Data Privacy and Security
HIPAA on the Horizon in the New Year: Important Lessons from an Active 2023 and Regulatory Initiatives to Watch for in 2024
2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain a challenge for HIPAA-covered entities as well as for their business associates. 2023 brought a large number of important HIPAA-related developments and lessons-learned that privacy/security officials and health care attorneys should be aware of when planning for HIPAA compliance activities in 2024. This article features lessons learned in some of the most significant HIPAA-related enforcement actions and guidance documents from the U.S. Department of Health and Human Services’ Office for Civil Rights’ (“OCR”) in 2023, and ends with a summary of some of the ongoing OCR regulatory initiatives to monitor in 2024. OCR’s First Enforcement Action Related to a Phishing Attack On December 7, 2023, the OCR announced a $480,000 settlement with Lafourche Medical Group (“LMG”), a Louisiana-based medical group specializing in emergency medicine, occupational medicine, and laboratory testing. The settlement marks the first time that OCR resolved a phishing attack under HIPAA. According to OCR Director Melanie Fontes Rainer, phishing is “the most common way that hackers gain access to health care systems to steal sensitive data and health information.” In March 2021, a staff member of LMG was the victim of a phishing attack that compromised the staff member’s email account containing the electronic protected health information (“PHI” or “ePHI”) of as many as 34,000 patients. LMG reported the incident to OCR in May 2021, and OCR began its investigation in January 2022. After OCR investigated the breach, it determined that LMG had failed to comply with the following basic HIPAA requirements: (i) conducting a risk analysis to determine vulnerabilities to PHI, and (ii) creating and maintaining policies and procedures to regularly review information system activity and to safeguard PHI against cyberattacks. As a result of these findings, LMG entered into a resolution agreement with OCR on November 3, 2023, which requires LMG to pay a $480,000 penalty to OCR and implement a two-year corrective action plan (“CAP”) to address the HIPAA violations identified in OCR’s investigation. As part of the CAP, LMG has agreed to undertake HIPAA compliance activities that are required of health care providers: Establish and implement security measures to reduce security risks and vulnerabilities; Develop, maintain, and revise written policies and procedures as necessary to comply with HIPAA; and Provide training to all staff members who have access to patient PHI on HIPAA policies and procedures. OCR’s report of this first-of-a-kind settlement noted that in 2023 (through November), based on data breaches reported to it, over 89 million individuals had been affected by large data breaches (those involving 500 or more individuals). This was up from 2022, in which over 55 million individuals were affected by these large data breaches. To drive home the significance of OCR’s enforcement action, OCR noted in its press release about the settlement, “Phishing attacks can result in identity theft, financial loss, discrimination, stigma, mental anguish, negative consequences to the reputation, health, or physical safety of the individual or to others identified in the individual’s protected health information.” Lesson learned: Covered entities should regularly update and review the risk analysis and ensure the organization has adopted business grade security measures to protect ePHI. Covered entities should also routinely review and update written HIPAA privacy and security policies and procedures, and, most importantly, deliver frequent staff training to ensure staff remain vigilant and skeptical of any suspicious emails or other contact, and report the emails or other contact immediately to the privacy and security officers. Staff training is a critical line of defense against phishing attacks. Embedded Tracking Technologies- HIPAA Covered Entities and Business Associates Should Carefully Review Their Websites In December 2022, OCR issued a bulletin that warned HIPAA covered entities and business associates against the use of embedded tracking technologies that could track individually-identifiable health information on the covered entities’ or business associates’ websites. OCR defined “tracking technology” as “a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app.” While some covered entities track online user activity internally, many covered entities contract with third-party analytics companies to track and analyze the data about the individual users’ access to and interaction with the covered entity’s website. Common third-parties used to track website use data include: Meta Pixel, Google Analytics and Adobe Analytics. Tracking technologies allow the covered entity to gain insights about users’ online activities for marketing purposes, and to help improve patient experience on the website and to improve patient care, among other reasons. However, the third-parties who track the data are also able to use the data to target ads and to otherwise