HIPAA’s Structural Gaps: Why a Portability Statute Became America’s Healthcare Privacy Law, and Why That History Still Matters

Tuesday, June 23, 2026 

Overview

Kirk Nahra of WilmerHale, one of the nation’s leading healthcare privacy attorneys with nearly three decades in the field, explains how the Health Insurance Portability and Accountability Act’s origins as a labor-mobility and administrative-efficiency statute—not a privacy law—created structural coverage gaps that exclude pharmaceutical companies, life insurers, and most consumer health apps, and why the resulting proliferation of overlapping state and federal law now threatens to produce what Nahra calls “growing chaos” that is “bad for both industry and for patients.”

Instructor(s)
Kirk Nahra
, Partner, WilmerHale; Co-Chair AI Practice & Cybersecurity & Privacy Practice

Keywords

Health Insurance Portability and Accountability Act (HIPAA) • HIPAA covered entities and business associates • HIPAA administrative simplification provisions • Washington My Health My Data Act • state consumer health privacy laws • healthcare privacy regulatory framework • HIPAA scope exclusions pharmaceutical industry • group health plan employer firewall HIPAA • who is not covered by HIPAA • why does HIPAA exclude life insurers and drug companies • what companies must comply with HIPAA privacy rule

Key Takeaways

  • HIPAA is not a general health privacy law. Coverage is limited to the three covered-entity categories and their service providers—defined by labor-mobility and electronic-transaction provisions, not by data sensitivity. Nahra emphasized: “HIPAA has never been an overall health information privacy law.”
  • HHS wrote the Privacy Rule from scratch. Because Congress failed to enact substantive privacy legislation within HIPAA’s three-year window, the Privacy Rule is an administrative regulation written by HHS lawyers, constrained only by the statute’s pre-existing coverage definitions.
  • Major healthcare sectors are excluded. Pharmaceutical companies, life insurers, disability and workers’ compensation carriers, and most consumer health and wellness apps fall entirely outside HIPAA’s scope, despite holding extensive personal health information.
  • Employer-plan firewalls are structurally weak. Although the Privacy Rule draws lines between a group health plan and its sponsoring employer, most companies lack the organizational separation to implement those restrictions effectively, generating ongoing compliance risk.
  • State law now dominates the non-HIPAA space. The Washington My Health My Data Act is the leading template for consumer health privacy legislation targeting entities HIPAA does not reach; additional enactments are expected in New York and other states.
  • Twenty-two or more general privacy laws apply. State comprehensive consumer privacy statutes—now enacted in roughly two dozen jurisdictions—include health-data provisions that create parallel obligations for companies both inside and outside the HIPAA framework.
  • Regulatory fragmentation threatens patient care. Nahra predicted that the accumulation of inconsistent, overlapping, and sometimes contradictory laws will increasingly impair healthcare system efficiency, producing outcomes that are “bad for both industry and for patients.”
  • HIPAA misconceptions are pervasive. Common invocations of HIPAA by politicians, coaches, and public health officials are legally unfounded; none of those actors is a covered entity, and understanding who is—and is not—subject to the law is foundational competency for any privacy practitioner.

B-CLE Recording (CLE: $50) | Youtube Recording | Resource(s) | Speaker Bio(s) & Contact Info

Download the interview/transcript and slides here!

Interview/Transcript

This interview/transcript was the first of a three part series on Health Care Privacy 101. On June 23, 2026, Kirk Nahra of WilmerHale details the history of HIPPA, and the acts structural gaps. 

Wayne Stacy  00:30

So welcome everyone to the UC Berkeley Center for Law and Technology’s Expert Series, and today we truly have one of the great experts for you, Kirk Nahra from WilmerHale is joining us. You know, if you’ve been around the privacy and cybersecurity space for long, you, you’ve bumped into Kirk, and if you haven’t, you’ve missed out on one of the great experts in this area. You know, I could, I could read through all of the list of awards that would take our entire time period to make that all happen, but let me give you the highlights. We all know Wilmer, Kirk is the co-chair. I’m looking at the list here, so I get these names right. They’re the artificial intelligence practice, also co-chair of the cybersecurity practice, and co-chair of the privacy practice. The only thing I can find he’s not co-chair of is the patent practice, and I don’t think he wants anything to do with that. So, what you, what you see is this kind of breadth across modern data regulation, modern data handling. Kirk is dealing with it all, and he was nice enough to bring us a topic and donate his time to deal with with an issue that people often see kind of at a high level, but often don’t see enough of the details to know what they should really be concerned about. So we have a multi-part session coming from Kirk on healthcare privacy, looking at the fundamentals and what we’re going to be facing going forward, kind of the must knows if you’re going to be touching any of this kind of data. So, with that in mind, Kirk, I one, I want to thank you for joining us, for donating your time, and two, I want to turn it over to you and get out of your way.

 

Kirk Nahra  02:17

All right. Well, thank you. Thank you very much for having me. Happy to be here today, and as you just heard, what I want to try to cover today is to give you a sense of what I think is one of the most interesting overall topics in privacy law, which is the topic of healthcare privacy. I have been doing this for a long time, I’ve been doing this now for I think 26 or 27 years, and a lot of what we’re going to talk about, particularly today, is an important part of the history of how this law is developed. That law is not just history, it has real implications for how this field works today, but I do find as we’ve gotten further and further away from that initial period of time that the history actually is often not really well understood, and people don’t really have a good sense of why the law is the way it is today. So, what I want to try to do is give you a sense of that. As you heard, we’re going to talk about this in a couple of different sessions, but as I said, I think this this topic is important for a wide range of companies in a lot of different ways. One of my goals today is to teach you who this matters to, where it matters to different companies, why it matters in different ways. These issues obviously are of enormous importance to the overall health care system, one of the reasons that this topic is so important and so interesting is because you have so many critical public policy issues that overlay with the privacy component. I don’t think we ever really think about privacy law in isolation from the rest of what goes on in the world, but nowhere is there more set of overlaps and connections than we have in the healthcare system. So, really interesting set of topics. I also want you to think about these topics as relevant to you personally. Everybody listening to this session has been a patient, will continue to be a patient, your family will be a patient, your kids, your spouse, your parents, your friends, whatever it’s going to be. So these issues come up in so many different ways that are both relevant professionally to lawyers and other privacy professionals, as well as people individually, and that’s just a critical part of the overall topic that we’ll be covering. So today again is a, is the first in our series. We’re going to be doing three different topics that are really even at that level of three sessions, really sort of basic introduction, sort of making sure everyone’s on the same page, understanding the basics. I do want to emphasize how the field impacts lots of different issues. One of the reasons that I think this is, this is one of the most complicated areas of privacy law is the number of interested stakeholders. I always say that if you, you know, there are important privacy issues when somebody goes online and buys a pair of jeans from a blue jean store on the internet, but if you step back, I care about the data for when I buy a pair of jeans. The company that’s selling me the pair of jeans cares about it. No one else really cares that much about all the data, but in the healthcare space, it’s a fundamentally different system. We have obviously the interest of individuals. Those individuals can be just taxpayers and others. They can be patients. People might be patients today. They obviously use the healthcare system in the normal course of events. No one knows for sure today whether they will be a much more significant patient at some point in the future, most of us, for better or for worse, will be a patient more significantly as we get older. We also have the impact and the interests of government in this space. The in the United States, in particular, the government is the largest health care provider. The government is the largest health care payer. In addition to the typical government function of being the regulator of the space, we also have the interests of employers. Employers still, for the most part, pay for most of the health insurance coverage across the United States.

