Bill

Bill > A10357


NY A10357

NY A10357
Provides for the protection of health information; establishes requirements for communications to individuals about their health information; requires either written consent or a designated necessary purpose for the processing of an individual's health information.


summary

Introduced
02/26/2026
In Committee
02/26/2026
Crossed Over
Passed
Dead

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the general business law, in relation to providing for the protection of health information

AI Summary

This bill establishes the New York Health Information Privacy Act, which aims to protect individuals' health information by requiring that any "regulated health information" – broadly defined as information linkable to an identifiable person and related to their physical or mental health status – can only be processed with either the individual's explicit written consent or for a strictly necessary, legally defined purpose. The bill mandates that communications about health information must be in plain language and accessible, and it prohibits the sale of regulated health information. It also grants individuals rights to access and delete their health information, requires regulated entities to implement security safeguards, and establishes rules for service providers who handle this data. The Attorney General is empowered to enforce these provisions with civil penalties, and any contracts or waivers that contradict this act are deemed void. The act includes various exemptions, such as for information already protected by federal laws like HIPAA, and will take effect six months after becoming law.

Committee Categories

Business and Industry

Sponsors (30)

Last Action

referred to science and technology (on 02/26/2026)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...