Article 3 min read

New York Proposes New Hospital Cybersecurity Regulations – What You Need to Know

On December 6, 2023, New York proposed new cybersecurity requirements for all general hospitals operating in the state licensed under Article 28 of the Public Health Law, regardless of size or location.

There are 226 hospitals in New York State, including Veteran’s Affairs facilities (which would not be affected by these proposed regulations). Organizations have one year from the enactment date to achieve compliance with these new hospital cybersecurity regulations. The only exception is that general hospitals must immediately report cyber incidents to the Department within two hours of determining that a cybersecurity incident occurred. A “cybersecurity incident” is defined as a cybersecurity event that has a material adverse impact on normal operations, has a reasonable likelihood of materially harming any part of the regular operation(s), or results in the deployment of ransomware within part of the hospital’s information systems.

Highlights from the Proposed New York Cybersecurity Regulations for Hospitals

In addition, the new healthcare cybersecurity regulations will require all NY hospitals to adhere to the following:

Withum’s Cyber and Information Security Services Team has extensive experience helping healthcare organizations design, implement and monitor security programs, as well as respond to security events.