Most practices treat HIPAA as a form patients sign at the front desk. It is actually a set of operational obligations with deadlines, and the two moments when that becomes clear are unpleasant ones: after a laptop, an email account, or a billing vendor is compromised, and when a patient or a former employee files a complaint.
The Law Offices of Albert Goodwin advises New York City practices on breach response, records obligations, and regulatory investigations.
A ransomware event, a misdirected fax or email, a stolen device, a phishing compromise of a staff email account, or an employee accessing records they had no reason to see all raise the same initial question: was there a breach of unsecured protected health information requiring notification.
Under the federal breach notification rule, an impermissible acquisition, access, use, or disclosure of protected health information is presumed to be a breach unless the covered entity demonstrates a low probability that the information has been compromised, based on a risk assessment considering at minimum the nature and extent of the information involved, the unauthorized person who used or received it, whether the information was actually acquired or viewed, and the extent to which the risk has been mitigated. That risk assessment must be documented, and the documentation is what the regulator will ask for.
Encryption matters enormously here. Information encrypted to the applicable standard is generally not unsecured, which can mean a lost device triggers no notification obligation at all. Practices that encrypt laptops and phones convert a reportable event into a non-event.
New York's data breach notification law requires notice to affected New York residents and to the Attorney General, the Department of State, and the Division of State Police, and it defines private information to include certain health and health insurance information. The SHIELD Act separately requires businesses holding private information of New York residents to implement a reasonable data security program with administrative, technical, and physical safeguards. A practice that has complied with HIPAA is treated as satisfying the SHIELD Act's data security requirements, but the notification obligations still require attention, and the Attorney General has enforcement authority. Our page on SHIELD Act compliance covers the security program requirements, and data breach response covers the broader picture.
Investigations by the Office for Civil Rights arise from reported breaches, from patient complaints, and from compliance reviews. A large share of complaints involve two things: denial or delay of a patient's access to their own records, and impermissible disclosures.
What OCR asks for is predictable, and what practices cannot produce is also predictable. The requests typically include the practice's security risk analysis, its policies and procedures, workforce training records, business associate agreements, the breach risk assessment, and evidence of the corrective measures taken. The security risk analysis is required, must be reasonably current, and is the document most often missing entirely. A practice that can produce a dated risk analysis, a remediation plan, training logs, and executed business associate agreements is in a fundamentally different position from one that cannot, regardless of the underlying incident.
Penalties are tiered by culpability, from reasonable diligence failures through willful neglect, with substantially higher amounts and annual caps at the upper tiers, and willful neglect that goes uncorrected carries the most severe exposure. Resolution frequently comes through a settlement with a corrective action plan and monitoring rather than a formal penalty.
Note that HIPAA provides no private right of action. Patients cannot sue under it directly. They can and do file complaints, and they bring state law claims for breach of confidentiality and negligence, where New York recognizes a cause of action for a health care provider's breach of the duty of confidentiality.
This is the most common enforcement subject and the easiest to get right.
Under the federal access right, individuals may inspect and obtain a copy of their records in the form and format requested if readily producible, generally within thirty days, with one permitted extension on notice. Fees are limited to a reasonable, cost-based amount, and a practice may not condition access on payment of an outstanding balance for treatment.
New York adds its own requirements. Public Health Law section 18 gives qualified persons access to their medical records, sets a maximum per-page charge for paper copies, and provides that access may not be denied solely because of an inability to pay. It also addresses the narrow circumstances in which a provider may deny access on the ground that disclosure can reasonably be expected to cause substantial and identifiable harm, and the review process that follows such a denial.
Practices should also be aware of the federal information blocking rules, which prohibit practices likely to interfere with access, exchange, or use of electronic health information, subject to defined exceptions. Slow-walking a records request, or requiring an unnecessary form, can raise issues under those rules independent of HIPAA.
New York requires that a physician retain a patient record for at least six years, and for a minor, for at least six years and until one year after the minor reaches the age of eighteen, whichever is longer. Failure to maintain records that accurately reflect the care rendered is itself professional misconduct. Other requirements apply to specific record types and to hospitals and other facilities.
Those obligations do not end when the practice does. When a practice closes, is sold, or a physician retires or dies, the records must be preserved and remain accessible to patients. The practical arrangements are custodianship by a remaining or acquiring physician, a written custodial agreement with a records storage company, or transfer with patient notice, together with notification to patients of where their records are and how to obtain them. This is one of the most frequently neglected items in a practice wind-down, and it is a licensure matter as much as a business one.
In a sale, the treatment of records requires care: patient records are transferred subject to the applicable rules, and the acquiring practice becomes responsible for them. Where the transaction is structured as an asset purchase, the records provision and the patient notification plan should be drafted specifically rather than left to a general assignment clause. See selling a medical practice and records when partners separate.
Billing companies, electronic health record vendors, transcription services, answering services, cloud storage providers, shredding companies, and information technology contractors are business associates, and an agreement is required with each. The provisions worth negotiating beyond the regulatory minimum: a breach notification deadline shorter than the outer regulatory limit, an obligation to cooperate and bear the cost of notification where the vendor caused the breach, indemnification, a requirement to carry cyber liability insurance, security standards including encryption, audit rights, and clear obligations on return or destruction of data at termination. A practice that has to notify thousands of patients because a vendor was compromised, with no contractual recourse, has an expensive and avoidable problem. See vendor contract negotiation.
A recurring scenario: a staff member looks up the record of a relative, a neighbor, or a celebrity. This is an impermissible use requiring a breach analysis, it requires sanctions under the practice's own policies, and the absence of audit logging or of any sanction history is what turns an isolated incident into a finding of inadequate compliance. Access controls limiting staff to the minimum necessary, audit log review, and documented sanctions are the practical answer.
The sixty day notification clock runs from discovery, and the risk assessment that determines whether notification is required needs to be done properly and documented. If you have had a ransomware event, a compromised email account, a lost device, or an employee access issue, or if you have received an OCR letter or a patient complaint, contact us early. If nothing has happened yet, the highest value work is a current security risk analysis and executed business associate agreements, which are the two things regulators ask for first.
Call the Law Offices of Albert Goodwin at 212-233-1233 for a consultation.
You can contact us by phone at 212-233-1233 or by email at [email protected].