HIPAA, Breaches, and Patient Records

Most practices treat HIPAA as a form patients sign at the front desk. It is actually a set of operational obligations with deadlines, and the two moments when that becomes clear are unpleasant ones: after a laptop, an email account, or a billing vendor is compromised, and when a patient or a former employee files a complaint.

The Law Offices of Albert Goodwin advises New York City practices on breach response, records obligations, and regulatory investigations.

When Something Has Happened: The First Week

A ransomware event, a misdirected fax or email, a stolen device, a phishing compromise of a staff email account, or an employee accessing records they had no reason to see all raise the same initial question: was there a breach of unsecured protected health information requiring notification.

Under the federal breach notification rule, an impermissible acquisition, access, use, or disclosure of protected health information is presumed to be a breach unless the covered entity demonstrates a low probability that the information has been compromised, based on a risk assessment considering at minimum the nature and extent of the information involved, the unauthorized person who used or received it, whether the information was actually acquired or viewed, and the extent to which the risk has been mitigated. That risk assessment must be documented, and the documentation is what the regulator will ask for.

Encryption matters enormously here. Information encrypted to the applicable standard is generally not unsecured, which can mean a lost device triggers no notification obligation at all. Practices that encrypt laptops and phones convert a reportable event into a non-event.

Notification Obligations

  • Affected individuals must be notified without unreasonable delay and no later than sixty days after discovery.
  • The Secretary of Health and Human Services must be notified. For breaches affecting five hundred or more individuals, notice is required contemporaneously with individual notice; smaller breaches are reported in an annual submission after the close of the calendar year.
  • Prominent media must be notified for breaches affecting five hundred or more residents of a state or jurisdiction.
  • Business associates must notify the covered entity, on timing set by the rule and by the business associate agreement, which is one reason those agreements should specify a shorter internal deadline than the regulation's outer limit.

New York Obligations on Top

New York's data breach notification law requires notice to affected New York residents and to the Attorney General, the Department of State, and the Division of State Police, and it defines private information to include certain health and health insurance information. The SHIELD Act separately requires businesses holding private information of New York residents to implement a reasonable data security program with administrative, technical, and physical safeguards. A practice that has complied with HIPAA is treated as satisfying the SHIELD Act's data security requirements, but the notification obligations still require attention, and the Attorney General has enforcement authority. Our page on SHIELD Act compliance covers the security program requirements, and data breach response covers the broader picture.

OCR Investigations and Complaints

Investigations by the Office for Civil Rights arise from reported breaches, from patient complaints, and from compliance reviews. A large share of complaints involve two things: denial or delay of a patient's access to their own records, and impermissible disclosures.

What OCR asks for is predictable, and what practices cannot produce is also predictable. The requests typically include the practice's security risk analysis, its policies and procedures, workforce training records, business associate agreements, the breach risk assessment, and evidence of the corrective measures taken. The security risk analysis is required, must be reasonably current, and is the document most often missing entirely. A practice that can produce a dated risk analysis, a remediation plan, training logs, and executed business associate agreements is in a fundamentally different position from one that cannot, regardless of the underlying incident.

Penalties are tiered by culpability, from reasonable diligence failures through willful neglect, with substantially higher amounts and annual caps at the upper tiers, and willful neglect that goes uncorrected carries the most severe exposure. Resolution frequently comes through a settlement with a corrective action plan and monitoring rather than a formal penalty.

Note that HIPAA provides no private right of action. Patients cannot sue under it directly. They can and do file complaints, and they bring state law claims for breach of confidentiality and negligence, where New York recognizes a cause of action for a health care provider's breach of the duty of confidentiality.

Patient Access to Records

This is the most common enforcement subject and the easiest to get right.

Under the federal access right, individuals may inspect and obtain a copy of their records in the form and format requested if readily producible, generally within thirty days, with one permitted extension on notice. Fees are limited to a reasonable, cost-based amount, and a practice may not condition access on payment of an outstanding balance for treatment.

New York adds its own requirements. Public Health Law section 18 gives qualified persons access to their medical records, sets a maximum per-page charge for paper copies, and provides that access may not be denied solely because of an inability to pay. It also addresses the narrow circumstances in which a provider may deny access on the ground that disclosure can reasonably be expected to cause substantial and identifiable harm, and the review process that follows such a denial.

Practices should also be aware of the federal information blocking rules, which prohibit practices likely to interfere with access, exchange, or use of electronic health information, subject to defined exceptions. Slow-walking a records request, or requiring an unnecessary form, can raise issues under those rules independent of HIPAA.

Retention, and What Happens to Records When a Practice Ends

New York requires that a physician retain a patient record for at least six years, and for a minor, for at least six years and until one year after the minor reaches the age of eighteen, whichever is longer. Failure to maintain records that accurately reflect the care rendered is itself professional misconduct. Other requirements apply to specific record types and to hospitals and other facilities.

Those obligations do not end when the practice does. When a practice closes, is sold, or a physician retires or dies, the records must be preserved and remain accessible to patients. The practical arrangements are custodianship by a remaining or acquiring physician, a written custodial agreement with a records storage company, or transfer with patient notice, together with notification to patients of where their records are and how to obtain them. This is one of the most frequently neglected items in a practice wind-down, and it is a licensure matter as much as a business one.

In a sale, the treatment of records requires care: patient records are transferred subject to the applicable rules, and the acquiring practice becomes responsible for them. Where the transaction is structured as an asset purchase, the records provision and the patient notification plan should be drafted specifically rather than left to a general assignment clause. See selling a medical practice and records when partners separate.

Vendors and Business Associate Agreements

Billing companies, electronic health record vendors, transcription services, answering services, cloud storage providers, shredding companies, and information technology contractors are business associates, and an agreement is required with each. The provisions worth negotiating beyond the regulatory minimum: a breach notification deadline shorter than the outer regulatory limit, an obligation to cooperate and bear the cost of notification where the vendor caused the breach, indemnification, a requirement to carry cyber liability insurance, security standards including encryption, audit rights, and clear obligations on return or destruction of data at termination. A practice that has to notify thousands of patients because a vendor was compromised, with no contractual recourse, has an expensive and avoidable problem. See vendor contract negotiation.

Employees and Snooping

A recurring scenario: a staff member looks up the record of a relative, a neighbor, or a celebrity. This is an impermissible use requiring a breach analysis, it requires sanctions under the practice's own policies, and the absence of audit logging or of any sanction history is what turns an isolated incident into a finding of inadequate compliance. Access controls limiting staff to the minimum necessary, audit log review, and documented sanctions are the practical answer.

If You Have Had an Incident

The sixty day notification clock runs from discovery, and the risk assessment that determines whether notification is required needs to be done properly and documented. If you have had a ransomware event, a compromised email account, a lost device, or an employee access issue, or if you have received an OCR letter or a patient complaint, contact us early. If nothing has happened yet, the highest value work is a current security risk analysis and executed business associate agreements, which are the two things regulators ask for first.

Call the Law Offices of Albert Goodwin at 212-233-1233 for a consultation.

You can contact us by phone at 212-233-1233 or by email at [email protected].

Attorney Albert Goodwin

About the Author

Albert Goodwin Esq. is a licensed New York attorney with over 18 years of courtroom experience. His extensive knowledge and experience make him well-qualified to write authoritative articles on a wide range of legal topics. He can be reached at 212-233-1233 or [email protected].

Albert Goodwin gave interviews to and appeared on the following media outlets:

ProPublica Forbes ABC CNBC CBS NBC News Discovery Wall Street Journal NPR

Client Reviews

Verified feedback from our clients

Mr. Goodwin is everything you want in an attorney: professional, honest, thorough, and genuinely caring. He always explains things clearly, so I understood exactly what was happening and what to expect next. His attention to detail and persistence really stood out. Looking back, I feel lucky to have found him. He guided me through the whole process expertly, and I deeply appreciate all his hard work. Would definitely recommend him to anyone needing legal help.

Sarah M

Legal Services

Thanks to Mr. Albert Goodwin's hard work and smart thinking, I finally won my case, which has been a long time coming. He figured out solutions that no one else could see. I'm really impressed by his strong ethics - something that's rare these days. As my lawyer, he went above and beyond what I expected. I'm so grateful I found him and would definitely recommend him to anyone needing legal help.

Lawrence H

Legal Services

From our first meeting, I knew I was in great hands with Albert and his associate Katrina. They handled my case with incredible skill and efficiency, even though they took it over from another firm. What impressed me most was how quickly Albert responded to my questions with honest, clear answers - no sugarcoating, just straight talk. They managed a huge workload under tight deadlines, and their fees were very reasonable for such high-quality work. Beyond his legal expertise, Albert's wit and personality made a difficult process much easier to handle. I'm deeply grateful for their hard work and would absolutely choose them again. If you need legal help in New York, you won't find better representation than Albert's firm.

Adam F

Legal Services

VIEW MORE
New York State Bar Association Member Badge New York City Bar Association Member Badge American Bar Association Member Badge Avvo Rated Attorney Badge