In addition to the penalties, the law firm must take measures to enhance its cybersecurity posture.
The attacker was able to exploit a vulnerability in HPMB’s Microsoft Exchange email server, according to a March 27 New York attorney general news release.
Electronic health information, patient names, dates of birth and Social Security numbers were exposed as part of the breach.