N.Y. AG Proposes Adding Certain Health Data to Cybersecurity Law

Proposed Cyber measures in NYOn Thursday, New York Attorney General Eric Schneiderman (D) called for new legislation to bolster the state's data security law by expanding the definition of private information to include personal information, such as biometric information and health insurance details, Reuters reports.

Source: Source: iHealth Beat, Reuters | Published on January 16, 2015

AT&T data breach impacts 73 million

Schneiderman's proposal comes days after President Obama detailed a similar plan to prompt federal legislation on cybersecurity.

N.Y. Proposal Details

Under current state law, New York limits its definition of "private information" to:

  • Account numbers and passwords that "would permit access to an individual's financial account";
  • Driver's license or non-driver ID numbers; and
  • Social Security numbers.

Under the new proposal, companies would be required to report breaches of additional private information, including:

  • Biometric data;
  • Email addresses and passwords;
  • Health insurance data; and
  • Medical information

The proposal also would require all organizations that collect and store private information to implement adequate security measures.

In addition, the legislation would suggest that the state incentivize businesses to share forensic reports with law enforcement officials in the event of a data breach