Phone.com has been closely following and adhering to HIPAA requirements for more than nine years. This is essential for being a credible and reliable Business Associate (BA) for our Covered Entity (CE) and BA customers. However, over the decade since Phone.com made the commitment to become HIPAA compliant, many state governments have also enacted related policies and procedures. As a New Jersey-based company, Phone.com is also aware of New Jersey requirements and how these relate to HIPAA compliance.
New Jersey healthcare-related organizations must comply with the State’s Security Breach Notification policy whenever unauthorized access to computer personal information is detected. Failure to promptly report such breaches to the New Jersey State Police can result in the initiation of the Criminal Investigation Delay Provisions (Henry, 2026). Furthermore, if one incident impacts more than 1,000 New Jersey residents, the breach must also be reported to a nationwide consumer reporting agency (Henry, 2026). The New Jersey State Police Cyber Crimes Unit is responsible for addressing instances where computers, networks, or telecommunications devices have been the targets of cyber-attacks.
Healthcare incidents and breaches often trigger required responses regarding both HIPAA and State-based statutes, such as those in New Jersey. Organizations such as Phone.com or our impacted customers must ensure that they follow both Federal and State regulations. In some cases, such as New Jersey, the reporting requirement may be more stringent than the current HIPAA regulations. In such instances, it is prudent to respond in compliance with the stricter expectations.
Compliance with Federal and State regulations for the protection of personally identifiable or health-related information can be complex, especially if an organization operates in multiple states. Prevention of breaches is always the first step. This comes from carefully planned strategies and tactics, considerable focus on monitoring and management of systems, and regular employee awareness training. There are many frameworks that can be employed, including those from the National Institute of Standards and Technology (NIST), SOC2, and ISO27001. Unfortunately, the current time from breach to awareness in the global healthcare industry is 279 days (more than nine months!!) (Total Assure, 2026). That means that there is much more work to be done, and obligations to Federal and State regulations require constant attention! Phone.com is serious regarding prevention and compliance!
###
References
Henry, K. (2026). New Jersey Healthcare Data Breach Notification Law: Requirements, Deadlines, and HIPAA Overlap.
New Jersey State Police. (2026). Cyber Crimes Unit.
Total Assure. (2026). Average Time to Detect a Cyber Attack 2026: Critical Detection Statistics Every Business Must Know.