Penalty Amount
$100,000
Consumers Affected
6,443
EmblemHealth, Inc. settled with the New Jersey Attorney General over a 2016 data breach where Medicare Health Insurance Claim Numbers (containing Social Security numbers) were improperly disclosed on mailing labels to over 81,000 customers, including 6,443 in New Jersey. The company agreed to pay a $100,000 civil penalty and implement compliance reforms including ceasing use of HICNs with SSNs, enhancing employee training, and notifying the state of future breaches.
EmblemHealth must pay a $100,000 penalty, discontinue using HICNs that include SSNs for customer identification in mailings, implement formal responsibility transfer and privacy training for employees, and report any future breaches affecting New Jersey customers to the Division of Consumer Affairs for three years.
In-house legal teams should review vendor agreements and customer-facing documents (e.g., evidence of coverage mailings, privacy notices). Specifically, scrutinize clauses governing data sharing, data minimization, and instructions for third-party vendors to ensure sensitive identifiers like HICNs/SSNs are never included on physical mailings. Review employee training obligations and breach notification protocols to ensure they meet or exceed state requirements (like the NJ Identity Theft Prevention Act) and HIPAA standards. Contracts may need amendments to mandate explicit data field removal instructions for vendors, prohibit the inclusion of full SSNs on any mailed materials, and require immediate state notification for any unauthorized disclosure of health or SSN data.
Entity
EmblemHealth, Inc.
Also known as: EmblemHealth
Industry
Healthcare"health insurance provider EmblemHealth, Inc."
"pay the State a $100,000 civil penalty"
"violated the New Jersey Identity Theft Prevention Act, the New Jersey Consumer Fraud Act and the Health Insurance Portability and Accountability Act (HIPAA)."
"the label affixed to the mailing improperly included each customer’s HICN, which incorporates the nine digits of the customer’s Social Security number"
A multistate coalition co-led by New Jersey won a federal court order rejecting the Trump Administration’s decision not to request funding for the CFPB. The order struck down that decision and directed the Administration to follow the law and fund the agency; no monetary penalty or privacy violation is described.
New Jersey’s Attorney General and Division of Consumer Affairs alerted the public that three synthetic kratom-related compounds became illegal to possess or sell in the state under a temporary federal scheduling order. The release describes a controlled-substance alert, not a privacy enforcement action, and identifies no company, privacy violation, or monetary penalty.
$2.3M
Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.
$694.0M
New Jersey's Attorney General and Division of Consumer Affairs, along with 41 Attorneys General, reached a $694 million settlement with subprime auto lender Credit Acceptance Corporation over allegations it originated unaffordable loans its own systems predicted borrowers could not repay, employed aggressive debt-collection tactics, and failed to prevent deceptive vehicle-service contract and GAP product 'packing' by dealers. The multistate settlement stepped in after the CFPB permanently dropped its 2023 enforcement action against CAC in 2025. CAC will provide $60 million in cash restitution, $634 million in debt relief, an additional $15 million to the states, and implement injunctive lending reforms including loan off ramps, pre-loan disclosures, add-on packing safeguards, and a seven-year vehicle price cap. Note: this is a consumer-protection lending enforcement action, not a privacy matter; violation categories are best-fit mappings from the available taxonomy.
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.
$96.5M
New Jersey and a coalition of states and territories obtained preliminary approval for a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to raise drug prices. The settlements total approximately $96.5 million, and eligible consumers may submit claims for compensation.