BILL ANALYSIS                                                                                                                                                                                                    



                                                                  SB 337
                                                                  Page  1

          Date of Hearing:   September 9, 2009

                            ASSEMBLY COMMITTEE ON HEALTH
                                  Dave Jones, Chair
                  SB 337 (Alquist) - As Amended:  September 4, 2009

           SENATE VOTE  :   Not relevant
           
          SUBJECT  :   Health information.

           SUMMARY  :   Makes program and clarifying changes to provisions  
          governing privacy of medical information, and state governance  
          related to health information exchange (HIE) and health  
          information technology (HIT), including: 1) Revises the  
          timelines for reporting of unauthorized access to, or use or  
          disclosure of, patients' medical information, and provides  
          limited exemptions to the reporting timelines in cases where law  
          enforcement agencies are investigating such privacy breaches;  
          and, 2) Authorizes the Governor to designate a non-profit entity  
          to apply, or the California Health and Human Services Agency  
          (CHHSA) to apply, for federal funds available for HIE/HIT, and  
          establishes a related state fund for that purpose.   
          Specifically,  this bill  :

          1)Requires a clinic, health facility, home health agency, or  
            hospice to report any unauthorized access to, or use or  
            disclosure of, a patient's medical information to the  
            Department of Public Health (DPH), and to the affected patient  
            or patient's representative, no later than five  business  days,  
            instead of five days, after the unlawful or unauthorized  
            access, use, or disclosure has been detected by the entity.

          2)Requires the clinic, health facility, home health agency, or  
            hospice to delay reporting any unlawful or unauthorized  
            access, use, or disclosure of a patient's medical information  
            to DPH and the patient if a law enforcement agency or official  
            provides a written statement that notification of patients  
            would be likely to impede the law enforcement agency's  
            activities, and specifies a date on which the delay will end,  
            not to exceed 60 days.

          3)Requires the clinic, health facility, home health agency, or  
            hospice to delay reporting any unlawful or unauthorized  
            access, use, or disclosure of a patient's medical information  
            to DPH and the patient if a law enforcement agency or official  








                                                                  SB 337
                                                                  Page  2

            provides the entity with an oral statement and requires the  
            clinic, health facility, home health agency, or hospice to  
            document  the statement, including but not limited to the  
            identity of the enforcement agency or official, the date it  
            was made, and limits the delay to a date specified for the end  
            of the delay, not to exceed 30 calendar days from the date the  
            oral statement is made unless a written statement is received  
            during that time.

          4)Requires that the written statement received during the 30  
            calendar days after an oral statement is made by the law  
            enforcement agency or official include a date the delay is to  
            end, not to exceed 60 days. 

          5)Allows a law enforcement agency or official to request an  
            extension of the original 60-day delay based upon a written  
            declaration that there exists a bona fide, ongoing,  
            significant criminal investigation of serious wrongdoing, that  
            notification of patients will undermine the law enforcement  
            agency's activities, and that specifies a date upon which the  
            delay shall end, not to exceed 60 days after the end of the  
            original 60-day period.

          6)Requires a clinic, health facility, home health agency, or  
            hospice that is subject to a delay in reporting for law  
            enforcement purposes to report the unauthorized access to, or  
            use or disclosure of, the patient's medical information no  
            later than five  business  days, instead of five days, after the  
            date designated as the end of the delay.

          7)Authorizes CHHSA, or a department within CHHSA, to apply for  
            federal funds available through the American Recovery and  
            Reinvestment Act (Public Law 111-5 (ARRA)) for HIE /HIT. 

          8)Authorizes the Governor to, as an alternative to a direct  
            application by a state agency under 7) above, to designate a  
            qualified nonprofit entity as the state designated entity  
            (SDE) for the purposes of HIE, pursuant to requirements set  
            forth in ARRA. 

          9)Requires CHHSA or the SDE to facilitate and expand the use and  
            disclosure of electronic health information according to  
            nationally recognized standards and specifications, and  
            execute tasks related to accessing ARRA funds while protecting  
            the privacy and confidentiality of medical records to the  








                                                                  SB 337
                                                                  Page  3

            greatest extent possible. 

          10)Requires CHHSA or the SDE to develop a plan to ensure that  
            HIE capabilities are developed, adopted, and utilized  
            statewide to minimize disparities in access to HIT, as  
            specified.

          11)Requires CHHSA or the SDE to plan for a self-sustaining  
            funding mechanism that uses no General Fund moneys and  
            sustains administration of HIE when ARRA funds are no longer  
            available. 

          12)Requires the SDE, as a condition of the designation, to be  
            subject to oversight by CHHSA, 
          and to continually meet any conditions for the designation, as  
            determined by the Secretary of CHHSA. 

          13)Requires the SDE to be governed by a board which has diverse  
            composition; represents multiple types of organizations and  
            regions; and, includes the Secretary of CHHSA or his or her  
            designee, Chairs of the Assembly and Senate Health Committees  
            or their designees; at least two consumer representatives, one  
            with expertise in privacy and security of health information;  
            and, a majority of non-governmental employees.