profile the users. The guidance points out that individually identifiable health information (such as a person’s appointment date, home or email address, or IP address) is “protected health information” that is governed by HIPAA, even if the individual does not have a pre-existing relationship with the covered entity and even if the information does not include sensitive information like treatment information, diagnosis or billing data. As OCR noted in its guidance, the risk that the data being tracked is HIPAA-protected PHI is highest on those portions of a covered entity’s website that have user-authenticated pages (where the individual logs in) because the information on those pages are more likely to include sensitive health information like diagnosis, prescription and other treatment information. OCR’s bulletin warned that the use of individually identifiable health information that is tracked on a covered entity’s website must be in compliance with HIPAA’s privacy and security rules. This means, for example, that any third-party data tracker/analyst who the covered entity engages must have a written business associate agreement in place with the covered entity. Prior to, and after OCR’s bulletin, twenty or more class action lawsuits were filed against hospitals and health systems across the U.S. based on allegations that the hospitals were inappropriately sharing patient data with companies like Google, Facebook, Adobe and others for marketing purposes. Some of the cases have settled and others are ongoing. In response to the OCR bulletin, hospitals and health systems expressed alarm due to the proliferation of the use of website data trackers in use at nearly every hospital in the nation. Some have joined a legal challenge against the OCR bulletin. In November 2023, the American Hospital Association, the Texas Hospital Association and others filed suit against OCR claiming that the OCR bulletin improperly imposes HIPAA restrictions on information that is not “protected health information” as that term is defined under HIPAA. In February 2023, the Federal Trade Commission (“FTC”) began enforcing a lesser-known law called the FTC Health Breach Notification Rule (the “HBN Rule”) against companies that use website-embedded tracking technologies and disclose the data being tracked through these technologies to third-party tracking companies. The HBN Rule applies to non-HIPAA covered entities that are vendors of personal health records (or who are a related entity or service provider of a vendor of personal health records). The HBN Rule requires that a breach notification be filed with the FTC if there is an unauthorized disclosure of personal health information, such as to a third party that has embedded tracking technologies on the company’s website. Under this law, the FTC took enforcement action against well-known companies such as BetterHelp, GoodRx and Premom, requiring the payment of large civil money penalties and requiring that the companies adopt and enforce internal prohibitions on sharing user health data with third parties for advertising purposes. Additionally, the FTC issued industry guidance as a warning to others who use embedded tracking technologies on their websites. In July 2023, the OCR and FTC teamed up and issued a joint letter to 130 hospitals and telehealth providers about the risks and concerns regarding the use of the website tracking technologies, and issued a press release with a general warning to the hospital system and telehealth industry against the use of embedded tracking technologies. Lesson learned: HIPAA covered entities should carefully review their websites to ensure that any third party with embedded tracking technologies has signed a HIPAA-compliant business associate agreement, and to ensure that the use or disclosure of any data gleaned from tracking access to the company website is compliant with the HIPAA privacy rule. See our prior articles on this topic here and here. Rights of Access Initiative- Still a Top Priority for OCR In 2023, the OCR reached several new resolution agreements with entities alleged to have violated patients’ rights to timely access of their medical records. Under HIPAA, covered entities, like health care providers and payors, have a maximum of 30 days (which OCR describes as an “outer limit”) to provide patients with a copy of their medical record upon request. The “Right of Access Initiative” became an enforcement priority for OCR at the end of 2019, in an attempt to address patient complaints about difficulties they encountered in obtaining timely copies of their medical records. In fact, OCR’s final resolution agreement of 2023 in the amount of $80,000 marked OCR’s 46th such settlement in a little over three years. In response to what OCR views as a widespread issue of non-compliance, OCR has published guidance for covered entities’ implementation of this individual HIPPA right to access. Lesson learned: Review and audit the administrative processes your organization has in place for responding to requests for patient records to ensure they meet HIPAA’s requirements. Major Source of Risk: Covered Entity and Business Associate Failure to Conduct