Petition for Writ of Certiorari — South Carolina Medical Ass'n v. Thompson

Supreme Court brief2003

Ask Donna

What actually matters in this document.

Text

OM. 0314 Jut 2 | 2003

ICE OF THE CLERK

Tu he

Supreme Court of the Gnited States

¢

SOUTH CAROLINA MEDICAL ASSOCIATION, et ai.,

Petitioners,

Vv.

TOMMY G. THOMPSON, SECRETARY OF THE

U.S. DEPARTMENT OF HEALTH AND

HUMAN SERVICES, et al.,

Respondents.

¢

On Petition For A Writ Of Certiorari

To The United States Court Of Appeals

For The Fourth Circuit

PETITION FOR A WRIT OF CERTIORARI

¢

TERRY E. RICHARDSON, JR.*

DANIEL S. HALTIWANGER

RICHARDSON, PATRICK, WESTBROOK

& BRICKMAN

P.O. Box 1368

Barnwell, South Carolina 29812

(803) 541-7850

RICHARD J. LAZARUS

GEORGETOWN UNIVERSITY LAW

CENTER

600 New Jersey Ave., N.W.

Washington, D.C. 20001

(202) 662-9129

Counsel for Petitioners

* Counsel of Record

QUESTIONS PRESENTED

Section 264(c)(1) of the Health Insurance Portability

and Accountability Act of 1996 (HIPAA), 42 US.C. §

1320d-2 note(c)(1), mandates that the Secretary of Health

and Human Services (Secretary) promulgate standards

governing “the privacy of individually identifiable health

information transmitted in connection with” specified

transactions in the event that Congress failed to enact

“legislation governing [such] standards” within three

years of HIPAA’s enactment. The questions presented are:

1. Whether Article I, § 1 of the-U.S. Constitution, which

vests legislative power exclusively in Congress, bars

Congress in HIPAA from transferring to the Secretary the

legislative authority to enact medical privacy standards if,

after three years, Congress is unable to enact those

standards itself because they are too controversial.

2. Whether the Secretary’s medical privacy standards

are unlawful because they apply to all forms of

individually identifiable health information and therefore

exceed the scope of rulemaking authority conferred by

Congress in HIPAA, which expressly limits the application

of the Secretary’s privacy standards to such identifiable

health information only when “transmitted in connection

with” nine statutorily specified electronic transactions.

(i) :

PARTIES TO THE PROCEEDING

The South Carolina Medical Association, Physicians

Care Network, J. Capers Hiott, M.D., John R. Ross, M.D.,

Gordon E. Pennebaker, M.D., Carol S. Nichols, M.D.,

Dannette F. McAlheny, M.D., Herbert Moskow, M.D., and

the Louisiana State Medical Society were all appellants in

the Fourth Circuit below. Tommy G. Thompson, in his -

official capacity as Secretary of Health and Human

Services, and the United States Department of Health and

Human Services were appellees below.

—

(ii)

5 cama amma

TABLE OF CONTENTS

Page

Questions Presented .........---- essere ee ee eerie i

Parties to the Proceedings ...........+seesseeeeeees li

Opinions Below .......--.:.seeeee eee erent 1

Jurisdiction ........ 0c cece cence see nereneneeeees 2

Constitutional, Statutory, and Regulatory

Provisions Involved .........:ee eee eee eee eeeees 2

ee te 2

NE EN PO re eee rere ee eee 4

Reasons for Granting the Writ .......-----+sseee ees 9

I. Review of the Nondelegation

Doctrine Issue Is Warranted .........-. 10

II. Review of the Legality of the Scope

of the Secretary’s Medical Privacy

Standards Is Also Warranted ......... 20

Ill. | Review Is Warranted in this Case ..... 26

ee ST eee eee 30

Appendices ..........-. sees eeeeeeeeeeeececess Al

(iii)

TABLE OF AUTHORITIES

Cases:

Chevron U.S.A. Inc. v. Natural Resources Defense Council,

ig Sr I BE CEE hae ec nce hewer id eusk vows 20

Clinton v. City of New York, 524 U.S. 417 (1998) .... 14, 26

ETSI Pipeline Project v. Missouri, 484 U.S. 495 (1988) .. 26

Ferguson v. City of Charleston, 532 U.S. 67 (2001) ..... 28

Food & Drug Administration v. Brown & Williamson,

See Ni RAPED cncceenstaswens Perrer 20-21, 26

Immigration and Naturalization Service v. Chadha,

oS | er nr rer rere 14

Industrial Union Dept. v. American Petroleum Institute,

a gt eee ee eee ere rere 14

].W. Hampton, Jr. & Co. v. United States,

SO ER hooey eb enenseeven tee nes 11

Loving v. United States, 517 U.S. 748 (1996) .......... 18

Mistretta v. United States, 488 U.S. 361 (1989) ........ 18

Panama Refining Co. v. Ryan, 293 U.S. 388 (1935) .. 11,17

Touby v. United States, 500 U.S. 160 (1991) .......... 18

Whitman v. American Trucking Ass‘n,

eR gy | 10-11, 15, 17-18

Constitution, Statutes, and Regulations:

Chae SP IE sere tbaree ee vesece sean 3,9, 10

Clean Air Act, 42 U.S.C. §§ 7407-7409 ........... 17-18

28 U.S.C.

DE Kec naeenvcaurex tee dnesseeanekaeiE cies 8

De OTE Oe. Oe ee er ene Pee 8

DRE. ks texeGhbeehakedneb cia) eae ae 8

Health Insurance Portability and Accountability

Act of 1996, Pub. L. No. 104-191, 110 Stat.

fe BOT Tee Tre rere passim

Constitution, Statutes, Regulations (continued):

- Serrererrer ree ce ee 4,17, 24

Sf | Seer reer er err Te 5, 6, 21, 22

fb Seeerrrerer ret erry rer TT 16-17, 19, 21

y errrerrer Terr rr re 6, 21, 22, 24

fs Pee errr peer T errr ere rr ce passim

Social Security Act, Title XI

iy hss te &: | errr ren y se 5, 24

© TE7R, Se UDA... BURRS 6 ccc recccncsescanccts 2

eee Roe a oy eee 5, 6, 24

§ 1173(a), 42 U.S.C. § 1320d-2(a)(1) .......... passim

§ 1174 - §1179, 42 U.S.C. § 1320d-3 tod-8 ......... 5

45 C.F.R. (2003)

DS EE hi vawkcteeecccsmeneseerenueeee 7,21

DL. ch cde ind bk caeeeen ee eee cent ieeeee 28

De i bik keds here ae s0 rere eee 28

foot Peer errr ey parr rrr sre. 28

bt: Serer eee e rir err re 28

Miscellaneous:

Ass’n of American Medical Colleges, http://www.

aamc.org/advocacy/library/hipaa/corres

Peo tgey 8 eer errr ree eT rT ree 29-30

Confidentiality of Individually Identifiable Health

Information, Hearing before the Sen. Comm. on

Labor and Human Resources, 106" Cong., 2d

GN CIPOE ne kee eeestnkesedeserenaus ee enins 13

Confidentiality of Medical Information, Hearing before

the Senate Comm. on Health, Education, Labor

and Pensions, 107" Cong., 1* Sess. (1999) ....... 13

Confidentiality of Patient Records, Hearing before the

Subcomm. on Health of the House of

Representatives Ways & Means Comm., 107

(v)

