Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Thursday, December 26, 2013

HIPAA And The Dangerous Flea Bargain



Years ago, I represented a young man who had lost his job. “Idle hands” being “the devil’s workshop”, he got into drug trafficking while our case was pending.  In the process, he accidentally blew up a car stuffed with cocaine.  Reporting the fiasco to me, he jubilantly told me not to worry as he had worked out a great “flea bargain” with the “feds.”

Negotiated settlements can be the best way out of a legal problem.  They are especially beneficial when a Board such as the Psychology or Medical Board threatens a health care provider with the loss of a professional license.  Often these Boards will allow the provider to keep his license if the licensee pays a small fine and gets additional training.   But sometimes settlements, like my client’s car, can blow up on you.  Take the case of a Virginia psychiatrist accused of violating a patient’s privacy. 

In September of 2007, Dr. Jones* began treating a female highway patrol officer who had been beaten, kidnapped and raped by three men.  Although he diagnosed her with post traumatic stress disorder, he wrote that she was “not a danger to the public.”

Later that year, the patient filed a complaint with the doctor’s employer about his behavior.  Shortly after receiving her complaint, Dr. Jones’ employer fired him.

On January 30, 2008, other physicians had the trooper involuntarily committed to a mental health facility.  The facility discharged her on February 1, 2008.  Dr. Jones heard rumors about the trooper’s hospitalization.  On February 4, 2008, he contacted “a friend” and “co-worker” of the trooper and told her about the involuntary commitment.  He made a second call on February 7, 2008 to another of the trooper’s “co-workers”.  He again reported that the trooper had been involuntarily committed to a mental health facility. 

Based on Dr. Jones’ reports, the Highway Patrol suspended the trooper.  However, once the Patrol’s doctor found her to be “fit for duty”, the Patrol sent her back to work. 

When the Virginia Medical Board learned of Dr. Jones’ disclosures, it prosecuted him for violating state confidentiality laws.  An “informal” conference took place.  Such conferences often allow the Board and licensee to negotiate licensure issues.  The Board found that, “Despite direct and repeated questioning,” Dr. Jones could not “justify” violating the trooper’s privacy.  His only reason for calling her friends was that he was worried because she had a gun.  The Board fined Dr. Jones $5,000 and ordered him to take 8 hours of training in ethics.  Dr. Jones did not appeal the ruling.  He must have been very relieved to keep his license.  His relief would be short-lived. 

In 2011, the US Justice Department filed criminal charges against the doctor for violating HIPAA.  Prosecutors argued that his discussions with the troopers’ co-workers were in retaliation for her complaints against him.  Surprisingly, after the prosecution presented its case, a federal judge dismissed the charges.

HIPAA allows health care providers to release information that is:
1.       Necessary to prevent a “serious and imminent threat” to others IF
2.      The threat is made to a person reasonably able to lessen the threat – this may include law enforcement, family members, the target of the threat, or others.

So what can we learn from Dr. Jones’ case?
1.      When deciding whether to accept punishment offered by a licensing board, it’s important to consider the possibility of a subsequent federal charge related to the case.  It is likely that the HIPAA police relied in part on the Virginia Medical Board order when deciding whether to prosecute Dr. Jones.
2.      Credibility issues arise when a defendant’s words contradict earlier written statements.  Dr. Jones claimed that the patient was a threat after he wrote in her medical record that she was NOT a threat. 
3.      It’s important to report threats to the proper person.  Dr. Jones should have expressed his concerns to the trooper’s immediate supervisor, not to her “friends.”
4.      Only witnesses with first-hand knowledge of a threat should report it.  The doctors who committed the trooper were in the best position to evaluate her mental health and were the appropriate persons to report any threat that she posed.
5.      You should be sure that you have accurate information before filing any report.     Because Dr. Jones did not have complete or accurate information about the trooper’s commitment, the report he gave was based on rumors and was in error. 

While I’m sure that Dr. Jones was thrilled to avoid jail time, he was probably less joyous about paying thousands of dollars in attorney fees, enduring the negative nationwide publicity, and spending three years of his life defending the charges related to this incident.  The only good to come out of the case may be the many lessons it offers concerning HIPAA compliance.

*Dr. Jones is not this defendant’s real name.

