Pandora’s Box: Can HIPAA Still Protect Patient Privacy Under a National Health Care Information Network?

Sean T. McLaughlin, Pandora’s Box: Can HIPAA Still Protect Patient Privacy Under a National Health Care Information Network?, 42 Gonz. L. Rev. 29 (2006).

I. Introduction

In an attempt to address the rising costs of health care,[1] the Bush administration seeks to fully usher American medicine into the digital age.[2] The Federal Health Architecture[3] is currently coordinating its practice toward electronic health care.[4] Serving as models for the private sector, the U.S. Department of Defense and Veteran’s Administration both continue to develop policies and procedures to safeguard electronic medical privacy and security.[5] Most importantly, the U.S. Department of Health and Human Services (“HHS”) has laid the foundation for a national health care information network.[6]

Establishing a national health care information network continues to build momentum within Congress. Members of the U.S. Senate[7] and U.S. House of Representatives[8] recently introduced bi-partisan legislation empowering HHS to fund pilot projects. Both bills provide for regional grants that encourage increased use of electronic medical records. Each includes financial incentives to develop experimental computer networks capable of securely and efficiently exchanging electronic health care information.[9]

Ideally, a nationally accessible network will allow the health care industry to improve efficiency and quality, while reducing costs and errors.[10] Yet, the decisions facing the Bush administration in devising and implementing the network will have profound implications for how U.S. health care functions in the 21st century. To succeed in digitalizing American medicine, the Bush administration must first inspire the trust and confidence of lawmakers, patients, and other health care participants.[11] While providing participatory incentives to the health care industry, the federal government also needs to vigilantly protect individual privacy against foreseeable abuse and threats. Specifically, any national health care network must adhere to medical privacy and security protections mandated under the “Health Insurance Portability and Accountability Act” (“HIPAA”).[12]

While criticism of HIPAA’s legality and effectiveness[13] may serve a vital function in debating the best approach to safeguard medical privacy, federal involvement is here to stay.[14] A more critical issue is how HIPAA will function in an age where evolving computer technology continues to empower the rapid accumulation and dissemination of information. %CODE2%
This article focuses on the key medical privacy questions surrounding the Bush administration’s national health care information network. Part II examines the Administration’s proposal, including the adoption of electronic medical records. Part III highlights the operational technology available to network architects. Part IV details how the Bush administration should direct HHS to devise and manage the network in order to uphold and empower HIPAA’s medical privacy and security regulations.

II. Electronic Health Records and Momentum Toward a National

Health Care Information Network

Inconsistencies regarding non-electronic medical information continue to plague the U.S. health care system.[15] Data is routinely stored in disparate locations. Most health records often remain compartmentalized by issues pertaining to treatment, research, administration, or payment.[16] Further, transferring and utilizing non-electronic health information often proves slow, expensive, and inaccurate.[17]

In April 2004, President George W. Bush issued an executive order[18] urging the health care industry to implement and utilize electronic health records (“EHRs”).[19] Initially proposed in 1992 by the Institute of Medicine,[20] EHRs include a patient’s entire medical history.[21] Allowing for convenient access and organization, EHRs should greatly enhance information accuracy and health care delivery.[22] Shifting toward electronic use and storage will also empower researchers and public health officials to more efficiently accumulate and analyze data.[23] While the protracted benefits appear to greatly outweigh transition costs,[24] utilizing EHRs also raises important patient privacy concerns.[25]

In July 2004, HHS released: The Decade of Health Information Technology: Delivering Consumer-centric and Information-rich Health Care.[26] To help enact President Bush’s vision for twenty-first century medicine, the Department outlined four main goals: to inform clinical practice, to interconnect clinicians, to personalize health care, and to improve population health.[27] While upholding federal medical privacy and security standards,[28] HHS aims to eliminate current barriers of transferring electronic health care data.[29] Reiterating President Bush’s directive,[30] the proposal asks the health care industry to adopt interoperable EHRs[31] and improve patient access to personal health information.[32] Most importantly, the report also anticipates a national health care information network (“NHIN”).[33]

Under President Bush’s proposal, HHS foresees an easily accessible, web-based EHR vault.[34] To improve population health and clinical research, the network would increase and diversify health data collection and dissemination.[35] HHS also intends to publicly monitor[36] and limit the network solely for non-proprietary use.[37] Although it claims the plan does not “constitute a change in policy, rule, or law, and does not call for statutory changes in its own right,” [38] the Department acknowledges that the NHIN must co-exist with federal medical privacy protections.[39]

Given the heightened privacy concerns surrounding EHRs and computer networks,[40] understanding operational technology remains essential. How HHS proceeds will largely determine the influence and application of federal medical privacy law, and ultimately, the legal and political viability of President Bush’s NHIN proposal.[41]

III. The Computer Network Concept

Web-based computer networks allow users to share and exchange data.[42] Peer-to-peer networks grant multiple users simultaneous access to information. Although programs like Napster, Grokster, Kazaa, and Morpheus continue to highlight the technology’s growing popularity, distinct differences exist.[43] In its original form, Napster utilized a “closed network,” where a common server linked users.[44] More recent peer-to-peer programs operate under decentralized “pure networks.”[45] Through specialized software, a pure network empowers users to independently operate and share data.[46]

While peer-to-peer networks allow for high-volume data exchange, privacy and security concerns remain. Tech savvy users can easily retrieve and manipulate sensitive information. Individuals can also plant viruses, spyware, or other malicious logic onto another’s computer. Because peer-to-peer networks do not utilize a centralized server, accurately monitoring information use and disclosure also proves difficult.[47]

Client-server networks appear far more secure.[48] With client-server technology, users do not directly communicate; they only share and obtain data through a unifying, centrally-managed server.[49] Individuals utilize the network through an assigned username and password that the server must recognize and verify.[50] To protect against unauthorized activity, administrators can singularly employ numerous protective measures and dictate access levels.[51] Nonetheless, as technology and user expertise continue to develop, unassailable client-server network safety remains far from certain.[52]

Similar to the framework currently envisioned by other federal agencies,[53] the Bush administration’s proposed NHIN should employ client-server technology.[54] Client-server technology allows HHS to authorize and regulate network activity. It empowers network managers to effectively monitor patient information use and disclosure. Given the medical privacy protections that HHS must honor, NHIN client-server technology also stands apart as the Bush administration’s most viable option.

IV. HIPAA and Creating a Successful NHIN Framework

Over the last decade, “safeguarding medical privacy” emerged as a key mantra in the U.S. health care debate.[55] Despite gradual progress, until the mid-1990s, universal safeguards remained weak. The federal government left states to their own devices, causing protection levels to vary nationwide.[56]

In 1996, President Clinton signed the “Health Insurance Portability and Accountability Act” (“HIPAA”).[57] Among its various provisions,[58] HIPAA included a self-imposed deadline for Congress or the acting HHS Secretary[59] to finalize national medical privacy and security protections.[60]

Privacy cannot exist without security. By statutorily segregating these two interrelated interests, Congress viewed each with equal importance. Regarding privacy safeguards, Congress sought to “define and limit the circumstances in which an individual’s protected health information may be used or disclosed by covered entities.”[61] With key implications for the Bush administration’s NHIN proposal, HIPAA’s security provision primarily aimed to safeguard how parties physically access and transmit digital and electronic health data.[62] In 2002, the Bush administration affirmed HIPAA’s final privacy regulations.[63] Required compliance with HIPAA’s privacy rules began in April 2003,[64] but the federal government delayed adherence to the law’s security mandates[65] until April 2005.[66]

Although Bush administration officials might envision a de-centralized approach to electronic health information exchange,[67] HHS retains responsibility for ensuring that its NHIN adheres to federal law.[68] In order to inspire the faith and confidence of patients, lawmakers, and others, the Bush administration should proceed with caution in directing HHS to devise, implement, and regulate the NHIN. Accordingly, HIPAA’s medical privacy and security rules must play a central role.[69]

A. HIPAA’s Privacy Rule

1. Protected Health Information

HIPAA prohibits the improper use and disclosure of protected health information (PHI).[70] Whether in electronic or paper format,[71] PHI pertains to individually identifiable health information.[72] Although typically used to refer to medical history, PHI also includes any data that may reasonably identify a patient.[73]

Regardless of how HHS may pursue uniform patient classification,[74] EHRs will allow for more efficient PHI use and disclosure.[75] Because HHS should design the NHIN with client-server technology, network architects must consider how prospective participants may fall under HIPAA’s reach.[76]

2. Covered Entities

HIPAA directly governs covered entities:[77] health care providers,[78] health plans,[79] and health care clearing houses.[80] Generally, health care providers furnish, or receive payment for, medical services.[81] Health plans pay for or authorize medical care.[82] Health care clearinghouses include public and private entities that convert and format health information.[83]

To achieve President Bush’s goals, covered entities will utilize the NHIN. The initial hurdles involve selecting participants, assigning access, and regulating network activity. While increasing administrative efficiency and improving health care delivery are noble, preventing unaccountable information exchange must remain a paramount concern.[84] To maximize medical privacy protection and ensure regulatory consistency, HHS should utilize HIPAA’s definitions and mandates to organize and authorize NHIN activity.[85]

For PHI use, HHS should limit network access according to the covered functions[86] applicable to providers, plans, and clearinghouses.[87] HHS should also create sections for every EHR. Based on assigned access privileges, each portion should only display the minimum information necessary[88] for a covered entity to complete its covered function.[89]

For PHI disclosures,[90] covered entities should direct HHS to authorize network access to specifically identified recipients. As determined by the covered entity and authenticated by HHS, PHI recipients should only be able to view the applicable EHR sections required to complete a covered function or other specifically authorized activity. HHS should also require that covered entities, in order to authorize access for specific PHI recipients, enjoy a patient-relationship.[91] Inspiring trust in the Bush administration’s dedication to protecting individual privacy,[92] these requirements eliminate non-essential parties from accessing an individual’s medical history.[93]

3. Business Associates

Other organizations fall under HIPAA as “business associates.”[94] Business associates perform activities for, or provide services to, covered entities.[95] Through contract they must also promise covered entities that they will adequately safeguard PHI.[96]

Privacy concerns involving business associates will largely hinge on the network’s intended scope. At first glance, HHS could withhold business associate participation. Even outside the NHIN, covered entities could independently exchange PHI with their business associates. However, if the Bush administration strives to uniformly improve efficiency throughout the health care system, including business associates is imperative. Because most business associates deliver incidental administrative services,[97] allowing limited NHIN access would conserve time, effort, and resources. In turn, savings could be re-directed toward delivering improved care and containing costs.

Nonetheless, HIPAA fails to directly regulate business associates.[98] The law merely requires covered entities to monitor business associate behavior, uncover potential wrongdoing, and maintain patient privacy.[99] Unfettered NHIN access could compromise a covered entity’s ability to supervise how its business associates utilize patient PHI. Should the Bush administration determine that maximizing efficiency must drive initial NHIN implementation and use, HHS must work to preserve the delicate affiliation between covered entities and their business associates.

HIPAA’s business associate contract provision may remedy concerns.[100] HHS ought to require each covered entity to include additional terms that regulate the duration and scope of its business associate’s NHIN activity. Indicating the nature of their relationship, HHS should also compel covered entities to annually provide the Department with a detailed synopsis of their current business associates.[101] Upon certification, HHS should then only authorize limited NHIN access according to the particular service that each business associate provides.[102]

4. Authorization and Treatment, Payment, and Health Care Operations

Although not absolute,[103] covered entities may only use or disclose PHI pursuant to a valid, revocable authorization from the patient.[104] The authorization must identify the individual[105] and detail the specific PHI to be used or disclosed.[106] It shall also describe the specific purpose for intended PHI uses or disclosures[107] and highlight when any authorized activity expires.[108]

Prior to the NHIN’s debut, covered entities will need to alter their patient authorizations. Updated notices ought to include how and why covered entities intend to utilize the network. They should also inform patients how to access the network in order to view their own EHR.

