Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
VASettlementMultistate

23andMe, Inc.

Virginia Attorney General Jay Jones joined a coalition of 42 state attorneys general in a multistate settlement with 23andMe over a 2023 data breach that exposed the genetic data of approximately 6.9 million customers. The settlement requires 23andMe to pay $18 million to the states and $46.75 million to affected consumers, resolving allegations of inadequate security practices and delayed breach notification.

CriticalData BreachSecurity FailureHealth Data

$18.0M

VASettlementMultistate

23andMe

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

MediumData BreachSecurity FailureHealth Data

$663K

TXSettlementMultistate

23andMe

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

CriticalData BreachSecurity FailureBreach Notification Delay

$150.0M

CTSettlementMultistate

23andMe

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

HighData BreachSecurity FailureHealth Data

$18.0M

ORSettlementMultistate

23andMe

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureHealth Data

$18.0M

MNSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureBreach Notification Delay

$18.0M

NYEnforcement Action

3M Company

New York Attorney General Letitia James sued 3M, DuPont, and other chemical companies for knowingly causing decades of PFAS pollution through consumer products. The lawsuit alleges the companies hid toxicity risks, failed to warn the public, and seeks cleanup funding, damages, and injunctive relief.

LowNotice FailureConsent FailureHealth Data
MNSettlementMultistate

CVS Pharmacy, Inc.

Minnesota AG Ellison and a coalition of 37 AGs and the federal government reached a $36.5 million settlement with CVS Pharmacy, Inc. for allegedly submitting false Medicaid claims related to insulin pens from 2010-2020. CVS overbilled government healthcare programs by requesting reimbursement for ineligible refills and under-reporting days of supply.

CriticalHealth Data

$36.5M

NJAdministrative Order

Woodbury Family Pharmacy

The New Jersey State Board of Pharmacy temporarily suspended the license of pharmacist Nittal K. Lodha and the permit of Woodbury Family Pharmacy for allegedly practicing unsafely, maintaining unsanitary conditions, and interfering with patients' rights to transfer prescriptions to other pharmacies. The suspension was ratified on June 24, 2026.

LowHealth Data
FTCEnforcement Action

Amare Global Holdings

The FTC filed a contempt motion against Amare Global Holdings, Shawn Talbott, Patrick Hintze, and Hiep Tran for allegedly violating a 2005 FTC order that prohibited Talbott from making unsubstantiated health claims. The motion alleges that the defendants marketed dietary supplements for children and adults with false claims about treating depression, anxiety, and ADHD, and misrepresented scientific evidence. The FTC seeks compensatory damages for consumers.

LowConsent FailureHealth Data
FTCSettlement

Illuminate Education Inc.

The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.

LowSecurity FailureData BreachChildren's Data
FTCEnforcement Action

Amare Global Holdings Inc.

The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.

LowConsent FailureHealth DataChildren's Data
CAGuidance

U.S. Department of Health and Human Services(Department of Health and Human Services)

California Attorney General Rob Bonta sent a letter to the U.S. Department of Health and Human Services opposing a proposed rule that would eliminate model card requirements for AI tools in healthcare, warning that such rollbacks could lead to biased and unsafe healthcare decisions by reducing transparency.

LowAI/Automated DecisionsHealth Data
HHSEnforcement Action

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

QualDerm Partners, LLC

QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Center for Advanced Eye Care

The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Option Care Health, Inc.

Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

VNS Behavioral Health Inc. (“VNS Health”)

VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Emanuel Medical Center

Emanuel Medical Center (Healthcare Provider, GA) reported a HIPAA breach affecting 28,963 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

44North

44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Easterseals Northeast Indiana

Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wee Care Pediatrics, LLC

Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

National Association on Drug Abuse Problems

National Association on Drug Abuse Problems (Healthcare Provider, NY) reported a HIPAA breach affecting 90,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cedar Valley Services

Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Academic Urology & Urogynecology of Arizona

Academic Urology & Urogynecology of Arizona (Healthcare Provider, AZ) reported a HIPAA breach affecting 73,281 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data