{"id":5504,"date":"2025-05-28T15:25:07","date_gmt":"2025-05-28T19:25:07","guid":{"rendered":"https:\/\/bpslaw.com\/staging-site\/?p=5504"},"modified":"2025-07-31T14:11:56","modified_gmt":"2025-07-31T18:11:56","slug":"three-key-changes-breach-notification-law","status":"publish","type":"post","link":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/","title":{"rendered":"Three Key Changes to Breach Notification Law"},"content":{"rendered":"<p>The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended in three key aspects: (1) a new 30-day breach notification timeframe, (2) a new notice requirement for New York Department of Financial Services (\u201cDFS\u201d) regulated entities, and (3) an amended definition of \u201cPrivate Information.\u201d<\/p>\n<p>The SHIELD Act requires persons and businesses that own or license data containing Private Information to notify affected New York residents, certain state regulators, and consumer reporting agencies following a security \u201cbreach\u201d of that information. The recent amendment now sets forth an explicit 30-day notification timeline, instead of the previous requirement to notify \u201cin the most expedient time possible and without unreasonable delay.\u201d The recent amendment to the SHIELD Act also introduces a new requirement for DFS-regulated entities that experience a breach to notify DFS, the New York State attorney general, the New York Department of State and the state police. These requirements became effective as of December 21, 2024.<\/p>\n<p>The definition of \u201cPrivate Information\u201d under the SHIELD Act was expanded to explicitly include medical and health insurance information. Under the SHIELD Act, notice of a breach of any Private Information is required to be provided to the affected resident. Under the amended statute, Private Information now includes personal information consisting of \u201c\u2026(v) medical information regarding an individual\u2019s medical history, mental or physical condition or medical treatment or diagnosis by a health care professional; or (vi) health insurance information including an individual&#8217;s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify an individual or any information in an individual\u2019s application and claims history, including but not limited to, appeals history\u2026.\u201d<\/p>\n<p>Previously, the statute did not specifically require notifications for breaches that impacted medical or health insurance information. While HIPAA-covered entities are deemed compliant, and therefore exempt from the SHIELD Act\u2019s security requirements with respect to electronic Protected Health Information (\u201cePHI\u201d), healthcare providers and other organizations that process any New York resident\u2019s Private Information must still comply with respect to non-ePHI, including the thirty (30) day notification requirement for any breach of Private Information.<\/p>\n<p>For more information and regulatory guidance, please contact Robert Braumuller or Zaina S. Khoury at <a href=\"mailto:RBraumuller@bpslaw.com\">RBraumuller@bpslaw.com<\/a> or <a href=\"mailto:ZKhoury@bpslaw.com\">ZKhoury@bpslaw.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended in three key aspects: (1) a new 30-day breach notification timeframe, (2) a new notice requirement for New York Department of Financial Services (\u201cDFS\u201d) regulated entities, and (3) an amended [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":5511,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[82],"tags":[],"class_list":["post-5504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-client-alert"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Three Key Changes to Breach Notification Law | Bleakley Platt<\/title>\n<meta name=\"description\" content=\"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Three Key Changes to Breach Notification Law | Bleakley Platt\" \/>\n<meta property=\"og:description\" content=\"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\" \/>\n<meta property=\"og:site_name\" content=\"Bleakley Platt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-28T19:25:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-31T18:11:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"534\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Niki Jones\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Niki Jones\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\"},\"author\":{\"name\":\"Niki Jones\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/fc80856c4deab4e1f4bf0b7508666b28\"},\"headline\":\"Three Key Changes to Breach Notification Law\",\"datePublished\":\"2025-05-28T19:25:07+00:00\",\"dateModified\":\"2025-07-31T18:11:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\"},\"wordCount\":388,\"publisher\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#organization\"},\"image\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg\",\"articleSection\":[\"Client Alert\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\",\"url\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\",\"name\":\"Three Key Changes to Breach Notification Law | Bleakley Platt\",\"isPartOf\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg\",\"datePublished\":\"2025-05-28T19:25:07+00:00\",\"dateModified\":\"2025-07-31T18:11:56+00:00\",\"description\":\"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...