Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 14, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 14, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 14, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 14, 2025

      I test a lot of AI coding tools, and this stunning new OpenAI release just saved me days of work

      May 14, 2025

      How to use your Android phone as a webcam when your laptop’s default won’t cut it

      May 14, 2025

      The 5 most customizable Linux desktop environments – when you want it your way

      May 14, 2025

      Gen AI use at work saps our motivation even as it boosts productivity, new research shows

      May 14, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Strategic Cloud Partner: Key to Business Success, Not Just Tech

      May 14, 2025
      Recent

      Strategic Cloud Partner: Key to Business Success, Not Just Tech

      May 14, 2025

      Perficient’s “What If? So What?” Podcast Wins Gold at the 2025 Hermes Creative Awards

      May 14, 2025

      PIM for Azure Resources

      May 14, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Windows 11 24H2’s Settings now bundles FAQs section to tell you more about your system

      May 14, 2025
      Recent

      Windows 11 24H2’s Settings now bundles FAQs section to tell you more about your system

      May 14, 2025

      You can now share an app/browser window with Copilot Vision to help you with different tasks

      May 14, 2025

      Microsoft will gradually retire SharePoint Alerts over the next two years

      May 14, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Enzo Biochem to Pay $4.5 Million Settlement Over Cybersecurity Failures Leading to Data Breach

    Enzo Biochem to Pay $4.5 Million Settlement Over Cybersecurity Failures Leading to Data Breach

    August 14, 2024

    Enzo Biochem, Inc., a biotechnology company providing diagnostic testing services, has agreed to pay $4.5 million to resolve regulatory charges that its lax security protocols contributed to a cyberattack in April 2023. The Enzo Biochem data breach compromised the personal and private health information of approximately 2.4 million patients, including Social Security numbers, health histories, and other sensitive data.

    This settlement by Enzo Biochem announced on Tuesday, was secured by attorneys general of New York, New Jersey, and Connecticut, following investigations that uncovered severe lapses in the company’s data security practices.

    New York Attorney General Letitia James, in partnership with her counterparts in Connecticut and New Jersey, emphasized the gravity of Enzo’s failure to protect patient data.

    “Getting blood work or medical testing should not result in patients having their personal and health information stolen by cybercriminals,” Attorney General James stated. Healthcare companies like Enzo that do not prioritize data security put patients at serious risk of fraud and identity theft. Data security is part of patient safety, and my office will continue to hold companies accountable when they fail to protect New Yorkers.

    Details of the Enzo Biochem Data Breach and Lapses

    The Enzo Biochem cyberattack in question occurred in April 2023, when attackers were able to gain access to Enzo’s systems using two employee login credentials. An investigation by the Office of the Attorney General (OAG) revealed that these credentials were shared among five employees, and one of them had not been updated in over a decade, creating a significant vulnerability.

    Once inside the system, the attackers installed malicious software across several of Enzo’s systems, allowing them to steal vast amounts of data unnoticed.

    One of the most important aspects of Enzo Biochem data breach was the lack of a proper monitoring system. Enzo was unaware of the unauthorized access for several days, a delay that enabled the attackers to extract sensitive patient information, including names, addresses, dates of birth, phone numbers, Social Security numbers, and medical treatment or diagnosis details.

    The Enzo Biochem data breach affected 2.4 million patients, with 1,457,843 of them residing in New York.

    Settlement and Future Obligations

    As part of the settlement, Enzo Biochem has agreed to a series of stringent measures to enhance its cybersecurity protocols. These measures are aimed at preventing future breaches and ensuring that the company complies with the highest standards of data protection. The key provisions of the settlement include:

    Comprehensive Information Security Program: Enzo is required to maintain a robust information security program designed to protect the security, confidentiality, and integrity of private information.
    Access Control Policies: The company must implement and maintain policies and procedures that limit access to personal information, ensuring that only authorized personnel can access sensitive data.
    Multi-Factor Authentication (MFA): Enzo is mandated to implement and maintain MFA for all individual user accounts, adding an extra layer of security to prevent unauthorized access.
    Password Management: The settlement requires the establishment and maintenance of policies that enforce the use of strong, complex passwords and regular password rotation to mitigate the risk of credential-based attacks.
    Data Encryption: All personal information, whether stored or transmitted, must be encrypted to protect it from unauthorized access.
    Annual Risk Assessments: Enzo must conduct and document annual risk assessments to identify and address potential security vulnerabilities.
    Incident Response Plan: The company is also required to develop, implement, and maintain a comprehensive incident response plan to address any future data security issues promptly.

    New York will receive $2.8 million of the $4.5 million penalty, while the remaining amount will be distributed between New Jersey and Connecticut. This settlement by Enzo Biochem not only holds Enzo accountable but also serves as a stern warning to other companies in the healthcare industry about the critical importance of robust cybersecurity measures.

    Ongoing Efforts to Enhance Data Security

    This Enzo Biochem data breach case is part of a broader effort by Attorney General James to improve data security practices across various industries. In recent months, her office has taken several actions to hold companies accountable for poor cybersecurity and to provide guidance on best practices. These efforts include launching privacy guides for businesses and consumers, issuing alerts on identity theft protection services, and leading a coalition to address the rise of social media account takeovers.

    Earlier this year, Attorney General James released a comprehensive data security guide aimed at helping companies strengthen their data protection practices. James also issued a business guide on preventing credential stuffing attacks, which are increasingly being used by cybercriminals to gain unauthorized access to user accounts.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleMicrosoft Tackles 9 Zero-Day Exploits in August 2024 Patch Tuesday Update
    Next Article Ensuring Compliance: CFO Perspectives on Third-Party Risk Management

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 15, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-30419 – NI Circuit Design Suite SymbolEditor Out-of-Bounds Read Vulnerability

    May 15, 2025

    1 Comment

    1. insurance on September 2, 2024 1:46 PM

      Understanding Policy Riders: Policy riders can customize your insurance coverage to better meet your needs. At MAFA Insurance, we help clients understand the value of adding riders like critical illness or accidental death benefits to their policies.

      Reply
    Leave A Reply Cancel Reply

    Continue Reading

    Botswana Cyber Revolution Summit 2024: Leading the Charge in Cybersecurity Innovation

    Development

    10 Best Free and Open Source Linux Document Processors

    Linux

    King Bob pleads guilty to Scattered Spider-linked cryptocurrency thefts from investors

    Development

    Can you still get a Windows 10 upgrade for free in 2025? Short answer: Maybe

    News & Updates
    Hostinger

    Highlights

    Development

    What Is Cloud Computing?

    January 27, 2025

    Learn what cloud computing is, its benefits, types, key providers, and cost-saving strategies to help…

    Q&A: 10 emerging technologies to watch in 2024

    August 7, 2024

    The Surface you know and love (or hate) is dead — Microsoft’s Windows hardware enters a new era

    February 20, 2025

    King Arthur: Legion IX Set to Launch on Xbox Series X|S on May 6, 2025

    April 20, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.