BILL ANALYSIS
SENATE HEALTH
COMMITTEE ANALYSIS
Senator Elaine K. Alquist, Chair
BILL NO: SB 337
S
AUTHOR: Alquist
B
AMENDED: April 22, 2009
HEARING DATE: April 29, 2009
3
CONSULTANT:
3
Hansel/sh
7
SUBJECT
Patient medical information: disclosure: reporting.
SUMMARY
Revises the time limits by which clinics, health
facilities, home health agencies, and hospices must report
instances of unauthorized access to, or use or disclosure
of, patients' medical information. Requires these entities
to delay reports if a law enforcement agency or official
provides the entity with a statement that compliance with
the reporting requirement would be likely to impede the law
enforcement agency's activities, and specifies a date upon
which the delay shall end, with specific requirements for
oral, versus written, requests for delays in reporting.
CHANGES TO EXISTING LAW
Existing federal law:
Prohibits, under federal regulations implementing the
federal Health Insurance Portability and Accountability Act
(HIPAA), a health plan, health care clearinghouse or a
health care provider, who transmits health information in
electronic form (covered entity), from using or disclosing
Continued---
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 2
protected health information, for purposes other than
medical treatment or payment, or health care operations, as
defined, without written authorization of the patient, with
exceptions.
Requires covered entities, and their business associates,
to provide notice of medical privacy breaches involving the
unauthorized acquisition, access, use, or disclosure of
protected health information to each individual whose
information has been subject to a breach within 60 days of
the discovery of the breach.
Provides that if a law enforcement official determines that
notice of a medical privacy breach would impede a criminal
investigation or cause damage to national security, the
notice shall be delayed, in a specified manner.
Existing state law:
Prohibits, under the Confidentiality of Medical Information
Act (CMIA), licensed or certified health care
professionals, clinics and health facilities, health plans,
and contracting entities, as defined, from disclosing or
using a patient's medical information for any purpose not
necessary to provide health care services to the patient
and related administrative functions, without first
obtaining authorization from the patient or the patient's
representative, as specified, with exceptions.
Provides for administrative fines and civil penalties for
persons and entities subject to the CMIA who negligently
disclose, or who knowingly and willfully obtain, disclose,
or use, medical information in violation of the CMIA, and
authorizes the Attorney General, any district attorney, any
county counsel acting pursuant to an agreement with the
district attorney, or a city attorney, to seek civil
penalties for violations.
Requires every provider of health care to establish and
implement administrative, technical, and physical
safeguards to protect the privacy of patients' medical
information, and requires every provider to reasonably
safeguard confidential medical information from any
unauthorized access or unlawful access, use, or disclosure.
Defines unauthorized access as the inappropriate review or
viewing of patient medical information without a direct
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 3
need for diagnosis, treatment, or other lawful use of the
information.
Requires a clinic, health facility, home health agency, or
hospice to report any unlawful or unauthorized access to,
or use or disclosure of, a patient's medical information to
the Department of Public Health (DPH) and to the affected
patient or patient's representative, no later than five
days after the unlawful or unauthorized access, use, or
disclosure has been detected by the entity. Allows DPH to
assess a penalty of $100 for each day the unlawful or
unauthorized access, use, or disclosure is not reported,
following the initial five-day period, not to exceed
$250,000 per reported event.
Requires other persons or businesses that own or license
computerized data that includes personal information,
including medical information, to disclose any breach of
the security of the system to a resident whose unencrypted
personal information was acquired by an unauthorized
person. Provides that the notification may be delayed if a
law enforcement agency determines that notification will
impede a criminal investigation, as specified.
This bill:
Requires a clinic, health facility, home health agency, or
hospice to report any unauthorized access to, or use or
disclosure of, a patient's medical information to DPH and
to the affected patient or patient's representative, no
later than five business days after the unlawful or
unauthorized access, use, or disclosure has been detected
by the entity.
