Legal sources with official primary sources

Printed ·

Skip to main content
Skip to the answer

Back to the agents

Breach notification, Data breach notification

N.Y. Gen. Bus. Law §§ 899-aa and 899-bb

What this page is
Breach notification, Data breach notification
Checked against the official source
2026-08-15Changed
Responsible publisher
ExploreWorld Legal, editorial deskLiability position
Jurisdiction
State NY
Risk dimensions
security, privacy, operations
Tier
Tier 1
Coverage
29 %
Impact
5/5
Read
2026-08-15

Source chain

Every block in the register row has its own address, so an outcome can be cited down to the paragraph. The node carries the reference, the scope, the link to the official text and the outcomes in the tree that rest on the block.

  • Reasonable safeguards

    N.Y. Gen. Bus. Law § 899-bb(2)

    Administrative, technical and physical safeguards, with a named security coordinator and vendor selection duties.

  • Small business standard

    N.Y. Gen. Bus. Law § 899-bb(2)(c)

    Safeguards proportionate to size, complexity and the sensitivity of the data held.

  • Breach notification

    N.Y. Gen. Bus. Law § 899-aa

    Notice to affected residents and to the state authorities, including for unauthorised access without acquisition.

  • Administrative safeguards

    45 CFR 164.308

    Risk analysis, workforce access, training and incident procedures.

  • Physical safeguards

    45 CFR 164.310

    Facility access, workstation use and media handling.

  • Technical safeguards

    45 CFR 164.312

    Access control, audit controls, integrity and transmission security.

  • Business associate contracts

    45 CFR 164.314

    Written terms with every party that handles the data on your behalf.

N.Y. Gen. Bus. Law §§ 899-aa and 899-bb

Rule tree

Rules are tested top down. Conditions are statutory elements and each outcome points to the register blocks it rests on.

  1. br-hipaa-500

    Notice to HHS, individuals and media within 60 days

    risk · Requirement applies · breach

    45 CFR 164.404 to 164.408 require notice to individuals and HHS without unreasonable delay and no later than 60 days after discovery, and to media when more than 500 residents of a state are affected.

  2. br-ny

    Notice to residents and New York authorities

    risk · Requirement applies · breach, program

    N.Y. Gen. Bus. Law § 899-aa requires notice to affected residents in the most expedient time possible and within 30 days, and to the Attorney General, Department of State and State Police. More than 5,000 affected residents also requires notice to consumer reporting agencies.

  3. br-hipaa

    Notice to individuals within 60 days and annual log to HHS

    risk · Requirement applies

    Fewer than 500 affected: notice to individuals within 60 days and a report to HHS within 60 days after the end of the calendar year (45 CFR 164.408(c)).

Outcome

allowed · Outside the scope

The rule yields no requirement for the facts supplied

No breach of New York resident data or health information is stated. The other 48 states have their own notification laws that are not tested here.

fallback · sha256:sha256:fd0473f6d7c7dd2f2bee4e66c

Monitoring

The journal shows what moved in the register row, with the hash before and after. The impact score follows a rule stated in plain words.

How impact is scored: Grund: tillagd eller borttagen uppgift ger 3, ändrad uppgift 2, omläsning utan ändring 0. Tillägg: +1 när ändringen rör status eller tillämpningsdatum. Tillägg: +1 när agenten ligger i klass 1. Siffran begränsas till 0 till 5.

  • 2026-08-15 · 0/5 · lasning

    Raden läst mot den officiella publiceringen utan ändring

  • 2026-08-15 · 0/5 · lasning

    Raden läst mot den officiella publiceringen utan ändring

  • 2020-03-21 · 4/5 · tillampningsdatum, status

    Regeln började tillämpas enligt utgivaren

  • 2019-07-25 · 5/5 · antagande, identifierare, status

    Regeln antogs enligt N.Y. Gen. Bus. Law §§ 899-aa and 899-bb

  • 2005-04-20 · 4/5 · tillampningsdatum, status

    Regeln började tillämpas enligt utgivaren

  • 2003-02-20 · 5/5 · antagande, identifierare, status

    Regeln antogs enligt 45 CFR Part 164, Subpart C

Supervision

European counterparts

  • gdpr · Artiklarna 32 till 34 i dataskyddsförordningen täcker samma mark om säkerhet och anmälan, med en frist på sjuttiotvå timmar som SHIELD Act inte sätter.
  • gdpr-2016-679 · Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.

Artifacts and integrity

  • https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/manifest.json
  • https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/run
  • https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/monitor.json
  • sha256:31739960bd4fe85689ff70090024aa5ce3c1391be13d54ebe9bee04446a3cb4b
  • sha256:bbbd2536455b78ea7f90a7db3b2335ff6b718554d2357aee028c294c1a8fd775

The verdict is a machine classification of the outcome, not legal advice and not a compliance decision. Responsibility position · N.Y. Gen. Bus. Law §§ 899-aa and 899-bb

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit