Feature Data Privacy
NYDFS's First 2026 Cybersecurity Fine Wasn't About the MOVEit Hack. It Was About What Happened After.
On April 29, 2026, NYDFS issued a $2.25 million consent order against Delta Dental of New York—its first 2026 cybersecurity enforcement action. The underlying breach was a 2023 MOVEit zero-day. The violations were late notification, inadequate data disposal, and insufficient incident response plan detail. And the consent order bars insurance reimbursement. Here's what the enforcement record tells your program.
Table of Contents
TL;DR
- NYDFS issued its first 2026 cybersecurity enforcement action on April 29: a $2.25 million consent order against Delta Dental of New York for a 2023 MOVEit breach
- The violations were not the hack itself—they were late notification (well beyond the 72-hour rule), inadequate data disposal policies, and insufficient incident response plan detail
- The consent order bars Delta Dental from seeking insurance reimbursement, indemnification, or tax deduction for the penalty—the financial hit is direct
- SEC Regulation S-P’s 30-day customer notification requirement became mandatory for smaller entities on June 3, 2026, and is a named 2026 SEC examination priority
- Multiple parallel notification clocks are now active for most regulated financial entities; most programs are under-documented on at least one
Delta Dental didn’t create the MOVEit vulnerability. Progress Software shipped it. The Clop ransomware group exploited it globally in May 2023, hitting thousands of organizations across industries. Delta Dental was one of them.
None of that insulated it from NYDFS. The $2.25 million fine wasn’t about the breach. It was about data Delta Dental retained longer than it should have, a notification the organization sent weeks or months late, and an incident response plan that didn’t have enough operational detail to function under real conditions.
That’s the enforcement architecture regulators across frameworks are now building: the breach is the predicate event, but the violations are the response.
NYDFS’s First 2026 Cybersecurity Enforcement Action
On April 29, 2026, the New York Department of Financial Services announced a consent order against Delta Dental of New York and Delta Dental Insurance Co., assessing a $2.25 million civil monetary penalty.
The underlying incident was the 2023 MOVEit zero-day—the Progress Software file transfer tool vulnerability that CISA rated critical and that affected government agencies, universities, financial institutions, and healthcare organizations worldwide. Delta Dental’s data was compromised through its use of MOVEit.
NYDFS found three violations, each independent of whether the breach was preventable:
Violation 1: Late notification. Delta Dental did not notify NYDFS until mid-December 2023—well beyond the 72-hour window required by 23 NYCRR Part 500. The MOVEit vulnerability became public in late May 2023 when Progress Software disclosed it. The gap between when the breach occurred and when NYDFS was notified spanned months.
Violation 2: Inadequate data disposal policies. NYDFS Part 500.13 requires covered entities to maintain policies for the secure disposal of nonpublic information no longer necessary for business operations. Delta Dental’s disposal policies were inadequate. The practical consequence: data that should have been deleted was still retained when the breach occurred, expanding the scope of what was exposed.
Violation 3: Insufficient incident response plan detail. Delta Dental’s IR plan lacked the specificity NYDFS considers necessary for operational effectiveness. A generic plan—phases, roles, a CISO named as overall owner—is not the same as a plan detailed enough to actually use during a real incident.
One additional term: the consent order expressly prohibits the companies from seeking insurance reimbursement, indemnification, or any federal or state tax deduction or tax credit for the $2.25 million penalty. The financial deterrent is uninsurable and non-deductible by design.
Delta Dental did not admit or deny the findings.
The 72-Hour Rule: What “Determines” Actually Means
The notification timing violation in the Delta Dental case turns on a single statutory word: determines.
Under 23 NYCRR 500.17, a covered entity must notify the NYDFS Superintendent as promptly as possible, and within 72 hours, after determining that a cybersecurity event has occurred. Not after completing a forensic investigation. Not after quantifying the full population of affected individuals. Not after confirming that data was actually exfiltrated.
After determining.
NYDFS has made clear through prior guidance and enforcement actions that “determining” occurs when the covered entity has sufficient information to conclude a reportable event has occurred. For a widely-publicized zero-day vulnerability like MOVEit: if your organization used MOVEit and you learned in late May 2023 that MOVEit was being actively exploited to exfiltrate customer data, that’s the moment you have sufficient information.
The argument that you needed to wait for investigation completion—to know exactly how many records were affected, exactly what data was taken, exactly who is at risk—is not an adequate justification for a notification that arrives months late. NYDFS and other regulators have consistently rejected this logic. Investigation continues after notification; notification doesn’t wait for investigation to finish.
