Iowa · verified official-source register

Iowa Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Iowa case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
July 14, 2026
Amount
$18 million settlement; Iowa will receive $429,767
Legal basis
Iowa’s Consumer Fraud Act; Iowa Consumer Data Protection Act

Why the action was brought

23andMe’s 2023 data breach compromised the genetic data of 6.9 million customers worldwide, including genetic ancestry information in some cases, with subsets published for sale on the dark web. The investigation alleged unreasonable security practices, including inadequate credential-stuffing safeguards, rate limiting, monitoring, unusual-login investigation, vulnerability remediation, and design-feature testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International

Date
October 9, 2024
Amount
$52 million to the States; Iowa will receive $594,105
Legal basis
state consumer protection laws, personal-information protection laws, and breach-notification laws

Why the action was brought

Marriott’s guest reservation database was accessed by intruders for years, exposing 131.5 million guest records, including contact information, gender, dates of birth, preferred guest information, reservation information, hotel-stay preferences, and some passport numbers and payment-card information. Attorneys general alleged Marriott violated state consumer-protection, personal-information-protection, and breach-notification laws by failing to implement proper security measures.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem, Inc.

Date
September 29, 2020
Amount
$39,500,000.00 total; $199,694.24 to the Iowa Attorney General
Legal basis
Iowa Consumer Fraud Act, Iowa Code § 714.16; Iowa Personal Information Security Breach Protection Act, Iowa Code § 715C; federal Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, and implementing regulations, 45 C.F.R. §§ 160, 162, and 164

Why the action was brought

A criminal cyber-attacker gained unauthorized access to Anthem’s network and internally hosted enterprise data warehouse, exposing unencrypted personal and protected health information of approximately 78,800,000 individuals. The accessed data included names, birth dates, Social Security numbers, healthcare identification numbers, addresses, email addresses, phone numbers, employment information, and income data.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.