Michigan · verified official-source register

Michigan Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Michigan case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud

Date
October 05, 2023
Amount
$49.5 million; Michigan’s share: $1,150,595
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud failed to implement reasonable data security and remediate known security gaps, allowing unauthorized access to personal and protected health information, including Social Security numbers, financial information, and health information. It also failed to provide timely, complete, or accurate breach information, significantly delaying or preventing consumer notification after the 2020 ransomware event.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Carnival Cruise Line

Date
June 23, 2022
Amount
$1.25 million multistate settlement; Michigan will receive $29,016.47
Legal basis
State breach notification statutes; no specific statute or law is named

Why the action was brought

Carnival’s 2019 breach involved an unauthorized actor accessing employee email accounts containing names, addresses, passport and driver’s-license numbers, payment-card and health information, and a small number of Social Security numbers. Carnival learned of suspicious activity in May 2019 but reported the breach approximately 10 months later, increasing consumer risk; approximately 180,000 people were affected.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem

Date
2020-10-01
Amount
$39.5 million; Michigan's share: $354,542.05
Legal basis
No statutes or laws cited in the document.

Why the action was brought

In February 2015, Anthem disclosed attackers had infiltrated its systems beginning in February 2014 through malware installed via a phishing email. They accessed a data warehouse and harvested names, dates of birth, Social Security numbers, health care identification and employment information, addresses, email addresses, and phone numbers of 78.8 million Americans, including 636,075 Michigan residents.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.