Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, March 5, 2010

Lesson for Hospitals and Health Care Providers: Photos of Shark Bite Victim

Martin Memorial too mum: Hospital staff violated privacy of shark victim, an article from the Palm Beach Post. The article highlights the impact ubiquitous mobile devices with cameras are having on our society and the potential liability risks associated with the use/misuse of these devices by health care employees.

The article indicates that various hospital employees took photos of a shark bite victim when he arrived in the emergency room. The article discusses the action taken by the hospital in response to the incident. Another article indicates that the photos were emailed to others.

This type of situation is a nightmare for hospital administration, the privacy officer and legal counsel. The effort and investigation that likely went into figuring out who took photos, where those photos went and the procedure for recapturing/removing the photos from the various sources was time consuming and expensive (both in $$ and reputation) for the hospital.

As such, this incident provides a good example for training and reeducating health care employees on patient privacy issues. Health care employees and professionals must always remember to start from a framework of protecting the health and privacy of their patients. As the use of mobile devices with cameras and social media tools becomes more ingrained in our every day lives -- the ability for private information to be captured, transferred and spread in a viral fashion has become much easier. Caution must be used and this case highlights the importance of retraining staff and highlighting the importance of protecting your patient's privacy.

Sunday, February 14, 2010

AIS Report on Patient Privacy: Analysis of Willful Neglect Under HITECH

Recently I was interviewed for a story focused on the changes to the HIPAA civil penalty enforcement under the HITECH Act.

The article, Willful Neglect Is Difficult to Pin Down, but Can Result in Enormous HIPAA Penalties, appears in the Report on Patient Privacy: Practical News and Strategies for Complying with HIPAA, Volume 10, Number 2 February 2010 published by Atalantic Information Services, Inc. (AIS). The article discusses the definition and interpretation of "willful neglect" under the HIPAA penalty provisions. Health care privacy officers should find this article helpful in better understanding their role and responsibility in overseeing privacy compliance efforts.

The full story was reprinted on AIS Health Business Daily website.

Thursday, January 14, 2010

State Attorney General HIPAA HITECH Enforcement

My health law colleague, David Harlow, covers the news today on the first HIPAA enforcement action taken by a state attorney general under the new HITECH provision of American Recovery and Reinvestment Act of 2009 (ARRA).

David's post, HIPAA enforcement by state attorney general: The shape of things to come, provides a good summary of the announcement by the Connecticut Attorney General. More information via the Connecticut Attorney General press release.

The lawsuit filed by the Connecticut Attorney General Richard Blumenthal (coincidentally brother of David Blumenthal, National Coordinator of Health Information Technology) alleges that a health insurer, Health Net of Connecticut, Inc., failed to promptly notify the AG and other officials of a missing portable computer disk drive that contained unencrypted protected health information, Social Security numbers and bank accounts for approximately 446,000 individuals. The lawsuit also named UnitedHealth Group Inc. and Oxford Health Plans, LLC who acquired ownership of Health Net of Connecticut. The action also seeks a court order against Health Net to encrypt all information held on electronic devices.

Since the early days of HIPAA implementation and compliance there has largely been a lack of real enforcement efforts. The new provisions under HITECH allowing state attorney generals to file HIPAA enforcement actions on behalf of the public bring a new era of enforcement against health care providers who are unfortunate to have a health data breach and fail to properly respond to such breach in a timely manner.

David offers some good advice and takeaway points to health care providers and others who regularly handle health information. It is not enough to have policies and procedures in place but to regularly monitor whether they are being followed. Today's health data is liquid and it can flow in many directions. Providers need to understand where and how data is stored, used and transferred.

Wednesday, January 13, 2010

HISPC Reports on State Health Information Law, Business Practice and Policy

The Office of the National Coordinator for Health Information Technology (ONC) has made available a compendium of reports which detail variations in state health information law, business practices and policy related to privacy and security of health information and the electronic exchange of health information.

The reports were developed in 2009 as a part of the ongoing efforts of the Health Information Security and Privacy Collaboration (HISPC) that started in 2006 when I had the the opportunity to work on the initial round of HISPC work as it related to West Virginia. The efforts by HISPC was to take a national look (at a state level) on the privacy and security challenges faced by the variation of state laws, policies and practices.

The reports will be a great resource for those who regularly look at state health information legal issues. Following are the summaries of the five reports along with links to the various tables/appendices:
  • Report on State Medical Record Access Laws This report analyzes state laws that are intended to require health care providers (specifically, medical doctors and hospitals) to afford individuals access to their own health information and to identify potential barriers to the electronic exchange of health information. Specific state law provisions examined: scope of medical records to which patients are afforded access, format of information furnished, deadlines for responding to requests, fees for furnishing copies, record retention laws and access to records of minors.
  • Report on State Law Requirements for Patient Permission to Disclose Health Information In Phase I of the HISPC project a majority of participants reported significant variation in the business practices and policies surrounding the need for and process of obtaining patient permission to use and disclose personal health information for a variety of purposes, including for treatment. This report furthers the initial work of this project by collating and analyzing state laws that govern the disclosure of identifiable health information for treatment purposes to identify commonalities and differences.
  • Releasing Clinical Laboratory Test Results: Report on Survey of State Laws For this report, state statutes and regulations were analyzed to determine to whom clinical laboratories may release test results. This report focused on clinical laboratory and hospital licensing laws (that contain standards for hospital laboratories). It also examined general state medical record access laws to determine whether they provided an avenue for patients to access their clinical laboratory results directly.
  • Report on State Prescribing Laws: Implications for e-Prescribing This report identifies and analyzes the impact and variation of state laws related to e-prescribing. The report addresses state laws related to the e-prescribing of controlled and non-controlled substances as well as topics such as record keeping and content requirements, out-of-state prescriptions, and generic substitution laws.
  • Perspectives on Patient Matching: Approaches, Findings, and Challenges This report analyzes various approaches to matching patients to their health information in the context of electronic health information exchange. Current and potential methods for matching patients to their health records are discussed, challenges to performing patient matching such as scalability and ease of use are analyzed, and the types of information some HIOs use to match patients to their health records is described.

