Case Law Update: Just Because HIPAA Does Not Provide a Private Right of Action, Doesn't Mean that Other Avenues Exist

August 4th, 2017 - NAMAS
Categories:   Audits/Auditing   HIPAA|PHI  
0 Votes - Sign in to vote or comment.

Case Law Update: Just Because HIPAA Does Not Provide a Private Right of Action, Doesn't Mean that Other Avenues Exist

Simply stated, the Health Information Portability and Accountability Act (HIPAA) does not provide a private cause of action[1]. And, prior to the 2009 passage of the Health Information Technology for Economic and Clinical Health Act (HITECH Act)[2] and the more robust chain of liability (e.g. covered entities, business associates and subcontractors) under the Breach Notification Rule, several courts had held this notion to be true.[3]

Over the past decade, a shift has occurred where state and federal courts are holding that healthcare providers who breach HIPAA and other cybersecurity provisions may be pursued for a variety of common law claims including: negligence, emotional distress, breach of confidentiality, invasion of privacy, contract violations, and punitive damages.[4] The premise for bringing a cause of action for privacy violations stems from the fundamental source of American jurisprudence - the United States Constitution.
In re Columbia Valley Regional Medical Center, 41 S.W.3d 797, 802 (2001) established that, "there is a constitutional right of privacy in this case. Apart from any statutory or evidentiary privileges that apply, the medical records of an individual have been held to be within the zone of privacy protected by the United States Constitution."
See In re Xeller, 6 S.W.3d 618, 625 (Tex. App. - Houston [14th.] 1999, orig. proceeding) (citing Alpha Life Ins. Co. v. Gayle, 796 S.W.2d 834, 836 (Tex. App. - Houston [14th Dist.] 1990 no writ).

Recent cases that uphold this motion include:

These cases underscore the importance of compliance with HIPAA and the HITECH Act. Actions brought by the Federal Trade Commission, class action law suits and Securities and Exchange Commission requirements were not discussed. The take-away is that HIPAA, the HITECH Act, and other cybersecurity violations can and do form the basis of a wide variety of causes of action. Therefore, underscoring the need to be proactive instead of reactive.

This Week's Audit Tip Written By:

Rachel V. Rose, JD, MBA
Rachel V. Rose, Attorney at Law, PLCC

Rachel V. Rose, JD, MBA, is a Houston, TX-based attorney advising on federal and state compliance and areas of liability associated with a variety of healthcare, legal and regulatory issues including: HIPAA, the HITECH Act, the False Claims Act, Medicare issues, women's health as well as corporate and security regulations.

Article Resources:
[1] 42 USC § 1320d (1996).
[2] Pub. L. 111-5, Sec. 13001 (Feb. 17, 2009).
[3]Valentin-Munoz v. Island Fin. Corp., 364F. Supp. 2d 131, 136 (D. Puerto Rico 2005);
Univ. of Co. Hosp. Auth v. Denver Publ'g Co., 340F. Supp. 2d 1142, 1145-46 (D. Colo. 2004).
[4] R.K. v. St. Mary's Medical Center, 2012 WL 5834577 (WV S.Ct. (Nov. 15, 2012), cert. denied.

NAMAS is setting the standards in medical auditing & education    

The NAMAS team and faculty work hard to bring you membership resources, products, tools, and training that is not only timely and specific to medical auditing and compliance, but also that is     specific to the needs of medical practices today. NAMAS staff are industry recognized experts who provide audits and consulting services to active clients which gives NAMAS the cutting edge to provide relevant training.



Questions, comments?

If you have questions or comments about this article please contact us.  Comments that provide additional related information may be added here by our Editors.

Latest articles:  (any category)

Don't Let Your QPro Certification(s) Expire! Your Certifications Matter!
June 20th, 2019 - Chris Woolstenhulme, QCC, CMCS, CPC, CMRS
Hello QPro Members, Just a friendly reminder!                                                                                        ...
How to Properly Report Monitoring Patients Taking Blood-thinning Medications
June 18th, 2019 - Wyn Staheli, Director of Research
Codes 93792 and 93792, which were added effective January 1, 2019, have specific guidelines that need to be followed. This article provides some guidance and tips on properly reporting these services.
A United Approach
June 14th, 2019 - Namas
A United Approach As auditors, we all have a different perspective when evaluating documentation. It would be unreasonable to think that we all view things the same way. In my opinion, differing perspectives are what makes a great team because you can coalesce on a particular chart, work it through and ...
Documentation of E/M services for Neurology (Don't Forget the Cardiology Element)
June 13th, 2019 - Chris Woolstenhulme, QCC, CMCS, CPC, CMRS
According to Neurology Clinical Practice and NBIC, the neurologic exam is commonly lacking in documentation due to the extensive requirements needed to capture the appropriate revenue. With the lack of precise documentation, it results in a lower level of E/M than that which is more appropriate, which can cost a physician a lot ...
Medicare Now Reimburses for Remote Monitoring Services (G2010)
June 13th, 2019 - Aimee Wilcox, CPMA, CCS-P, CST, MA, MT, Director of Content
Medicare's 2019 Final Rule approved HCPCS code G2010 for reimbursement, which allows providers to be paid for remote evaluation of images or recorded video submitted to the provider (also known as "store and forward") to establish whether or not a visit is required. This allows providers to get paid for ...
Now is Your Chance to Speak Up! Tell CMS What You Think!
June 13th, 2019 - Chris Woolstenhulme, QCC, CMCS, CPC, CMRS
CMS is asking for your input, we all have ideas on how we would change healthcare documentation requirements and get rid of the burdensome requirements and regulations if it were up to us, so go ahead, speak up! Patients over Paperwork Initiative is being looked at to help significantly cut ...
Spotlight: Anatomy Images
June 13th, 2019 - Brittney Murdock, QCC, CMCS, CPC
When viewing CPT codes, Find-A-Code offers detailed anatomy images and tables to help with coding. For example 28445 offers a table with information to assist classification of gustilo fractures: Click on the image preview from the code information page to expand the image.

About Codapedia & Find-A-Code Contact Us Terms of Use Privacy Policy Advertise with Us

Codapedia™/Find-A-Code™ - 62 E 300 North, Spanish Fork, UT 84660 - Phone 801-770-4203 (9-5 Mountain) - Fax (801) 770-4428

Copyright © 2009-2019 Find A Code, LLC - CPT® copyright American Medical Association