🧪 TEST MODE ACTIVE Use test card: 4242 4242 4242 4242
TX JC-0508 May 24, 2002

Do Texas hospitals need patient consent before reporting their data to the Health Care Information Council?

Short answer: The Attorney General concluded hospitals do not need written patient authorizations to send required data to the Texas Health Care Information Council. Chapter 108 of the Health and Safety Code requires hospitals and other covered facilities to submit detailed discharge data, including patient names, Social Security numbers, diagnoses, and charges, to the Council, which compiles statewide health care data and reports to the public. A new privacy statute, chapter 181 (enacted by Senate Bill 11 in 2001), makes hospitals 'covered entities' that must follow the federal HIPAA privacy standards, which generally require a patient's written authorization before protected health information is disclosed. The Council asked whether chapter 181 therefore forced hospitals to collect signed authorizations before their routine chapter 108 reporting. The opinion said no. Section 181.103 lets a covered entity 'use or disclose protected health information without the express written authorization of the individual' to comply with the requirements of any federal or state law. Because chapter 108 is a state law that requires hospitals to report this data to the Council, the disclosure falls squarely within that exemption, so no patient consent is needed. The opinion also stressed that the identifying information hospitals send is locked down by chapter 108's strict confidentiality rules, civil and criminal penalties, and bars on releasing patient- or physician-identifying data or sharing it with other state agencies.

Apply this to your situation

This page answers the general question as of 2002. Ezel answers yours: what it means for your facts, under current Texas law, with citations.

Currency note: this opinion is from 2002
Subsequent statutory amendments, court decisions, or later AG opinions may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.
Disclaimer: This is an official Texas Attorney General opinion. AG opinions are persuasive authority in Texas courts but are not binding precedent. This summary is for informational purposes only and is not legal advice. Statutes can be amended; verify current law before relying on anything here. Consult a licensed attorney for advice on your specific situation.
About this page: The plain-English summary, reader guidance, and Q&A below were written by Ezel based on the official AG opinion. The original opinion (linked on this page as a PDF) is the authoritative source for any reliance.
View original AG opinion (PDF)

Plain-English summary

The Texas Health Care Information Council runs a statewide health care data collection system, gathering charges, utilization, provider quality, and outcome data from hospitals and other facilities and reporting to the public. Under chapter 108 of the Health and Safety Code, covered hospitals must submit detailed inpatient discharge data, including the patient's name, birth date, address, sex, race, Social Security number, diagnoses, surgical procedures, charges, payment source, and attending physician. In 2001, the Legislature enacted chapter 181 (Senate Bill 11), a medical-privacy statute that makes hospitals "covered entities" and requires them to follow the federal privacy standards adopted under the Health Insurance Portability and Accountability Act (HIPAA). Those standards generally require an individual's written authorization before protected health information is disclosed. The Council asked whether chapter 181 therefore required hospitals to obtain signed patient authorizations before their routine chapter 108 reporting.

The Attorney General concluded it did not. A hospital is a "covered entity" under chapter 181 because it collects, stores, and transmits protected health information, and the discharge data it sends is protected health information. But chapter 181 contains an express carve-out. Section 181.103 provides that a covered entity "may use or disclose protected health information without the express written authorization of the individual for public health activities or to comply with the requirements of any federal or state health benefit program or any federal or state law." Because chapter 108 is a state law that requires hospitals to disclose this data to the Council, the disclosure fits the first branch of that exemption, and no patient consent is needed. The opinion noted that section 181.103 has a second branch covering disclosures to public health and abuse-reporting authorities, but the hospital's reporting to the Council is already covered by the first branch, so it need not also fit the second.

The opinion was careful to point out that dropping the consent requirement does not leave patient data unprotected. The identifying information hospitals submit to the Council is governed by chapter 108's strict confidentiality regime: the Council generally may not release any data that could reasonably be expected to reveal a patient's or physician's identity, patient-identifying data is not subject to discovery or subpoena and is inadmissible in legal proceedings, the Council may not share confidential data with other state agencies, and chapter 108 carries both civil and criminal penalties for releasing or improperly accessing data in violation of the chapter.

Currency note

This opinion was issued in 2002. Subsequent statutory amendments, court decisions, or later Attorney General opinions may have changed the analysis. Treat this page as historical context, not current legal advice. Verify current law before relying on any specific rule, deadline, or remedy mentioned here.

What the opinion meant for those who asked

The Health Care Information Council (what the opinion held): The opinion held that hospitals could submit the patient data chapter 108 requires without first obtaining written patient authorizations, because section 181.103 exempts disclosures made to comply with state law. The Council's data collection was not blocked by the new privacy statute.

Hospitals and other covered facilities (what the opinion held for them): The opinion held that hospitals, though "covered entities" under chapter 181 and HIPAA, did not need to collect signed patient authorizations before their required chapter 108 reporting, because that reporting is mandated by state law and falls within the section 181.103 exemption.

Patients (what the opinion held for them): The opinion explained that even without a consent step, the identifying data hospitals send is protected by chapter 108's confidentiality rules, which bar the Council from releasing patient- or physician-identifying data, shield it from discovery and subpoena, and impose civil and criminal penalties for violations.

Common questions

Did Texas hospitals have to get patient consent before reporting data to the Council?
No. The opinion concluded chapter 181 did not require written patient authorizations, because section 181.103 lets a covered entity disclose protected health information without consent to comply with state law, and chapter 108 requires the reporting.

Doesn't HIPAA require written authorization to release medical records?
Generally yes, but the opinion explained that the Texas statute incorporating HIPAA (chapter 181) includes section 181.103's exemption for disclosures required by federal or state law, which covers the chapter 108 reporting.

Was patient data left unprotected once it reached the Council?
No. The opinion stressed that chapter 108 keeps the data confidential, bars releasing anything that could identify a patient or physician, shields it from discovery and subpoena, and backs those rules with civil and criminal penalties.

Which hospitals had to report?
Hospitals and certain other health care facilities had to submit the data under chapter 108, though the chapter excepts some rural providers, certain hospitals, and individual physicians.

Background and statutory framework

The Texas Health Care Information Council collects health care charges, utilization, provider quality, and outcome data and reports to the Governor, the Legislature, and the public. Tex. Health & Safety Code Ann. § 108.001; § 108.006(a)(1), (3), (6); § 108.013(a); see Tex. Att'y Gen. Op. No. JC-0469 (2002). Hospitals, chemical dependency treatment facilities, birthing centers, and other facilities must submit the patient data required by chapter 108, subject to exceptions for rural providers, certain hospitals, and individual physicians. Id. § 108.002(10), (15); § 108.009(a), (c), (d); § 108.010(a). Covered hospitals submit inpatient discharge data described by 25 Tex. Admin. Code § 1301.19(e), including patient name, birth date, address, sex, race, ethnicity, Social Security number, admission and diagnosis information, procedures, charges, payment source, physician identifiers, and facility information. 25 Tex. Admin. Code § 1301.12(a), § 1301.19(e).

That data is protected by chapter 108's confidentiality regime. Unless authorized by chapter 108, the Council may not release data that could reasonably be expected to reveal the identity of a patient or physician. Tex. Health & Safety Code Ann. § 108.013(c). Patient data and compilations that identify patients are not discoverable, subpoenable, or admissible, the same applies to physician data, and the Council and Department may not provide confidential data to other state agencies. Id. § 108.013(d), (e), (f), (i). Section 108.014 sets a civil penalty for knowingly or negligently releasing data in violation of the chapter, and section 108.0141 sets a criminal penalty for knowingly accessing or, with criminal negligence, releasing data in violation. Id. § 108.014, .0141.

Chapter 181, enacted by Senate Bill 11 of the 77th Legislature, makes a "covered entity" comply with the HIPAA privacy standards, including consent requirements. Act of May 27, 2001, 77th Leg., R.S., ch. 1511, § 1, 2001 Tex. Gen. Laws 5080; Tex. Health & Safety Code Ann. § 181.101(3); Tex. S.B. 11, 77th Leg., R.S. (2001). A "covered entity" is broadly defined and a "hospital" is included; "protected health information" is individually identifiable health information that identifies the individual. Id. § 181.001(b)(1), (b)(5); § 108.002(12). HIPAA directed the Secretary of Health and Human Services to set privacy standards, issued as the Federal Standards for Privacy of Individually Identifiable Health Information, which generally require written authorization for disclosure and, with exceptions, preempt contrary state law. Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, § 264, 110 Stat. 2024; 42 U.S.C. § 1320d-2, § 1320d-7; 65 Fed. Reg. 82462 (Dec. 28, 2000); 66 Fed. Reg. 12434 (Feb. 26, 2001); 67 Fed. Reg. 14776 (2002); 45 C.F.R. pts. 160, 164; § 164.508; § 164.534; § 160.304; see Tex. Att'y Gen. Op. No. JC-0411 (2001). The exemption that resolved the question was section 181.103, which permits a covered entity to use or disclose protected health information without express written authorization to comply with the requirements of any federal or state law, among other purposes. Id. § 181.103.

Citations

Statutes:

  • Tex. Health & Safety Code Ann. § 108.001; § 108.002(10), (12), (15), (16); § 108.0065; § 108.006(a)(1), (3), (6); § 108.009(a), (c), (d); § 108.010(a), (c), (h), (i); § 108.011; § 108.013(a), (c), (d), (e), (f), (i); § 108.014, .0141; § 181.001(b)(1), (b)(5); § 181.101(3); § 181.103
  • 25 Tex. Admin. Code § 1301.12(a), § 1301.19(e) (2002)
  • Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, § 264, 110 Stat. 2024
  • 42 U.S.C. § 1320d-2; § 1320d-7
  • 45 C.F.R. pts. 160, 164; § 164.508; § 164.534; § 160.304
  • 65 Fed. Reg. 82462 (Dec. 28, 2000); 66 Fed. Reg. 12434 (Feb. 26, 2001); 67 Fed. Reg. 14776 (2002)
  • Act of May 27, 2001, 77th Leg., R.S., ch. 1511, § 1, 2001 Tex. Gen. Laws 5080 (Senate Bill 11)
  • Tex. S.B. 11, 77th Leg., R.S. (2001)

Source

Original opinion text

Best-effort transcription from a scanned PDF. Minor errors may remain — the linked PDF is authoritative.

OFFICE OF THE ATTORNEY GENERAL - STATE OF TEXAS
JOHN CORNYN

May 24, 2002

Mr. Jim Loyd Opinion No. JC-0508
Executive Director
Texas Health Care Information Council Re: Whether a hospital is authorized to report
206 East Ninth Street, Suite 19.140 information required by chapter 108, Health and
Austin, Texas 78701 Safety Code, without obtaining the written
consent of the affected patient (RQ-0481-JC)

Dear Mr. Loyd:

On behalf of the Texas Health Care Information Council (the "THCIC" or "council") you ask whether chapter 181 of the Health and Safety Code, enacted by Senate Bill 11 of the Seventy-seventh Legislature, requires hospitals to obtain written authorizations from patients prior to sending statutorily-required confidential identifying information to THCIC. See Act of May 27, 2001, 77th Leg., R.S., ch. 1511, § 1, 2001 Tex. Gen. Laws 5080, 5386. We conclude that chapter 181 of the Health and Safety Code does not require hospitals to obtain written authorizations from patients prior to sending confidential identifying information to the council.

The Texas Health Care Information Council is charged with developing a statewide health care data collection system "to collect health care charges, utilization data, provider quality data, and outcome data" and disseminating it for the benefit of employers, other health-care consumers, and health-care providers. See Tex. Health & Safety Code Ann. § 108.006(a)(1), (3), (6) (Vernon 2001). See also Tex. Att'y Gen. Op. No. JC-0469 (2002) at 2-4 (describing council's work). It is to report to the Governor, the legislature, and the public. See Tex. Health & Safety Code Ann. § 108.001 (Vernon 2001); see also id. § 108.013(a) (Vernon Supp. 2002) (data received by the council to be used for the benefit of the public). Hospitals, chemical dependency treatment facilities, birthing centers, and certain other health-care facilities, see id. § 108.002(10), (15) (Vernon Supp. 2002), must submit to the council the patient data required by chapter 108 of the Health and Safety Code. See id. § 108.009(a) (Vernon 2001).[1] But see id. § 108.009(c)-(d) (excepting rural providers, certain hospitals, and individual physicians).

Covered hospitals must submit to the council the discharge data described by section 1301.19(e) of title 25, Texas Administrative Code. See also 25 Tex. Admin. Code § 1301.12(a) (2002) (hospitals shall submit discharge files on inpatients). This includes the individual patient's name, birth date, address, sex, race, ethnicity, social security number, information about admission, diagnosis, surgical procedures, charges, source of payment, certain accounting information, name and number of the attending physician and the operating or other physician, and the name and address of the facility. See id. § 1301.19(e).

