New York State Senators Liz Krueger, Amanda Brouk, Leroy Comrie, Jessica Fernandez, Pat Ryan Hinchey, Emily Hoylman-Sigal, Cordell Cleare Jackson, John Liu, Michelle Hinchey, and Webb introduced Senate Bill S. 929 during the 2025-2026 Regular Sessions. The bill aims to amend the General Business Law by establishing the New York Health Information Privacy Act.
Regulated entities, which include healthcare providers, insurers, and other organizations that process health data, must now obtain explicit consent from individuals before processing their regulated health information. It includes clear communication about what data is collected, how it will be used, and with whom it may be shared.
Entities are required to provide individuals with easy access to their health information and the ability to request its deletion. Failure to comply with these regulations can result in legal repercussions, making it necessary for organizations to review and possibly overhaul their data management practices.
HIPAA establishes baseline standards for the protection of health information, S. 929 on the other hand introduces stricter requirements specific to New York State. For example, the New York bill requires explicit consent from individuals before their health data can be processed or shared, whereas HIPAA allows for certain disclosures without consent under specific circumstances.
S. 929 discusses individual rights, like the ability to access and delete personal health information, which goes beyond HIPAA's provisions. This creates a dual-layered regulatory environment where healthcare organizations operating in New York must navigate both federal and state laws.
Related: HIPAA Compliant Email: The Definitive Guide
Yes, there are specific circumstances under which regulated entities may process health information without consent.
If an organization processes health information without valid consent, it may face legal consequences under the New York Health Information Privacy Act, including potential fines and enforcement actions.
Individuals should be able to make requests through an easy-to-use interface provided by the regulated entity. Organizations are required to respond to these requests within a specified timeframe.