Skip to Main Content
Services Talent Knowledge
Site Search


Our attorneys stay on top of changes in legislation, agency regulations, case law, and industry trends—then craft timely legal alerts to keep clients up to date on legal developments important to their business.

September 3, 2019

DOH Implements New Notification Protocols for Cybersecurity Incidents

Earlier this year, we wrote about cybersecurity guidance and resources tailored to the health care industry released by the US Department of Health and Human Services (HHS). This guidance identified common cybersecurity issues faced by health care organizations and provided cybersecurity practices that could be implemented by these organizations to mitigate any identified threats or vulnerabilities.

On August 12, 2019, the NYS Department of Health (DOH) Office of Health Information Management followed suit in highlighting these concerns by releasing a letter to administrators and technology officers announcing new notification protocols that should be used by providers to inform the DOH when a potential cybersecurity incident has occurred at their facility or agency. These new changes were to take effect immediately and apply to the following providers: hospitals, nursing homes, diagnostic and treatment centers, adult care facilities, home health agencies, and licensed home care services agencies.

The DOH guidance defines a cybersecurity incident as “the attempted or successful unauthorized access, use, disclosure, modification, or destruction of data or interference with an information system operations.” While acknowledging that providers are required to contact various other agencies when cybersecurity-related events occur, the DOH noted it has been able to provide significant assistance to providers when these types of events occur, so long as timely notice of these events is provided.

In order to obtain the DOH’s assistance, providers must:

  1. Notify law enforcement
  2. Notify the telephone numbers provided within the poster enclosed with the DOH letter
  3. In instances of immediate threat to public health or safety, provide an emergency notification by dialing 911

The DOH also advised that the poster must be posted in facilities and agencies to provide immediate awareness of the notification protocol to staff as well as to be used for reference purposes.

Moving forward, providers should consider adding the DOH notification to their existing cybersecurity-incident and breach-notification policies. However, the DOH’s new protocol does not relieve providers of their responsibility to make other required cybersecurity-related notifications, including to the individuals whose data has been compromised, the HHS, and, in the case of compromised private financial information, the state Attorney General’s Office, the Department of State, and the Division of State Police.

If you have any questions regarding the content of this alert, please contact Dena DeFazio, associate, at or another member of the firm’s Health Care & Health and Human Services Practice Area.


Click here to sign up for alerts, blog posts, and firm news.

Featured Media


Website Accessibility Lawsuits: Several "Tester" Plaintiffs—Competello, Fernandez, Liz, Riley, and Trippett—Targeting Businesses in Recent Flurry of Lawsuits


CDPAP Providers Get First Look at the Future of CDPAP Without FIs


New York State Fiscal Year 2025 Budget: Implications for Employers Unpacked


Lab Providers Under Increased Scrutiny From Civil and Criminal Agencies for OTC COVID-19 Test Claims


NYS Appellate Court Dismisses Claim Based on Material Misrepresentations in Insurance Application


It's Not Over Yet. Turning Your Judgments Into Dollars.

We're Growing in DC!

We’re excited to announce Barclay Damon’s combination with Washington DC–based Shapiro, Lifschitz & Schram. SLS’s 10 lawyers, three paralegals, and four administrative staff will join Barclay Damon while maintaining their current office in DC’s central business district. Our clients will benefit from SLS’s corporate, real estate, finance, and construction litigation experience and national energy-industry profile, and their clients from our full range of services.

Read More

This site uses cookies to give you the best experience possible on our site and in some cases direct advertisements to you based upon your use of our site.

By clicking [I agree], you are agreeing to our use of cookies. For information on what cookies we use and how to manage our use of cookies, please visit our Privacy Statement.

I AgreeOpt-Out