Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Personalis, Inc.

Personalis, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 650 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
FTCSettlement

Express Scripts, Inc.(Express Scripts)

Antitrust enforcement action where the FTC settled with Express Scripts, a major pharmacy benefit manager, for using anticompetitive rebating practices that artificially inflated insulin prices. The settlement requires ESI to change its business practices to increase transparency and lower patient out-of-pocket costs, potentially saving $7 billion over 10 years.

Low
HHSEnforcement Action

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates.

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates. (Healthcare Provider, MO) reported a HIPAA breach affecting 17,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
NJEnforcement ActionMultistate

Novartis AG, Sandoz AG, Sandoz Group AG

New Jersey Acting Attorney General Jennifer Davenport, alongside 42 states and territories, filed a multistate complaint against Novartis AG and its subsidiaries Sandoz AG and Sandoz Group AG alleging a conspiracy to fix prices, allocate markets, and rig bids for 31 generic drugs, inflating costs for consumers and public healthcare programs. The complaint also alleges Novartis fraudulently spun off Sandoz to shield itself from liability for prior antitrust violations. This action builds on evidence from three previous multistate generic drug price-fixing complaints.

Low
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) announced the appointment of Sabrina Boyson Ross as its first Chief Privacy Auditor and the formation of a new Audits Division. The division will conduct regulatory examinations of businesses to determine compliance with the California Consumer Privacy Act, and its findings may lead to enforcement referrals.

Low
HHSEnforcement Action

Pafford Medical Services

Pafford Medical Services (Healthcare Provider, AR) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mindoula Health, Inc.

Mindoula Health, Inc. (Business Associate, MD) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CTSettlementMultistate

Lannett Company, Inc., Bausch Health US, LLC, Bausch Health Americas, Inc.(Bausch Health)

Connecticut Attorney General William Tong led a coalition of 48 states and territories in announcing settlements with Lannett Company, Inc. and Bausch Health entities totaling $17.85 million. The settlements resolve allegations that the companies engaged in conspiracies to inflate prices and limit competition for generic prescription drugs. The companies agreed to cooperate in ongoing litigation and implement internal reforms, while a new complaint was filed against Novartis and subsidiaries.

Critical

$17.9M

HHSEnforcement Action

Lincoln National Corporation d/b/a/ Lincoln Financial

Lincoln National Corporation d/b/a/ Lincoln Financial (Health Plan, IN) reported a HIPAA breach affecting 998 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
CANew Law

California State Legislature

Senator Josh Becker introduced SB 923, the Expanding Privacy Rights Act, sponsored by CalPrivacy. The bill would expand the CCPA right to delete to include personal information obtained from third-party sources, and require businesses to provide multiple methods (e.g., webform) for submitting privacy requests.

Low
HHSEnforcement Action

Health and Hospital Corporation of Marion County

Health and Hospital Corporation of Marion County (Healthcare Provider, IN) reported a HIPAA breach affecting 792 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email, Laptop.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

BAYADA Home Health Care, Inc.

BAYADA Home Health Care, Inc. (Healthcare Provider, NJ) reported a HIPAA breach affecting 9,526 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wakefield & Associates, LLC

Wakefield & Associates, LLC (Business Associate, TN) reported a HIPAA breach affecting 31,751 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTSettlementMultistate

Comstar, LLC(Comstar)

Comstar, LLC, an ambulance billing vendor, suffered a data breach in March 2022 that exposed sensitive patient information, including Social Security numbers and medical records, of over 349,000 residents in Connecticut and Massachusetts. The settlement requires Comstar to pay $515,000 and implement enhanced security measures such as phishing protection and annual security assessments.

MediumData BreachSecurity FailureHealth Data

$515K

CTSettlement

Charter Communications and Cox Communications(Charter Communications, Cox Communications)

The Connecticut Attorney General and Consumer Counsel secured a settlement requiring Charter Communications to adhere to consumer protection commitments as it acquires Cox Communications. The agreement, pending PURA approval, includes pricing transparency, service reliability improvements, a $3 million digital access investment, and compliance with the Connecticut Data Privacy Act. It also maintains a Connecticut workforce and office, and prevents cost pass-through to customers.

Low
CTSettlement

Charter

The Connecticut Attorney General and Consumer Counsel announced a settlement with Charter Communications regarding its proposed acquisition of Cox Communications. The settlement includes consumer protections such as billing transparency, service reliability improvements, a $3 million digital access investment, and other commitments. It is pending approval by the Public Utilities Regulatory Authority.

Low
HHSEnforcement Action

Clinic Service Corporation

Clinic Service Corporation (Business Associate, CO) reported a HIPAA breach affecting 82,331 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
MASettlementMultistate

Comstar, LLC(Comstar)

Massachusetts Attorney General secured a $515,000 settlement with Comstar, LLC for a March 2022 data breach that exposed sensitive patient information of over 326,000 Massachusetts residents. Comstar violated Massachusetts Data Security regulations and HIPAA by failing to maintain adequate security measures. The settlement includes monetary payment and mandated security improvements.

