Lexology November 21, 2024
New York hospitals have less than a year to dust off their Health Insurance Portability and Accountability Act (HIPAA) compliance programs and update them to comply with more stringent and detailed state regulations. Last month, the New York State Department of Health (NYSDOH) published a notice of adoption of new hospital cybersecurity requirements, codified at 10 NYCRR § 405.46, aimed at enhancing the protection of patients’ protected health information (PHI), as defined in HIPAA, and personally identifiable information (PII) (the Regulations). The Regulations create a number of requirements for general hospitals licensed under Article 28 of the Public Health Law. Regulated entities are expected to come into compliance by Oct. 2, 2025 (i.e., within one year of adoption), with the...