Penalty Amount
$450,000
Consumers Affected
198,260
US Radiology Specialists, Inc. failed to upgrade its firewall, leading to a ransomware attack that compromised the personal and health data of over 198,000 patients, including 92,000 New Yorkers. The company agreed to pay $450,000 in penalties and implement comprehensive data security measures, including encryption and data deletion policies.
US Radiology must pay $450,000 in penalties, enhance its information security program, create an IT asset management program, encrypt patient data, implement penetration testing, and delete unnecessary personal data.
In-house legal teams should review all vendor and service provider agreements, particularly those involving healthcare data processing or radiology services. Focus on clauses mandating specific data security standards (e.g., firewall maintenance, encryption), breach notification timelines and procedures, data retention and deletion policies, and audit rights to verify compliance. Given the entity's role as a service provider to facilities like Windsong Radiology, agreements must explicitly require adherence to HIPAA and state data security laws, with provisions for mandatory security upgrades and regular vulnerability assessments. Contracts may need amendments to include concrete technical requirements (e.g., timely patching of known vulnerabilities) and indemnification terms for data breaches resulting from inadequate security.
Entity
US Radiology Specialists, Inc.
Also known as: US Radiology
Industry
HealthcareOfficial Press Release
https://ag.ny.gov/press-release/2023/attorney-general-james-secures-450000-medical-company-providing-services-western
us radiology aod
https://ag.ny.gov/sites/default/files/settlements-agreements/us-radiology-aod.pdf
New York Attorney General Enforcement Page
https://ag.ny.gov/press-releases
"US Radiology Specialists, Inc. (US Radiology)"
"$450,000"
"did not prioritize upgrading its hardware, which left its network exposed to a known vulnerability, leading to a ransomware attack"
"198,260 patients"
New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.
$400.0M
New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.
New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.
$5.9M
New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.
$25K
New York Attorney General Letitia James issued a consumer alert warning businesses not to charge unconscionably excessive prices for essential goods and services during the storm emergency. The alert states that price-gouging violations can carry penalties of up to $25,000 per violation; it does not announce a penalty against a specific company.
New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.