Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Massachusetts PATCH Act, Requires Additional Protection for Certain Confidential Health Care Information

By William Daley & Guest Contributor on July 18, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

Earlier this year, Governor Charlie Baker signed into law an Act to Protect Access to Confidential Healthcare (the PATCH Act), which prevents information regarding “sensitive health care services” from being shared with anyone other than the patient in the form of Explanation of Benefits (EOB) and Summary of Payment (SOP) forms. When more than one person is covered by the same medical insurance plan, sensitive health care information can be disclosed through the use of these common forms, sometimes including information on sexual assault, domestic violence, mental health disorders, or sexual and reproductive health. When the EOB or SOP is provided to the named policyholder—rather than the specific beneficiary that the services described therein relate to—the beneficiary’s confidentiality can be compromised. 

The PATCH Act seeks to protect privacy in a number of ways by: allowing insurers to send SOP forms directly to the patient rather than to the primary policyholder; allowing patients to choose their preferred address and method for receiving SOPs; providing only general information about certain sensitive services or visits; and providing patients the option to opt-out of receiving SOPs if no payment is due.

The PATCH Act requires an insurer to honor a beneficiary’s request with regard to information regarding sensitive health care services in a summary of payment. The PATCH Act further requires that, through regulations, the Division of Insurance define what constitutes “sensitive health care services.”  Moreover, those regulations will also include “requirements for reasonable reporting by carriers to the division regarding compliance and the number and type of complaints received regarding noncompliance” with the Act. Notably, the final version of the Act, S.2296, did not include reporting requirements for “breaches of confidentiality” as earlier versions had—like Bill S.557.

The Division of Insurance will also “develop and implement a plan to educate providers and consumers regarding the rights of insured members and the responsibilities of carriers to promote compliance with” the Act. Nonetheless, insurers may want to proactively analyze this legislation and how it may affect their standard policies and procedures.

Photo of William Daley William Daley

William Maxwell Daley focuses his practice on insurance coverage litigation and business litigation. Read his full rc.com bio here.

Read more about William DaleyEmail
  • Posted in:
    Health Care and Life Sciences
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo