HMGT 372 DISC3
CHAPTER
327
HEALTH INFORMATION MANAGEMENT
D iscussions of health information today almost always begin with a mention of the Health Insurance
Portability and Accountability Act of 1996 (HIPAA).1 HIPAA was originally intended to protect health coverage for employees who change or lose their jobs, but despite its name, it did not actually provide for “portability” of health insurance. Instead, it prohibited a new employer’s health plan from excluding workers or charging them higher premiums because of preexisting conditions, but it did so only under lim- ited circumstances.
There were so many loopholes and exceptions to the law that many consumers received little benefit from it. Thus the lasting legacy of HIPAA does not relate to insurance coverage at all—either portable or
9 After reading this chapter, you will
• understand that maintaining accurate and complete health records serves many purposes, the most important of which is to aid in clinical decision-making;
• know that health information is highly confidential but must be disclosed in many situations;
• appreciate that all healthcare personnel must be familiar with federal and state privacy laws;
• see that the Health Insurance Portability and Accountability Act privacy standards overlie, but generally do not replace, other confidentiality laws; and
• understand that serious criminal and civil penalties can be assessed for breaches of information security and confidentiality.
Quality information is essential to all aspects of today’s healthcare system. [Health infor- mation management] has the body of knowl- edge and practice that ensure the availability of health information to facilitate real-time healthcare delivery and critical health-related decision making for multiple purposes across diverse organizations, settings, and disciplines.
—AmericAn HeAltH informAtion
mAnAgement AssociAtion, AnnuAl
report 4 (2014)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
C o p y r i g h t 2 0 2 0 . H e a l t h A d m i n i s t r a t i o n P r e s s .
A l l r i g h t s r e s e r v e d . M a y n o t b e r e p r o d u c e d i n a n y f o r m w i t h o u t p e r m i s s i o n f r o m t h e p u b l i s h e r , e x c e p t f a i r u s e s p e r m i t t e d u n d e r U . S . o r a p p l i c a b l e c o p y r i g h t l a w .
EBSCO Publishing : eBook Collection (EBSCOhost) - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS AN: 2361947 ; Stuart Showalter.; The Law of Healthcare Administration, Ninth Edition Account: s4264928.main.eds
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n328
otherwise—but to regulations meant to improve the security of electronic health transactions (read: billing) and protect the privacy of health informa- tion.2 These were published by the Department of Health and Human Ser- vices after Congress was unable to agree on its own version of federal privacy and security standards.
HIPAA defines health information as
any information, whether oral or recorded in any form or medium, that—
(A) is created or received by a health care provider, health plan, public health
authority, employer, life insurer, school or university, or health care
clearinghouse; and
(B) relates to the past, present, or future physical or mental health or condition
of an individual; or the past, present, or future payment for the provision of
health care to an individual.3 [Emphasis added.]
This broad definition covers any information related to the provision of or payment for healthcare. It includes demographics, insurance coverage, medical history, clinical findings, test results, medical images, procedures performed, and so forth. It also includes information not directly related to health—such as the names of a patient’s children, her favorite food, the kind of car she drives, or the high school she attended—if somehow relevant to her healthcare situation.
Health information has been preserved on paper for centuries, but today patient records consist of more than traditional medical charts in color-tabbed folders. For example, they may include photographic and radiographic images (film, digital, holographic); computer and internet files (e.g., stored in “the cloud” or on hard drives, CDs, flash drives, other media); and sound recordings (e.g., dictation)—all of which may be accessed and perhaps downloaded via a desktop, laptop, or mobile device. In short, the record of care includes all data and information in any format that are “gathered about a patient from the moment he or she enters the hospital [or doctor’s office] to the moment of discharge or transfer.”4
Health information is maintained primarily to facilitate continuity of care, but it is also needed for accurate coding and billing, documentation of medical necessity, ethical decision-making, protection of patients’ and providers’ legal interests, public health and research, peer review and quality assurance, medical education, accreditation and licensure, and myriad other purposes. Because health information is used in many ways and by many organizations, HIPAA defines two other terms critical to its application: covered entity and protected health information.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 329
Covered Entity, Protected Health Information, and De-identification
A covered entity is any healthcare provider, health insurance plan, or billing company. Protected health information (PHI) is identifying information collected or used by a covered entity. PHI does not include information contained in education or employment records or information that has been “de-identified.”5 Eighteen indicators must be scrubbed from PHI before it can be considered de-identified, including names; small geographic areas; dates related to the individual (e.g., dates of birth and death); phone and fax numbers; mail and email addresses; URLs; identifying numbers (e.g., Social Security numbers, health record numbers); and photographs, fingerprints, and similar images. In short, PHI consists of data containing enough details that would make it easy to track or identify a person, their family and rela- tives, or their associates; if such identifiers have been removed or the informa- tion has been aggregated or encrypted, it does not amount to PHI.
Form and Content of Records
In most states, the form and content of records are dictated by the statutes, rules, and regulations of the licensing agencies. These directives date back to the time records were kept on paper and often merely require that an “ade- quate” or “complete” record be maintained. A few statutes specify categories of information that must be included but leave other details to the administra- tive rule. For example, the Florida statute requires that a hospital must use a
system of problem-oriented medical records for its patients, which system shall
include the following elements: basic client data collection; a listing of the
patient’s problems; the initial plan with diagnostic and therapeutic orders as
appropriate for each problem identified; and progress notes, including a discharge
summary. The [state licensing] agency shall, by rule, establish criteria for such
problem-oriented medical record systems in order to ensure comparability among
facilities and to facilitate the compilation of statewide statistics.6
The agency’s implementing regulation then lists two dozen specific items that must be included in every inpatient record, including, for example, the chief complaint or reason for seeking care, personal and family medical history, reports of physical examinations, lab and imaging reports, consul- tation reports, specific treatments given, and documentation of informed consent. There are additional requirements for patients undergoing invasive procedures and for ambulatory care patients.7 In short, the Florida regulatory
covered entity A health plan, healthcare clearinghouse, or healthcare provider that transmits any health information in electronic form.
protected health information (PHI) Any health-related information that identifies or can be used to identify the individual to whom it pertains.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n330
scheme is detailed about the contents of a medical record, and it must be followed. Health information management (HIM) professionals must ensure that medical records comply with the applicable requirements.
Some states’ licensure regulations explicitly authorize an electronic health record (EHR) system, as long as it contains the required content. In theory, a computerized record eliminates handwritten or printed documents, improves accuracy, and saves time and money. The American Recovery and Reinvestment Act of 2009,8 the Affordable Care Act, and the Health Information Technol- ogy for Economic and Clinical Health Act (HITECH, discussed later in this chapter) encourage the widespread adoption of EHRs. The EHR concept raises issues of confidentiality, durability, and compliance with licensure requirements, and as always there is some resistance to change, but healthcare is clearly headed in that direction. Where the law has not kept pace with this technological prog- ress, the advice of legal counsel and state associations should be sought.
The Joint Commission has standards for health records9 and may revoke an organization’s accreditation for failure to comply with its terms. Noncompli- ance also could be presented as evidence of negligence if such failure was a cause of injury.10 The federal government set similar standards in its Medicare Con- ditions of Participation (COP).11 In addition, state laws require hospitals and physicians to maintain certain information and report it to public authorities for statistical purposes. These requirements are discussed later in this chapter.
Record entries must be “authenticated”; that is, they must be dated and signed or otherwise verified by the person making the entry. This nota- tion can be done by electronic signatures, written signatures or initials, rubber stamp signature, or computer key. If rubber stamp or electronic signatures are used, the individual identified by the stamp or electronic authentication must be the only individual who uses it.12
A hospital health record is complete when it contains the patient’s medical history; admitting diagnosis; consultations and test results; compli- cations; informed consent; physician orders, nursing notes, and medication records; discharge summary (clinical resume) with provisions for follow-up care; and final diagnosis—all within 30 days following discharge. HIM poli- cies must require that attending physicians keep their records current and complete them in a reasonable time (typically, no more than 30 days) after a patient’s discharge; disciplinary measures should be prescribed for physicians who do not comply with these requirements.
Failure to maintain complete, accurate, and legible records can have severe adverse effects in civil litigation (see Legal Decision Point). For example, a nurse’s failure to record observations of a patient’s condition is evidence of possible negligence for a jury to consider. Health records are used as evidence in malpractice suits—in fact, they are often the most important “witness” in such cases—so the absence of standard entries or the inclusion of inaccurate information often leads to a verdict for the plaintiff.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 331
Legal Decision Point
Consider the following report:
1. What does the first entry on 4/1 say? 2. A nurse added “clarification: clear liquids when awake” to the report, and an auditor wrote
“handwriting problem” in the margin. If an entry is illegible, can the document containing the entry be considered accurate and complete?
3. What are some ways to improve the quality of this physician’s records?
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n332
Inaccurate information must be corrected as soon as it is discovered. Erasure or obliteration of medical information, even if inaccurate, should not be permitted (see Law in Action). Instead, if the error is in a paper record the person making the change should
• carefully draw a line through the error, leaving the original writing legible;
• describe the reason for the change; • date the corrected entry; and • authenticate it in the same manner as any other entry.
Entries in an electronic record are part of the permanent record and cannot be changed, thus corrections of errors in an EHR system must be made by an addendum. As in paper records, the addendum should detail the reasons for the new information and should be dated and authenticated in the same manner as other entries. The organization must have a policy outlining these procedures.13
The wisdom of following this practice of careful correction is illus- trated by a Connecticut case involving a psychiatric patient who had been left unattended in a locked room and was later “found in the room with her head wedged between the side rail and the mattress of her bed, unconscious, with
no pulse, blood pressure, or respiratory function.” A few days later, on the orders of the director of nursing,
the original record was surreptitiously removed
from the chart and a “revised” record was sub-
stituted without the knowledge of the hospital
administration and in violation of explicit hos-
pital policy. The substituted record was demon-
strably false and conflicted with other records
and the testimony of staff members on duty
that morning as to their actual observations.
The revised record came to light after suit was
commenced when a nurse not connected with
the psychiatric unit brought to the attention of
the hospital administration that she had been
forced to rewrite a note on the original record.
The trial court instructed the jury without objec-
tion that they could consider the substitution
of the records as a circumstance indicating the
defendant’s consciousness of negligence.14
Law in Action
A physician left written orders that his patient be given a saline solution of “.3 NS.” The attending nurse overlooked the decimal point and gave the patient a solution that was ten times the intended concentration. Believing he was not at fault, the physician tried to clarify his original order by trac- ing over it in pen to read:
This “clarification” only compounded the problem and looked like a cover-up. The jury returned a verdict in favor of the plaintiffs.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 333
A verdict against the hospital in the amount of $3.6 million was upheld on appeal.
The adverse implications of an incomplete health record were demon- strated in Carr v. St. Paul Fire and Marine Insurance Company.15 The patient came to the hospital’s emergency department (ED) complaining of severe abdominal pains and vomiting but was examined only by a licensed practical nurse and two orderlies. The court noted that the nurse and one of the order- lies had been “sweethearts” and later married and that all three were “close friends.” (The relevance of these facts becomes apparent later.) One of the orderlies took the patient’s vital signs, but the hospital was unable to contact the patient’s doctor, who was out of town. The patient left, saying he would return when his doctor returned. The patient died later that evening after returning to the hospital by ambulance in even greater distress. The death certificate opined that the decedent had suffered a heart attack.
Witnesses at the trial testified that the patient’s vital signs were “nor- mal” during the first visit, but the three ED personnel and possibly the physician who completed the death certificate were the only ones who had ever viewed the record of the visit. The friendship among the three ED staff becomes relevant at this point: Someone destroyed the record that night after the patient died.
In the resulting lawsuit, the jury was allowed to infer that the docu- ments probably revealed a medical emergency necessitating attendance by a physician. The court stated:
No one knows the effect [destruction of the records] had on the jury, but the jury
certainly had a right to infer that the record had it been retained would have shown
that a medical emergency existed and that a doctor should have been called and
that more attention should have been given him than was given.16
As this case shows, the best witness in malpractice litigation is often a thor- ough and complete health record. In many cases, such records are convinc- ing evidence that the patient received reasonable care under all the facts and circumstances. An incomplete or missing record may spell disaster for the defense.
