HIPAA privacy law is difficult to provide "one-size-fits-all" protection for abortion patients
As multiple U.S. states tighten abortion restrictions, abortion advocates and Democratic lawmakers are urging the Biden administration to strengthen patient data protection. However, several privacy and legal experts say HIPAA is not an all-purpose privacy shield, and its enforcement exception clauses and regulatory limitations make it difficult to achieve comprehensive protection in the short term.

Abortion rights advocates and Democratic lawmakers are urging the Biden administration to strengthen data protections for patients seeking abortion services, amid concerns that clinic and hospital information could be used to prosecute individuals seeking the procedure in states where abortion is illegal.
Possible actions involve the Health Insurance Portability and Accountability Act (HIPAA), alaw that is often cited but little understood, designed to protect sensitive medical information from being disclosed without patient consent or knowledge.
But HIPAA does not provide the comprehensive health data protection many Americans assume it does. According to several data privacy and legal experts interviewed by Healthcare Dive, federal agencies have little ability to strengthen the law without help from Congress.
Experts say any action by the Department of Health and Human Services (HHS) to strengthen HIPAA or prevent abortion-related data from being shared with law enforcement agencies would either be difficult to enforce, vulnerable to legal challenges, or take too long to help patients in the short term.
In this legal environment, healthcare providers—caught between the risk of legal retaliation and their duty to patients—should focus on minimizing and protecting the data they collect, while closely monitoring changes in the legality of abortion in their states.
"Usually the law tries to catch up with developments in the real world. But this time it's the opposite; the real world is trying to catch up, adjust to, or adapt to the law," said Bruce Armon, a healthcare lawyer at Saul Ewing Arnstein & Lehr.“"The best practice for the provider community is to follow developments almost daily."
HIPAA's law enforcement exceptions
After the Supreme Court's historic decision in June overturning Roe v. Wade,dozens of states quickly restricted abortion services. The ruling sparked a national discussion about privacy, as digital records such as text messages, browser histories, and emails have been used in the past toprosecute pregnancy-related criminal charges。
Medical data stored by healthcare providers could also be used to prosecute patients and providers, even though it falls under HIPAA's privacy umbrella.
"There are many gray areas and loopholes," said Ashley Thomas, senior counsel at Holland & Knight.
Under HIPAA, law enforcement agencies can request patient information from covered entities, and covered entities are permitted but not required to comply.
According toguidance recently issued by HHS, if state law prohibits abortion but does not explicitly require providers to report, then a provider reporting an abortion case would violate HIPAA.
But if a court order or subpoena is received, providers are permitted to report abortion data. As conservative state attorneys general crack down on reproductive health services, such orders could become more frequent.
"There are a lot of gray areas here, and they overlap, intersect, and change very quickly," said Matthew Bernstein, founder of information management consulting firm Bernstein Data.
Providers who want to protect patients from prosecutioncan adopt policies not to respond to law enforcement requests unless a warrant is received, said Lucia Savage, chief privacy and regulatory officer at Omada Health.
But subpoenas or court orders are not something providers can ignore, or they may face lawsuits, although providers performing abortions for out-of-state patients may face complex legal details. In the absence of federal protections, some conservative states,including Missouri, are considering suing out-of-state providers who perform abortions for their residents.
"That sounds unconstitutional. But a lot of these practices seem unconstitutional to me," said Dianne Bourque, a partner at Mintz focusing on health law.
No "clean, perfect solution"
President Joe Biden signed an executive order in July, asking Federal Trade Commission Chair Lina Khan and HHS Secretary Xavier Becerra to consider issuing new HIPAA guidance to guard against digital surveillance.
Some Democratic senatorsurged HHS to further update the lawto limit or explicitly prevent health data from being shared with law enforcement agencies targeting those seeking abortions.
HHS's Office for Civil Rights (OCR), which oversees HIPAA, "will look at all its options. That's how the agency responds to an executive order. But I think its options will be limited," said Savage, who served as chief privacy officer for HHS's health IT department during the Obama administration.
