Petition for Writ of Certiorari — South Carolina Medical Ass'n v. Thompson
Supreme Court brief2003
Ask Donna
What actually matters in this document.
Text
OM. 0314 Jut 2 | 2003
ICE OF THE CLERK
Tu he
Supreme Court of the Gnited States
¢
SOUTH CAROLINA MEDICAL ASSOCIATION, et ai.,
Petitioners,
Vv.
TOMMY G. THOMPSON, SECRETARY OF THE
U.S. DEPARTMENT OF HEALTH AND
HUMAN SERVICES, et al.,
Respondents.
¢
On Petition For A Writ Of Certiorari
To The United States Court Of Appeals
For The Fourth Circuit
PETITION FOR A WRIT OF CERTIORARI
¢
TERRY E. RICHARDSON, JR.*
DANIEL S. HALTIWANGER
RICHARDSON, PATRICK, WESTBROOK
& BRICKMAN
P.O. Box 1368
Barnwell, South Carolina 29812
(803) 541-7850
RICHARD J. LAZARUS
GEORGETOWN UNIVERSITY LAW
CENTER
600 New Jersey Ave., N.W.
Washington, D.C. 20001
(202) 662-9129
Counsel for Petitioners
* Counsel of Record
QUESTIONS PRESENTED
Section 264(c)(1) of the Health Insurance Portability
and Accountability Act of 1996 (HIPAA), 42 US.C. §
1320d-2 note(c)(1), mandates that the Secretary of Health
and Human Services (Secretary) promulgate standards
governing “the privacy of individually identifiable health
information transmitted in connection with” specified
transactions in the event that Congress failed to enact
“legislation governing [such] standards” within three
years of HIPAA’s enactment. The questions presented are:
1. Whether Article I, § 1 of the-U.S. Constitution, which
vests legislative power exclusively in Congress, bars
Congress in HIPAA from transferring to the Secretary the
legislative authority to enact medical privacy standards if,
after three years, Congress is unable to enact those
standards itself because they are too controversial.
2. Whether the Secretary’s medical privacy standards
are unlawful because they apply to all forms of
individually identifiable health information and therefore
exceed the scope of rulemaking authority conferred by
Congress in HIPAA, which expressly limits the application
of the Secretary’s privacy standards to such identifiable
health information only when “transmitted in connection
with” nine statutorily specified electronic transactions.
(i) :
PARTIES TO THE PROCEEDING
The South Carolina Medical Association, Physicians
Care Network, J. Capers Hiott, M.D., John R. Ross, M.D.,
Gordon E. Pennebaker, M.D., Carol S. Nichols, M.D.,
Dannette F. McAlheny, M.D., Herbert Moskow, M.D., and
the Louisiana State Medical Society were all appellants in
the Fourth Circuit below. Tommy G. Thompson, in his -
official capacity as Secretary of Health and Human
Services, and the United States Department of Health and
Human Services were appellees below.
—
(ii)
5 cama amma
TABLE OF CONTENTS
Page
Questions Presented .........---- essere ee ee eerie i
Parties to the Proceedings ...........+seesseeeeeees li
Opinions Below .......--.:.seeeee eee erent 1
Jurisdiction ........ 0c cece cence see nereneneeeees 2
Constitutional, Statutory, and Regulatory
Provisions Involved .........:ee eee eee eee eeeees 2
ee te 2
NE EN PO re eee rere ee eee 4
Reasons for Granting the Writ .......-----+sseee ees 9
I. Review of the Nondelegation
Doctrine Issue Is Warranted .........-. 10
II. Review of the Legality of the Scope
of the Secretary’s Medical Privacy
Standards Is Also Warranted ......... 20
Ill. | Review Is Warranted in this Case ..... 26
ee ST eee eee 30
Appendices ..........-. sees eeeeeeeeeeeececess Al
(iii)
TABLE OF AUTHORITIES
Cases:
Chevron U.S.A. Inc. v. Natural Resources Defense Council,
ig Sr I BE CEE hae ec nce hewer id eusk vows 20
Clinton v. City of New York, 524 U.S. 417 (1998) .... 14, 26
ETSI Pipeline Project v. Missouri, 484 U.S. 495 (1988) .. 26
Ferguson v. City of Charleston, 532 U.S. 67 (2001) ..... 28
Food & Drug Administration v. Brown & Williamson,
See Ni RAPED cncceenstaswens Perrer 20-21, 26
Immigration and Naturalization Service v. Chadha,
oS | er nr rer rere 14
Industrial Union Dept. v. American Petroleum Institute,
a gt eee ee eee ere rere 14
].W. Hampton, Jr. & Co. v. United States,
SO ER hooey eb enenseeven tee nes 11
Loving v. United States, 517 U.S. 748 (1996) .......... 18
Mistretta v. United States, 488 U.S. 361 (1989) ........ 18
Panama Refining Co. v. Ryan, 293 U.S. 388 (1935) .. 11,17
Touby v. United States, 500 U.S. 160 (1991) .......... 18
Whitman v. American Trucking Ass‘n,
eR gy | 10-11, 15, 17-18
Constitution, Statutes, and Regulations:
Chae SP IE sere tbaree ee vesece sean 3,9, 10
Clean Air Act, 42 U.S.C. §§ 7407-7409 ........... 17-18
28 U.S.C.
DE Kec naeenvcaurex tee dnesseeanekaeiE cies 8
De OTE Oe. Oe ee er ene Pee 8
DRE. ks texeGhbeehakedneb cia) eae ae 8
Health Insurance Portability and Accountability
Act of 1996, Pub. L. No. 104-191, 110 Stat.
fe BOT Tee Tre rere passim
Constitution, Statutes, Regulations (continued):
- Serrererrer ree ce ee 4,17, 24
Sf | Seer reer er err Te 5, 6, 21, 22
fb Seeerrrerer ret erry rer TT 16-17, 19, 21
y errrerrer Terr rr re 6, 21, 22, 24
fs Pee errr peer T errr ere rr ce passim
Social Security Act, Title XI
iy hss te &: | errr ren y se 5, 24
© TE7R, Se UDA... BURRS 6 ccc recccncsescanccts 2
eee Roe a oy eee 5, 6, 24
§ 1173(a), 42 U.S.C. § 1320d-2(a)(1) .......... passim
§ 1174 - §1179, 42 U.S.C. § 1320d-3 tod-8 ......... 5
45 C.F.R. (2003)
DS EE hi vawkcteeecccsmeneseerenueeee 7,21
DL. ch cde ind bk caeeeen ee eee cent ieeeee 28
De i bik keds here ae s0 rere eee 28
foot Peer errr ey parr rrr sre. 28
bt: Serer eee e rir err re 28
Miscellaneous:
Ass’n of American Medical Colleges, http://www.
