BILL ANALYSIS                                                                                                                                                                                                    



                                                                  SB 337
                                                                  Page  1

          Date of Hearing:   August 19, 2009 

                        ASSEMBLY COMMITTEE ON APPROPRIATIONS
                                Kevin De Leon, Chair

                  SB 337 (Alquist) - As Amended:  August 17, 2009  

          Policy Committee:                              Health Vote:19-0

          Urgency:     No                   State Mandated Local Program:  
          No     Reimbursable:              

           SUMMARY  

          This bill modifies medical privacy provisions established by SB  
          541 (Alquist), Chapter 605, Statutes of 2008. Specifically, this  
          bill requires a clinic, health facility, home health agency, or  
          hospice to: 

          1)Report unauthorized access to private patient medical  
            information to the California Department of Public Health  
            (DPH) and patients no later than five business days after  
            detection. Under current law the timeline is five calendar  
            days. 

          2)Delay the reporting to patients impacted by a medical  
            information security breach if a law enforcement agency  
            provides an oral or written statement that compliance with the  
            reporting of a medical privacy breach within five business  
            days would impede a law enforcement investigation. 

           FISCAL EFFECT  

          Absorbable workload to DPH to continue oversight of medical  
          privacy in California health facilities. 

           COMMENTS  

           1)Rationale  . This bill clarifies provisions established by the  
            author in SB 541 in 2008. SB 541 established penalties for  
            breaches of medical privacy of up to $25,000 per patient and  
            $17,500 per subsequent occurrence of unauthorized access to  
            medical information. This bill clarifies the required  
            reporting time to DPH from five calendar days to five business  
            days and requires hospitals to comply with law enforcement  








                                                                  SB 337
                                                                  Page  2

            investigations by delaying patient notification of breaches  
            according to requirements established by this bill. 

           2)Background  . Seemingly lax privacy policies have resulted in  
            several very high profile medical privacy breaches in recent  
            years. For example, several celebrities treated at a Los  
            Angeles hospital, including Britney Spears, Farrah Fawcett,  
            and Maria Shriver had their medical records viewed or  
            disclosed by numerous unauthorized employees. Several hundred  
            employees have been disciplined related to these events. One  
            employee faced federal criminal charges for viewing dozens of  
            high-profile patient records, as well as the addresses, phone  
            numbers, and social security numbers of more than 1,000  
            patients. Additional breaches have occurred more recently  
            following the birth of octuplets in southern California. The  
            medical center in the octuplets case has been fine almost  
            $500,000.  

           3)State and Federal Privacy Laws  . California medical privacy law  
            has historically been stricter than federal law. State law  
            requires providers to give patients access to personal medical  
            information, an opportunity to review and correct this  
            information, and an assurance that medical information be  
            disclosed only as permitted by law. However, with the passage  
            of the American Recovery and Reinvestment Act (ARRA) this  
            year, federal law has been significantly strengthened in  
            several areas.  For example, ARRA expands and clarifies  
            provisions of current federal law established by the Health  
            Insurance Portability and Accountability Act (HIPAA) in 1996.  
            ARRA addresses what businesses and entities are covered by  
            HIPAA patient protections, increases patient protections with  
            respect to disclosure of health information, provides greater  
            patient access to their medical records, and attempts to limit  
            the marketing and sale of medical information. In addition,  
            ARRA enacted breach requirements that are more stringent than  
            current California law. 
           



           Analysis Prepared by  :    Mary Ader / APPR. / (916) 319-2081