Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act

Federal RegisterJul 14, 2010

Ask Donna

What actually matters in this document.

Text

DEPARTMENT OF HEALTH AND HUMAN SERVICES

Office of the Secretary

45 CFR Parts 160 and 164

RIN: 0991-AB57

Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act

AGENCY:

Office for Civil Rights, Department of Health and Human Services.

ACTION:

Notice of proposed rulemaking.

SUMMARY:

The Department of Health and Human Services (HHS or “the Department”) is issuing this notice of proposed rulemaking to modify the Standards for Privacy of Individually Identifiable Health Information (Privacy Rule), the Security Standards for the Protection of Electronic Protected Health Information (Security Rule), and the rules pertaining to Compliance and Investigations, Imposition of Civil Money Penalties, and Procedures for Hearings (Enforcement Rule) issued under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The purpose of these modifications is to implement recent statutory amendments under the Health Information Technology for Economic and Clinical Health Act (“the HITECH Act” or “the Act”), to strengthen the privacy and security protection of health information, and to improve the workability and effectiveness of these HIPAA Rules.

DATES:

Submit comments on or before September 13, 2010.

ADDRESSES:

You may submit comments, identified by RIN 0991-AB57, by any of the following methods (please do not submit duplicate comments):

•

Federal eRulemaking Portal: http://www.regulations.gov.

Follow the instructions for submitting comments. Attachments should be in Microsoft Word, WordPerfect, or Excel; however, we prefer Microsoft Word.

•

Regular, Express, or Overnight Mail:

U.S. Department of Health and Human Services, Office for Civil Rights, Attention: HITECH Privacy and Security Rule Modifications, Hubert H. Humphrey Building, Room 509F, 200 Independence Avenue, SW., Washington, DC 20201. Please submit one original and two copies.

•

Hand Delivery or Courier:

Office for Civil Rights, Attention: HITECH Privacy and Security Rule Modifications, Hubert H. Humphrey Building, Room 509F, 200 Independence Avenue, SW., Washington, DC 20201. Please submit one original and two copies. (Because access to the interior of the Hubert H. Humphrey Building is not readily available to persons without Federal government identification, commenters are encouraged to leave their comments in the mail drop slots located in the main lobby of the building.)

Inspection of Public Comments:

All comments received before the close of the comment period will be available for public inspection, including any personally identifiable or confidential business information that is included in a comment. We will post all comments received before the close of the comment period at

http://www.regulations.gov.

Because comments will be made public, they should not include any sensitive personal information, such as a person's social security number; date of birth; driver's license number, State identification number or foreign country equivalent; passport number; financial account number; or credit or debit card number. Comments also should not include any sensitive health information, such as medical records or other individually identifiable health information, or any non-public corporate or trade association information, such as trade secrets or other proprietary information.

FOR FURTHER INFORMATION CONTACT:

Andra Wicks, 202-205-2292.

SUPPLEMENTARY INFORMATION:

The discussion below includes a description of the statutory and regulatory background of the proposed rules, a section-by-section description of the proposed modifications, and the impact statement and other required regulatory analyses. We solicit public comment on the proposed rules. Persons interested in commenting on the provisions of the proposed rules can assist us by preceding discussion of any particular provision or topic with a citation to the section of the proposed rule being discussed.

I. Statutory and Regulatory Background

The regulatory modifications proposed below concern several sets of rules that implement the Administrative Simplification provisions of title II, subtitle F, of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104-191), which added a new part C to title XI of the Social Security Act (sections 1171-1179 of the Social Security Act, 42 U.S.C. 1320d-1320d-8). The Health Information Technology for Economic and Clinical Health (HITECH) Act, which was enacted as title XIII of division A and title IV of division B of the American Recovery and Reinvestment Act of 2009 (ARRA), Public Law 111-5, modifies certain provisions of the Social Security Act pertaining to the Administrative Simplification Rules (HIPAA Rules) and requires certain modifications to the HIPAA Rules themselves.

A. HIPAA Administrative Simplification—Statutory Background

The Administrative Simplification provisions of HIPAA provided for the establishment of national standards for the electronic transmission of certain health information, such as standards for certain health care transactions conducted electronically and code sets and unique health care identifiers for health care providers and employers. The Administrative Simplification provisions of HIPAA also required the establishment of national standards to protect the privacy and security of personal health information and established civil money and criminal penalties for violations of the Administrative Simplification provisions. The Administrative Simplification provisions of HIPAA apply to three types of entities, which are known as “covered entities”: health care providers who conduct covered health care transactions electronically, health plans, and health care clearinghouses.

B. HIPAA Administrative Simplification—Regulatory Background

The rules proposed below concern the privacy and security standards issued pursuant to HIPAA, as well as the enforcement rules that implement HIPAA's civil money penalty authority. The Standards for Privacy of Individually Identifiable Health Information, known as the “Privacy Rule,” were issued on December 28, 2000, and amended on August 14, 2002.

See

65 FR 82462, as amended at 67 FR 53182. The Security Standards for the Protection of Electronic Protected Health Information, known as the “Security Rule,” were issued on February 20, 2003.

See

68 FR 8334. The Compliance and Investigations, Imposition of Civil Money Penalties, and Procedures for Hearings regulations, collectively known as the “Enforcement Rule,” were issued as an interim final rule on April 17, 2003 (68 FR 18895), and revised and issued as a final rule, following rulemaking, on February 16, 2006 (71 FR 8390).

The Privacy Rule protects individuals' medical records and other individually

identifiable health information created or received by or on behalf of covered entities, known as “protected health information.” The Privacy Rule protects individuals' health information by regulating the circumstances under which covered entities may use and disclose protected health information and by requiring covered entities to have safeguards in place to protect the privacy of the information. As part of these protections, covered entities are required to have contracts or other arrangements in place with business associates that perform functions for or provide services to the covered entity and that require access to protected health information to ensure that these business associates likewise protect the privacy of the health information. The Privacy Rule also gives individuals rights with respect to their protected health information, including rights to examine and obtain a copy of their health records and to request corrections.

The Security Rule, which applies only to protected health information in electronic form, requires covered entities to implement certain administrative, physical, and technical safeguards to protect this electronic information. As with the Privacy Rule, the Security Rule requires covered entities to have contracts or other arrangements in place with their business associates that provide satisfactory assurances that the business associates will appropriately safeguard the electronic protected health information they receive, create, maintain, or transmit on behalf of the covered entities.

The Enforcement Rule establishes rules governing the compliance responsibilities of covered entities with respect to cooperation in the enforcement process. It also provides rules governing the investigation by the Department of compliance by covered entities, both through the investigation of complaints and the conduct of compliance reviews. It establishes rules governing the process and grounds for establishing the amount of a civil money penalty where the Department has determined a covered entity has violated a requirement of a HIPAA Rule. Finally, the Enforcement Rule establishes rules governing the procedures for hearings and appeals where the covered entity challenges a violation determination.

C. The HITECH Act—Statutory Background

The HITECH Act, enacted on February 17, 2009, is designed to promote the widespread adoption and standardization of health information technology. Subtitle D of title XIII, entitled “Privacy,” supports this goal by adopting amendments designed to strengthen the privacy and security protections of health information established by HIPAA. These provisions include extending the applicability of certain of the Privacy and Security Rules' requirements to the business associates of covered entities; requiring HIPAA covered entities and business associates to provide for notification of breaches of “unsecured protected health information”; establishing new limitations on the use and disclosure of protected health information for marketing and fundraising purposes; prohibiting the sale of protected health information; requiring the consideration of a limited data set as the minimum necessary amount of information; and expanding individuals' rights to access and receive an accounting of disclosures of their protected health information, and to obtain restrictions on certain disclosures of protected health information to health plans. In addition, subtitle D adopts provisions designed to strengthen and expand HIPAA's enforcement provisions. We provide a brief overview of the relevant statutory provisions below.

In the area of business associates, the Act makes a number of changes. First, section 13401 of the Act applies certain provisions of the Security Rule that apply to covered entities directly to their business associates and makes business associates liable for civil and criminal penalties for the failure to comply with these provisions. Similarly, section 13404 makes business associates of covered entities civilly and criminally liable under the Privacy Rule for making uses and disclosures of protected health information that do not comply with the terms of their business associate contracts. The Act also provides that the additional privacy and security requirements of subtitle D of the Act are applicable to business associates and that such requirements shall be incorporated into business associate contracts. Finally, section 13408 of the Act requires that organizations that provide data transmission of protected health information to a covered entity or business associate and that require routine access to such information, such as Health Information Exchange Organizations, Regional Health Information Organizations, and E-prescribing Gateways, as well as vendors that contract with covered entities to offer personal health records to patients as part of the covered entities' electronic health records, shall be treated as business associates for purposes of the HITECH Act and the HIPAA Privacy and Security Rules and required to enter into business associate contracts.

Section 13402 of the Act sets forth the breach notification provisions, requiring covered entities and business associates to provide notification following discovery of a breach of unsecured protected health information. Additionally, section 13407 of the Act, enforced by the Federal Trade Commission (FTC), applies similar breach notification provisions to vendors of personal health records and their third party service providers.

Section 13405 of the Act requires the Department to modify certain Privacy Rule provisions. In particular, section 13405 sets forth certain circumstances in which covered entities must comply with an individual's request for restriction of disclosure of his or her protected health information, provides for covered entities to consider a limited data set as the minimum necessary for a particular use, disclosure, or request of protected health information, and requires the Secretary to issue guidance to address what constitutes minimum necessary under the Privacy Rule. Section 13405 also requires the Department to modify the Privacy Rule to require covered entities that use or maintain electronic health records to provide individuals, upon request, with an accounting of disclosures of protected health information through an electronic health record for treatment, payment, or health care operations; generally prohibits the sale of protected health information without a valid authorization from the individual; and strengthens an individual's right to an electronic copy of their protected health information, where a covered entity uses or maintains an electronic health record.

Section 13406 of the Act requires the Department to modify the marketing and fundraising provisions of the Privacy Rule. With respect to marketing, the Act requires authorizations for certain health-related communications, which are currently exempted from the definition of marketing, if the covered entity receives remuneration in exchange for making the communication. The Act also strengthens an individual's right under the Privacy Rule to opt out of fundraising communications by requiring the Department to modify the Privacy Rule so that covered entities must provide individuals with a clear and conspicuous opportunity to opt out of receiving fundraising

communications and by requiring that an opt out be treated as a revocation of authorization under the Privacy Rule.

Section 13410 of the Act addresses enforcement in a number of ways. First, section 13410(a) provides that the Secretary's authority to impose a civil money penalty will only be barred to the extent a criminal penalty has been

imposed

, rather than in cases in which the offense in question merely constitutes an offense criminally

punishable.

In addition, section 13410(a) of the Act requires the Secretary to formally investigate any complaint where a preliminary investigation of the facts indicates a possible violation due to willful neglect and to impose a penalty where a violation is found in such cases. Section 13410(c) of the Act provides, for purposes of enforcement, for the transfer to the HHS Office for Civil Rights of any civil money penalty or monetary settlement collected under the Privacy and Security Rules and also requires the Department to establish by regulation a methodology for distributing to harmed individuals a percentage of the civil money penalties and monetary settlements collected under the Privacy and Security Rules. Effective as of February 18, 2009, section 13410(d) of the Act also modified the civil money penalty structure for violations of the HIPAA Rules by implementing a tiered increase in the amount of penalties based on culpability. In addition, as of February 18, 2009, section 13410(e) of the Act also granted State Attorneys General the authority to enforce the HIPAA Rules by bringing civil actions on behalf of State residents in court.

Section 13421 states that HIPAA's State preemption provisions at 42 U.S.C. 1320d-7 shall apply to the provisions of subtitle D of the HITECH Act in the same manner as they do to HIPAA's provisions.

1

Section 13423 of the Act provides a general effective date of February 18, 2010, for most of its provisions, except where a different effective date is otherwise provided.

1

We note that section 13421 of the HITECH Act and HIPAA's State preemption provisions do not affect the applicability of other Federal law, such as the Confidentiality of Alcohol and Drug Abuse Patient Records Regulation at 42 CFR Part 2, to a covered entity's use or disclosure of health information.

The Act also provides for the development of guidance, reports, and studies in a number of areas, including guidance on appropriate technical safeguards to implement the HIPAA Security Rule (section 13401(c)); for purposes of breach notification, guidance on the methods and technologies for rendering protected health information unusable, unreadable, or indecipherable to unauthorized individuals (section 13402(h)); guidance on what constitutes the minimum necessary amount of information for purposes of the Privacy Rule (section 13405(b)); a report by the Government Accountability Office (GAO) regarding recommendations for a methodology under which harmed individuals may receive a percentage of civil money penalties and monetary settlements under the HIPAA Privacy and Security Rules (section 13410(c)); a report to Congress on HIPAA Privacy and Security enforcement (section 13424(a)); a study and report on the application of privacy and security requirements to non-HIPAA covered entities (section 13424(b)); guidance on de-identification (section 13424(c)); and a study on the Privacy Rule's definition of “psychotherapy notes” at 45 CFR 164.501, with regard to including test data that is related to direct responses, scores, items, forms, protocols, manuals, or other materials that are part of a mental health evaluation (section 13424(f)).

Finally, the Act includes provisions for education by HHS on health information privacy and for periodic audits by the Secretary. Section 13403(a) provides for the Secretary to designate HHS regional office privacy advisors to offer guidance and education to covered entities, business associates, and individuals on their rights and responsibilities related to Federal privacy and security requirements for protected health information. Section 13403(b) requires the HHS Office for Civil Rights, not later than 12 months after enactment, to develop and maintain a multi-faceted national education initiative to enhance public transparency regarding the uses of protected health information, including programs to educate individuals about potential uses of their protected health information, the effects of such uses, and the rights of individuals with respect to such uses. Section 13411 requires the Secretary to provide for periodic audits to ensure covered entities and business associates comply with the applicable requirements of the HIPAA Privacy and Security Rules.

