Monday, November 12, 2012

Social Media Raises Privacy Concerns for Healthcare Providers



Used appropriately and in professional contexts, social media such as Facebook and Twitter can provide useful vehicles for communicating general healthcare information to the public, promoting new hospital/provider facilities and programs, building professional connections and providing an outlet to share experiences. Personal uses of social media, however, can have serious legal consequences, especially if patient-specific information is shared.

Q:        What are some improper uses of social media by healthcare providers?
A:        A physician, on his blog, referring to a patient by name and describing details of her care; a medical student filming a surgery with the patient’s face clearly visible and posting the video on YouTube; a nurse posting on her Facebook page that she had treated a “cop killer” the day following many news accounts naming the accused shooter and the hospital where he was treated; and a hospital admissions clerk, using her personal Smartphone, and after work hours, posting on her Facebook page the name of a celebrity that came to the hospital where she worked – and the reason for his admission.

Q:        Do such “posts” break any laws?
A:        The federal Health Insurance Portability and Accountability Act (“HIPAA”) privacy regulations forbid healthcare facilities (and their employees) from using or disclosing patient information without authorization, unless the use is for a legitimate purpose, such as patient treatment. Under HIPAA, patient information in all forms—electronic, “paper,” and verbal—is protected. Healthcare workers cannot talk about their patients outside of work, so, unless a patient gives written permission to disclose her patient information, a posting on Facebook, Twitter, YouTube or other form of social media likely is a HIPAA violation. It could also give rise to a host of claims under Ohio common law (e.g. invasion of privacy, intentional infliction of emotional distress, etc.)

Q:        What makes social media sharing a particular HIPAA risk?
A:        Because social media is informal, fast-paced, and conversational in nature, the risk of a HIPAA violation may not be appreciated. Healthcare workers who would never dream of handing out a paper document or even an e-mail with patient information may, without thinking, reveal too much in a Facebook post.

Q:        Might a hospital be responsible for a social media HIPAA violation, even if unaware of the post? 
A:        Potentially, yes.  HIPAA rules require hospitals and other “covered entities” to implement detailed policies and procedures and train their workforce members about HIPAA, including employees’ personal obligations to protect the privacy of patient information.  For HIPAA violations, fines can be imposed: ranging from $100 for a single, unintentional disclosure of one patient’s information up to $1.5 million for “willfully negligent” violations of HIPAA involving multiple disclosures or multiple patients. For an intentional HIPAA violation, the government can bring a criminal prosecution of up to 10 years in prison. Not every HIPAA violation leads to government penalties, but if the Government believes that employees’ improper social media posts reflect a facility’s general laxity about HIPAA compliance, the facility is more likely to be required to undertake extensive corrective action and pay hefty fines. 

Q:        Can an individual be penalized for a HIPAA violation for sharing patient information with Facebook “friends”?
A:        Yes. Individuals, as well as facilities, can be prosecuted criminally for HIPAA violations. Also, HIPAA specifically requires the employing healthcare facility to impose disciplinary measures—up to and including termination—for HIPAA violations.  An individual who is a physician, nurse, social worker or other licensed professional could also face discipline from the state’s licensing board for breach of patient confidentiality or unprofessional conduct. 

Q:        What steps can healthcare providers take to minimize HIPAA liability risks associated with social media?
A:        Providers should have comprehensive HIPAA privacy policies and procedures that are regularly reviewed.  Given the special risks associated with social media, providers should consider including a specific policy (and workforce education) on the subject. 

This “Law You Can Use” column was provided by the Ohio State Bar Association (OSBA). It was prepared by Cincinnati attorney Sara Simrall Rorer, a partner in the Health and Life Sciences Practice Group of Taft Stettinius & Hollister, LLP. Articles appearing in this column are intended to provide broad, general information about the law. Before applying this information to a specific legal problem, readers are urged to seek advice from an attorney.

Labels: , , , ,

Monday, November 5, 2012

Technology and Social Media Raise New Challenges with Confidential Information



Q:        How has the treatment of confidential information changed since the Internet explosion?
A:        While confidential information is as old as the first secret, the computer revolution of the last couple of decades has raised many questions about how the law addresses ownership and use of confidential information. Life-changing new technology has forced us to determine how the old legal rules apply to new situations. Today, people have easier access to more information than ever before, and most of that information exists in a highly mobile form. As a result, it is much more difficult to protect confidential information today than in the past, so it is more important than ever to take appropriate steps to protect information and avoid the legal problems that result from disclosures of confidential information.

Q:        What kinds of confidential information are affected by the technological changes?
A:        Anything that a person or company might not want somebody else to know has been affected, including such important categories of confidential information as business trade secrets, medical records and student records. Since virtually all information is created and/or stored electronically, anything that a company or an individual might like to keep confidential is subject to new challenges raised by Internet accessibility.

Q:        What is a trade secret?
A:        A trade secret is a form of confidential information recognized by statute in Ohio (and all states in one form or another). In short, trade secrets have value because of the very fact that they are kept confidential. For example, the owner of the formula for a soft drink will go to great lengths to make sure that formula is kept secret, since it is the crown jewel of the business. If the formula were to become known by those outside the business, the company would stand to lose a lot of money because the recipe for creating the drink’s distinctive taste would be available to its competitors. That is a trade secret.

