Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

New York SHIELD Act Attorney: Is Your Cybersecurity Reasonable?

New York SHIELD Act Attorney: Is Your Cybersecurity Reasonable?

Earlier this week, we spoke with a physician who operates a busy medical practice in New York.

Thousands of patient records. Employees handling sensitive information every day.

He had never heard of the New York SHIELD Act.

He is not alone.

Many New York businesses do not realize that the SHIELD Act applies to them and imposes legal obligations to protect personal information.

There is another problem. The statute was enacted in 2019 for a cybersecurity environment that no longer exists.

Today, according to the NSA and other Five Eyes cybersecurity agencies (June 22, 2026 statement):

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”

Yet the SHIELD Act still requires businesses to implement and maintain “reasonable safeguards” to protect sensitive information.

What qualifies as “reasonable” in an era of AI-driven cyberattacks is becoming one of the most important questions facing New York businesses.

Whether the law has kept pace with technology or not, the legal obligation remains.

What the SHIELD Act actually requires

The Stop Hacks and Improve Electronic Data Security (SHIELD) Act was signed into law on July 25, 2019 (NY Senate, S5575B).

The data security provisions became effective on March 21, 2020 (S5575B, § 6)

New York already had a law requiring businesses to respond after a data breach occurred.

The SHIELD Act went further. It imposed a legal duty to protect personal information before a breach happens:

“Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data.” See N.Y. Gen. Bus. Law § 899-bb(2)(a). [Emphasis added].

It applies broadly to businesses of all sizes, including:

  1. medical practices/healthcare providers
  2. financial institutions;
  3. law firms;
  4. investment advisers;
  5. startups;
  6. family offices; and
  7. co-op/condo boards

The law is triggered by the residency of the individual whose data is collected; not by the location of the business.

As a result, even out-of-state companies could be covered if they hold personal information about New York residents.

The standard is simply “reasonable safeguards.” The problem is that the statute never defines what “reasonable” means.

It certainly does not explain what reasonable security looks like in an age of AI-driven cyberattacks ( which the NSA warned in 2026 are evolving on a timeline measured in months, not years).

The statute gives categories, not a level

Instead of providing a definition, the statute describes a compliance framework that businesses can follow.

The cybersecurity provisions require a business to “designate one or more employees to coordinate the security program.” § 899-bb(2(b)(ii)(A)(i).

The law also requires businesses to:

  • Identify “reasonably foreseeable internal and external risks.”
  • Assess “the sufficiency of safeguards in place to control the identified risks.”
  • Train and manage “employees in the security program practices and procedures.”
  • “Adjust[] the security program in light of business changes or new circumstances.”

Notably, the statute outlines these requirements but never defines what qualifies as a “reasonable” safeguard in practice.

That question has become increasingly important as AI-driven cyber threats continue to evolve.

The technical safeguards focus on a business’s systems and controls. The statute requires businesses to:

  • Assess “risks in network and software design.”
  • Assess “risks in information processing, transmission and storage.”
  • Detect, prevent, and respond to “attacks or system failures.”
  • Regularly test and monitor “the effectiveness of key controls, systems and procedures.”

The physical safeguards address the protection and handling of data. Businesses must:

  • Assess “risks of information storage and disposal.”
  • Detect, prevent, and respond to “intrusions.”
  • Protect against “unauthorized access to or use of private information during or after the collection, transportation and destruction or disposal of the information.”

See N.Y. Gen. Bus. Law § 899-bb(2)(b)(ii)(B)-(C).

A 2019 standard meets a 2026 threat

On June 22, 2026, the National Security Agency and allied cyber security agencies published a joint statement:

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months” (NSA, Five Eyes Cyber Security Agencies Statement, June 22, 2026). {emphasis added].

Agencies drove the point home with another observation:

“Cyber risk assumptions can become outdated in months, not years” (Id.).

That creates an obvious problem. The New York SHIELD Act was enacted in 2019.

It was written for a cybersecurity environment that no longer exists.

Today’s threat landscape is being reshaped by AI at a pace measured in months, not years.

Yet the law remains in force. The fact that technology has evolved does not relieve businesses of their obligations.

