BILL ANALYSIS
SENATE HEALTH
COMMITTEE ANALYSIS
Senator Elaine K. Alquist, Chair
BILL NO: SB 337
S
AUTHOR: Alquist
B
AMENDED: September 4, 2009
HEARING DATE: September 10, 2009
3
CONSULTANT:
3
Chan-Sawin/sh
7
PURSUANT TO SENATE RULE 29.10
SUBJECT
Health information
SUMMARY
Revises the timelines for reporting of unauthorized access
to, or use or disclosure of, patients' medical information,
and provides limited exemptions to the reporting timelines
in cases where law enforcement agencies are investigating
such privacy breaches. Authorizes the California Health
and Human Services Agency (CHHSA) to apply for federal
health information technology (HIT) and health information
exchange (HIE) grant funds. If no application is made by
the state, requires the governor to designate a qualified
nonprofit entity to apply for federal HIE grant funds on
behalf of the state. If the state submits the application,
creates in the State Treasury the California Health
Information Technology and Exchange Fund. Establishes
legislative intent that activities related to HIE be funded
by federal funds, private contributions, and funds
generated by a self-sustaining funding mechanism to be
created by the entity establishing the HIE.
Continued---
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 2
CHANGES TO EXISTING LAW
Existing federal law:
Prohibits, under federal regulations implementing the
federal Health Insurance Portability and Accountability Act
(HIPAA), a health plan, health care clearinghouse or a
health care provider, who transmits health information in
electronic form (covered entity), from using or disclosing
protected health information, for purposes other than
medical treatment or payment, or health care operations, as
defined, without written authorization of the patient, with
exceptions.
Requires covered entities, and their business associates,
to provide notice of medical privacy breaches involving the
unauthorized acquisition, access, use, or disclosure of
protected health information to each individual whose
information has been subject to a breach within 60 days of
the discovery of the breach.
Provides that if a law enforcement official determines that
notice of a medical privacy breach would impede a criminal
investigation or cause damage to national security, the
notice shall be delayed, in a specified manner.
Allows, under the federal American Recovery and
Reinvestment Act of 2009 (ARRA), certain medical providers
to receive incentive payments for meaningful use of HIT, as
specified, and provides other funding related to HIT
promotion and HIE.
Existing state law:
Prohibits, under the Confidentiality of Medical Information
Act (CMIA), licensed or certified health care
professionals, clinics and health facilities, health plans,
and contracting entities, as defined, from disclosing or
using a patient's medical information for any purpose not
necessary to provide health care services to the patient
and related administrative functions, without first
obtaining authorization from the patient or the patient's
representative, as specified, with exceptions.
Provides for administrative fines and civil penalties for
persons and entities subject to the CMIA who negligently
disclose, or who knowingly and willfully obtain, disclose,
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 3
or use, medical information in violation of the CMIA, and
authorizes the Attorney General, any district attorney, any
county counsel acting pursuant to an agreement with the
district attorney, or a city attorney, to seek civil
penalties for violations.
Requires every provider of health care to establish and
implement administrative, technical, and physical
safeguards to protect the privacy of patients' medical
information, and requires every provider to reasonably
safeguard confidential medical information from any
unauthorized access or unlawful access, use, or disclosure.
Defines unauthorized access as the inappropriate review or
viewing of patient medical information without a direct
need for diagnosis, treatment, or other lawful use of the
information.
Requires a clinic, health facility, home health agency, or
hospice to report any unlawful or unauthorized access to,
or use or disclosure of, a patient's medical information to
the Department of Public Health (DPH) and to the affected
patient or patient's representative, no later than five
days after the unlawful or unauthorized access, use, or
disclosure has been detected by the entity.
Allows DPH to assess a penalty of $100 for each day the
unlawful or unauthorized access, use, or disclosure is not
reported, following the initial five-day period, not to
exceed $250,000 per reported event.
Requires other persons or businesses that own or license
computerized data that includes personal information,
including medical information, to disclose any breach of
the security of the system to a resident whose unencrypted
personal information was acquired by an unauthorized
person.
Provides that the notification may be delayed if a law
enforcement agency determines that notification will impede
a criminal investigation, as specified.
This bill:
Medical Privacy Provisions
Requires a clinic, health facility, home health agency, or
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 4
hospice to report any unauthorized access to, or use or
disclosure of, a patient's medical information to DPH and
to the affected patient or patient's representative, no
later than five business days after the breach has been
detected by the entity.
Requires the clinic, health facility, home health agency,
or hospice to delay reporting any unlawful or unauthorized
access, use, or disclosure of a patient's medical
information to DPH if a law enforcement agency or official
provides the entity with a written or oral statement that
compliance with the reporting requirement would be likely
to impede the law enforcement agency's activities that
relate to the unlawful or unauthorized access to, and use
or disclosure of, a patient's medical information, and
specifies a date upon which the delay shall end, not to
exceed 60 days after a written request was made, or 30 days
after an oral request is made.
Requires, in the case that the statement of the law
enforcement agency or official is made orally, the clinic,
health facility, home health agency, or hospice to document
the statement and to limit the delay in reporting to the
date specified in the oral statement, not to exceed 30
calendar days from the date the oral statement is made,
unless a written statement is received during that time
period.
Allows a law enforcement agency or official to request an
extension of the 60-day delay based upon a written
declaration that there exists a bona fide, ongoing,
significant criminal investigation of serious wrongdoing,
that notification of patients will undermine the law
enforcement agency's activities, and that specifies a date
upon which the delay shall end, not to exceed 60 days after
the end of the original 60-day period.
Requires a clinic, health facility, home health agency, or
hospice that is subject to a delay in reporting for law
enforcement purposes to report the unauthorized access to,
or use or disclosure of, the patient's medical information
no later than five business days after the date designated
as the end of the delay.
Health information technology and exchange amendments
States findings and declarations concerning the importance
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 5
of establishing HIE for the purpose of sharing health
information records and meeting requirements around
meaningful use of health information technology set forth
in ARRA.
Authorizes CHHSA, or one of its departments, to apply for
federal HIT and HIE grants, pursuant to requirements set
forth in ARRA.
Requires the Governor to designate a nonprofit entity, as
specified, to apply for federal funds and establish HIE if
no application is made by the state.
Requires CHHSA or the state-designated entity (SDE) to
facilitate and expand the use of electronic health
information according to nationally recognized standards
and specifications, and execute tasks related to accessing
ARRA funds while protecting the privacy and confidentiality
of medical records to the greatest extent possible.
Requires CHHSA or the SDE to develop a plan to ensure that
HIE capabilities are developed, adopted, and utilized
statewide while minimizing disparities in access to HIT, as
specified.
Requires the SDE, as a condition of the designation, to be
subject to oversight by CHHSA and to continually meet any
conditions for the designation, as determined by the
Secretary of CHHSA.
Specifies that the governing board of the SDE must contain,
at a minimum, the secretary of CHHSA, chairs of the Senate
and Assembly Committees on Health, and two consumer
representatives, as specified.
Requires any workgroups or subcommittees of the governing
board to represent multiple types of organizations and
regions and to meet publicly and transparently.
Requires the board to have nondiscrimination and conflict
of interest policies, as specified.
Requires the SDE to report to CHHSA and the Legislature at
least annually.
Requires CHHSA or the SDE to create a plan for a
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 6
self-sustaining funding mechanism that uses no General Fund
(GF) moneys and sustains the administration of HIE when
ARRA funds are no longer available.
Creates the California Health Information Technology and
Exchange Fund in the State Treasury, in the event the state
does apply for and receive federal funds, to hold federal
funds, private contributions, or funds generated by a
self-sustaining funding mechanism to be established by
CHHSA or SDE.
Specifies that moneys in the fund be made available, upon
appropriation by the Legislature, for purposes related to
HIT and HIE.
Declares legislative intent that activities related to HIE
be funded by federal funds, private contributions, and
funds generated by a self-sustaining funding mechanism to
be created by the entity establishing the health
information exchange.
FISCAL IMPACT
According to the Assembly Appropriations analysis on August
18, 2009 regarding the medical privacy portion of the bill:
Absorbable workload to DPH to continue oversight of
medical privacy in California health facilities.
Does not contain a mandate on law enforcement.
