The data breach happened between 2013 and 2015 and affected tens of millions of members.
The settlement, affecting Excellus and the Blue Cross Blue Shield Association, requires the parties to make internal security changes, and to pay out $3.3 million in fees and $1 million in reimbursed expenses, according to the announcement.
A hearing on the settlement is set for April 13.