Key developments
States secure $18 million 23andMe bankruptcy settlement
A bipartisan coalition of 43 attorneys general secured an $18 million bankruptcy settlement with 23andMe over its 2023 breach affecting 6.9 million customers worldwide, including 305,245 New Yorkers and 16,479 Delaware residents. The states asserted up to $150 million in allowed claims, but recovery is limited by the bankruptcy estate; New York will receive more than $705,000 and Delaware $159,654. Investigators said 23andMe failed to use reasonable credential-stuffing defenses such as breached-password checks and mandatory multifactor authentication, while customer data sold to TTAM Research, now 23andMe Research Institute, is subject to added security and deletion-right obligations.
Why it matters
The settlement ties genetic-data breach liability to bankruptcy asset sales and sets conditions for continued use of highly sensitive consumer DNA data.
Sources & driving stories
NEW YORK STATE ATTORNEY GENERAL
New York State Attorney General coverageSTATE OF DELAWARE NEWS
State of Delaware News coverageNYC health system vendor breach affected 58,778
NYC Health + Hospitals disclosed that a breach at business associate Solventum Health Information Systems affected 58,778 patients, according to a June 18 HHS Office for Civil Rights filing reported by Becker’s Hospital Review. Unauthorized access occurred around March 29, and exposed protected health information included names, addresses, dates of birth, medical record numbers, medical histories and diagnoses. NYC Health + Hospitals said a threat actor posted the data to the dark web on April 19, two days before Solventum notified the health system.
Why it matters
This is NYC Health + Hospitals’ third disclosed data security incident of 2026 and adds another vendor-linked PHI exposure involving dark-web publication.
Sources & driving stories
BECKER'S HOSPITAL REVIEW · Giles Bruce
Becker's Hospital Review coveragePolice record alleges Michigan EBT system hack
Michigan Capitol Confidential reported that a May 13, 2024 Oakland County police report said Michigan’s Bridge Card EBT system had been hacked and that multiple user numbers and PINs were discovered. The report surfaced through records obtained in a SNAP fraud investigation involving $248 in stolen benefits allegedly spent at a Sam’s Club in Georgia. Michigan’s health department and EBT vendor FIS did not confirm or deny the possible breach, while USDA data showed more than $1.5 million in replaced Michigan SNAP benefits across 2,968 approved claims from fiscal years 2023 through 2025.
Why it matters
The reporting raises unresolved accountability questions over benefit-card credential exposure and vendor-state breach transparency.
Sources & driving stories
MICHIGAN CAPITOL CONFIDENTIAL
Michigan Capitol Confidential coverageWorth noting
WORTH NOTING
MSG biometric breach lawsuit
Holt Hackney reported that Carlos Avalos filed a class action alleging Madison Square Garden failed to safeguard patron PII and biometric profiles, with alleged ShinyHunters data including facial-recognition records, background checks, credit scores and Social Security numbers tied to as many as 26 million people.
WORTH NOTING
Rogers County inmate leak unresolved
KTUL’s Burt Mummolo reported that Breach Boyz sent additional private inmate data after an earlier list containing driver’s license numbers, home addresses and Social Security numbers, while county investigators, OSBI and a security company still found no confirmed county breach.
WORTH NOTING
Clearview privacy settlement vacated
Law360 reported that the Seventh Circuit vacated a Clearview AI biometric privacy settlement, citing procedural flaws around class representative agreement and characterizing class benefits as comparatively meager.
Still unclear
OPEN QUESTION
Will genetic-data protections survive future transfers?
The 23andMe settlement imposes deletion rights and security obligations after a bankruptcy sale, but long-term enforcement will depend on how courts and regulators police successor entities handling DNA data.
OPEN QUESTION
Who must explain EBT credential exposure?
The Michigan reporting leaves the breach source unresolved because the state and FIS did not confirm whether card numbers, PINs or vendor systems were compromised.
