News & Analysis as of

Data Breach Enforcement Actions Penalties

Awatif Mohammad Shoqi Advocates & Legal...

Legal Consequences Under the UAE's Cybercrimes Law.

A nation's reputation is crucial, and the UAE has implemented strong legislation to address these issues under the Federal Law No. (34) of 2021 (cybercrimes law). These laws specifically target online activities concerning...more

Bennett Jones LLP

23andMe's Data Breach: Key Takeaways

Bennett Jones LLP on

On June 17, 2025, the Office of the Privacy Commissioner of Canada (OPC) released a summary of its investigation findings regarding a data breach at 23andMe, which affected nearly seven million customers, including...more

DLA Piper

Italy: The Garante Issues First GDPR Fine Over Employees Email Metadata Privacy Breach

DLA Piper on

The Italian Data Protection Authority (the Garante) has issued its first GDPR fine for, among other breaches, unlawful retention of metadata from employees’ emails and web browsing activities. The decision applies, for the...more

Ogletree, Deakins, Nash, Smoak & Stewart,...

2025 Enforcement Trends: Risk Analysis Failures at the Center of HHS’s Multimillion-Dollar HIPAA Penalties

In the first five months of 2025, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced it had entered into ten Health Insurance Portability and Accountability Act (HIPAA) resolution...more

Orrick, Herrington & Sutcliffe LLP

California privacy agency issues two actions for non-compliance

On May 8, the California Privacy Protection Agency (CPPA) ordered a Florida-based data broker to pay a $46,000 fine for failing to register and pay an annual fee as required by the Delete Act. The CPPA noted that the...more

Health Care Compliance Association (HCCA)

Former OCR Director Fontes Rainer Reflects On ‘Imperfect’ RSP Law, Urges Final Security Reg

In October, the HHS Office for Civil Rights (OCR) fined Providence Medical Institute (PMI) $240,000, an amount that reflected a 20% discount for having “recognized security practices” (RSPs) in place. But many more covered...more

Alston & Bird

UK Data Protection Regulator Fines UK Law Firm ~$80,000 Following Ransomware Incident

Alston & Bird on

On April 14, 2025, the UK data protection regulator (the Information Commissioner’s Office (“ICO”)) fined DPP Law (“DPP”) £60,000 (approximately $80,000) following a ransomware incident. In its penalty notice, the ICO found...more

Troutman Pepper Locke

Movie Theater Data Breach Leads to Settlement and Class Action Lawsuits

Troutman Pepper Locke on

New York Attorney General (AG) Letitia James and global movie theater operator National Amusements, Inc. (National) settled a lawsuit stemming from a 2022 data breach reported by National, which affected 82,128 National...more

Conyers

Privacy and Data Breaches In the Cayman Islands

Conyers on

Since the introduction of the Data Protection Act (the “DPA”) in 2017, there has been a steady increase in the number of data protection breaches that have been reported to the Office of the Ombudsman . It is expected that...more

Seyfarth Shaw LLP

FTC Rules Political Ad Marketing Firm Cambridge Analytica Deceived Facebook Users

Seyfarth Shaw LLP on

Synopsis: On December 6, 2019, the Federal Trade Commission issued a unanimous ruling against political data firm Cambridge Analytica for violating Section 5 of the FTC Act by misrepresenting that it would not download...more

Mitratech Holdings, Inc

The Scariest Data Privacy Breaches of 2019

Mitratech Holdings, Inc on

With it being Halloween, October being National Cybersecurity Awareness Month, and 2019 drawing to an end, let’s take a look at the data privacy breaches giving compliance professionals a fright this year! ...more

White & Case LLP

UK ICO issues £183m GDPR fine in stark warning to businesses

White & Case LLP on

The UK Information Commissioner's Office has announced its intention to issue a £183 million fine to British Airways, in respect of a personal data breach under the GDPR. The announcement has wide-ranging consequences for...more

Hogan Lovells

Time to Take Notice: ICO to Impose Record Fine for Data Security Breach

Hogan Lovells on

On 8 July 2019, the UK data protection authority (Information Commissioner’s Office; ICO) issued a notice of its intention to fine British Airways (BA) GBP 183.39 million (approx. USD 229.46 million) for infringements of the...more

Hogan Lovells

HIPAA Penalty Caps to Be Reduced and Tied to Culpability Level

Hogan Lovells on

In a dramatic turn, the US Department of Health and Human Services (HHS) has announced that effective immediately, penalties for many HIPAA violations will be subject to substantially reduced limits. ...more

Akin Gump Strauss Hauer & Feld LLP

California Passes Landmark Consumer Privacy CCPA—What it Means for Businesses

• California recently passed the landmark California Consumer Privacy Act that goes into effect in 2020, which grants California residents new privacy rights. • The CCPA creates a private right of action for California...more

Bricker Graydon LLP

Judge upholds fourth largest HIPAA penalty of $4.3 million for Texas cancer center

Bricker Graydon LLP on

The U.S. Department of Health and Human Services Office of Civil Rights (OCR) announced that an administrative law judge has upheld its fourth largest HIPAA penalty against the University of Texas MD Anderson Cancer Center....more

Ballard Spahr LLP

Appeals Board Upholds $4.3 Million in HIPAA Penalties Against Hospital

Ballard Spahr LLP on

The Departmental Appeals Board of the Department of Health and Human Services (“Board”) has granted summary judgment against the University of Texas MD Anderson Cancer Center (“Center”) and upheld the imposition of $4.3...more

Fenwick & West LLP

Yahoo’s $35M SEC Settlement: Takeaways from the First Enforcement Action for Failure to Disclose a Data Breach

Fenwick & West LLP on

The U.S. Securities and Exchange Commission announced on April 24, 2018, that Yahoo! — now known as Altaba — agreed to pay a $35 million penalty to settle claims that the company failed to timely disclose a 2014 data breach...more

Akin Gump Strauss Hauer & Feld LLP

In Principle: 10 Things Authorised Firms Need to Know for 2018 – The World of Financial Regulation as the UK Prepares to Exit the...

There is much for authorised firms to consider in the year ahead. Firms have been through the intensive period of the enactment of the second Markets in Financial Instruments Directive (MiFID II), but must now step up their...more

Snell & Wilmer

2017 HIPAA Enforcement – Appears Not To Be Slowing Down

Snell & Wilmer on

To state the obvious, there has been some uncertainty regarding how the Trump Administration will affect federal agency enforcement efforts. However, at least, in regard to HIPAA Privacy and Security, the U.S. Department of...more

Ballard Spahr LLP

OCR Announces First HIPAA Enforcement Action against a Business Associate

Ballard Spahr LLP on

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced an agreement with Catholic Health Services of the Archdiocese of Philadelphia (CHCS), settling allegations that CHCS violated the Health...more

Troutman Pepper

The New Normal: Taking Responsibility for Your Vendors

Troutman Pepper on

As financial institutions continue to strive for reduced costs and greater efficiencies, they are increasingly turning to third-party vendors to handle a wide variety of tasks, from marketing and sales to payment processing....more

22 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide