Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Tuesday, July 14, 2026 · 6:48 PM EDT

Key developments

NEW YORK STATE ATTORNEY GENERAL

States secure $18 million 23andMe bankruptcy settlement

A bipartisan coalition of 43 attorneys general secured an $18 million bankruptcy settlement with 23andMe over its 2023 breach affecting 6.9 million customers worldwide, including 305,245 New Yorkers and 16,479 Delaware residents. The states asserted up to $150 million in allowed claims, but recovery is limited by the bankruptcy estate; New York will receive more than $705,000 and Delaware $159,654. Investigators said 23andMe failed to use reasonable credential-stuffing defenses such as breached-password checks and mandatory multifactor authentication, while customer data sold to TTAM Research, now 23andMe Research Institute, is subject to added security and deletion-right obligations.

Why it matters

The settlement ties genetic-data breach liability to bankruptcy asset sales and sets conditions for continued use of highly sensitive consumer DNA data.

Sources & driving stories

NEW YORK STATE ATTORNEY GENERAL

New York State Attorney General coverage

STATE OF DELAWARE NEWS

State of Delaware News coverage
BECKER'S HOSPITAL REVIEW

NYC health system vendor breach affected 58,778

NYC Health + Hospitals disclosed that a breach at business associate Solventum Health Information Systems affected 58,778 patients, according to a June 18 HHS Office for Civil Rights filing reported by Becker’s Hospital Review. Unauthorized access occurred around March 29, and exposed protected health information included names, addresses, dates of birth, medical record numbers, medical histories and diagnoses. NYC Health + Hospitals said a threat actor posted the data to the dark web on April 19, two days before Solventum notified the health system.

Why it matters

This is NYC Health + Hospitals’ third disclosed data security incident of 2026 and adds another vendor-linked PHI exposure involving dark-web publication.

Sources & driving stories

BECKER'S HOSPITAL REVIEW · Giles Bruce

Becker's Hospital Review coverage
MICHIGAN CAPITOL CONFIDENTIAL

Police record alleges Michigan EBT system hack

Michigan Capitol Confidential reported that a May 13, 2024 Oakland County police report said Michigan’s Bridge Card EBT system had been hacked and that multiple user numbers and PINs were discovered. The report surfaced through records obtained in a SNAP fraud investigation involving $248 in stolen benefits allegedly spent at a Sam’s Club in Georgia. Michigan’s health department and EBT vendor FIS did not confirm or deny the possible breach, while USDA data showed more than $1.5 million in replaced Michigan SNAP benefits across 2,968 approved claims from fiscal years 2023 through 2025.

Why it matters

The reporting raises unresolved accountability questions over benefit-card credential exposure and vendor-state breach transparency.

Sources & driving stories

MICHIGAN CAPITOL CONFIDENTIAL

Michigan Capitol Confidential coverage

Worth noting

WORTH NOTING

MSG biometric breach lawsuit

Holt Hackney reported that Carlos Avalos filed a class action alleging Madison Square Garden failed to safeguard patron PII and biometric profiles, with alleged ShinyHunters data including facial-recognition records, background checks, credit scores and Social Security numbers tied to as many as 26 million people.

WORTH NOTING

Rogers County inmate leak unresolved

KTUL’s Burt Mummolo reported that Breach Boyz sent additional private inmate data after an earlier list containing driver’s license numbers, home addresses and Social Security numbers, while county investigators, OSBI and a security company still found no confirmed county breach.

WORTH NOTING

Clearview privacy settlement vacated

Law360 reported that the Seventh Circuit vacated a Clearview AI biometric privacy settlement, citing procedural flaws around class representative agreement and characterizing class benefits as comparatively meager.

Still unclear

OPEN QUESTION

Will genetic-data protections survive future transfers?

The 23andMe settlement imposes deletion rights and security obligations after a bankruptcy sale, but long-term enforcement will depend on how courts and regulators police successor entities handling DNA data.

OPEN QUESTION

Who must explain EBT credential exposure?

The Michigan reporting leaves the breach source unresolved because the state and FIS did not confirm whether card numbers, PINs or vendor systems were compromised.