          14)Requires any workgroups or subcommittees of the board to  
            represent multiple types of organizations and regions and to  
            meet publicly and transparently.

          15)Requires the board to have nondiscrimination and conflict of  
            interest policies, as specified.

          16)Requires the SDE to report to CHHSA and the Legislature at  
            least annually.

          17)Creates the California Health Information Technology and  
            Exchange Fund (Fund) in the State Treasury, contingent on  
            CHHSA directly applying for and receiving federal ARRA HIE/HIT  
            funds, makes moneys in the Fund available upon appropriation  
            by the Legislature, for HIE/HIT purposes, including any  
            interest and dividends earned on deposits, and specifies that  
            the Fund will consist of, but not be limited to, federal  
            funds.
          18)Declares the intent of the Legislature that activities  
            associated with HIE be funded solely through federal funds,  








                                                                  SB 337
                                                                  Page  4

            private contributions, and funds generated by the  
            self-sustaining funding mechanism in 11) above.

           EXISTING FEDERAL LAW  :

          1)Prohibits, under federal regulations implementing the federal  
            Health Insurance Portability and Accountability Act, a health  
            plan, health care clearinghouse, or a health care provider,  
            who transmits health information in electronic form (covered  
            entity), from using or disclosing protected health  
            information, for purposes other than medical treatment or  
            payment, or health care operations, as defined, without  
            written authorization of the patient, with exceptions.

          2)Requires, under ARRA, covered entities and their business  
            associates to provide notice of medical privacy breaches  
            involving the unauthorized acquisition, access, use, or  
            disclosure of protected health information to each individual  
            whose information has been subject to a breach within 60 days  
            of the discovery of the breach.

          3)Provides that if a law enforcement official determines that  
            notice of a medical privacy breach would impede a criminal  
            investigation or cause damage to national security, the notice  
            shall be delayed, in a specified manner.

          4)Establishes, under ARRA, the Health Information Technology for  
            Economic and Clinical Health (HITECH) Act, to provide grants  
            to states to promote the electronic movement and use of health  
            information among organizations using nationally recognized  
            interoperability standards and incentive payments to providers  
            for HIE/HIT adoption.  

           EXISTING STATE LAW  :

          1)Prohibits, under the Confidentiality of Medical Information  
            Act (CMIA), licensed or certified health care professionals,  
            clinics and health facilities, health plans, and contracting  
            entities, as defined, from disclosing or using a patient's  
            medical information for any purpose not necessary to provide  
            health care services to the patient and related administrative  
            functions, without first obtaining authorization from the  
            patient or the patient's representative, as specified, with  
            exceptions.









                                                                  SB 337
                                                                  Page  5

          2)Provides for administrative fines and civil penalties for  
            persons and entities subject to the CMIA who negligently  
            disclose, or who knowingly and willfully obtain, disclose, or  
            use, medical information in violation of the CMIA, and  
            authorizes the Attorney General, any district attorney, any  
            county counsel acting pursuant to an agreement with the  
            district attorney, or a city attorney, to seek civil penalties  
            for violations.

          3)Requires every provider of health care to establish and  
            implement administrative, technical, and physical safeguards  
            to protect the privacy of patients' medical information, and  
            requires every provider to reasonably safeguard confidential  
            medical information from any unauthorized access or unlawful  
            access, use, or disclosure.

          4)Requires a clinic, health facility, home health agency, or  
            hospice to report any unlawful or unauthorized access to, or  
            use or disclosure of, a patient's medical information to DPH  
            and to the affected patient or patient's representative, no  
            later than five days after the unlawful or unauthorized  
            access, use, or disclosure has been detected by the entity.   
            Allows DPH to assess a penalty of $100 for each day the  
            unlawful or unauthorized access, use, or disclosure is not  
            reported, following the initial five-day period, not to exceed  
            $250,000 per reported event.

          5)Requires other persons or businesses that own or license  
            computerized data that includes personal information,  
            including medical information, to disclose any breach of the  
            security of the system to a resident whose unencrypted  
            personal information was acquired by an unauthorized person.   
            Provides that the notification may be delayed if a law  
            enforcement agency determines that notification will impede a  
            criminal investigation, as specified.

           FISCAL EFFECT  :   This bill, as amended, has not been analyzed by  
          a fiscal committee.

           COMMENTS  :   

           1)PURPOSE OF THIS BILL  .  The author states that this bill is  
            intended to make two revisions to existing medical privacy  
            requirements in SB 541 (Alquist), Chapter 605, Statutes of  
            2008 that health facilities notify patients and DPH when they  








                                                                  SB 337
                                                                  Page  6

            detect any unlawful or unauthorized access to, or use or  
            disclosure of, a patient's medical information.  The first is  
            to revise the timeline for reporting such breaches from five  
            days to five business days.  The second is to allow for a  
            delay in the reporting of such breaches when a law enforcement  
            agency or official makes a statement that it would impede a  
            law enforcement investigation of the breach.  The author  
            states that these are reasonable revisions of the reporting  
            requirements for medical privacy breaches that are consistent  
            with the intent of the original legislation.  

            The author also states that ARRA, which includes $36 billion  
            in federal funding to encourage the adoption and use of  
            HIE/HIT, provides an unprecedented opportunity to develop and  
            implement the HIE/HIT infrastructure needed to modernize and  
            improve California's health care system.  The author argues  
            that this bill is needed because it is critical that  
            California implement HIE as soon as possible, as HIE is the  
            mechanism for sharing health records across providers, and  
            lack of HIE jeopardizes the ability of the state and providers  
            to meet ARRA requirements and draw down an expected $3 billion  
            in Medicare and Medicaid incentive payments beginning in  
            October 2010.  The author contends that in order for  
            California to establish HIE before federal deadlines and draw  
            down ARRA incentive payments, legislation is needed  
            immediately.  Moreover, the author states that this bill is  
            needed because although ARRA funding guidelines allow a state  
            governor to appoint an SDE through an executive order,  
            guidance provided by Legislative Counsel indicates that the  
            executive order must reference existing state law.  According  
            to the author, there is no existing state law addressing HIE. 

           2)BACKGROUND  .  The Congress passed ARRA on February 13, 2009 and  
            President Obama signed the bill on February 17, 2009.  Under  
            the medical privacy provisions of ARRA, entities that transmit  
            health information in an electronic form are required to  
            provide notice of a medical privacy breach to an individual  
            whose information has been subject to a breach, within 60 days  
            of the discovery of the breach.  The 60-day requirement is  
            delayed in the case that a law enforcement official determines  
            that notice of a medical privacy breach would impede a  
            criminal investigation or cause damage to national security.   
            However, ARRA provides that state medical privacy breach  
            notification laws that are more protective of medical privacy  
            (such as the notification requirements in California law) are  








                                                                  SB 337
                                                                  Page  7

            not preempted.

          A component of ARRA, the HITECH Act, provides grants to states  
            to promote the electronic movement and use of health  
            information among organizations using nationally recognized  
            interoperability standards.  The state grant program is  
            intended to enable providers to qualify for Medicare and  
            Medicaid financial incentives authorized by ARRA, by providing  
            HIE/HIT that meets meaningful use requirements, and to  
            establish a technical infrastructure to support health care  
            reform.  The electronic health record (EHR) adoption loan  
            program will allow states to make loans to health care  
            providers to prepare for the adoption of EHRs, and is targeted  
            specifically towards developing widespread and sustainable HIE  
            capacity in support of the meaningful use definition that  
            qualifies providers for the Medicare and Medicaid incentive  
            payments scheduled for the end of 2010.  The HITECH Act also  
            supports state public health programs to ensure that public  
            health stakeholders prepare for HIE and mobilizes clinical  
            data needed for consumer engagement and health reform across  
            all states.  

          The federal grant application for ARRA HIE funding is due by  
            October 16, 2009 and California is expected to receive $33-38  
            million for HIE.  No state match is required for the first  
            wave of funding, but state matching funds will be required  
            beginning in 2011.  Only the state or an SDE may submit an  
            application, and the federal government has indicated a desire  
            to distribute ARRA funds as expeditiously as possible.  

           3)SUPPORT  .  The California Hospital Association (CHA) and  
            Catholic Healthcare West (CHW) support this bill, including  
            the most recent amendments which establish a state governance  
            structure for the use of ARRA HIE/HIT funds.  CHA states the  
            governance is critical in ensuring hospitals' ability to  
            continue to provide safe, efficient care to all Californians  
            through electronic data availability.  CHW writes that the  
            amendments provide for effective governance for the use of  
            HIE/HIT, laying the groundwork for California hospitals'  
            ability to meet new federal standards for HIE/HIT.

           4)RECENT AMENDMENTS  .  This bill was amended on the Assembly  
            Floor to add the provisions establishing the state governance  
            structure for HIE/HIT which had not previously been heard in  
            an Assembly policy committee.  The medical privacy provisions  








                                                                  SB 337
                                                                  Page  8

            were heard in Assembly Health Committee on June 30, 2009 and  
            passed 19-0.  This bill passed the Assembly 74-0 on August 27,  
            2009 but that action was rescinded and this bill was returned  
            to the Assembly for purposes of adding the HIE/HIT amendments.

           5)POLICY QUESTION  .  In the event that the Governor decides to  
            designate an SDE, this bill requires the SDE to be governed by  
            a board, and establishes several requirements relating to  
            board membership.  Should this bill also establish other  
            requirements for board membership, such as how many members  
            serve on the board, and whether any members should be health  
            care providers, who would be core users of HIE/HIT? 

           6)TECHNICAL AMENDMENTS  .  

             a)   On page 8, line 16, delete "on" and insert "or".

             b)   On page 8, line 20, delete the second "on" and insert  
               "or".

             c)   On Page 8, line 24, delete "be comprised of" and insert  
               "comprise".

           REGISTERED SUPPORT / OPPOSITION :

           Support 
           
          Catholic Healthcare West
          California Hospital Association
           
            Opposition 
           
          None on file.

           Analysis Prepared by  :   Allegra Kim and Marjorie Swartz / HEALTH  
          / (916) 319-2097