What cybersecurity incident reporting obligations do New York companies face
New York requires companies to notify affected residents within 30 days of discovering a data breach and file reports with state regulators.

New York companies face three layers of data breach obligations that expanded significantly in late 2024 and early 2025. Companies must notify affected individuals, file reports with regulators, and implement security safeguards. The rules now move faster than they did before: the state eliminated exemptions that previously allowed companies to delay notification while investigating breach scope or restoring systems.
A breach occurs the moment unauthorized access compromises personal information, even if the data was not actually taken. This broad definition means a breach of a password file triggers notification requirements immediately, since the password file's compromise creates a reasonable risk that other data could be accessed. The clock starts when a company determines that a breach has occurred, not when the breach happened.
The 30-Day Notification Rule and What Triggers It
Starting December 21, 2024, New York requires businesses to notify affected residents within 30 days of discovering a data breach. The law says notification must occur "in the most expedient time possible and without unreasonable delay," but 30 days is the outer limit with no exceptions. This amendment eliminated previous flexibility that allowed companies to delay notification while investigating breach scope or restoring systems. The only remaining exception permits delays requested by law enforcement for criminal investigations.
The law defines a breach as "unauthorized access to or acquisition of computerized data that compromises the security, confidentiality, or integrity of private information." Notably, mere unauthorized access suffices—the data does not need to be physically taken or copied. This means a breach of employee credentials, password files, or administrative access triggers notification requirements immediately, since such compromises create a reasonable risk that more sensitive data could be accessed.
"Private information" is broadly defined as any identifying information combined with sensitive data elements. This includes names combined with Social Security numbers, driver's license numbers, financial account details with security codes, biometric data, or usernames and emails paired with passwords. As of March 21, 2025, the law expanded to include medical and health insurance information: medical records, diagnoses, policy numbers, claims history, and treatment details. This expansion means healthcare providers, health insurers, and companies that maintain employee health benefits must now apply the 30-day rule to medical data breaches.
Notifying Regulators, Credit Bureaus, and Data Owners
When a breach occurs, companies must file simultaneous notice with the New York Attorney General's office, the Department of State Division of Consumer Protection, and the State Police. These agencies coordinated a unified submission portal, allowing businesses to file once rather than submitting separate reports to each entity. The filing must include the timing of notification sent to affected individuals, the content of the notification, and the count of residents affected.
If the breach affects more than 5,000 New York residents, companies must separately notify the three major credit reporting agencies with details about when notification occurred and how many residents were affected. This threshold is significant because notifying credit bureaus can trigger fraud alert systems that alert affected individuals automatically.
Companies that maintain data for other entities—such as cloud storage providers, payment processors, email hosting services, or customer relationship management vendors—face their own obligations. Service providers must notify the data owner immediately and in any event within 30 days of discovering the breach. The data owner then has its own 30-day window to notify affected individuals. This two-step process can compress timelines for the ultimate consumer notification, since the service provider's notification triggers the data owner's clock immediately.
NYDFS Financial Services Reporting and Ransom Payments
Banks, insurers, and other entities regulated by the New York Department of Financial Services face a separate, faster requirement that runs parallel to the general 30-day rule. These companies must report cybersecurity incidents to NYDFS within 72 hours of determining that a breach occurred, not 30 days. The 72-hour clock starts when the company determines the incident meets the reporting threshold—that is, when it will be reported to another regulator, impacts a material portion of the entity's information systems, or has a reasonable likelihood of materially harming normal operations. The 72-hour requirement became effective December 1, 2023 and applies to all cybersecurity incidents meeting these criteria, regardless of whether consumer notification is required.
For ransomware incidents and extortion attempts, the timeline is even tighter. Companies must notify NYDFS within 24 hours of completing or receiving a ransom demand, not the normal 72 hours. They must then submit a written explanation within 30 days detailing why the payment was made, what alternatives were considered, and how legal compliance was ensured. A February 2025 clarification specified that only companies meeting NYDFS's definition of "covered entity" must use the 72-hour process. Smaller operations or those outside financial services follow the general 30-day rule instead, though they must still file with the state attorney general.
Security Safeguards and the SHIELD Act
Notification is only half the obligation. New York's SHIELD Act requires any business that maintains computerized personal data of New York residents to "develop, implement and maintain reasonable safeguards to protect the security" of that information. This requirement applies to any entity not already subject to compliance with other data security laws like HIPAA or the Gramm-Leach-Bliley Act, which automatically satisfy the requirement if implemented.
Reasonable safeguards fall into three categories. Administrative safeguards require designating one or more employees to coordinate the data security program, training staff on data security practices, identifying reasonably foreseeable risks, assessing the sufficiency of existing controls, selecting service providers capable of maintaining appropriate safeguards (and requiring those safeguards by contract), and adjusting procedures as business circumstances change. Technical safeguards require evaluating network and software vulnerabilities, assessing information processing and storage methods, detecting and responding to attacks, and regularly testing the effectiveness of key controls and systems. Physical safeguards mandate assessing storage and disposal risks, preventing unauthorized access during collection and transportation, and erasing electronic media so that information cannot be read or reconstructed within a reasonable timeframe.
Small businesses have some flexibility. Companies with fewer than 50 employees, less than $3 million in annual revenue (calculated over the last three fiscal years), or less than $5 million in year-end total assets must implement safeguards "appropriate for the size and complexity" of their operations. The nature and scope of business activities and the sensitivity of collected personal information determine the required level of safeguards. A solo consultant handling email addresses only faces different requirements than a staffing agency maintaining Social Security numbers and background checks.
“Mere unauthorized access suffices—the data does not need to be physically taken or copied for a breach to trigger notification requirements.”
Penalties, Enforcement, and Time Limits
The New York Attorney General—and only the Attorney General—can bring enforcement actions for violations. Individuals have no private right of action to sue companies directly over breaches. For knowing or reckless violations of the notification requirements, courts may impose civil penalties of the greater of $5,000 or $20 per instance of failed notification, capped at $250,000. Absent knowing or reckless conduct, penalties are lower or only recover actual costs. The Attorney General must bring enforcement actions within three years of learning about the violation or when notice was sent to state agencies, whichever is earlier, but in no event more than six years from the date the company discovered the breach unless the company took steps to hide it.
For failing to maintain reasonable security safeguards under the SHIELD Act, courts can impose civil penalties up to $5,000 per violation with no statutory cap, potentially leading to significantly higher total fines than notification violations. The Attorney General has pursued cases against companies that failed to encrypt sensitive data, maintained inadequate access controls, or did not properly vet third-party service providers. NYDFS-regulated entities face additional penalties under DFS rules for violations of cybersecurity requirements, beyond the general notification and safeguards penalties.
How New York Compares to Federal and National Standards
For HIPAA-covered entities like healthcare providers and health insurance companies, New York's 30-day requirement is significantly faster than the federal standard of 60 days. This means a healthcare provider with patients across multiple states faces the tighter New York deadline if any New York residents are affected. Some states have adopted similar timelines: Colorado, Florida, and Washington now also require 30-day notification. However, many states still allow 45 days or longer, making New York one of the stricter jurisdictions.
The NYDFS 72-hour rule for financial services entities aligns with Securities and Exchange Commission requirements for public company incident disclosure, reflecting the heightened risk associated with financial data breaches and the systemic importance of financial institutions. This parallel timeline ensures that financial regulators receive information quickly enough to assess market impact and systemic risk. The 24-hour ransom payment reporting requirement is particularly stringent nationally and reflects regulatory concerns about ransomware funding and criminal enterprise financing.



