A registered nurse has filed a class action lawsuit in the Southern District of New York claiming that certain provisions of the American Recovery and Reinvestment Act (“ARRA”) (the new stimulus legislation enacted in February) violate the privacy rules laid out in the Health Insurance Portability and Accountability Act (“HIPAA”) and the federal Privacy Act.
Beatrice Heghmann of Durham, North Carolina claims that, pursuant to ARRA, the White House Office of Health Reform is working with the Department of Health and Human Services (“HHS”) to design a new system that would create electronic health records for millions of Americans by 2014. According to Heghmann’s complaint, this planned system poses a major threat to individual privacy: she claims individuals’ personal health information (“PHI”) could be just a “mouse click away from being accessible to an intruder.”
Heghmann takes issue with ARRA’s provision allowing HHS to determine what constitutes the “minimum necessary” amount of PHI allowed to be disclosed under HIPAA, as well as how best to implement “de-identification” of protected information. According to Heghmann’s complaint, HHS Secretary Kathleen Sebelius is “empowered to totally vitiate the privacy provisions under HIPAA and link medical information contained in Plaintiff’s personal health record directly to Plaintiff and all others similarly situated.” Heghmann argues that the $22 billion earmarked for the electronic registry is merely a vehicle to obtain access to this confidential health care information.
Heghmann is seeking certification for a class of similarly situated individuals and is requesting an injunction to prevent the government from disbursing the $22 billion budgeted for the Electronic Health Records System.