Utah · verified official-source register

Utah Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Utah case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency

Date
March 11, 2021
Amount
$21 million total payment to the states; Utah's share not stated; payment suspended unless AMCA violates certain terms of the settlement agreement
Legal basis
No statutes or laws cited in the document

Why the action was brought

An unauthorized user accessed AMCA’s internal system from August 1, 2018, through March 30, 2019. AMCA failed to detect the intrusion despite warnings from payment-processing banks. Exposed information included Social Security numbers, payment-card information, and sometimes medical-test names and diagnostic codes, affecting over 7 million individuals, including more than 21,000 Utah residents.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
not stated in the official release
Amount
$52 million; Utah: $594,551
Legal basis
state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

Marriott’s Starwood guest reservation database was breached after intruders remained undetected from July 2014 through September 2018, compromising 131.5 million U.S. guest records, including contact, birth-date, reservation, preference, limited passport, and payment-card data. The Attorneys General alleged Marriott failed to implement reasonable security and remediate deficiencies, causing the data exposure.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

23andMe

Date
not stated in the official release
Amount
$18 million settlement; Utah's share: $461,688; separate $46.75 million class-action settlement
Legal basis
state data privacy, consumer protection, and genetic information privacy laws

Why the action was brought

In 2023, 23andMe suffered a data breach affecting approximately 6.9 million users. Compromised identities, ancestry, and genetic profiles were exposed, and hackers posted lists for sale on the dark web, reportedly targeting Ashkenazi Jewish and Chinese users. The investigation examined alleged violations of state data privacy, consumer protection, and genetic information privacy laws.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.