According to the Assembly Appropriations analysis on
September 9, 2009 regarding the HIT and HIE portion of the
bill:
California is expected to qualify for $3 billion in
federal ARRA provider incentive payments from 2011 to
2016. No state match is required in calendar year
2010. State contributions to draw down federal funding
in future years include: at least $1 for each $10 of
federal funds in 2011, $1 for each $7 of federal funds
in 2012, and $1 for each $3 in federal funding for
2013-2016. According to stakeholders, non-GF state
contribution possibilities include support from health
technology industry groups, provider associations, or
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 7
non-profit groups. In addition, the state contribution
may also be generated via the self-funding mechanism
to be established pursuant to intent language
contained in this bill.
Future GF savings in Medi-Cal likely if HIT efforts
are successful. Within the past several years, both
the RAND Corporation and the Legislative Analyst's
Office (LAO) have provided estimates of savings of
technology solutions in health care. RAND estimates
national net annual savings following adoption of $34
billion. LAO estimates, based on research in other
states, fee-for-service Medi-Cal savings in California
of up to $300 million GF annually by increasing
coordination and reducing duplication across a variety
of patient service areas.
BACKGROUND AND DISCUSSION
According to the author, the medical privacy provisions of
SB 337 are intended to make technical and clarifying
changes to last session's SB 541 (Alquist), Chapter 605,
Statutes of 2008. Specifically, it modifies existing
requirements that health facilities notify patients and DPH
when they detect any unlawful or unauthorized access to, or
use or disclosure of, a patient's medical information by:
1) revising the timeline for reporting such breaches from
five days to five business days; and, 2) allowing for a
delay in the reporting of such breaches when a law
enforcement agency or official makes a statement that it
would impede a law enforcement investigation. These
provisions align state law with federal requirements and
are consistent with the intent of the original legislation.
Beyond the medical privacy clean-up issues, the author
argues that this bill is needed because it is critical that
California implement HIE as soon as possible, as HIE is the
mechanism for sharing health records across providers.
ARRA provides an unprecedented opportunity to develop and
implement the HIT and HIE infrastructure needed to
modernize and improve California's health care system.
Establishing HIE capabilities within the state is critical
in order for health care providers to draw down Medicare
and Medicaid incentive payments available to California
providers beginning October 2010. It also provides for
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 8
governance and oversight of HIE activities to protect and
maintain the public's trust.
Notification of breaches of medical privacy under federal
law
Under the medical privacy provisions of the recently
enacted ARRA, entities that transmit health information in
an electronic form are required to provide notice of a
medical privacy breach to an individual whose information
has been subject to a breach, within 60 days of the
discovery of the breach. The 60-day requirement is delayed
in the case that a law enforcement official determines that
notice of a medical privacy breach would impede a criminal
investigation or cause damage to national security.
However, the ARRA provides that state medical privacy
breach notification laws that are more protective of
medical privacy (such as the notification requirements in
SB 541) are not preempted.
American Recovery and Reinvestment Act of 2009
On February 17, 2009, President Barack Obama signed the
federal economic stimulus bill, ARRA, which includes more
than $36 billion for HIT and HIE over the next several
years. The majority of these funds ($34 billion) are
incentive payments that will go to Medicaid and Medicare
providers who are able to demonstrate "meaningful use" of
health information technology. California is expected to
receive more than $3 billion in provider incentive
payments. In addition, ARRA provides $2 billion in
discretionary funding for HIT promotion, including $564
million in planning and implementation grants of which
California is expected to receive $33-38 million to
establish an HIE.
In August 2009, the federal Office of the National
Coordinator for Health Information Technology announced the
availability of grant funding for planning and
implementation of HIE. Grant applications are due October
16, 2009. Additional federal guidance indicates that
states who choose not to establish HIE within a state
agency or department should designate a nonprofit to
establish the exchange through an Executive Order issued by
the governor. The federal government has indicated a
desire to distribute ARRA funds as expeditiously as
possible.
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 9
CHHSA has convened an HIE advisory board to advise the
state on issues relating to HIE. CHHSA indicates that a
determination of whether the state or SDE will submit an
application on behalf of California will be made before the
October grant deadline.
According to the State Level Health Information Exchange
Project, sixteen states have chosen to designate a separate
nonprofit entity to establish the exchange through
public-private partnerships. Another seven states have
chosen to establish health information exchange within a
state agency or department.
