HHS Office for Civil Rights
The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules
Today, the Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) which proposes significant changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule (the “Privacy Rule”). The NPRM includes numerous changes to the Privacy Rule that are part of HHS’ Regulatory Sprint to Coordinated Care which is intended to eliminate administrative barriers to a health care delivery system that fosters care coordination and value-based care for patients. OCR also issued a fact sheet about this NPRM, which is available here. This NPRM comes nearly two years after OCR issued a Request for Information (“RFI”) in December 2018 calling for information from the public regarding ways that HIPAA regulations could be modernized to support coordinated, value-based care. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived HIPAA violations or a lack of regulatory certainty. Clarifications to existing regulations will impact stakeholders beyond their involvement in care coordination arrangements. The changes will also impact data sharing arrangements and reduce unnecessary administrative burdens on health care providers and health plans, such as eliminating the requirement to obtain an individual’s signature for the Notice of Privacy Practices (“NPP”) or the requirement to retain copies of the NPP for six years. Further, the proposed changes to the Privacy Rule provide clarification to the laws governing patient rights of access to their health records, and help to better facilitate disclosures of health information in order to improve care for patients in emergencies or who are experiencing a health crisis, including mental health crises and opioid overdose situations. Comments to the NPRM are invited from stakeholders, and will be due some time in February 2021, at a date that is 60 days after the NPRM is published in the Federal Register. Please contact the author of this post or your regular Dorsey attorney if you have questions about how these changes to the Privacy Rule could impact you, and for assistance in submitting comments to the OCR. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis on Dorsey’s Health Law Blog and on Dorsey’s Regulatory Sprint Webpage as new information becomes available.
December 10, 2020
by Alissa Smith
HHS Office for Civil Rights
2020’s a Bust, but HIPAA Enforcement Is on a Roll!
The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has been actively enforcing HIPAA regulations this year, including a series of seven settlements under OCR’s Right of Access Initiative to enforce patients’ rights to timely access their medical records at a reasonable cost. This year, OCR has recorded more than $12.2 million in resolution agreements. This post summarizes OCR’s settlements in 2020 to date. The OCR settlements have impacted a wide range of sectors in the health industry from health insurers, to hospital systems, physician clinics, FQHCs, mental health and substance abuse providers, business associates, and nonprofits serving those with AIDS/HIV. Enforcement has been taken against all sizes of entities, including against solo practitioners and very small non-profits. As with nearly all settlements with OCR, it was the initial breach notification that triggered the investigation. However, the settlement ultimately resulted after OCR’s investigation discovered widespread non-compliance with HIPAA’s privacy and security requirements. The following post provides a summary of these enforcement actions, and begins with an update about Anthem’s recent $39.5M settlement with 43 states and D.C. stemming from its massive data breach in 2014-2015, which resulted in a record $16 million settlement with OCR in 2018. Health Insurer Enforcement Anthem and 43-State Coalition Reach $39.5 Million Settlement Over Data Breach On September 30, 2020, state attorneys general in 43 states and Washington D.C. announced that they had reached a $39.5 million settlement with Anthem Inc., an Indianapolis, IN-based health insurer. This settlement stemmed from an investigation by the state attorneys general into the largest health data breach in history, a series of state-sponsored cyberattacks in December 2014 and January 2015 that exposed the ePHI of nearly 79 million individuals. In 2018, Anthem agreed to pay $16 million to OCR and to take substantial corrective action to settle potential violations of the HIPAA privacy and security rules related to the 2014 data breach. See the HHS press release about the OCR settlement here. Anthem has also paid $115 million to settle a class action related to the breach, the largest-ever class action settlement related to a data breach. Premera Blue Cross Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People In March, in the second-largest HIPAA settlement ever, Premera Blue Cross (PBC), the largest health plan