We discuss many of the Act's statutory provisions in more detail below where we describe section-by-section how these proposed regulations would implement those provisions of the Act. However, we do not discuss in detail the breach notification provisions in sections 13402 of the Act or the modified civil money penalty structure in section 13410(d) of the Act, which as explained below, have been the subject of previous rulemakings. In addition, we do not address in this rulemaking the accounting for disclosures requirement in section 13405 of the Act, which is tied to the adoption of a standard under the HITECH Act at subtitle A of title XIII of ARRA, or the penalty distribution methodology requirement in section 13410(c) of the Act, which is to be based on the recommendations noted above to be developed at a later date by the GAO. These provisions will be the subject of future rulemakings. Further, we clarify that we are not issuing regulations with respect to the new authority of the State Attorneys General to enforce the HIPAA Rules. Finally, other than the guidance required by section 13405(b) of the Act with respect to what constitutes minimum necessary, this proposed rule does not address the studies, reports, guidance, audits, or education efforts required by the HITECH Act.

D. The HITECH Act—Regulatory Background

As noted above, certain of the HITECH Act's privacy and security provisions have already been the subject of rulemakings and related actions. In particular, the Department published interim final regulations to implement the breach notification provisions at section 13402 of the Act for HIPAA covered entities and business associates in the

Federal Register

on August 24, 2009 (74 FR 42740), effective September 23, 2009. Similarly, the FTC published final regulations implementing the breach notification provisions at section 13407 for personal health record vendors and their third party service providers on August 25, 2009 (74 FR 42962), effective September 24, 2009. For purposes of determining to what information the HHS and FTC breach notification regulations apply, the Department also issued, first on April 17, 2009 (published in the

Federal Register

on April 27, 2009, 74 FR 19006), and then later with its interim final rule, the guidance required by the HITECH Act under 13402(h) specifying the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals. In addition, to conform the provisions of the Enforcement Rule to the new tiered and increased civil money penalty structure made effective by the HITECH Act on the day after enactment, or February 18, 2009, the Department published an interim final rule on October 30, 2009 (74 FR 56123), effective November 30, 2009.

II. General Issues

A. Effective and Compliance Dates

As noted above, section 13423 of the Act provides that the provisions in subtitle D took effect one year after enactment,

i.e.,

on February 18, 2010, except as specified otherwise. There are a number of exceptions to this general rule. Some provisions were effective the day after enactment,

i.e.,

February 18, 2009. For example, the tiered and increased civil money penalty provisions of section 13410(d) were effective for violations occurring after the date of enactment. Sections 13402 and 13407 of the Act regarding breach notification required interim final rules within 180 days of enactment, with effective dates 30 days after the publication of such rules. Other provisions of the Act have later effective dates. For example, the provision at section 13410(a)(1) of the Act providing that the Secretary's authority to impose a civil money penalty will only be barred to the extent a criminal penalty has been

imposed,

rather than in cases in which the offense in question merely constitutes an offense that is criminally

punishable,

becomes effective for violations occurring on or after February 18, 2011. The rules proposed below generally pertain to the statutory provisions that became effective on February 18, 2010, or, in a few cases, on a later date.

We note that the final rule will not take effect until after most of the provisions of the HITECH Act became effective on February 18, 2010. We recognize that it will be difficult for covered entities and business associates to comply with the statutory provisions until after we have finalized our changes to the HIPAA Rules. In addition, we recognize that covered entities and business associates will need some time beyond the effective date of the final rule to come into compliance with the final rule's provisions. In light of these considerations, we intend to provide covered entities and business associates with 180 days beyond the effective date of the final rule to come into compliance with most of the rule's provisions. We believe that providing a 180-day compliance period best comports with section 1175(b)(2) of the Social Security Act, 42 U.S.C. 1320d-4, and our implementing provision at 45 CFR 160.104(c)(1), which require the Secretary to provide at least a 180-day period for covered entities to comply with modifications to standards and implementation specifications in the HIPAA Rules. While the Social Security Act and the HIPAA Rules permit the Secretary to further delay the compliance date for small health plans, we do not believe that it is necessary to do so for this rule both because most of the changes being proposed are discrete modifications to existing requirements of the HIPAA Rules, as well as because the Department is proposing an additional one-year transition period to modify certain business associate agreements, which should provide sufficient relief to all covered entities, including small health plans. The Department welcomes comment on the assumption that it is not necessary to extend the compliance date for small health plans.

We also expect that for future modifications to the HIPAA Rules, in most cases, a 180-day compliance period will suffice. Accordingly, we propose to add a provision at § 160.105 to address the compliance date generally for implementation of new or modified standards in the HIPAA Rules. Proposed § 160.105 would provide that with respect to new standards or implementation specifications or modifications to standards or implementation specifications in the HIPAA Rules, except as otherwise provided, covered entities and business associates must comply with the applicable new standards or implementation specifications or modifications to standards or implementation specifications no later than 180 days from the effective date of any such change. Where future modifications to the HIPAA Rules necessitate a longer compliance period, we would provide so accordingly in the regulatory text. We propose to retain the compliance date provisions at §§ 164.534 and 164.318, which provide the compliance dates of April 14, 2003, and April 20, 2005, for initial implementation of the HIPAA Privacy and Security Rules, respectively, for historical purposes only.

We note that proposed § 160.105 regarding the compliance date of new or modified standards or implementation specifications would not apply to modifications to the provisions of the HIPAA Enforcement Rule because such provisions are not standards or implementation specifications (as the terms are defined at § 160.103). Such provisions are in effect and apply at the time the final rule becomes effective or as otherwise specifically provided. We also note that our proposed general rule for a 180-day compliance period for new or modified standards would not apply where we expressly provide a different compliance period in the regulation for one or more provisions. For purposes of this proposed rule, this would mean that the 180-day compliance period would not govern the time period required to modify those business associate agreements that qualify for the longer transition period proposed in § 164.532. We seek comments on any potential unintended consequences of establishing a 180-day compliance date as a regulatory default, with the noted exceptions.

B. Other Proposed Changes

While passage of the HITECH Act necessitates much of the rulemaking below, it does not account for all of the proposed changes to the HIPAA Privacy, Security, and Enforcement Rules encompassed in this rulemaking. The Department is taking this opportunity to improve the workability and effectiveness of all three sets of HIPAA Rules. The Privacy Rule has not been amended since 2002, and the Security Rule has not been amended since 2003. While the Enforcement Rule was amended in the October 30, 2009, interim final rule to incorporate the enforcement-related HITECH statutory changes that are already effective, it has not been otherwise substantively amended since 2006. In the intervening years, HHS has accumulated a wealth of experience with these rules, both from public contact in various forums and through the process of enforcing the rules. In addition, we have identified a number of needed technical corrections to the rules. Accordingly, we propose a number of modifications that we believe will eliminate ambiguities in the rules and/or make them more workable and effective. Further, we propose a few modifications to conform the HIPAA Privacy Rule to provisions in the Patient Safety and Quality Improvement Act of 2005 (PSQIA). We address the substantive proposed changes in the section-by-section description of the proposed rule below. Technical corrections are discussed at the end of the section-by-section description of the other proposed amendments to the rules.

III. Section-by-Section Description of the Proposed Amendments to Subparts A and B of Part 160

Subpart A of part 160 of the HIPAA Rules contains general provisions that apply to all of the HIPAA Rules. Subpart B of part 160 contains the regulatory provisions implementing HIPAA's preemption provisions. We propose to amend a number of these provisions. Some of the proposed changes are necessitated by the statutory changes made by the HITECH Act, while others are of a technical or conforming nature.

A. Subpart A—General Provisions, Section 160.101—Statutory Basis and Purpose

This section sets out the statutory basis and purpose of the HIPAA Rules. We propose a technical change to include a reference to the provisions of the HITECH Act upon which most of the regulatory changes proposed below are based.

B. Subpart A—General Provisions, Section 160.102—Applicability

This section sets out to whom the HIPAA Rules apply. We propose to add a new paragraph (b) to make clear, consistent with the provisions of the HITECH Act that are discussed more fully below, that the standards, requirements, and implementation specifications of the subchapter apply to business associates, where so provided.

C. Subpart A—General Provisions, Section 160.103—Definitions

Section 160.103 contains definitions of terms that appear throughout the HIPAA Rules. For ease of reference, we propose to move several definitions currently found at § 160.302 to § 160.103 without substantive change to the definitions themselves. This category includes definitions of the following terms: “ALJ,” “civil money penalty,” and “violation or violate.” As the removal of these definitions, along with the removal of other definitions discussed below (

e.g.,

“administrative simplification provision” and “respondent”), would leave § 160.302 unpopulated, we propose to reserve that section. We also propose to remove a comma from the definition of “disclosure” inadvertently inserted into the definition in a prior rulemaking, which is not intended as a substantive change to the definition. In addition, we propose to replace the term “individually identifiable health information” with “protected health information” in the definition of “standard” to better reflect the scope of the Privacy and Security Rules. Further, we propose the following definitional changes:

1. Definition of “Administrative Simplification Provision”

This definition is currently located in the definitions section of subpart C of part 160 of the HIPAA Enforcement Rule. We propose to remove the definition of this term from § 160.302 and move it to the definitions section located at § 160.103 for clarity and convenience, as the term is used repeatedly throughout the entire part 160. We also propose to add to the definition a reference to sections 13400-13424 of the HITECH Act.

2. Definition of “Business Associate”

Sections 164.308(b) of the Security Rule and 164.502(e) of the Privacy Rule require a covered entity to enter into a contract or other written agreement or arrangement with its business associates. The purpose of these contracts or other arrangements, generally known as business associate agreements, is to provide some legal protection when protected health information is being handled by another person (a natural person or legal entity) on behalf of a covered entity. The HIPAA Rules define “business associate” generally to mean a person who performs functions or activities on behalf of, or certain services for, a covered entity that involve the use or disclosure of protected health information. Examples of business associates include third party administrators or pharmacy benefit managers for health plans, claims processing or billing companies, transcription companies, and persons who perform legal, actuarial, accounting, management, or administrative services for covered entities and who require access to protected health information. We propose a number of modifications to the definition of “business associate.” In particular, we propose to modify the definition to conform the term to the statutory provisions of PSQIA, 42 U.S.C. 299b-21,

et seq.,

and the HITECH Act. Additional modifications are made for the purpose of clarifying circumstances when a business associate relationship exists and for general clarification of the definition.

a. Inclusion of Patient Safety Organizations

We propose to add patient safety activities to the list of functions and activities a person may undertake on behalf of a covered entity that give rise to a business associate relationship. PSQIA, at 42 U.S.C. 299b-22(i)(1), provides that Patient Safety Organizations (PSOs) must be treated as business associates when applying the Privacy Rule. PSQIA provides for the establishment of PSOs to receive reports of patient safety events or concerns from providers and provide analyses of events to reporting providers. A reporting provider may be a HIPAA covered entity and, thus, information reported to a PSO may include protected health information that the PSO may analyze on behalf of the covered provider. The analysis of such information is a patient safety activity for purposes of PSQIA and the Patient Safety Rule, 42 CFR 3.10,

et seq.

While the HIPAA Rules as written would encompass a PSO as a business associate when the PSO was performing quality analyses and other activities on behalf of a covered health care provider, we propose this change to the definition of business associate to more clearly align the HIPAA and Patient Safety Rules.

We note that in some cases a covered health care provider, such as a public or private hospital, may have a component PSO that performs patient safety activities on behalf of the health care provider.

See

42 CFR 3.20. In such cases, the component PSO would not be a business associate of the covered entity but rather the persons performing patient safety activities would be workforce members of the covered entity. However, if the component PSO contracts out some of its patient safety activities to a third party, the third party would be a business associate of the covered entity. In addition, if a component PSO of one covered entity performs patient safety activities for another covered entity, such component PSO would be a business associate of the other covered entity.

b. Inclusion of Health Information Organizations (HIO), E-Prescribing Gateways, and Other Persons That Facilitate Data Transmission; as Well as Vendors of Personal Health Records

Section 13408 of the HITECH Act, which became effective on February 18, 2010, provides that an organization, such as a Health Information Exchange Organization, E-prescribing Gateway, or Regional Health Information Organization, that provides data transmission of protected health information to a covered entity (or its business associate) and that requires access on a routine basis to such protected health information must be treated as a business associate for purposes of the Act and the HIPAA Privacy and Security Rules. Section 13408 also provides that a vendor that contracts with a covered entity to allow the covered entity to offer a personal health record to patients as part of the covered entity's electronic health record shall be treated as a business associate. Section 13408 requires that such organizations and vendors enter into a written business associate contract or other arrangement with the covered entity in accordance with the HIPAA Rules.

In accordance with the Act, we propose to modify the definition of “business associate” to explicitly designate these persons as business

associates. Under proposed paragraphs (3)(i) and (ii) of the definition, the term “business associate” would include: (1) A Health Information Organization, E-prescribing Gateway, or other person that provides data transmission services with respect to protected health information to a covered entity and that requires routine access to such protected health information; and (2) a person who offers a personal health record to one or more individuals on behalf of a covered entity.

Section 13408 of the Act makes reference to Health Information Exchange Organizations; however, we instead include in the proposed definition the term “Health Information Organization” because it is our understanding that “Health Information Organization” is the more widely recognized and accepted term to describe an organization that oversees and governs the exchange of health-related information among organizations.

2

Section 13408 of the Act also specifically refers to Regional Health Information Organizations. However, we do not believe the inclusion of the term in the definition of “business associate” is necessary as a Regional Health Information Organization is simply a Health Information Organization that governs health information exchange among organizations within a defined geographic area.

3

Further, the specific terms of “Health Information Organization” and “E-prescribing Gateway” are merely illustrative of the types of organizations that would fall within this paragraph of the definition of “business associate.” We request comment on the use of these terms within the definition and whether additional clarifications or additions are necessary.

2

Department of Health and Human Services, Office of the National Coordinator for Health Information Technology, The National Alliance for Health Information Technology Report to the Office of the National Coordinator For Health Information Technology: Defining Key Health Information Terms, Pg. 24 (2008).

3

Id.

at 25.

Section 13408 also provides that the data transmission organizations that the Act requires to be treated as business associates are those that require access to protected health information on a routine basis. Conversely, data transmission organizations that do not require access to protected health information on a routine basis would not be treated as business associates. This is consistent with our prior interpretation of the definition of “business associate,” through which we have indicated that entities that act as mere conduits for the transport of protected health information but do not access the information other than on a random or infrequent basis are not business associates.

See http://www.hhs.gov/ocr/privacy/hipaa/faq/providers/business/245.html.

