Skip to content Skip to navigation

OCR: Business Associates Blocking Access to Data are in Violation of HIPAA

October 4, 2016
by Heather Landi
| Reprints

It is an impermissible use of protected health information (PHI) for a business associate to block a healthcare provider’s access to data in order to resolve a payment dispute, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) stated in a new guidance.

In the guidance, posted last week in a “frequently asked questions” format, OCR clarified that business associates that block a client hospital, clinic or other healthcare entity's access to patient data are likely in violation of the Health Information Portability and Accountability Act (HIPAA) Privacy Rule.

“Generally, if a business associate blocks access to the PHI it maintains on behalf of a covered entity, including terminating access privileges of the covered entity, the business associate has engaged in an act that is an impermissible use under the Privacy Rule,” OCR stated.

For example, it would be impermissible for an electronic health record (EHR) developer to activate a “kill switch” embedded in its software that renders the data inaccessible to its provider client in order to resolve a payment dispute. “Similarly, in the event of termination of the agreement by either party, a business associate must return PHI as provided for by the business associate agreement. If a business associate fails to do so, it has impermissibly used PHI,” the OCR guidance stated.

There have been high profile cases of business disputes between EHR vendors and providers in which the vendors have blocked a hospital or clinic’s assess to patient records. As cited in a September 2014 article in the Boston Globe, staff members and clinicians at Full Circle Health Care, a clinic based in Presque Isle, Maine, were locked out of the EHR. As part of a billing dispute, the vendor for the clinic’s electronic health records, German-based company CompuGroup, took steps to block the staff’s ability to look up medical histories on its 4,000 patients.

Additionally, in the guidance, OCR stated that a business associate is required by the HIPAA Security Rule to ensure the confidentiality, integrity, and availability of all electronic PHI (ePHI) that it creates, receives, maintains, or transmits on behalf of a covered entity. Maintaining the availability of the ePHI means ensuring the PHI is accessible and usable upon demand by the healthcare provider, whether the data is maintained in an EHR, cloud, data backup system, database, or other system. “This also includes, in cases where the business associate agreement specifies that PHI is to be returned at termination of the agreement, returning the PHI to the covered entity in a format that is reasonable in light of the agreement to preserve its accessibility and usability. A business associate that terminates access privileges of a covered entity, or otherwise denies a covered entity’s access to the ePHI it holds on behalf of the covered entity, is violating the Security Rule,” OCR stated.

Further, OCR stated that a business associate is required by the HIPAA Privacy Rule and its business associate agreement to make PHI available to its provider client as necessary to satisfy the provider’s obligations, as a covered entity, to provide access to individuals under 45 CFR § 164.524. To that end, a business associate may not deny its provider client access to the PHI the business associate maintains on behalf of the healthcare provider if that provider needs the PHI to satisfy its obligations.

“OCR recognizes, however, that there may be certain arrangements that authorize the business associate to destroy or dispose of PHI, or perform data aggregation or otherwise combine data from multiple sources,” the agency stated. For example, a covered entity may engage a business associate to perform data aggregation of information from multiple sources that renders the disaggregated original source data unreturnable to the covered entity. The agency does not consider these contractual arrangements to constitute impermissible data blocking or access termination, OCR stated.

 

Topics

News

Healthcare Data Breaches: A Year in Review

The latest year-in-review Breach Barometer report from Protenus paints a stark picture—2016 average at least one health data breach per day, affecting more than 27 million patient records.

Healthcare Industry Could Save $9.4B with Full Adoption of Electronic Transactions

The healthcare industry continues to make modest progress toward full adoption of electronic business transactions, but significant gaps remain, representing an opportunity for $9.4 billion in savings, according to new data from the 2016 CAQH Index.

ONC Announces Phase 2 Winners of Consumer, Provider App Challenges

ONC today announced the Phase 2 winners for the Consumer Health Data Aggregator Challenge and the Provider User Experience Challenge.

Health Affairs: ACOs with High Numbers of Minority Patients Struggle in Quality

Accountable care organizations (ACOs) that have a high proportion of minority patients were associated with low scores on about three-fourths of Medicare quality performance measures, according to new research published in Health Affairs.

Trump Taps David Shulkin, an Obama Appointee, for VA Secretary

President-elect Donald Trump announced yesterday that David Shulkin, M.D.—an Obama administration appointee and current VA undersecretary—will lead the Department of Veterans Affairs.

NIST Publishes Draft Update to Cybersecurity Framework

The National Institute of Standards and Technology (NIST) has published proposed updates to the Framework for Improving Critical Infrastructure Cybersecurity—also known as the Cybersecurity Framework.