Your incident response decision log should document the specific moment when the organization’s determination of a cybersecurity event occurs—the evidence available, who made the determination, and who approved the notification. That document is the first thing regulators ask for when they’re assessing whether notification timing was appropriate.
The Parallel Notification Landscape in 2026
The Delta Dental case is specifically about NYDFS Part 500. But most regulated financial entities are operating under multiple parallel notification obligations, each with its own clock, trigger definition, and reporting mechanism.
| Framework | Who It Covers | Clock | Trigger Event |
|---|---|---|---|
| NYDFS 23 NYCRR 500 | NY-licensed banks, insurers, mortgage servicers, fintechs | 72 hours | ”Determines” cybersecurity event occurred |
| Bank regulators (OCC/FDIC/Fed) | Banks and service providers to banks | 36 hours | ”Computer-security incident” determination |
| SEC Regulation S-P | Broker-dealers, RIAs, funds, transfer agents | 30 days (customer notification) | Unauthorized access to sensitive customer info |
| FTC Safeguards Rule | Non-bank financial institutions | 30 days (FTC notification) | Breach of 500+ consumers’ unencrypted info |
| SEC Item 1.05 (8-K) | Public companies | 4 business days | Material incident determination |
| State breach notification laws | Varies by state | 30–90 days (varies) | Unauthorized acquisition of personal info |
These clocks are independent of each other. A single incident at a registered investment adviser that holds New York licenses may trigger NYDFS (72 hours after determination), SEC Reg S-P (30-day customer notification), and potentially state notification laws covering affected customers in other jurisdictions—all with different trigger definitions running simultaneously.
The SEC Regulation S-P deadline matters specifically right now: smaller SEC-regulated entities—RIAs below $1.5 billion in AUM and funds below $1 billion—had a compliance deadline of June 3, 2026. Firms that relied on the extended deadline and haven’t built out a written incident response program and customer notification procedures are now operating without required controls. The SEC has named Regulation S-P compliance as a named 2026 Division of Examinations priority. That means exam staff are actively looking for it.
The Data Disposal Violation: The Part That Multiplies Your Risk
The data disposal violation doesn’t generate as many headlines as the notification timing failure, but it’s arguably the more consequential operational lesson.
Here’s why it matters. NYDFS found that Delta Dental’s data disposal policies were inadequate—meaning the organization retained nonpublic customer information beyond the point where it was necessary for business operations. When the MOVEit breach occurred, more data was exposed than needed to be available.
This is data disposal failure as a force multiplier: the policy gap doubled as a breach scope gap. Every piece of customer data retained beyond its legitimate retention period is incremental breach exposure that wouldn’t exist if the disposal program worked correctly.
The framework requirements are explicit. NYDFS Part 500.13 requires covered entities to include in their cybersecurity program policies and procedures for the secure disposal of nonpublic information no longer necessary for business operations, except where retention is required by law or regulation. The FTC Safeguards Rule includes a comparable data retention limitation. SEC Regulation S-P, in its amended form, includes data security provisions that touch retention and disposal practices.
A defensible data disposal program answers four questions:
What retention periods apply to each category of nonpublic information? Not a generic “7-year retention policy” but category-specific schedules tied to the business purpose and applicable regulatory requirements for each data type.
Who executes disposal at end-of-retention? A retention schedule that no one is actually running is not a disposal program—it’s a document. There needs to be an operational process with a specific owner.
What documentation exists that disposal occurred? When a breach happens and a regulator asks “why was this data still available?”, the answer needs to be documented evidence of disposal execution—not an assertion that the policy would have required disposal.
How does disposal interact with litigation holds and regulatory holds? Data on litigation hold or regulatory hold cannot be disposed of even if the retention period has passed. Your disposal program needs a mechanism to check for active holds before executing disposal.
The privacy impact assessment process includes data inventory and retention mapping precisely because the disposal obligation is only operationalizable when you know what data you have and what retention schedule applies to it.
The Incident Response Plan Specificity Gap
The third violation—insufficient IR plan detail—reflects a pattern NYDFS has been flagging for years.
Generic IR plans look adequate until they’re actually used. They describe phases: Identification, Containment, Eradication, Recovery, Lessons Learned. They name a CISO as owner. They reference outside counsel. They satisfy a checkbox review.
What they don’t do—and what NYDFS’s enforcement record consistently finds missing—is answer the operational questions that arise in the first six hours of a real incident:
At what point is the organization “determining” a cybersecurity event under 23 NYCRR 500? Who makes that determination? What evidence standard applies? Is there a written decision framework that produces a documented record?
