Court Rules

Healthcare Enforcement Actions

Privacy and consumer protection enforcement actions against healthcare companies.

830

Total Actions

$8.9B

Total Fines

TX

Tris Pharmaceuticals

Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.

$7.5M

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

$400.0M

CT

Sandoz Inc. and Fougera Pharmaceuticals Inc.

Connecticut Attorney General William Tong announced a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. resolving allegations that the generic drug manufacturers conspired to inflate prices, limit competition, and restrain trade. The settlement includes consumer restitution and injunctive reforms; court approval was being sought.

$400.0M

CO

Sandoz Inc. and Fougera Pharmaceuticals Inc.

Colorado joined a 43-state-and-territory settlement resolving allegations that Sandoz and Fougera participated in a long-running conspiracy to inflate generic drug prices, reduce competition, and restrain trade. The companies agreed to pay approximately $469 million and implement reforms; the states are seeking court approval.

$469.0M

CT

U.S. Department of Health and Human Services (HHS)

Connecticut Attorney General William Tong joined a coalition of 22 attorneys general and Pennsylvania’s governor in a letter urging HHS to keep federal vaccine recommendations grounded in scientific and medical evidence. The letter asks HHS to preserve the ACIP’s role and current vaccine recommendation categories; it is a policy advocacy action, not a privacy enforcement action.

NY

Laboratory Corporation of America (Labcorp)

Labcorp agreed to pay $2,287,455 and make security and vendor-management reforms following a 2019 breach of its debt collector AMCA that potentially exposed personal information of more than 27.5 million people, including Labcorp patients’ sensitive medical information. The settlement requires stronger security and incident response practices, limits on vendor data sharing, enhanced vendor oversight, contractual cybersecurity requirements, and an independent security assessment.

Data BreachSecurity FailureHealth Data

$2.3M

NY

Laboratory Corporation of America

New York and a bipartisan coalition of 43 other attorneys general reached an agreement with Laboratory Corporation of America (Labcorp) following a 2019 breach at its debt-collection vendor, AMCA, that potentially exposed personal information of more than 27.5 million people. Labcorp will pay $2,287,455 to the states and implement extensive security and vendor-risk reforms.

Data BreachSecurity FailureHealth Data

$2.3M

CT

Laboratory Corporation of America

Connecticut Attorney General William Tong led a 44-attorney-general coalition settlement with Laboratory Corporation of America over the 2019 AMCA breach, which potentially exposed personal information of more than 27.5 million people, including 10.2 million Labcorp patients. Labcorp will pay $2,287,455 and implement enhanced vendor-risk management, information-security, and oversight measures.

Data BreachSecurity FailureHealth Data

$2.3M

CO

Laboratory Corporation of America

Colorado and a bipartisan coalition of attorneys general reached a $2,287,455 settlement with Laboratory Corporation of America over the 2019 data breach at its debt collector, American Medical Collection Agency. The settlement requires stronger vendor risk management and information security practices, with particular requirements for medical debt collectors.

Data BreachSecurity Failure

$2.3M

NJ

Laboratory Corporation of America Holdings (LabCorp)

Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.

Data BreachSecurity FailureHealth Data

$2.3M

NY

Generic drug manufacturers, including Apotex, Heritage, Bausch, Lannett, and Glenmark Pharmaceuticals USA, Inc.

New York Attorney General Letitia James and a bipartisan multistate coalition secured more than $96 million in settlements with generic drug manufacturers accused of conspiring to raise prices and limit competition. The settlement proceeds are being distributed to eligible consumers, and settling defendants agreed to cooperate in ongoing cases and make reforms to prevent future misconduct.

$96.0M

CT

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

Connecticut and a coalition of 47 other states and territories announced preliminary court approval of a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to inflate drug prices. The release does not give the date of the court’s preliminary approval, so the event date reflects the press release date.

OR

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

Oregon and a multistate coalition announced a plan to distribute settlement funds to people who paid inflated prices for certain generic drugs. The release says a federal court granted preliminary approval of the distribution plan this month; it does not give the date of that approval, and the reported conduct concerns alleged antitrust violations rather than a privacy violation.

$96.5M

CT

Abbott Laboratories

Connecticut joined 39 other states and the federal government in a $384 million False Claims Act settlement with Abbott Laboratories over allegations that the company failed to manufacture powder infant formula and nutritional therapy products in compliance with federal and state requirements at its Sturgis, Michigan, and Casa Grande, Arizona facilities. Abbott allegedly manufactured formula in conditions that risked microorganism contamination and failed to disclose contamination test results to the FDA during 2019 and 2022 inspections. The settlement resolves claims that Abbott caused false claims to be submitted to the WIC program and state Medicaid programs between January 1, 2018, and December 31, 2022.

Security FailureNotice FailureRecord Retention

$384.2M

OR

Abbott Laboratories

Abbott Laboratories agreed to pay more than $384 million — including $977,558 to Oregon — to resolve allegations that it sold powder infant formula and nutritional therapy products made in unsafe manufacturing conditions to Medicaid and food assistance programs such as WIC between January 2018 and December 2022. Investigators found Abbott failed to maintain manufacturing equipment and control water at its Sturgis, Michigan, and Casa Grande, Arizona, facilities, and withheld test results showing contamination during FDA inspections in 2019 and 2022. The settlement was negotiated by the National Association of Medicaid Fraud Control Units on behalf of the federal government and 39 states.

Security FailureNotice Failure

$384.2M

MN

Omega Dental Care

Minnesota Attorney General Keith Ellison announced the first round of restitution, issuing 8 refund checks totaling $38,634 to consumers harmed by Omega Dental Care, a defunct Eden Prairie dental clinic owned and operated by Anne Soberay. The refunds, paid from the state's Consumer Protection Restitution Account (CPRA), compensate consumers who paid out of pocket for dental services that were never provided. The refunds follow an earlier settlement between the AG's office and Omega Dental Care and Soberay. Note: this is a consumer protection (non-delivery of services) action, not a privacy enforcement action; no privacy violation types from the taxonomy apply.

NJ

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

New Jersey and a coalition of states and territories obtained preliminary approval for a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to raise drug prices. The settlements total approximately $96.5 million, and eligible consumers may submit claims for compensation.

$96.5M

MN

Sanford Health and North Memorial Health

The Minnesota Attorney General entered into a 10-year oversight agreement with Sanford Health and North Memorial Health to allow their merger to proceed, conditioned on commitments to invest $600 million in Minnesota hospitals, maintain core services including the Level 1 trauma center at Robbinsdale Hospital, honor collective-bargaining agreements, and maintain charity care and government program participation. The agreement also requires quarterly meetings and annual reporting to the Attorney General for 10 years.

CO

U.S. Department of Health and Human Services

Attorney General Weiser joined a coalition of attorneys general in suing to block new unlawful conditions on Title X funding imposed by HHS, which would penalize states and providers that refuse to abandon nondiscrimination initiatives or conform to the administration's ideological vision of family planning. The lawsuit argues the conditions conflict with federal law, violate the Administrative Procedure Act, and are unconstitutionally vague.

CT

Anthem, ConnectiCare, and UnitedHealthcare

Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.

NY

Thirty Madison, Inc.

New York Attorney General Letitia James secured $400,000 from Thirty Madison, Inc., an online medication provider, for misleading consumers about auto-renewing subscriptions and making cancellation difficult. The company failed to clearly disclose subscription terms and non-refundable fees, and required multiple steps to cancel. The settlement requires payment, refunds to eligible subscribers, and changes to subscription practices.

Notice FailureConsent FailureDark Patterns

$400K

MN

Stevens Community Medical Center

Minnesota Attorney General Keith Ellison reached a settlement with Stevens Community Medical Center (SCMC) over allegations that SCMC improperly calculated discounts required for uninsured patients with household incomes under $125,000, violating the Minnesota Hospital Agreement and state law. As a result, some uninsured patients were billed up to 20.5% more than allowed. SCMC must provide up to $1,412,776.25 in refunds or medical-debt reductions to potentially eligible patients.

Notice Failure

$1.4M

TX

American Academy of Pediatrics

Texas Attorney General Ken Paxton launched an investigation into the American Academy of Pediatrics (AAP) over concerns that the organization may be promoting and recommending childhood vaccines for financial gain. The AAP has been issued a Civil Investigative Demand to determine the basis of its vaccine recommendations and whether they are influenced by financial incentives from pharmaceutical donors.

Notice Failure
NJ

Sandoz Inc.

Attorney General Jennifer Davenport joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations of widespread price-fixing and anticompetitive conduct in the generic drug market. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to internal reforms to ensure fair competition.

$400.0M

CT

Sandoz Inc.

Minnesota Attorney General Keith Ellison joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations that the generic drug manufacturer engaged in conspiracies to artificially inflate and manipulate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to injunctive terms and internal reforms.

$400.0M

CT

Sandoz Inc.

Attorney General Tong led a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations that the generic drug manufacturer engaged in conspiracies to artificially inflate and manipulate prices, reduce competition, and unreasonably restrain trade. Sandoz will pay approximately $469 million total and implement internal reforms to ensure fair competition and compliance with antitrust laws.

