New York · Legislation Insight

NY S09269: Health Data Consent Rule for Small Business

A new New York law requires separate written consent before you can use customer health information for marketing or third-party sharing.

Most professional services owners in New York don't realize that collecting customer health information—even indirectly—now triggers strict consent requirements under a new state law.

Senate Bill S09269 establishes requirements for how businesses handle health data. The provision that affects you most is buried in § 1122 (pages 3–4): you must obtain separate, plain-language, written consent from each customer before processing their health information for marketing, advertising, or sharing with third parties.

What counts as health data?

The law's definition is broad. It includes obvious things like medical history or prescription information. But it also covers inferred health data—information you deduce about someone's health status—and even location data (like visits near a clinic) or purchase records that suggest health conditions.

If your business collects any of this, the rule applies to you.

What you must do

You have two paths:

Path 1: Get written consent. Before you process health data for marketing, advertising, or sharing with vendors or partners, you must obtain a separate, opt-in written authorization from the customer. The authorization must be in plain language—not buried in a terms-of-service agreement. This is a higher bar than most privacy policies currently meet.

Path 2: Limit processing to necessary purposes. If you don't get written consent, you can only process health data for the narrow purposes the law explicitly permits. These are listed in the statute and generally cover direct service delivery and legal compliance—not marketing or business development.

Timeline

The law becomes effective 6 months after enactment. Regulatory agencies may begin drafting rules and guidance immediately upon enactment, so clarifications may come before the compliance deadline.

Who this affects

Professional services firms that collect or use health-related customer data should review their current practices now. This includes:

• Practices that maintain patient or client health records
• Businesses that use location or purchase data for targeted marketing
• Any firm sharing customer data with third parties for any reason related to health

What to do now

Audit your data collection and use practices. Identify where health information enters your systems—directly or indirectly. Review your current consent mechanisms and privacy policies. If you're processing health data for marketing or third-party sharing without explicit opt-in consent, you'll need to either obtain that consent or stop those practices before the effective date.

Plain-language consent forms and updated privacy policies should be drafted well before the deadline to allow time for customer outreach.

Source: New York Senate Bill S09269, § 1122, pages 3–4. For a detailed, business-specific guide to compliance, contact your industry association or legal counsel.

Source: S09269 · § 1122, Pages 3–4 · Effective 6 months after enactment; rules/regulations may be promulgated immediately upon enactment · Legislative data via LegiScan (CC BY 4.0), read and summarized by RESignal. Awareness, not legal advice — verify at the source.
Want this for your own business?
Get a free, data-grounded read on professional services — the decisions, the money, and the rules that actually affect you, before you act.
Get my free brief →
© RESignal, Inc. · Patent Pending · All insights · Get a free brief