Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans Prepared for: CALIFORNIA HEALTHCARE FOUNDATION Prepared by: Health Privacy Project Author: Joy Pritts, J.D. February 2002 Acknowledgments Health Privacy Project is a part of the Institute for Health Care Research and Policy at Georgetown University. The Health Privacy Project is dedicated to raising public awareness of the importance of ensuring health privacy in order to improve health care access and quality, both on an individual and a community level. Additional background information on health privacy can be obtained by visiting www.healthprivacy.org. The author would like to acknowledge the participation of a group of individuals whose expertise, industriousness, and guidance were essential to this report: Janlori Goldman, Director, Health Privacy Project; Sam Karp and Claudia Page, California HealthCare Foundation; and Scott Sanders, High Noon Communications. Additionally, a special thank you goes to Dani Collier, Project Manager, Regulatory Compliance, PacifiCare of California and the staff of the Department of Managed Health Care for taking time out of their busy sched- ules to review this guide. Their input was invaluable. The California HealthCare Foundation (CHCF) is an independent philanthropy committed to improving California’s health care delivery and financing systems. Our goal is to ensure that all Californians have access to affordable, quality health care. CHCF’s work focuses on informing health policy decisions, advancing efficient business practices, improving the quality and efficiency of care delivery, and promoting informed health care and coverage decisions. The iHealth Reports series focuses on emerging technology trends and applications and related policy and regulatory developments. Additional copies of this report and other publications in the iHealth Report series can be obtained by calling the California HealthCare Foundation’s publications line at 1-888-430-CHCF (2423) or visiting us online at www.chcf.org. Disclaimer This guide is intended to provide information related to the requirements for implementing the HIPAA Privacy Rule as of the date hereof. It is provided with the understanding that the authors and publishers are not engaged in rendering legal or other professional services. To obtain more current information on the Privacy Rule, or if legal advice or other expert assistance is required, the services of a competent professional should be sought. The authors and publishers specifically disclaim any liability, loss or risk incurred as a consequence of the use, either direct or indirect, of any information presented herein. ISBN 1-929008-84-8 Copyright © 2002 California HealthCare Foundation Contents 5 Overview 6 Purpose 7 I. Background The Value of Health Information Why Health Privacy Matters Protecting Health Privacy 9 II. The Federal Health Privacy Rule Introduction Who is Covered? What is Covered? Requirements Compliance Remedies and Penalties 16 III. The Interaction of the Federal Health Privacy Rule and California Privacy Laws Introduction Complying with Both State and Federal Laws 19 IV. The Impact on Insurers Subject to the Insurance Information and Privacy Protection Act Background Restrictions on Use and Disclosure of Health Information Patient Rights Administrative Requirements Looking Ahead 34 V. The Impact on Knox-Kneene Health Care Service Plans Background Restrictions on Use and Disclosure of Health Information Patient Rights Administrative Requirements for Health Care Service Plans Looking Ahead 49 Appendices Appendix A: Key Resources for Implementation Assistance Appendix B: Checklist of Key Items for Implementation 51 Endnotes Overview THIS GUIDE IS INTENDED FOR HEALTH INSURERS (subject to the Insurance Information and Privacy Protection Act) and health care service plans (subject to the Knox-Keene Health Care Service Plan Act). Health care providers should consult either Implementing the Federal Health Privacy Rule in California: A Guide for Providers, or Implementing the Federal Health Privacy Rule in California: A Guide for Pharmacists, Physical Therapists and Others, CHCF publications specifically designed for their needs. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 5 Purpose THIS GUIDE IS DESIGNED TO HELP CALIFORNIA health insurers and health care service plans to comply with the new Federal Health Privacy Rule, which was issued by the U.S. Department of Health and Human Services in December 2000. The guide is specific to holders of health information in California, which has its own state health privacy laws. The guide is meant to serve as a general road map for imple- menting the Privacy Rule and will help health insurers and plans begin the process of determining what steps they will need to take to come into compliance with the Privacy Rule in April 2003. The guide, however, is not a step-by-step manual for bringing an insurer or health care service plan into compliance. It provides a thorough understanding of what will and will not be required under the Privacy Rule and will help individuals and organizations begin to think about how to best integrate those requirements into existing practices. As implementation draws near, it will be important to consult other resources, as appropriate, to ensure full compliance. Specifically, the guide: s Provides background on the value of health information and health privacy; s Explains the Privacy Rule-how it came into being, who and what it covers, and its general framework; s Discusses, in general, the preemption provisions of the Privacy Rule and explains the resulting relationship between the federal rule and California health privacy laws; and s Analyzes how insurers and health care service plans will be required to implement the Privacy Rule and the rights it provides to patients to access and amend their health infor- mation in light of existing California law. Because health insurers and health care service plans are subject to different requirements under California law, the implemen- tation requirements for each of these categories is addressed in a separate section. Each of these sections stands alone and may be read individually. 6 | CALIFORNIA HEALTHCARE FOUNDATION I. Background The Value of Health Information Health insurers and health care service plans are naturally aware of the value of health information. Its primary value is the key role it plays in the provision of high-quality care to the patient. Without information about a patient’s condition, providers cannot offer adequate care, nor can payers cover the cost of that care. Some other uses of health information also benefit patients and the larger community, while others primarily benefit the holder of the information. Some of the latter uses include: s Managing disease; s Ensuring quality and accountability; s Investigating fraud and abuse; s Monitoring public health; s Insuring adequate government oversight; and s Expanding commercial activities Why Health Privacy Matters Given the numerous uses of health information and the number of people who have access to health information in today’s complex health care system, many patients have concerns about the privacy of their own, identifiable health information. Patients fear that their employers, family mem- bers, or friends may discover that they have a sensitive health condition that could negatively impact their job security, relationships, or personal safety. Among those with heightened concerns are adolescents, immigrants, mental health patients, people with HIV/AIDS, and victims of domestic violence. These concerns are magnified by the increased use of tech- nology by health care organizations. While computerized records and use of the Internet can provide greater protections for information, they also open the door for broader access if confidentiality and security are breached. In fact, the media reports regularly on heath privacy and security violations. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 7 Many patients have developed a variety of Protecting Health Privacy “privacy-protective” behaviors to shield them- As a result of these fears and their negative selves from what they consider to be harmful impact on the quality of health care, many and intrusive uses of their health information. states—including California—and the Federal A poll conducted for the California HealthCare government have enacted protections for health Foundation in January 1999 found that: information. These laws vary considerably as s One in five American adults believes that a to the entities and types of specific information health care provider, insurance plan, govern- they cover and the strength of the protections ment agency, or employer has improperly that they provide. disclosed personal medical information. Half of these people say it resulted in personal embarrassment or harm. s One in six American adults says he or she has done something out of the ordinary to keep personal medical information confiden- tial. Among the actions reported are: going to another doctor; paying out-of-pocket for serv- ices; not seeking care; giving inaccurate or incomplete information on a medical history; and asking a doctor not to write down the health problem or record a less serious or embarrassing condition. s Only a third of U.S. adults say they trust health plans and government programs like Medicare to maintain confidentiality all or most of the time. 8 | CALIFORNIA HEALTHCARE FOUNDATION II. The Federal Health Privacy Rule Although Congress has recog- Introduction nized the importance of In the last few years, health privacy has emerged as a prom- inent health care policy issue at the federal level. Although protecting the confidentiality Congress has recognized the importance of protecting the con- of health information, it has fidentiality of health information, it has been unable to pass any comprehensive health privacy legislation. Congress did, been unable to pass any however, give limited authority to the U.S. Department of comprehensive health privacy Health and Human Services to issue regulations protecting the privacy of health information. Understanding the genesis of legislation. the Federal Health Privacy Rule is important for understanding the scope of the federal rule and how it operates. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) includes a major initiative, known as Privacy Rule Updates the “administrative simplification provisions,” intended to cut To receive email notification on administrative health care costs by standardizing electronic changes to the Privacy Rule health care transactions. Prior to HIPAA’s passage, this and other health privacy news sign up to the Health Privacy move towards standardization raised serious privacy concerns. Project’s listserv at: To reconcile these competing priorities of safeguarding privacy http://www.healthprivacy.org. and easing the flow of health data, Congress included in HIPAA a requirement that if it failed to pass comprehensive health privacy legislation by August 1999, the Secretary of the United States Department of Health and Human Services (HHS) would issue regulations. Despite the introduction of numerous proposals, Congress failed to meet its deadline, and the duty passed to HHS to promulgate health privacy regulations. As required under HIPAA, the Secretary of HHS issued final health privacy regulations in December 20001 (see Timeline next page). After a short delay, the final regulation, known as the “Privacy Rule,” became effective April 14, 2001. The Privacy Rule has the force of law. Compliance with the Privacy Rule is generally required by April 2003. Although the Privacy Rule is “final,” that does not mean that it will not be changed. HHS has made it clear that it intends to engage in additional rule-making to substantively change the rule in the near future.2 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 9 These persons and organizations are referred to Timeline as “covered entities.”4 Any person or organization November 3, 1999 that provides or pays for health care should review Draft rule published in the Federal Register. these provisions carefully to determine whether February 17, 2000 or not they are covered by the Privacy Rule. Public comment period closes. The Department of Health and Human Services Health Plans received more than 52,000 comments The definition of “health plan” is quite broad on the draft. and generally includes any individual or group December 28, 2000 plan that provides or pays for medical care.5 The final privacy rule is published in the The term encompasses both private and govern- Federal Register. mental plans. It includes health insurance issuers April 14, 2001 and HMOs. High-risk pools are specifically The rule becomes effective, but covered covered, as are Medicaid and Medicare plans. entities do not yet have to comply with it. Additionally, most employee health benefit plans July 6, 2001 are covered. HHS releases guidance, interpreting the final rule. The Privacy Rule specifically excludes certain April 14, 2003 entities that provide or pay for health care. For Covered health care providers and most example, small employee health benefit plans health plans must be in compliance with (fewer than 50 participants) that are self-adminis- the rule. tered are exempt. Likewise, workers’ compensa- April 14, 2004 tion carriers are excluded from the definition Small health plans must be in compliance. of health plan. Furthermore, government-funded programs that only incidentally provide or pay for the cost of health care are not health plans.6 Health Care Clearinghouses Who Is Covered? “Health care clearinghouse” is a term of art under The Privacy Rule does not apply to everyone the Privacy Rule, and differs somewhat from who receives or maintains health information. the manner in which the term is generally used. Congress authorized HHS to issue regulations Under the Privacy Rule, a health care clearing- only with respect to three specified types house is an entity that translates health infor- of entities that transfer or maintain health infor- mation received from other entities either into or mation. The Privacy Rule, therefore, directly from the standard format that will be required applies only to: for electronic transactions under HIPAA.7 For s Health plans; instance, many health providers use the services s Health care clearinghouses; and of a health care clearinghouse to process their s Health care providers who transmit health claims information into a standard format for information in electronic form in connection submission to a health plan. with specified financial and administrative transactions (such as claims for payment).3 10 | CALIFORNIA HEALTHCARE FOUNDATION Health Care Providers Who Electronically Standard transactions.13 To come within the Transmit Health Information scope of the Privacy Rule, the health information The Privacy Rule covers health care providers must be transmitted in standard format in con- who transmit health information in electronic nection with one of the financial and administra- form in connection with HIPAA standard trans- tive transactions listed in Section 1173 of HIPAA. actions.8 A health care professional or facility These transactions include, but are not limited must meet all three of the following criteria to to, health claims, determining enrollment and be covered by HIPAA. eligibility in a health plan, and referral authoriza- tion.14 Providers who submit health claims elec- Health care provider. For purposes of the regula- tronically will be required to transmit them in tion, “health care provider” includes any person standard format by October 2003 at the latest.15 or entity that furnishes, bills, or is paid for health care in the normal course of business.9 “Health In addition to covering those providers who care,” in turn, is broadly defined as “care, services, directly engage in such transactions, the Privacy or supplies related to the health of an individ- Rule also covers those who rely on third-party ual.”10 Thus, the term health care provider billing services to conduct such transactions on includes both persons (such as dentists and their behalf.16 In contrast, providers who operate podiatrists) and entities (such as hospitals and solely on an out-of-pocket basis and do not sub- clinics). It includes mainstream practitioners mit insurance claims probably will not be subject (such as physicians, nurses, and psychothera- to the rule. For instance, an Internet pharmacy pists), as well as providers of alternative care that only accepts credit card payments will not be (such as homeopaths and acupuncturists). The covered by the Privacy Rule. If this Internet phar- Privacy Rule also covers both the providers of macy also accepts insurance payments, however, care and services (such as practitioners) and the then it may be covered by the rule. providers of health supplies requiring a prescrip- tion (such as pharmacists and hearing aid dis- What Is Covered? pensers). However, the Privacy Rule is not intended to encompass blood banks, sperm Generally, the Privacy Rule covers “protected banks, organ banks, or similar organizations.11 health information” in any form that is created or received by a covered entity.17 There are a number Transmitting health information electronically.12 of elements that must be satisfied before health To “transmit health information in electronic information is protected by the Privacy Rule. form,” a provider must transfer personally identi- First, it must be “health information” as defined fiable health information via computer-based in the rule. Second, the health information must technology. Using the Internet, an Intranet, or a be individually identifiable. Finally, it must be private network system will bring a provider created or received by a covered entity.18 within the reach of the Privacy Rule. Similarly, information transferred from one location to another using magnetic tape or disk is covered by the Privacy Rule. In contrast, sending informa- tion via fax is not considered to be transmitting information electronically. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 11 Health Information If health information meets these criteria, it is “Health information” is broadly defined as considered “protected health information” and is meaning any oral or recorded information relat- covered by the rule regardless of the media or ing to the past, present, or future physical or form in which it is maintained or transmitted. mental health of an individual, the provision of This means that oral, written, and electronic health care to the individual, or the payment information is protected health information.23 for health care.19 This definition is broad enough Because this guide focuses on implementing to encompass not only the traditional medical the Privacy Rule, the term “health information” record but also physicians’ personal notes and as used in this guide refers only to “protected billing information. health information,” i.e., individually identifiable health information created or received by a Individually Identifiable covered entity. Individually identifiable health information” is health information that identifies or reasonably can be used to identify the individual.20 Health Requirements information that has been “de-identified” is In the broadest of terms, the Privacy Rule does not covered. A covered entity may de-identify two things: (1) it imposes new restrictions on health information by removing specific identi- how covered entities can use and share health fiers (including, but not limited to, name, social information; and (2) it creates new rights for security number, medical record number, and individuals concerning their own health informa- address). Alternatively, a covered entity may treat tion. A general overview of the requirements of information as de-identified if a qualified statis- the Privacy Rule follows. The specific imple- tician, using accepted principles, determines mentation requirements will vary depending on that the risk that the individual could be identi- existing California law and are discussed in fied is very small.21 Sections IV and V of this guide. Created or Received by a Covered Entity General Restrictions on Use and Disclosure Health information that is “created or received The Privacy Rule governs the “use” and “disclo- by a covered entity” is protected under the rule.22 sure” of protected health information by covered Any health information that a patient would entities. These two terms have specific meanings divulge to his or her doctor would be covered. within the context of the Privacy Rule.24 In contrast, health information that is created or received by others is not covered. For example, Use. Protected health information is used when it is shared, examined, applied or analyzed within a if an individual fills out a health assessment covered entity that receives or maintains the survey as part of donating blood to the Red information. Cross, that information would not be protected because the Red Cross is not a covered entity. Disclosure. Protected health information is disclosed when it is released, transferred, allowed to be accessed, or otherwise divulged outside the entity holding the information. 12 | CALIFORNIA HEALTHCARE FOUNDATION In general, the Privacy Rule prohibits covered Authorization entities from using or sharing protected health s If the intended purpose of obtaining or using information without the individual’s permission. health information is not specifically permitted The Privacy Rule then lists a number of excep- in the Privacy Rule, any covered entity must tions where use and disclosure are permitted obtain an individual’s signed written permis- without the individual’s written permission. sion, an “authorization,” prior to using or dis- When disclosure is permitted without the closing the health information. patient’s permission, the Privacy Rule generally imposes conditions specific to the purpose for s An authorization is generally used for purposes which the health information is being released. other than treatment, payment, or health care In order to use or disclose health information for operations. Authorization forms are specifically a purpose that is not specified in the rule, the required for many uses, such as disclosures of covered entity must first obtain a patient’s writ- psychotherapy notes ten permission. s In contrast to a consent, an authorization is a detailed form containing specifics about: Key Restrictions on Use and Disclosure with whom information is being shared; how Some of the major restrictions on using and it is to be used and disclosed; and the length disclosing health information include: of time it is effective. These forms must be tailored to fit the particular purpose for Consent which the health information is to be used s Health care providers who provide treatment or disclosed. or health care products directly to patients must obtain an individual’s written permis- Minimum Necessary sion, a “consent,” prior to using or disclosing s For most uses and disclosures, a covered entity health information for treatment, payment, is required to develop policies and practices or health care operations purposes.25 reasonably assuring that the minimum amount s Health plans are not required to obtain such of health information necessary is used or a consent. shared. Consent forms generally advise patients that s This standard does not apply to requests by their health information may be used for treat- or disclosures to health care providers for ment, payment, and health care operations treatment purposes. purposes and inform them of their general rights with respect to this information. Consents do Business Associates not contain specific details of the covered entities’ In order to disclose protected health information use and disclosure of health information, but to a third party who assists them with their refer patients to the covered entities’ notice of business functions (business associates), covered privacy practices for this information. (See entities are required to have contracts ensuring “Patients’ Rights,” below.) that the business associate will adequately safeguard the information. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 13 Affording Patient Rights Compliance The Privacy Rule also grants individuals a num- Health care providers, health care clearinghouses ber of rights over their health information. The and most health plans that are covered by the main rights include: (1) the right to receive a Privacy Rule must comply with the new require- notice of information practices; (2) the right to ments by April 2003.26 Small health plans see and copy their own health information; (those with annual receipts of $5 million or less) (3) the right to amend their health information, have an additional 12 months to come into if it is inaccurate; and (4) the right to an compliance27 (see Timeline). It should be noted accounting of disclosures. that these deadlines might change if HHS sub- Covered entities have the duty to ensure that stantively alters the Privacy Rule through official individuals are able to exercise these rights with rule-making procedures.28 respect to protected health information that The HHS Office for Civil Rights (OCR) is they maintain. in charge of ensuring compliance with and enforcing the Privacy Rule.29 In performing these Administrative Requirements functions, OCR’s general philosophy is to pro- The Privacy Rule requires covered entities to vide a cooperative approach towards compliance, implement a number of administrative practices including use of technical assistance and informal in order to ensure compliance. Among other means to resolve disputes.30 things, covered entities are required to: On July 6, 2001, OCR issued its first set of s Develop written privacy policies and proce- guidance to answer many common questions dures with respect to who has access to health about the new Privacy Rule and to clarify some information within an organization, how it of the confusion regarding the Privacy Rule’s will be used, and when the information may potential impact on health care delivery and be disclosed; access.31 Within its limited resources, OCR intends to continue to provide technical assis- s Put into place appropriate administrative, tance to help covered entities implement the technical, and physical safeguards to protect Privacy Rule.32 The initial guidance and other the privacy of protected health information; information about the new rule are available on s Train personnel about the Privacy Rule; the Web at http://www.hhs.gov/ocr/hipaa. s Designate a privacy officer, who will be in charge of implementing the Privacy Rule; s Designate a contact person, whom people can contact with questions about privacy; and s Maintain documentation of consents, autho- rizations, procedures and policies, training, and other activities undertaken in compliance with the Privacy Rule. 14 | CALIFORNIA HEALTHCARE FOUNDATION Covered entities are not required to obtain Remedies and Penalties prior approval from HHS for their compliance HIPAA establishes civil and criminal penalties for activities (such as developing privacy policies). violations of the Privacy Rule. There is a $100 Neither are they currently required to submit civil penalty up to a maximum of $25,000 per compliance reports, although this may change in year for each standard violated. 39 For knowing, the future.33 Rather, compliance issues will come wrongful disclosures of health information, a to the OCR’s attention primarily through two criminal penalty may be imposed.40 It is a gradu- different means: ated penalty that may escalate to a maximum of s Complaints. Anyone who believes that a $250,000 for particularly egregious offenses. covered entity is in violation of the Privacy HIPAA does not give individuals a federal right Rule may file a complaint with OCR.34 to sue for violations of the Act. Because the s Compliance reviews. OCR has the authority Privacy Rule creates a new “duty of care” with to conduct compliance reviews to determine respect to health information, it is possible, how- whether covered entities are complying with ever, that violations may be the grounds for state the requirements of the Privacy Rule.35 tort actions. The rule requires covered entities to cooperate The Privacy Rule does not contain any provisions with any resulting investigations.36 In these specifically addressing penalties. Rather, HHS proceedings, covered entities are required to doc- plans at a future date to issue an Enforcement ument that they have undertaken the necessary Rule governing penalties that will apply to all of steps to achieve compliance (e.g., establishing a the regulations issued under Administrative privacy policy).37 They are also required to pro- Simplification provisions of HIPAA, including vide access to such protected health information the Privacy Rule.41 and other relevant information as necessary for compliance and investigation purposes.38 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 15 III. The Interaction of the Federal Health Privacy Rule and California Privacy Laws In a state like California, Introduction where there are strong, The Federal Privacy Rule was not issued in a vacuum. Privacy protective laws already exist in many states. California, in detailed health privacy particular, has been in the forefront of enacting laws that standards in place, there protect the privacy of health information. effectively will be dual tracks The Federal Privacy Rule essentially sets a national “floor” of privacy standards that protect the health information of all of regulation, one state and Americans. It preempts or overrides state laws that are contrary one federal, whose require- to the Federal Privacy Rule and that are less protective. ments often intertwine. State laws that are not contrary to the Federal Privacy Rule remain effective. A state law is “contrary to” the Federal Privacy Rule when: s A covered entity would find it impossible to comply with both the state and federal requirements; or s The provision of state law stands as an obstacle to the accomplishment and execution of the Federal Privacy Rule.42 State Reporting Laws Q: Will the Federal Privacy Even if a state law is contrary to the Federal Privacy Rule, it Rule interfere with state will not be preempted if it is “more stringent.” Generally, a reporting laws? state law is considered to be more stringent if: A: No. HIPAA expressly ex- s It is more restrictive than the Federal Privacy Rule with cludes from federal preemp- respect to a use or disclosure,; or tion state laws that require health plans to report (or to s It provides greater rights of access or amendment with respect provide access to) information to individuals’ access to their own health information.43 for: management audits; In a state like California, where there are strong, detailed financial audits; program monitoring and evaluation; health privacy standards in place, there effectively will be dual and licensure or certification tracks of regulation, one state and one federal, whose require- for facilities or individuals. ments often intertwine. See 45 C.F.R. § 160.203(d). 16 | CALIFORNIA HEALTHCARE FOUNDATION Complying with Both State advance notice of this policy. To comply with and Federal Laws both laws, follow the strictest standard—in this A health insurer or health care service plan case, give notice that only written requests for should first determine whether it is covered by copies will be accepted. the Federal Privacy Rule. It should then deter- When the state and federal standards are not mine which health privacy laws it must already comparable, it will be necessary to determine if comply with under California law. Some of the state law is contrary to the Federal Privacy the major California health privacy statutes that Rule and, if so, if it is more stringent. Making may apply to insurers and plans include: this determination will not always be a straight- s Confidentiality of Medical Information Act;44 forward process. Using this guide should make it s Insurance Information and Privacy Protection somewhat easier. Act.45 s Knox-Keene Health Care Service Plan Act;46 and Enforcing California Law s Medi-Cal statute and regulations.47 Q: Who will enforce the California health Additionally, there are a number of state statutes privacy laws after implementation that protect the privacy of health information of the Federal Privacy Rule? associated with information gained through the A: California health privacy laws will continue treatment of certain medical conditions, includ- to be enforced at the state level. Violation ing, but not limited to, the following: of a California law may result in the im- position by a California court, licensing body s Mental health;48 or regulating agency of civil and/or criminal s HIV/AIDS tests;49 and penalties. s Alcohol and drug dependency.50 Q: Will patients have the right to sue? Once a health plan has identified all the state A: Yes, in many cases. Many California health laws that are particularly applicable to it, it privacy statutes (e.g., Insurance Information will need to compare the provisions of the state and Privacy Protection Act) give patients the right to sue if their health information laws to the requirements of the Federal Privacy is improperly disclosed or if they are Rule on an item-by-item basis. The following improperly denied access to their health sections of this guide will discuss many of the information. Patients generally will retain provisions of the Federal Privacy Rule, California these rights to sue for violations of their state laws, and how they interact. privacy rights under California law after implementation of the Federal Privacy Rule. The Federal Privacy Rule has many standards that are similar to those in California privacy laws. When the standards are comparable, plans should follow the “more stringent” standard. For example, under California law, an individ- ual’s request for a copy of his health information must be in writing. The Federal Rule permits insurers to have a policy of accepting only writ- ten requests for copies so long as the plan gives Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 17 The purpose of this guide is to provide a general road map to the combined state and federal requirements that health care plans will have to comply with upon implementation of the Federal Privacy Rule. From the state perspective, this guide focuses on the Insurance Information and Privacy Protection Act, the Confidentiality of Medical Information Act, and the Knox-Keene Health Care Service Plan Act. This guide does not identify or address all of the state health privacy laws that may be applicable to any given covered entity—it only highlights some of the major relevant state privacy laws. The guide also only addresses some of the major changes in practice that the Federal Privacy Rule will require. The Federal Privacy Rule is lengthy and detailed, and careful reading of the entire rule will be necessary to ensure complete compliance. 18 | CALIFORNIA HEALTHCARE FOUNDATION IV. The Insurance Information and Privacy Protection Act Under the IIPPA, health Background insurers currently may disclose Existing Requirements in California Law health information to a The Insurance Information and Privacy Protection Act (IIPPA) applies (with some exceptions) to anyone engaged in third party if the recipient the business of insurance. Among others, it covers commercial agrees not to further disclose health insurers as well as fraternal benefit society plans.51 In general terms, the IIPPA regulates the collection, use, and the information. The Federal disclosure of a broad range of “personal information,” includ- Privacy Rule takes this ing health information, gathered in connection with insurance transactions.52 It generally prohibits disclosing health infor- requirement one step further, mation unless the insurer either has the individual’s written [requiring health insurers] to authorization or the disclosure is for a purpose specifically enter into written contracts. permitted by the statute. In addition to restricting disclosures, the IIPPA gives individuals rights with respect to their health information, including the right to see, copy, and amend their own information. It also requires health insurers to provide individuals with a notice describing how their information may be collected and shared. Similarities between California Law and the Federal Privacy Rule The framework of the Federal Privacy Rule is fairly similar to the IIPPA, although it applies to a narrower category of information—individually identifiable health information.53 It generally prohibits using or sharing health information without the individual’s permission unless the purpose for the disclosure is specifically permitted by the rule. When disclosure is permitted without the individual’s permission, the Privacy Rule generally imposes conditions specific to the purpose for which the health information is being used or released. If a purpose is not specified in the regulation, the insurer must obtain an individual’s authorization prior to using or disclosing the health information. And like California law, the Federal Privacy Rule gives individuals the right to see, copy, and amend their health information. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 19 Key Differences between California Law Minimum Necessary Standard and the Federal Privacy Rule The IIPPA generally limits the amount of health The Federal Privacy Rule, however, does signifi- information that a health insurer can disclose to cantly differ from California law in the following what is “reasonably necessary” for the specified key areas: purpose.54 Health insurers will be required to adhere to a stricter standard under the Federal s Health insurers will be required to have con- Privacy Rule. The Privacy Rule requires covered tracts with those they share information with entities, including health insurers, to request, use, for administrative or business functions that and disclose the minimum amount of health will require those “business associates” to information necessary to accomplish their goals. adequately safeguard the health information; This is known as the “minimum necessary” stan- s In many circumstances, health insurers will dard. This standard does not apply to disclosures be required to limit the health information to or requests by a health care provider for they request, use, or disclose to the minimum treatment purposes.55 amount necessary to accomplish the intended purpose; s Health insurers will be prohibited from requir- Minimum Necessary vs. HIPAA ing patients to provide access to psychotherapy Transaction Standards notes as a condition of enrollment or payment Under the HIPAA transaction standards, cov- of a claim. ered entities who process health claims-type information electronically will be required s Health insurers will be required to undertake to use a set format that includes certain data additional administrative duties to comply elements. For example, health insurers will with the Privacy Rule, such as training, desig- be required to accept health claims that are electronically submitted in the standard format. nating a privacy official, and designing new notice and authorization forms. Q: How will the minimum necessary stan- dards affect these standard transactions? These key differences, as well as the regulations A: It depends on the specific data element that govern obtaining, using, and disclosing at issue. The minimum necessary rule does health information for particular purposes, are not apply to those data elements that are discussed below. required under the transaction standards. However, to the extent providing infor- mation on a standard form is discretionary, Restrictions on Use and Disclosure a covered entity may conduct a minimum of Health Information necessary analysis to determine whether The Federal Privacy Rule establishes some use providing such optional information is necessary to accomplish the intended and disclosure restrictions that are generally purpose. See HHS Guidance. applicable in most circumstances. It also estab- lishes rules that apply when health information is used or shared for specific purposes. 20 | CALIFORNIA HEALTHCARE FOUNDATION The Privacy Rule is intended to make health s Determination of eligibility or coverage insurers evaluate their privacy practices and (including coordination of benefits or the improve them as needed to prevent unnecessary determination of cost-sharing amounts); or inappropriate access to protected health infor- s Risk-adjusting amounts due based on enrollee mation.56 For most routine purposes, the Privacy health status and demographic characteristics; Rule requires that health plans have policies and procedures to request, use, and share the mini- s Billing, claims management, collection acti- mum amount of health information necessary to vities, obtaining payment under a contract for accomplish the intended purpose. As a general reinsurance; rule, health insurers are not required to conduct a s Review of health care services with respect to case-by-case review. medical necessity, coverage under a health Uses. For uses (i.e., utilizing or sharing health plan, appropriateness of care, or justification information within an entity), a health insurer of charges; and must identify those within the organization who s Utilization review activities, including precerti- need access to health information, the categories fication and preauthorization of services, and or type of information they need, and conditions concurrent and retrospective review of services. appropriate to such access.57 The health insurer must develop policies and procedures that imple- ment this analysis and must document them in written or electronic form.58 Preparing to Implement the Privacy Rule: Key Questions Disclosures and requests for disclosures. For Perform a “health information” audit, answer- routine or recurring requests and disclosures, a ing some of these key questions: health insurer’s policies must limit the protected Who has access to health information within health information disclosed or requested to the organization? the minimum amount necessary for that parti- cular type of disclosure or request.59 These Who should have access to this information? policies must also be maintained in written or What type and amount of health information electronic form.60 are reasonably necessary for them to accomplish their job? A health insurer is limited in the type and Should there be a limit on the time frame in amount of information it can request for pay- which they have access? ment purposes? This limitation, however, should not interfere with normal business practices. Should there be other constraints on access, (e.g. information should not be removed from The minimum necessary standard does apply to the premises)? requests for payment purposes. “Payment,” however, is broadly defined in the Privacy Rule From whom does the health insurer request and, among other things, includes: health information on a regular basis? What types of health information are requested? Is all the requested information necessary for the intended purpose of the information? Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 21 Business Associates: Sharing Health A health insurer can be a business associate of Information for Administrative Purposes another covered entity. When the health insurer Health insurers may routinely hire other com- performs functions or provides services in addi- panies and consultants to perform a wide variety tion to or not directly related to the provision of functions for them. Insurers, for example, of insurance, the insurer is a business associate may work with outside attorneys and account- with respect to those additional functions or ants. Under the IIPPA, health insurers currently services.65 For example, when an insurer acts as a may disclose health information to a third party third party administrator for a self-funded group to enable it to perform a business, professional health plan, it is a business associate of the or insurance function on the insurer’s behalf, group health plan. if the recipient agrees not to further disclose the information.61 The Federal Privacy Rule takes this requirement Violation of Contracts one step further. Health insurers that wish to Q: Can a health insurer be held respon- use outside sources to perform these types of sible if a business associate violates its administrative functions will be required to enter contract? into written contracts ensuring that the recipient A: Only if the health insurer knew the busi- of the information (a “business associate”) ness associate was materially violating its con- appropriately safeguards the health information.62 tractual duty to safeguard health information and did nothing about it. An insurer that Definition of “business associate.” Under the knows that its business associate engages in Privacy Rule, anyone who performs a function a pattern of activity or a practice that materially involving the use of health information on behalf violates the privacy provisions of its contract must take reasonable steps to correct the of a covered entity, including a health insurer, or situation. If these steps are unsuccessful, who furnishes certain services (such as legal, the health insurer is required to either: actuarial, or other administrative services) to the (1) terminate the contract if feasible; or (2) if insurer is a “business associate.”63 termination of the contract is not feasible, report the problem to the U.S. Department A key element of being a business associate is of Health and Human Services. that the person or organization receives health 45 C.F.R. § 164.504(e). information either from or on behalf of a health insurer. Under this standard, a billing agency would be a business associate, while a supplier of paper products would not. The rule is not intended to cover those who merely act as a con- duit for protected health information, like the U.S. Postal Service or FedEx.64 22 | CALIFORNIA HEALTHCARE FOUNDATION The necessary elements of a business associate Uses and Disclosures That Do Not Require contract. The Privacy Rule contains a fairly an Individual’s Written Permission lengthy, detailed list of provisions that must be Both the IIPPA and the Federal Privacy Rule included in a business associate contract. Among allow a health insurer to use and disclose health other things, the business associate contract must information without the individual’s written provide that the business associate will:66 permission in a number of circumstances.67 The laws generally impose conditions specific to s Not use or further disclose the information the particular purpose for which the health infor- other than as permitted or required by the mation is to be used or disclosed. Due to the contract or as required by law; number of circumstances under which use and s Use appropriate safeguards to prevent use or disclosure are permitted without any patient per- disclosure of the information other than mission and the details of the related conditions, as provided for by its contract; only a few of these purposes are discussed.68 s Ensure that subcontractors who receive pro- Treatment, payment and health care operations. tected health information from a business The IIPPA allows health plans to disclose health associate agree to the same restrictions and information without the individual’s written conditions as in the contract; and authorization for a number of purposes, including:69 s Authorize termination of the contract by the s To determine an individual’s eligibility for an covered entity if the covered entity determines insurance benefit or payment; that the business associate has violated a mate- s To a medical care institution or medical pro- rial term of the contract. fessional for the purpose of verifying insurance coverage or benefits; Information Obtained for Underwriting s To a medical care institution for the purpose of informing the individual of a medical Often a health plan will receive health infor- mation for the purpose of underwriting, problem of which the individual might not premium rating, or other similar activity related be aware; to creating or renewing a health insurance s To other insurance institutions to allow either contract without the individual’s authorization. the disclosing or receiving institution to Q: What happens to this information if perform its function in connection with an the insurance contract is never placed? insurance transaction; Can the health plan still use or share the health information? s To detect or prevent fraud; A: No. This information generally may not be s To provide customer service;70 used for any other purpose without the s To carry out business planning and develop- individual’s authorization. ment; 71 and 45 C.F.R. § 164.514. s To conduct legal services.72 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 23 After implementing the Federal Privacy Rule, health insurers will still be able to disclose health Restrictions on Use of Social Security Numbers information without the individual’s written per- Health insurers and health care service plans mission for these purposes. The Federal Rule should be aware of a recently-enacted Califor- allows health plans, including health insurers, to nia law that restricts the use of social security use and disclose protected health information numbers. Under the state law, health insurers, without the individual’s written permission for health care service plans, and others may purposes of treatment, payment, or health care not engage in any of the following activities: operations.73 All of the above purposes are con- • Publicly posting or publicly displaying an sidered to be treatment, payment, or health care individual’s social security number; operations functions under the Federal Rule.74 • Printing the individual’s social security num- (It should be noted that even though a health ber on any card required for the individual insurer can disclose health information without to access products or services (such as a the individual’s permission for these purposes, health plan identification card); it may only do so in certain circumstances • Requiring the individual to transmit his or her if a business associate contract is in place. See social security number over the Internet discussion about business associates above.) unless the connection is secure or the social security number is encrypted; In contrast, health care providers must obtain a patient’s consent prior to using health • Requiring an individual to use his or her information for treatment, payment, or health social security number to access an Internet Web site, unless a password or unique per- care operations purposes, under the Federal sonal identification number is also required Privacy Rule.75 to access the Web site; and • Printing an individual’s social security number on any materials (such as explanation of benefits forms), unless required by state or Web Sites federal law. A health insurer that has a website that pro- vides information about its customer services The use of social security numbers for internal must post its notice of privacy practices on verification or administrative purposes is per- its site in such a manner that people are able mitted. There are staggered compliance dates to download it. for these various requirements, the earliest being January 1, 2003. See Cal. Stats. 2001 ch 45 C.F.R. § 164.520(c). 720, adding Section 1798.85 to the Civil Code. 24 | CALIFORNIA HEALTHCARE FOUNDATION Right to request heightened protections in the Law enforcement. The IIPPA permits a health context of treatment, payment, and health care insurer to disclose health information “as required operations. Although health insurers are not by law.”79 The Federal Privacy Rule does not required to obtain written permission to use or change this standard but does specifically limit disclose an individual’s health information for permitted disclosures to the health information treatment, payment, or health care operations that is relevant to the requirements of the law.80 purposes, this does not mean that the individual Civil discovery. A health insurer may disclose has no right whatsoever over the information. protected health information in response to a The Federal Privacy Rule gives individuals subpoena, discovery request, or other lawful the right to request heightened protections in process that is not accompanied by a court order two manners: (1) by asking that a health insurer without the individual’s authorization only when restrict its uses and disclosures, and (2) by asking the insurer has received certain assurances.81 In that an insurer send communications by specific particular, the party seeking the information means.76 These rights were crafted, at least must provide a written statement that it has partially, in response to requests from advocacy made reasonable efforts to ensure that the indi- groups representing those with sensitive medical vidual who is the subject of the information has conditions. been given notice of the request and a chance to s Right to request restrictions.77 Individuals object to it. Alternatively, the requester must have the right to request that covered entities, present documentation that it has sought a pro- including health insurers, restrict how they tective order. use or share protected health information for the purposes of treatment, payment, and Marketing82 health care operations. Health insurers are not A health insurer may use or disclose health infor- required to agree to requests to restrict, but are mation for marketing purposes without the indi- bound by any agreements to which they agree. vidual’s written permission depending on who is actually performing the marketing activities. s Right to Request Confidential Communica- The Federal Privacy Rule requires a health plan tions.78 Some individuals are concerned about to obtain an individual’s authorization prior to: receiving information about their health treat- ment or payment at home. Under the Federal s Selling protected health information to a third Privacy Rule, they will have the right to party for its use and re-use; and request that covered entities, including health s Disclosing protected health information to a insurers, contact them only in a specified man- third party for the third party’s own, inde- ner (such as telephoning them only at work) pendent marketing use. or sending communications only to a specific location. A health insurer must agree to such a request if the individual clearly states that the disclosure of the protected health information could endanger him or her. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 25 However, the Privacy Rule permits a health Existing requirements for authorizations under insurer to use or disclose health information for IIPPA. The IIPPA provides for two different marketing purposes without the individual’s types of authorization forms. A detailed authori- authorization if the following conditions are met: zation form is used when disclosure is sought by an insurer, agent, or insurance support s The health insurer uses or discloses health organization, and an abbreviated form is used information only to market health-related when disclosure of information is sought by products and services on its own or a third parties other than insurers, agents, or insurance party’s behalf; support organizations. The abbreviated form, s The information is only disclosed to a business which had minimal requirements, will no longer partner that assists the insurer with such be acceptable upon implementation of the communications; and Federal Privacy Rule.87 Rather, the authorization will have to comply with the detailed elements s The marketing communication contains of an authorization form as required by the required information, including details on Federal Privacy Rule, plus any additional require- how the individual may opt out of receiving ments of the IIPPA. future marketing communications. Essential elements of authorization submitted Authorizations by those other than insurance organizations Currently, under the IIPPA, if a disclosure is not (IIPPA and Federal Privacy Rule). In order to specifically permitted or required by the statute, a comply with both the IIPPA and the Federal health insurer must obtain a patient’s authoriza- Privacy Rule, an authorization form that is sub- tion prior to disclosing his or her health informa- mitted by someone other than an insurer, insur- tion.83 The Federal Privacy Rule takes a similar ance agent, or insurance support organization approach. For purposes that are not expressly must, at a minimum: addressed in the Federal Privacy Rule, covered s Be written in plain language;88 entities, including health insurers, will be s Be separate (with some exceptions);89 required to obtain a patient’s authorization prior to using or disclosing his or her protected s Be signed and dated;90 health information.84 s Specifically describe the health information to For example, the Federal Privacy Rule permits be used or disclosed;91 providers to disclose protected health informa- s State the name or function of the person tion to a health insurer for enrollment purposes (organization) authorized to make the only pursuant to a written authorization of the disclosure;92 individual.85 An insurer may, however, condition enrollment on the enrollee’s providing such s State the specific date or event after which an authorization form.86 the insurer is no longer authorized to disclose the information; this date may not exceed one year after the date the authorization was originally obtained;93 26 | CALIFORNIA HEALTHCARE FOUNDATION s State the names or functions of persons Revocation of authorizations.100 An individual (organizations) authorized to use or receive has the right to submit a written revocation of the information;94 his or her authorization at any time. A revocation is not effective, however, to the extent that a s Inform the individual of his or her right to covered entity has taken action in reliance on it. revoke the authorization under the Federal Neither is a revocation effective with respect to Privacy Rule; and95 authorizations that were obtained as a condition s Include a statement that information used of providing insurance coverage when other laws or disclosed under the authorization may be provide the insurer with the right to contest a subject to redisclosure by the recipient and claim under the policy. may no longer be protected by the Federal Privacy Rule.96 Disclosures to Sponsors of Group Health Plans Authorizations submitted by insurers, insurance Under California law, health insurers that issue agents, or insurance support organizations. coverage to group health plans generally are pro- Authorizations submitted by insurers, insurance hibited from sharing identifiable health informa- agents or insurance support organizations must tion with the sponsors of the plan without the have all the above elements. In addition they individual’s authorization.101 Since this standard is must:97 more stringent than the Federal Privacy Rule, it s Specify the purpose for which the information will remain in place.102 Health insurers may, how- is being disclosed; ever, disclose “summary health information” to a plan sponsor to permit the plan sponsor to solicit s State that they are effective for the term of the premium bids for providing health insurance coverage (in lieu of expiring in one year); and coverage under the group health plan or for the s Advise the individual of his or her right to purpose of modifying, amending, or terminating receive a copy of the authorization. the group health plan.103 “Summary health infor- mation” is information that summarizes the If an authorization is requested by a health claims history, claims expenses, or type of claims insurer for its own use or disclosure of health experienced by individuals for whom a plan information that it maintains, the authorization sponsor has provided health benefits under a form must include additional elements. Among group health plan from which certain identifiers other things, such an authorization must:98 (such as name, social security number, birth date s If applicable, state that the covered entity will [except year] and others) have been removed.104 not condition treatment, payment, enrollment Health insurers that act as third party adminis- in the health plan, or eligibility of benefits trators for self-insured group health plans will be on the individual’s providing the requested constrained in disclosing health information to authorization; and plan sponsors through general restrictions in the s State that the individual has the right to refuse business associate contracts they have with group to sign the form. health plans.105 A health insurer that obtains an authorization for its own uses or disclosures must give the individ- ual a copy of the signed authorization.99 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 27 Information Related to Psychotherapy Patient Rights Information related to psychotherapy is given In addition to imposing restrictions on how heightened protection by both California law health insurers can use and disclose protected and the Federal Privacy Rule. The rules vary health information, both California law and the depending on the specific type of psychotherapy- Federal Privacy Rule grant patients rights with related information being sought. respect to their own health information. These Psychotherapy-related information other than rights are based in fair information practice notes of a therapy session. If a health insurer principles, and essentially give patients the right: wishes to obtain psychotherapy-related informa- (1) to know how their information is being used; tion (other than psychotherapy notes) from a (2) to know with whom it is being shared; (3) to provider, under the CMIA the insurer must sub- review their information, and (4) to amend it, mit a detailed, written request to that provider.106 if necessary. The request must include: (1) the specific infor- mation related to psychotherapy treatment that is Notice of Privacy Practices being requested; (2) the specific intended use Those subject to the IIPPA should already be of the information; (3) how long the information familiar with furnishing notices of information will be used; and (4) other information. The practices to applicants and policyholders with patient’s signature is not required on the request, respect to their personal information.110 A notice but he or she must be provided with a copy.107 of information practice under the IIPPA must For example, a health insurer desiring infor- specify the source and type of information an mation about a diagnosis related to psychothera- insurer collects about an individual. Additionally, py would need to submit to the provider a the notice must inform individuals of disclosures written request specifically detailing the infor- that the insurer is permitted to make without mation it desires. the individual’s written authorization. It must also advise individuals of their rights to see, copy, Psychotherapy notes. The Federal Privacy Rule and correct their personal information. imposes even more restrictions on the disclosure of psychotherapy notes (i.e., notes documenting The Federal Privacy Rule will require health or analyzing the contents of conversations taking insurers to provide similar notices specifically place during therapy).108 A request under the describing their privacy practices with respect to CMIA will not be sufficient for obtaining these protected health information. We anticipate that notes. Rather, a health insurer wishing to obtain most health insurers will use separate notices this information must submit to the provider a to fulfill their requirements under the IIPPA and detailed authorization form signed by the patient the Federal Privacy Rule since there are different that specifically permits the use or disclosure of events that trigger when the notices must be psychotherapy notes. Perhaps most importantly, provided. In addition, the content elements of health insurers are prohibited from conditioning the notices differ substantially.111 enrollment or payment of claims on a patient’s Health insurers must give the privacy notices signing such an authorization to disclose required by the Federal Privacy Rule to existing psychotherapy notes.109 members no later than April 14, 2003 (April 14, 2004 for small plans). After this date, new enrollees must be given the notice at the time of enrollment. 28 | CALIFORNIA HEALTHCARE FOUNDATION Contents of a notice of privacy practice. The Giving Patients Access to Their Own Federal Privacy Rule is quite detailed in the con- Health Information tent requirements for a notice of privacy prac- Existing requirements. Health insurers subject to tices. Providers will need to consult the rule the IIPPA should already be familiar with provid- to determine the exact language that a notice ing enrollees access to their own personal infor- requires in order to be in compliance. mation, including health information. The IIPPA also requires health insurers to permit individuals In general, a notice of privacy practice must:112 to see, copy, and correct or amend their health s Be written in plain language; information.113 s Contain a prominent statement that the notice New requirements. The Federal Privacy Rule is about how medical information may be has a similar regulatory scheme. It requires cov- used and disclosed; ered health insurers to permit individuals to see s Describe how the insurer protects health infor- and copy their health information that is in a mation under the Privacy Rule; “designated record set,” a term that includes (with respect to plans) enrollment, payment, s Specify when health information may be claims adjudication, and case or medical manage- used or released without the individual’s prior ment record systems.114 The Privacy Rule also written consent or authorization; grants individuals the right to request amend- s Describe, including at least one example, the ments to their health information if it is incorrect types of uses and disclosures that an insurer is or inaccurate. Generally, the “floor” set by the permitted to make under the Privacy Rule for Federal Privacy Rule is less detailed and protec- treatment, payment, and health care opera- tive than that contained in the IIPPA. tions purposes; Interplay between state and federal require- s Describe individuals’ rights with respect to ments. The net result of the interplay between their protected health information (such as state and federal patient access provisions is that, their right to revoke an authorization and their for the most part, health insurers who already right to amend their health information) and comply with the state statute will not be required describe how to exercise those rights; to substantially change their practices with the implementation of the Federal Privacy Rule. s Notify individuals of how they may obtain We will note the changes that will be necessary access to their health information, including in the following discussion. obtaining copies; s Include information about how individuals can file complaints about privacy matters with both their health care service plan and the U.S. Department of Health and Human Services; and s Provide the name of a contact person for additional information. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 29 Scope. Under the IIPPA, an individual generally Requests. Under state law, an individual’s request has the right to see and copy his or her own to inspect or copy his or her health information health information that is reasonably retrievable.115 must be in writing.119 The Federal Privacy Rule The Federal Privacy Rule gives individuals will allow this practice to continue so long as the the similar right to see and copy their health plan has given the individual notice that it only information that is in the enrollment, payment, accepts written requests.120 The health insurer claims adjudication, and case or medical manage- should require the individual to provide reason- ment record systems maintained by or for a able verification of identity before responding health plan.116 Since records in these systems to the request.121 should be reasonably retrievable, the Privacy Rule Time limits. A health insurer must generally generally does not appear to change the scope respond to a request to see or copy health infor- of information that must be made available mation within 30 days of receiving a request.122 to a person. If an insurer cannot comply within this time The one exception to this rule appears to be in frame, it may extend the response time until no the area of “privileged information.” Under the more than 30 business days after receipt, if it IIPPA, the individual does not have a right of notifies the individual of the delay.123 Within the access with respect to “privileged information, “ deadline, a health insurer must tell the individual which is defined in IIPPA as information collect- the nature and substance of information they ed in connection with or in reasonable anticipa- hold and must permit the person to see and copy tion of a claim for insurance benefits or civil the information in person or to obtain a copy or criminal proceedings. 117 by mail.124 The Federal Rule has a similar, but narrower, Format of information. If the information is exclusion. The Federal Rule excludes access to in coded form, a written accurate translation in information compiled in reasonable anticipation plain language must be provided.125 of civil, criminal, or administrative actions. It Fees. Under the IIPPA, a health insurer was does not appear to exclude access to information allowed to charge a “reasonable” fee to cover the compiled in connection with or in reasonable costs incurred in providing a copy of health anticipation of a claim for insurance benefits.118 information to individuals. The Federal Privacy Therefore, health insurers will be required to Rule specifies that those fees are limited to the provide access to this type of information after cost of supplies and labor for copying, as well as implementation of the Federal Privacy Rule postage.126 Charging fees for retrieving and handling the information or for processing the request, however, is prohibited.127 30 | CALIFORNIA HEALTHCARE FOUNDATION Denying patients access. Under the IIPPA, the Accounting of disclosures. When responding to a main category of health information that request for access to personal information under health insurers may deny access to (other than the IIPPA, a health insurer is already required “privileged information”128) appears to be mental to give individuals the identity, if recorded, health record information. Under the IIPPA, of those persons to whom the plan has disclosed a health insurer may not supply mental health personal information, including health informa- record information directly to the individual tion, within the prior two years.132 The Federal without the approval of the qualified treating Privacy Rule expands on this requirement. professional.129 Under the accounting provisions of the Privacy The Federal Privacy Rule will alter this proce- Rule, within 60 days of receiving a request, dure. Under the federal rule, health insurers will health insurers will be required to give the patient no longer be able to deny access to mental health a list of disclosures made within the past six records by merely relying on the treating profes- years.133 This accounting is not as broad as it first sional’s say-so. There will have to be a profession- appears. First, it only applies to “disclosures” (i.e., al determination that access to the information is information shared with third parties). It does reasonably likely to endanger the life or physical not apply to “uses” (i.e., information utilized or safety of the individual or another person.130 shared within a health insurer’s own organiza- tion). Additionally, the accounting provisions Individuals denied access to their health informa- do not apply to any disclosures that are made for tion by a health insurer have a right to have that treatment, payment, or health care operations decision reviewed under the Federal Privacy purposes. Health insurers will, however, be Rule.131 A health insurer must give patients a required to account for other disclosures that written denial in plain language that generally they may routinely make, such as those made to explains the basis of the denial. This notice must researchers and to health oversight agencies. also advise the individual of his or her right to have this decision reviewed. If the individual Amendment. The IIPPA contains a comprehen- requests a review, the health insurer must sive framework granting individuals the right to promptly refer the material to a licensed health request that health insurers correct, amend, or care professional who did not participate in the delete personal information, including health original decision. The reviewer, who is selected information, that the insurer maintains.134 by the health plan, makes a binding determina- Because the IIPPA provides individuals greater tion whether to grant or deny access. rights of access and amendment than the Federal Privacy Rule, the new federal rule will have little impact on the state law.135 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 