Court Rules
All enforcement actions
SettlementHigh Risk

NJ Division of Consumer Affairs Fines Virtua Medical Group $417K for HIPAA Violations

Virtua Medical Group, P.A.April 4, 2018New Jersey Attorney General

Penalty Amount

$417,816

Consumers Affected

1,654

Summary

Virtua Medical Group agreed to pay $417,816 and implement a corrective action plan to settle allegations that it failed to properly secure electronic protected health information (ePHI). A vendor's server misconfiguration publicly exposed the medical records of over 1,650 patients via Google searches. The New Jersey Division of Consumer Affairs found VMG violated HIPAA's Security and Privacy Rules by not adequately vetting the vendor's security and failing to conduct proper risk analysis.

Remedy

VMG must pay $417,816 in civil penalties and fees. It must hire a third-party to conduct a thorough security risk analysis of ePHI storage, transmission, and receipt, submitting reports to the Division within 180 days and annually for two years. The Corrective Action Plan mandates improved data security practices and vendor oversight.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should immediately review all vendor and business associate agreements, particularly those involving third-party service providers that handle sensitive data like medical transcriptions or cloud storage. Specific clauses to scrutinize include security requirements (encryption, access controls), mandatory risk assessment obligations, breach notification timelines and procedures, audit rights for compliance verification, and data retention/destruction terms. Given this enforcement action, agreements may need strengthening to require vendors to provide regular security certifications (e.g., SOC 2), implement mandatory security training, and include explicit indemnification for data breaches caused by vendor negligence. For customer or partner agreements, ensure data processing addendums incorporate HIPAA-level safeguards and clearly allocate liability for third-party mishandling of protected information.

Contract Search Terms

business associate agreementrisk assessment clausesecurity requirements specificationbreach notification procedureaudit rights provisiondata encryption standardvendor management policyHIPAA compliance certificationincident response plandata retention schedule

Laws Cited

Health Insurance Portability and Accountability Act (HIPAA) Security RuleHealth Insurance Portability and Accountability Act (HIPAA) Privacy RuleNew Jersey Consumer Fraud Act

Violation Types

Entity Details

Entity

Virtua Medical Group, P.A.

Also known as: Virtua Medical Group

Industry

Healthcare

Official Sources

Source Evidence

Entity Name
"Virtua Medical Group, P.A. (“VMG”)"
Fine Amount
"pay $417,816"
Violation Types
"violated the federal Health Insurance Portability and Accountability Act’s (HIPAA) Security Rule"
Violation Types
"publicly exposed the medical information – including patient names, medical diagnoses and prescriptions"
Violation Types
"VMG was not aware of the source of the information viewed by the daughter because Best Medical Transcription had not notified them of the security breach"
Laws Cited
"Health Insurance Portability and Accountability Act’s (HIPAA) Security Rule"

Related Enforcement Actions

NJ

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.

NJ

U.S. Department of Transportation

A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.

NJ

Opportunity Financials, LLC

Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.

NJ

Sandoz Inc.

$400.0M

Attorney General Jennifer Davenport joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations of widespread price-fixing and anticompetitive conduct in the generic drug market. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to internal reforms to ensure fair competition.

NJ

New Jersey Division of Consumer Affairs

Press release announcing that Governor Mikie Sherrill will nominate consumer protection expert Christopher L. Peterson to serve as Director of the New Jersey Division of Consumer Affairs. Peterson is a former senior CFPB official and legal scholar. No enforcement action or privacy violation is described.

NJ

Paramount and Warner Bros.

The New Jersey Attorney General announced that Paramount and Warner Bros. have agreed to put their merger on hold while a lawsuit challenging the merger proceeds. The agreement prevents the merger from moving forward until the end of trial or June 1, 2027, whichever comes first.