Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Sunday, May 18, 2014

Why you should not sign everything put in front of you: HIPAA Business Associate Agreements

courtesy of backstage.com

The Health Insurance Portability and Accountability Act of 1996 and its subsequent amendments ("HIPAA") includes the contractual arrangements between Covered Entities and Business Associates, and now downstream Business Associates, or subcontractors (under the Health Information Technology for Economic and Clinical Health Act "HITECH").

This entry presumes the reader has a basic knowledge of HIPAA, but if not, please see the above link for HIPAA.

Today, we look at the evolving and complicated nature of Business Associate Agreements ("BAAs"). These are the agreements mandated by HIPAA, and now HITECH, although the recent amendments and the preamble make clear that the requirements of HIPAA and the HITECH Act apply to a Subcontractor regardless of whether the Business Associate fails to enter into a contract with the Subcontractor. This is very important below when we cover some of the complications.

First:
HIPAA requires certain provisions to be covered in BAAs. Often, the Covered Entity will put in additional provisions, usually around indemnity, audits, breach notification timelines, and data protection minimums not required by HIPAA, such as encryption.  These provisions are unduly burdensome, especially given the characteristics of most Business Associates - small operations. It is understandable why an entity would want to put these protections in place, but it may may stifle the ability to outsource and place a strain on relationships.

Second:
It is understandable why the government wants to reach further than Covered Entities and have direct oversight of Business Associates. Think about it, Dr. Jones on the neighborhood corner may not have the wherewithal to properly secure data or to respond to breaches. Or given that the new provisions provide for the State Attorneys General to bring civil actions on behalf of state residents for HIPAA violations, for damages or to enjoin further violations. I once had a privacy attorney argue with me via email (which cc'd numerous colleagues) that HIPAA as amended by HITECH absolutely did not provide for a private right of action. Well, duh - but given that the states can now do so on behalf of its citizens...it is practically the same thing. But I understand, in the law, one must be precise.

Third:
Large organizations that are now clearly defined as Business Associates, according to the guidance issued with the final rules, at first stated they would not sign BAAs. Remember above, where the new rules provide for liability whether a BAA is signed or not...?  Well, their refusal did not last long. See a discussion about Amazon Web Services here. What large providers who do not wish to be rolled under HIPAA have done, is placed administrative requirements on the Covered Entities or Business Associates which use their services, such as list all accounts for which they have patient data. Many organizations are unable to fulfill these requirements. So what is the solution - sign something they cannot fulfill or don't sign and HIPAA applies anyway. This is yet to be tested, but it is a popular conundrum.

Organizations should be careful about signing any old BAA placed in front of them. Watch your salespeople, too. They are likely presented individual BAAs when they show -  either the BAA does not apply or the employees are committing the company to a BAA without proper review. And this can be costly given the additional items that are in a BAA as discussed above.  And how can an organization signing tens or hundreds of BAAs possibly manage to push all the same provisions to downstream vendors? They conflict with each other - and Covered Entities need to understand that with the additions of clauses that are not required by HIPAA, they are setting their Business Associates up for failure.

Last, many small business owners that are Covered Entities do not understand HIPAA completely. Heck, neither do I. After a professional conference, Business Associates or potential Business Associates will be deluged with requests to sign BAAs. Sometimes, the exact same template is used, including with various clauses that include internal directions such as [choose one of the two clauses below]. It can be frustrating on all sides. Most individuals, however, are just trying to do the right thing. If a Covered Entity wants an organization to sign a BAA and the relationship does not exist, the organization can easily respond with a tight explanation. If still pushed, adding a line such as "This agreement only applies where the organization acts in the capacity of a Business Associate under HIPAA" will generally satisfy the needs of both sides. This is another untested, yet relatively popular strategy.

The conclusion here is that you should not sign everything put in front of you - or your employees. Educate all individuals to send the BAAs to a central office. Push back, or scale back, non-HIPAA provisions. It will be interesting to see how these natural conflicts play out in the next few years.



