Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Personic Management Company LLC

Personic Management Company LLC (Business Associate, VA) reported a HIPAA breach affecting 10,929 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CAEnforcement Action

Data Brokers

The California Privacy Protection Agency (CalPrivacy) announced the creation of a Data Broker Enforcement Strike Force to investigate privacy violations by data brokers under the CCPA and Delete Act. The strike force will focus on compliance with registration requirements and other obligations, building on previous enforcement actions to increase accountability.

LowData Broker Non-Compliance
HHSEnforcement Action

County of Catawba

County of Catawba (Health Plan, NC) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CASettlementMultistate

Greystar Management Services LLC(Greystar)

California Attorney General Rob Bonta announced a $7 million settlement with Greystar Management Services LLC for using RealPage's algorithmic software to illegally align rent prices with competitors by sharing confidential pricing information, violating antitrust laws. Greystar must cease using such anticompetitive algorithms, refrain from data sharing, accept monitoring, and cooperate in the ongoing case against RealPage.

HighAI/Automated Decisions

$7.0M

CTSettlementMultistate

Purdue Pharma

The U.S. Bankruptcy Court confirmed a $7.4 billion settlement between Purdue Pharma, the Sackler Family, and 55 attorneys general to resolve claims over the opioid crisis. Connecticut will receive up to $64 million for treatment, prevention, and victim support. The settlement bars the Sacklers from selling opioids and requires public disclosure of documents.

Critical

$7.4B

HHSEnforcement Action

Dermatology Associates of Concord

Dermatology Associates of Concord (Healthcare Provider, MA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Marrs Ear, Nose & Throat, PA

Marrs Ear, Nose & Throat, PA (Healthcare Provider, FL) reported a HIPAA breach affecting 6,376 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

St. John’s Riverside Hospital

St. John’s Riverside Hospital (Healthcare Provider, NY) reported a HIPAA breach affecting 2,238 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency announced approval of regulations implementing the Delete Act, which will allow consumers to submit a single delete request to multiple data brokers via a new state-hosted platform (DROP). Data brokers must retrieve and process these requests every 45 days starting August 2026, deleting all associated personal data unless a legal exemption applies.

LowData Broker Non-ComplianceOpt-Out FailureRecord Retention
HHSEnforcement Action

West Suburban Eye Surgery Center LLC

West Suburban Eye Surgery Center LLC (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Morton Drug Company

Morton Drug Company (Healthcare Provider, WI) reported a HIPAA breach affecting 40,051 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Steven J. Pearlman MD PC

Steven J. Pearlman MD PC (Healthcare Provider, NY) reported a HIPAA breach affecting 10,182 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Healthcare Therapy Services, Inc.

Healthcare Therapy Services, Inc. (Healthcare Provider, IN) reported a HIPAA breach affecting 15,027 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Marshfield Clinic Health System

Marshfield Clinic Health System (Healthcare Provider, WI) reported a HIPAA breach affecting 35,952 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Loving and Living Center, PC dba Awakenings Center

Loving and Living Center, PC dba Awakenings Center (Healthcare Provider, NC) reported a HIPAA breach affecting 17,800 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
CTSettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

Connecticut Attorney General William Tong, along with California and New York Attorneys General, settled with Illuminate Education, Inc. for failing to protect student data in a breach that exposed personal information of millions of students. The settlement, the first under Connecticut's Student Data Privacy Law, requires Illuminate to pay $5.1 million and implement enhanced cybersecurity measures.

HighData BreachSecurity FailureStudent Data

$5.1M

NYSettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.

HighData BreachStudent DataSecurity Failure

$5.1M

CTEnforcement Action

Altice/Optimum Online(Altice)

Connecticut Attorney General William Tong filed an expanded complaint against Altice/Optimum Online for deceptive advertising and hidden 'Network Enhancement' fees that collected at least $39.1 million from consumers. The company allegedly misled customers with 'price for life' deals while burying fees in fine print and targeting Spanish speakers with English-only disclosures. The complaint seeks penalties and disgorgement under the Connecticut Unfair Trade Practices Act.

LowNotice Failure
CASettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.

HighData BreachStudent DataHealth Data

$5.1M

HHSEnforcement Action

The Chase Group Employee Benefit Plan

The Chase Group Employee Benefit Plan (Health Plan, NM) reported a HIPAA breach affecting 817 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Archer Health

Archer Health (Healthcare Provider, CA) reported a HIPAA breach affecting 4,285 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) announced its new public-facing name, CalPrivacy, and launched eight privacy tips to help Californians protect their personal data. The agency also announced the upcoming Delete Request and Opt-Out Platform (DROP) for consumers to delete data from data brokers in a single step, launching in January 2026.

Low
HHSEnforcement Action

Motorola Solutions

Motorola Solutions (Health Plan, IL) reported a HIPAA breach affecting 22,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tampa Bay Treatment Associates

Tampa Bay Treatment Associates (Healthcare Provider, FL) reported a HIPAA breach affecting 3,682 individuals. Breach type: Theft. Location of breached information: Electronic Medical Record.

LowData BreachHealth Data
HHSEnforcement Action

Denton MHMR Center

Denton MHMR Center (Healthcare Provider, TX) reported a HIPAA breach affecting 108,967 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Incyte Pathology, P.S.

Incyte Pathology, P.S. (Healthcare Provider, WA) reported a HIPAA breach affecting 629 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
CAGuidance

California healthcare providers, service plans, and contractors(Healthcare Providers)

California Attorney General Rob Bonta issued an informational bulletin summarizing new responsibilities under SB 81, which expands protections for immigrants' medical information by designating immigration status as protected data under the Confidentiality of Medical Information Act (CMIA) and restricts immigration enforcement access to non-public areas of healthcare facilities.

LowHealth Data
HHSEnforcement Action

Expert MRI

Expert MRI (Healthcare Provider, CA) reported a HIPAA breach affecting 209,560 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Judson Center

Judson Center (Healthcare Provider, MI) reported a HIPAA breach affecting 976 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Tri Century Eye Care PC

Tri Century Eye Care PC (Healthcare Provider, PA) reported a HIPAA breach affecting 200,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure

Explore Enforcement Data