Although clinical records should be comprehensive, incident reports— forms used to document unusual occurrences—are not meant to be part of the health record and should not be included. They are prepared in anticipa- tion of possible litigation and for the hospital’s attorneys to use. If they are included in the health record, they will be available as evidence in a lawsuit. In most states, incident reports are considered privileged, not subject to dis- covery, and not admissible.
The incident report process is conducted for educational purposes and to improve standards of patient care and general safety. The reports
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n334
can be completed by anyone with knowl- edge of the facts of an event, but they are most often written by clinical personnel regarding incidents involving patient care. Incident reports need to be written with candor; they should contain only objective facts, not judgments or accusations. Staff cannot be forthright if they are apprehen- sive that the reports will be available to potential malpractice plaintiffs, so those preparing the documents must be assured of the reports’ confidentiality.
Treatment is increasingly episodic in today’s fragmented and special- ized healthcare world. It can be delivered by different providers, at discrete points in time, and recorded in different EHR systems. On the surface it would seem a simple task for EHR systems to share information with each other—a process known as “interoperability”—but as it turns out, that is easier said than done. Organizational policies or contract terms can prevent sharing. The EHR technologies may be nonstandard or incompatible—that is, they lack interoperability—or vendors or providers may actually take will- ful actions that impede the flow of health information. Such actions amount to “information blocking,” a practice prohibited by federal law and punish- able by civil monetary penalties.
Other causes of mismatched patient records include incorrect patient identification at registration, time pressures during treatment, insufficient training of personnel, use of templates and copy/paste functions in the EHR, and simple human errors. Whatever the cause, it is not uncommon for a clinician to have an incomplete or inaccurate picture of a patient’s medi- cal history and condition because the record and the patient do not match. Obviously, the failure to match patients to their proper records can result in medical errors, increased costs, and a negative patient experience (see Types of Patient Matching Errors).
Records Retention
Hospital policies regarding retention of health records depend on local law and the standards of professional care appropriate to the type of institution involved. Governing bodies must not only be familiar with applicable legal requirements regarding the length of time that records must be preserved but also analyze their particular medical and administrative needs. For example, to enable epidemiological studies (or for other pedagogic reasons), teaching hos- pitals and research institutions may wish to retain records longer than typical
Types of Patient Matching Errors
Patient matching errors are of two types. A “false negative” (an error in which a record is not linked to the patient to whom it belongs) can occur in a single facility or when multiple provider organiza- tions are involved. A “false positive,” on the other hand, involves records that contain information relating to another person entirely. Either error presents clear liability issues.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 335
acute care hospitals do. All institutions need to retain records long enough to facilitate continuing programs of peer review and quality assurance.
The law on record retention varies widely, and from state to state, on such matters as the length of time records must be kept and whether alterna- tive media (e.g., microfilming, electronic formats) may substitute for records that were originally kept on paper. Medicare’s COP require that records be maintained for at least five years,17 but many states specify longer periods. Formats other than paper are permitted unless explicitly proscribed, and some items (e.g., nurses’ notes, original X-ray films) may be destroyed sooner than others. To complicate matters, a state’s statutes of limitation must be considered. Traditionally, the limitation period for torts did not begin to run against a minor until she reached the age of majority. (If the limitation period were two years and the age of majority were 21, a newborn could file suit a day short of her twenty-third birthday and still have a valid claim.) Many states have changed this common-law rule. Florida, for example, provides:
In no event shall the action be commenced later than 4 years from the date of the
incident or occurrence out of which the cause of action accrued, except that this
4-year period shall not bar an action brought on behalf of a minor on or before the
child’s eighth birthday.18
In summary, the length of time patients’ clinical records are retained and those records’ format are determined by standards of professional practice, the operational and medical needs of the particular organization, and local law in each state. Institutional policies on these questions must be carefully developed and periodically reviewed with legal counsel. Private organizations such as The Joint Commission and the American Hospital Association (AHA) also have published statements of policy on retention and destruction of records. The current policy statement of the AHA rec- ommends that records be retained for at least ten years. As more and more electronic records are created where paper records would have existed before, storage logistics becomes simpler and retention periods can be extended. Some organizations are now archiving their EHRs permanently.
Access to Health Information Ownership and Control of Records State law generally provides that healthcare providers (e.g., physicians, hos- pitals) own and have physical possession and control of health records.19 Neither patients nor authorized representatives have a right to physical pos- session of the original health records, and The Joint Commission flatly states, “Original medical records are not released unless the hospital is responding to law and regulation.”20
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n336
Ownership and the right to control do not prohibit patients and inter- ested third parties from accessing health records. Patients have a right to view and copy their records, have copies sent to any new physician of their choice, and appoint authorized representatives (e.g., their attorneys) to examine the documents. One exception may be cases in which disclosure of information might adversely affect a patient’s physical or mental health.21 In such situa- tions, attending physicians may have the authority to deny patients access to their records.
The estates of deceased physicians and physicians who retire from practice, relocate, or are otherwise unavailable are obligated to notify their former patients and make copies of the records available.22 Hence, in a New York case, the court invalidated a provision in a deceased physician’s will that his executor burn all his professional records.23 Physicians are also required to transfer a health record (or copies of it) to a former patient’s new physician when the patient so requests.
The Patient’s Right to Access Under the Health Insurance Portability and Accountability Act The long-held paternalistic belief that health records are not to be read by the patient is no longer valid. HIPAA and state laws codify patients’ right to the information in their health records. HIPAA gives patients the right to exam- ine and obtain copies of their records and request correction of any errors.24 The request may be denied only for good cause, such as if
• disclosure of the information would be likely to endanger the life or physical safety of the patient or another person;
• the information is contained in psychotherapy notes; or • it was compiled for use in a civil, criminal, or administrative
proceeding.
HIM departments usually have a contract agency whose full-time job it is to copy health records and release the information pursuant to patients’ requests. This function is often referred to as release of information (ROI); at most hospitals, the ROI function becomes, in effect, a department of its own within HIM because of the number of subpoenas and other requests for copies.
HIPAA also gives patients greater control over the use of their health information. For example, a signed authorization must be obtained from the patient before health information can be used for marketing or fundrais- ing purposes. Under HIPAA, patients have a right to obtain a listing (also known as accounting) of purposes for which their health information was disclosed other than for treatment, payment, or routine healthcare operations
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 337
(e.g., peer review, quality assurance) or at their own request. Accordingly, healthcare facilities and physicians must keep account of health information disclosures to the following entities, among others:
• Accrediting agencies such as The Joint Commission • State oversight agencies • Public health organizations • Law enforcement agencies • Funeral directors • Tumor registries
The accounting must indicate the date of the disclosure, the name of the recipient, the information disclosed, and the purpose of the disclosure.25
HIPAA does not replace state law protections, and before HIPAA was passed many states already had laws providing for access—but HIPAA does trump any state law that conflicts with its provisions. Thus, for example, HIPAA would nullify a state statute that gave a right of access to a broader class of persons or that would allow records to be released only to other physicians and not to the patients themselves (see The Court Decides: Opis Management Resources, LLC v. Secretary at the end of this chapter).
Many state statutes do not address the right of minor patients to obtain information from their health records or their parents’ right to that information. HIPAA defers to state law regarding parents’ right to access their children’s records, and it would seem that mature minors who can consent for treatment without parental consent should be permitted to access their own records. Emancipated minors are treated as adults in such matters.
In the past, physicians and hospitals routinely refused to allow patients access to their health records. Three rationales were often asserted: (1) records are technical and not understood by laypersons; (2) revelation of the information might adversely affect the patient’s or another’s life, health, or physical safety; or (3) the privacy of third parties (by which they usually meant healthcare personnel) should be protected. The first and third reasons are no longer supportable under HIPAA. The second reason remains valid because HIPAA allows physicians to deny patients access to their own records if the information would endanger the life or physical safety of the patient or another person. For example, a person such as a friend or family member who reports domestic violence may fear retaliation by the abuser. In that case, the patient may be denied access if allowing them to see the records would be likely to reveal the source of the information. (Note, however, that a deci- sion to deny access on these grounds may be reviewable, thus expert advice is recommended.)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n338
HIPAA was passed more than 20 years ago, and hospitals and physi- cians have since reevaluated their policies. Today, health records are available to anyone whom the patient authorizes to receive them. Reasonable safe- guards have been instituted to protect healthcare information from unau- thorized use and disclosure. Although patients cannot arbitrarily be denied access, hospitals should know how to handle such requests. Especially impor- tant are the moral and legal duties of the hospital or physician to ensure that patients’ authorization of third parties is current and genuine. Healthcare personnel must be sensitive to the validity and authenticity of documents that purport to be a patient’s authorization to release information.26
Release of Information Without Patient Consent Confidentiality is governed by both state and federal laws. Accordingly, both HIPAA’s privacy regulations and state law must be consulted to determine reliable answers to the questions that continually arise about the release of medical information.
Disclosure of personal information does not offend the US Constitu- tion.27 Although the US Supreme Court has recognized an individual’s con- stitutional right to make certain personal decisions without interference by the government or other third parties,28 no federal constitutional provision prohibits the release of health information. As discussed in the next section, in many situations, third parties have a legitimate interest in and a legal right to medical information regarding a particular patient. In those cases, release of health information without the patient’s consent is permitted and, indeed, sometimes required.
Court Orders and Subpoenas A valid court order directing that health records be made available to a third party must be honored, and the patient’s consent is not required. Generally, the legal process for obtaining health record information is through a sub- poena duces tecum—a request that a witness bring specified documents to a court or other tribunal that has jurisdiction over pending litigation.
Under most states’ procedural rules, during the litigation process, attorneys may themselves issue subpoenas for records relating to the other party using blank forms provided by the court. The lawyer for the defendant in a malpractice suit, for example, routinely subpoenas all the plaintiff ’s health records from other healthcare providers to have the case evaluated by a medical expert. Under HIPAA’s privacy standards, if an attorney’s sub- poena is not accompanied by a court order (i.e., an order signed by a judge or equivalent judicial official), a healthcare provider may release the patient’s records only if (1) a patient authorization accompanies the subpoena or (2) the party issuing the subpoena has made a reasonable effort to give the
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 339
patient notice of the request. If in doubt, the record owner may petition the court for a determination of whether the records must be turned over. (Hos- pital HIM/ROI departments are usually facile with these requirements and should be consulted. In fact, in most health systems all subpoenas are referred to the HIM department for action.)
Statutory Reports Certain state and federal statutes require or permit hospitals and medical personnel to report health information to public authorities. The types of information reported include vital statistics (deaths, births, fetal deaths), abortions, communicable and infectious diseases, injuries that may be the result of criminal acts, drug abuse, and child or elder abuse or neglect. These reporting requirements are permissible as a legitimate exercise of the govern- ment’s power to provide for the general welfare.29 The disclosures must be “accounted for” (as noted earlier) under HIPAA.
The reporting requirements differ somewhat from state to state, so detailing all the requirements here is not possible. However, healthcare pro- viders must be familiar with the law of their particular jurisdictions because failure to report to the appropriate public authorities may lead to civil liability or criminal penalties.
Duty to Warn Third Parties In addition to statutory reporting obligations, providers have a common-law duty to warn third parties of foreseeable risks of harm. HIPAA permits such disclosure when the healthcare provider believes it “is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public” and is made to someone who is able to prevent or lessen the threat.30
In a California case with a tragic outcome, a male student was receiv- ing voluntary outpatient psychiatric treatment at a university hospital. Several hospital psychotherapists were aware that he had threatened to kill a par- ticular individual. One of the psychologists felt the student should be com- mitted and asked the campus police to detain him, which they did; he was later released, however, when the chief of psychiatry reviewed and reversed the order for detention. Two months later, the student killed his intended victim.
A trial court dismissed the victim’s parents’ lawsuit, holding that the psychotherapists and the university had no duty to warn the victim. However, the California Supreme Court reversed and remanded the case for trial. The high court felt that, under the circumstances, members of a jury might rea- sonably conclude that they had a duty to disclose the foreseeable dangers the patient posed (see The Court Decides: Tarasoff v. Regents of the University of California at the end of this chapter).
