HomeFrameworksHealthcare & Human ServicesNYS 405.46 Hospital Cyber

Framework  Healthcare & Human Services

NYS 405.46 Hospital Cyber

Section 405.46 of Title 10 of the New York Codes, Rules and Regulations is the New York State Department of Health's cybersecurity regulation for general hospitals licensed under Article 28 of the Public Health Law.

Adopted October 2, 2024, it required hospitals to begin reporting material cybersecurity incidents to the Department within 72 hours immediately, and gave them one year, until October 2, 2025, to meet the rest. It is the first state rule to require a full cybersecurity program of hospitals on top of HIPAA.

In writing, a hospital needs a cybersecurity program built on an annual risk assessment, written cybersecurity policies and procedures covering a listed set of topics (information security, access controls, asset and data governance, business continuity and disaster recovery, systems and network security and monitoring, application security, incident response, third-party service provider security, and more), a designated chief information security officer who reviews and attests to the written procedures each year, an incident response plan that is tested, records of annual penetration testing and vulnerability management, multifactor or risk-based authentication, staff training records, and audit trails and compliance documentation retained for six years.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedCyber policy 2026by name, on record
405.46 Handledwith AllyMatter
Protect the Ward the Modern WayEvery 405.46 policy, acknowledged by the hospital workforce
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee on record
Who read which version, and when
03
Show the Department of Health the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

All general hospitals licensed under Article 28 of the New York Public Health Law. Other Article 28 facilities such as nursing homes and diagnostic and treatment centers are not covered by this section (verify any later expansion).

What the assessor asks to see

Surveyors ask for the CISO designation and reporting line, the current risk assessment, the written cybersecurity policies approved by the governing body, the incident response plan and test records, the log of incidents and the 72-hour reports made to the Department, penetration test and vulnerability remediation records, multifactor authentication and access review evidence, asset inventory, third-party service provider security policy and vendor assessments, staff training records, and audit trail retention showing six years.

Where the requirement sits: 10 NYCRR 405.46 (phased effectiveness 2025-2026 - verify)

Key dates

Adopted and effective October 2, 2024 with immediate 72-hour incident reporting. Compliance with the full program required by October 2, 2025. Documentation must be retained for six years.

What AllyMatter does here

Policy and training-acknowledgment layer.

AllyMatter publishes this site.

Assessors

Who assesses NYS 405.46 Hospital Cyber

New York State Department of Health surveyors, who can review cybersecurity compliance during Article 28 surveillance and complaint investigations, and the Department's enforcement staff. There is no certification.

No firm has claimed a NYS 405.46 Hospital Cyber assessor listing yet. Claim yours →

Consultants

Who helps with NYS 405.46 Hospital Cyber

Health care cybersecurity consultancies, virtual CISO providers, and the hospital associations' member programs. Engagements typically cover a 405.46 gap assessment, policy set drafting, risk assessment, penetration testing, and building the CISO attestation and 72-hour reporting workflow. The state paid grants to hospitals to fund the work.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

Echelon CyberUSANot yet verified
What they do
VCISO
Who they help
Echelon Cyber is a vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
URM ConsultingUKNot yet verified
What they do
ISO 27001 consultancy
Who they help
URM Consulting is an ISO 27001 consultancy based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Nettitude (LRQA Cyber Security)Birmingham, UKNot yet verified
What they do
CREST partner
Who they help
Nettitude (LRQA Cyber Security) is a CREST partner based in Birmingham, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BridewellUKNot yet verified
What they do
Cyber posture + ISMS management
Who they help
Bridewell is a cyber posture + ISMS management based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for NYS 405.46 Hospital Cyber

Tools that name this framework in their own material.

Related reading

  1. Cyber Countdown: New York Hospitals Face New Data Security MandatesCompares 405.46 line by line against HIPAA, showing where the New York rule is more prescriptive, including the CISO's annual attestation.Holland & Knight
  2. New York Cybersecurity Regulations for General Hospitals Take Effect October 2, 2025Runs through the programme, testing, incident response and 72-hour reporting duties a general hospital had to have in place by the deadline.Nixon Peabody

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for NYS 405.46 Hospital Cyber

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of NYS 405.46 Hospital Cyber in AllyMatter

Approve the policies NYS 405.46 Hospital Cyber asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.