Thursday, April 10, 2014

Privacy: Don't let it go (our take on the ubiquitous song)

Information is shared around the world today
With a few data laws to be seen
One might wish for regulation
So do I, the Privacy Queen

Companies collect data like a swirling storm inside
Couldn’t keep them straight, heaven knows we’ve tried

Don’t let them in, don’t let them see
Be the private person you always want to be
Conceal, don’t reveal, don’t let them know
How much do they know?

Don’t let it go, don’t let it go
We can stop it furthermore
Don’t let it go, don’t let it go
Block cookies and slam the door

Someone should care
What they’re going to say
The argument rages on
Cause breaches don’t bother them anyway

It’s great how some countries protect personal data by law
And the companies that once controlled it can’t get to it at all

It’s time to see what we can do
To test the limits and break through
Do right, not wrong, pass data laws
For all

Don’t let it go, don’t let it go
Pass some laws and rules
Don’t let it go, don’t let it go
Scrap those data tools

Take a stand, the data stays
Let your rights rage on

Big data flurries through the web and into the ground
Information spirals in millions of bits all around
And one thought crystallizes like an icy blast
Data is rarely deleted – the past is never past

Don’t let it go, don’t let it go
New uses rise like the breaking of the dawn
Don’t let it go, don’t let it go
Once given, that data’s gone

Take a stand
In this big data reign
Should data brokers rage on?
Privacy never stopped them anyway



Saturday, February 15, 2014

HIPAA encounters of the Personal Kind

I wish today's post to be light-hearted, but realize in the end, there may be some lessons learned....be careful. You, too, may become conscious of your own privacy.

My cell phone rang the other day and I answered it "hello."  What follows is the gist of the conversation. I could be partially wrong in the exact wording, but the meaning remains the same. I have changed Paul's name to protect the unknowing.

K: Hello
Bob: Hi. I'm calling to speak with K Royal about an emergency room visit to blah blah hospital on this past Saturday on February 8.
(please note - at this point, he has disclosed my protected health information if someone other than me had answered the phone).
K: this is K.
B: Hi, this is Bob, an RN at blah blah hospital. Before I go any further, I need to confirm your identity to maintain confidentiality. What is your date of birth?
K: (really?! you've already blown it, mister) Hi Bob, can you confirm your identity to me before I provide you with my date of birth?
B: Uh, no. 
K: So there is nothing you can do, at all, to prove you are calling from the hospital? (I was expecting him to say - sure, call the hospital and ask for me or my extension)
B: No. can't think of anything. I just want your date of birth.
K: Okay, let's try this - tell me if you are calling to survey me on how well your service was or if you want to discuss something of a medical nature.
B: Ma'am, I can't tell you that. It violates HIPAA.
K: Actually, it does not. I am not asking you to give me any personal or protected information. I am just asking for the general nature of your call.
B: Ma'am that does violate HIPAA. HIPAA won't let me tell you the purpose of my call. 
K: Bob, I am a privacy attorney and very familiar with HIPAA, I can assure you that it does not. How about this...are you calling to survey me about your service? cause if you are, it was fabulous and I felt everything went smoothly. 
B: Ma'am, I cannot answer that question because it would violate HIPAA. And if you won't give me your date of birth, we seem to have a problem. I know HIPAA very well - and it won't let me continue without it.
K: Bob, I actually seem to know HIPAA better than you do ... at least in this instance ... because HIPAA would not stop you from answering that question. 
B: So what do you want to do?
K: I guess we're at an impasse, Bob. You cannot verify who you are or where you are calling from, you want me to provide you with even further personal information, and you won't tell me the purpose of your call. Sooooo, I think we're done here - and I truly hope you were not calling to tell me something popped up on the tests and I am dying. Feel free to call me back when you either learn more about what you can say under HIPAA or can provide verification of who you are. Have a good afternoon. Bye bye.

I called the privacy officer and left a message to call me. Nothing.

So what did we learn here (other than stupid stuff like this brings out my snarky side)?
1) It is a HIPAA violation for a covered entity to give out information before verifying the patient's identity - as in his opening statement.
2) When people ask for personal information, verify who they are.
3) Not all health care personnel in the US really know and understand HIPAA rules.
4) Patients need to be vigilant about their health care AND their personal information.

