Court Rules
All enforcement actions
Enforcement ActionLow Risk

TX AG Sues PowerSchool for Breach Exposing 880K Children's Data

PowerSchoolSeptember 3, 2025Texas Attorney General

Consumers Affected

880,000

Summary

Texas Attorney General Ken Paxton filed a lawsuit against PowerSchool, a provider of cloud-based services for K-12 schools, following a data breach that exposed the personal and health information of over 880,000 Texas school-aged children and teachers. The breach occurred in December 2024 when a hacker gained administrative access through a subcontractor's account and stole unencrypted data including Social Security numbers, medical details, and disability records. The lawsuit alleges PowerSchool violated Texas law by failing to implement basic security measures and by misleading customers about its security practices.

Contract Impact

In-house legal teams should review all vendor agreements with education technology providers, particularly those handling student, children’s, or employee data, to ensure they include explicit requirements for multi-factor authentication, adequate access controls, and data encryption for all sensitive data. Contracts should also mandate compliance with applicable state privacy laws, require vendors to accurately represent their security standards without deceptive marketing claims, and include clear breach notification timelines and subcontractor security obligations. Additionally, teams should verify that vendors are contractually required to adhere to security best practices for protecting health information and student records, and that remedies for security failures are clearly outlined.

Contract Search Terms

multi-factor authentication requirementsdata encryption standardsaccess control provisionsstudent data protectionchildren's data safeguardshealth information securitysubcontractor security requirementsdata breach notification timeline

Laws Cited

Texas Deceptive Trade Practices ActIdentity Theft Enforcement and Protection Act

Violation Types

Entity Details

Entity

PowerSchool

Industry

Technology

Official Sources

Source Evidence

Entity Name
"PowerSchool"
Laws Cited
"Texas Deceptive Trade Practices Act"
Laws Cited
"Identity Theft Enforcement and Protection Act"
Violation Types
"unprecedented data breach exposed the sensitive personal identifying information and protected health information of more than 880,000 Texas school-aged children and teachers"
Violation Types
"failed to implement even the most basic security features, including multi-factor authentication, adequate access controls, and proper data encryption"
Violation Types
"provider of cloud-based services for K-12 schools"

Related Enforcement Actions

TX

Tris Pharmaceuticals

$7.5M

Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.

TX

Plum Organics

Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.

TX

Health Care Service Corporation (including Blue Cross and Blue Shield of Texas)

Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.

TX

N/A (consumer alert; no enforcement target)

Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.

TX

TikTok

A Texas state district court (Judge Cory Liu) has found TikTok liable for lying to parents about the safety of its platform and for exposing children to inappropriate and explicit content, making Texas the first state in the nation to hold TikTok liable on these claims. The court found that although TikTok claimed it would remove graphic videos depicting drugs, nudity, alcohol, injuries, and profanity, such videos remained accessible to minors, even under 'Restricted Mode.' No penalty has been imposed yet; Attorney General Paxton will proceed to trial, expected next month, where relief and penalties will be determined.

TX

TriWest Healthcare Alliance Corp.

Texas Attorney General Ken Paxton opened an investigation into TriWest Healthcare Alliance Corp., the U.S. government contractor that administers the VA Community Care Network and the Defense Health Agency's TRICARE West Region, over reports that it wrongfully denied health care claims by falsely treating insureds as having other health insurance (OHI). The OAG has issued Civil Investigative Demands (CIDs) and plans to interview consumers and employees to determine whether TriWest violated the Texas Deceptive Trade Practices Act. No findings or penalties have been imposed yet.