Related bills
SB 368 (Maldonado) allows the Office of Health Information
Integrity (OHII) to audit the procedures and records of a
health care provider at any time in order to determine the
provider's compliance with requirements to establish and
implement appropriate administrative, technical, and
physical safeguards to protect the privacy of patient's
medical information, and to reasonably safeguard
confidential medical information from any unauthorized
access or unlawful access, use, or disclosure. Currently
in the Senate Health Committee; is a two-year bill.
Prior legislation
AB 211 (Jones) Chapter 602, Statutes of 2008, establishes
OHII to ensure the enforcement of state confidentiality of
medical information, to impose administrative fines for the
unauthorized use of medical information upon referral from
DPH, and require providers of health care to establish and
implement appropriate administrative, technical, and
physical safeguards to protect the privacy of patient's
medical information.
SB 541 (Alquist) Chapter 605, Statutes of 2008, increases
the maximum penalties levied against hospitals for
immediate jeopardy and other specified violations, requires
licensed clinics, health facilities, hospices, and home
health agencies to prevent unlawful access to, use, or
disclosure of patients' medical information, establishes
administrative penalties for violations, and requires the
patient and the DPH be notified of any unlawful access to,
use, or disclosure of a patient's medical information.
SB 320 (Alquist) of 2007 would have required the California
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 10
Office of HIPAA Implementation, in consultation with the
others, to develop a plan for implementation of the
California Health Care Information Infrastructure Program
no later than March 1, 2009, that would seek to provide the
opportunity for every resident of the state to have an
electronic health record. Vetoed by the Governor.
SB 1338 (Alquist) of 2006 would have required CHHSA, in
conjunction with certain other state departments, to
develop a strategic plan to foster the adoption of HIT.
This plan would have included, among other provisions, HIT
standards and identified incentives to promote the use of
electronic health records (EHRs) and personal health
records. Held in the Assembly Appropriations Committee.
SB 1672 (Maldonado) of 2006 would have required the
California Health Facilities Financing Authority to
establish a low-interest loan program to provide financing
for the purchase of health care information technology
systems to participating health care institutions,
providers, and provider organizations, as specified. Held
in the Senate Appropriations Committee.
AB 1672 (Nation, Richman) of 2005, in an early version,
would have established deadlines for various health care
entities to adopt EHRs, provided enhanced Medi-Cal
reimbursement for EHR adoption, and provided state funding
to promote HIT development. These provisions were amended
out of the bill.
Arguments in support
The California Hospital Association (CHA) states that SB
337's language regarding privacy breach reporting in five
business days allows hospitals to perform preliminary fact
and patient verifications in order to perform required
notifications. CHA further states that effective
governance of the use of federal ARRA funds is crucial in
ensuring hospitals' ability to continue to provide safe,
efficient care to all Californians through electronic data
availability.
Catholic Healthcare West (CHW) states that this bill aligns
California statute with new provisions in federal
regulations, which allow for a delay in notification in
support of criminal investigations. CHW further states
that recent amendments to SB 337 provide for effective
STAFF ANALYSIS OF SENATE BILL SB 337 (Alquist)Page 11
governance of HIT and HIE, and lay the groundwork for
California hospitals' ability to meet new federal standards
for HIT compliance.
The Children's Partnership states that funding and
successful implementation of HIE will ensure that the state
and health care providers can comply with ARRA meaningful
use requirements, which will facilitate their access to
available federal Medicaid and Medicare payments and
promote better health outcomes for all Californians.
COMMENTS
Bill reflects recent amendments.
When the bill was heard in Senate Health Committee on April
29, 2009, it dealt with medical privacy issues and the
reporting of breaches in medical privacy. These provisions
were amended in the Assembly to establish timelines around
how long delays in reporting breaches in medical privacy
can occur in the event a request is made by law
enforcement. In addition, amendments were added in the
Assembly to establish the statutory authority for the state
or a SDE to apply for and receive federal grant funds to
establish an HIE, and provide a framework for the oversight
and governance of HIE in California.
POSITIONS
Support: (version amended 09/04/2009)
California Hospital Association
Catholic Healthcare West
The Children's Partnership
Oppose: None received
-- END --