For several years, some New York legislators have been attempting to enact a stand-alone consumer health privacy law aimed at health-related data that falls outside the federal Health Insurance Portability and Accountability Act (HIPAA). Such data includes information collected by apps, wearables, websites, advertisers, and other consumer-facing businesses. Nixon Peabody reported on the previous version of the New York Health Information Privacy Act (NYHIPA), which passed both houses of the state legislature but, was ultimately vetoed by the governor. In February, the New York Senate introduced a revised version (S9269) that would add a new Article 42-A to the General Business Law.
Who is regulated
If passed, the revised NYHIPA would apply to any entity that (1) is “located in” New York, (2) controls or processes regulated health information (RHI) of New York residents, or (3) controls or processes RHI of individuals physically present in New York. The bill would reach companies of all sizes but provide certain entity-level exemptions. Most notably, the law would not apply to HIPAA covered entities and business associates with respect to HIPAA protected health information, or to federal, state, and local government entities processing data for governmental purposes.
Scope of “regulated health information”
The bill defines RHI as any information that identifies or could reasonably be linked to an individual and that relates to the individual’s past, present, or future physical or mental health. Covered categories of RHI include health conditions and diagnoses, reproductive and sexual health information, gender-affirming care information, biometric data, and genetic data, as well as location information showing an attempt to obtain health services, and health inferences derived from non-health data through algorithms or machine learning.
What data is not covered
Although the definition of RHI is broader than HIPAA’s definition of “protected health information,” in that it would capture data held by many businesses not traditionally considered healthcare companies, the revised bill excludes “deidentified information” that meets the statute’s safeguards. The law would also not apply to substance use disorder records under 42 CFR Part 2, clinical trial data under the Common Rule, FDA-regulated activities, FERPA-covered education records, Fair Credit Reporting Act data, employment-related information, and data already subject to other privacy laws that are at least as protective as NYHIPA.
Sale restrictions
If enacted, the legislation would effectively prohibit regulated entities from selling RHI. A “sale” is defined broadly to include any exchange for monetary or other valuable consideration and is not limited to traditional data brokerage.
Consent and “valid authorizations”
Despite the ban on sale of RHI, regulated entities could process RHI for a narrow set of permitted purposes, such as security and fraud prevention, legal compliance, providing a product or service the consumer requested, and certain internal business operations (excluding marketing, advertising, and research). Regulated entities could also sell or otherwise process RHI pursuant to a “valid authorization” from the individual. The bill provides that regulated entities cannot condition products or services on authorization; however, the bill is also unclear as to what kinds of processing regulated entities would be required to perform without authorization, if any. Regulated entities cannot discriminate against consumers who decline to provide an authorization by charging different prices, imposing penalties, or providing lower quality services.
To be valid, the authorization must be obtained separately from other agreements, identify the data to be processed, describe the nature and purpose of processing, disclose recipients, and any consideration received, expire within a year, and be supported by clear affirmative consent. Regulated entities must also provide an easy mechanism for individuals to revoke authorization at any time. For consumers with online accounts, regulated entities would be required to ensure that account settings list all authorized processing activities and allow one-click revocation for each activity.
Data minimization and security
Regulated entities would be required to maintain reasonable administrative, technical, and physical safeguards, and securely dispose of RHI no later than 60 days after it is no longer needed for the original purpose.
Consumer rights
NYHIPA would grant individuals the right to access and delete their RHI at any time. Regulated entities would be required to provide copies of all RHI, delete data, or cancel an online account, within 30 days of a request.
Enforcement and penalties
If enacted, the bill would not provide a private right of action. Enforcement would rest exclusively with the New York Attorney General, who could seek injunctions, restitution, disgorgement of profits, and civil penalties of up to $15,000 per violation.
Next steps
The state legislature’s renewed push to pass the bill underscores New York’s focus on regulating consumer health and health-adjacent data. If enacted, New York would join states like Washington, Nevada, and Connecticut in regulating health-related information beyond the reach of HIPAA and granting New Yorkers significant new rights over their personal health data.
Nixon Peabody’s Healthcare team is closely monitoring NYHIPA and the broader wave of state consumer health privacy laws. We are ready to help clients assess their exposure, develop compliant data practices, and prepare for potential enactment. If you have questions about how NYHIPA could affect your business, please contact any of the authors of this alert or your regular Nixon Peabody attorney.



