Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Communications Workers of America Local 1180 Security Benefits Fund

Communications Workers of America Local 1180 Security Benefits Fund (Health Plan, NY) reported a HIPAA breach affecting 18,550 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”)

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) (Healthcare Provider, FL) reported a HIPAA breach affecting 13,230 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

North Shore University Hospital Sleep Disorders Center

North Shore University Hospital Sleep Disorders Center (Healthcare Provider, NY) reported a HIPAA breach affecting 13,332 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Blue Cross and Blue Shield of Texas

Blue Cross and Blue Shield of Texas (Health Plan, IL) reported a HIPAA breach affecting 12,086 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Gardner Health Services

Gardner Health Services (Healthcare Provider, CA) reported a HIPAA breach affecting 26,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

MediumData BreachHealth DataUnauthorized Data Sharing
CPPASettlement

American Honda Motor Co.(Honda)

The California Privacy Protection Agency settled with American Honda Motor Co. for CCPA violations, including making it difficult for consumers to opt-out of data sharing, using dark patterns in its privacy tool, hindering authorized agent requests, and sharing data with ad tech companies without proper contracts. Honda must pay a $632,500 fine, implement new processes for privacy requests, certify compliance, train employees, and ensure appropriate data sharing contracts.

MediumOpt-Out FailureDark PatternsConsent Failure

$633K

HHSEnforcement Action

Total Medical Imaging

Total Medical Imaging (Healthcare Provider, FL) reported a HIPAA breach affecting 27,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Restorix Health, Inc.

Restorix Health, Inc. (Business Associate, LA) reported a HIPAA breach affecting 38,553 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Mental Health Association Inc.

Mental Health Association Inc. (Healthcare Provider, MA) reported a HIPAA breach affecting 12,633 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Alpine Ears, Nose & Throat, P.L.L.C.

Alpine Ears, Nose & Throat, P.L.L.C. (Healthcare Provider, CO) reported a HIPAA breach affecting 65,648 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

AuthoraCare Collective

AuthoraCare Collective (Healthcare Provider, NC) reported a HIPAA breach affecting 57,944 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Contents Trader, Inc.

Contents Trader, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 27,329 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Pemiscot Memorial Health System

Pemiscot Memorial Health System (Healthcare Provider, MO) reported a HIPAA breach affecting 33,279 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataUnauthorized Data Sharing
CASettlement

Tilting Point Media LLC(Tilting Point Media)

Tilting Point Media LLC illegally collected and shared children's personal data in its mobile app game 'SpongeBob: Krusty Cook-Off' without parental consent, violating COPPA and CCPA. The settlement imposes a $500,000 civil penalty and injunctive terms to ensure compliance with children's data privacy laws.

MediumChildren's DataConsent FailureUnauthorized Data Sharing

$500K

HHSEnforcement Action

Insurance ACE/Humana Inc.

Insurance ACE/Humana Inc. (Health Plan, KY) reported a HIPAA breach affecting 15,003 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Strive Holdco, LLC

Strive Holdco, LLC (Healthcare Provider, TX) reported a HIPAA breach affecting 51,477 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
NYSettlement

College Board

College Board licensed student data to third parties and used it for marketing without proper consent, violating New York law. The settlement requires College Board to pay $750,000 and prohibits future commercial use of student data from school-administered exams.

MediumUnauthorized Data SharingConsent FailureStudent Data

$750K

CTSettlementMultistate

Easy Healthcare Corporation(Easy Healthcare)

Connecticut, Oregon, and the District of Columbia reached a $100,000 settlement with Easy Healthcare Corporation, the operator of the Premom ovulation tracking app, for sharing sensitive user health and location data with third parties without appropriate disclosures or user consent. The settlement requires the company to implement comprehensive privacy and security programs, obtain consent before sharing health or location data, and provide users with a method to delete their personal information.

MediumUnauthorized Data SharingNotice FailureHealth Data

$100K

FTCConsent DecreeMultistate

Easy Healthcare Corporation(Easy Healthcare)

The FTC charged Easy Healthcare Corporation, operator of the Premom fertility app, with deceiving users by sharing their sensitive health data with third parties for advertising without consent and failing to notify breaches as required by the Health Breach Notification Rule. Under a proposed consent decree, the company will pay a $100,000 civil penalty, be barred from sharing health data for advertising, and must implement privacy and security measures.

MediumUnauthorized Data SharingConsent FailureNotice Failure

$100K

NJSettlementMultistate

VIZIO

VIZIO and Inscape settled allegations that they collected viewing data from Smart TVs without adequate disclosure and consent, selling it to third parties. They agreed to pay $1 million to New Jersey, destroy collected data, and implement privacy measures including obtaining consumer consent and establishing a privacy program.

MediumNotice FailureConsent FailureUnauthorized Data Sharing

$1.0M

NJSettlement

Dataium

Dataium settled allegations that it used history sniffing to track consumers' online browsing without consent and sold personal data of 400,000 consumers to a data broker without notice. The settlement imposes a $400,000 monetary penalty, requires a privacy program, and mandates transparency and opt-out mechanisms.

MediumNotice FailureConsent FailureUnauthorized Data Sharing

$400K

Explore Enforcement Data