BILL ANALYSIS                                                                                                                                                                                                    






                                 SENATE HEALTH
                               COMMITTEE ANALYSIS
                        Senator Elaine K. Alquist, Chair


          BILL NO:       SB 337                                       
          S
          AUTHOR:        Alquist                                      
          B
          AMENDED:       April 22, 2009                              
          HEARING DATE:  April 29, 2009                               
          3
          CONSULTANT:                                                 
          3
          Hansel/sh                                                   
          7
                                                                     
                                        

                                     SUBJECT
                                         
              Patient medical information: disclosure: reporting.


                                     SUMMARY  

          Revises the time limits by which clinics, health  
          facilities, home health agencies, and hospices must report  
          instances of unauthorized access to, or use or disclosure  
          of, patients' medical information.  Requires these entities  
          to delay reports if a law enforcement agency or official  
          provides the entity with a statement that compliance with  
          the reporting requirement would be likely to impede the law  
          enforcement agency's activities, and specifies a date upon  
          which the delay shall end, with specific requirements for  
          oral, versus written, requests for delays in reporting.  


                             CHANGES TO EXISTING LAW  

          Existing federal law:
          Prohibits, under federal regulations implementing the  
          federal Health Insurance Portability and Accountability Act  
          (HIPAA), a health plan, health care clearinghouse or a  
          health care provider, who transmits health information in  
          electronic form (covered entity), from using or disclosing  
                                                         Continued---



          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 2


          

          protected health information, for purposes other than  
          medical treatment or payment, or health care operations, as  
          defined, without written authorization of the patient, with  
          exceptions.

          Requires covered entities, and their business associates,  
          to provide notice of medical privacy breaches involving the  
          unauthorized acquisition, access, use, or disclosure of  
          protected health information to each individual whose  
          information has been subject to a breach within 60 days of  
          the discovery of the breach.  

          Provides that if a law enforcement official determines that  
          notice of a medical privacy breach would impede a criminal  
          investigation or cause damage to national security, the  
          notice shall be delayed, in a specified manner.
          Existing state law:
          Prohibits, under the Confidentiality of Medical Information  
          Act (CMIA), licensed or certified health care  
          professionals, clinics and health facilities, health plans,  
          and contracting entities, as defined, from disclosing or  
          using a patient's medical information for any purpose not  
          necessary to provide health care services to the patient  
          and related administrative functions, without first  
          obtaining authorization from the patient or the patient's  
          representative, as specified, with exceptions.

          Provides for administrative fines and civil penalties for  
          persons and entities subject to the CMIA who negligently  
          disclose, or who knowingly and willfully obtain, disclose,  
          or use, medical information in violation of the CMIA, and  
          authorizes the Attorney General, any district attorney, any  
          county counsel acting pursuant to an agreement with the  
          district attorney, or a city attorney, to seek civil  
          penalties for violations.  

          Requires every provider of health care to establish and  
          implement administrative, technical, and physical  
          safeguards to protect the privacy of patients' medical  
          information, and requires every provider to reasonably  
          safeguard confidential medical information from any  
          unauthorized access or unlawful access, use, or disclosure.  
           

          Defines unauthorized access as the inappropriate review or  
          viewing of patient medical information without a direct  




          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 3


          

          need for diagnosis, treatment, or other lawful use of the  
          information.

          Requires a clinic, health facility, home health agency, or  
          hospice to report any unlawful or unauthorized access to,  
          or use or disclosure of, a patient's medical information to  
          the Department of Public Health (DPH) and to the affected  
          patient or patient's representative, no later than five  
          days after the unlawful or unauthorized access, use, or  
          disclosure has been detected by the entity.  Allows DPH to  
          assess a penalty of $100 for each day the unlawful or  
          unauthorized access, use, or disclosure is not reported,  
          following the initial five-day period, not to exceed  
          $250,000 per reported event.  

          Requires other persons or businesses that own or license  
          computerized data that includes personal information,  
          including medical information, to disclose any breach of  
          the security of the system to a resident whose unencrypted  
          personal information was acquired by an unauthorized  
          person.  Provides that the notification may be delayed if a  
          law enforcement agency determines that notification will  
          impede a criminal investigation, as specified.
          
          This bill:
          Requires a clinic, health facility, home health agency, or  
          hospice to report any unauthorized access to, or use or  
          disclosure of, a patient's medical information to DPH and  
          to the affected patient or patient's representative, no  
          later than five business days after the unlawful or  
          unauthorized access, use, or disclosure has been detected  
          by the entity.  