in the Pacific Northwest, agreed to pay $6.85 to OCR and to implement a corrective action plan to settle potential HIPAA privacy and security rules violations related to a data breach. Using malware installed through a phishing email, cyber-attackers gained access to PBC’s system in August 2014 and went undetected until January 2015, resulting in the exposure of over 10.4 million individuals’ electronic protected health information (ePHI). OCR’s investigation determined that PBC had “systemic noncompliance with the HIPAA Rules including failure to conduct an enterprise-wide risk analysis, and failures to implement risk management, and audit controls.” See the HHS press release here. Hospital and Health System Enforcement Lifespan Pays $1.04 Million to Settle Unencrypted Stolen Laptop Breach Affecting Over 20,000 People In June, Lifespan Health System Affiliated Covered Entity (“Lifespan ACE”), a Rhode Island-based non-profit health system, agreed to pay a $1.04 million settlement to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA privacy and security rules related to the theft of a hospital employee’s unencrypted laptop. The laptop contained the ePHI of more than 20,000 individuals. OCR’s investigation determined that there had been systematic noncompliance with the HIPAA Rules, including a failure to encrypt ePHI on laptops, a lack of device and media controls, and a failure to have a business associate agreement in place with the Lifespan Corporation, the parent company and business associate of Lifespan ACE. See the HHS press release here. Physician and Clinic Enforcement Solo Practice Pays $100,000 for Failing to Implement HIPAA Security Rule Requirements In February, Steven A. Porter, M.D., a Utah gastroenterologist and solo practitioner, agreed to pay $100,000 to OCR and to adopt a corrective action plan to settle a potential violation of the HIPAA security rule. OCR determined that Dr. Porter’s practice had demonstrated significant noncompliance with the HIPAA rules, specifically, failing to conduct any risk analysis and failing “to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” See the HHS press release here. Orthopedic Clinic Pays $1.5 Million to Settle Systemic Noncompliance with HIPAA Privacy and Security Rules In July, Georgia-based Athens Orthopedic Clinic PA (“Athens Orthopedic”) agreed to pay $1.5 million to OCR and to implement a corrective action plan to settle potential violations of the HIPAA privacy and security rules. A hacker used a vendor’s credentials to access Athens Orthopedic’s electronic medical record system and exfiltrated patient health data, then demanded money from Athens Orthopedic in return for the return of the stolen records. Nearly 210,000 individuals were affected by the breach. OCR’s investigation found noncompliance with the HIPAA privacy and security rules, including “failures to conduct a risk analysis, implement risk management and audit controls, maintain HIPAA policies and procedures, secure business associate agreements with multiple business associates, and provide HIPAA Privacy Rule training to workforce members.” See the HHS press release here. FQHC Pays $25,000 for Failing to Implement HIPAA Security Rule Requirements In March, Metropolitan Community Health Services (“Metro”), doing business as Agape Health Services, agreed to pay $25,000 to OCR and to implement a corrective plan to settle potential violations of the HIPAA security rule. In 2011, Metro reported impermissible disclosure of PHI to an unknown email account, which affected over 1,200 patients. OCR’s investigation found that Metro had failed to conduct any risk analysis, failed to implement any HIPAA security rule policies and procedures, and not provided workforce members with security awareness training until 2016. Metro is a Federally Qualified Health Center that provides medical services in underserved areas in rural North Carolina on a sliding fee scale, which was taken into account in reaching this agreement. See the HHS press release here. Business Associate Enforcement CHSPSC Agrees to Pay $2.3 Million to Settle Data Breach Affecting Over 6 Million People In March, CHSPSC LLC (“CHSPSC”) agreed to pay $2.3 million and to adopt a corrective action plan to settle potential violation of the HIPAA privacy and security rules related to a breach affecting more than 6 million people. CHSPSC is based in Tennessee and provides a variety of business associate services, including IT and health information management. In 2014, the Federal Bureau of Investigation (FBI) notified CHSPSC that it had traced a cyber-attack to CHSPSC’s information system. OCR’s subsequent investigation found “longstanding, systematic noncompliance” with the HIPAA security rule, including “failure to conduct a risk analysis, and failures to implement information system activity review, security incident procedures, or access