Saturday, February 1, 2014

What is a Privacy Counsel, anyway?

My name is K and I am a privacy counsel.

Most of the time when people ask what I do, they have no clue when I say "I am a privacy counsel." Confession time, I usually only say I'm an attorney, but sometimes they want to know what I practice. I don't practice. I am in-house. For those that don't know, in-house means that I am not with a law firm and do not take clients. I work for a company as an employee. The company is my client.

And given that I blog about privacy, I have to always disclaim that my views are not those of my employer.

But back to the question, what is a privacy counsel anyway? If I said I was an employment counsel or IP counsel, people would not be confused. I work in privacy. That is what is confusing, because people in the U.S. don't get privacy and I'm a dork.

Working in Silicon Valley does make for a little more acceptance. With the number of global companies here, they all pretty much have people doing what I do. It's kinda cool. There are lots of other privacy counsels.

Okay, Okay - back to the question. It means I make sure that the laws of the nations who have privacy laws are followed. Every other country who has privacy laws at all approach privacy vastly different than does the U.S.  We look at data on a sectoral level - health care, education, financial. There is no national privacy law in the U.S. and no national protections for general data on individuals. The states are a little different. 46 states have data breach laws - and they have many commonalities and some differences. The strongest data protection laws are in California, Texas, and Massachusetts. 

So in the U.S., I make sure we abide by sectoral laws and state laws. Globally, I deal with the laws of the European Union (28 or so different sets of law for the various countries, if you include the EEA 30 or so), APAC, Canada, Mexico, etc. etc. And I love it.

As stated above, I love privacy law. I caution people not to think of it as privacy, because most people tend to have tunnel vision. Think of it as personal data management - and in many cases, the most sensitive data I deal with (and thus, protect) is that of employees.

But like any area of compliance, it is always an uphill battle. Compliance is a cost center not a money maker. Ensuring certain protections are in place can slow down innovation and development. And especially given that most would prefer to build the house, then add the fence for privacy - we (privacy professionals) would prefer you to bring us the blueprints and make sure you are not building on someone else's property and/or get the right permits. Privacy by Design, or Privacy by Default. Build the product right to begin with. Then I am not a roadblock, I am a roadsign. I can point you in the right direction if you come to me early. If you come to me when you are ready to roll it out...well, I have to come up to speed on the product, check the contracts, vet the vendors, and know every data element you collect, how, when, what, where you get it, share it, and store it, how to send it, back it up, and delete it. 

So that is what a privacy counsel does.

It is one of the fastest growing fields in the world.

And when it is me - you get all this personality with the package. fun time, my friends, fun times.

Thursday, January 30, 2014

Practical HIPAA basics for Patients and their Families

My daughter was rushed to the ER one evening and I joined her. She was 18, maybe 19. They took her to do an ultrasound and I started walking with the bed. The employees stopped me and said I could not accompany her, she was an adult. She looked at them and said "I want her with me." And they replied that HIPAA would not permit me to accompany her. I explained that I could take the time to educate them as to why that statement was not true and would be happy to educate their supervisors if they also held the same mistaken beliefs, but given my daughter's emergency - if she was okay with going alone, I would not object at this time. My daughter agreed and off they went. I complained the next day.

I have another daughter who was having x-rays done as an outpatient and was also told I could not accompany her due to HIPAA. She was actually a minor. I was prepared in a non-emergent situation with a minor to object, but this daughter was actually quite happy for me not to accompany her - she was 15. Very independent. 

In one case, my mother was in the hospital following surgery and the nurses were giving her a hard time about her lack of following their instructions....and my mom is a nurse. She wasn't following the instructions, because the nurses were only taking into account the immediate situation and not the full history - which was clearly in the record. I called to inform them. Upon the nurse haughtily telling me she could not speak to me about my mother due to HIPAA, my response was that first, HIPAA would not stop her and second, I am not asking her for information, merely providing information to her. She need only listen - not speak. (Yeah, I can be a bit of a prat, but while firm, I was also very polite in all situations described above). 