\",\"breadcrumb\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage\",\"url\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg\",\"contentUrl\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg\",\"width\":800,\"height\":534},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/bpslaw.com\/staging-site\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Three Key Changes to Breach Notification Law\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#website\",\"url\":\"https:\/\/bpslaw.com\/staging-site\/\",\"name\":\"Bleakley Platt\",\"description\":\"A Full Service New York Law Firm\",\"publisher\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#organization\"},\"alternateName\":\"BPS\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/bpslaw.com\/staging-site\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#organization\",\"name\":\"Bleakley Platt & Schmidt, LLP\",\"url\":\"https:\/\/bpslaw.com\/staging-site\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2020\/08\/bps-law-logo-banner.jpg\",\"contentUrl\":\"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2020\/08\/bps-law-logo-banner.jpg\",\"width\":1200,\"height\":628,\"caption\":\"Bleakley Platt & Schmidt, LLP\"},\"image\":{\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/fc80856c4deab4e1f4bf0b7508666b28\",\"name\":\"Niki Jones\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/63ce8477a3363b442583f215902136ff559b4f2a48677d307d6ed0e1bd07f032?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/63ce8477a3363b442583f215902136ff559b4f2a48677d307d6ed0e1bd07f032?s=96&d=mm&r=g\",\"caption\":\"Niki Jones\"},\"sameAs\":[\"http:\/\/www.nikijones.com\"],\"url\":\"https:\/\/bpslaw.com\/staging-site\/author\/niki-jones\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Three Key Changes to Breach Notification Law | Bleakley Platt","description":"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Three Key Changes to Breach Notification Law | Bleakley Platt","og_description":"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...","og_url":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/","og_site_name":"Bleakley Platt","article_published_time":"2025-05-28T19:25:07+00:00","article_modified_time":"2025-07-31T18:11:56+00:00","og_image":[{"width":800,"height":534,"url":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg","type":"image\/jpeg"}],"author":"Niki Jones","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Niki Jones","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#article","isPartOf":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/"},"author":{"name":"Niki Jones","@id":"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/fc80856c4deab4e1f4bf0b7508666b28"},"headline":"Three Key Changes to Breach Notification Law","datePublished":"2025-05-28T19:25:07+00:00","dateModified":"2025-07-31T18:11:56+00:00","mainEntityOfPage":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/"},"wordCount":388,"publisher":{"@id":"https:\/\/bpslaw.com\/staging-site\/#organization"},"image":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage"},"thumbnailUrl":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg","articleSection":["Client Alert"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/","url":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/","name":"Three Key Changes to Breach Notification Law | Bleakley Platt","isPartOf":{"@id":"https:\/\/bpslaw.com\/staging-site\/#website"},"primaryImageOfPage":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage"},"image":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage"},"thumbnailUrl":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg","datePublished":"2025-05-28T19:25:07+00:00","dateModified":"2025-07-31T18:11:56+00:00","description":"The New York General Business Law \u00a7 899-aa, also known as, the New York Stop Hacks and Improve Data Security Act (\u201cSHIELD Act\u201d), was amended...","breadcrumb":{"@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#primaryimage","url":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg","contentUrl":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2025\/07\/BPS-Client-Alert-Shield-Act.jpg","width":800,"height":534},{"@type":"BreadcrumbList","@id":"https:\/\/bpslaw.com\/staging-site\/three-key-changes-breach-notification-law\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/bpslaw.com\/staging-site\/"},{"@type":"ListItem","position":2,"name":"Three Key Changes to Breach Notification Law"}]},{"@type":"WebSite","@id":"https:\/\/bpslaw.com\/staging-site\/#website","url":"https:\/\/bpslaw.com\/staging-site\/","name":"Bleakley Platt","description":"A Full Service New York Law Firm","publisher":{"@id":"https:\/\/bpslaw.com\/staging-site\/#organization"},"alternateName":"BPS","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/bpslaw.com\/staging-site\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/bpslaw.com\/staging-site\/#organization","name":"Bleakley Platt & Schmidt, LLP","url":"https:\/\/bpslaw.com\/staging-site\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bpslaw.com\/staging-site\/#\/schema\/logo\/image\/","url":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2020\/08\/bps-law-logo-banner.jpg","contentUrl":"https:\/\/bpslaw.com\/staging-site\/wp-content\/uploads\/2020\/08\/bps-law-logo-banner.jpg","width":1200,"height":628,"caption":"Bleakley Platt & Schmidt, LLP"},"image":{"@id":"https:\/\/bpslaw.com\/staging-site\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/fc80856c4deab4e1f4bf0b7508666b28","name":"Niki Jones","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bpslaw.com\/staging-site\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/63ce8477a3363b442583f215902136ff559b4f2a48677d307d6ed0e1bd07f032?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/63ce8477a3363b442583f215902136ff559b4f2a48677d307d6ed0e1bd07f032?s=96&d=mm&r=g","caption":"Niki Jones"},"sameAs":["http:\/\/www.nikijones.com"],"url":"https:\/\/bpslaw.com\/staging-site\/author\/niki-jones\/"}]}},"_links":{"self":[{"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/posts\/5504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/comments?post=5504"}],"version-history":[{"count":5,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/posts\/5504\/revisions"}],"predecessor-version":[{"id":5512,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/posts\/5504\/revisions\/5512"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/media\/5511"}],"wp:attachment":[{"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/media?parent=5504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/categories?post=5504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bpslaw.com\/staging-site\/wp-json\/wp\/v2\/tags?post=5504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}