Skip to content

Data Breach Fines and Penalties by Law: NYDFS, HIPAA, PCI DSS, GDPR, SEC and New York SHIELD

Data breach fines and penalties under NYDFS Part 500, HIPAA, PCI DSS, GDPR, the SEC rule and New York's SHIELD Act, with the enforcement actions behind them.

Invadel TeamSeptember 14, 20267 min read

The breach itself is the first bill. The second arrives from whichever regulators have jurisdiction over the data, and for a New York company that is often several at once: the Department of Financial Services if you are licensed by it, HHS if the data is health information, the card brands through your acquirer if it is card data, the SEC if you are public, the New York Attorney General under the SHIELD Act for everyone, and European regulators if any of the people affected were in the EU. This guide sets out what each can impose and, wherever possible, what they actually have imposed, with the enforcement actions linked.

We stick to two kinds of numbers: statutory maxima, and penalties that were announced by the regulator. Card brand fines are contractual and unpublished, and we say so rather than repeat the figures that circulate online.

NYDFS Part 500 (New York financial services)

The Department of Financial Services enforces 23 NYCRR Part 500 through consent orders, and the amounts have grown. Recent actions:

  • PayPal, $2 million, January 23, 2025. Failures in cybersecurity policies and access management, insufficiently trained personnel, and no mandatory multi-factor authentication for customer accounts. The incident: a data flow change in December 2022 exposed Forms 1099-K containing names, dates of birth and full Social Security numbers, followed by credential stuffing. (Hunton Andrews Kurth summary of the consent order)
  • Healthplex, $2 million, August 14, 2025. Sections cited: 500.12(b) (no MFA on email for external access to the internal network), 500.13 (no data retention policy), 500.17(a) (notification to DFS delayed more than four months against the 72-hour requirement), 500.17(b) (improper annual certifications for 2018 through 2021). The breach began with a phishing attack on one employee’s mailbox. (Pillsbury summary)
  • GEICO, $9.75 million, and Travelers, $1.55 million, November 25, 2024, jointly with the New York Attorney General, over breaches of auto insurance quoting systems that exposed about 116,000 and 4,000 New Yorkers respectively. GEICO’s settlement requires a comprehensive cybersecurity risk assessment and penetration testing; Travelers’ cites a missing MFA on an agent portal. (NYDFS press release)
  • Residential Mortgage Services, $1.5 million, March 3, 2021, the first Part 500 penalty to come out of a routine examination rather than a reported breach: an unreported email compromise and no periodic risk assessments. (National Law Review)

What the pattern shows: the penalties cite specific sections (MFA, risk assessment, notification, certification), and the false annual certification is treated as its own violation. The regulation’s own testing requirement is §500.5, annual penetration testing from inside and outside the information systems’ boundaries; see NYDFS penetration testing.

HIPAA (health information)

HHS’s Office for Civil Rights imposes civil money penalties in tiers by culpability, with per-violation amounts and an annual cap per provision that are adjusted for inflation each year; the current figures are in 45 CFR §102.3. Most resolutions come as settlement agreements with corrective action plans. The 2025 record:

The finding behind most of these is the same: no risk analysis covering the system that was breached. A dated penetration test report is the evidence that answers it; see HIPAA penetration testing requirements.

PCI DSS (card data)

PCI DSS is a contractual standard, not a law. Non-compliance fines are assessed by the card brands against the acquiring bank, which passes them to the merchant under the merchant agreement, along with forensic investigation costs, card reissuance costs and, in serious cases, loss of the ability to accept cards. The amounts are set by the brands and the acquirer and are not published; the figures quoted on many websites are estimates, not schedules. The controls that determine liability are the ones a Qualified Security Assessor checks, including the penetration testing in Requirement 11.4. See PCI DSS penetration testing requirements.

GDPR (EU residents’ data)

The General Data Protection Regulation applies to any company processing the personal data of people in the EU, wherever the company is. Article 83 sets two tiers of administrative fine:

  • up to €10 million or 2% of worldwide annual turnover, whichever is higher, for violations of controller and processor obligations including security of processing (Article 32);
  • up to €20 million or 4% of worldwide annual turnover, whichever is higher, for violations of the basic principles, data subjects’ rights and international transfer rules.

Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a breach, where feasible. Our GDPR penetration testing page covers Article 32’s “process for regularly testing, assessing and evaluating the effectiveness” of security measures, which is where penetration testing sits in the regulation.

SEC (public companies)

Since December 2023, the SEC’s cybersecurity disclosure rules require public companies to disclose a material cybersecurity incident on Form 8-K (Item 1.05) within four business days of determining that it is material, and to describe their cybersecurity risk management, strategy and governance annually in Form 10-K. The penalty exposure is the SEC’s general enforcement authority for disclosure failures, plus the securities litigation that follows a stock drop. The rule turns a breach into a disclosure event with a clock.

New York SHIELD Act (everyone doing business in New York)

The Stop Hacks and Improve Electronic Data Security Act, in General Business Law §§899-aa and 899-bb, applies to any business holding the private information of New York residents, regardless of where the business is.

  • Safeguards (§899-bb): businesses must maintain reasonable administrative, technical and physical safeguards. The Attorney General may seek civil penalties of up to $5,000 per violation.
  • Breach notification (§899-aa): notice to affected residents and to the Attorney General, the Department of State and the State Police, within 30 days of discovery under the 2024 amendment. For knowing or reckless failures to notify, penalties of the greater of $5,000 or up to $20 per failed notification, capped at $250,000.
  • Enforcement is by the Attorney General; there is no private right of action under the statute.

The Attorney General uses the SHIELD Act alongside the sector regulators, as the GEICO and Travelers and Orthopedics NY actions above show.

FTC Safeguards Rule (non-bank financial institutions)

The amended Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions to maintain an information security program including, where continuous monitoring is not in place, annual penetration testing and vulnerability assessments every six months, and since May 2024 to notify the FTC within 30 days of a breach affecting 500 or more consumers. The FTC enforces through consent orders that typically impose twenty-year compliance programs and, for order violations, civil penalties.

The cost that dwarfs the fine

Regulatory penalties are a fraction of the total. The average data breach cost $11.5 million in the United States in 2026, with detection, escalation and lost business making up nearly two-thirds of it. (IBM Cost of a Data Breach Report 2026) For small and medium-sized enterprises, insurer data puts the average incident at $264,000, with $152,000 in crisis services alone. (NetDiligence Cyber Claims Study 2025) And 33% of attacked SMEs reported a substantial fine afterwards. (Hiscox Cyber Readiness Report 2025) The full figures are on our data breach statistics page.

What every one of these regulators asks for first

Read the consent orders and resolution agreements together and one document appears in all of them: evidence that the company knew its vulnerabilities before the attacker did. NYDFS calls it the risk assessment and the §500.5 penetration test. OCR calls it the risk analysis. PCI DSS calls it Requirement 11.4. GDPR calls it Article 32’s regular testing. The FTC calls it annual penetration testing. A dated report, with the retest showing the fixes, is the same answer to all of them. Our reports carry a mapping to each framework; see the sample report or scope an engagement.

Sources

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation