Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

New York State Enforces Data Breach Notification Law

By William L. Weiner on June 30, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

Earlier this month, New York Attorney General Eric Schneiderman announced his state had entered into a settlement with CoPilot Provider Support Services, Inc. (CoPilot)—a settlement resulting from CoPilot’s violation of the data breach notification requirements of the New York General Business Law (GBL) that requires companies, among other things, to provide notice of a breach as soon as possible. Under the terms of the settlement, CoPilot, which operates a website physicians use to determine whether certain medications are covered by insurance, must pay a $130,000 fine, update its relevant policies and procedures to ensure compliance with New York’s consumer protection and data security laws, and train all of its officers, managers, and employees as to their duties in making certain CoPilot complies with the GBL and provides timely notice to any consumers affected by a data breach.

Here, CoPilot violated the GBL by waiting for more than one year, to notify consumers that the security of their data had been breached as a result of a cyberattack in October 2015—one in which the attacker accessed confidential patient reimbursement data stored by CoPilot, including names, addresses, phone numbers, birth dates, and medical insurance information. Although CoPilot notified the FBI of the breach, which began an investigation in February 2016, CoPilot waited until January 2017 before notifying affected consumers.

When one learns of data breaches involving healthcare services providers, one’s initial thought is often the notification requirements under the federal HIPAA or HITECH breach notification rule. However, the above matter serves as a valuable reminder that one needs also to be mindful of and comply with state law requirements, especially considering that all but two states have enacted their own breach notification rules relating to more than just personal health information.

 

Photo of William L. Weiner William L. Weiner

Bill Weiner represents physicians, group practices, and other privately-held companies on matters of healthcare law. In addition, he serves as outside corporate counsel for a large, international manufacturing company, headquartered in Canada and with facilities throughout the U.S. and U.K. He focuses his…

Bill Weiner represents physicians, group practices, and other privately-held companies on matters of healthcare law. In addition, he serves as outside corporate counsel for a large, international manufacturing company, headquartered in Canada and with facilities throughout the U.S. and U.K. He focuses his practice on healthcare commercial transactions and counsels physicians and their practices on billing and reimbursement, corporate governance, medical staff and regulatory issues, licensing and credentialing, government audits, HIPAA/privacy, the corporate practice of medicine, and the sale, merger, and reacquisition of practices.

Read more about William L. WeinerEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Health Law Rx
  • Organization:
    Akerman LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo