Welcome to the Sausage Factory

Nov. 9, 2011
Often new legislative trends in privacy and security law are driven by a single incident that grabs headlines.  And when a privacy incident directly

Often new legislative trends in privacy and security law are driven by a single incident that grabs headlines. And when a privacy incident directly touches lawmakers personally ... then expect a new privacy law.

For example, California's landmark security breach notification law came about in response to a high-profile breach involving a California state government database. Now, as I've discussed previously in this blog, there have been several much-publicized incidents involving hospital employees improperly accessing the medical records of public records and celebrities at Cedars-Sinai Medical Center and UCLA Medical Center.

Two new bills are making their way through the California legislature in response to these recent events, S.B. 541 and A.B. 211. The word around the hallways of Sacramento is that Governor Schwarzenegger has a strong personal interest in the passage of these measures because UCLA Medical Center employees improperly accessed his wife's medical records.

S.B. 541 creates a new administrative penalty for hospitals, home health agencies, hospices and licensed clinics that fail to "prevent unlawful or unauthorized access to, and use or disclosure of, patients' medical information."Â The penalty is $25,00 per patient, with a cap of $250,000 "per reported event."

Don't HIPAA and state medical privacy laws already prohibit this conduct? Yes, but not quite so specifically.  As they say, you don't want to know how sausage and law gets made.  It's not pretty and it's certainly not consistent, but this is how privacy law gets made in the U.S.

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...