One customer service employee who clicked on one email has led to an enforcement action that will cost a company $2 million to settle with the New York Department of Financial Services, the regulator announced yesterday.
Why it matters: The penalty against Healthplex, Inc. underscores how a single phishing incident, which was compounded by missing cybersecurity controls and delayed reporting, can trigger sweeping regulatory consequences. DFS has made clear that complying with its cybersecurity regulation is not optional, and enforcement will be swift when companies fall short.
Driving the news:
- In late 2021, a Healthplex customer service employee clicked on a phishing email, giving threat actors access to their Microsoft Office 365 account.
- Because Healthplex lacked a data retention policy, the compromised mailbox held more than 100,000 emails, some containing nonpublic information (NPI).
- Multi-factor authentication (MFA) was not enabled for external access to the company’s Outlook Web Access after the company migrated to O365 earlier that year, in violation of DFS rules.
- Healthplex waited more than four months to notify DFS, well beyond the regulation’s 72-hour requirement.
What they’re saying: “Health insurance providers are entrusted with highly sensitive personal information and health data of policyholders,” DFS Superintendent Adrienne A. Harris said. “Healthplex’s failure to adhere to these rules resulted in the exposure of the sensitive data of tens of thousands of consumers.”
The violations: DFS found Healthplex violated provisions requiring:
- MFA for network access from external networks.
- Secure disposal of NPI no longer needed for business operations.
- Timely reporting of cybersecurity events.
- Accurate annual compliance certifications.
The settlement:
- $2 million civil penalty.
- Hiring of an independent auditor to assess MFA controls across core business systems.
- Continued remediation, including MFA enablement and adoption of a records retention policy.