Miscellaneous (continued):

oe me | RPRRETETT TET ORT ee 13

EOS COME, BEC. SOI GE bcc ces cceccencesduvers 13

The Consumer Protection and Medical Confidentiality Act

of 1998, Hearing before the Subcomm. on

Government Management, Information and

Technology of the House of Representatives

Comm. on Government Reform and Oversight,

106” Cong, 2d Seas. (2998)... ns ccccvescenvenss 13

63 Fed. Reg. (1998)

DY Seer, reer rere eee rT 6

ere rere errr Te yee see Te TS 6

Ri, | MPEP ETETRTETTE ee rete ee ey 6

SG kA apace UN Sah nccetaeseeeaee eee eeeas 7

64 Fed. Reg. (1999)

Sere PPE eT TT Tee TT TT ere re 7

SS 6 MPOTERETeTT CTT etree er 22

GUUEE oc kcntaeoeesevhens catdpeeayeteneee 7, 24

GEE. check een cece suceess bates OR RREED 23-24

GUO sa acincycsvscvveesescetneseeeeeee 22-23

65 Fed. Reg. (2000)

DEE ar enke Sve cdiveuenetepenebeaereak ee 6, 23

D PPEe Sv ivewenn eae aseesasakakes Meee neeeeee 23

S| eee eT Teer ee re ee 7

Sh MPLETTEE RCL Tee te ee 5

TOUS scene ever seeewbieebasebauneeeeyaeee 27

OT vs ceneee Ney kaw eke neon ee eke ous Rane 27

GE 60400 scieued ened hese onan’ eee 7,25

| TET T TT Tee ee ee 27

Re vv esebeedscaree eeieeaeesaeen ee eee 7

|. MUTEEST ETRE CT eee ee ee 25

PE vvcccvacyd eee enneteeeerbeerunee ed 29

So Been rrere rere yi reer rere re 10, 29

DPE “on cescenscuaveulelabeseheneouean 10, 29

i alii ai iii = —

Miscellaneous (continued):

66 Fed. Reg. (2001)

EE Sia can Co Csheceveseeneutateeeneteatews 8

DERG cevwscersonnentessrececesceceaneosexs 8

67 Fed. Reg. (2002)

GE Seow eM ise nreenenenaetayso0 bevene es 8, 29

SE. a Rds ce dene eweeeuceneshasereenes 28

EE. cc ochevevessseusecntesssancengns 28

cas evecdcou hous eesatboaseeuer exeanews 29

68 Fed. Reg. (2003)

SS Seer Tree TT re rT ere TT ee 6, 23

5 QPPereververri rec Terr srr er er rrr Te 6, 23

Lawrence O. Gostin, Health Information Privacy, 80

Commedl L Rev. GSE (IPI) nosis cs cccessccvess 11-12

Lawrence O. Gostin & Tames G. Hodges, Jr.,

Personal Privacy and Common Goods: A

Framework for Balancing Under National

Health Information Privacy Rule, 86 Minn. L.

fg re Aree errr err rr 11

H.R. 1057, Medical Information Privacy and Security Act,

Se Cn FI EE ig oi cvdcescvcnceases 12

H.R. 1941, Health Information Privacy Act of 1999, 106"

ee Berets sere ree 12

H.R. 2404, Personal Medical Information Protection Act of

1999, 106" Cong., 1" Sess. (1999) ............... 12

H.R. 2878, Medical Privacy in the Age of New Technologies

Act of 1999, 106" Cong., 1* Sess. (1999) .......... 12

Health Care Records: Books Open to Abuse, TRIAL, 42

errr ry erry Pree pr tore 28

Medical Records Confidentiality in the Modern Delivery of

Health Care, Hearing before the Health and

Environment Subcomm. of the House of

Representatives Comm. on Commerce, 107"

Cs FU MOO vac oer as isnt sussescaxeass

_—

Miscellaneous (continued):

Patient Confidentiality, Hearing before the Subcomm. on

Health of the House of Representatives Ways &

Means Comm., 106" Cong., 2d Sess. (1998) ...... 13

Ann Rodgers-Melnick, Privacy Rules May Limit Clergy

Hospital Visits, Post-Gazette, http:/ / www.post-

-gazette.com/healthscience/20030228hospitals4.asp

CVORINRG, FUND TD, BOD secs scccccsssesesseesces 29

S. 573, Medical Information Privacy and Security Act of

1999, 106" Cong., 1* Sess. (1999) ............05. 12

S. 578, Health Care Personal Information Nondisclosure Act

of 1999, 106" Cong., 1* Sess. (1999) ............. 12

S. 881, Medical Information Protection Act of 1999, 106"

CR, Ks PPE hace Ru kecebscnenuseenecis 12

S. 1360, Medical Records Confidentiality Act, 104" Cong.,

PGE. Aa Waa Paine creksanakenceakees 12

S. 1368, Medical Information Privacy and Security Act,

gg a re eee re 12

S. 2129, Health Care Privacy Protection Act, 103" Cong.,

ND 66455) ceeeansiwesknceecaeee ious 12

S. 2352, Patient Privacy Rights Act of 1998, 105" Cong.,

PL NOE 0 hey soeadeeakesst eee 12

S. 2609, Medical Information Protection Act of 1998, 105"

Cy Ae SIO ones ctwncbecwsavistestes 12

Charity Scott, Is Too Much Privacy Bad for your Health?

An Introduction to the Law, Ethics, and HIPAA

Rule on Medical Privacy, 17 Ga. St. U. L. Rev. 481

PE -velscvscseuvassbivrahenceeo ee kee Cee nens 12

Richard Sobel, A New Wound to Medical Privacy -

Administration Rules Eviscerate Patient Consent,

L.A. Times 15 (August 23, 2002) ............... 28

(viii)

In the %

Supreme Court of the United States

No. 03-

SOUTH CAROLINA MEDICAL ASSOCIATION, ef al.,

Petitioners,

Vv.

TOMMY G. THOMPSON, SECRETARY OF THE U.S. DEPARTMENT

OF HEALTH AND HUMAN SERVICES, et al.,

Respondents.

On Petition for a Writ of Certiorari to

the United States Court of Appeals for the Fourth Circuit

PETITION FOR A WRIT OF CERTIORARI

Petitioners, South Carolina Medical Association, Physicians

Care Network, J. Capers Hiott, M.D., John R. Ross, M.D.,

Gordon E. Pennebaker, M.D., Carol S. Nichols, M.D., Dannette

F. McAlheny, M.D., Herbert Moskow, M.D., and the Louisiana

State Medical Society, respectfully petition this Court for a

writ of certiorari to review the judgment of the United

States Court of Appeals for the Fourth Circuit in this case.

OPINIONS BELOW

The opinion of the Fourth Circuit is reported at 327

F.3d 346 and reproduced in the appendix hereto (“App.”)

at Al. The opinion of the district court is unreported and

is reproduced at App. A18.

2

JURISDICTION

The judgment of the Fourth Circuit was entered on

April 25, 2003. App. Al. This Court has jurisdiction to

issue the requested writ of certiorari pursuant t9 28 U.S.C.

§ 1254(1).

CONSTITUTIONAL, STATUTORY,

AND REGULATORY PROVISIONS INVOLVED

Article 1, § 1, of the U.S. Constitution, is reproduced at

App. A42. Sections 261, 262, and 264 of the Health

Insurance Portability and Accountability Act of 1996, Pub.

L. No. 104-191, 110 Stat. 1936, 2021, 2034 (1996), codified at

42 U.S.C. §§ 1320d through 1320d-8, and §§ 1320d note,

1320d-2 note, are reproduced at App. A42-A62. The

Secretary’s definition of “ protected health information,” 45

C.F.R. § 160.103 (2003), is reproduced at App. A62-A63.

INTRODUCTION

During the 1990s, Congress repeatedly struggled to

address acontroversy of enormous importance to millions

of Americans: the extent to which their personal medical

records should be deemed private and not subject to

disclosure without their permission. The issue became

especially pressing during that decade because of then-

rising demands for disclosure of such medical records by

private and public entities who, relying on the potential

ease of electronic transmissions, contended they could

beneficially use the records to further important public

purposes, including safeguarding public health,

promoting medical research, reducing medical costs,

enhancing accountability, investigating fraud, and

assisting law enforcement.

