Biotech Company Pays $4.5 Million for Data Breach

Rivkin Radler LLP
Contact

Rivkin Radler LLP

The Office of the New York State Attorney General announced on August 13 that Letitia James, along with the Attorneys General of Connecticut and New Jersey, fined Enzo Biochem, Inc. $4.5 million for failing to adequately safeguard its patients’ health data.

Enzo conducts drug research and development, and provides diagnostic services. In 2023, hackers accessed Enzo’s networks using two employee login credentials. The credentials were shared among five Enzo employees and one set of credentials had not been changed for 10 years. The hackers installed malicious software on Enzo’s systems, stealing files and data concerning 2.4 million patients, including names, addresses, birth dates, phone numbers, social security numbers, and health information. Enzo did not become aware of the breach for several days because it lacked a system to monitor suspicious activity. 

In addition to the $4.5 million penalty, Enzo has agreed to adopt a series of safeguards to strengthen its cybersecurity going forward.

This settlement is only the latest example of the New York Attorney General’s focus on enforcing cybersecurity.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Rivkin Radler LLP

Written by:

Rivkin Radler LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Rivkin Radler LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide