Missouri · verified official-source register

Missouri Privacy Enforcement Cases

1 verified case record from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

1 official case source link · state register dated August 31, 2026

Actual case links

Missouri case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 1

Blackbaud, Inc.

Date
2023-11-06
Amount
$49,500,000 total to the Attorneys General; $818,266.00 to Missouri; injunctive relief
Legal basis
Missouri Revised Statutes §§ 407.010, et seq.; Missouri Revised Statutes § 407.1500; Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936, as amended by the Health Information Technology for Economic and Clinical Health Act, Pub. L. No. 111-5, 123 Stat. 226; 42 U.S.C. § 1320d-5(d); 45 C.F.R. Part 160 and Part 164, Subparts A, C, and E; 45 C.F.R. §§ 160.103, 164.304, 164.308, 164.310, 164.312, 164.502(b), and 164.514(d)

Why the action was brought

Blackbaud software managed donor identifying information, donation history, and financial information. On May 14, 2020, a ransomware attack resulted in unauthorized access to and exfiltration of sensitive donor information. The breach affected over one million files related to over 13,000 customers, impacting donors, including Missouri residents. The document does not specify a particular violation.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.