Sunday, September 1, 2013

Timing is Everything



          As a child, I remember watching a television show dedicated to debunking Bible miracles.  Scientists had studied everything from the creation to the resurrection and assured us that every “miracle” could be explained scientifically.  I was very upset to learn that the Red Sea parted for Moses and the Israelites because of a rare phenomenon called “wind settling.”  The wind had blown the sea out of the way of the Israelites.  It was the wind, not Moses, who rescued God’s people from Pharaoh’s army. 
With tears in my eyes, I turned to my Dad and said, “I guess Moses wasn’t that big a deal after all.”
“But you are forgetting one very important fact,” my Dad answered.  “The scientists said that “wind settling” is rare.  Yet, that wind parted the sea at the very moment Moses needed to escape.  And it stopped blowing just in time for the sea to close up over the Egyptian army.  Sometimes the timing of an event is the miracle.”
Since that night, I have often been reminded that timing is everything.

          April 20, 2010, was a ho-hum day for the CBS news team.  The evening news reported that lobbyists from JP Morgan Chase opposed federal financial regulations.  Union lobbyists announced that they were going to oppose “moderate” Democrats as well as Republicans in the upcoming elections.  The Tea Party complained that the Ohio Republican Party wasn’t supporting the Tea Party agenda.  Of course, the biggest story of April 20th was still percolating in a Deepwater Horizon drilling rig.  Had the rig blown earlier in the day, CBS would not have needed to spice up the news with its copier identity theft story.
          Months earlier, CBS had purchased 4 used copiers, removed the copiers’ hard drives, and downloaded documents that had been copied, faxed, or scanned on the machines.  They hit “paydirt” with all four copiers.  One was from the Sex Crimes Division of a Police Department.  Another was from a construction company.  It had thousands of names, addresses, and Social Security numbers.  The third was from another police department and contained information relating to drug investigations.  The hard drive on the fourth copier turned out to be a Pandora’s Box for Affinity Health Plan.  It contained medical information on approximately 344,579 patients insured by Affinity. 
          Like most of us at the time, Affinity probably did not know that modern-day copiers record every document copied.  Unaware of this handy feature, Affinity simply turned in its copiers at the end of the copiers’ lease period.  It also failed to document in its HIPAA-mandated “Risk Assessment” the fact that medical information was stored on its copiers. Thanks to the CBS story, Affinity had to file a confession of wrong-doing known as a “Breach Notification Report.”  Within a month, the feds had launched an investigation.
Three years later, Affinity owed the feds $1,215,780.  This is in addition to the hundreds of thousands of dollars spent on investigators, forensic computer analysts, and lawyers.  Affinity also agreed to try to track down all of its former copiers and delete patient records from the hard drives on those copiers.  It must revise its risk assessment and confidentiality policies.  Once the government has approved those new policies, Affinity must educate its employees about the policies.
The Affinity copier scandal and the resulting fine seem insignificant compared to the billions of dollars in damages resulting from the Gulf oil rig explosion that monopolized news organizations for months after April 20th.  In fact, had the explosion occurred a few hours earlier on the 20th, it is possible that we would not have known about Affinity Health Care and its copier problems.  Other health care providers, law firms, federal agencies, and police departments may have continued taking broken copiers to the dump.    Edward Snowden and Wiki-leaks could have avoided all their legal problems by getting their top secret information from discarded copiers, thumb drives, laptops, DVD’s and computers.
But then, as Moses could tell us, timing is everything.

Saturday, November 24, 2012

Patterns - HIPAA Prosecutions Increase



Usually I love patterns.  Quilt patterns, weaving patterns, and patterns in math and science fascinate me.  “The Code” is a BBC television show that explores patterns in nature.  It has captivated me for hours.  (I know there were only three shows, but I found the reruns on YouTube).  If you study a pattern, you can often predict what will happen when you next see that pattern.  For example, if you notice a State Trooper parked on the side of I-40 and you see that you are going over 80 mph, it’s likely that you will next see flashing lights, hear a siren, and be relieved of a substantial amount of cash.  Recently, I found an even more upsetting pattern while studying HIPAA prosecutions.

In 2005, North Carolina passed a law that requires all businesses to notify customers when the business suffers a security breach of customer information.  In 2009, the federal government passed a similar law requiring health care providers to notify patients of security breaches affecting patient information.  Providers must also report certain breaches to the federal government.  The law gave state Attorneys General authority to prosecute HIPAA violations.

In 2010, a Massachusetts hospital hired a company to erase computer tapes with medical information on 800,000 patients.  It shipped several boxes of the unencrypted back-up  tapes to the company.  Only one of the boxes arrived at its intended destination.  No one ever found the other boxes.  In compliance with breach notification laws, the hospital reported the breach to the government.  The state Attorney General’s office responded by initiating a HIPAA prosecution against the hospital.  Eventually, the case settled for $750,000 in penalties. 

In another case, thieves stole a laptop containing unencrypted patient records maintained by a Massachusetts Eye and Ear Clinic.  After the clinic filed a breach report, the HIPAA police fined the clinic $1.5 million and required it to retain an “independent monitor” of its security practices.  The clinic had never conducted the security risk analyses required by HIPAA.  Its policies governing portable devices were “inadequate.”

BlueCross BlueShield of Tennessee also felt the sting of a breach report.  On 57 unencrypted hard drives, the company had recorded customer service calls that included patient names, Social Security numbers and medical information.  BCBS stored the hard drives at a leased facility.  Thieves stole the drives.  As required by law, BCBS filed a breach notification report.  The HIPAA police rode onto the scene and hit the company with a $1.5 million penalty.  BCBS must also meet numerous administrative requirements in the future.  
Apparently, the federal government is even willing to go after state agencies for HIPAA violations.  The Alaska Department of Health and Social Services filed a breach report stating that thieves had broken into a DHSS employee’s car and stolen a USB drive containing unencrypted patient information.  Based on the breach report, the HIPAA police began an investigation.  Alaska had to pay $1.7 million in penalties and has to comply with numerous provisions to improve its security standards.  Where was Sarah Palin when they needed her?

The feds have stated that the breach reporting laws are an “important enforcement tool.”  What an understatement!  The reports serve as detailed confessions of HIPAA violations.  With those reports and hundreds of regulations, standards, and guidelines that only lawyers who are computer experts can understand, prosecution should be a piece of cake.

Yet, we can learn from the above cases.  First, encrypt all patient/customer data.  Be sure to encrypt emails that transmit patient information, including xrays.  Second, make sure that any person or agency that has access to your patient information has signed a business associate agreement as required by HIPAA.  Third, if you sustain a breach, immediately notify your attorney.  DO NOT try to file a breach report without legal advice – unless you have a few million dollars to throw away.  Fourth, be extremely careful in how you destroy patient records that are no longer needed.  If you ship them to a facility for destruction, be sure that you have checked out the facility and have a business associate agreement with it.   

If you study the federal government’s HIPAA website, you will see that there have been more breach notification reports than there are stars in the sky.  Accordingly, the HIPAA police have hired a private corporation to help with prosecutions.  It paid the company  millions of dollars in 2012.  It seems to me that leveling multi-million dollar fines against an overburdened health care industry and against states that are already drowning in debt may not be the best solution to the problem of privacy rights violations.  Perhaps someone in Washington needs to take a look at this.  Wait – never mind – that’s how we got into this mess in the first place.

( See, I do love patterns. Even my dishcloths have patterns.)

Wednesday, February 1, 2012

Facebook and HIPAA: More Ways to Get In Trouble

After a rough day at work, an emergency room physician decided to let off some steam. She logged onto Facebook and wrote about an odd-ball patient. Because of confidentiality requirements imposed by her professional ethics and by HIPAA, the federal privacy regulations, the doctor knew better than to publish her patient’s name. Unfortunately, she put enough information about the patient in her post that her readers were able to figure out his identity. In the uproar that followed, the doctor lost her job and her staff privileges at the hospital. The Medical Board issued a formal reprimand and fined her. We don’t know yet whether the HIPAA police have taken action or whether the patient has filed an invasion of privacy lawsuit.

The case reminded me of a defamation suit from the 1950’s. It involved a book about a world-famous fashion store. (Note that I’m not telling you which one.) The author wrote that the models from New York and Paris were “call girls” and that wealthy men paid thousands of dollars to go out with the women. He wrote that the salesmen were homosexuals. He claimed that the saleswomen were cheaper than the models but were also available for hire. Of course, the store filed suit for defamation. The nine models employed by the store also filed suit. Of the store’s 25 salesmen, 15 filed suit. In addition, 30 of the 382 saleswomen filed a claim with the court.

The author asked the court to dismiss the employees’ suit. Because he had not published their names, he argued that he was not liable to them. The court ruled that even though the author had not identified the models by name, readers of the book could easily determine the models’ identities. Likewise, it ruled that readers would be able to figure out the names of the 25 salesmen. However, the court found that it would be very difficult to figure out the identities of the saleswomen mentioned in the book because the store had 382 saleswomen at the time. Accordingly, the court allowed the models and salesmen to go to the jury, but dismissed the claims of the saleswomen.

HIPAA prohibits unauthorized disclosure of protected “individually identifiable” information. In other words, if you can figure out the identity of the patient from the information disclosed, the information is protected. For example, if a physician says he is treating the Governor of North Carolina, most North Carolinians would know the name of the doctor’s patient.

Assume a nurse asks her Facebook prayer group to pray for “one of our beloved ministers and his wife.” She writes that the clinic where she works has diagnosed the preacher with a social disease. If there is more than one minister, the members of the prayer group wouldn’t know which minister the nurse had outed. Has the nurse violated HIPAA?

