What Does the New York SHIELD Act Require After a Data Breach?

What Does the New York SHIELD Act Require After a Data Breach?

The letter usually arrives weeks after the damage is done. A company you trusted with your Social Security number, your bank account, or your medical history writes to say someone accessed your information without permission. Whether you live in Manhattan, Brooklyn, or Westchester County, that letter exists because of the SHIELD Act, the New York law that requires businesses to protect your data and to tell you when they fail.

The Act sets strict deadlines, spells out what a breach notice must say, and carries real penalties for companies that stay silent. What it does not do is hand you a lawsuit of your own—a distinction that shapes how these cases are actually pursued.

What Is the New York SHIELD Act?

The SHIELD Act, the Stop Hacks and Improve Electronic Data Security Act, is New York’s data security law, signed in 2019. It amended General Business Law § 899-aa to strengthen breach notification requirements and added § 899-bb, which requires businesses holding New Yorkers’ private information to maintain reasonable data safeguards.

The law works in two parts. Section 899-aa governs what happens after a breach: who must be told, how quickly, and in what form. Section 899-bb governs what should happen before one, requiring every covered business to maintain reasonable administrative, technical, and physical safeguards for the private information it holds.

The Act’s reach extends far beyond companies with a New York address: any business anywhere that owns or licenses computerized data containing a New York resident’s private information must comply. A retailer in Ohio holding a Queens customer’s card number answers to it just as a Midtown employer does.

One recurring confusion deserves a correction: the SHIELD Act is a state data security law, entirely separate from New York City’s 2026 amendments to its local debt collection rules. Different law, different problem.

What Counts as a Data Breach Under New York Law?

New York defines a breach as unauthorized access to, or acquisition of, computerized private information. Since the SHIELD Act, mere access counts—a hacker copying files, a lost laptop, or an employee viewing records without a legitimate work purpose can all trigger the law’s notification requirements.

Before 2019, the law reached only information actually acquired—downloaded, copied, or carried out the door. The SHIELD Act closed that gap: unauthorized viewing of protected data now counts, even when nothing ever left the company’s systems.

In deciding whether information was accessed or acquired without authorization, the statute points businesses to several indicators:

  • Signs the information was viewed, communicated with, used, or altered without valid authorization.

  • Physical possession by an unauthorized person, such as a lost or stolen laptop.

  • Indications the information was downloaded or copied.

  • Reports of misuse, such as fraudulent accounts or identity theft complaints.

The law includes a good-faith exception: an employee who accesses records for a legitimate business purpose has not caused a breach. That exception collapses the moment the information is misused or disclosed. A billing clerk who opens a patient file to process a claim is doing her job; the same clerk who opens a neighbor’s chart and repeats what she found has triggered the statute. In our experience representing patients, that second scenario is more common than most New Yorkers realize.

What Information Is Protected as “Private Information”?

Private information includes your name combined with a Social Security number, driver’s license number, financial account or card numbers, or biometric data, plus online credentials like a username and password. Since March 21, 2025, New York’s definition also covers medical information and health insurance information.

New York law draws a line between “personal information,” anything that identifies you, such as your name, and “private information,” the sensitive elements that trigger the statute when paired with it. A breach of your name alone requires nothing; your name plus any protected element starts the clock.

The protected elements include:

  • Social Security number.

  • Driver’s license or non-driver ID number.

  • Financial account, credit card, or debit card number, with any required access code.

  • Biometric data such as a fingerprint, voiceprint, or retina image.

  • A username or email address combined with a password or security question and answer.

  • Medical information, including treatment history and diagnoses.

  • Health insurance information, such as policy numbers and claims history.

The last two categories are new, added effective March 21, 2025, pulling hospitals, clinics, insurers, and their vendors squarely into the statute. Encryption is a safe harbor only when it holds: data encrypted with a key the intruder also obtained counts as unprotected.

How Quickly Must a Company Notify Me After a Breach?

Businesses must notify affected New York residents in the most expedient time possible, and no later than 30 days after discovering the breach. The only exception is a delay requested for the legitimate needs of law enforcement. The 30-day deadline took effect December 21, 2024.

