Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Beverly Hills Oncology Medical Group

Beverly Hills Oncology Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 57,655 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
TXSettlement

Google

Texas Attorney General Ken Paxton secured a $1.375 billion settlement with Google for unlawfully tracking Texans' geolocation data, incognito browsing activity, and biometric identifiers without consent. This is the largest single-state privacy settlement against Google, significantly larger than multistate settlements. The agreement resolves two major privacy enforcement actions brought by Texas.

CriticalGeolocation DataConsent FailureBiometric Data

$1.4B

CAEnforcement ActionMultistate

U.S. Department of Justice(Department of Justice)

California Attorney General Rob Bonta joined 15 attorneys general in filing an amicus brief to limit a U.S. DOJ subpoena seeking medical records of transgender youth from Children's Hospital of Philadelphia, arguing it violates patient privacy and could intimidate providers of gender-affirming care.

LowHealth DataChildren's Data
CTInvestigation

Food Distributors and Grocery Retailers(Food Distributors and Retailers)

Connecticut Attorney General William Tong is expanding an inquiry into high grocery prices by sending letters to major food distributors and retailers. The inquiry found no evidence of price gouging at the retail level but will now investigate the supply chain for potential unfair profiteering. The AG also cited factors like tariffs and SNAP cuts that contribute to high prices.

Low
CASettlement

Sling TV LLC and Dish Media Sales LLC(Sling TV)

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV LLC and Dish Media Sales LLC, resolving allegations that the streaming service violated the CCPA by failing to provide an easy-to-use opt-out mechanism for the sale of personal information and insufficient privacy protections for children. The settlement, subject to court approval, requires Sling TV to implement streamlined opt-out processes across all devices, stop redirecting users to cookie preferences for CCPA opt-outs, and add kid-specific profiles with default opt-out of data sales and targeted advertising. This is the first enforcement action from the DOJ's 2024 investigative sweep of streaming services.

MediumOpt-Out FailureChildren's DataConsent Failure

$530K

CASettlement

Sling TV LLC(Sling TV)

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

MediumOpt-Out FailureChildren's Data

$530K

HHSEnforcement Action

Hale Makua Health Services

Hale Makua Health Services (Healthcare Provider, HI) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXInvestigation

Lorex Technology Inc.

Texas Attorney General Ken Paxton opened an investigation into Lorex Technology Inc. for allegedly deceptively selling security cameras with components from CCP-linked Dahua, posing privacy and national security risks. The investigation will determine if Lorex misrepresented the cameras as secure and safe for residential use despite known supply chain vulnerabilities and federal restrictions on Dahua products.

LowSecurity Failure
HHSEnforcement Action

Northwest Radiologists, Inc./Mount Baker Imaging

Northwest Radiologists, Inc./Mount Baker Imaging (Healthcare Provider, WA) reported a HIPAA breach affecting 362,713 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Better Vision Eyecare, LLC

Better Vision Eyecare, LLC (Healthcare Provider, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Health Management Systems of America

Health Management Systems of America (Healthcare Provider, MI) reported a HIPAA breach affecting 4,213 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CAInvestigation

OpenAI

The California Attorney General conducted an investigation into OpenAI's recapitalization plan and secured a memorandum of understanding ensuring charitable assets are used for their intended purpose, safety is prioritized, and OpenAI remains in California. The AG will not oppose the plan and will monitor ongoing adherence to these commitments.

Low
HHSEnforcement Action

REACH, Inc

REACH, Inc (Healthcare Provider, AK) reported a HIPAA breach affecting 1,195 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

VirMedice, LLC

VirMedice, LLC (Business Associate, AZ) reported a HIPAA breach affecting 1,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Physicians to Children & Adolescents

Physicians to Children & Adolescents (Healthcare Provider, KY) reported a HIPAA breach affecting 9,536 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Southwest Urology

Southwest Urology (Healthcare Provider, OH) reported a HIPAA breach affecting 1,310 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Fairbanks Urology

Fairbanks Urology (Healthcare Provider, AK) reported a HIPAA breach affecting 1,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Saint Mary’s Home of Erie

Saint Mary’s Home of Erie (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Michael R. Schwartz, MD Inc.

Michael R. Schwartz, MD Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 9,080 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
CTSettlementMultistate

TFG Holding, Inc.(TFG Holding)

Connecticut Attorney General secured a $1 million multistate settlement with TFG Holding, Inc. for deceptive VIP membership program marketing and billing practices. The company must improve disclosures, obtain explicit consent, provide easy cancellation, and offer restitution to affected consumers.

HighConsent FailureOpt-Out FailureNotice Failure

$1.0M

HHSEnforcement Action

Legacy Health, LLC

Legacy Health, LLC (Business Associate, TX) reported a HIPAA breach affecting 6,547 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Express Canna Cards, LLC

Express Canna Cards, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 5,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
NYSettlement

Wojeski & Company

New York Attorney General Letitia James settled with public accounting firm Wojeski & Company over two data breaches in 2023 and 2024 that exposed personal information of over 4,700 New York residents, including social security numbers and medical benefits. The firm failed to implement adequate data security measures, did not encrypt sensitive data, and delayed notifying affected consumers of the breaches for over a year. Wojeski must pay $60,000 in penalties and implement enhanced cybersecurity measures including encryption, incident response plans, and employee training.

LowData BreachSecurity FailureBreach Notification Delay

$60K

HHSEnforcement Action

North Atlantic States Carpenters Health Benefits Fund

North Atlantic States Carpenters Health Benefits Fund (Health Plan, MA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Modernizing Medicine, Inc.

Modernizing Medicine, Inc. (Business Associate, FL) reported a HIPAA breach affecting 198,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Heartland Health Center

Heartland Health Center (Healthcare Provider, NE) reported a HIPAA breach affecting 43,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

River City Eye Care, LLC

River City Eye Care, LLC (Healthcare Provider, OR) reported a HIPAA breach affecting 6,588 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Coalesce, LLC dba Benefitelect

Coalesce, LLC dba Benefitelect (Business Associate, AZ) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

U.S. Department of Education(Department of Education)

Connecticut Attorney General William Tong joined 18 other attorneys general in filing a comment letter opposing a U.S. Department of Education proposal to expand data collection on race, admissions, and student performance from colleges and universities. The coalition argues the proposal is unreasonably burdensome, unlikely to yield quality data, and could be misused to target lawful diversity, equity, and inclusion initiatives, raising student privacy concerns.

LowStudent Data
CAGuidanceMultistate

U.S. Department of Education

California Attorney General Rob Bonta led a coalition of 18 attorneys general in submitting a comment letter opposing the U.S. Department of Education's proposal to collect extensive student data on race, admissions, and financial aid. The coalition argues the data collection is burdensome, unlikely to yield quality data, and may be misused to target lawful diversity, equity, and inclusion efforts.

LowStudent Data

Explore Enforcement Data