Close Menu
Legal MagLegal Mag
  • Home
  • Legal News
  • Intellectual Property
  • Litigation
  • Regulation
  • Technology
  • More
    • Firms
    • Law Practice
    • Trending
    • Press Release
What's On

Seven charged in $100M California jewelry heist, largest in US history

June 19, 2025

States challenge bankrupt 23andMe’s right to auction genetic information

June 11, 2025

Jimmy Buffett’s widow battles co-trustee over $275 million trust

June 6, 2025

Longtime Hardee’s franchisee sues chain over franchise agreement dispute

May 29, 2025

Apple warns ruling in App Store case may cost ‘substantial sums annually’

May 8, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Legal MagLegal Mag
Newsletter
  • Home
  • Legal News
  • Intellectual Property
  • Litigation
  • Regulation
  • Technology
  • More
    • Firms
    • Law Practice
    • Trending
    • Press Release
Legal MagLegal Mag
Home » Enzo BioChem Settles With NJ, Other States for $4.5M Over Health Data Breach
Litigation

Enzo BioChem Settles With NJ, Other States for $4.5M Over Health Data Breach

News RoomBy News RoomAugust 14, 20244 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Enzo BioChem has agreed to a $4.5 million settlement with New Jersey, New York and Connecticut over its alleged deficient data and security safeguards, which led to a 2023 ransomware attack that compromised the personal health data of 2.4 million patients, including about 331,600 New Jersey residents.

An investigation into the April 2023 cyberattack on Enzo revealed that the company’s networks were accessed using two employee login credentials with administrator privileges. The heightened risk of the attack was due to the practice of those two logins being shared between five employees. One of the login credentials had not been changed in 10 years, according to the consent order reached between the company and the states.

Enzo, a New York-based biotechnology company that offers diagnostic testing at its laboratories in New York, Connecticut and New Jersey, was represented by counsel with Baker & Hostetler.

The cyberattack installed malicious software on Enzo’s systems, a fact that the company was not aware of until several days later because there was no monitoring system for suspicious activity, according to the order.

“The attackers subsequently provided respondents with information concerning the systems and data they had accessed, including a listing of hundreds of thousands of files the attackers had exfiltrated, which the attackers claimed comprised approximately 1.4 terabytes of data, some of which contained patient information,” the order said. “The attackers demanded a ransom payment to provide the decryption key to unlock the encrypted files and not publicly release the stolen information.”

New Jersey will receive about $930,000, New York will recoup $2.8 million, and Connecticut is set to receive approximately $743,110, each state announced.

The states’ attorneys general, Matthew J. Platkin from New Jersey, Letitia James from New York, and William Tong from Connecticut, filed an administrative action against Enzo over the breach. In it, the states alleged that a November 2021 Health Insurance Portability and Accountability Act risk assessment conducted by an Enzo vendor identified several risks to the company’s information systems and recommended corrective actions. Those were not implemented before the 2023 data breach, according to the consent order.

“It is stunning that as recently as last year, this health care company apparently did not abide by basic security precautions for online accounts, such as instructing its employees not to share passwords,” Platkin said. “Businesses of all kinds, and especially health care firms, must make robust cybersecurity a top priority. Poor data security and privacy practices make it easy for cybercriminals to exploit technological vulnerabilities and gain access to sensitive health information.”

The states alleged that the data breach violated HIPPA and the New Jersey Consumer Fraud Act. In addition to paying the settlement, Enzo agreed to strengthen its cybersecurity practices through various measures, including maintaining a comprehensive information security program designed to protect patient information.

In a statement, James said that getting blood work should not result in patients having their personal health information stolen by cybercriminals.

“Health care companies like Enzo that do not prioritize data security put patients at serious risk of fraud and identity theft,” James said. “Data security is part of patient safety, and my office will continue to hold companies accountable when they fail to protect New Yorkers.”

In a statement on the settlement, Tong said that a comprehensive Connecticut investigation discovered Enzo’s failure to safeguard the data of the state’s residents.

“This agreement sends a strong message to companies that we will hold them accountable if they fail to take reasonable measures to protect consumers’ information,” Tong said.

New Jersey acting Director of the Division of Consumer Affairs Cari Fais said in a news release that the division is committed to ensuring that businesses implement strong information security measures and holding businesses accountable when they fail to take proper precautions to safeguard consumers’ data.

Enzo was represented by Kimberly C. Gordy, a partner with Baker & Hostetler in Houston. Gordy did not immediately respond to a request for comment.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePFAS’ Regulatory Scrutiny Here to Stay Despite Legal Challenges, Environmental Experts Say
Next Article Pa. Appeals Court Rejects ‘Statutory Employer’ Challenge to $15.5M Worker Injury Verdict

Related Posts

Miami Judge Threatened: Perpetrator Gets 20 Years in Prison

August 23, 2024

Lawsuit Says NYS Assembly Refuses To Certify Ex-Legislative Director’s $100K Harassment Judgment

August 23, 2024

Judge Grants Sanctions Request Against IT Consulting Company Following ‘Egregious’ Document Production Behavior

August 23, 2024
Latest Articles

States challenge bankrupt 23andMe’s right to auction genetic information

June 11, 20250 Views

Jimmy Buffett’s widow battles co-trustee over $275 million trust

June 6, 20251 Views

Longtime Hardee’s franchisee sues chain over franchise agreement dispute

May 29, 20253 Views

Apple warns ruling in App Store case may cost ‘substantial sums annually’

May 8, 20253 Views
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

The 2024 Am Law 100: Ranked by Gross Revenue

By News RoomApril 16, 2024

For the full 2024 Am Law 100 report, click here. For more ways to analyze the…

The 2024 A-List: Top 20 Firms

August 6, 2024

Defending Claims Where Extreme Weather Is to Blame: Our Changing Climate’s Impact on Civil Litigation

July 18, 2024
© 2025 Legal Mag. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.