Requires mobile applications on cell phones, smart phones and tablets that offer a subscription service provide an option to cancel the subscription on its application and have the option posted in a clear and conspicuous format.
Requires medical records to be made available to patients in an electronic format through a web portal and in a format that allows patients to save records to their own device; requires electronic medical records systems to give qualified persons access to records in a single, secure format and to establish policies and procedures to endure confidentiality.
Requires the owner, licensee or operator of a generative artificial intelligence system to conspicuously display a notice on the system's user interface that is reasonably calculated to consistently apprise the user that the outputs of the generative artificial intelligence system may be inaccurate.
This bill requires New York State to keep lottery winners' personal information confidential from the public, including names and addresses. It directly affects anyone who wins a lottery prize over $5,000, preventing the state lottery division from disclosing their identity without their explicit consent. The key provision mandates that winners must actively consent for their details to be shared; otherwise, the state cannot publish or share their information publicly. The law also clarifies that payment procedures remain unchanged, including payments to estates or under court orders, but anonymity applies to all public disclosures. This is a privacy-focused change to existing lottery procedures.
Relates to computer-related crimes; creates the crimes unlawful disruption of computer services in the first and second degree, unlawful computer access assistance in the first and second degree, unauthorized use of internet domain name or profile, and unlawful introduction of a computer contaminant; allows for a civil action for compensatory damages for victims of such crimes.
Relates to establishing the crime of larceny by cyber extortion which occurs when a person intends to obtain property from another person or entity located in the state of New York through the use of certain malicious software.
S 681 prohibits most private employers from requiring fingerprinting or mandatory iris/retina scans as a condition of hiring or continued employment. It directly affects private-sector workers and employers, with key exceptions for state/municipal employees, public hospitals, medical colleges affiliated with public hospitals, and private hospitals. The bill amends labor law to make this prohibition explicit and takes effect immediately upon enactment. It does not apply to government workers or healthcare facilities receiving public funding.
This bill (A 428) protects New York users of paid online dating services by setting clear consumer safeguards. It limits subscription contracts to $1,000 total (with exceptions for short-term plans), bans requiring forced add-on services (like grooming), and guarantees a minimum number of matches per month for paid plans over $25. Users gain the right to cancel without penalty if matches aren't delivered for two months, receive a refund (minus a small fee), and get their personal data deleted or returned upon cancellation. The law directly affects all paid online dating platforms operating in New York, ensuring transparency and reducing deceptive practices.
This bill amends New York's penal law and related statutes to explicitly include "medical information" and "health insurance information" in the legal definition of "personal identifying information." It defines medical information as details about an individual's medical history or treatment, and health insurance information as policy numbers, subscriber IDs, or claims history. These changes mean that identity theft involving such sensitive health data will now be covered under existing identity theft laws, which previously did not explicitly include these categories. The bill also removes outdated definitions from related laws to streamline the updated framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.