New Cybersecurity and Incident Reporting Requirements for New York Hospitals

Hospitals in New York must report cyberattacks to the State Department of Health within 72 hours of discovery and have 12 months to implement a list of cybersecurity measures to improve their defenses against cyberattacks. The new cybersecurity requirements were enacted on October 2, 2024, in response to a large number of cyberattacks on New York hospitals that have disrupted patient care and violated patient privacy. According to the New York Department of Health, there was at least one major cyberattack on a New York hospital every month in 2023 that required a response from the Department of Health and more needs to be done to make it harder for those attacks to succeed.

The new legislation, which was proposed last year, is the first time that New York has had its own cybersecurity regulations covering healthcare, protected health information (PHI), and personally identifiable information (PII). The state of New York has previously relied on hospitals complying with federal HIPAA law – the HIPAA Security Rule – to ensure that their information systems and patient data are protected. While the HIPAA Security Rule sets minimum standards for cybersecurity it lacks detail and does not state what cybersecurity measures need to be implemented.

Given the number of cyberattacks hitting healthcare organizations in recent years, HIPAA compliance is clearly not enough. The U.S. Department of Health and Human Services is currently working on an update to the HIPAA Security Rule, but it is unclear what new cybersecurity requirements will be added. In the meantime, the HHS has published two sets of cybersecurity performance goals (HPH CPGs) that include cybersecurity measures that are likely to have the greatest impact on improving security; however, those goals are only voluntary.

Two U.S. Senators recently proposed new legislation that would set more stringent cybersecurity standards for healthcare organizations although it remains to be seen whether there will be sufficient support in the House and the Senate to get that legislation passed. In the meantime, it is left to individual states to implement legislation to get hospitals to make the necessary investments in cybersecurity.

The new cybersecurity requirements do not apply to all HIPAA-covered entities in New York, only general hospitals that are licensed pursuant to article 28 of the Public Health Law, of which there are around 195 in New York State. Other healthcare providers such as nursing homes, diagnostic treatment centers, public health centers, and some Veteran’s Affairs facilities are not required to comply with the new law, although they may voluntarily choose to do so.

Implementing the new cybersecurity measures is expected to come at a cost ranging from between $50,000 and $200,000 for small hospitals with fewer than 10 beds to around $2 million for hospitals with more than 100 beds.  To ease the financial burden of compliance, the state has set aside a fund of $500 million to help cover the cost. Covered hospitals have been permitted to apply for grants since early 2024.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

Effective immediately is the requirement to report any material cybersecurity incident to the state Department of Health within 72 hours. While there may not be much information to report at such an early stage of the investigation and breach response, the report will allow the Department of Health to set up an emergency health response and limit exposure to other healthcare entities in New York State. A material incident is any cyber incident that “has a material adverse impact on the normal operations of the hospital,”, or “has a reasonable likelihood of materially harming any part of the normal operation(s) of the hospital,” or “results in the deployment of ransomware within a material part of the hospital’s information systems.”

Covered hospitals have until October 2, 2025, to ensure they implement the required cybersecurity measures, although they should do so as soon as possible. The new requirements, detailed here, include:

  • Designate a Chief Information Security Officer (CISO) either directly or through a third party
  • Implement a comprehensive cybersecurity risk program
  • Conduct a comprehensive and accurate annual security risk assessment
  • Maintain an audit trail for detecting and responding to cyber incidents
  • Conduct cybersecurity testing, including pen tests and vulnerability scans
  • Implement multi-factor authentication on external-facing systems
  • Review user access privileges annually and delete accounts that are no longer required
  • Limit the use of privileged accounts
  • Establish a detailed incident response plan
  • Provide regular cybersecurity training to staff members, and update the training to include risks identified by the risk assessment

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/