S T A T E   O F   N E W   Y O R K
 ________________________________________________________________________
 
                                   6200
 
                        2023-2024 Regular Sessions
 
                           I N  A S S E M B L Y
 
                               April 3, 2023
                                ___________
 
 Introduced by M. of A. K. BROWN -- read once and referred to the Commit-
   tee on Governmental Operations
 
 AN  ACT  to  amend  the  state  technology law, in relation to requiring
   certain security  measures  before  state  funds  can  be  distributed
   digitally
 
   THE  PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
 BLY, DO ENACT AS FOLLOWS:
 
   Section 1. The state technology law is amended by adding a new section
 106-c to read as follows:
   § 106-C. DIGITAL DISTRIBUTION OF  STATE  FUNDS.    ANY  STATE  AGENCY,
 BOARD,  BUREAU,  AUTHORITY,  COMMISSION, DIVISION, OR OTHER GOVERNMENTAL
 ENTITY PERFORMING A GOVERNMENTAL OR PROPRIETARY FUNCTION FOR  THE  STATE
 THAT  ALLOWS FOR THE DIGITAL DISTRIBUTION OF STATE FUNDS SHALL REQUIRE A
 PERSON TO CREATE AN ACCOUNT WITH THE GOVERNMENTAL ENTITY  THROUGH  WHICH
 STATE  FUNDS CAN BE DISTRIBUTED TO SUCH PERSON.  SUCH ACCOUNT SHALL HAVE
 THE FOLLOWING SECURITY FEATURES:
   1. VERIFIED ACCOUNT. (A) TO CREATE AN ACCOUNT, A  USER  SHALL  PROVIDE
 AND CONFIRM THE FOLLOWING INFORMATION:
   (I) THE USER'S FULL NAME;
   (II) THE USER'S PHYSICAL RESIDENTIAL ADDRESS;
   (III) THE USER'S DATE OF BIRTH;
   (IV) AT LEAST TWO OF THE FOLLOWING:
   (A) THE USER'S SOCIAL SECURITY NUMBER;
   (B) THE USER'S DRIVER'S LICENSE NUMBER;
   (C) THE USER'S UNITED STATES PASSPORT NUMBER;
   (D) THE USER'S TAXPAYER IDENTIFICATION NUMBER; OR
   (E)  ANY  OTHER FORM OF IDENTIFICATION ISSUED BY A GOVERNMENTAL ENTITY
 APPROVED BY THE OFFICE; AND
   (V) THE USER'S EMAIL ADDRESS OR TELEPHONE NUMBER.
   (B) THE USER'S ACCOUNT SHALL HAVE A UNIQUE USERNAME CHOSEN BY THE USER
 USING RULES APPROVED BY THE OFFICE.
 
  EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                       [ ] is old law to be omitted.
                                                            LBD10356-01-3
              
             
                          
                 A. 6200                             2
 
   (C) THE GOVERNMENTAL ENTITY SHALL VALIDATE THE INFORMATION PROVIDED BY
 THE USER TO CREATE SUCH ACCOUNT IS ACCURATE.
   2.  MULTI-FACTOR AUTHORIZATION. TO ACCESS AN ACCOUNT MADE UNDER SUBDI-
 VISION ONE OF THIS SECTION, A USER SHALL BE REQUIRED TO USE  THE  USER'S
 USERNAME  AND  TWO  OF THE FOLLOWING METHODS OF AUTHENTICATION TO VERIFY
 SUCH USER'S IDENTITY:
   (A) A PASSWORD;
   (B) ANSWERS TO PREVIOUSLY PROVIDED SECURITY QUESTIONS;
   (C) BIOMETRIC DATA, INCLUDING FINGERPRINT, FACIAL  OR  VOICE  RECOGNI-
 TION;
   (D) AN AUTHORIZATION CODE SENT BY PHONE CALL, TEXT MESSAGE OR EMAIL TO
 THE APPROPRIATE CONTACT INFORMATION PROVIDED; OR
   (E) ANY OTHER AUTHORIZATION TYPES APPROVED BY THE OFFICE.
   §  2. This act shall take effect one year after it shall have become a
 law. Effective immediately, the addition, amendment and/or repeal of any
 rule or regulation necessary for the implementation of this act  on  its
 effective date are authorized to be made and completed on or before such
 effective date.