By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: HIPAA: Liability to Private Parties for Violations
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Business > Hospital Administration > HIPAA: Liability to Private Parties for Violations
BusinessHospital AdministrationMedical RecordsPolicy & Law

HIPAA: Liability to Private Parties for Violations

David Harlow
David Harlow
Share
0 Min Read
SHARE

HipaaLast week, Connecticut joined at least nine other states (DE, KY, ME, MN, MO, NC, TN, UT, WV — see cases cited in the opinion, linked to below) in recognizing that, while HIPAA does not create a private right of action for violation of privacy, it does constitute a standard against which the actions of a defendant in such a case will be judged. In other words, if a covered entity or business associate or downstream contractor releases PHI other than in accordance with HIPAA (i.e., for treatment, payment or health care operations purposes, or to or at the direction of the data subject or his or her legal representative), the breach of the HIPAA rule may be the basis for a finding of a breach of a duty of care in a state court negligence action.

As the Connecticut Supreme Court observed in its opinion in Byrne v. Avery Ctr. for OB GYN, which was released earlier this week:

[A]ssuming, without deciding, that Connecticut’s common law recognizes a negligence cause of action arising from health care providers’ breaches of patient privacy in the context of complying with subpoenas, we agree with the plaintiff and conclude that such an action is not preempted by HIPAA and, further, that the HIPAA regulations may well inform the applicable standard of care in certain circumstances . . . .

[T]o the extent it has become the common practice for Connecticut health care providers to follow the procedures required under HIPAA in rendering services to their patients, HIPAA and its implementing regulations may be utilized to inform the standard of care applicable to such claims arising from allegations of negligence in the disclosure of patients’ medical records . . . .

The court also found that an action under state law was not pre-empted by HIPAA. In other words, the HIPAA standard of care may be used to judge the actions of the covered entity but that does not mean that HIPAA bars an individual from seeking redress for a breach under state law.

What does this mean for covered entities, business associates and downstream contractors? It is yet another reminder that exposure for violations of standards of care and conduct embodied in HIPAA regulations is not limited to indemnification clauses in business associate agreements or audits or enforcement actions brought by the OCR or a state attorney general. A data subject may bring suit if a covered entity, business associate or downstream contractor experiences a breach.

More Read

caregivers policy
Reducing Hospital Readmissions: An Interview with Robert Wood Johnson Foundation’s Anne Weiss
CMS Finds More Than 10% of Payments Paid Improperly
Big Data = Big Savings in Healthcare
Quality of Service in Healthcare: Have You Assessed Yours?
Physician Online Reputations: What Role for Hospitals?

The Connecticut case involved responding to a subpoena. There are specific HIPAA rules about responding to subpoenas, and the provider in this case likely should have provided notice to the data subject and an opportunity to quash. The breach was not the result of an outside hack — it was apparently the result of inadequate policies and procedures, and/or staff training, at a covered entity.

Other cases could involve breaches in other contexts. For example, a social media posting including PHI could be the basis of a state law claim, not just a complaint filed with OCR. And in fact, it is likely that the plaintiff bar will begin filing OCR complaints as part of their case preparation in breach of privacy matters; an OCR finding of a HIPAA violation could obviate the need for a trial on liability in a state court breach of privacy case — the case would go straight to a trial or settlement discussions on the amount of the damages.

At one end of the spectrum, the liability under a state law claim may run into the hundreds of millions of dollars. (Consider the Johns Hopkins settlement; while not a HIPAA case, it provides a sense of the monetary damages that may be incurred through lax attitudes towards privacy.)

I urge covered entities, business associates and downstream contractors to take these lessons to heart and redouble their compliance efforts accordingly.

photo: Flickr cc caliorg

TAGGED:HIPAA
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5kFollowersLike
4.5kFollowersFollow
2.8kFollowersPin
136kSubscribersSubscribe

Latest News

a woman walking on the hallway
6 Easy Healthcare Ways to Sit Less and Move More Every Day
Health
September 9, 2025
Clinical Expertise
Healthcare at a Crossroads: Why Leadership Matters More Than Ever
Global Healthcare
September 9, 2025
travel nurse in north carolina
Balancing Speed and Scope: Choosing the Nursing Degree That Fits Your Goals
Nursing
September 1, 2025
intimacy
How to Keep Intimacy Comfortable as You Age
Relationship and Lifestyle Senior Care
September 1, 2025

You Might also Like

Good riddance: United finally gives up on ACA marketplaces

April 28, 2016

Survey Shows Future of Cloud Computing in Healthcare Organizations

May 27, 2011

Left to Our Own Devices

April 14, 2011

The PCMH and Home Care Data: An Interview with Melissa McCormack

December 19, 2013
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?