Enterprise-Wide Security Risk Analysis In May and June 2023, OCR entered into resolution agreements with two separate business associates who, in similar fact patterns, were found to have lacked a sufficient enterprise-wide risk analysis of their security function, leading to the breach of hundreds of thousands of patient records. In one situation, the business associate provided billing, coding and IT services to health care providers and, through a compromise in the business associate’s systems, the PHI of hundreds of individuals was exfiltrated from an unsecured server by an unauthorized person. In the other situation, a business associate that provides practice management, practice analytics and revenue cycle management services to health care providers inadvertently allowed a file transfer protocol (“FTP”) server containing hundreds of thousands of individuals’ data to be openly accessible on the internet. OCR also cited a covered entity for non-compliance with the risk analysis standard. In February 2023, OCR entered into a resolution agreement with a large health system in order to resolve a data breach impacting 2.81M individuals following a hacking incident. When OCR investigated the incident, it found that the health system lacked a risk analysis to determine the risks and vulnerabilities to its patients’ ePHI. OCR also found a number of important security rule violations that stemmed from the initial failure to conduct risk analyses, including failing to implement an authentication process, failing to monitor the activity of users on the system, and failure to have security measures in place for ePHI that was being transmitted electronically. In September 2023, OCR and the Office of the National Coordinator for Health Information Technology (“ONC”) published an updated version of a do-it-yourself security risk assessment tool, intended for small and medium-sized covered entities. The updated tool is intended to make it easier for covered entities and business associates to assess the security risk to ePHI and to mitigate that risk. Lesson learned: In resolution agreements, OCR routinely cites companies for failing to complete an enterprise-side security rule risk analysis. In fact, this is one of the most common sources of HIPAA violations that lead to subsequent settlement agreements with OCR. The bottom line is that there is no substitute for an enterprise-wide security rule risk analysis. This type of risk analysis should be conducted routinely by covered entities and by their business associates in order to identify and mitigate the security risks to all repositories of electronic PHI. Another lesson that comes out of this pair or resolution agreements in 2023 is that covered entities should carefully vet and audit the HIPAA compliance program and practices of their potential and current business associates. In the end, although business associates have their own liability under HIPAA, the patient data and patient relationships at risk are those of the covered entity served by the business associate. Even Small Breaches Can Result in Liability In 2023, OCR settled two cases that contained fact patterns OCR has addressed in guidance and settlement agreements repeatedly: snooping and social media breaches. Notably, these cases each also involved a small number of patients, and the enforcement actions signal to covered entities and business associates that even small breaches can result in liability. One resolution agreement was with a hospital related to its security staff snooping in patient records. The other resolution agreement was with a physician practice that responded to a negative review on Google in a way that acknowledged the patient relationship and disclosed patient information. Lessons learned: Ongoing staff training regarding impermissible uses and disclosures of patient information is a critical element of a provider’s HIPAA compliance activities. Include basic reminders in HIPAA workforce training through, for example, use of the resolution agreements in the way that OCR intends them to used- as an example for others to help prevent similar conduct in the future. COVID-19 HIPAA Enforcement Discretion Ends and OCR Emphasized its Enforcement Priority and Strategy for Cybersecurity In August 2023, years of HIPAA-related enforcement discretion by OCR related to the COVID-19 pandemic came to an end. The enforcement discretion that OCR exercised throughout the early days of the COVID-19 pandemic related to matters such as the use of non-HIPAA compliant telehealth technologies, and non-HIPAA compliance related to COVID-19 vaccine patient scheduling, public health and health oversight disclosures, and community based testing sites. OCR published notifications and guidance to the public to prepare HIPAA covered entities and business associates for an end to the waiver of enforcement discretion. OCR also announced the development of a new enforcement division at OCR, called the Health Information Privacy, Data and Cybersecurity Division, which will focus on OCR’s work and role in cybersecurity. Additionally, citing a 93% increase in large data breaches due to cybersecurity events between 2018-2022 (with