Breach notification, Data breach notification
N.Y. Gen. Bus. Law §§ 899-aa and 899-bb
- What this page is
- Breach notification, Data breach notification
- Checked against the official source
- 2026-08-15Changed
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
Does Breach notification apply to your operation, and which paragraph decides?
Breach notification rests on N.Y. Gen. Bus. Law §§ 899-aa and 899-bb and is tested here by a deterministic rule tree of 3 rules with a coverage score of 29 percent. The tree reads your facts, names the paragraph that decides the question and returns an outcome carrying citation, content hash and read date 2026-08-15. The outcome is a machine classification, not a compliance decision.
N.Y. Gen. Bus. Law §§ 899-aa and 899-bbChecked against the publisher 2026-08-15Official text
A source reference, not legal advice.
- Jurisdiction
- State NY
- Risk dimensions
- security, privacy, operations
- Tier
- Tier 1
- Coverage
- 29 %
- Impact
- 5/5
- Read
- 2026-08-15
Source chain
Every block in the register row has its own address, so an outcome can be cited down to the paragraph. The node carries the reference, the scope, the link to the official text and the outcomes in the tree that rest on the block.
- Reasonable safeguards
N.Y. Gen. Bus. Law § 899-bb(2)
Administrative, technical and physical safeguards, with a named security coordinator and vendor selection duties.
- Small business standard
N.Y. Gen. Bus. Law § 899-bb(2)(c)
Safeguards proportionate to size, complexity and the sensitivity of the data held.
- Breach notification
N.Y. Gen. Bus. Law § 899-aa
Notice to affected residents and to the state authorities, including for unauthorised access without acquisition.
- Administrative safeguards
45 CFR 164.308
Risk analysis, workforce access, training and incident procedures.
- Physical safeguards
45 CFR 164.310
Facility access, workstation use and media handling.
- Technical safeguards
45 CFR 164.312
Access control, audit controls, integrity and transmission security.
- Business associate contracts
45 CFR 164.314
Written terms with every party that handles the data on your behalf.
N.Y. Gen. Bus. Law §§ 899-aa and 899-bb
Rule tree
Rules are tested top down. Conditions are statutory elements and each outcome points to the register blocks it rests on.
br-hipaa-500
Notice to HHS, individuals and media within 60 days
risk · Requirement applies · breach
45 CFR 164.404 to 164.408 require notice to individuals and HHS without unreasonable delay and no later than 60 days after discovery, and to media when more than 500 residents of a state are affected.
br-ny
Notice to residents and New York authorities
risk · Requirement applies · breach, program
N.Y. Gen. Bus. Law § 899-aa requires notice to affected residents in the most expedient time possible and within 30 days, and to the Attorney General, Department of State and State Police. More than 5,000 affected residents also requires notice to consumer reporting agencies.
br-hipaa
Notice to individuals within 60 days and annual log to HHS
risk · Requirement applies
Fewer than 500 affected: notice to individuals within 60 days and a report to HHS within 60 days after the end of the calendar year (45 CFR 164.408(c)).
Outcome
allowed · Outside the scope
The rule yields no requirement for the facts supplied
No breach of New York resident data or health information is stated. The other 48 states have their own notification laws that are not tested here.
fallback · sha256:sha256:fd0473f6d7c7dd2f2bee4e66c
Monitoring
The journal shows what moved in the register row, with the hash before and after. The impact score follows a rule stated in plain words.
How impact is scored: Grund: tillagd eller borttagen uppgift ger 3, ändrad uppgift 2, omläsning utan ändring 0. Tillägg: +1 när ändringen rör status eller tillämpningsdatum. Tillägg: +1 när agenten ligger i klass 1. Siffran begränsas till 0 till 5.
2026-08-15 · 0/5 · lasning
Raden läst mot den officiella publiceringen utan ändring
2026-08-15 · 0/5 · lasning
Raden läst mot den officiella publiceringen utan ändring
2020-03-21 · 4/5 · tillampningsdatum, status
Regeln började tillämpas enligt utgivaren
2019-07-25 · 5/5 · antagande, identifierare, status
Regeln antogs enligt N.Y. Gen. Bus. Law §§ 899-aa and 899-bb
2005-04-20 · 4/5 · tillampningsdatum, status
Regeln började tillämpas enligt utgivaren
2003-02-20 · 5/5 · antagande, identifierare, status
Regeln antogs enligt 45 CFR Part 164, Subpart C
Supervision
- Office of the Attorney General of New York
- U.S. Department of Health and Human Services, Office for Civil Rights
European counterparts
- gdpr · Artiklarna 32 till 34 i dataskyddsförordningen täcker samma mark om säkerhet och anmälan, med en frist på sjuttiotvå timmar som SHIELD Act inte sätter.
- gdpr-2016-679 · Båda texterna kräver dokumenterade säkerhetsåtgärder och skriftliga villkor med leverantörer. HIPAA gäller bara hälsodata, EU-texten inte.
Artifacts and integrity
- https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/manifest.json
- https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/run
- https://legal.exploreworldai.com/api/public/v1/us-agents/us-breach-notification/monitor.json
- sha256:31739960bd4fe85689ff70090024aa5ce3c1391be13d54ebe9bee04446a3cb4b
- sha256:bbbd2536455b78ea7f90a7db3b2335ff6b718554d2357aee028c294c1a8fd775
The verdict is a machine classification of the outcome, not legal advice and not a compliance decision. Responsibility position · N.Y. Gen. Bus. Law §§ 899-aa and 899-bb
Verifiable trust signals
- Six fixed blocks, one source per line
- No sentence written by a language model
- Engine version and read date on every answer
- No customer data, no documents, no advice
- Model card and audit published under the EU AI Act