Loading chat...
NY S09269
Bill
Status
Introduced
2/20/2026
Primary Sponsor
Liz Krueger
Click for details
AI Summary
- Prohibits the sale of regulated health information and requires either valid written authorization or a strictly necessary purpose (such as providing requested services, security, or legal compliance) for any processing of health data
- Defines "regulated health information" broadly to include data linked to individuals' physical or mental health status, including conditions, treatments, medications, genetic/biometric data, reproductive health, gender-affirming care, and location data indicating attempts to access health services
- Grants individuals the right to access all their regulated health information within 30 days and request deletion, with regulated entities required to communicate deletion requests to service providers and third parties
- Establishes civil penalties of up to $15,000 per violation, enforced exclusively by the New York Attorney General, with a 6-year statute of limitations
- Exempts HIPAA-covered entities and information, clinical trial data, government agencies, and employment-related health information from the law's requirements
Legislative Description
Provides for the protection of health information; establishes requirements for communications to individuals about their health information; requires either written consent or a designated necessary purpose for the processing of an individual's health information.
Last Action
REFERRED TO INTERNET AND TECHNOLOGY
2/20/2026
Committee Referrals
Internet and Technology2/20/2026
Full Bill Text
No bill text available