New York SHIELD Act and Home Health Agencies: What State Law Adds Beyond HIPAA
Compliance

New York SHIELD Act and Home Health Agencies: What State Law Adds Beyond HIPAA

3 min read
SF
Obi Ibeto

New York's Stop Hacks and Improve Electronic Data Security Act — the SHIELD Act — became effective March 21, 2020, and applies to any person or business that owns or…

New York's Stop Hacks and Improve Electronic Data Security Act — the SHIELD Act — became effective March 21, 2020, and applies to any person or business that owns or licenses computerized data that includes private information about New York residents, regardless of whether the organisation is physically located in New York. For home health agencies serving New York patients or employing New York residents, the SHIELD Act operates independently of HIPAA as a state-level data security obligation with its own compliance requirements, its own breach notification timeline, and its own enforcement mechanism through the New York Attorney General.

HIPAA compliance is necessary but not sufficient for SHIELD Act compliance. The SHIELD Act was specifically designed to apply standards beyond what HIPAA requires in areas where the legislature determined that federal protection was inadequate. Understanding what the SHIELD Act adds — and how to build one programme that satisfies both frameworks — is essential for New York home health agencies.

What the SHIELD Act Requires: The Reasonable Security Programme Standard

The SHIELD Act requires covered businesses to implement and maintain reasonable safeguards to protect the security, confidentiality, and integrity of private information. Businesses with fewer than 50 employees, less than $3 million in gross revenue, or less than $5 million in total assets (small businesses under the SHIELD Act definition) may implement a simplified security programme that satisfies the standard. Most home health agencies serving New York patients will exceed at least one of these thresholds and must implement the full reasonable security programme standard.

The SHIELD Act's reasonable security programme specifies required administrative, technical, and physical safeguards that parallel the HIPAA Security Rule provisions but are framed as state-level obligations with independent enforceability. Key areas where the SHIELD Act adds specificity beyond what HIPAA's general standard requires:

       Risk assessment: the SHIELD Act explicitly requires a written risk assessment — not just risk analysis — that evaluates the threats to private information in the organisation's control. This aligns with HIPAA's risk analysis requirement but adds the "written" specification that HIPAA implies but does not state as explicitly.

       Workforce training: the SHIELD Act requires security awareness training of employees on the organisation's security programme and policies. This parallels HIPAA but applies to all employees who handle New York private information — not just those with access to ePHI as defined under HIPAA.

       Vendor oversight: the SHIELD Act requires that third-party service providers that access private information maintain appropriate safeguards — implemented through contractual requirements. This parallels the HIPAA BAA requirement but uses a broader definition of private information that may capture vendor relationships not covered by HIPAA's PHI definition.

SHIELD Act Breach Notification: Faster Than HIPAA

The SHIELD Act breach notification requirement diverges most significantly from HIPAA in timing. Under the SHIELD Act, organisations must notify affected New York residents "in the most expedient time possible and without unreasonable delay" following discovery of a breach. The New York AG has interpreted this standard in enforcement actions to mean materially faster than HIPAA's 60-day maximum — with 30 days frequently cited as the outer bound of "most expedient time possible."

For breaches affecting more than 500 New York residents, the SHIELD Act also requires notification to the Attorney General, the Department of State, and the Department of Financial Services — three separate notifications that are entirely independent of the HIPAA HHS OCR portal submission. Each of these agencies receives its own notification letter with specified content, and the SHIELD Act notification must be coordinated to occur simultaneously with or before individual patient notification.

Building One Programme for Both HIPAA and SHIELD Act

The overlap between HIPAA Security Rule requirements and SHIELD Act requirements is substantial enough that a comprehensive HIPAA programme — implemented to the 2026 mandatory standards — satisfies the SHIELD Act technical safeguard requirements as a byproduct. The primary additions required to satisfy the SHIELD Act beyond HIPAA: breach notification procedures that target a 30-day timeline rather than 60 days; notification procedures for the AG, Department of State, and DFS for large breaches; and training documentation that confirms all employees who handle New York private information (not just ePHI-accessing employees) have completed security training.

 

Protecting your home health agency does not have to be complicated. It has to be done — completely, correctly, and documented in a way that holds up when it matters. ShieldForce makes that possible for organisations without IT departments, without compliance staff, and without the budget of a hospital system. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore SHIN-NY Compliance Solutions — shieldforce.io/shin-ny

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#Compliance#HIPAA#security documentation#Change Healthcare#Healthcare Billing Fraud#SHIN-NY#SHIELD Act#home health cybersecurity#security rule
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.