Regardless, many health care functions escape HIPAA’s authorization requirement. Covered entities do not require patient authorization to use or disclose PHI for treatment, payment, and health care operations (“TPO”).[109] As a result, HHS must resolve whether the NHIN is necessary and appropriate for all TPO purposes.[110]

Under HIPAA, treatment involves the “provision, coordination, or management of health care and related services by one or more health care providers . . . .”[111] Utilizing patient PHI over the NHIN to improve health care delivery remains a key premise behind President Bush’s proposal.[112] Even with limitations, the network will allow providers to more effectively use PHI when administering care. Because EHRs will maintain past and current diagnoses, prescriptions, and procedures, providers will enjoy immediate access to a patient’s entire medical history. Moreover, solely relying on patient memory or displaced paper records will no longer impair providers, especially in emergency situations.

For treatment-related PHI disclosures,[113] although not required by HIPAA, HHS should require that each party enjoy a patient-relationship.[114] For each intended recipient, NHIN architects should also require that covered entities individually authorize HHS to grant time-specific EHR access.[115] Striking the appropriate balance between maximizing efficiency and ensuring patient privacy, this process facilitates proper treatment-related data exchange.

Although HIPAA’s payment exception primarily refers to provider reimbursements,[116] it also applies to health plans receiving premiums or processing coverage and benefits.[117] For payment-related PHI use and disclosure, EHR access privileges will again play a large role regarding how the network will ultimately operate. While HHS should delineate PHI use based on covered function, and limited pursuant to patient-relationships,[118] HIPAA allows covered entities to disclose payment-related PHI to any third-party, including non-covered entities.[119]

Understandably, opening the network to any non-covered entity raises glaring privacy concerns. While business associate activity can be held accountable through contract,[120] NHIN managers must take additional steps to safeguard patients. HHS should require applicable covered entities to identify specific payment-related PHI recipients.[121] After receiving individual authorization from the covered entity, HHS should delineate access only to those EHR sections necessary to complete the targeted transaction.[122]

For health care operations, HIPAA separates regulated activity into quality and competence assurance,[123] insurance services,[124] fraud detection and compliance,[125] and various business functions.[126] Covered entities may use or disclose PHI to any third party for its own health care operations.[127] If the PHI disclosure involves another covered entity, both parties must enjoy a patient-relationship.[128]

Similar to HIPAA’s payment provision, health care operations involving third parties also creates privacy dilemmas. For PHI disclosures between covered entities, utilizing a covered function, patient-based approach not only ensures HIPAA compliance, it duly protects individual privacy. If HHS deems broad NHIN activity essential, it should require covered entities to identify non-covered entity health care operations recipients, and after receiving authorization, delineate limited EHR access.[129]

6. The “Minimum Necessary” Standard

When utilizing PHI, HIPAA requires covered entities to adhere to its “minimum necessary” standard.[130] For PHI use, covered entities must identify workforce members that require access to an individual’s PHI[131] and proscribe appropriate limitations.[132] For PHI disclosures, HIPAA addresses routine and non-routine activity.[133] For routine disclosures, covered entities shall only transmit the amount reasonably necessary to achieve the specifically intended purpose.[134] Regarding non-routine releases, covered entities must develop internal procedures that limit the amount of PHI disclosed.[135]

Because client-server networks provide centralized access to information, oversight must rest with HHS operators. Creating a uniform framework not only provides clarity and consistency,[136] but it also allows HHS to properly regulate how participants and others utilize and access patient PHI over the network. Therefore, HIPAA’s minimum necessary standard should govern all NHIN use.

Prior to implementation, HHS should solicit feedback and require covered entities to differentiate between “routine” and “non-routine” disclosure activity. Covered entities ought to indicate why any “non-routine” disclosure cannot be achieved through alternative means.[137] Upon receiving this information, HHS should develop specific minimum necessary EHR access standards for covered functions and activities by business associate and other third parties.[138] Although requiring users to abide by strict guidelines may initially stifle efficiency, HHS should nonetheless proceed with caution. Given the potential for abuse and the delicate nature of an individual’s PHI, NHIN-specific ‘minimum necessary’ standards properly uphold patient privacy and ensure the network operates according to President Bush’s intended goals.[139]

For PHI use, the federal government must work closely with covered entities in properly training workforce members.[140] HHS should also require that business associates and other third parties adequately instruct their employees regarding NHIN access and use.[141] Under HIPAA, HHS could delineate internal employee NHIN access authority to network participants.[142] However, centralized control empowers HHS to maximize patient privacy and ensure that participants and their employees properly utilize the network.

NHIN participants should identify specific employees based on how they manage patient PHI.[143] Depending on whether employed by a covered entity, business associate, or other third party, HHS should authorize work force members to only enjoy access to the minimum EHR sections necessary to complete their work-related tasks.[144] While perhaps cumbersome, the Bush administration must ensure patients, lawmakers, and others who utilize the NHIN remain properly trained and closely monitored.

7. Patient Rights

HIPAA also grants patients key rights over their medical information. Health plans and covered entities with direct treatment relationships[145] must notify patients regarding their privacy practices.[146] Explaining the covered entity’s duties and obligations,[147] the notice also informs patients regarding their PHI rights and explains enforcement procedures.[148]

Covered entities will need to alter their notification practices and include information regarding PHI use and disclosure through the NHIN. To meet the April 2003 compliance deadline,[149] most covered entities mailed or posted in-office notices. To alleviate additional administrative burdens, the federal government needs to provide further assistance. Congress should authorize financial support for NHIN notice-related costs. Through its website, the Department should also require that all patients, prior to receiving individualized access to their own EHR, register with a username and password[150] and acknowledge a universal, NHIN-oriented privacy notice.[151]

By utilizing dual NHIN notification procedures, HHS will accomplish two key goals. First, locally administered NHIN-based notices ensure continued compliance with HIPAA. Additionally, they immediately inform patients, especially those without computer access, about how their PHI could be used and exchanged over the network. Second, through website notice acknowledgement and registration, HHS can further increase trust and awareness regarding NHIN privacy practices and begin to securely account for individuals seeking personal access to their own EHR.[152]

a. Individual Right to PHI Access

Although not absolute, HIPAA also grants patients the right to access their PHI.[153] Patients can review and obtain copies of their PHI; however, their PHI must be a part of a covered entity’s “designated record set.”[154] If a covered entity declines an individual access to their own PHI, HIPAA also differentiates between “reviewable” and “non-reviewable” denials.[155] “Reviewable” denials involve decisions intended to protect patients from harm.[156] A “non-reviewable” access denial pertains to PHI which is located within psychotherapy notes, compiled in anticipation for certain legal action, regulated by federal clinical research rules, held by correctional facilities, protected under the “Privacy Act of 1974,” or obtained under a promise of confidentiality.[157]

Because EHRs incorporate HIPAA’s designated record set model, patients should be entitled to view all information in their EHR. Accordingly, HHS must create and maintain secure patient access to the NHIN, including user-names and passwords.[158] Unlike coordinating with larger organizations, ensuring individual privacy and security for home computer use seems unrealistic. To further strengthen the patient-provider relationship,[159] HHS should authorize personal access to EHRs through secure computer workstations operated by an individuals’ primary care provider or applicable equivalent.[160]

Although patients may still utilize their HIPAA rights to demand access to PHI outside the NHIN, HHS, through a client-server network, will manage EHR access. As a result, the federal government must also assume greater responsibility for HIPAA’s “reviewable” and “non-reviewable” distinction. Prior to the NHIN’s debut, HHS should require covered entities to inform the Department regarding any patient PHI that they initially deem inaccessible under HIPAA.[161] Upon review, HHS should then develop protocols that eliminate certain information from a patient’s view.[162]

If a patient still seeks access to PHI not located in their EHR or believes that their EHR remains incomplete, HHS should direct patients to request access from the applicable covered entity outside the NHIN. If unsuccessful, patients should resolve any dispute through their local Regional Health Information Organization (RHIO).[163] As a last resort, patients should enjoy the right to appeal any decision by a covered entity or RHIO to HHS for final disposition.

b. Individual Right to PHI Amendments

Under HIPAA, individuals may also ask any covered entity to amend PHI existing within the individual’s designated record set.[164] Within sixty days, covered entities must provide a written reply.[165] Under certain conditions, covered entities may deny PHI amendment requests.[166] However, once accepted, covered entities must incorporate updated information and notify their business associates.[167] If specifically identified by the patient, covered entities must also inform any other persons that receive the individual’s PHI.[168]

While allowing patients to directly submit amendment requests through HHS or RHIOs may appear convenient, the Bush administration should work to strengthen the patient-provider relationship.[169] When attempting to amend PHI located within their EHR, individuals ought to deliver requests through their primary care provider.[170] If accepted, HHS should then require providers to inform all necessary parties, ensure the new information accurately enters the NHIN, and prompt patients to immediately acknowledge and verify the correction.

Aiding patients and covered entities alike, the NHIN will greatly facilitate HIPAA’s amendment process. Because EHRs mirror the law’s designated record set, most valid amendment requests should be honored. Patients should encounter minimal resistance, and the time between amendment requests and final action ought to greatly decrease. Most importantly, health care providers and others will be able to perform their duties while continually utilizing the most accurate information.[171]

c. Individual Right to PHI Accounting and Restrictions

HIPAA also creates a limited accounting right regarding PHI disclosures.[172] The main exceptions include: activity prior to the April 2003 compliance date,[173] PHI disclosures for TPO,[174] and PHI released pursuant to individual authorization,[175] law enforcement,[176] or national security.[177] Individuals may only demand an accounting for PHI disclosures covering a six-year period.[178]

Patients can request that covered entities only release their information for TPO purposes.[179] HIPAA also allows individuals to dictate how and where they receive their own PHI.[180] Covered entities must document, and comply with, reasonable requests,[181] including instances where an individual’s health and safety may be in danger.[182]

The NHIN should greatly empower patient accounting and restriction rights. Client-server technology will enable HHS to efficiently trace all network activity. In complying with HIPAA’s “Security Rule,”[183] all covered entities must also monitor and safeguard their network activity.[184] As such, patients deserve broader network accounting rights. While maintaining HIPAA’s law enforcement and national security exceptions, HHS should expand NHIN accounting rights to include all TPO disclosures.

The Bush administration ought to provide patients with the option to request NHIN accounting through either specific covered entities or their applicable RHIO.[185] Given the advantages that client-server technology provides, either option will ensure that valid accounting requests are quickly answered.[186] Unlike HIPAA’s accounting right, HHS should require patients to initially contact their primary care provider, or applicable equivalent,[187] regarding PHI restrictions. Upon accepting a patient’s request, providers should notify all necessary parties[188] and direct HHS to limit access to applicable TPO-related EHR sections. Should patients worry that a covered entity ignored their accepted restriction request, periodic accounting requests through their local RHIO ensure that any alleged misbehavior does not escape governmental review.

8. HIPAA Preemption and State Medical Privacy Law

HIPAA will only preempt state laws[189] with inferior privacy protections.[190] HIPAA preemption also applies when covered entities cannot possibly comply with both statutes or a state law frustrates HIPAA’s goals.[191]

HIPAA will not supersede “more stringent” state law.[192] Typically “more stringent” state statutes contain tougher restrictions that limit PHI use or disclosure,[193] allow individuals broader rights to PHI access or amendment,[194] provide more focused notice,[195] or require greater detailed accounting practices.[196] Where HIPAA does not wholly preempt state law, it may supplement local practice and impart additional obligations.[197]

Although HIPAA operates as a national baseline for patient privacy protection, how the NHIN will interact with state medical privacy law remains unclear.[198] Through client-server technology, patient EHRs will electronically reside at a centrally managed location. Moreover, network participants will invariably operate in different states and access patient information from various locations.

In meeting the April 2003 compliance deadline,[199] health care organizations should already understand where HIPAA does not preempt applicable state law. Nonetheless, because simultaneously placating every state’s medical privacy laws would be impractical,[200] network drafters should defer to HIPAA. Devising a HIPAA-compliant network provides two key advantages: 1) a cognizable framework for covered entities to evaluate how “more stringent” state medical privacy protections may apply to their NHIN activity;[201] and 2) a legally sound operating system, should state medical privacy law not apply to the NHIN.[202]

Nonetheless, in order to ensure that organizations do not initially balk at utilizing its NHIN, the federal government must provide additional guidance. Prior to granting access, HHS should require covered entities, business associates, and others to indicate a “home of record” and direct all participants to acknowledge written guidance regarding NHIN’s potential impact on local medical privacy laws. As time elapses, the Department ought to explore devising state-specific NHIN software and implementing internal network protocols that preemptively limit NHIN access and use according to individual state laws.

Although federal courts are certain to wrestle with how the NHIN, HIPAA, and state medical privacy laws intersect, the federal government must empower and assist local organizations in preparing for this foreseeable legal uncertainty. If neglected, confidence in HHS’s ability to competently manage the national use and exchange of electronic patient health information will likely plummet.

B. HIPAA’s Security Rule

Effective April 2005,[203] HIPAA’s security protections require covered entities to protect the integrity and availability of all electronic PHI that they create, receive, maintain, or transmit.[204] Covered entities must also “protect against any reasonably anticipated threats or hazards to data security or integrity.”[205]

To ensure compliance, HIPAA grants broad flexibility to covered entities. In addition to considering costs and the likelihood of security threats, covered entities must also examine their own size and technological capabilities.[206] For implementation specifics, HIPAA also differentiates between “required” and “addressable” security mandates.[207] Covered entities must employ “required” provisions,[208] but may examine environmental and feasibility factors when deciding to enact “addressable” safeguards.[209]

Given the vast amount of patient PHI that participants will use and access through the NHIN, HHS must work diligently to address all foreseeable security issues.[210] Conversely, the Department must demand heightened security precautions from all network participants. Although HIPAA only compels covered entities to abide by its “required” implementation standards,[211] HHS should utilize HIPAA’s “Security Rule” as the template for NHIN security management. As such, the Bush administration must demand that all NHIN participants abide by the law’s mandatory provisions.

1. Administrative Safeguards

HIPAA requires covered entities to “implement policies and procedures to prevent, detect, contain, and correct security violations.”[212] Specifically, they must conduct a risk analysis of electronic PHI confidentiality, integrity, and availability.[213] Covered entities shall also implement appropriate safeguards to reduce threats and vulnerabilities.[214]

Covered entities must develop and utilize procedures to “review records of information system activity.”[215] They shall assess and train their work force and only as needed, assign individual electronic PHI access privileges.[216] HIPAA also requires covered entities to identify, document, and remedy suspected security breaches.[217] They must implement contingency plans to back up and store copies of electronic PHI.[218] In addition, covered entities shall conduct regular technical and non-technical evaluations to ensure their electronic PHI remains properly secure.[219]

Because HHS will utilize client-server technology in order to manage and operate its NHIN,[220] it must ensure that all users meet these strict guidelines. Although the Department cannot possibly monitor every worksite, it can take preventative measures to maximize NHIN security.

First, HHS should require that all network participants submit an annual NHIN security report. Authored by each organization’s Security Official,[221] the report would assure the Department that each participant both implemented and adhered to HIPAA’s administrative safeguards.[222] The reports should also indicate how participants have upheld NHIN security and appropriately addressed security threats and violations.

