Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Gaylord Hospital, Inc

Gaylord Hospital, Inc (Healthcare Provider, CT) reported a HIPAA breach affecting 62,232 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

CEI Vision Partners, LLC

CEI Vision Partners, LLC (Business Associate, MO) reported a HIPAA breach affecting 10,841 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Total Medical Imaging

Total Medical Imaging (Healthcare Provider, FL) reported a HIPAA breach affecting 27,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Carolina Arthritis Associates

Carolina Arthritis Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 36,961 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Lake Washington Vascular

Lake Washington Vascular (Healthcare Provider, WA) reported a HIPAA breach affecting 21,534 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Somnia, Inc.

Somnia, Inc. (Business Associate, NY) reported a HIPAA breach affecting 19,069 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Restorix Health, Inc.

Restorix Health, Inc. (Business Associate, LA) reported a HIPAA breach affecting 38,553 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

UNITED BACKCARE PS dba Pacific Rehabilitation Centers

UNITED BACKCARE PS dba Pacific Rehabilitation Centers (Healthcare Provider, WA) reported a HIPAA breach affecting 18,900 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

St. Marys NDS LLC

St. Marys NDS LLC (Business Associate, AZ) reported a HIPAA breach affecting 11,715 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

U.S. HEALTHWORKS-SMMPP, L.C.

U.S. HEALTHWORKS-SMMPP, L.C. (Business Associate, AZ) reported a HIPAA breach affecting 10,673 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Primary Health-SMMPP, L.C.

Primary Health-SMMPP, L.C. (Business Associate, AZ) reported a HIPAA breach affecting 67,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Primary Health Services Center, Inc.

Primary Health Services Center, Inc. (Healthcare Provider, LA) reported a HIPAA breach affecting 17,202 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mental Health Association Inc.

Mental Health Association Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 12,633 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
NYSettlement

Fantasia Trading LLC, Power Mobile Life LLC, and Smart Innovation, LLC(eufy)

New York Attorney General Letitia James secured a $450,000 settlement from three companies distributing eufy-branded home security cameras for failing to implement adequate data security measures. The companies’ cameras had unencrypted video streams accessible without authentication, exposing private consumer footage. The settlement requires the companies to implement stronger security protocols, including encryption, vulnerability testing, and a comprehensive information security program.

MediumSecurity Failure

$450K

HHSEnforcement Action

Behavioral Health Resources

Behavioral Health Resources (Healthcare Provider, WA) reported a HIPAA breach affecting 49,213 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alpine Ears, Nose & Throat, P.L.L.C.

Alpine Ears, Nose & Throat, P.L.L.C. (Healthcare Provider, CO) reported a HIPAA breach affecting 65,648 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
NYSettlement

Equifax Information Services, LLC(Equifax)

New York Attorney General Letitia James announced a settlement with Equifax Information Services, LLC for inaccurately reporting credit scores to lenders due to a coding error, which lowered consumers' scores and inflated costs for loans and insurance between March and April 2022. Equifax will pay $725,000 and implement safeguards to prevent future errors, with restitution for affected consumers.

MediumData Broker Non-Compliance

$725K

CTSettlement

Carvana

Connecticut Attorney General William Tong announced a $1.5 million settlement with Carvana to resolve hundreds of consumer complaints about delays in title and registration, delayed payments to sellers, and deceptive vehicle representations. The settlement includes a $1 million restitution fund for affected consumers and a $500,000 penalty to the state, with $250,000 suspended if Carvana complies. Carvana must comply with Connecticut laws and improve customer service.

Medium

$500K

HHSEnforcement Action

Pediatric Home Respiratory Services, LLC d/b/a Pediatric Home Service

Pediatric Home Respiratory Services, LLC d/b/a Pediatric Home Service (Healthcare Provider, MN) reported a HIPAA breach affecting 41,792 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Buffalo Surgery Center

Buffalo Surgery Center (Healthcare Provider, NY) reported a HIPAA breach affecting 64,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Plastic Surgery Center

The Plastic Surgery Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 64,813 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Watsonville Community Hospital

Watsonville Community Hospital (Healthcare Provider, CA) reported a HIPAA breach affecting 30,312 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Legacy Treatment Services, Inc.

Legacy Treatment Services, Inc. (Healthcare Provider, NJ) reported a HIPAA breach affecting 29,898 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CPPASettlement

PayDae, Inc. (d/b/a Infillion) and The Data Group, LLC(Infillion and The Data Group)

The California Privacy Protection Agency (CPPA) settled with two data brokers, Infillion and The Data Group, for failing to register and pay annual fees as required by the Delete Act. Infillion paid $54,200 and The Data Group paid $46,600, and both agreed to injunctive terms. This is part of a broader enforcement effort against non-compliant data brokers.

MediumData Broker Non-Compliance

$101K

NYConsent Decree

Noblr

New York Attorney General Letitia James settled with auto insurance company Noblr for $500,000 over a data breach that exposed personal information of approximately 80,000 New York residents. The breach, discovered in January 2021, was caused by Noblr’s failure to implement reasonable data security safeguards, including exposing plaintext driver’s license numbers and failing to monitor site traffic for malicious activity. In addition to the monetary penalty, Noblr must enhance its data security program, implement monitoring systems, and maintain a data inventory of private information.

MediumData BreachSecurity Failure

$500K

HHSEnforcement Action

PracticeSuite, Inc.

PracticeSuite, Inc. (Business Associate, FL) reported a HIPAA breach affecting 13,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Teton Orthopaedics

Teton Orthopaedics (Healthcare Provider, PA) reported a HIPAA breach affecting 13,409 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

River Region Cardiology

River Region Cardiology (Healthcare Provider, AL) reported a HIPAA breach affecting 48,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Community Connections

Community Connections (Healthcare Provider, DC) reported a HIPAA breach affecting 18,949 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NYSettlement

HealthAlliance

New York Attorney General Letitia James secured a $550,000 settlement from Hudson Valley health care operator HealthAlliance over a 2023 data breach that compromised the personal and medical information of 242,641 New Yorkers. The breach occurred after HealthAlliance failed to patch a known vulnerability in its web application system, allowing cyberattackers to exfiltrate patient and employee data. As part of the settlement, HealthAlliance must pay the penalty and implement enhanced cybersecurity measures including a comprehensive security program, patch management policy, and data inventory requirements.

MediumData BreachSecurity FailureHealth Data

$550K

Explore Enforcement Data