controls.” See the HHS press release here. Right of Access Initiative Enforcement In 2019, OCR announced the Right of Access Initiative as an enforcement priority to support individuals’ right to timely access to their health records at a reasonable cost and in the readily producible format of their choice under the HIPAA privacy rule’s right of access provision, 45 CFR § 164.524. The HIPAA Rules generally require covered health care providers to provide medical records within 30 days of the request and providers can only charge a reasonable cost-based fee. This right to patient records extends to parents seeking access to their minor children’s medical records. To date this year, OCR has completed seven enforcement actions totaling $396,500 in settlement payments under the Right of Access Initiative, bringing the total number of enforcement settlements under this initiative to nine. In June, Housing Works Inc. (Housing Works), a New York City-based non-profit organization providing a range of services to individuals living with and affected by HIV/AIDS, including health care, agreed to pay $38,000 to OCR and to take corrective actions to settle a potential right of access violation. In complaints filed with OCR in July and August 2019, a patient alleged that he had not received his records in response to a June 2019 request. OCR opened an investigation, found a possible violation, and the patient received his medical records in November 2019. In July, All Inclusive Medical Services (AIMS), a California-based multi-specialty family medicine clinic, has agreed to pay $15,000 to OCR and to adopt a corrective action plan to settle a potential right of access violation. A patient alleged that in January 2018, AIMS had denied her requests to inspect and receive a copy of her records, in an April 2018 complaint filed with OCR. The patient ultimately received her medical records in August 2020. In August, Beth Israel Lahey Health Behavioral Services (BILHBS), the largest network of mental health and substance use disorder services in eastern Massachusetts, agreed to pay $70,000 to OCR and to take corrective actions following a potential right of access violation. A personal representative filed a complaint with OCR in April 2019 alleging that she had requested her father’s medical records in February 2019 and BILHBS had failed to provide them. BILHBS provided the requested medical records in October 2019. In August, Patricia King, M.D. (King MD), a small provider of psychiatric services in Virginia, agreed to pay $3,500 to OCR and to adopt a corrective action plan to settle a potential right of access violation. OCR received a complaint from a patient in October 2018, alleging that King MD failed to respond to her August 2018 request for her medical records. After OCR provided King MD with technical assistance on right of access requirements, a second complaint, and an OCR investigation that found that the failure to provide the requested medical records was a potential violation, the patient received her medical records in July 2020. In August, Wise Psychiatry, PC (Wise Psychiatry) a small provider of psychiatric services in Colorado, agreed to pay $10,000 to OCR and to take corrective actions to settle a potential right of access violation. A father requested his minor son’s medical records in November 2017, and following two complaints to OCR, OCR providing technical assistance to Wise Psychiatry on the HIPAA right of access requirements, and OCR opening an investigation, Wise Psychiatry sent the requested medical records in May 2019. See HHS’s press release about OCR’s first five right to access settlements of 2020 here. In September, Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), agreed to pay $160,000 and to adopt a corrective action plan to settle a potential right of access violation. SJHMC is based in Arizona and is a large, acute-care hospital with several hospital-based clinics. A mother made several requests for her son’s medical records, as his personal representative, beginning in January 2018, but did not receive all of the requested records until December 2019. See the HHS press release here. In September, NY Spine Medicine (NY Spine), a private medical practice specializing in neurology and pain management with offices in New York and Florida, agreed to pay $100,000 and to take corrective actions to settle a potential right of access violation. A patient requested a copy of her medical records in June 2019, and NY Spine provided some records in response, but did not provide the diagnostic films that the patient had specifically requested until October 2020, after OCR had initiated an investigation. See the HHS press release here. OCR’s enforcement of the HIPAA security and privacy rules this year is increasingly aggressive. Per HHS, OCR’s enforcement actions are “designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.” If you have questions about HIPAA compliance, please contact the authors, your regular Dorsey attorney or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
