Connecticut · verified official-source register

Connecticut Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Connecticut case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million payment to states; Connecticut will receive $1,992,130.00
Legal basis
State consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

Marriott failed to implement reasonable data security and remediate data security deficiencies while attempting to use and integrate Starwood into its systems. Intruders went undetected from July 2014 through September 2018, resulting in the exposure of 131.5 million U.S. guest records, including contact information, birth dates, reservation data, preferences, passport numbers, and payment card information.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Inmediata

Date
2023-10-17
Amount
$1.4 million payment to states; Connecticut's share: $60,154
Legal basis
State consumer protection laws, breach notification laws, and HIPAA requirements

Why the action was brought

Inmediata exposed protected health information of approximately 1.5 million consumers online for almost three years because of a coding issue. It failed to implement reasonable data security, including secure code review and crawling controls, delayed breach notification for over three months, sent misaddressed notices, and provided unclear, incomplete information, allowing sensitive patient data to be viewed or potentially downloaded.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem

Date
09/30/2020
Amount
$39.5 million multistate settlement; Connecticut’s share: $3.8 million
Legal basis
None stated

Why the action was brought

Cyber attackers infiltrated Anthem’s systems beginning in February 2014 through malware installed via a phishing email and accessed its data warehouse. They collected names, birth dates, Social Security numbers, healthcare identification and employment information, addresses, email addresses, and phone numbers of 78.8 million Americans, including 1.7 million Connecticut residents. The settlement addressed Anthem’s data-security practices and required strengthened safeguards.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.