Court Rules
All enforcement actions
Consent DecreeHigh RiskMultistate

NJ-Led Multistate $4.5M Settlement with Enzo Biochem for Data Breach

Enzo Biochem, Inc.August 13, 2024New Jersey Attorney General

Penalty Amount

$4,500,000

Consumers Affected

2,400,000

Summary

Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.

Remedy

Enzo must pay $4.5 million and implement a comprehensive information security program, including multi-factor authentication, strong passwords, encryption, annual risk assessments, and an incident response plan.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams should prioritize reviewing all agreements involving the handling of protected health information (PHI), particularly Business Associate Agreements (BAAs) with vendors and service providers, customer contracts for laboratory services, and employee data access agreements. Key clauses to scrutinize include data security obligations (e.g., encryption, access controls), breach notification timelines and procedures (ensuring alignment with HIPAA's 60-day requirement and stricter state laws), audit rights to verify vendor security practices, indemnification provisions covering data breach costs, and restrictions on subprocessors. Given the settlement's focus on deficient cybersecurity leading to a ransomware attack, contracts may need amendments to mandate specific security frameworks (e.g., NIST), require regular penetration testing and risk assessments, shorten breach notification windows beyond HIPAA minimums, and incorporate state-specific compliance certifications (e.g., New Jersey Consumer Fraud Act).

Contract Search Terms

HIPAA Business Associate Agreementdata security addendumbreach notification clauseencryption standard clauseincident response plan requirementaudit rights clauseindemnification for security incidentssubprocessor approval processdata retention and disposal schedulestate privacy compliance certification

Laws Cited

Health Insurance Portability and Accountability ActNew Jersey Consumer Fraud Act

Violation Types

Entity Details

Entity

Enzo Biochem, Inc.

Also known as: Enzo Biochem

Industry

Healthcare

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Enzo Biochem, Inc."
Fine Amount
"$4.5 million"
Laws Cited
"Health Insurance Portability and Accountability Act"
Laws Cited
"New Jersey Consumer Fraud Act"
Violation Types
"failing to adequately safeguard the personal and private health information of its patients"
Consumers Affected
"approximately 2.4 million patients nationwide"

Related Enforcement Actions

CT

Enzo Biochem, Inc.

$4.5M

Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.

NY

Enzo Biochem, Inc.

$4.5M

New York Attorney General Letitia James, along with the Attorneys General of Connecticut and New Jersey, settled with Enzo Biochem, Inc. for $4.5 million over a 2023 ransomware attack that exposed health and personal data of 2.4 million patients, including 1.4 million New York residents. The investigation found Enzo had inadequate data security practices, including shared employee login credentials, lack of multi-factor authentication, no suspicious activity monitoring, and unencrypted personal information. As part of the settlement, Enzo will pay the penalty and implement enhanced cybersecurity measures including MFA, encryption, risk assessments, and an incident response plan.

NJ

Match Group, Inc.

$650K

The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.

NJ

Amazon

On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.

NJ

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.

NJ

U.S. Department of Transportation

A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.