Skip to content Skip to navigation

OCR: Business Associates Blocking Access to Data are in Violation of HIPAA

October 4, 2016
by Heather Landi
| Reprints

It is an impermissible use of protected health information (PHI) for a business associate to block a healthcare provider’s access to data in order to resolve a payment dispute, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) stated in a new guidance.

In the guidance, posted last week in a “frequently asked questions” format, OCR clarified that business associates that block a client hospital, clinic or other healthcare entity's access to patient data are likely in violation of the Health Information Portability and Accountability Act (HIPAA) Privacy Rule.

“Generally, if a business associate blocks access to the PHI it maintains on behalf of a covered entity, including terminating access privileges of the covered entity, the business associate has engaged in an act that is an impermissible use under the Privacy Rule,” OCR stated.

For example, it would be impermissible for an electronic health record (EHR) developer to activate a “kill switch” embedded in its software that renders the data inaccessible to its provider client in order to resolve a payment dispute. “Similarly, in the event of termination of the agreement by either party, a business associate must return PHI as provided for by the business associate agreement. If a business associate fails to do so, it has impermissibly used PHI,” the OCR guidance stated.

There have been high profile cases of business disputes between EHR vendors and providers in which the vendors have blocked a hospital or clinic’s assess to patient records. As cited in a September 2014 article in the Boston Globe, staff members and clinicians at Full Circle Health Care, a clinic based in Presque Isle, Maine, were locked out of the EHR. As part of a billing dispute, the vendor for the clinic’s electronic health records, German-based company CompuGroup, took steps to block the staff’s ability to look up medical histories on its 4,000 patients.

Additionally, in the guidance, OCR stated that a business associate is required by the HIPAA Security Rule to ensure the confidentiality, integrity, and availability of all electronic PHI (ePHI) that it creates, receives, maintains, or transmits on behalf of a covered entity. Maintaining the availability of the ePHI means ensuring the PHI is accessible and usable upon demand by the healthcare provider, whether the data is maintained in an EHR, cloud, data backup system, database, or other system. “This also includes, in cases where the business associate agreement specifies that PHI is to be returned at termination of the agreement, returning the PHI to the covered entity in a format that is reasonable in light of the agreement to preserve its accessibility and usability. A business associate that terminates access privileges of a covered entity, or otherwise denies a covered entity’s access to the ePHI it holds on behalf of the covered entity, is violating the Security Rule,” OCR stated.

Further, OCR stated that a business associate is required by the HIPAA Privacy Rule and its business associate agreement to make PHI available to its provider client as necessary to satisfy the provider’s obligations, as a covered entity, to provide access to individuals under 45 CFR § 164.524. To that end, a business associate may not deny its provider client access to the PHI the business associate maintains on behalf of the healthcare provider if that provider needs the PHI to satisfy its obligations.

“OCR recognizes, however, that there may be certain arrangements that authorize the business associate to destroy or dispose of PHI, or perform data aggregation or otherwise combine data from multiple sources,” the agency stated. For example, a covered entity may engage a business associate to perform data aggregation of information from multiple sources that renders the disaggregated original source data unreturnable to the covered entity. The agency does not consider these contractual arrangements to constitute impermissible data blocking or access termination, OCR stated.




ONC National Coordinator Gets Live Look at Carequality Data Exchange

Officials from Carequality have stated that there are now more than 150,000 clinicians across 11,000 clinics and 500 hospitals live on its network. These participants are also able to share health data records with one another, regardless of technology vendor.

American Red Cross, Teladoc to Provide Telehealth Services to Disaster Victims

The American Red Cross announced a partnership with Teladoc to deliver remote medical care to communities in the United States that are significantly affected by disasters.

Report: The Business of Cybercrime in Healthcare is Growing

While stolen financial data still has a higher market value than stolen medical records, as financial data can be monetized faster, there are indications that there is ongoing development of a market for stolen medical data, according to an Intel Security McAfee Labs report.

Phishing Attack at Baystate Health Potentially Exposes Data of 13K Patients

A phishing scam at Baystate Health in Springfield, Mass. has potentially exposed the personal data of 13,000 patients, according to a privacy statement from the patient care organization and a report from MassLive.

New Use Cases Driving Growth in Health Data Exchange through Direct

In an update, DirectTrust reported significant growth in Direct exchange of health information and the number of trusted Direct addressed enabled to share personal health information (PHI) in the third quarter of 2016.

Insurers to CBO: Consider Private Insurers’ Data in Evaluations of Telemedicine

Eleven private insurers, including Aetna, Humana and Anthem, are urging the Congressional Budget Office (CBO) to consider the experience of commercial insurers when evaluating the impact of telemedicine coverage in Medicare.