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n340
The Tarasoff doctrine is limited to situations in which the provider knows the patient is a serious or imminent threat to a readily identifiable victim. One justice noted this limitation in a separate opinion:
I concur in the result in this instance only because the complaints allege that
defendant therapists did in fact predict that [the patient] would kill and were there-
fore negligent in failing to warn of that danger. Thus the issue here is very narrow:
we are not concerned with whether the therapists, pursuant to the standards of
their profession, “should have” predicted potential violence; they allegedly did so
in actuality. Under these limited circumstances I agree that a cause of action can
be stated.31
Because the ability to predict dangerousness has been seriously ques- tioned over the years (see Legal Brief), providers are usually held to have no duty to warn of a person’s generalized threats to unspecified individuals. For example, in a case interpreting Tarasoff, the California Supreme Court held that the government had no duty to warn the community or the police that a juve- nile delinquent released from governmental custody to the home of his mother had exhibited violent tendencies toward young children. In the absence of an imminent risk to an identifiable victim, the juvenile’s criminal act that caused the death of a five-year-old was not foreseeable, and no liability was imposed.32
The duty to warn third parties strikes a balance between an individual’s right to confidentiality and a third person’s right to know that a risk exists. The imminence and probability of the risks and the identification of the prob-
able victim must be carefully considered to justify the conclusion that the third person’s interests are paramount to the confidentiality of health information.33 As a practical matter, the professional who must balance these interests is in the unenviable position of having to predict violent behavior despite medical science’s inability to forecast self-injury or injury to others accurately (see discussion of involuntary detention or commitment in chapter 2).
The existence and extent of a defendant’s duty is a question of law for the court to determine. If a duty exists, whether it was breached and whether the breach was the proximate cause of injury are questions of fact for a jury. Thus, foreseeability is a question for the jury,
Legal Brief
An internet search using such key words as predicting dangerousness will result in myriad results demonstrating the controversial nature of the assumption that such predictions are reli- able. One source flatly states, “In reality, no one can predict future dangerousness precisely and with absolute certainty” (R. T. M. Phillips, Predicting the Risk of Future Dangerousness, AMA JournAl of Ethics [published June 2012], at https://journalofethics.ama-assn.org/article/ predicting-risk-future-dangerousness/2012-06).
For this reason, trial judges and opposing counsel will likely scrutinize rigorously any opin- ion of dangerousness so as not to prejudice the individual against whom it is asserted.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 341
and reluctance to send this question to the jury may be the reason some jurisdictions have rejected the Tarasoff rule in favor of the physician–patient privilege.34 Even California declined to apply the principle in a case in which a psychiatrist was allegedly aware of a patient’s suicidal tendencies and failed to restrain the patient or warn the parents.35 The court held that Tarasoff’s duty to warn applies only when the risk to be prevented is the danger of violent assault, not when the risk is suicide. When the patient is in danger of self- inflicted harm, the proper course would seem to be involuntary commitment.
Peer Review Statutes As discussed more fully in chapter 8, peer review is a type of quality assurance process. Under federal regulations, peer review organizations have the right to access patient records and other information.36 The information must be held in confidence and must not be disclosed, except as authorized by law— for example, as aggregate data that do not identify an individual patient or healthcare provider. The HIPAA privacy regulations recognize and permit compliance with these statutes.
Lien Statutes A third party’s legal right to receive medical information regarding a par- ticular patient is further enforced by hospital lien statutes, which exist in approximately one-third of states. The lien laws grant healthcare providers a legal claim under which the cost of hospitalization is paid from damages that a patient recovers from the person or entity whose civil wrong necessitated the patient’s treatment. In these cases, the tortfeasor is entitled to access the patient’s health information—without patient authorization—to assess the legitimacy of the medical bills.
Liability for Unauthorized Disclosure The Hippocratic Oath requires physicians to hold inviolate and confidential all infor- mation entrusted to them by their patients (see Legal Brief). This ethical obligation may be incorporated in state regulations governing the licensure of physicians and healthcare institutions, and its violation may be a cause for revoking or suspending a license. Whether violation of licensure regulations creates a civil cause of action for damages is a different issue. Clearly, the HIPAA privacy regulations set a standard of care for confidentiality irrespective of other state laws.
Legal Brief
What I may see or hear in the course of the treat- ment or even outside of the treatment in regard to the life of men, which on no account one must spread abroad, I will keep to myself, holding such things shameful to be spoken about.
—The Hippocratic Oath, translation by Ludwig Edelstein (thE hippocrAtic
oAth, tExt, trAnslAtion And intErprEtAtion [Johns Hopkins Press, 1943])
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n342
No doctrine of confidential or privileged communication between patient and physician or patient and institution existed in early common law. It recognized privileged communications in only three relationships: attorney–client, husband–wife, and clergy–penitent. However, most states now have statutes that cover the doctor–patient relationship as well. Although the details of these statutes differ, they essentially codify the Hippocratic Oath. These statutes do not always apply to out-of-court disclosures; they often apply only to disclosures made in the course of judicial or quasi-judicial proceedings. Furthermore, they may not apply to institutional providers. Thus, a plaintiff often must base cases involving breach of confidence on tort or contract principles or on specific statutes such as HIPAA.
Legal action may be brought for at least three types of infringement: defamation of character, invasion of privacy, or breach of an implied contract to respect confidentiality. The first two violations are discussed in the follow- ing sections; breach of an implied contract is addressed in chapter 5.
Defamation As stated in chapter 5, defamation is a written or verbal communication to a third party of information that diminishes the esteem, respect, or confidence with which a living person is regarded by exciting adverse or derogatory feelings against that person.37 Written defamation is libel, while spoken defa- mation is slander. In either event, to be considered defamatory the com- munication must be made (published) to someone other than the aggrieved party. For example, in Farris v. Tvedten, a physician’s dictated letter addressed personally to a nurse that suggested the nurse may have committed a crime by administering a substitute for a prescribed medicine did not constitute libel because no third party received the communication.38
Successful defamation suits for release of information from a health record are uncommon. Even in the absence of a legitimate motive for pub- lishing the information, the truth of a published statement is a complete defense to a defamation charge.39 Even if the statement is not true, evidence of a proper motive or a reasonable belief that the statement is true generally provides a partial defense that may mitigate damages.
In addition, the law has long recognized two privileges that may afford a defense even when a defamatory statement is made. The first is absolute privilege, which attaches to judicial and administrative proceedings. In one case, for example, when a hospital honored a court-ordered subpoena and released a health record that indicated the plaintiff was under the influence of alcohol, the release was privileged and defamation was not proved. Whether the record was false had no bearing on the case.40
The second is qualified privilege, which concerns information rea- sonably believed to be true and published with a proper motive in mind. Information may be communicated in good faith to protect or advance the
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 343
legitimate interests of the publisher or to protect someone else’s interests. For example, in a New York case, the name of a frequent visitor to a hospital’s ED was placed on a list of persons suspected of being drug abusers. The court held that the communications were protected by qualified privilege because hospital personnel had a duty to communicate their opinions to other staff.41
Whether the information was reasonably believed to be true and pub- lished in good faith is a question of fact for the jury. If the publication was motivated by spite or ill will (malice in fact), the publisher may be liable for punitive and compensatory damages. Because most hospitals and physicians do not recklessly disregard the truth or publish information they know to be false, they are unlikely to be held liable for malice in fact.
Examples of qualified privilege predate HIPAA by many years. Even if a disclosure of information could be justified under traditional defamation law, the HIPAA privacy standards may provide other theories on which plain- tiffs could premise recovery.
Invasion of Privacy Invasion of privacy was recognized as a tort following the publication in 1890 of a famous Harvard Law Review article coauthored by future US Supreme Court Justice Louis D. Brandeis. Brandeis and his law partner, Samuel War- ren, asserted that privacy is a common-law right—“the more general right of the individual to be let alone.”42 In general terms, it is the right to be free from unwarranted publicity, and to live without unwarranted interference by the public in matters with which the public is not necessarily concerned. A tortious invasion of the right is the unwarranted appropriation or exploitation of one’s personality; the publicizing of one’s private affairs with which the public has no legitimate concern; or the wrongful intrusion into one’s private activities in such a manner as to cause outrage, mental suffering, shame, or humiliation to a person of ordinary sensibilities.43
Most courts recognize the tort, but some have imposed limitations to discourage unwarranted litigation and to strike a proper balance between privacy and free speech. A few states have recognized the right of privacy by enacting statutes that carefully set limitations to the cause of action. In con- trast to actions based on the law of defamation, the truth of an unwarranted publication is not necessarily a defense to a suit alleging invasion of privacy. On the other hand, express consent to the publication is a defense.
To succeed in an action for invasion of privacy, the plaintiff does not have to prove monetary loss; damages can be awarded for mental suffering. The right is personal to the individual; the privacy of a deceased person can- not be invaded, so in most cases surviving relatives have no cause of action when the alleged tort occurs after the person’s death.44 Similarly, in contrast to defamation, the “privacy” of a corporation or partnership cannot be invaded; other legal principles, such as copyright and trademark, are used to
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n344
protect a business entity from unwarranted appropriation of its name.45 Cases involving invasion of privacy may include the following:
• Unauthorized commercial appropriation of the plaintiff ’s name, personality, professional skills, or photograph
• Use of the plaintiff ’s name or likeness for the defendant’s own purposes, even if the use was not commercial and the defendant did not benefit financially from it
• Physical intrusion into someone’s private affairs • Disclosure of private information to those who have no legitimate need
to know it
Photography and Observation The Pennsylvania case of Clayman v. Bernstein is an early example of unau- thorized use (appropriation) of a patient’s likeness for innocent but ulterior purposes.46 A physician had photographed the plaintiff ’s facial disfigurement for use in education, but because the patient had not agreed to be photo- graphed, the court found in her favor and prohibited the use of the photos.
More recently, a plastic surgeon was sued for using recognizable before- and-after photos of his patient on television and in a promotion titled “Cream Versus Plastic Surgery” at Garfinckel’s department store.47 Patient consent was an issue in the case; if the patient did give consent, she did not do so in writing. The jury returned sizable verdicts against the surgeon and the department store. Although photos may be taken for inclusion in a patient’s health record, these kinds of cases demonstrate that the patient must give written consent. Most healthcare providers have standard consent forms for this purpose.
Providers may be held liable on the basis of any of the principles just discussed for using photography without patient consent or in a manner that does not accord with professional standards of medical practice. Today, the risk is exacerbated by smartphones’ photo and video capabilities. Provider organizations need to have clear policies about the use of cell phones and similar devices to photograph patients, and physicians in particular need to be continually reminded that they are subject to HIPAA and other privacy laws.
The issues are similar to those that arise when unauthorized visitors are allowed to observe during surgery or medical examinations; such practices are invasions of the patient’s privacy if permitted without consent. Teaching hos- pitals especially should make clear in the general consent form patients sign at admission that medical students may accompany treating physicians and that the opportunity to observe is an integral part of the students’ education.
In cases alleging invasion of privacy, the courts must balance conflict- ing public policy values: “the right of the individual to be let alone” versus the public’s “right to know.” The right to be let alone diminishes as one’s
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 345
fame or notoriety increases, as demonstrated by the case about the autopsy photos of NASCAR driver Dale Earnhardt, who was killed in a crash at the Daytona Motor Speedway in 2001.
Like those of any accident victim in Florida, Earnhardt’s autopsy records were subject to the state’s public records laws, and the autopsy report and certain other items were promptly made available to the public. The autopsy photographs, however, were not. When news organizations tried to obtain copies of the photos, the Earnhardt family objected. The Florida legislature quickly passed an amendment to the public records laws that shielded autopsy photos from disclosure (see Legal Decision Point). The media challenged the law. In ruling that the law is constitutional and that the records (the photographs) must not be released, the court looked into “the seriousness of the intrusion into the family’s right to privacy.”