For years, the statute imposed no fixed deadline, and many companies read “without unreasonable delay” generously, taking months to investigate while stolen data circulated. Amendments signed in December 2024 ended the open-ended timeline.

Three changes matter most to consumers:

  • A hard outer limit of 30 days from discovery—among the shorter breach deadlines in the country.

  • No more delay while a company assesses the breach’s scope or restores its systems; investigation no longer excuses silence.

  • The same 30-day limit for vendors and service providers, who must alert the data’s owner.

Only one exception survives: delay for the legitimate needs of law enforcement. If your letter arrived months after discovery, the company may have violated the statute; keep the letter and the envelope; the dates on them matter.

Who Must Be Notified and What Must the Notice Say?

Companies must notify the New York Attorney General, Department of State, and State Police—and consumer reporting agencies when more than 5,000 New York residents are affected. The notice to you must describe what categories of information were exposed and include contact information for agencies that help with identity theft.

Your letter is one piece of a larger reporting web. The company must also file with the Attorney General, the Department of State’s Division of Consumer Protection, and the State Police, and businesses regulated by the Department of Financial Services must notify it as well. When a breach affects more than 5,000 New York residents, the company must alert Equifax, Experian, and TransUnion so the bureaus can watch for fraud.

The notice you receive must contain specific elements:

  • The name and contact information of the notifying business.

  • A description of the categories of personal and private information accessed or acquired, not a vague nod to “some of your information”.

  • Phone numbers and websites for state and federal agencies offering guidance on breach response and identity theft protection.

Most notices come by mail, though breaches affecting more than 500,000 New Yorkers may use substitute notice through the company’s website and statewide media.

Can I Sue a Company Under the SHIELD Act?

No. The SHIELD Act does not create a private right of action; only the New York Attorney General can enforce it, with civil penalties reaching $250,000 for notification failures and $5,000 per violation of the safeguard requirements. Consumers must instead pursue separate legal claims based on the breach.

This is the question that surprises consumers most. A violation of the SHIELD Act, even a flagrant one, does not by itself let you file suit under the Act. The legislature placed enforcement with the Attorney General, whose office can pursue:

  • Court orders stopping ongoing violations.

  • Damages for the actual costs and losses, including consequential financial losses, of people denied required notice.

  • Civil penalties of the greater of $5,000 or up to $20 per failed notification, capped at $250,000, for knowing or reckless violations.

  • Penalties of up to $5,000 per violation of the safeguard requirements.

Those figures go to the state, not to you; a $250,000 penalty is not a consumer check.

None of this makes the Act irrelevant. A documented violation is powerful evidence: a company that ignored its safeguard duties, or sat on a breach past the 30-day deadline, has demonstrated the carelessness that supports the separate claims New York law does allow.

What Legal Claims Can New York Consumers Bring After a Breach?

New York consumers can pursue common-law claims such as negligence, negligent supervision, and breach of implied contract, along with General Business Law § 349 claims when a company misrepresented its data security. In medical records cases, claims against the facility must be framed as institutional negligence under New York precedent.

The claims with real force exist outside the SHIELD Act. Depending on the facts, a New York consumer harmed by a breach may pursue:

  • Negligence — the company failed to use reasonable care in protecting your information, and you were harmed as a result.

  • Negligent hiring, supervision, or retention — the company kept an employee in a position of access despite warning signs, or failed to monitor how records were used.

  • Breach of implied contract — you provided your information as part of a transaction carrying an unspoken promise to protect it.

  • Deceptive practices under General Business Law § 349 — the company assured the public its data was secure while its practices said otherwise.

Medical records cases follow rules set by New York’s highest court. In Doe v. Guthrie Clinic, a nurse recognized a patient as her sister-in-law’s boyfriend, opened his chart, and texted her sister-in-law about his condition while he was still waiting to be seen. The Court of Appeals held the clinic could not be sued directly for the disclosure because the employee acted outside the scope of her job.

What survives that ruling is the institutional case: the facility itself was negligent in who it hired, how it supervised access, and what safeguards it failed to build. That is how attorney Jeff Mehalic frames these cases—the defendant is the hospital or clinic, not the individual employee; the facility controls the systems, the audit logs, and the training.

A SHIELD Act or HIPAA violation still matters here: it helps establish what reasonable care required, even though neither statute lets you sue directly. Courts also look for concrete harm—fraudulent charges, out-of-pocket costs, the fallout of private health details spreading—so document those harms early.

What Should I Do After Receiving a Data Breach Notice in New York?

Read the notice carefully and keep it, place a fraud alert or credit freeze with the three credit bureaus, change compromised passwords, monitor your accounts and credit reports, and document any fraudulent activity or losses. Then talk with a consumer protection attorney about whether the breach supports a legal claim.

The first days matter, for your finances and for any future case:

  • Save the notice, the envelope, and every follow-up—dates, descriptions, and monitoring offer all matter later.

  • Freeze your credit with Equifax, Experian, and TransUnion; a freeze is free and blocks new accounts in your name.

  • Change compromised passwords, starting with the breached account and anywhere you reused the same credentials.

  • Pull your credit reports and review them for accounts and inquiries you do not recognize.

  • Watch your statements, including health insurance explanations of benefits, which can reveal medical identity theft.

  • Report identity theft promptly; the Federal Trade Commission’s IdentityTheft.gov builds a personal recovery plan, and the New York Attorney General’s identity theft resources explain state-specific protections.

  • Track every expense and hour the breach costs you; concrete records of harm anchor a claim.

Time limits apply to breach claims in New York generally; a few years, depending on the theory and evidence, such as audit logs, can be overwritten. If the breach involves your medical records, speaking with a lawyer early preserves options that waiting can close.

Contact a New York Data Breach Attorney

If a company exposed your private information or someone at a hospital or clinic viewed your medical records without a legitimate reason, you deserve straight answers. At Mehalic Law PLLC, attorney Jeff Mehalic represents consumers in data breach and medical privacy cases throughout New York, including Manhattan, Brooklyn, Queens, the Bronx, Staten Island, Long Island, Westchester County, and Dutchess County, as well as West Virginia. Our practice focuses exclusively on representing consumers. The consultation is free, and most cases are handled on contingency, so you owe nothing unless we recover for you.

Call us today to discuss your situation with an experienced New York consumer protection attorney.

Frequently Asked Questions About the New York SHIELD Act

Does the SHIELD Act Apply to Companies Located Outside New York?

Yes. Any person or business that owns or licenses computerized data containing a New York resident’s private information must comply, wherever it operates. An online retailer in California owes the same notification and safeguard duties to a Bronx consumer as a company headquartered in Manhattan.

What Safeguards Does the SHIELD Act Require Businesses to Maintain?

Section 899-bb calls for reasonable administrative, technical, and physical safeguards—designating security personnel, training employees, assessing risks, monitoring systems, and disposing of data securely. Businesses compliant with HIPAA, Gramm-Leach-Bliley, or New York’s financial services cybersecurity regulation are deemed compliant, and small businesses may scale their programs to their size and data sensitivity.

Does the SHIELD Act Cover Paper Records?

No. The statute applies to computerized data, so a breach involving only paper files falls outside its notification requirements. Paper medical records remain protected by HIPAA and by New York common-law confidentiality duties, so a provider that mishandles physical charts is not off the hook—the legal route is simply different.

What Happens if a Company Never Notifies Me About a Breach?

The Attorney General can sue for an injunction, the actual losses of people entitled to notice, and civil penalties. For you, the silence can strengthen a negligence or deceptive practices claim, because concealing a known breach is strong evidence of unreasonable conduct.

Can I Get Free Credit Monitoring After a New York Data Breach?

New York law does not automatically require it, but breached companies commonly offer one to two years of free monitoring, and Attorney General settlements frequently require it. Accept the protection, but read the enrollment terms; some agreements contain arbitration provisions worth reviewing with a lawyer.

How Long Do I Have to File a Lawsuit After a Data Breach in New York?

It depends on the claim. Negligence and General Business Law § 349 claims generally carry a three-year limitations period, while contract-based theories can allow longer. Deadlines and available claims vary with the facts, so consult an attorney promptly rather than assuming time remains.