OquiliaOquiliaOquilia — India's Financial Intelligence Platform
Calculators
Compare
Tax
NRI
News
Investigations
Oquilia Advisor
HomeCalculatorsInvestigationsNews
View All CalculatorsSIP CalculatorEMI CalculatorIncome TaxFD CalculatorPPF CalculatorAll 150+ Calculators
View All CompareHome Loan RatesPersonal LoansCredit CardsHealth InsuranceTerm InsuranceMutual FundsFD RatesEducation Loan
View All TaxOld vs New RegimeTax Saving under 80CIncome Tax SlabsCapital Gains TaxSave Tax on SalaryITR Filing Guide
View All NRINRI Investment GuideNRI Tax FilingNRI Banking & NRE FDNRI Real EstateDTAA CalculatorNRE FD Calculator
View All NewsLatest NewsFraud & EnforcementInvestigationsBlog / GuidesReports
Investigations
View All ToolsAm I Underinsured?Policy AuditJargon DecoderMutual Fund Discovery
For Business
View All LearnFinancial GlossaryFAQAbout OquiliaContact
Oquilia Advisor
  1. Home
  2. News
  3. IRDAI fines Star Health Rs 3.39 crore over cyber-security norms
Enforcement

IRDAI fines Star Health Rs 3.39 crore over cyber-security norms

IRDAI, by an order dated 25 July 2025, imposed a Rs 3.39 crore penalty and a warning on Star Health for non-compliance it found with its Information and Cyber Security Guidelines, 2023.

Oquilia Newsroom
Financial news desk covering SEBI, RBI, IRDAI, and Budget-related developments.
|Published 30 Jul 2026, 13:08 IST|7 min read · 1,473 words
Verified Sources|Source: IRDAI|Last reviewed: 30 July 2026
IRDAI fines Star Health Rs 3.39 crore over cyber-security norms

What the Record Shows

The Insurance Regulatory and Development Authority of India (IRDAI) imposed a monetary penalty of Rs 3.39 crore on Star Health and Allied Insurance Company Ltd, together with a formal warning, through an order dated 25 July 2025. The Authority announced the action the same day in a press release published on its website, titled "Press Release - Star Health Insurer 25.07.2025". Per that record, the penalty was levied for non-compliance the Authority found with multiple provisions of the IRDAI Information and Cyber Security Guidelines, 2023.

The penalty was imposed under Section 102 of the Insurance Act, 1938, read with Section 14 of the IRDAI Act, 1999, the statutory powers under which the regulator penalises a supervised insurer. As with any such order, it is appealable to the Securities Appellate Tribunal under Section 110 of the Insurance Act, 1938.

Two things need stating plainly at the outset. First, the published record did not itemise each specific control failure behind the Rs 3.39 crore figure; it recorded non-compliance with several provisions of the 2023 guidelines and set the penalty and warning accordingly. Second, the order followed a cyber incident that the company had confirmed in October 2024, in which customer data was compromised. The penalty and the earlier incident are best read as sequential facts on the public timeline. The order as published does not, in its own terms, establish that the penalty was a finding about the breach itself rather than about compliance with the guidelines. Star Health said it was examining its legal remedies.

How It Worked

The IRDAI Information and Cyber Security Guidelines, 2023 set out what an insurer's information-security framework must look like. In broad terms they require a board-approved cyber-security policy, defined governance and accountability for information security, technical and organisational controls, periodic audits and assurance, and the reporting of cyber incidents to the regulator. They are a supervisory standard: the Authority can inspect against them and act where it finds a licensed insurer falling short.

Per the order dated 25 July 2025, IRDAI found Star Health non-compliant with multiple provisions of those guidelines. The Rs 3.39 crore penalty reflects the Authority's assessment across the provisions it found breached, alongside the formal warning. Because the published record did not break the figure down provision by provision, this report does not attribute the penalty to any single named control; what is on the record is a finding of non-compliance with several requirements of the 2023 framework.

On the timeline, the sequence is documented rather than causal. In October 2024, Star Health confirmed a cyber incident in which customer information, including personal and medical data, was compromised. The company acknowledged the incident publicly at that time. Some months later, in July 2025, IRDAI passed the order under discussion. It is important not to collapse those two events into cause and effect beyond what the record states: the order penalises non-compliance with the cyber-security guidelines, and the published text does not itemise a link between the specific penalty amount and the specific breach. Reported together, they show a regulator acting on an insurer's information-security obligations in a period when that insurer had also suffered a data incident.

The action ran through the Authority's standard route for a penalty under Section 102, which involves a show-cause process before a final order. The order is the operative record; the warning accompanies it as a separate regulatory sanction.

Who Lost Money

Unlike a mis-selling or claims penalty, this is a data-security matter, so the harm at its centre is exposure of information rather than a direct taking of money. The people most closely affected are the health policyholders whose personal and medical details, per the company's own October 2024 confirmation, were compromised in the cyber incident. Medical and identity data is sensitive precisely because its misuse can be lasting and hard to reverse, even when no immediate financial loss is visible.

The Rs 3.39 crore penalty itself is paid to the government. It is punitive and regulatory; it does not compensate the individual policyholders whose data was exposed, and the order does not quantify or award any loss to them. A policyholder concerned about the handling of their data or a related grievance can raise it with the insurer and, if unresolved, escalate through the Bima Bharosa grievance portal.

Where a data breach causes downstream harm, remedies sit outside this order, in data-protection and consumer channels rather than in the insurance penalty, which addresses the insurer's compliance with the regulator's guidelines.

Where It Stands Now

As of today, the order dated 25 July 2025 stands. It is recorded on the IRDAI website in the press release on the Star Health penalty, and a review of the Authority's listings and appellate records turned up no order staying or setting it aside.

Star Health said at the time that it was examining its legal remedies, and reports noted it may prefer an appeal to the Securities Appellate Tribunal under Section 110 of the Insurance Act, 1938. As reviewed for this report, no SAT order reversing or staying the penalty is on the public record, so the penalty and warning currently remain operative. Readers can contrast this with a separate insurer matter Oquilia has tracked, in which an IRDAI order against Care Health Insurance was stayed by SAT pending appeal, which shows such orders do travel up the appellate ladder and can be paused there.

Because this is a regulatory penalty under the insurance statutes and not a criminal proceeding, it does not amount to a criminal conviction. The company's route against it is a statutory appeal to the tribunal.

What It Means

The practical significance of this order is that data security is now a supervised obligation for insurers, enforced in the same way as claims settlement or solvency. IRDAI's 2023 guidelines turned cyber-security governance into something the regulator can inspect and penalise, and this action is an example of that enforcement in practice.

For a policyholder, the takeaways are modest but useful. Your insurer holds sensitive medical and identity data, and it is required to protect it and to report incidents. If you are told your data may have been exposed, monitor your accounts and identity for misuse, keep the insurer's notification, and escalate any unresolved concern through the insurer's grievance officer and then the Bima Bharosa portal. When choosing cover, you can weigh premiums with a tool such as Oquilia's health insurance premium calculator, while remembering that how an insurer handles data and claims matters as much as price. For the wider record of such actions, the enforcement archive collects regulator orders as they are recorded, including a parallel IRDAI penalty on HDFC Life Insurance.

FAQ

What exactly did IRDAI order?

IRDAI, by an order dated 25 July 2025, imposed a monetary penalty of Rs 3.39 crore and a formal warning on Star Health and Allied Insurance Company Ltd. Per the order, the penalty was for non-compliance the Authority found with multiple provisions of the IRDAI Information and Cyber Security Guidelines, 2023, and was levied under Section 102 of the Insurance Act, 1938.

Was the penalty imposed for the October 2024 data breach?

Not as a stated finding. The order records non-compliance with the 2023 cyber-security guidelines. The company had separately confirmed a cyber incident in October 2024 in which customer data was compromised. The published record presents these as sequential facts and does not, in its own terms, establish that the penalty amount was a finding about the breach itself.

Is this a criminal case?

No. This is an administrative order under the insurance statutes, not a criminal conviction. It records non-compliance the Authority found with its guidelines and imposes a penalty and a warning. The company can appeal the order to the Securities Appellate Tribunal.

Can the order be appealed?

Yes. The order is appealable to the Securities Appellate Tribunal under Section 110 of the Insurance Act, 1938. Star Health said it was examining its legal remedies. As reviewed for this report, no appellate order staying or setting aside the penalty is on the public record, so it currently stands.

Were affected policyholders compensated?

No. The Rs 3.39 crore penalty is paid to the government and is punitive; it does not compensate individual policyholders whose data was exposed. Anyone with a related grievance can raise it with the insurer and escalate through the Bima Bharosa portal.

Where can I read the official record?

IRDAI published a press release on the action, dated 25 July 2025, on its website. The direct link appears in the source note below.

This report is based on the IRDAI press release dated 25 July 2025 on the penalty on Star Health and Allied Insurance Company Ltd and the company's public statements, reviewed on 30 July 2026.

This report describes enforcement actions and allegations on the public record, attributed to the officials cited. An order, FIR or chargesheet is not a conviction; parties are presumed innocent until proven guilty.

Named in this report, or spotted an error? Corrections and responses: editor@oquilia.com. We correct errors promptly and record responses from named parties.

Sources & Citations

  1. Press Release - Star Health Insurer, IRDAI order dated 25 July 2025 — IRDAI

Try the Related Calculators

insurance/health insurance premium

Continue Reading

irdai penalty hdfc life insurance policyholder outsourcingirdai penalty care health insurance claims handling lapses

This article was last reviewed on 30 July 2026by Oquilia's editorial team. Every claim is sourced from primary regulatory materials (CBDT, IRDAI, RBI, SEBI, Indian Kanoon). View our methodology.

Found an error? Report an issue.

CalculatorsInsuranceInvestTaxLoansNRIMBAHNIAI
Oquilia

150+ calculators · Zero commissions

Oquilia

Intelligent financial analysis. 150+ calculators & unbiased analysis.

Data: IRDAI · RBI · SEBI · AMFI

Calculators

  • SIP
  • EMI
  • Income Tax
  • FD
  • PPF
  • NPS
  • Gratuity
  • HRA
  • ELSS
  • All 150+

Insurance

  • Compare Plans
  • Companies
  • Claims Data
  • Hospitals
  • Health Premium
  • Term Premium
  • Section 80D

Tax & Loans

  • Old vs New
  • Capital Gains
  • TDS
  • Home Loan EMI
  • Car Loan EMI
  • Rent vs Buy
  • Prepayment

More Tools

  • Invest Hub
  • Tax Planning
  • Loan Tools
  • Loan Harassment Help
  • NRI Hub
  • MBA Finance
  • HNI Wealth
  • Glossary
  • News
  • Blog
  • Reports
  • Tools
  • Oquilia Advisor

Company

  • About
  • Contact
  • FAQ
  • Legal Hub
  • Privacy
  • Terms
  • Disclaimer
  • Cookie Policy
  • Grievance
  • Disclosure

Newsletter

Monthly digest

Policy moves, deadline reminders, and the most-used calculators each month.

Designed & developed by QX137, React & Next.js studio

Regulatory & data sources

RBISEBIIRDAIIncome Tax DeptAMFIPFRDAOECD TaxBISWorld Bank

Regulatory data last updated: July 2026. Figures are cross-checked against primary IRDAI, SEBI, RBI, CBDT and AMFI publications before they ship.

© 2026 Oquilia. Not a licensed financial advisor. All third-party logos and trademarks belong to their respective owners.

PrivacyTermsDisclaimerSitemap