1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,672
Total Actions
16
Jurisdictions
$50.5B+
Total Fines Tracked
Somerset County Children and Youth Services (Healthcare Provider, PA) reported a HIPAA breach affecting 2,251 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Coos County Family Health Services (Healthcare Provider, NH) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Twin Cities Pain Clinic (Healthcare Provider, MN) reported a HIPAA breach affecting 3,572 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Retina Group of Florida (Healthcare Provider, FL) reported a HIPAA breach affecting 152,691 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Texas Attorney General Ken Paxton filed a lawsuit against PowerSchool, a provider of cloud-based services for K-12 schools, following a data breach that exposed the personal and health information of over 880,000 Texas school-aged children and teachers. The breach occurred in December 2024 when a hacker gained administrative access through a subcontractor's account and stole unencrypted data including Social Security numbers, medical details, and disability records. The lawsuit alleges PowerSchool violated Texas law by failing to implement basic security measures and by misleading customers about its security practices.
The FTC settled allegations against Apitor Technology for violating COPPA by allowing a third party to collect geolocation data from children without parental consent. Apitor must pay a $500,000 suspended fine, delete improperly collected data, and implement measures to comply with COPPA, including obtaining parental consent and notifying parents.
$500K
Teamsters Union 25 Health Services & Insurance Plan (Health Plan, MA) reported a HIPAA breach affecting 19,231 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The FTC released a statement by Chairman Ferguson, joined by Commissioners Holyoak and Meador, regarding the enforcement action against Disney Worldwide Services for alleged violations of the Children's Online Privacy Protection Act (COPPA). The statement addresses the case involving children's privacy protections.
North Oaks Health System (Healthcare Provider, LA) reported a HIPAA breach affecting 6,243 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
The FTC alleges that Disney violated COPPA by failing to properly label children-directed videos on YouTube as 'Made for Kids,' allowing the collection of personal data from children under 13 without parental consent. Disney will pay a $10 million civil penalty and must implement a program to ensure accurate video designations, potentially incorporating age assurance technologies.
$10.0M
La Perouse, LLC (Business Associate, NV) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The FTC distributed refunds to consumers who purchased deceptively marketed treatment plans from Golden Sunrise Nutraceutical. The company and its medical director were barred from making unsupported health claims about curing COVID-19, cancer, and Parkinson's disease after a court order in September 2025. Over $40,700 was sent to 578 consumers, with additional claims possible until May 2026.
$103K
University of Iowa Community Home Care (Healthcare Provider, IA) reported a HIPAA breach affecting 109,029 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
University of Iowa Health Care (Healthcare Provider, IA) reported a HIPAA breach affecting 101,875 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Carrollton Ear, Nose and Throat, PC (Healthcare Provider, GA) reported a HIPAA breach affecting 3,569 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Anthony L. Jordan Health Corporation (Healthcare Provider, NY) reported a HIPAA breach affecting 2,974 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Florida Attorney General James Uthmeier issued a subpoena to Lorex as part of an ongoing consumer protection and data privacy investigation. The probe examines Lorex’s ties to Dahua Technology and potential foreign spying risks, including unauthorized access to children’s data, and whether the company misled consumers about the privacy and security of its camera products and apps. The subpoena seeks documents related to corporate structure, third-party contracts, software update origins, data center locations, security vulnerabilities, and marketing claims about privacy and security.
Reimagine Network (Healthcare Provider, CA) reported a HIPAA breach affecting 4,799 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Greater Pittsburgh Orthopaedics Associates (Healthcare Provider, PA) reported a HIPAA breach affecting 35,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.
Prime Therapeutics LLC (Business Associate, MN) reported a HIPAA breach affecting 2,266 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Laptop.
College Parkside Pharmacy (Healthcare Provider, NY) reported a HIPAA breach affecting 5,736 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Assisted Living Pharmacy Service, LLC (Healthcare Provider, WI) reported a HIPAA breach affecting 5,590 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
College Hometown Pharmacy (Healthcare Provider, NY) reported a HIPAA breach affecting 9,742 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Pacific Imaging Management, LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 13,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Department of Social Services for Vance County, North Carolina (Business Associate, NC) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Independent Health Association, Inc. (Health Plan, NY) reported a HIPAA breach affecting 637 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.
zizzl llc (Business Associate, WI) reported a HIPAA breach affecting 2,416 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Beech Acres Parenting Center (Healthcare Provider, OH) reported a HIPAA breach affecting 19,315 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Vital Imaging Medical Diagnostic Centers, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 260,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
FTC Chairman Andrew Ferguson sent warning letters to major technology companies, urging them not to weaken data security or censor American consumers' speech in response to foreign government demands. He reminded them that such actions could violate the FTC Act's prohibition on unfair and deceptive practices, particularly if companies break promises about encryption and security. The letters cite foreign laws like the EU's Digital Services Act and UK's Investigatory Powers Act as pressures that might lead to non-compliance.
All data sourced from official government enforcement pages.