Bill

Bill > A02141


NY A02141

NY A02141
Provides for the protection of health information; establishes requirements for communications to individuals about their health information; requires either written consent or a designated necessary purpose for the processing of an individual's health information.


summary

Introduced
01/15/2025
In Committee
01/22/2025
Crossed Over
Passed
Dead

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the general business law, in relation to providing for the protection of health information

AI Summary

This bill provides comprehensive protections for health information privacy in New York by establishing strict rules for how regulated entities can collect, process, and use an individual's health data. The legislation defines "regulated health information" as any information reasonably linkable to an individual and related to their physical or mental health, and creates detailed requirements for how such information can be handled. Specifically, the bill mandates that entities can only process an individual's health information with either explicit written consent or for strictly necessary purposes like providing a requested service, protecting against fraud, or complying with legal obligations. The bill requires clear, accessible communications about data processing, provides individuals with rights to access and delete their health information, and mandates robust security measures. Entities are prohibited from selling health information and must obtain separate, clear authorizations for different types of data processing. The New York Attorney General is empowered to enforce these provisions, with potential penalties of up to $15,000 per violation or 20% of revenue from New York consumers. The law would apply to most entities processing health information of New York residents, with some specific exemptions for government entities, healthcare providers already covered by HIPAA, and certain clinical research contexts. The bill aims to give individuals more control over their sensitive health data and prevent unauthorized or exploitative use of personal health information.

Committee Categories

Business and Industry, Housing and Urban Affairs

Sponsors (31)

Last Action

substituted by s929 (on 01/22/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...