Court Rules

Privacy Enforcement Tracker

1,640 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,640

Total Actions

16

Jurisdictions

$50.0B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Delta County Memorial Hospital District (Delta Health)

Delta County Memorial Hospital District (Delta Health) (Healthcare Provider, CO) reported a HIPAA breach affecting 148,363 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

United of Omaha Life Insurance Company

United of Omaha Life Insurance Company (Health Plan, NE) reported a HIPAA breach affecting 107,894 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Surgery Center of Mid Florida

Surgery Center of Mid Florida (Healthcare Provider, FL) reported a HIPAA breach affecting 48,684 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sutton Dental Arts

Sutton Dental Arts (Healthcare Provider, OR) reported a HIPAA breach affecting 4,109 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

EMS Department for the Kansas City, Kansas Fire Department

EMS Department for the Kansas City, Kansas Fire Department (Healthcare Provider, KS) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sun City Pediatrics, PA

Sun City Pediatrics, PA (Healthcare Provider, TX) reported a HIPAA breach affecting 4,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Change Healthcare, Inc.

Change Healthcare, Inc. (Business Associate, MN) reported a HIPAA breach affecting 192,700,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Counseling of Bristol County, Inc.

Community Counseling of Bristol County, Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 44,991 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Fairfax Radiological Consultants

Fairfax Radiological Consultants (Healthcare Provider, VA) reported a HIPAA breach affecting 3,512 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

Change Healthcare

Connecticut Attorney General William Tong urged residents to enroll in free credit monitoring and identity theft protection following the Change Healthcare cyberattack in February 2024, which exposed sensitive health data. The breach potentially impacted up to one-third of Americans, but Change Healthcare has failed to provide individual notice to affected consumers. The AG joined other attorneys general in April 2024 to demand that UnitedHealth Group take more meaningful action to protect those harmed.

LowHealth DataData BreachBreach Notification Delay
FTCConsent Decree

NGL Labs, LLC(NGL Labs)

NGL Labs, LLC and its founders were sued by the FTC and Los Angeles DA for marketing an anonymous messaging app to children and teens, making false claims about AI content moderation, sending fake messages to boost engagement, and violating COPPA by collecting kids' data without parental consent. They must pay $5 million, with $500,000 as a civil penalty and $4.5 million for consumer redress, and are banned from offering the app to users under 18. The order requires age gates, data deletion, and prohibits false claims about AI and recurring charges.

MediumChildren's Data

$500K

HHSEnforcement Action

School Employees' Benefit Trust

School Employees' Benefit Trust (Health Plan, IN) reported a HIPAA breach affecting 1,371 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Palomar Health Medical Group

Palomar Health Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 1,140,221 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Ascension Health

Ascension Health (Healthcare Provider, MO) reported a HIPAA breach affecting 5,466,931 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Atlanta Perinatal Consultants, LLP

Atlanta Perinatal Consultants, LLP (Healthcare Provider, GA) reported a HIPAA breach affecting 1,508 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CASettlement

Tilting Point Media LLC

California Attorney General Rob Bonta and Los Angeles City Attorney Hydee Feldstein Soto announced a $500,000 settlement with Tilting Point Media LLC over allegations that the company violated COPPA and the CCPA by illegally collecting and sharing children’s personal data without parental consent via its 'SpongeBob: Krusty Cook-Off' mobile game. The settlement requires Tilting Point to pay $500,000 in civil penalties and comply with injunctive terms including implementing neutral age screens, obtaining parental consent for children’s data collection/sharing, and maintaining an SDK governance framework. Tilting Point must also submit annual compliance reports to the California DOJ and LA City Attorney’s Office.

MediumChildren's DataConsent FailureNotice Failure

$500K

HHSEnforcement Action

Regional Obstetrical Consultants PC

Regional Obstetrical Consultants PC (Healthcare Provider, TN) reported a HIPAA breach affecting 25,650 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
FTCSettlement

NGL

The FTC settled with NGL for deceptively marketing its anonymous messaging app to children and teens, using fake messages to trick users into paid subscriptions without proper consent. The order banned marketing to users under 18 and required $4.5 million in refunds for unauthorized charges.

HighChildren's DataConsent Failure

$4.5M

HHSEnforcement Action

Georgia Kidney Associates, Inc.

Georgia Kidney Associates, Inc. (Healthcare Provider, GA) reported a HIPAA breach affecting 9,940 individuals. Breach type: Theft. Location of breached information: Other.

LowData BreachHealth Data
FTCConsent Decree

Avast Limited(Avast)

The FTC finalized an order against Avast for selling consumers' web browsing data for advertising after promising privacy protection. Avast must pay $16.5 million, is banned from selling such data, must delete collected data, obtain consent, notify consumers, and implement a privacy program.

CriticalNotice FailureConsent Failure

$16.5M

HHSEnforcement Action

The Lash Group, LLC

The Lash Group, LLC (Business Associate, PA) reported a HIPAA breach affecting 15,196 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Geisinger

Geisinger (Healthcare Provider, PA) reported a HIPAA breach affecting 1,276,026 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

CriticalData BreachHealth DataUnauthorized Data Sharing
CASettlement

Tilting Point Media LLC(Tilting Point Media)

Tilting Point Media LLC illegally collected and shared children's personal data in its mobile app game 'SpongeBob: Krusty Cook-Off' without parental consent, violating COPPA and CCPA. The settlement imposes a $500,000 civil penalty and injunctive terms to ensure compliance with children's data privacy laws.

MediumChildren's DataConsent FailureUnauthorized Data Sharing

$500K

TXWarning Letter

data brokers(Data Brokers)

Texas Attorney General Ken Paxton issued warning letters to over 100 data brokers for failing to register with the Texas Secretary of State as required by the Texas Data Broker Law. The law, which took effect March 1, 2024, mandates that data brokers register and implement data protection safeguards. This enforcement action is part of a new initiative to protect Texans' privacy.

LowData Broker Non-Compliance
TXWarning Letter

Multiple Unnamed Data Broker Companies

Texas Attorney General Ken Paxton issued warning letters to over 100 companies informing them of their apparent failure to register as data brokers with the Texas Secretary of State by the March 1, 2024 deadline required by Chapter 509 of the Texas Business and Commerce Code. The notification follows the establishment of a specialized privacy enforcement team within the AG’s Consumer Protection Division to enforce Texas privacy laws. The letters alert companies to potential penalties for noncompliance with registration and data safeguard requirements under Texas’s Data Broker Law.

LowData Broker Non-Compliance
TXWarning Letter

Multiple Data Brokers(Data Brokers)

Texas Attorney General Ken Paxton sent notification letters to over 100 companies for failing to register as data brokers under Texas Business and Commerce Code Chapter 509, which requires registration by March 1, 2024, and implementation of data safeguards. This action is part of an initiative to enforce privacy laws and protect consumer data.

LowData Broker Non-Compliance
HHSEnforcement Action

Neurobehavioral Medicine Consultants, P.C.

Neurobehavioral Medicine Consultants, P.C. (Healthcare Provider, OH) reported a HIPAA breach affecting 18,182 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CASettlement

Blackbaud

California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

HighData BreachSecurity FailureBreach Notification Delay

$6.8M

HHSEnforcement Action

ASBESTOS WORKERS LOCAL 42 WELFARE PLAN

ASBESTOS WORKERS LOCAL 42 WELFARE PLAN (Health Plan, GA) reported a HIPAA breach affecting 520 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

IBEW LOCAL 236 WELFARE FUND

IBEW LOCAL 236 WELFARE FUND (Health Plan, CT) reported a HIPAA breach affecting 3,217 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data