Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

NJ Businesses Liable for Healthcare Data Breach Regardless of Misuse

Author: Scarinci Hollenbeck, LLC

Date: February 2, 2017

Key Contacts

Back

New Jersey businesses can be held liable for data breaches involving sensitive healthcare data, even if the information wasn’t misused.

Healthcare Data

The Third Circuit Court of Appeals recently held that Horizon Blue Cross Blue Shield of New Jersey may be held liable for a data breach under the Fair Credit Reporting Act (FCRA), despite the lack of evidence that any of the stolen data was used to the plaintiffs’ detriment. 

Healthcare Data Breaches
The Court’s decision in serves as an important reminder of the significant liability New Jersey businesses can face in the wake of patient data breach. According to several studies, the healthcare companies are more susceptible to data breaches when compared to other industries. In fact, the Ponemon Institute found that almost 90 percent of all healthcare organizations it studied suffered at least one data breach in the past two years. On average, those cyberattacks cost $2.2 million per incident.

Risk Mitigation Steps
Because of the significant risk of exposure faced by healthcare companies, it is important that they take appropriate steps to address those risks.  For example:

  • Review IT infrastructure with those that maintain the company’s servers, hardware, software and cloud-based systems to ensure proper security systems are in place. As companies may be held liable for a data breach despite a lack of evidence of misuse or breach, ensuring that the proper standard of care is taken to protect patient data is essential to mitigating risk.
  • Review policies, handbooks, and security procedures applicable to company personnel and personnel of key business associates. Employees are the first line of defense against purposeful third party intrusion and accidental misuse. 
  • Review agreements with vendors and suppliers to ensure that they are committing to a proper standard of care and are properly responsible for any data breach they cause affecting company’s patients’ data.
  • Ensuring proper disclosure is made to patients regarding the company’s use, sharing, storage and transmittal of company’s patients’ data and obtaining a proper acknowledgment of any such disclosure.

Potential Resources
This is a growing area of potential risk and liability.  New Jersey businesses that handle personal health information or other patient data should take steps to minimize the risk of data breaches.  Those steps should include consulting with attorneys specializing in cybersecurity risk analysis and mitigation to help navigate these steps. 

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Scarinci Hollenbeck, LLC, LLC

    Related Posts

    See all
    What Founders Can Learn From Start-up Suits post image

    What Founders Can Learn From Start-up Suits

    High-profile founder litigation is more than just a media spectacle. For startup founders, these cases underscore the legal and structural risks that can arise when rapid growth outpaces formal oversight. While launching a new company can be both an exciting and deeply rewarding endeavor, founders must be mindful that it also comes with significant risks. […]

    Author: Dan Brecher

    Link to post with title - "What Founders Can Learn From Start-up Suits"
    Corporate Governance Reviews: A Practical Guide for New Jersey Companies post image

    Corporate Governance Reviews: A Practical Guide for New Jersey Companies

    Every New Jersey company should periodically evaluate its governance framework. Strong corporate governance protects directors and officers, builds investor confidence, reduces litigation exposure, and positions a company for sustainable growth. The first quarter of the year is a great time to evaluate your corporate governance practices and perform any routine maintenance needed to keep that […]

    Author: Ken Hollenbeck

    Link to post with title - "Corporate Governance Reviews: A Practical Guide for New Jersey Companies"
    What to Do After Being Served with a Lawsuit: Steps to Protect Your Legal Rights post image

    What to Do After Being Served with a Lawsuit: Steps to Protect Your Legal Rights

    Being served with a lawsuit is one of the most stressful legal events a business or individual can face. Whether the claim involves a contract dispute, an employment matter, an intellectual property issue, or another legal challenge, the actions you take in the first few days can significantly shape the outcome of your case. Acting […]

    Author: Robert E. Levy

    Link to post with title - "What to Do After Being Served with a Lawsuit: Steps to Protect Your Legal Rights"
    Will 2026 Be a Banner Year for SPACs? Understanding the Risks and Opportunities post image

    Will 2026 Be a Banner Year for SPACs? Understanding the Risks and Opportunities

    Special Purpose Acquisition Companies (SPACs) continue to gain momentum as we move through 2026. After enduring a significant contraction following the 2021 boom and the regulatory scrutiny that followed, SPAC activity rebounded sharply in 2025 and now carries forward into 2026 with real momentum. The SPAC resurgence reflects broader improvements in both market conditions and the […]

    Author: Dan Brecher

    Link to post with title - "Will 2026 Be a Banner Year for SPACs? Understanding the Risks and Opportunities"
    Why Compliance Monitoring Matters for NY and NJ Businesses post image

    Why Compliance Monitoring Matters for NY and NJ Businesses

    Compliance programs are no longer judged by how they look on paper, but by how they function in the real world. Compliance monitoring is the ongoing process of reviewing, testing, and evaluating whether policies, procedures, and controls are being followed—and whether they are actually working. What Is Compliance Monitoring? In today’s heightened regulatory environment, compliance […]

    Author: Dan Brecher

    Link to post with title - "Why Compliance Monitoring Matters for NY and NJ Businesses"
    When Are New Jersey Business Owners Personally Liable for Corporate Debt? post image

    When Are New Jersey Business Owners Personally Liable for Corporate Debt?

    New Jersey personal guaranty liability is a critical issue for business owners who regularly sign contracts on behalf of their companies. A recent New Jersey Supreme Court decision provides valuable guidance on when a business owner can be held personally responsible for a company’s debt. Under the Court’s decision in Extech Building Materials, Inc. v. […]

    Author: Charles H. Friedrich

    Link to post with title - "When Are New Jersey Business Owners Personally Liable for Corporate Debt?"

    No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

    Sign up to get the latest from our attorneys!

    Explore What Matters Most to You.

    Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

    Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

    Let`s get in touch!

    * The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.

    Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!