Regulators may have some authority here. The HIPAA statute itself is relatively brief, and much of the interpretation today comes from rules and regulations. OCR can issue non-binding sub-regulatory guidance, attempt rulemaking, or step up enforcement actions, experts said.
To fully close or mitigate abortion-related law enforcement exceptions, regulators would have to issue new rules. That takes time—sometimes years from proposal to finalization—and would not help patients or providers in the interim.
"The regulatory process can take years. And providers have only days, maybe a week or two, to decide how to properly care for patients," Armon said.
OCR could also try to fold abortion data protections into the 2021 Notice of Proposed Rulemaking (NPRM) on new HIPAA rules. Regulators have flexibility between what is in the notice and what ends up in the final rule, as long as the final rule meets thelogical outgrowth standard, Savage said.
Among other things,the 2021 NPRMsought to increase permissible disclosures of individual health information and improve care coordination and case management. Regulators could try to find a rationale to argue that protecting reproductive health data is a natural outgrowth of that NPRM, Savage said.
Lawyers also noted that OCR needs to be mindful of the parameters of the HIPAA statute. Any changes to HIPAA regulations must align exactly with the statute to ensure the Biden administration does not overstep its authority in overriding state laws.
HIPAA has a section stating that nothing in the law shall be construed to invalidate or limit the authority or power of state law under certain circumstances, including reporting of disease or injury, death, or public health interventions.
Conservative states could use these circumstances to circumvent HHS efforts to strengthen HIPAA protections for abortion patients, said Bourque of Mintz. For example, if a state attorney general frames a request for abortion data as related to preventing harm, and OCR limits providers' ability to share that data, the state could claim HHS exceeded the bounds allowed by HIPAA, potentially sparking a legal battle.
"You can't say this will work or won't work. But that's the basis for the argument," Bourque said. "There is no clean, perfect solution."
This is one of many legal gray areas emerging in the ongoing fight over abortion rights, as both pro-choice and anti-abortion camps face complex issues at the federal and state levels.
For example, even if HHS explicitly says providers cannot share abortion-related data with law enforcement, public health agencies could still obtain that data by framing requests as public health requests and then share it with law enforcement, Bourque said.
Additionally, HIPAA allows providers to disclose protected health information that they believe constitutes evidence of a crime committed on the premises. In states where abortion is criminalized, if a healthcare worker believes an illegal abortion occurred, they are permitted to share that information with authorities without patient consent.
Lawyers said that if HHS restricts abortion data sharing, HIPAA could become contradictory. It could also conflict with whistleblower protection laws if healthcare workers who report abortions are protected for good-faith reporting of violations.
"I don't know who would win," Bourque said. "It's a perfect storm."
Provider best practices
Experts say the best solution is for Congress to act and address gaps in HIPAA and U.S. privacy laws to eliminate concerns related to reproductive rights. But in the absence of comprehensive action, the responsibility to protect patient medical data—and to protect providers themselves from legal retaliation—falls largely on providers, especially those operating in states where abortion is illegal.
Experts advise that providers should collect only the minimum data needed to provide patient care and pay close attention to retention obligations, especially for data that could reveal which reproductive health services a patient received.
"If you don't need to collect it, don't collect it. If you no longer need to retain it, destroy it," Bernstein said.
Doctors are not legally required to record in medical records that a patient may have shown signs of an abortion. If an enforceable subpoena is received, this can mitigate consequences, Thomas said.
It's also important to know what you can and cannot do under HIPAA, Bourque said.
The lawyer said she has seen stateforms requiring providers to share far more than the regulations actually authorize.
"Everyone has to be careful," especially when facing potential overreach by law enforcement, Bourque said. "To comply with HIPAA, you have to comply with the minimum. Provide only what is requested, don't volunteer more, or you'll face HIPAA issues."