Key developments
States secure reduced 23andMe breach recovery
A 42-state coalition reached an $18 million immediate bankruptcy recovery from 23andMe over its 2023 breach affecting 6.9 million customers worldwide. State reports said exposed data included genetic ancestry information later offered for sale on the dark web; Texas is set to receive $1,266,860, Minnesota $514,871, and Iowa just under $430,000. The settlement also adds security obligations including enhanced safeguards, risk assessments, an independent advisory board, state privacy-law enforcement, and continued deletion rights.
Why it matters
The settlement tests how privacy regulators can preserve remedies and data-protection obligations after a company holding highly sensitive genetic data enters bankruptcy.
Sources & driving stories
KPRC CLICK2HOUSTON
KPRC Click2Houston coverageFOX 9 MINNEAPOLIS-ST. PAUL
FOX 9 Minneapolis-St. Paul coverageKWQC
KWQC coverageAssuranceAmerica says cyberattack exposed 7 million
AssuranceAmerica reported that a March 2026 cyberattack may have exposed personal information for 6,998,886 people. Fox News’ Kurt Knutsson reported that suspicious activity was detected March 17 after an employee was targeted, and investigators found an unauthorized third party accessed parts of the insurer’s IT environment and copied files. Potentially exposed data includes names, contact details, auto policy or account information, driver and vehicle information, claims information, driver’s license numbers, and in some cases Tax ID information.
Why it matters
Driver’s license, insurance, and claims data can support identity theft, insurance fraud, and highly credible impersonation attempts at large scale.
Sources & driving stories
FOX NEWS · Kurt Knutsson
Fox News coverageJudge blocks DOJ demand for voter data
A federal judge dismissed a U.S. Department of Justice lawsuit seeking personal and protected information from New Mexico voters, according to KOAT’s Amari Saxton. The case, filed in December 2025, alleged New Mexico and other states withheld information and failed to meet election-integrity standards. New Mexico officials said disclosure of Social Security numbers and dates of birth could create severe identity risks, and the court found the DOJ demand letter lacked an identifiable basis.
Why it matters
The ruling limits federal access to sensitive voter-registration data and reinforces privacy safeguards around election records.
Sources & driving stories
KOAT · Amari Saxton
KOAT coverageWorth noting
WORTH NOTING
NYC hospital vendor PHI posted
Healthcare Facilities Today reported that Solventum, a business associate of NYC Health + Hospitals, suffered unauthorized access to patient PHI around March 29, with a threat actor posting names, addresses, dates of birth, medical record numbers, histories, and diagnoses to the dark web on April 19.
WORTH NOTING
Case & Associates SSNs exposed
Federman & Sherwood’s Caroline Chesher reported an investigation into a Case & Associates Properties breach affecting about 932 Texas residents, with names and Social Security numbers potentially exposed.
WORTH NOTING
California age-assurance comments filed
Future of Privacy Forum submitted comments to the California DOJ on draft SB 976 rules, urging flexible performance-based age assurance, clearer parental-consent revocation rules, and tighter language on age-assurance data use and deletion.
Still unclear
OPEN QUESTION
Can post-bankruptcy privacy controls be enforced?
23andMe’s assets and consumer data moved through bankruptcy while state settlements impose ongoing security, deletion-rights, and oversight duties, raising practical enforcement questions.
OPEN QUESTION
Are breach-notification timelines keeping pace?
AssuranceAmerica detected suspicious activity in March but notified after a June file review, while the NYC Health + Hospitals vendor incident involved PHI posted before downstream notifications were complete.
