{"id":1392,"date":"2017-11-14T14:39:45","date_gmt":"2017-11-14T19:39:45","guid":{"rendered":"http:\/\/blogs.luc.edu\/compliance\/?p=1392"},"modified":"2017-11-14T14:39:45","modified_gmt":"2017-11-14T19:39:45","slug":"what-happens-when-the-police-demand-phi","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=1392","title":{"rendered":"What Happens When The Police Demand PHI"},"content":{"rendered":"<p><em>Alexander Thompson<br \/>\nSenior Symposium Editor<br \/>\nLoyola University Chicago School of Law, J.D. 2018<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>It happens in every emergency department: a law enforcement officer comes into the ER at two o\u2019clock in the morning and demands to test the blood alcohol levels of a patient brought in after an auto accident. The officer pulls an exhausted nurse to the side in the hopes that the nurse will forget his or her training, or become anxious enough to give up the information for fear of being arrested. Yet no matter the specific facts, the question remains: can a hospital give law enforcement officers a patient\u2019s PHI without authorization from the patient? In some situations, is it even required?<\/p>\n<p>There is a provision under the HIPAA Privacy Rule that allows, and in some cases, requires, entities to disclose patient\u2019s PHI to law enforcement without the patient\u2019s authorization. However, state law can complicate this picture with more restrictive regulations and guidance.<\/p>\n<p><!--more--><\/p>\n<p><strong>The University of Utah Hospital Incident <\/strong><\/p>\n<p>While the scenario might be different each time, the threat of a law enforcement officer demanding information about a patient is very real. <a href=\"http:\/\/www.cnn.com\/2017\/09\/01\/health\/utah-nurse-arrest-police-video\/index.html\">On July 26th, 2017<\/a>, police entered the University of Utah Hospital burn unit and demanded that the victim of a recent crash have his blood drawn, and that the results be handed over to the officers. A nurse refused, citing the hospital\u2019s policy on blood draws, which referenced the patient\u2019s right to privacy under both HIPAA and state law. <a href=\"http:\/\/www.cnn.com\/2017\/09\/01\/health\/utah-nurse-arrest-police-video\/index.html\">The nurse told<\/a> the officers that absent a court order, the patient\u2019s consent, or official notification patient was under arrest, she could not comply with the request. Since none of these criteria applied, the nurse refused to give any information without authorization from the patient. The law enforcement officers proceeded to arrest the nurse.<\/p>\n<p>The arrest was recorded, and the video posted online, where it went viral. The incident quickly became headline news. This high-profile situation opened the door to a conversation about HIPAA and patient\u2019s privacy rights throughout the country.<\/p>\n<p><strong>HIPAA <\/strong><\/p>\n<p><a href=\"https:\/\/www.law.cornell.edu\/cfr\/text\/45\/164.512\">45 C.F.R. \u00a7 164.512(f)<\/a> is the regulation within HIPAA that governs disclosures of PHI to law enforcement officers. This regulation allows for disclosures to be made under six circumstances: 1) pursuant to process and as otherwise required by law, 2) giving limited information for identification and location purposes, 3) when the PHI concerns victims of a crime, 4) informing decedents, 5) notifying police regarding crime on the premises, and 6) reporting crime in emergencies.<\/p>\n<p>In the situation at the University of Utah, the nurse stated that she could give the law enforcement officers the blood draw information if the law enforcement officers had a court order, the patient gave consent, or the law enforcement officers placed the patient under arrest. In light of HIPAA and state law, she was correct.<\/p>\n<p>As to her first statement: under 45 C.F.R. \u00a7 164.512(f)(1), a court order would allow the nurse to give the police officers the blood draw information.<\/p>\n<p>While the nurse used the phrase \u201cpatient consent,\u201d as the second set of circumstances under which she could release the information, \u201c<a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/faq\/264\/what-is-the-difference-between-consent-and-authorization\/index.html\">authorization<\/a>\u201d is actually the correct term. HIPAA does allows for the release of patient information (that isn\u2019t allowed under treatment, payment or healthcare operations) with the <a href=\"https:\/\/www.law.cornell.edu\/cfr\/text\/45\/164.508\">patient\u2019s prior written authorization<\/a>.<\/p>\n<p>Finally, as for the third statement from the nurse, there is a <a href=\"http:\/\/www.sltrib.com\/opinion\/commentary\/2017\/09\/01\/paul-cassell-cop-who-arrested-nurse-was-wrong-but-the-law-is-complicated\/\">Utah law<\/a> allowing for blood draws of patients who police have reasonable belief were driving under the influence. This brings to light the fact that not only was federal privacy law important during this scenario but that state privacy law was as well.<\/p>\n<p><strong>State Law <\/strong><\/p>\n<p>While these HIPAA provisions may seem straightforward and easy to implement through policies and procedures, state law complicates things. If state privacy laws are <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/faq\/399\/does-hipaa-preempt-state-laws\/index.html\">more restrictive<\/a> than the HIPAA privacy regulations, then state law preempts that section of HIPAA. For example, Illinois has very restrictive <a href=\"http:\/\/www.ilga.gov\/legislation\/ilcs\/ilcs3.asp?ActID=2043&amp;ChapterID=57\">mental health<\/a>, <a href=\"http:\/\/www.ilga.gov\/legislation\/ilcs\/ilcs3.asp?ActID=1550&amp;ChapterID=35\">AIDS<\/a>, and <a href=\"http:\/\/www.ilga.gov\/legislation\/ilcs\/ilcs3.asp?ActID=1567&amp;ChapterID=35\">genetic information<\/a> privacy acts. Therefore, entities in Illinois have to abide by both HIPAA privacy regulations and the more restrictive privacy laws mentioned above.<\/p>\n<p>In the Utah scenario discussed above, there was an applicable state law. However, the Utah state law added a wrinkle to HIPAA privacy law as <a href=\"http:\/\/www.sltrib.com\/opinion\/commentary\/2017\/09\/01\/paul-cassell-cop-who-arrested-nurse-was-wrong-but-the-law-is-complicated\/\">it allowed police<\/a> to order a blood draw when the police have reasonable belief an individual was driving under the influence. In this situation, the police were actually <a href=\"http:\/\/www.sltrib.com\/opinion\/commentary\/2017\/09\/01\/paul-cassell-cop-who-arrested-nurse-was-wrong-but-the-law-is-complicated\/\">attempting to prove<\/a> that the driver had not been operating a vehicle while under the influence and thus, the statute did not apply in this situation.<\/p>\n<p><strong>Conclusion <\/strong><\/p>\n<p>The situation at the University of Utah Hospital is extremely troubling, since the nurse followed HIPAA and state law exactly as written, and was still arrested. In order to ensure that this never happens again, states and hospitals can take preventative steps. For instance, in Utah the state legislature is <a href=\"https:\/\/www.usnews.com\/news\/best-states\/utah\/articles\/2017-09-21\/after-nurse-arrest-utah-lawmakers-to-clarify-blood-draw-law\">drafting a new provision<\/a> to clarify when law enforcement officers can require a blood draw. The University of Utah Hospital itself has <a href=\"http:\/\/www.foxnews.com\/us\/2017\/09\/05\/utah-hospital-restricts-police-access-after-nurses-arrest.html\">banned law enforcement officers<\/a> from patient care areas and from interacting with nurses.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It happens in every emergency department: a law enforcement officer comes into the ER at two o\u2019clock in the morning and demands to test the blood alcohol levels of a patient brought in after an auto accident. The officer pulls an exhausted nurse to the side in the hopes that the nurse will forget his or her training, or become anxious enough to give up the information for fear of being arrested. Yet no matter the specific facts, the question remains: can a hospital give law enforcement officers a patient\u2019s PHI without authorization from the patient? In some situations, is it even required?<\/p>\n<p>There is a provision under the HIPAA Privacy Rule that allows, and in some cases, requires, entities to disclose patient\u2019s PHI to law enforcement without the patient\u2019s authorization. However, state law can complicate this picture with more restrictive regulations and guidance.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[321,1032,1228,1577,1597,1622,1623],"class_list":["post-1392","post","type-post","status-publish","format-standard","hentry","category-hipaa-health-information","tag-breach","tag-hipaa-2","tag-law-enforcement","tag-phi","tag-police","tag-privacy","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/1392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1392"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/1392\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}