Publication

Compliance Deadline Approaching for New HIPAA Privacy Rule on Reproductive Health Care

October 23, 2024
Medical equipment in a doctors office

On April 22, 2024, the Department of Health and Human Services (HHS) issued a final rule limiting the use and disclosure of an individual’s protected health information (PHI) related to reproductive health care. The final rule modifies the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and establishes a new attestation requirement for disclosures involving reproductive health care. HIPAA covered entities and business associates are required to be in compliance with this new requirement by December 23, 2024.

BACKGROUND

In the wake of the Supreme Court decision in Dobbs v. Jackson Women’s Health Organization overturning a precedent that protected the constitutional right to an abortion, there has been a significant rise in state laws restricting abortions, several of which impose civil or criminal liability on individuals for seeking, obtaining, providing, or facilitating an abortion outside of the parameters of the state’s restrictions. There is a concern that these state laws increase the likelihood that an individual’s PHI may be disclosed in ways that undermine the purpose of HIPAA, namely, that disclosures made pursuant to these laws may erode the trust that individuals have in their health care providers and health care systems.

To address these concerns, HHS amended the Privacy Rule to limit the circumstances in which the use or disclosure of an individual’s PHI about reproductive health care is permitted to be made for certain non-health care purposes. Specifically, the final rule prohibits a covered entity or business associate from using or disclosing PHI for any of the following purposes:

  • To conduct a criminal, civil, or administrative investigation into any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care that is lawful under the circumstances in which it is provided;
  • To impose criminal, civil, or administrative liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care that is lawful under the circumstances in which it is provided; or
  • To identify any individual, health care provider, or other person for any purpose described above.

These are referred to as “prohibited purposes.” The final rule defines PHI related to reproductive health care broadly and overrules state laws that mandate the use or disclosure of such PHI for a prohibited purpose.

NEW ATTESTATION REQUIREMENT

The final rule imposes a new requirement under which, in certain circumstances, before disclosing PHI, covered entities and business associates must first obtain an attestation that a requested use or disclosure of the PHI is not for a prohibited purpose. HHS has provided a model attestation that covered entities and business associates can use to satisfy this requirement. An attestation is required for all requests for PHI potentially related to reproductive health care for:

  • health care oversight activities;
  • judicial or administrative proceedings;
  • law enforcement purposes; and/or
  • disclosures to coroners and medical examiners.

The requestor must attest that the requested disclosure is not for a prohibited purpose, and the attestation must include a notice of criminal penalties for persons who knowingly obtain or disclose PHI in violation of HIPAA. Covered entities and business associates cannot rely on an attestation if it is incomplete, if the covered entity or business associate knows that any material information on the attestation is false, or if a reasonable covered entity or business associate in the same position would not believe the requestor’s statement that the use or disclosure is not for a prohibited purpose. Covered entities and business associates that disclose information pursuant to a defective attestation violate the Privacy Rule.

COMPLIANCE CHECKLIST

The Privacy Rule applies to group health plans as “covered entities.” For fully-insured group health plans, HIPAA compliance generally falls to the insurer. However, for employers that sponsor self-insured group health plans, the plan administrator (typically, the employer) retains responsibility for HIPAA compliance and shares these responsibilities with “business associates” that provide services to the plan, such as a third-party administrator (TPA).

The final rule presents plan administrators of self-insured group health plans with a good opportunity to review their current HIPAA compliance status and prepare for the new attestation requirement. The following items should be reviewed prior to the December 23, 2024, compliance deadline:

  • Update HIPAA policies and procedures: A group health plan is required to maintain HIPAA policies and procedures that outline the manner in which the plan operates in compliance with all aspects of the Privacy Rule. The policies and procedures should be updated by December 23, 2024, to reflect the new attestation requirement.
  • Confirm compliance with TPA: A group health plan’s TPA is directly subject to the attestation requirement under the final rule as a business associate. Since disclosure requests may be received directly by the TPA, plan administrators should confirm that their TPAs are ready to process requests for PHI potentially related to reproductive health care pursuant to the attestation requirement when applicable. Keep in mind that the TPA may also refer these requests back to the plan administrator for review and approval, and therefore, the plan administrator must be aware of its obligations under the final rule as well. 
  • Review business associate agreements (BAAs): Group health plans are required to have a BAA in place with each business associate that provides services to the plan. The final rule does not require covered entities and business associates to address the limitations on disclosures related to reproductive health care in either existing or new BAAs. However, in the commentary to the final rule, HHS suggests that covered entities and business associates may wish to modify existing (or future) BAAs to acknowledge the disclosure requests subject to the attestation requirement and to allocate their respective responsibilities for handling such requests. This may be helpful in BAAs with business associates that could potentially receive a disclosure request related to reproductive health care, such as the employer’s major medical plan TPA or an employee assistance program (EAP) service provider. 
  • Schedule HIPAA workforce training: Group health plans are required to train all members of their workforce as to the appropriate manner of handling PHI. Trainings generally occur upon hire, when changes in the law impact the responsibilities of workforce members, and at periodic intervals thereafter. The changes under the final rule create new responsibilities for workforce members who handle disclosure requests, and they should be trained on the new requirements before December 23, 2024. 
  • Stay tuned for updates to HIPAA Notice of Privacy Practices (NPP): The final rule amends the content requirements for a group health plan’s NPP. With regard to the limitations on disclosures related to reproductive health care, the NPP must include (i) a description of the prohibited purposes and at least one example of a prohibited purpose in sufficient detail for an individual to understand the prohibition, and (ii) a description of the types of uses and disclosures requiring an attestation and at least one example. However, because the final rule amends the content requirements of the NPP for other changes unrelated to reproductive health care, the compliance deadline for providing a revised NPP is delayed until February 16, 2026. Given the extended deadline, group health plans may wish to take a wait-and-see approach to making all the required changes to the NPP, in the event that HHS revises its model NPP prior to 2026.

For more information about HIPAA requirements for your employee benefit plans, please contact Shalina Schaefer, Tara Sciscoe, Chris Sears, or the Ice Miller Workplace Solutions lawyer with whom you regularly work.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related Services & Industries

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights