Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCSettlement

Paddle

The FTC entered into a settlement with U.K.-based payment processor Paddle to resolve allegations that its unfair payment processing practices facilitated tech support scammers operating in Cyprus. Paddle agreed to pay a $5 million monetary penalty as part of the settlement.

High

$5.0M

HHSEnforcement Action

Harbin Clinic, LLC

Harbin Clinic, LLC (Healthcare Provider, GA) reported a HIPAA breach affecting 176,149 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTEnforcement Action

Planet Zaza of East Haven(Planet Zaza)

Attorney General William Tong obtained a $4.93 million judgment against Planet Zaza of East Haven and its owner for persistent illegal cannabis sales in violation of a court order. The court imposed penalties of $5,000 per day for each day of violation and $25,000 per day for violating the temporary injunction, totaling $4.93 million.

High

$4.9M

HHSEnforcement Action

Ascension Health

Ascension Health (Healthcare Provider, MO) reported a HIPAA breach affecting 437,329 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Onsite Mammography

Onsite Mammography (Business Associate, MA) reported a HIPAA breach affecting 357,265 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

The City of Long Beach, CA

The City of Long Beach, CA (Healthcare Provider, CA) reported a HIPAA breach affecting 258,191 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Bell Ambulance, Inc.

Bell Ambulance, Inc. (Healthcare Provider, WI) reported a HIPAA breach affecting 237,830 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Endue Software

Endue Software (Business Associate, ME) reported a HIPAA breach affecting 118,028 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Kelly & Associates Insurance Group, Inc.

Kelly & Associates Insurance Group, Inc. (Business Associate, MD) reported a HIPAA breach affecting 553,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alabama Ophthalmology Associates

Alabama Ophthalmology Associates (Healthcare Provider, AL) reported a HIPAA breach affecting 131,576 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Dameron Hospital

Dameron Hospital (Healthcare Provider, CA) reported a HIPAA breach affecting 210,706 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Frederick Health

Frederick Health (Healthcare Provider, MD) reported a HIPAA breach affecting 934,326 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Dental Care, Inc.

Community Dental Care, Inc. (Healthcare Provider, MN) reported a HIPAA breach affecting 134,903 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners

CDHA Management, LLC and Spark DSO, LLC dba Chord Specialty Dental Partners (Healthcare Provider, TN) reported a HIPAA breach affecting 173,430 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Liberty Resources, Inc.

Liberty Resources, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 103,711 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Hillcrest Convalescent Center, Inc.

Hillcrest Convalescent Center, Inc. (Healthcare Provider, NC) reported a HIPAA breach affecting 106,194 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Care Alliance

Community Care Alliance (Healthcare Provider, RI) reported a HIPAA breach affecting 114,975 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTSettlement

Stone Academy

Connecticut Attorney General William Tong announced a $5 million settlement with Stone Academy and its owners for unfair and deceptive conduct. The defunct for-profit nursing school misrepresented its programs and failed to provide promised education, abruptly closing in February 2023. The settlement provides cash compensation to harmed students and bars the owners from higher education employment.

High

$5.0M

NYEnforcement ActionMultistate

Elon Musk and DOGE(DOGE)

New York Attorney General Letitia James led a multistate lawsuit against Elon Musk and his Department of Government Efficiency (DOGE) for gaining unauthorized access to the U.S. Treasury's payment system, which contains Americans' sensitive personal data and controls vital funding. A federal judge granted a temporary restraining order blocking DOGE from accessing this data and requiring the destruction of any records already obtained, with a preliminary injunction hearing set for February 14, 2025.

HighUnauthorized Data Sharing
NJEnforcement ActionMultistate

U.S. Department of Treasury(U.S. Treasury)

New Jersey Attorney General Matthew J. Platkin joined a coalition of 19 attorneys general in filing a lawsuit against the Trump administration for illegally granting Elon Musk and DOGE unauthorized access to the U.S. Treasury Department's central payment system, which contains sensitive personal information such as Social Security numbers and bank details. The lawsuit seeks an injunction to halt this policy and a declaration that it is unlawful and unconstitutional.

HighSecurity Failure
HHSEnforcement Action

Blue & Co., LLC

Blue & Co., LLC (Business Associate, IN) reported a HIPAA breach affecting 228,999 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

VectraRx Mail Pharmacy Services, LLC

VectraRx Mail Pharmacy Services, LLC (Healthcare Provider, AZ) reported a HIPAA breach affecting 109,383 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Escambia Community Clinics, Inc. dba Community Health Northwest Florida

Escambia Community Clinics, Inc. dba Community Health Northwest Florida (Healthcare Provider, FL) reported a HIPAA breach affecting 143,969 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

University Diagnostic Medical Imaging, PC

University Diagnostic Medical Imaging, PC (Healthcare Provider, NY) reported a HIPAA breach affecting 138,080 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Asheville Eye Associates, PLLC

Asheville Eye Associates, PLLC (Healthcare Provider, NC) reported a HIPAA breach affecting 204,984 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Allegheny Health Network Home Medical Equipment LLC and Allegheny Health Network Home Infusion LLC

Allegheny Health Network Home Medical Equipment LLC and Allegheny Health Network Home Infusion LLC (Healthcare Provider, PA) reported a HIPAA breach affecting 292,773 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
FTCConsent Decree

General Motors LLC, General Motors Holdings LLC, and OnStar LLC(General Motors)

The FTC alleged that General Motors and its OnStar subsidiary collected and sold drivers' precise geolocation and driving behavior data (e.g., hard braking, speeding) to consumer reporting agencies without adequately notifying consumers or obtaining their affirmative consent. A proposed consent order bans the companies from disclosing this sensitive data to consumer reporting agencies for five years and requires them to implement clearer consent mechanisms, data access/deletion processes, and opt-out options.

HighGeolocation DataConsent FailureUnauthorized Data Sharing
HHSEnforcement Action

Mid America Physician Services

Mid America Physician Services (Healthcare Provider, KS) reported a HIPAA breach affecting 104,513 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Newport Harbor Pathology Medical Group, Inc.

Newport Harbor Pathology Medical Group, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 119,341 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CTSettlement

Stone Academy

Connecticut Attorney General William Tong announced a $5 million preliminary settlement with Stone Academy and its owners for unfair and deceptive conduct. The for-profit nursing school failed to deliver promised education, lacking textbooks, experienced teachers, and clinical training, and abruptly closed in February 2023. The settlement provides cash payments to harmed students, bars the owner from higher education employment for five years, and includes measures to help students complete their education.

HighNotice FailureConsent Failure

$5.0M

Explore Enforcement Data