aamc.org/advocacy/library/hipaa/corres
Peo tgey 8 eer errr ree eT rT ree 29-30
Confidentiality of Individually Identifiable Health
Information, Hearing before the Sen. Comm. on
Labor and Human Resources, 106" Cong., 2d
GN CIPOE ne kee eeestnkesedeserenaus ee enins 13
Confidentiality of Medical Information, Hearing before
the Senate Comm. on Health, Education, Labor
and Pensions, 107" Cong., 1* Sess. (1999) ....... 13
Confidentiality of Patient Records, Hearing before the
Subcomm. on Health of the House of
Representatives Ways & Means Comm., 107
(v)
Miscellaneous (continued):
oe me | RPRRETETT TET ORT ee 13
EOS COME, BEC. SOI GE bcc ces cceccencesduvers 13
The Consumer Protection and Medical Confidentiality Act
of 1998, Hearing before the Subcomm. on
Government Management, Information and
Technology of the House of Representatives
Comm. on Government Reform and Oversight,
106” Cong, 2d Seas. (2998)... ns ccccvescenvenss 13
63 Fed. Reg. (1998)
DY Seer, reer rere eee rT 6
ere rere errr Te yee see Te TS 6
Ri, | MPEP ETETRTETTE ee rete ee ey 6
SG kA apace UN Sah nccetaeseeeaee eee eeeas 7
64 Fed. Reg. (1999)
Sere PPE eT TT Tee TT TT ere re 7
SS 6 MPOTERETeTT CTT etree er 22
GUUEE oc kcntaeoeesevhens catdpeeayeteneee 7, 24
GEE. check een cece suceess bates OR RREED 23-24
GUO sa acincycsvscvveesescetneseeeeeee 22-23
65 Fed. Reg. (2000)
DEE ar enke Sve cdiveuenetepenebeaereak ee 6, 23
D PPEe Sv ivewenn eae aseesasakakes Meee neeeeee 23
S| eee eT Teer ee re ee 7
Sh MPLETTEE RCL Tee te ee 5
TOUS scene ever seeewbieebasebauneeeeyaeee 27
OT vs ceneee Ney kaw eke neon ee eke ous Rane 27
GE 60400 scieued ened hese onan’ eee 7,25
| TET T TT Tee ee ee 27
Re vv esebeedscaree eeieeaeesaeen ee eee 7
|. MUTEEST ETRE CT eee ee ee 25
PE vvcccvacyd eee enneteeeerbeerunee ed 29
So Been rrere rere yi reer rere re 10, 29
DPE “on cescenscuaveulelabeseheneouean 10, 29
i alii ai iii = —
Miscellaneous (continued):
66 Fed. Reg. (2001)
EE Sia can Co Csheceveseeneutateeeneteatews 8
DERG cevwscersonnentessrececesceceaneosexs 8
67 Fed. Reg. (2002)
GE Seow eM ise nreenenenaetayso0 bevene es 8, 29
SE. a Rds ce dene eweeeuceneshasereenes 28
EE. cc ochevevessseusecntesssancengns 28
cas evecdcou hous eesatboaseeuer exeanews 29
68 Fed. Reg. (2003)
SS Seer Tree TT re rT ere TT ee 6, 23
5 QPPereververri rec Terr srr er er rrr Te 6, 23
Lawrence O. Gostin, Health Information Privacy, 80
Commedl L Rev. GSE (IPI) nosis cs cccessccvess 11-12
Lawrence O. Gostin & Tames G. Hodges, Jr.,
Personal Privacy and Common Goods: A
Framework for Balancing Under National
Health Information Privacy Rule, 86 Minn. L.
fg re Aree errr err rr 11
H.R. 1057, Medical Information Privacy and Security Act,
Se Cn FI EE ig oi cvdcescvcnceases 12
H.R. 1941, Health Information Privacy Act of 1999, 106"
ee Berets sere ree 12
H.R. 2404, Personal Medical Information Protection Act of
1999, 106" Cong., 1" Sess. (1999) ............... 12
H.R. 2878, Medical Privacy in the Age of New Technologies
Act of 1999, 106" Cong., 1* Sess. (1999) .......... 12
Health Care Records: Books Open to Abuse, TRIAL, 42
errr ry erry Pree pr tore 28
Medical Records Confidentiality in the Modern Delivery of
Health Care, Hearing before the Health and
Environment Subcomm. of the House of
Representatives Comm. on Commerce, 107"
Cs FU MOO vac oer as isnt sussescaxeass
_—
Miscellaneous (continued):
Patient Confidentiality, Hearing before the Subcomm. on
Health of the House of Representatives Ways &
Means Comm., 106" Cong., 2d Sess. (1998) ...... 13
Ann Rodgers-Melnick, Privacy Rules May Limit Clergy
Hospital Visits, Post-Gazette, http:/ / www.post-
-gazette.com/healthscience/20030228hospitals4.asp
CVORINRG, FUND TD, BOD secs scccccsssesesseesces 29
S. 573, Medical Information Privacy and Security Act of
1999, 106" Cong., 1* Sess. (1999) ............05. 12
S. 578, Health Care Personal Information Nondisclosure Act
of 1999, 106" Cong., 1* Sess. (1999) ............. 12
S. 881, Medical Information Protection Act of 1999, 106"
CR, Ks PPE hace Ru kecebscnenuseenecis 12
S. 1360, Medical Records Confidentiality Act, 104" Cong.,
PGE. Aa Waa Paine creksanakenceakees 12
S. 1368, Medical Information Privacy and Security Act,
gg a re eee re 12
S. 2129, Health Care Privacy Protection Act, 103" Cong.,
ND 66455) ceeeansiwesknceecaeee ious 12
S. 2352, Patient Privacy Rights Act of 1998, 105" Cong.,
PL NOE 0 hey soeadeeakesst eee 12
S. 2609, Medical Information Protection Act of 1998, 105"
Cy Ae SIO ones ctwncbecwsavistestes 12
Charity Scott, Is Too Much Privacy Bad for your Health?
An Introduction to the Law, Ethics, and HIPAA
Rule on Medical Privacy, 17 Ga. St. U. L. Rev. 481
PE -velscvscseuvassbivrahenceeo ee kee Cee nens 12
Richard Sobel, A New Wound to Medical Privacy -
Administration Rules Eviscerate Patient Consent,
L.A. Times 15 (August 23, 2002) ............... 28
(viii)
In the %
Supreme Court of the United States
No. 03-
SOUTH CAROLINA MEDICAL ASSOCIATION, ef al.,
Petitioners,
Vv.
TOMMY G. THOMPSON, SECRETARY OF THE U.S. DEPARTMENT
OF HEALTH AND HUMAN SERVICES, et al.,
Respondents.
On Petition for a Writ of Certiorari to
the United States Court of Appeals for the Fourth Circuit
PETITION FOR A WRIT OF CERTIORARI
Petitioners, South Carolina Medical Association, Physicians
Care Network, J. Capers Hiott, M.D., John R. Ross, M.D.,
Gordon E. Pennebaker, M.D., Carol S. Nichols, M.D., Dannette
F. McAlheny, M.D., Herbert Moskow, M.D., and the Louisiana
State Medical Society, respectfully petition this Court for a
writ of certiorari to review the judgment of the United
States Court of Appeals for the Fourth Circuit in this case.
OPINIONS BELOW
The opinion of the Fourth Circuit is reported at 327
F.3d 346 and reproduced in the appendix hereto (“App.”)
at Al. The opinion of the district court is unreported and
is reproduced at App. A18.
2
JURISDICTION
The judgment of the Fourth Circuit was entered on
April 25, 2003. App. Al. This Court has jurisdiction to
issue the requested writ of certiorari pursuant t9 28 U.S.C.
§ 1254(1).
CONSTITUTIONAL, STATUTORY,
AND REGULATORY PROVISIONS INVOLVED
Article 1, § 1, of the U.S. Constitution, is reproduced at
App. A42. Sections 261, 262, and 264 of the Health
Insurance Portability and Accountability Act of 1996, Pub.
L. No. 104-191, 110 Stat. 1936, 2021, 2034 (1996), codified at
42 U.S.C. §§ 1320d through 1320d-8, and §§ 1320d note,
1320d-2 note, are reproduced at App. A42-A62. The
Secretary’s definition of “ protected health information,” 45
C.F.R. § 160.103 (2003), is reproduced at App. A62-A63.
INTRODUCTION
During the 1990s, Congress repeatedly struggled to
address acontroversy of enormous importance to millions
of Americans: the extent to which their personal medical
records should be deemed private and not subject to
disclosure without their permission. The issue became
especially pressing during that decade because of then-
rising demands for disclosure of such medical records by
private and public entities who, relying on the potential
ease of electronic transmissions, contended they could
beneficially use the records to further important public
purposes, including safeguarding public health,
promoting medical research, reducing medical costs,
enhancing accountability, investigating fraud, and
assisting law enforcement.
