NYHIPA vs. HIPAA: New York’s Health Data Privacy Law Explained

NYHIPA-vs-HIPAA

If your New York healthcare practice is HIPAA-compliant, you may still be breaking the law. Just not a law that exists yet.

The New York Health Information Privacy Act (NYPHIPA) is a proposed state law that targets the health data that HIPAA does not cover. That means fitness apps, wearable devices, wellness platforms, healthcare-related browsing history and other modern data sources are not included. 

The original NYHIPA bill (S929) was vetoed by the Governor in Hochul in December in 2025. However a revised version, Senate Bill S9269, passed both the New York Senate and Assembly in June 2026. Now it is awaiting the Governor’s signature. It will take effect six months later, to become the law. 

The blog breaks down exactly what NYHIPA covers, how it differs from HIPAA, who it applies to and what your practice should do before law is enacted. 

What Is the New York Health Information Privacy Act (NYHIPA)?

NYHIPA is a New York proposed state law designed to protect health-related data that HIPAA does not cover. 

HIPAA was written in 1996, before fitness apps or smartwatches even existed. It was built for the hospitals, health plans, and medical clearinghouses and their business associates. That is where the protection ends. It was never designed to cover the kind of health data that modern technology collects everyday. NYHIPA is the legislative response to that gap. 

The original NYHIPA bill (S929) was passed by both the New York Senate and Assembly in January 2025. But it got vetoed in December 2025 due to concerns from businesses in healthcare, technology and financial services arguing rules were too broad. 

Lawmakers responded with a revised version, Senate Bill S9269, introduced in February 2026. It got passed in both houses in June 2026 and is currently delivered to the Governor for signature. Which is why healthcare practices should start preparing for it now. 

New York is not the only state acting on this law. Washington, Nevada, Virginia, and Connecticute have all passed consumer health data laws beyond HIPAA. NYHIPA, if signed, would be the most expansive of all of them. 

NYHIPA vs. HIPAA: A Side-by-Side Comparison

HIPAA regulates who handles the data. NYHIPA regulates what data is handled regardless of who holds it. The major distinction is what makes NYHIPA applicable to thousands of businesses that never had to think about health privacy compliance before.  

Dimension

HIPAA

NYHIPA (2026 Revised Bill)

Governing body

Federal (HHS)

New York State (AG enforcement)

Who it covers

Covered entities + business associates

Any entity processing RHI of NY residents or individuals in NY 

Data protected

Protected Health Information (PHI) 

Regulated Health Information (RHI)

Scope

Healthcare providers, plans, clearinghouses, and business associates

Telehealth, apps, wearables, employers, wellness platforms, advertisers

Out-of-state applicability

Limited

Yes. Applies to any entity processing data of NY residents

Data sale restrictions

Limited

Near-total ban on sale of RHI

Private right of action

No

No,removed in 2026 revised bill 

Consent model

Opt-out in most cases

Valid authorization required before processing (opt-in)

Penalties

Civil monetary penalties vary by violation category and culpability

Up to $15,000 per violation; AG enforcement only 

Exemptions

Broad (most HIPAA-covered data and entities) 

21 exemptions in the revised bill (expanded from 4 in 2025 version) 

Status

Active federal law

Passed both houses June 2026; awaiting Governor’s signature 

Enforcement

Federal regulators (HHS/OCR) 

New York Attorney General

What “regulated health information” means under NYHIPA

Regulated Health Information (RHI) refers to any data that is reasonably linkable to a person or device, and is collected or processed in connection with the person’s physical or mental health. 

This is a deliberately broad definition. RHI includes: 

  • Location data ((for example, GPS coordinates near a clinic or pharmacy) 
  • Payment data linked to health-related purchases
  • Health-related browsing history
  • Reproductive health information
  • References about health drawn from non-health data. It means a company can be covered by NYHIPA but never directly asks about your health. 

Whereas, HIPAA’s definition of protected health information (PHI) is tied more specifically to medical records, treatment history, and billing information held by covered entities. Following HHS guidance on health data and tracking technologies, it is already clear that most consumer-facing digital health tools fall outside PHI. 

