The NY SHIELD Act: What New York Businesses Need to Know to Stay Compliant

August 15, 2026
August 15, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech

Here is the fact that surprises most business owners: you do not have to be located in New York to be bound by New York’s data security law. If you hold computerized private information about even a single New York resident, the Stop Hacks and Improve Electronic Data Security (SHIELD) Act applies to you. A dental practice in New Jersey with New York patients, a SaaS startup in Austin with New York users, a small e-commerce shop in Ohio shipping to Brooklyn—all of them are covered.

For small and mid-sized businesses, healthcare practices, and startups, that reach is easy to miss until something goes wrong. This guide explains what the SHIELD Act is, who it applies to, what it actually requires, and the concrete steps you can take to get compliant. Every legal figure below is drawn from the current text of the statute itself.

What the SHIELD Act is

The SHIELD Act is a New York State law that does two things. First, it modernized New York’s long-standing data breach notification rule (General Business Law § 899-aa). Second, it created an affirmative obligation to protect data in the first place (General Business Law § 899-bb), requiring covered businesses to maintain “reasonable safeguards” for the private information they hold.

The Act was submitted by the New York Attorney General’s office and signed into law on July 25, 2019. Its provisions phased in on two dates: the updated breach notification rules took effect October 23, 2019, and the data security requirements took effect March 21, 2020. Importantly, the law has been amended since then, so the requirements described here reflect the statute as it currently stands—not just the original 2019 version.

The Attorney General is the sole enforcer. The SHIELD Act does not create a private right of action, which means an individual consumer cannot sue your business directly under the statute for a security lapse (§ 899-bb(2)(e)). That does not make the risk theoretical—the Attorney General can, and does, pursue penalties, as covered below.

Does it apply to you?

The scope is deliberately broad. The data security requirement reaches “any person or business that owns or licenses computerized data which includes private information of a resident of New York” (§ 899-bb(2)(a)). There is no requirement that you conduct business in New York, maintain an office there, or reach any revenue threshold. Holding the data is enough.

What counts as “private information” is the key question, and it is broader than many businesses assume. Under § 899-aa(1)(b), private information generally means a person’s name or identifier combined with any one of the following unencrypted data elements:

  • Social Security number
  • Driver’s license number or non-driver ID card number
  • A financial account, credit, or debit card number together with a security or access code—or a card number that could be used to access an account without additional information
  • Biometric information, such as a fingerprint, voice print, or retina or iris image
  • Medical information, meaning information about a person’s medical history, condition, treatment, or diagnosis
  • Health insurance information, such as a policy or subscriber ID number or claims history

Private information also independently includes a user name or email address paired with a password or a security question and answer that would permit access to an online account. It does not include information lawfully made public through government records.

For a general SMB, that typically means customer payment records and employee files. For a healthcare practice, it means patient identifiers, diagnoses, and insurance details—the medical and health insurance categories were added to the statute specifically to cover this, and the most sensitive specialties, such as behavioral health practices, carry the highest exposure. For a startup, it very often means the usernames and passwords sitting in your application’s user database. If any of that describes data you hold on New Yorkers, you are covered.

The core requirement: reasonable safeguards

At the heart of the SHIELD Act is a straightforward mandate: develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of private information, including secure disposal (§ 899-bb(2)(a)). The statute then spells out what a qualifying data security program looks like across three categories (§ 899-bb(2)(b)(ii)).

Reasonable administrative safeguards include designating one or more employees to coordinate the security program, identifying reasonably foreseeable internal and external risks, assessing whether existing safeguards control those risks, training employees on your security practices, selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract, and adjusting the program as your business changes.

Reasonable technical safeguards include assessing risks in your network and software design, assessing risks in how information is processed, transmitted, and stored, detecting and responding to attacks or system failures, and regularly testing and monitoring the effectiveness of your key controls.

Reasonable physical safeguards include assessing the risks of how information is stored and disposed of, detecting and responding to intrusions, protecting against unauthorized access during collection, transport, and destruction of data, and disposing of private information within a reasonable time once it is no longer needed—by erasing electronic media so the data cannot be read or reconstructed.

Notice that these are described as reasonable safeguards “such as” these examples. The law is built to be flexible and scalable rather than a rigid technical checklist, which is what makes the next two sections so important.

“We’re too small to matter”—the small business reality

Many small businesses assume a law like this is aimed at large enterprises. It is not, and the statute does not exempt small businesses from the security requirement. What it does instead is right-size the standard.

A “small business” is defined as any business with fewer than 50 employees; or less than $3 million in gross annual revenue in each of the last three fiscal years; or less than $5 million in year-end total assets (§ 899-bb(1)(c)). Note that this is an “or” test—meeting any single one of those three conditions qualifies you.