Where does the NYDFS notification go and what does it include? Who drafts it, who approves it, who submits it to the NYDFS online portal? What information must the notification contain? Does anyone on your incident response team have the NYDFS portal credentials tested and ready?
How does the plan handle a third-party-originated breach? The MOVEit scenario is now a template case: the breach originates in a vendor’s software, the vendor’s investigation produces the forensic evidence, and the financial institution is responsible for regulatory notification based on evidence it doesn’t control the timeline of. Your IR plan should specify how you handle that dependency.
What evidence is preserved at the moment of determination? Digital forensic evidence can be altered by the same remediation steps that stop the breach. The plan should sequence evidence preservation before remediation—and specify who makes that call.
The NYDFS Part 500 Class A requirements post covers the full examination-readiness landscape. The IR plan specificity standard—detailed enough to be operationally useful under real incident conditions, not just documentation for its own sake—is one of the examination gaps that shows up most consistently.
The Insurance Prohibition Signal
The non-reimbursement term in the Delta Dental consent order—prohibiting insurance reimbursement, indemnification, or tax deduction for the penalty—has become increasingly standard in NYDFS cybersecurity enforcement since 2024.
It’s worth understanding what this term is doing. If a regulatory penalty is fully recoverable through D&O insurance or cyber insurance, the regulated entity bears none of the economic consequence—the insurer does. That model doesn’t deter the conduct regulators are targeting. The non-reimbursement term ensures the fine is a direct cost to the institution: borne by the people making governance decisions about notification timing, data disposal investment, and IR plan quality.
For risk and compliance teams working with insurance brokers and carriers: the increasing prevalence of non-reimbursement terms in regulatory consent orders changes the calculus on regulatory penalty coverage. Policies priced on the assumption that NYDFS penalties are recoverable may be overstating their protective value for the specific risk category they’re ostensibly covering.
By October 2025, NYDFS had issued 27 consent orders totaling more than $144 million in cybersecurity fines under Part 500 since Superintendent Harris took office. The Delta Dental consent order is the opening of the 2026 enforcement cycle. First doesn’t mean only.
So What?
The Delta Dental enforcement action established something that every regulated financial institution with a New York license needs to internalize: the breach creates the regulatory attention, but the violations are in the response.
You can be hit by a widely-publicized zero-day in third-party software you didn’t write, exploited by a criminal ransomware group you didn’t invite. You can remediate the technical issue completely and experience no downstream data misuse. And you can still receive a multi-million dollar regulatory penalty because your notification was late, your data disposal policy was inadequate, and your incident response plan wasn’t specific enough to actually use.
The data disposal gap costs you twice: it expands the breach scope and creates a standalone violation. The notification gap is a pure timing failure—preventable with a documented determination process and tested notification procedures. The IR plan gap is an investment failure—the cost of specificity is measured in hours of plan development; the cost of insufficient specificity is measured in consent order terms.
The Data Privacy Compliance Kit includes a multi-clock notification matrix, data inventory and retention mapping templates, and an incident response checklist structured around the determination moment—the clock-start event that determines whether your notification is timely under NYDFS, SEC Reg S-P, and FTC Safeguards.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did NYDFS find in the Delta Dental cybersecurity consent order?
When does the NYDFS 72-hour breach notification clock start?
Which institutions are covered by SEC Regulation S-P's 30-day customer notification requirement?
What does the Delta Dental consent order say about insurance reimbursement for the penalty?
What does 'adequate data disposal policy' mean under NYDFS Part 500?
What parallel notification obligations might apply to a single breach at a financial institution?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
New Jersey's A5328 Is the Costliest Data Broker Law in the Country — and It's Already in Effect for Sensitive Data
New Jersey signed A5328 on June 30, 2026, banning the sale of sensitive financial and personal data immediately and creating registration fees up to $1.5 million. GLBA covers some fintechs — but 'financial services' doesn't automatically mean exempt. Here's the analysis every fintech and data aggregator needs to run now.
Jul 29, 2026
Data Privacy
California's DELETE Act: The August 1, 2026 DROP Deadline and the GLBA Exemption Test Every Fintech Needs to Pass
California's DELETE Act requires data brokers to process consumer deletion requests through the DROP system starting August 1, 2026. The penalty is $200 per request per day. Most GLBA-covered financial institutions are exempt — but many fintechs aren't sure which category they're in. Here's how to run the analysis.
Jul 28, 2026
Data Privacy
Privacy Impact Assessment for Mixed GLBA and Non-GLBA Data: Scope the Data, Not the Entity
Use a data privacy impact assessment template to separate GLBA and non-GLBA processing by data flow, purpose, person, use, and state-law scope.
Jul 25, 2026