          Requires the clinic, health facility, home health agency,  
          or hospice to delay reporting any unlawful or unauthorized  
          access, use, or disclosure of a patient's medical  
          information to DPH if a law enforcement agency or official  
          provides the entity with a written or oral statement that  
          compliance with the reporting requirement would be likely  
          to impede the law enforcement agency's activities, and  
          specifies a date upon the delay shall end.

          Requires, in the case that the statement of the law  
          enforcement agency or official is made orally, the clinic,  
          health facility, home health agency, or hospice to document  
          the statement and to limit the delay in reporting to the  




          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 4


          

          date specified in the oral statement, not to exceed 30  
          calendar days from the date the oral statement is made,  
          unless a written statement is received during that time  
          period.

          Requires a clinic, health facility, home health agency, or  
          hospice that is subject to a delay in reporting for law  
          enforcement purposes to report the unauthorized access to,  
          or use or disclosure of, the patient's medical information  
          no later than five business days after the date designated  
          as the end of the delay.


                                  FISCAL IMPACT  

          Unknown.


                            BACKGROUND AND DISCUSSION  

          The author states that SB 337 is intended to make two  
          revisions to existing requirements that health facilities  
          notify patients and the DPH when they detect any unlawful  
          or unauthorized access to, or use or disclosure of, a  
          patient's medical information.  Those requirements were  
          contained in SB 541 (Alquist) of last session.

          The first is to revise the timeline for reporting such  
          breaches from five days to five business days.  The second  
          is to allow for a delay in the reporting of such breaches  
          when a law enforcement agency or official makes a statement  
          that it would impede a law enforcement investigation.  

          The author states that these are reasonable revisions of  
          the reporting requirements for medical privacy breaches for  
          health facilities that are consistent with the intent of  
          the original legislation.
          
          2007-08 Medical Privacy Legislation
          In response to several high profile incidents involving  
          unauthorized access to, and misuse of, patients'  
          confidential medical information, the Legislature enacted  
          two bills in the 2007-2008 Session, SB 541 (Alquist -  
          Chapter 605, Statutes of 2008) and AB 211 (Jones - Chapter  
          602, Statutes of 2008).  





          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 5


          

          SB 541 requires health care facilities to prevent unlawful  
          or unauthorized access to, use or disclosure of, patients'  
          medical information and to establish safeguards to protect  
          the privacy of patients' medical information.  Among its  
          provisions, SB 541 additionally requires a clinic, health  
          facility, home health agency, or hospice to report any  
          unlawful or unauthorized access to, or use or disclosure  
          of, a patient's medical information to DPH and to the  
          affected patient or patient's representative, no later than  
          five days after the unlawful or unauthorized access, use,  
          or disclosure has been detected by the entity.  The bill  
          authorizes DPH to assess a penalty of $100 for each day  
          that an unlawful or unauthorized access, use, or disclosure  
          of medical information is not reported, beyond five days  
          after it has been detected, up to a maximum of $250,000 per  
          reported event.  

          AB 211 requires health care providers to establish  
          appropriate safeguards to protect patients' medical  
          information from unauthorized or unlawful access, use, or  
          disclosure.  The bill also establishes the Office of Health  
          Information Integrity (OHII) and gives it authority, upon a  
          referral from DPH, to assess administrative fines against  
          any person or health care provider for unauthorized use of  
          patients' medical information.  AB 211 also allows the  
          Office to recommend that a licensing board further  
          investigate and discipline a health care provider for  
          violations of the bill's provisions.  

          In support of the bills, DPH released data indicating that  
          349 medical information confidentiality violations,  
          involving 5,235 patients, had occurred in general acute  
          care hospitals in the prior two-year period.  Prior to the  
          enactment of these bills, the only remedy DPH had, if a  
          health facility failed to safeguard patients' medical  
          records, was to issue a notice of deficiency and require  
          the facility to implement a plan of correction, which is  
          cumbersome and less effective than imposing an  
          administrative penalty.  Among the violations cited by DPH  
          were those that occurred at the UCLA Medical Center.  
                                            
          DPH also indicated that while it could refer individual  
          providers within a health facility to the relevant  
          licensing board or to law enforcement, the then-existing  
          provisions of the CMIA did not adequately address  
          unauthorized access to medical records, as opposed to  




          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 6


          

          negligent or willful disclosure of the records.

          Another factor precipitating passage of the two bills was  
          press coverage indicating that hospitals and other health  
          care organizations commonly use patients' information for  
          fundraising efforts without their express permission.

