Med Mal 101: Back to Basics is 12-part series produced by Friday, Eldredge & Clark. Written by the attorneys in the Medical Malpractice Group, the content is designed to give physicians and other healthcare providers information they need to know about malpractice litigation.
The Health Insurance Portability and Accountability Act of 1996, (HIPAA) protects an individual’s personal health information (PHI) from unlawful disclosure. When served with a subpoena to provide medical records, a medical care provider must take care to properly honor the subpoena, while also avoiding unlawful disclosure of personal health information.
A subpoena alone may be insufficient to allow disclosure of PHI. Therefore, in most cases, a subpoena for medical records will also include a HIPAA compliant medical authorization signed by the patient. If a subpoena requests medical records and permission from the patient is not clear, it is best to contact an attorney prior to disclosure of records to ensure HIPAA compliance.
A HIPAA-covered provider may disclose information to a party issuing a subpoena only if the notification requirements of the Privacy Rule are met. Before responding to the subpoena, the provider or plan must receive “satisfactory assurances” that certain steps have been taken to protect the patient’s privacy.
Under the statute, a covered entity receives “satisfactory assurances” when the party issuing the subpoena provides a written statement and accompanying documentation demonstrating that:
The statute also describes what a qualified protective order requires. The protective order must have been issued by order of a court or of an administrative tribunal, or by stipulation of the parties to the litigation or administrative proceeding. A qualified protective order prohibits parties from using or disclosing protected health information for any purpose other than the litigation or proceeding for which such information was requested and requires the return to the covered entity or destruction of the protective health information, including all copies made, at the conclusion of the litigation or proceeding.
Next month, we will address the discovery process in medical malpractice cases.
 See 45 C.F.R. § 164.512(e).
 See 45 C.F.R. § 164.512(e); see also https://www.hhs.gov/hipaa/for-individuals/court-orders-subpoenas/index.html.
 See 45 C.F.R. § 164.512(e)(1)(iii).
 See 45 C.F.R. § 164.512(e)(1)(v).
 See 45 C.F.R. § 164.512(e)(1)(v)(A)-(B).
The information was written by the attorneys in the Medical Malpractice Group at Friday, Eldredge & Clark, LLP. This is not a substitute for legal advice and should be considered for general guidance only. For more information or if you have further questions, please contact one of our Medical Malpractice Attorneys.
The 12-month series will include the following topics:
- Part 1: How a Lawsuit Gets Started - Jan. 2019
- Part 2: Responding to a Complaint - Feb. 2019
- Part 3: The Legal Standard of Care in Arkansas - March 2019
- Part 4: Casusation - April 2019
- Part 5: Damages - May 2019
- Part 6: You Received a Subpoena - Now What? - June 2019
- Part 7: Subpoena and HIPAA - July 2019
- Information That is Shared About a Provider During a Lawsuit
- Depositions - What to Expect
- Motions, Settlements and Trial
- What to Expect at Trial
- The Appeals Process