Oregon · verified official-source register

Oregon Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Oregon case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud

Date
not stated in the official release
Amount
$49.5 million payment to the states; Oregon’s share: $655,791.00
Legal basis
State consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s deficient data security and response to a 2020 ransomware event exposed personal and protected health information, including contact, demographic, Social Security, driver’s-license, financial, employment, wealth, donation, and health data. It allegedly failed to implement reasonable security, remediate known gaps, and provide timely, complete, accurate breach information, delaying or preventing consumer notification.

View Official Multistate Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Premera Blue Cross, known in Oregon as LifeWise Health Plan of Oregon

Date
not stated in the official release
Amount
$10 million settlement; Oregon will receive $1.3 million
Legal basis
Health Insurance Portability and Accountability Act (HIPAA); federal and state laws

Why the action was brought

Premera failed to address known cybersecurity vulnerabilities and maintain adequate administrative, physical, and technical safeguards. A spear-phishing email installed malware, allowing a hacker nearly a year of unrestricted access to personal and protected health information, including names, addresses, Social Security numbers, health information, member numbers, bank details, and email addresses of millions.

View Official Multistate Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Avalon Healthcare Management

Date
not stated in the official release
Amount
$200,000 settlement; Oregon's share: $100,000
Legal basis
Health Insurance Portability and Accountability Act (HIPAA) and state breach notification statutes, including Oregon law requiring notice of a security breach in the most expeditious manner, but no more than 45 days after discovery

Why the action was brought

In July 2019, a scammer accessed an Avalon employee’s email after a phishing scam. The breach exposed names, addresses, Social Security numbers, dates of birth, driver’s license numbers, medical treatment information, and limited financial information of 14,500 employees and patients. Avalon notified affected individuals approximately 10 months later, exceeding Oregon’s 45-day requirement.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.