a 278% increase in large breaches involving ransomware), the Department of Health and Human Services published a concept paper outlining the Department’s cybersecurity strategy for health care providers. The strategy calls for new voluntary health care-specific cybersecurity goals; developing incentives and supports with Congress that will be used to help hospitals improve cybersecurity; and strategies for increasing accountability and coordination within the health care sector. Ongoing OCR Regulatory Initiatives- Changes are Coming OCR has introduced several HIPAA regulatory initiatives that are still under consideration by the agency, and many of which may become finalized in 2024. It is important for privacy/security officials and health care counsel to be familiar with the proposed regulations in order to understand OCR’s perspective because that helps in steering internal compliance protocols, training and accountability at the organization: Reproductive Health Care OCR issued a Notice of Proposed Rulemaking (“NPRM”) on April 12, 2023 to prohibit the use or disclosure of PHI to identify, investigate, prosecute, or sue patients, providers, and others involved in the provision of legal reproductive health care, including abortion. The public comment period closed on June 16, 2023 and OCR received over 25,000 comments. A final rule has not yet been published. Substance Use Disorder (“SUD”) Treatment Records In coordination with the Substance Abuse and Mental Health Services Administration (SAMHSA), OCR issued a NPRM on November 28, 2022 to align certain aspects of 42 CFR part 2 (Part 2) with HIPAA. Part 2 protects patient records maintained in connection with substance abuse education prevention, training, treatment, rehabilitation or research in order to ensure privacy for SUD patients. The public comment period closed on January 31, 2023 and OCR received over 200 comments. A final rule has not yet been published. HITECH Request for Information (“RFI”) Regarding Mitigating Security Practices and the Sharing of Monetary Settlements with Individuals Harmed OCR published a RFI on April 6, 2022, seeking public input on portions of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The RFI specifically requests input on: (i) recognized security practices that OCR will consider when determining potential fines, audit results, or other remedies for resolving potential violations of HIPAA; and (ii) the methodology under which an individual harmed by a potential HIPAA violation may receive a percentage of a monetary penalty/settlement collected with respect to such violation. The public comment period closed on June 6, 2022. OCR has yet to announce further action on this RFI. HIPAA Privacy Rule Updates OCR issued a NPRM on January 1, 2021 to modify the HIPAA Privacy Rule to encourage patient engagement in health care, remove barriers to coordinated care, and decrease regulatory burden. The public comment period closed on May 6, 2021 and OCR received over 1,300 comments. A final rule has not yet been published. The proposed new rules, if finalized, would require some significant changes at HIPAA covered entities and business associates, such as: allowing patients to inspect their PHI in person and take notes or photographs of their PHI; changing the maximum time to provide access to PHI from 30 days to 15 days; new rules about costs for records including certain circumstances when ePHI must be provided at no cost, requirements to provide estimates of fees for copies, and requirements to post fee schedules for records access on the website; individuals will be permitted to request that their PHI be transferred to a personal health application or direct ePHI to be send to another covered entity; covered entities will be required to inform individuals that they have the right to obtain or direct copies of their PHI to a third-party when a summary of PHI is offered instead of a copy; the requirement for HIPAA-covered entities to obtain written confirmation that a Notice of Privacy Practices has been provided will be removed; covered entities will be allowed to disclose PHI to avert a threat to health or safety when harm is “seriously and reasonably foreseeable” (as opposed to the current, more stringent standard that only allows such disclosure when harm is “serious and imminent," and expansion of permissible uses and disclosures by covered entities based on care coordination, case management and based on a good faith belief that the disclosure it is in the best interest of the individual. While the pending HIPAA updates are intended to ease the administration burden on HIPAA-covered entities in the long run, there will be a significant short term burden associated with changes to policies and procedures, changes related to notices of privacy practices, changes to medical record access processes and others. The authors will continue to monitor these initiatives for updates and changes in 2024. If you have any questions about HIPAA, cyber-attacks, OCR investigations, or regulatory changes, reach out to your regular Dorsey attorney or to any member of the Dorsey & Whitney LLP Healthcare Transactions and Regulations practice group.
January 3, 2024
by Alissa Smith and Seamus Taylor
Data Privacy and Security
Privacy of Substance Use Disorder Records and The CARES Act: Steps Toward Harmonizing Part 2 Privacy Laws with HIPAA
The recently-enacted Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) is generally known for providing relief funds and other resources to help individuals, small businesses, state and local governments, and hospitals and healthcare providers address the COVID-19 public health emergency. However, among the lesser-known of the CARES Act provisions are changes to federal law that will allow a significant harmonization of rules governing the confidentiality of substance use disorder patient records with the general federal rules governing the privacy of individually identifiable health information (i.e., the HIPAA privacy rules). Currently, a unique set of federal regulations found at 42 C.F.R. Part 2 restrict the disclosure and use of substance use disorder patient records that are maintained in connection with any federally-assisted substance use disorder program. These “Part 2” rules are far stricter than the federal HIPAA privacy rules that apply generally to health plans and health care providers. For example, whereas the HIPAA privacy rules allow health plans and health care providers to use and disclose protected health information (“PHI”) for purposes of treatment, payment, and health care operations without a patient’s written or oral consent, the Part 2 rules do not. Another important distinction between the Part 2 rules and HIPAA is that if a patient authorizes the disclosure of PHI under HIPAA to an entity that is not regulated by HIPAA, then the PHI disclosed to that recipient falls outside the protections of HIPAA. In contrast, when a patient consents to the disclosure of their substance use disorder records under Part 2, the Part 2 rules continue to apply to the records disclosed, even when the recipient is not a regulated Part 2 SUD program. Section 3221 of the CARES Act modifies the statute governing the confidentiality of SUD records in various and important ways. First, a Part 2 SUD program will be allowed to obtain the prior written consent of a patient to use and disclose SUD records for purposes of treatment, payment, and health care operations as permitted by the HIPAA privacy rules. An SUD program will need to obtain that patient consent only once, and the consent will apply to all future uses and disclosures of SUD records until a patient revokes the consent in writing. The statute goes on to state that any information disclosed pursuant to such a consent may then be redisclosed in accordance with the HIPAA regulations. Although not entirely clear, this appears to mean that an entity not regulated by HIPAA that receives SUD records pursuant to a consent may redisclose the records without limitation under either HIPAA or the Part 2 rules. The CARES Act also states explicitly that the HIPAA breach notification provisions apply to SUD records held by a Part 2 program in the same manner that those rules apply to HIPAA covered entities. Furthermore, the CARES Act extends HIPAA’s penalty and enforcement provisions to violations of the Part 2 rules. Although the Department of Health and Human Services (“HHS”) will need to issue regulations to confirm the operation of these enforcement provisions, this appears to mean that the HHS Office for Civil Rights may take on the civil enforcement of the Part 2 rules, in addition to enforcing the HIPAA rules. The primary reason for the historically strict privacy rules applicable to SUD records is to ensure that a patient receiving treatment for a substance use disorder in a Part 2 program is not more vulnerable because of the availability of their patient record than an individual with a substance use disorder who does not seek treatment. In an effort to maintain this public policy goal while at the same time making the Part 2 rules more consistent with the HIPAA rules, the CARES Act enacts a general antidiscrimination provision prohibiting any entity from discriminating against an individual on the basis of information in Part 2 SUD records in: (a) admission, access to, or treatment for health care; (b) hiring, firing, or terms of employment or receipt of worker’s compensation; (c) the sale, rental, or continued rental of housing; (d) access to federal, state, or local courts; or (e) access to, approval of, or maintenance of government social services and benefits. Furthermore, other than as authorized by a court order or consented to by the patient, no SUD records or testimony relaying the information contained in such records, may be disclosed or used in any civil, criminal, administrative, or legislative proceedings conducted by any governmental authority against a patient. The statute mandates that regulations to implement and enforce these CARES Act provisions be issued to facilitate their application to all uses and disclosure of SUD records occurring on or after one (1) year following the enactment of the CARES Act (which would be March 27th, 2021). Once implemented, the CARES Act provisions will be helpful to Part 2 programs, many of which struggle with the complexity of complying with both HIPAA and the Part 2 privacy rules. But the new Part 2 law will by no means alleviate all of that complexity. For example, a Part 2 program will be required to obtain a patient’s written consent in order to use and disclose SUD records for treatment, payment, and health care operations purposes; for those Part 2 program patients that refuse to sign such a consent, the Part 2 program will likely need to segregate those SUD records in order to manage the stricter limitations on their use and disclosure. Moreover, the CARES Act does not harmonize Part 2 and HIPAA entirely; there will remain many uses and disclosures that are permitted under HIPAA but not permitted with regard to SUD records under Part 2. Ultimately the CARES Act provisions modifying the Part 2 confidentiality rules will mitigate, but not eliminate, the complexities of managing patient records regulated by two separate sets of federal privacy rules. If you have questions about the CARES Act, HIPAA, or the Part 2 rules, please contact the author or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
