Penalty Amount
$1,000,000
Consumers Affected
213,935
New York Attorney General Letitia James reached a settlement with Albany ENT & Allergy Services (AENT) over two 2023 ransomware attacks that compromised the medical records of over 200,000 New Yorkers. The OAG found AENT failed to maintain reasonable data security safeguards, inadequately oversaw third-party security vendors, and initially failed to disclose all exposed consumer data to the state. AENT will pay $1 million in penalties (with $500,000 suspended pending $2.25 million in security investments) and implement comprehensive data security measures including encryption, multi-factor authentication, and vendor oversight.
AENT must pay $1 million in penalties to New York State, with $500,000 suspended provided the company invests $2.25 million over five years to upgrade and maintain its information security program. AENT is required to establish and maintain a comprehensive information security program including: an inventory of all private information on its networks; encryption of all private information stored or transmitted; multi-factor authentication for remote device access; controls to monitor and log security activity; a process for timely installation of critical security updates; an incident response plan; and oversight of third-party information security vendors. AENT must also offer affected consumers one year of free credit monitoring.
In-house legal teams should review all agreements with third-party security vendors to ensure they require timely installation of security updates, network activity logging, encryption of private information, and multi-factor authentication for remote access. Vendor contracts must include clear oversight provisions mandating that vendors maintain reasonable security safeguards and promptly report breaches. Companies should also update their internal information security program clauses to require private information inventories, incident response planning, and full compliance with state breach notification laws to prevent delayed or incomplete disclosures to regulators.
Entity
Albany ENT & Allergy Services, P.C.
Also known as: Albany ENT & Allergy Services
Industry
HealthcareOfficial Press Release
https://ag.ny.gov/press-release/2024/attorney-general-james-secures-225-million-capital-region-health-care-provider
FxJ0ZW4o7gU73uaNLCuYbaKlm7oyWp6YrNfSYre7FHg=377 ;JSUlJSUlJSU
https://urldefense.com/v3/__https:/links-1.govdelivery.com/CL0/https:*2F*2Fag.ny.gov*2Fsites*2Fdefault*2Ffiles*2Fsettlements-agreements*2Faent-final-aod-fully-executed.pdf/1/01000192d91d22b0-7dd89d9d-f202-4bbd-b3c3-17f05ec89ea7-000000/FxJ0ZW4o7gU73uaNLCuYbaKlm7oyWp6YrNfSYre7FHg=377__;JSUlJSUlJSUlJQ!!Ke5ujdWW74OM!9irw9YLOR2rAVD2KJ9xkok0A7hpb3hVA-EdXWbkuL6xHRvBR1hNG2DdmQCDs8-Zdr1XZRnnYVdbudtFZjGx7PFDLARfebkWUMTRZwASJSDix$
New York Attorney General Enforcement Page
https://ag.ny.gov/press-releases
"Albany ENT & Allergy Services, P.C. (AENT)"
"AENT is also required to pay $1 million in penalties and costs to the state"
"AENT suffered two cyberattacks that compromised the medical records of over 200,000 New Yorkers"
"AENT failed to adequately monitor the third-party vendors responsible for their cybersecurity functions. As a result, those vendors did not timely install critical security software updates, adequately log and monitor network activity, properly encrypt consumers’ private information before and after the attacks, utilize multi-factor authentication for all remote access, or otherwise maintain a reasonable information security program."
"compromised the medical records of over 200,000 New Yorkers"
"The OAG investigation determined that AENT had not initially disclosed to the state the exposure of over 80,000 New York resident driver’s license numbers"
New York Attorney General Letitia James obtained a temporary restraining order from the U.S. District Court for the Northern District of California blocking Paramount Skydance Corp.'s proposed $110 billion merger with Warner Bros. Discovery, Inc. The lawsuit alleges the merger would illegally reduce competition in film and television, leading to higher prices and fewer choices for consumers.
$18.0M
New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.
New York Attorney General Letitia James and 11 other attorneys general filed a lawsuit to block the proposed $110 billion merger between Paramount Skydance Corp. and Warner Bros. Discovery, Inc., alleging the merger would violate antitrust law by reducing competition in theatrical film releases and basic cable television markets, leading to higher prices for consumers and fewer diverse entertainment options.
New York Attorney General Letitia James sued 3M, DuPont, and other chemical companies for knowingly causing decades of PFAS pollution through consumer products. The lawsuit alleges the companies hid toxicity risks, failed to warn the public, and seeks cleanup funding, damages, and injunctive relief.
New York Attorney General Letitia James joined a bipartisan coalition of 48 other attorneys general in submitting comments to the FCC urging stronger rules to combat illegal robocalls. The coalition recommends expanding the definition of telephone number resellers, prohibiting resale of certain numbers, and requiring mandatory education for companies selling phone numbers. This is a regulatory advocacy action, not a direct enforcement action against a specific company.
New York Attorney General Letitia James issued guidance to New Yorkers donating to Venezuela earthquake relief, warning about fraudulent charities and scams. The guidance provides tips on verifying charities, avoiding phishing, and reporting suspicious organizations.