California AB 1298?

There was some minor news
towards the end of 2007 about an extension of the California privacy laws. In brief (pun not intended), AB1298 was written to include medical data in the definition of what should be protected by breach law. The now famous SB1386 was too narrow.

California’s data-breach law – the first in the nation – previously covered only financial information. It took effect on July 1, 2003, and inspired similar laws in more than 40 states. Most of those laws don’t cover medical information, however; Delaware and Arkansas are among the few that do.

In July 2006, Republican Gov. Arnold Schwarzenegger issued an executive order to store medical records on computers, which probably will result in more data breaches, said Robert Herrell, a legislative assistant to Assemblyman Dave Jones, D-Sacramento, who wrote the bill.

I hardly think it fair to give such credit to CA without mentioning the medical records provision of HIPAA. Anyway, the big deal is that medical information is unprotected and people need to know when it is mismanaged to the point of being lost or stolen:

Federal privacy and security regulations have not been enough to protect patients as medical information moves onto computers. A survey in 2006 by Phoenix Health Systems showed that 39 percent of health care providers and 33 percent of insurers reported security incidents in the previous six months. Only 56 percent of providers had implemented federal security standards and 78 percent complied with federal privacy standards. Thirteen percent of insurers were out of compliance with federal privacy standards.

[…]

California’s law also was written because the World Privacy Forum, a nonprofit group in San Diego, issued a report in 2006 on medical identity theft. About a quarter of a million people per year are victims of this crime, according to Pam Dixon, the report’s author.

“I think a lot of organizations will end up being surprised by this law,” Dixon said.

They really should have been headed in that direction anyway. I am just surprised that several months have passed since October 2007 when AB 1298 became law (with a vote of 76-0!) and I have not been hearing more AB 1298 discussion. Perhaps breach disclosure/privacy laws have become mainstream.

The best report I have seen so far on this was published by Frank Russo, where he describes in detail the benefits of both AB 1168 and AB 1298.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.