A lab calls a patient at home and gives his blood test results to his wife. A TV station does a feature on a sleep disorders clinic, shoots video of patients, and broadcasts it. A lawyer leaves a client’s medical files in an open conference room while she goes to court.
At first glance, all three scenarios might seem innocuous. But all three involve confidential patient information covered by Rhode Island’s patient privacy law, the federal Health Insurance Portability & Accountability Act (HIPAA), or both.
Nationwide, the onset of HIPAA’s privacy rules in 2003 and security rules last April has forced the health care industry to get a crash course on all the legal requirements. But in daily practice, many questions remain, and in Rhode Island, state laws also complicate the picture.
At a HIPAA forum at the Rhode Island Bar Association’s annual meeting this month, two Providence lawyers explained the rules to their peers and warned of potential pitfalls.
Kimberly I. McCarthy, of Partridge, Snow & Hahn, focused on Rhode Island’s laws, which pre-date HIPAA’s privacy rules by 25 years, but weren’t known to many people, she said, until HIPAA came along and they set out to write policies that complied with both.
The good news locally, McCarthy said, was that Rhode Island’s laws were already stricter than HIPAA; they’re said to be the toughest in the nation. But HIPAA also covers only a narrow set of entities and circumstances, she warned, while the state laws apply to everyone.
WPRI Channel 12 found this out the hard way, McCarthy said, in 1996, after it broadcast a story on a sleep disorders clinic. A man saw a promo for the 11 o’clock news showing him at the clinic, and called anchor Walter Cryan to stop him from running the story. Channel 12 played the segment anyway, and the man sued and won damages from the TV station.
Rhode Island law also covers items you might not think, McCarthy said, such as answers to medical questions on a driver’s license application or the names of doctors who treated you in a given time frame. And it requires patients’ explicit, written consent, including a statement of purpose, before information can be released, even to a person’s spouse or lawyer.
It’s not enough for a patient to tell a lab, for example, that it’s OK to give his wife his blood test results; her name would have to be on record, in writing. And a doctor can’t just hand over a patient’s files because she got a note saying to give his lawyer “whatever she asks for.”
In this context, McCarthy and Stephen Zubiago, of Nixon Peabody, agreed, HIPAA’s privacy rules pose few new challenges for local health care providers. What HIPAA adds, however, is what Zubiago called “affirmative” responsibilities: It’s not enough to never have disclosed information improperly; under HIPAA, just the fact information isn’t kept securely – say, if patient files are kept in unlocked cabinets, or if a lawyer discusses a client’s health within earshot of a colleague – can constitute a violation.
HIPAA also requires specific systems and procedures, Zubiago said: You must have a privacy policy; you must sign confidentiality agreements with anyone with whom you’ll share health records; you must conduct a security assessment and implement minimum safeguards. And when you do disclose information, with the proper permissions, you must keep a record.
Many hospitals, health plans and other larger health care organizations have HIPAA compliance staff to handle all these issues. But among smaller providers, and even among many lawyers, McCarthy and Zubiago said, many still don’t know all the requirements, while others have been scared by exaggerated “myths.”
“It’s a complicated, specific area of law,” Zubiago said, “and not all people who interact with the health care system understand it.”