In contrast, however, entities that manage the exchange of protected health information through a network, including providing patient locator services and performing various oversight and governance functions for electronic health information exchange, have more than “random” access to protected health information and thus, would fall within the definition of “business associate.”

c. Inclusion of Subcontractors

We propose to add language in paragraph (3)(iii) of the definition of “business associate” to provide that subcontractors of a covered entity—

i.e.,

those persons that perform functions for or provide services to a business associate, other than in the capacity as a member of the business associate's workforce, are also business associates to the extent that they require access to protected health information. We also propose to include a definition of “subcontractor” in § 160.103 to make clear that a subcontractor is a person who acts on behalf of a business associate, other than in the capacity of a member of the workforce of such business associate. Even though we use the term “subcontractor,” which implies there is a contract in place between the parties, we note that the definition would apply to an agent or other person who acts on behalf of the business associate, even if the business associate has failed to enter into a business associate contract with the person. We request comment on the use of the term “subcontractor” and its proposed definition.

The proposed modifications are similar in structure and effect to the Privacy Rule's initial extension of privacy protections from covered entities to business associates through contract requirements to protect downstream protected health information. The proposed provisions avoid having privacy and security protections for protected health information lapse merely because a function is performed by an entity that is a subcontractor rather than an entity with a direct relationship with a covered entity. Allowing such a lapse in privacy and security protections may allow business associates to avoid liability imposed upon them by sections 13401 and 13404 of the Act, thus circumventing the congressional intent underlying these provisions. The proposed definition of “subcontractor” also is consistent with Congress' overall concern that the privacy and security protections of the HIPAA Rules extend beyond covered entities to those entities that create or receive protected health information in order for the covered entity to perform its health care functions. For example, as discussed above, section 13408 makes explicit that certain types of entities providing services to covered entities—

e.g.,

vendors of personal health records—shall be considered business associates. Therefore, consistent with Congress' intent in sections 13401 and 13404 of the Act, as well as its overall concern that the HIPAA Rules extent beyond covered entities to those entities that create or receive protected health information, we propose that downstream entities that work at the direction of or on behalf of a business associate and handle protected health information would also be required to comply with the applicable Privacy and Security Rule provisions in the same manner as the primary business associate, and likewise would incur liability for acts of noncompliance. We note, and further explain below, that this proposed modification would not require the covered entity to have a contract with the subcontractor; rather, the obligation would remain on each business associate to obtain satisfactory assurances in the form of a written contract or other arrangement that a subcontractor will appropriately safeguard protected health information. For example, under this proposal, if a business associate, such as a third party administrator, hires a company to handle document and media shredding to securely dispose of paper and electronic protected health information, then the shredding company would be directly required to comply with the applicable requirements of the HIPAA Security Rule (

e.g.,

with respect to proper disposal of electronic media) and the Privacy Rule (

e.g.,

with respect to limiting its uses and disclosures of the protected health information in accordance with its contract with the business associate).

d. Exceptions to Business Associate

We also propose to move the provisions at §§ 164.308(b)(2) and 164.502(e)(1)(ii) to the definition of business associate. These provisions provide that in certain circumstances, such as when a covered entity discloses protected health information to a health care provider concerning the treatment of an individual, a covered entity is not required to enter into a business

associate contract or other arrangement with the recipient of the protected health information. While we do not change the meaning of these provisions, we believe these limitations on the scope of “business associate” are more appropriately placed in the definition as exceptions to the term to make clear that the Department does not consider the recipients of the protected health information in these circumstances to be business associates. The movement of these exceptions and refinement of the definition of “business associate” also would help clarify that a person is a business associate if it meets the definition of “business associate,” even if a covered entity, or business associate with respect to a subcontractor, fails to enter into the required contract with the business associate.

e. Technical Changes to the Definition

For clarity and consistency, we also propose to change the term “individually identifiable health information” in the current definition of “business associate” to “protected health information,” since a business associate has no obligations under the HIPAA Rules with respect to individually identifiable health information that is not protected health information.

3. Definition of “Compliance Date”

The term “compliance date” currently refers only to covered entities. We propose a technical change to include business associates in the term, in light of the HITECH Act amendments, which apply certain provisions of the HIPAA Rules to business associates.

4. Definition of “Electronic Media”

The term “electronic media” was originally defined in the Transactions and Code Sets Rule issued on August 17, 2000 (65 FR 50312) and was included in the definitions at § 162.103. That definition was subsequently revised and moved to § 160.103. The purpose of the revision was to clarify that—

the physical movement of electronic media from place to place is not limited to magnetic tape, disk, or compact disk. This clarification removes a restriction as to what is considered to be physical electronic media, thereby allowing for future technological innovation. We further clarified that transmission of information not in electronic form before the transmission, for example, paper or voice, is not covered by this definition.

68 FR 8339, Feb. 20, 2003.

We propose to revise the definition of “electronic media” in the following ways. First, we would revise paragraph (1) of the definition to conform it to current usage, as set forth in “Guidelines for Media Sanitization” (

Definition of Medium,

NIST SP 800-88, Glossary B, p. 27 (2006)). The NIST definition, which was updated subsequent to the issuance of the Privacy and Security Rules, was developed in recognition of the likelihood that the evolution of development of new technology would make use of the term “electronic storage media” obsolete in that there may be “storage material” other than “media” that house electronic data. Second, we would add to paragraph (2) of the definition of “electronic media” a reference to intranets, to clarify that intranets come within the definition. Third, we propose to change the word “because” to “if” in the final sentence of paragraph (2) of the definition of “electronic media.” The definition assumed that no transmissions made by voice via telephone existed in electronic form before transmission; the evolution of technology has made this assumption obsolete. This modification would extend the policy described in the preamble discussion quoted above, but correct its application to current technology, where some voice technology is digitally produced from an information system and transmitted by phone.

5. Definition of “Protected Health Information”

We propose to modify the definition of “protected health information” at § 160.103 to provide that the Privacy and Security Rules do not protect the individually identifiable health information of persons who have been deceased for more than 50 years. This proposed modification is explained more fully below in Section VI.E. of the preamble where we discuss the proposed changes to the Privacy Rule related to the protected health information of decedents.

6. Definition of “Respondent”

The definition of the term “Respondent,” which is currently in § 160.302, would be moved to § 160.103. A reference to “business associate” would be added following the reference to “covered entity” in recognition of the potential liability imposed on business associates for violations of certain provisions of the Privacy and Security Rules by sections 13401 and 13404 of the Act.

7. Definition of “State”

The HITECH Act at section 13400, which became effective February 18, 2010, includes a definition of “State” to mean “each of the several States, the District of Columbia, Puerto Rico, the Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands.” This definition varies from paragraph (2) of the HIPAA definition of “State” at § 160.103, which does not include reference to American Samoa and the Northern Mariana Islands. Thus, for consistency with the definition applied to the HIPAA Rules by the HITECH Act, we propose to add reference to American Samoa and the Commonwealth of the Northern Mariana Islands in paragraph (2) of the definition of “State” at § 160.103.

8. Definition of “Workforce”

The HITECH Act is directly applicable to business associates and has extended liability for compliance with certain provisions of the Privacy and Security Rules to business associates. Because some provisions of the Act and the Privacy and Security Rules place obligations on the business associate with respect to workforce members, we propose to revise the definition of “workforce member” in § 160.103 to make clear that such term includes the employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a business associate, is under the direct control of the business associate.

D. Subpart B—Preemption of State Law, Section 160.201—Statutory Basis

We propose to modify § 160.201 regarding the statutory basis for the preemption of State law provisions to add a reference to section 264(c) of HIPAA, which contains the statutory basis for the exception to preemption at § 160.203(b) for State laws that are more stringent than the HIPAA Privacy Rule. We also propose to add a reference to section 13421(a) of the HITECH Act, which applies HIPAA's preemption rules to the HITECH Act's privacy and security provisions. Finally, we propose to re-title the provision to read “Statutory basis” instead of “Applicability.”

We also take this opportunity to make clear that section 264(c)(2) of HIPAA and § 160.203(b) do not create a Federal evidentiary privilege. Additionally, we take this opportunity to make clear that neither the HIPAA statute nor its implementing regulations give effect to State physician-patient privilege laws or provisions of State law relating to the privacy of individually identifiable health information for use in Federal court proceedings. Therefore, consistent with the Supremacy Clause, any State law that was preempted prior to HIPAA because of conflicts with a Federal law would continue to be preempted. Nothing in HIPAA or its implementing regulations is intended to expand the

scope of State laws, regardless of whether they are more or less stringent than Federal law.

E. Subpart B—Preemption of State Law, Section 160.202—Definitions.

1. Definition of “Contrary”

The term “contrary” is currently defined in § 160.202 to make clear when the preemption provisions of HIPAA apply to State law. Consistent with the limited application of the HIPAA provisions to covered entities only, the current definition of the term “contrary” does not include reference to business associates. However, section 13421(a) of the HITECH Act provides that the HIPAA preemption provision (section 1178 of the Social Security Act) applies to the provisions and requirements under the HITECH Act “in the same manner” as it would apply under the HIPAA provisions. Thus, the preemption provisions would apply to business associates, who are now, by virtue of the HITECH Act, required to comply with certain provisions of the HIPAA Rules and are subject to penalties for noncompliance, as discussed elsewhere. Thus, we propose to amend the definition of “contrary” by inserting references to business associates in paragraph (1) of the definition. We also expand the reference to the HITECH statutory provisions in paragraph (2) of the definition to encompass all of the sections of subtitle D of the HITECH Act, rather than merely to section 13402, which was added by the breach notifications regulations. These changes would give effect to section 13421(a).

2. Definition of “More Stringent”

The term “more stringent” is part of the statutory preemption language under HIPAA. HIPAA preempts State law that is contrary to a HIPAA privacy standard unless, among other exceptions, the State law is more stringent than the contrary HIPAA privacy standard. The current regulatory definition of “more stringent” does not include business associates. We propose to amend the definition to add a reference to business associates, for the reasons set out in the preceding discussion.

IV. Section-by-Section Description of the Proposed Amendments to the Enforcement Rule—Subparts C and D of Part 160

Section 13410 of the HITECH Act made several amendments that directly impact the Enforcement Rule, which applies to the Secretary's enforcement of all of the HIPAA Administrative Simplification Rules, as well as the recently promulgated Breach Notification Rule. We issued an interim final rule on October 30, 2009, 74 FR 56123, to address the HITECH Act amendments impacting the Enforcement Rule that became effective on February 18, 2009. For context, we describe those modifications to the Enforcement Rule briefly below. We then provide a section-by-section description of the other section 13410 amendments that are part of this proposed rule.

In addition, sections 13401 and 13404 of the HITECH Act impose direct civil money penalty liability on business associates for violations of the HITECH Act and certain Privacy and Security Rule provisions. In doing so, sections 13401(b) and 13404(c) of the Act provide that section 1176 of the Social Security Act shall apply to a violation by a business associate “in the same manner” as it would apply to a covered entity with respect to such a violation. Both provisions are, by virtue of section 13423, effective February 18, 2010.

The provisions of subparts C and D of part 160 currently apply by their terms solely to covered entities. Accordingly, to implement sections 13401(b) and 13404(c) of the Act, we propose to revise a number of provisions in both subparts to reflect this statutory change by adding the term “business associate” where appropriate, following a reference to “covered entity.” For ease, we list the sections in which the term “business associate” is added here rather than repeat the change in each discussion of the sections below: §§ 160.300; 160.304; 160.306(a) and (c); 160.308; 160.310; 160.312; 160.316; 160.401; 160.402; 160.404(b); 160.406; 160.408(c) and (d); and 160.410(a) and (c).

In addition to these references, we propose to add a paragraph in § 160.402(c)(2) to describe a business associate's liability for the actions of its agents, in accordance with the Federal common law of agency. This proposed modification is discussed more fully below in the discussion of § 160.402(c).

As noted above, the Department issued an interim final rule (IFR) on October 30, 2009, revising the Enforcement Rule to incorporate the provisions required by section 13410(d) of the HITECH Act that immediately took effect: Four categories of violations that reflect increasing levels of culpability, the corresponding tiers of civil money penalty amounts, and the revised limitations placed on the Secretary's authority to impose penalties. More specifically, the IFR revised subpart D of the Enforcement Rule to transfer the definitions of “reasonable cause,” “reasonable diligence,” and “willful neglect” from § 160.410(a) to a new definitions section at § 160.401. The IFR revised § 160.404 to incorporate, for violations occurring on or after February 18, 2009, the new penalty scheme required by section 13410(d), as follows: For violations in which it is established that the covered entity did not know and, by exercising reasonable diligence, would not have known that the covered entity violated a provision, an amount not less than $100 or more than $50,000 for each violation; for a violation in which it is established that the violation was due to reasonable cause and not to willful neglect, an amount not less than $1000 or more than $50,000 for each violation; for a violation in which it is established that the violation was due to willful neglect and was timely corrected, an amount not less than $10,000 or more than $50,000 for each violation; and for a violation in which it is established that the violation was due to willful neglect and was not timely corrected, an amount not less than $50,000 for each violation; except that a penalty for violations of the same requirement or prohibition under any of these categories may not exceed $1,500,000 in a calendar year. It also revised the affirmative defenses in § 160.410 for violations occurring on or after February 18, 2009, to remove a covered entity's lack of knowledge as an affirmative defense and to provide an affirmative defense when violations not due to willful neglect are corrected within 30 days. Finally, the IFR added a requirement that a notice of proposed determination pursuant to § 160.420 also reference the applicable category of violation. Readers are encouraged to refer to the IFR for a more detailed discussion of these topics as well as the Enforcement Rule's statutory and regulatory background.

See

74 FR 56123, 56124, Oct. 30, 2009.

The rules proposed below would revise many provisions of subparts C and D of part 160. However, the Department's current interpretations of the regulatory provisions at subparts C and D continue unchanged, except to the extent they are inconsistent with the changes to those provisions, as indicated below.

A. Subpart C—Compliance and Investigations, Section 160.304—Principles for Achieving Compliance

Section 160.304 identifies cooperation and assistance as two overarching principles for achieving compliance. The principle of cooperation, in § 160.304(a), states that “[t]he Secretary will, to the extent practicable, seek the cooperation of covered entities in

obtaining compliance with the applicable administrative simplification provisions.”

Section 13410(a) of the HITECH Act adds a new subsection (c) to section 1176 of the Social Security Act:

(c) NONCOMPLIANCE DUE TO WILLFUL NEGLECT.—

(1) IN GENERAL.—A violation of a provision of this part due to willful neglect is a violation for which the Secretary is required to impose a penalty under subsection (a)(1).

(2) REQUIRED INVESTIGATION.—For purposes of paragraph (1), the Secretary shall formally investigate any complaint of a violation of a provision of this part if a preliminary investigation of the facts of the complaint indicate such a possible violation due to willful neglect.

Section 13410(b)(1) makes the provisions of section 13410(a) effective February 18, 2011.

Under section 1176(c), HHS is required to impose a civil money penalty for violations due to willful neglect. Accordingly, although the Secretary often will still seek to correct indications of noncompliance through voluntary corrective action, there may be circumstances (such as circumstances indicating willful neglect), where the Secretary may seek to proceed directly to formal enforcement. As a conforming amendment, HHS proposes to add the phrase, “and consistent with the provisions of this subpart,” to § 160.304(a) to recognize the statutory revision.

B. Subpart C—Compliance and Investigations, Section 160.306(c)—Complaints to the Secretary

Section 160.306(c) of the Enforcement Rule currently provides the Secretary with discretion to investigate HIPAA complaints, through use of the word “may.” The new willful neglect provisions, at section 1176(c)(2) of the Social Security Act, will require HHS to investigate “any complaint of a violation of a provision of this part if a preliminary investigation of the facts of the complaint indicates * * * a possible violation due to willful neglect.”

HHS proposes to implement section 1176(c)(2) by adding a new paragraph (1) at § 160.306(c) to provide that the Secretary

will

investigate any complaint filed under this section when a preliminary review of the facts indicates a possible violation due to willful neglect. As a practical matter, HHS currently conducts a preliminary review of every complaint received and proceeds with the investigation in every eligible case where its preliminary review of the facts indicate a possible violation of the HIPAA Rules. Nevertheless, we propose this addition to § 160.306 to make clear our intention to pursue an investigation where a preliminary review of the facts indicates a possible violation due to willful neglect.

HHS proposes to conform the remainder of § 160.306(c) accordingly. The new § 160.306(c)(2) (presently, the initial sentence of § 160.306(c)) would be revised by replacing “complaints” with “any other complaint” to distinguish the Secretary's discretion with respect to complaints for which HHS's preliminary review of the facts does not indicate a possible violation due to willful neglect from the statutory requirement to investigate

all

complaints for which HHS's preliminary review of the facts indicates a possible violation due to willful neglect, as set out in the new § 160.306(c)(1). The current second sentence of § 160.306(c), which addresses the content of an investigation, would be renumbered as § 160.306(c)(3) and amended by changing the first word of the sentence from “such” to “an,” to signal the provision's application to any investigation, regardless of whether a preliminary review of the facts indicates a possible violation due to willful neglect.

C. Subpart C—Compliance and Investigations, Section 160.308—Compliance Reviews

Section 160.308 provides that the Secretary may conduct compliance reviews. Use of the word “may” in this section makes clear that this is a discretionary activity. While complaints and not compliance reviews are specifically mentioned in the statutory language of section 13410(a)(1)(B) of the Act regarding willful neglect, HHS proposes to also amend § 160.308 to provide that the Secretary will conduct a compliance review to determine whether a covered entity or business associate is complying with the applicable administrative simplification provision when a preliminary review of the facts indicates a possible violation due to willful neglect. This revision to § 160.308 furthers Congress' intent to strengthen enforcement with respect to potential violations due to willful neglect and ensures that investigations, whether or not initiated by complaint, are handled in a consistent manner. Also, the current language of § 160.308 would be redesignated as paragraph (b), and the words “in any other circumstance” would be added to the end of this paragraph to indicate that the discretionary authority of this paragraph applies to cases where the preliminary review of the facts does not indicate a possible violation due to willful neglect. Note that if HHS initiates an investigation of a complaint because its preliminary review of the facts indicates a possible violation due to willful neglect, HHS would not also be required to initiate a compliance review under this section, since it would be duplicative to do so.

D. Subpart C—Compliance and Investigations, Section 160.310—Responsibilities of Covered Entities

Section 160.310 explains a covered entity's responsibilities during complaint investigations and compliance reviews to make information available to the Secretary and to cooperate with the Secretary. Section 160.310(c)(3) provides that any protected health information obtained by the Secretary in connection with an investigation or compliance review will not be disclosed by the Secretary, except as necessary for determining and enforcing compliance with the HIPAA Rules or if otherwise required by law. We propose to also allow the Secretary to disclose protected health information if permitted under the Privacy Act at 5 U.S.C. 552a(b)(7). Section 552a(b)(7) permits the disclosure of a record on an individual contained within a Privacy Act protected system of records to another agency or instrumentality of any governmental jurisdiction within or under the control of the United States for a civil or criminal law enforcement activity if the activity is authorized by law and if the agency has made a written request to the agency that maintains the record. This proposed change is necessary to permit the Secretary to cooperate with other law enforcement agencies, such as the State Attorneys General pursuing HIPAA actions on behalf of State residents pursuant to section 13410(e) of the Act, or the Federal Trade Commission, pursuing remedies under other consumer protection authorities.

E. Subpart C—Compliance and Investigations, Section 160.312—Secretarial Action Regarding Complaints and Compliance Reviews

Where noncompliance is indicated, § 160.312 requires the Secretary to attempt to resolve situations by informal means. Section 1176(c)(2) of the Social Security Act, as added by section 13410(a) of the HITECH Act, will require formal investigation of a complaint “if a preliminary investigation of the facts of the complaint indicate * * * a possible

violation due to willful neglect.” Further, section 1176(c)(1) of the Social Security Act, as added by section 13410(a) of the HITECH Act, will require the Secretary to impose a civil money penalty where HHS makes a finding of a violation involving willful neglect. In addition to the proposed modification to § 160.306(c)(1), in light of the new provisions at section 1176(c), we propose to make clear that HHS is not required to attempt to resolve cases of noncompliance due to willful neglect by informal means. To do so, we propose to replace the word “will” in § 160.312(a)(1) with “may.” While this change would permit HHS to proceed with a willful neglect determination as appropriate, it would also permit HHS to seek to resolve complaints and compliance reviews that did not indicate willful neglect by informal means (

e.g.,

where the covered entity or business associate did not know and by exercising reasonable diligence would not have known of a violation, or where the violation is due to reasonable cause).

It should be noted that this amendment would not change the substance of the response set forth in the April 18, 2005, preamble to the proposed Enforcement Rule, at 70 FR 20224, 20245-6, regarding objections to the 60-day time limit for filing a request for a hearing. In that response, HHS indicated that it was not reasonable to assume that a notice of proposed determination would be served on a respondent with no warning because the covered entity would necessarily be made aware of, and have the opportunity to address, HHS's compliance concerns throughout the investigative period preceding the notice of proposed determination. This proposed change to § 160.312 would allow the Secretary to proceed directly to a notice of proposed determination without first attempting to resolve the matter informally. This proposed revision does not change the fact that during the course of a complaint investigation or a compliance review, a covered entity or business associate would be made aware of, and have the opportunity to address, HHS's compliance concerns.

F. Subpart D—Imposition of Civil Money Penalties, Section 160.401—Definitions

Section 160.401 provides definitions of the terms “reasonable cause,” “reasonable diligence,” and “willful neglect.” As discussed in the interim final rule, at 74 FR 56123, 56126-7, given section 13410(d) of the Act's use of these terms to describe the increasing levels of culpability for which increasing minimum levels of penalties may be imposed, HHS transferred these definitions from their prior placement at § 160.410(a) to signal the definitions' broader application to the entirety of subpart D of part 160. However, because section 13410(d) of the Act referred to these terms but did not amend these definitions, the interim final rule did not alter their content. HHS encourages readers, as it did in the interim final rule, to refer to prior preambles to the Enforcement Rule for detailed discussions of these terms at 70 FR 20224, 20237-9 and 71 FR 8390, 8409-11.

While the provisions of section 13410 of the Act do not explicitly require modification of these definitions, HHS is concerned that the

mens rea

demarcation between the categories of culpability associated with the new tiers of civil money penalty amounts is not sufficiently clear based on the existing definitions. As a result, certain violations (

i.e.,

those of which a covered entity or business associate has or should have knowledge, but does not have the conscious intent or reckless indifference associated with willful neglect) might not fit squarely within one of the established tiers. Therefore, HHS proposes to amend the definition of reasonable cause to clarify the scope of violations fitting within that definition.

HHS does not propose to otherwise modify the definitions associated with the categories of culpability of the amended section 1176(a) of the Social Security Act. However, we wish to clarify how the Secretary intends to apply these terms within this newly established context, to assist covered entities and business associates in tailoring their compliance activities appropriately. Accordingly, the discussion below also addresses the terms associated with the other categories of culpability (

i.e.,

knowledge, reasonable diligence, and willful neglect).

1. Reasonable Cause

Reasonable cause is currently defined, at § 160.401, to mean “circumstances that would make it unreasonable for the covered entity, despite the exercise of ordinary business care and prudence, to comply with the administrative simplification provision violated.” This definition is consistent with the Supreme Court's ruling in

United States

v.

Boyle,

469 U.S. 241, 245 (1985), which focused on whether circumstances were beyond the regulated person's control, thereby making compliance unreasonable.

See

70 FR 20224, 20238. Prior to the HITECH Act, section 1176 of the Social Security Act treated reasonable cause as a partial limitation on the Secretary's authority to impose a civil money penalty. That is, by establishing that a violation was due to reasonable cause and not willful neglect and was either corrected within a 30-day period or such additional period as the Secretary determined to be appropriate, a covered entity or business associate would bar the Secretary's imposition of a civil money penalty.

As described above, section 13410(d) of the HITECH Act revised section 1176 of the Social Security Act to establish four tiers of increasing penalty amounts to correspond to the levels of culpability associated with the violation. The first category of violation (and lowest penalty tier) covers situations where the covered entity or business associate did not know, and by exercising reasonable diligence would not have known, of a violation. The second category of violation (and next highest penalty tier) applies to violations due to reasonable cause and not to willful neglect. The third and fourth categories (and second-highest and highest penalty tiers) apply to circumstances where the violation was due to willful neglect that is corrected within a certain time period and willful neglect that is not so corrected, respectively. The importance of

mens rea,

or state of mind, in determining the degree of culpability is clear with respect to the first, third, and fourth categories, in that there is no

mens rea

with respect to the lowest category of violation, while the existence of

mens rea

is presumed with respect to the third and fourth categories of violation.

However, the current definition of reasonable cause does not address

mens rea

with respect to the second category of violations. HHS therefore proposes to amend the definition of “reasonable cause” in § 160.401 to clarify the full scope of violations that will come within the reasonable cause category of violations, including those circumstances that would make it unreasonable for the covered entity or business associate, despite the exercise of ordinary business care and prudence, to comply with the administrative simplification provisions violated, as well as those circumstances in which a covered entity or business associate has knowledge of a violation but lacks the conscious intent or reckless indifference associated with the willful neglect category of violations. To that end, HHS proposes to replace the current definition of “reasonable cause” with the following:

an act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the covered entity or business associate did not act with willful neglect.

As modified, the definition of “reasonable cause” will continue to recognize those circumstances that would make it unreasonable for the covered entity or business associate, despite the exercise of ordinary business care and prudence, to comply with the administrative simplification provisions violated. Consider the following example:

A covered entity received an individual's request for access but did not respond within the time periods provided for in § 164.524(b)(2). HHS's investigation reveals that the covered entity had compliant access policies and procedures in place, but that it had received an unusually high volume of requests for access within the time period in question. While the covered entity had responded to the majority of access requests received in that time period in a timely manner, it had failed to respond in a timely manner to several requests for access. The covered entity did respond in a timely manner to all requests for access it received subsequent to the time period in which the violations occurred.

In this example, the covered entity had knowledge of the violations but the investigation revealed circumstances that would make it unreasonable for the covered entity, despite the exercise of ordinary business care and prudence, to comply with the administrative simplification provisions violated. The investigation also revealed that the covered entity acted in a way that demonstrated a good faith attempt to comply with § 164.524(b)(2) by having compliant policies and procedures in place, responding to the majority of access requests in a timely manner, and otherwise responding to subsequent requests as required. In contrast, had the investigation revealed that the series of access requests occurred over a longer period of time, and that the covered entity did not attempt to address the backlog or communicate with the individuals, in writing, regarding the reasons for the delay or the date by which the covered entity would complete its action on the requests, the notice of proposed determination might alternatively categorize the violation as being due to willful neglect.

The modified definition of reasonable cause will also encompass those circumstances in which a covered entity or business associate has knowledge of the violation but lacks the conscious intent or reckless indifference associated with willful neglect. Consider the following example:

A covered entity presented an authorization form to a patient for signature to permit a disclosure for marketing purposes that did not contain the core elements required by § 164.508(c). HHS's investigation reveals that the covered entity was aware of the requirement for an authorization for a use or disclosure of protected health information for marketing and had attempted to draft a compliant authorization but had not included in the authorization the core elements required under § 164.508.

In this example, the covered entity failed to act with the ordinary care and business prudence of one seeking to comply with the Privacy Rule. Therefore, the violation cannot be considered to come within the category of violation that is associated with violations where the covered entity did not know (and by exercising reasonable diligence would not have known) of the violation. Yet, because the covered entity had attempted to draft a compliant authorization, it cannot be established that the omission was due to willful neglect involving either a conscious, intentional failure or reckless indifference to the obligation to comply with § 164.508. Unless otherwise resolved by informal means, HHS would have grounds to find that the violation was due to reasonable cause.

2. Knowledge and Reasonable Diligence

Prior rulemaking preambles discussing the Enforcement Rule explain the concept of knowledge, as it applies to the limitations (

i.e.,

affirmative defenses) that section 1176(b) of the Social Security Act places on the Secretary's authority to impose a civil money penalty. As they explain, “the knowledge involved must be knowledge that [a] violation has occurred, not just knowledge of the facts constituting the violation.”

See

71 FR 8390, 8410, Feb. 16, 2006. Moreover, a covered entity or business associate cannot assert an affirmative defense associated with its “lack of knowledge” if such lack of knowledge has resulted from its failure to inform itself about compliance obligations or to investigate received complaints or other information indicating likely noncompliance.

See

70 FR 20224, 20237-8, Apr. 18, 2005 and 71 FR 8390, 8410-11, Feb. 16, 2006.

Section 13410(d) of the Act establishes the category of violations where the covered entity or business associate did not know (and by exercising reasonable diligence would not have known) of a violation as warranting the lowest range of civil money penalty amounts. The HITECH Act incorporated the concepts of knowledge and reasonable diligence from HIPAA, and it did not revise their substance. HHS therefore expects to apply these existing concepts to the newly established penalty structure consistent with its prior interpretations. Consider the following examples:

1. A covered health care provider with a direct treatment relationship with an individual patient failed to provide the patient a complete notice of privacy practices in compliance with § 164.520(c). HHS's investigation reveals that the covered entity has a compliant notice of privacy practices, policies and procedures for provision of the notice, and appropriate training of its workforce regarding the notice and its distribution. The violation resulted from a printing error that failed to print two pages of the notice of privacy practices. The printing error affected a small number of the covered entity's supply of notices and was an isolated failure to provide an individual with the covered entity's notice of privacy practices.

2. A business associate failed to terminate a former employee's access privileges to electronic protected health information in compliance with § 164.308(a)(3)(ii)(C). HHS's investigation reveals that the business associate's policies and procedures require the termination of such access within a reasonable time period. The HHS investigation reveals that the business associate attempted to terminate the former employee's access in accordance with its policy, but that it instead terminated the access of a current employee who had the same name as the former employee.

In both examples, HHS's investigations reveal that the covered entity or business associate has compliant policies and procedures in place, as well as some action by each covered entity or business associate indicating its intent to implement the respective Privacy Rule requirements. The investigations also reveal noncompliance that the exercise of reasonable diligence would not have avoided.

HHS also notes that, in some circumstances, we expect that the knowledge of an employee or agent of a covered entity or business associate may determine whether a violation implicates the “did not know” or “reasonable cause” categories of violation. That is, absent an exception under the Federal common law of agency, the knowledge of an employee or agent will generally be imputed to its principal (

i.e.,

the covered entity or business associate).

See

70 FR 20224, 20237 and 71 FR 8390, 8402-3 (discussing imputation of knowledge under the Federal common law of agency and violations attributed to a covered entity, respectively). Consider the following example:

A hospital employee accessed the paper medical record of his ex-spouse while he was on duty to discover her current address for a personal reason, knowing that such access is not permitted by the Privacy Rule and contrary to the policies and procedures of the hospital. HHS's investigation reveals that the covered entity had appropriate and reasonable safeguards regarding employee access to medical records, and that it had delivered appropriate training to the employee.

In this example, the “did not know” category of violation is implicated with respect to the covered entity because the

mens rea

element of knowledge cannot be established. That is, while the employee's act is attributed to the covered entity, the employee's knowledge of the violation cannot be imputed to the covered entity because the employee was acting adversely to the covered entity. The Federal common law of agency does not permit the imputation of knowledge to the principal where the agent consciously acts in a manner that is adverse to the principal.

3. Willful Neglect

Willful neglect is defined, at § 160.401, to mean the “conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated.” The term not only presumes actual or constructive knowledge on the part of the covered entity that a violation is virtually certain to occur but also encompasses a conscious intent or degree of recklessness with regard to its compliance obligations.

While the HITECH Act references willful neglect in several provisions, it does not revise the term's definition. HHS therefore expects to apply the current definition of willful neglect to all newly established contexts in the same manner as previously discussed. Consider the following examples:

1. A covered entity disposed of several hard drives containing electronic protected health information in an unsecured dumpster, in violation of § 164.530(c) and § 164.310(d)(2)(i). HHS's investigation reveals that the covered entity had failed to implement any policies and procedures to reasonably and appropriately safeguard protected health information during the disposal process.

2. A covered entity failed to respond to an individual's request that it restrict its uses and disclosures of protected health information about the individual. HHS's investigation reveals that the covered entity does not have any policies and procedures in place for consideration of the restriction requests it receives and refuses to accept any requests for restrictions from individual patients who inquire.

3. A covered entity's employee lost an unencrypted laptop that contained unsecured protected health information. HHS's investigation reveals the covered entity feared its reputation would be harmed if information about the incident became public and, therefore, decided not to provide notification as required by § 164.400

et seq.

The facts in these examples demonstrate that the covered entities had actual or constructive knowledge of their various violations. In addition, the covered entities' failures to develop or implement compliant policies and procedures or to respond to incidents as required by § 164.400

et seq.

demonstrate either conscious intent or reckless disregard with respect to their compliance obligations. In the second example, the covered entity's refusal to accept any requests for restrictions from individual patients who inquire would be grounds for a separate finding of a violation due to willful neglect.

4. Correction of Willful Neglect Violations

We also note that while a covered entity's or business associate's correction of a willful neglect violation will not bar the imposition of a civil money penalty, such correction may foreclose the Secretary's authority to impose a penalty from the highest penalty tier prescribed by section 1176(a)(1) of the Social Security Act. While not all violations can be corrected, in the sense of being fully undone or remediated, HHS has previously set forth a broad interpretation of “corrected,” in light of the statute's association of the term with “failure to comply.”

See

71 FR 8390, 8411 (recognizing that the term “corrected” could include correction of a covered entity's noncompliant procedure by making the procedure compliant). For example, in the event a covered entity's or business associate's inadequate safeguards policies and procedures result in an impermissible disclosure, the disclosure violation itself could not be fully undone or corrected. The safeguards violation, however, could be “corrected” in the sense that the noncompliant policies and procedures could be brought into compliance. In any event, corrective action will always be required of a covered entity or business associate.

G. Subpart D—Imposition of Civil Money Penalties, Section 160.402—Basis for a Civil Money Penalty

Section 160.402(a) provides the general rule that the Secretary will impose a civil money penalty upon a covered entity if the Secretary determines that the covered entity violated an administrative simplification provision. Paragraphs (b) and (c) of this section explain the basis for a civil money penalty against a covered entity where more than one covered entity is responsible for a violation, where an affiliated covered entity is responsible for a violation, and where an agent of a covered entity is responsible for a violation. As explained above, this proposed rule would add references to “business associate” where appropriate in this section to effectuate the HITECH Act's imposition of liability on business associates for violations of the HITECH Act and certain Privacy and Security Rule provisions.

Further, in paragraph (c), which provides the basis for the imposition of a civil money penalty against a covered entity for the acts of its agent, in accordance with the Federal common law of agency, we propose to add a parallel provision providing for civil money penalty liability against a business associate for the acts of its agent. Thus, we propose to add a new paragraph (2) to § 160.402(c) to provide that a business associate is liable, in accordance with the Federal common law of agency, for a civil money penalty for a violation based on the act or omission of any agent of the business associate, including a workforce member or subcontractor, acting within the scope of the agency.

The existing language of § 160.402(c) regarding the liability of covered entities for the acts of their agents would be redesignated as paragraph (1), with one substantive change. This section currently provides an exception for covered entity liability for the acts of its agent in cases where the agent is a business associate, the relevant contract requirements have been met, the covered entity did not know of a pattern or practice of the business associate in violation of the contract, and the covered entity did not fail to act as required by the Privacy or Security Rule with respect to such violations. We propose to remove this exception to principal liability for the covered entity so that the covered entity remains liable for the acts of its business associate agents, regardless of whether the covered entity has a compliant business associate agreement in place. This change is necessary to ensure, where the covered entity has contracted out a particular obligation under the HIPAA Rules, such as the requirement to provide individuals with a notice of privacy practices, that the covered entity remains liable for the failure of its business associate to perform that obligation on the covered entity's behalf.

We do not believe this proposed change would place any undue burden on covered entities, since covered entities are customarily liable for the acts of their agents under agency common law. We note that this proposed regulatory change does not create liability for covered entities with respect to business associates that are not agents,

e.g.,

independent contractors. The determination of whether a business associate is an agent of a covered entity, or whether a subcontractor is an agent of a business associate, will be based on the facts of the relationship, such as the level of control over the business associate's or subcontractor's conduct.

H. Subpart D—Imposition of Civil Money Penalties, Section 160.408—Factors Considered in Determining the Amount of a Civil Money Penalty

1. Determination of Penalty Amounts Prior to the HITECH Act

Section 160.408 implements section 1176(a)(2) of the Social Security Act, which requires the Secretary, when imposing a civil money penalty, to apply the provisions of section 1128A of the Social Security Act “in the same manner as such provisions apply to the imposition of a civil money penalty under section 1128A.” As currently written, Section 1128A requires the Secretary to take into account—

(1) The nature of the claims and the circumstances under which they were presented,

(2) The degree of culpability, history of prior offenses and financial condition of the person presenting the claims, and

(3) Such other matters as justice may require.

Like other regulations that implement section 1128A, HHS tailored these factors by breaking them down into their component elements and providing a more specific list of circumstances, within each component, that apply to the context of HIPAA Rule violations. Because the Enforcement Rule applies to a number of rules, which apply to an enormous number of entities and circumstances, HHS left to the Secretary's discretion the decisions of whether and how (

i.e.,

as either aggravating or mitigating) to consider the following factors in determining the amount of a civil money penalty:

(a) The nature of the violation, in light of the purpose of the rule violated.

(b) The circumstances, including the consequences, of the violation, including but not limited to * * * [specific circumstances]

(c) The degree of culpability of the covered entity, including but not limited to * * * [specific circumstances]

(d) Any history of prior compliance with the administrative simplification provisions, including violations, by the covered entity, including but not limited to * * * [specific circumstances]

(e) The financial condition of the covered entity, including but not limited to * * * [specific circumstances]

(f) Such other matters as justice may require.

See

70 FR 20224, 20235-6 and 71 FR 8390, 8407-9 for a discussion of HHS's interpretation of the factors currently enumerated in § 160.408.

2. Determination of Penalty Amounts After the HITECH Act

As discussed in more detail in the IFR, section 13410(d) of the HITECH Act modified section 1176(a)(1) of the Social Security Act in several ways, including the establishment of tiers of penalty amounts that are associated with increasing levels of culpability. It also added a provision to section 1176(a)(1) of the Social Security Act directing HHS to “base such determination [of the appropriate penalty amount] on the nature and extent of the violation and the nature and extent of the harm resulting from such violation.” The HITECH Act did not modify section 1176(a)(2) (requiring application of section 1128A). In addition, many of the factors currently identified by § 160.408 already pertain to the nature of the violation and the resulting harm. Section 160.408(a), for example, identifies the nature of the violation for consideration; paragraph (b) addresses the circumstances, including the consequences, of the violation (

e.g.,

physical harm, financial harm and whether the violation hindered or facilitated an individual's ability to obtain health care); and paragraph (f) addresses such other matters as justice may require. Thus, HHS did not modify § 160.408 in the IFR.

Upon further consideration of the statutory mandates and the significantly broader range of penalty amounts available, HHS believes it is appropriate to amend the structure of § 160.408, to make explicit the new statutory requirement that the Secretary consider the nature and extent of the violation and the nature and extent of the harm resulting from the violation, in addition to those factors enumerated in section 1128A. Thus, HHS proposes to revise § 160.408(a) and (b), as discussed below, to require the Secretary's consideration of the nature and extent of the violation, as well as the nature and extent of the harm resulting from violation, in addition to those factors referenced by section 1128A. We would exclude, however, the factor presently identified as § 160.408(c) (the degree of culpability of covered entity), which originated in section 1128A. Congress' revision of section 1176(a)(1) of the Social Security Act to establish increasing tiers of penalty amounts that reflect increasing degrees of culpability renders consideration of the degree of culpability as an aggravating or mitigating factor redundant. In contrast, HHS is not proposing to amend the Secretary's discretion with respect to the non-exhaustive list of specific circumstances that may be considered.

In addition, HHS proposes to reorganize the remaining, specific circumstances under § 160.408(a) and (b) to better reflect the categories to which they are now attributed, to add another circumstance for consideration under each, as described below, to explicitly provide that the Secretary's consideration of all specific circumstances is optional, and to modify the phrase “prior violations” in subsections (c)(1) and (2) to read “indications of noncompliance.”

a. The Nature and Extent of the Violation

HHS proposes to revise subsection (a) to identify “[t]he nature and extent of the violation,” as the first factor the Secretary must consider in determining a civil money penalty amount. While the “the nature of the violation” was previously identified for consideration, as it is grounded in section 1128A, the current list of factors in § 160.408 does not specifically reference “the extent of the violation,” which section 1176(a) now requires. We also propose to transfer “the time period during which the violation(s) occurred,” to this factor and to add, “the number of individuals affected,” since both circumstances might be indicative measures of “the nature and extent of the violation.” Our compliance and enforcement experience to date further supports the addition of the latter, particularly with respect to potential violations that negatively affect numerous individuals (

e.g.,

where disclosure of protected health information in multiple explanation of benefits statements that were mailed to the wrong individuals resulted from one inadequate safeguard but affected a large number of beneficiaries). We recognize these specific circumstances might also be considered under § 160.406, with respect to counting violations. In this regard, we direct readers' attention to 71 FR 8390, 8409 (responding to a comment expressing concern that the overlap of certain variables proposed in § 160.406 with factors proposed in § 160.408 might result in compound liability by asserting that since

consideration of such circumstances may be relevant to each separable element of the penalty calculation, their consideration will be different in nature).

b. The Nature and Extent of the Harm Resulting From the Violations

HHS proposes to revise subsection (a) to identify “[t]he nature and extent of the harm resulting from the violation” as the second factor the Secretary must consider. This minor amendment merely conforms the factor's language to the amended statutory language and continues to include the optional consideration of several specific circumstances which might be indicative of harm. In addition to these specific circumstances, HHS proposes to add reputational harm to make clear that reputational harm is as cognizable a form of harm as physical or financial harm.

c. The History of Prior Compliance With the Administrative Simplification Provisions

HHS proposes to modify the phrase “prior violations” in § 160.408(c)(1) and (2) to read “indications of noncompliance.” As defined in § 160.302, “violation” or “violate” means, “as the context may require, failure to comply with an administrative simplification provision.” Use of the term is generally reserved, however, to circumstances in which the Department has made a formal finding of a violation through a notice of proposed determination. As explained in 71 FR 8390, 8408, a covered entity's general history of HIPAA compliance is relevant in determining the amount of a civil money penalty within the penalty range. When we reviewed this language of § 160.408(c)(1) and (2) for the purposes of this rulemaking, we noticed that the regulatory text uses the term “violation” which is generally reserved for use in a notice of proposed determination. We are proposing to change this terminology to “indications of noncompliance” to make the regulatory language consistent with HHS' policy of considering a covered entity's general history of HIPAA compliance.