April 22, 2020
by Ross C. D'Emanuele
Data Privacy and Security
A Massive Number of New Health Law Regulatory Proposals as Part of the “Regulatory Sprint to Coordinated Care”: Proposed Changes to the Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP, Privacy Laws Governing Substance Use Disorder Records, and the Stark Law Advisory Opinion Process
Today, the Centers for Medicare & Medicaid Services (CMS) and the Department of Health and Human Services (HHS) Office of Inspector General (OIG) each released their long-anticipated proposed rules to revise the federal self-referral law (or “Stark Law”) regulations, the safe harbors under the federal anti-kickback statute (AKS), and the civil monetary penalty law (CMP) for beneficiary inducements. The proposed rules are part of HHS’s “Regulatory Sprint to Coordinated Care,” which seeks to remove regulatory obstacles to care coordination and a value-based healthcare delivery system. The HHS press release regarding the proposed rules is available here, and includes links to each of the CMS and OIG proposed rules. For our prior posts on the Regulatory Sprint to Coordinated Care, see here and here. Relatedly, the Substance Abuse and Mental Health Services Administration (SAMHSA) published proposed rules to revise privacy rules for substance use disorder records on August 26, and CMS published proposed rules to revise the Stark Law advisory opinion regulations on August 14 (as part of the Medicare Physician Fee Schedule proposed rule). We are reviewing the proposed rules and will post an in-depth analysis shortly.
October 9, 2019
by Alissa Smith and Laura B. Morgan
Data Privacy and Security
CMS "Actively Working" on Stark Law Reforms to be Issued Later this Year; “Regulatory Sprint to Coordinated Care” Continues
The Centers for Medicare & Medicaid Services (CMS) is “actively working” on updates to regulations under the federal physician self-referral law (or “Stark Law”), according to CMS Administrator Seema Verma during a March 4, 2019 speech. Verma stated that the updated regulations will be issued later this year, and “will represent the most significant changes to the Stark law since its inception.” Verma explained in her remarks that the Stark Law, when enacted in 1989, made sense in a fee-for-service context, but as health care transitions to a value-based system where providers take on risk and payment is for outcomes rather than individual services, “we don’t have nearly as much need to interfere with who’s getting paid for what service.” According to Verma, CMS hopes that Stark Law regulatory changes “will help spur better care coordination and help support our work to remove barriers to innovation while continuing to provide appropriate safeguards for our programs.” Verma stated that the updated regulations will include “clarifying the regulatory definitions of volume or value, commercial reasonableness and fair market value; addressing issues such as lack of signature, incorrect dates or other areas of technical noncompliance; and updating the regulation to address a world in which there are cybersecurity and electronic health records requirements.” These Stark Law regulatory reforms are part of the “Regulatory Sprint to Coordinated Care” launched by the Department of Health and Human Services (HHS). Under this initiative, various HHS agencies have issued requests for information (RFIs) to solicit feedback from stakeholders on removing regulatory obstacles to care coordination. CMS published an RFI on June 25, 2018 soliciting comments regarding Stark Law reforms (as we described in our post here), which received 392 comments before the close of the comment period. We anticipate that CMS will summarize and respond to many of the comments that it received in preamble to the proposed Stark Law regulations to be issued later this year, as well as incorporate suggestions from stakeholders in the proposed regulations themselves. Also as part of the Regulatory Sprint, the HHS Office of Inspector General (OIG) published an RFI on August 27, 2018 soliciting comments on reforms to the anti-kickback statute and beneficiary inducements civil monetary penalty (as we described in our post here), which received 359 comments before the close of the comment period. Additionally, the HHS Office for Civil Rights (OCR) published an RFI on December 14, 2018 soliciting comments on reforms to the Health Insurance Portability and Accountability Act (HIPAA) privacy and security regulations, on which the comment period closed last month. The fourth and final area of focus of the Regulatory Sprint (according to an HHS press release) is 42 CFR Part 2, which relates to the confidentiality of substance use disorder patient records. An RFI under the Regulatory Sprint for this regulation has not been published by the Substance Abuse and Mental Health Services Administration (SAMHSA, which is the agency that administers this regulation). We will provide information about regulatory reform developments under these other areas of the Regulatory Sprint as they become available.
