Indiana · verified official-source register

Indiana Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Indiana case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International Inc.

Date
Wednesday, October 9, 2024
Amount
$52 million payment to states; Indiana will receive over $900,000
Legal basis
state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

Marriott’s Starwood guest reservation database was breached, exposing 131.5 million U.S. guest records, including contact information, dates of birth, reservation details, preferences, limited unencrypted passport numbers, and unexpired payment card information. Intruders remained undetected from July 2014 through September 2018. Attorneys general alleged Marriott failed to implement reasonable security and remediate deficiencies, particularly integrating Starwood.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Blackbaud

Date
2023-10-05
Amount
$49.5 million; Indiana will receive nearly $3.6 million
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s deficient data security allowed hackers to access its network during a 2020 breach, exposing demographic information, Social Security numbers, driver’s license numbers, financial information, donation history, and protected health information belonging to consumers connected to more than 13,000 customers. Blackbaud allegedly violated consumer protection, breach-notification, and HIPAA requirements by delaying or omitting complete, accurate customer notification.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Morgan Stanley Smith Barney LLC

Date
2023-11-21
Amount
$6.5 million total; $690,000 for Indiana
Legal basis
No exact statutes or laws cited

Why the action was brought

Morgan Stanley Smith Barney LLC allegedly exposed customers’ personal information through inadequate device decommissioning, including hiring an inexperienced moving company, failing to monitor disposal, auctioning equipment containing data, and losing 42 potentially unencrypted servers. The investigation found inadequate vendor controls and hardware inventories, allowing both data-security incidents to occur and risking disclosure of millions of customers’ sensitive information.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.