On December 24, New York Gov. Kathy Hochul (D) signed into law an amendment to section 899-aa of the N.Y. General Business Law, also known as The Shield Act, modifying the law’s data breach notification requirements.
The amendment, which took effect immediately, incorporates provisions that other states have adopted in recent years. First, the amendment shortens the timeline for notifying consumers about data breaches. Second, the amendment adds regulatory reporting requirements.
Read more…
Source: JD Supra News
Related:
- Judge rules the Pentagon’s supply chain risk label for Anthropic unlawful
August 28, 2026
A federal judge ruled the Pentagon’s decision to label AI company Anthropic a ‘supply chain risk’ violated the law and ordered the designation be removed Thursday evening. Judge Rita Lin wrote that while the military should have wide latitude to decide which companies to work with, its actions against Anthropic “constituted unlawful retaliation in violation of ...
- China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems
August 26, 2026
The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. ...
- Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
August 26, 2026
A cyberattack on U.S. medical device maker Boston Scientific is causing an ongoing “global disruption” to its operations, according to a federal regulatory filing on Wednesday. This is the latest health tech giant to face a cyberattack in recent weeks. The Massachusetts-based company, which makes medically implanted devices like pacemakers and defibrillators, confirmed in a filing with the ...
- CareCloud confirms 3.7M patients had their medical records stolen in data breach
August 19, 2026
Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health ...
- Meta is back in the courtroom to face its biggest social media addiction trial yet
August 19, 2026
Meta’s business relies on hooking young people and exploiting their data and attention, a lawyer for a group of state attorneys general argued in opening statements for the latest blockbuster trial against the social media giant on Tuesday. The trial could be Meta’s most consequential legal fight yet over youth safety and addiction. If Meta loses ...
- Top US hedge funds targeted by major vishing campaign
August 9, 2026
Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned. BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – ...
