Data privacy is a hot topic. We regularly speak on data privacy at Reed Smith’s annual California continuing legal education day, and it takes hours to prepare because the landscape changes so rapidly. The law changes day-by-day, both legislatively and in our courts, and entire emerging industries (e.g., the “apps” industry) are organized around the collection and monetization of personal information disclosing what we do, when we do it, for how long, and where we are located. The very definition of “privacy” is now robustly debated, which is a significant change from the days when everyone knew that “private” information meant name, date of birth, social security number, account numbers, or some combination thereof. Today if you asked 25 privacy professionals to define “private” information, you might get 25 answers, and some would say “everything.”
When we expanded our drug and medical device practice into the data privacy realm a few years ago (along with the co-author of this post, Reed Smith’s Joshua Marker, an outstanding privacy lawyer and active blogger in his own right), we found that the healthcare industry was, for the most part, ahead of the game because the rules were relatively clear. Everyone agreed that personal health information was private, and there was HIPAA, the ubiquitous federal law that has regulated the security and privacy of personal health information since enacted in 1996. Drug and medical device companies typically are not HIPAA-covered entities, but they often have possession of personal health information in connection with patients who use their products, and our experience is that our clients and the lawyers who represent them take patient privacy very seriously.
One thing that has not changed is that there is no private right of action under HIPAA. That does not mean, of course, that plaintiffs have not tried to sue over breaches of security involving their private information. A handful of cases have permitted state law claims supported in part by alleged HIPAA violations, pleaded as claims like “negligence per se.” And there are numerous state laws regulating medical information that have garnered more attention as data privacy has become front-page news.Continue Reading Privacy of Medical Information: No Harm, No Foul, No Private Right of Action