When Can HIPAA be Broken?
HIPAA cannot be “broken” inasmuch as the HIPAA Privacy Rule accommodates the circumstances in which covered entities may use or disclose Protected Health Information for purposes other than treatment, payment, or health care operations. Should a circumstance exist which is not accommodated, HHS’ Office for Civil Rights has the authority to exercise enforcement discretion.
One of the reasons covered entities find HIPAA compliance confusing is that the HIPAA Privacy Rule can sometimes be misinterpreted by organizations claiming to be subject experts. When these self-proclaimed experts have a prominent online profile, their misinterpretations can gain traction and influence policies and procedures implemented by covered entities to comply with HIPAA – potentially resulting in avoidable HIPAA violations.
How These Misinterpretations Evolve
In the case of articles discussing when can HIPAA be broken, it appears some “experts” started reading the HIPAA Privacy Rule’s General Rules, identified the standards that suited their narrative, and ignored the rest. This is evidenced by claims that times when HIPAA can be broken include for public health activities, law enforcement purposes, to report cases of abuse or neglect, and to support workers’ compensation claims.
However, all of these events are covered by clause “(vi)” of §164.502(a)(1), which permits uses and disclosures of Protected Health Information “as permitted by and in compliance with any of the following:”
(A) This section (e.g. §164.502).
(B) Section §164.512 and, where applicable, §164.509.
(C) Section §164.514(e), (f), or (g).
Uses and Disclosures of PHI Permitted by §164.502
Uses and disclosures of PHI permitted by §164.502 include disclosures to business associates, and personal representatives, disclosures by business associates to subcontractors, and disclosures by whistleblowers and workforce members who are the victims of a crime.
Uses and Disclosures of PHI Permitted by §164.512
Uses and disclosures of PHI permitted by §164.512 include disclosures for public health activities, law enforcement purposes, to report cases of abuse or neglect, and to support workers’ compensation claims. The reference to §164.509 relates to disclosures subject to an attestation.
Uses and Disclosures of PHI Permitted by §164.514
Uses and disclosures of PHI permitted by §164.514 include disclosures for fundraising purposes, disclosures of limited data sets, and disclosures of de-identified PHI. This section of the HIPAA Privacy Rule is often misinterpreted as a definition of PHI under HIPAA.
When Can HIPAA be Broken with a “Legal Waiver”?
The “legal waiver” is a further example of a self-proclaimed expert taking a Privacy Rule standard out of context and applying it to their narrative. Claiming that HIPAA can be broken with a legal waiver, Dr. Danielle Kelvas of HIPAAexams.com explains:
“The HIPAA waiver […] is a legal document that permits covered entities to use or disclose a patient’s protected health information (PHI), without individual authorization, to a third party when meeting specific conditions.” Dr. Danielle Kelvas HIPAAexams.com
However, the only circumstance in which a “legal waiver” is required to disclose PHI without authorization is when a covered entity disclosures PHI for limited research purposes and the disclosure is authorized by an Institutional Review Board (see §164.512(i)).
Every other circumstance in which it is claimed HIPAA can be broken with a legal waiver in Dr. Kelvas’ article is permitted by the HIPAA Privacy Rule’s General Rules discussed above and by §164.510(b) of the HIPAA Privacy Rule relating to disclosures of PHI to support disaster relief efforts. No document or “legal waiver” is required in any of these circumstances.
Breaking HIPAA and Enforcement Discretion
Under §1135 of the Social Security Act, the Secretary for Health and Human Services (HHS) has the authority to issue a HIPAA Notice of Enforcement Discretion if the President declares an emergency or disaster and the Secretary declares the event a public health emergency.
A HIPAA Notice of Enforcement Discretion permits HHS’ Office for Civil Rights to exercise enforcement discretion when healthcare organizations in areas affected by the public health emergency use or disclosure PHI in specific circumstances not normally accommodated by the HIPAA Privacy Rule.
Because the HIPAA Notice of Enforcement Discretion permits healthcare organizations to use or disclosure PHI in circumstances not normally accommodated by the HIPAA Privacy Rule, they are not breaking HIPAA all the time the Notice of Enforcement Discretion remains in force.
HIPAA covered entities and business associates who may have been misled by misinterpretations of the HIPAA Privacy Rule are advised to review policies and procedures implemented on the basis of the misinformation and amend them as appropriate – seeking professional HIPAA compliance advice when necessary.