Because, however, of fundamental conflicts regarding
how the balance should be struck between personal
privacy and these other competing social policy objectives,
3
Congress was unable to enact any legislation that
announced standards governing the possible disclosure of
personal medical records. In session after session,
members of Congress introduced bills, committees held
hearings, but the necessary compromises proved elusive.
Congress ultimately chose to break the legislative
logjam, but did so in a patently unconstitutional manner
that has set a dangerous legislative precedent that
warrants this Court’s plenary review. In the Health
Insurance Portability and Accountability Act of 1996
(HIPAA), Pub. L. No. 104-191, 110 Stat. 1936 (1996),
Congress effectively imposed on itself a three-year
deadline to enact standards governing medical privacy.
Congress made that deadline enforceable by mandating
that the Secretary of Health and Human Services
(Secretary) promulgate medical privacy standards for
certain transactions in the event that Congress failed to
meet its own deadline. In short, Congress sought by
HIPAA’s express terms and deliberate design to
accomplish precisely what Article I, § 1 of the US.
Constitution provides cannot be done: transfer to the
executive branch the authority to enact legislation in the
event that the democratic legislative processes failed to
produce a result.
The medical privacy standards since promulgated by
the Secretary, moreover, underscore the constitutional
pitfalls of Congress’s misguided abdication of legislative
responsibility. Although HIPAA made absolutely no
effort to provide any intelligible principle to guide the
Secretary’s decision concerning how the difficult policy
balance should be struck in the fashioning of federal
medical privacy standards, HIPAA at least limited the
Secretary’s legislative purview to a series of specifically-
listed electronic transactions of medical records. The
Secretary’s final regulations, however, even abandoned
4
that statutory bound, concluding that public policy
warranted medical privacy standards no matter what their
form or their method of transmission. The Secretary,
therefore, made even more complete Congress’s
unconstitutional delegation of legislative authority to the
executive branch by wholly untethering the rulemaking
from even the most limited congressional guideposts. The
regulatory upshot is a medical privacy regulation that
portends revolutionary changes in the medical profession
and the privacy of American citizens, which requires
expenditures of billions of dollars for compliance and
which authorizes widespread disclosure of private
medical information in the absence of patient consent.
Petitioners, the South Carolina Medical Association,
Louisiana Medical Society, and six individual doctors filed
in federal district court a lawsuit challenging the
constitutionality of HIPAA’s delegation of legislative
authority to the Secretary and the legality of the
Secretary’s medical privacy standards. The district court
dismissed the lawsuit and the court of appeals affirmed.
STATEMENT
Statutory and Regulatory Background. In 1996,
Congress passed HIPAA. The purpose of Subtitle F of
HIPAA, entitled “ Administrative Simplification,” was “to
improve the Medicare program ***, the Medicaid program
*** and the efficiency and effectiveness of the health care
system, by encouraging the development of a health
information system through the establishment of
standards and requirements for the electronic transmission
of certain health information.” HIPAA, § 261, 110 Stat.
2021; 42 U.S.C. § 1320d note. Prior to HIPAA’s enactment,
there were as many as 400 different electronic formats
being used for health care forms, resulting in gross
inefficiencies. Subpart F sought to create one uniform
5
language for electronic transmission of standard health
insurance information. See 65 Fed. Reg. 82463 (2000).
To that end, Section 262 of HIPAA added a new Part C,
also entitled “ Administrative Simplification,” to Title XI of
the Social Security Act. See 110 Stat. 2021-2031. Part C in
turn included nine separate statutory provisions, Sections
1171-1179, which, inter alia, defined the relevant statutory
terms (Section 1171), established requirements for the
adoption of standards (Section 1172), described the
relevant standards to be promulgated (Section 1173), and
established relevant timetables, enforcement programs,
and federal preemption policies. (Sections 1174-1179). See
42 U.S.C. §§ 1320d - 1320d-8.
Of particular relevance to the instant case, Section
1173(a) empowered the Secretary to adopt “standards for
transactions, and data elements for such transactions, to
enable health information to be exchanged electronically.”
See 42 U.S.C. § 1320d-2(a)(1). Section 1173(a) further
listed nine different specific electronic transactions to
which the Secretary’s standards would apply.’
HIPAA also reflected congressional awareness of the
substantial personal privacy implications of enabling
electronic transmissions of medical records.
Standardization of the features of medical records kept in
electronic form necessarily made their disclosure that
much easier and the need for privacy standards that much
more pressing. At the time of HIPAA’s enactment,
' The listed transactions include:
(A) Health claims or equivalent encounter information. (B) Health
claims attachments. (C) Enrollment and disenrollment in a health
plan. (D) Eligibility for a health plan. (E) Health care payment
and remittance advice. (F) Health plan premium payments. (G)
First report of injury. (H) Health claim status. (I) Referral
certification and authorization.
42 U.S.C. § 1320d-2.
6
Congress had tried for several years, without success, to
enact applicable medical privacy standards. Legislators
were unable to forge the necessary compromises between
privacy advocates and those seeking greater disclosure of
medical records. See pages 11-14, infra.
To break the legislative deadlock and to ensure that
some standards would be in existence by the time that the ~
Secretary’s regulations designed to enable electronic
transmission of medical records became effective, Section
264(a) of HIPAA instructed the Secretary to provide
Congress within one year “detailed recommendations on
standards with respect to the privacy of individually
identifiable health information.” 110 Stat. 2033; 42 U.S.C.
§ 1320d-2 note(a). Section 264(c) further provided that if
Congress failed within three years to enact standards
“with respect to the privacy of individually identifiable
health information transmitted in connection with the
transactions described in section 1173(a) of the Social
Security Act (as added by [HIPAA] section 262),” then the
Secretary “shall promulgate final regulations containing
such standards.” 110Stat. 2033; 42 U.S.C. § 1320d-2note(c).
The Secretary’s Rulemakings. Pursuant to Section
1173 of the Social Security Act, as added by Section 262 of
HIPAA, the Secretary has since issued proposed and final
rules intended to facilitate the electronic transmission of
medical records by standardizing their format and other
features. The Secretary has confined the scope of each of
these rulemakings to the nine transactions specifically
listed in Section 1173. See, e.g., Health Insurance Reform:
Security Standards, 68 Fed. Reg. 8334, 8342 (2003); Health
Insurance Reform: Standards: 65 Fed. Reg 50312 (2000);
Health Insurance Reform: Standards for Electronic
Transactions, 63 Fed. Reg. 25272, 25320 (1998); Health
Insurance Reform: National Standard Employer Identifier,
63 Fed. Reg. 32784 (1998); Security and Electronic
7
Signature Standards, 63 Fed. Reg. 43242 (1998).
The Secretary did not, however, likewise confine the
medical privacy standards challenged in this litigation
either to the nine transactions listed in Section 1173(a) or
to their electronic transmission. In the December 2000
final rulemaking, the Secretary decided to “expand the
definition of protected health information to encompass all
individually identifiable health information transmitted or
maintained by a covered entity, regardless of form.” 65
Fed. Reg. 82462, 82496 (2000); see 65 Fed. Reg. 82618
(2000); 45 C.F.R. § 160.103 (2003) (“transmitted or
maintained in any * * * form or medium”).
The final regulations, in this respect, departed
significantly from the Secretary’s proposed regulations. In
the proposed rulemaking, “only those providers who
engage in the electronic administrative simplification
transactions [were] covered * * *. Any provider who
maintains a solely paper information system would not be
subject to these privacy standards.” 64 Fed. Reg. 59918,
99923 (1999). While the rulemaking commentary
accompanying that far more limited proposal asserted that
the Secretary possessed more authority than exercised in
the proposed rules, the Secretary acknowledged that “the
HIPAA legislative authority is more limited in scope * * *
and does not always permit us to propose the policies that
we believe are optimal.” Id. According to the Secretary,
“the HIPAA limits the application of our proposed rule to
health plans, health care clearinghouses, and to any health
care provider who transmits health information in
electronic form in connection with transactions referred to
in section 1173(a)(1) of the [Social Security] Act.” Id.
