On March 5, 2003, the draft version of the Illinois HIPAA Preemption Analysis was completed and released by the state. The comment period for the Preemption Analysis was recently concluded on May 30, 2003, and, although there has been no guidance issued on when the final version will be available, it is not anticipated that there will be any significant modifications or new developments to the draft version. The purpose of this Client Alert is not to review the methodology by which the HIPAA preemption process is conducted in general, nor to set forth each and every instance where the Preemption Analysis asserts that an Illinois statute is "more stringent"1 than the HIPAA2 privacy rule3 . Rather, highlighted below are the Illinois acts or statutes under which some of the more significant preemption issues have been raised, including certain instances in which aspects of Illinois law may be more stringent than the Privacy Rule.
Ambulatory Surgical Treatment Center Act (210 ILCS 5/1)
- The Act governs the licensure and inspection of ambulatory surgical centers. Centers are required to keep clinical records including a signed informed consent for treatment.
- The Privacy Rule does not require a signed consent for treatment and, accordingly, this requirement is likely to be considered "more stringent" than the Privacy Rule.
Nursing Home Care Act (210 ILCS 45/1-101)
- The Act sets forth the framework under which certain types of long-term care facilities are regulated. Facilities are required to provide policies and procedures and a notice of privacy practices in 12-point font.
- The Privacy Rule does not mandate the font of policies and procedures or a notice of privacy practices and, accordingly, this requirement in the Act is likely to be considered "more stringent" than the Privacy Rule.
- A notice of privacy rights must be provided to each long-term care resident in addition to the provision of a Privacy Rule-required notice of privacy practices.
Hospital Licensing Act (210 ILCS 85/1)
- The Act sets forth the regulatory authority pursuant to which the Illinois Department of Public Health regulates hospitals in Illinois.
- The Act does not require that hospitals present patients with a notice of privacy practices, but only states that this is optional. Under the Privacy Rule, a notice of privacy practices is required and, accordingly, the portion of the Act that makes the provision of a notice of privacy practices permissive rather than mandatory will be pre-empted by the Privacy Rule.
- The Act also contains more stringent requirements with regard to the creation and maintenance of a designated record set than those mandated by the Privacy Rule. These requirements will need to be complied with by hospitals.
Insurance Information and Privacy Protection (215 ILCS 5/1001)
- This Article of the Illinois Insurance Code sets forth the standards under which information collected in connection with insurance transactions by insurance entities is used and disclosed.
- Health insurance issuers, among other entities, are required to provide a notice of information practices to individuals covered by the plan. These notice requirements supplement the notice of privacy practices contemplated by the Privacy Rule and it is possible to comply with both federal and state law. However, the Illinois law requirement that such a notice be provided upon policy renewal or at least once every 24 months is more stringent than the Privacy Rule requirement that a notice simply be made available once every three years.
- The state law requires the insurance issuer to provide access to certain records held by it within 30 days of a request for access, which is more stringent than the Privacy Rule’s requirement that access be provided within 60 days of a request for access.
- The state law requires that personal information that is amended, in addition to being provided on a going-forward basis to persons and entities requiring such information, must also be provided to all persons or entities that have received the unamended information within the last two years. The Privacy Rule does not provide for such a "look-back" of amended information and as such the Illinois law is more stringent than the Privacy Rule.
- The Illinois insurance code permits individual information to be disclosed as part of the marketing of a product or service absent an objection by the individual, e.g. an opt-out. This provision is contrary to the Privacy Rule’s requirement that disclosures for marketing purposes are only allowed pursuant to an executed authorization, and as such the Illinois insurance code provision is pre-empted by the Privacy Rule.
- Under Illinois law, disclosures by the insurer are allowed to persons or entities shown on the records of an insurer as having a beneficial interest in the policy of insurance as long as such disclosures are limited to what is reasonably necessary. However, under the Privacy Rule, absent a signed authorization, such disclosures can only be made for payment activities and, accordingly, unless the activity can be validly classified as a payment activity, the Privacy Rule preempts the Illinois law.
AIDS Confidentiality Act (410 ILCS 305/1)
The Act regulates the circumstances of HIV testing and the disclosure of test results.
- Illinois law requires that where an authorization for disclosure of test results is required, such authorization must specifically state that HIV test results are being released. This requirement is more stringent than the Privacy Rule because the Privacy Rule does not distinguish between classes of protected health information and would not require that an authorization state as such.
- The Act adds a "need to know" qualifier to disclosures of HIV test results for treatment purposes and is therefore more stringent than the Privacy Rule which does not add any such limitations to disclosures made for treatment.
- The Illinois law requires that HIV test results and an informed consent to release must be maintained in a confidential and segregated manner from the rest of the medical record such that only authorized persons have access. This requirement is more stringent than the Privacy Rule which does not specify that any particular category of health information in a record set be segregated from the rest of the medical record.
Genetic Information Privacy Act (410 ILCS 513/ 1)
- The Act regulates the circumstances under which an individual’s genetic information may be released to certain entities.
- Illinois law requires that any release of genetic information requires a specific authorization of the individual. This requirement is more stringent than the Privacy Rule because the Privacy Rule does not mandate that genetic information be treated differently than other types of health information and as such an authorization would not be required under the Privacy Rule for treatment, payment or health care operations.
If you are an entity that is subject to specific health care or health care-related Illinois laws and regulations, we advise you to consult with an attorney if you are unsure as to whether the law or regulation in question may either be preempted by the Privacy Rule or contain more stringent requirements than the Privacy Rule.
Footnotes
1 Defined in 45 C.F.R. Section 160.202, as amended (2002).
2 The Privacy Standards, the Electronic Transactions Standards, and the Security Standards promulgated under the Administrative Simplifications subtitle of the Health Insurance Portability and Accountability Act of 1996.
3 Standards for Privacy of Individually Identifiable Health Information, 45 C.F.R. Parts 160 and 164, as amended (2002).
This article is intended to provide clients with information on recent legal developments. It should not be construed as legal advice or legal opinion on specific facts. Pursuant to applicable Rules of Professional Conduct, it may constitute advertising.