1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Labcorp agreed to pay $2,287,455 and make security and vendor-management reforms following a 2019 breach of its debt collector AMCA that potentially exposed personal information of more than 27.5 million people, including Labcorp patients’ sensitive medical information. The settlement requires stronger security and incident response practices, limits on vendor data sharing, enhanced vendor oversight, contractual cybersecurity requirements, and an independent security assessment.
$2.3M
New York and a bipartisan coalition of 43 other attorneys general reached an agreement with Laboratory Corporation of America (Labcorp) following a 2019 breach at its debt-collection vendor, AMCA, that potentially exposed personal information of more than 27.5 million people. Labcorp will pay $2,287,455 to the states and implement extensive security and vendor-risk reforms.
$2.3M
Connecticut Attorney General William Tong led a 44-attorney-general coalition settlement with Laboratory Corporation of America over the 2019 AMCA breach, which potentially exposed personal information of more than 27.5 million people, including 10.2 million Labcorp patients. Labcorp will pay $2,287,455 and implement enhanced vendor-risk management, information-security, and oversight measures.
$2.3M
Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.
$2.3M
Connecticut Attorney General William Tong issued an advisory that newly enacted privacy laws take effect October 1, 2026, including Public Act 26-64 (SB4), which amends the Connecticut Data Privacy Act, and Public Act 26-15 (SB5), which established the Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act). The new laws regulate surveillance pricing, facial recognition technology, genetic data collected by direct-to-consumer testing companies, a ban on the sale of precise geolocation data, a data broker registry, AI use in employment decisions, and chatbots offered to children. No enforcement action was taken; this is prospective guidance alerting consumers and businesses to new rights and compliance requirements.
Connecticut Attorney General William Tong announced a civil investigative demand into MediaLab.AI Inc., owner of the Kik Messenger app, over lax age assurance practices, content moderation, and child safety failures that advocates have dubbed a "predator's paradise." The action follows a July 2025 notice of violation under the Connecticut Data Privacy Act for privacy notice deficiencies and processing sensitive data — including health, biometric, and precise geolocation data — without proper consent, which the company has only partially addressed. The new investigation seeks records related to practices that may constitute unfair or deceptive acts or practices under the CTDPA and the Connecticut Unfair Trade Practices Act. No fine has been imposed to date.
Texas Attorney General Ken Paxton opened an investigation into TriWest Healthcare Alliance Corp., the U.S. government contractor that administers the VA Community Care Network and the Defense Health Agency's TRICARE West Region, over reports that it wrongfully denied health care claims by falsely treating insureds as having other health insurance (OHI). The OAG has issued Civil Investigative Demands (CIDs) and plans to interview consumers and employees to determine whether TriWest violated the Texas Deceptive Trade Practices Act. No findings or penalties have been imposed yet.
Virginia Attorney General Jay Jones joined a coalition of 42 state attorneys general in a multistate settlement with 23andMe over a 2023 data breach that exposed the genetic data of approximately 6.9 million customers. The settlement requires 23andMe to pay $18 million to the states and $46.75 million to affected consumers, resolving allegations of inadequate security practices and delayed breach notification.
$18.0M
Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.
$663K
Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.
$150.0M
Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.
$18.0M
A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.
$18.0M
A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.
$18.0M
New York Attorney General Letitia James sued 3M, DuPont, and other chemical companies for knowingly causing decades of PFAS pollution through consumer products. The lawsuit alleges the companies hid toxicity risks, failed to warn the public, and seeks cleanup funding, damages, and injunctive relief.
Minnesota AG Ellison and a coalition of 37 AGs and the federal government reached a $36.5 million settlement with CVS Pharmacy, Inc. for allegedly submitting false Medicaid claims related to insulin pens from 2010-2020. CVS overbilled government healthcare programs by requesting reimbursement for ineligible refills and under-reporting days of supply.
$36.5M
The New Jersey State Board of Pharmacy temporarily suspended the license of pharmacist Nittal K. Lodha and the permit of Woodbury Family Pharmacy for allegedly practicing unsafely, maintaining unsanitary conditions, and interfering with patients' rights to transfer prescriptions to other pharmacies. The suspension was ratified on June 24, 2026.
The FTC filed a contempt motion against Amare Global Holdings, Shawn Talbott, Patrick Hintze, and Hiep Tran for allegedly violating a 2005 FTC order that prohibited Talbott from making unsubstantiated health claims. The motion alleges that the defendants marketed dietary supplements for children and adults with false claims about treating depression, anxiety, and ADHD, and misrepresented scientific evidence. The FTC seeks compensatory damages for consumers.
The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.
The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.
California Attorney General Rob Bonta sent a letter to the U.S. Department of Health and Human Services opposing a proposed rule that would eliminate model card requirements for AI tools in healthcare, warning that such rollbacks could lead to biased and unsafe healthcare decisions by reducing transparency.
BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.
Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.
Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
All data sourced from official government enforcement pages.