New York Health Information Privacy Act Passed by State Legislature

The New York Legislature recently passed a new bill – the New York Health Information Privacy Act (HIPA) – that will impose strict requirements on organizations that handle health and wellness data. The aim of the Act is to ensure better protection for health data not currently covered by the Health Insurance Portability and Accountability Act (HIPAA).

HIPAA only applies to HIPAA-covered entities (healthcare providers, health plans, and healthcare clearinghouses) and any business associates of those entities provided with access to protected health information. Personally identifiable health information is now collected by a vast range of apps and wearable devices, yet the data collected by the apps and devices is generally not covered by the HIPAA Rules, even though the data collected would be classed as protected health information if collected by a HIPAA-regulated entity. HIPA aims to address that data privacy gap.

New York’s HIPA is awaiting the signature of state Governor Kathy Hochul. If signed into law, any company that collects health data would be required to obtain consent from consumers before the data could be processed, unless the processing of the data was for a purpose necessary to the product or service being provided. The Act does not restrict the use or sale of any de-identified information, so data with all personal information stripped out can continue to be used or sold without consent.

There are several requirements concerning consent. Importantly, consent to use personal health data cannot be a condition of using the product or service and cannot affect an individual’s experience of that product or service. Consent can be withdrawn at any time and there is a requirement for personal data to be deleted on request. While other state privacy laws do not apply to HIPAA-regulated entities, the New York Health Information Privacy Act is focused on non-HIPAA-covered data. That means that an entity such as a healthcare provider that is required to comply with the HIPAA Rules must also comply with HIPA for any non-HIPAA-covered health data collected, stored, or transmitted.

Another distinction from other state privacy laws is the New York Health Information Privacy Act applies to data collected from individuals in the state of New York, not only New York residents. For example, a Texas resident would be protected by the New York Health Information Privacy Act from the date they arrive in New York state to the date they leave. If passed, the New York Health Information Privacy Act will take effect in one year from the date the state governor signs the Act into law. If enacted, the penalties for noncompliance will be severe. Up to $15,000 per violation or 20% of the revenue generated from New York customers for the previous fiscal year, whichever is greater.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/