Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Rural Health Services

Rural Health Services (Healthcare Provider, SC) reported a HIPAA breach affecting 36,542 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTCoalitionMultistate

Meta Platforms, Inc.(Meta)

Attorney General William Tong led a bipartisan coalition of 42 attorneys general in urging Meta Platforms to protect users from fraudulent investment ads on Facebook that facilitate pump-and-dump schemes, causing significant financial losses. The coalition calls for enhanced ad review processes, including human review for investment ads, and suggests ceasing investment ads if scams cannot be curbed.

Low
HHSEnforcement Action

Clarkston Chiropractic Sports & Wellness

Clarkston Chiropractic Sports & Wellness (Healthcare Provider, MI) reported a HIPAA breach affecting 2,757 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NYEnforcement ActionMultistate

23andMe, Inc.(23andMe)

New York Attorney General Letitia James, joined by 27 other state attorneys general and the District of Columbia, filed a lawsuit against 23andMe to block the company’s planned sale of 15 million customers’ genetic and health data without their consent or knowledge. The coalition argues 23andMe must comply with state laws requiring express informed consent for the sale or transfer of sensitive genetic data. The lawsuit seeks to prevent misuse, exposure in future breaches, and unauthorized use of customers’ private genetic information.

LowConsent FailureHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Repay Management Services, LLC

Repay Management Services, LLC (Health Plan, GA) reported a HIPAA breach affecting 606 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
CTEnforcement ActionMultistate

23andMe

Connecticut joined a coalition of 28 attorneys general to object to 23andMe's proposed sale of genetic data in bankruptcy without customer consent. The states argue such sensitive information requires express consent and cannot be sold like ordinary property. Attorney General Tong also advised consumers to delete their data and genetic samples.

LowUnauthorized Data SharingConsent FailureBiometric Data
HHSEnforcement Action

Southern Connecticut Vascular Center, LLC

Southern Connecticut Vascular Center, LLC (Healthcare Provider, CT) reported a HIPAA breach affecting 154,417 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

Blue Shield of California

Blue Shield of California (Business Associate, CA) reported a HIPAA breach affecting 1,543 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Episource, LLC

Episource, LLC (Business Associate, CA) reported a HIPAA breach affecting 6,725,572 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sharp Community Medical Group

Sharp Community Medical Group (Healthcare Provider, CA) reported a HIPAA breach affecting 26,976 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Centivo Corporation

Centivo Corporation (Business Associate, GA) reported a HIPAA breach affecting 630 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Public Health Trust of Miami Dade County DBA Jackson Health System

Public Health Trust of Miami Dade County DBA Jackson Health System (Healthcare Provider, FL) reported a HIPAA breach affecting 2,599 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Sharp HealthCare

Sharp HealthCare (Healthcare Provider, CA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

NYC Health + Hospitals

NYC Health + Hospitals (Healthcare Provider, NY) reported a HIPAA breach affecting 5,728 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Huron Regional Medical Center, Inc.

Huron Regional Medical Center, Inc. (Healthcare Provider, SD) reported a HIPAA breach affecting 25,398 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Sensata Technologies, Inc. Health and Welfare Benefit Plan

Sensata Technologies, Inc. Health and Welfare Benefit Plan (Health Plan, MA) reported a HIPAA breach affecting 15,630 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Jupiter Family Medicine PC

Jupiter Family Medicine PC (Healthcare Provider, MI) reported a HIPAA breach affecting 3,000 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
CTNew Law

House Bill No. 7181(Connecticut)

Connecticut passed House Bill No. 7181 to strengthen enforcement against illegal cannabis and tobacco sales by increasing penalties, allowing municipalities to retain civil penalties, and creating a task force. The law also expands bans on online sales of e-cigarettes and improves age verification to prevent youth access to addictive products.

Low
HHSEnforcement Action

Cumberland County Hospital Association

Cumberland County Hospital Association (Healthcare Provider, KY) reported a HIPAA breach affecting 36,659 individuals. Breach type: Hacking/IT Incident. Location of breached information: Other.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Renkim Corporation

Renkim Corporation (Business Associate, MI) reported a HIPAA breach affecting 105,518 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
FTCSettlement

Paddle

The FTC entered into a settlement with U.K.-based payment processor Paddle to resolve allegations that its unfair payment processing practices facilitated tech support scammers operating in Cyprus. Paddle agreed to pay a $5 million monetary penalty as part of the settlement.

High

$5.0M

HHSEnforcement Action

Next Step Healthcare LLC

Next Step Healthcare LLC (Healthcare Provider, MA) reported a HIPAA breach affecting 12,090 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Horizon Blue Cross Blue Shield NJ

Horizon Blue Cross Blue Shield NJ (Health Plan, NJ) reported a HIPAA breach affecting 781 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Oliver Street Dermatology Management LLC

Oliver Street Dermatology Management LLC (Business Associate, TX) reported a HIPAA breach affecting 13,717 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Providia Home Care, LLC dba Preferred Care Home Health Services

Providia Home Care, LLC dba Preferred Care Home Health Services (Healthcare Provider, FL) reported a HIPAA breach affecting 38,401 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Upper Dublin Family Dentistry

Upper Dublin Family Dentistry (Healthcare Provider, PA) reported a HIPAA breach affecting 5,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Missouri Department of Conservation

Missouri Department of Conservation (Health Plan, MO) reported a HIPAA breach affecting 10,260 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Gateway Community Services, Inc.

Gateway Community Services, Inc. (Healthcare Provider, FL) reported a HIPAA breach affecting 34,498 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Northwestern Community Services Board

Northwestern Community Services Board (Healthcare Provider, VA) reported a HIPAA breach affecting 21,856 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Mary B. Toporcer, MD, P.C.

Mary B. Toporcer, MD, P.C. (Healthcare Provider, PA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data