New York’s SHIELD Act does two things to organisations handling health data: it extends breach notification duties beyond what HIPAA requires, and it imposes a standalone “reasonable safeguards” obligation that reaches any business — anywhere — holding New York residents’ private information.
What the SHIELD Act is
The Stop Hacks and Improve Electronic Data Security Act, signed in 2019, amended New York’s breach notification statute (General Business Law section 899-aa) and added a new data security requirement (section 899-bb). Its two effective dates — late 2019 for the notification changes, March 2020 for the safeguards requirement — are long past; both halves are fully in force.
Two design choices give the Act its reach. First, it dropped the old requirement that a business conduct business in New York: the Act applies to any person or business that owns or licenses computerised private information of a New York resident, wherever that business sits. Second, it broadened “private information” well beyond the classic name-plus-SSN formula to include biometric information, account credentials (username or email address with password or security answers), and financial account numbers usable without additional codes. Health information held by a HIPAA-regulated entity is separately picked up: a breach of information governed by HIPAA triggers the Act’s state-notification machinery even where the data would not otherwise meet the private-information definition.
The reasonable safeguards requirement
Section 899-bb requires every covered business to develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of private information. Unusually for a state statute, it then says what reasonable looks like, listing elements across three familiar categories.
Administrative safeguards include designating an employee to coordinate the security programme, identifying reasonably foreseeable internal and external risks, assessing the sufficiency of safeguards in place, training and managing employees in the programme, selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract, and adjusting the programme as circumstances change.
Technical safeguards include assessing risks in network and software design and in information processing, transmission, and storage; detecting, preventing, and responding to attacks or system failures; and regularly testing and monitoring the effectiveness of key controls.
Physical safeguards include assessing risks of information storage and disposal, protecting against unauthorised access during collection, transport, and destruction, and disposing of private information within a reasonable time so it cannot be read or reconstructed.
If that list sounds like a compressed version of the HIPAA Security Rule, that is not a coincidence — and the Act acknowledges it directly. A business that is regulated by and compliant with HIPAA and HITECH is a “compliant regulated entity” deemed to satisfy the safeguards requirement. Two cautions on that deeming provision. It assumes you actually are compliant — a HIPAA programme that exists on paper but fails in practice does not earn the safe harbour, and a New York Attorney General investigation after a breach will test the substance, starting with your risk analysis. And it covers the safeguards section only; the breach notification obligations apply regardless.
Breach notification under New York law
The SHIELD Act expanded “breach” to include unauthorised access to private information, not just acquisition — so an intruder who viewed data without exfiltrating it can still trigger notification. Factors such as indications that the information was viewed, communicated with, used, or altered guide the access determination.
When a breach occurs, the business must notify affected New York residents in the most expedient time possible and without unreasonable delay, and must notify three state bodies: the Attorney General, the Department of State, and the State Police. Where more than 5,000 New York residents are notified at once, consumer reporting agencies must also be told.
For HIPAA-regulated organisations, the Act builds a partial bridge: if you notify affected individuals under HIPAA’s Breach Notification Rule, you need not send duplicate individual notices under state law — but you must notify the New York Attorney General within five business days of notifying HHS. That five-day clock is easy to miss because it attaches to your HHS filing, including the annual small-breach submission, not to the breach itself. Put it in your incident response runbook explicitly.
Enforcement and penalties
There is no private right of action under the SHIELD Act; enforcement belongs to the New York Attorney General, an office with an active track record of data security actions against healthcare and health-adjacent companies. For violations of the safeguards requirement, courts may award civil penalties of up to $5,000 per violation. For knowing or reckless failures to notify, penalties can reach the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000. The AG can also seek injunctive relief and consent agreements that impose multi-year security programme obligations — often more costly in practice than the penalty itself.
New York organisations in regulated verticals may face additional regimes beyond the SHIELD Act — insurers and other licensees under the Department of Financial Services cybersecurity regulation, and hospitals under state hospital cybersecurity requirements — which is one more reason to run a single well-documented security programme rather than a patchwork.
Running one programme that satisfies both
Because the SHIELD Act’s safeguards map so directly onto HIPAA’s, the work is mostly consolidation rather than addition:
- Treat your HIPAA Security Rule programme as the master programme, and verify it is genuinely current — the deeming provision only helps if compliance is real.
- Add the New York notification steps to your incident response plan: AG, Department of State, State Police, the five-business-day post-HHS clock, and the 5,000-resident credit-agency threshold.
- Update your breach assessment procedure to account for access-not-just-acquisition, which is broader than the trigger many HIPAA-built procedures use.
- Confirm vendor contracts require appropriate safeguards — your business associate agreements will usually carry this, but non-BAA vendors holding private information need equivalent terms.
- Keep the evidence organised: designated security lead, risk assessments, training records, testing results. These are precisely the artefacts an AG inquiry requests.
Where SuperHIPAA fits
The platform keeps your safeguards, policies, training records, and vendor register in one evidenced system — which is what the SHIELD Act’s deeming provision effectively asks you to be able to prove. Our team helps you fold the New York-specific notification steps into your existing incident response plan.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report on your HIPAA foundation, which under the SHIELD Act’s deeming provision is also your New York data security position. If you are further along than you thought, we will tell you that too.