Alaska · verified official-source register

Alaska Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Alaska case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud Inc.

Date
October 5, 2023
Amount
$49.5 million payment to states; Alaska will receive $358,925
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s software held contact and demographic information, Social Security and driver’s-license numbers, financial, employment and wealth information, donation history, and protected health information. In a 2020 ransomware event, unauthorized persons accessed its network. The company allegedly lacked reasonable security, failed to remediate known gaps, and delayed or omitted complete, accurate breach notifications, exposing millions of consumers.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

TTAM

Date
2025-06-30
Amount
injunctive relief only
Legal basis
None stated

Why the action was brought

The settlement concerns TTAM obtaining most of 23andMe’s assets, including customer genetic data and DNA samples, through a bankruptcy proceeding. It provides additional protections for Alaskans, including limits on data and sample access and continuing deletion rights. The document does not state a specific failure, violation, or resulting harm.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Premera Blue Cross

Date
2019-07-11
Amount
$10 million total; approximately $467,000 to Alaska
Legal basis
federal Health Insurance Portability and Accountability Act (HIPAA); state consumer protection act

Why the action was brought

Premera failed to secure sensitive consumer data, allowing a hacker unauthorized access to a network containing protected health information, Social Security numbers, bank account information, names, addresses, phone numbers, dates of birth, member identification numbers, and email addresses for nearly a year. It ignored known vulnerabilities and misled consumers about access and security, exposing data of more than 10.4 million consumers nationwide.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.