Bill
Bill > A04983
NY A04983
NY A04983Provides for the protection of health information; establishes requirements for communications to individuals about their health information; requires either written consent or a designated necessary purpose for the processing of an individual's health information.
summary
Introduced
02/27/2023
02/27/2023
In Committee
06/03/2024
06/03/2024
Crossed Over
Passed
Dead
12/31/2024
12/31/2024
Introduced Session
2023-2024 General Assembly
Bill Summary
AN ACT to amend the general business law, in relation to providing for the protection of health information
AI Summary
This bill establishes the New York Health Information Privacy Act, which provides for the protection of health information. The key provisions of the bill are:
1. It defines "regulated health information" as any information reasonably linkable to an individual's physical or mental health, and prohibits the sale of an individual's regulated health information to third parties or the processing of such information without the individual's valid authorization or for a permissible purpose (such as providing a requested service or complying with legal obligations).
2. It requires regulated entities to obtain written consent from individuals before processing their regulated health information, and provides detailed requirements for what must be included in a valid authorization. Regulated entities must also provide individuals with mechanisms to easily revoke their authorization.
3. It grants individuals the right to request access to and deletion of their regulated health information, and requires regulated entities and their service providers to comply with such requests.
4. It imposes security and data retention requirements on regulated entities, and regulates the use of service providers that process regulated health information on behalf of regulated entities.
5. It provides for enforcement by the Attorney General, including civil penalties of up to $15,000 per violation or 20% of revenue from New York consumers, whichever is greater.
Overall, the bill aims to enhance privacy protections for individuals' health information in the private sector.
Committee Categories
Business and Industry, Housing and Urban Affairs
Sponsors (29)
Linda Rosenthal (D)*,
Juan Ardila (D),
Jeffrion Aubry (D),
Rodneyse Bichotte Hermelyn (D),
Ed Braunstein (D),
Chris Burdick (D),
Brian Cunningham (D),
Erik Dilan (D),
Jeffrey Dinowitz (D),
Harvey Epstein (D),
Patricia Fahy (D),
Deborah Glick (D),
Jessica González-Rojas (D),
Ron Kim (D),
Dana Levenberg (D),
Nikki Lucas (D),
John McDonald (D),
Marcela Mitaynes (D),
Steve Otis (D),
Phil Ramos (D),
Karines Reyes (D),
Rebecca Seawright (D),
Amanda Septimo (D),
Maryjane Shimsky (D),
Jo Anne Simon (D),
Al Stirpe (D),
Yudelka Tapia (D),
Al Taylor (D),
Fred Thiele (D),
Last Action
substituted by s158e (on 06/03/2024)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
Loading...