New York Hospitals Face Stricter Cybersecurity Rules Beyond HIPAA Compliance
BankInfoSecurity
|
Contributed by: Drex DeFord
Summary
New York hospitals must now adhere to stricter cybersecurity regulations than the federal HIPAA security rule, introducing significant compliance challenges for healthcare providers. Effective from October 2024, hospitals are required to report cyber incidents within 72 hours and must comply with additional mandates by October 2025, including multifactor authentication and appointing a Chief Information Security Officer. These regulations extend beyond HIPAA-protected data to include personally identifiable and business information, complicating data governance efforts. Healthcare professionals need to proactively demonstrate compliance plans to regulators, addressing the challenges posed by this expanded data landscape.