Monday, January 11, 2010

The Saga Over The Privacy of Medicare Claims Data Continues . . .

Guest post by Michele Grinberg, my colleague in the Health Care Practice Group at Flaherty, Sensabaugh Bonasso PLLC.

Through indirection find direction out? With apologies to William Shakespeare, the U.S. Court of Appeals for the11th Circuit and D.C. circuit say: NO, not this time.

In Jennifer D. Alley, Real Time Medical Data, LLC v. U.S. Dept. of Health and Human Services, issued Dec. 18, 2009, the Court held that plaintiffs Alley & Real Time Data cannot obtain certain Medicare data for procedures performed in Florida, Georgia, Mississippi and Tennessee by AMA physicians and for all Florida physicians (the certified class). Specifically, Medicare Part B raw claims data that could easily be matched to a particular physician and then aggregated to calculate the total annual Medicare payment by physician cannot be disclosed to Alley. Alley had sought the information through filing a federal Freedom of Information Request (FOIA).

The reason? Because the Florida District Court in 1979 issued a permanent injunction in Florida Medical Assn. v. Dept. of Health Education & Welfare, prohibiting DHHS (then HEW) from disclosing “any list of annual Medicare reimbursements…for any years, which would personally and individually identify those providers of services …. Any such disclosure of annual Medicare reimbursement amounts, for any years, in a manner that would personally and individually identify the providers….is contrary to federal law.” (quoted in Alley)

Judge Carnes in a well-authored opinion (for those of you, like me, who care about good writing) enjoys the irony of hearing argument that sounds much like the health policy arguments heard in the mid-1970s. His second sentence reads: “The present national debate over health care rhymes a lot with one that took place three decades ago.” But whether it’s still good policy or not, Judge Carnes holds that plaintiffs cannot collaterally attack the 1979 injunction by arguing it does not apply to the data sought or the context has shifted in favor of disclosure or the reimbursement methodology has changed. Rather, if plaintiffs believe the injunction is no longer valid, their recourse is to go back to the court where the injunction issued and challenge it there.

In a footnote, the 11th Circuit references a recent 2009, United States of Court of Appeals D.C. Circuit, decision: Consumers’ Checkbook, Center For Study of Services. v. U.S. Department of Health and Human Services. The lower court’s holding in this case was discussed in this blog in 2008 (Consumers' Checkbook v HHS Update). In the 11th Circuit footnote (No.9), the court observes that in a factually similar case, the D.C. Circuit has held that FOIA exemption 6 permits DHHS to not disclose the requested Medicare data. FOIA exemption 6 protects from disclosure government agency files that constitute “a clearly unwarranted invasion of personal privacy.”

What we have then are two cases: one that upholds a 1979 injunction which enjoins DHHS from providing Medicare data that can be manipulated to identify annual reimbursements to individual physicians and other providers but which injunction reaches only the certified class of providers (identified above); and a second case that holds that providing similar Medicare data that can be tied to individual providers is protected from disclosure by a FOIA exemption. Thus, data elements which might indirectly seem disclosable are not if they lead to a resulting disclosure which invades personal privacy. We will see what changes health insurance reform brings, if any.

The AMA provides additional analysis of the decision in a story posted January 11, 2010, Appeals court rejects effort to sell Medicare physician claims data. Also, Law.com reports on the decision in its article, Mark Twain Lives On in Federal Judge's Ruling on Release of Medicare Data.

Tuesday, December 22, 2009

Lorman Medical Records Law Seminar: March 18, 2010

On March 18, 2010 I will be speaking on Medical Records Law at a seminar in Charleston, West Virginia. The seminar is sponsored by Lorman Educational Services. Joining me for the day long seminar will be three very knowledgeable health care colleagues:
  • Michael T. Harmon, MPA, CIPP/G, Compliance Specialist for the West Virginia Mutual Insurance Company, a Medical Professional Liability Insurance Company
  • Sallie H. Milam, J.D., CIPP/G, Executive Director of the West Virginia Health Information Network and Chief Privacy Officer for the West Virginia State Government
  • James W. Thomas, Esq., Manager of the Charleston, West Virginia Business Law Department of Jackson Kelly PLLC whose practice focuses primarily upon health care matters of a business, regulatory and operational nature
Additional information about the seminar and how to register can be found at Lorman Educational Services. Following is the full seminar agenda:

8:30 am – 9:00 am


Registration




9:00 am – 9:15 am


Overview




9:15 am – 10:30 am


HIPAA Compliance: Reality and Perspective



— Michael T. Harmon, MPA, CIPP/G



  • Overview
  • Enforcement
  • Complaints
  • Case Examples
  • Summary of HITECH Changes




10:30 am – 10:45 am


Break




10:45 am – 12:00 pm


HITECH Financial Incentives for Implementation of HIT



— James W. Thomas, Esq.



  • Qualifying an Electronic Health Record System
  • Available Financial Incentives




12:00 pm – 1:00 pm


Lunch (On Your Own)




1:00 pm – 2:00 pm


Health Information Exchange in West Virginia: Impact on Patient Records



— Sallie H. Milam, J.D., CIPP/G




2:00 pm – 2:15 pm


Break




2:15 pm – 3:30 pm


Consumer Driven Health Care: HITECH, Health 2.0, Social Media and Personal Health Records



— Robert L. Coffield, Esq.



  • HITECH Breach Notification Requirements
  • Impact of Health 2.0 and Social Media Technology on the Future of Health Care
  • Development and Adoption of Personal Health Records
  • Discuss the Legal Implications of Emerging Technology




3:30 pm – 4:30 pm


Panel Discussion



— Robert L. Coffield, Esq., Michael T. Harmon, MPA, CIPP/G, Sallie H. Milam, J.D., CIPP/G and James W. Thomas, Esq.