How NYHIPA’s authorization model differs from HIPAA’s consent rules

Under HIPAA, health information can usually be used or shared for permitted purposes, such as treatment, payment or healthcare operations, without asking the patient every time. Patients can opt out. But consent is not required upfront.

NYHIPA flips this entirely. Under the revised bill, a business must obtain a valid authorization from the person before processing their RHI unless the processing falls within a permitted purpose. 

Valid authorization under NYHIPA requires business to explain:

  • What RHI is being collected
  • Why it is being collected
  • Who it will be shared with
  • How long it will be retained

This opt-in model is one of the most operationally demanding parts of NYHIPA for businesses 

Who Does NYHIPA Apply To?

NYHIPA applies to any entity that meets at least one of these three conditions:

  1. It controls or processes RHI of a New York resident
  2. It controls or processes RHI of a person physically present in New York at the time of processing
  3. It is located in New York and controls or processes RHI

A company headquartered in Texas, Virginia or California, with no office in New York, must still comply with NYHIPA. Especially if it handles health data belonging to New York residents. 

Type of Business

What They May Do With Health Data

Fitness apps

Track exercise, steps, workouts, or other health information

Smartwatches/ wearables

Collect heart rate, activity, sleep, or other health data

Telehealth apps

Collect health information outside a doctor’s official medical record 

Employers

Run health or fitness tracking programs for employees 

Advertising companies

Use health-related data to serve targeted ads 

Payment processors 

Handle transactions linked to health-related purchases 

Schools

Handle health information that isn’t protected by HIPAA or FERPA

Overall, NYHIPA applies to many different businesses that handle regulated health information (RHI), even if they are not traditional healthcare providers.

Does NYHIPA apply if you’re already HIPAA-compliant?

Being HIPAA-compliant does not make a business automatically exempt from NYHIPA. 

The FastMed ruling is one example of how North Carolina extended provider liability beyond HIPAA. NYHIPA takes that principle further, applying it to a much broader category of entities and data types 

HIPAA-covered entities are only exempt from NYHIPA to the extent that the specific data qualifies as PHI under HIPAA. Any health-related data outside the definition, remains subject to NYHIPA. 

In practice, this means most healthcare practices have two compliance obligations: HIPAA for their clinical data, and NYHIPA for everything else. 

What the 2026 Revised NYHIPA Bill Changed

The original 2025 NYHIPA bill was vetoed in December 2025 after businesses in healthcare, technology, and finance argued that the rules are quite broad and difficult to follow. 

Senate Bill S9269 was introduced in February 2026, after several changes. Here is what changed:

 

  • The number of exemptions expanded from 4 to 21, meaning more types of data and organizations may be excluded from the law. 
  • The 20% revenue penalty was removed.
  • Civil penalties are now capped at $15,000 per violation. Enforced by the New York Attorney General only 
  • The look-back period for authorization requests was reduced from 12 months to 9 months. 
  • Businesses now have an additional 30 days to respond to RHI copy requests.
  • The definition of RHI was expanded and made more specific with greater clarity on what data is covered.  
  • New exemptions added for substance use disorder, clinical trial data, employee and job applicant information, and FCRA-covered data. 

What stayed the same?

The most operationally demanding parts of the bill remains unchanged: 

  • The core framework remains the same. 
  • The authorization-first processing model remains. Businesses must obtain valid consent before processing RHI. 
  • The strictly necessary standard also remains (business can use RHI for specific, disclosed, necessary purposes). 

What exemptions does NYHIPA 2026 include?

NYHIPA is broad, but a few categories are exempt from NYHIPA, including:

  • PHI under HIPAA: Health information that is already protected under HIPAA can be exempt. Only while it is being handled under HIPAA-covered capacity. 
  • Government entities: State agencies, local governments, and other public bodies are generally exempt when they carry out their official duties. 
  • Clinical trial and research data: Data collected for FDA-regulated clinical trials and human-subject research is exempt. 
  • Substance use disorder records: Records protected under federal Part 2 privacy rules, such as addiction treatment records, are exempt. 
  • De-identified information: Health data that cannot reasonably identify a person,is exempt.
  • Employee and job applicant information: Added in the 2026 revised bill. 
  • FCRA-covered data: Information already governed by the Fair Credit Reporting Act is exempt.

