Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

McEwen & Associates

McEwen & Associates (Business Associate, TX) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FTCWarning Letter

Various technology companies

FTC Chairman Andrew Ferguson sent warning letters to over a dozen major technology companies, reminding them of their obligations under the FTC Act to protect American consumers' data security and privacy, even when facing pressure from foreign governments to weaken encryption or censor content. The letters warn that weakening security measures or censoring speech in response to foreign demands could constitute deceptive practices under the FTC Act.

LowSecurity Failure
HHSEnforcement Action

Arkansas Primary Care Clinic

Arkansas Primary Care Clinic (Healthcare Provider, AR) reported a HIPAA breach affecting 2,491 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
MAConsent Decree

Peabody Properties, Inc.(Peabody Properties)

Massachusetts Attorney General Andrea Joy Campbell announced a $795,000 settlement with Peabody Properties, Inc. for failing to protect personal information and delaying breach notifications after multiple data breaches exposed nearly 14,000 residents' sensitive data. The consent decree requires payment to the Commonwealth and implementation of comprehensive cybersecurity measures.

MediumSecurity FailureBreach Notification Delay

$795K

HHSEnforcement Action

Revere Health PC

Revere Health PC (Healthcare Provider, UT) reported a HIPAA breach affecting 605 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

CareTracker, Inc.

CareTracker, Inc. (Business Associate, NY) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXInvestigation

Meta Platforms, Inc. and Character Technologies, Inc.

Texas Attorney General Ken Paxton opened an investigation into Meta and Character.AI via Civil Investigative Demands, alleging deceptive trade practices including misrepresenting AI chatbots as confidential mental health tools while harvesting user data for targeted advertising. The probe assesses potential violations of Texas consumer protection laws and the SCOPE Act, particularly regarding privacy misrepresentations, concealment of data usage, and harms to children. This builds on prior investigations into Character.AI for SCOPE Act compliance.

LowChildren's DataNotice FailureConsent Failure
HHSEnforcement Action

Pediatric Otolaryngology Head & Neck Surgery Associates, P.A.

Pediatric Otolaryngology Head & Neck Surgery Associates, P.A. (Healthcare Provider, FL) reported a HIPAA breach affecting 43,446 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General William Tong is seeking a preliminary injunction to block the U.S. Department of Agriculture from forcing states to share private data of SNAP participants, including social security numbers and shopping history. USDA is threatening to cut off administrative funding if states do not comply, which AG Tong argues violates federal privacy laws and the Constitution.

LowUnauthorized Data Sharing
HHSEnforcement Action

Bevel Health Medical Group

Bevel Health Medical Group (Healthcare Provider, PA) reported a HIPAA breach affecting 510 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
TXInvestigation

Meta AI Studio and Character.AI(Meta and Character.AI)

Texas Attorney General Ken Paxton has opened an investigation into Meta AI Studio and Character.AI for deceptive practices in marketing AI chatbots as mental health services to children. The platforms are accused of impersonating licensed professionals, fabricating qualifications, and exploiting user data for advertising without proper disclosure. Civil Investigative Demands have been issued to examine violations of Texas consumer protection laws and the SCOPE Act.

LowChildren's DataUnauthorized Data SharingNotice Failure
HHSEnforcement Action

Lake City Cancer Care, LLC

Lake City Cancer Care, LLC (Healthcare Provider, FL) reported a HIPAA breach affecting 9,980 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Anaheim

Welcome Dentistry-Anaheim (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mower County Health and Human Services

Mower County Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Alert Medical Alarms

Alert Medical Alarms (Healthcare Provider, PA) reported a HIPAA breach affecting 39,218 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

CPAP Medical Supplies and Services Inc.

CPAP Medical Supplies and Services Inc. (Healthcare Provider, FL) reported a HIPAA breach affecting 90,133 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Welcome Dentistry-Los Angeles

Welcome Dentistry-Los Angeles (Healthcare Provider, CA) reported a HIPAA breach affecting 1,001 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

UnitedHealthcare

UnitedHealthcare (Health Plan, CT) reported a HIPAA breach affecting 3,215 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Laurel Cancer Care, LLC

Laurel Cancer Care, LLC (Healthcare Provider, MS) reported a HIPAA breach affecting 1,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Zelis Healthcare LLC

Zelis Healthcare LLC (Business Associate, MA) reported a HIPAA breach affecting 4,289 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Dr. Doug's Pediatric Dentistry

Dr. Doug's Pediatric Dentistry (Healthcare Provider, UT) reported a HIPAA breach affecting 3,590 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Altos Inc

Altos Inc (Business Associate, CA) reported a HIPAA breach affecting 1,634 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mission City Community Network, Inc.

Mission City Community Network, Inc. (Healthcare Provider, CA) reported a HIPAA breach affecting 11,016 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

PROVAIL

PROVAIL (Healthcare Provider, WA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Aflac Incorporated (“Aflac”)

Aflac Incorporated (“Aflac”) (Health Plan, GA) reported a HIPAA breach affecting 13,924,906 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Friesen Group

Friesen Group (Healthcare Provider, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Center for Disability Services, Inc.

Center for Disability Services, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 3,343 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CPPAEnforcement Action

Tractor Supply Company(Tractor Supply)

The California Privacy Protection Agency (CPPA) filed a petition in Superior Court to enforce a subpoena against Tractor Supply Company for alleged CCPA violations, including failure to honor consumers' right to opt-out of the sale and sharing of personal information. This is the CPPA's first judicial action to enforce an investigative subpoena, and the agency is seeking court assistance to compel the company's compliance.

LowOpt-Out Failure
HHSEnforcement Action

South Coast Pediatrics

South Coast Pediatrics (Healthcare Provider, CA) reported a HIPAA breach affecting 7,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Oglethorpe, Inc.

Oglethorpe, Inc. (Healthcare Provider, FL) reported a HIPAA breach affecting 92,332 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data