(2007)

92 Op. Att'y Gen. 107
Procedural entryThis page is a short order in (2007). Read the opinion of the Court — 92 Op. Att'y Gen. 51
Maryland Attorney General Reports·Decided August 6, 2007·Published

Opinion

In your capacity as Chair of the Task Force to Study Electronic Health Records, you have requested our opinion on various questions related to the impact of the Maryland Medical Records Confidentiality Act, Title 4, Subtitle 3 of the Health-General Article ("HG"), Annotated Code of Maryland, on the design and operation of a statewide health information exchange ("HIE") mechanism. An HIE, in brief, enables the electronic transmission of clinical and payment information about a patient among participating health care providers and payers.

Your specific questions are as follows:

1. Does the Medical Records Confidentiality Act prohibit creation of an HIE?

2. Assuming that the Act does not prohibit creation of an HIE, does it mandate or prohibit particular aspects of an HIE's design or operation?

3. Does the Act require explicit patient consent for his or her medical records to become part of the HIE, or may these records be included without consent?

4. If routine exchanges of medical records may occur among HIE collaborators without patient consent, does a patient nevertheless have a right under the Act to "opt out" of the HIE — that is, insist that all or part of his or her medical records be excluded from the HIE?

5 In what respects does the Act require information about mental health services to be handled differently from other medical records?

For the reasons stated below, we conclude as follows:

1. The Medical Records Confidentiality Act does not prohibit creation of an HIE.

2. The Act mandates that collaborators in the HIE enter contractual obligations regarding the security and redisclosure of medical records, so that all access to the records within the HIE is for legally recognized purposes and redisclosure outside the HIE is prohibited.

3. If a patient's medical records are to become part of an HIE as a consequence of the provider's participation in the HIE, this fact should be disclosed to the patient as part of the informed consent process preceding the rendering of services, so that the patient may weigh this factor in deciding whether to receive services from the provider. However, the "authorization" specified in the Act, which goes beyond common law consent, is not required for a patient's medical records to become part of the HIE, so long as the transmission of medical records is solely for the purposes of health care for the patient, payment for that care, or the other objectives specified in HG § 4-3051 and so long as suitable administrative and technical safeguards are in place to prevent improper access to or use of the records.2

4. A patient does not have a right under the Act to "opt out" of an HIE — to receive services from a health care provider while insisting that the medical records related to that service be excluded from the HIE.

5. To the extent that medical records pertaining to mental health services are included in the HIE, the Act requires special procedures to ensure limited access.

Most participants in an HIE would be subject to federal law on the confidentiality of medical records, particularly the Privacy Rule issued by the Department of Health and Human Services to implement the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Your request, however, does not ask us to address HIPAA issues.3 In addition, to the extent that the HIE includes the medical records of patients in alcohol abuse and drug abuse treatment programs, disclosure and use of these records would be governed by the federal regulations on confidentiality of alcohol and drug abuse patient records.42 CFR Part 2. These federal regulations are incorporated by reference into Maryland law. See HG § 8-601(c).

I
Purpose and Nature of a Health Information Exchange
It has become apparent that advances in information technology offer a variety of benefits for health care. "[F]ragmented, disorganized, and inaccessible clinical information adversely affects the quality of health care and compromises patient safety. . . . The expanded use of health [information technology] has great potential to improve the quality of care, bolster the preparedness of our public health infrastructure, and save money on administrative costs." Government Accountability Office, Health Information Technology: Early EffortsInitiated But Comprehensive Privacy Approach Needed for NationalStrategy, GAO Report 07-238, at 6 (January 2007).

Making patient information portable is seen as part of the overall solution. Achieving that portability can be realized via several mechanisms; an HIE is one approach. An HIE is a utility that allows for "provider-centric" patient information (generated as a result of a specific encounter between a patient and a health care provider and maintained by the provider) to be made visible and available in a "patient-centric" manner (available to any provider that a patient sees, regardless of where and when the information was generated). An HIE is based upon common standards and other design features that enable "interoperability" — the ability of the system's components to exchange patient information so that it can be readily used. See Office of the National Coordinator for Health Information Technology, Goals of Strategic Framework, available atwww.hhs.gov/healthit/goals.html (last accessed June 14, 2007).

A recent federal study identified 101 state-based HIE projects in 35 different states. Agency for Healthcare Research and Quality,Evolution of State Health Information Exchange: A Study of Vision,Strategy, and Progress 4 (January 2006). This study observed that, although these projects "share similar goals to improve quality health care and reduce costs," they "vary tremendously with respect to engaged stakeholders, available funding, community history, selected technology, and implementation strategy. This variation is particularly true for the infrastructure components selected to enable information sharing."Id. at 1.

Key issues about the design and operation of a statewide HIE in Maryland are unresolved. Indeed, making recommendations on this point is one of the assignments of the Task Force. Chapter 291, Laws of Maryland 2005. Based on the experience in other states, we can assume that, were an HIE to be established, participants would include hospitals, physicians and other health care professionals, laboratories, pharmacies, and payers of various kinds. It is unlikely, we gather, that an HIE would entail the aggregation of medical records into a single database. Instead, the HIE would probably involve a central locator, which is an electronic index showing which providers have information about a particular patient, and a protocol by which the information could be accessed once its location had been identified. One or more contractors would undoubtedly be necessary to operate the exchange and its component technology.

II
Scope and Purpose of Medical Records Confidentiality Act
Maryland's Medical Records Confidentiality Act, enacted in 1990, long predated the HIPAA Privacy Rule and is generally not preempted by it.4

Free access — add to your briefcase to read the full text and ask questions with AI

(2007), 92 Op. Att'y Gen. 107 (Md. 2007).

92 Op. Att'y Gen. 107 ((2007)) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Acosta v. Cary
365 So. 2d 4 (Louisiana Court of Appeal, 1978)
Lemon v. Stewart
682 A.2d 1177 (Court of Special Appeals of Maryland, 1996)
Shady Grove Psychiatric Group v. State
736 A.2d 1168 (Court of Special Appeals of Maryland, 1999)
Suesbury v. Caceres
840 A.2d 1285 (District of Columbia Court of Appeals, 2004)
Warner v. Lerner
705 A.2d 1169 (Court of Appeals of Maryland, 1998)