Ohio · verified official-source register

Ohio Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Ohio case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International Inc.

Date
2024-10-09
Amount
$52 million; more than $1.5 million to Ohio
Legal basis
State consumer protection laws

Why the action was brought

Marriott’s acquired Starwood guest-reservation system was breached from as early as July 2014 through September 2018, exposing contact details, reservation data, and in some cases unencrypted passport numbers and payment card information of 131.5 million hotel guests. The investigation found Marriott failed to implement reasonable security measures despite representations about its security practices.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Inmediata

Date
10/17/2023
Amount
$1.4 million to the participating states; Ohio's share: $56,041
Legal basis
State breach notification laws and the federal Health Insurance Portability and Accountability Act (HIPAA)

Why the action was brought

Inmediata exposed protected health information of 1.5 million consumers online and in search-engine indexes for three years, potentially allowing internet users to access and download sensitive patient data. It allegedly failed to implement reasonable data security and secure-code reviews, delayed breach notification more than three months, sent some notices incorrectly, and provided unclear information.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud, Inc.

Date
2023-10-05
Amount
$49,500,000 total payment to the Attorneys General; Ohio's share: $1,296,502; injunctive relief
Legal basis
Ohio Consumer Sales Practices Act, R.C. § 1345.01, et seq.; Ohio Data Breach Notification Law, R.C. § 1349.19, et seq.; Health Insurance Portability and Accountability Act of 1996 (HIPAA), Pub. L. No. 104-191, 110 Stat. 1936, as amended by the Health Information Technology for Economic and Clinical Health Act, Pub. L. No. 111-5, 123 Stat. 226; 42 U.S.C. § 1320d-5(d); HIPAA Privacy Rule, 45 C.F.R. Part 160 and Part 164, Subparts A and E; HIPAA Security Rule, 45 C.F.R. Part 160 and Part 164, Subparts A and C; R.C. 1345.07

Why the action was brought

On May 14, 2020, Blackbaud discovered a ransomware attack involving unauthorized access and exfiltration of sensitive donor information, including identifying, donation-history, and financial information. The incident affected over one million files relating to more than 13,000 customers. The investigation examined Blackbaud’s compliance with consumer-protection, data-breach-notification, personal-information-protection, and HIPAA requirements.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.