If anything, it raises the bar. What is “reasonable” security is measured against what a business knew, or should have known, about foreseeable risks.

Following a public warning from the NSA, it is becoming increasingly difficult to argue that AI-enabled cyberattacks are unforeseeable.

The SHIELD Act already requires businesses to adjust their security programs for “business changes or new circumstances.”

A risk assessment prepared before June 22, 2026 and never revisited may therefore present its own compliance problem.

In short, the threat environment has changed dramatically. The legal obligation to maintain reasonable safeguards has not.

What information triggers the duty

“Private information” is far broader than most New York businesses assume.

It includes traditional identifiers such as Social Security numbers, driver’s license numbers, and payment card data.

But the statute also covers biometric information, health insurance information, and “medical information” concerning an individual’s “medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional.”

Even login credentials can qualify.

A “user name or e-mail address in combination with a password” that provides access to an online account is protected under the statute as well. (§ 899-aa(1)(b)).

“Private information” is broader than most owners assume.

Two important qualifications apply.

First, the SHIELD Act recognizes that not every business has the same resources.

A “small business” is generally one with less than 50 employees (less than $3 million in annual revenue) or or less than $5 million in total assets.

Such businesses are only required to maintain safeguards that are “appropriate for the size and complexity” of the business. (§ 899-bb(1)(c), (2)(c)).

Second, some businesses could qualify for a statutory safe harbor.

An entity that is already subject to and compliant with regulatory frameworks such as HIPAA, the Gramm-Leach-Bliley Act, or 23 NYCRR Part 500 is deemed compliant with the SHIELD Act’s data security requirements. (§ 899-bb(1)(a), (2)(b)(i)).

The key point is that the safe harbor depends on actual compliance. It is not enough to operate in a regulated industry.

A business must be able to demonstrate that it is complying with the applicable regulatory framework.

No private right of action — and why that is not comfort

The SHIELD Act has teeth. A business that fails to maintain “reasonable safeguards” may face enforcement by the New York Attorney General and civil penalties of up to $5,000 per violation.

The statute also states that “Nothing in this section shall create a private right of action.”

That does not mean a business can’t be sued after a breach.

Plaintiffs often bring negligence claims instead, and the SHIELD Act could become a benchmark for what constitutes reasonable cybersecurity.

In practice, your compliance records can become either your strongest defense or the plaintiff’s strongest exhibit.

How Dilendorf Law Firm helps

Max Dilendorf has worked as a digital asset attorney since 2017. He has handled more than 100 cybercrime matters involving financial institutions, telecommunications carriers, account takeovers, SIM swaps, and authentication failures.

That experience shapes how we approach compliance. We know which records are requested after an incident and which documents become critical evidence.

Our team also includes retired federal law enforcement investigators, including former FBI and U.S. Secret Service agents with decades of cybercrime experience.

We help businesses answer a question the SHIELD Act does not: What is reasonable for your business?

We assess existing safeguards, review vendor agreements, and conduct tabletop exercises. The goal is to identify gaps before an incident occurs; not afterward.

We advise medical practices, financial firms, investment advisers, startups, family offices, and co-op and condominium boards throughout New York.

If you have already been breached, call today — the first days decide everything: +1 212 457 9797 or info@dilendorf.com.

Frequently asked questions

Does the SHIELD Act apply to my small practice or business?

Most likely, yes. The duty applies to “any person or business that owns or licenses computerized data which includes private information of a resident of New York” (§ 899-bb(2)(a)). There is no industry limitation and no minimum size. A business with fewer than fifty employees, or under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets may satisfy the statute with safeguards “appropriate for the size and complexity” of the business (§ 899-bb(1)(c), (2)(c)) — a scaled duty, not an exemption.

My practice complies with HIPAA. Am I already covered?

Possibly, but only if the compliance is real and documented. A “compliant regulated entity” — one subject to and in compliance with HIPAA and HITECH regulations, Gramm-Leach-Bliley safeguards rules, or 23 NYCRR Part 500 — is deemed to satisfy the reasonable safeguards requirement (§ 899-bb(1)(a), (2)(b)(i)). The safe harbor depends on actual compliance rather than industry status, so the practical question is whether your risk analysis, training records, and vendor agreements would survive review.

