ALLcrimesfood&drugstaxestelecomcommercehealthconservationtransportationagricultureveteransbrowse all titles »
0

42 U.S.C. § 299b–22Privilege and confidentiality protections

submitted 82 years ago by Pub. L. 109-41 to r/title-42-THE-PUBLIC-HEALTH-AND-WELFARE · 1,802 words · no verdicts yet

in plain englishAI-generated · not legal advice

Patient safety work product is privileged and confidential, so it usually can't be subpoenaed or used as evidence. There are limited exceptions, like sharing it for patient safety work or, with court approval, in criminal cases. Providers who report in good faith are protected, and violators can face civil penalties.

(a) Privilege. Despite any other federal, state, or local law, and subject to subsection (c), patient safety work product is privileged. It cannot be: (1) Subpoenaed or ordered produced in a federal, state, or local civil, criminal, or administrative case, including disciplinary cases against a provider; (2) Discovered in such a case; (3) Disclosed under the Freedom of Information Act or a similar state or local law; (4) Used as evidence in a federal, state, or local government civil, criminal, rulemaking, or adjudicatory proceeding, including against a provider; or (5) Used in a professional disciplinary proceeding run by a state-authorized disciplinary body. (b) Confidentiality. Despite any other law, and subject to subsection (c), patient safety work product is confidential and cannot be disclosed. (c) Exceptions. Except as provided in (g)(3): (1) Exceptions from both privilege and confidentiality. Subsections (a) and (b) do not block: (A) Disclosing relevant work product for a criminal case — but only after a court privately reviews it and finds it contains evidence of a crime, is material to the case, and isn't reasonably available elsewhere. (B) Disclosing work product as needed to carry out subsection (f)(4)(A) (equitable relief for retaliation). (C) Disclosing identifiable work product if every provider named in it agrees. (2) Exceptions from confidentiality only. Subsection (b) does not block: (A) Disclosure to carry out patient safety activities. (B) Disclosure of nonidentifiable work product. (C) Disclosure to grantees, contractors, or others doing authorized research, evaluation, or demonstration projects — as far as HIPAA rules would allow disclosing protected health information for that purpose. (D) Disclosure by a provider to the FDA about a product or activity the FDA regulates. (E) Voluntary disclosure by a provider to its own accrediting body. (F) Disclosures the Secretary decides are needed for business operations and fit this part's goals. (G) Disclosure to law enforcement about a crime, or a suspected crime, if the discloser reasonably believes it's necessary for law enforcement. (H) For anyone other than a patient safety organization, disclosure of work product that does not judge the quality of care of an identifiable provider or describe an identifiable provider's actions or failures. (3) Exception from privilege only. Subsection (a) does not block voluntary disclosure of nonidentifiable work product. (d) Continued protection of information after disclosure (1) In general. Work product disclosed under (c) stays privileged and confidential; the disclosure is not a waiver, and the protections follow the work product even after someone else receives it. (2) Exception. Despite (1), and subject to (3): (A) If work product is disclosed in a criminal case, its confidentiality protection (not privilege) ends for that disclosed work product. (B) If work product is disclosed as nonidentifiable under (c)(2)(B), both its privilege and confidentiality protections end for that work product. (3) Construction. (2) does not end protection for any other patient safety work product besides what was actually disclosed. (4) Limitations on actions (A) Patient safety organizations. (i) A patient safety organization cannot be forced to disclose information it collected or developed under this part — whether or not it's patient safety work product — unless the information is identified, is not patient safety work product, and isn't reasonably available elsewhere. (ii) This limit does not apply to actions against a patient safety organization itself, or to disclosures under (c)(1). (B) Providers. An accrediting body cannot take accrediting action against a provider for good-faith participation in collecting, developing, reporting, or keeping patient safety work product under this part. It also cannot require a provider to reveal its communications with a patient safety organization. (e) Reporter protection (1) In general. A provider cannot take an adverse employment action against someone because that person, in good faith, reported information to the provider meaning to have it sent to a patient safety organization, or reported it directly to one. (2) Adverse employment action means: (A) Losing a job, not getting promoted, or losing any other job benefit the person would otherwise get; or (B) A negative decision about the person's accreditation, certification, credentialing, or licensing. (f) Enforcement (1) Civil monetary penalty. Subject to (2) and (3), anyone who knowingly or recklessly discloses identifiable patient safety work product in violation of (b) can be fined up to $10,000 per violation. (2) Procedure. The rules in section 1320a–7a (except subsections (a), (b), and the first sentence of (c)(1)) apply to these penalties the same way they apply under that section. (3) Relation to HIPAA. The same act or omission cannot be penalized under both this subsection and the HIPAA regulations issued under section 264(c)(1). (4) Equitable relief (A) In general. Any harmed individual may sue to stop conduct that violates subsection (e) and to get other fair relief — including getting their job back, back pay, and restored benefits. (B) Against State employees. A state or state agency cannot claim the privilege in subsection (a) unless it has already agreed to be sued under (A), and that agreement is still in effect. (g) Rule of construction. Nothing in this section: (1) Limits other federal, state, or local laws that give greater privilege or confidentiality than this section does; (2) Limits or changes the law's requirements for information that isn't privileged or confidential under this section; (3) Except as provided in (i), changes how the HIPAA confidentiality regulations or section 1320d–5 apply; (4) Limits any provider's, patient safety organization's, or other entity's power to make a contract requiring more confidentiality or letting someone else make a disclosure under this section; (5) Preempts or affects a state law requiring a provider to report information that isn't patient safety work product; or (6) Limits any requirement to report product or activity safety information to the FDA. (h) Clarification. Nothing in this part stops anyone from doing more analysis on the same or similar issues that were already reported to or assessed by a patient safety organization or evaluation system. (i) Clarification of application of HIPAA confidentiality regulations to patient safety organizations. Under the HIPAA confidentiality regulations: (1) Patient safety organizations count as "business associates"; and (2) Their patient safety activities involving a provider count as that provider's "health care operations." (j) Reports on strategies to improve patient safety (1) Draft report. No later than 18 months after any network of patient safety databases starts operating, the Secretary, with the Director, must write a draft report on effective strategies to reduce medical errors and improve patient safety, including any measures the Secretary thinks should encourage using them, including in federally funded programs. The Secretary must let the public comment on the draft and send it to the Institute of Medicine for review. (2) Final report. No later than 1 year after the date in (1), the Secretary must send Congress a final report.
the actual law source: uscode.house.gov ↗public domain
(a) Privilege

Notwithstanding any other provision of Federal, State, or local law, and subject to subsection (c), patient safety work product shall be privileged and shall not be—

(1)

subject to a Federal, State, or local civil, criminal, or administrative subpoena or order, including in a Federal, State, or local civil or administrative disciplinary proceeding against a provider;

(2)

subject to discovery in connection with a Federal, State, or local civil, criminal, or administrative proceeding, including in a Federal, State, or local civil or administrative disciplinary proceeding against a provider;

(3)

subject to disclosure pursuant to section 552 of title 5 (commonly known as the Freedom of Information Act) or any other similar Federal, State, or local law;

(4)

admitted as evidence in any Federal, State, or local governmental civil proceeding, criminal proceeding, administrative rulemaking proceeding, or administrative adjudicatory proceeding, including any such proceeding against a provider; or

(5)

admitted in a professional disciplinary proceeding of a professional disciplinary body established or specifically authorized under State law.

(b) Confidentiality of patient safety work product

Notwithstanding any other provision of Federal, State, or local law, and subject to subsection (c), patient safety work product shall be confidential and shall not be disclosed.

(c) Exceptions

Except as provided in subsection (g)(3)—

(1) Exceptions from privilege and confidentiality

Subsections (a) and (b) shall not apply to (and shall not be construed to prohibit) one or more of the following disclosures:

(A)

Disclosure of relevant patient safety work product for use in a criminal proceeding, but only after a court makes an in camera determination that such patient safety work product contains evidence of a criminal act and that such patient safety work product is material to the proceeding and not reasonably available from any other source.

