Cookies on BBB.org

We use cookies to give users the best content and online experience. By clicking “Accept All Cookies”, you agree to allow us to use all cookies. Visit our Privacy Policy to learn more.

Manage Cookies
Share
Business Profile

Medical Lab and Testing

Enzo

This business is NOT BBB Accredited.

Find BBB Accredited Businesses in Medical Lab and Testing.

About

Important information

  • Government Actions:
    Government Action: BBB reports on known government actions involving business’ marketplace conduct:
    NYAG Secures $4.5 Million from Biotech Company for Failing to Protect New Yorkers’ Health Data

    The following describes a government action that has been resolved by either a settlement or a decision by a court or administrative agency. If the matter is being appealed, it will be noted below.

    On 8/13/2024, New York Attorney General Letitia James and the attorneys general of Connecticut and New Jersey announced that they had secured $4.5 million from Enzo Biochem, Inc. (Enzo) for failing to adequately safeguard the personal and private health information of its patients. Enzo is a biotechnology company that offers patients diagnostic testing at its laboratories in New York, Connecticut, and New Jersey. The Office of the Attorney General (OAG) found that Enzo had poor data security practices, which led to a ransomware attack that compromised the personal and private information of approximately 2.4 million patients, including more than 1.4 million New York residents. As a result of today’s agreement, Enzo will pay $4.5 million, of which New York will receive $2.8 million, and will strengthen its data security practices. 

    In 2023, cyber-attackers were able to access Enzo’s networks using two employee login credentials. The OAG later found that those two login credentials were shared between five Enzo employees and one of the login credentials hadn’t been changed in the last ten years, putting Enzo at heightened risk of a cyberattack. Once logged in, the attackers installed malicious software on several of Enzo’s systems. Enzo was not aware of the attackers’ activity until several days later because the company did not have a system or process in place to monitor or provide notice of suspicious activity. The attackers were able to steal files and data that contained patient information for 2.4 million patients, including 1,457,843 New Yorkers. Information that was compromised included names, addresses, dates of birth, phone numbers, Social Security numbers, and medical treatment/diagnosis information. 

    As a result of today’s agreement, Enzo has agreed to pay a $4.5 million penalty, of which New York will receive $2.8 million, and adopt a series of measures aimed at strengthening its cybersecurity practices going forward, including: 

    -Maintaining a comprehensive information security program designed to protect the security, confidentiality, and integrity of private information;
    -Implementing and maintaining policies and procedures that limit access to personal information;
    -Implementing and maintaining multi-factor authentication for all individual user accounts;
    -Establishing and maintaining policies and procedures that require using strong, complex passwords and password rotation;
    -Encrypting all personal information, whether stored or transmitted;
    -Conducting and documenting annual risk assessments; and
    -Developing, implementing, and maintaining a comprehensive incident response plan for potential data security issues

Business Details

BBB File Opened:
2/1/1990
Business Started:
1/1/1986
Business Incorporated:
1/1/1986
Type of Entity:
Corporation
Alternate Names:
Enzo Clinical Labs, Inc.
Business Management:
Ms. Kara Cannon, CEO
Ms. Patricia Eckart, CFO

Additional Contact Information

Principal Contacts
Ms. Kara Cannon, CEO
Customer Contacts
Ms. Patricia Eckart, CFO
Fax numbers
Primary Fax: (631) 755-5561
Additional Phone Numbers
Other Phone: (631) 755-5500
Other Phone: (800) 522-5052

Additional Information

Business Categories
Medical Lab and Testing

More Resources

BBB Business Profiles may not be reproduced for sales or promotional purposes.

BBB Business Profiles are provided solely to assist you in exercising your own best judgment. BBB asks third parties who publish complaints, reviews and/or responses on this website to affirm that the information provided is accurate. However, BBB does not verify the accuracy of information provided by third parties, and does not guarantee the accuracy of any information in Business Profiles.

When considering complaint information, please take into account the company's size and volume of transactions, and understand that the nature of complaints and a firm's responses to them are often more important than the number of complaints.

BBB Business Profiles generally cover a three-year reporting period. BBB Business Profiles are subject to change at any time. If you choose to do business with this business, please let the business know that you contacted BBB for a BBB Business Profile.

As a matter of policy, BBB does not endorse any product, service or business. Businesses are under no obligation to seek BBB accreditation, and some businesses are not accredited because they have not sought BBB accreditation. BBB charges a fee for BBB Accreditation. This fee supports BBB's efforts to fulfill its mission of advancing marketplace trust.