October 15, 2020
by Alissa Smith and Elizabeth Greiter
HHS Office for Civil Rights
CMS "Actively Working" on Stark Law Reforms to be Issued Later this Year; “Regulatory Sprint to Coordinated Care” Continues
The Centers for Medicare & Medicaid Services (CMS) is “actively working” on updates to regulations under the federal physician self-referral law (or “Stark Law”), according to CMS Administrator Seema Verma during a March 4, 2019 speech. Verma stated that the updated regulations will be issued later this year, and “will represent the most significant changes to the Stark law since its inception.” Verma explained in her remarks that the Stark Law, when enacted in 1989, made sense in a fee-for-service context, but as health care transitions to a value-based system where providers take on risk and payment is for outcomes rather than individual services, “we don’t have nearly as much need to interfere with who’s getting paid for what service.” According to Verma, CMS hopes that Stark Law regulatory changes “will help spur better care coordination and help support our work to remove barriers to innovation while continuing to provide appropriate safeguards for our programs.” Verma stated that the updated regulations will include “clarifying the regulatory definitions of volume or value, commercial reasonableness and fair market value; addressing issues such as lack of signature, incorrect dates or other areas of technical noncompliance; and updating the regulation to address a world in which there are cybersecurity and electronic health records requirements.” These Stark Law regulatory reforms are part of the “Regulatory Sprint to Coordinated Care” launched by the Department of Health and Human Services (HHS). Under this initiative, various HHS agencies have issued requests for information (RFIs) to solicit feedback from stakeholders on removing regulatory obstacles to care coordination. CMS published an RFI on June 25, 2018 soliciting comments regarding Stark Law reforms (as we described in our post here), which received 392 comments before the close of the comment period. We anticipate that CMS will summarize and respond to many of the comments that it received in preamble to the proposed Stark Law regulations to be issued later this year, as well as incorporate suggestions from stakeholders in the proposed regulations themselves. Also as part of the Regulatory Sprint, the HHS Office of Inspector General (OIG) published an RFI on August 27, 2018 soliciting comments on reforms to the anti-kickback statute and beneficiary inducements civil monetary penalty (as we described in our post here), which received 359 comments before the close of the comment period. Additionally, the HHS Office for Civil Rights (OCR) published an RFI on December 14, 2018 soliciting comments on reforms to the Health Insurance Portability and Accountability Act (HIPAA) privacy and security regulations, on which the comment period closed last month. The fourth and final area of focus of the Regulatory Sprint (according to an HHS press release) is 42 CFR Part 2, which relates to the confidentiality of substance use disorder patient records. An RFI under the Regulatory Sprint for this regulation has not been published by the Substance Abuse and Mental Health Services Administration (SAMHSA, which is the agency that administers this regulation). We will provide information about regulatory reform developments under these other areas of the Regulatory Sprint as they become available.
March 18, 2019
by Alissa Smith and Laura B. Morgan
HHS Office for Civil Rights
How HHS’s New Division in the Office for Civil Rights Will Enforce Rights of Conscience and Religious Freedom
When the U.S. Department of Health and Human Services (“HHS”) announced a new Conscience and Religious Freedom Division in the HHS Office for Civil Rights (“OCR”), it framed a problem and a solution. The press release stated that “fundamental and unalienable rights of conscience and religious freedom” are not being fully enforced on a federal level, and that as part of President Trump’s promise to uphold such rights a new division in OCR will be tasked with vigorous and effective enforcement.[1] What was less immediately clear in the announcement was how the new division of OCR will improve enforcement of conscience and religious freedom rights. Here we provide an overview of the history and cites to various laws in the conscience and religious freedom space that OCR may use for enforcement, as well as a summary of the recent proposed regulations that OCR issued on this topic on January 26, 2018 Religious Discrimination Against Federal Healthcare Beneficiaries The new OCR division cites several laws prohibiting discrimination against recipients of HHS assistance on the basis of religion. OCR enforces the following: Section 508 of the Social Security Act, for the Maternal and Child Health Services Block Grant Section 533 of the Public Health Services Act, for the Projects for Assistance in Transition from Homelessness Section 1908 of the Public Health Service Act, for the Preventive Health and Health Services Block Grants Section 1947 of the Public Health Service Act, for the Community Mental Health Services Block Grant and the Substance Abuse Prevention and Treatment Block Grants The Family Violence Prevention and Services Act, for programs, services and activities under the Act The Communications Act of 1934, for federally-funded public telecommunication entities[2] Existing Conscience Laws Since the 1970s, several statutes have been enacted that protect the rights of providers, entities and beneficiaries of federal health care programs to object in a variety of ways to certain health care services. OCR reviews complaints under these laws and can take action to enforce them. In its recently proposed rule, OCR details several laws it intends to enforce.[3] Some of the earliest conscience protections, which are called the “Church Amendments”, prohibit a person from being required to perform abortions or sterilizations if contrary to his or her religious or moral beliefs. Entities are provided similar protection. Discrimination in employment of physicians and other personnel, and in residency and internship programs based on a person’s religious or moral beliefs regarding abortion and sterilization is also prohibited. The Church Amendments apply to grants, contracts, loans and loan guarantees under the Public Health Service Act and in some instances, under the Developmental Disabilities Assistance and Bill of Rights Act.[4] The Coats-Snowe Amendment extends abortion-related nondiscrimination provisions to federal, state and local governments receiving federal financial assistance. It protects conscience rights of entities, which includes physicians, physician trainees and residents.[5] The Weldon Amendment attached to an HHS appropriation bill similarly prohibits funds going to any government, agency or program that requires individuals or entities to provide, pay for, cover, or refer for abortions.[6] The Consolidated Appropriations Act of 2017 expands Weldon Amendment protections to the Medicare Advantage program.[7] The Affordable Care Act includes a variety of conscience protections related to assisted suicide, abortion, and the individual mandate to carry insurance.[8] Revised Conscience Rule In January 2018, OCR announced a proposed rule to strengthen conscience-based protections for individuals and entities with objections to certain activities based on religious belief and moral convictions.[9] The proposed rule is not entirely new, however. It would make significant changes to 45 CFR part 88 (entitled: “ENSURING THAT DEPARTMENT OF HEALTH AND HUMAN SERVICES FUNDS DO NOT SUPPORT COERCIVE OR DISCIMINATORY POLICIES OR PRACTICES IN VIOLATION OF FEDERAL LAW”), which stems originally from a 2008 Bush-era rule.[10] The Bush-era rule was itself revised substantially in 2011 during the Obama administration.[11] OCR now proposes to return much of 45 CFR part 88 to its 2008 Bush-era form, adding a requirement that certain recipients of HHS funds certify they comply with conscience protection laws and notify individuals of their rights thereunder.[12] The proposed rule details OCR’s enhanced investigative and enforcement abilities and expands its enforcement authority to more conscience-protection laws than the 2008 or 2011 iterations.[13] The rulemaking states that OCR will “handle complaints [both formal and not], perform compliance reviews, investigate, and seek appropriate action,” including terminating funding and requiring repayment.[14] OCR states that a more centralized approach to enforcement of conscience protections is necessary in part due to rapidly rising complaints. OCR notes that ten conscience-related complaints were filed from implementation of 45 CFR part 88 in 2008 until the November 2016 presidential election.[15] However, since President Trump’s election, thirty-four complaints have been filed.[16] We will continue to monitor the development of this rule as it proceeds through the rulemaking process. [1] https://www.hhs.gov/about/news/2018/01/18/hhs-ocr-announces-new-conscience-and-religious-freedom-division.html [2] https://www.hhs.gov/conscience/religious-freedom/index.html [3] 83 Fed. Reg. 3880. [4] Id. at 3882. [5] Id. at 3882-83. [6] Id. at 3883. [7] Id. [8] Id. [9] https://www.hhs.gov/about/news/2018/01/19/hhs-takes-major-actions-protect-conscience-rights-and-life.html [10] 83 Fed. Reg. at 3885. [11] Id. [12] Id. at 3891. [13] Id. [14] Id. at 3899. [15] Id. at 3886. [16] Id.
February 7, 2018
by Alissa Smith and Aaron Mohr