Penalty Amount
$4,500,000
Consumers Affected
2,400,000
Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.
Enzo must pay $4.5 million and implement a comprehensive information security program, including multi-factor authentication, strong passwords, encryption, annual risk assessments, and an incident response plan.
In-house legal teams should prioritize reviewing all agreements involving the handling of protected health information (PHI), particularly Business Associate Agreements (BAAs) with vendors and service providers, customer contracts for laboratory services, and employee data access agreements. Key clauses to scrutinize include data security obligations (e.g., encryption, access controls), breach notification timelines and procedures (ensuring alignment with HIPAA's 60-day requirement and stricter state laws), audit rights to verify vendor security practices, indemnification provisions covering data breach costs, and restrictions on subprocessors. Given the settlement's focus on deficient cybersecurity leading to a ransomware attack, contracts may need amendments to mandate specific security frameworks (e.g., NIST), require regular penetration testing and risk assessments, shorten breach notification windows beyond HIPAA minimums, and incorporate state-specific compliance certifications (e.g., New Jersey Consumer Fraud Act).
Entity
Enzo Biochem, Inc.
Also known as: Enzo Biochem
Industry
HealthcareOfficial Press Release
https://www.njoag.gov/attorney-general-platkin-and-multistate-coalition-secure-4-5-million-from-enzo-biochem-for-failing-to-protect-health-data/
2024 0813 Enzo NJ Consent Order DCA Executed
https://www.nj.gov/oag/newsreleases24/2024-0813_Enzo-NJ-Consent-Order-DCA-Executed.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Enzo Biochem, Inc."
"$4.5 million"
"Health Insurance Portability and Accountability Act"
"New Jersey Consumer Fraud Act"
"failing to adequately safeguard the personal and private health information of its patients"
"approximately 2.4 million patients nationwide"
$4.5M
Connecticut Attorney General William Tong, along with New York and New Jersey attorneys general, secured a $4.5 million settlement from Enzo Biochem, Inc. for failing to protect patient health data, resulting in a ransomware attack that compromised 2.4 million patients' information. Enzo must pay the fine and implement enhanced cybersecurity measures including multi-factor authentication and annual risk assessments.
$4.5M
New York Attorney General Letitia James, along with the Attorneys General of Connecticut and New Jersey, settled with Enzo Biochem, Inc. for $4.5 million over a 2023 ransomware attack that exposed health and personal data of 2.4 million patients, including 1.4 million New York residents. The investigation found Enzo had inadequate data security practices, including shared employee login credentials, lack of multi-factor authentication, no suspicious activity monitoring, and unencrypted personal information. As part of the settlement, Enzo will pay the penalty and implement enhanced cybersecurity measures including MFA, encryption, risk assessments, and an incident response plan.
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.
On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.
A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.