Second, HHS should coordinate with the private sector to create, provide, and continually update specific software that enables access to the NHIN. Upon authenticating covered entities, businesses associates and others for NHIN access,[223] HHS should individually permit Security Officials to download NHIN software for their organization through the Department’s website. In addition to minimizing unauthorized use, universally mandated NHIN software will help guarantee that users access the network in the same manner. Streamlining how participants access the NHIN provides HHS with the best opportunity to uniformly combat emerging security threats.[224]

Finally, HHS should require annual security training for all authorized NHIN users. Coordinated through a participant’s Security Official, yearly training would minimize data entry errors and ensure PHI integrity.[225] NHIN participants should also document each session in their annual report. In turn, the Department will be able to collect and analyze various procedures as well as implement future uniform training guidelines for all NHIN users.

2. Physical and Technical Safeguards

HIPAA also requires covered entities to establish individual physical security procedures to limit electronic access to patient PHI.[226] Covered entities must ensure that computer workstations function properly and contain safeguards that prohibit unintended PHI access.[227] In addition to utilizing software that monitors computer activity,[228] covered entities must protect PHI from improper modification and destruction.[229]

For their workforce members, covered entities are required to create individual authorization mechanisms for those required to access patient PHI.[230] Most pertinent to the NHIN, covered entities must implement procedures to “guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.”[231] Further, covered entities are required to establish procedures for electronic PHI access during emergencies.[232]

Similar to HIPAA’s administrative requirements, HHS should specifically demand all network participants indicate their full compliance with the law’s physical and technical safeguards.[233] HHS should require all NHIN users to maintain and examine audit trials of their own network activity, conduct periodic simulated emergency drills, and include appropriate analysis in their Security Official’s annual report.

For workforce computers, HHS should require that all NHIN activity occur through specified stationary machines.[234] The Department should also mandate that all NHIN-capable computers utilize technology that immediately recognizes authorized individual users and automatically disconnects from the network after a specified period of inactivity.[235]

To further aid NHIN participants in physically securing electronic patient PHI from unauthorized use and improper alteration, HHS should provide specific technological assistance. In addition to NHIN software, the Department should employ firewalls and transmission control protocol wrappers.[236] It should also require all network users to utilize standardized NHIN-specific smart card devices.[237] In addition, HHS should recommend and authorize security programs that NHIN users may utilize to further safeguard PHI.[238]

As computer technology continues to evolve, HHS will inevitably need to develop additional safety measures. Nonetheless, by faithfully adhering to HIPAA’s security mandates during initial NHIN creation and implementation, HHS and network participants will be able to rely on a sound organizational foundation to collectively address future threats and concerns. By demonstrating a proactive, universal approach to NHIN security, the Bush administration will also continue to gain the trust of lawmakers, patients, and other health care participants.

V. Conclusion

The Bush administration’s plan for a national health care information network offers an abundance of promise. Once fully realized, the NHIN will empower authorized users to access medical information from anywhere in the country. It will also revolutionize how patients, providers, and others interact under our present health care system. While almost certain to improve efficiency and reduce costs, the network also presents the federal government with grave challenges.

Given the highly sensitive nature of medical information, the health care industry and network architects face complex, transitional hurdles. Moreover, the Bush administration must work to convince patients, lawmakers, and others that increased performance is compatible with meaningful medical privacy protection. Instead of eschewing HIPAA, the Bush administration should direct HHS to utilize the law—and its privacy and security regulations—to devise, implement, and manage the NHIN.

HIPAA provides network drafters with a familiar national framework to organize and regulate NHIN access and use. By using HIPAA, the federal government conveys to patients that it does not intend to use the NHIN to weaken privacy or autonomy. This approach relieves providers, hospitals, insurers, and others from new and unnecessary regulatory burdens. It also provides opportunities to uncover and remedy operational defects in the law, further empowers patient rights, and ensures that federal medical privacy law keeps pace with the evolving digital landscape.

As Americans grow increasingly comfortable with the instant convenience that computer technology provides, the U.S. health care system must follow suit. Yet, without the faith and confidence of those who will fund and utilize it, any attempts at establishing a national health care network are destined to fail.


*. J.D., Notre Dame Law School. In addition to academic mentors past and present, the author would like to thank Mr. Mike Piper, Mrs. Cheri Dolezal, Mr. Jerry Dolezal, and Mr. Ron Curtin for providing the opportunity to make this article possible.