31 After implementation of the Federal Privacy Policies and Procedures Rule, individuals will continue to have the right Health insurers must develop and implement to request that health insurers correct, amend, or policies and procedures for using and maintain- delete health information.136 Plans will have 30 ing health information in compliance with the business days to respond to these requests.137 The Privacy Rule.139 These policies and procedures steps that insurers must take if they either accept should address, at a minimum, who has access to or deny the request remain essentially the same. health information within the organization; how Among other things, a health insurer must: health information will be used within the organ- s Notify the individual, in writing, whether it ization; and when, to whom, and under what has accepted or denied the request; conditions the information may be disclosed. s If the request is accepted, make the requested Safeguards change and inform third parties designated A health insurer must have appropriate adminis- by the individual; and trative, technical, and physical safeguards in place s If the request is denied, afford the individual to protect the privacy of protected health infor- the opportunity to submit a statement in dis- mation, and reasonably safeguard the informa- agreement, and provide the statement not only tion from intentional or unintentional use or in conjunction with subsequent disclosures of disclosure.140 Examples of appropriate safeguards the contested information, but also to those include requiring that documents containing designated by the individual as having received protected health information be shredded prior the contested information in the past two to disposal, and using passwords for access to years. computers that contain identifiable health infor- mation.141 HHS has emphasized that this rule requires only “reasonable efforts” to protect Administrative Requirements health information. for Health Insurers The Federal Privacy Rule will impose a number Training of administrative requirements on all covered A health insurer will be required to train all health insurers. For the most part, these require- members of its workforce on the policies and ments are fairly general. HHS, recognizing that procedures regarding protected health infor- there are vast differences in the nature, size, and mation required by the regulation no later than organization of health insurers, decided that a its compliance date with the regulation. New “one-size-fits-all” set of administrative require- members of the workforce should receive training ments would not be workable. Rather, the within a reasonable period of time after they administrative requirements are intended to be begin working.142 Again, training requirements flexible and scalable, depending on the particular are flexible and scalable and will vary with the insurer’s circumstances.138 Some of the major size of the organization. administrative requirements are listed below. 32 | CALIFORNIA HEALTHCARE FOUNDATION Privacy Officer and Contact Person Looking Ahead The Federal Privacy Rule requires a health insur- Clearly, the new Privacy Rule will require health er to designate a privacy official for the develop- insurers to make significant changes to their oper- ment and implementation of its policies and ations in order to comply with both the Privacy procedures.143 In addition, a health insurer will Rule and existing California laws. Understanding be required to identify a contact person who is how the various laws interact and what practices responsible for receiving complaints.144 At its will be required will be challenging. Compliance option, the insurer can designate one person for will require identifying all of the privacy-related both functions.145 statutes that apply to a particular insurer and doing a line-by-line comparison of these state Complaint Procedure requirements with those of the Privacy Rule. Health insurers must establish a process for Insurers will need to review their existing practices individuals to file complaints about the insurer’s to see what changes they will need to make to health privacy policies and practices and its come into compliance. Hopefully, this guide has compliance with the Federal Rule.146 helped to begin that process. There is not a sub- stantial amount of time for insurers to complete Documentation the changes they will need to make and it is Health insurers will be required to maintain incumbent upon insurers to use this period wisely. documentation in a variety of areas including, but not limited to, the following: s Authorizations;147 s Consents, if they elect to use them;148 s Agreed restrictions on using or disclosing health information for treatment, payment and health care operations;149 s Disclosures for purposes other than treatment, payment, or health care operations;150 s Minimum necessary policies for use and disclosure of health information;151 and n Training of personnel.152 This documentation must be kept for six years from the date of its creation or the date it was last in effect, whichever is later.153 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 33 V. The Impact on Knox-Keene Health Care Service Plans Because the state law Background [Knox-Keene] does not con- Over 23 million Californians receive their health care through health care service plans (popularly known as HMOs or man- tain procedural requirements aged care plans).154 Most of these plans are licensed under the specifying when and how Knox-Keene Health Care Service Plan Act (Knox-Keene Act).155 individuals must be given Existing Requirements in California Law access to their own health These plans should already be familiar with state laws govern- ing the use and disclosure of health information. Knox-Keene information, health care plans are subject to the Confidentiality of Medical Information service plans had a lot Act (CMIA), which restricts how health care service plans of discretion in this area. . . may disclose their enrollees’ and subscribers’ “medical infor- mation.”156 CMIA covers individually identifiable information The Federal Privacy Rule. . . regarding a patient’s medical history, mental or physical requires covered health plans condition, and treatment that is in the possession of or was derived from a provider of health care, a health care service to permit individuals to plan, or a contractor. It protects information in electronic or see and copy their health physical form. information. . . [and] grants Generally, the CMIA prohibits a health care service plan from disclosing medical information without a patient’s writ- individuals the right to ten authorization.157 It then specifically lists a number of request amendments. exceptions where disclosure is permitted without the patient’s permission. For each permitted disclosure, the CMIA generally imposes specific conditions dependent on the purpose of the disclosure. If a purpose is not enumerated in the CMIA, the health care service plan must obtain a patient’s authoriza- tion prior to disclosure. The Act sets out the form and sub- stance for such authorizations.158 In addition to restricting the disclosure of medical information, California law (through the Knox-Keene Act) also requires health care service plans to have policies permitting patients access to their own medical records.159 Furthermore, plans must provide individuals with a written statement describing how the plan maintains the confidentiality of medical information in their possession.160 34 | CALIFORNIA HEALTHCARE FOUNDATION New Requirements s Individuals will now have the right to request The Federal Privacy Rule adopts a similar scheme: that health care service plans amend their it permits health care service plans to use and health information if it is incorrect. disclose protected health information for specified s Health care service plans will be required to purposes without the individual’s written permis- undertake additional administrative duties sion. To disclose health information for purposes to comply with the federal rule, such as not specified in the regulation, an authorization implementing safeguards, training employees, is required. Additionally, the Federal Privacy Rule designating a privacy official, and maintain- grants patients the right to see and copy their ing documentation of compliance with own health information. the regulation. Key Differences between California Law These key differences, as well as the rules that and the Federal Privacy Rule govern obtaining, using, and disclosing health While the Privacy Rule is similar in many information for particular purposes, are discussed respects to the CMIA, there are some key areas below. where health care service plans will have to alter their practices under the Federal Privacy Rule, Restrictions on Use and Disclosure including: of Health Information s Health care service plans will be required to have contracts with those they share infor- Oral Communications mation with for administrative functions; the Health care service plans must already comply contracts will require those “business associ- with the CMIA, which governs the disclosure of ates” to adequately safeguard the health medical information in electronic or physical information. form.161 Although the CMIA does not expressly cover oral information, many health care service s In many circumstances, health care service plans already have internal policies governing plans will be required to limit the health infor- whom they may share information with orally. mation they request, use, or disclose to the For example, many health care service plans have minimum amount necessary to accomplish specific rules limiting who may be furnished the intended purpose. claims information over the telephone. The s Health care service plans will be required Federal Privacy Rule formalizes these practices by to provide individuals with a notice of privacy covering health information transmitted or practices by April 14, 2003; after that date, maintained in any format, including oral com- new enrollees must receive notice at the time munications.162 of enrollment. s Having a general policy for allowing individ- uals access to their own health information will no longer be sufficient. Health care service plans will be required to follow a detailed set of regulatory provisions for permitting access. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 35 Minimum Necessary Standard Medi-Cal Requirements California law currently limits the amount of A commercial health care service plan that health information that can be disclosed in cer- contracts with either the state or a county to provide Medi-Cal services must comply with tain circumstances. For example, a provider may the Privacy Rule. In addition it must also adhere disclose health information to a health care serv- to Medicaid specific confidentiality require- ice plan for payment purposes only to the extent ments contained in the following sources: necessary to allow responsibility for the payment • Its contract with the government agency to be determined and payment to be made.163 • The Federal Medicaid Regulations (Title 42, The Federal Privacy Rule builds on these existing Code of Federal Regulations, Section rules and policies. The Privacy Rule is intended 431.300 et seq.), and to make covered entities, including health care • Section 14100.2 of the California Welfare and service plans, evaluate their privacy practices and Institutions Code, and the related regulations. improve them as needed to prevent unnecessary In very general terms, these standards prohibit or inappropriate access to protected health infor- the disclosure of protected health information mation.164 As a general rule, they do not require a generated in connection with Medi-Cal ser- case-by-case review. vices for any purpose not directly connected with the administration of the Medi-Cal For most routine purposes, the rule requires program. Because the Medi-Cal standards for that health care service plans have policies and use and disclosure are more restrictive than procedures to request, use, and disclose the the Privacy Rule, they will not be preempted by the Federal rule. It should be noted, how- minimum amount of health information neces- ever, that Medi-Cal patients will have the right sary to accomplish the intended purpose. It is to see, copy and amend their own health important to note that there are a number of information, (including claims information).* major exceptions to the minimum necessary requirement. Most significantly, the minimum *The Federal Medicaid regulations (both those finalized necessary standard does not apply to disclosures and on hold, and those proposed) require states to ensure through their contracts that managed care plans to or requests by a health care provider for treat- establish and implement procedures to ensure that ment purposes.165 Neither does it apply to any use enrollees can request to see, receive a copy of, and or disclosure that is required by law.166 request an amendment of their records. See 42 C.F.R. § 438.224(d) and 66 Fed. Reg. 43670 (Aug. 20, 2001) (notice of proposed rule making). Uses For uses (i.e., utilizing or sharing health infor- mation within an organization), a health care service plan must identify those within their organization who need access to health infor- mation, the categories or type of information they need, and conditions appropriate to such access.167 The health care service plan must develop policies and procedures that implement this analysis and must document them in written or electronic form.168 36 | CALIFORNIA HEALTHCARE FOUNDATION Disclosures and Requests for Disclosures Limits on Requests For routine or recurring requests for health Health care service plans are limited in the type information, a plan’s policies must limit the pro- and amount of information they can request for tected health information requested to the payment and health care operations, but this lim- minimum amount necessary to accomplish the itation should not interfere with normal business use for which the information is requested.169 The practices. The minimum necessary standard does same standard applies to routine disclosures of apply to requests for payment and health care health information—the plan is required to have operations purposes. However, the terms “pay- policies in place that limit the type and amount ment” and “health care operations,” are broadly of health information disclosed to the minimum defined in the Privacy Rule and, among other amount necessary. These protocols must be things, include: maintained in written or electronic form.170 s Determination of eligibility or coverage (including coordination of benefits or the Uses, Requests, and Disclosures That Are Not Routine or Recurring determination of cost-sharing amounts); Most uses, requests, and disclosures that are out s Risk-adjusting amounts due based on enrollee of the ordinary must be reviewed on an individ- health status and demographic characteristics; ual basis to determine the minimum amount s Billing, claims management, collection activi- necessary to fulfill the intended purpose. For cer- ties, obtaining payment under a contract tain requests, a health care service plan can rely for reinsurance; on the requesters’ representation that they have asked for the minimum amount of information s Review of health care services with respect to necessary. For example, a health care service plan medical necessity, coverage under a health could rely on the representation of an attorney plan, appropriateness of care, or justification or other professional that he or she has requested of charges; the minimum amount of information necessary s Utilization review activities, including precerti- to provide a professional service.171 fication and preauthorization of services, and concurrent and retrospective review of services; s Contacting health care providers and patients with information about treatment alternatives; s Evaluating practitioner and provider perform- ance; and s Conducting quality assessment and improve- ment activities. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 37 Business Associates: Sharing Health Definition of a “business associate.” Under the Information for Administrative Purposes federal regulation, anyone who performs a Existing requirements. Health care service plans function involving the use of health information routinely hire other companies and consultants on behalf of a health care service plan or who to perform a wide variety of functions for them. furnishes certain services (such as legal, actuarial, Plans, for example, may work with outside or other administrative services) to the plan is attorneys, accountants and bill collectors. Under a “business associate.”174 A key element of being the CMIA, health care service plans currently a business associate is that the person or organ- may freely disclose health information without ization receives health information either from patient permission for a variety of these adminis- or on behalf of a provider. Under this standard, trative purposes, such as billing, claims manage- a billing agency would be a business associate, ment, and medical data processing. The CMIA while a supplier of paper products would not. then prohibits the recipient of this health infor- The Privacy Rule is also not intended to cover mation from further disclosing it in a way that those who merely act as a conduit of protected would violate the Act.172 health information, like the U.S. Postal Service or FedEx.175 New requirements. The Federal Privacy Rule takes this requirement one step further. Health The necessary elements of a business associate care service plans that wish to use outside sources contract. The Privacy Rule contains a fairly to perform these types of administrative functions lengthy, detailed list of provisions that must be will be required to enter into written contracts included in a business associate contract. Among ensuring that the recipient of the information other things, the business associate contract (a “business associate”) appropriately safeguards must provide that the business associate will:176 the health information.173 This may be a major s Not use or further disclose the information change for many health care service plans. other than as permitted or required by the contract or as required by law; s Use appropriate safeguards to prevent use or Can a Health Plan Be Held Responsible if a Business Associate Violates its disclosure of the information other than as Contract? provided for by its contract; Only if the plan knew the business associate s Ensure that subcontractors who receive pro- was materially violating its contractual duty to tected health information from a business safeguard health information and did nothing about it. A plan that knows that its business associate agree to the same restrictions and associate engages in a pattern of activity or a conditions as in the contract; practice that materially violates the privacy s Authorize termination of the contract by the provisions of its contract must take reasonable steps to correct the situation. If these steps covered entity if the covered entity determines are unsuccessful, the plan is required to either: that the business associate has violated a 1) terminate the contract if feasible; or 2) material term of the contract. if termination of the contract is not feasible, report the problem to HHS. See 45 C.F.R. § 164.504(e)(1(ii). 38 | CALIFORNIA HEALTHCARE FOUNDATION Uses and Disclosures That Do Not Require After implementing the Federal Privacy Rule, an Individual’s Written Permission health care service plans will still be able to dis- Both the CMIA and the Federal Privacy Rule close health information without the individual’s allow a provider to use and disclose health infor- written permission for these purposes. The mation without the patient’s consent or authori- Federal Rule allows health plans, including health zation in a number of circumstances.177 The laws care service plans, to use and disclose protected generally impose conditions specific to the par- health information without the individual’s ticular purpose for which the health information written permission for the core purposes of treat- is to be used or disclosed. Due to the number ment, payment, and health care operations.179 of circumstances under which use and disclosure And all of the above purposes are considered to are permitted without any patient permission be treatment, payment, or health care operations and the details of the related conditions, only a functions.180 (It should be noted that even though few of these purposes are discussed. a health insurer can disclose health information without the individual’s permission for these pur- Treatment, payment and health care operations. poses, it may only do so in certain circumstances The CMIA allows health care service plans to if a business associate contract is in place. (See disclose health information without the individ- “business associates,” above.) ual’s written authorization for a number of pur- poses, including:178 In contrast, health care providers must obtain a patient’s consent prior to using health informa- s To providers of health care, health care service tion for treatment, payment and health care plans, contractors, or other health care facili- operations purposes, under the Federal Privacy ties for purposes of diagnosis or treatment of Rule.181 the patient; Health plans will still be able to use health s To any person or entity responsible for paying information that they obtain from providers to for health care services rendered to the patient, administer their own plans. Once a provider has to the extent necessary to allow responsibility obtained a patient’s consent, the provider may to be determined and payment to be made; disclose health information to a health care serv- s For billing, claims management, medical data ice plan for payment purposes. The plan may processing, or other administrative services; then use this information without the patient’s express permission for its own payment and s To review health care services with respect to health care operations purposes.182 medical necessity, level of care, quality of care, or justification of charges; and s For licensing and accrediting the health care service plan. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 39 Right to request heightened protections in the Law enforcement. Under the CMIA and the context of treatment, payment, and health care Federal Privacy Rule, health care service plans operations. Although health care service plans are may disclose health information pursuant to a not required to obtain written permission to use search warrant lawfully issued to a governmental or disclose an individual’s health information for law enforcement agency.186 treatment, payment, or health care operations Civil discovery. A health care service plan may purposes, this does not mean that the individual disclose protected health information in response has no right whatsoever over the information. to a subpoena, discovery request, or other lawful The Federal Privacy Rule gives individuals the process that is not accompanied by a court order right to request heightened protections in two without the individual’s authorization only when manners: (1) by asking that a health plan restrict the health plan has received certain assurances.187 its uses and disclosures and (2) by asking that a In particular, the party seeking the information plan send communications by specific means.183 must provide a written statement that it has These rights were crafted, at least partially, in made reasonable efforts to ensure that the indi- response to requests from advocacy groups repre- vidual who is the subject of the information has senting those with sensitive medical conditions. been given notice of the request and a chance s Right to request restrictions. Individuals have to object to it. Alternatively, the requester must the right to request that covered entities, present documentation that it has sought a including health care service plans, restrict protective order.188 how they use or share protected health infor- Research. Both the CMIA and the Federal mation for the purposes of treatment, pay- Privacy Rule permit providers to disclose health ment, and health care operations. Health care information for research purposes without the service plans are not required to agree to permission of the patient.189 Providers should be requests to restrict, but are bound by any aware, however, that the conditions under which agreements to which they agree.184 health information can be disclosed for research s Right to request confidential communications. purposes are substantially altered by the Federal Some individuals are concerned about receiv- Privacy Rule. In the most general terms, in order ing information about their health treatment to disclose health information to researchers, a or payment at home. Under the Federal provider will be required to obtain documenta- Privacy Rule, individuals will have the right to tion that a waiver of authorization for the use request that covered entities, including health and disclosure of health information was care service plans, contact them only in a spec- approved by either: (1)an Institutional Review ified manner (such as telephoning them only Board (IRB), which reviews federally funded at work) or sending communications only to a research; (2)or a “privacy board,” a new board specific location. A plan must agree to such a that will review privately funded research using request if the individual clearly states that the the same principles as an IRB.190 The specific disclosure of the protected health information conditions under which health information can could endanger him or her.185 be used and disclosed for research purposes are quite detailed and should be reviewed closely. 40 | CALIFORNIA HEALTHCARE FOUNDATION Authorizations s State the specific uses and limitations on the Currently, under the CMIA, if a disclosure is not use of medical information by the persons specifically permitted or required by the statute, a authorized to receive the information;202 health plan must obtain a patient’s authorization s Advise the individuals of their right to receive prior to disclosing his or her health informa- a copy of the authorization;203 tion.191 The Federal Privacy Rule takes a similar approach. For purposes that are not expressly s Inform individuals of their right to revoke the addressed in the Federal Privacy Rule, covered authorization under the Federal Privacy entities, including health care service plans, will Rule;204 and be required to obtain a patient’s authorization s Include a statement that information used prior to using or disclosing his or her protected or disclosed under the authorization may be health information.192 The authorization required subject to redisclosure by the recipient and by the Privacy Rule is quite similar to that pro- may no longer be protected by the Federal vided for in the CMIA, but there are some differ- Privacy Rule.205 ent requirements.193 When a health care service plan seeks an authori- Essential elements of authorization forms. Most zation to use or disclose health information plans will probably prefer that a single authoriza- that it maintains, the authorization form must tion form that conforms to both federal and state include additional elements. Among other things, requirements be submitted. In order to comply such an authorization must:206 with both the CMIA and the Federal Privacy Rule, an authorization form must, at a minimum: s If applicable, state that the plan will not con- dition treatment, payment, enrollment in the s Be handwritten by the person who signs it or health plan, or eligibility of benefits on the be in 8-point typeface or larger;194 individual’s providing the requested authoriza- s Be separate (with some exceptions);195 tion; and s Be signed and dated;196 s State that the individual has the right to refuse s Specifically describe the health information to to sign the form. be used or disclosed;197 A plan that obtains an authorization for its own s State the specific limitations on the type of uses or disclosures must give the individual a information to be disclosed;198 copy of the signed authorization.207 s State the name or function of the person (organ- ization) authorized to make the disclosure;199 Revocation of authorizations.208 An individual has the right to submit a written revocation of s State the specific date after which the health his or her authorization at any time. A revocation care service plan is no longer authorized to dis- is not effective, however, to the extent that a close the information;200 covered entity has taken action in reliance on it. s State the names or functions of persons Neither is a revocation effective with respect to (organizations) authorized to use or receive the authorizations that were obtained as a condition information;201 of obtaining insurance coverage when other laws provide the insurer with the right to contest a claim under the policy. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 41 Marketing Psychotherapy-related information other than Among the more controversial aspects of the notes of a therapy session. If a health care service Federal Privacy Rule are the “marketing provi- plan wishes to obtain psychotherapy-related sions.” Under these provisions, providers and information from a provider, the plan must sub- health plans are permitted to use health informa- mit a detailed, written request (under the tion for marketing purposes (for their own ser- CMIA)211 to that provider.212 The request must vices or those of a third party) so long as the include: (1) the specific information related to marketing material identifies the provider as the psychotherapy treatment that is being requested; source and gives the patient the opportunity to (2) the specific intended use of the information; “opt out” of receiving further materials.209 This (3) how long the information will be used; essentially gives the health plan one chance to and (4) other information. The patient’s signa- send the patient marketing materials before the ture is not required on the request, but he or she patient is even given the opportunity to object. must be provided with a copy. For example, a health care service plan desiring information Health care service plans in California, however, about a diagnosis related to psychotherapy would should be aware that the CMIA appears to need to submit to the provider a written request require a patient’s written authorization before specifically detailing the information it desires. engaging in many marketing activities.210 Because this standard is more consumer-protective than Psychotherapy Notes. The Federal Privacy Rule the federal regulation, the state law will remain in imposes even more restrictions on the disclosure effect, and health care service plans should get of psychotherapy notes (i.e., notes documenting patients’ written authorization before using or or analyzing the contents of conversations taking sharing their health information for marketing. place during therapy).213 A request under the CMIA will not be sufficient for obtaining these Information Related to Psychotherapy notes. Rather, if a health plan wishes to obtain Information related to psychotherapy is given this information it must submit to the provider a heightened protection by both California law detailed authorization form signed by the patient and the Federal Privacy Rule. The rules vary that specifically permits the use or disclosure of depending on the specific type of psychotherapy- psychotherapy notes. Perhaps most importantly, related information being sought. health plans are prohibited from conditioning enrollment or payment of claims on a patient’s signing such an authorization to disclose psychotherapy notes.214 42 | CALIFORNIA HEALTHCARE FOUNDATION Patient Rights We anticipate that most health care service plans In addition to imposing restrictions on how will want to use a single notice of privacy prac- health care service plans can use and disclose pro- tices to comply with both state and federal law. tected health information, both California law This can be accomplished by crafting a notice and the Federal Privacy Rule grant individuals that contains the elements required by both state rights with respect to their own health informa- and federal law. Plans should furnish the notice tion. These rights are based in fair information upon request and at the times specified by the practice principles, and essentially give people the Federal Privacy Rule in order to comply with right: (1) to know how their health information both state and federal law. is being used; (2) to know with whom it is being Contents of the notice of privacy practice. Gen- shared; (3) to review their health information; erally, a notice of privacy practices must contain and (4) to amend it, if necessary. all of the specific requirements of the Knox- Keene Act plus the requirements of the Federal Notice of Privacy Practices Privacy Rule. While the requirements under Currently, health care service plans licensed the Knox-Keene Act are fairly brief, the Federal under the Knox -Keene Act are required, upon Privacy Rule is quite detailed in the content request, to give enrollees and subscribers a writ- requirements for a notice of privacy practices. ten statement that describes how the health care Health care service plans will need to consult the service plan maintains the confidentiality of rule to determine the exact language that a notice medical information in its possession.215 If a plan requires in order to be in compliance. In order contracts with others to provide health care to comply with both laws, a notice of privacy services, the notice must also describe the con- practices generally must: tracting organization’s privacy practices.216 Addi- s Be written in plain language;221 tionally, the notice must contain information about how patients, subscribers and enrollees s Be in 12-point or larger typeface;222 may obtain access to their medical information, s Contain a heading that the notice is about including obtaining copies.217 how medical information may be used and The Federal Privacy Rule requires a similar notice disclosed;223 of privacy practices, which must be given to s Advise individuals how they may obtain access enrollees upon request and at other specified to their health information, including obtain- times.218 Under the Federal Privacy Rule, health ing copies;224 care service plans are required to provide a notice of privacy practices to individuals covered by the s Describe how the plan protects health infor- plan by April 14, 2003 (the compliance deadline mation under the respective laws;225 for the federal rule).219 After that date, the notice s Describe when health information may be must be given to new enrollees at the time of released without the individual’s prior authori- their enrollment, and upon request.220 zation;226 s Advise individuals that any disclosure of med- ical information beyond the provisions of law is prohibited;227 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 43 s Describe the types of medical information Scope. In general, individuals will have the right that may be collected and the type of sources to see and copy their own enrollment, payment, that may be used to collect the information, claims adjudication, and case or medical man- and the purposes for which the plan will agement records maintained by a health care obtain medical information from other health service plan.234 care providers;228 Requests. A health care service plan may require s Describe individuals’ rights with respect to that individuals submit their requests to inspect their protected health information (such as or copy their own medical records in writing, their right to revoke an authorization and their so long as the plan has given notice that it right to amend their health information) and only accepts written requests.235 The health care describe how to exercise those rights;229 service plan should require individuals to provide some reasonable verification of their s Include information about how an individual identity before providing access to the requested can file complaints about privacy matters with information.236 both their health care service plan and the Department of Health and Human Services;230 Time limit. In general, a health care service plan and will have 30 days after receipt to respond to a request to see and copy health information. The s Provide the name of a contact person for deadline may be extended up to 30 days without additional information. 