Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Privacy And Data Security topic

No spam. Unsubscribe anytime.

County attorneys brief supervisors on HIPAA updates, reproductive-health privacy rule and planned risk analysis

2703573 · January 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

County attorneys updated supervisors on an HHS final rule on reproductive-health privacy, ongoing HIPAA policy updates, and plans to move privacy functions to Human Resources and to conduct a county risk analysis; staff flagged a likely budget request next fiscal year for the risk analysis.

Assistant County Attorney Nathan Peters and First Assistant County Attorney Susie Nearing briefed the board on updates to the county’s HIPAA policy, a new federal final rule addressing reproductive-health privacy, and plans for a countywide risk analysis.

Peters said the 2024 federal rule broadly prohibits using or disclosing protected health information (PHI) to investigate or impose liability on individuals for seeking reproductive-health care; the county’s HIPAA policy will be updated to reflect that rule, and the county will add an attestation form for requestors where appropriate.

The attorneys emphasized the “minimum necessary” principle for PHI and cautioned employees against sharing PHI in unsecured ways (for example, in broadly shared Microsoft Teams documents, text messages, or non-county email). They outlined breach-notification requirements and said county IT will be involved in the planned security/risk analysis.

Nearing said the county intends to shift day-to-day privacy-officer responsibilities into Human Resources and to use the County Attorney’s Office as a consultative resource for complex questions. She said a comprehensive risk analysis is overdue and that the county will likely request budget funds in the next fiscal year to hire a consultant or otherwise resource that work. Supervisors asked scenario questions about employee medical information, confidentiality, and when a worker may authorize release of personal health information; attorneys explained the differences between HIPAA, employee-record confidentiality (for example FMLA), and the county’s internal policies.

No formal policy vote occurred at the work session; staff said they will circulate updated policy language and updated intranet resources to departments and proceed with risk-analysis planning and policy updates.