MediumData BreachHealth DataSecurity Failure

$515K

CAInvestigation

businesses with significant online presence in the retail, grocery, and hotel sectors(Retail, Grocery, and Hotel Businesses)

California Attorney General Rob Bonta announced an investigative sweep targeting businesses that use surveillance pricing, which involves setting individualized prices based on consumer data. The Department of Justice is sending information request letters to companies in the retail, grocery, and hotel sectors to assess compliance with the CCPA's purpose limitation principle. This action seeks to ensure that consumers are not charged different prices without proper disclosure and that businesses adhere to privacy laws.

LowSurveillance PricingAI/Automated Decisions
FTCSettlement

Growth Cave, LLC(Growth Cave)

Consumer fraud case where the FTC settled with Growth Cave defendants for operating a deceptive business opportunity and credit repair scheme that cost consumers nearly $50 million. The settlement permanently bans them from such activities, requires asset liquidation to pay a $48.6 million judgment, and prohibits misleading earnings claims and AI use.

Critical

$48.6M

HHSEnforcement Action

WindRose Health Network

WindRose Health Network (Healthcare Provider, IN) reported a HIPAA breach affecting 691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NYWarning LetterMultistate

xAI

A bipartisan coalition of 35 state attorneys general led by New York Attorney General Letitia James sent a demand letter to xAI on January 26, 2026, requiring the company to address its Grok chatbot’s creation and sharing of nonconsensual intimate images, including child sexual abuse material. The AGs demand that xAI implement safeguards to prevent Grok from generating such content, delete existing harmful content, suspend offending users, and give X users control over whether their content can be edited by Grok. No monetary penalty has been imposed as this is a pre-enforcement demand for action.

LowConsent FailureChildren's DataUnauthorized Data Sharing
CAGuidance

California Privacy Protection Agency (CalPrivacy)

The California Privacy Protection Agency (CalPrivacy) announced the launch of the Delete Request and Opt-out Platform (DROP) during Data Privacy Week. DROP allows Californians to submit a single request to delete their personal information from over 500 registered data brokers, as required by the Delete Act. The platform is free and has already seen over 176,000 sign-ups since January 1, 2026.

LowData Broker Non-ComplianceOpt-Out Failure
HHSEnforcement Action

Pecan Tree Dental, PLLC

Pecan Tree Dental, PLLC (Healthcare Provider, TX) reported a HIPAA breach affecting 13,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NJGuidance

N/A (General Warning to New Jersey Sellers)

New Jersey Acting Attorney General Jennifer Davenport and the Division of Consumer Affairs issued general guidance warning sellers against engaging in price gouging during a declared state of emergency ahead of a major winter storm. The guidance cites New Jersey’s price gouging law, which prohibits price increases exceeding 10% of pre-emergency prices for necessary goods and services during the emergency and 30 days after its termination. Violations carry civil penalties up to $10,000 for first offenses and $20,000 for subsequent offenses, with each individual sale counted as a separate violation.

Low
FTCEnforcement Action

Top Healthcare Options Insurance Agency Inc(Top Healthcare Options)

Telemarketing enforcement case where the FTC obtained a temporary restraining order against defendants who deceptively marketed limited benefit health plans as comprehensive health insurance. The scheme caused tens of millions of dollars in harm to consumers seeking health coverage. The court halted operations at the FTC's request.

High
OREnforcement Action

Ryan Tong

Consumer protection case involving charity fraud. A former Orangetheory Fitness instructor pleaded guilty to stealing charitable donations collected during workout classes between 2021 and 2024. He diverted over $24,000 intended for charities to his personal Venmo account to fund his cocaine habit. The Oregon DOJ and Multnomah County DA's Office pursued criminal charges and civil claims to secure restitution and prevent future charitable sector involvement.

Low
HHSEnforcement Action

Precipio, Inc.

Precipio, Inc. (Healthcare Provider, CT) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Jefferson-Blount-St. Clair Mental Health Authority

Jefferson-Blount-St. Clair Mental Health Authority (Healthcare Provider, AL) reported a HIPAA breach affecting 30,434 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
NJCoalitionMultistate

Trump Administration

New Jersey, serving as co-lead of a 22-state coalition, filed a motion for summary judgment on January 22, 2026, seeking an expedited order to stop the Trump Administration from defunding the Consumer Financial Protection Bureau (CFPB) before March 2026. The states argue that defunding the CFPB would undermine federal and state consumer protection efforts, including states’ reliance on CFPB consumer complaint data and mortgage lending data for enforcement actions. This motion builds on a December 2025 lawsuit filed by the same coalition challenging the administration’s threats to withhold CFPB funding.

Low

Explore Enforcement Data