Court Rules
All enforcement actions
Consent DecreeHigh RiskMultistate

NJ-Led Multistate $4.5M Settlement with Enzo Biochem for Data Breach

Enzo Biochem, Inc.August 13, 2024New Jersey Attorney General

Penalty Amount

$4,500,000

Consumers Affected

2,400,000

Summary

Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.

Remedy

Enzo must pay $4.5 million and implement a comprehensive information security program, including multi-factor authentication, strong passwords, encryption, annual risk assessments, and an incident response plan.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams should prioritize reviewing all agreements involving the handling of protected health information (PHI), particularly Business Associate Agreements (BAAs) with vendors and service providers, customer contracts for laboratory services, and employee data access agreements. Key clauses to scrutinize include data security obligations (e.g., encryption, access controls), breach notification timelines and procedures (ensuring alignment with HIPAA's 60-day requirement and stricter state laws), audit rights to verify vendor security practices, indemnification provisions covering data breach costs, and restrictions on subprocessors. Given the settlement's focus on deficient cybersecurity leading to a ransomware attack, contracts may need amendments to mandate specific security frameworks (e.g., NIST), require regular penetration testing and risk assessments, shorten breach notification windows beyond HIPAA minimums, and incorporate state-specific compliance certifications (e.g., New Jersey Consumer Fraud Act).

Contract Search Terms

HIPAA Business Associate Agreementdata security addendumbreach notification clauseencryption standard clauseincident response plan requirementaudit rights clauseindemnification for security incidentssubprocessor approval processdata retention and disposal schedulestate privacy compliance certification

Laws Cited

Health Insurance Portability and Accountability ActNew Jersey Consumer Fraud Act

Violation Types

Entity Details

Entity

Enzo Biochem, Inc.

Also known as: Enzo Biochem

Industry

Healthcare

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Enzo Biochem, Inc."
Fine Amount
"$4.5 million"
Laws Cited
"Health Insurance Portability and Accountability Act"
Laws Cited
"New Jersey Consumer Fraud Act"
Violation Types
"failing to adequately safeguard the personal and private health information of its patients"
Consumers Affected
"approximately 2.4 million patients nationwide"

Related Enforcement Actions

CT

Enzo Biochem, Inc.

$4.5M

Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.

NY

Enzo Biochem, Inc.

$4.5M

New York Attorney General Letitia James, along with the Attorneys General of Connecticut and New Jersey, settled with Enzo Biochem, Inc. for $4.5 million over a 2023 ransomware attack that exposed health and personal data of 2.4 million patients, including 1.4 million New York residents. The investigation found Enzo had inadequate data security practices, including shared employee login credentials, lack of multi-factor authentication, no suspicious activity monitoring, and unencrypted personal information. As part of the settlement, Enzo will pay the penalty and implement enhanced cybersecurity measures including MFA, encryption, risk assessments, and an incident response plan.

NJ

Trump Administration

A multistate coalition co-led by New Jersey won a federal court order rejecting the Trump Administration’s decision not to request funding for the CFPB. The order struck down that decision and directed the Administration to follow the law and fund the agency; no monetary penalty or privacy violation is described.

NJ

Mitragynine pseudoindoxyl, MGM-15, and MGM-16

New Jersey’s Attorney General and Division of Consumer Affairs alerted the public that three synthetic kratom-related compounds became illegal to possess or sell in the state under a temporary federal scheduling order. The release describes a controlled-substance alert, not a privacy enforcement action, and identifies no company, privacy violation, or monetary penalty.

NJ

Laboratory Corporation of America Holdings (LabCorp)

$2.3M

Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.

NJ

Credit Acceptance Corporation (CAC)

$694.0M

New Jersey's Attorney General and Division of Consumer Affairs, along with 41 Attorneys General, reached a $694 million settlement with subprime auto lender Credit Acceptance Corporation over allegations it originated unaffordable loans its own systems predicted borrowers could not repay, employed aggressive debt-collection tactics, and failed to prevent deceptive vehicle-service contract and GAP product 'packing' by dealers. The multistate settlement stepped in after the CFPB permanently dropped its 2023 enforcement action against CAC in 2025. CAC will provide $60 million in cash restitution, $634 million in debt relief, an additional $15 million to the states, and implement injunctive lending reforms including loan off ramps, pre-loan disclosures, add-on packing safeguards, and a seven-year vehicle price cap. Note: this is a consumer-protection lending enforcement action, not a privacy matter; violation categories are best-fit mappings from the available taxonomy.