Consent Failure

$400.0M

CO

Sandoz Inc.

Attorney General Phil Weiser joined a coalition of 43 states and territories announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations that the generic drug manufacturer engaged in conspiracies to artificially inflate and manipulate prices, reduce competition, and unreasonably restrain trade. Sandoz will pay approximately $469 million including previous settlements and agreed to meaningful reforms to ensure fair competition and compliance with antitrust laws.

Unauthorized Data Sharing

$400.0M

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

Unauthorized Data SharingConsent FailureDark Patterns
MN

Allina Health

The Minnesota Attorney General is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review is conducted under Minnesota's health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest. No enforcement action has been taken; this is a public consultation.

CO

Glenmark Pharmaceuticals

Attorney General Phil Weiser joined a bipartisan coalition of 48 states and territories in announcing a $29.6 million settlement with Glenmark Pharmaceuticals. The settlement resolves allegations that Glenmark participated in a widespread conspiracy to inflate prices, reduce competition, and restrain trade for numerous generic prescription drugs. Glenmark also agreed to cooperate in ongoing multistate litigation and implement internal reforms.

Unauthorized Data Sharing

$29.6M

FTC

Vanilla Chip LLC

The FTC finalized a settlement with Vanilla Chip LLC (doing business as TruHeight) and its principals over allegations that they deceptively advertised height-enhancing supplements for children and teenagers without competent and reliable scientific evidence. The FTC also alleged that TruHeight used fake social media bot profiles and relied on reviews written by employees, vendors, or consumers who received free products or discounts for 5-star reviews. Under the final order, TruHeight must pay $750,000 and is barred from making unsupported health claims or misrepresenting reviews.

Notice Failure

$750K

MN

Omega Dental Care

Minnesota Attorney General Keith Ellison reached a settlement with Annelle Soberay and Omega Dental Care, a defunct dental clinic that shut down in late 2024 without providing advance notice or transitional care to patients. The settlement allows consumers to obtain refunds from the Consumer Protection Restitution Account for fees paid for services that were never provided.

Notice FailureConsent Failure
NJ

Woodbury Family Pharmacy

The New Jersey State Board of Pharmacy temporarily suspended the license of pharmacist Nittal K. Lodha and the permit of Woodbury Family Pharmacy for allegedly practicing unsafely, maintaining unsanitary conditions, and interfering with patients' rights to transfer prescriptions to other pharmacies. The suspension was ratified on June 24, 2026.

Health Data
FTC

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

Consent FailureNotice FailureChildren's Data
MN

Allina Health

The Minnesota Attorney General's Office is holding a community forum to gather public input on the proposed acquisition of Allina Health by Sutter Health. The review will assess compliance with state health care transaction law, charities law, and antitrust law to determine if the transaction is in the public interest.

CO

GS Labs

Colorado Attorney General Phil Weiser and a bipartisan coalition of 18 attorneys general announced a $4.87 million settlement with GS Labs, a former COVID-19 rapid testing business. The company was found to have violated the Colorado Consumer Protection Act by falsely advertising test results with no wait times, same day appointments, and no out-of-pocket expenses, while overcharging consumers and insurance providers.

Notice FailureConsent Failure

$4.9M

MN

GS Labs

Attorney General Ellison announced a $4.87 million multistate settlement with GS Labs for overcharging patients, charging unlawful administrative fees, and failing to deliver timely COVID-19 test results. The settlement includes $3.63 million in restitution to affected consumers and $1.25 million to the multistate group, along with injunctive relief if GS Labs resumes operations.

Notice FailureConsent Failure
FTC

Amare Global Holdings Inc.

The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.

Consent FailureHealth DataChildren's Data
TX

Purdue Pharma, Inc. and the Sackler Family

Texas Attorney General Ken Paxton announced the effective date of a $7.4 billion settlement with Purdue Pharma, Inc. and the Sackler family over their role in fueling the opioid crisis. Texas will receive $286.5 million from the settlement, bringing the state’s total opioid recovery funds to over $3 billion. The settlement includes permanent bans on Sackler opioid sales in the U.S., public release of 30 million company documents, and distribution of funds for addiction treatment and prevention over 15 years.

$7.4B

CT

Purdue Pharma

Connecticut Attorney General William Tong announced that Purdue Pharma will dissolve as the company’s bankruptcy concludes and a $7.4 billion settlement with Purdue and the Sackler family takes effect. The settlement permanently bars the Sacklers from selling opioids in the U.S., directs funds to addiction treatment and prevention, and requires the release of over 30 million documents related to Purdue’s opioid business. Connecticut is expected to receive $64 million from the settlement, with first payments anticipated in fall 2026.