I. Section 160.410—Affirmative Defenses

Section 160.410 currently implements the limitations placed on the Secretary's authority to impose a civil money penalty under section 1176(b) of the Act. As amended by the IFR, § 160.410 is organized to implement section 13410(d) of the HITECH Act in a way that distinguishes the affirmative defenses available to covered entities and business associates prior to, on, or after February 18, 2009, the day after section 13410(d) of the HITECH Act became effective.

See

74 FR 56123, Oct. 30, 2009, for a detailed discussion of the IFR's recent amendments.

Section 13410(a)(1) revises section 1176(b) to replace the phrase, “if the act constitutes an offense

punishable

under section 1177” with “a penalty

has been imposed

under section 1177 with respect to such act.” This statutory change is effective February 18, 2011.

HHS proposes to amend § 160.410 to implement the revision of section 1176(b)(1) of the Social Security Act by providing in a new paragraph (a)(1) that the affirmative defense of criminally “punishable” is applicable to penalties imposed prior to February 18, 2011. A new paragraph (a)(2) in that section would make clear that, on or after February 18, 2011, the Secretary's authority to impose a civil money penalty will only be barred to the extent a covered entity or business associate can demonstrate that a penalty has been imposed under 42 U.S.C. 1320d-6 with respect to such act. As a conforming change, current paragraphs (a)(2) and (a)(3) are renumbered as paragraphs (b)(1) and (b)(2), respectively, and current paragraph (b) is renumbered as paragraph (c).

As an additional conforming change, HHS also proposes to amend § 160.410(a)(3)(i) (which has been redesignated as § 160.410(b)(2)(i)) to replace the term “reasonable cause” with the unrevised text of its current definition. This will ensure that the current definition is applied to violations occurring prior to February 18, 2009, thereby avoiding any potential issues regarding a retroactive application of the revised term.

J. Section 160.412—Waiver

We propose conforming changes to this section, to align the cross-references to § 160.410 with the proposed revisions to that section discussed above.

K. Subpart D—Imposition of Civil Money Penalties, Section 160.418—Penalty Not Exclusive

We propose to revise this section to incorporate a reference to the provision of the Patient Safety and Quality Improvement Act of 2005 at 42 U.S.C. 299b-22 that provides that penalties are not to be imposed under both that act and the Privacy Rule for the same violation.

V. Section-by-Section Description of the Proposed Amendments to Subpart A of Part 164 and the Security Rule in Subpart C of Part 164

The HITECH Act made several amendments that directly impact current provisions of the HIPAA Security Rule. We discuss the proposed changes to the Security Rule as a result of the HITECH Act in our section-by-section description below. We also discuss various technical and conforming proposed changes to the Security Rule, as well as proposed changes to provisions in subpart A of part 164, which applies to both the Security and Privacy Rules.

A. Technical Changes to Subpart A—General Provisions

1. Section 164.102—Statutory Basis

This section sets out the statutory basis of part 164. We propose a technical change to include a reference to the provisions of sections 13400 through 13424 of the HITECH Act upon which the regulatory changes proposed below are based.

2. Section 164.104—Applicability

This section sets out to whom part 164 applies. We propose to replace the existing paragraph (b) with an applicability statement for business associates, consistent with the provisions of the HITECH Act that are discussed more fully below. Proposed paragraph (b) would make clear that, where provided, the standards, requirements, and implementation specifications of the HIPAA Privacy, Security, and Breach Notification Rules apply to business associates. We propose to remove as unnecessary the existing language in § 164.104(b) regarding the obligation of a health care clearinghouse to comply with § 164.105 relating to organizational requirements of covered entities.

3. Section 164.105—Organizational Requirements

a. Section 164.105

Section 164.105 outlines the organizational requirements and implementation specifications for health care components of covered entities and for affiliated covered entities. As § 164.105 now also applies to subpart D of part 164 regarding breach notification for unsecured protected health information, we propose to remove several references to subparts C and E throughout this section to make clear that the provisions of this section also apply to the new subpart D of this part. In addition, we propose the following modifications to this section.

b. Section 164.105(a)(2)(ii)(C)-(E)

We propose to modify this section to remove as unnecessary paragraphs (C) and (D), which pertain to the obligation of a covered entity to ensure that any component that performs business associate-like activities and is included in the health care component complies with the requirements of the Privacy and Security Rules, and to re-designate paragraph (E) as (C). A covered entity's obligation to ensure that a health care component complies with the Privacy and Security Rules is already set out at § 164.105(a)(2)(ii). In addition, in light of a business associate's new direct liability for compliance with certain of the Security and Privacy Rule provisions, we request comment on whether we should require, rather than permit as is currently the case under § 164.105(a)(2)(iii)(C), a covered entity that is a hybrid entity to include a component that performs business associate-like activities within its health care component so that such components are directly subject to the Rules.

c. Section 164.105(a)(2)(iii)(C)

We propose to modify this section to re-designate § 164.105(a)(2)(iii)(C) as (D), and to include a new paragraph (C), which makes clear that, with respect to a hybrid entity, the covered entity itself, and not merely the health care component, remains responsible for complying with §§ 164.314 and 164.504 regarding business associate arrangements and other organizational requirements. This proposed modification is intended to recognize that hybrid entities may need to execute legal contracts and conduct other organizational matters at the level of the legal entity rather than at the level of the health care component.

d. Section 164.105(b)(1)

We propose to fix a minor typographical error in this paragraph by redesignating the second paragraph (1) as paragraph (2).

e. Section 164.105(b)(2)(ii)

We propose to simplify this paragraph by collapsing subparagraphs (A), (B), and (C) regarding the obligations of an affiliated entity to comply with the Privacy and Security Rules into one provision, and to expand the reference to compliance with the “part” so that the breach notification obligations in subpart D are also included.

4. Section 164.106—Relationship to Other Parts

We propose to add a reference to business associates, consistent with their inclusion elsewhere throughout the other HIPAA Rules.

B. Modifications to the HIPAA Security Rule in Subpart C

1. References to Business Associates

The Security Rule, as it presently stands, does not directly apply to business associates of covered entities. However, section 13401 of the HITECH Act, which became effective on February 18, 2010, provides that the Security Rule's administrative, physical, and technical safeguards requirements in §§ 164.308, 164.310, and 164.312, as well as its policies and procedures and documentation requirements in § 164.316, shall apply to business associates in the same manner as these requirements apply to covered entities, and that business associates shall be civilly and criminally liable for penalties for violations of these provisions.

Accordingly, to implement section 13401 of the HITECH Act, we propose to insert references to “business associate” in subpart C, as appropriate, following references to “covered entity” to make clear that these provisions of the Security Rule also apply to business associates. In particular, we propose to modify the following sections by adding references to business associates: §§ 164.302 (applicability), 164.304 (definitions of “administrative safeguard” and “physical safeguard”), 164.308, 164.310, 164.312, and 164.316. In addition, we propose the changes below to the Security Rule.

2. Section 164.306—Security Standards: General Rules

Section 13401 of the HITECH Act pertaining to requirements on business associates does not specifically make reference to § 164.306 of the Security Rule. However, § 164.306 sets out the general rules that apply to all of the security standards and implementation specifications that follow. Thus, for example, § 164.306(b)(2) sets out the particular factors that covered entities must take into account in deciding which security measures to use, and § 164.306(d) sets out the general rule that required implementation specifications must be implemented and the process and basis for implementing addressable implementation specifications. Accordingly, §§ 164.308, 164.310, and 164.312 provide that the administrative, physical, and technical safeguards of the Security Rule must be implemented “in accordance with § 164.306.” We do not believe that Congress intended to apply enumerated Security Rule sections to business associates in a different manner than to covered entities, as evidenced by the statutory language that these sections should be applied to business associates “in the same manner that such sections apply to the covered entity.” For these reasons, we also propose to revise § 164.306 to insert the word “business associate,” as appropriate, so that the general rules found at § 164.306 apply to business associates in the same manner as covered entities.

In addition, we propose technical revisions to § 164.306(e) to more clearly indicate that to maintain security measures that continue to meet the requirements of §§ 164.308, 164.310, and 164.312, covered entities and business associates must review and modify such security measures and update documentation accordingly under § 164.316(b)(2)(iii).

3. Section 164.308—Administrative Safeguards

First, as noted above, we propose to modify § 164.308 to include throughout appropriate references to business associates. Second, we propose a technical change to § 164.308(a)(3)(ii)(C) regarding security termination procedures for workforce members, to add the words “or other arrangement with” after “employment of” in recognition of the fact that not all workforce members are employees (

e.g.,

some may be volunteers) of a covered entity or business associate. Third, we propose to remove the reference to § 164.306 in paragraph (b)(1) as unnecessary. Fourth, as discussed below, we propose a number of modifications to the provisions in this section regarding business associate contracts and other arrangements to conform to and address modifications proposed in the definition of “business associate,” including the proposed inclusion of subcontractors within the scope of “business associate.”

Section 164.308(b) provides that a covered entity may permit a business associate to create, receive, maintain, or transmit electronic protected health information only if the covered entity has a contract or other arrangement in place to ensure the business associate will appropriately safeguard the protected health information. Section 164.308(b)(2) contains several exceptions to this general rule for certain situations that do not give rise to a business associate relationship, such as where a covered entity discloses electronic protected health information to a health care provider concerning the treatment of an individual. We propose to remove these exceptions from § 164.308(b)(2), since as discussed

above, we propose to include these as exceptions to the definition of “business associate.”

In addition, we propose to modify § 164.308(b)(1) and (2) to clarify the new proposed requirements on business associates with regard to subcontractors. As described above with respect to the definition of “business associate” in § 160.103, we propose to include in the definition subcontractors that create, receive, maintain, or transmit protected health information on behalf of a business associate. However, we do not intend this proposed modification to mean that a covered entity is required to have a contract with the subcontractor. Rather, such obligation is to remain with the business associate who contracts with the subcontractor. Accordingly, in § 164.308(b)(1), we propose to clarify that covered entities are not required to obtain satisfactory assurances in the form of a contract or other arrangement with a business associate that is a subcontractor. In § 164.308(b)(2), we then propose to make clear that it is the business associate that must obtain the required satisfactory assurances from the subcontractor to protect the security of electronic protected health information.

We propose to remove the provision at § 164.308(b)(3), which provides that a covered entity that violates the satisfactory assurances it provided as a business associate of another covered entity will be in noncompliance with the Security Rule's business associate provisions, as a covered entity's actions as a business associate of another covered entity are now directly regulated by the Security Rule's provisions that apply to business associates.

Finally, in § 164.308(b)(4) (renumbered as § 164.308(b)(3)), which requires documentation of the required satisfactory assurances through a written contract or other arrangement, we propose to add a reference to the new paragraph at § 164.308(b)(2) regarding business associates and subcontractors.

4. Section 164.314—Organizational Requirements

Section 13401 of the HITECH Act does not include § 164.314 among the provisions for which business associates are directly liable. However, section 13401 does state that § 164.308 applies to business associates “in the same manner” that the provision applies to covered entities. Section 164.308(b) requires a covered entity's business associate agreements to conform to the requirements of § 164.314. Accordingly, in order for § 164.308(b) to apply to business associates in the same manner as it applies to covered entities, we have revised § 164.314 to reflect that it is also applicable to agreements between business associates and subcontractors that create, receive, maintain, or transmit electronic protected health information.

We also propose a number of modifications to the business associate contract requirements in § 164.314 to streamline the provisions. First, we propose to remove § 164.314(a)(1)(ii) regarding the steps a covered entity must take if it knows of a material breach or violation by the business associate of the contract. A parallel provision exists in the Privacy Rule's business associate contract provisions at § 164.504 and, since a business associate for purposes of the Security Rule is also always a business associate for purposes of the Privacy Rule, the inclusion of a duplicate provision in the Security Rule is unnecessary. For the same reason, we also propose to remove the contract provision at § 164.314(a)(2)(i)(D) authorizing the termination of the contract by the covered entity if it is determined the business associate has violated a material term of the contract. A parallel provision exists in the Privacy Rule at § 164.504(e)(2)(iii). Also, because the Privacy Rule has a parallel provision, we remove the specific requirements under § 164.314(a)(2)(ii) for other arrangements, such as a memorandum of understanding when both a covered entity and business associate are governmental entities, and instead simply refer to the requirements of § 164.504(e)(3).

Second, we propose the following modifications to the remaining contract provision requirements: (1) In § 164.314(a)(2)(i)(A), we streamline the provision to simply indicate a business associate's obligation to comply with the Security Rule; (2) in § 164.314(a)(2)(i)(B), we revise the language with respect to ensuring subcontractors implement reasonable and appropriate safeguards to refer to the proposed requirement at § 164.308(b)(4) that would require a business associate to enter into a contract or other arrangement with a subcontractor to protect the security of electronic protected health information; and (3) in § 164.314(a)(2)(i)(C), with respect to the reporting of security incidents by business associates to covered entities, we make clear that the business associate contract must provide that the business associate will report to the covered entity breaches of unsecured protected health information as required by § 164.410 of the breach notification rules.

Third, we add a provision at § 164.314(a)(2)(iii) that provides that the requirements of this section for contracts or other arrangements between a covered entity and business associate would apply in the same manner to contracts or other arrangements between business associates and subcontractors required by the proposed requirements of § 164.308(b)(4). For example, to comply with proposed § 164.314(a)(2)(i)(C), a business associate contract between a business associate and a business associate subcontractor must provide that the subcontractor report any security incident of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410, to the business associate. Thus, if a breach of unsecured protected health information occurs at or by a subcontractor, the subcontractor must notify the business associate of the breach, which then must notify the covered entity of the breach. The covered entity then notifies the affected individuals, the Secretary, and, if applicable, the media, of the breach, unless it has delegated such responsibilities to a business associate.

Finally, we propose to remove the reference to subcontractors in § 164.314(b)(2)(iii) regarding amendment of group health plan documents as a condition of disclosure of protected health information to a plan sponsor, to avoid confusion with the use of the term subcontractor when referring to subcontractors that are business associates. This modification does not constitute a substantive change to § 164.314(b).

