Enzo Biochem Settles Ransomware Data Breach Class Action for $7.5 Million
The Farmingdale, NY-based life sciences and diagnostics company Enzo Biochem has agreed to pay $7.5 million to settle a consolidated class action lawsuit stemming from a 2023 ransomware attack and data breach. Hackers breached its network and used ransomware to encrypt files on April 6, 2024. According to regulatory filings, Enzo Biochem determined on April 11, 2023, that there had been unauthorized access to the clinical test information of 2,470,000 individuals. The compromised data was mostly limited to names and clinical test information, although approximately one-quarter of those individuals – around 600,000 – also had their Social Security numbers compromised in the incident. The Enzo Biochem data breach was one of the largest healthcare data breaches reported in 2023. Several Enzo Biochem class action lawsuits were proposed in response to the data breach alleging Enzo Biochem data security was substandard and Enzo Biochem was negligent by failing to implement reasonable and appropriate safeguards to protect the sensitive personal and health data it collected and stored. The...
December 2024 Healthcare Data Breach Report
It was a relatively quiet end to the year in terms of healthcare data breaches, with only 46 data breaches of 500 or more healthcare records reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) in December. The low December total meant that for only the second time since 2009, there was a year-over-year reduction in healthcare data breaches. The OCR data breach portal currently shows 721 reports of large data breaches in 2024, down 3.48% from 2023’s record-breaking total of 747 large healthcare data breaches. December saw the third-lowest monthly breach total of 2024, with large data breaches falling by 34.3% month-over-month to the second-lowest December total in the past 5 years, with 33 fewer large data breaches than December 2023. December was also a relatively good month in terms of breached healthcare records, with 3,938,375 healthcare records reported as exposed, impermissibly disclosed, or stolen – the second-lowest monthly total of 2024, although that does represent a 14.5% month-over-month increase in breached records. Compared...
Morrison Community Hospital Agrees to $675K Settlement to Resolve Ransomware Lawsuit
Morrison Community Hospital, a critical access hospital in Illinois, has agreed to a $675,000 settlement to resolve a lawsuit filed in response to a 2023 ransomware and data breach. On September 24, 2023, the BlackCat/ALPHV ransomware group used ransomware to encrypt files on its network after exfiltrating sensitive data. When the ransom was not paid, the BlackCat/ALPHV group leaked the stolen data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights on November 23, 2023, as involving the protected health information of 122,488 current and former patients. The compromised data included names, birth dates, addresses, Social Security numbers, and medical information. Affected patients took legal action against the hospital – In re: Morrison Community Hospital Data Breach Litigation – in the Circuit Court for the 14th Judicial District in Whiteside County, Illinois. The lawsuit alleged insufficient safeguards had been implemented to prevent cyberattacks which amounted to negligence, and as a result of that failure, a hacker was able to breach...
OSHA Terminates COVID-19 Rulemaking and Works on Standard Addressing a Broader Range of Infectious Diseases
The Occupational Safety and Health Administration (OSHA) has abandoned efforts to establish a final COVID-19 safety standard to ensure workers in healthcare settings are protected from COVID-19. OSHA issued an Emergency Temporary Standard (ETS) on June 21, 2021, after determining that COVID-19 posed a grave danger to healthcare workers. At that point, almost half a million healthcare workers had contracted COVID-19, and more than 1,600 healthcare workers had died as a result of COVID-19 infections. After issuing the ETS, OSHA received petitions from industry associations including the American Nurses Association, International Association of Fire Chiefs, and National Nurses United (NNU) urging OSHA to adopt a permanent standard to protect healthcare workers from COVID-19 and to also issue a separate standard covering a broader range of infectious diseases. OSHA submitted a draft final COVID-19 rule to the White House Office of Management and Budget on December 7, 2022; however, on April 10, 2023, House Joint Resolution 7 was signed into law by President Biden terminating the...
Email Accounts Compromised at LifeBridge Health
LifeBridge Health has discovered unauthorized access to employee email accounts. Effortless Office Enterprises has suffered a cyberattack, and Han Van Duong, M.D. has experienced a break-in and theft of laptop computers containing patient data. LifeBridge Health LifeBridge Health in Maryland has discovered unauthorized access to several employee email accounts. The breach was detected on November 12, 2024, and the forensic investigation determined that the email accounts had been compromised between August 27, 2024, and September 21, 2024. The breach was limited to email accounts, with no other systems affected. File attachments and emails in the account were reviewed and found to contain patient information. The types of information involved varied from individual to individual and may have included names plus one or more of the following: dates of birth, dates of service, Social Security numbers, medical record numbers, health insurance claim numbers, and limited treatment information. Individual notifications were mailed to the affected individuals on January 10, 2025, and...