Requires the clinic, health facility, home health agency,
or hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical
information to DPH if a law enforcement agency or official
provides the entity with a written or oral statement that
compliance with the reporting requirement would be likely
to impede the law enforcement agency's activities, and
specifies a date upon the delay shall end.
Requires, in the case that the statement of the law
enforcement agency or official is made orally, the clinic,
health facility, home health agency, or hospice to document
the statement and to limit the delay in reporting to the
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 4
date specified in the oral statement, not to exceed 30
calendar days from the date the oral statement is made,
unless a written statement is received during that time
period.
Requires a clinic, health facility, home health agency, or
hospice that is subject to a delay in reporting for law
enforcement purposes to report the unauthorized access to,
or use or disclosure of, the patient's medical information
no later than five business days after the date designated
as the end of the delay.
FISCAL IMPACT
Unknown.
BACKGROUND AND DISCUSSION
The author states that SB 337 is intended to make two
revisions to existing requirements that health facilities
notify patients and the DPH when they detect any unlawful
or unauthorized access to, or use or disclosure of, a
patient's medical information. Those requirements were
contained in SB 541 (Alquist) of last session.
The first is to revise the timeline for reporting such
breaches from five days to five business days. The second
is to allow for a delay in the reporting of such breaches
when a law enforcement agency or official makes a statement
that it would impede a law enforcement investigation.
The author states that these are reasonable revisions of
the reporting requirements for medical privacy breaches for
health facilities that are consistent with the intent of
the original legislation.
2007-08 Medical Privacy Legislation
In response to several high profile incidents involving
unauthorized access to, and misuse of, patients'
confidential medical information, the Legislature enacted
two bills in the 2007-2008 Session, SB 541 (Alquist -
Chapter 605, Statutes of 2008) and AB 211 (Jones - Chapter
602, Statutes of 2008).
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 5
SB 541 requires health care facilities to prevent unlawful
or unauthorized access to, use or disclosure of, patients'
medical information and to establish safeguards to protect
the privacy of patients' medical information. Among its
provisions, SB 541 additionally requires a clinic, health
facility, home health agency, or hospice to report any
unlawful or unauthorized access to, or use or disclosure
of, a patient's medical information to DPH and to the
affected patient or patient's representative, no later than
five days after the unlawful or unauthorized access, use,
or disclosure has been detected by the entity. The bill
authorizes DPH to assess a penalty of $100 for each day
that an unlawful or unauthorized access, use, or disclosure
of medical information is not reported, beyond five days
after it has been detected, up to a maximum of $250,000 per
reported event.
AB 211 requires health care providers to establish
appropriate safeguards to protect patients' medical
information from unauthorized or unlawful access, use, or
disclosure. The bill also establishes the Office of Health
Information Integrity (OHII) and gives it authority, upon a
referral from DPH, to assess administrative fines against
any person or health care provider for unauthorized use of
patients' medical information. AB 211 also allows the
Office to recommend that a licensing board further
investigate and discipline a health care provider for
violations of the bill's provisions.
In support of the bills, DPH released data indicating that
349 medical information confidentiality violations,
involving 5,235 patients, had occurred in general acute
care hospitals in the prior two-year period. Prior to the
enactment of these bills, the only remedy DPH had, if a
health facility failed to safeguard patients' medical
records, was to issue a notice of deficiency and require
the facility to implement a plan of correction, which is
cumbersome and less effective than imposing an
administrative penalty. Among the violations cited by DPH
were those that occurred at the UCLA Medical Center.
DPH also indicated that while it could refer individual
providers within a health facility to the relevant
licensing board or to law enforcement, the then-existing
provisions of the CMIA did not adequately address
unauthorized access to medical records, as opposed to
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 6
negligent or willful disclosure of the records.
Another factor precipitating passage of the two bills was
press coverage indicating that hospitals and other health
care organizations commonly use patients' information for
fundraising efforts without their express permission.