231 a reason if the plan notifies the patient.237 Giving Patients Access to Their If the health care service plan does not maintain Own Health Information the requested health information, but knows Under the Knox-Keene Act, health care service where the information is kept, the plan must let plans currently must have policies and procedures the individual know where to direct his or her that give individuals access to their own health request.238 (For example, if a person requests information that is maintained by the plan.232 a medical record from a health care service plan Because the state law does not contain procedural which does not maintain medical records, and requirements specifying when and how individ- the plan knows that the record is kept by one uals must be given access to their own health of its contracting providers, the plan must advise information, health care service plans had a lot of the person to direct the request to the contract- discretion in this area. This will change under ing provider.) the Federal Privacy Rule, which contains detailed Format of information. The health care service provisions governing individuals’ rights to see, plan generally must provide the health informa- copy, and amend their own health information. tion in the format requested by the individual.239 Generally, the Privacy Rule requires covered The plan may give the individual an explanation health plans to permit individuals to see and copy or summary of the information, instead of the their health information that is in a “designated actual record, if the individual agrees in advance.240 record set,” a term that includes (with respect to plans) enrollment, payment, claims adjudication, and case or medical management record systems.233 The Privacy Rule also grants individuals the right to request amendments to their health informa- tion if it is incorrect or inaccurate. 44 | CALIFORNIA HEALTHCARE FOUNDATION Fees. A health care service plan may charge a rea- Right to review. In the following three circum- sonable fee for providing the individual with a stances, a health care service plan may deny an copy of health information. The fee can include individual access to his or her protected health the cost of supplies and labor for copying as well information, but must provide an opportunity as postage.241 Charging fees for retrieving and for review of that denial if: handling the information or for processing the s A licensed health care professional, in the request, however, is prohibited. 242 exercise of professional judgment, determines A plan can also charge a reasonable cost-based fee that it is reasonably likely that access to the for explaining or summarizing health informa- requested information would endanger the life tion when an individual has agreed to an expla- or physical safety of the individual or another nation or summary in lieu of the actual record.243 person; Denying patients access. The Federal Privacy s The requested information makes references to Rule permits providers to deny patients access another person and the licensed health care to health information in some circumstances. professional, in the exercise of professional In some instances the right to deny access is judgment, determines that access is reasonably absolute and there is no review process. In others, likely to cause substantial harm to that other the patient has the right to have the decision person; or to deny access reviewed. s The request for access is made by the individ- No right of review. When an individual requests ual’s personal representative and a licensed information in the following categories, a health health care professional, in the exercise of pro- care service plan may deny the request without fessional judgment, determines that providing affording the patient any right of review of the access to that representative is reasonably likely decision.244 to cause substantial harm to the individual or another person. s Psychotherapy notes; Review of denials. The Federal Privacy Rule cre- s Information compiled in anticipation of or for ates a framework for reviewing denials of access use in a civil, criminal, or administrative to health information.245 As a preliminary matter, action or proceeding; when a health care service plan decides to deny s Protected health information maintained by a access to health information, it must furnish covered entity that is subject to Clinical individuals with a written denial in plain lan- Laboratory Improvements Amendments guage within 30 days of receiving the individual’s (CLIA) or exempt from CLIA regulations; request. The denial notice must generally explain the basis of the denial and advise the individuals s Information obtained from someone other than of their right to have this decision reviewed.246 a health care provider under a promise of con- fidentiality where access would be reasonably If the individual requests a review, the plan must likely to reveal the source of that information. promptly refer the material to a licensed health care professional who did not participate in the original decision.247 The designated reviewer, who is selected by the plan, makes the final determination whether access should be granted or denied.248 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 45 Accounting of Disclosures Accepting requests for amendment. If the health The Federal Privacy Rule also grants individuals care service plan accepts the request, it must the right to receive an accounting of prior dis- (1) make the appropriate amendment, and (2) closures of health information.249 Within 60 days inform the individual in a timely fashion that the of receiving a request, a health care service plan amendment is accepted. The plan must then fur- will be required to give an individual a list of nish the amendment both to entities identified disclosures made within the past six years.250 by the individual and to other entities known to This accounting is not as broad as it first appears. have received the erroneous information.256 First, it only applies to “disclosures” (i.e., infor- Denying requests for amendment. A health care mation shared with third parties). It does not service plan may deny individual’s request for apply to “uses” (i.e., information utilized or amendment if the plan determines that the shared within a plan’s organization).251 Addi- information or record: (1) was not created by tionally, the accounting provisions do not apply the plan, unless the originator of the protected to any disclosures that are made for treatment, health information is no longer available to make payment, or health care operations purposes.252 the amendment; (2) is not a part of the desig- Plans will, however, be required to account for nated record set; (3) would not be available for other disclosures that they may routinely make, inspection (see summary of right of access, such as those made to researchers and to above); or (4) is accurate and complete.257 health oversight agencies. If the health care service plan denies an individ- Right to Amend Health Information ual’s request, it must give the individual a timely, The Federal Privacy Rule gives individuals the written denial, which includes (1) the basis for right to amend or supplement their health infor- the denial, (2) the individual’s right to submit a mation that is maintained by a covered entity, written statement disagreeing with the denial and including health care service plans.253 For exam- how to exercise that right, (3) a statement that ple, an individual who disagrees with a medical the individual can request the health care service opinion can submit a second opinion to be plan to include the individual’s request and the included in the medical record. The individual denial with any future disclosures of the informa- has this right for as long as the health care service tion (if the individual does not file a statement of plan maintains the information.254 The plan must disagreement), and (4) a description of how the act on an individual’s request for amendment no individual can file a complaint with the covered later than 60 days after it receives the request.255 entity or the Secretary of HHS.258 The deadline may be extended up to 30 days. If the individual files a statement of disagree- ment, the covered entity can prepare a rebuttal to the individual’s statement. The entity must pro- vide a copy of the rebuttal to the individual. The request for amendment, the denial, the statement of disagreement (if submitted), and rebuttal (if any), or a summary of such information must be provided with any subsequent disclosure of the protected health information.259 46 | CALIFORNIA HEALTHCARE FOUNDATION Administrative Requirements for Training Health Care Service Plans A health care service plan will be required to The Federal Privacy Rule will impose a number train all members of its workforce on the policies of administrative requirements on health care and procedures regarding protected health infor- service plans. For the most part, these require- mation required by the regulation no later than ments are fairly general. HHS, recognizing that the compliance date. New members of the work- there are vast differences in the nature, size, and force should receive training within a reasonable organization of health care plans, decided that a period of time after they begin working.264 “one-size-fits-all” set of administrative require- Again, training requirements are flexible and ments would not be workable. Rather, the scalable. For example, a small health care service administrative requirements are intended to be plan may be able to satisfy the training require- flexible and scalable, depending on the particular ment by providing each new member of the plan’s circumstances.260 Some of the major workforce with a copy of the plan’s privacy policies administrative requirements are listed below. and requiring these members to acknowledge that they have reviewed the policy.265 Policies and Procedures Health care service providers must develop and Privacy Officer and Contact Person implement policies and procedures for using The Federal Privacy Rule requires a health care and maintaining health information in compli- service plan to designate a privacy official ance with the Privacy Rule.261 These policies for the development and implementation of its and procedures should address, at a minimum, policies and procedures.266 In addition, a plan who has access to health information within will be required to identify a contact person who the organization; how health information will is responsible for receiving complaints.267 At its be used within the organization; and when, to option, the plan can designate one person whom, and under what conditions the infor- for both functions.268 The implementation of mation may be disclosed. these requirements will depend on the size and organization of the plan’s office. Safeguards A health care service plan must have appropriate Complaint Procedure administrative, technical, and physical safeguards Health care service plans must establish a process in place to protect the privacy of protected for individuals to file complaints about the health information, and reasonably safeguard the provider’s health privacy policies and practices information from intentional or unintentional and its compliance with the Federal Rule.269 use or disclosure262. Examples of appropriate safe- guards include requiring that documents contain- ing protected health information be shredded prior to disposal, and requiring that file cabinets containing such records be locked.263 Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 47 Documentation Looking Ahead Health care service plans will be required to Clearly, the new Privacy Rule will require health maintain documentation in a variety of areas care service plans to make significant changes including, but not limited to, the following: to their operations in order to comply with both s Agreed restrictions on using or disclosing the Privacy Rule and existing California laws. health information for treatment, payment Understanding how the various laws interact and and health care operations;270 what practices will be required will be challeng- ing. Compliance will require identifying all of the s Authorizations;271 privacy-related statutes that apply to a particular s Disclosures for purposes other than treatment, plan and doing a line-by-line comparison of payment and health care operations;272 these state requirements with those of the Privacy Rule. Health plans will need to review their s Minimum necessary policies for use and dis- existing practices to see what changes they will closure of health information;273 and need to make to come into compliance. Hope- s Training of personnel.274 fully, this guide has helped to begin that process. There is not a substantial amount of time for This documentation must be kept for six years plans to complete the changes they will need to from the date of its creation or the date it was make and it is incumbent upon them to use last in effect, whichever is later.275 this period wisely. 48 | CALIFORNIA HEALTHCARE FOUNDATION Appendix A: Key Resources for Implementation Assistance Department of Health and Human Services (HHS) Information on all the Administrative Simplification require- ments (including, but not limited to, the Privacy Rule): http://aspe.hhs.gov/admnsimp/index.htm. Office of Civil Rights (OCR), HHS Information on the Privacy Rule, including the text of the rule and technical guidance: http://www.hhs.gov/ocr/hipaa. Massachusetts Medical Society HIPAA Resources Useful links, questions/answers, and HIPAA implementation tips: http://www.mass.med.org. American Health Information Management Association Association that represents health information management professionals who work throughout the health care industry. HIPAA related articles, frequently asked questions, practice briefs, and links to other Web sites: http://www.ahima.org/hot.topics. Health Privacy Project Information about protecting the privacy of health informa- tion, including the Federal Privacy Rule, state health privacy laws, and current developments: http://www.healthprivacy.org. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 49 Appendix B: Checklist of Key Items for Implementation 1. Adopt written privacy procedures, specifying: s who has access to health information, s how health information will be used within the provider’s organization, and s when the information may be disclosed. (New under HIPAA) 2. Draft Notice of Information Practices. (New under HIPAA) 3. Draft Consent Forms. (New under HIPAA) 4. Revise or draft Authorization Forms. (CMIA and HIPAA) 5. Revise or draft Contracts with Business Associates. (New under HIPAA) 6. Designate: s contact person for receiving complaints, and s privacy officer (can be same person). (New under HIPAA) 7. Train personnel about protecting privacy and requirements of Privacy Rule. (New under HIPAA) 50 | CALIFORNIA HEALTHCARE FOUNDATION Endnotes 1. Standards for Privacy of Individually Identifiable 16. See Standards for Privacy of Individually Health Information: Final Rule, vol. 65, Federal Identifiable Health Information: Final Rule, Register (“65 Fed. Reg.”) pp. 82462-82829 Preamble (“Preamble to Privacy Rule”) 65 Fed. (Dec. 28, 2000). This rule is codified in title 45, Reg. 82477. Code of Federal Regulations (45 C.F.R.). 17. 45 C.F.R. § 164.500. 2. Standards for Privacy of Individually Identifiable 18. 45 C.F.R. § 164.501 (defining “protected health Health Information: Guidance (hereinafter information” and “individually identifiable health “HHS Guidance”) (July 6, 2001). Available online information”) and § 160.103 (defining “health at http://www.hhs.gov/ocr/hipaa/. information”). 3. 45. C.F.R. § 160.102 and § 164.104. 19. 45 C.F.R. § 160.103 (defining “health information”). 4. 45 C.F.R. § 160.103 (defining “covered entity”). 20. 45 C.F.R. § 164.501 (defining “individually identi- 5. 45 C.F.R. § 160.103 (defining “health plan”). fiable health information”). 6. 45 C.F.R. § 160.103 (defining “health plan”). 21. 45 C.F.R. § 164.502 and § 164.514. 7. 45 C.F.R. § 160.103 (defining “health care 22. 45 C.F.R. § 164.501 (defining “individually identi- clearinghouse”). fiable health information”). 8. 45 C.F.R. § 160.102 and § 164.104 (explaining 23. There is some controversy over the scope of infor- “applicability). mation that may be protected by HHS in the Privacy Rule. Some parties have challenged the con- 9. 45. C.F.R. § 160.103 (defining “health care stitutionality of the rule, contending that HHS provider”). only had the authority to regulate claims-related 10. 45 C.F.R. § 160.103 (defining “health care”). health information in electronic format. See South 11. 65 Fed. Reg. 82477. Carolina Medical Association v. HHS, No. 01-CV- 2965 (U.S.D.C). S. Car.) (filed 7/16/01). 12. See Standards for Privacy of Individually Identifiable Health Information: Proposed Rule, 24. See 45 C.F.R. § 164.501 (defining “use” and Preamble (“Preamble to Proposed Privacy Rule”), “disclosure”). 64 Fed. Reg. 59937 (November 3, 1999). 25. Providers who have only an indirect treatment rela- 13. There is some controversy concerning whether tionship with patients are not required to obtain a provider must actually use the required format to consent. See 45 C.F.R. § 164.506(a)(2). An indirect become a “covered entity” or whether they may treatment relationship is one where the health care become “covered” by merely electronically conduct- provider does not directly interact with patients, ing one of the transactions listed in HIPAA. such as many radiologists in hospital settings. See 45 C.F.R. § 164.501 (defining “indirect treatment 14. See 42 U.S.C. Sec. 1320d-2(a) for the full list of relationship”). electronic transactions that will trigger coverage of the privacy regulation. 26. Although Congress recently extended the deadline for complying with the transaction standards, it did 15. Congress recently passed the Administrative not alter the deadline for complying with the Simplification Compliance Act, Pub. Law 107-105, Privacy Rule. See Administrative Simplification that permits covered entities that cannot meet the Compliance Act, Pub. Law 107-105. October 2002 deadline for complying with the transactions regulations to obtain a one year delay. 27. 