Network services for personal health records (PHRs) are emerging in a complex and often uncertain legal and policy environment. In this paper, we discuss the policy landscape in the context of emerging Consumer Access Services – those services or organizations seeking to help individuals make electronic connections across multiple sources of their health information.
Regulations promulgated under the Health Insurance Portability and Accountability Act (HIPAA), in effect since April 2003, put in place a set of privacy and security rules intended to build safeguards into the practice of health care. The Privacy Rule became law as public concern about the confidentiality of personal health information reached a high level, coupled with a growing awareness that the lack of privacy safeguards in health care heightened the risk that some people would choose to withdraw from full participation in their own care.
Under current federal statute1 and regulation2 , there are three categories of Covered Entities that must comply with the HIPAA Privacy Rule: health care providers that transmit protected health information in electronic form to pay claims or engage in other standard transactions under the law, health plans, and health care clearinghouses.3 In this respect, many of today's personal health record vendors do not qualify as Covered Entities and are not subject to the Privacy Rule.
The Privacy Rule includes:
Through its Office for Civil Rights,5 the U.S. Department of Health and Human Services (HHS) enforces the Privacy Rule directly as applied to Covered Entities. The Department of Justice is empowered to investigate and prosecute criminal violations of the law, and state enforcement mechanisms are also empowered to oversee and apply the law. According to the HHS Office for Civil Rights, since the Privacy Rule went into effect in April 2003, more than 29,000 voluntary complaints have been received, about 80 percent of which have been resolved. As of July 31, 2007, corrective action has been taken in fewer than 5,000 cases, most of which have been in the past 2 years.6 There have been no civil penalties assessed and only a handful of criminal prosecutions under the Privacy Rule.
Related to the enforcement challenge are difficulties in interpretation of the Privacy Rule. Although it has been in place since 2003, many Covered Entities remain confused about what the Privacy Rule does and does not allow, as documented most recently by the Health Information Privacy and Security Collaborative (HISPC).7
Below are important questions on whether consumer protections and policy enforcement are adequate in the emerging environment of consumer data streams and networked PHRs.
Answer: Not necessarily. It depends on whether the Consumer Access Service is operated by, or on behalf of, a Covered Entity.
The Privacy Rule is limited by the scope of the HIPAA statute. Most notably, HIPAA only applies directly to Covered Entities – which many Consumer Access Services and PHRs are not. To the extent that a Covered Entity does offer a PHR directly to its patients or members, the Covered Entity must comply with the Privacy Rule. If the Covered Entity contracts with a third party to provide a PHR to consumers on its behalf, it must enter into a "Business Associate Agreement," which limits that contractor's use and disclosure of health information. These downstream entities are restricted in their use and disclosure only through contract law. In general, Business Associates are not directly regulated under HIPAA. As a result, if a Business Associate violates the contract, the Covered Entity can take the Business Associate to court under contract law. But it is the Covered Entity – not the Business Associate – that may be subject to regulatory enforcement action for the violation. (The regulation states that the Covered Entity is only liable when it knew of a Business Associate's breaches and took no action.)
Thus, if a Covered Entity provides a Consumer Access Service to its patients, members, or employees, then the Covered Entity must comply with Privacy Rule requirements (even if the actual service is supplied by a vendor under a Business Associate agreement). However, if the Consumer Access Service is neither a Covered Entity nor acting as a Business Associate of a Covered Entity, it is not governed by the federal regulation. Such a Consumer Access Service may receive identifiable patient health data that originated at a Covered Entity8 primarily in two ways:
From a Covered Entity based on an authorization from the consumer:

From the consumer who has obtained copies of her medical records directly from the Covered Entity and supplied them separately to the Consumer Access Service:

Some emerging Consumer Access Services are structured to encourage consumers to authorize their providers and plans to disclose health information directly to the Consumer Access Service. The public may not be aware that once the Consumer Access Service has received information from a Covered Entity based on the consumer's signed authorization, that information is no longer covered under the federal Privacy Rule. In other words, HIPAA privacy protections do not "follow" the data; they only apply when in the hands of a Covered Entity or its Business Associate(s). Non-covered organizations are not required to do many activities that are required of HIPAA-Covered Entities. For example, they are not required to train their staffs about privacy and confidentiality, or maintain an accounting of disclosures, or require an authorization before re-disclosing health information to other non-covered entities.
However, it is important to note that any organization in this marketplace –whether HIPAA-covered or not – can exceed the Privacy Rule requirements. Organizations may provide for higher levels of individual control over data flowing in or out of PHRs than are afforded to consumers under the Privacy Rule.
The HIPAA Privacy Rule did contemplate the use of networked health information systems, but only within the constraints of the Covered Entity/Business Associate framework. It is important to note that the HIPAA statute devoted little attention to e-health and privacy, let alone Consumer Access Services or networked PHRs.9
All new PHRs and Consumer Access Services demand thoughtful and carefully crafted practices to balance the need for consumer data streams to flow more readily with the need to protect privacy. A comprehensive approach to privacy is warranted in light of the emerging environment.
(See the Overview document for Nine Core Principles for addressing privacy in a networked environment.)
