Court Rules

Privacy Enforcement Tracker

1,640 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,640

Total Actions

16

Jurisdictions

$50.0B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCSettlementMultistate

Grubhub

The FTC and the Illinois Attorney General took action against food delivery company Grubhub for deceptive earnings claims, blocking diners from accounts and funds, and unfairly listing restaurants without permission. The settlement required Grubhub to change its operations and provide over $23.8 million in refunds to 640,038 affected consumers.

LowConsent FailureNotice Failure
HHSEnforcement Action

Omaha Surgical Center

Omaha Surgical Center (Healthcare Provider, NE) reported a HIPAA breach affecting 1,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tycon Medical Systems, Inc.

Tycon Medical Systems, Inc. (Healthcare Provider, VA) reported a HIPAA breach affecting 112,847 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Dragonfly Health

Dragonfly Health (Business Associate, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Polaris Endeavors

Polaris Endeavors (Healthcare Provider, FL) reported a HIPAA breach affecting 4,552 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Khalil Foundation (DBA Khalil Center)

Khalil Foundation (DBA Khalil Center) (Healthcare Provider, IL) reported a HIPAA breach affecting 1,153 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
FTCConsent Decree

Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC(Marriott)

The FTC finalized an order against Marriott International and Starwood Hotels for failing to implement reasonable data security, which led to three data breaches affecting over 344 million customers. The companies must implement a comprehensive security program, delete unnecessary personal information, allow U.S. customers to request deletion, and restore stolen loyalty points. They are also prohibited from misrepresenting their data security practices.

LowSecurity Failure
HHSEnforcement Action

Effortless Office Enterprises, LLC

Effortless Office Enterprises, LLC (Business Associate, NV) reported a HIPAA breach affecting 3,112 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

HealthEquity, Inc.

HealthEquity, Inc. (Business Associate, UT) reported a HIPAA breach affecting 1,549 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Richmond University Medical Center

Richmond University Medical Center (Healthcare Provider, NY) reported a HIPAA breach affecting 674,033 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
NYConsent Decree

Noblr

New York Attorney General Letitia James settled with auto insurance company Noblr for $500,000 over a data breach that exposed personal information of approximately 80,000 New York residents. The breach, discovered in January 2021, was caused by Noblr’s failure to implement reasonable data security safeguards, including exposing plaintext driver’s license numbers and failing to monitor site traffic for malicious activity. In addition to the monetary penalty, Noblr must enhance its data security program, implement monitoring systems, and maintain a data inventory of private information.

MediumData BreachSecurity Failure

$500K

CPPASettlement

PayDae, Inc. (d/b/a Infillion) and The Data Group, LLC(Infillion and The Data Group)

The California Privacy Protection Agency (CPPA) settled with two data brokers, Infillion and The Data Group, for failing to register and pay annual fees as required by the Delete Act. Infillion paid $54,200 and The Data Group paid $46,600, and both agreed to injunctive terms. This is part of a broader enforcement effort against non-compliant data brokers.

MediumData Broker Non-Compliance

$101K

CPPASettlement

PayDae, Inc. (Infillion) and The Data Group, LLC(Infillion and Data Group)

The California Privacy Protection Agency (CPPA) settled with two data brokers, PayDae, Inc. (Infillion) and The Data Group, LLC, for failing to register as required by Senate Bill 362 (the Delete Act). Infillion paid $54,200 and The Data Group paid $46,600, and both agreed to injunctive terms to ensure future compliance with registration requirements.

LowData Broker Non-Compliance
HHSEnforcement Action

California Correctional Health Care Services

California Correctional Health Care Services (Healthcare Provider, CA) reported a HIPAA breach affecting 1,416 individuals. Breach type: Loss. Location of breached information: Paper/Films.

LowData BreachHealth Data
HHSEnforcement Action

Regional Care, Inc.

Regional Care, Inc. (Healthcare Clearing House, NE) reported a HIPAA breach affecting 225,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

PracticeSuite, Inc.