45 C.F.R. § 160.103 (defining “small health plan”) In order to qualify for the one-year delay, a covered and § 164.534 (specifying compliance dates). entity must submit a compliance plan no later than 28. See HHS Guidance at 6-7, stating that HHS October 2002. The date for complying with the intends to alter the rule. Privacy Rule is not delayed or effected by this Act. 29. Statement of Delegation of Authority, 65 Fed. See 147 Congressional Record S13077 (daily ed. Reg. 82381 (Dec. 28, 2000). December 12, 2001) (statement of Senator Dorgan). 30. Preamble to Proposed Privacy Rule, 64 Fed. Reg. 6002. 31. See HHS Guidance, note 5. Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 51 32. See HHS Guidance, note 5, at 3; 45 C.F.R. § 57. 45 C.F.R. § 164.514(d)(2). 160.304 and 65 Fed. Reg. 82603. 58. 45 C.F.R. § 164.530(j). 33. See 45 C.F.R. § 160.310. 59. 45 C.F.R. § 164.514(d)(3) and (4). 34. 45 C.F.R. § 160.306. 60. 45 C.F.R. § 164.530(j). 35. 45 C.F.R. § 160.308. 61. Cal. Ins. Code § 791.13(b)(1). 36. 45 C.F.R. § 160.310. 62. 45 C.F.R. § 164.502(e). 37. See discussion of documentation requirements in 63. 45 C.F.R. § 160.103 (defining “business associate”). “Administrative Requirements,” above. 64. 65 Fed. Reg. 82476. 38. 45 C.F.R. § 160.310. 65. 65 Fed. Reg. 82476. 39. 42 U.S.C. § 1320d-5. 66. 45 C.F.R. § 164.504(e)(2). 40. 42 U.S.C. § 1320d-6. 67. See generally Cal. Ins. Code § 791.13(b)-(r). 41. Preamble to Privacy Rule, 65 Fed. Reg. 82487. 68. It is beyond the scope of this guide to address every 42. 45 C.F.R. § 160.202. circumstance under which disclosure is permitted 43. 45 C.F.R. § 160.202. without the individual’s permission. The IIPPA alone lists 18 of these circumstances. 44. Cal. Civ. Code § 56-§ 56.37. 69. Cal. Ins. Code § 791.13(b), (c), (d), and (q). 45. Cal. Ins. Code § 791-§ 791.27 70. Cal. Ins. Code § 791.13(b) allows insurers to dis- 46. Cal. Health & Safety Code § 1340-§ 1399.76 close health information to a third party to perform 47. Cal. Welf. & Inst. Code § 14100.2. “business, professional or insurance function(s).” 48. The Lanterman-Petris-Short Act, codified at Cal. This broad provision appears to cover functions Welf. & Inst. Code § 5328 et seq. such as “customer service” and business planning and development” that would be considered to be 49. Cal. Health & Safety Code § 120775, § 120975-§ treatment, payment, and health care operations 121020. under the Federal Privacy Rule. For these functions, 50. Cal. Welf. & Inst. Code § 11970.5-§ 11977. no individual authorization would be required. The state provision however appears broad enough to 51. Cal. Ins. Code § 791 et seq. The IIPPA applies to a cover other functions that might not come within broad category of insurers; however, this discussion the definitions of “treatment, payment and health is limited to health insurers because only they will care operations.” For these functions, a health be subject to the requirements of the Federal insurer would be required to obtain a patient’s per- Privacy Rule. mission. 52. “Personal information” is defined as “individually 71. See note 289. identifiable information gathered in connection with an insurance transaction from which judg- 72. See note 289. ments can be made about an individual’s character, 73. 45 C.F.R. § 164.502(a). habits, avocations, finances, occupation, general reputation, credit, health, or any other personal 74. See 45 C.F.R. § 164.501 (defining these terms). characteristics”). The definition of “personal infor- 75. 45 C.F.R. § 164.506(a). mation” specifically includes “medical record infor- 76. 45 C.F.R. § 164.522. mation....Cal. Ins. Code § 791.02 (defining “per- sonal information”). 77. 45 C.F.R. § 164.522(a). 53. See 45 C.F.R. § 164.500. 78. 45 C.F.R. §164.522(b). 54. Cal. Ins. Code § 791.13. 79. Cal. Ins. Code § 791.13(g). 55. 45 C.F.R. § 164.502(b) (explaining when mini- 80. 45 C.F.R. § 164.512(a) mum necessary standard applies). 81. 45 C.F.R. § 164.512(f). 56. Guidance at 20. 52 | CALIFORNIA HEALTHCARE FOUNDATION 82. The IIPPA allows an insurer to disclose health 102. See 45 C.F.R. § 164.504(f )(3) (describing limita- information to a third party without an individual’s tions on group health plans and the plans that issue written permission for marketing purposes so long their coverage). as the individual is given the opportunity to “opt 103. 45 C.F.R. § 164.504(f )(1). out” of such uses. The third party is permitted to use the information for its own purposes. Cal. Ins. 104. 45 C.F.R. § 164.504(a) (defining “summary health Code § 791.13(k). In contrast, the Federal Privacy information”). Rule would require an individual’s written authori- 105. See 45 C.F.R. § 164.504(e) and 65 Fed. Reg. zation in this scenario. Therefore, the Federal 82509. Privacy Rule appears to be more stringent. 106. Cal. Civ. Code § 56.104. In order to release the 83. CITE information, the provider must have, in addition to 84. 45 C.F.R. § 164. the request, a signed general consent permitting it to use and disclose health information for treat- 85. Although the Federal Privacy Rule allows providers ment, payment, and health care operations under to disclose health information to insurance com- the Federal Privacy Rule. See 45 C.F.R. § 164.506. panies for health care operations with a general consent form, pre-enrollment underwriting is not 107. The patient may waive receiving a copy of the considered to be a health care operation of the request by submitting a signed letter to this effect provider and an authorization to disclose is to the provider. See Cal. Civ. Code § 56.104. required. 65 Fed. Reg. 82490 108. See 45 C.F.R. § 164.508(a)(2) and § 164.501 86. 45 C.F.R. § 164.508. (defining “psychotherapy notes”). 87. See Cal. Civ. Code § 56.11. 109. See 45 C.F.R. § 164.508(b)(4). 88. 45 C.F.R. § 164.508(c)(2). 110. See Cal. Ins. Code § 791.04. 89. See 45 C.F.R. § 164.508(b)(2). An authorization 111. Compare Cal. Ins. Code § 791.04(a) with 45 can be combined with other authorizations to C.F.R. § 164.520(b) and (c). use or disclose health information. This rule does 112. 45 C.F.R. § 164.520(b). This list is not exhaustive not apply to authorizations to use or disclose psy- because the requirements of the Federal Privacy chotherapy notes, which must always be separate. Rule are so detailed in this area. Please see the regu- It also does not apply where a covered entity has lation itself for all of the required elements of a conditioned the provision of treatment, payment, notice of privacy practices. or enrollment in a health plan, or the eligibility of benefits on the provision of an authorization. 113. Cal. Ins. Code § 791.08 and 791.09. 90. Cal. Ins. Code § 791.13 and 45 C.F.R. 114. See 45 C.F.R. § 164.524 (giving patients access to § 164.508(c)(1). information in a “designated record set”) and 45 C.F.R. § 164.501 (defining “designated record set”). 91. 45 C.F.R. § 164.508(c). 115. Cal. Ins. Code § 791.08. 92. 45 C.F.R. § 164.508(c). 116. 45 Fed. Reg. § 164.524 and § 164.501(defining 93. 45 C.F.R. § 164.508(c) and Cal. Ins. Code designated record set). § 791.13. 117. See Cal. Ins. Code § 791.08 (providing for access to 94. 45 C.F.R. § 164.508(c). “personal information”); 791.02(s) (defining “per- 95. 45 C.F.R. § 164.508(c). sonal information” as not including “privileged information”) and 791.02(v) (defining “privileged 96. 45 C.F.R. § 164.508(c). information”). 97. Cal. Ins. Code § 791.06. 118. See 45 C.F.R. § 164.524(a). 98. 45 C.F.R. § 164.508(d). 119. Cal. Ins. Code § 791.08(a). 99. 45 C.F.R. § 45 C.F.R. § 164.508(d)(2). 120. 45 C.F.R. § 164.524(b)(1). 100. 45 C.F.R. § 164.508(b)(5). 121. Cal. Ins. Code § 791.08(a); 45 C.F.R. § 164.514(h). 101. Per Cal. Dept. of Ins. 122. 45 C.F.R. § 164.524(b)(2). Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 53 123. The federal rule gives a health plan 30 days to 143. 45 C.F.R. § 164.530(a). respond and allows them one 30 day extension, so 144. 45 C.F.R. § 164.530(a). long as they notify the individual of the delay. 45 C.F.R § 164.524(b)(2). California law requires a 145. Preamble to Proposed Rule, 64 Fed. Reg. 59988. health plan to respond to such requests within 146. 45 C.F.R. § 164.506(d). 30 business days (a period which is longer than “30 days,” because it excludes weekends and holidays, 147. 45 C.F.R. § 164.508(b)(6). but shorter than the extended period allowed by 148. 45 C.F.R. § 164.506(b). the federal rule). Cal. Ins. Code § 791.08. 149. 45 C.F.R. § 164.522(a). 124. Cal. Ins. Code § 791.08(a). 150. 45 C.F.R. § 164.528(d)(1). 125. Cal. Ins. Code § 791.08(a). 151. 45 C.F.R. § 164.514 and § 164.530(i) and 126. 45 C.F.R. § 164.524(c). 164.530(j). 127. 45 C.F.R. 164.524 and 65 Fed. Reg. 82557 152. 45 C.F.R. § 164.530(b) and § 164.530(j)(1). (explaining acceptable fees). 153. 45 C.F.R. § 164.530(j)(2). 128. Privileged information is information that is collected in connection or anticipation of a claim 154. Benedict Carey, A Referee in Disputes between for insurance benefits or civil or criminal proceed- Patients, HMOs: A year after its debut, a state ings. Cal. Ins. Code § 791.02. See discussion agency offers a glimpse of how expanded rights may above about scope of access provisions. play out nationwide. Health; S-1 (July 30, 2001). 129. Cal. Ins. Code § 791.08(c). 155. This discussion focuses on health care service plans that are subject to the Knox-Keene Act. There are, 130. 45 C.F.R. § 164.524(a)(3). however, some health care service plans that are 131. 45 C.F.R. § 164.524(a)(3). exempt from the Knox-Keene Act. See Cal. Health & Safety Code § 1343(e). 132. Cal. Ins. Code § 791.08(a). 156. The CMIA applies to licensed health care 133. 45 C.F.R. § 164.528. providers, health care service plans licensed under 134. Cal. Ins. Code § 791.09. the Knox-Keene Act and contractors (medical groups that do not technically fall within the other 135. The IIPPA amendment provisions will not be categories). Cal. Civ. Code § 56.10. preempted by the Federal Privacy Rule because they do not conflict with the federal regulation. See 45 157. Cal. Civ. Code § 56.10. C.F.R. §§ 160.202 and 160.203 (explaining when 158. Cal. Civ. Code § 56.11. state law is preempted by the Federal Privacy Rule). Plans can easily comply with both the state and 159. Cal. Health & Safety Code § 1364.5. federal law by meeting the higher standards of the 160. Cal. Health & Safety Code § 1364.5. state law. 161. Cal. Civ. Code § 56.10 and § 56.05(f) 136. Cal. Ins. Code § 791.09. (defining “medical information”). 137. Cal. Ins. Code § 791.09.(a). 162. 45 C.F.R. § 164.501 (defining “protected health 138. 65 Fed. Reg. 82471. information”). In general, the Privacy Rule restricts the sharing of health information orally, but does 139. 5 C.F.R. § 164.530. not provide access to oral communications. Under 140. 45 C.F.R. § 164.530(c) and Cal. Civ. Code § the Rule, oral communications do not have to be 56.101 (requiring providers to preserve the confi- recorded. Since patients only have access to health dentiality of medical information if they create, information in “designated record sets” as a practi- maintain, preserve, store, abandon, destroy, or cal matter they do not have access rights to oral dispose of such information). Additionally, HHS information. However, if oral communications are is to issue more detailed final HIPAA-mandated recorded and used to make decisions about a per- security regulations. son, oral information may become part of a desig- nated record set and then must be made available 141. 65 Fed. Reg, 82562 and HHS Guidance at 22. to the patient upon request. Standards for Privacy 142. 45 C.F.R. § 164.530(b). of Individually Identifiable Health Information: Guidance at 28 (July 6, 2001) (hereinafter “Guidance”). 54 | CALIFORNIA HEALTHCARE FOUNDATION 163. Cal. Civ. Code § 56.10(c)(2). 193. See Cal. Civ. Code § 56.11. 164. Guidance at 20. 194. Cal. Civ. Code § 56.11. 165. 45 C.F.R. § 164.502(b) (explaining when 195. See 45 C.F.R. § 164.508(b)(2). An authorization minimum necessary standard applies). can be combined with other authorizations to use or disclose health information. This rule does not 166. 45 C.F.R. § 164.502(b)(2). apply to authorizations to use or disclose psycho- 167. 45 C.F.R. § 164.514(d)(2). therapy notes, which must always be separate. 168. 45 C.F.R. § 164.530(j). It also does not apply where a covered entity has conditioned the provision of treatment, payment 169. 45 C.F.R. § 164.502(b) and § 164.514(d)(4). or enrollment in a health plan, or the eligibility of 170. 45 C.F.R. § 164.530(j). benefits on the provision of an authorization. 171. 45 C.F.R. § 164.514(d). 196. Cal. Civ. Code § 56.11 and 45 C.F.R. § 164.508(c)(1). 172. Cal. Civ. Code § 56.10(c)(3). 197. 45 C.F.R. § 164.508(c). 173. 45 C.F.R. § 164.502(e). 198. Cal. Civ. Code § 56.11. 174. 45 C.F.R. § 160.103 (defining “business associate”). 199. Cal. Civ. Code § 56.11 and 45 C.F.R. §164.508(c). 175. 65 Fed. Reg. 82476. 200. Cal. Civ. Code § 56.11 and 45 C.F.R. §164.508(c) 176. 45 C.F.R. § 164.504(e)(2). (the Federal Privacy Rule also allows a person 177. See generally Cal. Civ. Code § 56.10and 45 C.F.R. to specify an event that would terminate the § 164.512. authorization). 178. Cal. Civ. Code § 56.10(c). 201. Cal. Civ. Code § 56.11 and 45 C.F.R. §164.508(c). 179. 45 C.F.R. § 164.502(a). 202. Cal. Civ. Code § 56.11. 180. See 45 C.F.R. § 164.501 (defining these terms). 203. Cal. Civ. Code §56.11. 181. 45 C.F.R. § 164.506(a). 204. 45 C.F.R. §164.508(c). 182. Although the CMIA allows providers who contract 205. 45 C.F.R. § 164.508(c). with health care service plans to share health 206. 45 C.F.R. § 164.508(d). information with those plans for the purpose of administering the plan without a patient’s express 207. 45 C.F.R. § 45 C.F.R. § 164.508(d)(2). permission, this state law will be superceded by 208. 45 C.F.R. § 164.508(b)(5). the Federal Privacy Rule which requires written consent prior to such a disclosure. Cal. Civ. Code 209. 45 C.F.R. § 164.514(e). § 56.10(c)(10). 210. Cal. Civ. Code § 56.10(d) specifies that a provider 183. 45 C.F.R. § 164.522. may not share, sell, or otherwise use any medical information for any purpose not necessary to 184. 45 C.F.R. § 164.522(a). provide health care services to the patient. 185 45 C.F.R. §164.522(b). 211. Cal. Civ. Code § 56.104. 186. Cal. Civ. Code § 56.10(b) and 45 C.F.R. § 164.512. 212. In order to release the information, the provider 187. Cal. Civ. Code § 56.10(b) and 45 C.F.R. must also have a signed consent permitting it to use § 164.512(f). and disclose health information for the purposes of treatment, payment, and health care operations 188. 45 C.F.R. § 164.512(f). under the Federal Privacy Rule. See 45 C.F.R. 189. Cal Civ. Code § 56.10 (c)(7) and 45 C.F.R. § 164.506. § 164.512(i). 213. See 45 C.F.R. § 164.508(a)(2) and § 164.501 190. 45 C.F.R. § 164.512(i). (defining “psychotherapy notes”). 191. Cal. Civ. Code § 56.10(a). 214. See 45 C.F.R. § 164.508(b)(4). 192. 45 C.F.R. § 164.508. . 215. Cal. Health & Safety Code § 1364.5(b). Implementing the Federal Health Privacy Rule in California: A Guide for Health Insurers and Health Care Service Plans | 55 216. Cal. Health & Safety Code § 1364.5(b). 244. 45 C.F.R. § 164.524(a). There are additional circumstances, such as requests from inmates, that 217. Cal. Health & Safety Code § 1364.5(b). generally would not be encountered by health 218. 45 C.F.R. § 164.520. care service plans. 219. 45 C.F.R. § 164.520(c). April 14, 2004 is the com- 245. 45 C.F.R. § 164.524(d). pliance date for small health plans (i.e., those health 246. 45 C.F.R. § 164.524(d). plans with annual receipts of $5 million or less). 45 C.F.R. § 160.103 (defining “small health plan”) 247. 45 C.F.R. § 164.524(d). and § 164.534 (specifying compliance dates). 248. 45 C.F.R. § 164.524(d). 220. 45 C.F.R. § 164.520(c). 249. 45 C.F.R. § 164.528. 221. 45 C.F.R. § 164.520(b). 250. 45 C.F.R. § 164.528(a). 222. Cal. Health & Safety Code § 1364.5(c). 251. 45 C.F.R. § 164.528(a) (providing accounting of 223. 45 C.F.R. § 164.520(b). “disclosures”) and § 164.501 (defining “disclosure” and “use”). 224. Cal. Health & Safety Code § 1364.5(c) and 45 C.F.R. 520(b). 252. 45 C.F.R. § 164.528(a). 225. Cal. Health & Safety Code § 1364.5(c) and 253. 45 C.F.R. § 164.526. 45 C.F.R. 520(b). 254. 45 C.F.R. § 164.526(a). 226. Cal. Health & Safety Code § 1364.5(c) and 255. 45 C.F.R. § 164.526(b). 45 C.F.R. 520(b). 256. 45 C.F.R. § 164.526(c). 227. Cal. Health & Safety Code § 1364.5(c). 257. 45 C.F.R. § 164.526(d). 228. Cal. Health & Safety Code § 1364.5(c). 258. 45 C.F.R. § 164.526(d). 229. 45 C.F.R. § 164.520(b). 259. 45 C.F.R. § 164.526(d). 230. 45 C.F.R. § 164.520(b). 260. 65 Fed. Reg. 82471. 231. 45 C.F.R. § 164.520(b). 261. 45 C.F.R. § 164.530. 232. Cal. Health & Safety Code § 1364.5(c)(4). 262. § 164.530(c). In addition, HHS is to issue more 233. See 45 C.F.R. § 164.524 (giving patients access to detailed final HIPAA-mandated security regulations. information in a “designated record set”) and 45 C.F.R. § 164.501 (defining “designated record set”). 263. 65 Fed. Reg, 82562. 234. 45 C.F.R. § 164.524(a) and § 164.501 (defining a 264. 45 C.F.R. § 164.530(b). “designated record set”). As a general rule, providers 265. Preamble to Proposed Standard for Privacy of in a group practice prepayment plan maintain the Individually Identifiable Health Information, actual medical records, and must give the individual 64 Fed. Reg. 59989 (Nov. 3, 1999). access to those records. 266. 45 C.F.R. § 164.530(a). 235. 45 C.F.R. § 164.524(a). 267. 45 C.F.R. § 164.530(a). 236. 45 C.F.R. § 164.514(h). 268. Preamble to Proposed Rule, 64 Fed. Reg. 59988. 237. 45 C.F.R. § 164.524(b). 269. 45 C.F.R. § 164.506(d). 238. 45 C.F.R. § 164.524(d). 270. 45 C.F.R. § 164.522(a). 239. 45 C.F.R. § 164.524(c). 271. 45 C.F.R. § 164.508(b)(6). 240. 45 C.F.R. § 164.524(c). 272. 45 C.F.R. § 164.528(d)(1). 241. 45 C.F.R. § 164.524(c). 273. 45 C.F.R. § 164.514 and § 164.530(i) and 242. 45 C.F.R. § 164.524 and 65 Fed. Reg. 82557 164.530(j). (explaining acceptable fees). 274. 45 C.F.R. § 164.530(b) and § 164.530(j)(1). 243. 45 C.F.R. § 164.524(c). 275. 45 C.F.R. § 164.530(j)(2). 56 | CALIFORNIA HEALTHCARE FOUNDATION Related Publications in the iHealthReports series include: q HIPAA Administrative Simplification: Tool Kit for Small Group and Safety-Net Providers q Comparing eHealth Privacy Initiatives q E-Encounters q E-Disease Management q E-Prescribing q Wireless and Mobile Computing These reports can be obtained by visiting the CHCF Web site at www.chcf.org or by calling the Publications line at 1-888-430-CHCF (2423).