N.Y. hospitals face stiff cybersecurity requirements under proposed rules

New York healthcare

New York hospitals would be required to have a cybersecurity program that includes regular cyber risk assessments under newly proposed regulations.

The proposed rules, which would require the reporting of material cyber incidents within two hours, are designed to strengthen the cybersecurity of hospitals and their networks, said New York Gov. Kathy Hochul in a press release Monday.

Complying with the proposed rules would initially cost hospitals tens of thousands or tens of millions of dollars, according to the draft rules, which noted program maturity as a dictating factor. Hospitals would be allowed to subcontract for cybersecurity services.

lock iconTHIS IS MEMBERS-ONLY CONTENT. To continue reading, choose one of the options below.