Home | About | RSS Feed | Contact and Publicity Guidelines | Comment Policy the Law, the Universe, and Everything 

advertise-here4


Slip Opinions


Groundhog Day. (fp)

Banned in Tucson. (kw)

The Best and Worst of 2011 in Race and Law (kw)

Tortured to death for trespassing. (fp)

Drones of contention. (fp)

DOJ still coddling banks. (fp)

Creative destruction? Thank banks. (fp)

Blog about a new book, on how to talk to little girls--stressing smarts not cutes.   LAC

Macey on the heroic Rakoff. (fp)

Captured NY Fed. (fp)


solicitors

Our Podcast

Subscribe to Law Talk

law-rev-contents2.jpg


  • Posts by Author

  • Categories

  • Archives


  • Recent Comments


    • Car accident claim lawyers on Symposium Next Week on "A Legal Theory for Autonomous Artificial Agents"

    • Andrew MacKie-Mason on Can't the Supreme Court Just Say No to Cameras?

    • Joe on Employment Division v. Smith is Wrong

    • Shag from Brookline on Employment Division v. Smith is Wrong

    • Joe on Employment Division v. Smith is Wrong

    • Joe on Super En Banc in the Ninth Circuit

    • Shag from Brookline on Employment Division v. Smith is Wrong

    • G. Calamita on Symposium Next Week on "A Legal Theory for Autonomous Artificial Agents"

    • Joe on Super En Banc in the Ninth Circuit

    • Howard Wasserman on Can't the Supreme Court Just Say No to Cameras?

    • Gerard Magliocca on Super En Banc in the Ninth Circuit

    • Mike on Super En Banc in the Ninth Circuit

    • Ben on Lifecycles and the Firm

    • Samir Chopra on Symposium Next Week on "A Legal Theory for Autonomous Artificial Agents"

    • Chris Berry on Who Gets to Keep Trover?
  •  

    Site Meter

    About the Blog

    Concurring Opinions is a multiple authored, general interest legal blog.

    (Image: Wikicommons)

HIPAA-cracy

posted by William McGeveran

This morning, vindication! When a long New York Times investigative piece says exactly what you have been saying for a long time, it feels very good.

So it is with this morning’s thumbsucker [reg/$$ req'd] about the ridiculous overzealousness and misunderstanding of HIPAA by health care professionals. HIPAA is the Clinton-era law that was principally concerned with making health insurance portable, but has become better known for its privacy-protection requirements. (In fact, the statute largely delegated development of all the details of the privacy provisions to the Department of Health and Human Services, which engaged in a lengthy and torturous rulemaking process.) As recounted at length in the Times piece, many employees at hospitals, doctors’ offices, and insurance companies use the statute’s supposed requirements as a shield for bureaucratic inflexibility in releasing information, even to close family members of an incapacitated patient. I have had numerous encounters with just such ill-informed stubbornness myself, and I find it maddening. (You can only imagine some of the arguments I have had with telephone receptionists who blindly invoke HIPAA.)

In addition to the direct trouble it causes for patients and their family, I fear the continued misuse of HIPAA undermines support for all privacy regulation. This is the only direct contact many people will ever have with privacy law in action. Who could blame them if they conclude that legal privacy restrictions are for the birds? Disregard for patient privacy was widespread before HIPAA, and I have no doubt legal regulation was called for. There have been 27,778 complaints under the law. But those harms are less visible to most of us than the new harm of mindless overprotection.

What’s fascinating is that the excessive caution in response to HIPAA comes against a backdrop of extremely low risk of sanctions. Exclusive enforcement power lies with HHS — the law provides no private right of action. And HHS has never imposed any civil or criminal penalty (although there are three criminal cases ongoing at the moment, those situations are extreme outliers). What explains this risk aversion given the vanishingly small risk of any real penalty?


The article points to one cause: the regulations are long and often vague (though not as bad as some claim); it is always easier to say “no” than to figure out how to say “yes.” HHS must do a better job at presenting plain-English materials. Training of front-line staff — who often have the most public contact — also needs to improve. There are policy changes that could help with these problems, starting with greater effort at HHS.

In addition, I blame the army of consultants who descended on the health care industry after HIPAA passed and exaggerated its complexity to claim that only retention of their high-priced services could ensure compliance. Many offices are still spooked by that sales pitch. Increased clarity from HHS might help here too.

Finally, I agree completely with the HHS official who told the Times,

“Either innocently or purposefully, entities often use this as an excuse. They say ‘Hipaa made me do it’ when, in fact, they chose for other reasons not to make the permitted disclosures.”

I call this last phenomenon “HIPAA-cracy.” You often see the same mindset in dealing with, say, insurance coverage disputes. Inflexibility and unhelpfulness are all too often a part of the modern health care experience. And I’m not sure whether any amount of careful regulatory design can overcome that.

[Cross-posted at Info/Law]


 July 3, 2007 at 12:10 pm   Posted in: Administrative Law, Health Law, Privacy, Privacy (Medical)   Print This Post Print This Post

Responses (8)

  1. Frank - July 3, 2007 at 1:47 pm

    Excellent points, all. It reminds me of a the constant evocation of “security” when anyone asks for any flexibility re established procedures.

    It’s particularly sad here because HIPAA-cracy may undermine any chance we have of a coherent, interoperable, electronic medical records system; see, e.g.,

    http://www.ncvhs.hhs.gov/050816p1.pdf

  2. Eric Goldman - July 3, 2007 at 3:09 pm

    You write: “I fear the continued misuse of HIPAA undermines support for all privacy regulation.” I hear what you’re saying, but I would phrase it differently. HIPAA vividly demonstrates the true costs of privacy regulation–whether the overprotection is rational or not, it was predictable and inevitable, and the resulting hidden costs should give us pause when contemplating other new privacy regulatory efforts. Eric.

  3. William McGeveran - July 3, 2007 at 3:39 pm

    I don’t think the industry response was “inevitable,” or a “true cost.” Other industries have managed to integrate privacy requirements, here and in other countries, without so much apparent overprotection.

    But certainly you are right that, since a big part of the problem here was poor design of these particular regulations, HIPAA is a cautionary tale for lawmakers in future.

    And what I meant was, if average citizens see HIPAA as the best we can do, then public support for undertaking privacy protection measures at all will be (unreasonably) reduced.

  4. Doug Sylvester - July 3, 2007 at 5:22 pm

    Not much to add here except to say that you are overlooking the role that privacy lawyers have played in this arena. I had the (mis)fortune of working for a firm at the moment GLB came into effect and our firm went to full court press to convince clients to take a far more “protective” (read: apparatchik enforced) view of GLB than I think was necessary or even wise.

    My guess is that most doctors use lawyers to explain what HIPAA means and, as a result, are prone to accept the view that it means “no information at any time to anyone…even the patient.” The over-reaction of people to privacy issues is only made worse by the actions of the bar in overhyping both the dangers (to my mind) of over and under compliance with these “laws” and, worse, “public expectations” of privacy.

    Ok–I think I’ve overplayed my hand here…

  5. Doug Sylvester - July 3, 2007 at 5:24 pm

    Ok–I’m not usre you overlooked the role that lawyers play..you were just too nice in calling them “consultants.”

  6. David Harlow - July 4, 2007 at 10:49 am

    Well, folks, it’s not true only if and when the NYT says it is . . . Lots of ridiculous behaviors have been inappropriately blamed on HIPAA for at least as long as the regs have been in effect. But hey, it’s only one link in a chain . . . . As a practicing health care attorney, I see HIPAA as just the latest fig leaf some parties try to use in explaining behaviors or in negotiating a deal when they don’t want to do something — as in, gee, I’d really like to agree with your reasonable request but I can’t (HIPAA made me do it). Before HIPAA it was Stark, the Anti-Kickback Statute, or incomplete readings of other regulatory schemes.

    Some states (including mine, the Former People’s Republic of Massachusetts) have privacy rules stricter than HIPAA in many respects so the HIPAA-cracy is perhaps less pronounced than it is elsewhere.

    See my post on rampant HIPAA confusion at: http://healthblawg.typepad.com/healthblawg/2007/05/hipaa_confusion.html

  7. Mary H - August 6, 2007 at 6:39 pm

    I read the NYT article with interest and curiosity. You all can scorn those of us who toe the overzealous line undertaken by our employers, but your jobs are not at stake. As a lowly psychiatric social worker I WILL be terminated immediately if I give information to family members trying to help their relatives, unless I have a current release. Yes, it’s cruel and ridiculous and interferes with care, but I won’t help my patients by getting fired because our corporate compliance officer is, um, eager. She has put a regulation in place where we cannot even use patient last names in our own internal emails to need to know staff. Indeed, under HIPAA we’re told that we can’t confirm or deny that a person receives treatment from us even if the relative or partner calling regularly attends appointments with the patient. I agree that’s it’s ridiculous and I’m furious that I’ve been lied to, but it doesn’t help my real life situation.

  8. Stella Brown - May 19, 2011 at 4:17 am

    I can understand telephone privacy, as well as all the digital/portable data; (which seemingly can be given to just about anyone, other than family). Digital info is NOT the reason family and friends go to the hospital, F-ing Retards!!! We go there to see our loved ones; possibly for the very last time before they die from neglect and infections the hospital staff could have prevented if they cared about human life more than money and power.

    I was refused the RIGHT to see my FATHER before he died. Why? Keep people who actually do “CARE” away from their loved one while the staff doesn’t bother to tell Charlie Brown, “Hey, your daughter loves you and wants to see you; we wouldn’t tell her any ‘personal information’; Like where you were moved to, or what kind of infection we gave you, this time…”

    No! We are scared of violating Hipaa, so we just let elderly stroke patients sit here (all slumped over and dirty, lonely, wondering why his daughter won’t come and see him?) with at least three tubes in his body which should have been out long ago!!! One of those tubes, probably the “feeding” line is where the gastro infection entered; and the other one is just standard protocall, right? The one in the throat keeps him here till the ins. runs out, or till ya’ll kill him. Yes, I said it! He died thinking I didn’t love him; because you fools don’t use common ethics which have always been standard. When friends and family show up to comfort their loved one, you do not send them away crying and intentionally never bother to let the patient know what sort of bull shit is actually happening right here in the U.S. of Asinine.

    Alma and Debbie, I will never forget you two pieces of dirt

Leave a Reply

Spam protection by WP Captcha-Free


  • « Previous post
  • Next post »

Authors

Daniel J. Solove
Kaimipono Wenger
Dave Hoffman
Frank Pasquale
Deven Desai
Danielle Citron
Lawrence Cunningham
Sarah Waldeck
Jaya Ramji-Nogales
Solangel Maldonado
Gerard Magliocca

Guests

Derek Bambauer
Gabriella Coleman
andré douglas pond cummings
David Gray
Brishen Rogers
Joseph Turow
Elizabeth A. Wilson













Previous Guests

Michael Abramowicz
Michelle Adams
Robert Ahdieh
Marvin Ammori
Michelle Anderson
Laura Appleman
Taunya Lovell Banks
Ann Bartow
Steven Bellovin
Adam Benforado
Gaia Bernstein
Francesca Bignami
Josh Blackman
Joseph Blocher
Jeremy Blumenthal
Kathleen Boozang
Bruce Boyden
Donald Braman
Al Brophy
Neil H. Buchanan
Bill Burke-White
Scott Burris
Paul Butler
Ryan Calo
Naomi Cahn
Anupam Chander
Miriam Cherry
Jack Chin
Glenn Cohen
Jennifer Collins
Caroline Mala Corbin
Thomas Crocker
Allison Danner
Brannon Denning
Deven Desai
Mike Dimino
Mark Edwards
Maxine Eichner
Jessica Erickson
David Fagundes
Lisa Fairfax
Joshua Fairfield
Christine Haight Farley
Kim Ferzan
Dan Filler
Mary Anne Franks
Michael Froomkin
Amanda Frost
Brian Frye
Timothy Glynn
Rachel Godsil
Eric Goldman
Kyle Graham
David Gray
Craig Green
Tristin Green
Jonathan Hafetz
Meredith Harbach
Michelle Harner
Jeffrey Harrison
Hosea Harvey
Erica Hashimoto
Jennifer Hendricks
Carissa Hessick
Laura Heymann
Robert Hillman
Gilbert A. Holmes
Nicole Huberfeld
Christine Hurt
Darian Ibrahim
Sherrilyn Ifill
John Ip
Shavar Jeffries
Kevin Johnson
Kristin Johnson
Jeff Jonas
Courtney Joslin
Dan Kahan
Jeffrey Kahn
Brian Kalt
Sam Kamin
Michael Kang
Chimène Keitner
Alicia Kelly
Orin Kerr
Nancy Kim
Heidi Kitrosser
Adam Kolber
Russell Korobkin
Alex Kreit
Anita S. Krishnakumar
Susan Kuo
Greg Lastowka
Sarah Lawsky
Youngjae Lee
Margaret Lewis
Erik Lillquist
Jeff Lipshaw
Jonathan Lipson
Jacqueline Lipton
Matthew Lister
Joseph Liu
Michael Madison
Kevin Noble Maillard
Solangel Maldonado
Jason Mazzone
Linda McClain
William McGeveran
Salil Mehra
Carrie Menkel-Meadow
Max Minzner
Viva Moffat
Scott Moss
Eric Muller
Jaya Ramji-Nogales
Helen Norton
Elizabeth Nowicki
Paul Ohm
Angela Onwuachi-Willing
Michael O'Shea
David Opderback
Kristen Osenga
Rafael Pardo
Marcy Peek
Eduardo Peñalver
Robert Percival
Michael J. Pitts
Marc Poirier
David Post
Amanda Pustilnik
Shruti Rana
Geoffrey Rapp
Neil Richards
Lori Ringhand
Alice Ristroph
Marc Roark
Sasha Romanosky
Tuan Samahon
Susan Scafidi
David Schraub
Paul Secunda
Jonathan Siegel
Jessica Silbey
Peter Smith
Judd Sneirson
Adam Steinman
Charles Sullivan
Rick Swedloff
Olivier Sylvain
Steph Tai
Andrew Taslitz
Robert Tsai
Jenia Turner
Steve Vladeck
Ari Waldman
Spencer Weber Waller
Howard Wasserman
Melissa Waters
Frank Wu
Alfred Yen
Corey Yung
David Zaring
Timothy Zick
Michael Zimmer
Jonathan Zittrain

Ownership

Concurring Opinions is a
general-interest legal blog
operated by Concurring
Opinions LLC, a Pennsylvania
Limited Liability Corporation.

Blogroll

Above the Law
Access to Justice
ACS Blog
Althouse
Balkinization
Becker-Posner Blog
BlackProf
BoingBoing
Chicago Law Faculty Blog
Conglomerate
CrimLaw
Crime & Federalism
CrimProf Blog
Crooked Timber
Derechoalderecho
Discourse.net
Dorf on Law
Election Law
Emergent Chaos
The Faculty Lounge
Feminist Law Profs
43(B)log
Freakonomics Blog
Freedom to Tinker
Google Blogoscoped
How Appealing
Ideoblog
Info/Law
Instapundit.com
Juris Novus
Jurisdynamics
Just Books
Law and Humanities Blog
Law and Letters
Law Librarian Blog
Legal Profession Blog
Legal Theory Blog
Legal Times Blog
Leiter Reports
Brian Leiter's Law School Reports
Lessig Blog
Madisonian Theory
Media Law Blog
Mirror of Justice
The Moderate Voice
National Security Advisors
Opinio Juris
Point of Law
PrawfsBlawg
ProfessorBainbridge.com
Property Prof Blog
Red Tape Chronicles
The Right Coast
Schneier on Security
SCOTUSBlog
Security Dilemmas
Sentencing Law and Policy
Simple Justice
Sivacracy.net
The Situationist
Susan Crawford
TalkLeft
Talking Points Memo
TaxProf Blog
TeachPrivacy Blog
Tech & Marketing Law
Truth on the Market
Volokh Conspiracy
WorkPlace Prof Blog
WSJ Law Blog
Wonkette
The Yin Blog


© Concurring Opinions

Powered by WordPress