
Selling patient data without authorization can be a HIPAA crime
HIPAA treats paid third-party access to patient records as marketing. Without a separate signed authorization, it can carry criminal penalties.
Most people would agree that there is an expectation of privacy when a patient walks into an exam room that extends beyond the clinical encounter to maintaining confidentiality, integrity and availability of an individual’s medical record. This concept pre-dates the Health Insurance Portability and Accountability Act of 1996 (HIPAA). In fact, the United States Supreme Court in UNION PAC. RY. CO. v. BOTSFORD, 141 U.S. 250 (May 25, 1891) held that “[n]o right is more sacred, or is more carefully guarded, by the common law, than the right of every individual to the possession and control of his own person.”
What do privacy and confidentiality mean in the context of HIPAA? First, the Privacy Rule is something that most people are aware of because upon entering a provider’s care, we are required to read the
Patients or their legal surrogate decision maker, also execute the requisite HIPAA Authorization Form. An important nuance – under the Privacy Rule, “consent” is different than “authorization.” As the U.S. Department of Health and Human Services
By way of contrast, “authorization” connotes the “require[ment] by the Privacy Rule for uses and disclosures of protected health information not otherwise allowed by the Rule. Where the Privacy Rule requires patient authorization, voluntary consent is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization. An authorization is a detailed document that gives covered entities permission to use protected health information for specified purposes, which are generally other than treatment, payment, or health care operations, or to disclose protected health information to a third party specified by the individual.”
This brings us to a scenario that is not uncommon – the physician or other provider has a remunerative arrangement with a third party (e.g., pharmaceutical company clinical trial or consulting arrangement with a medical device company) where the third party wants access to the electronic medical records and patient schedule to determine what patient may be a candidate for a clinical trial or procedure involving a medical device. Unfortunately, this conduct treads into illegal marketing and sale of the patient’s protected health information.
“
This type of conduct, if appropriate patient authorization is not obtained, can also result in criminal HIPAA violations. As the
- Between November 2017 and December 2020, Harvey paid Kirby Dandridge, 38, Sylvia Taylor, 43, Kara Thompson, 30, Melanie Russell, 41, and Adrianna Taber, 26, to provide him with names and phone numbers of Methodist patients who had been involved in motor vehicle accidents. After obtaining the information, Harvey sold the information to third persons including personal injury attorneys and chiropractors.
- The conspiracy charge carries a maximum penalty of five years imprisonment, a fine of $250,000 and three-year period of supervised release.
- Harvey was also charged with seven counts of obtaining patient information with the intent to sell it for financial gain on various dates between November 12, 2017, and September 7, 2019. Each of those charges carries a maximum penalty of 10 years’ imprisonment, a fine of $250,000 and three years’ of supervised release.
- Dandridge, Taylor, Thompson, Russell, and Taber were each charged with separate violations of disclosing the information to Harvey in violation of HIPAA. That charge carries a maximum penalty of one year imprisonment, a $50,000 fine and a one-year period of supervised release.
In sum, the sales and marketing of PHI without the requisite patient authorization is both violative of the fundamental trust that should exist between a provider and a patient and can also lead to criminal liability. Making sure that appropriate safeguards are in place and that patients are fully informed before signing a separate Authorization Form are two steps to mitigate risk.