Q:        How has technology affected trade secrets law?
A:        Because the formula referenced above almost certainly exists electronically, it could, in a split second, be emailed or posted on the Internet and become available to millions of people. Such a disclosure could cripple the business. For example, the formula could inadvertently be shared by an employee who leaves a mobile device such as a laptop, an iPhone or a flash drive in an insecure location.
            In light of these new challenges, the owner of information involving trade secrets must take appropriate steps to protect the information. In particular, the owner of the information must determine how to limit the physical locations of the information in all forms, electronic and otherwise.

Q:        If, as an employee of a company, I’ve developed a list of LinkedIn contacts or Twitter followers, who owns that contact list?
A:        If the list has been developed as part of your employment, then the employer will likely want to retain ownership and has strong grounds for doing so. The more complicated situations involve situations where some of the contacts relate to your employment and some do not, or where some of the contacts pre-date your employment. In order to avoid future misunderstandings, it is wise for both sides to specifically spell out as much as possible what each expects regarding ownership of contact information developed through the Internet.

Q:        If I have business contact information on my personal smartphone, don’t I own it?
A:        Not necessarily. This is the “BYOD” (bring your own device) issue that is currently receiving attention among employers. An employer may maintain trade secret protection for information located on an employee’s personal device. Both the employer and the employee should, therefore, plan for how to handle the situation where the device is lost. For example, there are programs that enable remotely “wiping” the device of data if it cannot be located.
            As an employee, you should not assume you have free rein to use job-related information on your smartphone. Such an assumption could lead to unwanted legal problems for you. 

This “Law You Can Use” column was provided by the Ohio State Bar Association. It was prepared by attorney Bill Nolan of the Columbus office of Barnes & Thornburg LLP. Articles appearing in this column are intended to provide broad, general information about the law. Before applying this information to a specific legal problem, readers are urged to seek advice from an attorney.

Labels: , , , , ,

Monday, August 20, 2012

An FTC Violation in One Hundred and Forty Characters (or Less)


Approximately 800 million people use Facebook, and Twitter has about 200 million account holders. Add in all of the bloggers and it becomes crystal clear that social media is more than just a fad. Social media is being used worldwide to connect old acquaintances, make business referrals, and market and advertise products and services. Chances are a vast majority of a company’s employees, customers, potential customers, and competitors access a social media site on a daily basis. Because social networks amass such huge audiences, social media is quickly becoming a preferred way for businesses to tout products and services.

Q:       Who regulates the use of social media as an advertising mechanism?
A:        The Federal Trade Commission regulates the use of endorsements and testimonials in advertising through its published Guides Concerning the Use of Endorsements and Testimonials in Advertising. These endorsement guides, which have been in effect for more than 20 years, address endorsements by consumers, experts, organizations, and celebrities. In fact, FTC revised its endorsement guides in 2009 to include blogs and social networking sites.

Q:       What qualifies as an endorsement?
A:        Under the guides, an endorsement is “any advertising message (including verbal statements, demonstrations, or depictions of the name, signature, likeness, or other identifying personal characteristics of an individual or the name or seal of an organization) that consumers are likely to believe reflects the opinions, beliefs, findings, or experiences of a party other than the sponsoring advertiser, even if the views expressed by that party are identical to those of the sponsoring advertiser.” 

Q:       What is the purpose of the FTC’s endorsement guides?
A:        The FTC’s aim is to ensure that endorsements are truthful and not misleading. Under the guides, endorsements must reflect the honest opinions, findings, beliefs, or experiences of the endorser, and not the marketer of the product. To help further this principle, “material connections” between marketers and endorsers that might affect the weight or credibility of the endorsement, such as connections that consumers would not normally expect, must be disclosed.
Q:       Don’t these updated regulations only apply when a sponsoring advertiser pays a blogger or spokesperson, like a famous celebrity, to tout its products online?
A:        No. If there is any relationship between the endorser and the marketer of the product that might affect how consumers evaluate the endorsement, the FTC regulations apply and the relationship should be disclosed. For example, the regulations would apply if a company’s receptionist wrote on her personal Facebook page a glowing review of a new product just launched by the company. Because the connection between the endorser (the receptionist) and the seller of the product (the company) might affect the weight or credibility of the endorsement, the receptionist’s employment must be clearly and conspicuously disclosed on her page. If the receptionist fails to disclose her relationship with the seller, her post would violate the FTC’s endorsement guides.

Q:       What can a business do to avoid violating the FTC’s endorsement guides?
A:        To avoid violating FTC regulations, businesses should educate their employees about what they can and cannot say and do online. An easy way to educate employees on how to properly use social media for business purposes is to adopt a clear, well-written social media policy.

Q:       Where can I go to get more information about the FTC’s Endorsement Guides?
A:        Visit the FTC’s website business legal resources page at http://business.ftc.gov/legal-resources/5/33 for more information.

This “Law You Can Use” column was provided by the Ohio State Bar Association (OSBA). It was prepared by Alan J. Hartman, a partner and head of the Technology Practice Group at Dressman Benzinger & LaVelle psc. For more information on a variety of legal topics, visit the OSBA’s website at www.ohiobar.org. Articles appearing in this column are intended to provide broad, general information about the law. Before applying this information to a specific legal problem, readers are urged to seek advice from an attorney. 

Labels: , ,