Because, however, of fundamental conflicts regarding

how the balance should be struck between personal

privacy and these other competing social policy objectives,

3

Congress was unable to enact any legislation that

announced standards governing the possible disclosure of

personal medical records. In session after session,

members of Congress introduced bills, committees held

hearings, but the necessary compromises proved elusive.

Congress ultimately chose to break the legislative

logjam, but did so in a patently unconstitutional manner

that has set a dangerous legislative precedent that

warrants this Court’s plenary review. In the Health

Insurance Portability and Accountability Act of 1996

(HIPAA), Pub. L. No. 104-191, 110 Stat. 1936 (1996),

Congress effectively imposed on itself a three-year

deadline to enact standards governing medical privacy.

Congress made that deadline enforceable by mandating

that the Secretary of Health and Human Services

(Secretary) promulgate medical privacy standards for

certain transactions in the event that Congress failed to

meet its own deadline. In short, Congress sought by

HIPAA’s express terms and deliberate design to

accomplish precisely what Article I, § 1 of the US.

Constitution provides cannot be done: transfer to the

executive branch the authority to enact legislation in the

event that the democratic legislative processes failed to

produce a result.

The medical privacy standards since promulgated by

the Secretary, moreover, underscore the constitutional

pitfalls of Congress’s misguided abdication of legislative

responsibility. Although HIPAA made absolutely no

effort to provide any intelligible principle to guide the

Secretary’s decision concerning how the difficult policy

balance should be struck in the fashioning of federal

medical privacy standards, HIPAA at least limited the

Secretary’s legislative purview to a series of specifically-

listed electronic transactions of medical records. The

Secretary’s final regulations, however, even abandoned

4

that statutory bound, concluding that public policy

warranted medical privacy standards no matter what their

form or their method of transmission. The Secretary,

therefore, made even more complete Congress’s

unconstitutional delegation of legislative authority to the

executive branch by wholly untethering the rulemaking

from even the most limited congressional guideposts. The

regulatory upshot is a medical privacy regulation that

portends revolutionary changes in the medical profession

and the privacy of American citizens, which requires

expenditures of billions of dollars for compliance and

which authorizes widespread disclosure of private

medical information in the absence of patient consent.

Petitioners, the South Carolina Medical Association,

Louisiana Medical Society, and six individual doctors filed

in federal district court a lawsuit challenging the

constitutionality of HIPAA’s delegation of legislative

authority to the Secretary and the legality of the

Secretary’s medical privacy standards. The district court

dismissed the lawsuit and the court of appeals affirmed.

STATEMENT

Statutory and Regulatory Background. In 1996,

Congress passed HIPAA. The purpose of Subtitle F of

HIPAA, entitled “ Administrative Simplification,” was “to

improve the Medicare program ***, the Medicaid program

*** and the efficiency and effectiveness of the health care

system, by encouraging the development of a health

information system through the establishment of

standards and requirements for the electronic transmission

of certain health information.” HIPAA, § 261, 110 Stat.

2021; 42 U.S.C. § 1320d note. Prior to HIPAA’s enactment,

there were as many as 400 different electronic formats

being used for health care forms, resulting in gross

inefficiencies. Subpart F sought to create one uniform

5

language for electronic transmission of standard health

insurance information. See 65 Fed. Reg. 82463 (2000).

To that end, Section 262 of HIPAA added a new Part C,

also entitled “ Administrative Simplification,” to Title XI of

the Social Security Act. See 110 Stat. 2021-2031. Part C in

turn included nine separate statutory provisions, Sections

1171-1179, which, inter alia, defined the relevant statutory

terms (Section 1171), established requirements for the

adoption of standards (Section 1172), described the

relevant standards to be promulgated (Section 1173), and

established relevant timetables, enforcement programs,

and federal preemption policies. (Sections 1174-1179). See

42 U.S.C. §§ 1320d - 1320d-8.

Of particular relevance to the instant case, Section

1173(a) empowered the Secretary to adopt “standards for

transactions, and data elements for such transactions, to

enable health information to be exchanged electronically.”

See 42 U.S.C. § 1320d-2(a)(1). Section 1173(a) further

listed nine different specific electronic transactions to

which the Secretary’s standards would apply.’

HIPAA also reflected congressional awareness of the

substantial personal privacy implications of enabling

electronic transmissions of medical records.

Standardization of the features of medical records kept in

electronic form necessarily made their disclosure that

much easier and the need for privacy standards that much

more pressing. At the time of HIPAA’s enactment,

' The listed transactions include:

(A) Health claims or equivalent encounter information. (B) Health

claims attachments. (C) Enrollment and disenrollment in a health

plan. (D) Eligibility for a health plan. (E) Health care payment

and remittance advice. (F) Health plan premium payments. (G)

First report of injury. (H) Health claim status. (I) Referral

certification and authorization.

42 U.S.C. § 1320d-2.

6

Congress had tried for several years, without success, to

enact applicable medical privacy standards. Legislators

were unable to forge the necessary compromises between

privacy advocates and those seeking greater disclosure of

medical records. See pages 11-14, infra.

To break the legislative deadlock and to ensure that

some standards would be in existence by the time that the ~

Secretary’s regulations designed to enable electronic

transmission of medical records became effective, Section

264(a) of HIPAA instructed the Secretary to provide

Congress within one year “detailed recommendations on

standards with respect to the privacy of individually

identifiable health information.” 110 Stat. 2033; 42 U.S.C.

§ 1320d-2 note(a). Section 264(c) further provided that if

Congress failed within three years to enact standards

“with respect to the privacy of individually identifiable

health information transmitted in connection with the

transactions described in section 1173(a) of the Social

Security Act (as added by [HIPAA] section 262),” then the

Secretary “shall promulgate final regulations containing

such standards.” 110Stat. 2033; 42 U.S.C. § 1320d-2note(c).

The Secretary’s Rulemakings. Pursuant to Section

1173 of the Social Security Act, as added by Section 262 of

HIPAA, the Secretary has since issued proposed and final

rules intended to facilitate the electronic transmission of

medical records by standardizing their format and other

features. The Secretary has confined the scope of each of

these rulemakings to the nine transactions specifically

listed in Section 1173. See, e.g., Health Insurance Reform:

Security Standards, 68 Fed. Reg. 8334, 8342 (2003); Health

Insurance Reform: Standards: 65 Fed. Reg 50312 (2000);

Health Insurance Reform: Standards for Electronic

Transactions, 63 Fed. Reg. 25272, 25320 (1998); Health

Insurance Reform: National Standard Employer Identifier,

63 Fed. Reg. 32784 (1998); Security and Electronic

7

Signature Standards, 63 Fed. Reg. 43242 (1998).

The Secretary did not, however, likewise confine the

medical privacy standards challenged in this litigation

either to the nine transactions listed in Section 1173(a) or

to their electronic transmission. In the December 2000

final rulemaking, the Secretary decided to “expand the

definition of protected health information to encompass all

individually identifiable health information transmitted or

maintained by a covered entity, regardless of form.” 65

Fed. Reg. 82462, 82496 (2000); see 65 Fed. Reg. 82618

(2000); 45 C.F.R. § 160.103 (2003) (“transmitted or

maintained in any * * * form or medium”).

The final regulations, in this respect, departed

significantly from the Secretary’s proposed regulations. In

the proposed rulemaking, “only those providers who

engage in the electronic administrative simplification

transactions [were] covered * * *. Any provider who

maintains a solely paper information system would not be

subject to these privacy standards.” 64 Fed. Reg. 59918,

99923 (1999). While the rulemaking commentary

accompanying that far more limited proposal asserted that

the Secretary possessed more authority than exercised in

the proposed rules, the Secretary acknowledged that “the

HIPAA legislative authority is more limited in scope * * *

and does not always permit us to propose the policies that

we believe are optimal.” Id. According to the Secretary,

“the HIPAA limits the application of our proposed rule to

health plans, health care clearinghouses, and to any health

care provider who transmits health information in

electronic form in connection with transactions referred to

in section 1173(a)(1) of the [Social Security] Act.” Id.