(B)

Disclosure of patient safety work product to the extent required to carry out subsection (f)(4)(A).

(C)

Disclosure of identifiable patient safety work product if authorized by each provider identified in such work product.

(2) Exceptions from confidentiality

Subsection (b) shall not apply to (and shall not be construed to prohibit) one or more of the following disclosures:

(A)

Disclosure of patient safety work product to carry out patient safety activities.

(B)

Disclosure of nonidentifiable patient safety work product.

(C)

Disclosure of patient safety work product to grantees, contractors, or other entities carrying out research, evaluation, or demonstration projects authorized, funded, certified, or otherwise sanctioned by rule or other means by the Secretary, for the purpose of conducting research to the extent that disclosure of protected health information would be allowed for such purpose under the HIPAA confidentiality regulations.

(D)

Disclosure by a provider to the Food and Drug Administration with respect to a product or activity regulated by the Food and Drug Administration.

(E)

Voluntary disclosure of patient safety work product by a provider to an accrediting body that accredits that provider.

(F)

Disclosures that the Secretary may determine, by rule or other means, are necessary for business operations and are consistent with the goals of this part.

(G)

Disclosure of patient safety work product to law enforcement authorities relating to the commission of a crime (or to an event reasonably believed to be a crime) if the person making the disclosure believes, reasonably under the circumstances, that the patient safety work product that is disclosed is necessary for criminal law enforcement purposes.

(H)

With respect to a person other than a patient safety organization, the disclosure of patient safety work product that does not include materials that—

(i)

assess the quality of care of an identifiable provider; or

(ii)

describe or pertain to one or more actions or failures to act by an identifiable provider.

(3) Exception from privilege

Subsection (a) shall not apply to (and shall not be construed to prohibit) voluntary disclosure of nonidentifiable patient safety work product.

(d) Continued protection of information after disclosure
(1) In general

Patient safety work product that is disclosed under subsection (c) shall continue to be privileged and confidential as provided for in subsections (a) and (b), and such disclosure shall not be treated as a waiver of privilege or confidentiality, and the privileged and confidential nature of such work product shall also apply to such work product in the possession or control of a person to whom such work product was disclosed.

(2) Exception

Notwithstanding paragraph (1), and subject to paragraph (3)—

(A)

if patient safety work product is disclosed in a criminal proceeding, the confidentiality protections provided for in subsection (b) shall no longer apply to the work product so disclosed; and

(B)

if patient safety work product is disclosed as provided for in subsection (c)(2)(B) (relating to disclosure of nonidentifiable patient safety work product), the privilege and confidentiality protections provided for in subsections (a) and (b) shall no longer apply to such work product.

(3) Construction

Paragraph (2) shall not be construed as terminating or limiting the privilege or confidentiality protections provided for in subsection (a) or (b) with respect to patient safety work product other than the specific patient safety work product disclosed as provided for in subsection (c).

(4) Limitations on actions
(A) Patient safety organizations
(i) In general

A patient safety organization shall not be compelled to disclose information collected or developed under this part whether or not such information is patient safety work product unless such information is identified, is not patient safety work product, and is not reasonably available from another source.

(ii) Nonapplication

The limitation contained in clause (i) shall not apply in an action against a patient safety organization or with respect to disclosures pursuant to subsection (c)(1).

(B) Providers

An accrediting body shall not take an accrediting action against a provider based on the good faith participation of the provider in the collection, development, reporting, or maintenance of patient safety work product in accordance with this part. An accrediting body may not require a provider to reveal its communications with any patient safety organization established in accordance with this part.

(e) Reporter protection
(1) In general

A provider may not take an adverse employment action, as described in paragraph (2), against an individual based upon the fact that the individual in good faith reported information—

(A)

to the provider with the intention of having the information reported to a patient safety organization; or

(B)

directly to a patient safety organization.

