Quietly, at the end of April, HIPAA was significantly weakened. HHS published what sounds like an innocuous notification in the Federal Register: Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties. This notification is actually an enormous change to the HIPAA penalty structure, a drastic reduction in HIPAA fines.
The existing penalty structure under HIPAA is based on the HITECH Act of 2009, which increased HIPAA’s fines in an attempt to give teeth to HIPAA enforcement. Since HIPAA began being enforced in 2003 until the HITECH Act, fines had barely been issued despite an enormous amount of HIPAA violations. HITECH was Congress’s rebuff to this weak enforcement approach. After HITECH’s more potent penalty structure, HHS finally began issuing fines. The chart below is how HHS has been interpreting the HITECH penalty framework since the HITECH Act:
There were some ambiguities under the HITECH Act as to these penalty tiers, but HHS had long interpreted these tiers according to the above chart. But now, HHS has suddenly changed its mind and adopted a very different interpretation. Under this new interpretation, the penalty tier limits are now as follows:
Notice the new annual limits. There are severe reductions in the annual limits for nearly every category except for uncorrected willful neglect. This change yanks many of the teeth out of HIPAA enforcement.
Last year was a record-setting year for HIPAA enforcement. On HHS’s website, OCR has touted its 2018 enforcement:
OCR has concluded an all-time record year in HIPAA enforcement activity. In 2018, OCR settled 10 cases and secured one judgment, together totaling $28.7 million. This total surpassed the previous record of $23.5 million from 2016 by 22 percent. In addition, OCR also achieved the single largest individual HIPAA settlement in history of $16 million with Anthem, Inc., representing a nearly three-fold increase over the previous record settlement of $5.5 million in 2016.
Here is an overview of the resolution agreements and enforcement actions with civil monetary penalties from 2018:
There have been quite a number of state HIPAA enforcement cases this year, and one expert points out a trend toward increasing state enforcement of HIPAA.
An article in Data Breach Today discusses a number of state HIPAA enforcement cases. Here are some of the ones discussed:
Massachusetts — $75,000 settlement with McLean Hospital for a data breach involving 1,500 victims based on an employee who routinely took home unencrypted backup tapes with PHI. From the state press release:
The AG’s complaint alleges that McLean, a psychiatric hospital in Belmont, allowed an employee to regularly take home eight unencrypted back-up tapes containing clinical and demographic information from the Harvard Brain Tissue Resource Center that the hospital possessed. The tapes contained personal information such as names, social security numbers, diagnoses and family histories. When the employee was terminated from her position at McLean in May 2015, she only returned four of the tapes, and the hospital was unable to recover the others.
New Jersey — $100,000 settlement with EmblemHealth for a 2016 breach involving 81,000 victims. Details from the state’s press release:
The incident at issue took place on October 3, 2016 when EmblemHealth’s vendor sent a paper copy of EmblemHealth’s Medicare Part D Prescription Drug Plan’s Evidence of Coverage to 81,122 of its customers, including 6,443 who live in New Jersey.
The label affixed to the mailing improperly included each customer’s HICN, which incorporates the nine digits of the customer’s Social Security number, as well as an alphabetic or alphanumeric beneficiary identification code. (The number shown was identified as the “Package ID#” on the mailing label and did not include any separation between the digits.)
During its investigation, the Division found that following the departure of the EmblemHealth employee who typically prepared the Evidence of Coverage mailings, the task was assigned to a team manager of EmblemHealth’s Medicare Products Group, who received minimal training specific to the task and worked unsupervised. Before forwarding the data file to the print vendor, this team manager failed to remove the patient HICNs from the electronic data file.
Move over robocop, there’s a new constable in town — the robocall cop. In the past decade, robocalls have surged. There has also been a dramatic rise in litigation about these calls under the Telephone Consumer Protection Act (TCPA). The TCPA litigation is led by a small group of serial litigators, people who have assumed the role of private enforcers of the TCPA. This is a fascinating story about how privacy law combats the growing scourge of robocalls. We are seeing the effective use of private litigation as an enforcement tool, but there are differing interpretations about the virtues of the robocall cops. Also wrapped up on the story is the issue of harm.
Robocalls are rising at an alarming rate. In the month of September 2017 alone, there were 2.4 billion robocalls. The number keeps rising per month, and September 2018 gave birth to 4.1 billion robocalls. At this rate, there may be billions and billions more robocalls than stars in the universe! Robocalls are definitely a problem. I’ve never heard of anyone who likes robocalls; the mosquito probably ranks higher in popularity. But robocalls persist and proliferate. Annually, in the United States, the number of robocalls exceeds 100 per person. There are 4.5 million robocall complaints per year to the FTC.
Along with the rise of robocalls, litigation has also been increasing. Lawsuits are perhaps a bit more popular than robocalls or mosquitos, but not by much. The TCPA, 47 U.S.C. § 227, passed in 1991, requires various forms of prior consent for robocalls, which are calls made with what the TCPA refers to as an “automatic telephone dialing system” (ATDS). Violations of the TCPA can be enforced through a private right of action, and there are statutory damages of $500 per violation ($1,500 for willful violations). The number of TCPA lawsuits has skyrocketed, from 14 federal cases in 2007 to 4,392 federal cases in 2017.
Pagosa Springs Medical Center (PSMC) has agreed to pay $111,400 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) for an alleged violation of HIPAA. OCR found that the company failed to deactivate a former employee’s access to a web-based calendar that contained the protected health information (PHI) of 557 patients. The company also failed to obtain a business associate agreement (BAA) with the calendar company (Google).