Open Access. Powered by Scholars. Published by Universities.®

Privacy Law Commons™

Open Access. Powered by Scholars. Published by Universities.®

HIPAA

Discipline
Institution
Publication Year
Publication
Publication Type

Articles 1 - 30 of 43

Full-Text Articles in Privacy Law

Patient Privacy In The Digital Age: Reimagining Health Data Laws To Protect Patients’ Constitutional Rights, Adriana Almeida Mehtani May 2026

Patient Privacy In The Digital Age: Reimagining Health Data Laws To Protect Patients’ Constitutional Rights, Adriana Almeida Mehtani

Barry Law Review

No abstract provided.


Law Enforcement, Reproductive Health Information, And The Hipaa Privacy Rule, Stacey A. Tovino Oct 2025

Law Enforcement, Reproductive Health Information, And The Hipaa Privacy Rule, Stacey A. Tovino

Faculty Articles

On April 26, 2024, the federal Department of Health and Human Services (HHS) promulgated a final rule (Final Rule) amending the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The Final Rule prohibits HIPAA covered entities and business associates from using and disclosing protected health information (PHI) to conduct criminal, civil, or administrative investigations into an individual for the mere act of seeking, obtaining, providing, or facilitating lawful reproductive health care. The Final Rule also prohibits HIPAA covered entities and business associates from using and disclosing PHI to impose criminal, civil, and administrative liability on any individual, or to …


Hipaa, Sandra B. Wadeh, Victoria Sintes, Anna Olson, Ethan Lowry Mar 2025

Hipaa, Sandra B. Wadeh, Victoria Sintes, Anna Olson, Ethan Lowry

SPARK Symposium Presentations

HIPAA is a federal law designed to protect patient privacy by regulating how Protected Health Information is handled, stored, and shared. Violations of HIPAA can result in severe civil and criminal penalties, including fines, lawsuits, and even imprisonment for willful misconduct.


Federalism, State Action, And Workers' Medical Privacy, Ani B. Satz Jan 2025

Federalism, State Action, And Workers' Medical Privacy, Ani B. Satz

Indiana Law Journal

Injured workers entering state workers’ compensation systems effectively forego their medical privacy. This is due to widespread judicial misinterpretation of the HIPAA Privacy Rule (HPR) as excluding injured workers from federal medical privacy protections. As a result, medical privacy for workers’ compensation claims is effectively governed by state law. This Article argues that states have failed to protect the medical privacy of injured workers adequately and that there is a pressing need for legislative reform. The Article presents the first comprehensive survey in the legal literature of state action protecting the medical privacy of injured workers. Part I describes the …


Artificial Intelligence And The Hipaa Privacy Rule: A Primer, Stacey A. Tovino Jan 2025

Artificial Intelligence And The Hipaa Privacy Rule: A Primer, Stacey A. Tovino

Faculty Articles

No abstract provided.


Postmortem Privacy, Anita L. Allen, Jennifer E. Rothman Nov 2024

Postmortem Privacy, Anita L. Allen, Jennifer E. Rothman

Michigan Law Review

Since their inception in the late nineteenth century, privacy rights have been widely understood to terminate with a person’s death. The “no-privacy-rights-for- the-dead” doctrine has been repeated for nearly 130 years. As demonstrated in this Article, the reality on the ground deviated from this common pronouncement even early on. The divergence is so great today that sustained consideration of postmortem privacy is essential. This is especially so given urgent calls to protect the digital assets of the dead and evolving technology that allows for the reanimation of deceased performers and loved ones. This Article provides a theoretical foundation for determining …


The New Eu-Us Data Protection Framework's Implications For Healthcare, Charlotte A. Tschider, Marcelo Corrales Compagnucci, Timo Minssen Jan 2024

The New Eu-Us Data Protection Framework's Implications For Healthcare, Charlotte A. Tschider, Marcelo Corrales Compagnucci, Timo Minssen

Faculty Publications & Other Works

In July 2023, the United States and the European Union introduced the Data Privacy Framework (DPF), introducing the third generation of cross-border data transfer agreements constituting adequacy with respect to personal data transfers under the General Data Protection Regulation (GDPR) between the European Union (EU) and the US. This framework may be used in cross-border healthcare and research relationships, which are highly desirable and increasingly essential to innovative health technology development and health services deployment. A reliable model meeting EU adequacy requirements could enhance the transfer of patient and research participant data. While the DPF might present a familiar terrain …


My Body, My Choice, My Data: Information Privacy After Dobbs, My Kim Ong Jan 2024

My Body, My Choice, My Data: Information Privacy After Dobbs, My Kim Ong

University of San Francisco Law Review

No abstract provided.


Privacy For Student-Patients: A Call To Action, Stacey A. Tovino Jan 2023

Privacy For Student-Patients: A Call To Action, Stacey A. Tovino

Emory Law Journal

Consider a law student who has a mental or reproductive health issue that the student wishes to keep private. If the student seeks care at an off-campus health clinic that is not affiliated with the student’s law school or university, the student typically has a number of federally enforceable privacy rights. For example, the federal HIPAA Privacy Rule will typically apply and prohibit the clinic from disclosing the student’s protected health information to professors, parents, and other third parties without the student’s prior written authorization. The law student also will have the right to receive a notice of privacy practices, …


Genealogy Sites And Adoptions–Connecting Families Or Ruining Them?, Taylor Bialek Jan 2023

Genealogy Sites And Adoptions–Connecting Families Or Ruining Them?, Taylor Bialek

Touro Law Review

No abstract provided.


Is There A Fundamental Right To Privacy When An Educational Institution Requires A Student To Disclose Proof Of His Or Her Vaccination Status?, Mary D. Fatscher Jan 2023

Is There A Fundamental Right To Privacy When An Educational Institution Requires A Student To Disclose Proof Of His Or Her Vaccination Status?, Mary D. Fatscher

Touro Law Review

In 2020, the coronavirus disease (“COVID-19”) dominated the world. Although the public has progressively become more informed about the disease and how to safeguard itself, challenges persist as there is still much unknown. Aside from wearing masks, social distancing, and despite its undetermined consequences, the COVID-19 vaccination has emerged as a primary solution to substantially reducing the incidence and severity of the virus in our country. Many COVID-19 vaccine mandates were initiated once three pharmaceutical and biotechnology companies including Pfizer-BioNTech, Moderna, and Johnson & Johnson received Emergency Use Authorization from the Food and Drug Administration (“FDA”).


Big Data, Big Gap: Working Towards A Hipaa Framework That Covers Big Data, Ryan Mueller Oct 2022

Big Data, Big Gap: Working Towards A Hipaa Framework That Covers Big Data, Ryan Mueller

Indiana Law Journal

One lasting impact of the Health Insurance Portability and Accountability Act (HIPAA) is the privacy protections it provides for our sensitive health information. In the era of Big Data, however, much of our health information exists outside the traditional doctor-patient dynamic. From wearable technology, to mobile applications, to social media and internet browsing, Big Data organizations collect swaths of data that shed light on sensitive health information. Big Data organizations largely fall outside of HIPAA’s current framework because of the stringent requirements for when the HIPAA protections apply, namely that the data must be held by a covered entity, and …


Confidentiality, Warning And Aids: A Proposal To Protect Patients, Third Parties And Physicians Apr 2022

Confidentiality, Warning And Aids: A Proposal To Protect Patients, Third Parties And Physicians

Touro Law Review

No abstract provided.


Making An Offer That Can't Be Refused: The Need For Reform In The Rules Governing Informed Consent And Doctor-Patient Agreements, Timothy C. Macdonnell Jan 2022

Making An Offer That Can't Be Refused: The Need For Reform In The Rules Governing Informed Consent And Doctor-Patient Agreements, Timothy C. Macdonnell

Scholarly Articles

On a daily basis, throughout the country, patients are required to sign informed consent forms regarding the care they receive from their doctors. Informed consent forms are an important part of ensuring patients are making an intelligent, autonomous decision regarding their healthcare based on the facts related to their particular situation. However, frequently these consent forms contain what amount to contract-like terms that require patients to permit doctors to substitute other healthcare providers to care for the patient under the doctor’s supervision (substituted caregiver terms). Often these terms are presented to patients on the eve of surgery and on a …


Patching The Data Security Blanket: How A Stronger, Collaborative Ftc Is The Answer Right Under Our Nose, Jose A. Gonzalez Lopez Jan 2022

Patching The Data Security Blanket: How A Stronger, Collaborative Ftc Is The Answer Right Under Our Nose, Jose A. Gonzalez Lopez

Marquette Intellectual Property & Innovation Law Review

None


Problematic Interactions Between Ai And Health Privacy, W. Nicholson Price Ii Nov 2021

Problematic Interactions Between Ai And Health Privacy, W. Nicholson Price Ii

Articles

Problematic Interactions Between AI and Health Privacy Nicholson Price, University of Michigan Law SchoolFollow Abstract The interaction of artificial intelligence (AI) and health privacy is a two-way street. Both directions are problematic. This Essay makes two main points. First, the advent of artificial intelligence weakens the legal protections for health privacy by rendering deidentification less reliable and by inferring health information from unprotected data sources. Second, the legal rules that protect health privacy nonetheless detrimentally impact the development of AI used in the health system by introducing multiple sources of bias: collection and sharing of data by a small set …


Ai's Legitimate Interest: Towards A Public Benefit Privacy Model, Charlotte A. Tschider Jan 2021

Ai's Legitimate Interest: Towards A Public Benefit Privacy Model, Charlotte A. Tschider

Faculty Publications & Other Works

Health data uses are on the rise. Increasingly more often, data are used for a variety of operational, diagnostic, and technical uses, as in the Internet of Health Things. Never has quality data been more necessary: large data stores now power the most advanced artificial intelligence applications, applications that may enable early diagnosis of chronic diseases and enable personalized medical treatment. These data, both personally identifiable and de-identified, have the potential to dramatically improve the quality, effectiveness, and safety of artificial intelligence.

Existing privacy laws do not 1) effectively protect the privacy interests of individuals and 2) provide the flexibility …


Covid-19 And The Hipaa Privacy Rule: Asked And Answered, Stacey A. Tovino Jan 2021

Covid-19 And The Hipaa Privacy Rule: Asked And Answered, Stacey A. Tovino

Faculty Articles

The severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2), the virus that causes coronavirus disease 2019 (COVID-19), raises important and vexing privacy and security issues. Public health officials, law and policy makers, and members of the general public disagree, for example, regarding the amount and type of individually identifiable health data that should be collected, used, and disclosed for public health surveillance, public health investigation, and public health intervention. Stakeholders also diverge in their opinions regarding the sufficiency of federal and state data privacy and security laws. Some stakeholders believe that current statutes and regulations are sufficient to protect individually identifiable …


The Healthcare Privacy-Artificial Intelligence Impasse, Charlotte A. Tschider Jan 2020

The Healthcare Privacy-Artificial Intelligence Impasse, Charlotte A. Tschider

Faculty Publications & Other Works

With the advent of the Internet, wireless technologies, advanced computing, and, ultimately, the integration of mobile devices into patient care, medical device technologies have revolutionized the healthcare sector. What once was a highly personal, one-to-one relationship between physician and patient has now been expanded, including medical device manufacturers, third party healthcare system providers, even physician-as-a-service for interpreting the data complex systems churn out. The introduction of technology to the healthcare field has, at an ever-increasing rate, transformed human health management.

Reworking privacy commitments in an AI world is an important endeavor. It may mean that we reconceptualize what these rights …


Assumed Compliance, Stacey A. Tovino Jan 2020

Assumed Compliance, Stacey A. Tovino

Faculty Articles

No abstract provided.


A Recent Renaissance In Privacy Law, Margot Kaminski Jan 2020

A Recent Renaissance In Privacy Law, Margot Kaminski

Publications

Considering the recent increased attention to privacy law issues amid the typically slow pace of legal change.


The Federalism Challenges Of Protecting Medical Privacy In Workers' Compensation, Ani B. Satz Oct 2019

The Federalism Challenges Of Protecting Medical Privacy In Workers' Compensation, Ani B. Satz

Indiana Law Journal

Under current law, injured workers face a Hobson’s choice: They may file for workers’ compensation or maintain their medical privacy. The reason for this is that § 164.512(l) of the Health Insurance Portability and Accountability Act’s Privacy Rule (HPR) is widely misinterpreted by courts and legislatures as a wholesale waiver of privacy protections for injured workers. Section 164.512(l) excludes workers’ compensation from federal privacy protections that may frustrate the efficient administration of workers’ compensation claims. As the history and intent behind the HPR indicate, § 164.512(l) is premised on the assumption that states will protect workers’ privacy by creating and …


"You Have The Data"...The Writ Of Habeas Data And Other Data Protection Rights: Is The United States Falling Behind?, Sarah L. Lode Jan 2019

"You Have The Data"...The Writ Of Habeas Data And Other Data Protection Rights: Is The United States Falling Behind?, Sarah L. Lode

Indiana Law Journal

In Part I of this Note, I will discuss the writ of habeas data that has been developed primarily, but not exclusively, in Latin American countries. I will discuss the intricacies of the writ, how it evolved, and how it is applied today. Using Argentina as an example, I will discuss how the writ would be used by an Argentine citizen to protect her personal data. Part II summarizes the previously employed data protection scheme in the European Union, the Data Protection Directive (“the Directive”), and will also discuss the new EU data protection regulation, the General Data Protection Regulation …


A Timely Right To Privacy, Stacey A. Tovino Jan 2019

A Timely Right To Privacy, Stacey A. Tovino

Faculty Articles

On December 28, 2017, the federal Department of Health and Human Services ("HHS") settled its fiftieth case involving potential violations of the privacy, security, and breach notification rules ("Rules") that implement the Health Insurance Portability and Accountability Act ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH"). This Article catalogues and examines currently available enforcement actions involving the HIPAA and HITECH Rules, including the cases in which HHS has entered into a settlement agreement with a HIPAA covered entity or business associate, the cases in which HHS has imposed a civil money penalty on a HPAA …


Privacy Of Information And Dna Testing Kits, Shanna Raye Mason Jan 2018

Privacy Of Information And Dna Testing Kits, Shanna Raye Mason

Catholic University Journal of Law and Technology

In modern times, consumers desire for more control over their own health and healthcare. With this growing interest of control, direct to consumer DNA testing kits have never been more popular. However, many consumers are unaware of the potential privacy concerns associated with such use. This comment examines the popularity and privacy risks that are likely unknown to the individual consumer. This comment also addresses the shortcomings of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as the Genetic Information Nondiscrimination Act of 2008 (GINA) in regard to protecting individual’s genetic information from misuse. This comment …


Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino Jan 2018

Remarks On Patient Privacy: Problems, Perspectives, And Opportunities, Stacey A. Tovino

Faculty Articles

No abstract provided.


Health Information Technology And Hipaa: Can We Satisfy Security And Privacy Standards In The Digital Age, Robert Malone Sep 2017

Health Information Technology And Hipaa: Can We Satisfy Security And Privacy Standards In The Digital Age, Robert Malone

Oklahoma Journal of Law and Technology

No abstract provided.


The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino Jan 2017

The Hipaa Privacy Rule And The Eu Gdpr: Illustrative Comparisons, Stacey A. Tovino

Faculty Articles

In this Article, Professor Tovino compares and contrasts three illustrative concepts and rights in the Privacy Rule and/or the GDPR, including the concepts of authorization and consent, the rights of amendment and rectification, and the right to erasure. Identified similarities reflect the core values of HHS and the EU with respect to maintaining the confidentiality and privacy of personal data and protected health information, respectively. Identified differences reflect the Privacy Rule's original, narrow focus on health industry participants and individually identifiable health information compared to the GDPR's broad focus on data controllers and personal data. Other differences reflect, perhaps, the …


Teaching The Hipaa Privacy Rule, Stacey A. Tovino Jan 2017

Teaching The Hipaa Privacy Rule, Stacey A. Tovino

Scholarly Works

Twenty years ago, President Clinton signed the Health Insurance Portability and Accountability Act of 1996 (HIPAA) into law. Over the past two decades, the federal Department of Health and Human Services (HHS) has published several sets of rules implementing the Administrative Simplification provisions within HIPAA as well as the Health Information Technology for Economic and Clinical (HITECH) Act within the American Recovery and Reinvestment Act (ARRA). These rules include, but certainly are not limited to, a final rule published on January 25, 2013, governing the use and disclosure of protected health information by covered entities and their business associates (the …


Teaching The Hipaa Privacy Rule: Illustrative Comparisons, Stacey A. Tovino Jan 2017

Teaching The Hipaa Privacy Rule: Illustrative Comparisons, Stacey A. Tovino

Faculty Articles

Twenty years ago, President Clinton signed the Health Insurance Portability and Accountability Act of 1996 (HIPAA) into law. Over the past two decades, the federal Department of Health and Human Services (HHS) has published several sets of rules implementing the Administrative Simplification provisions within HIPAA as well as the Health Information Technology for Economic and Clinical (HITECH) Act within the American Recovery and Reinvestment Act (ARRA). These rules include, but certainly are not limited to, a final rule published on January 25, 2013, governing the use and disclosure of protected health information by covered entities and their business associates (the …