On Jan. 5, 2024, the New York State Attorney General, Bureau of Internet and Technology, announced a settlement with Refuah Health Center, Inc. (Refuah), a Hudson Valley federally qualified health center.  The settlement resulted in an Assurance of Discontinuance (AoD), in which the attorney general agreed to certain relief from Refuah in lieu of commencing an enforcement action.  Such AoDs are becoming more and more common in New York, as the attorney general—through the Bureau of Internet and Technology—investigates data breaches reported under N.Y. Gen. Bus. Law §899-aa.

Prior to October 2019, the reporting obligations under §899-aa concerned themselves solely with “private information,” defined generally as name or some other identifier coupled with a more sensitive data element, such as credit card number or social security number.