Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

Carlton County Public Health and Human Services

Carlton County Public Health and Human Services (Healthcare Provider, MN) reported a HIPAA breach affecting 3,502 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Maximus, Inc.

Maximus, Inc. (Business Associate, VA) reported a HIPAA breach affecting 4,955 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Palo Verde Hospital

Palo Verde Hospital (Healthcare Provider, CA) reported a HIPAA breach affecting 594 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Cache Valley Ear Nose & Throat

Cache Valley Ear Nose & Throat (Healthcare Provider, UT) reported a HIPAA breach affecting 26,469 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Brainard Surgery Center LLC

Brainard Surgery Center LLC (Healthcare Provider, OH) reported a HIPAA breach affecting 1,820 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Drug and Alcohol Treatment Services, Inc.

Drug and Alcohol Treatment Services, Inc. (Healthcare Provider, PA) reported a HIPAA breach affecting 22,215 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Orthopaedic Specialists of Connecticut

Orthopaedic Specialists of Connecticut (Healthcare Provider, CT) reported a HIPAA breach affecting 22,541 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Icon Family Healthcare LLC

Icon Family Healthcare LLC (Healthcare Provider, CA) reported a HIPAA breach affecting 1,800 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
FLEnforcement Action

Snap, Inc.

Florida Attorney General James Uthmeier filed a lawsuit against Snap, Inc., operator of Snapchat, for violating Florida’s HB3 child social media protection law and the Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The suit alleges Snap knowingly allowed children under 13 to create accounts, failed to obtain parental consent for 14-15 year old users, deployed addictive dark pattern design features to children, and deceived parents about platform risks including predator access, drug sales, and harmful content. The legal action seeks to hold Snap accountable for noncompliance with Florida child safety and privacy laws.

LowChildren's DataConsent FailureNotice Failure
HHSEnforcement Action

Onsite Mammography

Onsite Mammography (Business Associate, MA) reported a HIPAA breach affecting 357,265 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

HighData BreachHealth DataSecurity Failure
TXEnforcement Action

23andMe

Texas Attorney General Ken Paxton filed a motion to appoint a Consumer Privacy Ombudsman in the Chapter 11 bankruptcy case of 23andMe to protect the sensitive genetic and personal data of Texans. The genetic testing company seeks to sell assets that may include genetic data, health information, and personally identifiable information. The AG's office is also informing Texans of their rights under Texas law to request deletion of their data and genetic samples.

LowBiometric DataUnauthorized Data Sharing
HHSEnforcement Action

90 Degree Benefits, Inc. – St. Paul

90 Degree Benefits, Inc. – St. Paul (Business Associate, WI) reported a HIPAA breach affecting 1,268 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
CTRegulatory Report

Office of the Attorney General

The Connecticut Office of the Attorney General released an updated enforcement report on the Connecticut Data Privacy Act (CTDPA) for 2024, summarizing investigations into companies handling connected vehicles, genetic data, palm recognition, teen messaging apps, and facial recognition. The report outlines expanded enforcement priorities around opt-out practices and dark patterns, and includes legislative recommendations to strengthen the CTDPA.

LowOpt-Out FailureDark PatternsChildren's Data
NJEnforcement Action

Discord, Inc.(Discord)

The New Jersey Attorney General filed a lawsuit against Discord, Inc. for deceptive business practices under the Consumer Fraud Act. Discord misrepresented its Safe Direct Messaging and age verification features, failing to protect children from

LowChildren's DataSecurity Failure
FLInvestigation

Roblox

Florida Attorney General James Uthmeier issued a subpoena to Roblox on April 16, 2025, as part of an investigation into the gaming platform’s child-protection policies and children’s data practices. The subpoena demands documents related to Roblox’s marketing to children, age-verification procedures, chat moderation, and processing of minors’ personal data, following reports of children being exposed to harmful content and predatory actors on the platform. No fines or remedies have been imposed yet, as the investigation is ongoing.

LowChildren's Data
CPPACoalitionMultistate

Consortium of Privacy Regulators (California, Colorado, Connecticut, Delaware, Indiana, New Jersey, Oregon)

Eight state regulators, including the California Privacy Protection Agency and attorneys general from seven states, formed the bipartisan Consortium of Privacy Regulators to collaborate on the implementation and enforcement of their privacy laws. The group aims to share expertise, resources, and coordinate investigations to protect consumer privacy across jurisdictions.

Low
HHSEnforcement Action

Recovery Epicenter Foundation

Recovery Epicenter Foundation (Healthcare Provider, FL) reported a HIPAA breach affecting 800 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

HEALTH AND WELLNESS OF TEXAS

HEALTH AND WELLNESS OF TEXAS (Healthcare Provider, TX) reported a HIPAA breach affecting 500 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Magnolia Manor Inc.

Magnolia Manor Inc. (Healthcare Provider, GA) reported a HIPAA breach affecting 960 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Bell Ambulance, Inc.

Bell Ambulance, Inc. (Healthcare Provider, WI) reported a HIPAA breach affecting 237,830 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

The City of Long Beach, CA

The City of Long Beach, CA (Healthcare Provider, CA) reported a HIPAA breach affecting 258,191 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure
HHSEnforcement Action

AHS Sherman LLC dba AHS Sherman Medical Center

AHS Sherman LLC dba AHS Sherman Medical Center (Healthcare Provider, TX) reported a HIPAA breach affecting 908 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Health Care Service Corporation

Health Care Service Corporation (Health Plan, IL) reported a HIPAA breach affecting 2,944 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Blue Cross and Blue Shield of Texas

Blue Cross and Blue Shield of Texas (Health Plan, IL) reported a HIPAA breach affecting 12,086 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Blue Cross and Blue Shield of Oklahoma

Blue Cross and Blue Shield of Oklahoma (Health Plan, IL) reported a HIPAA breach affecting 1,020 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Blue Cross and Blue Shield of Illinois

Blue Cross and Blue Shield of Illinois (Health Plan, IL) reported a HIPAA breach affecting 6,903 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Parc Provence Memory Care Facility

Parc Provence Memory Care Facility (Healthcare Provider, MO) reported a HIPAA breach affecting 13,954 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Gatesworth Senior Living St. Louis

The Gatesworth Senior Living St. Louis (Healthcare Provider, MO) reported a HIPAA breach affecting 31,124 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Summit Healthcare Medical Associates

Summit Healthcare Medical Associates (Healthcare Provider, AZ) reported a HIPAA breach affecting 1,861 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Endue Software

Endue Software (Business Associate, ME) reported a HIPAA breach affecting 118,028 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

HighData BreachHealth DataSecurity Failure

Explore Enforcement Data