惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
小众软件
小众软件
美团技术团队
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
D
Docker
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Hackread – Cybersecurity News, Data Breaches, AI and More
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
B
Blog
雷峰网
雷峰网
The Cloudflare Blog

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Delta Dental Agrees to $2.25 Million Settlement with NYDF...
2026-05-08 · via Privacy & Cybersecurity Law Blog

Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response

On April 30, 2026, the New York State Department of Financial Services (NYDFS) announced a $2.25 million settlement with Delta Dental Insurance Company, a licensed health insurer, and Delta Dental of New York, Inc., a licensed non-profit dental expense indemnity (together, “Delta Dental”), for violations of NYDFS’s Cybersecurity Regulation (23 NYCRR Part 500).

The settlement follows NYDFS’s investigation into Delta Dental’s response to a 2023 cybersecurity incident that exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer tool. Delta Dental reported that the unauthorized access to its MOVEit tool resulted in the theft of approximately 60,000 files containing patient information, such as names, addresses, Social Security numbers, government-issued identification numbers, financial account information, tax identification numbers, health insurance policy numbers and patient health information.

NYDFS alleged that Delta Dental’s “inadequate incident response policies and procedures allowed threat actors to exploit vulnerabilities to obtain unauthorized access to New Yorkers' personal information.” Specifically, NYDFS alleged that Delta Dental violated the Cybersecurity Regulation as follows:

  • Failure to Limit Data Retention: Delta Dental failed to implement data retention settings, policies, procedures, and controls designed to protect consumer data and the company’s IT systems. For example, Delta Dental lengthened its IT systems’ default retention settings and stored the exfiltrated files for longer than 30 days.
  • Delayed Notice to NYDFS: Despite becoming aware of the incident in June 2023 and determining consumer data was affected in July 2023, Delta Dental did not notify NYDFS of the incident until December 15, 2023. (The Cybersecurity Regulation requires covered entities to notify NYDFS within 72 hours of discovery of an incident.)
  • Lacked Incident Response Policies: NYDFS found that Delta Dental failed to implement and maintain a written policy addressing incident response, including a plan that sufficiently addressed the company’s reporting obligations to regulators.

NYDFS’s consent order was limited to a monetary penalty, with no further action taken by the regulator against Delta Dental.