Data breaches in New York’s healthcare sector are a pressing issue. In the past two years, the U.S. Department of Health and Human Services reported 41 significant breaches affecting 500 or more individuals. These incidents often stem from cyberattacks and ransomware.
Some notable breaches include:
- Change Healthcare: A cyberattack revealed in February 2024 affected around 4 million New Yorkers.
- Albany ENT & Allergy Services: In late 2024, they settled for $2.25 million due to a breach that compromised over 200,000 patient records.
- Richmond University Medical Center: A ransomware attack in early 2025 impacted over 670,000 people.
Given this alarming trend, New York State has enacted strict laws to enhance data security. The N.Y. SHIELD Act, implemented in 2019 and updated in 2024, mandates that businesses protect personal information and notify those affected by breaches. This law now has a tighter notification timeline and a broader definition that includes health-related data.
In October 2024, new cybersecurity regulations for hospitals were finalized. These ensure hospitals report cybersecurity incidents within 72 hours and perform annual risk assessments.
Another significant development is the New York Health Information Privacy Act (NYHIPA), which is awaiting the governor’s approval. This law aims to strengthen health data privacy and would impose strict rules on collecting and selling sensitive health information. It would also grant individuals control over their data and enforce penalties for violations.
As the landscape of healthcare data security continues to evolve, experts highlight the need for organizations to stay vigilant. Regular training and robust security measures are crucial. In a recent survey by the Ponemon Institute, 67% of healthcare organizations reported that they don’t have a comprehensive data protection strategy.
As organizations face these ongoing challenges, it’s essential for healthcare providers to prioritize data security. Legal experts and cybersecurity professionals encourage a proactive approach to mitigate risks and protect sensitive information. Keeping up with changes in laws and best practices can make a significant difference in safeguarding patient data.
For more information on healthcare data security, you can visit the U.S. Department of Health and Human Services website.