If you qualify, your security program complies as long as it contains reasonable administrative, technical, and physical safeguards that are “appropriate for the size and complexity of the small business, the nature and scope of the small business’s activities, and the sensitivity of the personal information” you collect (§ 899-bb(2)(c)). In plain terms: you are held to a standard that fits your business, not a Fortune 500 standard. But “appropriate to your size” is not the same as “nothing,” and it does not reduce your breach notification obligations at all. Every business, regardless of size, must notify affected New Yorkers when a breach occurs.

Already regulated? The safe harbor path

If your business already operates under certain federal or state data security frameworks, you may be deemed compliant with the SHIELD Act’s security requirement without building a separate program. The statute calls this being a “compliant regulated entity”—a business that is subject to, and in compliance with, any of the following (§ 899-bb(1)(a) and (2)(b)(i)):

  • The data security regulations under Title V of the federal Gramm-Leach-Bliley Act (GLBA)
  • The regulations implementing HIPAA and the HITECH Act
  • New York’s Department of Financial Services Cybersecurity Regulation, 23 NYCRR Part 500
  • Other data security rules and statutes administered by a federal or New York state agency

This is significant for two of our audiences in particular. A healthcare practice already meeting the HIPAA Security Rule is, on the data security side, positioned to satisfy the SHIELD Act through that compliance. A fintech startup or financial services firm covered by GLBA or DFS Part 500 is in the same position. The critical caveat: the safe harbor only applies if you are genuinely subject to and in compliance with that framework. Claiming HIPAA coverage while your Security Rule risk analysis is years out of date does not qualify you—and the safe harbor addresses the § 899-bb security requirement, not your separate obligation to notify after a breach.

Breach notification: what happens when something goes wrong

The SHIELD Act broadened the trigger for a reportable breach. A “breach of the security of the system” now includes unauthorized access to private information, not just unauthorized acquisition (§ 899-aa(1)(c)). In practice, that means an incident where private data was merely viewed or exposed can qualify, even if you cannot prove it was copied or taken.

When a breach occurs, you must notify affected New York residents in the most expedient time possible and, under the current statute, within 30 days after the breach is discovered—subject to a limited exception for legitimate law enforcement needs (§ 899-aa(2)). Notice can be delivered by written, electronic, or telephone notification, with a substitute-notice option in defined high-cost or large-scale situations (§ 899-aa(5)).

Beyond notifying individuals, you must also notify the New York Attorney General, the Department of State, and the Division of State Police about the timing, content, and distribution of the notices. If your business is a covered entity under the DFS regulation, you must also notify the Department of Financial Services (§ 899-aa(8)). If more than 5,000 New York residents must be notified at once, consumer reporting agencies must be notified as well.

There is a narrow exception worth understanding. If an exposure was an inadvertent disclosure by someone authorized to access the data, and you reasonably determine it is unlikely to result in misuse or harm, individual notice may not be required—but you must document that determination in writing and keep it for at least five years. If the incident affected more than 500 New York residents, you must provide that written determination to the Attorney General within 10 days (§ 899-aa(2)(a)). Separately, HIPAA covered entities that report a breach to the U.S. Department of Health and Human Services must also notify the New York Attorney General within five business days of notifying HHS (§ 899-aa(9)).

Penalties and enforcement

Because only the Attorney General enforces the SHIELD Act, the practical risk is a state enforcement action rather than private lawsuits—but the exposure is real.

For breach notification failures, where a court finds a business acted knowingly or recklessly, the civil penalty is the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000 (§ 899-aa(6)). A court may also award affected individuals their actual costs or losses, including consequential financial losses, where required notice was not provided.

For failures to meet the data security requirement, a violation of § 899-bb is treated as a violation of New York’s deceptive-practices law (§ 349), and the Attorney General may bring an action to stop the violation and to obtain civil penalties under General Business Law § 350-d—which provides for a penalty of not more than $5,000 for each violation (§ 899-bb(2)(d) and § 350-d).

The takeaway is not fear. It is that “reasonable safeguards” is an enforceable legal standard, and—as the true cost of a breach makes clear—the cost of building a program in advance is far lower than the cost of explaining to the Attorney General why you did not.

Your SHIELD Act compliance checklist

Use this as a quick self-assessment. If you cannot confidently check every box, there is work to do:

  • We know whether we hold private information about New York residents, and where it lives.
  • We have designated someone to coordinate our data security program.
  • We have conducted a documented risk assessment of our systems and data.
  • We have written administrative, technical, and physical safeguards in place, appropriate to our size.
  • We vet our vendors and service providers and require safeguards in our contracts.
  • We train employees on our security practices.
  • We securely dispose of private information we no longer need.
  • We have a written breach response plan that meets the 30-day notification deadline and the Attorney General, State Police, Department of State, and (if applicable) DFS notification requirements.
  • If we rely on the HIPAA, GLBA, or DFS Part 500 safe harbor, we can prove we are actually compliant with that framework.