The medical examiner testified that the photographs were “gruesome, grisly and highly disturbing,” and the physician attending Mr. Earnhardt after the accident confirmed this. The trial court found that such publication would
be an indecent, outrageous, and intolerable invasion, and would cause deep and
serious emotional pain, embarrassment, humiliation and sadness to Dale Earnhardt’s
surviving family members. It is evident from our review of the record that the publi-
cation of the nude and dissected body of Mr. Earnhardt would cause his wife and
children pain and sorrow beyond the poor power of our ability to express in words.48
Release of medical information to persons who have a legitimate interest in the information does not ordinarily constitute an invasion of the patient’s privacy, even absent an explicit consent to do so.49 Individuals and orga- nizations with a legitimate interest include patients’ attorneys, insurance carriers, various government agencies, bona fide research personnel, and family members (in some circumstances, but especially if they are or will be participating in the patient’s care and the patient does not object).50 As mentioned earlier, HIPAA permits release of information for treat- ment, payment, and healthcare operations (e.g., quality assurance, peer review) and to healthcare oversight agencies. It permits disclosure to a friend or family member if the patient agrees or, if the patient is unable to consent, if disclosure is in the
Legal Decision Point
In its statute protecting autopsy photographs, the Florida legislature noted, “the existence of the World Wide Web and the proliferation of personal computers throughout the world encourages and promotes the wide dissemination of photographs and video and audio recordings 24 hours a day and that widespread unauthorized dissemination of autopsy photographs and video and audio recordings would subject the immediate family of the deceased to continuous injury” (Campus Communications, Inc. v. Earnhardt, 821 So. 2d 388, 393 [Fla. App. 2002]). Do you think current legal standards regarding these kinds of privacy issues are sufficient?
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n346
patient’s best interests. Persons who consent to publicity or who place them- selves in the public eye through their activities and exploits (e.g., musicians, actors, politicians) implicitly waive their rights of privacy to the extent that the public has a legitimate interest in newsworthy events.51 This principle also applies to persons who are not public figures but who are temporarily in the public eye. Unless news stories and photographs exceed the bounds of ordinary decent conduct, persons cannot complain when, for example, the press reports an accident or a crime they are involved in or when they figure in any other newsworthy event, as long as the publicity is not misleading or the facts are not misrepresented.
Publication of information acknowledging an individual’s admission to a hospital, naming the physician, and describing the patient’s medical condition in general terms (e.g., “good,” “fair,” “critical”) usually presents no legal risk of liability for invasion of privacy unless the patient objects.52 If the mere fact of the patient’s admission could reveal the presence of a condi- tion thought to be shameful or humiliating, however—as might occur, for example, when the institution in question is known to treat only substance abusers, sex offenders, or those with mental illness—the provider could be held liable for announcing the admission, at least if the patient is not a public figure. Furthermore, irrespective of the kind of facility, HIPAA has provi- sions allowing the patient to request that no information about their care be released, including the fact that they have been admitted.53
State and Federal Confidentiality Laws Physicians and hospital personnel must be familiar with state and federal statutes and regulations that create a positive duty not to release medical information in certain circumstances. HIPAA was mentioned earlier, and state and federal laws provide for “superconfidentiality” of substance abuse, HIV and AIDS, and mental health records. For example, New York’s men- tal hygiene law prohibits state mental institutions from making case records available, except as provided by law; violation of this state statute created civil liability to a patient when a hospital director released the record to an adverse attorney.54
Illinois has comprehensive legislation that grants mental health patients or their parents or guardians a right of access to mental health records. It applies principles of confidentiality to all services related to mental health or developmental disability that are furnished by physicians, psychiatrists, psychologists, social workers, and nurses in the community at large.55 The personal notes of a therapist are part of the accessible record, and no information can be disclosed without written consent of the patient, parent, or guardian except to professional colleagues, peer review commit- tees, and institutions having legal custody of the patient. Furthermore, the
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 347
statute includes detailed provisions on testimonial disclosures in judicial and quasi-judicial proceedings. Violation of these provisions is a criminal and civil offense; the patient can sue for an injunction and may also seek damages, including recovery of attorneys’ fees.
Federal laws such as the Comprehensive Drug Abuse Prevention and Control Act of 1970;56 the Drug Abuse Office and Treatment Act of 1972;57 and the Comprehensive Alcohol Abuse and Alcoholism Prevention, Treat- ment, and Rehabilitation Act Amendments of 198358 impose stringent con- fidentiality of records of patients receiving treatment for drug dependency and alcoholism under programs supported by federal funds. Underlying these rules is the principle that confidentiality encourages patients to seek help for drug and alcohol abuse and psychiatric problems.
The legislation applies to all federally assisted healthcare providers whether the assistance is research on the abuse of drugs or alcohol or through Medicare, Medicaid, or other governmental payment programs. Together, the statutes and attendant regulations provide that medical information is to be disclosed only to those connected with the program.59 Family members, law enforcement officials, and courts have no access except as specifically pro- vided, unless the patient has given express written consent to the disclosure.
Disclosures without a patient’s consent can be made only to personnel in drug or alcohol programs who have a legitimate need to know, to other providers (to the extent necessary to meet a bona fide medical emergency), to organizations conducting research and evaluations (as long as patients are not identified), or on court order based on good cause.60 These patients may not be identified in any civil, criminal, or administrative procedure, and informa- tion cannot be released to law enforcement officials without a court order. Normal civil or criminal proceedings and their usual subpoena processes do not justify breach of a substance abuse or mental health patient’s right to confidentiality. Hospital and medical personnel, therefore, must develop poli- cies to prohibit release of all medical information concerning these patients without a court order.
Courts have ordered release of information in proceedings to revoke criminal probation, in cases of child neglect, and for investigation by the Internal Revenue Service (IRS).61 In one criminal proceeding to determine a person’s potential for rehabilitation, good cause for a disclo- sure was not established when the credibility of a witness was in ques- tion.62 A New York court protected the confidentiality of photographs that had been taken in the waiting room of a methadone treatment clinic and were later sought by law enforcement officials investigating a mur- der.63 A judicial in camera (Latin phrase meaning “in chamber”) review is often necessary to establish good cause and to determine what portion of the record may be released.
in camera In secret; privately (from Latin camera: room, chamber).
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n348
HIPAA Standards, the HITECH Act, and the Red Flags Rule HIPAA permeates health records law, and no one section of a textbook can do justice to the issues it presents (see Legal Brief). Until this point, there- fore, this text has considered HIPAA’s effects only as they might illuminate the general privacy concerns that have existed since Hippocrates. The fol- lowing discussion examines HIPAA standards significant to this chapter, in particular those that
• give patients more control over their PHI than they had previously, • set limits on the use and disclosure of PHI, and • hold violators accountable for breaches through enhanced civil and
criminal penalties.
Uses and Disclosures of Personal Health Information HIPAA requires health providers and health plans to provide patients with a notice of privacy practices that explains how patients’ PHI will be maintained and used. Patients have the right to prevent some uses of their PHI (e.g., marketing, research, fundraising), but PHI may be used and disclosed for treatment and payment purposes and for routine healthcare operations (e.g., for care management, peer review). If the patient does not object, her name, location, and general condition may be listed in the facility directory. PHI may also be disclosed to friends and family members involved in the patient’s care.
Disclosure of PHI is permitted for the following purposes:
• Required by law • To report abuse, neglect, and domestic violence
• For healthcare oversight activities • As evidence in judicial and
administrative proceedings • To aid law enforcement investigation • For coroners, medical examiners, and
funeral directors • For organ, eye, and tissue donation • For certain research • To avert a serious threat to health or
safety • For certain governmental functions,
such as national security • For workers’ compensation claims
Legal Brief
HIPAA is a massive statute of which only one part addresses the privacy of health information. In this chapter we are concerned primarily with those provi- sions that deal with privacy issues and their imple- menting regulations. (As is usually the case, the regulations are more detailed than the law itself.)
The website http://hhs.gov/hipaa/ provides detailed information for individuals and health- care professionals about HIPAA rules, individuals’ rights, compliance guidance, FAQs, and more.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 349
Regardless of whether the disclosure is permitted by law or authorized by the patient, the organization must “limit the protected health information disclosed to the information reasonably necessary to achieve the purpose for which the disclosure is sought.”64 Disclosures that are not permitted by the foregoing cannot be made without the patient’s (or legal representative’s) written authorization.
HIPAA preempts state laws that provide less protection or grant the patient fewer rights of access. Each state’s laws need to be analyzed to determine whether any of its provisions are preempted. In 2002, the Florida Hospital Association convened a committee of attorneys and compliance officers to review more than 200 laws and regulations of that state that affect the privacy of health information. The committee found several provisions that conflict with HIPAA. For example, one section of the Florida mental health law provides that patients have a right to access their records unless the physician determines that release would be “harmful to the patient,”65 whereas the HIPAA regulations state that access may be denied only if it would endanger the patient’s “life or physical safety.”66 As the Florida statute allows a physician to deny access because of potential emotional harm—not only danger to the patient’s life or physical safety—the statute is contrary to HIPAA and is preempted.67
In the few cases challenging HIPAA’s privacy rules, the courts have upheld the regulations. For example, in South Carolina Medical Association v. Thompson, a federal court ruled that Congress had not unconstitutionally delegated its legislative power to the executive branch by giving the secretary of the US Department of Health and Human Services (HHS) broad rule- making authority:
Because Congress laid out an intelligible principle in HIPAA to guide agency action,
we reject appellants’ claim that the statute impermissibly delegates the legislative
function. We also conclude that regulations promulgated pursuant to HIPAA are
not beyond the scope of the congressional grant of authority, and that neither the
statute nor the regulations are impermissibly vague.68
Privacy Breaches and the Health Information Technology for Economic and Clinical Health Act Although the HIPAA standards have been part of the regulatory landscape since 1996, privacy breaches continue to occur. Recognizing the need for greater vigilance, in 2009 Congress passed the Health Information Technol- ogy for Economic and Clinical Health (HITECH) Act to help clamp down on the problem. The law sharply increased the administrative penalties that can be imposed on violators—to as much as $50,000 per violation—and included criminal penalties of fines and prison time of up to ten years.69 If a
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n350
breach of unsecured PHI affects 500 or more individuals, a covered entity must notify the secretary of HHS of the breach no later than 60 calendar days from the discovery of the breach, and the details are posted on the HHS website (see Legal Brief).
In addition to increasing the penalties for HIPAA breaches, the HITECH Act included the following changes:
• Business associates are required to notify their affiliated covered entities of breaches of which they become aware.
• Covered entities are required to notify all affected individuals of unauthorized disclosure of their PHI as soon as reasonably possible.
• HIPAA rules extend directly to a covered entity’s business associates who have access to PHI.
• An individual’s right to obtain an accounting of disclosures is expanded.
• The standards for using PHI for marketing and fundraising purposes are different.
• State attorneys general have a new enforcement authority.
• Review of HIPAA-related policies and training programs; business associate agreements; and physical, technical, and administrative safeguards is required.
• “Meaningful use” objectives for electronic health records are established; the achievement of these objectives qualifies providers for financial bonuses.
Medical Identity Theft and the Red Flags Rule One other significant issue regarding access to health information is identity theft. Accord- ing to the Federal Trade Commission,
medical identity theft happens when a person
seeks health care using someone else’s name
or insurance information. A survey conducted
by the Federal Trade Commission (FTC) found
that close to [450,000 persons each year] have
Legal Brief
The number of privacy breaches has grown steadily, and millions of individuals have been affected. In 2014, for example, the HHS Office for Civil Rights received 277 reports of breaches involving 500 or more individuals. In 2015, 2016, and 2017 the numbers were 289, 344, and 385, respectively. The 2014 breaches affected more than 21 million people; that number was up from slightly more than 8 million individuals the year before. The five-year cumulative total (2010– 2014) for large breaches was more than 41 mil- lion. By way of comparison, the three-year total for 2015–2017 came to more than 132 million. The types of breaches include theft or loss of laptops and other devices, loss of paper records, improper disposal, unauthorized access by health- care personnel, and hacking of network servers.
—HHS Office for Civil Rights, 2013–2014 rEport to congrEss on thE BrEAch notificAtion progrAM,
and 2015, 2016, and 2017 rEport to congrEss on BrEAchEs of unsEcurEd protEctEd hEAlth inforMAtion
(accessed August 27, 2019), at https://www. hhs.gov/sites/default/files/breach-report-to-
congress-2015-2016-2017.pdf.
business associates Outside persons or organizations that use protected health information while providing services on behalf of a “covered entity” (a healthcare organization); business associate functions include billing, claims processing, utilization review, and so on.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 351
experienced some form of medical identity theft. Victims may find their benefits
exhausted or face potentially life-threatening consequences due to inaccuracies
in their medical records. The cost to health care providers—left with unpaid bills
racked up by scam artists—can be staggering, too.70
To address this problem, the FTC and a number of other federal agencies published the Red Flags Rule, a requirement that certain organi- zations adopt a written identity theft prevention program.71 Authority for the rule was grounded in the Fair and Accurate Credit Transactions Act of 2003 (FACTA),72 which applies to financial institutions and creditors and is aimed primarily at theft of individuals’ financial information. However, the agencies interpreted FACTA’s term creditor to include healthcare providers who allow patients to make installment payments. The American Medical Association and other provider groups felt the requirements were unneces- sarily burdensome, costly, and complex, and as a result Congress amended FACTA to exempt healthcare providers from the identity theft rules.73
Notwithstanding this development, providers must be alert for the warning signs of medical identity theft. Given the public’s expectation of privacy protections—and bolstered by HIPAA, the HITECH Act, and other privacy and security standards—the spirit of the Red Flags Rule is likely to become the standard of care in identity theft cases.
The following red flags are some of the warning signs of medical identity theft:
• Identification documents appear to have been altered or forged. • A photograph or the physical description of the patient on file is
inconsistent with the appearance of the person presenting for care. • Identifying information is inconsistent with information already on file
(e.g., Social Security number does not match). • Identifying information is associated with known or suspected
fraudulent activity (e.g., address is fictitious or a mail drop; phone number is a pager or an answering service).
• Address or telephone number is the same as that submitted by numerous other patients.
• Mail to the account address is returned despite ongoing patient visits. • The person fails to provide all requested identifying information. • When questioned, the person is unable to provide authenticating
information beyond that generally available from a wallet or consumer report.74
Healthcare providers should adopt some form of identity theft preven- tion program to address the red flags they might encounter. The program
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n352
should be tailored to the provider’s setting (e.g., physician practice, hospital), and all staff who open patient accounts, handle billing operations, or otherwise deal with patient information must be trained to spot the warning signs (see Legal Brief). Ideally, the program should be approved by the governing board (or at least senior management) and monitored for effective- ness. Identity theft thus becomes another responsibility of the compliance depart- ment (see chapter 15).
Confidentiality and Other Issues in Telemedicine The healthcare field is becoming more comfortable with providing clinical services through telemedicine (aka “telehealth” or “e-health”; see Legal Brief). Use of tele- communication technology can improve access to care and clinical outcomes, and thus it presents significant benefit to both the clinician and the patient. However,
telemedicine also carries with it certain legal issues and, as is often the case, the legal system lags behind technological developments.
HIPAA’s privacy and security standards, including liability for breaches, clearly apply to telemedicine services—thus the security of the online network used for an e-health encounter must be ensured. While providing health
services at a distance improves access to care for patients in remote areas or in an emergency, it also raises malpractice issues for the provider and questions about liabil- ity insurance coverage. These problems may not be specific to telemedicine, but a heightened regard for thorough documen- tation is warranted.
Whether a telehealth “visit” is cov- ered by the patient’s health insurance may also be an issue. Medicare covers telehealth encounters on a limited basis only, Med- icaid reimbursement varies from state to state, and private health plans also vary
Legal Brief
Healthcare organizations’ records are subject not only to medical identity theft but to other criminal activity as well. In 2013, the payroll accounts of a public hospital in Leavenworth, Washington, were hacked to the tune of $1.03 million by cyberthieves based in Ukraine and Russia. The thieves used “money mules”—individuals who are duped into being conduits for the transactions—to transfer the money. Once the theft was reported, the unwit- ting accomplices’ personal accounts were frozen, leaving them with nothing but embarrassment and the hassle of explaining their involvement to the authorities. Nearly half a million dollars of the public hospital’s money was “gone for good,” according to news reports.
—Jefferson Robbins, At Least 46 Percent of Hospital’s Hacked Money Gone for Good
(published June 19, 2013), at http://www. wenatcheeworld.com/news/2013/jun/03/
at-least-40-percent-ofhospitals-hackedmoney/
Legal Brief
Although some states’ definitions vary, Medicare regulations consider telemedicine to involve “mul- timedia communications equipment that includes, at a minimum, audio and video equipment permit- ting two-way, real-time interactive communication between the patient and distant site physician or practitioner” (42 C.F.R. § 410.78[a][3]). The definition excludes telephone calls and use of fax machines or email.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 353
widely. The practitioner must take these differences into account to avoid possible liability for false claims.
When the clinician and patient are not in the same jurisdiction, questions arise as to which state’s medical records and licensure laws apply. Restrictive laws in some states may require a practitioner to obtain a license when delivering care across state lines. If a physician serves patients in sev- eral states—or if those patients travel frequently or regularly spend a portion of the year in another location—must the physician be licensed in multiple states, pay multiple licensure fees, and meet the regulatory requirements of each locale? Will a pharmacy in a different state honor a telemedicine physi- cian’s prescriptions, especially for controlled substances? May a hospital rely on the credentialing and privileging decisions of the physician’s “home” hos- pital, or must he also obtain privileges and credentials at the distant facility? If the former, is there written documentation of those decisions? How will the distant hospital conduct peer review of the telemedicine practitioner?
Myriad other issues, too numerous to discuss at length here, surround telemedicine technologies. For example, multiple regulatory agencies—the Food and Drug Administration, Federal Communications Commission, Fed- eral Trade Commission, and Office of the National Coordinator for Health Information, to name a few—have jurisdiction over some aspect of mobile medical applications and devices that are involved in telemedicine. These agencies’ regulations often conflict or overlap with one another. Telemedi- cine is a growing field that presents many legal issues but many opportunities as well.
Use of Health Records in Legal Proceedings
As mentioned earlier (under the heading Liability for Unauthorized Disclo- sure), common law formerly did not recognize a physician–patient privilege. Today most states have a statute on testimonial privilege that prohibits the physician (and perhaps other clinical personnel) from testifying about state- ments made by the patient in the course of the doctor–patient relationship unless the patient waives the privilege. The purpose of the privilege is to encourage candid communication between doctor and patient and thus pro- mote the quality of care.
A typical privilege statute reads as follows:
Except as otherwise provided by law, a person duly authorized to practice medi-
cine or surgery shall not disclose any information that the person has acquired in
attending a patient in a professional character, if the information was necessary to
enable the person to prescribe for the patient as a physician, or to do any act for
the patient as a surgeon. If the patient brings an action against any defendant to
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n354
recover for any personal injuries, or for any malpractice, and the patient produces
a physician as a witness in the patient’s own behalf who has treated the patient
for the injury or for any disease or condition for which the malpractice is alleged,
the patient shall be considered to have waived the privilege provided in this sec-
tion as to another physician who has treated the patient for the injuries, disease,
or condition.75
As the previously discussed statute recognizes, parties in a lawsuit are deemed to have waived the testimonial privilege by putting their medical conditions at issue. Their records are admissible at trial, and their physicians are allowed to testify. The health information of someone who is not a party to the litigation is not usually admissible in evidence, however. The testi- monial privilege protects the confidentiality of those persons and prohibits their physicians from testifying. The privilege statutes also apply to pretrial proceedings and to investigations conducted by state legislative bodies.
When a privilege does not apply, health records are admissible as evi- dence under one or more of the exceptions to the hearsay rule. The hearsay rule prohibits secondhand evidence, and although health records are techni- cally hearsay, they are considered reliable and are admissible if their authentic- ity is properly established.76 Some jurisdictions allow records to be admitted into evidence only when the person who entered the information in the chart is not available to testify in person. In any event, the parties to the litigation often attest to the records’ authenticity and agree that they may be used.
The fundamental purpose of litigation is to determine the truth and achieve justice for the parties. Information collected and maintained in the regular course of a patient’s care presumably helps establish the truth. Because physicians, nurses, and hospitals do not ordinarily falsify health infor- mation, courts can be reasonably confident that the health record accurately reports the facts of the case. In addition, records are usually more reliable than personal recollections. Witnesses are often forgetful or may not be avail- able to testify in person. Furthermore, many people may have made entries on the record. Even in the rare case they are all available, testimony by each person involved would be time-consuming and expensive. To exclude health records from evidence because they are hearsay would defeat the legitimate goals of the judicial process.
Federal Government’s Access to Personal Health Information
Under HIPAA, government agencies have access to PHI for healthcare oversight and other legitimate purposes. Even before HIPAA was passed, however, the Federal Rules of Evidence gave the courts broad discretion
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 355
to determine when to grant access. For example, in one case, the IRS was allowed to obtain the health records of a deceased person to deter- mine whether gifts of property given during the patient’s lifetime were made in “contemplation of death” and thus subject to the federal estate tax.77 In another case, the IRS obtained the surgical records of a physi- cian who had failed to file tax returns.78 In yet another case, the National Institute of Occupational Safety and Health was allowed to subpoena employees’ health records maintained under the Occupational Safety and Health Act.79 In none of these situations did the respective state’s privileged communication statute apply to protect the confidentiality of the records.
In a case widely publicized in 1983, HHS sought the records of a severely disabled newborn (Baby Jane Doe). The government contended that the parents’ refusal to consent to surgery for spina bifida, hydrocephalus, and other severe congenital conditions amounted to unlawful discrimination against a disabled person in violation of federal law. The district court denied the government’s request for access to the records, held that Baby Jane Doe’s parents had made “a reasonable choice among alternative medical treat- ments,” and found that the parents’ refusal to consent to treatment did not violate the Rehabilitation Act of 1973, which prohibits discrimination on the basis of disability.80 Although access to the records was not granted, the court noted in its opinion that disclosure would not have been barred by a state privilege of confidentiality because no state statutory privilege exists when a federal question is being decided.81
State authorities also have obtained information necessary to enforce the law and to protect against fraud and abuse. For example, the US Court of Appeals for the Sixth Circuit held that a psychotherapist was required to disclose the names of patients and the dates of their treatment to a grand jury investigating an alleged scheme to defraud the Michigan Blue Cross Blue Shield plan.82 In a similar case, a court denied a claim of privilege and permitted the New York Department of Social Services to review a psychia- trist’s Medicaid patients’ records when investigating the physician’s billing practices.83 In another New York case investigating a death in a hospital’s intensive care unit, neither the state’s privileged communication statute nor a constitutional right of privacy prohibited a grand jury from accessing patients’ medical information.84 In California and many other jurisdictions, the agency responsible for licensure may review health records when exam- ining the professional conduct of a physician whose hospital privileges have been revoked, although the law may require that the names of patients be deleted.85
Law enforcement officials’ requests for PHI often present a challenge. Routine requests such as court orders and subpoenas can be handled by a hospital’s HIM or ROI department, but many requests are not routine and
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n356
are made on an emergency basis. For example, law enforcement personnel may request PHI to
• locate a suspect or fugitive, • retrieve or preserve evidence of a crime, • deal with imminent threats to public safety, or • determine the blood alcohol level of a person in custody.
As a general proposition, disclosures of PHI should not be made to law enforcement officials without the patient’s consent, explicit statutory authority, or a court order. However, determination of whether disclosure is permitted in a given case involves complicated, fact-dependent legal calcu- lus at which most hospital personnel are not likely to be adept. Institutions should have policies to address these issues, and they must train personnel in the ED, outpatient clinics, and other areas likely to receive the requests.
For its members, the Florida Hospital Association (FHA) published a handbook that compares HIPAA requirements and Florida law and offers general suggestions for dealing with law enforcement personnel:
• Document the law officer’s identity (e.g., name, badge number). • Determine the purpose of the request and whether the officer has legal
authority to make it. • Ask that the request be submitted in writing, preferably in an official
document. • Provide only the minimum amount of information, preferably with
identifying information eliminated. • Consult the facility’s privacy officer, compliance officer, risk manager,
or legal counsel if time permits.
In addition to these suggestions, the FHA handbook describes 28 scenarios that hospitals and physicians might encounter. All scenarios are followed by discussion of possible solutions and can be used as an educational resource. Healthcare providers might find it useful to obtain or develop a resource similar to the FHA’s handbook and to use it as the basis for their policies and training programs.86
State Open Meeting and Public Records Laws
Every state has statutes that determine when government agencies must allow the public to attend meetings and to make minutes and other records available for public inspection.87 These statutes are often referred to as
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 357
sunshine laws, which connotes that the public is entitled to have light shed on the conduct of governmental affairs. They are also, more prosaically, called open meeting laws or public records laws.