Answer: To answer this question, consider the case of a person named Millie:
First, imagine that Millie goes to the doctor and receives a notice saying that her information can be used in various ways allowed under HIPAA. A year later, she visits the doctor's office and gets a treatment, and the doctor sends a claim to Millie's health insurance company. The insurance company then processes and pays the claim. The event generates several transactions and copies of information about Millie – none of which require Millie's specific consent. This is because under HIPAA, Covered Entities may make certain disclosures of personal health information for purposes of treatment, payment, and health care operations (TPO) without any consent from the consumer.10
Then, imagine that the insurance company offers Millie an online PHR that lets her view copies of that claims history. The mere fact that Millie is given an online account to view copies of claims does not change the nature of the health plan's permissible uses of the information under TPO rules.11
Now, let's imagine that the PHR offers Millie a chance to add her own contributions of information. For example, she could fill out a patient diary, or a health risk assessment, or perhaps enter a past diagnosis of which the health plan had previously been unaware. Or maybe Millie can connect her health plan PHR account to another source of health information about her, such as a home monitoring device or even from her other doctors or pharmacies. Do these new streams of information about Millie, captured through a PHR from a Covered Entity, fall under the TPO rules? Can they be used or disclosed the same way the claim from her doctor's office might be?
Clearly, such issues about HIPAA and TPO are clearly beyond the understanding of the average consumer. A more relevant question, therefore, is whether people like Millie can make informed choices about new personal health information services. Whether covered by HIPAA or not, organizations that offer Consumer Access Services or PHRs must have sound and transparent practices for consumer notice and consent, as well as the other areas of this framework. Sound practices for obtaining consumer consent include making choices proportional. That is, the more unexpected or disclosing the activity, the more specific the consent mechanism required to authorize it. (See CP2: Policy Notice to Consumers and CP3: Consumer Consent to Collections, Uses, and Disclosures of Information.)
Answer: Existing state health privacy laws are generally directed at health care providers and health plans. The vast majority are virtually silent on emerging developments such as regional health information exchanges or networked PHRs.12 The result is that state law may restrict the circumstances under which a Health Data Source may send data to a PHR (such as by requiring patient consent), but does not protect the information once it has been transferred to the PHR.
Furthermore, to the extent that state laws may protect health information in consumer data streams, they often do so inconsistently. HIPAA sets a floor of protections, and does not displace state laws that are more stringently privacy-protective. Many states have more stringent safeguards in place to impose condition- or issue-specific safeguards (i.e., HIV/AIDS, mental health, genetic information), or to address consumer access to their own records (e.g., requiring health care entities to respond more rapidly to consumer requests for records than HIPAA requires). These state laws may impose differing standards on different Health Data Sources and impact their ability to transfer health information to a PHR.
The National Council of State Legislatures (NCSL) and the National Governor's Association have launched an initiative to explore the need for new and consistent policies. Efforts are also underway at the federal level (in the Health Information Privacy and Security Collaboration and in legislative proposals) to "harmonize" state health privacy laws to avoid variations that some believe impede interoperability and data sharing. However, a number of studies suggest that most variations in state law can be addressed through policy and technical solutions.13
Overall, however, the lack of federal and state regulation, as well as the evolving interplay of state and federal laws, results in an uncertain regulatory environment. This can be chilling to the nascent market of Consumer Access Services. Fundamental questions about consumer consent for uses and disclosures, notice, enforcement, and chain-of-trust agreements are being determined outside of the regulatory environment, and many companies are uncertain how to proceed in their early products and services.
Answer: Perhaps, but certainly not yet – and not consistently across the industry.
There is some hope that vendors' recognition of public concern about safeguarding personal information will drive competition to produce services with stronger and more responsive privacy components. Today, in the absence of regulatory clarity, most PHR ventures develop and adopt their own privacy and security policies, either as individual companies, or through trade and professional associations. However, such policies are inconsistent and often confusing. Because consumers do not have simple or foolproof ways to distinguish good privacy practices from bad, organizations may not be motivated to compete on the basis of privacy protection, and/or determine that "mining" personal data is more profitable than investing in stronger privacy protections. It is not clear there is a "market" for privacy, since many of the practices that would assure privacy safeguards are not observable by consumers. (The potential role of regulation of PHRs and Consumer Access Services by the Federal Trade Commission (FTC) is discussed in CP9: Enforcement of Policies.)
Answer: Yes, for the following reasons:
Frequent news reports remind Americans about the risks to their health privacy by theft, breach, and unauthorized or unwelcome disclosure of their personal health information.i Eight in 10 Americans say they are "very concerned" about the risk of identity theft and fraud with networked personal health records, according to a Markle Foundation 2006 survey.ii Concerns are intensified in the context of electronic information sharing, as documented by a 2007 survey showing that the public believes a computer-based medical records system is less secure than a paper-based one.iii Three in five Americans believe that their health information is not adequately protected under federal and state laws and current business practices, according to a Harris Interactive study commissioned by the Institute of Medicine.iv
Moreover, such concerns can lead to privacy protective behaviors that actually undermine health, particularly among members of the most vulnerable demographic groups. Surveys consistently show that people with chronic diseases and racial and ethnic minorities are the most likely to withhold information from providers and avoid care to shield themselves from discrimination, stigma, and unwanted exposure.v
__________
©2008-2011, Markle Foundation
This work was originally published as part of a compendium called The Markle Connecting for Health Common Framework for Networked Personal Health Information. It is made available free of charge, but subject to the terms of a License. You may make copies of this work; however, by copying or exercising any other rights to the work, you accept and agree to be bound by the terms of the License. All copies of this work must reproduce this copyright information and notice.