- What they do
- VCISO
- Who they help
- Echelon Cyber is a vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Healthcare & Human Services
NYS 405.46 Hospital Cyber
Section 405.46 of Title 10 of the New York Codes, Rules and Regulations is the New York State Department of Health's cybersecurity regulation for general hospitals licensed under Article 28 of the Public Health Law.
Adopted October 2, 2024, it required hospitals to begin reporting material cybersecurity incidents to the Department within 72 hours immediately, and gave them one year, until October 2, 2025, to meet the rest. It is the first state rule to require a full cybersecurity program of hospitals on top of HIPAA.
In writing, a hospital needs a cybersecurity program built on an annual risk assessment, written cybersecurity policies and procedures covering a listed set of topics (information security, access controls, asset and data governance, business continuity and disaster recovery, systems and network security and monitoring, application security, incident response, third-party service provider security, and more), a designated chief information security officer who reviews and attests to the written procedures each year, an incident response plan that is tested, records of annual penetration testing and vulnerability management, multifactor or risk-based authentication, staff training records, and audit trails and compliance documentation retained for six years.
Who has to comply
All general hospitals licensed under Article 28 of the New York Public Health Law. Other Article 28 facilities such as nursing homes and diagnostic and treatment centers are not covered by this section (verify any later expansion).
What the assessor asks to see
Surveyors ask for the CISO designation and reporting line, the current risk assessment, the written cybersecurity policies approved by the governing body, the incident response plan and test records, the log of incidents and the 72-hour reports made to the Department, penetration test and vulnerability remediation records, multifactor authentication and access review evidence, asset inventory, third-party service provider security policy and vendor assessments, staff training records, and audit trail retention showing six years.
Where the requirement sits: 10 NYCRR 405.46 (phased effectiveness 2025-2026 - verify)
Key dates
Adopted and effective October 2, 2024 with immediate 72-hour incident reporting. Compliance with the full program required by October 2, 2025. Documentation must be retained for six years.
What AllyMatter does here
Policy and training-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses NYS 405.46 Hospital Cyber
New York State Department of Health surveyors, who can review cybersecurity compliance during Article 28 surveillance and complaint investigations, and the Department's enforcement staff. There is no certification.
No firm has claimed a NYS 405.46 Hospital Cyber assessor listing yet. Claim yours →
Consultants
Who helps with NYS 405.46 Hospital Cyber
Health care cybersecurity consultancies, virtual CISO providers, and the hospital associations' member programs. Engagements typically cover a 405.46 gap assessment, policy set drafting, risk assessment, penetration testing, and building the CISO attestation and 72-hour reporting workflow. The state paid grants to hospitals to fund the work.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- ISO 27001 consultancy
- Who they help
- URM Consulting is an ISO 27001 consultancy based in UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- CREST partner
- Who they help
- Nettitude (LRQA Cyber Security) is a CREST partner based in Birmingham, UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Cyber posture + ISMS management
- Who they help
- Bridewell is a cyber posture + ISMS management based in UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for NYS 405.46 Hospital Cyber
Tools that name this framework in their own material.
Related reading
- Cyber Countdown: New York Hospitals Face New Data Security MandatesCompares 405.46 line by line against HIPAA, showing where the New York rule is more prescriptive, including the CISO's annual attestation.Holland & Knight
- New York Cybersecurity Regulations for General Hospitals Take Effect October 2, 2025Runs through the programme, testing, incident response and 72-hour reporting duties a general hospital had to have in place by the deadline.Nixon Peabody
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NYS 405.46 Hospital Cyber
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of NYS 405.46 Hospital Cyber in AllyMatter
Approve the policies NYS 405.46 Hospital Cyber asks for, keep every version, and record a named acknowledgment from each person who has to read them.