(emphasis added).’

> The Secretary has undertaken several subsequent administrative

actions extending the effectiveness and compliance dates of the

December 2000 privacy standards and has also modified the

8

Proceedings Below. Petitioners, two state medical

associations, a network c health care providers, and six

physicians, filed a complai:.: in federal district court, based

on the Constitution, 28 U.S.C. §§ 1331, 1337, 2201,

challenging the constitutionality of HIPAA’s delegation of

lawmaking authority to the Secretary and to the legality of

the Secretary’s privacy standards under HIPAA.

Petitioners contended that HIPAA violated the

nondelegation doctrine by conferring legislative authority

on the Secretary. Petitioners further alleged that the

privacy standards exceeded the scope of the Secretary’s

statutory authority by extending those standards to all

personal medical records whatever their form or method

of transmission, including both paper and electronic.

The district court dismissed the complaint. App. A18.

The court ruled that HIPAA provided a sufficient

limitation on the Secretary’s discretion to avoid offending

nondelegation doctrine concerns. Id. at A26-A29. The

district court also rejected petitioners’ second contention

upon concluding that the plain meaning of HIPAA

supported the Secretary’s interpretation that the statute

authorized promulgation of medical privacy standards

applicable to all personal medical records. Id. at A29-A32.

The court of appeals affirmed. App. Al. On the

nondelegation issue, the court concluded that HIPAA

announced a “general policy” that guided the Secretary’s

lawmaking authority to an extent sufficient to satisfy the

nondelegation doctrine and that Congress had effectively

agreed to the standards by default -- by not enacting

legislation that formally objected to. the Secretary’s

recommendations. Id. at A8-A11. With regard to the

scope of the Secretary’s lawmaking authority under

standards in some respects not relevant to the issues raised in this

case. See 66 Fed. Reg. 12434 (2001); 66 Fed. Reg. 12738 (2001); 67 Fed.

Reg. 53182 (2002).

PR 5 weed

9

HIPAA, the appellate court further held that “the plain

language of HIPAA indicates that HHS could reasonably

determine that the regulation of individually identifiable

health information should include non-electronic forms of

that information.” Id. at A12-A13.

REASONS FOR GRANTING THE WRIT

This petition presents two legal issues warranting this

Court’s review. First, the Secretary of HHS promulgated

medical privacy regulations pursuant to an improper

congressional transfer to the Secretary of legislative

lawmaking authority that violates Article 1, § 1, of the

United States Constitution. By deliberate congressional

design, HIPAA assigns to the Secretary the exclusive

responsibility of legislating by rulemaking medical privacy

standards in the event that Congress is unable to enact

such standards within three years. The Constitution does

not countenance such a blatant reallocation of legislative

authority to the executive branch whenever Congress

concludes that a policy matter of fundamental importance

to millions of Americans and the health care profession is

too difficult and controversial for Congress to handle.

Second, in subsequently promulgating medical privacy

standards, the Secretary ignored the only clear guidance

that Congress did provide in HIPAA, which was to restrict

the scope of the privacy standards to electronic

transmissions associated with nine statutorily-listed

transactions. The Secretary thereby exceeded the scope of

the delegation of authority Congress intended to confer.

This second error not only provides an independent legal

error warranting invalidation of the regulations, but also

further underscores HIPAA’s violation of the

nondelegation doctrine. If, as the Secretary claims, HIPAA

does provide the Secretary with authority to extend its

10

medical privacy regulations essentially to all medical

records, then sucha massive delegation would have made

it all the more necessary that it be accompanied by the

constitutionally required “intelligible principle” sufficient

to guide the Secretary’s exercise of such lawmaking

authority. Here, however, there was none.

Review is warranted even though the court of appeals

below is the first to consider the constitutionality of

HIPAA and the lawfulness of the Secretary’s medical

privacy standards. The extraordinary breadth and depth

of those standards implicate the core personal autonomy

and privacy rights of millions of Americans and they are

at this moment requiring hundreds of thousands of health

care providers to change dramatically their services, at a

cost of billions of dollars. By the Secretary’s own

accounting, the regulations directly apply to 12,200 health

plans, 6480 hospitals, and 630,000 non-hospital providers,

including 562,916 small businesses and_ individual

physicians. 65 Fed. Reg. 82765, 82779 (2000). Although

invariably touted as promoting patient privacy, the

Secretary's regulations in fact authorize disclosure of

historically confidential patient information ina variety of

circumstances, including to government officials without

a warrant, and without the patient’s consent. In such

extreme circumstances, prudence justifies the Court’s

departing from its normal practice of delaying review for

several years .. allow further lower court litigation. The

petition should instead be granted.

I. REVIEW OF THE NONDELEGATION

DOCTRINE ISSUE IS WARRANTED

“In a delegation challenge, the constitutional question

is whether the statute has delegated legislative power to

the agency. Article I, § 1 of the Constitution * * * permits

no delegation of those powers.” Whitman v. American

;

2

‘

;

J

.

*

x

%

"]

3

‘

3

:

$

11

Trucking Ass’n, 531 U.S. 457, 472 (2001). “Congress

manifestly is not permitted to abdicate, or to transfer to

others, the essential legislative functions with which it is

thus vested.” Panama Refining Co. v. Ryan, 293 U.S. 388,

421 (1935). This Court has, accordingly, repeatedly held

“that when Congress confers decisionmaking authority

upon agencies Congress must ‘lay down by legislative act

an intelligible principle to which the person or body

4%

authorized to [act] is directed to conform’” American

Trucking Ass’n, 531 U.S. at 472, quoting J. W. Hampton,

Jr., & Co. v. United States, 276 U.S. 394, 409 (1928).

In HIPAA, Congress blatantly abdicated its legislative

authority in violation of the nondelegation doctrine.

HIPAA Section 264(c) expressly instructed the Secretary to

promulgate medical privacy standards in the event that

Congress proved unable to meet its own deadline for

doing so. Hence, Congress expressly predicated its

transfer of legislative responsibility to the Secretary on

Congress’s failure to pass legislation that might, at the

very least, have provided the Secretary with the

“intelligible principle’ required to render such an

allocation of lawmaking authority constitutional.

The reasons for Congress’s abdication of legislative

responsibility are plain. Determining what factors should

be relevant to the fashioning of medical privacy standards

and their relative weight in the balancing necessary for

their application is complex and controversial. Lawrence

O. Gostin, James G. Hodges, Jr., Personal Privacy and

Common Goods: A Framework for Balancing Under National

Health Information Privacy Rule, 86 Minn. L. Rev. 1439, 1454

(2002). “Hard choices” must be made in deciding whether

we should “sharply limit the systematic collection of

identifiable health care data in order to achieve reasonable

levels of informational privacy” or “decide that the value

of information collection is so important to the

12

achievement of societal aspirations for health that the law

ought not promise absolute or even significant levels of

privacy at all * **.” Lawrence O. Gostin, Health Information

Privacy, 80 Cornell L. Rev. 451, 455 (1995).

What happened prior to and in the aftermath of

HIPAA’s enactment is that the hard choices presented by

fashioning medical privacy standards became a “ political

hot potato” that Congress preferred to toss to the

Secretary. Charity Scott, Js Too Much Privacy Bad for your

Health? An Introduction to the Law, Ethics, and HIPAA Rule on

Medical Privacy, 17 Ga. St. U. L. Rev. 481, 481 (2000).

“[V]arious competing interests and starkly different views

over where we should strike the appropriate ethical

balance * * * stymied all efforts to pass such federal

legislation.” Id. at 505. “About a half dozen policy

questions * * * apparently prove[d] intractable in the

congressional debates.” Id. at 513.

Inthe months just before the HIPAA deadline, multiple

bills were pending in the House’ and Senate,* with

> See H.R. 1057, Medical Information Privacy and Security Act, 106"

Cong., 1" Sess. (1999); H.R. 1941, Health Information Privacy Act of

1999, 106" Cong., 1 Sess. (1999); H.R. 2404, Personal Medical

Information Protection Act of 1999, 106" Cong., 1* Sess. (1999); H.R.

2878, Medical Privacy in the Age of New Technologies Act of 1999,

106" Cong., 1* Sess. (1999).

* S.573, Medical Information Privacy and Security Act of 1999, 106"

Cong., 1" Sess. (1999); S. 578, Health Care Personal Information

Nondisclosure Act of 1999, 106" Cong., 1* Sess. (1999); S. 881, Medical

Information Protection Act of 1999, 106" Cong., 1* Sess. (1999); see

also S. 2129, Health Care Privacy Protection Act, 103% Cong., 2d Sess.

(1994); S. 1360, Medical Records Confidentiality Act, 104" Cong., 1*

Sess. (1995); S. 1368, Medical Information Privacy and Security Act,

105" Cong., 1* Sess. (1997); S. 2352. Patient Privacy Rights Act of 1998,

105" Cong., 2d Sess. (1998); S. 2609, Medical Information Protection

Act of 1998, 105" Cong., 2d Sess. (1998);

Ks hich aS CLs Racers Cree S

13

extensive hearings held in both chambers.’ None passed.

As later described by Senator Patrick Leahy, a major

sponsor of pending legislation, “We couldn't do the job on

our own and we have instead shifted the responsibility to

the administration.” 146 Cong. Rec. S 6186 (2000).° Then-

Secretary Donna Shalala similarly described the

relationship between Congress and the executive branch

in her press conference announcing her medical privacy

standards: “Congress tried to write these regulations and they

actually couldn’t get it done, they couldn’t find a consensus to

get it finished.” J.A. 272 (emphasis added).’ Finally, in

announcing the Secretary’s proposed medical privacy

standards, President Clinton likewise commented that the

° See, e.g., Confidentiality of Individually Identifiable Health Information,

Hearing before the Sen. Comm. on Labor and Human Resources,

106" Cong., 2d Sess. (198); Patient Confidentiality, Hearing before the

Subcomm. on Health of the House of Representatives Ways & Means

Comm., 106" Cong., 2d Sess. (1998); The Consumer Protection and

Medical Confidentiality Act of 1998, Hearing before the Subcomm. on

Government Management, Information and Technology of the House

of Representatives Comm. on Government Reform and Oversight,

106" Cong., 2d Sess. (1998); Confidentiality of Medica! !:formation,

Hearing before the Senate Comm. on Health, Education, Labor and

Pensions, 107 Cong., 1* Sess. (1999); Medical Records Confidentiality in

the Modern Delivery of Health Care, Hearing before the Health and

Environment Subcomm. of the House of Representatives Comm. on

Commerce, 107" Cong., 1* Sess. (1999); Confidentiality of Patient

Records, Hearing before the Subcomm. on Health of the House of

Representatives Ways & Means Comm., 107" Cong., 2d Sess. (2000).

* But the Senator simultaneously acknowledged the impropriety of

such a shift: “This Congress has the responsibility to protect the

privacy of Americans - and that includes protection of their medical

records. The place for these protections is in legislation - not

regulation.” 146 Cong. Rec. S 6186; see id. at E 2307 (remarks of Rep.

Condit) (“Congress failed to act on this crucial issue.”).

” “J.A.” refers to the joint appendix filed in the court of appeals.

14

reason for executive branch action was congressional

default. See J.A. 261 (“I am taking this action today

because Congress failed to act, and because a few years

ago Congress explicitly gave me the authority to step in if

they were unabie to deal with this issue.”).

Political convenience was therefore clearly the motive

for congressional abdication in HIPAA, but it is equally

clear that “the fact that a given law or procedure is

efficient, convenient, and useful in facilitating functions of

government, standing alone, will not save it if it is

contrary to the Constitution.” Immigration and

Naturalization Service v. Chadha, 462 U.S. 919, 944 (1983).

“[P]olicy arguments supporting even useful ‘political

inventions’ are subject to the demands of the Constitution

which defines powers and * * * sets out just how those

powers are to be exercised.” Id. at 945. “That a

congressional cession of power is voluntary does not make

it innocuous. * * * Abdication of responsibility is not part

of the constitutional design.” Clinton v. City of New York,

524 U.S. 417, 452 (1998) (Kennedy, J., concurring). Where

there are “hard choices” to be made, and where issues are

“politically so divisive that the necessary decision or

compromise [is] difficult, if not impossible, to hammer out

in the legislative forge,” it is that much more, not less,

important under our Constitution that the decisions are

ultimately “made by the elected representatives of the

people * * * [and] the buck stops with Congress.”

Industrial Union Dept. v. American Petroleum Institute,

448 U.S. 607, 687 (1980) (Rehnquist, J., concurring).

Nor is there any merit to the court of appeals’

conclusion (App. A8) that HIPAA otherwise provided the

“intelligible principle” necessary to convert an improper

delegation of legislative responsibility into a constitutional

assignment of executive branch rulemaking authority

pursuant to a federal statute. HIPAA provides no such

plitinaiixs MAS tnt 2 eM Th 2

ew tel

Si Le ett Cs DC ts Bt

15

“intelligible principle.” To constitute an intelligible

principle under this Court’s precedent, a congressional

enactment must, at a bare minimum, identify the

substantive factors relevant in fashioning a regulation. In

some circumstances, the statute should go further and

provide some guidance concerning how the agency should

procedurally and/or substantively strike the balance

between competing considerations. The precise tevel of

congressional guidance necessary in a particular context

depends on the breadth of the regulations at issue. As

described by this Court in Whitman v. American Trucking

Ass’n, “the degree of agency discretion that is acceptable

varies according to the scope of the power congressionally

conferred.” 531 U.S. at 475. For “setting * * * standards

that affect the entire national economy,” such as the

Secretary's medical privacy standards, Congress “must

provide substantial guidance.” Id.

HIPAA, however, not only fails to provide the

constitutionally required “substantial guidance,” it fails to

provide any meaningful guidance at all. HIPAA mandates

the Secretary’s promulgation of medical privacy standards

if Congress fails to do so, but without offering the barest

suggestion of the substantive factors relevant to their

promulgation, let alone any guidance concerning how to

strike a balance between them. Privacy in the medical

context is exceedingly important, but like other ethical

values, it is not absolute and is subject to qualification.

Yet, in HIPAA, Congress never provides the Secretary

with even the most minimal guidance concerning what

factors should be relevant in assessing the privacy

concerns implicated by particular medical records or what

factors should be relevant in assessing the social policy

objectives allegedly favoring disclosure of those records.

Even more particularly, Congress never addresses: (1)

What factors the Secretary should consider in determining

16

the scope of medical privacy rights that an individual

should have; (2) What factors the Secretary should

consider in determining what procedures an individual

should have for exercising those rights; or (3) What factors

the Secretary should consider in determining what uses

and disclosures of that information should be authorized.

The court of appeals’ fundamental error was its

mistaking for an intelligible principle in HIPAA the

presence in the Act of some congressional guidance as to

the scope of the medical privacy standards. We do not

deny that HIPAA provides some such statutory bounds.

Indeed, as we argue in Part II below, the Secretary’s

privacy standards are separately flawed because they

ignore those express bounds. But the fact that rulemaking

authority has some outer bounds is not the constitutional

equivalent of an intelligible principle for exercising the

lawmaking authority within those established bounds, let

alone the “substantial guidance” necessary in this case in

light of the extraordinary breadth and depth of the

Secretary’s medical privacy standards.

Hence, HIPAA’s provision (Section 264, 42 U.S.C.

§1320d-2 note(b)) that the standards should “at least”

cover (1) “The rights that an individual who is a subject of

individually identifiable health information should have”;

(2) “The procedures that should be established for the

exercise of such rights” and (3) “the uses and disclosures

of such information that should be authorized or

required” falls nowhere near the applicable constitutional

standard. Wholly missing from the statute is any

substantial congressional guidance regarding how the

Secretary is to determine what those individual “rights”

should be or what “disclosures * * * should be authorized

or required.” Indeed, even this purported legislative

guidance provides no bounds because, HIPAA merely

provides that the standards must “at least” cover these

agit

SD Bek

Sei Ps

Oa ah LARNER Bia Tet A ane seen ee,

17

topics. Id.

No more persuasive is the lower court's additional

reliance (App. A8-A9) upon either the preamble statement

in HIPAA Section 261 regarding HIPAA’s general purpose

or the fact that HIPAA’s privacy standards are limited “to

communications of listed information by particular

covered entities.” Section 261's preamble statement

provides absolutely no guidance for the Secretary

concerning how individual rights should be protected or

to what extent. It is merely a general preamble statement

applicable to the entire statute and of no special legal

import. See Panama Refining, 293 U.S. at 418. Nor does

the fact that HIPAA’s privacy standards are limited to

individually identifiable health information by certain

entities excuse Congress from providing the Secretary

with guidance on how to determine privacy standards for

such crucial personal information.’

Indeed, this Court’s recent decision in Whitman v.

American Trucking Ass‘n is illustrative of both the failings

of HIPAA and the lower courts’ misapplication of this

Court's nondelegation doctrine precedent. In American

Trucking, the Court rejected a nondelegation challenge to

the EPA Administrator’s promulgation of a national

ambient air quality standard pursuant to the Clean Air

Act, 42 U.S.C. §§ 7407-7409. The Court concluded that the

Clean Air Act provided the necessary “intelligible

principle” because the Act both identified the factors

relevant and not relevant to the Administrator’s selection

of a standard and instructed the Administrator how the

® To be sure, where, unlike in HIPAA, Congress has delegated to an

agency the narrow task of defining a technical term of limited

application, no further guidance may be necessary. See American

Trucking Ass’n, 531 U.S. at 574 (comparing minimal legislative

guidance necessary for agency definition of a “country elevator” to

“substantial guidance” necessary for national air quality standards).

ee

18

balance should be struck. The Act made plain that

economic compliance costs were irrelevant to standard

setting, which should consider only public health risks,

and that the Administrator should set the air quality

standards ata level “requisite” or “sufficient, but not more

than necessary” to protect public health. 531 U.S. at 473.

However, under the Secretary’s view, endorsed by the

court of appeals below, it would presumably have been

sufficient in American Trucking had the Clean Air Act

simply mandated the Administrator’s promulgation of

national air quality standards, without more. So long as

the federal statute provided some jurisdictional bounds --

presumably such as “air quality” and “national standards”

-- the Constitution’s nondelegation doctrine would require

no more. Such an extraordinary misapprehension of this

Court’s precedent warrants this Court's review.”

Nor is there any merit to the court of appeals’ further

suggestion that any constitutional infirmity is somehow

° —Fhe other recent cases in which this Court has rejected

nondelegation doctrine challenges are similarly distinguishable from

this case. In Touby v. United States, 500 U.S. 160 (1991), the Attorney

General's authority to designate “controlled substances” was sharply

circumscribed to those presenting an “imminent hazard.” In Loving

v. United States, 517 U.S. 748, 772 (1996), the President's choices for

determining the aggravating factors in capital cases under military

law were “set within boundaries the President may not exceed.” In

Mistretta v. United States, 488 U.S. 361, 379 (1989), the U.S. Sentencing

Commission did not run afoul of the nondelegation doctrine because

“[t]he statute outlines the policies which prompted establishment of

the Commission, explains what the Commission should do and how

it should do it, and sets out specific directives to govern specific

situations” and other federal statutes established applicable

sentencing boundaries. Not only does HIPAA provide no comparable

level of legislative guidance to the Secretary, but the reach of the

Secretary's privacy standards into the daily lives of millions of

Americans is far greater than the agency rules at issue in Loving,

Touby, or Mistretta.

19

cured because HIPAA Section 264 called for the Secretary

to promulgate medical privacy standards after first

making recommendations regarding such standards to

Congress. No serious claim can be maintained that such

a reporting requirement bears any relevance to HIPAA’s

constitutionality. The court of appeals’ view to the

contrary - “That Congress did not enact additional

measures in light of these recommendations indicates the

legislature’s satisfaction with HHS’s proposed approach”

(App. A11) - is wholly untenable.

Congress acts in only one meaningful way under the

Constitution: by enacting legislation. Congressional receipt

of executive branch recommendations does not amount to

a legislative enactment approving or disapproving of

those recommendations. Such a reporting requirement is

perfectly sensible, but it is of absolutely no constitutional

moment to a nondelegation challenge. Indeed, Congress’s

failure to enact legislation in response to those

recommendations merely underscores the impropriety of

HIPAA’s attempt to circumvent the constitutionally

demanded legislative process by purporting to assign that

function to the Secretary.

Finally, any possible doubt regarding the existence of

an intelligible principle in HIPAA is removed by

examination of the rulemaking record itself. The Secretary

published more than 700 hundred pages of preamble

commentary to accompany the proposed and final

rulemaking. That commentary explains in some detail

why the Secretary chose to strike the balance between

privacy concerns and other competing social concerns in

a variety of contexts. What is striking is that in none of that

explanation does the Secretary ever refer to any relevant

principles established by the governing statute, HIPAA.

The rulemaking record is stunningly silent, no doubt

because so too is HIPAA.

20

The Secretary, in effect, decided entirely on her own

both what the relevant factors should be and how to strike

the balance between them in the final rulemaking. Wholly

absent from the Secretary’s reasoning was any suggestion

that HIPAA guided the Secretary’s balancing process in

any way, let alone in the “substantial” way required by

this Court’s precedent.

II. REVIEW OF THE LEGALITY OF THE SCOPE OF

THE SECRETARY’S MEDICAL PRIVACY

STANDARDS IS ALSO WARRANTED

The Secretary’s medical privacy standards, moreover,

are invalid on yet a second, distinct ground. They exceed

the statutory authority that HIPAA conferred on the

Secretary. Although, as described above, HIPAA is itself

unconstitutional under the nondelegation doctrine,

Congress did make some effort at least to place outer

bounds on the substantive scope of the Secretary’s

authority. In the final rulemaking, however, the Secretary

blithely transgressed that statutory bound by

promulgating medical privacy standards that apply to all

personal medical records regardless of their form or their

method of transmission.

“Because this case involves an administrative agency’s

construction of a statute that it administers, [this Court's]

analysis is governed by Chevron U.S.A. Inc. v. Natural

Resources Defense Council, Inc., 467 U.S. 837 (1984).” Food

& Drug Administration v. Brown & Williamson, 529 U.S.

120, 132 (2000). Under Chevron, “although agencies are

generally entitled to deference in the interpretation of

statutes that they administer, a reviewing ‘court, as well as

the agency, must give effect to the unambiguously

expressed intent of Congress.” Id. at~125-126, quoting

Chevron, 467 U.S. at 842-843. “In determining whether

Congress has specifically addressed the question at issue,

21

a reviewing court should not confine itself to examining a

particular statutory provision in isolation. The meaning *

** of certain words or phrases may only become evident

when placed in context.” Id. at 132.

In this case, moreover, the Secretary is entitled to no

judicial deference. The plain meaning of HIPAA’s relevant

language, read both in isolation and in its broader

statutory context, makes clear that the Secretary does not

possess sweeping lawmaking authority to enact medical

privacy standards applicable to all individually

identifiable health information.

It is common ground that HIPAA Section 264(c)(1) is

the exclusive source of the Secretary’s authority to

promulgate medical privacy standards. Section 264,

however, expressly limits the Secretary’s standard setting

authority “to the privacy of individually identifiable

health information transmitted in connection with the

transactions described in section 1173(a) of the Social Security

Act (as added by section 262)” (emphasis added). Section

1173(a) in turn sets forth nine specific transactions for

which the Secretary shall “adopt standards for

transactions, and data elements for such transactions, to

enable health information to be exchanged electronically.”

Only those nine transactions are covered and, even then,

only as necessary to enable their electronic transmission.

Contrary to the court of appeals’ ruling below, therefore,

Section 264's cross-reference to Section 1173(a) expressly

contradicts the Secretary’s decision in the final regulations

to issue privacy standards applicable to personal medical

records “transmitted or maintained in any . . . form or

medium.” 45 C.F.R. § 160.103 (2003).

HIPAA’s overall statutory structure confirms the

extent of the Secretary’s usurpation of legislative

authority. Most strikingly, comparison of the language of

Section 264(a), in which the Secretary is asked to make

22

privacy standard recommendations to Congress, to the

language of Section 264(c), in which the Secretary is given

rulemaking authority, underscores congressional intent to

deny the Secretary the very sweeping authority he now

claims. While Section 264(a) instructed the Secretary to

provide Congress with “recommendations on standards

with respect to the privacy of individually identifiable

health information,” without any further qualification,

Congress in 264(c) expressly qualified the Secretary's

rulemaking authority “to the privacy of individually

identifiable health information transmitted in connection

with the transactions described in section 1173(a).” The

Secretary, however, has essentially read that express

limitation on his authority out of existence.

The reason for the contrasting language in Sections

264(a) and 264(c) is also clear. The overall purpose of

Section 1173(a), added by Section 262 of HIPAA, was to

promote electronic transmission of health care information

in the listed transactions by establishing uniform

standards (e.g., formats, identifiers, and data codes) for the

electronic transmission of certain health information.

Before HIPAA, the lack of such standardization had

resulted in gross inefficiencies because there were

hundreds of different (and incompatible) electronic

formats. At the same time, however, as the Secretary

herself explained, Congress understood that “ [t]he risk of

improper uses and disclosures has increased as the health

care industry has begun to move from primarily paper-

based information systems to systems that operate in

various electronic forms.” 64 Fed. Reg. 59920 (1999).

Technological “advances have reduced or eliminated

many of the logistical obstacies that previously served to

protect the confidentiality of health information and the

privacy interests of individuals.” Id.

It is for that reason that Congress concluded “that

acne aa: An Rene

en aS

23

privacy standards must accompany the electronic data

interchange standards and that the increased ease of

transmitting and sharing individually identifiable health

information must be accompanied by an increase in the

privacy and confidentiality.” 64 Fed. Reg. 60006. Fearful

that Congress would be unable to enact the privacy

standards in a timely basis itself, Congress decided to

allocate some interim lawmaking authority over medical

privacy standards to the Secretary in the event of

congressional failure to meet a three year deadline. But, in

taking this dramatic step, Congress also took care to limit

the Secretary’s lawmaking authority over privacy

standards to the electronic transmission of the same nine

transactions listed in Section 1173(a) that Congress knew

it was otherwise promoting in HIPAA.”

"Significantly, the Secretary’s privacy standards are the only

HIPAA standards that the Secretary has sought to apply to

nonelectronic forms of medical records. The Secretary is authorized

to promulgate a wide array of non-privacy standards under Section

1173(a) and for none of those other standards has the Secretary sought

to apply standards beyond the four corners of Section 1173(a). Instead,

consistent with the plain meaning of the Statutory language, the

Secretary has promulgated standards applicable only to the

Statutorily-listed transactions and electronic transmissions. See

Health Insurance Reform: Security Standards, 68 Fed. Reg. 8334, 8342

(2003) (“While we agree that protected health information in paper or

other form also should have appropriate security protections, the

Proposed rule proposing the security standards proposed to apply

those standards to health information in electronic form only. Weare,

accordingly, not extending the scope in this final rule.”); Health

Insurance Reforms: Standards for Electronic Transactions, 65 Fed.

Reg. 50312, 50318 (2000) (rejecting suggestion “that the transaction

standards and their codes sets, in some manner, apply to paper

transactions” because otherwise “many health care providers would

revert to paper claims if the data requirements were less restrictive

than those for electronic claims.”); see 64 Fed. Reg. 59928 (“Our prior

proposals under HIPAA have addressed only electronically

24

In the Federal Register commentary accompanying the

proposed medical privacy standards, unlike in the final

rulemaking, the Secretary recognized that HIPAA placed

significant limits on the Secretary’s authority to issue

medical privacy standards. The Secretary expressly

admitted that “the HIPAA legislative authority is more

limited in scope * * *and does not always permit us to

propose the policies that we believe are optimal.” 64 Fed.

Reg. 59923. The Secretary went on to describe how under

the proposed regulation, “[a]ny provider who maintains

a solely paper information system would not be subject to

these privacy standards, thus leaving another gap in the

system of protection we propose to create.” Id. In the final

regulations, however, the Secretary effectively ignored

HIPAA’s express limitations and decided unilaterally to

close that “gap” by extending the privacy standards to all

personal medical records, including those maintained

under “a solely paper information system.”

The court of appeals erred by finding support (App.

A12-A13) for the Secretary’s interpretation in two

provisions added to the Social Security Act by HIPAA

Section 261: Section 1171(6)’s definition of “individually

identifiable information” and Section 1173's purpose “to

enable health information to be exchanged electronically.”

Neither provision, however, redefines the bounds of the

Secretary’s standard setting authority set forth in HIPAA

Section 264(c). It is neither relevant nor surprising that

“individually identifiable health information” can extend

for some purposes in the Social Security Act to such

information in nonelectronic forms. What is dispositive is

that Congress in HIPAA Section 264(a) expressly declined

to confer standard setting authority on the Secretary for all

such personal health information. Nor, contrary to the

maintained and transmitted information.”).

25

court of appeals’ did Congress in Section 264(c) grant

authority to the Secretary to issue privacy standards to the

extent the Secretary thought such standards would

“enable health information to be exchanged

electronically.” As previously described, Section 264(c)’s

grant of agency lawmaking authority is more narrowly

drawn and contains no such unbounded purpose.

No doubt that is why, prior to the final rulemaking, it

was essentially common ground that the Secretary lacked

any such extraordinarily expansive rulemaking authority

_to promulgate medical privacy standards. In her formal

recommendations to Congress in 1997, the Secretary

acknowledged the absence in HIPAA of the very authority

She subsequently asserted in the final rulemaking.

Secretary Shelala stated that HIPAA “calls for the

Secretary of HHS to impose confidentiality controls on

electronic transmission systems.” J.A. 355 (emphasis

added). President Clinton similarly acknowledged that

further legislation would be necessary to extend privacy

standards to paper transactions. J.A. 262 (“only through

legislation can we cover all paper records”).

The rulemaking itself even expressly acknowledges the

weakness of its underlying legal argument by deliberately

structuring the relevant regulation to allow for its partial

invalidation with the least amount of disruption. See 65

Fed. Reg. 82496 (“We have structured the definition this

way so that, if a court were to disagree with our view of

our authority in this area, the rule would still be

operational, albeit with respect to a more limited universe

of information.”).

Finally, the Secretary contended in the rulemaking that

a broader assertion of jurisdiction made sense as a matter

of policy because otherwise those subject to regulation

might be able to avoid the privacy standards simply by

avoiding electronic transmissions. See 65 Fed. Reg. 82619.

26

We question whether the advantages of electronic

transmissions would be so easily outweighed, but in any

event, the short answer is that such a policy concern is for

Congress to address in the first instance. If the Secretary

believes that rules of broader applicability are needed, the

Secretary must persuade Congress to provide the

Secretary with broader authority. In HIPAA, however,

Congress has not only declined to provide such broad

authority, but instead accomplished just the opposite

result. In the interim, “regardless of how serious the

problem an administrative agency seeks to address, * * * it

may not exercise its authority ‘in a manner that is

inconsistent with the administrative structure that

Congress enacted into law.’” FDA v. Brown & Williamson,

529 U.S. at 125, quoting ETSI Pipeline Project v. Missouri,

484 U.S. 495, 517 (1988).

/

Ill. REVIEW IS WARRANTED IN THIS CASE __

We readily acknowledge that this Court’s normal

practice is not to grant review in the first case that presents

a legal issue, but instead to await further litigation. The

extraordinary nature of both Congress’s action in HIPAA

and the Secretary’s rulemaking warrant a departure from

that practice in this case.

Most simply put, the enormous impact of the

Secretary’s usurpation of legislative authority in

promulgating the medical privacy standards justifies this

Court’s immediate attention. Any nondelegation issue

implicates fundamental issues of individual liberty.

“Separation of powers was designed to implement a

fundamental insight: concentration of power in the hands

of a single branch is a threat to liberty.” Clinton v. City of

New York, 524 U.S. at 450 (Kennedy, J., concurring). But,

the liberty implications at stake in this litigation are

magnified many fold because of the breadth, depth, and

27

character of the rulemaking at issue, which is likely why

the Secretary received nearly 52,000 comments on the

proposed regulation. 65 Fed. Reg. 82566.

As described by the Secretary herself in the final 2000

rulemaking “[t]his final rule establishes, for the first time,

a set of basic national privacy standards ***” and the rules

promulgated by the Secretary “are likely the largest single

federal initiative to protect Privacy.” 65 Fed. Reg. 82464,

82468. See J.A. 261 (remarks of President Clinton) (“the

first comprehensive national standards for protection of

medical records”). The Secretary's rulemaking affects the

privacy rights on a matter that for millions of Americans

strikes at fundamental notions of personal autonomy. The

Hippocratic oath of confidentiality lies at the foundation

of the doctor-patient relationship. Like other privileges, it

is not absolute. But there is nothing merely technical nor

incidental about fashioning a legal standard to govern the

terms for its potential breach. It is instead the very kind of

legal issue for which any meaningful lawmaking calling

for the breach of confidentiality must be well grounded in

legislation enacted by democratically elected

representatives of the people. Especially because the

executive branch has its own bureaucratic policies

favoring disclosure, it is all the more incumbent that

Congress not be circumvented, even if it seems politically

expedient to do so.

However, just such a circumvention of the iegislative

process was, albeit at Congress’s own initiative, precisely

what happened pursuant to HIPAA As a result, the

personal medical records of 282 million Americans are

now subject to disclosure based on privacy standards

established by the Secretary not only in the absence of the

constitutionally required “intelligible principle” bit in

blatant violation of the limited bounds established by

Congress in HIPAA.

28

Although the Secretary touts the regulations as

safeguarding patient privacy, the regulations in fact

authorize widespread releases of historically confidential

patient information. Under the regulations, no patient

consent is frequently necessary for release of private

medical information to government agencies. Hence, law

enforcement officers now can often obtain ready access to

personial medical records in a host of circumstances (see 45

C.F.R. § 164.512; 67 Fed. Reg. 53226-32 (2002)), which raises

a distinct constitutional issue under this Court’s recent

ruling in Ferguson v. City of Charleston, 532 U.S. 67 (2001).

Patient consent is similarly not necessary for 1eleases of

personal medical information that fall within the

potentially open-ended category of “uses and disclosures

to carry out treatment, payment, or health care

operations.” 45 C.F.R. § 164.506; 67 Fed. Reg. 53208-19

(2002); Richard Sobel, A New Wound to Medical Privacy --

Administration Rules Eviscerate Patient Consent, L.A. Times

15 (August 23, 2002). Because, moreover, the Secretary's

privacy regulations now narrowly define what constitutes

“marketing,” even the regulatory promise that covered

entities must obtain prior patient authorization before~

using patient health information or disclosing it for

commercial purposes often proves illusory in practice. 45

C.F.R. §§ 164.501, 164.508(a)(3); Health Care Records: Books

Open to Abuse, TRIAL, 42 (October 2002) (“Not only do the

changes define marketing in a very troubling way, but

they also remove some safeguards that were in the

regulation.”). Whatever the merits of these sweeping

decisions by the Secretary for when patient consent is not

required for disclosure of quintessentially private medical

information, Congress provided no guidance, let alone an

intelligible principle, to guide the Secretary’s lawmaking.

Finally, regulatory compliance, which is just now

beginning, is requiring hundreds of thousands of large

29

and small medical providers to make major changes in the

way they provide their services. Based on the Secretary’s

own analysis, “[t]here are approximately 12,200 health

plans * * *, 6480 hospitals, and 630,000 non-hospital

providers that will bear implementation costs under the

final rule.” 65 Fed. Reg. 82765. That includes 562,916

“small health care entities,” including, nonprofit health

plans, small physician practices, small businesses

providing health coverage, aid pharmacies. Id. at 82779.

The health care industry in the United States currently

amounts to more than 13 percent of the nation’s economic

output. Literally billions of dollars of investments will be

necessary for compliance, especially in the first few years

of the privacy standard’s legal effectiveness. By the

Secretary’s own calculations, “[t]he estimated cost of

compliance with the final rule is $ 17.6 billion over the ten

year period, 2003-2012.” 65 Fed. Reg. 82760." Other

estimates predict costs as high as $40 billion for that same

time period. Whatever the ultimate tally, the dollar

amount will plainly not only be in the billions, but, even

more importantly, will be merely a reflection of the

extraordinarily far-reaching changes in individual

behavior that the medical privacy standards will require,

only a fraction of which were likely contemplated.”

"' Based on subsequent modifications, the Secretary has reduced the

estimated cost’ of compliance with the privacy standards by $100

million over ten years. 67 Fed. Reg. 53182, 53259 (2002).

* For instance, clergy have learned that their visits to hospitals to

counsel ill patients are now severely restricted. Ann Rodgers-

Melnick, Privacy Rules May Limit Clergy Hospital Visits, Post-Gazette,

http:/ / www.post-gazette.com/healthscience/ 20030228hospitals4.asp

(visited June 11, 2003). Ina letter to the Secretary dated November 20,

2001, approximately 200 organizations and individuals, including the

Association of American Medical Colleges, American Psychological

Society, American Hospital Association, and virtually every major

——

30

CONCLUSION

The petition for a writ of certiorari should be granted.

Respectfully submitted.

July 2003

TERRY E. RICHARDSON, JR.*

DANIEL S. HALTIWANGER

RICHARDSON, PATRICK, WESTBROOK &

BRICKMAN

P.O. Box 1368

BARNWELL, SOUTH CAROLINA 29812

(803) 541-7850

RICHARD J. LAZARUS

GEORGETOWN UNIVERSITY

LAW CENTER

600 NEW JERSEY AVE., N.W.

WASHINGTON, D.C. 20001

(202) 662-9129

Counsel for Petitioners

* Counsel of Record

medical research facility in the nation, voiced their “ serious concerns”

regarding the Secretary’s December 2000 final rules, including how

the rules would “seriously impair” research. See Ass’n of American

Medical Colleges, http:// www.aamc.org/ advocacy /library/hipaa

/corres/2001/112001.htm (visited 6/11/03). Although the Secretary

has since modified the rules in some limited respects in response to

the medical research community’s concerns, the existence of such

correspondence underscores both the practical importance of the legal

issues presented and the constitutional impropriety of the Secretary’s -

assertion of exclusive lawmaking authority over medical privacy

standards in derogation of the Constitution’s deliberate design.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.