          DPH reports that since January 1, 2009, when SB 541 took  
          effect, it has substantiated 18 cases of breaches of  
          medical confidentiality involving health facilities.  

          Notification of breaches of medical privacy under federal  
          law
          Under the medical privacy provisions of the recently  
          enacted federal economic stimulus bill, the American  
          Recovery and Reinvestment Act (ARRA), entities that  
          transmit health information in an electronic form are  
          required to provide notice of a medical privacy breach to  
          an individual whose information has been subject to a  
          breach, within 60 days of the discovery of the breach.  The  
          60-day requirement is delayed in the case that a law  
          enforcement official determines that notice of a medical  
          privacy breach would impede a criminal investigation or  
          cause damage to national security.  However, the ARRA  
          provides that state medical privacy breach notification  
          laws that are more protective of medical privacy (such as  
          the notification requirements in SB 541) are not preempted.  
           
          
          Related Bills
          SB 368 (Maldonado) - Allows OHII to audit the procedures  
          and records of a health care provider at any time in order  
          to determine the provider's compliance with requirements to  
          establish and implement appropriate administrative,  
          technical, and physical safeguards to protect the privacy  
          of patient's medical information, and to reasonably  
          safeguard confidential medical information from any  
          unauthorized access or unlawful access, use, or disclosure.  
           Currently in the Senate Health Committee; the author has  
          made this a two-year bill.

          AB 1011 (Jones) - By April 1, 2010, requires OHII to report  
          to the Legislature on the impact of federal changes related  
          to health care technology and the privacy of health and  
          medical information, including recommendations for  
          statutory changes to ensure that California's medical  




          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 7


          

          privacy laws are minimally compliant with or exceed federal  
          privacy laws.  Scheduled to be heard April 28 in the  
          Assembly Health Committee.

          Prior legislation
          AB 1301 (Alquist), Chapter 647, Statutes of 2006 requires  
          general acute care hospitals, acute psychiatric hospitals,  
          and special hospitals to report adverse events to the  
          Department of Health Services (now DPH) no later than five  
          days after the event has been detected, or in the case of  
          an urgent or emergent threat, not later than 24 hours after
          the adverse event has been detected.  Requires DPH, by  
          January 1, 2013, to provide information regarding reports  
          of substantiated adverse events and the outcomes of
          inspections on its website.

          SB 1312 (Alquist), Chapter 895, Statutes of 2006 authorizes  
          DPH to assess administrative penalties on hospitals based  
          on deficiencies constituting immediate jeopardy to the  
          health and safety of a patient.  Requires inspections and  
          investigations of long-term care facilities certified by  
          the Medicare or Medicaid program to determine compliance  
          with federal standards and California statutes and  
          regulations. Eliminates existing law that provides an  
          exemption for specified health care facilities from
          periodic inspections by DPH.
          
          Arguments in support
          The California Hospital Association (CHA) states that many  
          hospitals operate manual systems to assign patient  
          identification numbers and in those cases, identifying and  
          extracting data regarding patients whose medical  
          information has been improperly accessed, used, or  
          disclosed would be a labor intensive process that could  
          take more than five days, as currently provided in law.   
          CHA supports the change to five business days for  
          reporting, but notes that it would still be stricter than  
          federal law.  CHA also states that the provisions of the  
          bill allowing a delay in reporting at the request of law  
          enforcement are similar to those adopted as part of ARRA,  
          and argues that patient privacy laws that deviate  
          extensively from federal laws place additional burdens and  
          expense on hospitals, which could be better utilized  
          provided care to patients.
          





          STAFF ANALYSIS OF SENATE BILL  SB 337 (Alquist)Page 8


          

                                     COMMENTS
                                         
          1.  Process for renewal of law enforcement requests for  
          delays.  SB 337 provides that a health care provider shall  
          delay notification of DPH and an affected individual of a  
          medical privacy breach if a law enforcement official or  
          agency provides a statement that the notification would  
          impede the agency's enforcement activities, and specifies a  
          date on which the delay shall end.  If the statement is  
          made orally, which is the form most requests are likely to  
          be made due to the five day reporting window, the delay is  
          limited to 30 calendar days, unless a written statement is  
          received during that time that specifies a different date.   
          However, the bill does not specify a time limit for the  
          delay in the written statement.  Does the author wish to  
          specify a time limit for the delay in reporting under these  
          circumstances?

                                         
                                   POSITIONS  


          Support:  American Federation of State, County and  
          Municipal Employees 
                 California Hospital Association

          
          Oppose:   None received


                                   -- END --