Idaho · verified official-source register

Idaho Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Idaho case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Retrieval-Masters Creditors Bureau, under the name American Medical Collection Agency (AMCA)

Date
December 9, 2020
Amount
$21 million total payment to the states; Idaho share not stated; payment suspended unless the company violates certain settlement terms
Legal basis
No statutes or laws cited in the document

Why the action was brought

An unauthorized user accessed AMCA’s internal system between August 2018 and March 2019. AMCA failed to detect the intrusion despite warnings from payment-processing banks. The breach exposed Social Security numbers, payment card information, and, in some instances, names of medical tests and diagnostic codes belonging to more than 7 million people nationwide, including 3,068 Idaho residents.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Experian; T-Mobile; Experian Data Corp. (“EDC”)

Date
not stated in the official release
Amount
More than $16 million paid by the companies to the states; Idaho will receive $172,000. T-Mobile’s separate settlement is $2.43 million. Experian will pay an additional $1 million to resolve the EDC investigation.
Legal basis
Idaho Code

Why the action was brought

The 2015 Experian breach exposed names, addresses, dates of birth, Social Security numbers, identification numbers, and related credit-assessment information of consumers applying for T-Mobile services. An unauthorized actor accessed Experian’s network. EDC’s 2012 breach involved an identity thief obtaining sensitive personal information after posing as a private investigator, and EDC failed to prevent or provide notice.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Carnival Cruise Line

Date
not stated in the official release
Amount
$1.25 million multistate settlement; Idaho will receive $13,088
Legal basis
Idaho law; state breach notification statutes

Why the action was brought

An unauthorized individual accessed Carnival employee email accounts containing names, addresses, passport and driver’s license numbers, payment card and health information, and some Social Security numbers. Carnival became aware of suspicious activity in May 2019 but reported the breach approximately 10 months later, raising concerns about email security and delayed breach notification.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.