Wednesday, June 24, 2026
Overview
Kirk Nahra of WilmerHale’s second session on healthcare privacy law dissects the HIPAA Privacy Rule’s core operational framework—the definition of protected health information, the three-category permitted-use structure, and the business associate regime—explaining why HHS deliberately chose weaker individual consent rights to preserve a functioning healthcare system, and why that trade-off continues to define the law’s limits today.
Instructor(s)
Kirk Nahra, Partner, WilmerHale; Co-Chair AI Practice & Cybersecurity & Privacy Practice
Keywords
protected health information (PHI) definition HIPAA • HIPAA treatment payment healthcare operations • HIPAA business associate agreement • HIPAA individual authorization requirements • HIPAA de-identification standard re-identification risk • HIPAA national priority purposes disclosures • Northwestern Memorial Hospital v. Ashcroft privacy interest de-identified data • HIPAA individual rights access amendment • FERPA HIPAA overlap student health records • what is protected health information under HIPAA • when does HIPAA require patient authorization for disclosure • can a hospital share records without patient consent HIPAA
Key Takeaways
- PHI scope is broader than expected. Any personally identifying information a covered entity holds about a person because they are a patient or insured qualifies as PHI—including enrollment data with no clinical content. Nahra’s rule: “any personally identifying information you have about a person because they are your patient or your insured is protected health information.”
- No patient consent required for TPO. HHS deliberately eliminated the patient consent requirement for treatment, payment, and healthcare operations activities, concluding that genuine consent rights in those contexts would functionally paralyze the healthcare system.
- Authorization is required for unusual uses. Any disclosure outside TPO and the national priority purposes—such as marketing a patient’s recovery story or releasing records to a prospective employer—requires a specific, signed, informed authorization that the covered entity cannot coerce.
- De-identification extinguishes HIPAA protection. Once data meets the low-risk-of-re-identification standard, the HIPAA rules no longer apply and the patient is deemed to retain no privacy interest in it—a conclusion the Seventh Circuit rejected in the partial-birth-abortion subpoena litigation on broader constitutional-privacy grounds.
- Business associates are now directly regulated. Since the HITECH Act and 2013 regulations, business associates face both contractual BAA obligations and direct government enforcement—a major expansion from the purely contractual model of the rule’s first decade.
- Hosting encrypted data still creates BA status. A cloud-storage firm that cannot access the patient records it hosts is nonetheless a business associate because the service involves PHI; encryption reduces compliance burden but does not eliminate the relationship.
- FERPA-HIPAA gap harms assault survivors. Student health clinic records are governed by FERPA, not HIPAA, enabling universities to access those records in litigation—a protection that disappears if the student sought care at an off-campus hospital instead.
- Individual rights are structurally underutilized. Rights such as confidential communications for abuse victims nominally exist under HIPAA but remain largely unknown to the populations who need them most, limiting their practical protective value.
B-CLE Recording (CLE: $50) | Youtube Recording | Resource(s) | Speaker Bio(s) & Contact Info
Download the interview/transcript and slides here!
Interview/Transcript
This interview/transcript was the second of a three part series on Health Care Privacy 101. On June 24, 2026, Kirk Nahra of WilmerHale dissected HIPPA and what qualifies as protected health information.
Wayne Stacy 00:30
So welcome everyone to the UC Berkeley Center for Law and Technology’s Expert Series. We have a session two for you today. Kirk Nahra from WilmerHale is joining us again. If you haven’t seen session one, I got to recommend you go back and watch session one. It is a really enlightening history of HIPAA and how we got here, as Kirk says, not something you’d set out to design, but this is where we are, so it’s great to know how we got here. So, again, session one, you can find that here in the files for UC Berkeley. But now we want to go to session two and talk about what’s coming. So, with that quick introduction, for those of you that didn’t see session one, Kirk is the co-chair of the artificial intelligence practice, co-chair of the cybersecurity practice, and co-chair of the privacy practice at WilmerHale. Put all that together, that indicates he’s really, really good at what he does, and incredibly knowledgeable over a 25-26 year practice in this area. So with that, Kirk, I will let you start with session two and get out of your way.
Kirk Nahra 01:47
Great, thank you. Thank you very much. And, as always, happy to be here. So, what we’re going to do today, just to continue the series, the first session, we, we talked a lot about why HIPAA is the way it is. It’s the result of a statute, the Health Insurance Portability and Accountability Act, that focused on portability of health insurance, then moved on to standard electronic transactions, and only at the end of that thinking got to barely mentioning privacy and security, but again, the impact of the statute was on who could be subject to the HIPAA rule. So we learned about why HIPAA is the way it is. Very different than law in every other country, certainly, and results in HIPAA not being a comprehensive overall healthcare privacy rule, but a healthcare privacy rule, very important one, but health care privacy rule that applies in certain situations to certain kinds of entities for certain kinds of information. So, what we’re going to do today is actually talk about the substance of HIPAA. We talked about who is covered by it, but we’re going to talk a little bit more about the substance of HIPAA, and in particular some of the key decisions that were made, some of the key choices that were made by the regulators, the lawyers at HHS, who were drafting these rules. So, when I think about privacy laws in general, I always want my students to answer a few questions. Well, first question, which we covered in last session for HIPAA, was, Who is subject to the rules? Then we have who’s protected by the rules, and once you know who’s protected by the rules, you think about what information about those people is protected by the rules. You can use that framework for any, any privacy law that you have.
Kirk Nahra 01:50
There is, you know, then then there’s a fourth category we’ll get to, which is like once you know who’s protected and who’s covered, what are you allowed to do with that information. There is, of course, no law that says you have information you can’t do anything with it. So every law, every privacy law says you can do x but not do y. So, in connection with the HIPAA rules, let’s focus on what the information is that’s protected by the privacy rule. The phrase we’re going to use, the key reference in the rules, is called protected health information. Acronym is PHI. I told you in the first session that if my students misspell HIPAA, I will fail them. They might get PHI wrong, they might say personal health information, that’s not right, but it’s not terribly wrong. The phrase, however, is protected health information. Alright, so let’s move on from that starting point now. I also mentioned in the first session that one of the justifications for even having a field of healthcare privacy law is the idea that there’s something different about health information, but let’s explore that a little bit, because I think it’s a little hard to justify in certain situations. So, for example, we would probably all agree, somebody has a different perspective. I’m always happy to hear it, but we would generally agree that information about your HIV status, your mental health status, your substance abuse information would be sensitive information deserving of appropriate significant protections. That’s fine. However, as we were going to learn in a minute, I want you to understand that if a hospital has your name and address because you are a patient, your name and address also is protected under the HIPAA rules and gets basically the exact same protection that your HIV, mental health, or substance abuse information does. That doesn’t mean that your name and address, when the bank has it, or the grocery store has it, or the library has it, is health information, but it does mean that it’s protected health information, subject to HIPAA rules and HIPAA protections. Alright, so that’s the starting point. Then think about some information that is clearly health information, but might be less sensitive. I always use the example of foot surgery records. I play a lot of tennis. Let’s say one day I twist my ankle and I need surgery on my ankle. I care about that data. My doctor cares about that data. Very few other people care about Kirk Nahra’s ankle injury. However, if Lebron James has exactly the same ankle injury, and he will never play in the NBA again after that ankle injury, everybody cares about that, but they don’t care about it because it’s ankle injury, they care about it because it’s Lebron James information. So sensitivity might be specific to the person rather than the information, and so that is certainly a challenging component of what makes something health information. We have to factor that in.
Kirk Nahra 06:10
So, putting aside that broader question, let’s talk about how the HIPAA rules, in particular, deal with this information. It’s actually a little tricky to get to the right definitions. We have to go through a number of sort of cross references, but the way it works is essentially as follows. It has to be individually identifiable health information, that means it has to be about a specific known person, and it has to be. A subset of health information, which has its own definition, but it includes information that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, so let’s think about particularly that last piece. When you have your first day at your new job, you fill out a bunch of forms with your employer. One of those firms, one of those forms is going to be signing up for the health insurance program. In that form, you’re going to write down your name, your address, your email, your phone number. If you have to pay for some portion of it, maybe it’s got financial information, it’s going to list your dependents, but that’s all it’s going to have. That information clearly relates to the past, present, or future payment for the provision of health care. That’s how you get signed up for your health insurance, and so that information, none of which is obviously about your health is legally defined by the HIPAA rules as protected health information fully subject to the protections of the HIPAA rules. So my rule, when I’m giving advice to clients on this, is that if you are subject to the HIPAA rules, your healthcare provider or health insurer, for example, any personally identifying information you have about a person because they are your patient or your insured is protected health information subject to the HIPAA rules. So very broad scope, as long as you’re one of the people who is protected by the HIPAA rules.
Kirk Nahra 06:10
Now there are a couple of exclusions in that. For example, it is excluded if you have information in what are called education records covered by the Family Educational Rights and Privacy Act, that is the FERPA law that applies to colleges, universities, some high schools. They give you an example of where that creates some tensions if you are a student at a college, and you go to the student health clinic, and they prescribe you aspirin, or they give you a flu shot, that information is subject to the FERPA law, not the HIPAA rules. If you go across the street to the hospital, and you get the exact same flu shot, the hospitals covered by HIPAA, because it’s not part of the educational environment. Where that gets tricky is things like sexual assaults. There’s a number of cases that have been brought against universities, in particular, addressing their response to sexual assaults, and the universities in defending those litigation matters went to the local, I mean, went to the school health clinics and were able to get information about reports of sexual assaults. They were able to get that information because those are university educational records, not HIPAA records. If the impacted student had gone across the street to the hospital and reported it at the hospital. The university would have had no way to get access to that information. So, the fact that student health clinic information is not covered by HIPAA creates a disparity in the protections that are available to a student when they report a sexual assault. To be fair, virtually no student understands that. So, that’s a challenge with that. We also have an exclusion for employment records held by a covered entity as role as an employer, that’s the line between the group health plan and employment records. Your Family Medical Leave Act, your disability claim, your workers comp claim, your excuse for missing work for a doctor’s appointment, all of that is employment records not covered by the HIPAA rule, so that’s the information that’s covered by the rules. Then we get to what I always think is the most interesting part of any privacy law, which is what you can and cannot do with the information. Again, you can look at that point for any privacy law that exists, the HIPAA example is a particularly interesting one, and a particularly important one. This is probably the single most important policy decision that was made in the drafting of the HIPAA rules. The premise that the drafters of the rule went in with was they wanted to make it relatively easy to use and disclose information for normal important healthcare purposes and harder for everything else, so we’re going to talk about what that means, but that’s the premise of the rules. Now, as we go through this, I do want those of you who are involved in any kind of broader privacy discussions, I do want you to think about whether the HIPAA model could actually be a useful model as part of the national privacy law, because it’s going to define certain disclosures that are automatic and certain that require additional permission. That might be a worthwhile model to think about in the context of broader privacy issues. So, in writing the HIPAA rules, there are three ways that you are allowed by the law to use and disclose protected health information. There’s three categories. First of all, we have what’s called individual consent.However, the individual consent under the HIPAA rules is presumed by the law, meaning it’s automatic. The idea for that was to take normal health care activities and make those uses and disclosures automatic with assumed or presumed individual consent. The three words that we call use are treatment, payment, and health care operations. Those are what HHS defined to be the sort of normal, common, typical things that happen in the healthcare industry. Treatment is pretty straightforward. Every patient expects to have their information used for treatment purposes. Every patient expects to have