BILL ANALYSIS
SB 337
Page 1
Date of Hearing: August 19, 2009
ASSEMBLY COMMITTEE ON APPROPRIATIONS
Kevin De Leon, Chair
SB 337 (Alquist) - As Amended: August 17, 2009
Policy Committee: Health Vote:19-0
Urgency: No State Mandated Local Program:
No Reimbursable:
SUMMARY
This bill modifies medical privacy provisions established by SB
541 (Alquist), Chapter 605, Statutes of 2008. Specifically, this
bill requires a clinic, health facility, home health agency, or
hospice to:
1)Report unauthorized access to private patient medical
information to the California Department of Public Health
(DPH) and patients no later than five business days after
detection. Under current law the timeline is five calendar
days.
2)Delay the reporting to patients impacted by a medical
information security breach if a law enforcement agency
provides an oral or written statement that compliance with the
reporting of a medical privacy breach within five business
days would impede a law enforcement investigation.
FISCAL EFFECT
Absorbable workload to DPH to continue oversight of medical
privacy in California health facilities.
COMMENTS
1)Rationale . This bill clarifies provisions established by the
author in SB 541 in 2008. SB 541 established penalties for
breaches of medical privacy of up to $25,000 per patient and
$17,500 per subsequent occurrence of unauthorized access to
medical information. This bill clarifies the required
reporting time to DPH from five calendar days to five business
days and requires hospitals to comply with law enforcement
SB 337
Page 2
investigations by delaying patient notification of breaches
according to requirements established by this bill.
2)Background . Seemingly lax privacy policies have resulted in
several very high profile medical privacy breaches in recent
years. For example, several celebrities treated at a Los
Angeles hospital, including Britney Spears, Farrah Fawcett,
and Maria Shriver had their medical records viewed or
disclosed by numerous unauthorized employees. Several hundred
employees have been disciplined related to these events. One
employee faced federal criminal charges for viewing dozens of
high-profile patient records, as well as the addresses, phone
numbers, and social security numbers of more than 1,000
patients. Additional breaches have occurred more recently
following the birth of octuplets in southern California. The
medical center in the octuplets case has been fine almost
$500,000.
3)State and Federal Privacy Laws . California medical privacy law
has historically been stricter than federal law. State law
requires providers to give patients access to personal medical
information, an opportunity to review and correct this
information, and an assurance that medical information be
disclosed only as permitted by law. However, with the passage
of the American Recovery and Reinvestment Act (ARRA) this
year, federal law has been significantly strengthened in
several areas. For example, ARRA expands and clarifies
provisions of current federal law established by the Health
Insurance Portability and Accountability Act (HIPAA) in 1996.
ARRA addresses what businesses and entities are covered by
HIPAA patient protections, increases patient protections with
respect to disclosure of health information, provides greater
patient access to their medical records, and attempts to limit
the marketing and sale of medical information. In addition,
ARRA enacted breach requirements that are more stringent than
current California law.
Analysis Prepared by : Mary Ader / APPR. / (916) 319-2081