Therefore, government hospitals and hospital authorities are covered not only by federal statutes and regulations but also by laws at the state, county, and municipal levels, some of which do not apply to other healthcare organizations.88 For example, a county-owned hospital was subject to the state’s sunshine laws and its personnel records were subject to inspection even though they contained information about employees’ prior felony con- victions, drug and alcohol problems, unlisted phone numbers, physical and mental examinations, and communications from third persons who provided the information believing it was confidential.89
Likewise, a county hospital authority in Georgia was subject to that state’s similar legislation, and the Supreme Court of Georgia held that a news- paper had the right to access the names, job titles, and salaries of all hospital employees who earned more than $28,000.90 In Florida, Gadd v. News-Press Publishing Company, Inc. held that a newspaper was entitled to view a public hospital’s medical staff files and its utilization review documents.91 Although another Florida statute exempts peer review records and proceedings from use in an action against a provider of health services,92 the Public Records Act does not do so specifically, so the Gadd court held that the apparent inconsis- tency between the two statutory schemes was a matter for the legislature to resolve. These cases are examples of the typical judicial approach to interpret- ing the sunshine laws liberally, in accordance with legislative intent.
Most of the sunshine statutes contain exceptions to the right of public access. Some of the exceptions are cast in general language, but some are more specific—as is the exception in Florida related to autopsy photos (see the discussion about Dale Earnhardt earlier in the chapter). A court may cre- ate an exception when it is presented with a persuasive reason for limiting the applicability of the legislation. Typically, the statutes exclude meetings and records related to pending litigation, negotiations with labor unions, acquisition of capital (e.g., the purchase of real estate), and disciplinary action against governmental personnel.
Questions about public records laws involve balancing various interests. The outcome of each case depends on the language of the relevant statute, judicial understanding of legislative intent, the purposes or motives of those seeking access, and the countervailing interests of the defendant or third parties.
Summary
The title of this chapter reflects a belief that the term medical records is passé because information about a person’s health (or payment for health-related
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n358
services) can be maintained in many types of media other than paper. Regard- less of the form in which it is maintained, health information must be accu- rate and its confidentiality must be ensured. This chapter reviews the various ways in which health information is properly used, such as for documentation of treatment, for accurate billing, and as evidence in legal forums. It also discusses HIPAA and other state and federal laws that govern the protection of health information. It outlines circumstances in which third parties may legitimately access individuals’ health information with and without patient consent, and it points out the pitfalls that one can encounter when that infor- mation is improperly disclosed.
Discussion Questions
1. Describe the nuances of the terms medical records and health information. Why does HIPAA use the latter term?
2. When might a patient’s favorite color or high school alma mater be considered health information?
3. Describe some circumstances in which confidential health information may be disclosed without the patient’s consent.
4. Why do you suppose physician–patient privilege did not exist in common law but had to be created by statute?
5. What is the proper way to make changes to a written health record? 6. Who owns physical health records, X-ray images, and other items
containing health information? 7. How can the inability to predict dangerousness be reconciled with the
emotional issue of registering convicted sex offenders and preventing them from living in proximity to schools and other places that children frequent?
8. Describe the provisions of the HITECH Act and the Red Flags Rule and how they affect healthcare operations.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 359
The Cour t Decides
Opis Management Resources, LLC v. Secretary, Fla. Agency for Healthcare Admin.
713 F.3d 1291 (11th Cir., 2013)
BLACK, Circuit Judge:
The issue before us is whether § 400.145 of the Florida Statutes—which provides for the release of medical records of deceased residents of nursing homes to certain speci- fied individuals—is preempted by the federal Health Insurance Portability and Accountabil- ity Act of 1996 (HIPAA), 42 U.S.C. § 1320d to d-9, and its implementing regulations. . . .
I. BACKGROUND The underlying facts are not in dispute. Plaintiffs-Appellees . . . (collectively the Nurs- ing Facilities or the Facilities) are operators and managers of skilled nursing facilities in Florida. In the course of their operations, [they] received requests from spouses and attorneys-in-fact for the medical records of deceased nursing home residents. The Facili- ties refused to disclose the records because the parties requesting them were not “per- sonal representatives” under the relevant provisions of HIPAA, which regulates the release of protected health information by covered entities. Consequently, the request- ing parties filed complaints with the U.S. Department of Health and Human Services Office for Civil Rights, which concluded the Nursing Facilities’ actions were consistent with HIPAA.
Defendant-Appellant Florida Agency for Health Care Administration (the State Agency), however, issued citations to the Nursing Facilities for violating Florida law by refusing to release the records. Specifi- cally, the Facilities were cited for violating § 400.145 of the Florida Statutes, which
requires licensed nursing homes to release a former resident’s medical records to the spouse, guardian, surrogate, or attorney-in- fact of any such resident.* In written corre- spondence to individuals who had requested and been denied deceased residents’ medical records, the State Agency explained that it interprets § 400.145 in a manner allowing a spouse to qualify as a personal representa- tive such that a deceased spouse’s medical records may be disclosed under HIPAA.
Given the dueling interpretations of the relevant statutes, the Nursing Facilities filed a complaint in the district court seeking a declaratory judgment that § 400.145 is preempted by HIPAA. The parties then filed cross-motions for summary judgment. In rul- ing on the motions, the district court found that § 400.145 was preempted because it impeded the accomplishment and execution of HIPAA’s purposes and objectives. The court granted the Nursing Facilities’ motion for summary judgment, explaining that the Flor- ida statute affords nursing home residents less protection than is required by the federal law. This appeal followed. . . .
III. DISCUSSION [The court begins by reminding readers that the laws of the United States are the supreme law of the land and that where state and federal law directly conflict, “state law must give way.” Therefore, HIPAA supersedes any contrary state law. A state law is “contrary” to HIPAA if complying with both the state
(continued)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n360
and federal requirements is impossible or the state law “stands as an obstacle” to achiev- ing HIPAA’s objectives. The opinion contin- ues as follows.]
Regarding deceased individuals, the Pri- vacy Rule further specifies that:
If under applicable law an execu- tor, administrator, or other person has authority to act on behalf of a deceased individual or of the individual’s estate, a covered entity [such as the plaintiffs] must treat such person as a personal rep- resentative under this subchapter, with respect to protected health information relevant to such personal representation.
[Also, if an individual is deceased,] a covered entity may disclose to a family member, or [other relatives, friends or other persons identified by the indi- vidual] who were involved in the indi- vidual’s care or payment for health care prior to the individual’s death, pro- tected health information of the indi- vidual that is relevant to such person’s involvement. . . .
According to the State Agency, § 400.145 enumerates groups of people, includ- ing spouses, who may access a deceased resident’s medical records “on behalf of ” the resident, meaning that they should be treated as personal representatives. Thus, rather than conflicting with HIPAA and the Privacy Rule, § 400.145 supplements and works in tandem with the federal law.
The fatal flaw in the State Agency’s argu- ment is that the plain language of § 400.145 does not empower or require an individual to act on behalf of a deceased resident. The unadorned text of the state statute authorizes sweeping disclosures, mak- ing a deceased resident’s protected health information available to a spouse or other enumerated party on request, without any need for authorization, for any conceivable
reason, and without regard to the authority of the individual making the request to act in a deceased resident’s stead. See 45 C.F.R. § 164.502(g)(4) (providing that a person authorized to act on behalf of a deceased individual must be treated as a personal rep- resentative “with respect to protected health information relevant to such personal repre- sentation” [emphasis added]). We therefore agree with the district court that § 400.145 frustrates the federal objective of limiting disclosures of protected health information, and that the statute is thus preempted by the more stringent privacy protections of HIPAA and the Privacy Rule. . . .
[T]he Florida legislature has not amended or modified § 400.145 to address the impact of HIPAA and its implementing regulations. Section 400.145 does not require a HIPAA- compliant authorization to accompany a request for a deceased individual’s medical records, nor can the statute plausibly be read as creating a limited personal representation in the person of a surviving spouse in light of the blanket disclosures that it requires. Given the opportunity, we are confident the Florida legislature could bring § 400.145 into compli- ance with federal law in any number of ways. Amending the statute, however, is a task for the state legislature, not a panel of federal judges. . . .
For the foregoing reasons, we agree with the district court that § 400.145 of the Florida Statutes impedes the accomplishment and execution of the full purposes and objectives of HIPAA and the Privacy Rule in keeping an individual’s protected health information confidential. Accordingly, the district court’s grant of summary judgment is AFFIRMED.
*The statute reads, in pertinent part: “400.145: Records of care and treatment of resident; copies to be furnished. — (1) Unless expressly prohibited by a legally competent resident, any nursing home . . . shall furnish to the spouse,
(continued from previous page)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 361
guardian, surrogate, proxy, or attorney in fact . . . of a current [or former] resident a copy of
that resident’s records which are in the posses- sion of the facility.”
Discussion Questions
1. Summarize in a succinct sentence (or two at the most) why this statute is “contrary” to HIPAA. 2. A similar Florida statute applicable to hospitals reads as follows:
Any licensed facility shall, upon written request, and only after discharge of the patient, furnish, in a timely manner, without delays for legal review, to any person admitted therein for care and treatment or treated thereat, or to any such person’s guardian, curator, or personal representa- tive, or in the absence of one of those persons, to the next of kin of a decedent or the parent of a minor, or to anyone designated by such person in writing, a true and correct copy of all patient records, including X rays, and insurance information concerning such person.93
What HIPAA-related infirmities do you see in this language, and how would the Opis Manage- ment court decide a case alleging that this statute is preempted?
~ ~
The Cour t Decides
Tarasoff v. Regents of the University of California 17 Cal. 3d 425, 131 Cal. Rptr. 14 (1976)
Tobriner, J.
On October 27, 1969, Prosenjit Poddar killed Tatiana Tarasoff. Plaintiffs, Tatiana’s parents, allege that two months earlier Poddar confided his intention to kill Tatiana to Dr. Lawrence Moore, a psychologist employed by the Cowell Memorial Hospital at the University of Califor- nia at Berkeley. They allege that on Moore’s request, the campus police briefly detained Poddar, but released him when he appeared rational. They further claim that Dr. Harvey Powelson, Moore’s superior, then directed that no further action be taken to detain Poddar. No one warned plaintiffs of Tatiana’s peril.
Concluding that these facts set forth causes of action against neither therapists and policemen involved, nor against the Regents of the University of California as their employer, the superior court sustained defendants’ demurrers to plaintiffs’ second amended complaints without leave to amend. This appeal ensued.
Plaintiffs’ complaints predicate liability on two grounds: defendants’ failure to warn plaintiffs of the impending danger and their failure to bring about Poddar’s confinement pursuant to the Lanterman-Petris-Short Act
(continued)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n362
[the California law allowing involuntary, psy- chiatric admission of persons considered dangerous to themselves or others]. Defen- dants, in turn, assert that they owed no duty of reasonable care to Tatiana and that they are immune from suit under the California Tort Claims Act of 1963.
We shall explain that defendant thera- pists cannot escape liability merely because Tatiana herself was not their patient. When a therapist determines, or pursuant to the standards of his profession should deter- mine, that his patient presents a serious danger of violence to another, he incurs an obligation to use reasonable care to protect the intended victim against such danger. The discharge of this duty may require the thera- pist to take one or more of various steps, depending upon the nature of the case. Thus it may call for him to warn the intended vic- tim or others likely to apprise the victim of the danger, to notify the police, or to take whatever other steps are reasonably neces- sary under the circumstances.
In the case at bar, plaintiffs admit that defendant therapists notified the police, but argue on appeal that the therapists failed to exercise reasonable care to protect Tatiana in that they did not confine Poddar and did not warn Tatiana or others likely to apprise her of the danger. . . .
Plaintiffs . . . can amend their complaints to allege that, regardless of the therapists’ unsuccessful attempt to confine Poddar, since they knew that Poddar was at large and dan- gerous, their failure to warn Tatiana or others likely to apprise her of the danger constituted a breach of the therapists’ duty to exercise reasonable care to protect Tatiana. . . .
