
Trump Administration Executive Order (EO) Tracker
There has been a significant development in the ongoing debate regarding the scope of the authority of the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) to issue penalties under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). The U.S. Court of Appeals for the Fifth Circuit vacated, on January 14, 2021, a $4.3M civil monetary penalty imposed by the OCR for alleged violations of HIPAA’s Privacy and Security Rules. The court held that OCR’s decision to levy such penalties against the University of Texas M.D. Anderson Cancer Center (“MD Anderson”) in connection with three data breach incidents occurring in 2012 and 2013 was “arbitrary, capricious, and otherwise unlawful.” This decision may have a significant strategic impact in defending HIPAA investigations initiated by OCR, and OCR’s approach in using its enforcement authority.
Following an investigation stemming from a 2012 theft of an unencrypted laptop and the loss of two unencrypted flash drives in 2012 and 2013, OCR determined that MD Anderson failed to implement a mechanism to encrypt electronic PHI (“ePHI”) in violation of the HIPAA Security Rule and improperly disclosed ePHI in violation of the HIPAA Privacy Rule. As the parties did not reach a settlement (which is the more common means by which OCR procures payment from entities for alleged violations), OCR sought to impose civil monetary penalties totaling $4.3M under HIPAA’s tiered penalty scheme. Specifically, the agency assessed $1.3M for the lack of encryption and $3M ($1.5M per year) for the impermissible disclosures of ePHI. MD Anderson twice unsuccessfully challenged OCR’s decision in administrative proceedings before appealing to the Fifth Circuit Court of Appeals.
The Fifth Circuit agreed with MD Anderson that OCR “offered no lawful basis for its civil monetary penalties” and held that the agency’s fine ran afoul of the Administrative Procedure Act. The unanimous panel provided four independent reasons for its decision:
While the case has been remanded to the HHS Departmental Appeals Board for further proceedings, the Fifth Circuit’s published decision is an important ruling for organizations subject to HIPAA. Among other potential impacts, this ruling may affect: determinations as to whether an incident meets the definition of “breach” under HIPAA; how entities evaluate their compliance with Security Rule provisions; how entities defend against OCR allegations of HIPAA violations; and how OCR approaches future enforcement actions.
In light of this significant decision, and a new Administration, it will be critical to monitor developments in this case, as well as other guidance that may be released in light of the precedent set by the Fifth Circuit.
Authored by Marcy Wilder, Scott Loughlin, Paul Otto, Andrew Bank, and Madeline Gitomer.