Court Rules
All enforcement actions
SettlementMedium Risk

NY AG Fines Albany ENT $500K for Inadequate Data Security

Albany ENT & Allergy Services, P.C.October 29, 2024New York Attorney General

Penalty Amount

$1,000,000

Consumers Affected

213,935

Summary

New York Attorney General Letitia James reached a settlement with Albany ENT & Allergy Services (AENT) over two 2023 ransomware attacks that compromised the medical records of over 200,000 New Yorkers. The OAG found AENT failed to maintain reasonable data security safeguards, inadequately oversaw third-party security vendors, and initially failed to disclose all exposed consumer data to the state. AENT will pay $1 million in penalties (with $500,000 suspended pending $2.25 million in security investments) and implement comprehensive data security measures including encryption, multi-factor authentication, and vendor oversight.

Remedy

AENT must pay $1 million in penalties to New York State, with $500,000 suspended provided the company invests $2.25 million over five years to upgrade and maintain its information security program. AENT is required to establish and maintain a comprehensive information security program including: an inventory of all private information on its networks; encryption of all private information stored or transmitted; multi-factor authentication for remote device access; controls to monitor and log security activity; a process for timely installation of critical security updates; an incident response plan; and oversight of third-party information security vendors. AENT must also offer affected consumers one year of free credit monitoring.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams should review all agreements with third-party security vendors to ensure they require timely installation of security updates, network activity logging, encryption of private information, and multi-factor authentication for remote access. Vendor contracts must include clear oversight provisions mandating that vendors maintain reasonable security safeguards and promptly report breaches. Companies should also update their internal information security program clauses to require private information inventories, incident response planning, and full compliance with state breach notification laws to prevent delayed or incomplete disclosures to regulators.

Contract Search Terms

third-party security vendor oversightdata encryption (stored and transmitted)multi-factor authentication (remote access)security patch management timelineincident response planprivate information inventorynetwork activity logging and monitoringbreach notification disclosure requirements

Violation Types

Entity Details

Entity

Albany ENT & Allergy Services, P.C.

Also known as: Albany ENT & Allergy Services

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"Albany ENT & Allergy Services, P.C. (AENT)"
Fine Amount
"AENT is also required to pay $1 million in penalties and costs to the state"
Violation Types
"AENT suffered two cyberattacks that compromised the medical records of over 200,000 New Yorkers"
Violation Types
"AENT failed to adequately monitor the third-party vendors responsible for their cybersecurity functions. As a result, those vendors did not timely install critical security software updates, adequately log and monitor network activity, properly encrypt consumers’ private information before and after the attacks, utilize multi-factor authentication for all remote access, or otherwise maintain a reasonable information security program."
Violation Types
"compromised the medical records of over 200,000 New Yorkers"
Violation Types
"The OAG investigation determined that AENT had not initially disclosed to the state the exposure of over 80,000 New York resident driver’s license numbers"

Related Enforcement Actions

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.

NY

Evolutions Festival LLC and 845 Vibrations LLC

$5.9M

New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.

NY

No specific company named

$25K

New York Attorney General Letitia James issued a consumer alert warning businesses not to charge unconscionably excessive prices for essential goods and services during the storm emergency. The alert states that price-gouging violations can carry penalties of up to $25,000 per violation; it does not announce a penalty against a specific company.

NY

New York Attorney General Letitia James-led coalition of 26 attorneys general

New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.