Court Rules
All enforcement actions
SettlementMedium Risk

NY AG Fines HealthAlliance $550K for Unpatched Vulnerability

HealthAllianceDecember 9, 2024New York Attorney General

Penalty Amount

$550,000

Consumers Affected

242,641

Summary

New York Attorney General Letitia James secured a $550,000 settlement from Hudson Valley health care operator HealthAlliance over a 2023 data breach that compromised the personal and medical information of 242,641 New Yorkers. The breach occurred after HealthAlliance failed to patch a known vulnerability in its web application system, allowing cyberattackers to exfiltrate patient and employee data. As part of the settlement, HealthAlliance must pay the penalty and implement enhanced cybersecurity measures including a comprehensive security program, patch management policy, and data inventory requirements.

Remedy

HealthAlliance must pay $550,000 in penalties, with $850,000 of a $1.4 million total penalty suspended due to its financial condition and role providing essential care in underserved areas. The entity is required to implement a comprehensive information security program, maintain a data inventory with appropriate encryption, adopt a patch management policy requiring critical vulnerabilities to be patched within 72 hours or neutralized, and implement additional network activity restriction and monitoring measures.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams should review all vendor agreements with healthcare technology providers to ensure they include requirements for timely notification of security vulnerabilities, and that the company's patch management policies are aligned with vendor remediation timelines. Contracts should also mandate that vendors notify the company immediately of any critical vulnerabilities, and that the company has the right to take systems offline if patches cannot be applied within 72 hours. Additionally, teams should update data security clauses to require encryption of all patient and employee data, maintenance of a data inventory, and network monitoring/restriction measures. For healthcare entities, ensure that any settlement or consent decree requirements for information security programs are incorporated into vendor service agreements to avoid future liability.

Contract Search Terms

patch management policyvulnerability remediation timelinevendor security alertdata inventory requirementscritical vulnerability patchinghealth data securitynetwork activity monitoringencryption of private information

Violation Types

Entity Details

Entity

HealthAlliance

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"secured $550,000 from a Hudson Valley health care facility operator, HealthAlliance"
Fine Amount
"HealthAlliance is required to pay $550,000 in penalties"
Fine Amount
"HealthAlliance agreed to pay a $1,400,000 penalty, of which $850,000 will be suspended"
Event Date
"December 9, 2024"
Jurisdiction
"New York Attorney General Letitia James"
Event Type
"As a result of today’s agreement"

Related Enforcement Actions

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.

NY

Evolutions Festival LLC and 845 Vibrations LLC

$5.9M

New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.

NY

No specific company named

$25K

New York Attorney General Letitia James issued a consumer alert warning businesses not to charge unconscionably excessive prices for essential goods and services during the storm emergency. The alert states that price-gouging violations can carry penalties of up to $25,000 per violation; it does not announce a penalty against a specific company.

NY

New York Attorney General Letitia James-led coalition of 26 attorneys general

New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.