If a court were to look to the fashion store case for guidance, the answer might depend on how many ministers worked at the church. If there were 25 or fewer, the nurse would be liable. If the nurse belonged to a church with hundreds of ministers, she might not.

However, another recent case indicates that a health care provider might suffer punishment even when it is impossible to figure out the identity of the patient he writes about. The case involved two nurses who posted on a social media site cell phone pictures of a patient’s x-ray. The x-ray showed that the patient had a sex toy lodged in her body. Although the public couldn’t determine the patient’s name, the hospital fired the nurses. The hospital didn’t claim that the nurses had violated HIPAA. It fired them on the grounds that making fun of any patient in public was “unprofessional conduct.”

Clearly, businesses, especially health care facilities, need written social media policies and should educate employees about those policies. The policies should apply to any publication made by employees on Facebook, Twitter, MySpace and other social media sites. It should prohibit employees from identifying customers, patients, co-workers, suppliers, referral sources, supervisors, and others connected to the employer on those sites. It should also prohibit publishing photographs or x-rays related to work on the sites. Businesses should consider prohibiting posts that reflect poorly on the company, such as pictures showing employees in compromising situations. It may also require employees who post opinions on sensitive topics to include a note that the opinions do not reflect the views of the employer. Finally, the policies should specify how the employer will discipline employees who violate the regulations. Employees should sign a statement that they have a copy of the policies and agree to abide by their terms.

Meanwhile, we’ll all enjoy those wonderfully entertaining blogs, videos, and photos of ourselves and others at our worst – and best. And be glad that some of our parents still haven’t figured out how to turn on a computer.

Saturday, January 7, 2012

Sex, Lies, and HIPAA

On New Years Eve, I love watching shows that list the best movies, novels, tunes, and news articles of the year. I decided to create my own list by naming the best lawsuit of 2011 – at least in my opinion. This isn’t the biggest money judgment of the year, but it has the most interesting set of facts that I found. Bear in mind that this case hasn’t gone to a jury at this point. We only have the Plaintiff’s side of the story. But according to her . . .

Arizona’s nurse Liska was a single mother of two young sons. For years, she had suffered from many orthopedic ailments. As if she weren’t busy enough, in 2007, she began an affair with one of her treating physicians. The man was married and the father of “several” children. Not altogether happy with Ms. Liska’s appearance, the doctor-boyfriend paid for her to have a breast enhancement procedure. The tab came to over $8000.00. Perhaps to keep the bill down, he prescribed “legitimate” medications for his lover while she was recovering from the breast surgery. Among other medications, he called in a prescription for Soma on April 9, 2008. Shortly thereafter, Liska ended the affair.

On August 25, 2008, Liska obtained a refill of the Soma prescription. During the process, the pharmacy contacted her former boyfriend to verify the prescription. The jilted doctor denied having prescribed the drug. The pharmacy reported the problem to the local police department. Detective David Dodge took the case.

To begin his investigation, Dodge contacted the physician. The doctor denied writing the prescription and claimed that he did not know Liska. Later the doctor sent an anonymous letter to the medical board, and various hospitals where Liska worked. He claimed that a doctor at one of the hospitals was writing prescriptions in exchange for sex from Liska and her “nurse friends”. He also made false reports to the Arizona Board of Nursing.

Meanwhile, Dodge went to Liska’s home. He had obtained her ten-year prescription history from Walgreen’s. He confronted her with the report and accused her of prescription fraud. He told her that unless she confessed, he would arrest her right then. He told her that she could not leave his presence or terminate the interview. He made numerous other threats, but Liska denied wrongdoing.

After a while, Dodge told Liska she would have to go to the police department. He allowed her to change from her pajamas, but insisted on watching her change clothes in case she might try to escape. (During the time of these events, Liska was hobbling around on a broken leg that was in a cast.)

The detective continued his harassment at the police department. He refused to allow Liska to call an attorney and did not read her any Miranda warnings. After continuing his threats for several hours, he eventually allowed her to leave without arresting her. Dodge then met with Liska’s Director of Nursing. Shortly after that meeting, Liska lost her job. The discharge letter falsely stated that the employer had conducted its own investigation and confirmed Liska’s arrest. Dodge then went to the Nursing Board.

Weeks later, the Police Department disciplined Dodge. It later issued a letter stating that Liska had committed no crime “whatsoever.” The Nursing Board dropped its case against Liska in 2009.

Not surprisingly, Liska decided to fight back. She sued the United States, Dodge and his wife, the Police Department, the City, the Police Chief and his wife, Walgreens, the former boyfriend and his wife along with various other people. The motions to dismiss soon followed in 2010.

