Law360 Delta Dental Fined $2.25M for Data Breach Lapses in New York
Article Content
- •Delta Dental fined $2.25 million for cybersecurity compliance failures.
- •The breach involved the MOVEit file transfer software.
- •NYDFS found Delta Dental's cybersecurity program inadequate.
Delta Dental has been fined $2.25 million by the New York State Department of Financial Services (NYDFS) due to inadequate cybersecurity policies that led to a data breach. The investigation revealed that the company's cybersecurity program failed to comply with state regulations for data protection, resulting in the theft of sensitive consumer information. The breach involved the MOVEit file transfer software, which was exploited to access private data. As a consequence of these findings, Delta Dental is now facing significant financial penalties. The company has been ordered to improve its cybersecurity measures to prevent future incidents. This case highlights ongoing concerns regarding data protection practices in the healthcare sector. The breach's impact on consumers remains significant, as sensitive personal information was compromised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Delta Dental in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and 13.5GB from Philips, including sensitive engineering documents and project plans. The attacks exploit…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…