...

Ekim IT Solutions

Blog / New York Dental Practice Data Privacy: SHIELD Act and HIPAA
All Dental

New York Dental Practice Data Privacy: SHIELD Act and HIPAA

Ekim IT Solutions guide to New York SHIELD Act and HIPAA compliance for dental practices
A New York dental practice should treat HIPAA as the federal health-data baseline and the SHIELD Act as an additional state privacy and breach framework.

HIPAA protects protected health information, while New York’s SHIELD Act expands state data-security and breach-notification requirements around private information belonging to New York residents.

The frameworks overlap, but they are not identical. A useful compliance program should understand what information is covered, what safeguards are required, and which notification duties apply when an incident occurs.

The overlap is real, but the frameworks are not interchangeable HIPAA compliance can satisfy the SHIELD Act reasonable-safeguards provision for a regulated entity that is actually compliant, but New York notification duties still have to be evaluated separately. Simply being a dental practice that falls under HIPAA is not the same as having performed the required risk analysis, implemented safeguards, maintained policies, and documented the program.
Need HIPAA and NY SHIELD Act aligned as one dental security program? Find out in 15 minutes if we are the right fit.
Schedule a Discovery Call →
Different coverage, overlapping security work The first question is what kind of information the practice is protecting.

HIPAA and the SHIELD Act both matter to a New York dental practice, but they reach different categories of information and use different legal frameworks.

HIPAAProtects protected health information, with the Security Rule specifically applying to electronic protected health information created, received, maintained, or transmitted by covered entities and business associates.
New York SHIELD ActApplies to businesses that own or license computerized data containing private information of New York residents, including certain combinations involving financial information, biometric information, and online credentials.
Build one practical security program The day-to-day controls overlap heavily even when the laws are different.

The SHIELD Act calls for reasonable administrative, technical, and physical safeguards, while HIPAA also requires administrative, physical, and technical safeguards for ePHI. A dental practice benefits from operating one coordinated security program around its real environment.

AdministrativeRisk identification, employee training, service-provider oversight, program adjustment, workforce procedures, and documentation.
TechnicalNetwork and software risk assessment, authentication, access controls, attack detection and response, transmission security, backups, and monitoring.
PhysicalFacility and device protections, secure disposal, physical access controls, and protection against unauthorized access.
Breach timing is not identical A New York practice cannot safely rely on the longer federal timeline when state law may require faster action.

The article distinguishes HIPAA’s individual-notice timeline from New York’s state timing and additional notice requirements.

HIPAAIndividual notice must be provided without unreasonable delay and no later than 60 days after discovery of a reportable breach of unsecured PHI.
New YorkCovered state notice is described as required in the most expedient time possible and without unreasonable delay, with a 30-day outer limit after discovery, subject to statutory exceptions and law-enforcement delay.

Stack the HIPAA and SHIELD Act Privacy Layers

Combine the two frameworks into one operating model while keeping their different coverage and breach duties visible.

One dental practice, two overlapping frameworks

1. Review each privacy layer2. Connect the shared safeguards
Federal Health-Data LayerHIPAA

Protects PHI and applies Security Rule safeguards to ePHI handled by covered entities and business associates.

Risk analysis and risk managementAccess management and authenticationAdministrative, physical, and technical safeguards
Shared SafeguardsCoordinate the controls without collapsing the legal differences.
New York Privacy LayerSHIELD Act

Covers private information of New York residents and adds state reasonable-safeguards and breach-response requirements.

Administrative safeguardsTechnical safeguardsPhysical safeguards and state breach duties
Shared Operating Controls
Risk + Access ManagementSecurity + Monitoring ControlsDocumented Incident Response
Still DifferentWhat Information Is Covered

HIPAA centers on PHI and ePHI. The SHIELD Act also reaches covered private information such as certain financial, biometric, and online-credential combinations.

Still DifferentBreach Timing + State Notices

HIPAA individual notice can run to 60 days, while New York can require faster action and separate state notifications depending on the incident.

The right model is coordinated, not duplicated.A New York dental practice can align shared safeguards across HIPAA and the SHIELD Act, but it still needs to understand which information each framework covers and which federal and state notification duties apply after an incident.

Frequently Asked Questions

Not completely. For the SHIELD Act’s reasonable-safeguards requirement, New York law treats an entity that is subject to and in compliance with HIPAA and HITECH security requirements as a compliant regulated entity. That deemed-compliance provision applies to the SHIELD Act’s reasonable-security requirement, but it does not mean HIPAA replaces New York’s separate breach-notification requirements or other applicable state-law obligations.
The deadline depends on which law applies and whether the incident meets that law’s definition of a reportable breach. HIPAA requires individual notice without unreasonable delay and no later than 60 days after discovery of a reportable breach of unsecured protected health information. New York General Business Law § 899-aa generally requires affected New York residents to be notified in the most expedient time possible, without unreasonable delay, and within 30 days after discovery of a qualifying breach, subject to statutory exceptions and permitted law-enforcement delay.
Generally, no additional duplicate notice to the same affected people is required under New York § 899-aa when breach notice is provided to them under HIPAA or HITECH. New York agency-notification requirements can still apply, including notice to the New York Attorney General, Department of State, and Division of State Police when New York residents are being notified. A HIPAA covered entity that reports a breach to the U.S. Department of Health and Human Services must also notify the New York Attorney General within five business days after notifying HHS.
Yes. New York’s definition of private information includes a username or email address combined with a password or security question and answer that would permit access to an online account. This means a compromised login can potentially trigger New York breach-analysis requirements even when the incident does not involve traditional identifiers such as a Social Security number or financial account number.
The IT team should help contain the incident, preserve technical evidence, and determine which systems, accounts, and information may have been affected, but IT should not make the legal reportability decision alone. The dental practice should involve its privacy or compliance leadership and qualified legal counsel to determine whether HIPAA, New York law, contractual requirements, cyber-insurance obligations, or other notification rules are triggered by the specific facts.
Assuming HIPAA compliance means you’re covered under New York’s SHIELD Act too?

Ekim IT Solutions works exclusively with dental practices across New York and nationwide. We build the complete compliance program that addresses which information SHIELD covers, what safeguards it requires, and how notification obligations differ from HIPAA alone.

Compliance built for both HIPAA and the SHIELD Act.
Get a New York data privacy compliance review →