State cybersecurity regulations that apply to some hospitals in New York state go well compliance under the federal HIPAA security rule, posing expanded data governance challenges for providers, said Matthew Bernstein of consulting firm Bernstein Data.
New York State’s cybersecurity regulations for general hospitals went into effect last year, with a compliance requirement for hospitals to report cyber incidents within 72 hours to the state health department starting in October 2024.
But on Oct. 1, 2025, the compliance deadline for the rest of the regulations went into effect. That long list of requirements covers multifactor authentication, risk analysis, designating a CISO, incident response and other issues.
The types of data covered are also vast – not only HIPAA protected health information but also personally identifiable information, business data and more, Bernstein said.
Among the biggest compliance challenges for hospitals are identifying and governing this expanded set of sensitive data, he said.
“The requirements as to what to protect and the risk assessments associated with protecting that are really different under this new law,” he said. “The important thing is to show the regulator that you have a plan to come into compliance, even if you can’t be fully compliant on day one.”
In this audio interview with Information Security Media Group (see audio link below photo), Bernstein also discussed:
- Other comparisons between New York state regulations and the HIPAA security rule;
- The state’s new prescriptive, system-wide and annual risk assessment requirements;
- Tackling data sprawl in healthcare environments.
Bernstein, founder and information governance strategist at consulting firm Bernstein Data, led information management practices in various global financial services businesses at Deutsche Bank for more than 20 years. Before launching Bernstein Data, he was head of group information and records management at Deutsche Bank, with global responsibility for records management, archiving and eDiscovery operations.