$7.4B

NY

Purdue Pharma

New York Attorney General Letitia James announced the shutdown of opioid manufacturer Purdue Pharma as part of a $7.4 billion settlement with a bipartisan coalition of 54 other state attorneys general. The Sackler family, former owners of Purdue, are permanently barred from selling opioids in the U.S. and have no involvement in Knoa Pharma, the new public benefit corporation replacing Purdue. Purdue was sentenced on criminal charges related to its role in the opioid crisis on April 28, 2026, with the new entity operating under strict oversight and excess revenue funding opioid abatement efforts.

$7.4B

VA

Virginia Attorney General Jay Jones joined a bipartisan coalition of 44 state attorneys general in submitting a comment letter supporting a proposed U.S. Department of Labor rule to increase transparency requirements for pharmacy benefit managers (PBMs) servicing employer-funded ERISA health plans. The coalition urged the DOL to clarify that the proposed rule does not preempt existing state PBM transparency laws and to coordinate enforcement with state attorneys general. This action is a policy advocacy comment letter and does not constitute an enforcement action against any specific entity.

FTC

Vanilla Chip LLC

The FTC alleged that Vanilla Chip LLC (d/b/a TruHeight) deceptively advertised height-enhancing supplements for children and teens without competent scientific evidence, and used fake employee-written and incentivized 5-star reviews. The proposed settlement requires TruHeight and its principals to pay $750,000, bars false health claims, and prohibits misleading review practices. A $4 million total judgment is partially suspended due to the respondents' inability to pay the full amount.

$750K

HHS

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

Data BreachHealth DataSecurity Failure
HHS

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

Data BreachHealth DataUnauthorized Data Sharing
HHS

QualDerm Partners, LLC

QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

The Center for Advanced Eye Care

The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

Data BreachHealth DataSecurity Failure
HHS

Option Care Health, Inc.

Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
CT

23andMe

Connecticut Attorney General William Tong submitted testimony in support of genetic privacy legislation that would grant residents exclusive control over their DNA and genetic data. The legislation is inspired by his office's investigation into 23andMe's data breach affecting over six million customers and the company's subsequent bankruptcy. The bill requires express consent for DNA use, imposes security measures, and prohibits marketing use of DNA.

Data BreachBiometric Data
HHS

VNS Behavioral Health Inc. (“VNS Health”)

VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

Emanuel Medical Center

Emanuel Medical Center (Healthcare Provider, GA) reported a HIPAA breach affecting 28,963 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

44North

44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

Data BreachHealth DataSecurity Failure
HHS

Easterseals Northeast Indiana

Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wee Care Pediatrics, LLC

Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

National Association on Drug Abuse Problems

National Association on Drug Abuse Problems (Healthcare Provider, NY) reported a HIPAA breach affecting 90,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cedar Valley Services

Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Academic Urology & Urogynecology of Arizona

Academic Urology & Urogynecology of Arizona (Healthcare Provider, AZ) reported a HIPAA breach affecting 73,281 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Resource Corporation of America

Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Communications Workers of America Local 1180 Security Benefits Fund

Communications Workers of America Local 1180 Security Benefits Fund (Health Plan, NY) reported a HIPAA breach affecting 18,550 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.

Data BreachHealth DataUnauthorized Data Sharing
HHS

VPS Medical PLLC

VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cedar Point Health, LLC

Cedar Point Health, LLC (Healthcare Provider, CO) reported a HIPAA breach affecting 23,114 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

University Spine Center

University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.

Data BreachHealth DataSecurity Failure
HHS

Alexes Hazen MD, PLLC

Alexes Hazen MD, PLLC (Healthcare Provider, NY) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email, Network Server.

Data BreachHealth DataSecurity Failure
HHS

First Choice Community Home Care, Inc.

First Choice Community Home Care, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 725 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

BlueCross BlueShield of Tennessee, Inc.

BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 1,670 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

ApolloMD Business Services, LLC

ApolloMD Business Services, LLC (Business Associate, GA) reported a HIPAA breach affecting 626,540 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Five Star Home Health, Inc.

Five Star Home Health, Inc. (Healthcare Provider, OK) reported a HIPAA breach affecting 1,575 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Houston Health Department

Houston Health Department (Healthcare Provider, TX) reported a HIPAA breach affecting 7,445 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Carolina Foot & Ankle Associates

Carolina Foot & Ankle Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wendy Foster OD

Wendy Foster OD (Healthcare Provider, KS) reported a HIPAA breach affecting 20,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Counseling Center of Wayne & Holmes Counties

Counseling Center of Wayne & Holmes Counties (Healthcare Provider, OH) reported a HIPAA breach affecting 83,354 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Adapt Integrated Health Care

Adapt Integrated Health Care (Healthcare Provider, OR) reported a HIPAA breach affecting 2,908 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Marin Cancer Care

Marin Cancer Care (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

EDGAR A MARTORELL MD LLC

EDGAR A MARTORELL MD LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 1,107 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Cottage Hospital

Cottage Hospital (Healthcare Provider, NH) reported a HIPAA breach affecting 1,005 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

TriZetto Provider Solutions

TriZetto Provider Solutions (Business Associate, MO) reported a HIPAA breach affecting 3,433,965 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Apex Spine & Neurosurgery, LLC

Apex Spine & Neurosurgery, LLC (Healthcare Provider, GA) reported a HIPAA breach affecting 2,500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Triad Radiology Associates

Triad Radiology Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 11,011 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
HHS

WIRX Pharmacy

WIRX Pharmacy (Healthcare Provider, PA) reported a HIPAA breach affecting 20,047 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Issaqueena Pediatric Dentistry PA

Issaqueena Pediatric Dentistry PA (Healthcare Provider, SC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Personalis, Inc.

Personalis, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 650 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
FTC

Express Scripts, Inc.

Antitrust enforcement action where the FTC settled with Express Scripts, a major pharmacy benefit manager, for using anticompetitive rebating practices that artificially inflated insulin prices. The settlement requires ESI to change its business practices to increase transparency and lower patient out-of-pocket costs, potentially saving $7 billion over 10 years.

HHS

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates.

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates. (Healthcare Provider, MO) reported a HIPAA breach affecting 17,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
NJ

Novartis AG, Sandoz AG, Sandoz Group AG

New Jersey Acting Attorney General Jennifer Davenport, alongside 42 states and territories, filed a multistate complaint against Novartis AG and its subsidiaries Sandoz AG and Sandoz Group AG alleging a conspiracy to fix prices, allocate markets, and rig bids for 31 generic drugs, inflating costs for consumers and public healthcare programs. The complaint also alleges Novartis fraudulently spun off Sandoz to shield itself from liability for prior antitrust violations. This action builds on evidence from three previous multistate generic drug price-fixing complaints.

HHS

Pafford Medical Services

Pafford Medical Services (Healthcare Provider, AR) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Mindoula Health, Inc.

Mindoula Health, Inc. (Business Associate, MD) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

Data BreachHealth DataSecurity Failure
CT

Lannett Company, Inc., Bausch Health US, LLC, Bausch Health Americas, Inc.

Connecticut Attorney General William Tong led a coalition of 48 states and territories in announcing settlements with Lannett Company, Inc. and Bausch Health entities totaling $17.85 million. The settlements resolve allegations that the companies engaged in conspiracies to inflate prices and limit competition for generic prescription drugs. The companies agreed to cooperate in ongoing litigation and implement internal reforms, while a new complaint was filed against Novartis and subsidiaries.

$17.9M

HHS

Lincoln National Corporation d/b/a/ Lincoln Financial

Lincoln National Corporation d/b/a/ Lincoln Financial (Health Plan, IN) reported a HIPAA breach affecting 998 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

Data BreachHealth DataUnauthorized Data Sharing
HHS

Health and Hospital Corporation of Marion County

Health and Hospital Corporation of Marion County (Healthcare Provider, IN) reported a HIPAA breach affecting 792 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email, Laptop.

Data BreachHealth DataUnauthorized Data Sharing
HHS

BAYADA Home Health Care, Inc.

BAYADA Home Health Care, Inc. (Healthcare Provider, NJ) reported a HIPAA breach affecting 9,526 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Wakefield & Associates, LLC

Wakefield & Associates, LLC (Business Associate, TN) reported a HIPAA breach affecting 31,751 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
CT

Comstar, LLC

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

Data BreachSecurity FailureHealth Data

$515K

HHS

Clinic Service Corporation

Clinic Service Corporation (Business Associate, CO) reported a HIPAA breach affecting 82,331 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
MA

Comstar, LLC

Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.

Data BreachHealth DataSecurity Failure

$515K

HHS

WindRose Health Network

WindRose Health Network (Healthcare Provider, IN) reported a HIPAA breach affecting 691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure
HHS

Pecan Tree Dental, PLLC

Pecan Tree Dental, PLLC (Healthcare Provider, TX) reported a HIPAA breach affecting 13,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

Data BreachHealth DataSecurity Failure