(2) Adverse employment action

For purposes of this subsection, an “adverse employment action” includes—

(A)

loss of employment, the failure to promote an individual, or the failure to provide any other employment-related benefit for which the individual would otherwise be eligible; or

(B)

an adverse evaluation or decision made in relation to accreditation, certification, credentialing, or licensing of the individual.

(f) Enforcement
(1) Civil monetary penalty

Subject to paragraphs (2) and (3), a person who discloses identifiable patient safety work product in knowing or reckless violation of subsection (b) shall be subject to a civil monetary penalty of not more than $10,000 for each act constituting such violation.

(2) Procedure

The provisions of section 1320a–7a of this title, other than subsections (a) and (b) and the first sentence of subsection (c)(1), shall apply to civil money penalties under this subsection in the same manner as such provisions apply to a penalty or proceeding under section 1320a–7a of this title.

(3) Relation to HIPAA

Penalties shall not be imposed both under this subsection and under the regulations issued pursuant to section 264(c)(1) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note) for a single act or omission.

(4) Equitable relief
(A) In general

Without limiting remedies available to other parties, a civil action may be brought by any aggrieved individual to enjoin any act or practice that violates subsection (e) and to obtain other appropriate equitable relief (including reinstatement, back pay, and restoration of benefits) to redress such violation.

(B) Against State employees

An entity that is a State or an agency of a State government may not assert the privilege described in subsection (a) unless before the time of the assertion, the entity or, in the case of and with respect to an agency, the State has consented to be subject to an action described in subparagraph (A), and that consent has remained in effect.

(g) Rule of construction

Nothing in this section shall be construed—

(1)

to limit the application of other Federal, State, or local laws that provide greater privilege or confidentiality protections than the privilege and confidentiality protections provided for in this section;

(2)

to limit, alter, or affect the requirements of Federal, State, or local law pertaining to information that is not privileged or confidential under this section;

(3)

except as provided in subsection (i), to alter or affect the implementation of any provision of the HIPAA confidentiality regulations or section 1320d–5 of this title (or regulations promulgated under such section);

(4)

to limit the authority of any provider, patient safety organization, or other entity to enter into a contract requiring greater confidentiality or delegating authority to make a disclosure or use in accordance with this section;

(5)

as preempting or otherwise affecting any State law requiring a provider to report information that is not patient safety work product; or

(6)

to limit, alter, or affect any requirement for reporting to the Food and Drug Administration information regarding the safety of a product or activity regulated by the Food and Drug Administration.

(h) Clarification

Nothing in this part prohibits any person from conducting additional analysis for any purpose regardless of whether such additional analysis involves issues identical to or similar to those for which information was reported to or assessed by a patient safety organization or a patient safety evaluation system.

(i) Clarification of application of HIPAA confidentiality regulations to patient safety organizations

For purposes of applying the HIPAA confidentiality regulations—

(1)

patient safety organizations shall be treated as business associates; and

(2)

patient safety activities of such organizations in relation to a provider are deemed to be health care operations (as defined in such regulations) of the provider.

(j) Reports on strategies to improve patient safety
(1) Draft report

Not later than the date that is 18 months after any network of patient safety databases is operational, the Secretary, in consultation with the Director, shall prepare a draft report on effective strategies for reducing medical errors and increasing patient safety. The draft report shall include any measure determined appropriate by the Secretary to encourage the appropriate use of such strategies, including use in any federally funded programs. The Secretary shall make the draft report available for public comment and submit the draft report to the Institute of Medicine for review.

(2) Final report

Not later than 1 year after the date described in paragraph (1), the Secretary shall submit a final report to the Congress.

Source credit: (July 1, 1944, ch. 373, title IX, § 922, as added Pub. L. 109–41, § 2(a)(5), July 29, 2005, 119 Stat. 427.)

history & why it existsrecord from the source credit
  • 1944Enacted · Pub. L. 109-41 · 119 Stat. 427

A history note hasn’t been published yet. The record shows enactment by Pub. L. 109-41 on 1944-07-01.

all 0 arguments · sorted by: best

0/280

no arguments yet — make the first case