It's been almost a year since the publication of the HIPAAA Omnibus Rule. Since then then the regulatory mavens have been quiet. And that's not surprising. Solutions for our contemporary health privacy challenges such as big data and information collected by mobile apps generally lie outside the scope of HIPAA. In the interim some state courts have been showing surprising vitality in filling HIPAA’s remedial gap, the absence of a private right of action.

In Walgreen Co. v. Hinchy, 2014 WL 6130795 (Ind. Ct. App.), Withers, the defendant's employee-pharmacist, viewed the prescription records of the plaintiff-customer. Withers then divulged the information she learned from those records (including that the plaintiff had failed to fill her oral contraception prescription) to her husband, the customer’s ex-boyfriend and the father of the plaintiff’s child. Plaintiff brought breach of privacy claims agains the pharmacist and alleged both vicarious liability and direct negligence against the employer pharmacy chain. The jury returned a verdict for $1.8 million.