Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

Faculty Articles

Discipline
Institution
Keyword
Publication Year

Articles 1 - 30 of 61

Full-Text Articles in Privacy Law

Law Enforcement, Reproductive Health Information, And The Hipaa Privacy Rule, Stacey A. Tovino Oct 2025

Law Enforcement, Reproductive Health Information, And The Hipaa Privacy Rule, Stacey A. Tovino

Faculty Articles

On April 26, 2024, the federal Department of Health and Human Services (HHS) promulgated a final rule (Final Rule) amending the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The Final Rule prohibits HIPAA covered entities and business associates from using and disclosing protected health information (PHI) to conduct criminal, civil, or administrative investigations into an individual for the mere act of seeking, obtaining, providing, or facilitating lawful reproductive health care. The Final Rule also prohibits HIPAA covered entities and business associates from using and disclosing PHI to impose criminal, civil, and administrative liability on any individual, or to …


Misaligned: An Update On Trends In Data Privacy Laws And Their Effect On Individuals, Jena Martin, Erin Kelley Jan 2025

Misaligned: An Update On Trends In Data Privacy Laws And Their Effect On Individuals, Jena Martin, Erin Kelley

Faculty Articles

In 2021, a data privacy white paper was published with the support of the Center of Consumer Law and Education-a joint initiative with West Virginia University and Marshall University. That paper provided a comprehensive overview of data privacy around the country (and indeed, a look around the world) and discussed various ways that consumers engage with data and data privacy issues-while focusing on West Virginia and the issues that the state's residents face. Specifically, the paper provided the results of a survey of West Virginians and a set of focus groups held to discern what consumers in the state consider …


The Warrant Exception That Isn't: Fisa Section 702, "Defensive" Searches, And The Fourth Amendment, Noah C. Chauvin Jan 2025

The Warrant Exception That Isn't: Fisa Section 702, "Defensive" Searches, And The Fourth Amendment, Noah C. Chauvin

Faculty Articles

Section 702 of the Foreign Intelligence Surveillance Act allows the government to conduct warrantless electronic surveillance of non-Americans who are located overseas. Although the surveillance targets foreigners, Americans' communications are "incidentally" collected, too. Once the government has acquired Americans' communications, court-approved rules allow it to conduct warrantless searches for and through them in its Section 702 databases. Intelligence agencies have used these rules to turn this foreign intelligence program into a domestic spying tool, conducting tens of thousands of warrantless "backdoor" searches for Americans' private communications obtained under Section 702 every year.

Section 702 periodically sunsets; Congress most recently reauthorized …


Katz'S Imperfect Circle: An Empirical Study Of Reasonable Expectations Of Privacy, Tonja Jacobi, Christopher Brett Jaeger Jan 2025

Katz'S Imperfect Circle: An Empirical Study Of Reasonable Expectations Of Privacy, Tonja Jacobi, Christopher Brett Jaeger

Faculty Articles

Under Katz v. United States, the Fourth Amendment restricts government actions that infringe upon expectations of privacy that society recognizes as reasonable. This foundational test has long been criticized as circular, both because courts can shape the very expectations they seek to identify through their decisions and because governments can manipulate those expectations to expand the reach of their own power. But how do members of society decide what expectations are reasonable, and how do judges ascertain those expectations? And are expectations of privacy malleable even without deliberate manipulation?

This Article shows that the circularity critique is both understated …


Artificial Intelligence And The Hipaa Privacy Rule: A Primer, Stacey A. Tovino Jan 2025

Artificial Intelligence And The Hipaa Privacy Rule: A Primer, Stacey A. Tovino

Faculty Articles

No abstract provided.


Increasing Congressional Oversight Of Fisa Section 702 After Risaa, Noah C. Chauvin Jan 2025

Increasing Congressional Oversight Of Fisa Section 702 After Risaa, Noah C. Chauvin

Faculty Articles

In April of 2024, Congress passed the Reforming Intelligence and Securing America Act ("RISAA"). This bill reauthorized Section 702 of the Foreign Intelligence Surveillance Act ("FISA'), an important counterterrorism authority that was intended to make it easier for the government to spy on foreign terrorists but which has been repeatedly abused to spy on Americans. While RISAA enacted modest surveillance reforms, it also included substantial expansions of the government's spying powers. Moreover, it largely left intact the existing oversight regime for Section 702, which is deficient as a matter of law, policy, and fact.

This article assesses the extent to …


Consumer Privacy And The Dobbs Disruption, Mason R. Clark Jan 2024

Consumer Privacy And The Dobbs Disruption, Mason R. Clark

Faculty Articles

The right to reproductive privacy is under attack in the United States, and it is losing ground. Dobbs v. Jackson Women's Health Organization, the Supreme Court's 2022 decision that overruled Roe v. Wade's constitutional protection of abortion and jeopardized privacy rights by proxy, reflects this losing posture. Scholarship in reproductive privacy varyingly critiques federal privacy initiatives, evaluates regulatory interventions, and proposes civil rights frameworks in response to Dobbs. This Article, however, pinpoints how Dobbs created a gaping hole in state consumer privacy laws even as they propagated across the United States. Currently, there are no state consumer privacy laws that …


Growing Tensions: Consumer Privacy And Corporate Disclosures, Megan Wischmeier Shaner Jan 2024

Growing Tensions: Consumer Privacy And Corporate Disclosures, Megan Wischmeier Shaner

Faculty Articles

Data privacy and data security have become key issues for legislators, regulators, and individual citizens. Roughly two-thirds of Americans believe their data is being regularly tracked, monitored, and collected by companies and the government. A majority of U.S. adults also believe their data is less secure today than five years ago, expressing concerns that they have little control over how their personal information is being used and that the entities who control their data are not responsible stewards. In the absence of comprehensive federal regulation, a continuous stream of privacy statutes have been proposed at the state level. Beginning with …


Confidentiality Over Privacy, Stacey A. Tovino Jan 2023

Confidentiality Over Privacy, Stacey A. Tovino

Faculty Articles

No abstract provided.


Private Ownership Of Public Facts: Docudramas, Deals, And Life Story Rights, David Fagundes, Jorge L. Contreras Jan 2023

Private Ownership Of Public Facts: Docudramas, Deals, And Life Story Rights, David Fagundes, Jorge L. Contreras

Faculty Articles

From Elizabeth Taylor to Mike Tyson, celebrities have claimed ownership of their personae. But while the right of publicity and other laws give individuals the right to control commercial exploitation of their images, voices, mannerisms and taglines, the law stops short of recognizing a property interest in the events of their lives. On the contrary, the First Amendment protects producers of expressive works when telling non-defamatory stories about real people. The intuition that exists among celebrities and lay persons alike that individuals own their “life stories” has been fueled by the decades-old Hollywood practice of “acquiring” life story rights from …


Privacy For Student-Patients: A Call To Action, Stacey A. Tovino Jan 2023

Privacy For Student-Patients: A Call To Action, Stacey A. Tovino

Faculty Articles

Consider a law student who has a mental or reproductive health issue that the student wishes to keep private. If the student seeks care at an off-campus health clinic that is not affiliated with the student’s law school or university, the student typically has a number of federally enforceable privacy rights. For example, the federal HIPAA Privacy Rule will typically apply and prohibit the clinic from disclosing the student’s protected health information to professors, parents, and other third parties without the student’s prior written authorization. The law student also will have the right to receive a notice of privacy practices, …


In Celebration Of Dissents (And Lengthy Textbooks): How Digital Became Different For The Fourth Amendment And Why It Is Time For A Real Warrant Default, Stephen E. Henderson Jan 2022

In Celebration Of Dissents (And Lengthy Textbooks): How Digital Became Different For The Fourth Amendment And Why It Is Time For A Real Warrant Default, Stephen E. Henderson

Faculty Articles

The last decade has brought tremendous change to the Fourth Amendment, finally resulting in a ‘digital is different’ norm. We stand at an inflection point between a monolithic, analog past and a murky future of yet-unarticulated constitutional digital policing rules. It is a good time, then, to reflect upon how we came to be here and where we ought to go. This Essay first looks back to a monumental, majestic dissent: that of Justice Louis Brandeis in the 1928 decision of Olmstead v. United States. Every American, and especially every law student, ought to know that opinion, and judges …


Not So Private, Stacey A. Tovino Jan 2022

Not So Private, Stacey A. Tovino

Faculty Articles

Federal and state laws have long attempted to strike a balance between protecting patient privacy and health information confidentiality on the one hand and supporting important uses and disclosures of health information on the other. To this end, many health laws restrict the use and disclosure of identifiable health data but support the use and disclosure of de-identified data. The goal of health data de-identification is to prevent or minimize informational injuries to identifiable data subjects while allowing the production of aggregate statistics that can be used for biomedical and behavioral research, public health initiatives, informed health care decision making, …


A Solution For The Third-Party Doctrine In A Time Of Data Sharing, Contact Tracing, And Mass Surveillance, Tonja Jacobi, Dustin Stonecipher Jan 2022

A Solution For The Third-Party Doctrine In A Time Of Data Sharing, Contact Tracing, And Mass Surveillance, Tonja Jacobi, Dustin Stonecipher

Faculty Articles

Today, information is shared almost constantly. People share their DNA to track their ancestry or for individualized health information; they instruct Alexa to purchase products or provide directions; and, now more than ever, they use videoconferencing technology in their homes. According to the third-party doctrine, the government can access all such information without a warrant or without infringing on Fourth Amendment privacy protections. This exposure of vast amounts of highly personal data to government intrusion is permissible because the Supreme Court has interpreted the third-party doctrine as a per se rule. However, that interpretation rests on an improper understanding of …


At A Covid Crossroads : Public Health, Patient Privacy, And Health Information Confidentiality, Stacey A. Tovino Jan 2021

At A Covid Crossroads : Public Health, Patient Privacy, And Health Information Confidentiality, Stacey A. Tovino

Faculty Articles

This essay summarizes and assesses the various bulletins, guidance documents, and notices of enforcement discretion released by the federal Department of Health and Human Services regarding the application of the HIPAA Privacy Rule to the COVID-19 pandemic. Among other topics and actions, these authorities address the application of the HIPAA Privacy Rule to the use and disclosure of protected health information for public health activities, waive the application of certain HIPAA Privacy Rule requirements during the COVID-19 pandemic, and announce enforcement discretion regarding certain covered entities’ non-compliance with particular provisions within the HIPAA Privacy Rule. These authorities overwhelmingly, and appropriately, …


If You Don't Care, Who Will?, Chad J. Pomeroy Jan 2021

If You Don't Care, Who Will?, Chad J. Pomeroy

Faculty Articles

As a property law professor, I have lately found myself thinking a lot about privacy rights. Initially, the two topics (property and privacy) perhaps do not seem closely related, but I think they are—or, at least, I think the tie between the two is becoming much more pronounced and important, as modern life becomes ever more techno-centric. specifically, I think that privacy rights are, at this point, essentially an outgrowth of property rights. That is, one's right to privacy is dependent on what we traditionally view as one's property rights. At least, I think this is the current state of …


Two Constitutional Rights, Two Constitutional Controversies, Michael J. Perry Jan 2021

Two Constitutional Rights, Two Constitutional Controversies, Michael J. Perry

Faculty Articles

My overarching aim in the Article is to defend a particular understanding of two constitutional rights and, relatedly, a particular resolution of two constitutional controversies. The two rights I discuss are among the most important rights protected by the constitutional law of the United States: the right to equal protection and the right of privacy. As I explain in the Article, the constitutional right to equal protection is, at its core, the human right to moral equality, and the constitutional right to privacy is best understood as a version of the human right to moral freedom. The two controversies I …


