SP0414
LD 1337
PUBLIC Law, Chapter 373

Signed on 2011-06-16 00:00:00.0 - First Regular Session - 125th Maine Legislature
 
 
Bill Tracking, Additional Documents Chamber Status

An Act To Ensure Patient Privacy and Control with Regard to Health Information Exchanges

Be it enacted by the People of the State of Maine as follows:

Sec. 1. 22 MRSA §1711-C, sub-§7,  as amended by PL 1999, c. 512, Pt. A, §5 and affected by §7, is further amended to read:

7. Confidentiality policies.   A health care practitioner or , facility or state-designated statewide health information exchange shall develop and implement policies, standards and procedures to protect the confidentiality, security and integrity of health care information to ensure that information is not negligently, inappropriately or unlawfully disclosed. The policies of health care facilities must provide that an individual being admitted for inpatient care be given notice of the right of the individual to control the disclosure of health care information. The policies must provide that routine admission forms include clear written notice of the individual's ability to direct that that individual's name be removed from the directory listing of persons cared for at the facility and notice that removal may result in the inability of the facility to direct visitors and telephone calls to the individual.

Sec. 2. 22 MRSA §1711-C, sub-§8,  as enacted by PL 1997, c. 793, Pt. A, §8 and affected by §10, is amended to read:

8. Prohibited disclosure.   A health care practitioner or , facility or state-designated statewide health information exchange may not disclose health care information for the purpose of marketing or sales without written or oral authorization for the disclosure.

Sec. 3. 22 MRSA §1711-C, sub-§18  is enacted to read:

18 Participation in a state-designated statewide health information exchange.   The following provisions apply to participation in a state-designated statewide health information exchange.
A A health care practitioner may not deny a patient health care treatment and a health insurer may not deny a patient a health insurance benefit based solely on the provider's or patient's decision not to participate in a state-designated statewide health information exchange. Except when otherwise required by federal law, a payor of health care benefits may not require participation in a state-designated statewide health information exchange as a condition of participating in the payor's provider network.
B Recovery for professional negligence is not allowed against any health care practitioner or health care facility on the grounds of a health care practitioner's or a health care facility's nonparticipation in a state-designated statewide health information exchange arising out of or in connection with the provision of or failure to provide health care services. In any civil action for professional negligence or in any proceeding related to such a civil action or in any arbitration, proof of a health care practitioner's, a health care facility's or a patient's participation or nonparticipation in a state-designated statewide health information exchange is inadmissible as evidence of liability or nonliability arising out of or in connection with the provision of or failure to provide health care services. This paragraph does not prohibit recovery or the admission of evidence of reliance on information in a state-designated statewide electronic health information exchange when there was participation by both the patient and the patient's health care practitioner.
C A state-designated statewide health information exchange to which health care information is disclosed under this section shall provide an individual protection mechanism by which an individual may opt out from participation to prohibit the state-designated statewide health information exchange from disclosing the individual's health care information to a health care practitioner or health care facility.
D At point of initial contact, a health care practitioner, health care facility or other entity participating in a state-designated statewide health information exchange shall provide to each patient, on a separate form, at minimum:

(1) Information about the state-designated statewide health information exchange, including a description of benefits and risks of participation in the state-designated statewide health information exchange;

(2) A description of how and where to obtain more information about or contact the state-designated statewide health information exchange;

(3) An opportunity for the patient to decline participation in the state-designated statewide health information exchange; and

(4) A declaration that a health care practitioner, health care facility or other entity may not deny a patient health care treatment based solely on the provider's or patient's decision not to participate in a state-designated statewide health information exchange.

The state-designated statewide health information exchange shall develop the form for use under this paragraph, with input from consumers and providers. The form must be approved by the office of the state coordinator for health information technology within the Governor's office of health policy and finance.

E A health care practitioner, health care facility or other entity participating in a state-designated statewide health information exchange shall communicate to the exchange the decision of each patient who has declined participation and shall do so within a reasonable time frame, but not more than 2 business days following the receipt of a signed form, as described in paragraph D, from the patient, or shall establish a mechanism by which the patient may decline participation in the state-designated statewide health information exchange at no cost to the patient.
F A state-designated statewide health information exchange shall process the request of a patient who has decided not to participate in the state-designated statewide health information exchange within 2 business days of receiving the patient's decision to decline, unless additional time is needed to verify the identity of the patient. A signed authorization from the patient is required before a patient is newly entered or reentered into the system if the patient chooses to begin participation at a later date.

Except as otherwise required by applicable law, regulation or rule or state or federal contract, or when the state-designated statewide health information exchange is acting as the agent of a health care practitioner, health care facility or other entity, the state-designated statewide health information exchange shall remove health information of individuals who have declined participation in the exchange. In no event may health information retained in the state-designated statewide health information exchange as set forth in this paragraph be made available to health care practitioners, health care facilities or other entities except as otherwise required by applicable law, regulation or rule or state or federal contract, or when the health care practitioner, health care facility or other entity is the originator of the information.

G A state-designated statewide health information exchange shall establish a secure website accessible to patients. This website must:

(1) Permit a patient to request a report of who has accessed that patient's records and when the access occurred. This report must be delivered to the patient within 2 business days upon verification of the patient's identity by the state-designated statewide health information exchange;

(2) Provide a mechanism for a patient to decline participation in the state-designated statewide health information exchange; and

(3) Provide a mechanism for the patient to consent to participation in the state-designated statewide health information exchange if the patient had previously declined participation.

H A state-designated statewide health information exchange shall establish for patients an alternate procedure to that provided for in paragraph F that does not require Internet access. A health care practitioner, health care facility or other entity participating in the state-designated statewide health information exchange shall provide information about this alternate procedure to all patients. The information must be included on the form identified in paragraph D.
I A state-designated statewide health information exchange shall maintain records regarding all disclosures of health care information by and through the state-designated statewide health information exchange, including the requesting party and the dates and times of the requests and disclosures.
J A state-designated statewide health information exchange may not charge a patient or an authorized representative of a patient any fee for access or communication as provided in this subsection.
K Notwithstanding any provision of this subsection to the contrary, a health care practitioner, health care facility or other entity shall provide the form and communication required by paragraphs D and F to all existing patients following the effective date of this subsection.
L A state-designated statewide health information exchange shall meet or exceed all applicable federal laws and regulations pertaining to privacy, security and breach notification regarding personally identifiable protected health information, as defined in 45 Code of Federal Regulations, Part 160. If a breach occurs, the state-designated statewide health information exchange shall arrange with its participants for notification of each individual whose protected health information has been, or is reasonably believed by the exchange to have been, breached. For purposes of this paragraph, "breach" has the same meaning as in 45 Code of Federal Regulations, Part 164, as amended.
M The state-designated statewide health information exchange shall develop a quality management plan, including auditing mechanisms, in consultation with the office of the state coordinator for health information technology within the department, who shall review the plan and results.

Sec. 4. 22 MRSA §1711-C, sub-§20  is enacted to read:

20 Exemption from freedom of access laws.   Except as provided in this section, the names and other identifying information of individuals in a state-designated statewide health information exchange are confidential and are exempt from the provisions of Title 1, chapter 13.

Sec. 5. Report. A state-designated statewide health information exchange under the Maine Revised Statutes, Title 22, section 1711-C shall by January 1, 2012 present a progress report to the office of the state coordinator for health information technology within the Department of Health and Human Services. The report must include the projected implementation date for the secure website required under Title 22, section 1711-C.

Effective 90 days following adjournment of the 125th Legislature, First Regular Session, unless otherwise indicated.


Top of Page