Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
MAEnforcement ActionMultistate

Trump Administration

Massachusetts Attorney General Andrea Campbell filed a motion to enforce a preliminary injunction against the Trump Administration's demands for personal data of SNAP recipients. The court previously blocked such demands, but the administration renewed its request, threatening to withhold funding. The AG seeks to ensure compliance with federal privacy laws and protect SNAP recipients' sensitive information.

LowUnauthorized Data SharingChildren's Data
NYInvestigation

Instacart

New York Attorney General Letitia James sent a letter to Instacart demanding information about its use of algorithmic pricing, after a study found users were charged up to 23% more for identical products. The AG warned that Instacart’s pricing disclosures are non-compliant with New York’s Algorithmic Pricing Disclosure Act, which requires prominent notices near product prices when personal data is used to set prices. Instacart must provide details on its pricing experiments, automated tools, and compliance efforts with the state’s disclosure requirements.

LowSurveillance PricingNotice Failure
HHSEnforcement Action

ABKSW PREFERRED HEALTH PARTNERS, PLLC d/b/a NORTH TEXAS PREFERRED HEALTH PARTNERS

ABKSW PREFERRED HEALTH PARTNERS, PLLC d/b/a NORTH TEXAS PREFERRED HEALTH PARTNERS (Healthcare Provider, TX) reported a HIPAA breach affecting 2,074 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
ORInvestigation

Federal Law Enforcement Agencies(Federal Agents)

Civil rights investigation by the Oregon Attorney General into an incident where federal agents shot two people in Portland, examining whether officers acted outside lawful authority and addressing concerns about a pattern of excessive force.

LowSecurity Failure
HHSEnforcement Action

Devereux Foundation

Devereux Foundation (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CPPAAdministrative Order

Rickenbacher Data LLC, d/b/a Datamasters(Datamasters)

Datamasters, a data broker, failed to register with the California Data Broker Registry as required by the Delete Act. The company sold sensitive personal information including health conditions, age, race, and political views. As a result, it must pay a $45,000 fine and cease all sales of Californians' personal information.

LowData Broker Non-Compliance

$45K

OREnforcement Action

Novo Nordisk, Sanofi, Eli Lilly, Express Scripts, CVS Caremark, Optum

Consumer protection case: Oregon Attorney General filed a lawsuit against six major drug companies and pharmacy benefit managers for allegedly coordinating to inflate insulin prices, seeking $900 million in damages under the Unlawful Trade Practices Act.

CriticalSecurity Failure

$900.0M

HHSEnforcement Action

Pit River Health Service Inc.

Pit River Health Service Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 1,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Methodist Homes of Alabama and Northwest Florida

Methodist Homes of Alabama and Northwest Florida (Healthcare Provider, AL) reported a HIPAA breach affecting 1,406 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mid Michigan Medical Billing Service, Inc.

Mid Michigan Medical Billing Service, Inc. (Business Associate, MI) reported a HIPAA breach affecting 28,185 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
VAEnforcement Action

Social Media Platforms

Virginia Attorney General Jay Jones announced intent to enforce new provisions of the Virginia Consumer Data Protection Act that limit minors' social media usage to one hour per day without parental consent. The law, effective January 1, 2026, requires age verification and verifiable parental consent to change time limits, with potential penalties up to $7,500 per violation and injunctive relief. This follows a motion to dismiss a lawsuit by NetChoice challenging the law.

LowChildren's Data
HHSEnforcement Action

Andover Eye Associates

Andover Eye Associates (Healthcare Provider, MA) reported a HIPAA breach affecting 1,638 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Steel Encounters, Inc.

Steel Encounters, Inc. (Healthcare Provider, UT) reported a HIPAA breach affecting 959 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FTCSettlement

Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC(Disney)

The FTC settled with Disney for violating the COPPA Rule by mislabeling videos on YouTube, which allowed the collection of children's personal data without parental consent. Disney must pay a $10 million civil penalty and implement measures to ensure proper video labeling and compliance with COPPA.