their information used to have payment for those healthcare services. Healthcare operations is a little more complicated. It’s essentially the administrative activities of running a healthcare business. You need an accounting department, you need a law department, you need a technology department, you need a quality control department. This allows those departments to operate without the need for patients to give permission, because that permission is automatic. But the idea is we’re going to take the normal stuff and make it easy to do through automatic presumed consent. Then there’s a second category that we called national priority purposes, which is basically specific public policy exceptions, or examples may be better than exceptions, where excuse me, the drafters of the rule said we need to allow use of disclosure of information for these national priority purposes, essentially independent of patient permission. Easiest example of that, it’s just one of the examples is patient is in the hospitals diagnosed with Ebola. Public policy wants that Ebola patient to be disclosed to the public health authorities. It would be really odd if you had to go to that patient and say, hey, is it okay if we disclose to the public health authorities that you have Ebola, because if you have to ask them, they might say no. So, the HIPAA rules say you don’t need permission, you can just disclose information to public health authorities. There are provisions dealing with oversight, regulatory activities. There’s a litigation provision. There’s a bunch of specific little mini privacy rules that are designed around particular public policy purposes, where HHS, in drafting the rules, basically said if you follow these little mini rules, you don’t need any permission, and permission is largely irrelevant. So those are the first two categories. Then there’s a third category, which is called individual authorization, and this is basically a situation where there’s an unusual activity or an uncommon activity. We’ll talk about some examples in a few minutes, but the idea is something that’s out of the norm. If you want to do something that’s out of the norm, with the norm being treatment, payment, and healthcare operations. If you want to do something that’s out of the norm, you need specific patient permission for that. We’ll talk about what’s involved in that. We’ll talk about some examples in a minute, but those are the three categories. If it doesn’t fit one of those three categories, you are not allowed to use and disclose information that would be unlawful under the HIPAA rules. So let’s explain all this a little bit more. The purpose of these categories was to balance appropriate privacy protection with the efficient and effective operation of healthcare system. We wanted to protect privacy, but also have a working healthcare system. There was a recognition that if you gave consumers more or better privacy protection, that would be bad for the health care system, which means bad for patients. Let me walk you through some examples of that, just to think about. In the original draft of the HIPAA rules, patients needed to give their permission for those normal treatment payment healthcare operations purposes. Under that rule as drafted, not what the final rule says, as drafted, if a patient went into the doctor, the doctor would have to say, “Hi, patient, happy to have you here. I need your permission to use and disclose your information for treatment payment healthcare operations. Patients says I do not give you my consent. All the doctor could do at that point is to say, thank you for coming in, I can’t help you. Because if you don’t have permission to use their information for treatment, payment, health, derivation, you can’t do anything. So they said, we’re not going to, we’re not going to go through that choice, we’re just going to make it automatic. Now, there was an intermediate option, you could have said, all right, patient. Here’s the stuff we need to do. Here’s a list of every treatment purpose, every payment purpose, and all kinds of healthcare operations things we do, like quality control and training and payment and accounting, and all this stuff. You start checking boxes. Tell me, which of these things it’s okay for me to do. Now think about that. That would create chaos in the healthcare system. I don’t know what a patient would do when they’re given a list of 1,000 things the hospital needs to do with their data. They might check all the boxes, they might check none of the boxes. The worst thing would be if they started checking individual boxes, they would have no idea what to check, and patient one would check different things than patient two and different three. So, HHS basically said, “We’re not going to give them that option, that would be terrible for the health care system. And so, we’re going to say we’re not going to do that. We’re just not going to do that. We’re going to make a choice that says we’re going to protect your privacy. We’re going to have rules to protect your privacy, even in these normal situations. We’re just going to not go through this consent charade. We’re not going to do that, and we’re not going to give you better consent rights, more control, because if we gave you more control, that would be worse for the overall health care system, and that also means bad for patients. So, again, that was their public policy decision. You could debate that, you could take a different position, but again, I asked my students, if you want to take a different position, you have to explain to me what it’s going to be, and you have to explain to me what the effects will be on the healthcare system. This was HHS way to balance the two goals of having good privacy protection with a good working healthcare system, that was the best way they thought they could do it.
Kirk Nahra 06:40
Then think about some other things that are less specific, but also might be health information. Many of you have search history available on your laptop computers. If you don’t know to delete that, you’ve got lots of stuff on your on your laptop. If I see in your search industry search history, I see a search about how do I know when my cholesterol is too high. How am I.. how do you know if someone’s got diabetes? What are the risk factors for a COVID infection? Things like that. Is that health information about the person whose computer it is? Might be, might not be. They might be writing a paper, they might be curious about their friend, they might be wondering about all kinds of things, but it could be health information about a particular person. We just don’t know, and we have to factor that in. Then we’re starting to think about things like location information. There are a number of recent laws. We’ll talk about these in session three a little bit. There are a number of recent laws that some of which are offshoots of the Supreme Court decision in the Dobbs case involving reproductive rights information. There are a number of laws that protect location information as health information. One of those laws in the state of Washington protects information if you are, if your location is within 17 150 feet of a medical facility. Now I always say that I am doing this presentation from my office in Washington, DC. When I am sitting here talking to you, and I’m doing this presentation, and the rest of the day I’m reading my emails, and I’m doing my other Zoom calls. If that law were in effect in Washington, DC, rather in Washington state, my location information right this second would be legally defined as health care information, because the George Washington University Hospital is next door to my office building. Now, that obviously makes no sense for me, but that’s what the law says is healthcare information, because it’s defined within a radius of a healthcare facility, then we have lots of other information, like voting records, purchasing habits, television watching patterns, where healthcare providers, healthcare researchers, other people in the healthcare industry use that information to evaluate certain kinds of healthcare issues. So, as you think about those, it starts to get very difficult to pin down what exactly health information is and why it is sensitive. I said in session one that the law is becoming increasingly chaotic. One of the reasons is that there is more and more law defining a wider range of information as health information, and therefore making it sensitive information, but when you start to include things like location information, it starts to get much harder to explain and justify.
Kirk Nahra 09:33
Now, I do want to give you some other examples, just to think about how that work this works. There’s a similar approach in HIPAA to something called de-identification, which is the steps that you have to go through to remove the identifiers from certain patient information, such that it’s no longer connected to an identifiable patient. Basically, what HHS said is, look, we think there’s a lot of valuable uses for the healthcare system with this de-identified data. It’s good for public health, it’s good for research, there’s lots of other purposes for it. We’re going to create a standard that says it’s properly de-identified if there is a low risk of re-identification, but they were very explicit in saying if we went further than that, we made it more aggressive, and he said you have to have zero risk rather than low risk, they said what that would mean is it would create incremental additional protections for the consumers, but it would mean that nobody could actually use that information, because that’s far too aggressive a standard, and so we’re not going to do that. We’re going to make a choice that says good privacy protections while still having a working, efficient healthcare system, but what that means is that when your data has been de-identified, the choice they made was when your data has been de-identified consistent with the standard. The HIPAA rules no longer apply to that information. The decision was you, as a consumer, no longer have any relevant privacy interest in that data. Now I want to give you an example. There’s a little bit academic, but I think it’s a real-world example that you should be able to think about. There were a number of court cases in the very early 2000s where that was during the Bush administration. There was a federal law that regulated something called partial birth abortions, and there was a constitutional challenge to that law, and the Department of Justice, under Attorney General Ashcroft, was defending the constitutionality of that restriction on partial birth abortions. In the course of subpoena, in the course of defending that statute, they subpoenaed medical records from the teaching hospitals, Northwestern Memorial, being one of them, who were performing this sort of new experimental treatment. The Department of Justice in those subpoena said, “We don’t want to know who these people are. We don’t care who they are. We don’t need any information. We want, we don’t want any information about the identifiable patients. We just need to know how this, you know, this treatment procedure works. The hospitals all challenge the subpoenas. In the course of quashing the subpoenas, the Seventh Circuit made the following statement: even if there were no possibility that a patient’s identity might be learned from redacted medical record, there would be an invasion of privacy. No possibility. so that’s much more aggressive than the HIPAA de-identification standard. It also takes a fundamentally different approach. It says you still have a privacy interest in this information, even if nobody can tell who you are. So I want you to think about that, as you know, one of the, one of the challenges in healthcare privacy right now is, how do we fix the problems, but that kind of an approach that says you have an interest in your information, even if nobody knows that it’s about you, which we can understand in the context of an abortion case. It’s a little, you know, if this case had been about an experimental foot surgery, I’m not sure would have come out the same way, but really does sort of challenge what is healthcare privacy, what is privacy, what are our interests. Want you to think about that a little bit now. Moving from that academic to the more practical. I mentioned that one of the categories for permitted uses is something called authorizations. This is again real permission for specific things that are not typical or normal, and it requires real permission from the consumer. They don’t use the word informed consent, but it is basically an informed permission. Let me give you two examples, just to give you a sense of where this might come up. You have a rare disease, hospital treats you, hospital cures you of the rare disease. Hospital comes to you and says, we would like to tell your story on our website. We think there are other patients who have this condition, they would be inspired, they would learn there’s treatment possibilities. We want to tell your story, not going to lie, it’s good for the hospital too, but we want your permission. They can’t make you sign that they can’t threaten to withhold treatment. It’s just a pure choice for you. If you are willing to have your story told on their website, that’s obviously not a normal or common thing. If you are willing to have your story told on their website, you would sign an authorization permitting them to use and disclose your information for that particular purpose. That’s an example of an authorization. Another example: star athlete, you’re a basketball player in college, you’re about to be drafted number one in the WNBA. The team that’s about to draft you says, “Hey, we’re about to draft you number one, but we want to make sure that that ankle injury you had last year is properly cured. We need to see your medical records. You, as the star athlete, would go to your doctor and give that doctor authorization to disclose your medical records to the basketball team. If the basketball team called the doctor directly and said, ‘Hey, we want to see your records, the doctor would say, ‘Go away, I don’t have any permission to disclose it to you. But the athlete can say, ‘Look, I know it’s not normal, but I want you, I authorize you, doctor, to disclose that information to the basketball team, so that’s again one of the ways you can disclose information. It’s a permitted way to do it, but it’s very particular, very specific authorization permission from a patient.
Kirk Nahra 22:56
All right, let’s go to some of the other key concepts of the HIPAA rules. Remember, there’s HHS, we talked about in the first session, was sitting down to write these rules under a basically a blank slate, and they realized, you know, because they had limited authority on what they were able to, who they were able to apply the laws to, they recognized very quickly that hospitals and health insurers in particular use lots of vendors, and they realized very quickly that they had no authority, so they had to figure out what to do, so they made up the concept of what’s called a business associate. A business associate is essentially a service provider to a HIPAA-covered entity, service provider to a hospital, to a health insurer, where the service involves some kind of protected health information, and these are activities where the business associate is acting on behalf of the covered entity, so they had to figure out what their options were, and as I think about it, you know, I was not in that room, but as I think about it, they had sort of three choices. They could have said, “Well, Congress didn’t give us any authority over these service providers, patients are out of luck when data goes to them, we’re just going to give up,” or they could have said “we’re going to prohibit using service providers.” That’s really a tough thing to do, to say we got to change the whole business model, the entire healthcare industry. So, instead, they were very thoughtful, and they said, all right, look, we can’t regulate the vendor, the service provider, but we can regulate the hospital that wants to hire them, so what we’re going to do is we’re going to say the hospital, if you want to hire one of these vendors, you need to impose by contract on those vendors very specific contractual provisions that apply privacy and security controls to the vendor. So they made up this category of what are called business associates, and they made up something called a business associate agreement, where the regulation spells out what needs to be in that contract between a covered entity and its service providers, that was the best way that they could figure out to protect your privacy when the data moved from a hospital to the hospital’s vendor, but it was contractual. So, originally, for the first 10 years of the HIPAA rules, the obligations on business associates were only contractual. Then, in 2009 followed by regulations in 2013 Congress changed the scope of the law, so that business associates are now subject to the law directly. That means they have both contractual obligations, and they could be subject to government enforcement. That business associates have to follow the full security rule, they have to have lots of privacy requirements, but that again, it was a way for HHS to address the fact that HIPAA is not a general overall healthcare privacy rule, but in fact a privacy rule for certain kinds of entities, and those certain kinds of entities did not originally include business associates. So let’s spend a minute just thinking about these business associates and who they are. So hospital hires a data analytics firm to go look at medical records from the emergency room to make recommendations on how they could operate their emergency room more efficiently. That company is clearly a business associate, they’re acting on behalf of a hospital, they have patient information. In order to do that, prototype business associate, they would have to sign one of these contracts, etc. What about the company that provides toilet paper for the hospital? They’re clearly hired by the hospital to provide toilet paper, however, individual patient doesn’t have a toilet paper roll with their name on it, they just provide toilet paper, so they’re a supplier, they’re a vendor, but they’re not a business associate, because their service does not involve protected health information. Those first two are pretty straightforward. Then we get to a more complicated example, a cloud storage firm that only stores encrypted patient data. Now, that’s a little more complicated. It requires a little more thinking, but I would look at that and say, well, the cloud storage firm is a vendor. The service they are providing involves protected health information. They’re hosting all these patient records. The fact that they can’t access those records does not exempt them from being a business associate. It may mean they don’t have that much stuff to do to comply. I mean, for example, they don’t have to worry about authorizations, and is it treatment, payment, healthcare operations, or is it an Ebola? They’re not doing anything with the data, but they do have to protect it. They do have to hold it. So they are a business associate, that’s a little more complicated. Some of those discussions are interesting, but again, if you’re a lawyer in this space, your client could be the hospital health insurer, or it could be the business associate, and frankly, every hospital health insurer might have 3000 or 5000 business associates, meaning there’s a lot more clients who are business associates than there are clients who are hospitals.
Kirk Nahra 23:19
All right, last but not least, on the core provisions of the HIPAA rules, is I want you to think about and be aware of the individual rights provisions of the HIPAA rules. Again, almost every privacy rule creates some kind of individual rights for consumers. Here are some of the rights. We’re not going to go into a lot of detail about. You have a right to get an individual HIPAA privacy notice. You should all take a minute and think about whether you have seen a HIPAA privacy notice, where you have seen it, think about whether you read it, think about whether you signed it, if you signed it, think about what you are signing. You might be surprised at the answer to that. If you think about it. You have a right to what’s called access. You have a right to get a copy of your medical records, particularly important if you’re a student, you’re a young person who’s about to move to a different city, you know, I had to exercise my access right recently because my doctor retired and I needed to get a copy of my radical records to take to my new doctor. You have a right to get access to that. You have a right to what’s called amendment. If there’s a mistake in your records, you have a right to fix it. You have a right to a list of certain disclosures of your information, in some situations, you have the right to request that the hospital or health insurer do less with your information than they are permitted to do so. There are some complicated examples there. It’s not a right that gets exercised very often, particularly the confidential communications right is something that might come up, for example, if there’s an abused spouse who is covered by the other spouse’s health insurance information, it’s a right that exists, but it’s a right that you look at the situation and say, yeah, I bet the per the abused spouse has no idea this right exists. So these HIPAA individual rights exist, but often not well utilized, maybe doesn’t make them different from privacy rights in other areas. So, with that, we are going to wrap up session two on the key provisions of the HIPAA rules. We will turn next to session three, which is to talk a little bit about what else is going on in the healthcare space outside of the HIPAA rules, and to give you a little more understanding of sort of where a lot of the complexity is in the law today. So, thank you very much.
Wayne Stacy 36:12
Kirk thank you. I appreciate you recording another session with us, and I look forward to session three.
This transcript was created with an automated transcription service and reviewed by a human