BILL ANALYSIS
SB 337
Page 1
Date of Hearing: September 9, 2009
ASSEMBLY COMMITTEE ON HEALTH
Dave Jones, Chair
SB 337 (Alquist) - As Amended: September 4, 2009
SENATE VOTE : Not relevant
SUBJECT : Health information.
SUMMARY : Makes program and clarifying changes to provisions
governing privacy of medical information, and state governance
related to health information exchange (HIE) and health
information technology (HIT), including: 1) Revises the
timelines for reporting of unauthorized access to, or use or
disclosure of, patients' medical information, and provides
limited exemptions to the reporting timelines in cases where law
enforcement agencies are investigating such privacy breaches;
and, 2) Authorizes the Governor to designate a non-profit entity
to apply, or the California Health and Human Services Agency
(CHHSA) to apply, for federal funds available for HIE/HIT, and
establishes a related state fund for that purpose.
Specifically, this bill :
1)Requires a clinic, health facility, home health agency, or
hospice to report any unauthorized access to, or use or
disclosure of, a patient's medical information to the
Department of Public Health (DPH), and to the affected patient
or patient's representative, no later than five business days,
instead of five days, after the unlawful or unauthorized
access, use, or disclosure has been detected by the entity.
2)Requires the clinic, health facility, home health agency, or
hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical information
to DPH and the patient if a law enforcement agency or official
provides a written statement that notification of patients
would be likely to impede the law enforcement agency's
activities, and specifies a date on which the delay will end,
not to exceed 60 days.
3)Requires the clinic, health facility, home health agency, or
hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical information
to DPH and the patient if a law enforcement agency or official
SB 337
Page 2
provides the entity with an oral statement and requires the
clinic, health facility, home health agency, or hospice to
document the statement, including but not limited to the
identity of the enforcement agency or official, the date it
was made, and limits the delay to a date specified for the end
of the delay, not to exceed 30 calendar days from the date the
oral statement is made unless a written statement is received
during that time.
4)Requires that the written statement received during the 30
calendar days after an oral statement is made by the law
enforcement agency or official include a date the delay is to
end, not to exceed 60 days.
5)Allows a law enforcement agency or official to request an
extension of the original 60-day delay based upon a written
declaration that there exists a bona fide, ongoing,
significant criminal investigation of serious wrongdoing, that
notification of patients will undermine the law enforcement
agency's activities, and that specifies a date upon which the
delay shall end, not to exceed 60 days after the end of the
original 60-day period.
6)Requires a clinic, health facility, home health agency, or
hospice that is subject to a delay in reporting for law
enforcement purposes to report the unauthorized access to, or
use or disclosure of, the patient's medical information no
later than five business days, instead of five days, after the
date designated as the end of the delay.
7)Authorizes CHHSA, or a department within CHHSA, to apply for
federal funds available through the American Recovery and
Reinvestment Act (Public Law 111-5 (ARRA)) for HIE /HIT.
8)Authorizes the Governor to, as an alternative to a direct
application by a state agency under 7) above, to designate a
qualified nonprofit entity as the state designated entity
(SDE) for the purposes of HIE, pursuant to requirements set
forth in ARRA.
9)Requires CHHSA or the SDE to facilitate and expand the use and
disclosure of electronic health information according to
nationally recognized standards and specifications, and
execute tasks related to accessing ARRA funds while protecting
the privacy and confidentiality of medical records to the
SB 337
Page 3
greatest extent possible.
10)Requires CHHSA or the SDE to develop a plan to ensure that
HIE capabilities are developed, adopted, and utilized
statewide to minimize disparities in access to HIT, as
specified.
11)Requires CHHSA or the SDE to plan for a self-sustaining
funding mechanism that uses no General Fund moneys and
sustains administration of HIE when ARRA funds are no longer
available.
12)Requires the SDE, as a condition of the designation, to be
subject to oversight by CHHSA,
and to continually meet any conditions for the designation, as
determined by the Secretary of CHHSA.
13)Requires the SDE to be governed by a board which has diverse
composition; represents multiple types of organizations and
regions; and, includes the Secretary of CHHSA or his or her
designee, Chairs of the Assembly and Senate Health Committees
or their designees; at least two consumer representatives, one
with expertise in privacy and security of health information;
and, a majority of non-governmental employees.
14)Requires any workgroups or subcommittees of the board to
represent multiple types of organizations and regions and to
meet publicly and transparently.
