BILL ANALYSIS
------------------------------------------------------------
|SENATE RULES COMMITTEE | SB 337|
|Office of Senate Floor Analyses | |
|1020 N Street, Suite 524 | |
|(916) 651-1520 Fax: (916) | |
|327-4478 | |
------------------------------------------------------------
THIRD READING
Bill No: SB 337
Author: Alquist (D)
Amended: 5/6/09
Vote: 21
SENATE HEALTH COMMITTEE : 9-0, 4/29/09
AYES: Alquist, Strickland, Aanestad, DeSaulnier, Leno,
Maldonado, Negrete McLeod, Pavley, Wolk
NO VOTE RECORDED: Cedillo, Cox
SENATE APPROPRIATIONS COMMITTEE : Senate Rule 28.8
SUBJECT : Patient medical information: disclosure:
reporting
SOURCE : Author
DIGEST : This bill revises the time limits by which
clinics, health facilities, home health agencies, and
hospices must report instances of unauthorized access to,
or use or disclosure of, patients medical information,
requires these entities to delay reports if a law
enforcement agency or official provides the entity with a
statement that compliance with the reporting requirement
would be likely to impede the law enforcement agency's
activities, and specifies a date upon which the delay shall
end, with specific requirements for oral, versus written,
requests for delays in reporting.
ANALYSIS :
CONTINUED
SB 337
Page
2
Existing federal law:
1. Prohibits, under federal regulations implementing the
federal Health Insurance Portability and Accountability
Act (HIPAA), a health plan, health care clearinghouse or
a health care provider, who transmits health information
in electronic form (covered entity), from using or
disclosing protected health information, for purposes
other than medical treatment or payment, or health care
operations, as defined, without written authorization of
the patient, with exceptions.
2. Requires covered entities, and their business
associates, to provide notice of medical privacy
breaches involving the unauthorized acquisition, access,
use, or disclosure of protected health information to
each individual whose information has been subject to a
breach within 60 days of the discovery of the breach.
3. Provides that if a law enforcement official determines
that notice of a medical privacy breach would impede a
criminal investigation or cause damage to national
security, the notice shall be delayed, in a specified
manner.
Existing state law:
1. Prohibits, under the Confidentiality of Medical
Information Act (CMIA), licensed or certified health
care professionals, clinics and health facilities,
health plans, and contracting entities, as defined, from
disclosing or using a patient's medical information for
any purpose not necessary to provide health care
services to the patient and related administrative
functions, without first obtaining authorization from
the patient or the patient's representative, as
specified, with exceptions.
2. Provides for administrative fines and civil penalties
for persons and entities subject to the CMIA who
negligently disclose, or who knowingly and willfully
obtain, disclose, or use, medical information in
violation of the CMIA, and authorizes the Attorney
CONTINUED
SB 337
Page
3
General, any district attorney, any county counsel
acting pursuant to an agreement with the district
attorney, or a city attorney, to seek civil penalties
for violations.
3. Requires every provider of health care to establish and
implement administrative, technical, and physical
safeguards to protect the privacy of patients' medical
information, and requires every provider to reasonably
safeguard confidential medical information from any
unauthorized access or unlawful access, use, or
disclosure.
4. Defines unauthorized access as the inappropriate review
or viewing of patient medical information without a
direct need for diagnosis, treatment, or other lawful
use of the information.
5. Requires a clinic, health facility, home health agency,
or hospice to report any unlawful or unauthorized access
to, or use or disclosure of, a patient's medical
information to the Department of Public Health (DPH) and
to the affected patient or patient's representative, no
later than five days after the unlawful or unauthorized
access, use, or disclosure has been detected by the
entity.
6. Allows DPH to assess a penalty of $100 for each day the
unlawful or unauthorized access, use, or disclosure is
not reported, following the initial five-day period, not
to exceed $250,000 per reported event.
7. Requires other persons or businesses that own or license
computerized data that includes personal information,
including medical information, to disclose any breach of
the security of the system to a resident whose
unencrypted personal information was acquired by an
unauthorized person.
8. Provides that the notification may be delayed if a law
enforcement agency determines that notification will
impede a criminal investigation, as specified.
This bill:
CONTINUED
SB 337
Page
4
1. Requires a clinic, health facility, home health agency,
or hospice to report any unauthorized access to, or use
or disclosure of, a patient's medical information to DPH
and to the affected patient or patient's representative,
no later than five business days after the unlawful or
unauthorized access, use, or disclosure has been
detected by the entity.
2. Requires the clinic, health facility, home health
agency, or hospice to delay reporting any unlawful or
unauthorized access, use, or disclosure of a patient's
medical information to DPH if a law enforcement agency
or official provides the entity with a written or oral
statement that compliance with the reporting requirement
would be likely to impede the law enforcement agency's
activities, and specifies a date upon the delay shall
end.
3. Requires, in the case that the statement of the law
enforcement agency or official is made orally, the
clinic, health facility, home health agency, or hospice
to document the statement and to limit the delay in
reporting to the date specified in the oral statement,
not to exceed 30 calendar days from the date the oral
statement is made, unless a written statement is
received during that time period.
4. Allows a law enforcement agency or official to request
an extension of the 60-day delay based upon a written
declaration that there exists a bona fide, ongoing,
significant criminal investigation of serious
wrongdoing, that notification of patients will undermine
the law enforcement agency's activities, and that
specifies a date upon which the delay shall end, not to
exceed 60 days after the end of the original 60-day
period.
5. Requires a clinic, health facility, home health agency,
or hospice that is subject to a delay in reporting for
law enforcement purposes to report the unauthorized
access to, or use or disclosure of, the patient's
medical information no later than five business days
after the date designated as the end of the delay.
CONTINUED
SB 337
Page
5
Background
Under the medical privacy provisions of the recently
enacted federal economic stimulus bill, the American
Recovery and Reinvestment Act, entities that transmit
health information in an electronic form are required to
provide notice of a medical privacy breach to an individual
whose information has been subject to a breach, within 60
days of the discovery of the breach. The 60-day
requirement is delayed in the case that a law enforcement
official determines that notice of a medical privacy breach
would impede a criminal investigation or cause damage to
national security. However, the American Recovery and
Reinvestment Act provides that state medical privacy breach
notification laws that are more protective of medical
privacy are not preempted.
FISCAL EFFECT : Appropriation: No Fiscal Com.: Yes
Local: No
SUPPORT : (Verified 5/19/09)
California Hospital Association
CTW:mw 5/19/09 Senate Floor Analyses
SUPPORT/OPPOSITION: SEE ABOVE
**** END ****
CONTINUED