The U.S. Division of Well being and Human Providers (HHS) and the Substance Abuse and Psychological Well being Providers Administration (SAMHSA) just lately launched the lengthy anticipated Ultimate Rule to revise the Confidentiality of Substance Use Dysfunction (SUD) Affected person Data rules at 42 C.F.R. Half 2 (Half 2).
In March 2020, the Coronavirus Help, Aid, and Financial Safety (CARES) Act § 3221 referred to as for the alignment of sure Half 2 confidentiality protocols with HIPAA and HITECH Act necessities. The Ultimate Rule implements these standardizations with the targets of enhancing care coordination and reducing the burden on lined entities and enterprise associates, whereas safeguarding the confidentiality of SUD information.
As a fast refresher, Half 2 serves to guard SUD information created by federally assisted packages.[1] These confidentiality protections had been initially enacted to assist tackle issues round the usage of SUD info in prison proceedings, employment and housing discriminatory practices, baby custody hearings, and different administrative issues. Suppliers topic to Half 2 are usually prohibited from disclosing any info that will establish an individual as having or having had a SUD with out the individual’s consent.
As a result of Half 2 rules had been applied in 1975, over 20 years earlier than the implementation of HIPAA, suppliers have traditionally struggled to adjust to each legal guidelines. Particularly, suppliers topic to HIPAA had been additionally required to adjust to Half 2 for SUD information, which compelled these suppliers to adjust to typically inconsistent requirements for several types of well being info. Naturally, the presence of two competing requirements brought on confusion, elevated administrative burdens, and infrequently obstructed supplier entry to affected person info. The Ultimate Rule contains a number of adjustments to align Half 2 extra intently with HIPAA and to scale back these administrative burdens, as summarized beneath:
- Affected person Consent. Sufferers can now present a single consent to authorize all future makes use of and disclosures associated to remedy, cost, and well being care operations (TPO), as an alternative of requiring a brand new consent for every disclosure. A consent will stay efficient except it’s revoked by the affected person.
- Enhanced Protections for Counseling Session Notes. Parallel to HIPAA protections for psychotherapists’ notes, clinicians’ notes from SUD counseling classes should be maintained individually from different affected person information, and require particular affected person consent to reveal. Thus, if a affected person offers a common TPO consent, the counseling session notes will fall outdoors the scope of that consent and won’t be disclosed.
- Breach Notification. Breaches of Half 2 information shall be topic to the identical affected person notification necessities of the HIPAA Breach Notification Rule.
- Penalties. Violations of Half 2 will now be topic to the identical civil and prison enforcement authorities that apply to HIPAA violations.
- Affected person Complaints. Along with or in lieu of submitting a criticism for an alleged violation underneath the Half 2 program, sufferers can select to file a criticism immediately with the HHS Secretary. Additional, sufferers can request a listing of all disclosures made with consent for the previous 3 years.[2]
- Public Well being Authority Disclosure. De-identified information could be disclosed to public well being authorities with out affected person consent, in accordance with the HIPAA Privateness Rule.
- Investigations Secure Harbor. People working for investigative businesses that unlawfully receive a confidential Half 2 file with out the requisite court docket order can have restricted civil and prison legal responsibility, as long as the person acted with “affordable diligence” in evaluating whether or not the supplier is topic to Half 2 prior to creating the file request.
- Flexibility on Redisclosures. HIPAA regulated entities might redisclose SUD information acquired pursuant to a TPO authorization in a fashion in line with the HIPAA Privateness Rule, decreasing the necessity for segregating or segmenting SUD information from different PHI in every day operations.
The Ultimate Rule takes impact on April 16, 2024 and entities should guarantee full compliance by February 16, 2026. For extra info on the Ultimate Rule, see the HHS Ultimate Rule Reality Sheet. The Reality Sheet signifies that OCR plans to finalize adjustments to the HIPAA Discover of Privateness Practices to deal with makes use of and disclosures of PHI which can be additionally protected by Half 2. Moreover, HHS shall be growing steering on compliance with the brand new Half 2 necessities.
We encourage federally assisted packages and suppliers topic to Half 2 to start reviewing and updating compliance insurance policies and procedures, affected person consents, affected person notices, and contractual agreements to adjust to the adjustments underneath the Ultimate Rule. Suppliers with questions or searching for counsel can contact any member of our Healthcare Group for help.
FOOTNOTES
[1] See 42 U.S.C. § 290dd-2(a).
[2] This provision is tolled till the HIPAA accounting provision at 45 C.F.R. § 164.528 is revised.