Walgreens argued that it had legal authority to give Liska’s prescription records to the police. The court agreed. It noted that HIPAA allows providers to disclose information for law enforcement purposes in compliance with a subpoena, summons or “authorized investigative demand.” They may also disclose to a law enforcement official protected health information that may be evidence of criminal conduct that occurred on the premises. Believing that Liska had obtained drugs from the store by falsifying a prescription, Walgreens legally reported her prescription history to the police.

The court dropped Walgreens from the lawsuit. However, the case will go on. Even at this stage, the case has entertainment value and offers lessons. The obvious lesson is that, in a case like Liska’s, pharmacies may comply with police requests for information. It’s also a bad idea for a health care provider to have intimate relations with a patient. In North Carolina, that behavior often results in a licensing board taking away the provider’s license to practice. We’ll have to wait and see how the case is resolved before we make any other judgments. I’ll try to keep you posted.

Saturday, January 29, 2011

Curiosity Killed the Cat

Last year, a court sentenced a cardiac surgeon to four months in prison for violating the federal privacy law known as HIPAA. The penalty surprised those of us who have studied HIPAA. We thought imprisonment would be reserved for those who profited financially from disclosing confidential information. While the surgeon had illegally accessed information over 300 times, he had not sold the information, but had kept it to himself. The case gave a clear warning to health care providers. The HIPAA police are here and they mean business!
History of HIPAA
In 1996, Congress enacted HIPAA to encourage the use of electronic patient records. Congress hoped the law would reduce health care costs. The law included provisions for assigning each American a unique patient identification number. A patient’s entire medical history and related financial information would be attached to that number and accessible over the Internet. Strong opposition to HIPAA arose because of privacy concerns. Responding to those concerns, the Department of Health and Human Services (HHS) issued privacy regulations in 2002. The regulations require health care providers to protect information they receive from their patients. Recently, the federal government has begun vigorously enforcing HIPAA.

In a 2010 case similar to the one involving the surgeon, the government disciplined a nurse who accessed her ex-husband’s medical records at the hospital where she worked. Significantly, her actions also violated her ethical obligation to protect patient confidentiality. Her nursing board could revoke her nursing license for her actions.

Recent Cases - Pharmacies
In the early part of 2000, the HIPAA police learned that CVS pharmacies nationwide had been tossing old patient records into dumpsters behind the stores. This clearly violated HIPAA’s requirement that such records be shredded. To settle the enforcement action, CVS paid $2.25 million in fines and submitted to long-term monitoring of its privacy practices.

In 2010, the HIPAA police slammed Rite Aid Pharmacies with a $1 million fine. That year, the government also initiated an investigation into Walgreen’s HIPAA practices.

Since the enactment of laws requiring those who purchase cold medicines containing ephedrine to sign a pharmacy log, we’ve all seen the ephedrine logs beside the pharmacy cash registers. Last year, the HIPAA police cited a local pharmacy for positioning the log on a counter in a way that exposed the names of customers who had signed the log.

In another case, a pharmacy employee accidentally put one patient’s insurance card into a bag containing another patient’s medication.

Finally, another pharmacy chain did not comply with HIPAA’s requirement that all of its business associates sign confidentiality contracts agreeing to protect patient information. The associate in question was the pharmacy’s lawyer.

Inadvertent Disclosures – “Don’t Talk So Loud!”
HIPAA requires health care providers who talk about their patients to speak quietly so that they are not overheard. Last year, the government disciplined a physician who chose to discuss his patient’s HIV treatment in the clinic waiting room while other patients were present. It also disciplined a hospital nurse who chatted too loudly about her patient’s HIV diagnosis.

Other inadvertent disclosures that are illegal include:
1. Positioning computer screens on counters in a way that they could be viewed by people in the waiting areas of the clinic
2. Leaving patient charts out where they can be read
3. Talking to a patient on the telephone about his condition in a location where others can overhear the conversation
4. Leaving messages with people at the patient’s home or office or on answering machines without patient consent
5. Discussing a patient’s condition without patient consent – this may happen in cases where the provider seeks a second opinion or advice on a case
6. Talking about patients in office “huddles” when the huddle includes people who are not on the patient’s treatment team.

A Word to the Wise
Health care providers who receive a patient complaint concerning privacy practices or who are contacted by government investigators about potential privacy violations should immediately contact their practice attorney for guidance. We have learned from recent cases that HIPAA violations can result in significant fines, imprisonment, loss of staff privileges, and loss of professional licensure. Providers should not try to handle these cases without legal counsel.