Tuesday, December 8, 2009

FTC Exploring Privacy: Rountable Series

Over the next couple of months the Federal Trade Commission (FTC) will be hosting the Exploring Privacy: A Roundtable Services.

The roundtable discussions are day-long public roundtable discussions to explore the privacy challenges posed by the vast array of 21st century technology and business practices that collect and use consumer data.

The FTC indicates that the "roundtable discussions will cover topics including social networking, cloud computing, online behavioral advertising, mobile marketing, and the collection and use of information by retailers, data brokers, third-party applications, and other diverse businesses. The goal of the roundtables is to determine how best to protect consumer privacy while supporting beneficial uses of the information and technological innovation."

More information can be obtained on the FTC's Exploring Privacy website, including the dates and locations of the upcoming roundtable events in Berkeley, CA and Washington, DC, submitted public comments and other information.

The first roundtable was held this week in Washington, DC. Details of the event are available on the website including two interesting charts -- Data flow chart (personal data ecosystem) and Data flow charts (medical, social networking, mobile, behavioral advertising, and retail loyalty card).

Thursday, December 3, 2009

Chief Data Rights Officer

I love the creative and mind opening nature of Twitter tweets. Simple 140 character thoughts, questions, queries, etc.

As a lawyer who deals with pages, reams, volumes, boxes, rooms of written information on a daily basis I'm often amazed (and pleased) by the depth of concepts that can be expressed through 140 characters.

Example from today, @SusannahFox's tweet:
@SusannahFox What if, instead of a chief #privacy officer, ONC changed the conversation and appointed a chief data rights officer?
Susannah gets my "tweet of the day" award.

Monday, November 2, 2009

HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule

On October 30, 2009, the Secretary of the Department of Health and Human Services (HHS) issued the HIPAA Administrative Simplification: Enforcement Interim Final Rule, 45 CFR Part 160 (74 Federal Register 56123, October 30, 2009).

This new rule was developed and adopted by HHS to conform the enforcement regulations under HIPAA to the revisions made to HIPAA under the Health Information Technology for Economic and Clinical Health Act (HITECH), which was part of the American Recovery and Reinvestment Act of 2009 (ARRA).

The rule amends the HIPAA enforcement regulations to include the imposition of tiered ranges for civil money penalty amounts based upon an increasing culpability associated with the violation. A full chart of the violation categories and related amounts can be found in the rule.

The interim final rule is effective on November 30, 2009. Comments on the rule can be made prior to December 29, 2009.

Thursday, August 20, 2009

OCR Designates HIPAA Regional Office Privacy Advisors

The Acting Director and Principal Deputy Director for the Office for Civil Rights, Robinsue Frohboese, has designated Office for Civil Rights Regional Managers in each of the HHS Regional Offices to serve as the Regional Office Privacy Advisors. On July 27, 2009, Secretary Sebelius authorized the Director of the Office for Civil Rights to carry out the designation required under the Health Information Technology for Economic and Clinical Health (HITECH) Act (Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009 (ARRA).

The designation of these Regional Office Privacy Advisors was mandated by the ARRA-HITECH provisions under Section 13403(a). The Regional Office Privacy Advisors will offer guidance and education to covered entities, business associates, and individuals on their rights and responsibilities related to the HIPAA Privacy and Security Rules

The names, addresses, and contact information for each of the Regional Managers are listed together with a list of the States for which each Regional Manager has responsibility are listed below:

Region I - Boston (Connecticut, Maine, Massachusetts, New Hampshire, Rhode Island, Vermont)
Peter Chan, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Government Center
J.F. Kennedy Federal Building - Room 1875
Boston, MA 02203
Voice phone(617)565-1340
FAX (617)565-3809
TDD (617)565-1343

Region II - New York (New Jersey, New York, Puerto Rico, Virgin Islands)
Michael Carter, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Jacob Javits Federal Building
26 Federal Plaza - Suite 3312
New York, NY 10278
Voice Phone (212)264-3313
FAX (212)264-3039
TDD (212)264-2355

Region III - Philadelphia (Delaware, District of Columbia, Maryland, Pennsylvania, Virginia, West Virginia)
Paul Cushing, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
150 S. Independence Mall West
Suite 372, Public Ledger Building
Philadelphia, PA 19106-9111
Main Line (215)861-4441
Hotline (800) 368-1019
FAX (215)861-4431
TDD (215)861-4440

Region IV - Atlanta (Alabama, Florida, Georgia, Kentucky, Mississippi, North Carolina, South Carolina, Tennessee)
Roosevelt Freeman, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
Atlanta Federal Center, Suite 3B70
61 Forsyth Street, S.W.
Atlanta, GA 30303-8909
Voice Phone (404)562-7886
FAX (404)562-7881
TDD (404)331-2867

Region V - Chicago (Illinois, Indiana, Michigan, Minnesota, Ohio, Wisconsin)
Valerie Morgan-Alston, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
233 N. Michigan Ave., Suite 240
Chicago, IL 60601
Voice Phone (312)886-2359
FAX (312)886-1807
TDD (312)353-5693

Region VI - Dallas (Arkansas, Louisiana, New Mexico, Oklahoma, Texas)
Ralph Rouse, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1301 Young Street, Suite 1169
Dallas, TX 75202
Voice Phone (214)767-4056
FAX (214)767-0432
TDD (214)767-8940

Region VII - Kansas City (Iowa, Kansas, Missouri, Nebraska)
Frank Campbell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
601 East 12th Street - Room 248
Kansas City, MO 64106
Voice Phone (816)426-7277
FAX (816)426-3686
TDD (816)426-7065

Region VIII - Denver (Colorado, Montana, North Dakota, South Dakota, Utah, Wyoming)
Velveta Howell, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
1961 Stout Street -- Room 1426 FOB
Denver, CO 80294-3538
Voice Phone (303)844-2024
FAX (303)844-2025
TDD (303)844-3439