What does “reasonable” mean in practice?

The statute never defines it. It lists categories instead: designating a security coordinator, identifying “reasonably foreseeable internal and external risks,” assessing “the sufficiency of safeguards in place,” training employees, requiring vendor safeguards by contract, and adjusting the program for “new circumstances” (§ 899-bb(2)(b)(ii)(A)). Because the level is left open, reasonableness is assessed against your specific data, threats, and resources — and against what was publicly known at the time.

Why does the June 2026 NSA statement matter to my compliance file?

It affects foreseeability. The Five Eyes cyber security agencies stated that frontier AI is transforming offensive cyber capability and that “The timeline is not years, it is months” (NSA, June 22, 2026). Reasonableness is measured against what a business knew or should have known, and the statute requires the program to be adjusted for new circumstances. A risk assessment last updated before that date, with no review since, is difficult to defend as current.

Can my patients or clients sue me under the SHIELD Act?

Not under the statute itself: “Nothing in this section shall create a private right of action” (§ 899-bb(2)(e)). That is narrower protection than it sounds. Private plaintiffs typically sue in negligence after a breach, and negligence turns on what reasonable care required, which makes the statute’s safeguard categories a ready benchmark for measuring your conduct. Your documentation is usually the central evidence either way.

What can the Attorney General do if I am not compliant?

A failure to maintain reasonable safeguards is deemed a violation of General Business Law § 349, and the Attorney General may sue to enjoin it and obtain civil penalties (§ 899-bb(2)(d)). Penalties run up to “five thousand dollars for each violation” (§ 350-d), and the Attorney General’s guidance confirms up to $5,000 per violation for safeguard failures, alongside separate penalties of up to $20 per instance of failed notification, capped at $250,000 (NY OAG, SHIELD Act).

What counts as private information?

More than Social Security numbers. The definition includes driver’s license numbers, financial account and payment card numbers, biometric data, “medical information” regarding medical history, condition, treatment or diagnosis, health insurance information, and a username or email address combined with a password or security question and answer permitting access to an online account (§ 899-aa(1)(b)). For medical offices and advisory businesses, ordinary records routinely qualify.

Do I have to notify anyone if there is no evidence of misuse?

Sometimes not, but the exception must be documented. Where exposure resulted from inadvertent disclosure by authorized persons and the business reasonably determines misuse or harm is unlikely, consumer notice may not be required — but the determination must be made in writing and kept for at least five years, and if more than 500 New York residents are affected it must be provided to the Attorney General within ten days (NY OAG, SHIELD Act).

When should a business bring in a lawyer rather than an IT vendor?

Before an incident, and certainly at the moment one is suspected. Technical remediation and legal defensibility are different objectives: a vendor secures the environment, while counsel builds the record that answers the negligence question, handles notification analysis, preserves privilege where available, and allocates risk in vendor contracts. Dilendorf Law Firm combines that legal work with investigators who came from federal cybercrime enforcement.

This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.

Sources

[1] N.Y. Gen. Bus. Law § 899-bb, Data security protections (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/899-BB

[2] N.Y. Gen. Bus. Law § 899-aa, Notification; person without valid authorization has acquired private information (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/899-AA

[3] N.Y. Gen. Bus. Law § 350-d, Civil penalty (NYS Open Legislation). https://www.nysenate.gov/legislation/laws/GBS/350-D

[4] New York State Senate, Bill S5575B (2019), signed July 25, 2019, Chapter 117. https://www.nysenate.gov/legislation/bills/2019/S5575

[5] New York State Senate, S5575B bill text, § 6 (effective dates). https://legislation.nysenate.gov/pdf/bills/2019/S5575B

[6] Office of the New York State Attorney General, “SHIELD Act.” https://ag.ny.gov/resources/organizations/data-breach-reporting/shield-act

[7] National Security Agency, “Five Eyes Cyber Security Agencies Statement,” June 22, 2026. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation