Skip to content
Home » News » New York AG secures $550K settlement with health care operator over massive data breach

New York AG secures $550K settlement with health care operator over massive data breach

New York AG secures 0K settlement with health care operator over massive data breach

HealthAlliance’s data breach compromised personal and medical information of over 240,000 New Yorkers

NEW YORK — New York Attorney General Letitia James announced a $550,000 settlement with HealthAlliance, a Hudson Valley health care facility operator, for failing to protect patient data. The breach compromised the personal and medical information of 242,641 New Yorkers due to a vulnerability that HealthAlliance did not promptly address.

Finger Lakes Partners (Billboard)

The settlement requires HealthAlliance to strengthen its cybersecurity practices and pay penalties, highlighting the importance of robust data protection in health care services.

How the HealthAlliance data breach occurred

In July 2023, a HealthAlliance vendor issued a cybersecurity alert about a critical vulnerability in its web application. Despite being aware of the issue, HealthAlliance could not apply the necessary security patch due to technical difficulties. Instead of taking the system offline, it continued to operate, exposing patient data to risk.

Between September and October 2023, cyber-attackers exploited the vulnerability, accessing sensitive information, including:

  • Patient names
  • Addresses
  • Dates of birth
  • Social Security numbers
  • Medical diagnoses
  • Lab results and medications
  • Health insurance information
  • Financial information

In response, HealthAlliance conducted a forensic investigation, replaced affected devices, and applied the required security patches.


Penalties and strengthened security measures

Under the terms of the agreement, HealthAlliance will:

  1. Pay a $1.4 million penalty, with $850,000 suspended due to financial hardship and its role in serving underserved communities.
  2. Implement a comprehensive information security program to protect sensitive data.
  3. Maintain an accurate data inventory and ensure data encryption.
  4. Enforce a patch management policy to address critical vulnerabilities within 72 hours.
  5. Adopt additional security measures to monitor and restrict network activity.

Protecting New Yorkers’ data

“HealthAlliance provides essential health care services to New Yorkers, but it also has a responsibility to protect private medical information,” said Attorney General Letitia James. “Every company entrusted with sensitive data must take necessary precautions to ensure their systems are not vulnerable to cyberattacks.”


This settlement is part of Attorney General James’ broader initiative to protect New Yorkers from data breaches. Recent actions include:

  • $2.25 million settlement with a Capital Region health care provider in October 2024.
  • $4.5 million settlement with a biotech company in August 2024.
  • Consumer privacy guides and alerts issued throughout 2024 to help protect against cyber threats.

The case was handled by Assistant Attorney General Marc Montgomery and Deputy Bureau Chief Clark Russell of the Bureau of Internet and Technology, under the supervision of Bureau Chief Kim Berger. The Bureau is part of the Division for Economic Justice, led by Chief Deputy Attorney General Chris D’Angelo and overseen by First Deputy Attorney General Jennifer Levy.