The council makes certain classes of data available to the public, subject to strict confidentiality provisions. See Tex. Health & Safety Code Ann. §§ 108.010(c), (h), (i) (Vernon 2001) (collection and dissemination of provider quality data); .011 (dissemination, subject to restrictions, of public use data). See also Tex. Att'y Gen. Op. No. JC-0469 (2002) (explaining dissemination of data). Unless specifically authorized by chapter 108, the council may not release any data "that could reasonably be expected to reveal the identity of a patient" or "of a physician." Tex. Health & Safety Code Ann. § 108.013(c) (Vernon Supp. 2002). See also id. § 108.013(d) (confidentiality provisions and criminal penalties from certain other statutes applicable to data collected and used by the Department of Health and the council under chapter 108, Health and Safety Code); (e) (data on patients and compilations of that data that identify patients are not subject to discovery or subpoena, nor are they admissible in civil, administrative, or criminal proceeding); (f) (data on physicians and compilations of that data that identify physicians are not discoverable or admissible); (i) (council and department may not provide information made confidential by Health and Safety Code section 108.013 to any other agency of this state). Health and Safety Code section 108.014 establishes a civil penalty for "[a] person who knowingly or negligently releases data in violation of this chapter," while section 108.0141 establishes a criminal penalty for a person who knowingly accesses data in violation of this chapter, or a person "who with criminal negligence releases data in violation of this chapter." Id. §§ 108.014, .0141 (Vernon 2001). Thus, information identifying patients that hospitals submit to the council is subject to comprehensive confidentiality provisions under Health and Safety Code chapter 108.

You inquire only about chapter 181 of the Health and Safety Code, and your question is answered by the provisions of this statute. However, because chapter 181 refers to the federal privacy standards adopted under the Federal Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), see Tex. Health & Safety Code Ann. §§ 181.001, .101 (Vernon Supp. 2002), we will briefly describe the federal law. See Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 2024 (codified as amended in scattered sections of 42 U.S.C.). See also Tex. Att'y Gen. Op. No. JC-0411 (2001) at 1, 4-5 (discussing privacy standards under HIPAA). In the HIPAA, Congress directed the Secretary of Health and Human Services to promulgate regulations setting privacy standards for medical records, and these have been issued as the Federal Standards for Privacy of Individually Identifiable Health Information. See Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, § 264, 110 Stat. 2024 (codified at 42 U.S.C. § 1320d-2 (Supp. IV 1998) (historical & statutory note)); Standards for Privacy of Individually Identifiable Health Information, 65 Fed. Reg. 82462, 82829 (Dec. 28, 2000) (to be codified at 45 C.F.R. pts. 160, 164). With certain exceptions, they preempt contrary state law. See 42 U.S.C. § 1320d-7 (Supp. IV 1998). The rules became effective April 14, 2001, but they will not apply until April 14, 2003, or April 14, 2004, in the case of small health plans. See 65 Fed. Reg. 82462, 82829; 66 Fed. Reg. 12434 (Feb. 26, 2001) (to be codified at 45 C.F.R. § 164.534). They require an individual's written authorization for disclosure of certain health information. See 65 Fed. Reg. 82462, 82811 (Dec. 28, 2000) (to be codified as 45 C.F.R. § 164.508); see also Tex. Att'y Gen. Op. No. JC-0411 (2001) at 4. The Secretary of Health and Human Services has proposed modifications to the rules, but the answer to your question regarding Health and Safety Code chapter 181 is not affected by these. See 67 Fed. Reg. 14776 (2002) (proposed modification in rule entitled "Standards for Privacy of Individually Identifiable Health Information").[2]

A "covered entity" within Health and Safety Code chapter 181 must comply with the privacy standards adopted under HIPAA, including the standards relating to "uses and disclosures of protected health information" and the applicable consent requirements. See Tex. Health & Safety Code Ann. § 181.101(3) (Vernon Supp. 2002). Section 181.001(b)(1) of the Health and Safety Code defines "covered entity" to mean any person who:

(A) for commercial, financial, or professional gain, monetary fees, or dues, or on a cooperative, nonprofit, or pro bono basis, engages, in whole or in part, and with real or constructive knowledge, in the practice of assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information. The term includes a business associate, health care payer, governmental unit, information or computer management entity, school, health researcher, health care facility, clinic, health care provider, or person who maintains an Internet site;

(B) comes into possession of protected health information;

(C) obtains or stores protected health information under this chapter; or

(D) is an employee, agent, or contractor of a person described by Paragraph (A), (B), or (C) insofar as the employee, agent, or contractor creates, receives, obtains, maintains, uses, or transmits protected health information.

Id. § 181.001(b)(1).

A hospital is a covered entity within this definition. It is a person that, on a commercial or nonprofit basis, engages, "with real or constructive knowledge, in the practice of assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information." Id.; see also id. § 108.002(12) (defining "hospital" to include a public, for-profit, or nonprofit institution licensed or owned by the state). Hospitals collect "protected health information," which chapter 181 defines to mean "individually identifiable health information" relating to the physical or mental health or condition of an individual, to the provision of health care to an individual, or to the payment for the provision of health care to an individual, and that identifies the individual. Id. § 181.001(b)(5). See also 25 Tex. Admin. Code § 1301.19(e) (2002).

Even though a hospital is a covered entity within Health and Safety Code chapter 181, it need not obtain written authorizations from patients prior to sending confidential identifying information to THCIC as required by the HIPAA privacy regulations. It is exempted from securing written authorizations by section 181.103 of the Health and Safety Code, which provides as follows:

A covered entity may use or disclose protected health information without the express written authorization of the individual for public health activities or to comply with the requirements of any federal or state health benefit program or any federal or state law. A covered entity may disclose protected health information:

(1) to a public health authority that is authorized by law to collect or receive such information for the purpose of preventing or controlling disease, injury, or disability, including the reporting of disease, injury, vital events such as birth or death, and the conduct of public health surveillance, public health investigations, and public interventions;

(2) to a public health authority or other appropriate government authority authorized by law to receive reports of child or adult abuse, neglect, or exploitation; and

(3) to any state agency in conjunction with a federal or state health benefit program.

Tex. Health & Safety Code Ann. § 181.103 (Vernon Supp. 2002). There are two branches to this exception. The first one permits a covered entity to "use or disclose protected health information without the express written authorization of the individual" for public health activities, to comply with the requirements of a federal or state health benefit program, or to comply with federal or state law. Because a hospital is required by state law, specifically chapter 108 of the Health and Safety Code, to disclose protected health information to THCIC, it may do so pursuant to this branch of section 181.103 without the individual's express written authorization.

The second branch of section 181.103 permits a covered entity to "disclose protected health information" (1) to a public health authority that is authorized by law to collect or receive such information for various public health purposes; (2) to a public health authority or other government authority authorized by law to receive reports of child or adult abuse, neglect, or exploitation; and (3) to any state agency in conjunction with a federal or state health benefit program. This branch covers specific instances where the legislature made it very clear that covered entities could disclose certain protected health information to health authorities or governmental entities. See generally House Research Organization, Bill Analysis, Tex. Comm. Sub. S.B. 11, 77th Leg., R.S. (2001) at 3-4; Senate Business & Commerce Comm., Bill Analysis, Tex. S.B. 11, 77th Leg., R.S. (2001) (summaries of section 181.103 reflect the two branches of this provision). A hospital's disclosure of protected health information to THCIC is excepted by the first branch of section 181.103 and does not need to fall within the second branch of this provision as well. We conclude that a hospital may submit to the THCIC the data required by chapter 108 of the Health and Safety Code without obtaining the written consent of the affected patients.

                                   SUMMARY

Chapter 181 of the Health and Safety Code does not require hospitals to obtain written authorizations from patients prior to sending confidential identifying information to the Texas Health Care Information Council pursuant to chapter 108 of the Health and Safety Code. Section 181.103 of the Health and Safety Code expressly provides that a covered entity may use or disclose protected health information without the express written authorization of the individual to comply with the requirements of any state law. Because hospitals are required by chapter 108 of the Health and Safety Code to disclose protected health information to the council, they are within this exemption. Information regarding patient identity that is submitted by hospitals to the council is protected by strict confidentiality provisions included in Health and Safety Code chapter 108.

                                        Very truly yours,

                                        JOHN CORNYN
                                        Attorney General of Texas

HOWARD G. BALDWIN, JR.
First Assistant Attorney General

NANCY FULLER
Deputy Attorney General - General Counsel

SUSAN DENMON GUSKY
Chair, Opinion Committee

Susan L. Garrison
Assistant Attorney General, Opinion Committee


[1] The council also must collect data reflecting provider quality from hospitals, other health-care facilities, and physicians. See Tex. Health & Safety Code Ann. § 108.010(a) (Vernon 2001); see also id. § 108.002(10), (15), (16) (Vernon Supp. 2002) (defining "health care facility," "provider," and "provider quality"). See also id. § 108.0065 (Vernon 2001) (data collection with respect to Medicaid managed care organizations).

[2] The Department of Health and Human Services provides assistance to help covered entities comply with the regulations. See 65 Fed. Reg. 82462, 82801 (Dec. 28, 2000); 66 Fed. Reg. 12434 (Feb. 26, 2001) (to be codified at 45 C.F.R. § 160.304); see also Department of Health and Human Services, Office for Civil Rights, Internet site on HIPAA privacy standards, available at http://www.hhs.gov/ocr/hipaa (accessed Apr. 16, 2002). The Texas Health and Human Services Commission also provides information about HIPAA through the National Data Interchange Standards Task Force. See http://www.hhsc.state.tx.us/NDISTaskForce.html (accessed Apr. 16, 2002).

Get today's answer for your situation

You just read a 2002 opinion on this question. Ezel checks the current Texas statutes and case law and answers your specific situation, with citations.

Opens in Ezel Pro. Every answer cites the law it relies on.