Does HIPAA stop Tennessee from releasing legislators' health insurance enrollment and premium data in response to a public records request?
Apply this to your situation
This page answers the general question as of 2015. Ezel answers yours: what it means for your facts, under current Tennessee law, with citations.
Subject
Opinion No. 15-48, Release of Health Insurance Information for Members of the Tennessee General Assembly, June 5, 2015
Plain-English summary
Citizens used Tennessee's Public Records Act to request a detailed accounting of state-funded health insurance for current and former legislators dating back to 1992: who was enrolled in what year, what level of coverage they had, how much each member paid in premiums, how much the State paid in premiums, and aggregate claims paid for all members between 2010 and 2014. The state released the data. Two state representatives asked the AG whether the release violated the federal HIPAA Privacy Rule.
The AG said no. He worked through the analysis in layers. First, it was not clear the released data even qualified as "protected health information" (PHI) in the first place. The aggregate claims figure was not tied to any individual, and merely identifying who participated in a state-funded health insurance plan does not necessarily reveal anything about anyone's health. Second, even if the information were PHI disclosed by a HIPAA-covered entity, the Privacy Rule has an explicit exception at 45 C.F.R. § 164.512(a)(1) for disclosures "required by law." The Tennessee Public Records Act's mandate that public records be open for inspection qualifies as a law that "requires" disclosure. The federal Department of Health and Human Services has published guidance saying exactly that: state public records laws that mandate disclosure satisfy the "required by law" exception, and a covered entity may release PHI in response to such a request as long as the disclosure complies with the public records law's requirements.
Currency note
This opinion was issued in 2015. Subsequent statutory amendments, court decisions, or later AG opinions may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Common questions
Why was this even controversial?
HIPAA is famous for restricting disclosure of personal health information, and any release of data tied to a named individual's health insurance can feel like it implicates HIPAA. The opinion was prompted by political tension over disclosure of legislators' state-paid benefits.
What's the "required by law" exception?
45 C.F.R. § 164.512(a)(1) says a covered entity may use or disclose PHI to the extent the use or disclosure is required by law and complies with the relevant requirements of that law. "Required by law" covers state statutes that mandate disclosure, including public records laws.
Is enrollment in a health insurance plan really "PHI"?
Often not. PHI requires that the information relate to the past, present, or future physical or mental health of an individual, or to health care provided or paid for. Merely listing who was enrolled in a benefits plan (and at what coverage level) does not necessarily relate to any individual's health condition. As the AG pointed out, federal law required nearly every American to have health insurance in 2015, so the fact of enrollment itself reveals very little.
What about the aggregate claims figure?
That figure was a multi-year lump sum across all members of the legislature combined. It was not identifiable with any specific person and therefore was not PHI even under a broad reading.
Could a state agency refuse a Public Records Act request by citing HIPAA?
Per this opinion, no, at least not as a categorical defense. Where state law mandates disclosure, HIPAA permits the disclosure. The covered entity must still comply with the public records law's own scope and limitations.
What's the broader takeaway?
State public records laws and HIPAA are not in inherent conflict. HIPAA defers to "required by law" disclosures, including state open-records statutes. Agencies subject to both regimes should apply HIPAA's exceptions consistently with the state-law disclosure mandate.
Background and statutory framework
The Tennessee Public Records Act (Tenn. Code Ann. §§ 10-7-503 through 10-7-506) creates a strong presumption that "[a]ll state, county and municipal records shall, at all times during business hours, be open for personal inspection by any citizen of this state . . . unless otherwise provided by state law." Tenn. Code Ann. § 10-7-503(a)(2)(A). Schneider v. City of Jackson, 226 S.W.3d 332, 339-40 (Tenn. 2007), confirms the Act creates "a presumption of openness and express[es] a clear legislative mandate favoring disclosure of governmental records." The Act defines "public record" and "state record" broadly to include all material "regardless of physical form or characteristics made or received pursuant to law or ordinance or in connection with the transaction of official business by any governmental agency." Tenn. Code Ann. § 10-7-301(6).
Tennessee's confidentiality exception for medical records, Tenn. Code Ann. § 10-7-504(a)(1), shields "medical records of patients in state, county and municipal hospitals" and persons receiving care at public expense. As defined by Tenn. Code Ann. § 63-2-101(c)(4), medical records include histories, reports, diagnoses, treatment records, X-rays, and the like. Insurance enrollment data is not within that category.
The HIPAA Privacy Rule, 45 C.F.R. Part 160 and Subparts A and E of Part 164, generally restricts a "covered entity" from disclosing PHI. PHI is defined at 45 C.F.R. § 160.103 as information that relates to an individual's health or care, plus identifies that individual. The Privacy Rule contains an exception at 45 C.F.R. § 164.512(a)(1) permitting disclosure required by law. HHS guidance addresses this exact intersection with state open-records laws and concludes the rule permits disclosure when state public records law mandates it.
Citations
- Tenn. Code Ann. §§ 10-7-503 through 10-7-506 (Public Records Act)
- Tenn. Code Ann. § 10-7-503(a)(2)(A) (presumption of openness)
- Tenn. Code Ann. § 10-7-301(6) (broad definition of public record)
- Tenn. Code Ann. § 10-7-504(a)(1) (medical records confidentiality)
- Tenn. Code Ann. § 63-2-101(c)(4) (definition of medical records)
- 45 C.F.R. § 160.103 (definition of PHI)
- 45 C.F.R. § 164.512(a)(1) (required-by-law exception)
- Schneider v. City of Jackson, 226 S.W.3d 332 (Tenn. 2007)
Source
- Landing page: https://www.tn.gov/attorneygeneral/opinions.html
- Original PDF: https://www.tn.gov/content/dam/tn/attorneygeneral/documents/ops/2015/op15-48.pdf
Original opinion text
June 5, 2015
Opinion No. 15-48
Release of Health Insurance Information for Members of the Tennessee General Assembly
Question
Is it a violation of the Privacy Rule of the federal Health Insurance Portability and Accountability Act (HIPAA) to release the following information in response to requests made pursuant to Tennessee's Public Records Act:
(i) the names of current and former members of the Tennessee General Assembly who, since 1992, have or have had health care insurance coverage under the State health insurance plan;
(ii) the years in which each current and former member participated in the plan and the level of coverage (i.e., single, single split, family, family split) in each year;
(iii) the amount each current and former member paid in premiums for each year of participation in the plan and the aggregate total amount of premium payments paid by each current and former member for all the years of his or her participation;
(iv) the aggregate total amount of premiums paid by all members combined for the period 1992-2007 and for the period 2008-2014;
(v) the amount contributed by the State towards each member's premium payment for each year of participation in the plan and the aggregate total amount contributed by the State for all member premiums combined for those same years;
(vi) the aggregate total amount of premiums for all members combined paid by the State for the period 1992-2007 and for the period 2008-2014;
(vii) the amount of the May 2015 premium payments (member and State combined) for former members; and
(viii) the aggregate total amount paid in claims for all members combined for the period 2010-2014.
Opinion
No. The release of the information in response to requests made under Tennessee's Public Records Act does not violate the HIPAA Privacy Rule.
ANALYSIS
The information listed in items (i) through (viii) above in the Question (collectively "the information") was released in response to requests made pursuant to Tennessee's Public Records Act, Tenn. Code Ann. §§ 10-7-503 through 10-7-506. In sum and substance, the information released identifies by name each current and former Tennessee legislator who had health care insurance coverage under the State plan between 1992 and 2015, the level of coverage, how much each member paid in premiums for each year of coverage and in the aggregate for certain periods, and how much the State contributed towards each member's premium payments for each year of coverage and in the aggregate for certain periods. Also released, as a lump-sum figure, was the total amount paid in claims for all the members combined for the years 2010 through 2014.
Tennessee's Public Records Act mandates that "[a]ll state, county and municipal records shall . . . be open for inspection by any citizen of this state." Tenn. Code Ann. § 10-7-503(a)(2)(A). Those in charge of the records may not refuse any citizen the right of inspection, unless otherwise provided by state law. Id.
The Public Records Act covers all records created or received by government in its official capacity and it "create[s] a presumption of openness and express[es] a clear legislative mandate favoring disclosure of governmental records." Schneider v. City of Jackson, 226 S.W.3d 332, 339-40 (Tenn. 2007). The Act broadly defines "public record" and "state record" to include "all documents, papers, letters, maps, books, photographs, microfilms, electronic data processing files and output, films, sound recordings, or other material, regardless of physical form or characteristics made or received pursuant to law or ordinance or in connection with the transaction of official business by any governmental agency." Tenn. Code Ann. § 10-7-301(6).
The information released comes within the Act's definition of "state record." It was made or received by the State as part of its official business, particularly as the employer of the members of the General Assembly. The request for the information was made by citizens of Tennessee. The State was, therefore, required to make the information open for inspection, and those in charge of the records were required to make them available since state law does not provide otherwise.
The HIPAA Privacy Rule generally prohibits a "covered entity" from using or disclosing "protected health information." 45 C.F.R. Part 160 and Subparts A and E of Part 164 (2013). For purposes of this Opinion only we will assume that the information was disclosed by a covered entity.
If information being disclosed is not "protected health information" (PHI) as defined in the Privacy Rule, there can be no HIPAA violation, since the Privacy Rule applies only to PHI. The Privacy Rule defines "protected health information" in essence as health information (1) that (a) relates to the past, present, or future physical or mental health or condition of an individual, or (b) relates to the provision of health care to an individual, or (c) relates to the past, present, or future payment for the provision of health care to an individual, and (2) that identifies the individual (or would allow the individual to be identified). 45 C.F.R. § 160.103 (2013). PHI does not include a covered entity's own employment records. Id.
It is not by any means a given that the information actually is PHI within that definition. The information released does not correlate to the health or condition of any individually identifiable person. Nor does it correlate to payment for the provision of health care to any identifiable individual; the claims-paid amount is not individually identifiable with any person since it is just one lump-sum total for all claims paid for all members combined during a multi-year period. Moreover, the mere fact that any individual member or his or her family members participated in the State's health insurance program cannot reasonably be deemed PHI, especially now when federal law requires every individual to have health care insurance coverage. We will, nevertheless, also assume—solely for purposes of this Opinion—that the information is "protected health information" as that term is defined by the Privacy Rule.
Even assuming that the information was disclosed by a covered entity and even assuming that the information is PHI, there is no violation of the HIPAA Privacy Rule. The Privacy Rule contains exceptions. As specifically applicable here, the Privacy Rule includes an exception that allows the disclosure of PHI when disclosure is "required by law."
A covered entity may use or disclose protected health information to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law.
45 C.F.R. § 164.512(a)(1) (2013).
Accordingly, when Tennessee's Public Records Act requires a covered entity to disclose PHI, the covered entity is permitted under HIPAA's Privacy Rule to make the disclosure without running afoul of HIPAA as long as the disclosure complies with the Public Records Act. Disclosure of the information was, in this case, required by the Public Records Act. Therefore, regardless of whether the information is PHI, its release, in response to a Public Records Act request, does not violate the Privacy Rule.
The U.S. Department of Health & Human Services (HHS), the agency charged with promulgating and administering the Privacy Rule, publishes answers to "frequently asked questions" to serve as guidance for complying with the Privacy Rule. HHS has in fact provided such guidance on the very question that is the subject of this Opinion. The following question and answer, quoted in relevant part (with emphasis added), are posted on the HHS website:
Question:
State public records laws, also known as open records or freedom of information laws, all provide for certain public access to government records. How does the HIPAA Privacy Rule relate to these state laws?
Answer:
. . . If a state agency is a covered entity . . . the Privacy Rule applies to its disclosures of protected health information. The Privacy Rule permits a covered entity to use and disclose protected health information as required by other law, including state law. See 45 CFR 164.512(a). Thus, where a state public records law mandates that a covered entity disclose protected health information, the covered entity is permitted by the Privacy Rule to make the disclosure, provided the disclosure complies with and is limited to the relevant requirements of the public records law.
The guidance provided by HHS pertains here and fully supports the conclusion that disclosure of the information does not violate the HIPAA Privacy Rule. There is no HIPAA violation when disclosure of information, even protected health information, is required by state law. Disclosure of the information at issue was made in response to a request for access to that information under Tennessee's Public Records Act. The Public Records Act mandates that the information be disclosed. Therefore, release of the information was "required by law." Because the release of the information was required by state law, its disclosure is permitted by the Privacy Rule and does not violate HIPAA.
HERBERT H. SLATERY III
Attorney General and Reporter
ANDRÉE SOPHIA BLUMSTEIN
Solicitor General
Requested by:
The Honorable Kevin Brooks
State Representative
103 War Memorial Building
Nashville, Tennessee 37243
The Honorable Rick Womick
State Representative
G29 War Memorial Building
Nashville, Tennessee 37243
Footnote: The Act does carve out some exceptions by designating as "confidential" certain records that would otherwise be open for public inspection. Tenn. Code Ann. § 10-7-504(a)(1). Included in the records designated as confidential are "medical records of patients in state, county and municipal hospitals and medical facilities, and the medical records of persons receiving medical treatment, in whole or in part, at the expense of the state, county, or municipality." Id. But the information released here does not come within this exception. It is plain from the context that the term "medical records," as used in § 10-7-504(a)(1), refers only to records reflecting medical treatment provided to a specific individual. That is also how the term is commonly and normally understood and that is how the term has been defined as it generally applies to the healing arts: "medical records" include "medical histories, records, reports and summaries, diagnoses, prognoses, records of treatment and medication ordered and given, X-ray and radiology interpretations, physical therapy charts and notes and lab reports." Tenn. Code Ann. § 63-2-101(c)(4). The term does not include—either in the general statutory definition, or as it is commonly understood—the kinds of records that were disclosed here, i.e., records that pertain only to insurance coverage and that have nothing to do with treatment, diagnoses, or medications, and especially not of any individually identifiable person.
Get today's answer for your situation
You just read a 2015 opinion on this question. Ezel checks the current Tennessee statutes and case law and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the law it relies on.