Skip to Main Content

Publications

Enhanced HIPAA Privacy and Security Provisions under The HITECH Act and Its Interim Final Rule


While much of the media interest in the stimulus package enacted by Congress in January of this year and signed by the President in February focused on appropriations, the American Reinvestment and Recovery Act of 2009 (“ARRA”) has amplified the Health Insurance Portability and Accountability Act (“HIPAA”) privacy requirements for healthcare providers and business associates. ARRA includes the Health Information Technology for Economic and Clinical Health Act (“HITECH” or the “Act”). On August 24, 2009, the U.S. Department of Health and Human Services issued its Interim Final Rule (“IFR”) implementing the requirements of the Act. Healthcare providers and their business associates now need to know the new duties and obligations that HITECH and the IFR impose. While some provisions of the IFR will become effective over time, many of the regulations are effective as of September 23, 2009.

THE PUSH TO AN EMR FUTURE – A CARROT AND STICK APPROACH

Policy makers believe that the implementation of electronic medical records is one of the keys to improving the quality of, and access to, healthcare, while reducing its overall costs. Significant federal funds will be allocated to healthcare providers to encourage them to adopt standards and technologies for electronic medical records (“EMR”). The Act outlines how federal funds will be used to create a nationwide health information infrastructure and reflects Congress’ desire to promote an electronic exchange of healthcare information. Indeed, the Act provides incentive payments to healthcare providers who adopt EMR.

At the same time, through the enactment of the Act’s “Subtitle D-Privacy,” Congress also has demonstrated its concern with the ease with which personal health information can be transmitted, and as a result has enhanced the privacy and security protections found in HIPAA. Part I of HITECH “affects and improves” the privacy and security provisions of HIPAA. As explained below, the Act requires covered entities and, significantly, their business associates, to comply with a detailed method of providing notice in the event of a breach of unsecured personal health information. The Act’s carrot is the potential for the receipt of federal monies to implement EMR commencing in 2010 and running to 2015. The Act’s stick is, in part, to subject business associates to the same civil and criminal penalties as covered entities. Moreover, the Act includes sections designed to “improve enforcement” and to establish a system of audits.

The Department of Health and Human Services (“DHHS”) will issue annual guidance on appropriate technical safe-guards to implement EMR. The benefit of this regulatory development is that covered entities and their business associates now know that encryption of electronic protected health information (“PHI”) is expected, and that it will need to be implemented in the relatively near future.

THE INTERIM FINAL RULE, EFFECTIVE SEPTEMBER 23, 2009

The requirements of the Act and the IFR present both covered entities and business associates with new obligations. Because business associates now are subject to the same requirements as covered entities for purposes of HIPAA compliance, business associates will want to insure that their security measures for protecting unsecured and non-de-identified personal health information are robust.1 As a result, covered entities and their business associates should review their current business associate agreements to reflect the changes required by the Act and the IFR.

SIGNIFICANT PROVISIONS OF THE HITECH ACT

Accounting of personal health information.

Under the HIPAA Privacy Rule (45 CFR, §164.528), individuals have a right to receive an accounting of disclosures of personal health information, except for disclosures to carry out treatment, payment and healthcare operations.

The Act now excludes from this exception Electronic Health Records (“EHR”). Thus, if an individual requests an accounting of disclosures, the covered entities, and now their business associates, must produce for the individual EHRs used in treatment, in payment plans, and in healthcare operations.

This change in the law has the potential to make compliance with patients’ requests for accountings of disclosures more difficult and time consuming as EMRs become more prevalent, despite the Act’s limitation of the reach of an accounting request to three (3) years prior to the date of a request. In addition, and in keeping with the thrust of requiring business associates to monitor actively their use and disclosure of PHI, business associates also must provide an accounting to an individual if requested directly. The good news is that time is on the side of healthcare providers and business associates, this change is effective January 2014 for EHRs created prior to January 1, 2009, and is effective January 1, 2011 for EHRs acquired after January 1, 2009.

Access to information in electronic format. Individuals now have a right to obtain from a covered entity any information that is contained in electronic format, and fees charged may not be higher than the covered entity’s labor costs in responding to a request for a copy, summary, or explanation of the information.2

Marketing. The Act also addresses marketing communications. Covered entities previously could rely upon an authorization from an individual for the use of that individual’s PHI in marketing efforts resulting in direct or indirect payments to the covered entities. Now, any further exchange of any protected health information of that person is prohibited unless the individual has provided authorization that specifies whether the PHI may be further exchanged for future remuneration. DHHS will promulgate rules allowing individuals to opt out of marketing communications that contain or rely upon protected health information.

Vendors. The Act imposes new requirements upon vendors of PHI. Vendors of PHI that have discovered a breach must notify both affected individuals and the Federal Trade Commission upon the discovery of a disclosure or use of unsecured PHI. The Act provides penalties for “willful neglect” on vendors for failure to perform the mandatory notification.3

Enforcement and audits. In an effort to encourage future compliance, the Act contains provisions regarding “improved enforcement” and audits. The Act requires DHHS to investigate formally a complaint of a violation of the privacy standards if a preliminary investigation of the complaint demonstrates a possible violation due to “willful neglect.” Congress has charged DHHS with promulgation of regulations with regard to these amendments, as well as conducting periodic audits of covered entities and business associates to measure compliance with the requirements of HITECH.

THE HITECH ACT INTERIM FINAL RULE – NEW OBLIGATIONS

In understanding the IFR’s approach to disclosure, it is useful to recognize the definitions used in the Act as well as the Interim Final Rule. The Act defines “breach” as an “unauthorized acquisition, access, use or disclosure of PHI which compromises the security or privacy of such information…”4 “Unsecured PHI” is defined as PHI “that is not secured through the use of a technology or methodology” by the Secretary of the DHHS.5 The rule defines “a compromise of security” of PHI as a “significant risk of financial, reputational, or other harm to an individual.”6 If a breach has indeed occurred, then the covered entity must provide proper notice as outlined in the IFR.

Risk assessment. In the preamble to the IFR, DHHS states that in order to know whether an impermissible use or disclosure of PHI constitutes a breach, covered entities and business associates will need to perform a risk assessment to determine if there is a significant risk of harm to the individual as a result of the impermissable use or disclosure. As a result, covered entities and business associates will need to consider a number or combination of factors in determining and performing this risk assessment.

Some factors to consider in such a risk assessment would be who impermissibly used or disclosed the information, and to whom was the information impermissibly disclosed. If, for example, a laptop computer is stolen, and contains unsecured PHI, and is then later returned prior to access, a forensic analysis may demonstrate that the information regarding the PHI has not been opened, altered or transferred. The breach, involving the disclosure of unsecured PHI may not therefore pose a significant risk of economic or reputational harm.7

Covered entities and business associates should consider the type and amount of PHI involved in a breach. A violation of a privacy rule may not necessarily constitute a significant risk of financial or reputational harm that amounts to a breach requiring notification. All risk assessments will be fact specific, and covered entities and business associates must analyze the information for purposes of evaluating the economic, as well as reputational and personal, harm to the individual or individuals.

The risk assessment is crucial because if the covered entity or business associate determines that there is no “significant risk” of harm to the individual then no breach has occurred and no notification under the Act and the IFR is required. Of course, both covered entities and business associates have the burden of demonstrating that no breach has occurred if the use or disclosure poses a significant risk of harm to an individual.

The IFR exceptions to a “breach.” The IFR contains three exceptions to a breach. First, an unintentional acquisition, access or use of PHI by a “workforce member,” a term now used by DHHS in place of “employee,” if made in good faith, and within the course and scope of his or her employment and with no further use or disclosure, is an exception to a “breach.” If a billing employee, for instance, receives and opens an e-mail containing PHI which a nurse has mistakenly sent to the billing employee, such disclosure would fall under the exception. By contrast, a receptionist who accesses the PHI concerning an acquaintance’s treatment would not have acted in good faith.