VI. Section-by-Section Description of the Proposed Amendments to the Privacy Rule

The HITECH Act made a number of amendments that affect current provisions of the Privacy Rule. In the section-by-section description of the proposed regulatory changes below, we discuss the HITECH Act requirements and the regulatory provisions affected by them, as well as certain other substantive proposed changes to the Privacy Rule intended to improve the workability and effectiveness of the Rule and to conform the Privacy Rule to PSQIA. At the end of this discussion, we also briefly list a number of proposed technical corrections and conforming changes to the Privacy Rule that are not otherwise addressed elsewhere.

A. Section 164.500—Applicability

We propose to revise § 164.500 to include new § 164.500(c) and to

redesignate the current § 164.500(c) as (d). In accordance with section 13404 of the HITECH Act, which applies certain of the Privacy Rule requirements to business associates, as discussed more fully below, § 164.500(c) would now clarify that, where provided, the standards, requirements, and implementation specifications of the Privacy Rule apply to business associates.

B. Section 164.501—Definitions

1. Definition of “Health Care Operations”

PSQIA, 42 U.S.C. 299b-21

et seq.,

provides, among other things, that PSOs are to be treated as business associates of covered health care providers. Further, PSQIA provides that the patient safety activities of PSOs in relation to HIPAA covered health care providers are deemed to be health care operations under the Privacy Rule.

See

42 U.S.C. 299b-22(i).

We propose to amend paragraph (1) of the definition of “health care operations” to include a reference to patient safety activities, as defined in the PSQIA implementing regulation at 42 CFR 3.20. Many health care providers participating in the voluntary patient safety program authorized by PSQIA are HIPAA covered entities; PSQIA acknowledges that such providers must also comply with the Privacy Rule and deems patient safety activities to be health care operations under the Privacy Rule. While such activities are already encompassed within paragraph (1) of the definition, which addresses various quality activities, we propose to expressly include patient safety activities within paragraph (1) of the definition of health care operations to expressly conform the definition to PSQIA and to eliminate the potential for any confusion. This modification would also address public comments the Department received during the rulemaking period for the PSQIA implementing regulations, which urged the Department to modify the definition of “health care operations” in the Privacy Rule to expressly reference patient safety activities so that the intersection of the Privacy and PSQIA Rules would be clear.

See

73 FR 70732, 70780, November 21, 2008.

2. Definition of “Marketing”

The Privacy Rule requires covered entities to obtain a valid authorization from individuals before using or disclosing protected health information to market a product or service to them.

See

§ 164.508(a)(3). Section 164.501 defines “marketing” as making a communication about a product or service that encourages recipients of the communication to purchase or use the product or service. Paragraph (1) of the definition includes a number of exceptions to marketing for certain health-related communications. In particular, the Privacy Rule does not consider the following communications to be marketing: (1) Communications made to describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communications, including communications about: the entities participating in a healthcare provider network or health plan network; replacement of, or enhancements to, a health plan; and health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits; (2) communications made for the treatment of the individual; and (3) communications for case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual. Thus, a covered entity is permitted to make these excepted communications without an individual's authorization as either treatment or health care operations communications, as appropriate, under the Privacy Rule. In addition, the Privacy Rule does not require a covered entity to obtain individual authorization to communicate face-to-face or to provide only promotional gifts of nominal value to the individual.

See

§ 164.508(a)(3)(i). However, a covered entity must obtain prior written authorization from an individual to send communications to the individual about non-health related products or services or to give or sell the individual's protected health information to a third party for marketing.

See

the current paragraph (2) of the definition of “marketing” in the Privacy Rule. Still, concerns have remained about the ability under these provisions for a third party to pay a covered entity in exchange for the covered entity to send health-related communications to an individual about the third party's products or services.

Section 13406(a) of the HITECH Act, which became effective on February 18, 2010, addresses these marketing provisions. In particular, section 13406(a) of the HITECH Act limits the health-related communications that may be considered health care operations and thus, that are excepted from the definition of “marketing” under the Privacy Rule to the extent a covered entity receives or has received direct or indirect payment in exchange for making the communication. In cases where the covered entity would receive such payment, the HITECH Act at section 13406(a)(2)(B) requires that the covered entity obtain the individual's valid authorization prior to making the communication, or, if applicable, prior to its business associate making the communication on its behalf in accordance with its written contract. Section 13406(a)(2)(A) of the HITECH Act includes an exception to the payment limitation for communications that describe only a drug or biologic that is currently being prescribed to the individual as long as any payment received by the covered entity in exchange for making the communication is reasonable in amount. Section 13406(a)(3) of the Act provides that the term “reasonable in amount” shall have the meaning given such term by the Secretary in regulation. Finally, section 13406(a)(4) of the Act clarifies that “direct or indirect payment” does not include any payment for treatment of the individual. We believe Congress intended with these provisions to curtail a covered entity's ability to use the exceptions to the definition of “marketing” in the Privacy Rule to send communications to the individual that were motivated more by commercial gain or other commercial purpose rather than for the purpose of the individual's health care, despite the communication's being about a health-related product or service.

To implement the marketing limitations of the HITECH Act, we propose a number of modifications to the definition of “marketing” in the Privacy Rule at § 164.501. In particular, we propose to: (1) Revise the exceptions to marketing to better distinguish the exceptions for treatment communications from those communications made for health care operations; (2) add a definition of “financial remuneration;” (3) provide that health care operations communications for which financial remuneration is received are marketing and require individual authorization; (4) provide that written treatment communications for which financial remuneration is received are subject to certain notice and opt out conditions set out at § 164.514(f)(2); (5) provide a limited exception from the remuneration prohibition for refill reminders; and (6) remove the paragraph regarding an arrangement between a covered entity and another

entity in which the covered entity receives remuneration in exchange for protected health information. We propose to revise §§ 164.514(f)(2) and 164.520(b)(1)(iii)(A) to include the notice and opt out conditions that would attach to written treatment communications about products or services sent by a health care provider to an individual in exchange for financial remuneration by the third party whose product or service is being described. We also propose to make a conforming change to the authorization requirements for marketing at § 164.508(a)(3)(ii). We describe these proposed modifications in more detail below.

In paragraph (1) of the definition of “marketing,” we propose to maintain the general concept that “marketing” means “to make a communication about a product or service that encourages recipients of the communication to purchase or use the product or service.” In paragraph (2) of the definition, we propose to include three exceptions to this definition to encompass certain treatment and health care operations communications about health-related products or services. First, at proposed paragraph (2)(iii), we would exclude from the definition of “marketing” certain health care operations communications, except where, as provided by section 13406(a)(2) of the HITECH Act, the covered entity receives financial remuneration in exchange for making the communication. This provision would encompass the health care operations activities currently described in paragraph (1)(i) of the definition of “marketing,” which include communications to describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication. In addition, the provision would encompass health care operations communications for case management or care coordination, contacting of individuals with information about treatment alternatives, and related functions, to the extent these activities do not fall within the definition of treatment. These are activities that currently fall within paragraph (1)(iii) of the definition of “marketing.”

Although the HITECH Act uses the term “direct or indirect payment” to describe the limitation on permissible health care operations disclosures, we have substituted the term “financial remuneration” to avoid confusion since the Privacy Rule defines and uses the term “payment” to mean payment for health care and since the Privacy Rule's authorization requirements for marketing at § 164.508(a)(3) use the term “remuneration.” We propose to define “financial remuneration” in paragraph (3) of the definition of “marketing” to mean direct or indirect payment from or on behalf of a third party whose product or service is being described. We also propose to make clear, in accordance with section 13406(a)(4) of the HITECH Act, that financial remuneration does not include any direct or indirect payment for the treatment of an individual. Additionally, because the HITECH Act refers expressly to “payment,” rather than remuneration more generally, we have specified that only the receipt of financial remuneration in exchange for making a communication, as opposed to any other type of remuneration, is relevant for purposes of the definition of marketing. We propose a small conforming change to § 164.508(a)(3) to add the term “financial” before “remuneration” and to refer to the definition of “financial remuneration” for consistency with the HITECH Act and the proposed changes to the definition of “marketing.”

We also emphasize that financial remuneration for purposes of the definition of “marketing” must be in exchange for making the communication itself and be from or on behalf of the entity whose product or service is being described. For example, authorization would be required prior to a covered entity making a communication to its patients regarding the acquisition of new state of the art medical equipment if the equipment manufacturer paid the covered entity to send the communication to its patients. In contrast, an authorization would not be required if a local charitable organization, such as a breast cancer foundation, funded the covered entity's mailing to patients about the availability of new state of the art medical equipment, such as mammography screening equipment, since the covered entity would not be receiving remuneration by or on behalf of the entity whose product or service was being described. Furthermore, it would not constitute marketing and no authorization would be required if a hospital sent flyers to its patients announcing the opening of a new wing where the funds for the new wing were donated by a third party, since the financial remuneration to the hospital from the third party was not in exchange for the mailing of the flyers.

Second, in paragraph (2)(ii) of the definition, we propose to include the statutory exception to marketing at section 13406(a)(2)(A) for communications regarding refill reminders or otherwise about a drug or biologic that is currently being prescribed for the individual, provided any financial remuneration received by the covered entity for making the communication is reasonably related to the covered entity's cost of making the communication. Congress expressly identified these types of communications as being exempt from the remuneration limitation only to the extent that any payment received for making the communication is reasonable in amount. We request comment on the scope of this exception, that is, whether communications about drugs that are related to the drug currently being prescribed, such as communications regarding generic alternatives or new formulations of the drug, should fall within the exception. In addition, we considered proposing a requirement that a covered entity could only receive financial remuneration for making such a communication to the extent it did not exceed the actual cost to make the communication. However, we were concerned that such a requirement would impose the additional burden of calculating the costs of making each communication. Instead, we propose to allow costs that are reasonably related to the covered entity's cost of making the communication. We request comment on the types and amount of costs that should be allowed under this provision.

Third, proposed paragraph (2)(i) would exclude from marketing treatment communications about health-related products or services by a health care provider to an individual, including communications for case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual, provided, however, that if the communications are in writing and financial remuneration is received in exchange for making the communications, certain notice and opt out conditions are met. We note that while section 13406(a) of the HITECH Act expressly provides that a communication to an individual about a health-related product or service where the covered entity receives payment from a third party in exchange for making the communication shall not be considered a

health care operation

(emphasis added) under the Privacy Rule, and thus is marketing, it is unclear how Congress intended these provisions to apply to treatment communications between a health care provider and a patient. Specifically, it is unclear whether Congress intended to restrict

only those subsidized communications about products and services that are less essential to an individual's health care (

i.e.,

those classified as health care operations communications) or all subsidized communications about products and services, including treatment communications. Given this ambiguity and to avoid preventing communications to the individual by a health care provider about health related products or services that are necessary for the treatment of the individual, we do not propose to require individual authorization where financial remuneration is received by the provider from a third party in exchange for sending the individual treatment communications about health-related products or services. However, to ensure the individual is aware that he or she may receive subsidized treatment communications from his or her provider and has the opportunity to elect not to receive them, we propose to require a statement in the notice of privacy practices when a provider intends to send such subsidized treatment communications to an individual, as well as the opportunity for the individual to opt out of receiving such communications. In particular, the proposed rule would exclude from marketing and the authorization requirements written subsidized treatment communications only to the extent that the following requirements proposed at § 164.514(f)(2) are met: (1) The covered health care provider's notice of privacy practices includes a statement informing individuals that the provider may send treatment communications to the individual concerning treatment alternatives or other health-related products or services where the provider receives financial remuneration from a third party in exchange for making the communication, and the individual has a right to opt out of receiving such communications; and (2) the treatment communication itself discloses the fact of remuneration and provides the individual with a clear and conspicuous opportunity to elect not to receive any further such communications. Similar to the modifications discussed below regarding fundraising communications, the opt out method provided to an individual for subsidized treatment communications may not cause the individual to incur an undue burden or more than a nominal cost. We encourage covered entities to consider the use of a toll-free phone number, an e-mail address, or similar opt out mechanism that would provide individuals with a simple, quick, and inexpensive way to opt out of receiving future communications. We note that we would consider requiring individuals to write and send a letter to the covered entity asking not to receive future communications to constitute an undue burden on the individual for purposes of this proposed requirement. We request comment on how the opt out should apply to future subsidized treatment communications. For example, we request comment on whether the opt out should prevent all future subsidized treatment communications by the provider or just those dealing with the particular product or service described in the current communication. We also request comment on the workability of requiring health care providers that intend to send subsidized treatment communications to individuals to provide an individual with the opportunity to opt out of receiving such communications prior to the individual receiving the first communication and what mechanisms could be put into place to implement the requirement.

Given that the new marketing limitations on the receipt of remuneration by a covered entity would apply differently depending on whether a communication is for treatment or health care operations purposes, it is important to emphasize the difference between the two types of communications. We note first that communications by health plans concerning health-related products or services included in a plan of benefits or for case management or care coordination are never considered treatment for purposes of the Privacy Rule but rather would always be health care operations and require individual authorization under the proposed rule if financial remuneration is involved. With respect to subsidized communications by a health care provider about health-related products or services for case management or care coordination or to recommend alternative treatments or settings of care, whether the communication would require individual authorization, or a statement in the notice and an opportunity to opt out, would depend on to what extent the provider is making the communication in a population-based fashion (health care operations) or to further the treatment of a particular individual based on that individual's health care status or condition (treatment). For example, a covered health care provider who sends a pregnant patient a brochure recommending a specific birthing center suited to the patient's particular needs is recommending a setting of care specific to the individual's condition, which constitutes treatment of the individual. If the health care provider receives financial remuneration in exchange for making the communication, the provider would be required to have included a statement in its notice of privacy practices informing individuals that it may send subsidized treatment communications to the individual and that the individual has a right to opt out of such communications, and to disclose the fact of remuneration with the communication and provide the individual with information on how to opt out of receiving future such communications. In contrast, a health care provider who sends a blanket mailing to all patients with information about a new affiliated physical therapy practice would not be making a treatment communication. Rather, the provider would be making a communication for health care operations if it does not receive any financial remuneration for the communication, but would be making a communication for marketing if it does receive financial remuneration.

We are aware of the difficulty in making what may be in some cases close judgments as to which communications are for treatment purposes and which are for health care operations purposes. We also are aware of the need to avoid unintended adverse consequences to a covered health care provider's ability to provide treatment to an individual. Therefore, we request comment on the above proposal with regard to these issues, as well as the alternatives of excluding treatment communications altogether even if they involve financial remuneration from a third party or requiring individual authorization for both treatment and health care operations communications made in exchange for financial remuneration.