An important distinction: unlike comparable state laws in Washington and Nevada, NYHIPA does not automatically exempt nonprofits or entities already subject to FERPA or the Gramm-Leach-Bliley Act. 

Key Compliance Obligations Under NYHIPA

Businesses covered by NYHIPA must be prepared to meet the following key requirements:

Valid authorization requirements

Valid authorization under NYHIPA is more than just updating a privacy policy. Before processing, businesses must provide the individual with a clear disclosure about specific RHI being collected, its exact purpose, who it will be shared with and the time duration it will be retained for. 

The individual must then provide explicit, affirmative consent. This is different from HIPAA’s consent model. In practice it means rebuilding consent flows, updating vendor agreements, and retraining staff who handle data  intake. 

Data minimization and purpose limitation

Businesses can only collect and use regulated health information (RHI) for a specific, disclosed purpose. They cannot collect more health data than is strictly necessary for that stated function or hold on to the data “just in case” it becomes useful later. 

For example, a telehealth platform cannot collect a patient’s location history simply because it might be useful for future marketing. The purpose must be defined, disclosed, and necessary. 

Consumer rights under NYHIPA

Under NYHIPA, individuals have the following rights regarding their regulated health information: 

  • Access: The right to see what RHI a business holds about them
  • Correction: The right to request changes to inaccurate information
  • Deletion: The right to request deletion of their RHI, generally within 60 days of a valid request
  • Data portability: The right to receive a copy of their RHI
  • Opt-out of data sales: The right to prevent a business from selling their RHI

Note: HIPAA-covered entities retain the 6-year HIPAA data retention requirement for PHI. But for non-PHI data covered by NYHIPA, the 60-day deletion timeline applies. 

The private risk of action 

The 2026 revised bill (S9269) does not include a private right of action. Individuals cannot directly sue a business for NYHIPA violations. This was removed from the original 2025 bill during revision.

However, that does not mean enforcement is toothless. The New York Attorney General’s consumer protection authority includes the power to act on complaints, investigate violations, and pursue civil penalties,  including against out-of-state companies. The AG can also seek injunctive relief to stop violations before they happen.

How NYHIPA Compares to Other State Health Privacy Laws

New York is not the only state moving beyond HIPAA for consumer health data protection. State-level health privacy requirements already apply to California practices under SB 81, and similar momentum is building across the country. NYHIPA, if signed, would be the most expansive of any state law currently enacted. 

Feature

NYHIPA (NY, 2026)

My Health My Data Act (WA)

Nevada Health Data Act

Covered data

RHI (broadest definition)

Consumer health data

Consumer health data

Private right of action

No

Yes

No

Consent model

Authorization-first

Authorization-first

Varies

Nonprofit exemption

No

Yes

Partial

GLBA/FERPA exemption

Partial

Yes

Yes

NYHIPA stands out due to its broader definition of covered health information, authorization requirements, and limited exemptions. 

Is NYHIPA the strictest state health privacy law in the US?

Yes, NYHIPA is the strictest consumer health data privacy law in the United States in several key respects. 

It has the broadest definition of regulated health information (RHI) of any state law. 

It has fewer automatic exemptions than comparable laws in Washington, Nevada, Virginia, and Connecticut, even after the 2026 revision expanded exemptions from 4 to 21. 

It imposes a near-total ban on the sale of RHI. 

And unlike Washington’s My Health My Data Act, similar to Washington’s My Health My Data Act which includes a nonprofit exemption, NYHIPA does not. 

What New York Healthcare Practices Need to Do Now

State-level health privacy rules are only getting stronger. New York Practices cannot afford to wait for Governor Hochul’s signature to start preparing. 

Here’s what practices should start doing today:

  1. Audit your data map: Identify all health-adjacent data your practice and vendors collect that falls outside PHI/HIPAA coverage. This includes wellness apps, patient portals, wearable integrations, and any marketing tracking tools on your website.  
  2. Review vendor contracts: Any vendor that processes regulated health information on your behalf will need authorization agreements. These are similar to HIPAA Business Associate Agreements (BAAs) but distinct as existing BAAs will not automatically satisfy NYHIPA. Texas practices are already navigating this kind of three-layer compliance framework, and New York is heading in the same direction. 
  3. Update consent mechanisms:  Move to explicit, opt-in authorization for any non-PHI health data processing. Pre-checked boxes and passive consent flows will not meet NYHIPA’s standard. 
  4. Train remote and in-person staff: Train employees and remote healthcare staff trained beyond federal baseline needs training on NYHIPA requirements, not only HIPAA rules. 
  5. Assess your digital tools: Wellness apps, patient portals, wearable devices, and website tracking tools may all be in scope under NYHIPA. 
  6. Prepare deletion protocols: Your practice must be able to respond to valid RHI deletion requests within 60 days. This needs to be operationalized before the law takes effect, not after. 

New York’s Health Privacy Rules Are Getting Stricter, Your Remote Team Needs to Keep Pace

The compliance gap NYHIPA targets is not abstract. It shows up every time a remote medical billing specialist accesses a patient portal or every time a virtual front desk coordinator logs into an EHR. 

For practices with remote teams, the exposure compounds. NYHIPA is designed to cover health information that HIPAA does not govern. Every remote team member who touches that data is part of the compliance picture.

The question is not whether your remote staff has HIPAA training. The question is whether they understand New York’s full health privacy requirements and whether the staffing partner who placed them does too.

Practices that want to get ahead of NYHIPA are already building remote healthcare teams trained for compliance requirements that go beyond the federal baseline. 

If you want to understand what that looks like in practice, let’s talk.

Most Frequently Asked Questions

What is the New York Health Information Privacy Act (NYHIPA)?

The New York Health Information Privacy Act (NYHIPA) is a state law designed to protect health-related data that falls outside HIPAA’s coverage. The original bill was passed by the NY legislature in January 2025 but vetoed by Governor Hochul in December 2025. Its revised version,  S9269,  was introduced in the 2026 legislative session and is under review. It will require businesses to get valid customer authorization before processing regulated health information. 

No. NYHIPA does not replace HIPAA but covers what HIPAA does not. HIPAA is the federal law that governs protected health information (PHI) held by covered entities. NYHIPA covers a separate category of health-related data that is regulated health information (RHI). 

NYHIPA can be applied to any business or organization that controls or processes regulated health information (RHI) belonging to a New York resident or someone in New York, even if the organization is based in other states. This can include wellness apps, wearable device companies, telehealth platforms, advertisers, employers, and other businesses that handle health-related information not covered by HIPAA.

Under the 2026 revised bill (S9269), NYHIPA violations can result in civil penalties of up to $15,000 per violation, enforced by the New York Attorney General. The original bill included 20% of annual revenue, which was removed in the modified bill. 

No. As of September 2026, NYHIPA has not been enacted. The original bill, S9269, was vetoed in 2025. The revised bill, S9269, passed both the Senate and Assembly but has not yet become law.

Yes, if they handle regulated health information for a covered business. NYHIPA applies to organizations, but remote workers who handle RHI must follow the organization’s privacy and security requirements. Practices using virtual medical assistants must make sure their workers are trained on both HIPAA and NYHIPA requirements. 

The 2026 revised NYHIPA bill expands exemptions, provides more specific definitions of regulated health information (RHI), replaces the earlier 20% revenue-based penalty with civil penalties of up to $15,000 per violation, and clarifies consumer rights and service-provider requirements. The revised bill also does not provide individuals with a private right of action.

Subscribe to Our Newsletter
Receive occasional updates, hiring insights, and practical tips on building reliable remote teams, sent only when it’s useful.

Build Your Expert Remote Team in Less Than 10 Days.
Hiring top-tier talent is simple, fast, and reliable through Remote Scouts. 100% risk-free virtual assistant staffing with top 3% vetted candidates across multiple industries and regions. No more work delays.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Begin Your Risk-Free Hiring Process
Looking for a job? View Our Current Openings.