March 18, 2019
by Alissa Smith and Laura B. Morgan
Data Privacy and Security
The California Consumer Privacy Act of 2018—Increased Consumer Privacy Protections and Significant Business Compliance Burdens
August 21, 2018
by Joseph Lynyak and Sam Bolstad
Data Privacy and Security
HIMMS, Chronic Care Management, and the Top 5 Overlooked Items
Harnessing existing digital health solutions to improve chronic care management was a prominent topic at HIMMS this year (amongst many others, including AI and cybersecurity, both of which we will cover in upcoming blog posts). While this is not a new topic, it was particularly “buzzy” this year due to the ever-increasing number of large technology and wearables vendors entering the healthcare space, and as medical device manufacturers look to pair services with their existing devices. Chronic care management, as its name denotes, involves higher-touch and ongoing communication between the patient and the provider. Since digital health solutions are a cost-effective means to connect patients and providers, and because providers can use them to reach patients at home to help correct behaviors that contribute to or ameliorate chronic conditions, digital health solutions hold great promise as an effective chronic care management tool – and, indeed, as HIMMS this year made apparent, digital health solutions are poised for exponential growth. As with any relatively new field, however, we have noticed that certain key issues tend to be overlooked, often at great cost. Here are the top 5 overlooked issues we have noted: Value proposition in a crowded market: Make no mistake about it: this is a crowded market with many different types of vendors hoping to launch the next big thing in digital chronic care management solutions. So many of the pitch decks and conversations we have been privileged to be a part of tend to focus on the market size in terms of clinical need: that there are X number of patients with Y chronic condition who would welcome Z solution. The mistake, however, is presuming that this suffices to capture attention. The barrier to market entry is relatively low (FDA considerations, if applicable, notwithstanding!), and the customers – providers and patients – are relatively wary of yet another device, application, or website to manage. Investors and customers alike will ask, what, specifically, is your digital health chronic care solution’s real value proposition; what truly differentiates you? Effectively managing a chronic condition is the baseline minimum expectation. You must offer something more. EHR integration – the how and where: Many sellers of digital health chronic care solutions tout the ability of the device or software program to integrate with a provider’s EHR and/or with a patient-facing application so that providers and patients can monitor the relevant condition. This is all to the good, as transparent, real-time results are a key facet of chronic care management. The item that is missed, however, is how that information will be displayed in the EHR; where, exactly, will it appear? Is that in readable and, importantly, reportable format for the providers? It does a provider little good if a blood viscosity result appears in the EHR as a pdf attachment that is not searchable as a discrete data element. It is important to ask vendors and potential partners this at the outset, and to obtain the answer in writing. Process flow: Providers and medical device manufacturers alike are doing a good job of convening clinical experts to discuss particular care needs and associated care management regimen. This is then translated into the digital health offering. What is missed, however, is thinking through the end-to-end process between provider, patient, and both their interactions with the software, to ensure that it’s as seamless and hassle-free as possible. Patients who would be, well, patient with a clinician who is taking a few extra moments to answer a question would not necessarily be as patient with extra clicks or wait time from a digital health program. Providers, in turn, are looking for the least amount of clicks to enable them to do what they do best: offer the patients helpful advice. Mapping out the exact flow of when and how the software – and any integrated devices – will behave, and who is required to do what, is critical. Data ownership and access: While vendors – medical device and software and analytics alike – race to develop in-house chronic-care solutions, many are looking to partner with providers to provide clinical input and data and to serve as a beta testing and initial customer site. Partnerships are proliferating, and while good attention is paid in the negotiating process to the typical business terms, we have noted that data flow, ownership, and access tends to be a secondary thought. To be clear, HIPAA, privacy, and cybersecurity are still at the front of everyone’s minds; however, the operational brass tacks of exactly what data will display