Thursday, October 8, 2015

Workplace Wellness, Data Collection and Privacy

Speaking about the Affordable Care Act (ACA) at an event earlier this week, I emphasized the popularity of the ACA’s pre-existing exclusion ban on insurers.  That is, under the ACA, as of January 1, 2014, health insurers may no longer exclude coverage for an individual’s pre-existing health conditions.  Overall, consumers like that provision of the ACA. 

Yet, voluntary workplace wellness programs permit insurers to discriminate on a person’s health status.  Many times, this discrimination is in the form of health insurance cost differentials.  For example, employees who agree to participate in a wellness program and/or achieve a certain health goal may pay less for their health insurance.  In essence, these programs may have the same effect as pre-existing exclusion provisions.  The data collected by workplace wellness programs not only could be used to differentiate between premiums paid by “healthy” employees and “unhealthy employees,” but could also be sold to third parties who might use the wellness information to discriminate based on a person’s health status for purposes of life insurance, loans or other credit applications.

At least that is the fear expressed by privacy advocates interviewed by the Kaiser Health News writers.  On September 30, 2015, Kaiser Health News featured a collection of articles regarding the collection of employee health data through workplace wellness programs and the privacy of that information.  One article featured a story about a wellness program implemented by a wellness vendor hired by the City of Houston.  In exchange for a $300 reduction in the cost of their medical coverage, City employees were asked to take a health risk assessment that asked about their disease history, drug and seat-belt use, blood pressure and other “delicate” information.   The authorization form signed by city employees stated that their health information might be posted in areas that “are reviewable to the public” and that the information might be subject to re-disclosure and no longer protected by privacy law. 

Houston Police Officers’ Union objected so strongly to the health risk assessment that the city switched to a different program. 

Privacy advocates view the world of workplace wellness data collection as the “wild west” because it lacks regulation and guidance regarding how employee health information is collected, stored and disclosed.  Wellness vendors who collect and store employee health information may or may not be covered by the Health Insurance Portability and Accountability Act (HIPAA), depending on whether they are a Business Associate of a health plan or whether the vendor itself is a HIPAA covered entity.  Even if a vendor is governed by HIPAA, disclosing de-identified health information to third parties that can “re-identify” the information could cause privacy concerns by wellness program participants.  The articles point out that these third parties could use the re-identified health information for lending, credit or mortgage decisions.  For example, the article states that credit card companies could raise rates for employees that wellness programs reveal to be couch potatoes, inferring that they are more likely to default.  And life insurers could deny coverage or raise prices based on unhealthy wellness results. 

The message from these articles to wellness vendors is to pay attention to the privacy protections your programs offer.  Failing to adequately protect participant data privacy could undermine the wellness program’s ultimate goal of improving employee population health, as well as the ACA goal of eliminating use of health status for discriminatory purposes.  Here are some steps wellness vendors can take to strengthen their privacy protections:
1.   Read the fine print of your participant consent forms.   Determine what your fine print says about collecting and sharing participant health information.  One wellness vendor interviewed for the Kaiser Health News article remarked that he had no idea the company’s disclosures permitted direct marketing from third parties based on the participant’s “attributes.”  Know what you have agreed to do.

2.  Revise your fine print if the language does not fit with your company’s privacy policy.  For example, if the language would permit third parties to re-identify de-identified information, you may want to revise that language to prohibit such practice.

3.  Determine if your company is subject to HIPAA privacy and security rules, either as a Business Associate of a health plan or as a “covered entity” provider.  If your company delivers health services (and most do) as well as conducts “covered transactions” under HIPAA (i.e., electronically submits health information for purposes of tracking encounters or submitting claims), you are likely a covered entity subject to HIPAA.  As noted in the Kaiser Health News articles, wellness vendors are often on the “border” of being subject to HIPAA.  So, it is important to find out and if you are, to comply with the regulations.

4.  Start thinking and implementing best practices when it comes to privacy.  As stated earlier, privacy protection in the wellness arena is currently the “wild west.”  Such a state of uncertainty provides opportunity for wellness companies to emerge as leaders and establish privacy standards themselves, rather than waiting for an enforcement agency to eventually dictate those standards.

As always, consider the Center for Health Law Equity, LLC as a resource to help your company achieve and maintain compliance.
To read the full Kaiser Health News articles on wellness programs and privacy, click here