How Cybersecurity Advisory Group helps you get compliant

The SHIELD Act’s flexibility is a double-edged sword: “reasonable” safeguards leave you room to build a right-sized program, but they also leave you responsible for judging what is reasonable—and for proving it. Cybersecurity Advisory Group builds that program with you, mapped directly to what the statute requires.

We start with a risk assessment that identifies the private information you hold and the reasonably foreseeable internal and external risks around it—the foundation the statute expects. From there we develop your written data security program, documenting the administrative, technical, and physical safeguards § 899-bb calls for, and we design it to fit the size and complexity of your business rather than saddling a small practice with enterprise overhead.

We handle the pieces businesses most often overlook: vendor and third-party management, including the contractual safeguards the law requires you to impose on service providers; employee security awareness training, so your team actually follows the program; and the technical controls—secure storage and transmission, threat detection, and ongoing testing and monitoring—that turn policy into protection. We also build your breach-readiness plan so that if an incident occurs, you can meet the 30-day notice deadline and every regulator notification requirement without scrambling. For clients already under HIPAA, GLBA, or DFS Part 500, we help you confirm and document that your compliance genuinely qualifies you for the SHIELD Act safe harbor. For organizations too small to justify a full-time security hire, we deliver this through a fractional CISO model scaled to your size and budget.

Frequently asked questions

Does the SHIELD Act apply to my business if I’m not located in New York?

Yes. The law reaches any person or business that owns or licenses computerized private information of a New York resident, regardless of where the business is located (§ 899-bb(2)(a)). There is no office requirement and no revenue threshold—holding the data of even one New York resident is enough.

Is my small business too small to be covered?

No. Small businesses are not exempt. If you have fewer than 50 employees, under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets, you qualify as a “small business” and are held to safeguards appropriate to your size and complexity (§ 899-bb(1)(c), (2)(c))—but you must still maintain a program and still notify affected New Yorkers after a breach.

If my practice is HIPAA compliant, am I automatically SHIELD Act compliant?

Partly. HIPAA-regulated entities that are genuinely in compliance are deemed to satisfy the SHIELD Act’s data security requirement through the safe harbor (§ 899-bb(1)(a), (2)(b)(i)). That safe harbor does not remove your separate obligation to notify after a breach, and it only helps if your HIPAA compliance is real and current. See our guide to the 2026 HIPAA Security Rule for what “current” now means.

Can a customer or patient sue my business under the SHIELD Act?

No. The SHIELD Act does not create a private right of action (§ 899-bb(2)(e)). Only the New York Attorney General can enforce it. That said, a breach can still expose you to lawsuits under other legal theories, so this is not a reason to treat security lightly.

How fast do I have to report a data breach?

You must notify affected New York residents in the most expedient time possible and within 30 days of discovering the breach (§ 899-aa(2)), and separately notify the Attorney General, Department of State, and State Police—plus the Department of Financial Services if you are a DFS-covered entity (§ 899-aa(8)).

What are the penalties for getting this wrong?

For notification failures, a court can impose the greater of $5,000 or up to $20 per failed notification, capped at $250,000 (§ 899-aa(6)). For data security failures, the Attorney General can seek civil penalties of up to $5,000 per violation under General Business Law § 350-d (§ 899-bb(2)(d)).

Ready to find out where you stand?

The fastest way to understand your SHIELD Act exposure is a short conversation. Book a 30-minute discovery call with Cybersecurity Advisory Group, and we will walk through what applies to your business and what compliance would look like for you.

Sources: All statutory citations reflect the current text of New York’s General Business Law as published by the New York State Senate—GBL § 899-bb, GBL § 899-aa, and GBL § 350-d—and the New York Attorney General’s 2019 announcement of the SHIELD Act.

This article is provided for general informational purposes and does not constitute legal advice. For guidance on how the SHIELD Act applies to your specific situation, consult a qualified attorney.

Connect with Melissa Thornton on LinkedIn

Related Blogs

Shield with an unlocked padlock representing god-mode admin access from the N-able RMM zero-day
August 10, 2026
August 10, 2026

Your RMM Is Now the Attack Surface: What the N-able Zero-Day Means for MSPs

Read More
The Strategic Security Solution for Growing Practices — Fractional CISO Model Infographic
August 14, 2026
August 14, 2026

You Don't Need a Full-Time CISO. You Need a Fractional One.

Read More
Reality of Risk and Executive Governance Blueprint — Healthcare Cybersecurity Infographic
August 13, 2026
August 13, 2026

The $11 Million Reality Check

Read More