In perhaps the first widely publicized action taken against a “business associate” (as defined under the Health Insurance Portability and Accountability Act (HIPAA) and privacy and security regulations thereunder), the Minnesota Attorney General (AG) on January 19 filed a civil lawsuit in federal court against Accretive Health, Inc., for alleged violations of HIPAA, as well as alleged violations of that state’s medical privacy law and consumer debt collection practices laws. Minnesota v. Accretive Health Inc., D. Minn., No. 12-145, filed January 19, 2012. The lawsuit arises from the loss by an Accretive employee of a laptop containing several thousand records that included the individually identifiable health information of patients from Accretive’s hospital customers. The action is filed under the powers granted to state attorneys general under HITECH provisions that expanded the enforcement powers and civil penalties available for violations of HIPAA.

Accretive Health Inc., the business associate and defendant in the lawsuit, was engaged by two hospitals to perform revenue cycle management services, including a so-called “Quality and Total Cost of Care” service agreement that is alleged to have included intensive management of a hospital’s entire revenue cycle process (from patient admissions and registrations, to care coordination, to back office collections of patient receivables), for a fee that included a share of “incentive payments” received by the hospital from payors in return for achieving certain cost savings and quality measures. According to the complaint, management of the hospitals’ revenue cycles was performed through so-called “infused employees” of Accretive working on-site in various departments of the hospitals. The patient data was lost when a laptop containing data of approximately 17,000 to 23,000 patients allegedly was stolen from the back seat of a vehicle of an Accretive employee while parked at a local restaurant.

In the lawsuit, the AG alleges that the business associate failed to take adequate security precautions, such as encryption of the data on the lost laptop, to protect the patient information on the device. The information included patients’ names, addresses, phone numbers, Social Security numbers and certain clinical information, including information related to chronic conditions such as mental health and HIV/AIDS conditions. Further, the AG alleges that the business associate violated the Minnesota Health Records Act and various state consumer fraud and deceptive practices acts by, among other things, failing to disclose to the hospital patients its extensive role in the hospitals’ revenue cycle process, its role as a debt collector and its role in the proactive management of patient care, including the incentive payments based on the hospital’s cost savings.

While the remedies available to the AG in this case under HIPAA and the HITECH Act are limited to $25,000 per year, compared to the $1.5 million that the federal government could impose for violations, the defendant in this case, if found to have violated the consumer protection and debt collection agency laws, could face significant financial liability and negative effects on its business reputation. This new enforcement action highlights not only the risks inherent in failing to protect patient data that leads to a privacy breach, but also reveals the underlying scrutiny that will be applied to a business associate’s business practices as a result of a data breach. Following actions filed against covered entities in Connecticut and Vermont, this case may portend a new trend of enforcement against HIPAA business associates. Stay tuned…

See the AG’s complaint.

Photo of John Mulhollan John Mulhollan

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions…

John Mulhollan has actively served a variety of business and healthcare clients in Ohio and California, with a particular emphasis on the healthcare industry, for nearly ten years.

Mr. Mulhollan has experience counseling clients in a variety of substantive areas, including healthcare transactions and contractual negotiations involving Medicare and Medicaid fraud and abuse compliance, physician referral compliance under the Stark law and professional and facility licensing. He has assisted both nonprofit and for-profit clients with legal analysis and documentation of healthcare private offerings, joint venture agreements, leases and corporate governance matters in connection with complex transactions. Focused on providing sound, yet practical, advice, Mr. Mulhollan strives to understand and promote each client’s healthcare mission by providing legally compliant solutions to the challenges of today’s complex healthcare environment.

Mr. Mulhollan has represented large and small healthcare providers such as healthcare systems, individual hospitals and clinics, as well as physicians and ancillary healthcare businesses. The complex transactions he has handled range from single contractual services arrangements to large healthcare mergers and acquisitions. Examples include the acquisition of a county-owned community hospital by a nonprofit health system, shareholder relations and combinations with respect to private physician practices, and compliance and documentation support for a variety of healthcare ventures involving ambulatory surgery, diagnostic imaging and laboratory services. In addition to providing thorough legal analysis of business issues, Mr. Mulhollan is able to guide clients through complex issues ranging from Medicare/Medicaid certification, change of ownership and reimbursement implications of such transactions to detailed analysis and preparation of professional and vendor services agreements. He also provides guidance and support in the areas of operational restructuring of provider, supplier and medical group operations, including the expansion or contraction of services, outsourcing, marketing and development compliance and complex facility and vendor relationships.

Mr. Mulhollan has advised clients on a variety of organizational compliance efforts, including fraud and abuse and Stark law compliance and corporate policy development. He advises clients on physician professional services and on-call arrangements, medical director agreements, physician recruitment, graduate medical education and medical office leasing. Mr. Mulhollan has advised both healthcare and business clients on implementing the many requirements and compliance issues arising under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as well as compliance with state medical privacy and professional licensing laws.

In addition, Mr. Mulhollan’s business practice includes general business advice to healthcare and non-healthcare clients, including mergers and acquisitions, governance, shareholder transactions, professional entity formation and compliance with government regulations.

Mr. Mulhollan is a member of the American, Ohio and Cleveland Metropolitan (Health Law Section) Bar Associations, as well as the American Health Lawyers Association.