We note that face to face communications about products or services between a covered entity and an individual and promotional gifts of nominal value provided by a covered entity are not impacted by these proposed changes to the definition of “marketing.” These communications may continue to be made without obtaining an authorization under § 164.508 or meeting the notice and opt out requirements of § 164.514(f)(2). We also clarify that communications made by covered entities to individuals promoting health in general, such as communications about the importance of maintaining a healthy diet or getting an annual physical are still not considered to be marketing. These types

of communications do not constitute marketing because they are not promoting a specific product or service, and thus do not meet the definition of “marketing.” Similarly, communications about government and government-sponsored programs do not fall within the definition of “marketing” as there is no commercial component to communications about benefits available through public programs.

Finally, we have proposed to remove the language at paragraph (2) from the definition of “marketing” at § 164.501. The current language defines as marketing an arrangement between a covered entity and any other entity in which the covered entity discloses protected health information to the other entity, in exchange for remuneration, for the other entity or its affiliate to make a communication about its own product or service that encourages recipients of the communication to purchase or use that product or service. This language describes a situation which, as explained more fully below, would now constitute a “sale” of protected health information under section 13405(d) of the HITECH Act and § 164.508(a)(4) of this proposed rule. Because we propose to modify § 164.508 to implement section 13405(d) of the HITECH Act by prohibiting the sale of protected health information without an authorization, we propose to remove this paragraph from the definition of “marketing” as unnecessary and to avoid confusion.

C. Business Associates

1. Section 164.502—Uses and Disclosures

The Privacy Rule currently does not directly govern business associates. However, the provisions of the HITECH Act make specific requirements of the Privacy Rule applicable to business associates, and create direct liability for noncompliance by business associates with regard to those Privacy Rule requirements. In particular, section 13404 of the HITECH Act, which became effective February 18, 2010, addresses the application of the provisions of the HIPAA Privacy Rule to business associates of covered entities. Section 13404(a) discusses the application of contract requirements to business associates, paragraph (b) applies the provision of § 164.504(e)(1)(ii) regarding knowledge of a pattern of activity or practice that constitutes a material breach or violation of a contract to business associates, and paragraph (c) applies the HIPAA civil and criminal penalties to business associates. We discuss paragraphs (a) and (b) of section 13404 of the HITECH Act below. We address section 13404(c) regarding the application of penalties to violations by business associates above in the discussion of the proposed changes to the Enforcement Rule.

Section 13404(a) of the HITECH Act creates direct liability for business associates by providing that in the case of a business associate of a covered entity that obtains or creates protected health information pursuant to a written contract or other arrangement as described in § 164.502(e)(2) of the Privacy Rule, the business associate may use and disclose such protected health information only if such use or disclosure is in compliance with the applicable business associate contract requirements of § 164.504(e) of the Rule. Additionally, section 13404(a) applies the other privacy requirements of the HITECH Act to business associates just as they apply to covered entities.

Accordingly, we propose to modify § 164.502(a) of the Privacy Rule containing the general rules for uses and disclosures of protected health information to address the permitted and required uses and disclosures of protected health information by business associates. First, we propose to revise § 164.502(a) to provide that a business associate, like a covered entity, may not use or disclose protected health information except as permitted or required by the Privacy Rule or the Enforcement Rule. Second, we propose to revise the titles of § 164.502(a)(1) and (2) regarding permitted and required uses and disclosures to make clear that these paragraphs apply only to covered entities. Note that in § 164.502(a)(2)(ii), we also propose a technical change to replace the term “subpart” with “subchapter” to make clear that a covered entity is required to disclose protected health information to the Secretary as needed to determine compliance with any of the HIPAA Rules and not just the Privacy Rule.

Third, we propose to add new provisions at § 164.502(a)(4) and (5) to address the permitted and required uses and disclosures of protected health information by business associates.

4

In accordance with section 13404(a) of the HITECH Act, proposed § 164.502(a)(4) would allow business associates to use or disclose protected health information only as permitted or required by their business associate contracts or other arrangements pursuant to § 164.504(e), or as required by law. If a covered entity and business associate have failed to enter into a business associate contract or other arrangement, then the business associate may use or disclose protected health information only as necessary to perform its obligations for the covered entity (pursuant to whatever agreement sets the general terms for the relationship between the covered entity and business associate) or as required by law; any other use or disclosure would violate the Privacy Rule. In addition, proposed § 164.502(a)(4) makes clear that a business associate would not be permitted to use or disclose protected health information in a manner that would violate the requirements of the Privacy Rule, if done by the covered entity, except that the business associate would be permitted to use or disclose protected health information for the purposes specified under § 164.504(e)(2)(i)(A) or (B), pertaining to uses and disclosures for the proper management and administration of the business associate and the provision of data aggregation services for the covered entity, if such uses and disclosures are permitted by its business associate contract or other arrangement.

4

We propose to reserve § 164.502(a)(3) for provisions implementing modifications to the Privacy Rule required by the Genetic Information Nondiscrimination Act of 2008 (GINA), which were proposed on October 7, 2009.

See

74 FR 51698.

Section 164.502(a)(5) would require business associates to disclose protected health information either when required by the Secretary under subpart C of part 160 of this subchapter to investigate or determine the business associate's compliance with this subchapter, or to the covered entity, individual, or individual's designee, as necessary to satisfy a covered entity's obligations under § 164.524(c)(2)(ii) and (3)(ii), as modified, with respect to an individual's request for an electronic copy of protected health information. As section 13405(e) requires covered entities that maintain protected health information in an electronic health record to provide an individual, or the individual's designee, with a copy of such information in an electronic format, if the individual so chooses, and as section 13404(a) applies section 13405(e) to business associates as well, we propose to include such language in § 164.502(a)(5).

We propose to modify the minimum necessary standard at § 164.502(b) to require that when business associates use, disclose, or request protected health information, they limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request. Applying the minimum necessary standard is a condition of the permissibility of many uses and disclosures of protected health information. Thus, a business associate

is not making a permitted use or disclosure under the Privacy Rule if it does not apply the minimum necessary standard, where appropriate. Additionally, the HITECH Act at section 13405(b) addresses the application of minimum necessary and, in accordance with section 13404(a), also applies such requirements to business associates. We note that we have not added references to “business associate” to other provisions of the Privacy Rule that address uses and disclosures by covered entities. This is because we found such changes to be unnecessary, since a business associate generally may only use or disclose protected health information in the same manner as a covered entity (therefore any Privacy Rule limitation on how a covered entity may use or disclose protected health information automatically extends to business associates).

Section 164.502(e) sets out the requirements for disclosures to business associates. We propose in § 164.502(e)(1)(i) to provide that covered entities are not required to obtain satisfactory assurances from business associates that are subcontractors. Rather, as we previously discussed with regard to proposed modifications to the Security Rule pertaining to business associates, and as we discuss further below, we propose in the Privacy and Security Rules to require that business associates obtain satisfactory assurances, through a written contract or other arrangement, from subcontractors that provide that the subcontractor will comply with the applicable requirements of the Rules. Accordingly, each business associate subcontractor would be subject to the terms and conditions of a business associate agreement with a business associate, eliminating the need for a similar agreement with the covered entity itself.

We also propose to move the current exceptions to business associates at § 164.502(e)(1)(ii) to the revised definition of business associates found in § 160.103 for the reasons discussed in that section.

We propose a new § 164.502(e)(1)(ii) that provides that a business associate may disclose protected health information to a business associate that is a subcontractor, and to allow the subcontractor to create or receive protected health information on behalf of the business associate, if the business associate obtains satisfactory assurances, in accordance with § 164.504(e)(1)(i), that the subcontractor will appropriately safeguard the information. As such, the business associate must enter into a contract or other arrangement that complies with § 164.504(e)(1)(i) with business associate subcontractors, in the same manner that covered entities are required to enter into contracts or other arrangements with their business associates. As we discussed with regard to the requirements of the Security Rule regarding business associates, we believe that business associates are in the best position to ensure that subcontractors comply with the requirements of the Privacy Rule. For example, a covered entity may choose to contract with a business associate (contractor) to use or disclose protected health information on its behalf, the business associate may choose to obtain the services of (and exchange protected health information with) a subcontractor (subcontractor 1), and that subcontractor may, in turn, contract with another subcontractor (subcontractor 2) for services involving protected health information. Under the current rules, the covered entity would be required to obtain a business associate agreement with the contractor, the contractor would have a contractual requirement to obtain the same satisfactory assurances from subcontractor 1, and subcontractor 1 would in turn have a contractual requirement to obtain the same satisfactory assurances from subcontractor 2. The proposed revisions to the Privacy and Security Rules would not change the parties to the contracts. However, the contractor and subcontractors 1 and 2 all would now be business associates with direct liability under the HIPAA Rules, and would be required to obtain business associate agreements with the parties with whom they contract for services that involve access to protected health information. (

Note,

however, as discussed above with respect to the definition of “business associate,” direct liability under the HIPAA Rules attaches regardless of whether the contractor and subcontractors have entered into business associate agreements.) The proposed revisions ensure that the covered entity does not have a new obligation to enter into separate contracts with the business associate subcontractors.

We propose to remove § 164.502(e)(1)(iii), which provides that a covered entity that violates the satisfactory assurances it provided as a business associate of another covered entity will be in noncompliance with the Privacy Rule's business associate provisions, given that new proposed § 164.502(a)(4) would restrict directly the uses and disclosures of protected health information by a business associate, including a covered entity acting as a business associate, to those uses and disclosures permitted by its business associate agreement.

2. Section 164.504(e)—Business Associate Agreements

Section 164.504, among other provisions, contains the specific requirements for business associate contracts and other arrangements. As discussed previously, section 13404 of the HITECH Act provides that a business associate may use and disclose protected health information only if such use or disclosure is in compliance with each applicable requirement of § 164.504(e), and also applies the provisions of § 164.504(e)(1)(ii), which outline the actions that must be taken if the business associate has knowledge of a breach of the contract, to business associates. We propose a number of modifications to this section to implement these provisions and to reflect the Department's new regulatory authority with respect to business associates, as well as to reflect a covered entity's and business associate's new obligations under subpart D to provide for notification in the case of breaches of unsecured protected health information.

Section 164.504(e)(1)(ii) provides that a covered entity is not in compliance with the business associate requirements if the covered entity knew of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate's obligation under the contract or other arrangement, unless the covered entity took reasonable steps to cure the breach or end the violation, as applicable, and if such steps were unsuccessful, terminated the contract or arrangement or, if termination is not feasible, reported the problem to the Secretary. We propose to revise § 164.504(e)(1)(ii) to remove the requirement that covered entities report to the Secretary when termination of a business associate contract is not feasible. In light of a business associate's direct liability for civil money penalties for violations of the HIPAA Rules and both a covered entity's and business associate's obligations under subpart D to report breaches of unsecured protected health information to the Secretary, we have other mechanisms through which we expect to learn of such breaches and misuses of protected health information by a business associate. We also propose to add a new provision at § 164.504(e)(1)(iii) applicable to business associates with respect to subcontractors to mirror the requirements on covered entities in

§ 164.504(e)(1)(ii) (minus the requirement to report to the Secretary if termination of a contract is not feasible). Thus, proposed § 164.504(e)(1)(iii) would require a business associate, if it knew of a pattern or practice of activity of its business associate subcontractor that constituted a material breach or violation of the subcontractor's contract or other arrangement, to take reasonable steps to cure the breach of the subcontractor or to terminate the contract, if feasible. We believe this proposed provision would implement the intent of section 13404(b) of the HITECH Act, and aligns the requirements for business associates with regard to business associate subcontractors with the requirements for covered entities with regard to their business associates. In other words, a business associate that is aware of noncompliance by its business associate subcontractor must respond to the situation in the same manner as a covered entity that is aware of noncompliance by its business associate.

While business associates are now directly liable for civil money penalties under the HIPAA Rules for impermissible uses and disclosures as described above, business associates are still contractually liable to covered entities pursuant to their business associate contracts, as provided for and required by § 164.504(e). We propose certain modifications to these contract requirements. First, we propose to revise § 164.504(e)(2)(ii)(B) through (D) to require the following: in (B), that business associates comply, where applicable, with the Security Rule with regard to electronic protected health information; in (C), that business associates report breaches of unsecured protected health information to covered entities, as required by § 164.410; and in (D), that, in accordance with § 164.502(e)(1)(ii), business associates ensure that any subcontractors that create or receive protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information. These proposed revisions align the requirements for the business associate contract with the requirements in the HITECH Act and elsewhere within the HIPAA Rules.

Additionally with regard to business associate contract requirements, we propose to insert a new provision at § 164.502(e)(2)(ii)(H) and to renumber the current paragraphs (H) and (I) accordingly. Section 164.502(e)(2)(ii)(H), as proposed, would require that, to the extent the business associate is to carry out a covered entity's obligation under this subpart, the business associate must comply with the requirements of the Privacy Rule that apply to the covered entity in the performance of such obligation. The HITECH Act places direct liability for uses and disclosures and for the other HITECH Act requirements on business associates. Beyond such direct liability, this provision clarifies that a business associate is contractually liable not only for uses and disclosures of protected health information, but also for all other requirements of the Privacy Rule, as they pertain to the performance of the business associate's contract. For example, if a third party administrator, as a business associate of a group health plan, fails to distribute the plan's notice of privacy practices to participants on a timely basis, the third party administrator would not be directly liable under the HIPAA Rules, but would be contractually liable, for the failure. However, we emphasize that in this example, even though the business associate is not directly liable under the HIPAA Rules for failure to provide the notice, the covered entity remains directly liable for failure to provide the individuals with its notice of privacy practices because it is the covered entity's ultimate responsibility to do so, despite its having hired a business associate to perform the function.

We also propose to revise § 164.504(e)(3) regarding other arrangements for governmental entities to include references to the Security Rule requirements for business associates to streamline the two rules and, as discussed above, to avoid having to repeat such provisions in the Security Rule.

To implement the requirements of sections 13404(a) of the HITECH Act, we propose to include a new § 164.504(e)(5) that applies the requirements of § 164.504(e)(2) through (e)(4) to the contract or other arrangement between a business associate and its business associate subcontractor as required by § 164.502(e)(1)(ii) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and its business associate. As such, the business associate is required by § 164.502(e)(1)(ii) and by this section to ent

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.