In an opinion announced on January 10, 2012, the Ohio Tenth District Court of Appeals, in Columbus, Ohio, held that a hospital’s use of a patient’s individually identifiable health information (PHI) for obtaining payment of a patient’s account was a valid use of PHI for payment purposes under the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191 (“HIPAA”), and rejected the patient’s claim that disclosure of the patient’s PHI was a wrongful disclosure of medical information under Biddle v. Warren General Hospital, Ohio’s seminal case that established a personal injury tort for wrongful disclosure of confidential medical information.

In OhioHealth Corp. v. Ryan, No. 10AP-937, 2012-OH-60 (10th Dist. App., January 10, 2012), OhioHealth filed a legal action against Ryan, a former patient, to recover on an account for unpaid medical services. The defendant Ryan denied the allegations of the complaint and filed a counterclaim against OhioHealth alleging that OhioHealth created false PHI by claiming that Ryan was uninsured, and that OhioHealth engaged in unauthorized disclosure of said information to a third party. Ryan asserted that under Biddle v. Warren Gen. Hosp., 86 Ohio St. 3d 395 (1999), OhioHealth disclosed, without authorization or privilege, nonpublic medical information of Ryan obtained in a confidential relationship. OhioHealth countered that, as a “covered entity” under HIPAA, its actions were governed by HIPAA’s privacy regulations that specifically authorize disclosure of PHI for purposes of obtaining payment for services, and which preempt contrary state laws (and that no exceptions to state law preemption applied). The trial court granted OhioHealth’s motion to dismiss the patient’s counterclaim on the basis that the disclosure of PHI at issue was indeed permitted under HIPAA and therefore constituted an authorized, privileged use of medical information under the Biddle case. After additional motions for summary judgment and dismissal, the trial court issued a judgment entry finding there were no genuine issues of material fact remaining for trial and held defendant Ryan liable on the unpaid account. Defendant Ryan appealed both the dismissal of the counterclaim, and the judgment entry on the unpaid account.

Appellate Court Finds Biddle Case Inapplicable to Privileged Use of PHI for Payment

The Ohio Tenth District Court of Appeals, in addressing defendant Ryan’s first assignment of error, found that (a) Biddle v. Warren Gen. Hosp. was distinguishable from the instant case because OhioHealth’s disclosure of Ryan’s account information was a protected or “privileged” disclosure, meaning it was legally permitted under HIPAA without obtaining the patient’s consent, and that (b) no private right of action exists under HIPAA, which is the dispositive authority in the case. First, assuming that the Biddle case did apply, the Court found the disclosure in the present case was authorized by HIPAA for payment purposes, thus rendering the disclosure by OhioHealth permissive and not wrongful or unauthorized under Biddle. Further, the disclosure involved account information, and not the entire medical records of the patient, as was the case in Biddle. Second, the Court reasoned that the federal HIPAA law generally preempts or supersedes state laws that are contrary to its requirements, unless such state laws impose requirements that are more stringent than HIPAA (citing 45 C.F.R. § 160.202(6) and § 160.203(b)). The Court found that defendant Ryan failed to cite any Ohio authority more stringent than HIPAA. Third, and significantly, the Court of Appeals recognized that, even if there was a wrongful disclosure under HIPAA, there is no private right of action under HIPAA, as recognized by several federal district courts in Ohio on prior occasions. Ryan was without ability to bring an action under HIPAA in court. Thus, given the privileged, authorized disclosure of information by OhioHealth under HIPAA, and absent any more stringent state law requirement, the defendant was unable to establish a claim that OhioHealth engaged in the tort of wrongful disclosure of nonpublic medical information obtained in a confidential relationship under Biddle v. Warren General Hospital. The Court of Appeals upheld the dismissal of the defendant’s counterclaim against OhioHealth, and upheld the trial court’s summary judgment in favor of OhioHealth on the patient’s past due account.

Photo of John Mulhollan John Mulhollan

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions…

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions and contractual negotiations involving Medicare and Medicaid fraud and abuse compliance, physician referral compliance under the Stark law and professional and facility licensing. He has assisted both nonprofit and for-profit clients with legal analysis and documentation of healthcare private offerings, joint venture agreements, leases and corporate governance matters in connection with complex transactions. Focused on providing sound, yet practical, advice, Mr. Mulhollan strives to understand and promote each client’s healthcare mission by providing legally compliant solutions to the challenges of today’s complex healthcare environment.

Mr. Mulhollan has represented large and small healthcare providers such as healthcare systems, individual hospitals and clinics, as well as physicians and ancillary healthcare businesses. The complex transactions he has handled range from single contractual services arrangements to large healthcare mergers and acquisitions. Examples include the acquisition of a county-owned community hospital by a nonprofit health system, shareholder relations and combinations with respect to private physician practices, and compliance and documentation support for a variety of healthcare ventures involving ambulatory surgery, diagnostic imaging and laboratory services. In addition to providing thorough legal analysis of business issues, Mr. Mulhollan is able to guide clients through complex issues ranging from Medicare/Medicaid certification, change of ownership and reimbursement implications of such transactions to detailed analysis and preparation of professional and vendor services agreements. He also provides guidance and support in the areas of operational restructuring of provider, supplier and medical group operations, including the expansion or contraction of services, outsourcing, marketing and development compliance and complex facility and vendor relationships.

Mr. Mulhollan has advised clients on a variety of organizational compliance efforts, including fraud and abuse and Stark law compliance and corporate policy development. He advises clients on physician professional services and on-call arrangements, medical director agreements, physician recruitment, graduate medical education and medical office leasing. Mr. Mulhollan has advised both healthcare and business clients on implementing the many requirements and compliance issues arising under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as compliance with state medical privacy and professional licensing laws.

In addition, Mr. Mulhollan’s business practice includes general business advice to healthcare and non-healthcare clients, including mergers and acquisitions, governance, shareholder transactions, professional entity formation and compliance with government regulations.

Mr. Mulhollan is a member of the American, Ohio and Cleveland Metropolitan (Health Law Section) Bar Associations, as well as the American Health Lawyers Association.