HighChildren's DataConsent FailureNotice Failure

$10.0M

HHSEnforcement Action

Advanced Healthcare Professionals

Advanced Healthcare Professionals (Healthcare Provider, TX) reported a HIPAA breach affecting 800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTSettlement

Hartford Healthcare

The Connecticut Attorney General reached an agreement with Hartford Healthcare to address antitrust concerns in the acquisition of Manchester Memorial and Rockville General hospitals from Prospect Medical. The agreement includes conditions to limit cost increases, waive physician non-compete clauses, and maintain medical staff privileges to protect competition and physician mobility. This resolves the antitrust review under the state's notice of material change statute.

Low
HHSEnforcement Action

Associated Radiologists of the Finger Lakes, P.C.

Associated Radiologists of the Finger Lakes, P.C. (Business Associate, NY) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Exact Sciences Laboratories LLC

Exact Sciences Laboratories LLC (Healthcare Provider, WI) reported a HIPAA breach affecting 2,658 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Docs Medical Group, Inc. dba Pulse Urgent Care

Docs Medical Group, Inc. dba Pulse Urgent Care (Healthcare Provider, CA) reported a HIPAA breach affecting 4,035 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

CareOregon

CareOregon (Health Plan, OR) reported a HIPAA breach affecting 5,473 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
NYSettlement

OrthopedicsNY, LLP(OrthopedicsNY)

New York Attorney General Letitia James secured a $500,000 settlement with orthopedics practice OrthopedicsNY, LLP for failing to implement adequate data security measures, leading to a 2023 cyberattack that exposed personal and health information of approximately 656,000 patients and employees. The settlement requires OrthopedicsNY to pay the penalty, fund one year of free credit monitoring for affected individuals, and adopt enhanced data security practices including multifactor authentication, encryption, and annual risk assessments.

MediumData BreachSecurity FailureHealth Data

$500K

HHSEnforcement Action

BlueCross BlueShield of Tennessee, Inc.

BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 780 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Glendale Obstetrics & Gynecology PCA

Glendale Obstetrics & Gynecology PCA (Healthcare Provider, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
OREnforcement ActionMultistate

U.S. Department of Health and Human Services (HHS)(HHS)

Health and civil rights enforcement action. Oregon Attorney General Dan Rayfield led a coalition of 19 states and the District of Columbia in filing a lawsuit against the U.S. Department of Health and Human Services (HHS). The suit challenges a December 18, 2025 HHS 'declaration' that claims certain gender-affirming care is 'unsafe and ineffective' and threatens to exclude providers from Medicare/Medicaid for offering such care. The attorneys general argue HHS violated federal administrative law by implementing a major policy change without required notice-and-comment rulemaking, creating fear for patients and providers and threatening state Medicaid programs.

Low
CTCoalitionMultistate

Meta

Connecticut Attorney General William Tong, leading a coalition of 35 attorneys general, urged Meta to enforce its policies against misleading AI-generated weight loss ads on Instagram and Facebook. The ads promote non-FDA approved GLP-1 drugs without disclosing risks and use fake AI content. The coalition demands Meta restrict such ads, require clear risk disclosures, and label AI-generated content.

LowNotice Failure
HHSEnforcement Action

AllerVie Health

AllerVie Health (Healthcare Provider, TX) reported a HIPAA breach affecting 80,521 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

York Hospital

York Hospital (Healthcare Provider, ME) reported a HIPAA breach affecting 1,259 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Artemis Healthcare Inc.

Artemis Healthcare Inc. (Healthcare Provider, TN) reported a HIPAA breach affecting 45,867 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Riverland Community Health

Riverland Community Health (Healthcare Provider, MN) reported a HIPAA breach affecting 940 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
CTEnforcement ActionMultistate

Trump Administration

Attorney General William Tong joined a coalition of 21 states and D.C. in suing the Trump administration to prevent the defunding of the Consumer Financial Protection Bureau (CFPB). The lawsuit argues that the defunding is unlawful and would cripple consumer protection efforts and state enforcement capabilities. The coalition seeks a court order to ensure CFPB continues to receive funding and fulfill its duties.

Low

Explore Enforcement Data