Penalty Amount
$4,500,000
Consumers Affected
2,400,000
Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.
Enzo must pay $4.5 million and implement a comprehensive information security program, including multi-factor authentication, strong passwords, encryption, annual risk assessments, and an incident response plan.
In-house legal teams should prioritize reviewing all agreements involving the handling of protected health information (PHI), particularly Business Associate Agreements (BAAs) with vendors and service providers, customer contracts for laboratory services, and employee data access agreements. Key clauses to scrutinize include data security obligations (e.g., encryption, access controls), breach notification timelines and procedures (ensuring alignment with HIPAA's 60-day requirement and stricter state laws), audit rights to verify vendor security practices, indemnification provisions covering data breach costs, and restrictions on subprocessors. Given the settlement's focus on deficient cybersecurity leading to a ransomware attack, contracts may need amendments to mandate specific security frameworks (e.g., NIST), require regular penetration testing and risk assessments, shorten breach notification windows beyond HIPAA minimums, and incorporate state-specific compliance certifications (e.g., New Jersey Consumer Fraud Act).
Entity
Enzo Biochem, Inc.
Also known as: Enzo Biochem
Industry
HealthcareOfficial Press Release
https://www.njoag.gov/attorney-general-platkin-and-multistate-coalition-secure-4-5-million-from-enzo-biochem-for-failing-to-protect-health-data/
2024 0813 Enzo NJ Consent Order DCA Executed
https://www.nj.gov/oag/newsreleases24/2024-0813_Enzo-NJ-Consent-Order-DCA-Executed.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Enzo Biochem, Inc."
"$4.5 million"
"Health Insurance Portability and Accountability Act"
"New Jersey Consumer Fraud Act"
"failing to adequately safeguard the personal and private health information of its patients"
"approximately 2.4 million patients nationwide"
$4.5M
Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.
$4.5M
New York Attorney General Letitia James, along with the Attorneys General of Connecticut and New Jersey, settled with Enzo Biochem, Inc. for $4.5 million over a 2023 ransomware attack that exposed health and personal data of 2.4 million patients, including 1.4 million New York residents. The investigation found Enzo had inadequate data security practices, including shared employee login credentials, lack of multi-factor authentication, no suspicious activity monitoring, and unencrypted personal information. As part of the settlement, Enzo will pay the penalty and implement enhanced cybersecurity measures including MFA, encryption, risk assessments, and an incident response plan.
A multistate coalition co-led by New Jersey won a federal court order rejecting the Trump Administration’s decision not to request funding for the CFPB. The order struck down that decision and directed the Administration to follow the law and fund the agency; no monetary penalty or privacy violation is described.
New Jersey’s Attorney General and Division of Consumer Affairs alerted the public that three synthetic kratom-related compounds became illegal to possess or sell in the state under a temporary federal scheduling order. The release describes a controlled-substance alert, not a privacy enforcement action, and identifies no company, privacy violation, or monetary penalty.
$2.3M
Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.
$694.0M
New Jersey's Attorney General and Division of Consumer Affairs, along with 41 Attorneys General, reached a $694 million settlement with subprime auto lender Credit Acceptance Corporation over allegations it originated unaffordable loans its own systems predicted borrowers could not repay, employed aggressive debt-collection tactics, and failed to prevent deceptive vehicle-service contract and GAP product 'packing' by dealers. The multistate settlement stepped in after the CFPB permanently dropped its 2023 enforcement action against CAC in 2025. CAC will provide $60 million in cash restitution, $634 million in debt relief, an additional $15 million to the states, and implement injunctive lending reforms including loan off ramps, pre-loan disclosures, add-on packing safeguards, and a seven-year vehicle price cap. Note: this is a consumer-protection lending enforcement action, not a privacy matter; violation categories are best-fit mappings from the available taxonomy.