Get Security Assessment

HIPAA Compliance in New York: SHIELD Act & State Requirements

New York healthcare organizations face complex compliance obligations combining federal HIPAA with state-specific data protection and healthcare privacy laws. This guide covers the SHIELD Act, Public Health Law Article 27-F (HIV), Mental Hygiene Law, and other New York requirements.

Quick Answer

New York imposes healthcare privacy through three primary frameworks: HIPAA (federal), SHIELD Act (comprehensive data security law), and healthcare-specific statutes (HIV confidentiality, mental health records, medical records access). The SHIELD Act is particularly stringent: it requires "reasonable and appropriate" safeguards, mandates breach notification without unreasonable delay, and imposes personal liability for officers and directors. New York Public Health Law §2805-d gives patients broad rights to medical records within 15 days. Healthcare organizations must satisfy all three frameworks, with New York law often exceeding federal HIPAA requirements.

How New York Law Extends Beyond HIPAA

New York state law creates overlapping privacy and security requirements that frequently exceed HIPAA standards:

1. New York SHIELD Act (NY GBL §668)

The SHIELD Act (Cybersecurity in New York) applies broadly to healthcare entities:

2. New York Public Health Law Article 27-F (HIV Confidentiality)

Establishes strict confidentiality protections for HIV-related information:

3. New York Mental Hygiene Law (Article 33)

Protects confidentiality of mental health treatment records:

4. New York Medical Records Access Law (Public Health Law §2805-d)

Grants patients rapid access to medical records:

Key New York State Statutes & References

New York General Business Law §668 (SHIELD Act)
Cybersecurity law requiring reasonable and appropriate safeguards for personal information, breach notification without unreasonable delay, and reporting to New York Attorney General. Applies to all entities handling NY residents' data.
New York Public Health Law Article 27-F (HIV/AIDS Confidentiality)
Establishes strict confidentiality requirements for HIV testing, status, and medical information. Requires specific written authorization; unauthorized disclosure is a crime. More stringent than federal confidentiality rules.
New York Mental Hygiene Law Article 33 (Mental Health & Substance Abuse Treatment Confidentiality)
Protects mental health and substance abuse treatment records. Requires written consent before disclosure; even court orders cannot compel disclosure without patient agreement. Covers self-referential materials and psychotherapy notes.
New York Public Health Law §2805-d (Patient Access to Medical Records)
Grants patients right to access medical records within 15 days, receive copies, and obtain electronic records at no cost. Applies to all healthcare providers and facilities.
New York Public Health Law §2805-d(9) (Electronic Patient Access Standards)
Requires healthcare providers to make medical records available electronically. Electronic access must be provided at no charge; providers cannot charge for electronic transmission.
New York Penal Law Article 156 (Crimes of Identity Theft & Privacy Violations)
Criminalizes identity theft and unauthorized access to private information in healthcare records. Can result in criminal prosecution in addition to civil penalties.

New York Attorney General Enforcement

The New York Attorney General aggressively enforces healthcare privacy laws:

Notable enforcement: New York AG has pursued healthcare providers, health insurers, and healthcare vendors for SHIELD Act violations, data breaches, and inadequate security, resulting in multi-million dollar settlements and requirement for ongoing security audits.

Comparison: HIPAA vs. New York State Requirements

Area HIPAA New York Law More Stringent
Patient Access Timeline 60 days to provide records 15 days (Public Health Law §2805-d) New York
Electronic Record Access Can charge reasonable cost Must be provided at no cost New York
Breach Notification Timeline 60 days of discovery Without unreasonable delay (interpreted as days) New York
Security Standards Risk-based reasonable safeguards Reasonable AND appropriate; AG defines strictly (SHIELD Act) New York
HIV Information Confidentiality Covered under PHI; standard protections Article 27-F: Stricter rules, criminal liability for disclosure New York
Mental Health Records Psychotherapy notes protections Article 33: Stricter; no disclosure even with court order without consent New York
Personal Liability for Officers/Directors No personal liability (organizational liability only) Personal liability possible under SHIELD Act New York
Authorization Requirements Permissive; allows routine use authorizations Specific written consent required for sensitive data (HIV, mental health) New York

New York-Specific Breach Notification Requirements

SHIELD Act Notification Requirements

New York Attorney General Notification

Credit Monitoring Consideration

Encrypted Data Exemption

No notification required if:

Frequently Asked Questions

Does New York law apply to out-of-state healthcare providers? +

Yes. Both the SHIELD Act and healthcare-specific statutes apply to any entity processing personal information or healthcare data of New York residents, regardless of where the provider is located. If you have even a single New York patient or resident whose data you process, you must comply with New York's SHIELD Act, Article 27-F (for HIV data), and Article 33 (for mental health data). This applies even to purely out-of-state organizations.

What constitutes "reasonable and appropriate" security under the SHIELD Act? +

The SHIELD Act defines reasonable security as "safeguards that meet or exceed industry standards." The New York Attorney General has issued guidance requiring: administrative controls (policies, training, incident response), technical controls (encryption, access controls, intrusion detection), and physical controls. These standards are often interpreted more strictly than HIPAA's risk-based approach. The AG considers multi-factor authentication, data encryption (both in transit and at rest), and regular security audits as baseline expectations. The subjective "appropriate" standard means what's appropriate depends on the healthcare organization's size, sensitivity of data, and available resources.

Can officers and directors personally be held liable under New York law for data breaches? +

Yes. The SHIELD Act (unlike HIPAA) allows personal liability for officers and directors if they knowingly failed to implement reasonable security. This creates an unusual compliance situation: not only is the organization liable, but individual executives can personally face civil penalties. This has motivated many New York healthcare organizations to require directors and officers to take cybersecurity training and explicitly document their oversight of security matters. The threat of personal liability makes compliance with NY law distinctly more serious than HIPAA compliance alone.

What's the difference between NY Mental Hygiene Law Article 33 and HIPAA for mental health records? +

Article 33 is significantly stricter. Under HIPAA, you can disclose mental health treatment information with patient authorization for routine care, payment, and healthcare operations. Under Article 33, you need explicit, written informed consent for virtually any disclosure. More importantly, Article 33 prevents disclosure even when a court orders it (via subpoena) unless the patient consents—HIPAA would allow court-ordered disclosure. Article 33 also protects psychotherapist work product and self-referential notes from disclosure to anyone except the patient. If you handle mental health records of New York residents, Article 33 applies and is more restrictive than HIPAA.

Protect Your New York Healthcare Organization

New York's SHIELD Act and specialized healthcare privacy laws create complex compliance challenges. Get a professional security assessment to ensure compliance with HIPAA, the SHIELD Act, Article 27-F, and Article 33.

Get Your Security Assessment