(emphasis added).’
> The Secretary has undertaken several subsequent administrative
actions extending the effectiveness and compliance dates of the
December 2000 privacy standards and has also modified the
8
Proceedings Below. Petitioners, two state medical
associations, a network c health care providers, and six
physicians, filed a complai:.: in federal district court, based
on the Constitution, 28 U.S.C. §§ 1331, 1337, 2201,
challenging the constitutionality of HIPAA’s delegation of
lawmaking authority to the Secretary and to the legality of
the Secretary’s privacy standards under HIPAA.
Petitioners contended that HIPAA violated the
nondelegation doctrine by conferring legislative authority
on the Secretary. Petitioners further alleged that the
privacy standards exceeded the scope of the Secretary’s
statutory authority by extending those standards to all
personal medical records whatever their form or method
of transmission, including both paper and electronic.
The district court dismissed the complaint. App. A18.
The court ruled that HIPAA provided a sufficient
limitation on the Secretary’s discretion to avoid offending
nondelegation doctrine concerns. Id. at A26-A29. The
district court also rejected petitioners’ second contention
upon concluding that the plain meaning of HIPAA
supported the Secretary’s interpretation that the statute
authorized promulgation of medical privacy standards
applicable to all personal medical records. Id. at A29-A32.
The court of appeals affirmed. App. Al. On the
nondelegation issue, the court concluded that HIPAA
announced a “general policy” that guided the Secretary’s
lawmaking authority to an extent sufficient to satisfy the
nondelegation doctrine and that Congress had effectively
agreed to the standards by default -- by not enacting
legislation that formally objected to. the Secretary’s
recommendations. Id. at A8-A11. With regard to the
scope of the Secretary’s lawmaking authority under
standards in some respects not relevant to the issues raised in this
case. See 66 Fed. Reg. 12434 (2001); 66 Fed. Reg. 12738 (2001); 67 Fed.
Reg. 53182 (2002).
PR 5 weed
9
HIPAA, the appellate court further held that “the plain
language of HIPAA indicates that HHS could reasonably
determine that the regulation of individually identifiable
health information should include non-electronic forms of
that information.” Id. at A12-A13.
REASONS FOR GRANTING THE WRIT
This petition presents two legal issues warranting this
Court’s review. First, the Secretary of HHS promulgated
medical privacy regulations pursuant to an improper
congressional transfer to the Secretary of legislative
lawmaking authority that violates Article 1, § 1, of the
United States Constitution. By deliberate congressional
design, HIPAA assigns to the Secretary the exclusive
responsibility of legislating by rulemaking medical privacy
standards in the event that Congress is unable to enact
such standards within three years. The Constitution does
not countenance such a blatant reallocation of legislative
authority to the executive branch whenever Congress
concludes that a policy matter of fundamental importance
to millions of Americans and the health care profession is
too difficult and controversial for Congress to handle.
Second, in subsequently promulgating medical privacy
standards, the Secretary ignored the only clear guidance
that Congress did provide in HIPAA, which was to restrict
the scope of the privacy standards to electronic
transmissions associated with nine statutorily-listed
transactions. The Secretary thereby exceeded the scope of
the delegation of authority Congress intended to confer.
This second error not only provides an independent legal
error warranting invalidation of the regulations, but also
further underscores HIPAA’s violation of the
nondelegation doctrine. If, as the Secretary claims, HIPAA
does provide the Secretary with authority to extend its
10
medical privacy regulations essentially to all medical
records, then sucha massive delegation would have made
it all the more necessary that it be accompanied by the
constitutionally required “intelligible principle” sufficient
to guide the Secretary’s exercise of such lawmaking
authority. Here, however, there was none.
Review is warranted even though the court of appeals
below is the first to consider the constitutionality of
HIPAA and the lawfulness of the Secretary’s medical
privacy standards. The extraordinary breadth and depth
of those standards implicate the core personal autonomy
and privacy rights of millions of Americans and they are
at this moment requiring hundreds of thousands of health
care providers to change dramatically their services, at a
cost of billions of dollars. By the Secretary’s own
accounting, the regulations directly apply to 12,200 health
plans, 6480 hospitals, and 630,000 non-hospital providers,
including 562,916 small businesses and_ individual
physicians. 65 Fed. Reg. 82765, 82779 (2000). Although
invariably touted as promoting patient privacy, the
Secretary's regulations in fact authorize disclosure of
historically confidential patient information ina variety of
circumstances, including to government officials without
a warrant, and without the patient’s consent. In such
extreme circumstances, prudence justifies the Court’s
departing from its normal practice of delaying review for
several years .. allow further lower court litigation. The
petition should instead be granted.
I. REVIEW OF THE NONDELEGATION
DOCTRINE ISSUE IS WARRANTED
“In a delegation challenge, the constitutional question
is whether the statute has delegated legislative power to
the agency. Article I, § 1 of the Constitution * * * permits
no delegation of those powers.” Whitman v. American
;
2
‘
;
J
.
*
x
%
"]
3
‘
3
:
$
11
Trucking Ass’n, 531 U.S. 457, 472 (2001). “Congress
manifestly is not permitted to abdicate, or to transfer to
others, the essential legislative functions with which it is
thus vested.” Panama Refining Co. v. Ryan, 293 U.S. 388,
421 (1935). This Court has, accordingly, repeatedly held
“that when Congress confers decisionmaking authority
upon agencies Congress must ‘lay down by legislative act
an intelligible principle to which the person or body
4%
authorized to [act] is directed to conform’” American
Trucking Ass’n, 531 U.S. at 472, quoting J. W. Hampton,
Jr., & Co. v. United States, 276 U.S. 394, 409 (1928).
In HIPAA, Congress blatantly abdicated its legislative
authority in violation of the nondelegation doctrine.
HIPAA Section 264(c) expressly instructed the Secretary to
promulgate medical privacy standards in the event that
Congress proved unable to meet its own deadline for
doing so. Hence, Congress expressly predicated its
transfer of legislative responsibility to the Secretary on
Congress’s failure to pass legislation that might, at the
very least, have provided the Secretary with the
“intelligible principle’ required to render such an
allocation of lawmaking authority constitutional.
The reasons for Congress’s abdication of legislative
responsibility are plain. Determining what factors should
be relevant to the fashioning of medical privacy standards
and their relative weight in the balancing necessary for
their application is complex and controversial. Lawrence
O. Gostin, James G. Hodges, Jr., Personal Privacy and
Common Goods: A Framework for Balancing Under National
Health Information Privacy Rule, 86 Minn. L. Rev. 1439, 1454
(2002). “Hard choices” must be made in deciding whether
we should “sharply limit the systematic collection of
identifiable health care data in order to achieve reasonable
levels of informational privacy” or “decide that the value
of information collection is so important to the
12
achievement of societal aspirations for health that the law
ought not promise absolute or even significant levels of
privacy at all * **.” Lawrence O. Gostin, Health Information
Privacy, 80 Cornell L. Rev. 451, 455 (1995).
What happened prior to and in the aftermath of
HIPAA’s enactment is that the hard choices presented by
fashioning medical privacy standards became a “ political
hot potato” that Congress preferred to toss to the
Secretary. Charity Scott, Js Too Much Privacy Bad for your
Health? An Introduction to the Law, Ethics, and HIPAA Rule on
Medical Privacy, 17 Ga. St. U. L. Rev. 481, 481 (2000).
“[V]arious competing interests and starkly different views
over where we should strike the appropriate ethical
balance * * * stymied all efforts to pass such federal
legislation.” Id. at 505. “About a half dozen policy
questions * * * apparently prove[d] intractable in the
congressional debates.” Id. at 513.
