawa)

Wawa Inc. agreed to pay $8 million to resolve a multistate investigation into a data breach that compromised approximately 34 million payment cards between April 2019 and December 2019. The breach involved malware that harvested card data from point-of-sale terminals. New Jersey will receive $2.5 million, and Wawa must implement enhanced cybersecurity measures including a comprehensive security program and third-party audits.

HighData BreachSecurity Failure

$8.0M

CTSettlementMultistate

Carnival Cruise Line

Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.

HighData BreachSecurity FailureBreach Notification Delay

$1.3M

NJSettlementMultistate

Carnival Cruise Line(Carnival)

New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.

HighData BreachSecurity FailureBreach Notification Delay

$1.3M

NJSettlementMultistate

Sabre Corp.(Sabre)

New Jersey participated in a multi-state settlement resolving an investigation into a 2017 data breach at Sabre Hospitality Solutions. Intruders accessed the company's hotel booking system from August 2016 to March 2017, compromising data from over 1.3 million consumer credit cards, including CVV numbers and expiration dates. Sabre failed to promptly notify affected consumers. The $2.4 million settlement requires Sabre to implement enhanced data security measures, develop a breach notification plan, clarify contractual responsibilities with client hotels, and undergo third-party security assessments.

HighData BreachBreach Notification Delay

$2.4M

NJSettlementMultistate

CafePress

New Jersey joined a multistate $2 million settlement with online retailer CafePress over a 2019 data breach that exposed personal information of approximately 22 million consumers nationwide, including over 540,000 in New Jersey. The settlement requires CafePress to implement a comprehensive cybersecurity program, incident response plan, and third-party assessments for five years, with payment suspended pending compliance.

HighData BreachSecurity Failure

$2.0M

NJSettlementMultistate

CHS/Community Health Systems, Inc.(Community Health Systems)

New Jersey Attorney General settled with Community Health Systems, Inc. over a 2014 data breach affecting 6.1 million patients, including over 45,000 New Jersey residents. CHS will pay $5 million to 28 states and implement enhanced data security measures to protect personal and health information.

HighSecurity FailureData BreachHealth Data

$5.0M

CASettlementMultistate

Anthem, Inc.(Anthem)

Anthem, Inc. settled with California for $8.69 million over a 2014 data breach that exposed personal information of 78 million consumers, including 13.5 million Californians. The breach resulted from security deficiencies, and the settlement includes injunctive relief to improve information security practices. This action was part of a parallel multistate settlement.

HighData BreachSecurity FailureHealth Data

$8.7M

CASettlementMultistate

Premera Blue Cross(Premera)

Premera Blue Cross suffered a data breach in 2014 that exposed personal and medical information of 10.5 million consumers. As part of a multistate settlement, Premera agreed to pay $10 million in civil penalties and implement security improvements and a compliance program. California will receive over $1 million from the settlement.

HighData BreachHealth DataSecurity Failure

$10.0M

NJSettlementMultistate

Neiman Marcus

Neiman Marcus settled a multi-state investigation over a 2013 data breach that compromised payment card data of approximately 370,000 consumers nationwide, including 17,000 in New Jersey. The company agreed to pay $1.5 million and implement enhanced cybersecurity measures such as PCI compliance, network monitoring, and regular security assessments.

HighData BreachSecurity Failure

$1.5M

NJInvestigation

Facebook(Meta)

The New Jersey Attorney General announced an investigation into how the personal information of millions of Facebook users was harvested and obtained by Cambridge Analytica, a UK-based data analytics company. The AG expressed concern that Facebook may have allowed the harvesting and monetization of user data despite promises to keep it secure.

HighData BreachUnauthorized Data Sharing
NJSettlementMultistate

Nationwide Insurance(Nationwide)

Nationwide Insurance settled a multi-state investigation into a 2012 data breach that exposed personal information of 1.27 million consumers due to failure to apply a security patch. The settlement requires enhanced security practices, hiring a Technology Officer, and a $5.5 million payment to the states.

HighSecurity FailureData Breach

$5.5M

Explore Enforcement Data