As soon as Donald Asmonga’s twins were born, a stream of coupons for diapers and baby formula began flowing into his mailbox. Asmonga, a Maryland resident, never requested the mailings, but the makers of baby products knew he had just become a father.
”We were receiving stuff before we even had the babies,” he recalled. “Somehow, the big formula producing companies got hold of our names.”
Seifert Systems Invests in Energy Efficiency to Strengthen Operations
For manufacturers, energy is more than just another operating expense. It plays a critical role…
Learn More
Asmonga, who is the government relations manager for the American Health Information Management Association, a Chicago-based national group, surmises that they got hold of his name through medical records. That shouldn’t happen, he said.
”Health care information must not be used for purposes other than what the information was collected for,” he said. “We should not have a health insurance company (taking information) and selling it to a direct marketing firm without a patient giving consent to do that.”
A proposed federal rule governing how electronic medical records may be used deals squarely with Asmonga’s concern. But the proposal is getting mixed reviews, both from patients’ rights advocates and from the people it would affect most: health care providers and their business partners.
The U.S. Department of Health and Human Services seeks to form national standards to protect medical records stored electronically, and the paper printouts these records create. The rules include numerous patients’ rights protections, and would make it a crime to knowingly misuse someone’s medical records, an offense that would carry fines and jail time.
Patients now have no federal right to see their medical records, or to know how they are used. These rules would provide them. Experts disagree on how effective the rules would be, but they agree on one thing: complying with them will be expensive. The department estimates the cost at $3.8 billion over five years. But industry experts, such as Lawrence W. Vernaglia, a member of the health practice group with the Providence law firm of Hinckley, Allen & Snyder, say the cost may be much more – “10 times that” is what Vernaglia predicts.
Compliance will also be time consuming. Hospitals already are analyzing their policies, practices, and systems, even though they will not have to be fully compliant for two years.
Indeed, the task is huge.
”This is as big as Y2K, or bigger,” said David B. Schlosser, senior manager of public affairs for Cerner Corp., a Kansas City, Mo. company that develops management information systems for the health care industry.
The department announced the proposal Oct. 29 of last year. In response, more than 40,000 comments poured in during the ensuing comment period, which ended Feb. 17, a spokeswoman for the department said. A final rule will be enacted after all the comments have been reviewed, she said.
While many states, such as Rhode Island, already protect medical records with strict regulations, the rules are an attempt to provide certain “floor” protections. And in cases in which the state law is tougher than the federal rule, the state law would prevail. The rules would permit care providers and clearinghouses to use patient information for treatment, payment, operations, and some public policy priorities, such as research and law enforcement. But other disclosures, to a marketing firm, for instance, would require the patient’s written consent.
In short, information would be, “easy to use for health purposes, and difficult to use for other purposes,” according to the department.
In addition to giving patients the right to see – and correct mistakes in – their records, and to know who has access to them, the proposed rules require that hospitals, health maintenance organizations, health care providers, and health care clearinghouses release only the minimum amount of medical information necessary to carry out a given task, such as paying a claim. These entities covered in the rule would also have to set up safeguards to ensure that only those who have good reason to see a person’s medical records can do so.
”It is a fairly encompassing regulation to try and institute,” said Lisa Corrente, safety coordinator in the risk management department of Women & Infants Hospital in Providence, which is part of the Care New England hospital network. Corrente is a member of Care New England’s steering committee that is working to make the network’s hospitals comply with the rule.
One of the things Women & Infants and other hospitals will have to do is appoint a “privacy” officer to monitor compliance and investigate breeches in the confidentiality policy. It will also have to train all workers, and the vendors the hospital works with, to comply with the rule. Further, it must develop a contingency plan, should any of the physical protections designed to protect information fail. Corrente did not have an estimate for how much it will cost to do all this, but she did say, “We don’t suspect it will be inexpensive.”
To Vernaglia, who represents health care providers, the rules are a classic un-funded mandate.
Specifically, Vernaglia said providers will have to renegotiate contracts with their
business partners, such as billing, accounting and law firms, to be sure they are compliant. This, combined with the cost of training personnel and upgrading technology, will hurt health care providers – especially the small ones. While the proposed rule gives most providers two years to comply, small entities would have three years.
”These things are not going to happen for free,” Vernaglia said. “Our providers barely have enough money to keep their doors open. This is one more regulatory burden on an already taxed system.
”(The) nursing home, lab, doctor’s office, these groups are going to have new responsibilities that they didn’t dream of when they opened their doors,” he said.
But while some criticize the department, others note that it has simply done what Congress asked it to do. Lawmakers in 1996 passed the Health Insurance Portability and Accountability Act, known as the Kennedy-Kassebaum bill, that called upon Congress to pass national medical records privacy standards by Aug. 21, 1999.
But Congress missed the deadline. So, as directed by the bill, Health and Human Services Secretary Donna E. Shalala proposed her own rules.
How the rules will affect Rhode Island is unclear, experts say. State law already permits patients to see their medical records. It also prohibits the release of confidential health care information without the patient’s written consent.
But the state law, the Confidentiality of Health Care Communications Act, gives 23 exceptions to the rule. For example, no consent is required for the transfer of medical information when: a child transfers from one school district to another; when a doctor or dentist needs information for a diagnosis or treatment during an emergency; or when a health care provider needs to release information to its lawyers in order to have adequate legal representation.
Some would say the exceptions give away too much.
“There is a school of thought that the exceptions are too broad,” said Jeffrey F. Chase-Lubitz, a lawyer with the Providence law firm of Brown, Rudnick, Freed & Gesmer who represents health care providers and medical information companies.
Still, Rhode Island has done a particularly good job of protecting sensitive patient information, said Dr. Patricia A. Nolan, director of the state Department of Health. Nolan outlined her own concerns about the rules in a Feb. 10 letter to Shalala. For example, the rules would exempt the department from disclosure requirements when it uses records for public health purposes. But since the health department is also a health care provider, it is possible that the department could be treated like a hospital or any other covered entity, making the department exempt on one hand and covered on the other. This would impose an onerous burden on the department, Nolan said.
But even with the rules’ lack of clarity, and with the cost they will impose, many say they are worth it.
“Regulations may cost providers some money, but in the interests of patients, this is important,” said C. Peter Waegemann, executive director of the Boston-based Medical Records Institute. “I, as a patient, want to have my records safe and secure.”
Some say the rules don’t go far enough. For example, the rule exempts providers from gaining patient consent in order to deliver or pay for medical care. Consent should be required even in these instances, said Peter Kane, executive director of the National Coalition for Patient Rights, based in Andover, Mass.
But while the department may alter aspects of the rule based on the comments it has received from groups such as Kane’s, local medical providers are working to comply with the rule as it’s proposed now. And for those who handle medical information, it means not only upgrading systems, policies, and training, but also preparing to balance the need for information with the requirement for privacy.
“The fine line we walk,” said Carole Cotter, vice president, information services for Lifespan, the state’s largest hospital network, “is providing the information that is needed to take care of the patient, but not permitting access to information to (people) who have no right to have it.”