 

Kirk Nahra  06:36

That may or may not be changing in the future, but employers care a lot about this. Employers don’t care at all what you buy on the internet for your wardrobe, so we have to take into account the interests of employers. That also means that employees have some interest in data and healthcare about their fellow employees, because their costs may impact what the other employees pay for health care. Then we have things like taxpayers, where an enormous percentage of government expenditures at both state and federal level go to healthcare costs, and so taxpayers care a lot about what happens in the healthcare system, and then society at large. None of us know today whether we will benefit 25 years in the future from medical research that’s going on today, and so we have to think about this issue across the board in our society, which again makes it certainly unusual, perhaps unique in the overall consideration of privacy issues, particularly as they overlap with a wider range of public policy issues. If you are thinking about the healthcare system, if you come at these issues from an interest in healthcare or health law, you have to understand the impact of privacy law on the healthcare system. Every decision we make in the healthcare space is driven by information, that information is mostly about people, and so we have to think very carefully about that. Similarly, if you are interested from the privacy law perspective, I think you have to understand the core elements of how healthcare privacy works, because it is different than the rest of the healthcare space. It is certainly different than what happens in other parts of the world, and so it’s critical to at least understand that connection and have a baseline in overall healthcare issues. If you want to be viewed as somebody who knows about privacy law in general. So to give you a little more background before we launch into some of the particulars about how we got to where we are today in the state of law. This is a combination of law, policy, and technology, and I think it is fair to say that healthcare privacy was one of the driving forces in the development of United States privacy law. I often trace the development of sort of modern US privacy law to very late 90s, really 1999 when the HIPAA rules that we will start to talk about today, as well as the Gramm-Leach-Bliley Act, got introduced at roughly the same time, that was really the first time where law firms and companies, in particular, started to really pay attention to privacy law, particularly if you were in those industries of financial services and healthcare, and the development of the healthcare privacy field is still one of the driving forces of the development of privacy law in the United States. Most of the concept of having a field of healthcare privacy is derived from the idea that healthcare information is somehow different than other information, that information about your cholesterol level, or your heart function, or whether you have diabetes, is different from what kinds of genes you buy on the internet, and the idea that that information, by being different, and perhaps. More sensitive also deserves more protection than other kinds of information. We’re going to test that a little bit over the course of these next couple of sessions. That is an area that is very much, or that is a point that is very much subject to debate today, particularly as the law is changing so aggressively in our, in our current environment. It is fair to say that the law in this area used to be reasonably simple. Simple doesn’t mean easy, but there wasn’t that much law. Now we have anything but simple. We have more and more law, and that’s creating a lot of the confusion and complexity that that both exists in the field generally and that we will be talking about throughout the course of the next couple of sessions. So, now by contrast with that relative simplicity, we have lots of conflicts and lots of confusion and frankly lots of contradictions among different laws and the result of that package of developments for the legal system. This is a personal opinion, to be clear, but I don’t think it’s an, it’s a unique personal opinion, is that we have growing chaos, and what I’ve been calling an overall mess involving health care privacy, and I think what that is leading to is a growing likelihood that the overall body of “law” in this area, I’ve got law in quotes for a number of reasons, we’ll talk about in a second, but the overall body of law in this area, which has a good purpose, it’s designed to protect healthcare privacy, I am concerned that that law is actually going to get in the way of having a working healthcare system, which means it is bad for both industry and for patients. So, that’s going to be an important development. I think it’s important to understand sort of how we got to where we are today, which is really the purpose of these couple of sessions that we’re going to be doing. Now why do I say that the law is a growing mess at this point. First of all, the law is changing constantly. We have the HIPAA rules, which have been in effect since the very late 90s, really, really got finalized in the early 2000s. We have more and more law that has been passed in the last five or 10 years, some of that is being passed in the last year or two, some of that will be passed this year, and there will be more law next year. So, there’s lots of new law covering lots of different components of the healthcare privacy space. What we are seeing is that there are varying standards for different kinds of companies who have the exact same information, but in different contexts. We have more and more laws that are covering the same information, we have a growing confusion about what the idea of health information even means. Again, remember that premise that we’re, we think that healthcare privacy is different because healthcare information is different, but when you have growing confusion about what it means, that makes it hard to write appropriate law at the same time, that means it’s harder to justify why it should be protected more than other data. We are seeing aggressive enforcement at both the state and the federal level. Footnote: some of that was in the last administration more than this administration, but aggressive enforcement without actually having meaningful, clear law. And so what we are seeing is a growing environment with confusion, complications, inconsistencies, tensions, etc. So that’s sort of where we’re going at this point. Let me now think a little bit about HIPAA in general. We’re going to talk about the basis for that. We’re going to talk about how we got to that law, but talk a little bit about sort of what, what HIPAA is, why it exists the way it is, because it is not at all an intuitive privacy law. I think once you understand the history, you will understand why it is the way it is, but I will, will, will say in advance that if your assignment was to sit down and write a healthcare privacy law, you would have never ended up with the HIPAA rules. We ended up with the HIPAA rules because of the history of the law, and that’s really what I want to make sure gets across to folks today, so that you understand that. So we’re going to talk about some of the companies who need to be paying attention to the HIPAA rules. First of all, we’re going to talk about something called covered entities under the HIPAA rules. Those are the types of businesses, very carefully defined types of businesses, but they are the businesses who are directly subject to the HIPAA rules, they obviously have to pay attention to these rules. Then there are service providers to those covered entities. We’ll talk about them as well. They have to pay attention to the HIPAA rules. If you are a service provider to a service provider, you have to pay attention, meaning that these obligations often will follow downstream, at least in a contracting sense. Then virtually any employer that provides health insurance benefits to its employees has at least some implications and obligations under the HIPAA rules. That means that lots of companies who otherwise have nothing to do with the healthcare industry are actually subject to the HIPAA rules to varying degrees, some of which create meaningful compliance obligations, and then pretty much any company who wants to use healthcare information in their business activities, at least has to understand the HIPAA rules, has to think about whether they are impacted, has to think about whether the HIPAA rules will affect what they want to do with the information, how they want to gather it, how they want to use it, etc. So lots of people, lots of companies, lots of types of companies that have to pay attention to the HIPAA rules. So all right, let me go to the history at this point. The HIPAA statute goes back to 1996 It’s the Health Insurance Portability and Accountability Act. I tell my students when I teach this topic, I tell my young associates that the single most important thing I will teach them about this is how to spell HIPAA. It is H I P A A. I tell them to look at the name of the statute and find me a second P. The number of misspellings is astonishing, and I also emphasize for folks that it’s sort of a bellwether of if you send me a marketing communication as a vendor marketing your HIPAA services and you misspell HIPAA, I can guarantee you I will never hire you to utilize those services, but then we get a little more substantive on the spelling, so it’s a Health Insurance Portability and Accountability Act. The P, even the single P in HIPAA, does not stand for privacy, it stands for portability. And when I ask my students what portability means, they always answer the ability to take your data with you from one site to the next, that may be how we think about portability today. That is not what portability means in the HIPAA statute. Instead, portability means the ability to take your health insurance with you when you leave one employer to go to a new employer. Now, let me explain that. Back in the 90s, when this statute was being thought about, we had a situation in our health insurance system where if you wanted to change jobs and you had any kind of pre-existing medical condition, you were not going to be able to get health insurance with your new employer. That’s how the health insurance system worked at that point in time. So that created, in effect, an artificial restriction on the ability of people to change jobs. It became a real impediment to change jobs if you knew you weren’t going to be able to get health insurance at the new job. So Congress focused on that issue, and they created the portability provisions of the HIPAA statute, which were designed in effect to let you keep your health insurance from your current employer, when you went to a new employer, even if you had to pay for it, but you got to continue that health insurance with your old employer, even though you didn’t work there anymore. So it was Congress’s desire to create a solution to that pre-existing medical condition problem. Their solution was to create this idea of portability of health insurance. All fine, we can debate whether it worked, we can debate whether it’s useful, we can debate whether it’s necessary anymore, given the Affordable Care Act. But that’s why this statute existed, and it was a very popular provision, it was that that portion of the statute essentially was passed unanimously in Congress. You think about that idea, it’s a pretty substantive provision that affects health insurance coverage around the country. Pretty amazing that that was passed almost unanimously. I don’t know that Congress today could pass National Pizza Week unanimously, but they passed that portion of the HIPAA statute. So one of the things that Congress often does when they have an idea that everyone likes is they start throwing other stuff into the bill, and so one of the things they threw into the bill, in addition to portability of health insurance, was something called administrative simplification, and again, this will get us to privacy, but it’s part of the history. So, administrative simplification addressed the following issue. This is 1996 It’s the very beginning of the internet era. We are starting to have both the movement of healthcare from being a paper-based system to being a more electronic system, and through the internet, we have the ability to send electronic information more easily. So, Congress looked at the current situation, which essentially meant that, or resulted in every doctor having paper claim forms. They had their own paper claim forms. Every hospital had their own paper claim forms. They would mail those forms into the health insurer, and the health insurer would send them back the health insurer’s own paper form, and that was just a wildly inefficient system, so Congress basically said we’ve got this new internet, we’re moving to electronic, we’ve got computers. What if we came up with a single set of standard computer forms? They call them standard electronic transactions for some of the basic activities of the health care system, think a health insurance claim, and then the payment on that claim by the health insurer. If we came up with a standard format for that, everyone would use the same format, that would be much more efficient and save a lot of money for the healthcare system, it’d be more reliable, it’d be more accurate, etc. A lot of, lot of potential benefits there. Again, we can debate whether it worked or not, but that was the idea, was we were going to have these standard electronic transactions, but so far we haven’t gotten to privacy and security at all. So, what Congress then thought, I realized, you know, the idea of a body of 435 people being, you know, single thought, but the thinking was, all right we’re now creating a system where more and more of this sensitive medical information is going to be electronic. At the push of a button, that information can go to lots of different places. Maybe we should pay attention to privacy and security of that data. So that’s really how they got to privacy and security was, it wasn’t the first thing for the statute, it wasn’t even the second thing, it was a tail on one of the other parts of the bill dealing with administrative simplification, but if you read the HIPAA statute, and I am not encouraging you to do that at this point. If you read the HIPAA statute, there is almost no substantive information about privacy or security obligations. Instead, on privacy, for example, what Congress basically said was we’re going to give ourselves three years to write a privacy law. I then ask my students, when this comes up, what do you think happened in those three years? And maybe not surprisingly, they are often able to guess pretty quickly that absolutely nothing happened. Congress didn’t do anything to fulfill its own obligations to pass a privacy law, but what they wrote into the HIPAA statute was an obligation, if Congress failed to act, they imposed an obligation on the Department of Health and Human Services to write a privacy regulation, and so when we think about HIPAA privacy, what we really mean is a regulation written by lawyers at the Department of Health and Human Services when Congress failed to pass any actual statutory language related to privacy. So it is critical to understand how we got there. HHS essentially sits down with a blank piece of paper to make up privacy rules. The only relevant impact of the statute went to who could be covered by those privacy rules, and so that’s the only thing that was already on the piece of paper was who could be covered by the privacy and security rules, and what’s critical to understand for purposes of figuring out how this all works is that the scope of who could be covered by the privacy and security rules was not determined by who had sensitive medical information, It was determined by what kinds of companies were involved in portability of health insurance and standard electronic transactions. So that’s how we get to the scope of who is included in the HIPAA privacy rule. So it is critical to understand that HIPAA has never been an overall health information privacy law, that’s a result of the statutory history. It applies to certain information held by certain kinds of companies in certain situations. Mainly, what that ends up meaning is it applies to doctors, hospitals, health insurers, and then ultimately is going to apply to their service providers as well, but the other critical point to understand is that again, because the statute didn’t say anything about the substance, statute only said who could be covered by the rules, the rules were written by lawyers and policy makers at HHS, and they were essentially an effort to achieve two policy goals simultaneously. First of all, they wanted to protect and promote privacy and security of health care information, that was a critical goal, but they also had a second goal. Their second goal was to make sure that there was also an effective, efficient healthcare system. So we’re going to see in our next session a number of choices that were made by HHS in writing these rules, where they essentially said we could give you more privacy, but if we gave you more privacy, that would be bad for the healthcare system, and we’re not going to do that. We’re going to give you good privacy, but we want to have both good privacy and an effective, efficient healthcare system. So, we’re going to cover a little bit more of that, but I want to give you that background on how we got there.

 

Kirk Nahra  26:20

Now, let me fit this in the context of what you need to know overall, and how healthcare privacy works today. So, at that point in time, if you learned the HIPAA rules, you knew most of healthcare privacy, that was 90% of what people were thinking about in 1999 when the rules first started getting written, 2000-2001 when they were finalized, 2003 when they went into effect, that was really what you needed to pay attention to. Now you have a lot more other law that you need to be paying attention to. You have state laws that are like HIPAA, they are HIPAA, HIPAA light versions, perhaps. Two biggest examples are California and Texas. Those laws, in my personal opinion, are very confusing. It is very hard to figure out what they are trying to accomplish. It is very hard to make sense of them, but they exist. We are now seeing, as many of you are aware, state overall privacy laws. We’re up to 22 or 23 states at this point. All of those apply to some people in the healthcare industry, healthcare field, some companies that have health care information, and some of those laws have very particular health care requirements. There are state laws in every state about certain sensitive conditions. There are HIV laws, there are mental health laws, there are substance abuse laws. Those laws were passed at particular points in time, in particular relevant eras of history. You know, the HIV laws were not written in 1950 they were not written in 2020 they were written in a very specific window. Many of those laws served a good purpose at the time they were written, but may not make much sense today. We are also seeing a number of what we call non-HIPAA health data laws, or consumer health laws, with the Washington My Health My Data Act being the prototype of that. We’re seeing a number of those laws in other states, likely to see new ones in New York and elsewhere, there are separate principles involving medical research, both in the United States and globally. We have a variety of other federal laws, including the Part Two substance abuse rules and the Americans with Disabilities Act, that are relevant to different components of health care privacy. And then we also have international principles and standards where the law is just fundamentally different than what we have in the United States. So all right, what we have, let’s go back to the basic coverage of the HIPAA rules. The people who are subject to the HIPAA rules fit into three categories, they’re all called covered entities, so that’s a phrase you need to know, but the three categories are what are called health plans. That’s basically the insurance side of the equation, that’s Medicare, that’s Medicaid, that’s Blue Cross Blue Shield, that’s United Healthcare, and Cigna, NETNA, and you know all the other kinds of health insurance companies that exist. They are health care providers, not every healthcare providers. It’s only healthcare providers who submit those standard electronic transactions. So, if you’re a healthcare provider who only works on paper or doesn’t bill insurance, and there certainly are healthcare providers in that category, you’re actually not subject to the HIPAA rules, but generally, it’s going to be doctors, hospitals, pharmacies, and then we have something called clearing houses, which are essentially sort of middlemen in the communication of information from a healthcare provider to a health insurer and backwards. They are, they are important to the healthcare industry, they’re not all that important in the discussion of privacy, just. Because they don’t, there aren’t that many of them, and they don’t come up that often. We’re also going to talk in our next session about service providers, which are business associates. They are not quite covered entities, they’re not called covered entities, but they will ultimately be subject to the HIPAA privacy rules at all. So that’s who is covered by HIPAA. It’s also equally important to understand who’s not covered by HIPAA, so there are lots of people that have lots of health information that are not covered by the HIPAA rules. If you are certain lines of insurance that are not health insurance, you’re not covered. So, life insurance. Any of you who have applied for life insurance, your life insurer has as much health care information about you as anybody does. They may have more information about you, because they get it from so many different sources, but because you don’t take your life insurance with you from one employer to the next, life insurance is not covered by the HIPAA rules. Same with disability workers’ compensation, automobile insurance, which provides some healthcare benefits if you’re in an automobile accident. None of those lines of insurance are subject to the HIPAA rules. All of those lines of insurance have lots of healthcare information, so that’s just one area where that history excludes from the HIPAA rules lots of companies that have healthcare information. The entire pharmaceutical industry, they make pills, they’re critical to the healthcare industry, but they are not subject to the HIPAA rules. They themselves are not a health insurer, they themselves are not a healthcare provider, they themselves are not a clearing house, they themselves are not working on behalf of any of those entities. So they are not subject to the rules. Back in 1999 they probably didn’t have a lot of information about people, but now every, you know, you see advertising on social media, on television, on sort of every channel, they’re always collecting information. The messages say, if you, you know, if you have questions about your prescription, or you can’t afford your prescription, whatever, contact us at this website, call us here, whatever. So they have lots of information, not subject to the HIPAA rules at all. That is true generally for the life sciences industry overall, not covered by the HIPAA rules. Employers in general, we’ll come back to that complexity in a minute, but employers have lots of information about their employees, they have, you know, Family Medical Leave Act, they have disability claims, they have workers comp claims, they have a doctor’s note for why somebody missed work, they know that somebody’s out on leave because they got diagnosed with something, said not covered by the HIPAA rules. Most direct to consumer apps not covered by the HIPAA rules. You buy your Apple Watch, you go down the Apple, you go to the app store and download something not covered by the HIPAA rules. And then most technology companies in most settings. Now, I do want to raise just quickly, we won’t get too far into this, because a pretty complicated area. I do want to talk about one quirk about employers, which is the employer isn’t covered by the HIPAA rules, but the health plan that offers the insurance to employees is in fact covered by the health by the HIPAA rule. So, under the statute, the HHS could apply the rules to something called a group health plan, which is what you have if you’re an employee who gets health care benefits, but they couldn’t cover the employer directly because they didn’t fit the scope of the rules. The concern that they had, and they were trying to write rules to deal with, was that if your employer knew that you or your spouse or your child had an expensive illness, they might try to fire you. They want to make sure that didn’t happen, so that the rules essentially draw lines between the group health plan and the employer, and the idea is to prohibit information from going or make it difficult for information to go from the group health plan to the employer, but if you go back to your company and your company is just a random company in a random industry, they probably have very little in place to draw a line between the health plan, which is basically a benefits contract, and the employer itself. So that’s an area of a lot of complexity, just the result again of the HIPAA rules.

 

Kirk Nahra  34:25

So, a couple things just to close out this session, that means, and I want people to understand this very clearly. There are lots of situations where there is health information in the hands of a commercial entity, or just an entity of any kind that is not covered by the HIPAA rules, because there is no one who’s defined by the law as a covered entity. Couple examples I use: if a reporter asks a congresswoman whether she’s had a COVID vaccination, and the congresswoman says, I can’t answer that because of HIPAA, they are wrong. There are no HIPAA implications to that question. If a football coach is asked about the status of an injured quarterback, again, no HIPAA implications. A football coach is not a covered entity under the HIPAA rules. ESPN publishes a scoop about a player injury, again no implications under HIPAA. If a local government sends people door to door to encourage COVID vaccines, no HIPAA implications, because the local government, who’s sending college students out to encourage vaccinations, is not a healthcare provider, they’re not a health insurer, they’re not a clearing house. So, with that, we are finished with session one. I hope you’ve gotten sort of a basic background of why we got to where the HIPAA rules are, what it applies to, what it doesn’t apply to. Again, you would not have sat down to write a healthcare privacy law and written a law that excluded pharmaceutical companies and life insurers and the Apple Watch and all the healthcare mobile apps, but that’s a result of the HIPAA statute, and it’s critical to understand that we’re going to send in session two, we’ll talk about some of the key principles of the HIPAA rules, and then we’ll talk in session three a little bit about sort of the rest of the law and how this all fits together. So, thank you very much.

 

Kirk Nahra  36:21

Kirk. Thank you very much, and I look forward to the next session.

This transcript was created with an automated transcription service and reviewed by a human