Skip to content

Menu

The American Legal Blogger logo
HomeAboutContactSubmit Your BlogChannelsSubscribe
The American Legal Blogger logo
AboutChannelsPublishersSubscribeContact
The American Legal Blogger logo
Submit Your Blog
Search
Close

Start a Blog. Grow Your Practice.

Schedule Demo

New York Governor Vetoes Restrictive Health Privacy Law

By Libbie Canter, Elizabeth Brim, Ariel Dukes, Olivia Vega, Natalie Maas & Kyle Falkner on December 22, 2025
Email this postTweet this postLike this postShare this post on LinkedIn

On December 19, 2025, New York Governor Kathy Hochul vetoed the New York Health Information Privacy Act (“NYHIPA”).  While NYHIPA bore similarities to Washington’s My Health My Data Act (“MHMD”) and Nevada’s Health Privacy Law (“SB 370”), it had several provisions that would have raised novel compliance and legal questions.

  • Regulated Entities. NYHIPA’s scope would have applied more broadly than other similar laws, including to entities processing regulated health information of an individual who is physically present in New York during the period the individual is located in the state.  It is not clear how such a provision would have applied where companies do not collect precise geolocation in the regular course or do not link such geolocation data with account-level data.
  • Regulated Health Information. NYHIPA would have governed “regulated health information” (“RHI”), defined as “any information that is reasonably linkable to an individual, or a device, and is collected or processed in connection with the physical or mental health of an individual.”  In comparison, MHMD and SB 370 are focused on personal information linked or reasonably linkable to a consumer and that identifies the consumer’s health status.  Especially since NYHIPA’s definition lacked any examples of RHI, it was unclear whether and how the scope of the definition was intended to differ than other state laws.
  • “Valid Authorization” Requirements. NYHIPA required regulated entities to obtain “valid authorization” prior to processing RHI, unless the processing is “strictly necessary” for one of seven enumerated purposes.  Where required, NYHIPA included a novel standard for valid authorization, including that authorization must be executed “at least twenty-four hours after an individual creates an account or first uses the requested product or service.”
  • Retention Schedule. NYHIPA would have required regulated entities to maintain a publicly available retention schedule and dispose of an individual’s RHI pursuant to such schedule within a reasonable time, and “in no event later than sixty days, after it is no longer necessary to maintain for the permissible purpose or purposes identified.”
  • Exemptions. NYHIPA raised questions about the interplay with federal sectoral privacy laws.  While it included exemptions for protected health information (“PHI”) collected by covered entities or business associates subject to the Health Insurance Portability and Accountability Act, as amended, and its implementing regulations (“HIPAA”), it did not include other standard exemptions.  For example, it lacked exemptions found in MHMD and SB 370 for financial data regulated by the Gramm-Leach Bliley Act (“GLBA”) and Fair Credit Reporting Act (“FCRA”), employee data, data used for public health purposes as described in HIPAA (e.g., adverse event reporting), and data that has been de-identified in accordance with HIPAA.
Photo of Libbie Canter Libbie Canter

Libbie Canter represents a wide variety of multinational companies on privacy, cyber security, and technology transaction issues, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with global privacy laws. She routinely supports…

Libbie Canter represents a wide variety of multinational companies on privacy, cyber security, and technology transaction issues, including helping clients with their most complex privacy challenges and the development of governance frameworks and processes to comply with global privacy laws. She routinely supports clients on their efforts to launch new products and services involving emerging technologies, and she has assisted dozens of clients with their efforts to prepare for and comply with federal and state privacy laws, including the California Consumer Privacy Act and California Privacy Rights Act.

Libbie represents clients across industries, but she also has deep expertise in advising clients in highly-regulated sectors, including financial services and digital health companies. She counsels these companies — and their technology and advertising partners — on how to address legacy regulatory issues and the cutting edge issues that have emerged with industry innovations and data collaborations.

Read more about Libbie Canter
Show more Show less
Photo of Elizabeth Brim Elizabeth Brim

Elizabeth Brim is an associate in the firm’s Washington, DC office. She is a member of the firm’s Health Care and Data Privacy and Cybersecurity Practice Groups, advising clients on a broad range of regulatory and compliance issues. In addition, Elizabeth maintains an…

Elizabeth Brim is an associate in the firm’s Washington, DC office. She is a member of the firm’s Health Care and Data Privacy and Cybersecurity Practice Groups, advising clients on a broad range of regulatory and compliance issues. In addition, Elizabeth maintains an active pro bono practice.

Read more about Elizabeth Brim
Show more Show less
Photo of Ariel Dukes Ariel Dukes

Ariel Dukes is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity Practice Group.

Ariel counsels clients on data privacy, cybersecurity, and artificial intelligence. Her practice includes partnering with clients on compliance with comprehensive privacy…

Ariel Dukes is an associate in the firm’s Washington, DC office and a member of the Data Privacy and Cybersecurity Practice Group.

Ariel counsels clients on data privacy, cybersecurity, and artificial intelligence. Her practice includes partnering with clients on compliance with comprehensive privacy laws, FTC and consumer protection laws and guidance, and laws governing the handling of health-related data. Additionally, Ariel routinely counsels clients on drafting and negotiating privacy terms with vendors and third parties, developing privacy notices and consent forms, and responding to regulatory inquiries regarding privacy and cybersecurity topics. Ariel also advises clients on trends in artificial intelligence regulations and helps design governance programs for the development and deployment of artificial intelligence technologies across a number of industries.

Read more about Ariel Dukes
Show more Show less
Photo of Natalie Maas Natalie Maas

Natalie is an associate in the firm’s San Francisco office, where she is a member of the Food, Drug, and Device, and Data Privacy and Cybersecurity Practice Groups. She advises pharmaceutical, biotechnology, medical device, and food companies on a broad range of regulatory…

Natalie is an associate in the firm’s San Francisco office, where she is a member of the Food, Drug, and Device, and Data Privacy and Cybersecurity Practice Groups. She advises pharmaceutical, biotechnology, medical device, and food companies on a broad range of regulatory and compliance issues.

Natalie also maintains an active pro bono practice, with a particular focus on health care and reproductive rights.

Read more about Natalie Maas
Show more Show less
Photo of Kyle Falkner Kyle Falkner

Kyle Falkner is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Kyle advises clients on a wide range of data privacy, technology, and health care…

Kyle Falkner is an associate in the firm’s Washington, DC office. He is a member of the Data Privacy and Cybersecurity Practice Group and the Health Care Practice Group.

Kyle advises clients on a wide range of data privacy, technology, and health care issues. He assists clients in complying with U.S. state and federal privacy laws as well as federal health care laws and regulations.

Kyle also maintains an active pro bono practice focused on supporting international human rights initiatives and assisting small businesses and non-profits with data privacy compliance.

Read more about Kyle Falkner
Show more Show less
  • Posted in:
    Privacy & Data Security
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Subscribe to The American Legal Blogger

Subscribe Today
The American Legal Blogger logo
RSS Facebook LinkedIn Twitter
  • Home
  • About
  • Subscribe
  • Channels
  • Publishers
  • Contact

Welcome to American Legal Blogger

American Legal Blogger is a collaboration between the ABA Journal and LexBlog that brings together, in one place, the blogs, podcasts, and other insights and guidance generated by blogging lawyers across the US.

Learn more
Copyright © 2026, The American Legal Blogger. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo