Court Rules
All enforcement actions
SettlementMedium Risk

NJ AG Settles with Diamond Institute for $495K Over HIPAA Breach

Diamond Institute for Infertility and Menopause, LLCOctober 12, 2021New Jersey Attorney General

Penalty Amount

$495,000

Consumers Affected

14,663

Summary

The New Jersey Attorney General settled with Diamond Institute for Infertility and Menopause, LLC, following a data breach that exposed the electronic protected health information (ePHI) of 14,663 patients. The investigation found the clinic failed to implement required HIPAA Security Rule safeguards, including risk assessments, encryption, and access controls. The $495,000 settlement includes civil penalties and requires the clinic to implement a comprehensive information security program and corrective actions.

Remedy

Diamond must pay $495,000 ($412,300 in civil penalties and $82,700 in costs/fees). The settlement mandates the development and implementation of a comprehensive information security program, appointment of a qualified HIPAA Privacy and Security Officer, employee training, a written incident response plan, and specific technical safeguards including encryption, logging, access controls, risk assessments, and password management.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review vendor agreements (especially Business Associate Agreements under HIPAA), customer/patient service agreements, and employee access policies. Key clauses to scrutinize include data security requirements (encryption, access controls), breach notification timelines and procedures, audit and monitoring rights, and corrective action plan obligations. Given the settlement's focus on inadequate risk assessments and encryption, contracts should be updated to mandate regular security risk assessments, specify encryption standards for ePHI, require prompt breach reporting consistent with NJ and HIPAA timelines, and include enforceable remedies for security failures.

Contract Search Terms

risk assessmentencryptionaccess controlsbreach notification clausedata processing addendumsecurity incident responsebusiness associate agreementdata retention scheduleaudit rightscorrective action plan

Laws Cited

New Jersey Consumer Fraud ActHIPAA Privacy RuleHIPAA Security Rule

Violation Types

Entity Details

Entity

Diamond Institute for Infertility and Menopause, LLC

Also known as: Diamond Institute for Infertility and Menopause

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"Diamond Institute for Infertility and Menopause, LLC (“Diamond”)"
Fine Amount
"The settlement of $495,000 includes $412,300 in civil penalties and $82,700 in investigative costs and attorneys’ fees."
Violation Types
"failing to conduct an accurate and thorough risk assessment of potential risk and vulnerabilities to the confidentiality, integrity and availability of ePHI; failing to implement a mechanism to encrypt ePHI; failing to review and modify security measures as needed to continue reasonable and appropriate protection of ePHI; failing to implement proper procedures for creating, changing, and safeguarding passwords; and failing to implement procedures to verify that the person seeking access to ePHI is who they claim to be."
Consumers Affected
"compromised the personal information of 14,663 patients, including 11,071 New Jersey residents."
Remedy Types
"developing and implementing a comprehensive information security program that includes regular updates to keep pace with changes in technology and security threats; appointing a new HIPAA Privacy and Security Officer... training employees... developing and implementing a written incident response and data breach notification plan... implementing personal information safeguards and controls, including encryption, logging and monitoring, access controls, a risk assessment program, and password management."
Laws Cited
"violated the New Jersey Consumer Fraud Act, the federal Health Insurance Portability and Accountability Act (“HIPAA”) Privacy Rule, and the HIPAA Security Rule"

Related Enforcement Actions

NJ

Match Group, Inc.

$650K

The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.

NJ

Amazon

On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.

NJ

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.

NJ

U.S. Department of Transportation

A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.

NJ

Opportunity Financials, LLC

Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.

NJ

Sandoz Inc.

$400.0M

Attorney General Jennifer Davenport joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations of widespread price-fixing and anticompetitive conduct in the generic drug market. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to internal reforms to ensure fair competition.