“Please Unlock Your Phone”: Why Reasonable Suspicion Should Be Extended to Cursory Searches of Electronic Devices at the Border
Download a copy of this Note:
Student Note | 107 KY. L. J. ONLINE | Volume 107
“Please Unlock Your Phone”: Why Reasonable Suspicion Should Be Extended to Cursory Searches of Electronic Devices at the Border
Will Carroll[1]
“It would be foolish to contend that the degree of privacy secured to citizens by the Fourth Amendment has been entirely unaffected by the advance of technology.”[2]
I. Introduction
It is well established that the primary function of the Bill of Rights is to preserve essential liberties for citizens of the United States.[3] Cornerstone rights such as freedom of speech derive directly from the first ten amendments.[4] The protection of citizens from unreasonable searches and seizures by government agents also originates from the Bill of Rights.[5] The Fourth Amendment establishes:The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.[6]As one scholar noted, the Fourth Amendment “makes plain, perhaps more than any other provision of the Bill of Rights, that the Constitution does not tolerate the tactics of a police state.”[7] Unfortunately, U.S. border agents act with impunity, employing totalitarian, police state tactics by performing unconstitutional searches and seizures on a daily basis.[8] Although the right to be secure against unreasonable government intrusion is a vital freedom enjoyed by American citizens on the interior of the country, its sanctity is being violated at the border in an area dubbed the “Constitution-free zone.”[9]Traditionally, border searches are exempt from Fourth Amendment protections in a doctrine known fittingly as the border search exception.[10] This exception exists “pursuant to the long-standing right of the sovereign to protect itself by stopping and examining persons and property crossing into [the U.S.]” and is “reasonable simply by virtue of the fact that [the searches] occur at the border.”[11] In order to keep pace with rapidly advancing technology, some federal courts have explicitly extended the exception to electronic devices, holding that “reasonable suspicion is not needed for customs officials to search a laptop or other personal electronic storage devices at the border.”[12] This is particularly concerning because in today’s world, smartphones, tablets, and laptops have rapidly shifted from a luxury to a daily necessity.[13] The Supreme Court recognized that “modern cell phones . . . are now such a pervasive and insistent part of daily life that the proverbial visitor from Mars might conclude they were an important feature of human anatomy.”[14]The practice of searching electronic devices at the border has raised serious Constitutional concerns.[15] Statistics for the 2017 calendar year released by the U.S. Customs and Border Protection (“CBP”) show that 30,200 international travelers, both inbound and outbound, were subjected to electronic device searches.[16] This is roughly a 37% increase from 2016.[17] CBP insists that “the need for border searches of electronic devices is driven by [their] mission to protect the American people and enforce the nation’s laws in this digital age.”[18] Many disagree with these border searches, and in September 2017, the American Civil Liberties Union (“ACLU”) filed a lawsuit in federal court “on behalf of 11 travelers whose smartphones and laptops were searched without warrants at the U.S. border.”[19] The ACLU’s position is that Fourth Amendment protections should extend to border searches, “especially when it comes to electronic devices like smartphones and laptops.”[20]The most recent development in border search exception precedent was decided by the Ninth Circuit in United States v. Cotterman.[21] In Cotterman, the court ruled that a forensic search of electronic devices at the border requires reasonable suspicion.[22] Forensic examination of computers is “a powerful tool capable of unlocking password-protected files, restoring deleted material, and retrieving images viewed on web sites.”[23] While this decision is certainly a step in the right direction, it fails to address the problem of unwarranted cursory searches of electronic devices. A cursory search, or “basic search” according to CBP, is any search that does not require “external equipment, through a wired or wireless connection, to an electronic device not merely to gain access to the device, but to review, copy, and/or analyze its contents.”[24] Cursory searches expose your electronic device’s texts, emails, photos, internet history, and other personal information. This Note will argue that the reasonable suspicion standard currently applied to investigative searches of electronic devices at the border should be extended to cursory searches due to the clear violation of digital privacy and Fourth Amendment protections against unreasonable searches and seizures.Part II of this Note will discuss basic Fourth Amendment principles and the origins of the border search exception with accompanying case law. Part III will unpack the Ninth Circuit’s en banc decision in United States v. Cotterman and analyze the current situation of the border search exception. Part IV will illustrate arguments against extending reasonable suspicion to cursory searches of electronic devices at the border while presenting rebuttals to each of those arguments. Specifically, this Note argues that, in United States v. Cotterman, the Ninth Circuit should have extended the reasonable suspicion standard to cursory searches of electronic devices at the border. Part V lays out possible solutions to the issue and the impacts that might result from those solutions. Part VI concludes this Note.