Plaintiffs’ Complaints . . .
Plaintiffs’ first cause of action, [titled] “Failure to Detain a Dangerous Patient,” alleges that on August 20, 1969, Poddar was a voluntary outpatient receiving therapy at
Cowell Memorial Hospital. Poddar informed Moore, his therapist, that he was going to kill an unnamed girl, readily identifiable as Tati- ana, when she returned home from spending the summer in Brazil. Moore, with the concur- rence of Dr. Gold, who had initially examined Poddar, and Dr. Yandell, assistant to the director of the department of psychiatry, decided that Poddar should be committed for observation in a mental hospital. Moore orally notified Officers Atkinson and Teel of the campus police that he would request commitment. He then sent a letter to Police Chief William Beall requesting the assistance of the police department in securing Poddar’s confinement.
Officers Atkinson, Brownrigg, and Halle- ran took Poddar into custody, but, satisfied that Poddar was rational, released him on his promise to stay away from Tatiana. Powelson, director of the department of psychiatry at Cowell Memorial Hospital, then asked the police to return Moore’s letter, directed that all copies of the letter and notes that Moore had taken as therapist be destroyed, and “ordered no action to place Prosenjit Poddar in 72-hour treatment and evaluation facility.”
Plaintiffs’ second cause of action, entitled “Failure to Warn on a Dangerous Patient,” incorporates the allegations of the first cause of action, but adds the assertion that defen- dants negligently permitted Poddar to be released from police custody without “notify- ing the parents of Tatiana Tarasoff that their daughter was in grave danger from Prosenjit Poddar.” Poddar persuaded Tatiana’s brother to share an apartment with him near Tatiana’s residence; shortly after her return from Bra- zil, Poddar went to her residence and killed her. . . .
[The court holds that the first cause of action is barred by the principle of govern- mental immunity. The third and fourth—not summarized in this book—were also held to be invalid.] We direct our attention, therefore, to the issue of whether plaintiffs’ second
(continued from previous page)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 363
cause of action can be amended to state a basis for recovery.
Plaintiffs can state a cause of action against defendant therapists for negligent failure to protect Tatiana.
The second cause of action can be amended to allege that Tatiana’s death proxi- mately resulted from defendants’ negligent failure to warn Tatiana or others likely to apprise her of her danger. Plaintiffs contend that as amended, such allegations of negli- gence and proximate causation, with result- ing damages, establish a cause of action. Defendants, however, contend that in the circumstances of the present case they owed no duty of care to Tatiana or her parents and that, in the absence of such duty, they were free to act in careless disregard of Tatiana’s life and safety. . . .
The most important of [various] consider- ations in establishing duty is foreseeability. As a general principle, a “defendant owes a duty of care to all persons who are foresee- ably endangered by his conduct, with respect to all risks which make the conduct unrea- sonably dangerous.” As we shall explain, however, when the avoidance of foreseeable harm requires a defendant to control the conduct of another person, or to warn of such conduct, the common law has traditionally imposed liability only if the defendant bears some special relationship to the dangerous person or to the potential victim. Since the relationship between a therapist and his patient satisfies this requirement, we need not here decide whether foreseeability alone is sufficient to create a duty to exercise rea- sonable care to protect a potential victim of another’s conduct.
Although . . . under the common law, as a general rule, one person owed no duty to control the conduct of another, nor to warn those endangered by such conduct, the courts have carved out an exception to this
rule in cases in which the defendant stands in some special relationship to either the per- son whose conduct needs to be controlled or in a relationship to the foreseeable victim of that conduct. Applying this exception to the present case, we note that a relationship of defendant therapists to either Tatiana or Pod- dar will suffice to establish a duty of care; as explained in . . . the Restatement Second of Torts, a duty of care may arise from either “(a) a special relation * * * between the actor and the third person which imposes a duty upon the actor to control the third per- son” conduct, or (b) a special relation * * * between the actor and the other which gives to the other a right of protection.”
Although plaintiffs’ pleadings assert no special relation between Tatiana and defen- dant therapists, they establish as between Poddar and defendant therapists the special relation that arises between a patient and his doctor or psychotherapist. Such a relation- ship may support affirmative duties for the benefit of third persons. Thus, for example, a hospital must exercise reasonable care to control the behavior of a patient which may endanger other persons. A doctor must also warn a patient if the patient’s condition or medication renders certain conduct, such as driving a car, dangerous to others.
Although the California decisions that rec- ognize this duty have involved cases in which the defendant stood in a special relationship both to the victim and to the person whose conduct created the danger, we do not think that the duty should logically be constricted to such situations. Decisions of other juris- dictions hold that the single relationship of a doctor to his patient is sufficient to support the duty to exercise reasonable care to pro- tect others against dangers emanating from the patient’s illness. The courts hold that a doctor is liable to persons infected by his patient if he negligently fails to diagnose a contagious disease, or, having diagnosed the
(continued)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n364
illness, fails to warn members of the patient’s family.
Since it involved a dangerous mental patient, the decision in Merchants Nat. Bank & Trust Co. of Fargo v. United States [1967] comes closer to the issue. The Veterans Administration arranged for the patient to work on a local farm, but did not inform the farmer of the man’s background. The farmer consequently permitted the patient to come and go freely during nonworking hours; the patient borrowed a car, drove to his wife’s residence and killed her. Notwithstanding the lack of any “special relationship” between the Veterans Administration and the wife, the court found the Veterans Administration liable for the wrongful death of the wife.
In their summary of the relevant rulings [two scholars] conclude that the “case law should dispel any notion that to impose on the therapists a duty to take precautions for the safety of persons threatened by a patient, where due care so requires, is in any way opposed to contemporary ground rules on the duty relationship. On the contrary, there now seems to be sufficient authority to support the conclusion that by entering into a doctor–patient relationship the therapist becomes sufficiently involved to assume some responsibility for the safety, not only of the patient himself, but also of any third per- son whom the doctor knows to be threatened by the patient.”
Defendants contend, however, that impo- sition of a duty to exercise reasonable care to protect third persons is unworkable because therapists cannot accurately predict whether or not a patient will resort to violence. In support of this argument amicus represent- ing the American Psychiatric Association and other professional societies cites numerous articles which indicate that therapists, in the present state of the art, are unable reliably to predict violent acts; their forecasts, amicus claims, tend consistently to overpredict vio- lence, and indeed are more often wrong than
right. Since predictions of violence are often erroneous, amicus concludes, the courts should not render rulings that predicate the liability of therapists upon the validity of such predictions. . . .
We recognize the difficulty that a thera- pist encounters in attempting to forecast whether a patient presents a serious danger of violence. Obviously, we do not require that the therapist, in making that determi- nation, render a perfect performance; the therapist need only exercise “that reasonable degree of skill, knowledge, and care ordinar- ily possessed and exercised by members of [that professional specialty] under similar circumstances.” Within the broad range of reasonable practice and treatment in which professional opinion and judgment may differ, the therapist is free to exercise his or her own best judgment without liability; proof, aided by hindsight, that he or she judged wrongly is insufficient to establish negligence.
In the instant case, however, the plead- ings do not raise any question as to failure of defendant therapists to predict that Poddar presented a serious danger of violence. On the contrary, the present complaints allege that defendant therapists did in fact predict that Poddar would kill, but were negligent in failing to warn. Amicus contends, however, that even when a therapist does in fact pre- dict that a patient poses a serious danger of violence to others, the therapist should be absolved of any responsibility for fail- ing to act to protect the potential victim. In our view, however, once a therapist does in fact determine, or under applicable profes- sional standards reasonably should have determined, that a patient poses a serious danger of violence to others, he bears a duty to exercise reasonable care to protect the foreseeable victim of that danger. While the discharge of this duty of due care will nec- essarily vary with the facts of each case, in each instance the adequacy of the therapist’s
(continued from previous page)
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 365
conduct must be measured against the tra- ditional negligence standard of the rendition of reasonable care under the circumstances. As explained in [the same scholars’ article]: “* * * the ultimate question of resolving the tension between the conflicting interests of patient and potential victim is one of social policy, not professional expertise. * * * In sum, the therapist owes a legal duty not only to his patient, but also to his patient’s would- be victim and is subject in both respects to scrutiny by judge and jury.” . . .
We realize that the open and confidential character of psychotherapeutic dialogue encourages patients to express threats of violence, few of which are ever executed. Cer- tainly a therapist should not be encouraged routinely to reveal such threats; such disclo- sures could seriously disrupt the patient’s relationship with his therapist and with the persons threatened. To the contrary, the therapist’s obligations to his patient require that he not disclose a confidence unless such disclosure is necessary to avert danger to others, and even then that he do so dis- creetly, and in a fashion that would preserve the privacy of his patient to the fullest extent compatible with the prevention of the threat- ened danger.
The revelation of a communication under the above circumstances is not a breach of trust or a violation of professional ethics; as stated in the Principles of Medical Ethics
of the American Medical Association (1957), section 9: “A physician may not reveal the confidence entrusted to him in the course of medical attendance * * * unless he is required to do so by law or unless it becomes necessary in order to protect the welfare of the individual or of the commu- nity.” We conclude that the public policy favoring protection of the confidential char- acter of patient–psychotherapist commu- nications must yield to the extent to which disclosure is essential to avert danger to others. The protective privilege ends where the public peril begins.
Our current crowded and computerized society compels the interdependence of its members. In this risk-infested society we can hardly tolerate the further exposure to danger that would result from a concealed knowledge of the therapist that his patient was lethal. If the exercise of reasonable care to protect the threatened victim requires the therapist to warn the endangered party or those who can reasonably be expected to notify him, we see no sufficient societal interest that would protect and justify con- cealment. The containment of such risks lies in the public interest. For the foregoing reasons, we find that plaintiffs’ complaints can be amended to state a cause of action against defendants Moore, Powelson, Gold, and Yandell and against the Regents as their employer, for breach of a duty to exercise reasonable care to protect Tatiana.
Discussion Questions
1. This case was brought before the court on this procedural issue: whether the trial court was correct to dismiss the complaint before a trial could be held. What do you suppose happened after the case returned to the trial court?
2. What should the defendants have done differently? 3. Why is the board (the Regents) of the University of California a defendant?
~ ~
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n366
Notes
1. 42 U.S.C. §§ 1320d–1320d-9. 2. 45 C.F.R., Parts 160 and 164. 3. 42 U.S.C. § 1320d(4). 4. tHe Joint commission, 2013 HospitAl AccreditAtion stAndArds at
RC-1. 5. 45 C.F.R. § 164.514. 6. Fla. Stat. § 395.3015. 7. Fla. Admin. Code R. 59A-3.270, Health Information Management. 8. The American Recovery and Reinvestment Act of 2009, Pub. L. No.
111-5 (2009). 9. See, e.g., tHe Joint commission, 2013 HospitAl AccreditAtion
stAndArds, Standard RC.01.01.01, et seq. The Joint Commission has similar accreditation standards for nonhospital healthcare organizations.
10. Darling v. Charleston Community Memorial Hosp., 33 Ill. 2d 326, 211 N.E.2d 253 (1965), cert. denied, 383 U.S. 946 (1966).
11. 42 C.F.R. Part 482. 12. tHe Joint commission, supra note 9, at Standard RC.01.02.01. 13. The American Health Information Management Assn. has published a
“tool kit” that provides HIM professionals with guidance on how to amend an EHR. It is available to AHIMA members at http://library. ahima.org/doc?oid=105672#.XVlSUuhKiUk.
14. Pisel v. Stamford Hosp., 430 A.2d 1 (Conn. 1980). 15. 384 F. Supp. 821 (W.D. Ark. 1974). 16. Id. at 831. 17. 42 C.F.R. § 482.24. 18. Fla. Stat. § 95.11(4)(b). 19. See, e.g., Fla. Stat. §§ 395.3025 and 456.057. 20. This is an “element of performance” (see tHe Joint commission at
RC.01.05.01). 21. 21 Fla. Stat. § 395.3025; see also Matter of Weiss, 208 Misc. 1010, 147
N.Y.S.2d 455 (Sup. Ct. 1955). 22. Fla. Stat. §§ 456.057 and 456.058. 23. In re Culbertson’s Will, 57 Misc. 2d 391, 292 N.Y.2d 806 (Sup. Ct.
