Tennessee · verified official-source register

Tennessee Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Tennessee case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Medical Informatics Engineering, Inc. and NoMoreClipboard LLC

Date
May 29, 2019
Amount
$900,000 total; Tennessee receiving $21,238
Legal basis
Health Insurance Portability and Accountability Act (HIPAA); state Unfair and Deceptive Practice laws; Notice of Data Breach statutes; state Personal Information Protection Acts

Why the action was brought

Hackers infiltrated MIE’s WebChart application between May 7 and May 26, 2015, stealing electronic Protected Health Information of more than 3.9 million individuals. The compromised data included names, contact information, usernames, hashed passwords, Social Security numbers, health information, insurance information, diagnoses, and other personal data, allegedly violating HIPAA and state laws.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Anthem

Date
2020-10-02
Amount
$39.5 million; Tennessee’s share: $400,556.46
Legal basis
No statutes or laws cited

Why the action was brought

In 2014, cyber attackers infiltrated Anthem’s systems and harvested names, dates of birth, Social Security numbers, healthcare identification numbers, home and email addresses, phone numbers, and employment information for 78.8 million Americans, including 773,763 Tennessee residents. The document does not identify a specific failure or statutory violation, but Anthem agreed to data-security and governance requirements.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Equifax

Date
2019-07-22
Amount
$600 million total settlement; Consumer Restitution Fund of up to $425 million, including $300 million dedicated to consumer redress and up to an additional $125 million; $175 million payment to the states; Tennessee’s share: $3,516,675.07
Legal basis
No specific statutes or laws cited in the document

Why the action was brought

Equifax’s 2017 breach exposed social security numbers, names, dates of birth, addresses, credit card numbers, and sometimes driver’s license numbers of more than 147 million consumers. The investigation found Equifax failed to maintain reasonable security, fully patch a known critical software vulnerability, and replace monitoring software, allowing attackers unnoticed access for 76 days.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.