Enforcement actions are the clearest available statement of what regulators consider unlawful, and this hub collects them with the underlying orders cited.
Data Security Rules
September 21, 2026
The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.
Read more →
CCPA / CPRA
September 1, 2026
California is the only state whose comprehensive privacy law has produced a substantial public enforcement record, and it has two enforcers producing it. This charts the twelve publicly documented CCPA actions, the penalty in each, the document each rests on, and the allegations that recur across almost all of them.
Read more →
HIPAA
September 1, 2026
In 2019 the Office for Civil Rights announced that enforcing a patient's right to their own records would be an enforcement priority. The resulting settlements had reached 41 cases by September 2022 and have continued since. Read together they describe an unusually repetitive fact pattern: a person asks for records, months pass, and the file arrives only after a federal complaint.
Read more →
Biometric Privacy
August 31, 2026
Texas has regulated the commercial capture of biometric identifiers since 2009, and for more than a decade nobody enforced the statute. The record now consists of two Attorney General actions, against Meta and against Google, and the settlement documents are more informative than the headline figures.
Read more →