New York Hospitals Face Enforcement of 2024 Cybersecurity Requirements
The state of New York adopted new cybersecurity requirements for general hospitals on October 2, 2024. The requirement to report cyber incidents to the New York State Department of Health (DOH) took effect immediately, requiring cybersecurity incidents to be reported to the DOH’s Surge Operations Center within 72 hours. The deadline for compliance with the other requirements of the cybersecurity regulations is October 2, 2025.
The new regulations, codified at 10 NYCRR § 405.46, were penned in response to an increase in cyberattacks on New York hospitals and have similar requirements to the New York State Department of Financial Services Cybersecurity Requirements for Financial Services Companies. The new cybersecurity requirements apply to any general hospital licensed in New York under Article 28 of the Public Health Law and expand on the requirements of the Health Insurance Portability and Accountability Act (HIPAA), but importantly, they do not just apply to electronic protected health information (ePHI). The regulations apply to non-public information (NPI), a broad term that includes ePHI but also other information such as business records.
The reporting requirement has been in effect for over a year and requires cyber incidents to be reported within 72 hours of determining an incident has occurred if the incident has a material adverse impact on the normal operations of the hospital, has a reasonable likelihood of materially harming any part of normal operations of the hospital, or results in the deployment of ransomware on a material part of the hospital’s information systems.
The remaining requirements will start to be enforced from October 2, 2025, when hospitals must be able to demonstrate they are in compliance, or they could face penalties. The requirements can be found on this link. Some of the key requirements are listed below:
- Implement a comprehensive cybersecurity program to assess risks and vulnerabilities to non-public information and hospital operations
- Conduct risk assessments at least annually to assess internal and external cybersecurity risks
- Conduct vulnerability assessments and penetration tests
- Implement a cybersecurity policy that includes 15 minimum requirements, including an asset inventory, access controls such as multifactor authentication, system and network monitoring, audit trails, and third-party service provider and vendor management.
- Establish an Incident response plan to detect, respond to, and mitigate cybersecurity events, and establish normal operations
- Designate a Chief Information Security Officer
- Submit an annual report to the hospital’s governing body on the state of the cybersecurity program
While the cybersecurity regulations do not specify the penalties that can be imposed, the DOH considers the cybersecurity regulations to be part of the minimum standards that must be met by hospitals, and the DOH can impose civil monetary penalties and take actions against hospitals’ licenses if noncompliance is identified.