Region IX - San Francisco (American Samoa, Arizona, California, Guam, Hawaii, Nevada)
Michael Kruley, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
90 7th Street, Suite 4-100
San Francisco, CA 94103
Voice Phone (415)437-8310
FAX (415)437-8329
TDD (415)437-8311

Region X - Seattle(Alaska, Idaho, Oregon, Washington)
Linda Yuu Connor, Regional Manager
Office for Civil Rights
U.S. Department of Health and Human Services
2201 Sixth Avenue - M/S: RX-11
Seattle, WA 98121-1831
Voice Phone (206)615-2290
FAX (206)615-2297
TDD (206)615-2296

Monday, August 3, 2009

HIPAA Security Rule Enforcement Delegated to OCR

Today HHS Secretary Kathleen Sebelius announced that enforcement of the Security Rule under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) will be delegated to the Office for Civil Rights (OCR).

The official delegation occurred on July 27, 2009. More information about the transition of authority for the administration and enforcement of the Security Rule can be found in the OCR press release. The official Delegation of Authority by the Office of the Secretary has been issued and will appear in the August 4, 2009 Federal Register.

Prior to today, administration and enforcement of the HIPAA Security Rule has been the responsibility of the Centers for Medicare & Medicaid Services (CMS).

Monday, June 1, 2009

PHRs, The Model T, Meaningful Use and the Patient-Centric HIT Revolution

There is a growing discussion on the health consumer-centric (patient-centric) meaning of "meaningful use" of EHRs and health information technology. Jane Sarasohn-Kahn summarizes this discussion in her recent post, "Meaningful USe - or, whose health is it, anyway?" at Health Populi where she reflects on Ted Eytan's post, "Is it Meaningful If Patients Can't Use It?"

Since Ted's post other health care thought leaders have offered their comments. A list of these individuals can be found in Jane's post. As Jane mentions, this topic was central to much of the discussion that occurred during the first two days of the testimony before the National Committee on Vital and Health Statistics (NCVHS) on the Future of Personal Health Records held on May 20 and 21. The discussion will continue at the NCVHS hearing on June 9 when there will be a panel focused on "Consumer Advocates and Attitudes" that will include Susannah Fox, Dave deBronkart, Deven McGraw, JD and Robert Gellman, JD.

Jane mentions in her post our testimony before the Subcommittee on Privacy, Confidentiality and Security of the National Committee on Vital and Health Statistics (NCVHS) on the future of PHRs. Our panel, including me, Jane and Daniel Weitzner, the W3C Technology and Society Policy Director, opened the hearings on PHRs. Our role as the opening panel was to try to set the stage for the context of the discussion on the future of PHRs and consumer facing health care information technology.

As the opening speaker at the hearing I decided to stay away from immediately diving into the legal issues and instead give the committee a landscape view of where I think we are in the history of health information. My goal was to provide a historic framework for PHR development by drawing some historic parallels to the history of the development of our transportation system. By analogy I compared today's PHRs to the Model T era of the automobile area and taking a page from Dave deBronkart told the committee my personal family e-health information story. Below is a complete copy of my written testimony submitted to the committee.

As the discussion continues on "meaningful use" the role that PHRs play is important. Focusing on health care consumers and their practical use of PHR tools is vital to the future of our health care system. As I said in my testimony there will be game changers but we need to see the potential of today's Model T PHRs and build toward the Prius Hybrid PHRs of the future.


Prepared Statement for Subcommittee on Privacy, Confidentiality, and Security National Committee on Vital and Health Statistics (NCVHS)

Discussion on the Future of Personal Health Records

Good morning. I want to thank the Co-Chairs, Subcommittee and Committee Staff for the opportunity to participate in today’s discussion on the current state of the personal health record (PHR) and the future use of this and other health care technology tools by the health care industry and the health care consumer.

My name is Bob Coffield. I am a health care attorney from Charleston, West Virginia, with the law firm of Flaherty, Sensabaugh & Bonasso, PLLC. I have a broad-based health care practice, providing legal and business services to a variety of health care clients. A large portion of my practice focuses around health information issues, regulatory compliance, privacy, security, and health technology. Over the past five years, I have become involved in the social media movement, and that involvement has changed the way I live, work, collaborate and communicate. My involvement and interest in the social media movement and its impact on our lives has led me to focus a portion of my practice on legal concepts and issues generated by the use of social media tools and technologies in health care, law and other industries.

Introduction: Today’s PHR is the Model T

As the opening speaker, I want to set the stage for today’s discussion on the questions raised by the committee. As the committee examines the issues, I recommend that you look toward a longer horizon of 20 to 50 years. In this age of information and accelerating technology, it is often easier to predict what may happen in 50 years than what will happen next year. As information technology advances and new technologies are developed, it has become more difficult to conduct short-term strategic planning in the three to five-year range. Over the past 10 years of the maturing information era, we have seen incredible advances and significant disruption in all business, including health care.

At its center, the information age is characterized by the ability to create and transfer information and knowledge freely and to have instant access to knowledge that would have been impossible, difficult or too expensive to find in the past. Jane Sarasohn-Kahn and others today will provide the Committee with an understanding of the current health care consumer marketplace and the major motivators driving health care consumer empowerment in the information age, and also will provide a perspective on the current state of consumer engagement in health care. It is my belief that this changing era is having a profound impact on today’s health care industry. The strategies, systems, approaches and governing rules used today and by past generations may not be successful in today’s and tomorrow’s changing information era.

A part of today’s process should be to consider what the long-term goals are for health information technology, including the PHR, and how it can be used to drive consumer-focused and controlled health care in the information age. Along with this discussion, we have a responsibility to talk about why involvement of the consumer matters and what impact it will have on improving care, reducing costs and creating efficiencies in the health care system.

