Health Law Informer

New York May Be Paving the Way for State-level Cybersecurity Regulations on Health Care Facilities

Last month, a cyberattack forced two New York hospitals to divert and even discharge some patients to other facilities, while the affected hospitals shut down their IT systems to address the issue and restore their secure network. [cite] In the wake of this event, New York Governor Kathy Hochul has proposed a cybersecurity regulation that would create a new section, Section 405.46 of Title 10 of the Official Compilation Codes, Rules and Regulations of the State of New York, and which would apply to all general hospitals in New York State. Governor Hochul plans to allocate $500 million to back the proposed regulation. [cite]

Governor Hochul’s administration’s objective is for hospitals to establish cyber defense programs, as well as prepare for any potential attacks with tested plans. [cite] The proposed regulation aims to accomplish this through a series of detailed subsections.

For example:

The plan has already received constructive criticism from health care privacy professionals. Mari Savickis, Vice President for Public Policy at the College of Healthcare Information Management Executives, stated that requiring hospitals to report incidents within two hours in unrealistic and may even put patients at risk [cite]. Section 405.46 (n). Lee Kim, Senior Principal of Cybersecurity and Privacy at the Healthcare Information and Management Systems Society, felt that the proposed legislation should do more by way of addressing cybersecurity training for cyber professionals [cite]. In addition many in the health care industry predict that this type of hospital-specific cybersecurity regulation could spread to other states. 

New York State is accepting comments on Governor Hochul’s plan through February 5, 2024. If passed, Section 405.46 (p) provides general hospitals one (1) year from the date of adoption to comply with the new regulatory requirements, except that general hospitals must immediately begin reporting to the Department as required by subdivision (n) of this section.

About The Author