Insurer Healthplex Fined for Violating NY Cyber Rules (1)

Aug. 14, 2025, 8:15 PM UTCUpdated: Aug. 14, 2025, 9:02 PM UTC

Dental health insurer Healthplex Inc. will pay a $2 million fine to New York State Department of Financial Services for violating the state’s cybersecurity regulation, the regulator said Thursday.

A probe of Healthplex Inc.'s practices revealed that the company lacked a data retention policy limiting the storage of emails in Microsoft Outlook or multi-factor authentication controls set up in its Microsoft Outlook 365 email environment, the regulator said in a statement.

The regulator began investigating Healthplex, a UnitedHealth Group Inc. subsidiary, following a 2021 phishing incident that exposed the personal health information of tens of thousands of New York ...

Learn more about Bloomberg Law or Log In to keep reading:

Learn About Bloomberg Law

AI-powered legal analytics, workflow tools and premium legal & business news.

Already a subscriber?

Log in to keep reading or access research tools.