Nevada · verified official-source register

Nevada Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Nevada case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud

Date
Oct. 5, 2023
Amount
$49.5 million; Nevada will receive $559,828
Legal basis
state consumer protection laws, breach notification laws and HIPAA

Why the action was brought

Blackbaud’s software stored contact and demographic information, Social Security and driver’s license numbers, financial, employment, wealth, donation, and protected health information. The company allegedly failed to implement reasonable data security and remediate known gaps, enabling unauthorized network access; deficient, downplaying notifications delayed customer notice or led customers to believe notice was unnecessary, exposing millions’ information.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA)

Date
2021-03-11
Amount
Suspended $21 million total payment to the states; no Nevada share stated
Legal basis
No statutes or laws cited in the document

Why the action was brought

An unauthorized user accessed AMCA’s internal system from August 1, 2018, through March 30, 2019. AMCA failed to detect the intrusion despite warnings from payment-processing banks. The breach exposed Social Security numbers, payment card information, and sometimes medical-test names and diagnostic codes of more than 7 million individuals, including 345,447 Nevadans.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Anthem

Date
September 30, 2020
Amount
$39.5 million; Nevada’s share: $397,306.77
Legal basis
No statutes or laws cited.

Why the action was brought

Anthem’s network was compromised in February 2014 through malware installed via a phishing email. Attackers accessed its data warehouse and harvested names, dates of birth, Social Security numbers, healthcare identification numbers, home addresses, email addresses, phone numbers, and employment information affecting 78.8 million Americans, including 764,039 Nevada residents.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.