HHS Issues Modifications to the HIPAA Privacy, Security and Enforcement Rules

On July 8, 2010, the Department of Health and Human Services ("HHS") issued a notice of proposed rulemaking to modify the Privacy, Security and Enforcement Rules promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996.  The modifications implement changes made by the Health Information Technology for Economic and Clinical Health Act (the “HITECH” Act) enacted in 2009.

Some of the major changes to the HIPAA Rules include:

  • Adding “subcontractors” to the definition of “business associate” to provide that subcontractors that perform functions for or provide services to a business associate are also business associates to the extent they require access to protected health information (“PHI”);
  • Requiring business associates to enter into written contracts with those subcontractors (previously, business associates were only required to “ensure” that subcontractors agree to the same restrictions on the use and disclosure of PHI);
  • Applying the Security Rule and the Enforcement Rule penalty provisions directly to business associates;
  • Revising the definition of “marketing” in the Privacy Rule to delineate which specific activities constitute marketing of PHI;
  • Clarifying that a business associate is not making a permitted use or disclosure under the Privacy Rule if it does not apply the minimum necessary standard, where appropriate; and
  • Requiring covered entities to obtain an authorization from an individual for any disclosure of the individual’s PHI in exchange for direct or indirect remuneration (with a few exceptions such as exchanges for public health activities).

HHS will be accepting comments to the notice of proposed rulemaking for a period of 60 days after the notice of proposed rulemaking is published in the Federal Register on July 14, 2010.

In addition to the changes to the HIPAA Rules, HHS announced a new privacy website designed to “provide further confidence in the expectations Americans have for the privacy of their personal information” and to “inspire added trust in HHS’ efforts to improve our nation’s health through safe and secure health information exchanges.”  HHS also announced enhancements to its breach notification website that will provide consumers with more information regarding breaches involving PHI and ongoing breach investigations.  Currently, the HHS breach notification website lists only basic details about breaches, such as the name of the covered entity at issue and the number of individuals affected by the relevant breach.
 

HHS To Examine Breach Notification and Risk Mitigation Plans

The Office for Civil Rights (“OCR”) within the Department of Health and Human Services (“HHS”) has announced that it will more closely examine covered entities’ breach notification and risk mitigation plans.  OCR noted that small and medium sized covered entities have been particularly vulnerable to data breaches.  The National Institute of Standards and Technology (“NIST”) will publish a guide for covered entities that “outlines the steps to mitigate risks for data breaches, training for how to respond to breaches, and overall preparation in the event of a breach, such as alternate storage facilities for data.”

As previously discussed on this blog, OCR has announced an uptick in HIPAA Security Rule enforcement and issued draft guidance regarding the “risk analysis” implementation specification in the Security Rule.

HHS Official Reports Uptick in HIPAA Security Rule Enforcement

David Holtzman, a health information privacy specialist at the Office for Civil Rights (“OCR”) within the Department of Health and Human Services (“HHS”), stated at a health privacy conference on May 11, 2010, that OCR has been “vigorously” enforcing the Security Rule, which was promulgated pursuant to the Health Insurance Portability and Accountability Act (“HIPAA”).  Prior to 2009, HHS divided civil enforcement responsibility for HIPAA between OCR, which enforced the HIPAA Privacy Rule, and the Centers for Medicare and Medicaid Services (“CMS”), which enforced the HIPAA Security Rule.  In July 2009, the Secretary of HHS delegated authority to enforce the HIPAA Security Rule to OCR to “facilitate improvements by eliminating duplication and increasing efficiency.”

Holtzman stated that OCR is conducting compliance reviews for all HIPAA data breaches involving data for more than 500 individuals, and is working with covered entities to identify compliance issues that led to those breaches.  Marilou King, a senior attorney at the HHS Office of General Counsel, also mentioned that HHS is working to with a contractor to develop a process to audit coved entities for compliance with the HIPAA Privacy and Security Rules, and could utilize informal resolution agreements to address violations of the HIPAA Privacy and Security Rules.  Ms. King also mentioned that HHS intends to finalize soon the interim enforcement rule it released last year and issue a proposed rule regarding covered entities and business associates, as mandated by the Health Information Technology for Economic and Clinical Health (“HITECH”) Act.

The recent comments by HHS officials followed OCR’s issuance of draft guidance on May 7, 2010, regarding the risk analysis requirement in the HIPAA Security Rule.  The guidance defines several key terms that are not expressly defined in the Security Rule, including “vulnerability,” “threat” and “risk,” although the guidance noted that the terms “do not modify or update the Security Rule and should not be interpreted inconsistently with the terms used in the Security Rule.”  More critically, the guidance “explains several elements a risk analysis must incorporate, regardless of the method employed.”  Those elements include: (1) defining the scope of the analysis, (2) identifying where electronic protected health information is stored, received, maintained or transmitted, (3) identifying and documenting potential threats and vulnerabilities, (4) assessing current security measures, (5) determining the likelihood of threat occurrence, (6) determining the potential impact of threat occurrence, (7) determining the level of risk, (8) finalizing the risk analysis documentation and (9) periodically reviewing and updating the risk analysis.

Attorney General Launches New HIPAA Investigation

The Attorney General of Connecticut, Richard Blumenthal, is investigating an alleged breach of medical records at Griffin Hospital in Derby, Connecticut.  The hospital believes that a formerly affiliated radiologist gained unauthorized access to its digital Picture Archiving and Communications System (“PACS”), which stores patient information, including names, exam descriptions and medical record numbers.  In February, the hospital began receiving inquiries from patients who had been contacted by the radiologist to promote professional services offered at another medical facility.  In response to patient inquiries, the hospital conducted an internal investigation that revealed several instances of unauthorized access to the PACS system.  The hospital subsequently notified Attorney General Blumenthal.

In a statement, the Attorney General indicated that “unauthorized accessing of patient information is a violation of the federal HIPAA law that my office is empowered to enforce” and that he would “seek strong and significant sanctions, if warranted by the facts.”

Passed as part of the economic stimulus legislation in 2009, the HITECH Act authorizes state attorneys general to enforce HIPAA.  Attorney General Blumenthal was the first state attorney general to file a suit pursuant to this HITECH Act enforcement authority.  For more information on the first HITECH Act suit, please see our previous blog post

HHS Delays Enforcement of HITECH Act Business Associate Provisions

We understand that yesterday Adam H. Greene (Office of the General Counsel, Civil Rights Division, U.S. Department of Health & Human Services), speaking at the ABA’s 11th Annual Conference on Emerging Issues in Healthcare Law, indicated that enforcement of the business associate provisions of the Health Information Technology for Economic and Clinical Health Act (the “HITECH Act”), which became effective on February 17, 2010, will be delayed until final rules addressing those provisions are published.  The HITECH Act’s business associate provisions require business associates to implement the information security safeguards specified by the HIPAA Security Rule, and comply with certain requirements of the HIPAA Privacy Rule.  Similarly, the HITECH Act requires covered entities to provide in their business associate agreements that all of the HITECH Act’s security requirements applicable to covered entities are also applicable to business associates.

The Office for Civil Rights (“OCR”), which enforces HIPAA’s Privacy and Security Rules, has stated publicly that it is carefully evaluating how to proceed with HIPAA enforcement.  For example, Section 13411 of the HITECH Act requires HHS to “provide for periodic audits to ensure that covered entities and business associates” are complying with the HITECH Act and its implementing regulations.  At the 18th Annual National HIPAA Summit in early February, Sue McAndrew, the OCR’s Deputy Director for Health Information Privacy, explained that there are “1,000 ways” to conduct HIPAA audits and that OCR is working with a HIPAA expert to “map out essentially the range of options” to determine how best to effectively conduct HIPAA audits.

Despite the delay in enforcement, covered entities and business associates should take necessary actions to comply with the HITECH Act’s requirements.  Please see our client alert on HITECH compliance for more information.

Privacy and Data Security Risks in Cloud Computing

Cloud computing raises complex legal issues related to privacy and information security.  As legislators and regulators around the world grapple with the privacy and data security implications of cloud computing, companies seeking to implement cloud-based solutions should closely monitor this rapidly evolving legal landscape for developments.  In an article published on February 3, 2010, Lisa Sotto, Bridget Treacy and Melinda McLellan explore U.S. and EU legal requirements applicable to data stored by cloud providers, and highlight some of the risks associated with the use of cloud computing.

Connecticut AG Files First HITECH Act Suit

In a lawsuit he described as “[s]adly . . . historic,” Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. for allegedly failing to secure private patient medical records and financial information involving hundreds of thousands of Connecticut enrollees and promptly notify consumers endangered by the security breach.  The case marks the first action by a state attorney general under the Health Information Technology for Economic and Clinical Health (“HITECH”) Act to enforce provisions of the Health Insurance Portability and Accountability Act (“HIPAA”).  The suit also alleges a violation of Connecticut’s breach notification statute.

The complaint, filed January 12, 2010, alleges that on or about May 14, 2009 Health Net learned that a portable disk drive had disappeared from one of its offices.  The disk contained unencrypted protected health information, social security numbers and bank account numbers for approximately 1.5 million past and present enrollees, including 446,000 Connecticut residents.  Health Net did not begin notifying affected individuals until November 2009.

On January 13, 2010, the Attorney General filed a motion for a preliminary injunction.  The proposed injunction mandates that Health Net and related defendants (i) comply with the privacy, security and other requirements of HIPAA; (ii) take corrective action and make “all efforts” to protect affected citizens against identity theft and other harm; and (iii) conduct “effective training of all members of their respective workforces (including independent contractors) on the policies and procedures with respect to protected health information, and personal information as defined under state law, regarding the requirements of federal and state law.”

Interim Final Rule Implements Increased Penalties for HIPAA Violations

The Department of Health and Human Services (“HHS”) released an interim final rule to incorporate the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) categories of violations and tiered civil penalty amounts.  The interim final rule is expected to be published in the Federal Register on October 30, 2009 and takes effect on November 30, 2009.  The rule applies to violations of the Health Insurance Portability and Accountability Act of 2003 (“HIPAA”) that occur on or after February 18, 2009.

The interim final rule amends HIPAA’s enforcement regulations.  Specifically, the rule incorporates the HITECH Act’s categories of violations, tiered ranges of civil penalty amounts, and revised limitations on the Secretary of HHS’s authority to impose civil penalties for violations of HIPAA's rules.  Pursuant to the interim final rule, covered entities may be subject to tiers of penalties as described below:

  • If a covered entity did not know and, by exercising reasonable diligence, would not have known that it was in violation, the minimum civil penalty is $100 per violation.
  • If a violation was the result of “reasonable cause” involving circumstances that would make it unreasonable for the covered entity (despite the exercise of ordinary business care and prudence) to comply, the minimum penalty is $1000 per violation.
  • The minimum penalty for a violation that is the result of willful neglect and subsequently corrected is $10,000.
  • The minimum penalty for a violation that is the result of willful neglect and is not corrected is $50,000.
  • The maximum penalty amount for multiple violations is set at $1.5 million per calendar year.

HHS will be accepting comments on the interim final rule until December 29, 2009.  Read our earlier blog posting for further information regarding the HITECH Act.

Access a copy of the interim final rule.

HHS Posts Breach Notice Reporting Form

The Department of Health and Human Services (“HHS”) has posted to its website a notification form that may be used to report breaches of unsecured protected health information to the agency.  Although some state agencies requiring notice of a breach employ a standard reporting form, the form issued by HHS has several unique features and requests more information than a typical breach reporting form.  Some interesting features of the form include:

  • The form may be used to report both breaches affecting 500 or more individuals, as well as breaches affecting fewer than 500 individuals, although the former must be notified to the agency within 60 days of discovery and the later need only be logged over the course of the year and reported to the agency on an annual basis.
  • The form requires that, if the breach occurred "at or by" a business associate, that business associate must be identified by name and contact information must be provided.  The form is, however, required to be completed by the covered entity.
  • The form requires a description of the breach and provides drop-down lists to facilitate the description of the type of breach (e.g., theft, loss, improper disposal, etc.), the location of the "breached information" (e.g., laptop, desktop computer, network server, etc.) and the type of PHI affected (e.g., demographic information, financial information, clinical information or "other").
  • The form further requests a description of the safeguards that were in place prior to the breach and a description of actions taken in response to the breach, again via selection from a drop-down list.  Actions taken in response to the breach also may be described in narrative form.
  • The form requires completion of an attestation that the information provided is accurate, and acknowledgement that the Office of Civil Rights ("OCR") may be required to release information provided via the form pursuant to the Freedom of Information Act, that some of the information will be posted to HHS's web site, and that OCR will use the information to provide an annual report to Congress, as required by the HITECH Act.
  • The form also may be used to submit an "initial breach report" or an "addendum to previous report," implying that covered entities could submit the form based on then-available information and later file an addendum, which may be necessary in some cases to avoid missing the 60-day reporting deadline.

The form, which is intended to be submitted electronically, includes all of the required elements specified by the HITECH Act and HHS's implementing regulations.  HHS also has provided instructions for completing the form.

Becoming HITECH: Actions Covered Entities and Business Associates Should Take Now to Comply with the Requirements of the HITECH Act

The Health Information Technology for Economic and Clinical Health Act (the “HITECH Act”), which was signed into law in February 2009 as part of the economic stimulus package, substantially impacts requirements imposed by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The HITECH Act creates several new and potentially burdensome obligations that affect the relationship between covered entities and business associates. Because these changes are quite substantial and necessitate revisions to existing business associate agreements (“BAAs”), covered entities and business associates should begin compliance efforts as soon as possible. Read more on actions to take to comply with the requirements of the HITECH Act.

FTC and HHS Issue Final Breach Notification Rules

On August 17, the Federal Trade Commission ("FTC") issued a final rule ("FTC Final Rule") addressing security breaches of personal health records ("PHRs").  The FTC Final Rule applies to all breaches discovered on or after September 24, 2009, and to “foreign and domestic vendors of personal health records, PHR related entities, and third party service providers” that “maintain information of U.S. citizens or residents.”  The FTC Final Rule does not apply to covered entities or business associates as defined under regulations promulgated pursuant to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").  Full compliance is required by February 22, 2010.

The FTC Final Rule requires PHR vendors and PHR related entities to notify U.S. citizens and residents if their PHR identifiable health information is subject to a security breach, and requires additional notification of the FTC and prominent media outlets for breaches that affect 500 or more individuals.  Third party service providers must notify the PHR vendor, or PHR related entities to which they provide services, of any breaches they discover.  To facilitate the notification process, the FTC has developed a standard form entitled “Notice of Breach of Health Information” that PHR vendors and PHR related entities can complete and send to the FTC.  Both the form and the FTC Final Rule are available on the FTC’s website.
 
On August 19, 2009, as required by the Health Information Technology for Economic and Clinical Health Act ("HITECH"), the Department of Health and Human Services ("HHS") issued an interim final rule ("HHS Interim Final Rule") addressing security breaches of unsecured protected health information ("PHI").  The regulations will apply to all breaches occurring on or after September 23, 2009 that are discovered by covered entities and business associates, but the HHS Interim Final Rule indicates that HHS will not impose sanctions for failure to notify with respect to breaches that are discovered within the first 180 days after the effective date. 

Notably, unlike the FTC Final Rule, the HHS Interim Final Rule includes a harm threshold limiting the breach notification requirement to breaches that present a significant risk of harm.  This disparity may be due to the fact that breaches common to HIPAA-covered entities, such as those involving disclosures to other HIPAA-covered entities, are less likely to result in actual harm than the kinds of breaches suffered by the service providers and vendors covered under the FTC's Final Rule.  Similar to the FTC Final Rule, the HHS Interim Final Rule requires covered entities to (1) notify individuals if their PHI is subject to a security breach, and (2) notify the Secretary of HHS and prominent media outlets in the event of a breach that affects 500 or more individuals.  Business associates must notify the covered entity to which they provide services of any breaches they discover.  Finally, the HHS Interim Final Rule updated the  information security guidance issued by HHS in April 2009 to emphasize encryption and destruction as the only methods for securing PHI in a manner consistent with the HITECH Act’s breach notification provisions.  The HHS Interim Final Rule is available on the HHS website.

HHS Issues Information Security Guidance Related to HITECH Act Breach Notice Obligations

On April 17, the U.S. Department of Health and Human Services ("HHS") issued proposed information security guidance, as required by the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act") passed as part of American Recovery and Reinvestment Act of 2009 on February 17.  The HITECH Act requires covered entities and business associates, as well as vendors of personal health records, to provide notice of information security breaches affecting “unsecured protected health information” or “unsecured personal health record information,” respectively.  The HITECH Act further requires the Secretary of HHS to specify technologies and methodologies that would render protected health information ("PHI") unusable, unreadable, or indecipherable to unauthorized individuals.  If covered entities, business associates and vendors of personal health records apply the technologies and methodologies specified in the guidance to protected health information, they will not be required to provide notice to affected individuals, HHS or the media, as otherwise required by the HITECH Act, in the event the information is breached.

Interestingly, the guidance specifies only two methods for securing PHI in a manner that would avoid the application of the HITECH Act’s breach notification provisions.  First, the guidance provides that PHI will be deemed unusable, unreadable or indecipherable if it has been encrypted, provided the encryption key has not also been breached.  In this regard, HHS has followed the lead of more than 45 state breach notification laws that likewise provide “safe harbors” for encrypted information.  HHS does, however, specify that encryption must comply with the HIPAA Security Rule’s provisions and further provides two specific examples of encryption that have been deemed to meet this standard: (1) for data at rest, encryption consistent with National Institute of Standards and Technology Special ("NIST") Publication 800-111 and; (2) for data in transit, encryption that complies with Federal Information Processing Standard 140-2. 

Second, the guidance provides that PHI will be deemed unusable, unreadable or indecipherable if media on which it is stored or recorded has been destroyed by one of the following methods: (1) paper, film or other hard copy media have been shredded or destroyed such that PHI cannot be read or reconstructed; and (2) electronic media have been cleared, purged or destroyed consistent with NIST Special Publication 800-88 such that PHI cannot be retrieved. 

The guidance is clear that its recitation of information safeguards, though a proposal pending public comment, is intended to be exhaustive.  The guidance, developed jointly by the Office for Civil Rights, Office of the National Coordinator for Health Information Technology, and Centers for Medicare and Medicaid Services, acknowledges that use of the technologies and methodologies described therein are not required but, if used, “create the functional equivalent of a safe harbor” with respect to the breach notification provision contained in the HITECH Act.  The guidance also notes that any other applicable requirements, such as mitigation requirements contained in the Privacy Rule and state breach notification laws, must be followed to the extent applicable, regardless of adherence to the guidance.

As above, this information security guidance relates to two sets of forthcoming breach notification regulations.  The first, applicable to covered entities and business associates, will be issued by HHS and the second, applicable to vendors of personal health records and certain other non-HIPAA covered entities, was issued by the Federal Trade Commission in proposed form on April 16.

Public comments on the HHS information security guidance are due by May 21, 2009.  HHS has specifically signaled interest in receiving comments regarding whether limited data sets of PHI should be considered, by definition, to render PHI unusable, unreadable or indecipherable such that the HITECH Act’s breach notification provisions would not apply. 

In addition to the guidance, HHS also issued a request for information soliciting public comment on the breach notification provisions of the HITECH Act to inform its future rulemaking and its annual updates to the guidance.  The guidance is available here  and both the guidance and the request for information are available here.