惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
IT之家
IT之家
博客园 - Franky
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Help Net Security
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 【当耐特】
月光博客
月光博客
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件

Privacy & Cybersecurity Law Blog

EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template
Delta Dental Agrees to $2.25 Million Settlement with NYDF...
2026-05-08 · via Privacy & Cybersecurity Law Blog

Delta Dental Agrees to $2.25 Million Settlement with NYDFS Over MOVEit Data Breach Response

On April 30, 2026, the New York State Department of Financial Services (NYDFS) announced a $2.25 million settlement with Delta Dental Insurance Company, a licensed health insurer, and Delta Dental of New York, Inc., a licensed non-profit dental expense indemnity (together, “Delta Dental”), for violations of NYDFS’s Cybersecurity Regulation (23 NYCRR Part 500).

The settlement follows NYDFS’s investigation into Delta Dental’s response to a 2023 cybersecurity incident that exploited a zero-day vulnerability in Progress Software’s MOVEit file transfer tool. Delta Dental reported that the unauthorized access to its MOVEit tool resulted in the theft of approximately 60,000 files containing patient information, such as names, addresses, Social Security numbers, government-issued identification numbers, financial account information, tax identification numbers, health insurance policy numbers and patient health information.

NYDFS alleged that Delta Dental’s “inadequate incident response policies and procedures allowed threat actors to exploit vulnerabilities to obtain unauthorized access to New Yorkers' personal information.” Specifically, NYDFS alleged that Delta Dental violated the Cybersecurity Regulation as follows:

  • Failure to Limit Data Retention: Delta Dental failed to implement data retention settings, policies, procedures, and controls designed to protect consumer data and the company’s IT systems. For example, Delta Dental lengthened its IT systems’ default retention settings and stored the exfiltrated files for longer than 30 days.
  • Delayed Notice to NYDFS: Despite becoming aware of the incident in June 2023 and determining consumer data was affected in July 2023, Delta Dental did not notify NYDFS of the incident until December 15, 2023. (The Cybersecurity Regulation requires covered entities to notify NYDFS within 72 hours of discovery of an incident.)
  • Lacked Incident Response Policies: NYDFS found that Delta Dental failed to implement and maintain a written policy addressing incident response, including a plan that sufficiently addressed the company’s reporting obligations to regulators.

NYDFS’s consent order was limited to a monetary penalty, with no further action taken by the regulator against Delta Dental.