15)Requires the board to have nondiscrimination and conflict of
interest policies, as specified.
16)Requires the SDE to report to CHHSA and the Legislature at
least annually.
17)Creates the California Health Information Technology and
Exchange Fund (Fund) in the State Treasury, contingent on
CHHSA directly applying for and receiving federal ARRA HIE/HIT
funds, makes moneys in the Fund available upon appropriation
by the Legislature, for HIE/HIT purposes, including any
interest and dividends earned on deposits, and specifies that
the Fund will consist of, but not be limited to, federal
funds.
18)Declares the intent of the Legislature that activities
associated with HIE be funded solely through federal funds,
SB 337
Page 4
private contributions, and funds generated by the
self-sustaining funding mechanism in 11) above.
EXISTING FEDERAL LAW :
1)Prohibits, under federal regulations implementing the federal
Health Insurance Portability and Accountability Act, a health
plan, health care clearinghouse, or a health care provider,
who transmits health information in electronic form (covered
entity), from using or disclosing protected health
information, for purposes other than medical treatment or
payment, or health care operations, as defined, without
written authorization of the patient, with exceptions.
2)Requires, under ARRA, covered entities and their business
associates to provide notice of medical privacy breaches
involving the unauthorized acquisition, access, use, or
disclosure of protected health information to each individual
whose information has been subject to a breach within 60 days
of the discovery of the breach.
3)Provides that if a law enforcement official determines that
notice of a medical privacy breach would impede a criminal
investigation or cause damage to national security, the notice
shall be delayed, in a specified manner.
4)Establishes, under ARRA, the Health Information Technology for
Economic and Clinical Health (HITECH) Act, to provide grants
to states to promote the electronic movement and use of health
information among organizations using nationally recognized
interoperability standards and incentive payments to providers
for HIE/HIT adoption.
EXISTING STATE LAW :
1)Prohibits, under the Confidentiality of Medical Information
Act (CMIA), licensed or certified health care professionals,
clinics and health facilities, health plans, and contracting
entities, as defined, from disclosing or using a patient's
medical information for any purpose not necessary to provide
health care services to the patient and related administrative
functions, without first obtaining authorization from the
patient or the patient's representative, as specified, with
exceptions.
SB 337
Page 5
2)Provides for administrative fines and civil penalties for
persons and entities subject to the CMIA who negligently
disclose, or who knowingly and willfully obtain, disclose, or
use, medical information in violation of the CMIA, and
authorizes the Attorney General, any district attorney, any
county counsel acting pursuant to an agreement with the
district attorney, or a city attorney, to seek civil penalties
for violations.
3)Requires every provider of health care to establish and
implement administrative, technical, and physical safeguards
to protect the privacy of patients' medical information, and
requires every provider to reasonably safeguard confidential
medical information from any unauthorized access or unlawful
access, use, or disclosure.
4)Requires a clinic, health facility, home health agency, or
hospice to report any unlawful or unauthorized access to, or
use or disclosure of, a patient's medical information to DPH
and to the affected patient or patient's representative, no
later than five days after the unlawful or unauthorized
access, use, or disclosure has been detected by the entity.
Allows DPH to assess a penalty of $100 for each day the
unlawful or unauthorized access, use, or disclosure is not
reported, following the initial five-day period, not to exceed
$250,000 per reported event.
5)Requires other persons or businesses that own or license
computerized data that includes personal information,
including medical information, to disclose any breach of the
security of the system to a resident whose unencrypted
personal information was acquired by an unauthorized person.
Provides that the notification may be delayed if a law
enforcement agency determines that notification will impede a
criminal investigation, as specified.
FISCAL EFFECT : This bill, as amended, has not been analyzed by
a fiscal committee.
COMMENTS :
1)PURPOSE OF THIS BILL . The author states that this bill is
intended to make two revisions to existing medical privacy
requirements in SB 541 (Alquist), Chapter 605, Statutes of
2008 that health facilities notify patients and DPH when they
SB 337
Page 6
detect any unlawful or unauthorized access to, or use or
disclosure of, a patient's medical information. The first is
to revise the timeline for reporting such breaches from five
days to five business days. The second is to allow for a
delay in the reporting of such breaches when a law enforcement
agency or official makes a statement that it would impede a
law enforcement investigation of the breach. The author
states that these are reasonable revisions of the reporting
requirements for medical privacy breaches that are consistent
with the intent of the original legislation.
The author also states that ARRA, which includes $36 billion
in federal funding to encourage the adoption and use of
HIE/HIT, provides an unprecedented opportunity to develop and
implement the HIE/HIT infrastructure needed to modernize and
improve California's health care system. The author argues
that this bill is needed because it is critical that
California implement HIE as soon as possible, as HIE is the
mechanism for sharing health records across providers, and
lack of HIE jeopardizes the ability of the state and providers
to meet ARRA requirements and draw down an expected $3 billion
in Medicare and Medicaid incentive payments beginning in
October 2010. The author contends that in order for
California to establish HIE before federal deadlines and draw
down ARRA incentive payments, legislation is needed
immediately. Moreover, the author states that this bill is
needed because although ARRA funding guidelines allow a state
governor to appoint an SDE through an executive order,
guidance provided by Legislative Counsel indicates that the
executive order must reference existing state law. According
to the author, there is no existing state law addressing HIE.
2)BACKGROUND . The Congress passed ARRA on February 13, 2009 and
President Obama signed the bill on February 17, 2009. Under
the medical privacy provisions of ARRA, entities that transmit
health information in an electronic form are required to
provide notice of a medical privacy breach to an individual
whose information has been subject to a breach, within 60 days
of the discovery of the breach. The 60-day requirement is
delayed in the case that a law enforcement official determines
that notice of a medical privacy breach would impede a
criminal investigation or cause damage to national security.
However, ARRA provides that state medical privacy breach
notification laws that are more protective of medical privacy
(such as the notification requirements in California law) are
SB 337
Page 7
not preempted.
A component of ARRA, the HITECH Act, provides grants to states
to promote the electronic movement and use of health
information among organizations using nationally recognized
interoperability standards. The state grant program is
intended to enable providers to qualify for Medicare and
Medicaid financial incentives authorized by ARRA, by providing
HIE/HIT that meets meaningful use requirements, and to
establish a technical infrastructure to support health care
reform. The electronic health record (EHR) adoption loan
program will allow states to make loans to health care
providers to prepare for the adoption of EHRs, and is targeted
specifically towards developing widespread and sustainable HIE
capacity in support of the meaningful use definition that
qualifies providers for the Medicare and Medicaid incentive
payments scheduled for the end of 2010. The HITECH Act also
supports state public health programs to ensure that public
health stakeholders prepare for HIE and mobilizes clinical
data needed for consumer engagement and health reform across
all states.
The federal grant application for ARRA HIE funding is due by
October 16, 2009 and California is expected to receive $33-38
million for HIE. No state match is required for the first
wave of funding, but state matching funds will be required
beginning in 2011. Only the state or an SDE may submit an
application, and the federal government has indicated a desire
to distribute ARRA funds as expeditiously as possible.
3)SUPPORT . The California Hospital Association (CHA) and
Catholic Healthcare West (CHW) support this bill, including
the most recent amendments which establish a state governance
structure for the use of ARRA HIE/HIT funds. CHA states the
governance is critical in ensuring hospitals' ability to
continue to provide safe, efficient care to all Californians
through electronic data availability. CHW writes that the
amendments provide for effective governance for the use of
HIE/HIT, laying the groundwork for California hospitals'
ability to meet new federal standards for HIE/HIT.
4)RECENT AMENDMENTS . This bill was amended on the Assembly
Floor to add the provisions establishing the state governance
structure for HIE/HIT which had not previously been heard in
an Assembly policy committee. The medical privacy provisions
SB 337
Page 8
were heard in Assembly Health Committee on June 30, 2009 and
passed 19-0. This bill passed the Assembly 74-0 on August 27,
2009 but that action was rescinded and this bill was returned
to the Assembly for purposes of adding the HIE/HIT amendments.
5)POLICY QUESTION . In the event that the Governor decides to
designate an SDE, this bill requires the SDE to be governed by
a board, and establishes several requirements relating to
board membership. Should this bill also establish other
requirements for board membership, such as how many members
serve on the board, and whether any members should be health
care providers, who would be core users of HIE/HIT?
6)TECHNICAL AMENDMENTS .
a) On page 8, line 16, delete "on" and insert "or".
b) On page 8, line 20, delete the second "on" and insert
"or".
c) On Page 8, line 24, delete "be comprised of" and insert
"comprise".
REGISTERED SUPPORT / OPPOSITION :
Support
Catholic Healthcare West
California Hospital Association
Opposition
None on file.
Analysis Prepared by : Allegra Kim and Marjorie Swartz / HEALTH
/ (916) 319-2097