PracticeSuite, Inc. (Business Associate, FL) reported a HIPAA breach affecting 13,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Kitsap Mental Health Services

Kitsap Mental Health Services (Healthcare Provider, WA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Teton Orthopaedics

Teton Orthopaedics (Healthcare Provider, PA) reported a HIPAA breach affecting 13,409 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Summit Medical Group, PLLC

Summit Medical Group, PLLC (Healthcare Provider, TN) reported a HIPAA breach affecting 464,159 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
TXInvestigation

Character.AI, Reddit, Instagram, Discord, and 14 other companies

Texas Attorney General Ken Paxton launched investigations into Character.AI and 14 other companies, including Reddit, Instagram, and Discord, over potential violations of children’s privacy and safety laws. The investigations focus on compliance with the SCOPE Act and Texas Data Privacy and Security Act (TDPSA), which require parental consent for sharing minors’ data and mandate notice and consent requirements for children’s personal information. No fines or remedies have been imposed as the investigations are ongoing.

LowChildren's DataConsent FailureNotice Failure
CTEnforcement ActionMultistate

Firearms Industry

Connecticut Attorney General William Tong announced a multistate coalition of 16 attorneys general to use civil enforcement against irresponsible members of the firearms industry. The coalition will enforce state consumer protection and liability laws to reduce gun violence, with past actions including lawsuits against Glock for machine gun conversions and ghost gun dealers.

Low
HHSEnforcement Action

Northwest Asthma and Allergy Center

Northwest Asthma and Allergy Center (Healthcare Provider, WA) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
TXInvestigation

Character.AI

Texas Attorney General Ken Paxton has launched investigations into Character.AI and fourteen other companies, including Reddit, Instagram, and Discord, for potential violations of the SCOPE Act and TDPSA regarding children's privacy and safety. The investigations focus on unauthorized sharing of minors' data and lack of parental controls. No penalties have been imposed yet as the investigations are ongoing.

HighChildren's DataConsent FailureNotice Failure
TXInvestigation

Character.AI, Reddit, Instagram, Discord, and 11 other companies(Character.AI)

Texas Attorney General Ken Paxton announced investigations into 15 companies, including Character.AI, Reddit, Instagram, and Discord, for potential violations of the SCOPE Act and TDPSA concerning children's privacy. The investigations target practices such as unauthorized sharing of minors' personal data and failure to provide parental controls. This action is part of Texas's broader initiative to enforce data privacy laws.

LowChildren's DataConsent FailureNotice Failure
HHSEnforcement Action

El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare

El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare (Healthcare Provider, TX) reported a HIPAA breach affecting 1,854 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

River Region Cardiology

River Region Cardiology (Healthcare Provider, AL) reported a HIPAA breach affecting 48,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Connections

Community Connections (Healthcare Provider, DC) reported a HIPAA breach affecting 18,949 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NYSettlement

HealthAlliance

New York Attorney General Letitia James secured a $550,000 settlement from Hudson Valley health care operator HealthAlliance over a 2023 data breach that compromised the personal and medical information of 242,641 New Yorkers. The breach occurred after HealthAlliance failed to patch a known vulnerability in its web application system, allowing cyberattackers to exfiltrate patient and employee data. As part of the settlement, HealthAlliance must pay the penalty and implement enhanced cybersecurity measures including a comprehensive security program, patch management policy, and data inventory requirements.

MediumData BreachSecurity FailureHealth Data

$550K

FTCConsent Decree

Gravy Analytics Inc. and Venntel Inc.(Gravy Analytics)

The FTC took action against Gravy Analytics Inc. and Venntel Inc. for unlawfully tracking and selling sensitive consumer location data without consent. The proposed consent order prohibits the sale or use of sensitive location data, requires deletion of historic data, and mandates compliance programs. This is part of the FTC's series of actions against data brokers selling sensitive location data.

LowConsent FailureUnauthorized Data SharingGeolocation Data
HHSEnforcement Action

Atrium Health

Atrium Health (Healthcare Provider, NC) reported a HIPAA breach affecting 585,959 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

HighData BreachHealth DataUnauthorized Data Sharing

Explore Enforcement Data