Inthe months just before the HIPAA deadline, multiple
bills were pending in the House’ and Senate,* with
> See H.R. 1057, Medical Information Privacy and Security Act, 106"
Cong., 1" Sess. (1999); H.R. 1941, Health Information Privacy Act of
1999, 106" Cong., 1 Sess. (1999); H.R. 2404, Personal Medical
Information Protection Act of 1999, 106" Cong., 1* Sess. (1999); H.R.
2878, Medical Privacy in the Age of New Technologies Act of 1999,
106" Cong., 1* Sess. (1999).
* S.573, Medical Information Privacy and Security Act of 1999, 106"
Cong., 1" Sess. (1999); S. 578, Health Care Personal Information
Nondisclosure Act of 1999, 106" Cong., 1* Sess. (1999); S. 881, Medical
Information Protection Act of 1999, 106" Cong., 1* Sess. (1999); see
also S. 2129, Health Care Privacy Protection Act, 103% Cong., 2d Sess.
(1994); S. 1360, Medical Records Confidentiality Act, 104" Cong., 1*
Sess. (1995); S. 1368, Medical Information Privacy and Security Act,
105" Cong., 1* Sess. (1997); S. 2352. Patient Privacy Rights Act of 1998,
105" Cong., 2d Sess. (1998); S. 2609, Medical Information Protection
Act of 1998, 105" Cong., 2d Sess. (1998);
Ks hich aS CLs Racers Cree S
13
extensive hearings held in both chambers.’ None passed.
As later described by Senator Patrick Leahy, a major
sponsor of pending legislation, “We couldn't do the job on
our own and we have instead shifted the responsibility to
the administration.” 146 Cong. Rec. S 6186 (2000).° Then-
Secretary Donna Shalala similarly described the
relationship between Congress and the executive branch
in her press conference announcing her medical privacy
standards: “Congress tried to write these regulations and they
actually couldn’t get it done, they couldn’t find a consensus to
get it finished.” J.A. 272 (emphasis added).’ Finally, in
announcing the Secretary’s proposed medical privacy
standards, President Clinton likewise commented that the
° See, e.g., Confidentiality of Individually Identifiable Health Information,
Hearing before the Sen. Comm. on Labor and Human Resources,
106" Cong., 2d Sess. (198); Patient Confidentiality, Hearing before the
Subcomm. on Health of the House of Representatives Ways & Means
Comm., 106" Cong., 2d Sess. (1998); The Consumer Protection and
Medical Confidentiality Act of 1998, Hearing before the Subcomm. on
Government Management, Information and Technology of the House
of Representatives Comm. on Government Reform and Oversight,
106" Cong., 2d Sess. (1998); Confidentiality of Medica! !:formation,
Hearing before the Senate Comm. on Health, Education, Labor and
Pensions, 107 Cong., 1* Sess. (1999); Medical Records Confidentiality in
the Modern Delivery of Health Care, Hearing before the Health and
Environment Subcomm. of the House of Representatives Comm. on
Commerce, 107" Cong., 1* Sess. (1999); Confidentiality of Patient
Records, Hearing before the Subcomm. on Health of the House of
Representatives Ways & Means Comm., 107" Cong., 2d Sess. (2000).
* But the Senator simultaneously acknowledged the impropriety of
such a shift: “This Congress has the responsibility to protect the
privacy of Americans - and that includes protection of their medical
records. The place for these protections is in legislation - not
regulation.” 146 Cong. Rec. S 6186; see id. at E 2307 (remarks of Rep.
Condit) (“Congress failed to act on this crucial issue.”).
” “J.A.” refers to the joint appendix filed in the court of appeals.
14
reason for executive branch action was congressional
default. See J.A. 261 (“I am taking this action today
because Congress failed to act, and because a few years
ago Congress explicitly gave me the authority to step in if
they were unabie to deal with this issue.”).
Political convenience was therefore clearly the motive
for congressional abdication in HIPAA, but it is equally
clear that “the fact that a given law or procedure is
efficient, convenient, and useful in facilitating functions of
government, standing alone, will not save it if it is
contrary to the Constitution.” Immigration and
Naturalization Service v. Chadha, 462 U.S. 919, 944 (1983).
“[P]olicy arguments supporting even useful ‘political
inventions’ are subject to the demands of the Constitution
which defines powers and * * * sets out just how those
powers are to be exercised.” Id. at 945. “That a
congressional cession of power is voluntary does not make
it innocuous. * * * Abdication of responsibility is not part
of the constitutional design.” Clinton v. City of New York,
524 U.S. 417, 452 (1998) (Kennedy, J., concurring). Where
there are “hard choices” to be made, and where issues are
“politically so divisive that the necessary decision or
compromise [is] difficult, if not impossible, to hammer out
in the legislative forge,” it is that much more, not less,
important under our Constitution that the decisions are
ultimately “made by the elected representatives of the
people * * * [and] the buck stops with Congress.”
Industrial Union Dept. v. American Petroleum Institute,
448 U.S. 607, 687 (1980) (Rehnquist, J., concurring).
Nor is there any merit to the court of appeals’
conclusion (App. A8) that HIPAA otherwise provided the
“intelligible principle” necessary to convert an improper
delegation of legislative responsibility into a constitutional
assignment of executive branch rulemaking authority
pursuant to a federal statute. HIPAA provides no such
plitinaiixs MAS tnt 2 eM Th 2
ew tel
Si Le ett Cs DC ts Bt
15
“intelligible principle.” To constitute an intelligible
principle under this Court’s precedent, a congressional
enactment must, at a bare minimum, identify the
substantive factors relevant in fashioning a regulation. In
some circumstances, the statute should go further and
provide some guidance concerning how the agency should
procedurally and/or substantively strike the balance
between competing considerations. The precise tevel of
congressional guidance necessary in a particular context
depends on the breadth of the regulations at issue. As
described by this Court in Whitman v. American Trucking
Ass’n, “the degree of agency discretion that is acceptable
varies according to the scope of the power congressionally
conferred.” 531 U.S. at 475. For “setting * * * standards
that affect the entire national economy,” such as the
Secretary's medical privacy standards, Congress “must
provide substantial guidance.” Id.
HIPAA, however, not only fails to provide the
constitutionally required “substantial guidance,” it fails to
provide any meaningful guidance at all. HIPAA mandates
the Secretary’s promulgation of medical privacy standards
if Congress fails to do so, but without offering the barest
suggestion of the substantive factors relevant to their
promulgation, let alone any guidance concerning how to
strike a balance between them. Privacy in the medical
context is exceedingly important, but like other ethical
values, it is not absolute and is subject to qualification.
Yet, in HIPAA, Congress never provides the Secretary
with even the most minimal guidance concerning what
factors should be relevant in assessing the privacy
concerns implicated by particular medical records or what
factors should be relevant in assessing the social policy
objectives allegedly favoring disclosure of those records.
Even more particularly, Congress never addresses: (1)
What factors the Secretary should consider in determining
16
the scope of medical privacy rights that an individual
should have; (2) What factors the Secretary should
consider in determining what procedures an individual
should have for exercising those rights; or (3) What factors
the Secretary should consider in determining what uses
and disclosures of that information should be authorized.
The court of appeals’ fundamental error was its
mistaking for an intelligible principle in HIPAA the
presence in the Act of some congressional guidance as to
the scope of the medical privacy standards. We do not
deny that HIPAA provides some such statutory bounds.
Indeed, as we argue in Part II below, the Secretary’s
privacy standards are separately flawed because they
ignore those express bounds. But the fact that rulemaking
authority has some outer bounds is not the constitutional
equivalent of an intelligible principle for exercising the
lawmaking authority within those established bounds, let
alone the “substantial guidance” necessary in this case in
light of the extraordinary breadth and depth of the
Secretary’s medical privacy standards.
Hence, HIPAA’s provision (Section 264, 42 U.S.C.