DPH reports that since January 1, 2009, when SB 541 took
effect, it has substantiated 18 cases of breaches of
medical confidentiality involving health facilities.
Notification of breaches of medical privacy under federal
law
Under the medical privacy provisions of the recently
enacted federal economic stimulus bill, the American
Recovery and Reinvestment Act (ARRA), entities that
transmit health information in an electronic form are
required to provide notice of a medical privacy breach to
an individual whose information has been subject to a
breach, within 60 days of the discovery of the breach. The
60-day requirement is delayed in the case that a law
enforcement official determines that notice of a medical
privacy breach would impede a criminal investigation or
cause damage to national security. However, the ARRA
provides that state medical privacy breach notification
laws that are more protective of medical privacy (such as
the notification requirements in SB 541) are not preempted.
Related Bills
SB 368 (Maldonado) - Allows OHII to audit the procedures
and records of a health care provider at any time in order
to determine the provider's compliance with requirements to
establish and implement appropriate administrative,
technical, and physical safeguards to protect the privacy
of patient's medical information, and to reasonably
safeguard confidential medical information from any
unauthorized access or unlawful access, use, or disclosure.
Currently in the Senate Health Committee; the author has
made this a two-year bill.
AB 1011 (Jones) - By April 1, 2010, requires OHII to report
to the Legislature on the impact of federal changes related
to health care technology and the privacy of health and
medical information, including recommendations for
statutory changes to ensure that California's medical
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 7
privacy laws are minimally compliant with or exceed federal
privacy laws. Scheduled to be heard April 28 in the
Assembly Health Committee.
Prior legislation
AB 1301 (Alquist), Chapter 647, Statutes of 2006 requires
general acute care hospitals, acute psychiatric hospitals,
and special hospitals to report adverse events to the
Department of Health Services (now DPH) no later than five
days after the event has been detected, or in the case of
an urgent or emergent threat, not later than 24 hours after
the adverse event has been detected. Requires DPH, by
January 1, 2013, to provide information regarding reports
of substantiated adverse events and the outcomes of
inspections on its website.
SB 1312 (Alquist), Chapter 895, Statutes of 2006 authorizes
DPH to assess administrative penalties on hospitals based
on deficiencies constituting immediate jeopardy to the
health and safety of a patient. Requires inspections and
investigations of long-term care facilities certified by
the Medicare or Medicaid program to determine compliance
with federal standards and California statutes and
regulations. Eliminates existing law that provides an
exemption for specified health care facilities from
periodic inspections by DPH.
Arguments in support
The California Hospital Association (CHA) states that many
hospitals operate manual systems to assign patient
identification numbers and in those cases, identifying and
extracting data regarding patients whose medical
information has been improperly accessed, used, or
disclosed would be a labor intensive process that could
take more than five days, as currently provided in law.
CHA supports the change to five business days for
reporting, but notes that it would still be stricter than
federal law. CHA also states that the provisions of the
bill allowing a delay in reporting at the request of law
enforcement are similar to those adopted as part of ARRA,
and argues that patient privacy laws that deviate
extensively from federal laws place additional burdens and
expense on hospitals, which could be better utilized
provided care to patients.
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 8
COMMENTS
1. Process for renewal of law enforcement requests for
delays. SB 337 provides that a health care provider shall
delay notification of DPH and an affected individual of a
medical privacy breach if a law enforcement official or
agency provides a statement that the notification would
impede the agency's enforcement activities, and specifies a
date on which the delay shall end. If the statement is
made orally, which is the form most requests are likely to
be made due to the five day reporting window, the delay is
limited to 30 calendar days, unless a written statement is
received during that time that specifies a different date.
However, the bill does not specify a time limit for the
delay in the written statement. Does the author wish to
specify a time limit for the delay in reporting under these
circumstances?
POSITIONS
Support: American Federation of State, County and
Municipal Employees
California Hospital Association
Oppose: None received
-- END --