Court Rules
All enforcement actions
SettlementHigh RiskMultistate

Multistate AGs Fine Enzo Biochem $4.5M for Health Data Breach

Enzo Biochem, Inc.August 13, 2024Connecticut Attorney General

Penalty Amount

$4,500,000

Consumers Affected

2,400,000

Summary

Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.

Remedy

Enzo must pay $4.5 million and adopt comprehensive cybersecurity measures such as maintaining an information security program, implementing multi-factor authentication, encrypting personal information, conducting annual risk assessments, and developing an incident response plan.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review vendor agreements (especially those handling health data), customer/patient consent forms, and employee access policies for clauses related to data security, breach notification, and compliance with health data regulations. Specific clauses to examine include data protection standards, incident response timelines, audit rights, and requirements for multi-factor authentication and regular risk assessments. Given the ransomware attack stemming from poor credential management (shared, outdated logins), agreements should be updated to enforce strong authentication practices, encryption requirements, mandatory security training for personnel, and clear accountability for third-party subcontractors.

Contract Search Terms

data security clausemulti-factor authentication requirementrisk assessment provisionhealth data protectionbreach notification timelineemployee credential managementransomware mitigationHIPAA business associate agreementthird-party vendor securityencryption standards

Violation Types

Entity Details

Entity

Enzo Biochem, Inc.

Also known as: Enzo Biochem

Industry

Healthcare

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Enzo Biochem, Inc. (Enzo)"
Fine Amount
"$4.5 million"
Violation Types
"failing to adequately safeguard the personal and private health information of its patients"

Related Enforcement Actions

NY

Enzo Biochem, Inc.

$4.5M

New York Attorney General Letitia James, along with the Attorneys General of Connecticut and New Jersey, settled with Enzo Biochem, Inc. for $4.5 million over a 2023 ransomware attack that exposed health and personal data of 2.4 million patients, including 1.4 million New York residents. The investigation found Enzo had inadequate data security practices, including shared employee login credentials, lack of multi-factor authentication, no suspicious activity monitoring, and unencrypted personal information. As part of the settlement, Enzo will pay the penalty and implement enhanced cybersecurity measures including MFA, encryption, risk assessments, and an incident response plan.

NJ

Enzo Biochem, Inc.

$4.5M

Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.

CT

Zillow Group, Inc. and Redfin Corporation

$2.0M

Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.

CT

Anthem, ConnectiCare, and UnitedHealthcare

Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.

CT

TaxAct

$275K

Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.

CT

Manchester City Nissan

$4.0M

Connecticut Attorney General William Tong and the Federal Trade Commission announced a $4 million settlement with Manchester City Nissan (Chase Nissan LLC) resolving allegations that the dealership double-charged for 'certified pre-owned' vehicles and collected unauthorized junk fees. The settlement requires payment for consumer redress, prohibits misrepresentations, mandates clear disclosure of the maximum total price, and requires express informed consent for all charges.