§1320d-2 note(b)) that the standards should “at least”
cover (1) “The rights that an individual who is a subject of
individually identifiable health information should have”;
(2) “The procedures that should be established for the
exercise of such rights” and (3) “the uses and disclosures
of such information that should be authorized or
required” falls nowhere near the applicable constitutional
standard. Wholly missing from the statute is any
substantial congressional guidance regarding how the
Secretary is to determine what those individual “rights”
should be or what “disclosures * * * should be authorized
or required.” Indeed, even this purported legislative
guidance provides no bounds because, HIPAA merely
provides that the standards must “at least” cover these
agit
SD Bek
Sei Ps
Oa ah LARNER Bia Tet A ane seen ee,
17
topics. Id.
No more persuasive is the lower court's additional
reliance (App. A8-A9) upon either the preamble statement
in HIPAA Section 261 regarding HIPAA’s general purpose
or the fact that HIPAA’s privacy standards are limited “to
communications of listed information by particular
covered entities.” Section 261's preamble statement
provides absolutely no guidance for the Secretary
concerning how individual rights should be protected or
to what extent. It is merely a general preamble statement
applicable to the entire statute and of no special legal
import. See Panama Refining, 293 U.S. at 418. Nor does
the fact that HIPAA’s privacy standards are limited to
individually identifiable health information by certain
entities excuse Congress from providing the Secretary
with guidance on how to determine privacy standards for
such crucial personal information.’
Indeed, this Court’s recent decision in Whitman v.
American Trucking Ass‘n is illustrative of both the failings
of HIPAA and the lower courts’ misapplication of this
Court's nondelegation doctrine precedent. In American
Trucking, the Court rejected a nondelegation challenge to
the EPA Administrator’s promulgation of a national
ambient air quality standard pursuant to the Clean Air
Act, 42 U.S.C. §§ 7407-7409. The Court concluded that the
Clean Air Act provided the necessary “intelligible
principle” because the Act both identified the factors
relevant and not relevant to the Administrator’s selection
of a standard and instructed the Administrator how the
® To be sure, where, unlike in HIPAA, Congress has delegated to an
agency the narrow task of defining a technical term of limited
application, no further guidance may be necessary. See American
Trucking Ass’n, 531 U.S. at 574 (comparing minimal legislative
guidance necessary for agency definition of a “country elevator” to
“substantial guidance” necessary for national air quality standards).
ee
18
balance should be struck. The Act made plain that
economic compliance costs were irrelevant to standard
setting, which should consider only public health risks,
and that the Administrator should set the air quality
standards ata level “requisite” or “sufficient, but not more
than necessary” to protect public health. 531 U.S. at 473.
However, under the Secretary’s view, endorsed by the
court of appeals below, it would presumably have been
sufficient in American Trucking had the Clean Air Act
simply mandated the Administrator’s promulgation of
national air quality standards, without more. So long as
the federal statute provided some jurisdictional bounds --
presumably such as “air quality” and “national standards”
-- the Constitution’s nondelegation doctrine would require
no more. Such an extraordinary misapprehension of this
Court’s precedent warrants this Court's review.”
Nor is there any merit to the court of appeals’ further
suggestion that any constitutional infirmity is somehow
° —Fhe other recent cases in which this Court has rejected
nondelegation doctrine challenges are similarly distinguishable from
this case. In Touby v. United States, 500 U.S. 160 (1991), the Attorney
General's authority to designate “controlled substances” was sharply
circumscribed to those presenting an “imminent hazard.” In Loving
v. United States, 517 U.S. 748, 772 (1996), the President's choices for
determining the aggravating factors in capital cases under military
law were “set within boundaries the President may not exceed.” In
Mistretta v. United States, 488 U.S. 361, 379 (1989), the U.S. Sentencing
Commission did not run afoul of the nondelegation doctrine because
“[t]he statute outlines the policies which prompted establishment of
the Commission, explains what the Commission should do and how
it should do it, and sets out specific directives to govern specific
situations” and other federal statutes established applicable
sentencing boundaries. Not only does HIPAA provide no comparable
level of legislative guidance to the Secretary, but the reach of the
Secretary's privacy standards into the daily lives of millions of
Americans is far greater than the agency rules at issue in Loving,
Touby, or Mistretta.
19
cured because HIPAA Section 264 called for the Secretary
to promulgate medical privacy standards after first
making recommendations regarding such standards to
Congress. No serious claim can be maintained that such
a reporting requirement bears any relevance to HIPAA’s
constitutionality. The court of appeals’ view to the
contrary - “That Congress did not enact additional
measures in light of these recommendations indicates the
legislature’s satisfaction with HHS’s proposed approach”
(App. A11) - is wholly untenable.
Congress acts in only one meaningful way under the
Constitution: by enacting legislation. Congressional receipt
of executive branch recommendations does not amount to
a legislative enactment approving or disapproving of
those recommendations. Such a reporting requirement is
perfectly sensible, but it is of absolutely no constitutional
moment to a nondelegation challenge. Indeed, Congress’s
failure to enact legislation in response to those
recommendations merely underscores the impropriety of
HIPAA’s attempt to circumvent the constitutionally
demanded legislative process by purporting to assign that
function to the Secretary.
Finally, any possible doubt regarding the existence of
an intelligible principle in HIPAA is removed by
examination of the rulemaking record itself. The Secretary
published more than 700 hundred pages of preamble
commentary to accompany the proposed and final
rulemaking. That commentary explains in some detail
why the Secretary chose to strike the balance between
privacy concerns and other competing social concerns in
a variety of contexts. What is striking is that in none of that
explanation does the Secretary ever refer to any relevant
principles established by the governing statute, HIPAA.
The rulemaking record is stunningly silent, no doubt
because so too is HIPAA.
20
The Secretary, in effect, decided entirely on her own
both what the relevant factors should be and how to strike
the balance between them in the final rulemaking. Wholly
absent from the Secretary’s reasoning was any suggestion
that HIPAA guided the Secretary’s balancing process in
any way, let alone in the “substantial” way required by
this Court’s precedent.
II. REVIEW OF THE LEGALITY OF THE SCOPE OF
THE SECRETARY’S MEDICAL PRIVACY
STANDARDS IS ALSO WARRANTED
The Secretary’s medical privacy standards, moreover,
are invalid on yet a second, distinct ground. They exceed
the statutory authority that HIPAA conferred on the
Secretary. Although, as described above, HIPAA is itself
unconstitutional under the nondelegation doctrine,
Congress did make some effort at least to place outer
bounds on the substantive scope of the Secretary’s
authority. In the final rulemaking, however, the Secretary
blithely transgressed that statutory bound by
promulgating medical privacy standards that apply to all
personal medical records regardless of their form or their
method of transmission.
“Because this case involves an administrative agency’s
construction of a statute that it administers, [this Court's]
analysis is governed by Chevron U.S.A. Inc. v. Natural
Resources Defense Council, Inc., 467 U.S. 837 (1984).” Food
& Drug Administration v. Brown & Williamson, 529 U.S.
120, 132 (2000). Under Chevron, “although agencies are
generally entitled to deference in the interpretation of
statutes that they administer, a reviewing ‘court, as well as
the agency, must give effect to the unambiguously
expressed intent of Congress.” Id. at~125-126, quoting
Chevron, 467 U.S. at 842-843. “In determining whether
Congress has specifically addressed the question at issue,
21
a reviewing court should not confine itself to examining a
particular statutory provision in isolation. The meaning *
** of certain words or phrases may only become evident
when placed in context.” Id. at 132.
In this case, moreover, the Secretary is entitled to no
judicial deference. The plain meaning of HIPAA’s relevant
language, read both in isolation and in its broader
statutory context, makes clear that the Secretary does not
possess sweeping lawmaking authority to enact medical
privacy standards applicable to all individually
identifiable health information.