II. A Brief Legal History of the Border Search Exception
The Fourth Amendment protects citizens against unreasonable searches and seizures unless the government has secured a warrant upon probable cause.[25] It is important to note that “the usual remedy for a Fourth Amendment violation is suppression of the illegally seized evidence”[26] via the exclusionary rule. The exclusionary rule is “a deterrent sanction that bars the prosecution from introducing evidence obtained by way of a Fourth Amendment violation.”[27] The key factor when applying the exclusionary rule is whether or not the individual had a reasonable expectation of privacy in the area searched.[28] In his concurring opinion in Katz v. United States, Justice Harlan laid out the twofold test for determining whether an individual has an expectation of privacy in a certain area: “first that a person have exhibited an actual (subjective) expectation of privacy and, second, that the expectation be one that society is prepared to recognize as ‘reasonable.’”[29]Exceptions to Fourth Amendment protections are common in the U.S. legal system such as the doctrines of plain view[30] and search incident to arrest.[31] These exceptions demonstrate the willingness of courts to mold the plain text of the Amendment to fit specific situations. For example, in Carroll v. United States, the Supreme Court ruled that warrantless searches of vehicles were permitted as long as the officer performing the search had probable cause.[32] The relevant language asserts that “[t]ravelers may be so stopped in crossing an international boundary because of national self-protection reasonably requiring one entering the country to identify himself as entitled to come in, and his belongings as effects which may be lawfully brought in.”[33] This language laid the initial groundwork for the border search doctrine and is often cited in cases utilizing the exception.[34]Authority for the border search exception derives from several landmark Supreme Court decisions.[35] In justifying the border search doctrine, the Court has stated that the “exception is grounded in the recognized right of the sovereign to control, subject to substantive limitations imposed by the Constitution, who and what may enter the country.”[36] In particular, “the Government’s interest in preventing the entry of unwanted persons and effects is at its zenith at the international border.”[37] The Court has explicitly stated that “the expectation of privacy is less at the border than it is in the interior.”[38] However, despite the broad language of border search exception cases, the Court has also implied that the Fourth Amendment might impose limits on border searches, but it has never definitively spoken on the subject.[39] Courts must balance “the sovereign’s interests at the border” with the Fourth Amendment rights of the individual contesting the search.[40]While the Supreme Court has addressed searches of persons[41] and vehicles[42] at the border, it has never directly ruled on the issue of searches of personal electronic devices at the border. The law on border searches of electronic devices derives mostly from the Courts of Appeals.[43] In United States v. Arnold, the Ninth Circuit extended the border search exception to electronic devices, holding that “reasonable suspicion is not needed for customs officials to search a laptop or other personal electronic storage devices at the border.”[44] Five years later, the Ninth Circuit was called on again to review the issue of border searches and electronic devices in United States v. Cotterman.[45]
III. Cotterman and Beyon
2. United States v. Cotterman
In United States v. Cotterman, Howard Cotterman and his wife were crossing the U.S.-Mexico border when he was flagged by the Treasury Enforcement Communication System for potentially possessing child pornography.[46] During the search of his vehicle, border agent Antonio Alvarado recovered and inspected three cameras and two laptops containing personal photos, along with several password-protected files.[47] The Cottermans were set free; however, suspecting that Mr. Cotterman had child pornography locked behind password-protection, the agents transported the laptops and cameras 170 miles to an off-site facility in order to conduct a forensic search of the devices.[48] The investigative search revealed hundreds of images of child pornography behind the password-protected files on Mr. Cotterman’s laptop.[49]After a grand jury indicted Mr. Cotterman for several offenses related to child pornography,[50] Mr. Cotterman moved to suppress the evidence claiming that it was acquired from an unlawful search and seizure violating his Fourth Amendment rights.[51] Following lower court proceedings, a divided three panel Ninth Circuit held that “reasonable suspicion was not required for the search and that ‘the district court erred in suppressing the evidence lawfully obtained under border search authority.’”[52]On rehearing en banc, the court ruled that forensic examination of electronic devices at the border requires a showing of reasonable suspicion.[53] The court explained that “[electronic devices] contain the most intimate details of our lives: financial records, confidential business documents, medical records and private emails,”[54] all of which “implicate[ ] the Fourth Amendment’s specific guarantee of the people’s right to be secure in their ‘papers.’”[55] In coming to their conclusion, the majority conceded that “legitimate concerns about child pornography do not justify unfettered crime-fighting searches or an unregulated assault on citizens’ private information.”[56] The court stated that “[r]easonable suspicion is a modest, workable standard that is already applied in the extended border search, Terry stop, and other contexts.”[57] Finally, the court reasoned that “[i]ts application to the forensic examination here will not impede law enforcement’s ability to monitor and secure our borders or to conduct appropriate searches of electronic devices.”[58]The court applied this standard to Mr. Cotterman’s case and ruled that the investigative search of his laptop was conducted upon reasonable suspicion and his “motion to suppress therefore was erroneously granted.”[59] Although Mr. Cotterman was unable to suppress the evidence, the court correctly balanced “the sovereign’s interests at the border” with the Fourth Amendment rights of the individual contesting the search.[60] Citing Justice Scalia, the court explained that “[i]t would be foolish to contend that the degree of privacy secured to citizens by the Fourth Amendment has been entirely unaffected by the advance of technology.”[61] However, the court did not completely overrule Arnold, which rejected the requirement of reasonable suspicion for both cursory and investigative searches of electronic devices.[62] In fact, they explicitly stated that “we have approved a quick look and uninstructive search of laptops.”[63] While the court solved the issue of unreasonable investigative searches, the court is legitimizing the policy that cursory searches of personal electronic devices do not require reasonable suspicion.2. The Current SituationAs a result of Cotterman, travelers can be confident that border agents lack the authority to perform investigative searches of their electronic devices without reasonable suspicion. This is clearly a win for digital privacy rights. Unfortunately, the problem of suspicionless cursory searches is still rampant, as demonstrated by the ACLU, which recently filed a lawsuit against the Department of Homeland Security challenging border searches of electronic devices.[64]The concerning part of electronic device border searches stems from the fact that these are not isolated incidents. CBP released statistics for 2017 claiming that 30,200 international travelers, inbound and outbound, had their electronic devices searched.[65] That is roughly a 37% increase of electronic devices searched from 2016 to 2017.[66] CBP argues that national security outweighs the inconveniences of a small percentage of travelers, but privacy advocates disagree, stating that “[t]hey see the growth of a surveillance state eating away civil liberties a mouthful at a time.”[67]In early January 2018, CBP released a directive that outlined their procedures related to searching electronic devices at the border.[68] The directive states that “[t]he plenary authority of the Federal Government to conduct searches and inspections of persons and merchandise crossing our nation’s borders is well-established and extensive; control of the border is a fundamental principle of sovereignty.”[69]Outlining CBP procedures, the directive states:Border searches of electronic devices may include searches of the information stored on the device when it is presented for inspection or during its detention by CBP for an inbound or outbound border inspection. The border search will include an examination of only the information that is resident upon the device and accessible through the device’s operating system or through other software, tools or applications.[70]Further, the directive distinguishes between basic and advanced border searches, articulating:In the course of a basic search, with or without suspicion, an Officer may examine an electronic device and may review and analyze information encountered at the border . . . An advanced search is any search in which an Officer connects external equipment, through a wired or wireless connection, to an electronic device not merely to gain access to the device, but to review, copy, and/or analyze its contents.[71]The directive requires CBP to obtain reasonable suspicion before performing an advanced search, i.e. an investigative search.[72] Here, it is clear they are abiding by Cotterman’s precedent. In Cotterman, the advanced search occurred when the password-protected files on Mr. Cotterman’s computer were accessed by forensic software at the off-site facility.[73]In sum, the 2018 CBP Directive continues to permit unconstitutional border searches.[74] In America, the people are taking a stand. For example, there has been a recent spike in publications instructing readers on how to protect their privacy at the border[75] and privacy complaints continue to be filed against the Department of Homeland Security.[76] Even with this resistance, these constitutional violations are unlikely to stop.[77] What is the next step?The Supreme Court has never directly addressed border searches of electronic devices. In Riley v. California the Court ruled that “a warrant is generally required before [searching a cell phone], even when a cell phone is seized incident to arrest.”[78] The Court recognized that because times have changed and modern smartphones contain highly private and sensitive data, the intrusion on privacy today is not limited to physical realities.[79] Riley proves that federal courts are at the very least cognizant of the importance of electronic devices and would be a logical place for the Supreme Court to start in making future rulings. Until then, however, it is important for lower courts to take the Cotterman decision one step further and apply the reasonable suspicion standard to cursory searches of electronic devices.
3. Arguments Against Extending Reasonable Suspicion to Cursory Searches: the Cotterman Dissent
Judge Smith’s dissenting opinion in Cotterman lays out three primary arguments against extending reasonable suspicion to cursory searches of electronic devices: administrative burdens, national security concerns, and the diminished expectation of privacy at the border.[80] Although Judge Smith’s dissent was focused on the reasonable suspicion standard as applied to investigative searches of electronic devices, the same general arguments apply with equal force to cursory searches of electronic devices.A. The Dangers of Administrative BurdensThe primary argument against extending reasonable suspicion to cursory searches of electronic devices at the border is that the additional step of requiring border agents to use their reasonable judgment will create a potentially dangerous administrative burden.[81] The dissent in Cotterman was concerned that “[r]equiring law enforcement to make such complex legal determinations on the spot, and in the face of potentially grave national security threats, strips agents of their necessary discretion and deprives them of an efficient and administrable rule.”[82]Border agents must rely on their broad discretion without case-by-case determination of individuals because “[they] process hundreds of thousands of travelers each day and conduct thousands of searches of electronic devices each year.”[83] According to the dissent, forcing agents to comply with a case-by-case determination to conduct investigative searches of electronic devices at the border creates an undue burden due to the sheer number of individuals crossing the border every day.[84]In practice, however, the reasonable suspicion standard would cause minimal administrative burdens on border agents while preserving the critical rights guaranteed by the Fourth Amendment. The Cotterman court best articulated the sentiment when it stated, “[r]easonable suspicion is a modest, workable standard that is already applied in the extended border search, Terry stop, and other contexts.”[85] Continuing, the court explained that “[i]ts application to the forensic examination here will not impede law enforcement’s ability to monitor and secure our borders or to conduct appropriate searches of electronic devices.”[86]The same can easily be said about cursory examination of electronic devices. The standard of reasonable suspicion is less than probable cause, requiring “merely ‘a particularized and objective basis’ for suspecting” the individual is engaging in criminal activity.[87] Simply requiring border agents to have some reasonable, objective basis for conducting a cursory search on a personal electronic device is hardly an administrative burden.In the world of Constitutional Law, reasonable suspicion is a very moderate standard. The officer—or in cases of border searches, border agent—need not have a definitive certainty that the person is engaged in some unlawful conduct. Rather, the agent must assess the totality of the circumstances[88] and have some suspicion that the traveler coming through the border is involved in an illegal activity.The dissent in Cotterman worries that the holding forces agents “to determine on a case–by–case and moment–by–moment basis whether a search of digital data remains ‘unintrusive’…or has become ‘comprehensive and intrusive.’”[89] A solution is to simply extend reasonable suspicion to cursory searches of electronic devices. The “complex legal determination[]”[90] the dissent seems to be worried about would not exist if border agents were not required to differentiate between investigative and cursory searches. Applying the reasonable suspicion standard to both types of searches clearly eliminates this problem.B. The Interest in National SecurityThe Cotterman dissent also argued that there is an ever-present threat of terrorists entering the country.[91] Citing a U.S. Customs and Border Protection directive, Judge Smith explained that “border searches of electronic storage devices are ‘essential’ for ‘detect[ing] evidence relating to terrorism and other national security measures.’”[92] Further, terrorists tend to rely on electronic storage devices for a multitude of uses such as copying and altering passports and other travel documents.[93] Therefore, “[b]y providing special privacy protections for electronic devices at the border, the majority eliminates the powerful deterrent of suspicionless searches and significantly aids” terrorists and criminals.[94] This sentiment has been shared among scholars. One law review article suggests that the Cotterman decision has made it “more difficult for U.S. border agents to combat terrorism and child pornography” by carving “out a piece of the border search doctrine.”[95]Judge Smith predicted that “a reasonable suspicion requirement will likely disincentivize agents to conduct laptop searches in close cases.”[96] Theoretically, border agents accused of conducting an unreasonable search will face “very real consequences” such as the possibility of being sued in their official capacities for civil damages.[97] By disincentivizing border agents from conducting searches of electronic devices for fear of reprimand or legal action against them, the dissent argues that “these misaligned incentives create unnecessary risk … for our entire nation.”[98]However, there is no proof that extending reasonable suspicion to cursory searches, let alone investigative searches, would negatively impact the efficiency of border agents in carrying out their duties. Requiring the agent to make a reasonable determination in light of the totality of the circumstances is not a significant burden on the agent’s ability to carry out his duty. Reasonable suspicion “is a less demanding standard than probable cause and requires a showing considerably less than preponderance of the evidence.”[99] The border agent simply needs to have “a minimal level of objective justification” for searching the phone.[100] This standard is extremely flexible and, at the very least, creates a baseline for Fourth Amendment protections of electronic devices at the border.Further, the dissent’s argument that attaching reasonable suspicion to a border search of an electronic device will somehow disincentivize border agents from conducting a search in the first place is unfounded. Simply because a border agent must use a minimal level of objective justification to search an electronic device does not mean they will be exposed to legal consequences. In fact, lawsuits have already been filed against CBP for the invasive searches conducted on electronic devices even without the reasonable suspicion standard.[101]To assert that extending reasonable suspicion to searches of electronic devices would cause personal reprimand is baseless. If anything, it would diminish the number of lawsuits against CBP because the standard for conducting a search would be higher, theoretically resulting in a better-informed staff of border agents.C. The Diminished Expectation of Privacy at the BorderFinally, the dissent in Cotterman suggests that searches of electronic data have never been immune to the border search exception.[102] Judge Smith questioned the privacy of electronic devices to begin with, explaining that electronic storage devices are “hardly a bastion of privacy” because “they transmit a massive amount of intimate data to the public on an almost constant basis.”[103] According to Judge Smith, due to “the steady erosion of our privacy on the Internet, searches of electronic storage devices may be increasingly akin to a well-placed Internet search.”[104] The dissent asserts that “[m]apping our privacy rights by the amount of information we carry with us leads to unreasonable and absurd results.”[105]The Supreme Court has explicitly stated that because “an arrestee has diminished privacy interests does not mean that the Fourth Amendment falls out of the picture entirely.”[106] Further, “not every search ‘is acceptable solely because a person is in custody.’”[107] This same logic can be applied to travelers and border searches of electronic devices. The Cotterman court explained that “the uniquely sensitive nature of data on electronic devices carries with it a significant expectation of privacy and thus renders an exhaustive exploratory search more intrusive than with other forms of property.”[108] There is no reason why this principle should not also apply to cursory searches as well. The Court has already implied that searching the cell phone of an arrestee without a warrant is an unreasonable intrusion into the arrestee’s constitutional privacy due to the sensitive information contained on modern smartphones.[109] It is logical to apply the reasonable suspicion standard to cursory searches of electronic devices.The Supreme Court explicitly stated that “the Fourth Amendment protects people, not places.”[110] As the Court explained in Riley, “when ‘privacy-related concerns are weighty enough’ a ‘search may require a warrant, notwithstanding the diminished expectations of privacy’” of the individual.[111] Even more so, this Note is not arguing that a warrant is required for a border search of an electronic device, rather it is arguing that the workable standard of reasonable suspicion be applied. As the Supreme Court noted in 1990:Reasonable suspicion is a less demanding standard than probable cause not only in the sense that reasonable suspicion can be established with information that is different in quantity or content than that required to establish probable cause, but also in the sense that reasonable suspicion can arise from information that is less reliable than that required to show probable cause.[112]Pursuant to Riley, the privacy-related concerns in an individual’s electronic device should clearly outweigh the diminished expectation of privacy at the border.
4. Solutions and Results
The most effective way to fix this problem is through legislative action. However, due in large part to partisan politics, the burden of responsibility for upholding U.S. citizens’ Fourth Amendment rights in cases of electronic device border searches falls upon the federal courts. As discussed earlier, CBP’s latest directive was clearly influenced by the Cotterman decision.[113] If courts take the initiative in restoring digital privacy rights by applying the reasonable suspicion standard to cursory searches of electronic devices, CBP would abide by that decision. Therefore, while legislative action would be the most effective and secure way to establish this standard, courts clearly have the ability to influence CBP policies.What would the application of reasonable suspicion to cursory searches of electronic devices at the border entail? Although reasonable suspicion “is a less demanding standard than probable cause and requires a showing considerably less than preponderance of the evidence,” there must still be some “minimal level of objective justification for making the stop.”[114] In practice, a border agent would first need to assess the totality of the circumstances, i.e. the entire situation, as opposed to one specific factor.[115] Based on the totality of the circumstances, the agent would then make an objective determination as to whether the particular traveler was engaged in some type of criminal activity or may be a threat to national security.For instance, if the agent observes physical manifestations of nervousness from a particular traveler such as profuse sweating or shaking, that might be enough to satisfy the reasonable suspicion standard. The Supreme Court has noted that “nervous, evasive behavior is a pertinent factor in determining reasonable suspicion.”[116] Similarly, if the agent notices strange travel patterns in the traveler’s documents, that too might be enough to meet the low standard of reasonable suspicion. Again, reasonable suspicion “does not deal with hard certainties, but with probabilities.”[117] Applying this standard to cursory searches of electronic devices is a small demand, considering the privacy rights of U.S. citizens are being infringed upon by border agents on a daily basis.
5. Conclusion
Courts need to extend reasonable suspicion to cursory searches of electronic devices at the border. Generally speaking, however, that would only be the start. The border search exception’s detrimental effect on digital privacy is a stain on the integrity of the Constitution. The exception is a relic of the past in this age of rapid technological advancement. It clearly requires a new approach as we store more and more highly sensitive, confidential data on our phones, laptops, and tablets. At the end of the day, Cotterman was a strong starting point, but the next logical step is to extend the reasonable suspicion standard to cursory searches of electronic devices.
[1] J.D. Expected May 2019. Thank you to family, friends, and the Kentucky Law Journal staff for making this note possible.
[2] Kyllo v. United States, 533 U.S. 27, 33–34 (2001).
[3] Bill of Rights Institute, Bill of Rights of the United States of America (1791), http://www.billofrightsinstitute.org/founding-documents/bill-of-rights/ (last visited Jan. 20, 2018).
[4] U.S. Const. amend. I.
[5] Tracey Maclin, The Central Meaning of the Fourth Amendment, 35 Wm. & Mary L. Rev. 197, 197 (1993).
[6] U.S. Const. amend. IV.
[7] Maclin, supra note 5, at 197.
[8] See CBP Releases Updated Border Search of Electronic Device Directive and FY17 Statistics, U.S. Department of Homeland Security, https://www.cbp.gov/newsroom/national-media-release/cbp-releases-updated-border-search-electronic-device-directive-and (last modified Jan. 9, 2018).
[9] See The Constitution in the 100-Mile Border Zone, American Civil Liberties Union, https://www.aclu.org/other/constitution-100-mile-border-zone (last visited Jan. 22, 2018); see also Scott Bomboy, Does a Constitution-Free Zone Really Exist in America?, National Constitution Center (Feb. 15, 2013), https://constitutioncenter.org/blog/does-a-constitution-free-zone-really-exist-in-america (explaining that the phrase “Constitution free zone” derives from the fact that border agents can search any electronic device without cause, thus bypassing traditional Fourth Amendment protections).
[10] See United States v. Ramsey, 431 U.S. 606, 620 (1977).
[11] Id. at 616.
[12] United States v. Arnold, 533 F.3d 1003, 1008 (9th Cir. 2008). The standard of reasonable suspicion is defined as “a particularized and objective basis for suspecting the particular person stopped of criminal activity.” United States v. Cortez, 4419 U.S. 411, 417-18 (1981). In making such a determination, “the totality of the circumstances—the whole picture—must be taken into account.” Id. at 417.
[13] Emily Dreyfuss, No, iPhones Aren’t Luxury Items. They’re Economic Necessities, Wired (Mar. 7, 2017), https://www.wired.com/2017/03/no-iphones-arent-luxury-items-theyre-economic-necessities/.
[14] Riley v. California, 134 S. Ct. 2473, 2484 (2014).
[15] Marcus Wolf, Border Agents Can Legally Search Electronic Devices, Government Technology (Apr. 17, 2017), http://www.govtech.com/security/Border-Agents-Can-Legally-Search-Electronic-Devices.html.
[16] U.S. Department of Homeland Security, supra note 8.
[17] Id. (19,051 in 2016 compared to 30,200 in 2017).
[18] Id.
[19] Lawsuit on Behalf of 11 Travelers Challenges Searches of Electronic Devices as Unconstitutional, American Civil Liberties Union (Sept. 13, 2017), https://www.aclu.org/news/aclu-eff-sue-over-warrantless-phone-and-laptop-searches-us-border.
[20] Esha Bhandari, Nathan Freed Wessler, and Noa Yachot, Can Border Agents Search Your Electronic Devices? It’s Complicated, American Civil Liberties Union (Mar. 14, 2017), https://www.aclu.org/blog/privacy-technology/privacy-borders-and-checkpoints/can-border-agents-search-your-electronic.
[21] United States v. Cotterman, 709 F.3d 952 (9th Cir. 2013).
[22] Id. at 957.
[23] Id.
[24] CBP Directive No. 3340-049A: Border Search of Electronic Devices, U.S. Customs and Border Protection (Jan. 4, 2018), https://www.cbp.gov/sites/default/files/assets/documents/2018-Jan/CBP-Directive-3340-049A-Border-Search-of-Electronic-Media-Compliant.pdf.
[25] U.S. Const. amend. IV.
[26] Investigation and Police Practices, 80 Geo. L.J. 939, 939 (1992).
[27] Davis v. United States, 564 U.S. 229, 231–232 (2011).
[28] See Katz v. United States, 389 U.S. 347, 360 (1967) (Harlan, J. concurring).
[29] Id. at 361.
[30] See Coolidge v. New Hampshire, 403 U.S. 443, 465 (1971) (“It is well established that under certain circumstances the police may seize evidence in plain view without a warrant.”).
[31] See Hill v. California, 401 U.S. 797, 804–805 (1971) (holding that a search incident to a valid arrest does not violate the Fourth Amendment).
[32] Carroll v. United States, 267 U.S. 132,154 (1925).
[33] Id.
[34] See United States v. Montoya de Hernandez, 473 U.S. 531, 563 (1985) (Stevens, J. Concurring) (quoting Carroll, 267 U.S. at 154).
[35] See United States v. Ramsey, 431 U.S. 606 (1977); United States v. Flores-Montano, 541 U.S. 149 (2004).
[36] Ramsey, 431 U.S. at 620.
[37] Flores-Montano, 541 U.S. at 152.
[38] Id. at 154.
[39] United States v. Seljan, 547 F.3d 993, 999–1000 (9th Cir. 2008).
[40] United States v. Montoya de Hernandez, 473 U.S. 531, 539–40 (1985).
[41] See id. at 544.
[42] See Flores-Montano, 541 U.S. at 155-56.
[43] See United States v. Arnold, 533 F.3d 1003, 1008 (9th Cir. 2008); United States v. Cotterman, 709 F.3d 952 (9th Cir. 2013).
[44] Arnold, 533 F.3d at 1008.
[45] United States v. Cotterman, 709 F.3d 952 (9th Cir. 2013).
[46] Id. at 957.
[47] Id. at 957-58.
[48] Id. at 958.
[49] Id. at 959.
[50] Id.
[51] Id.
[52] Id.
[53] Id.at 968.
[54] Id. at 964.
[55] Id. (quoting U.S. Const. amend. IV).
[56] Id. at 966.
[57] Id. In Terry, the Supreme Court explained that “[w]hen an officer is justified in believing that the individual whose suspicious behavior he is investigating at close range is armed and presently dangerous to the officer or to others, it would appear to be clearly unreasonable to deny the officer the power to take necessary measures to determine whether the person is in fact carrying a weapon and to neutralize the threat of a physical harm.” Terry v. Ohio, 392 U.S. 1, 24 (1968). The Court ruled that “there must be a narrowly drawn authority to permit a reasonable search for weapons for the protection of the police officer, where he has reason to believe that he is dealing with an armed and dangerous individual, regardless of whether he has probable cause to arrest the individual for a crime.” Id. at 27 (emphasis added). Reasonable suspicion generally requires that the officer “point[s] to specific and articulable facts which, taken together with rational inferences from those facts, reasonably warrants” an intrusion. Id. at 21.
[58] Cotterman, 709 F.3d at 966.
[59] Id. at 970.
[60] United States v. Montoya de Hernandez, 473 U.S. 531, 539–40 (1985).
[61] Cotterman, 709 F.3d at 965 (quoting Kyllo v. United States, 533 U.S. 27, 33–34 (2001)).
[62] United States v. Arnold, 533 F.3d 1003, 1008 (9th Cir. 2008).
[63] Id. at 960.
[64] See Lawsuit on behalf of 11 Travelers supra note 19.
[65] U.S. Department of Homeland Security, supra note 8.
[66] Id.
[67] Frank Miniter, Are You Okay With The Government Searching Your Cell Phone?, Forbes (Jan. 8, 2018, 01:19PM), https://www.forbes.com/sites/frankminiter/2018/01/08/are-you-okay-with-the-government-searching-your-cell-phone/#173bca0410ed.
[68] U.S. Customs and Border Protection, supra note 25.
[69] Id.
[70] Id.
[71] Id.
[72] Id.
[73] United States v. Cotterman, 709 F.3d 952, 958 (9th Cir. 2013).
[74] Sophia Cope & Aaron Mackey, New CBP Border Device Search Policy Still Permits Unconstitutional Searches, Electronic Frontier Foundation (Jan. 8, 2018), https://www.eff.org/deeplinks/2018/01/new-cbp-border-device-search-policy-still-permits-unconstitutional-searches.
[75] See Hilary Beaumont, Invasion of Privacy: Border Agents are Seizing Travellers’ Phones and Asking for Their Passwords. Here’s How to Protect Yourself, Vice News (Feb. 17, 2017), https://news.vice.com/en_ca/article/ywn8pj/how-to-secure-your-phone-when-crossing-the-border; Esha Bhandari, Nathan Freed Wessler, and Noa Yachot, Can Border Agents Search Your Electronic Devices? It’s Complicated, American Civil Liberties Union (Mar. 14, 2017), https://www.aclu.org/blog/privacy-technology/privacy-borders-and-checkpoints/can-border-agents-search-your-electronic; Rebecca Harrington, Federal Agents Can Search Your Phone at the U.S. Border – Here’s How to Protect Your Personal Information, Business Insider (Sept. 13, 2017, 2:37 PM), http://www.businessinsider.com/can-us-border-agents-search-your-phone-at-the-airport-2017-2; and E.D Cauchi, What if U.S. Border Agents Ask for Your Cellphone?, NBC News (Apr. 4, 2017), https://www.nbcnews.com/news/us-news/what-if-u-s-border-agents-ask-your-cellphone-n742511; Esha Bhandari, Nathan Freed Wessler, and Noa Yachot, Can Border Agents Search Your Electronic Devices? It’s Complicated, American Civil Liberties Union (Mar. 14, 2017), https://www.aclu.org/blog/privacy-technology/privacy-borders-and-checkpoints/can-border-agents-search-your-electronic.
[76] Charlie Savage, Privacy Complaints Mount Over Phone Searches at US Border Since 2011, Boston Globe, https://www.bostonglobe.com/news/nation/2017/12/23/privacy-complaints-mount-over-phone-searches-border-since/3Nk97AUtgK7wQEKZ0pkRnI/story.html.
[77] Searches of Phones at the Border Unlikely to Stop, Washington Examiner (Jan. 16, 2018, 12:01 AM), http://www.washingtonexaminer.com/searches-of-phones-at-the-border-unlikely-to-stop/article/2645452.
[78] Riley v. California, 134 S.Ct. 2473, 2493 (2014).
[79] Id. at 2489-90.
[80] United States v. Cotterman, 709 F.3d 952, 981–94 (9th Cir. 2013) (Smith, J. dissenting).
[81] Id. at 982.
[82] Id.
[83] Id.
[84] Id.
[85] Id. at 966.
[86] Id.
[87] United States v. Tiong, 224 F.3d 1136, 1140 (9th Cir. 2000) (quoting Ornelas v. United States, 517 U.S. 690, 696 (1996)).
[88] The totality of the circumstances focuses on the entire situation rather than one specific factor. Totality-of-the-Circumstances Test, Black’s Law Dictionary (10th ed. 2014).
[89] Cotterman, 709 F.3d at 984. When the dissent mentions an “unitrusive” search, they mean a cursory search, and a “comprehensive” search means an investigative search.
[90] Id. at 984.
[91] Id. at 984–85.
[92] Id. at 985 (U.S. Customs and Border Protection, Border Search of Electronic Devices Containing Information, CBP Directive No. 3340–049 § 1 (2009), https://www.dhs.gov/xlibrary/assets/cbp_directive_ 3340-049.pdf).
[93] Cotterman, 709 F.3d at 985.
[94] Id.
[95] Michael Creta, A Step in the Wrong Direction: The Ninth Circuit Requires Reasonable Suspicion for Forensic Examinations of Electronic Storage Devices During Border Searches in United States v. Cotterman, B.C. L. Rev E-Supp., 2014, at 45. Michael Creta, A Step in the Wrong Direction: The Ninth Circuit Requires Reasonable Suspicion for Forensic Examinations of Electronic Storage Devices During Border Searches in United States v. Cotterman, 55 B.C. L. Rev E-Supplement 31, 45 (2014).
[96] Cotterman, 709 F.3d at 985.
[97] Id.
[98] Id. at 986.
[99] Illinois v Wardlow, 528 U.S. 119, 123 (2000).
[100] Id.
[101] See, e.g., Zack Huffman, Homeland Security Sued Over Warrantless Tech Searches at Border, Courthouse News Service (Sept. 13, 2017), https://www.courthousenews.com/homeland-security-sued-warrantless-tech-searches-border/.
[102] Cotterman, 709 F.3d at 986.
[103] Id.
[104] Id.
[105] Id. at 987.
[106] Riley v. California, 134 S.Ct. 2473, 2488 (2014).
[107] Id. (quoting Maryland v. King, 569 U.S. 435, 463 (2013)).
[108] Cotterman, 709 F.3d at 966 (majority opinion).
[109] Riley, 134 S.Ct. at 2489–90.
[110] Katz v. United States, 389 U.S. 347, 351 (1967).
[111] Riley, 134 S.Ct. at 2488 (quoting Maryland v. King, 569 U.S. 435, 438 (2013)).
[112] Alabama v. White, 496 U.S. 325, 330 (1990) (emphasis added).
[113] See U.S. Customs and Border Protection, supra note 91.
[114] Illinois v. Wardlow, 528 U.S. 119, 123 (2000) (citing United States v. Sokolow, 490 U.S. 1, 7 (1989)).
[115] Totality-of-the-Circumstances Test, Black’s Law Dictionary (10th ed. 2014).
[116] Wardlow, 528 U.S. at 124 (2000).
[117] United States v. Cortez, 449 U.S. 411, 418 (1981).
More Coverage, More Problems: No Private Remedies for Kentuckians Hurt by HIPAA Violations After Adoption of the Affordable Care Act
Note | KLJ Online Committee Editor Chelsea Hayes discusses the shortcomings of Kentucky law in protecting patients from violations of privacy, and what the state should do about it
Note | 103 KY. L. J. ONLINE 7 | Aug. 7, 2015
Chelsea N. Hayes[1]
Introduction
Kentucky is leading the way in America’s first state-based exchange to implement the Affordable Care Act (hereinafter “ACA”).[2] While this presumably will assist the one in six Kentuckians who are uninsured,[3] doctors and medical facilities may mistakenly disclose private documents with the high influx of new patients. Therefore, Kentucky citizens may question how to resolve violations of privacy mandated by the Health Insurance Portability and Accountability Act (hereinafter “HIPAA”).[4]HIPAA does not create a state-based private cause of action for violations of its privacy provisions.[5] Kentucky also has no state statute or common law right allowing state private causes of action for HIPAA violations.[6] While Kentucky has legislated a statute allowing private causes of action for other state statute violations, this right does not extend to federal statutes (e.g. HIPAA), regulations, or local ordinances.[7] Because HIPAA does not provide a plaintiff a federal private cause of action,[8] Kentucky refuses to infer a right where Congress has not.[9] Currently, the only way a person may pursue HIPAA violations is by filing a complaint with the Federal Office of Civil Rights (hereinafter “OCR”),[10] yet the individual receives no personal compensation.This note will first explore the interplay between the ACA and HIPAA in Section I, elaborating on Kentucky’s adoption of the ACA and expansion of its medical landscape. Section II explains existing precedent regarding state remedies for HIPAA violations and emphasizes aggrieved Kentuckians’ lack of recovery. Section III illuminates how Kentucky’s medical landscape is not unique from other states’, which allow state based causes of action. As a result, Kentucky should enact a statutory private cause of action to develop its medical landscape alongside the expansion of healthcare similar to West Virginia’s legislative scheme.
I. Background: Interaction between The Affordable Care Act and HIPAA
The implementation of the ACA allows millions of Americans the opportunity to receive affordable healthcare. Kentucky quickly adopted the ACA on a state level to provide statewide coverage and accessibility to Kentuckians.[11] As the number of individuals accessing healthcare increases, providers may become overwhelmed, and some protected health information may be unintentionally disclosed to the public. HIPAA governs these disclosures via regulations, violations, fines, and incarcerations,[12] incentivizing doctors and other health professionals to proceed carefully and diligently with the influx of patients. HIPAA alone, however, is insufficient to adequately address privacy because enforcement wavers at best, and individuals cannot receive adequate compensation because no federal private cause of action exists.
A. The Affordable Care Act
The ACA, enacted in 2010, employed a patient’s “Bill of Rights,” allowing “the American people the stability and flexibility [needed] to make informed decisions about their health.”[13] As of January 1, 2014, an estimated 14 million Americans will gain health insurance coverage via the Medicaid expansion or individual and/or small business tax reimbursements to lower healthcare costs via the federal and participating state exchanges.[14]These implementations provide individuals minimum health coverage that was once too costly to afford. More particularly, the Medicaid expansion[15] allows more vulnerable individuals 65 years or younger with an annual income below 133 percent of the federal poverty line to gain coverage despite pre-existing conditions or the inability to pay.[16] This means great benefits for the 7.8 million rural Americans who the United States Department of Health and Human Services (hereinafter “HHS”) predicts gained access to medical coverage under the ACA expansion.[17] Kentuckians are among these Americans who will benefit greatly.