The second exception arises if a person, authorized to access PHI under either a covered entity or business associate, inadvertently discloses PHI to another person with the same authorization at the same covered entity or business associate. The “same facility” can involve multiple locations and this exception would apply to a workforce member who has made a disclosure to a physician with staff purchases but at a different facility.8

The third regulatory exception to a breach involves disclosure of PHI by a covered entity or business associate who in good faith believed that the unauthorized person, to whom the disclosure was made, would not be able to retain the PHI. This exception could be applicable, for instance, in the case of a nurse handing a discharged patient papers belonging to a different patient which are then returned immediately. Under all of these exceptions, a covered entity or business associate must document why an impermissible use or disclosure falls under the specific exception.

Guidance if a breach has occurred. The preamble to the IFR suggests the following steps that a covered entity or business associate should take if a breach has occurred

  • The covered entity or business associate must determine whether there has been an impermissible use or disclosure of PHI under the privacy rule.
  • The covered entity or business associate must determine, and document, whether the impermissible use or disclosure compromises the security of the PHI. This is done by asking whether a significant use or disclosure poses a significant risk of financial, reputational, or other harm to the individual.
  • The covered entity or business associate must then determine whether the incident falls under an exception to the definition of “breach.”

THE NEW NOTIFICATION REGULATIONS IN CASE OF BREACH OF UNSECURED PHI

After conducting a risk assessment, and determining that indeed there has been a “breach” as defined, a covered entity must notify each individual whose unsecured PHI has been, or is reasonably believed by the covered entity to have been accessed, acquired, used, or disclosed as a result of such breach.9 Breaches are treated as “discovered” by the covered entity as of the first day that the breach is known or, by exercising reasonable diligence, would have been known, to the covered entity. If a breach is known to a workforce member or agent of the covered agent of the entity, the covered entity is deemed to have knowledge of the breach.

Covered entities and business associates must implement reasonable systems for discovery of breaches, and must train workforce members and other agencies to timely report privacy and security incidents. A reasonable system may involve the creation of a specific protocol under which it is clear who will decide if a breach has occurred, who will investigate the incident, who will document the actions taken in response, and who will craft and deliver the message to the media, if necessary.

Timeliness of notification. DHHS expects covered entities and business associates to make individual notifications “as soon as reasonably possible,” but in no case later than sixty (60) calendar days. Covered entities are permitted to provide required notification information in multiple mailings. Business associates must notify the covered entity of the discovery of the breach of unsecured PHI pursuant to the same deadlines. In addition to providing identification of those individuals whose unsecured PHI has been, or is reasonably believed to have been, used or disclosed, the business associate should also provide any other available information that it has which would be required in a notification provided by the covered entity. Both covered entities and business associates will need to update their business associate agreements to comply with this requirement.

Notification requirements – content of notification. The IFR sets forth the specific information required in notification of a breach. The required information includes:

  • a brief description of what happened, including the date of the breach and date of discovery;
  • a description of the types of unsecured PHI involved;
  • the steps individuals should take to protect themselves from potential harm resulting from the breach;
  • a brief description of what the covered entity is doing to investigate the breach, to mitigate any further harm, and to protect against further breaches; and
  • contact procedures for individuals which must include a toll free number.

In addition, notification may also include recommendations regarding contacting credit card companies or credit bureaus and information concerning steps that the covered entity is taking to retrieve the information. The notification must be in “plain language” and understandable by the party to whom the notification is sent. The covered entity, therefore, is required to comply with Title VI of the Civil Rights Act and Section 504 of the Americans with Disabilities Rights Act in providing notice.

Notification to the media and DHHS. If the covered entity or business associate experiences a breach of ensecured PHI involving more than five hundred (500) residents of a state or jurisdiction, the covered entity must promptly notify “prominent media outlets” serving the state or jurisdiction. The preamble to the IFR notes that a prominent media outlet in one jurisdiction may be different than another, and each covered entity will want to review its own circumstances for media notice.10 In addition, for breaches involving five hundred or more individuals, the Act requires covered entities to notify DHHS immediately. For breaches of less than five hundred individuals in one year, the IFR also mandates that covered entities log breaches during the year and that annual notification to DHHS be provided.11

“SAFE HARBOR” THROUGH ADOPTION OF TECHNOLOGIES & METHODOLOGIES

In a proposed rule issued in April of this year, and through the recent IFR, DHHS has issued guidance with regard to the technologies and methodologies that a covered entity should employ if it wishes to avail itself of a “safe harbor” with regard to PHI. If the covered entity employs the specific technologies and methodologies that are specified in DHHS’ guidance, the notification as outlined above is not required if there is a “breach.” The technologies and methodologies must result in making PHI unusable, unreadable, or indecipherable to unauthorized individuals, and therefore such protected health information is not considered “unsecured” and notification would not be required upon disclosure.12

Significantly, DHHS has termed its chosen methodologies “exhaustive” and as a result no others will allow safe harbor protection. In essence, two general methodologies are permitted. One is encryption; DHHS has provided that the encryption of PHI is a method by which the safe harbor may be attained. In addition, DHHS has also listed destruction, with no chance of reconstruction, as a second method to attain the safe harbor. The encryption technologies and methodologies are technical, and should be reviewed with IT personnel; for instance, DHHS recognizes that different types of encryption technology exist for “data at rest” and “data in motion.”

Notwithstanding the safe harbor, covered entities and now business associates still must comply with the remainder of the HIPAA privacy and security rules. This includes conducting a risk analysis within their organizations, and implementing reasonable and appropriate physical, administrative and technical safeguards.

Incentive payments and future guidance. Congress has budgeted entitlement funds for the adoption of technology of approximately Thirty-Four Billion Dollars, and appropriated funds of about Two Billion Dollars for health information technology grants and loans. Providers who can demonstrate and prove they are, or can become, “meaningful users” of electronic health records are eligible for such funds. DHHS is currently evaluating the definition of “meaningful use.” ARRA established the Health Information Technology Policy Committee (“HITPC”), and this Committee has issued a preliminary definition of the “meaningful use” of an EHR as enabling “significant and measurable improvements in population health through a transformed healthcare delivery system.” The Centers for Medicaid and Medicare have linked meaningful use to achieving measurable outcomes in patient engagement, care coordination, and population health.13 The goals are clear, but the manner in which these goals are measured will be important.

The incentive payments are to begin in 2011 and will be phased out in 2015. By 2015, providers are expected to utilize EHR and comply with the “meaningful use definition” or be subject to financial penalties under Medicare.

DHHS plans to establish, through its “Health Information Technology Extension Program,” regional centers which will provde technical assistance to healthcare providers in adopting EHR. For hospitals, DHHS expects incentives under Medicare to be available by October, 2010. DHHS will publish future rules for hospitals concerning the criteria that must be met in order to qualify for EHR incentive payments. Healthcare providers, including hospitals and others, will want to pay attention to future information concerning incentive payments.

CONCLUSION

Covered entities and business associates should review their business associate agreements and update them where needed to reflect the new requirements of the HITECH Act and the Interim Final Rule. In addition, covered entities will want to review their HIPAA privacy and security policies in light of these requirements.


 

[1] 45 CFR, Part 160 and part 164 (the Interim Final Rule is found in 74 Fed. Reg. 162)

[2] Title XIII Subtitle-D, Section 13404(c)

[3] Title XIII Subtitle-D, Section 13410

[4] Title XIII, Subtitle-D, §13400(1)

[5] Title XIII, Subtitle-D, §13402(h)

[6] 45 CFR, §164.402

[7] 74 Fed. Reg. 43744

[8] Preamble, Vol. 74. Fed. Reg. 162, p. 42744

[9] 45 CFR, §164.404

[10] 74 Fed. Reg. 42752

[11] 45 CFR, §164.408

[12] 74 Fed. Reg. 42740, Guidance Issue April 27, 2009 and updated August 24, 2009

[13] See, “Meaningful Use: The De