1968). 24. The regulations implementing the statute are found at 45 C.F.R.
Parts 160 and 164. Each specific point made in the text will not be referenced here.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 367
25. 45 C.F.R. § 164.528. 26. Thurman v. Crawford, 652 S.W.2d 240 (Mo. App. 1983) (a hospital
may take reasonable precautions to ascertain authenticity of a patient’s consent to release medical information and may refuse to honor consent when the date has been altered).
27. Whalen v. Roe, 429 U.S. 589 (1977). 28. Griswold v. Connecticut, 381 U.S. 479 (1965) (state may not prohibit
use of contraceptives or advice or assistance in their use); Roe v. Wade, 410 U.S. 113 (1973), and Doe v. Bolton, 410 U.S. 179 (1973) (abortion cases).
29. Robinson v. Hamilton, 60 Iowa 134, 14 N.W. 202 (1882); Planned Parenthood of Central Mo. v. Danforth, 428 U.S. 52 (1976).
30. 45 C.F.R. § 164.512(j). 31. Tarasoff v. Regents of the University of California, 17 Cal. 3d 425, 451
(1976). 32. Thompson v. County of Alameda, 27 Cal. 3d 741, 614 P.2d 728,
167 Cal. Rptr. 70 (1980). See also Mangeris v. Gordon, 94 Nev. 400, 580 P.2d 481 (1978); Leedy v. Hartnett, 510 F. Supp. 1125 (M.D. Pa. 1981) (Veterans Administration hospital had no duty to warn of discharged patient’s propensity for alcohol-induced violence without a readily identifiable victim), and Brady v. Hopper, 570 F. Supp. 1333 (D. Colo. 1983) (the psychiatrist had no duty to warn because the patient—John Hinckley Jr., who attempted to assassinate President Reagan—had not threatened to shoot anyone).
33. Mavroudis v. Superior Court for County of San Mateo, 102 Cal. App. 3d 594, 162 Cal. Rptr. 724 (1980); McIntosh v. Milano, 168 N.J. Super. 466, 403 A.2d 500 (1979).
34. See, e.g., Shaw v. Glickman, 45 Md. App. 718, 415 A.2d 625 (1980); Cole v. Taylor, 301 N.W.2d 766 (Iowa 1981); Case v. United States, 523 F. Supp. 317 (S.D. Ohio 1981); Hawkins v. King County Dep’t of Rehabilitative Servs., 602 P.2d 361 (Wash. App. 1979).
35. Bellah v. Greenson, 81 Cal. App. 3d 614, 146 Cal. Rptr. 535 (1978).
36. 42 C.F.R. Parts 462 and 476. 37. See generally 53 C.J.S., Libel & Slander §§ 1–9 (2009). 38. 623 S.W.2d 205 (Ark. 1981). 39. Koudsi v. Hennepin County Medical Center, 317 N.W.2d 705 (Minn.
1982) (the statement that the plaintiff was a patient in a hospital and had given birth was true and could not be defamation).
40. Gilson v. Knickerbocker Hosp., 280 A.D. 690, 116 N.Y.S.2d 745 (1952).
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n368
41. Griffin v. Cortland Memorial Hosp., Inc., 85 A.D.2d 837, 446 N.Y.S.2d 430 (1981) (a notation on a chart that an outpatient was abusing drugs was protected by qualified privilege).
42. Samuel D. Warren and Louis D. Brandeis, The Right of Privacy, 4 HArv. l. rev. 193 (1890).
43. See, e.g., Pavesich v. New England Life Ins. Co., 122 Ga. 190, 50 S.E. 68 (1905) and Housh v. Peth, 165 Ohio St. 35, 36, 133 N.E.2d 340, 341 (1956).
44. But cf. MacDonald v. Time, Inc., 554 F. Supp. 1053 (D. N.J. 1983) (when a living person is libeled, the claim survives death and is saved from abatement by the New Jersey survival statute).
45. Cf. Chico Feminist Women’s Health Center v. Butte Glenn Medical Soc’y, 557 F. Supp. 1190 (E.D. Cal. 1983) (California constitutional law gave an abortion clinic a cause of action for invasion of privacy—on behalf of women seeking its service—against the hospital, physicians, insurance company, and medical society for statements and activities intended to force the clinic’s closure; a corporation did not have cause of action for invasion of privacy in its own right).
46. 38 Pa. D. & C. 543 (1940). See also Estate of Berthiaume v. Pratt, 365 A.2d 792 (Me. 1976) (photographing a terminally ill patient for research when the patient objects is an invasion of privacy).
47. See Vassiliades v. Garfinckel’s, Brooks Bros., 492 A.2d 580 (D.C. App. 1985) (publication of photographs by the physician without the patient’s consent may be a tort; this opinion contains an excellent review of the state of the law).
48. Campus Communications, Inc. v. Earnhardt, 821 So. 2d 388, 402 (Fla. App. 2002).
49. Beth Israel Hosp. and Geriatric Center v. District Court in and for the City and County of Denver, 683 P.2d 343 (Colo. 1984) (the physician may have access to health records of his patients especially because case names and not patients’ names were requested).
50. Knecht v. Vandalia Medical Center, Inc., 14 Ohio App. 3d 129 (1984) (a qualified privilege based on commonality of interest existed when a woman employed by physicians told her son that his friend was examined for venereal disease).
51. But see Sinclair v. Postal Telegraph and Cable Co., 72 N.Y.S.2d 841 (Sup. Ct. 1935) (actors may insist on dignified public presentations of themselves and their work; hence, the defendant’s presentation of an actor’s picture presenting him in an undignified light, without permission, was wrongful).
52. Koudsi v. Hennepin County Medical Center, 317 N.W.2d 705 (Minn. 1982) (informing a family member that the plaintiff had borne a child
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 369
in the hospital did not violate any common law or statutory right to confidentiality).
53. 45 C.F.R. § 164.522(b). 54. Munzer v. Blaisdell, 183 Misc. 773, 49 N.Y.S.2d 915 (1944), aff’d,
269 A.D. 970, 58 N.Y.S.2d 359 (1945); N.Y. Mental Hyg. Law § 33. 13 (McKinney Supp. 1987).
55. Mental Health and Developmental Disabilities Confidentiality Act, 117, Ill. Ann. Stat. ch. 911–2, §§ 801–17 (Smith-Hurd 1987).
56. 42 U.S.C. § 242(a); 21 U.S.C.S. § 872 (c), (d). 57. 42 U.S.C. § 290ee-3. 58. 42 U.S.C. § 290dd-3. 59. 42 C.F.R. Part 2. 60. 42 U.S.C. § 290dd-2(b). Information can also be exchanged between
the Armed Forces and the Veterans Administration without violating the statute (42 U.S.C. § 290dd-2(e)).
61. See United States v. Hopper, 440 F. Supp. 1208 (N.D. Ill. 1977), Matter of Dwayne G., 97 Misc. 2d 333, 411 N.Y.S.2d 180 (1978), and United States v. Providence Hosp., 507 F. Supp. 519 (E.D. Mich. 1981) on these three points, respectively.
62. United States v. Fenyo, 6 M.J. 933 (1979), and United States v. Graham, 548 F.2d 1302 (8th Cir. 1977).
63. People v. Newman, 32 N.Y.2d 379, 298 N.E.2d 651, 345 N.Y.S.2d 502 (1973), cert. denied, 414 U.S. 1163 (1973).
64. 45 C.F.R. § 164.514(3)(ii). 65. Fla. Stat. § 394.4615(10). 66. 45 C.F.R. § 164.524(a)(3). 67. floridA HospitAl AssociAtion mAnAgement corp., floridA HipAA
preemption AnAlysis (2002). 68. 327 F.3d 346 (4th Cir. 2003). See also Citizens for Health v. Leavitt,
428 F.3d. 167 (3d Cir. 2005). 69. 42 U.S.C. §§ 1320d-5 and 1320d-6. 70. Federal Trade Comm’n Bureau of Consumer Protection, Medical Identity
Theft: FAQs for Health Care Providers and Health Plans (published January 2011), at https://www.ftc.gov/tips-advice/business-center/ guidance/medical-identity-theft-faqs-health-care-providers-health-plans.
71. See 16 C.F.R. § 681.1. 72. 15 U.S.C. §§ 1681 et seq. 73. 15 U.S.C. § 1681m(e)(4)(B). 74. 12 C.F.R. Part 41, Appendix J, Supplement A (2009). 75. Mich. Comp. Laws § 600.2157 (2015).
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
T h e L a w o f H e a l t h c a r e A d m i n i s t r a t i o n370
76. See, e.g., Weis v. Weis, 147 Ohio St. 416, 72 N.E.2d 245 (1947); Sims v. Charlotte Liberty Mutual Ins. Co., 256 N.C. 32, 125 S.E.2d 326 (1962); In re Estate of Searchill, 9 Mich. App. 614, 157 N.W.2d 788 (1968) (the mental competence of the deceased at the time a contested will was executed was at issue; the hospital’s health records were admissible on the question of competence); Rivers v. Union Carbide Corp., 426 F.2d 633 (3d Cir. 1970) (hospital records disclosing a history of alcoholism and intoxication at the time of an accident were admissible by virtue of Federal Business Records Act, 28 U.S.C. § 1732).
77. United States v. Kansas City Lutheran Home and Hosp. Ass’n, 297 F. Supp. 239 (W.D. Mo. 1969).
78. United States v. Providence Hosp., 507 F. Supp. 519 (E.D. Mich. 1981).
79. General Motors Corp. v. Director of NIOSH, 636 F.2d 163 (6th Cir. 1980).
80. United States v. University Hosp. of State Univ. of N.Y. at Stony Brook, 575 F. Supp. 607 (E.D.N.Y. 1983). The decision was later affirmed by a federal court of appeals but for different reasons. In the appellate court’s view, the factual situation was beyond the contemplation and intent of Congress when it enacted the Rehabilitation Act of 1973—the legislation prohibiting discrimination against disabled persons—and therefore the statute was not relevant. 729 F.2d 144 (2d Cir. 1984).
81. 575 F. Supp. at 611. 82. In re Zuniga, 714 F.2d 632 (6th Cir. 1983). 83. Camperlengo v. Blum, 56 N.Y.2d 251, 436 N.E.2d 1299, 451
N.Y.S.2d 697 (1982). 84. People v. Doe, 116 Misc. 2d 626, 455 N.Y.S.2d 945 (1982). 85. Board of Medical Quality Assurance v. Hazel Hawkins Memorial
Hosp., 135 Cal. App. 3d 561, 185 Cal. Rptr. 405 (1982) (a patient’s records of disciplinary proceedings, without names, may be subpoenaed).
86. floridA Hosp. Ass’n, HipAA requirements And floridA lAw: disclosures of protected HeAltH informAtion for lAw enforcement purposes (May 2006).
87. Reporters Committee for Freedom of the Press, Open Government Guide (accessed August 19, 2016), at http://www.rcfp.org/ogg.
88. The Mississippi statute, Section 25-41-3 (1986), however, grants a specific exemption to the boards, committees, and staffs of both “public and private hospitals.”
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
C h a p t e r 9 : H e a l t h I n f o r m a t i o n M a n a g e m e n t 371
89. Douglas v. Michel, 410 So. 2d 936 (Fla. App. 1982). 90. Richmond County Hosp. Auth. v. Southeastern Newspapers Corp.,
311 S.E.2d 806 (Ga. 1984); see also Moberly v. Herboldsheimer, 345 A.2d 855 (Md. App. 1975) (a newspaper may compel a municipal hospital to disclose an administrator’s salary and fees paid to legal counsel).
91. 412 So. 2d 894 (Fla. App. 1982). 92. Fla. Stat. § 768.40(4) (1985). 93. Fla. Stat. § 395.3025.
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use
Copying and distribution of this PDF is prohibited without written permission. For permission, please contact Copyright Clearance Center at www.copyright.com
EBSCOhost - printed on 5/24/2022 5:09 PM via UNIVERSITY OF MARYLAND GLOBAL CAMPUS. All use subject to https://www.ebsco.com/terms-of-use