As we discuss health information technology and PHRs today, we have a responsibility to stay focused on this question: “What will improve the quality of care for you and me, as consumers of health care?” This single question needs to remain at the center of today’s discussion and the continuing debate on consumer health information technology. As the health care industry becomes more and more specialized, complex and technologically advanced, we often lose sight of the purpose of the health care system. That purpose is human care and compassion. You and I, as health care consumers, must remain at the center. My hope is that the future of our health care system will use technology, including PHRs, to improve the human experience and interaction between the professional caregiver and health care consumer.

The questions I often struggle with and hope to hear discussion on today are: How will PHRs drive consumer empowerment, and how will this consumer empowerment lead to improving care? We can all sit around and discuss the best ways to build PHRs, but the questions remain whether or not the health care consumer will be attracted to use PHRs and whether providers will be willing to incorporate PHRs into the treatment and care process.

As I said at the opening of my remarks, I want to set the stage for the discussion and testimony today by sharing a story and painting a historical perspective. As I looked over the agenda of those speaking today, I was struck by the level of experience and diverse backgrounds that each of us brings to the discussion. However, because of the level of specialization represented in this gathering, there is the risk of remaining deep in the weeds, dealing with details, and failing to step back and take a wider view of the landscape. The story and analogy I want to share with you is my attempt to take you on a tour of that broader view.

I am a believer in the adage that history repeats itself. What we are trying to do today is to provide you with a perspective and prediction of the role that the PHR will (should) play in the health information technology infrastructure over the next 10 years. So a historical sketch of where we have been and where we are is valuable to the discussion of where we may go.

I want to start the story with a quote from the 1800s, by inventor Oliver Evans, as he spoke about the future of the transportation system in the United States.
"The time will come when people will travel in stages moved by steam engines from one city to another, almost as fast as birds can fly, 15 or 20 miles an hour . . .

A carriage will start from Washington in the morning, the passengers will breakfast at Baltimore, dine at Philadelphia and supper in New York the same day . . . .
The 1800’s saw the dawn of the railroad system in the United States, as a result of the development of the steam engine. These developments led to the widespread use of trains as a mode of transportation for a growing population that, until that time, had been relatively immobile. The growth of the railroad system started at the local level, grew to regional connections and ultimately led to a national network of railroad tracks from east to west and from north to south. Prior to this time, personal travel required one to travel on foot, by horse or by carriage.

My ancestors, who grew up in the hills of northern West Virginia, came to West Virginia (then Virginia) in the late 1700’s. As we say in West Virginia, “they lived out on the ridge.” A number of generations went by, and there was little mobility of my family. They lived out their lives on those same ridges for well over 150 years. They raised their families and farmed. They lived a relatively isolated and stationary life. Traveling beyond a few miles was difficult, impractical and largely unnecessary, at least from their perspective of the world.

However, by 1900, the landscape had changed, and the Industrial Revolution was having a profound impact on the world. My great-grandfather and grandmother had two sons who were teens in the 1890s. In the 1890s, my great-uncle went to college, came back and taught school for a few years and then went on to law school. Likewise, my grandfather went to college, came home like his brother to teach school for a few years, and then continued on to medical school in Cincinnati, Ohio – at that time a long distance from the northern part of West Virginia. He came back and practiced medicine in Wetzel County, West Virginia, from 1911 until his death in 1936. He saw home patients initially by horseback, and then in 1915, he traveled to Pittsburgh, Pennsylvania by train to pick up a brand new Ford Model T, which replaced his horse in his rural medical practice.

As the rail system in the United States matured, it grew into a more complex mass transportation system. Individuals who, prior to that time, had used their own modes of transportation, whether on foot, by horse or carriage, started to rely upon the system for transportation. They became passengers who didn’t own the train or the rails. As the railroad system developed, we saw issues related to standards, such as the gauge of tracks. Local, state and federal government become involved in furthering the growth and expansion of the railroad system by providing financial support, political influence and regulatory assistance to the growing railroad industry.

At that stage in history, no one in the powerful railroad industry would have predicted the disruptive influence by a young, different type of engineer - Henry Ford. With the advent of the automobile and the mass production of the Model T in 1908, our transportation system in the United States was forever changed. Over the next 20 years, the adoption of automobile travel was unprecedented. This revolution led to a demand for better roadways and improvement of the largely privately built turnpike roads. The Federal Highway Act of 1921 authorized the Bureau of Public Roads to provide public funding to help state highway agencies construct paved systems of highways, and this led to the Federal-Aid Highway Act of 1956, which authorized the creation of the Interstate Highway System.

By analogy, we can compare the development of the transportation system to the development of today’s health information system and draw many comparisons and parallels. The health information system, up through the 1950’s and 1960’s, was paper-based, centrally located and uncomplicated. The medical record system for my grandfather’s practice – to the extent that it was used – was simple. Likewise, the medical record system and documentation used by my father and uncle during their medical careers, roughly 1940-2000, was relatively non-complex. During this time, there was little specialization: Physicians were generalists in everything. In large part, physicians from this era cared for their patients from birth to death and, in the case of my grandfather, father, and uncle, cared for multiple generations of families. Providers during that time had a relatively comprehensive picture of the medical history of each individual, as well as that individual’s immediate and collateral family members. Prior to specialization in health care, we had a health system focused on the individual patient, and health information was centered on that individual and the individual’s family.

By the 1970’s, we saw the development of the first electronic health record – the problem-oriented medical record (POMR), predecessor of today’s current Electronic Health Records (EHR) and Electronic Medical Records (EMR). At this same time, we saw the expansion of medical litigation, which has played a significant role in the health information system over the past 30 years.

Prior to 2000, little had been written or heard about PHRs. Back in 2001, in a report called Strategy for Building a National Health Information Infrastructure, the National Committee on Vital and Health Statistics mentions PHRs and the growing consumer use of Internet-based health information services. This was important because it was the first time that a national health body acknowledged or officially recognized PHRs. In 2005, the American Health Information Management Association (AHIMA) formed a work group to examine the role of PHRs in relation to EHRs, and the pace and interest in PHRs has continued to increase since that time.

Over the last year, interest and activity in the development and use of PHRs has accelerated. This new-found interest has now culminated in the first law directly regulating PHRs and PHR vendors, under the Health Information Technology for Economic and Clinical Health Act (HITECH), which is a part of the American Recovery and Reinvestment Act of 2009, signed into law on February 17, 2009.

How is the history of our transportation system analogous to our health information system? On a basic level, both provide transportation – one transported humans, and the other, human information. Both started as uncomplicated systems that were not interconnected. I imagine you are already formulating other parallel points between these two systems.

To begin today’s discussion on PHRs, we need to examine where PHRs fit in this historical perspective and timeline. What is the equivalent of the PHR in the history of our transportation system? Today’s PHR is the equivalent of the Ford Model T. The PHR will be the vehicle to individually transport health information in the future, introduce the involvement of consumers in their own health information and wellness and inspire a time of innovation and creativeness over the next five to 10 years. If the age of the PHR takes off, it will bring about a wholesale change in the way that health information technology is structured and will radically disrupt traditional health care industry models.

There are various other analogies to be drawn between the two historical perspectives. For example, do the trains and the rail system represent the traditional health care providers and payors in the industry who are maintaining data in silos and segregated systems? Can we draw comparisons between the powerful railroad industry versus the nascent auto industry and the current health care and insurance industry and the emerging Health 2.0 technology movement? Are the disagreements that occurred in the railroad industry over the gauge of railroad tracks analogous to the debate occurring over the need and process to develop standards for health information technology? Can we draw parallels between our country’s development of a national network of railroads through local, state, and federal initiatives to those ongoing efforts by state health information exchanges (HIEs), regional health information organizations (RHIOs) and the national health informational network (NHIN)? Will there be similarities between the freedom that consumers felt the first time they bought an automobile and drove it down the road and the feeling of empowerment experienced when a health care consumer adopts and uses a PHR? In the coming years, will the connecting of EHR and EMR systems and the development of the NHIN be relegated to being used to transfer bulk health data, not unlike the role that the railroad system plays today?

As we look toward the future of PHRs, we have to understand that we are now looking at the Model T stage of PHRs: Call it PHR 1.0. The PHRs of the past 10 years and, in large part, the PHRs of today, are still relatively rudimentary and impractical, not unlike the first automobiles. I suspect my grandfather’s experience of traveling to Pittsburgh by train, having never owned a car before, to pick up his new Ford Model T and drive it back into the hills of West Virginia, was not unlike Dave deBronkart’s experience when he set up his Google Health account and imported his own health information from his providers. Prior to their experiences, neither knew how to drive the vehicle, but they learned in the parking lot. Once they both bought into the product, they didn’t have any good roads to drive on, and when the vehicle broke down they had to fix it themselves. However, through their efforts the world began to change, and their lives were and will be forever changed.

Over the next five to 10 years, and probably longer, we may see PHRs become the multi-colored, sleek-designed, more powerful automobiles, analogous to the golden era of the automobile industry from 1940 to 1950. Continuously over that time period, new personal options will be developed as add-ons to the PHR. As PHR adoption grows, we will have to develop larger, longer and more robust highway systems to allow for the transfer of health data by and between PHRs. Likewise, new standards will come into existence, not unlike those adopted by industry or those created by government. Safety features also will be developed continuously to protect and secure the health information maintained, stored and transferred through PHRs. Think of these as the modern-day innovation, adoption and enforcement of traffic signals, the use of seat belts and requirement for guard rails.

As we look toward the future, we also have to be aware that there will be game changers that we can’t envision at this time. Although PHRs might now be the industry solution to change the way we aggregate and store health information, new technology may be invented that disrupts this strategy and approach. For example, consider the impact that air travel had on the automobile industry. We must remain open to change in this new information era – change will be the norm and not the exception.

Using PHRs to Transform the Health Care Industry

The efforts by large technology companies and other Health 2.0 technology companies could transform the health care industry by triggering advancements in health information technology and laying the groundwork for overall health care delivery and payment reform. Although it is too early to say whether the PHR, in fact, will be the catalyst for health care reform, the Committee, government and the larger health care industry and community need to understand and explore PHRs and their role and consider how the consumer-focused PHR revolution will impact the health industry.

A convergence of factors could cause a comprehensive shift in the way health information is stored and used. Innovations in health information management technology are altering the way that patients, health care providers and payers maintain, use, control, and disclose health information. Through such technology, the current, decentralized system of records maintained by multiple providers and entities at multiple locations – often with conflicting and duplicative information – is being transformed into a centralized record maintenance system that may rely on personal health information networks (PHIN), where the PHR serves as the central repository for health information shared through a system of developing regional or national health information exchanges. Vince Kuraitis of the e-CareManagement Blog calls this change a “transformation from Industrial Age medicine to Information Age health care.”[1]

This transformation in the way information is maintained, stored, and exchanged empowers the health care consumer by offering a new level of control and responsibility over his or her care. It will directly impact the patient-provider relationship.

The traditional model for maintaining medical records, in which the provider of care stores, maintains, and updates the record, is based upon the need to provide continuity of care. The medical record reflects the plan of care, documents the care provided, and records communications among providers. Also, the medical record assists in protecting the legal rights and interests of both consumers and providers.

In the 21st century, our health care system simultaneously has become more fragmented and specialized, on one hand, and more coordinated and wellness-focused, on the other. Health care consumers have become mobile and now seek the services from a variety of providers engaging in numerous specialties. These same consumers change providers on a regular basis and take advantage of new models of care, like urgent care services, to complement traditional primary care services. The increasingly mobile population has caused breakdowns in continuity of care. As individuals move from city to city and state to state, they leave behind a trail of partial medical records – some on paper, some electronic – with various providers, insurers, and others.

The increasing popularity of EMRs, EHRs, RHIOs, and HIEs signals a need to address the increasing complexity of maintaining and sharing these different types and silos of health information. The PHR may be the disruptive technology that provides a simple alternative to ongoing efforts to create an interconnected network of interoperable health information systems with detailed querying functions, capable of making accessible in one place the health information and continuity of care record for individual consumers. In contrast, PHRs would travel with health care consumers and provide a central location for information regarding the consumers’ individualized needs.

Ownership of Health Information

The shift to a consumer-controlled PHR from a provider-based and controlled medical record raises traditional property law issues. As health information becomes increasingly networked and technology permits health information to be transferred more easily, the lines demarcating ownership of health information become further blurred.

Health information is often viewed under the traditional notion of property as a “bundle of rights,” including the right to use, dispose, and exclude others from using. This legal application of historic property law may not be well-suited to the information age, in which patient information is shared through a variety of formats, copied, duplicated, merged, and combined with other patient records into large scale databases of highly valuable information.

Who owns health information? The physician? The insurer? The health care consumer? Under the traditional theory, providers own the medical records they maintain, subject to the consumer’s rights of access in the information contained in the record.[2] This tradition stems from the era of paper records, where physical control meant control and ownership. Provider ownership of the record is not absolute, however; HIPAA and most state laws provide consumers with some right to access and receive a copy of the record. Health care consumers have received other rights out of the bundle of property rights, including the right to request corrections to their medical information and the assurance that such records are maintained confidentially.

The PHR model, where all records are centrally located and maintained by the consumer, flips and realigns the current provider-based ownership model of managing health information. Instead of provider-based control, where the provider furnishes access to and/or copies of the record and is required to seek patient authorization to release medical information, the PHR model puts the health care consumer in control of his or her medical and health information.

[1] Vince Kuraitis, E-CareManagement Blog, Birth Announcement: the Personal Health Information Network, March 8, 2008, http://e-caremanagement.com/birth-announcement-the-personal-health-information-network-phin/.

[2] Alcantara, Oscar L. and Waller, Adelle, Ownership of Health Information in the Information Age, originally published in Journal of the AHIMA, March 30, 1998; http://www.goldbergkohn.com/news-publications-57.html.

Tuesday, May 19, 2009

Modern Day Hatfield-McCoy: Google Health and Microsoft HealthVault

The Hatfields and McCoys, a metaphor for a modern day high-tech industry rivalry centered on personal health records (PHRs) involving Google Health, Microsoft HealthVault and other PHR vendors. An image that a West Virginia health care lawyer can really appreciate.

Thanks to a tweet by @2healthguru for pointing out the CNET article, Microsoft, Google in healthy competition. The article provides a good overview of the developing PHR movement and some insight into the future. However, I'm a bit concerned by the accuracy of the article when I see two of the individuals mentioned in the article (Matthew Holt and Dave deBronkart) tweeting (here and here) that they weren't really interviewed for the article.

Later this week I will be in D.C.along with others testifying at the Hearing on Personal Health Records before the National Committee on Vital and Health Statistics (NCVHS), Subcommittee on Privacy, Confidentiality and Security . The Subcommittee is looking at the future of the PHR marketplace and consumer-facing health information technology.

The story of the Hatfield-McCoy feud is woven into the fabric of southern West Virginia lore along the Tug River and well known by all West Virginians. Above is a photo of the West Virginia Hatfield clan around 1897, led by Devil Anse Hatfield, second from the left. For more history and photos check out the West Virginia Division of Culture and History.

Note: If you are into off-road vehicle trails, come visit West Virginia and check out the modern day version -- the Hatfield-McCoy Trails.

Tuesday, May 5, 2009

Virginia Department of Health Professions Breach: Extortion Demand Regarding 8M Patient Records and 35M Prescriptions

Information Week is covering a story involving an extortion letter sent last week to the Virginia Department of Health Professions seeking $10M to return more than 8M patient records and 35M prescriptions allegedly stolen from the Virginia Department of Health Professions.

The extortion demand was posted on WikiLeaks. The WikiLeaks website states:

May 3, 2009
Summary
On Thursday, April 30, the secure site for the Virginia Prescription Monitoring Program (PMP) was replaced with a $US10M ransom demand:
"I have your shit! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh :(For $10 million, I will gladly send along the password."
The site, https://www.pmp.dhp.virginia.gov/pmpwebcenter/login.aspx appears to have been entirely disabled and is presently unavailable.
The linked file provides the full ransom message.
The PMP is used by pharmacists and others to discover prescription drug abuse.
The PMP declined to comment, although when contacted, appeared to be aware of the issue, instantly referring inquiries to the director of the DHP, who is presently unavailable.

The Virginia Department of Health Professions website indicates that they are "currently experiencing technical difficulties which affet computerand email systems."

Sandra Whitely Ryals, Director of Virginia Department of Health Professionals, responded to the inquiry by Information Week stating that "a criminal investigation is under way by federal and state authorities."

The Washington Post Security Fix blog is also covering this story. Follow more news on this story via Google News.


UPDATE (5/5/09):
At the bottom of his follow up post, John Chilmark asks the question: "Now the question is, under HIPAA, does the VDHP have to send out breach notifications to all consumers whose records have been compromised?

Here is my quick assessment. The HIPAA privacy rule (pre-ARRA HITECH) does not contain provisions that require a covered entity to notify individuals impacted by an alleged breach. However, when I have assisted clients with these types of data breach situations in the past I typically discuss with the client whether it is good practice to provide notification. The HIPAA privacy rule provisions do contain a requirement that a covered entity should mitigate potential harm to patients/individuals when there is a violation of the privacy rule. My interpretation is that this might, under certain circumstances, include providing notice to such individuals whose data has been compromised. Also, a question that factors into the equation is whether or not the Virginia Department of Health Professsions qualifies as either a covered entity or business associate under the HIPAA privacy rule. Handling these situations are very fact specific and depend upon a number of factors.

The new federal breach notification requirements contained in the HITECH section of the American Recovery and Reinvestment Act (ARRA) do not apply because the provisions do not go into effect until 30 days after the Department of Health and Human Services (HHS) publishes the interim final data breach notification regulations which has not yet occurred. The new federal breach notification law will be implemented in conjunction with the Federal Trade Commission's (FTC) proposed health breach notification rule that will apply to PHRs, PHR related vendors and other third party providers. The proposed rule is currently out for comment.

The regulations are currently in the works and HHS has now issued initial guidance on what data is classified as unsecured protected health information (not secured by technology that renders it "unusable, unreadable or indecipherable"). See the April 27, 2009 guidance for more on what this means. The guidance outlines the types of technologies that, if used, create a safe harbor for HIPAA privacy covered entities adn business associates to avoid having to provide notice in a situation where there has been a breach.

Also, the VDHP will likely have to assess the Virginia Data Breach Act (state-by-state survey of state breach laws by the National Conference of State Legislatures) to see whether notification or other action is required under state law.Over 40 states now have distinct state laws governing breach notification that extend to and cover everything from traditional personal information (name, social security number, etc.) to health related information. I've not dealt nor reviewed the Virginia Act but suspect a strong likelihood that notification will be required.

UPDATE (5/6/09): The Roanoke Times provides an update on the status of the pending investigation with comments from Governor Tim Kaine. The article states:
Gov. Tim Kaine said today that a hacker’s reported access to patient prescription records from a state database was “an intentional criminal act against the commonwealth by somebody who was trying to harm others” . . .

The FBI and the Virginia State Police are investigating the matter. Kaine said he could not discuss the probe.

“Right now our goal is to make sure that the investigation and criminal process works so that the person who is responsible is caught and prosecuted . . . and that we protect people whose data has been compromised,” Kaine said this morning.

The article also indicates that under Virginia law notification is required and that Virginia's breach notification law requires, like many state laws, that notice must be provided "without unreasonable delay."
The article also indicates that Virginia law requires notification of individuals whose personal information may have been accessed due to a computer security breach. The law states that notification must be provided “without unreasonable delay.”

Friday, April 24, 2009

AHLA Teleconference: HIPAA Privacy Fundamentals

Next month I will be co-presenting on an American Health Lawyer Association Teleconference on the topic of HIPAA Privacy Regulation Fundamentals - An Introductory Course.

The teleconference is scheduled for May 13, 2009, 1:00 - 2:30 pm EST. My co-presenter is Rebecca L. Williams of Davis Wright Tremaine LLP and the moderator will be Phyllis Granade of Adorn & Yoss.

This teleconference is geared toward a gaining a basic understanding of HIPAA privacy law for health lawyers (think, HIPAA 101). We will also be discussing the impact of the changes unde rthe HITECH Act of 2009. Although geared toward health lawyers this teleconference would also be valuable for health care professionals and others in the industry interested in learning more about HIPAA.

You can find out more about the teleconference and how to register via the AHLA website.

Friday, April 17, 2009

FTC Proposed Health Breach Notification Rule for PHRs and Electronic Health Information

Yesterday, April 16, 2009, the Federal Trade Commission released its proposed Health Breach Notification Rule for Vendors of Personal Health Records (PHRs) and Electronic Health Information.

The official title of the proposed rule is: 16. C.F.R. Part 318: Notice of Proposed Rulemaking and Request for Public Comments Concerning Proposed Health Breach Notification Rule, Pursuant to the American Recovery and Reinvestment Act of 2009.

The FTC is seeking written comments electronically or in paper form. The comments must be submitted by June 1, 2009 and will be placed on the public record and made accessible at the FTC website at: http://www.ftc.gov/os/publiccomments.shtm.

The FTC's press release states:
The Federal Trade Commission today announced that it has approved a Federal Register notice seeking public comment on a proposed rule that would require entities to notify consumers when the security of their electronic health information is breached.

The American Recovery and Reinvestment Act of 2009 (the Recovery Act) includes provisions to advance the use of health information technology and, at the same time, strengthen privacy and security protections for health information. Among other things, the Recovery Act recognizes that there are new types of Web-based entities that collect or handle consumers’ sensitive health information. Some of these entities offer personal health records, which consumers can use as an electronic, individually controlled repository for their medical information. Others provide online applications through which consumers can track and manage different kinds of information in their personal health records. For example, consumers can connect a device such as a pedometer to their computers and upload miles traveled, heart rate, and other data into their personal health records. These innovations have the potential to provide numerous benefits for consumers, which can only be realized if they have confidence that the security and confidentiality of their health information will be maintained.

To address these issues, the Recovery Act requires the Department of Health and Human Services to conduct a study and report, in consultation with the FTC, on potential privacy, security, and breach notification requirements for vendors of personal health records and related entities. This study and report must be completed by February 2010. In the interim, the Act requires the Commission to issue a temporary rule requiring these entities to notify consumers if the security of their health information is breached. The proposed rule the Commission is announcing today is the first step in implementing this requirement.

In keeping with the Recovery Act, the proposed rule requires vendors of personal health records and related entities to provide notice to consumers following a breach. The proposed rule also stipulates that if a service provider to one of these entities experiences a breach, it must notify the entity, which in turn must notify consumers of the breach. The proposed rule contains additional requirements governing the standard for what triggers the notice, as well as the timing, method, and content of notice. It also requires entities covered by the proposed rule to notify the FTC of any breaches. The FTC can then post information about the breaches on its Web site, and notify the Secretary of Health and Human Services.
More information over at info.rmatics blog who appear to have done a quick summary of the proposed rule. I have only had a chance to quickly scan the proposed rule but will add addition comments once I have a chance to read the entire proposed regulations. Comments and thoughts of others are welcomed - please post your comments.