where, which party will provide that data, and exactly who will access the data and its derivatives is still oft-overlooked. Just as we recommend process flows from the user-end perspective (see above point), we also have found that data maps are instrumental to a successful partnership. If you have created one for your organization for cybersecurity and breach incident response, you will find that to be a useful starting point; you will then want to discuss and create a new, macro-level flow that reflects the flow across the parties. Then, check with counsel, and ensure that the relevant contracts (e.g., partnership, services, and/or BAA agreement(s)) align with that data map. Licensure – you probably need it: “Chronic care management” encompasses so many conditions that it can, at times, be used as a marketing lure to sell wellness-related devices and services. Any company that considers itself in the “wellness” sphere and employing people to provide ongoing advice – whether by phone, video, e-mail, or other means – should make a point to check with counsel as to whether professional licensure is required. It does not matter what label you give to those employees (e.g., “coach” vs. “counselor,” or “care guide” vs. “RN”), rather, it matters what type of care is being offered through the digital health solution and what condition(s) it is addressing. A digital health solution that addresses a specific clinical condition is likely one that is regulated, which means that the employees interacting with the patient are also likely to need some form of relevant licensure. This one is a mission-critical ask, so be sure to check with counsel early on (and title your employees correctly on your website and sales materials). We welcome your suggestions for additional focus topics within this series on digital health-related issues. Please contact Shira Hauschen at Hauschen.Shira@Dorsey.com with any comments, suggestions, or questions.
March 20, 2018
by Shira Hauschen
Data Privacy and Security
Cybersecurity Task Force Issues Report on Improving Cybersecurity in the Health Care Industry
The Cybersecurity Act of 2015 established the Health Care Industry Cybersecurity Task Force to respond to severe cyber-attacks within the rapidly-expanding information technology (“IT”) aspect of health care. Section 405(c) of the Act required the Task Force to research and develop a report summarizing the vulnerabilities in health care IT. On June 2nd, 2017, the Task Force released its Report on Improving Cybersecurity in the Health Care Industry. The Report is sobering, and finds that health care cybersecurity is in critical condition. The Report outlines six recommendations to improve cybersecurity in the health care industry: Define and streamline leadership, governance, and expectations for health care industry cybersecurity. Increase the security and resilience of medical devices and health IT. Develop the health care workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities. Increase health care industry readiness through improved cybersecurity awareness and education. Identify mechanisms to protect R&D efforts and intellectual property from attacks or exposure. Improve information sharing of industry threats, risks, and mitigations. These six recommendations recognize the need to assess cybersecurity at the industry level in order to better protect patient care and security. To use a cliché, health care cybersecurity will only be as strong as the weakest link in the industry. However, not every health care entity has similar resources. So, while the recommendations call for improvements and updates to guidance, regulations, and laws that affect health care cybersecurity, they do so in a way that recognizes the need for flexibility in the health care industry. For example, the first recommendation calls federal legislation “confusing” and “conflicting” and asks for a unified regulatory framework that untangles the current mess. In addition, the recommendations illustrate that the growing sophistication of health care IT demands a broader cybersecurity approach than previously required. The cybersecurity concern no longer rests with only protected health information at the provider level. Now, cybersecurity needs to branch out and include, for example, medical device developers. Improving patient care is clearly a central goal, and the Report speaks to that objective by highlighting problem areas with a direct connection to patient care outcomes. The Report also recognizes that the health care industry is a mosaic of large systems, private practices, payers, and developers where a one-size-fits-all approach is not conducive to progress. As such, this Report may trigger a cybersecurity-themed review of various regulatory areas that takes into account both patient care needs and variations in health care entity resources. Summer Associate Randall Hanson provided substantial assistance with the drafting of this blog post.
June 19, 2017
by Ross C. D'Emanuele