Speaking about the Affordable Care Act (ACA) at an event
earlier this week, I emphasized the popularity of the ACA’s pre-existing
exclusion ban on insurers. That is,
under the ACA, as of January 1, 2014, health insurers may no longer exclude
coverage for an individual’s pre-existing health conditions. Overall, consumers like that provision of the
ACA.
Yet, voluntary workplace wellness programs permit insurers
to discriminate on a person’s health status.
Many times, this discrimination is in the form of health insurance cost
differentials. For example, employees
who agree to participate in a wellness program and/or achieve a certain health
goal may pay less for their health insurance.
In essence, these programs may have the same effect as pre-existing
exclusion provisions. The data collected
by workplace wellness programs not only could be used to differentiate between
premiums paid by “healthy” employees and “unhealthy employees,” but could also
be sold to third parties who might use the wellness information to discriminate
based on a person’s health status for purposes of life insurance, loans or other
credit applications.
At least that is the fear expressed by privacy advocates
interviewed by the Kaiser Health News writers.
On September 30, 2015, Kaiser Health News featured a collection of
articles regarding the collection of employee health data through workplace
wellness programs and the privacy of that information. One article featured a story about a wellness
program implemented by a wellness vendor hired by the City of Houston. In exchange for a $300 reduction in the cost
of their medical coverage, City employees were asked to take a health risk
assessment that asked about their disease history, drug and seat-belt use,
blood pressure and other “delicate” information. The
authorization form signed by city employees stated that their health information
might be posted in areas that “are reviewable to the public” and that the
information might be subject to re-disclosure and no longer protected by
privacy law.
Houston Police Officers’ Union objected so strongly to the
health risk assessment that the city switched to a different program.
Privacy advocates view the world of workplace wellness data
collection as the “wild west” because it lacks regulation and guidance
regarding how employee health information is collected, stored and
disclosed. Wellness vendors who collect
and store employee health information may or may not be covered by the Health
Insurance Portability and Accountability Act (HIPAA), depending on whether they
are a Business Associate of a health plan or whether the vendor itself is a
HIPAA covered entity. Even if a vendor
is governed by HIPAA, disclosing de-identified health information to third
parties that can “re-identify” the information could cause privacy concerns by
wellness program participants. The
articles point out that these third parties could use the re-identified health
information for lending, credit or mortgage decisions. For example, the article states that credit
card companies could raise rates for employees that wellness programs reveal to
be couch potatoes, inferring that they are more likely to default. And life insurers could deny coverage or
raise prices based on unhealthy wellness results.
The message from these articles to wellness vendors is to
pay attention to the privacy protections your programs offer. Failing to adequately protect participant
data privacy could undermine the wellness program’s ultimate goal of improving
employee population health, as well as the ACA goal of eliminating use of
health status for discriminatory purposes.
Here are some steps wellness vendors can take to strengthen their
privacy protections:
1. Read
the fine print of your participant consent forms. Determine what your fine print says about
collecting and sharing participant health information. One wellness vendor interviewed for the
Kaiser Health News article remarked that he had no idea the company’s
disclosures permitted direct marketing from third parties based on the
participant’s “attributes.” Know what
you have agreed to do.
2. Revise
your fine print if the language does not fit with your company’s privacy policy. For example, if the language would permit
third parties to re-identify de-identified information, you may want to revise
that language to prohibit such practice.
3. Determine
if your company is subject to HIPAA privacy and security rules, either as a
Business Associate of a health plan or as a “covered entity” provider. If your company delivers health services (and
most do) as well as conducts “covered transactions” under HIPAA (i.e.,
electronically submits health information for purposes of tracking encounters
or submitting claims), you are likely a covered entity subject to HIPAA. As noted in the Kaiser Health News articles,
wellness vendors are often on the “border” of being subject to HIPAA. So, it is important to find out and if you
are, to comply with the regulations.
4. Start
thinking and implementing best practices when it comes to privacy. As stated earlier, privacy protection in the
wellness arena is currently the “wild west.”
Such a state of uncertainty provides opportunity for wellness companies
to emerge as leaders and establish privacy standards themselves, rather than
waiting for an enforcement agency to eventually dictate those standards.
As always, consider the Center for Health Law Equity, LLC as
a resource to help your company achieve and maintain compliance.
To read the full Kaiser Health News articles on
wellness programs and privacy, click here.
No comments:
Post a Comment