Privacy Daily is a service of Warren Communications News.

NY AG Settles With Car Insurers for $14.2M Over Data Breach Claims

Eight car insurance companies settled for $14.2 million with New York Attorney General Letitia James (D) over data breach claims impacting more than 825,000 state residents, the AG announced Tuesday.

Sign up for a free preview to unlock the rest of this article

Privacy Daily provides accurate coverage of newsworthy developments in data protection legislation, regulation, litigation, and enforcement for privacy professionals responsible for ensuring effective organizational data privacy compliance.

James settled with American Family Mutual Insurance Company/Midvale Indemnity Company, Farmers Insurance, Hagerty Insurance Agency, the Hartford Insurance Group, Infinity Insurance Company, Liberty Mutual Insurance, Metromile and State Auto Mutual Insurance Company.

The companies didn’t “implement reasonable data security controls to protect consumers’ private information,” she said. According to her office, several of the companies suffered more than one data breach. In addition, they lacked common data security safeguards and failed to use multifactor authentication to protect credentials.

An AG investigation found data hackers exploited the companies' “pre-fill” functions used for generating customer quotes. “By entering limited information into the tool, such as a person’s full name and date of birth, the other fields on the tool were pre-populated, such as an individual’s driver’s license numbers and similar information about other drivers in their household,” the AG's office said. “The OAG found that the car insurance companies did not take reasonable steps to protect pre-fill private information.”

The companies must adopt comprehensive information security programs and develop data inventory systems for protecting private information, the New York office said.