BILL NUMBER: AB 1830	INTRODUCED
	BILL TEXT


INTRODUCED BY   Assembly Member Conway

                        FEBRUARY 18, 2014

   An act to add Section 100509 to the Government Code, relating to
health care coverage.


	LEGISLATIVE COUNSEL'S DIGEST


   AB 1830, as introduced, Conway. California Health Benefit
Exchange: confidentiality of personally identifiable information.
   Existing law, the federal Patient Protection and Affordable Care
Act (PPACA), requires each state to establish an American Health
Benefit Exchange by January 1, 2014, that makes available qualified
health plans to qualified individuals and small employers. PPACA
prohibits an Exchange from using or disclosing the personally
identifiable information it creates or collects other than to the
extent necessary to carry out specified functions. Existing law also
requires an Exchange to establish and implement privacy and security
standards that are consistent with specified principles and to
require the same or more stringent privacy and security standards as
a condition of contract or agreement with individuals or entities. A
person who knowingly and willfully uses or discloses information in
violation of PPACA is subject to a civil penalty of no more than
$25,000 per person or entity, per use or disclosure, in additional to
any other penalties prescribed by law.
   Existing state law establishes the California Health Benefit
Exchange within state government, specifies the powers and duties of
the board governing the Exchange, and requires the board to
facilitate the purchase of qualified health plans through the
Exchange by qualified individuals and small employers by January 1,
2014. Existing law requires the board to employ necessary staff and
authorizes the board to enter into contracts. Under existing law, the
board of the Exchange is required to submit fingerprint images to
the Department of Justice for all employees, prospective employees,
contractors, subcontractors, volunteers, or vendors of the Exchange
whose duties include access to specified personal information for the
purposes of obtaining state or federal conviction records, as
specified.
   This bill would, where the Exchange creates or collects personally
identifiable information for the purpose of determining eligibility
for specified plans and programs, authorize the Exchange to use or
disclose that information only to the extent necessary to carry out
specified functions authorized under PPACA. The bill would prohibit a
contractor, subcontractor, volunteer, or vendor of the Exchange who
gains access to personally identifiable information in the course of
fulfilling his, her, or its duties as a contractor, subcontractor,
volunteer, or vendor from using or disclosing that information other
than to the extent necessary to carry out those duties. The bill
would require a contractor, subcontractor, volunteer, or vendor of
the Exchange to comply with the privacy and security standards
adopted by the Exchange pursuant to PPACA. An individual or entity
who knowingly and willfully violates these provisions would be
subject to a civil penalty of not more than $25,000 per individual or
entity, per use or disclosure, in addition to any other penalties
prescribed by law.
   Vote: majority. Appropriation: no. Fiscal committee: yes.
State-mandated local program: no.


THE PEOPLE OF THE STATE OF CALIFORNIA DO ENACT AS FOLLOWS:

  SECTION 1.  Section 100509 is added to the Government Code, to
read:
   100509.  (a) (1) Where the Exchange creates or collects personally
identifiable information for the purpose of determining eligibility
for enrollment in a qualified health plan, determining eligibility
for other insurance affordability programs, as defined in Section
155.20 of Title 45 of the Code of Federal Regulations, or determining
eligibility for exemptions from the individual responsibility
provisions in Section 5000A of the federal Internal Revenue Code, the
Exchange may only use or disclose the information to the extent
necessary to carry out the functions described in Section 155.200 of
Title 45 of the Code of Federal Regulations.
   (2) The Exchange shall not create, collect, use, or disclose
personally identifiable information while fulfilling its
responsibilities in accordance with this title and Section 155.200 of
Title 45 of the Code of Federal Regulations unless the creation,
collection, use, or disclosure is consistent with Section 155.260 of
Title 45 of the Code of Federal Regulations.
   (3) For purposes of this subdivision, "Exchange" includes a member
of the board or staff of the Exchange.
   (b) A contractor, subcontractor, volunteer, or vendor of the
Exchange who gains access to personally identifiable information in
the course of fulfilling his, her, or its duties as a contractor,
subcontractor, volunteer, or vendor of the Exchange shall not use or
disclose that information other than to the extent necessary to carry
out those duties.
   (c) A contractor, subcontractor, volunteer, or vendor of the
Exchange shall comply with the privacy and security standards adopted
by the Exchange pursuant to Section 155.260 of Title 45 of the Code
of Federal Regulations.
   (d) This section does not apply when the use or disclosure of
personally identifiable information is otherwise compelled by
judicial or administrative process or by any other provision of law,
except as otherwise provided in the federal act.
   (e) Where the Exchange or a contractor, subcontractor, volunteer,
or vendor of the Exchange has access to federal tax return
information, that information shall be kept confidential and
disclosed, used, and maintained only in accordance with Section 6103
of the federal Internal Revenue Code.
   (f) An individual or entity who knowingly and willfully violates
this section shall be subject to a civil penalty of not more than
twenty-five thousand dollars ($25,000) per individual or entity, per
use or disclosure, in addition to any other penalties prescribed by
law.
   (g) For purposes of this section, "personally identifiable
information" means information that includes or contains any element
of personal identifying information sufficient to allow
identification of the individual, including, but not limited to, the
individual's name, address, electronic mail address, telephone
number, social security number, credit card number, place or date of
birth, biometric records, or other information that, alone or in
combination with other publicly available information, reveals the
individual's identity.