Covid-19 And The Hipaa Privacy Rule: Asked And Answered, Stacey A. Tovino Jan 2021

Covid-19 And The Hipaa Privacy Rule: Asked And Answered, Stacey A. Tovino

Faculty Articles

The severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2), the virus that causes coronavirus disease 2019 (COVID-19), raises important and vexing privacy and security issues. Public health officials, law and policy makers, and members of the general public disagree, for example, regarding the amount and type of individually identifiable health data that should be collected, used, and disclosed for public health surveillance, public health investigation, and public health intervention. Stakeholders also diverge in their opinions regarding the sufficiency of federal and state data privacy and security laws. Some stakeholders believe that current statutes and regulations are sufficient to protect individually identifiable …


In A World Of "Fake News," What's A Social Media Platform To Do?, Evelyn Aswad Jan 2020

In A World Of "Fake News," What's A Social Media Platform To Do?, Evelyn Aswad

Faculty Articles

While the circulation of disinformation and misinformation online can pose a variety of risks to societies around the world, it should also be of concern that overreacting to such false information can undermine human rights, including freedom of expression. The business operations of global social media platforms frequently intersect with this latter concern because of a spike in the adoption of national laws that ban “fake news” as well as their own platform policies to tackle false information. This Essay assesses the corporate responsibility standards afforded by the United Nations’ Guiding Principles on Business & Human Rights as well as …


Losing The Freedom To Be Human, Evelyn Aswad Jan 2020

Losing The Freedom To Be Human, Evelyn Aswad

Faculty Articles

In 2019, Apple’s CEO warned that contemporary business models, which are based on harvesting our personal data and monetizing everything we do online, violate our privacy and will eventually cause us “to lose the freedom to be human.” Others have taken this privacy concern a step further by questioning whether these business models undermine mental autonomy, i.e., the ability to think and form opinions. The burgeoning chorus of concerns has triggered a variety of high-profile calls to explore whether international human rights law protects against intrusions on the inner sanctum of one’s mind, particularly with respect to the business models …


Assumed Compliance, Stacey A. Tovino Jan 2020

Assumed Compliance, Stacey A. Tovino

Faculty Articles

No abstract provided.


Going Rogue: Mobile Research Applications And The Right To Privacy, Stacey A. Tovino Jan 2019

Going Rogue: Mobile Research Applications And The Right To Privacy, Stacey A. Tovino

Faculty Articles

This Article investigates whether nonsectoral state laws may serve as a viable source of privacy and security standards for mobile health research participants and other health data subjects until new federal laws are created or enforced. In particular, this Article (1) catalogues and analyzes the nonsectoral data privacy, security, and breach notification statutes of all fifty states and the District of Columbia; (2) applies these statutes to mobile-app-mediated health research conducted by independent scientists, citizen scientists, and patient researchers; and (3) proposes substantive amendments to state law that could help protect the privacy and security of all health data subjects, …


The Federalism Challenges Of Protecting Medical Privacy In Workers' Compensation, Ani B. Satz Jan 2019

The Federalism Challenges Of Protecting Medical Privacy In Workers' Compensation, Ani B. Satz

Faculty Articles

This Article is the first to address the challenges of federalism in protecting medical privacy in workers’ compensation after the promulgation of the HPR and to propose legal change. The Article argues that workers’ compensation programs must align with the federal privacy protections of the HPR and proposes actions for the U.S. Department of Health and Human Services (HHS) and states to remedy departures. Part I discusses the complex relationship between the HPR and workers’ compensation. This relationship is often misunderstood by legislatures and courts, compounding the challenges of federalism in this area. Specifically, Part I addresses the HPR’s § …


Florida Law, Mobile Research Applications, And The Right To Privacy, Stacey A. Tovino Jan 2019

Florida Law, Mobile Research Applications, And The Right To Privacy, Stacey A. Tovino

Faculty Articles

This Article investigates whether state law contains comprehensive privacy, security, and breach notification standards that could apply to independent scientists who conduct mobile app mediated health research. Focusing only on Florida law, this Article assesses potentially relevant and applicable sources of privacy, security, and breach notification standards for health data of the type obtained during mobile app mediated health research studies. This Article concludes that, with one exception, Florida law tends to fall into one of two categories: (1) the law contains at least one data privacy, security, or breach notification standard, but the standard is limited in application to …


A Timely Right To Privacy, Stacey A. Tovino Jan 2019

A Timely Right To Privacy, Stacey A. Tovino

Faculty Articles

On December 28, 2017, the federal Department of Health and Human Services ("HHS") settled its fiftieth case involving potential violations of the privacy, security, and breach notification rules ("Rules") that implement the Health Insurance Portability and Accountability Act ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"). This Article catalogues and examines currently available enforcement actions involving the HIPAA and HITECH Rules, including the cases in which HHS has entered into a settlement agreement with a HIPAA covered entity or business associate, the cases in which HHS has imposed a civil money penalty on a HPAA …


Carpenter V. United States And The Fourth Amendment: The Best Way Forward, Stephen E. Henderson Jan 2018

Carpenter V. United States And The Fourth Amendment: The Best Way Forward, Stephen E. Henderson

Faculty Articles

We finally have a federal ‘test case.’ In Carpenter v. United States, the Supreme Court is poised to set the direction of the Fourth Amendment in the digital age. The case squarely presents how the twentieth-century third party doctrine will fare in contemporary times, and the stakes could not be higher. This Article reviews the Carpenter case and how it fits within the greater discussion of the Fourth Amendment third party doctrine and location surveillance, and I express a hope that the Court will be both a bit ambitious and a good measure cautious. As for ambition, the Court …


Fourth Amendment Anxiety, Kiel Brennan-Marquez, Stephen E. Henderson Jan 2018

Fourth Amendment Anxiety, Kiel Brennan-Marquez, Stephen E. Henderson

Faculty Articles

In Birchfield v. North Dakota (2016), the Supreme Court broke new Fourth Amendment ground by establishing that law enforcement’s collection of information can be cause for “anxiety,” meriting constitutional protection, even if subsequent uses of the information are tightly restricted. This change is significant. While the Court has long recognized the reality that police cannot always be trusted to follow constitutional rules, Birchfield changes how that concern is implemented in Fourth Amendment law, and importantly, in a manner that acknowledges the new realities of data-driven policing. Beyond offering a careful reading of Birchfield, this Article has two goals. First, …


Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino Jan 2018

Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino

Faculty Articles

No abstract provided.


The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino Jan 2017

The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino

Faculty Articles

In this Article, Professor Tovino compares and contrasts three illustrative concepts and rights in the Privacy Rule and/or the GDPR, including the concepts of authorization and consent, the rights of amendment and rectification, and the right to erasure. Identified similarities reflect the core values of HHS and the EU with respect to maintaining the confidentiality and privacy of personal data and protected health information, respectively. Identified differences reflect the Privacy Rule's original, narrow focus on health industry participants and individually identifiable health information compared to the GDPR's broad focus on data controllers and personal data. Other differences reflect, perhaps, the …


Teaching The Hipaa Privacy Rule: Illustrative Comparisons, Stacey A. Tovino Jan 2017

Teaching The Hipaa Privacy Rule: Illustrative Comparisons, Stacey A. Tovino

Faculty Articles

Twenty years ago, President Clinton signed the Health Insurance Portability and Accountability Act of 1996 (HIPAA) into law. Over the past two decades, the federal Department of Health and Human Services (HHS) has published several sets of rules implementing the Administrative Simplification provisions within HIPAA as well as the Health Information Technology for Economic and Clinical (HITECH) Act within the American Recovery and Reinvestment Act (ARRA). These rules include, but certainly are not limited to, a final rule published on January 25, 2013, governing the use and disclosure of protected health information by covered entities and their business associates (the …