As discussed in an earlier blog post, the New York state Stop Hacks and Improve Electronic Data Security Act (or “SHIELD Act”), was signed into law on July 25, 2019. A potential unintended side effect of the SHIELD Act may require health care companies to provide notification to the NY Attorney General for events that occurred well before its enforcement date. While the SHIELD Act’s data security requirements, which are covered under §4, will not come into effect until March 21, 2020, all other requirements, including the breach notification requirement, became effective on October 23, 2019. The notification enforcement date is important for any Covered Entity, as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), that has suffered a Breach, as defined by HIPAA, involving fewer than 500 individuals (“Minor HHS Breach”), was a breach of computerized data, and involved a New York resident.
Blog Editors
Recent Updates
- Federal Embryo Adoption Program Raises Potential Legal Questions for Reproductive Health
- Vermont’s H. 583 Restricts Private Equity and Hedge Funds with Ownership and Controlling Interests from Interfering with Clinical Judgment of Health Care Providers
- DOJ’s Second National Health Care Fraud Takedown of the Second Trump Administration Heavily Targets Medicaid Fraud
- FDA Regulations to Establish Minimum CGMP Requirements for Manufacturing, Packaging, Labeling, and Holding of Dietary Supplements
- OIG Advisory Opinion 26-14 Offers Another Favorable Path for Patient Access Through Sponsored Testing