I have heard HIPAA used as an excuse for so many things - doctors cannot talk to a family, nurses cannot listen to information from families, companies cannot respond to patients directly, etc. ad nauseum. 

So in this post, let me share a few things about HIPAA with you. (HIPAA is the Health Insurance Portability and Accountability Act of 1996, including all its subsequent amendments under the Affordable Care Act and implementing regulations that were effective in 2013 with the HIPAA Omnibus Rule). HIPAA has never been intended to interfere with medical care and in fact, to share patient information for treatment between health care providers, a patient authorization is not required. 

But to help address the situations above, 1) when a person verbally states that they want someone with them, that is patient authorization. And patient authorization is all that is required in HIPAA in order for a health care provider to share information - it does not need to be in writing, especially when the patient, the person, and the provider are standing there together. So when my daughter said she wanted me with her - that was sufficient. And yes, the hospital privacy officer agreed with me and sent us written apologies stating he would ensure that all staff were appropriate educated on that factor. It did not matter that we were related or that she was an adult and I her mother - what mattered was she gave permission. 

This leads into the situation with my other daughter. As a minor, she is not legally capable of providing legal consent, therefore, the parent was the appropriate person to grant consent. Perhaps at 15, her assent is desired or even required under certain state laws for medical treatment, but if an authorization to share medical information was required in writing, the parent or guardian would have to sign for it to be legal (foregoing any discussion here of emancipation and exceptions). Thus, as her parent, it was my right to give myself access to her information and accompany her to testing. 

Let's take that one step further. Perhaps the medical technician in either situation intended to protect the privacy of other patients. So? HIPAA provides for incidental disclosures, which covers situations in which patients are in close proximity and it is near impossible to maintain strict confidentiality. One should take reasonable precautions, but there is nothing illegal about an emergency room that has curtains instead of walls or stage all patients waiting on surgery in the same waiting area. That's not a valid enough reason to override a scared person's need to have their support person with them.

Last, my mother. Believe it or not, providers can share patient information with people the provider feels/knows is involved in the patient's care and wellbeing. Thus, knowing I was the daughter, the choice could have been made legally to provide me with information about my mother. True, this scenario can get complicated and ugly quickly - how could they verify who I am, or whether my mother and I were close, or any number of other variables. And so, it is logical that an entity would not permit employees to make this decision - but there are other ways to handle it. One could check with the patient, ask the doctor, or have an escalation process to find a potential solution rather than shutting out what may have been the only person in the patient's life (not the case here, but the nurse might not have known that). 

I hope this helps you with some basic misunderstandings about HIPAA. Please do not assume that your providers, health care employees, or even all privacy officers understand this - and by no means do I claim to know everything about HIPAA. Few take the time to fully understand all of HIPAA and sometimes a simple straightforward policy by the entity is much easier to train and enforce than are policies that enable HIPAA to be followed in full. And sometimes state law is more strict (I do not know of any, but they could exist). 

One final point, pl ease note that HIPAA is spelled with two As and NOT two Ps, e.g. HIPPA. If you are a consultant or vendor trying to get my business, you at least need to spell it right.

Thursday, September 27, 2012

HIPAA to the BA

Today's issue is HIPAA and Business Associate Agreements.

Under the HITECH Act, HIPAA will apply to Business Associates like it currently applies to Covered Entities. There is a proposed rule to implement this, which was expected to be finalized this past summer. It was not.  If Obama wins, there is no telling when the final rule will be issued.  If he loses, it is a safe bet that his regime will push to have the final rule issued before the end of the year in order to forestall its complete death.

The key to these proposed rules is that Covered Entities are trying to build in the elements of the proposed rules to their current Business Associate Agreements.  At present, certain elements are not expected out of Business Associates, but certainly Covered Entities would love to have these elements present now - like downstream enforcement to subcontractors of the Business Associates, audit trails, and the physical, administrative, and technical safeguards of the security rule.

There is a hope and a prayer that reasoning will overcome our Congress and some pieces of the HITECH Act will get repealed. But it's only a hope. and LOTS of prayer.