New Hampshire · verified official-source register

New Hampshire Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

New Hampshire case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Inmediata Health Group Corp.

Date
March 17, 2025
Amount
$1.4 million, including $25,000 to New Hampshire
Legal basis
New Hampshire Consumer Protection Act, RSA 358-A:2; New Hampshire Data Security Breach Notification Law, RSA 359-C:19 et seq.

Why the action was brought

Inmediata’s website configuration made patients’ electronic protected health information accessible to unauthorized internet users and searchable through Google. The exposed information included names, addresses, dates of birth, medical record numbers, health-insurance information, and medical information, affecting approximately 1.5 million individuals and creating risk of unauthorized disclosure.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
October 9, 2024
Amount
$52 million; New Hampshire’s share: $1.125 million
Legal basis
New Hampshire Consumer Protection Act, RSA 358-A; New Hampshire data breach notification law, RSA 359-C:20

Why the action was brought

Marriott’s Starwood guest-reservation database was compromised in four incidents between 2014 and 2020, exposing names, addresses, phone numbers, email addresses, passport numbers, dates of birth, gender, loyalty-account information, and reservation details. The states alleged Marriott lacked reasonable safeguards, failed to detect and contain unauthorized access, and delayed breach notifications, increasing consumers’ risks of identity theft and fraud.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Carnival Corporation & plc

Date
2025-03-17
Amount
$12.5 million; New Hampshire’s share is not stated
Legal basis
New Hampshire Consumer Protection Act, RSA 358-A:2; New Hampshire data-breach notification law, RSA 359-C:20

Why the action was brought

Carnival experienced multiple data breaches that exposed consumers’ and employees’ personal information. The investigation found that Carnival failed to maintain reasonable data-security practices, adequately protect personal information, detect and respond to incidents, and provide timely notice concerning the breaches, causing potential harm to affected individuals.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.