Washington · verified official-source register

Washington Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Washington case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
not stated in the official release
Amount
$18 million from the bankruptcy funds; Washington will receive $547,000; separate $46.8 million class-action settlement
Legal basis
Washington's consumer protection laws

Why the action was brought

23andMe’s breach affected 6.9 million consumers, including 221,401 Washingtonians, and exposed personal information, sometimes including genetic ancestry data. The attorneys general found unreasonable data-security practices. 23andMe learned of the breach months after information was publicly available; subsets were later offered for sale on the dark web, leaving customers vulnerable to hackers.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Premera Blue Cross

Date
not stated in the official release
Amount
$10 million nationwide; $5.4 million to Washington; nearly $4.6 million to the coalition of states
Legal basis
Health Insurance Portability and Accountability Act (HIPAA); Washington State Consumer Protection Act

Why the action was brought

Premera failed to secure sensitive personal and protected health information, including Social Security numbers, bank account information, names, addresses, phone numbers, dates of birth, member identification numbers and email addresses. A hacker accessed its network from May 5, 2014, to March 6, 2015, affecting more than 10.4 million individuals nationwide, including more than 6.4 million Washingtonians. The company ignored known vulnerabilities and misled consumers before and after the breach.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Uber

Date
not stated in the official release
Amount
Approximately $5.79 million, including more than $2.2 million to affected Washington drivers
Legal basis
Washington state’s data breach notification law; Washington’s data breach notification laws

Why the action was brought

Uber failed to adequately safeguard drivers’ personal data and waited more than a year—over 370 days—to notify the Washington Attorney General’s Office of the November 2016 breach. Unauthorized individuals accessed names and driver’s license numbers of nearly 13,000 Washington drivers, jeopardizing their personal information; Uber paid hackers to hide the breach and destroy stolen data.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.