It is common ground that HIPAA Section 264(c)(1) is
the exclusive source of the Secretary’s authority to
promulgate medical privacy standards. Section 264,
however, expressly limits the Secretary’s standard setting
authority “to the privacy of individually identifiable
health information transmitted in connection with the
transactions described in section 1173(a) of the Social Security
Act (as added by section 262)” (emphasis added). Section
1173(a) in turn sets forth nine specific transactions for
which the Secretary shall “adopt standards for
transactions, and data elements for such transactions, to
enable health information to be exchanged electronically.”
Only those nine transactions are covered and, even then,
only as necessary to enable their electronic transmission.
Contrary to the court of appeals’ ruling below, therefore,
Section 264's cross-reference to Section 1173(a) expressly
contradicts the Secretary’s decision in the final regulations
to issue privacy standards applicable to personal medical
records “transmitted or maintained in any . . . form or
medium.” 45 C.F.R. § 160.103 (2003).
HIPAA’s overall statutory structure confirms the
extent of the Secretary’s usurpation of legislative
authority. Most strikingly, comparison of the language of
Section 264(a), in which the Secretary is asked to make
22
privacy standard recommendations to Congress, to the
language of Section 264(c), in which the Secretary is given
rulemaking authority, underscores congressional intent to
deny the Secretary the very sweeping authority he now
claims. While Section 264(a) instructed the Secretary to
provide Congress with “recommendations on standards
with respect to the privacy of individually identifiable
health information,” without any further qualification,
Congress in 264(c) expressly qualified the Secretary's
rulemaking authority “to the privacy of individually
identifiable health information transmitted in connection
with the transactions described in section 1173(a).” The
Secretary, however, has essentially read that express
limitation on his authority out of existence.
The reason for the contrasting language in Sections
264(a) and 264(c) is also clear. The overall purpose of
Section 1173(a), added by Section 262 of HIPAA, was to
promote electronic transmission of health care information
in the listed transactions by establishing uniform
standards (e.g., formats, identifiers, and data codes) for the
electronic transmission of certain health information.
Before HIPAA, the lack of such standardization had
resulted in gross inefficiencies because there were
hundreds of different (and incompatible) electronic
formats. At the same time, however, as the Secretary
herself explained, Congress understood that “ [t]he risk of
improper uses and disclosures has increased as the health
care industry has begun to move from primarily paper-
based information systems to systems that operate in
various electronic forms.” 64 Fed. Reg. 59920 (1999).
Technological “advances have reduced or eliminated
many of the logistical obstacies that previously served to
protect the confidentiality of health information and the
privacy interests of individuals.” Id.
It is for that reason that Congress concluded “that
acne aa: An Rene
en aS
23
privacy standards must accompany the electronic data
interchange standards and that the increased ease of
transmitting and sharing individually identifiable health
information must be accompanied by an increase in the
privacy and confidentiality.” 64 Fed. Reg. 60006. Fearful
that Congress would be unable to enact the privacy
standards in a timely basis itself, Congress decided to
allocate some interim lawmaking authority over medical
privacy standards to the Secretary in the event of
congressional failure to meet a three year deadline. But, in
taking this dramatic step, Congress also took care to limit
the Secretary’s lawmaking authority over privacy
standards to the electronic transmission of the same nine
transactions listed in Section 1173(a) that Congress knew
it was otherwise promoting in HIPAA.”
"Significantly, the Secretary’s privacy standards are the only
HIPAA standards that the Secretary has sought to apply to
nonelectronic forms of medical records. The Secretary is authorized
to promulgate a wide array of non-privacy standards under Section
1173(a) and for none of those other standards has the Secretary sought
to apply standards beyond the four corners of Section 1173(a). Instead,
consistent with the plain meaning of the Statutory language, the
Secretary has promulgated standards applicable only to the
Statutorily-listed transactions and electronic transmissions. See
Health Insurance Reform: Security Standards, 68 Fed. Reg. 8334, 8342
(2003) (“While we agree that protected health information in paper or
other form also should have appropriate security protections, the
Proposed rule proposing the security standards proposed to apply
those standards to health information in electronic form only. Weare,
accordingly, not extending the scope in this final rule.”); Health
Insurance Reforms: Standards for Electronic Transactions, 65 Fed.
Reg. 50312, 50318 (2000) (rejecting suggestion “that the transaction
standards and their codes sets, in some manner, apply to paper
transactions” because otherwise “many health care providers would
revert to paper claims if the data requirements were less restrictive
than those for electronic claims.”); see 64 Fed. Reg. 59928 (“Our prior
proposals under HIPAA have addressed only electronically
24
In the Federal Register commentary accompanying the
proposed medical privacy standards, unlike in the final
rulemaking, the Secretary recognized that HIPAA placed
significant limits on the Secretary’s authority to issue
medical privacy standards. The Secretary expressly
admitted that “the HIPAA legislative authority is more
limited in scope * * *and does not always permit us to
propose the policies that we believe are optimal.” 64 Fed.
Reg. 59923. The Secretary went on to describe how under
the proposed regulation, “[a]ny provider who maintains
a solely paper information system would not be subject to
these privacy standards, thus leaving another gap in the
system of protection we propose to create.” Id. In the final
regulations, however, the Secretary effectively ignored
HIPAA’s express limitations and decided unilaterally to
close that “gap” by extending the privacy standards to all
personal medical records, including those maintained
under “a solely paper information system.”
The court of appeals erred by finding support (App.
A12-A13) for the Secretary’s interpretation in two
provisions added to the Social Security Act by HIPAA
Section 261: Section 1171(6)’s definition of “individually
identifiable information” and Section 1173's purpose “to
enable health information to be exchanged electronically.”
Neither provision, however, redefines the bounds of the
Secretary’s standard setting authority set forth in HIPAA
Section 264(c). It is neither relevant nor surprising that
“individually identifiable health information” can extend
for some purposes in the Social Security Act to such
information in nonelectronic forms. What is dispositive is
that Congress in HIPAA Section 264(a) expressly declined
to confer standard setting authority on the Secretary for all
such personal health information. Nor, contrary to the
maintained and transmitted information.”).
25
court of appeals’ did Congress in Section 264(c) grant
authority to the Secretary to issue privacy standards to the
extent the Secretary thought such standards would
“enable health information to be exchanged
electronically.” As previously described, Section 264(c)’s
grant of agency lawmaking authority is more narrowly
drawn and contains no such unbounded purpose.
No doubt that is why, prior to the final rulemaking, it
was essentially common ground that the Secretary lacked
any such extraordinarily expansive rulemaking authority
_to promulgate medical privacy standards. In her formal
recommendations to Congress in 1997, the Secretary
acknowledged the absence in HIPAA of the very authority
She subsequently asserted in the final rulemaking.
Secretary Shelala stated that HIPAA “calls for the
Secretary of HHS to impose confidentiality controls on
electronic transmission systems.” J.A. 355 (emphasis
added). President Clinton similarly acknowledged that
further legislation would be necessary to extend privacy
standards to paper transactions. J.A. 262 (“only through
legislation can we cover all paper records”).
The rulemaking itself even expressly acknowledges the
weakness of its underlying legal argument by deliberately
structuring the relevant regulation to allow for its partial
invalidation with the least amount of disruption. See 65
Fed. Reg. 82496 (“We have structured the definition this
way so that, if a court were to disagree with our view of
our authority in this area, the rule would still be
operational, albeit with respect to a more limited universe
of information.”).
Finally, the Secretary contended in the rulemaking that
a broader assertion of jurisdiction made sense as a matter
of policy because otherwise those subject to regulation
might be able to avoid the privacy standards simply by
avoiding electronic transmissions. See 65 Fed. Reg. 82619.
26
We question whether the advantages of electronic
transmissions would be so easily outweighed, but in any
event, the short answer is that such a policy concern is for
Congress to address in the first instance. If the Secretary
believes that rules of broader applicability are needed, the
Secretary must persuade Congress to provide the
Secretary with broader authority. In HIPAA, however,
Congress has not only declined to provide such broad
authority, but instead accomplished just the opposite
result. In the interim, “regardless of how serious the
problem an administrative agency seeks to address, * * * it
may not exercise its authority ‘in a manner that is
inconsistent with the administrative structure that
Congress enacted into law.’” FDA v. Brown & Williamson,
529 U.S. at 125, quoting ETSI Pipeline Project v. Missouri,
484 U.S. 495, 517 (1988).
/
Ill. REVIEW IS WARRANTED IN THIS CASE __
We readily acknowledge that this Court’s normal
practice is not to grant review in the first case that presents
a legal issue, but instead to await further litigation. The
extraordinary nature of both Congress’s action in HIPAA
and the Secretary’s rulemaking warrant a departure from
that practice in this case.
Most simply put, the enormous impact of the
Secretary’s usurpation of legislative authority in
promulgating the medical privacy standards justifies this
Court’s immediate attention. Any nondelegation issue
implicates fundamental issues of individual liberty.
“Separation of powers was designed to implement a
fundamental insight: concentration of power in the hands
of a single branch is a threat to liberty.” Clinton v. City of
New York, 524 U.S. at 450 (Kennedy, J., concurring). But,
the liberty implications at stake in this litigation are
magnified many fold because of the breadth, depth, and
27
character of the rulemaking at issue, which is likely why
the Secretary received nearly 52,000 comments on the
proposed regulation. 65 Fed. Reg. 82566.
As described by the Secretary herself in the final 2000
rulemaking “[t]his final rule establishes, for the first time,
a set of basic national privacy standards ***” and the rules
promulgated by the Secretary “are likely the largest single
federal initiative to protect Privacy.” 65 Fed. Reg. 82464,
82468. See J.A. 261 (remarks of President Clinton) (“the
first comprehensive national standards for protection of
medical records”). The Secretary's rulemaking affects the
privacy rights on a matter that for millions of Americans
strikes at fundamental notions of personal autonomy. The
Hippocratic oath of confidentiality lies at the foundation
of the doctor-patient relationship. Like other privileges, it
is not absolute. But there is nothing merely technical nor
incidental about fashioning a legal standard to govern the
terms for its potential breach. It is instead the very kind of
legal issue for which any meaningful lawmaking calling
for the breach of confidentiality must be well grounded in
legislation enacted by democratically elected
representatives of the people. Especially because the
executive branch has its own bureaucratic policies
favoring disclosure, it is all the more incumbent that
Congress not be circumvented, even if it seems politically
expedient to do so.
However, just such a circumvention of the iegislative
process was, albeit at Congress’s own initiative, precisely
what happened pursuant to HIPAA As a result, the
personal medical records of 282 million Americans are
now subject to disclosure based on privacy standards
established by the Secretary not only in the absence of the
constitutionally required “intelligible principle” bit in
blatant violation of the limited bounds established by
Congress in HIPAA.
28
Although the Secretary touts the regulations as
safeguarding patient privacy, the regulations in fact
authorize widespread releases of historically confidential
patient information. Under the regulations, no patient
consent is frequently necessary for release of private
medical information to government agencies. Hence, law
enforcement officers now can often obtain ready access to
personial medical records in a host of circumstances (see 45
C.F.R. § 164.512; 67 Fed. Reg. 53226-32 (2002)), which raises
a distinct constitutional issue under this Court’s recent
ruling in Ferguson v. City of Charleston, 532 U.S. 67 (2001).
Patient consent is similarly not necessary for 1eleases of
personal medical information that fall within the
potentially open-ended category of “uses and disclosures
to carry out treatment, payment, or health care
operations.” 45 C.F.R. § 164.506; 67 Fed. Reg. 53208-19
(2002); Richard Sobel, A New Wound to Medical Privacy --
Administration Rules Eviscerate Patient Consent, L.A. Times
15 (August 23, 2002). Because, moreover, the Secretary's
privacy regulations now narrowly define what constitutes
“marketing,” even the regulatory promise that covered
entities must obtain prior patient authorization before~
using patient health information or disclosing it for
commercial purposes often proves illusory in practice. 45
C.F.R. §§ 164.501, 164.508(a)(3); Health Care Records: Books
Open to Abuse, TRIAL, 42 (October 2002) (“Not only do the
changes define marketing in a very troubling way, but
they also remove some safeguards that were in the
regulation.”). Whatever the merits of these sweeping
decisions by the Secretary for when patient consent is not
required for disclosure of quintessentially private medical
information, Congress provided no guidance, let alone an
intelligible principle, to guide the Secretary’s lawmaking.
Finally, regulatory compliance, which is just now
beginning, is requiring hundreds of thousands of large
29
and small medical providers to make major changes in the
way they provide their services. Based on the Secretary’s
own analysis, “[t]here are approximately 12,200 health
plans * * *, 6480 hospitals, and 630,000 non-hospital
providers that will bear implementation costs under the
final rule.” 65 Fed. Reg. 82765. That includes 562,916
“small health care entities,” including, nonprofit health
plans, small physician practices, small businesses
providing health coverage, aid pharmacies. Id. at 82779.
The health care industry in the United States currently
amounts to more than 13 percent of the nation’s economic
output. Literally billions of dollars of investments will be
necessary for compliance, especially in the first few years
of the privacy standard’s legal effectiveness. By the
Secretary’s own calculations, “[t]he estimated cost of
compliance with the final rule is $ 17.6 billion over the ten
year period, 2003-2012.” 65 Fed. Reg. 82760." Other
estimates predict costs as high as $40 billion for that same
time period. Whatever the ultimate tally, the dollar
amount will plainly not only be in the billions, but, even
more importantly, will be merely a reflection of the
extraordinarily far-reaching changes in individual
behavior that the medical privacy standards will require,
only a fraction of which were likely contemplated.”
"' Based on subsequent modifications, the Secretary has reduced the
estimated cost’ of compliance with the privacy standards by $100
million over ten years. 67 Fed. Reg. 53182, 53259 (2002).
* For instance, clergy have learned that their visits to hospitals to
counsel ill patients are now severely restricted. Ann Rodgers-
Melnick, Privacy Rules May Limit Clergy Hospital Visits, Post-Gazette,
http:/ / www.post-gazette.com/healthscience/ 20030228hospitals4.asp
(visited June 11, 2003). Ina letter to the Secretary dated November 20,
2001, approximately 200 organizations and individuals, including the
Association of American Medical Colleges, American Psychological
Society, American Hospital Association, and virtually every major
——
30
CONCLUSION
The petition for a writ of certiorari should be granted.
Respectfully submitted.
July 2003
TERRY E. RICHARDSON, JR.*
DANIEL S. HALTIWANGER
RICHARDSON, PATRICK, WESTBROOK &
BRICKMAN
P.O. Box 1368
BARNWELL, SOUTH CAROLINA 29812
(803) 541-7850
RICHARD J. LAZARUS
GEORGETOWN UNIVERSITY
LAW CENTER
600 NEW JERSEY AVE., N.W.
WASHINGTON, D.C. 20001
(202) 662-9129
Counsel for Petitioners
* Counsel of Record
medical research facility in the nation, voiced their “ serious concerns”
regarding the Secretary’s December 2000 final rules, including how
the rules would “seriously impair” research. See Ass’n of American
Medical Colleges, http:// www.aamc.org/ advocacy /library/hipaa
/corres/2001/112001.htm (visited 6/11/03). Although the Secretary
has since modified the rules in some limited respects in response to
the medical research community’s concerns, the existence of such
correspondence underscores both the practical importance of the legal
issues presented and the constitutional impropriety of the Secretary’s -
assertion of exclusive lawmaking authority over medical privacy
standards in derogation of the Constitution’s deliberate design.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.