New York State announces $4.5M settlement with Eyemed Vision Care - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Health/Employee Benefits News
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Health/Employee Benefits News
Health/Employee Benefits News RSS Get our newsletter
Order Prints
October 18, 2022 Health/Employee Benefits News
Share
Share
Tweet
Email

New York State announces $4.5M settlement with Eyemed Vision Care

By Press Release

New York State Superintendent of Financial Services Adrienne A. Harris announced today that EyeMed Vision Care LLC (“EyeMed”) will pay a $4.5 million penalty to New York State for violations of DFS’s Cybersecurity Regulation (23 NYCRR Part 500) that contributed to the exposure of hundreds of thousands of consumers’ sensitive, non-public, personal health data, including data concerning minors. 

“It is critically important that consumers’ non-public information is kept safe from potential criminal activity, and DFS’s first-in-the-nation cybersecurity regulation requires New York-regulated entities to take that responsibility seriously,” said Superintendent Harris. “This settlement demonstrates DFS’s ongoing commitment to protecting consumers while ensuring the safety and soundness of financial institutions from cyber threats.” 

EyeMed, a licensed health insurance company, collects non-public information from its customers in the normal course of business. The Department’s investigation revealed that as a result of a July 1, 2020 phishing attack, a bad actor gained access to a shared EyeMed email mailbox which contained over six years’ worth of consumer non-public information (“NPI”), including that of minors.  

Upon further investigation, the Department found that, among other things, EyeMed had violated the Department’s cybersecurity regulation by failing to implement multi-factor authentication (“MFA”) throughout its email environment. Moreover, EyeMed failed to limit user access privileges by allowing nine employees to share login credentials to the affected email mailbox and failed to implement sufficient data retention and disposal processes, resulting in over six years’ worth of consumer data being accessible through the affected email mailbox. Had these controls been in place, the July 1, 2020 cybersecurity event could have been prevented or been limited in scope.  

In addition, the Department discovered that EyeMed failed to conduct an adequate risk assessment, a core requirement of the cybersecurity regulation, which could have identified the user access privilege and data disposal risks associated with the email mailbox that was subjected to the phishing attack. As a result, EyeMed’s cybersecurity certifications for the calendar years 2018 through 2021 were improper. 

As part of the settlement, EyeMed agreed to undertake significant remedial measures to better secure its data. Among other things, EyeMed will conduct a comprehensive cybersecurity risk assessment and develop a detailed action plan describing how EyeMed will address the risks identified in that assessment. The action plan will be subject to the review and approval of the Department.  

DFS’s Cybersecurity Regulation became effective in March 2017 and it has served as a model for other regulators, including the U.S. Federal Trade Commission, multiple states, the National Association of Insurance Commissioners (NAIC), and the CSBS Nonbank Model Data Security Law.  

To review the EyeMed consent order, visit the DFS website.

Press Release

Older

Colonial Surety offers commercial general liability protection for small businesses

Newer

Study targeting young insurance workers finds job commitment

Advisor News

  • Investor use of online brokerage accounts, new investment techniques rises
  • How 831(b) plans can protect your practice from unexpected, uninsured costs
  • Does a $1M make you rich? Many millionaires today don’t think so
  • Implications of in-service rollovers on in-plan income adoption
  • 2025 Top 5 Advisor Stories: From the ‘Age Wave’ to Gen Z angst
More Advisor News

Annuity News

  • Great-West Life & Annuity Insurance Company Trademark Application for “EMPOWER BENEFIT CONSULTING SERVICES” Filed: Great-West Life & Annuity Insurance Company
  • 2025 Top 5 Annuity Stories: Lawsuits, layoffs and Brighthouse sale rumors
  • An Application for the Trademark “DYNAMIC RETIREMENT MANAGER” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Product understanding will drive the future of insurance
  • Prudential launches FlexGuard 2.0 RILA
More Annuity News

Life Insurance News

  • Baby On Board
  • 2025 Top 5 Life Insurance Stories: IUL takes center stage as lawsuits pile up
  • Private placement securities continue to be attractive to insurers
  • Inszone Insurance Services Expands Benefits Department in Michigan with Acquisition of Voyage Benefits, LLC
  • Affordability pressures are reshaping pricing, products and strategy for 2026
More Life Insurance News

Property and Casualty News

  • How Selma Residents Are Safeguarding Wealth with Precious Metals Amid Economic Recovery
  • W. R. Berkley Corporation Names Erin Rotz President of Berkley Fire & Marine
  • Home insurance costs soar in North Bay
  • Enlyte to Acquire PartsTrader, Complementing Mitchell’s Auto Physical Damage Technology Solutions: Enlyte
  • TOP DEMOCRATS ON ENVIRONMENT, FINANCE, AND BANKING COMMITTEES LAUNCH INVESTIGATION INTO INSURANCE RATING COMPANY DEMOTECH, EVALUATIONS OF INSURER FINANCIAL STABILITY AMID GROWING CLIMATE RISK
More Property and Casualty News

- Presented By -

Top Read Stories

  • How the life insurance industry can reach the social media generations
More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • Two industry finance experts join National Life Group amid accelerated growth
  • National Life Group Announces Leadership Transition at Equity Services, Inc.
  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet