Options for Promoting Privacy on the National Information Infrastructure. Medical Record Privacy


Cost concerns are driving the nation's health care delivery system to a more cost-conscious, competitive, managed care environment. The health care industry is increasingly committed to computer networks that can collect, aggregate, and disseminate personal medical information on a nationwide basis. Use of the NII may help provide better care for less, and better use of information technology generally can make an important contribution to this effort. Existing and potential applications include telemedicine (remote medical diagnosis/care), unified electronic claims, personal health information systems, and computer-based patient records.138 The Physician Computer Network, Inc. (PCN), for example, has developed software that links physicians to insurance companies, clinical laboratories and hospitals. The system benefits doctors and patients by cutting the cost and delays associated with processing medical claims, receiving test results and changing medications and orders for hospitalized patients. In exchange for providing discount computers, PCN acquires aggregated patient records, including diagnoses and treatments, which it compiles and then sells to pharmaceutical companies and insurers.139

Public concern about medical privacy is quite high.140 Medical records often contain highly sensitive and personal information and can reveal more about an individual than virtually any other type of record.141 In response to public concerns, companies like PCN have implemented internal security measures and engaged a public accounting firm to certify that their data is maintained securely.142 In 1994, the Institute of Medicine called upon Congress to enact preemptive legislation to assure the confidentiality and protection of privacy rights in personally-identifiable health data.143 The National Research Council recently reported that computerized medical records are "vulnerable to misuse and abuse" and likewise called for the creation of additional incentives to ensure that healthcare industry employees protect patient information.144

Medical privacy concerns are not new. As early as 1977 the Privacy Protection Study Commission recognized that the trend toward computerization of medical record information posed "new problems" from a "privacy protection viewpoint."145 Among other things, the Commission concluded that medical records contained more information and were available to more users than ever before. Additionally the Commission found that changes in the medical profession, increased population mobility, and increased demands by third parties for medical record information had greatly diluted the control that medical care providers had once exercised over such information. The Commission predicted that the demand for access to such information by third party users would increase over time, observing:

[T]he importance of medical-record information to those outside of the medical-care relationship, and their demands for access to it, will continue to grow. Moreover, owing to the rising demand for access by third parties, coupled with the expense of limiting disclosure to that which is specifically requested by the non-medical user, there appears to be no natural limit to the potential uses of medical-record information for purposes quite different from those for which it was originally collected.146

The Commission's 1977 prediction is a 1997 reality. Today, industry amasses and shares staggering amounts of medical information.147 Health care providers are now able to develop centralized profiles on the medical condition of patients, as well as the treatment of that condition in order to facilitate care, research, and insurance billing and coverage.148 Another example is the Medical Information Bureau (MIB), a non-profit trade organization that serves life and disability insurance companies by maintaining extensive databanks of medical and other information on millions of Americans and Canadians.149 This information has been referred to as "the medical equivalent of a credit report."150

As the Privacy Protection Study Commission predicted in 1977, medical information is routinely shared with and viewed by third parties who are not involved in patient care. Secondary users of medical information include educational institutions, the civil and criminal justice systems, life and health insurers, rehabilitation and social welfare programs, credit agencies, public health agencies, and medical and social researchers.151 The American Medical Records Association has identified twelve categories of information seekers outside of the health care industry who have access to health care files, including employers, government agencies, credit bureaus, insurers, educational institutions, and the media.152

Traditionally, health care and health insurance providers have guarded patient privacy in accordance with professional codes of ethical behavior, such as doctor-patient confidentiality. But no federal statute generally protects the confidentiality of medical records in the private sector.153 As an OTA report observed, existing law allows development of private-sector databases and data exchanges of patient information without regulation, statutory guidance, or recourse for individuals harmed by misuse of the data.154

Not surprisingly, technology and market pressures are beginning to erode the traditional protections for medical records. Consensus is emerging that doctor-patient confidentiality practices and the widely varying protection afforded under individual state laws no longer adequately protect the privacy of medical information. The Computer-based Patient Record Institute (CPRI), for example, drafted principles that call for federal standardization of patient confidentiality safeguards including stiff penalties and fines for those who knowingly breach the confidentiality of patient records.155

Some health organizations and companies have adopted voluntary privacy standards based on fair information principles.156 Major model codes and statutes in this industry include, for example, the American Health Information Management Association's Health Information Model Legislation language.157 As a practical matter, however, model codes and statues have woven only a loose web of protection: they may apply to limited types of information, may not address secondary users of health information, lack enforcement powers, or simply have not been adopted (only a handful of States have comprehensive health-care information confidentiality statutes).158

The FTC recently entered into an agreement with the Medical Information Bureau (MIB) under which insurance companies must notify consumers when information provided by MIB plays a part in a decision to deny coverage or to charge a higher rate. Under these circumstances, MIB will give consumers a free copy of their medical information report, in order to verify that all information is correct.159

In its 1993 report, OTA concluded that the current system fails to address privacy issues in a borderless, computerized environment.160 Rep. Gary Condit, (D-Calif.) has echoed this conclusion: "[B]ecause health information increasingly moves from a computer in one state to a computer in another state, uniform federal rules are needed."161 State privacy advocates have voiced similar concerns.162

The nation is some years away from full computerization of the traditional patient record used for clinical care, but is moving swiftly in that direction. Organizations such as the Computer-based Patient Record Institute are coordinating policy development in this area.163 Meanwhile, a large volume of medical data is already computerized in the context of insurance payment, managed care, and internal management in health care facilities.

The 104th Congress considered these issues in some detail, particularly with respect to Senate consideration of S. 1360, The Medical Records Confidentiality Act. No general health record confidentiality legislation was enacted, but the House companion bill to S. 1360 has been reintroduced in the 105th Congress as HR 52.164

The Health Insurance Portability and Accountability Act (HIPAA), enacted in 1996,165 includes an administrative simplification subtitle to encourage the development of a health information system based on uniform technological standards for the electronic transmission of financial and administrative health care data. The Secretary of Health and Human Services is required to establish standards to facilitate such transactions. The standards are to include security standards as well as standards for a unique identifier.

HIPAA established a National Committee on Vital and Health Statistics to advise the Secretary of HHS on these standards issues and on medical records privacy. The Committee has held a series of hearings addressing different uses of medical records (e.g. providers, insurers, law enforcement, etc.).166

Another provision of the Act requires the Secretary to submit detailed recommendations to the Congress with respect to the privacy of individually identifiable health information (i.e. general health record confidentiality legislation applicable to health care providers, insurers, and others) by August 1997. If Congress does not itself act by August 1999, the Secretary must issue privacy standards applicable to electronic transmission before the transmission standards are implemented.167

