Report on Patient Privacy Volume 22, Number 11. MD Anderson Won Against OCR, But Agency’s Response—Including on Fines—Keeps Evolving: November 2022

Health Care Compliance Association (HCCA)
Contact

Health Care Compliance Association (HCCA)

Report on Patient Privacy Volume 22, Number 11. (November 2022)

Nearly five years passed from the time the University of Texas MD Anderson Cancer Center reported to the HHS Office for Civil Rights (OCR) that three breaches had occurred, until OCR—citing an inability to reach a voluntary settlement—moved to fine the Houston institution $4.348 million.

It would be another six years before a trio of Fifth Circuit Court of Appeals justices would tell OCR that its 2016 position, and previous administrative rulings upholding the fine, were “arbitrary, capricious, and otherwise unlawful.”,

MD Anderson and its attorneys were “thrilled that the Fifth Circuit agreed with our interpretation of the law,” attorney Scott McBride told RPP in a wide-ranging interview about the unique case. The litigation ended there because HHS officials didn’t appeal that January 2021 ruling, but “we would have been happy to go to the [Texas] Supreme Court if they wanted to,” said McBride, a partner in the Houston office of Morgan, Lewis & Bockius LLP.

Ultimately, MD Anderson owed the government nothing, although, of course, the case wasn’t free to pursue (more about that later). But it continues to pay dividends for other covered entities (CEs) and business associates (BAs) who now have a defined “path” to combat “overly aggressive” OCR enforcement of HIPAA regulations, said McBride.

The health care community also has MD Anderson to thank for at least a temporary tenfold reduction in civil money penalties (CMP). Just after its appeals were filed in April 2019, OCR issued a notice of enforcement discretion, acknowledging that the $1.5 million annual caps it had relied on—and which MD Anderson challenged as too high—were not appropriate under a new interpretation of the HITECH Act.

OCR set new maximums that would have reduced MD Anderson’s fine to $450,000; the agency promised to follow up with revised regulations.

Further, the circuit court reinterpreted significant issues related to encryption and impermissible disclosures, which CEs and BAs might not be aware of.

[View source.]

Written by:

Health Care Compliance Association (HCCA)
Contact
more
less

Health Care Compliance Association (HCCA) on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide