Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Intercommunity Action Inc.

Intercommunity Action Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 2,680 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Rockhill Women’s Care

Rockhill Women’s Care (Healthcare Provider, MO) reported a HIPAA breach affecting 70,129 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
FTCSettlement

Amazon.com, Inc.(Amazon)

The FTC secured a $2.5 billion settlement with Amazon, including a $1 billion civil penalty and $1.5 billion in consumer refunds, for enrolling millions of consumers in Prime subscriptions without proper consent and designing a deliberately difficult cancellation process. The order requires Amazon to implement clear enrollment disclosures, an easy cancellation method, and cease the unlawful practices.

CriticalConsent FailureDark PatternsNotice Failure

$1.0B

HHSEnforcement Action

Susan B. Allen Memorial Hospital

Susan B. Allen Memorial Hospital (Healthcare Provider, KS) reported a HIPAA breach affecting 11,866 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer, Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Doctors Imaging Group

Doctors Imaging Group (Healthcare Provider, FL) reported a HIPAA breach affecting 171,862 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
CPPAGuidance

California Privacy Protection Agency

The California Privacy Protection Agency (CPPA) announced the approval of final regulations covering cybersecurity audits, risk assessments, automated decisionmaking technology (ADMT), insurance companies, and updates to existing CCPA regulations. The regulations go into effect January 1, 2026, with phased compliance deadlines for businesses based on revenue and type of requirement.

LowAI/Automated DecisionsSecurity Failure
HHSEnforcement Action

City of St. Joseph, MO Health Department

City of St. Joseph, MO Health Department (Healthcare Provider, MO) reported a HIPAA breach affecting 11,538 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Healthcare Interactive

Healthcare Interactive (Business Associate, MD) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NYEnforcement ActionMultistate

United States Department of Agriculture (USDA)

A coalition of 21 state attorneys general led by New York Attorney General Letitia James obtained a temporary restraining order from the District Court for the Northern District of California blocking the USDA from demanding personally identifiable information of all SNAP recipients, including Social Security numbers, home addresses, and immigration statuses. The lawsuit argued that the USDA’s demand violated federal and state laws prohibiting disclosure of SNAP data except in narrow circumstances, and that the data would be used for immigration enforcement against recipients. The order also prohibits the USDA from withholding SNAP funding from plaintiff states that refuse to comply with the data demand.

LowUnauthorized Data SharingChildren's Data
NYEnforcement ActionMultistate

United States Department of Agriculture(USDA)

New York Attorney General Letitia James and a coalition of 20 other states sued the U.S. Department of Agriculture to stop its demand for personal information of SNAP recipients for immigration enforcement. The District Court issued a temporary restraining order blocking USDA's demand and preventing funding cuts, citing violations of laws protecting SNAP data confidentiality.

LowUnauthorized Data Sharing
HHSEnforcement Action

People Encouraging People

People Encouraging People (Healthcare Provider, MD) reported a HIPAA breach affecting 13,083 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”)

Health & Palliative Services of the Treasure Coast, Inc d/b/a Treasure Coast Hospice (“Treasure Health ”) (Healthcare Provider, FL) reported a HIPAA breach affecting 13,230 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Ennoble Care & Circa Health, LLC

Ennoble Care & Circa Health, LLC (Healthcare Provider, NJ) reported a HIPAA breach affecting 36,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sturgis Hospital

Sturgis Hospital (Health Plan, MI) reported a HIPAA breach affecting 77,771 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sun Valley Surgery Center

Sun Valley Surgery Center (Healthcare Provider, NV) reported a HIPAA breach affecting 27,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Trusteed Plan Services Corporation

Trusteed Plan Services Corporation (Business Associate, WA) reported a HIPAA breach affecting 7,977 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Munson Healthcare

Munson Healthcare (Healthcare Provider, MI) reported a HIPAA breach affecting 1,186 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
FLEnforcement Action

Gethins Limited, Toccata, Inc., Segpay Gateway LLC, Segregated Payments, Inc., D/B/A Segpay, Aylo Holdings USA Corp., Aylo Billings US Corp., Aylo Group Ltd, Nutaku Entertainment Ltd.(Gethins, Toccata, Segpay, Aylo, Nutaku)

Florida Attorney General James Uthmeier filed complaints against multiple pornography websites for violating Florida's age-verification law by not verifying users' ages, allowing children access to harmful material. The law requires such sites to implement age verification, and violations can result in fines up to $50,000 per violation. The complaints seek injunctions, civil penalties, and compliance with the law.

LowChildren's Data
HHSEnforcement Action

North Penn Comprehensive Health Services d.b.a Laurel Health Centers

North Penn Comprehensive Health Services d.b.a Laurel Health Centers (Healthcare Provider, PA) reported a HIPAA breach affecting 991 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cookeville Regional Medical Center

Cookeville Regional Medical Center (Healthcare Provider, TN) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Saint Anthony Hospital

Saint Anthony Hospital (Healthcare Provider, IL) reported a HIPAA breach affecting 6,679 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CANew Law

N/A

The California Legislature passed AB 566, the California Opt Me Out Act, which will require browsers to support opt-out preference signals (OOPS), allowing consumers to easily limit the sale and sharing of their personal information. The bill now heads to the Governor for signature. The CPPA commended the legislature for this action.

Low
HHSEnforcement Action

Franklin Dermatology Group, PLC

Franklin Dermatology Group, PLC (Healthcare Provider, TN) reported a HIPAA breach affecting 2,457 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Western Skies Wellness LLC

Western Skies Wellness LLC (Healthcare Provider, OR) reported a HIPAA breach affecting 1,700 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.

LowData BreachHealth DataUnauthorized Data Sharing
FTCInvestigation

Alphabet, Inc.; Character Technologies, Inc.; Instagram, LLC; Meta Platforms, Inc.; OpenAI OpCo, LLC; Snap, Inc.; X.AI Corp.(Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, X.AI)

The FTC issued 6(b) orders to seven technology companies to investigate the safety and privacy practices of their AI chatbots, particularly regarding impacts on children and teens. The inquiry focuses on compliance with children's privacy laws, data handling, and disclosures, requiring companies to provide information on these aspects.

LowChildren's DataNotice FailureConsent Failure
HHSEnforcement Action

Texas Center for Infectious Disease Associates

Texas Center for Infectious Disease Associates (Healthcare Provider, TX) reported a HIPAA breach affecting 1,236 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

PGA Development, Inc.

PGA Development, Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 23,899 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

Businesses

Connecticut, California, and Colorado attorneys general, along with the California Privacy Protection Agency, announced a joint investigative sweep targeting businesses that fail to honor Global Privacy Control (GPC) signals, which allow consumers to opt-out of the sale of their personal information. The coalition sent letters to non-compliant businesses demanding immediate compliance with state privacy laws requiring respect for consumer opt-out preferences.

LowOpt-Out Failure
CPPAEnforcement ActionMultistate

Multiple businesses(Multiple Businesses)

The California Privacy Protection Agency, together with the Attorneys General of California, Colorado, and Connecticut, announced an investigative sweep targeting businesses that fail to honor Global Privacy Control (GPC) signals, which automatically communicate consumers' opt-out requests. The coalition is contacting identified businesses and demanding immediate compliance with state privacy laws. This coordinated effort highlights the states' commitment to enforcing consumers' right to opt-out of the sale of their personal information.

LowOpt-Out Failure
HHSEnforcement Action

Medical Associates of Brevard, LLC

Medical Associates of Brevard, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 246,711 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure

Explore Enforcement Data