B. Kentucky’s Adoption of the ACA
In 2013, 640,000 Kentuckians were uninsured, entailing approximately 15 percent of the state’s population.[18] Prompted by the ACA, Kentucky created Kynect, its state healthcare exchange.[19] According to the Washington Post, “56,422 [Kentuckians] have signed up for new health-care coverage, with 45,622 of them enrolled in Medicaid and the rest in private health plans, according to figures released by the governor’s office . . . .”[20]Of the estimated 640,000 Kentuckians covered, 308,000 could become insured after expansion of the Medicaid eligibility guidelines in accordance with the ACA.[21] This number forecasts that many Kentuckians can seek once unobtainable medical care for untreated conditions stemming from smoking, cancer, preventable hospitalizations, heart disease, etc.[22]When Kentucky welcomed the ACA, however, officials may not have anticipated increasing HIPAA violations. Healthcare reform has allowed Kentuckians to seek healthcare with lower financial cost, but a potentially more significant one: possible loss of personal privacy with no compensation. According to the HHS, “[a]s of December 31, 2013, [the Office of Civil Rights] had 258 open complaints and compliance reviews” for HIPAA violations.[23] While this is a national statistic, one can only imagine the increase in complaints upon adoption of the ACA within Kentucky. Each of the 258 disclosures represents a person, who if he or she lived in Kentucky, would have no private cause of action to recover despite federal legislation.
C. HIPAA Governs Personal Health Information Leaks
Congress enacted HIPAA on August 21, 1996.[24] HIPAA’s main purpose is to encourage uniform standards and requirements for storing protected health information (hereinafter “PHI”) and to reduce clerical burdens on all involved parties.[25] Accordingly, those who maintain PHIs adopt “administrative, technical, and physical safeguards . . . to ensure the integrity and confidentiality of the information, to protect against any reasonably anticipated threats or hazards to the security or integrity of the information and unauthorized uses or disclosures of the information, and otherwise to ensure compliance with this part by the officers and employees of such person.”[26]HIPAA forms are the norm in all offices handling PHI because legislation covers health care providers, health care clearing houses, and health plans (all considered “covered entities”).[27] In 2009, the Health Information Technology for Economic and Clinical Health Act[28] (hereinafter “HITECH”) required modification and strengthening of the HIPAA’s rules by mandating the inclusion of business associates[29] in conjunction with covered entities. HITECH also added levels of culpability for PHI violations.[30]A covered entity breaches HIPAA when it discloses PHI without permission or for an inappropriate purpose.[31] This violation does not have to be intentional, but instead may be inadvertent.[32] In order to seek redress for a suspected HIPPA violation, an individual must file a complaint with the Secretary of the HHS.[33] The OCR, a subdivision under the HHS, manages and investigates violation complaints or suspicion of HIPAA violations.[34] After a covered entity violates HIPAA, the OCR allows a time frame in which the covered entity may take a “satisfactory” action to correct the breach and mitigate the damages.[35] If corrective action is taken, the OCR will simply fine the covered entity via civil penalties,[36] and if the violation is criminal in nature, the OCR may instruct the Department of Justice to investigate.[37]When civil monetary damages are sought for HIPAA violations, complainants or aggrieved persons themselves do not receive money compensation.[38] Instead, recoveries are deposited into the U.S. Treasury to further assist HIPAA investigations.[39] The aggrieved person merely receives notifications regarding the resolution of the violations.[40] While HIPAA clearly defines what constitutes a violation, the Act omits any express private cause of action for individuals to seek compensation for the dissemination of their PHI.[41] Consequently, complainants are merely left with filing a complaint to the OCR, with few states providing additional redress.[42]
II. Case Law: Few State Causes of Action for HIPAA Violations
HIPAA violations have increased throughout the years, but aggrieved persons are left with no federal remedies because HIPAA does not generate a private cause of action.[43] Some states, however, allow recovery in state court via common law tort claims and/or statutory recoveries.[44] States such as West Virginia recognize both, whereas Kentucky recognizes neither.[45]
A. Aggrieved Persons Harmed by HIPAA Violations Cannot Recover in Federal Court
The Supreme Court iterated in 1979 that despite a person violating a federal statute and harming another individual, a violation does not automatically prompt a private cause of action.[46] As a result, harmed persons do not individually benefit from HIPAA protections.[47] In fact, the Supreme Court in 2001 stated that HIPAA will never provide a cause of action for wronged individuals unless amended with the intent to establish that right.[48] This results in summary judgment for the defendant covered entity,[49] and the OCR provides the singular remedy.[50]
B. States Allowing HIPAA Violations to Establish the Standard of Care in Tort Claims
Recently few states have allowed HIPAA guidelines to provide the standard of care for common law claims in state court litigation. In these jurisdictions, HIPAA rules supply the baseline for what a medical professional should do regarding privacy and security of PHI in negligence claims. This allows plaintiffs to claim that the covered entity was negligent according to the statutory regulations of HIPAA without need for expert testimony, establishing negligence per se.[51] A negligence per se claim statutorily establishes the standard of care[52] and permits aggrieved individuals to recover tort damages where no compensatory remedy is available through the OCR.[53] Additionally, this method allows plaintiffs to stand in court without immediately granting the defendant summary judgment.[54] The small number of state cases, indicates that this recovery has not yet picked up steam, but serves as a reminder that states surrounding Kentucky have implemented repercussions for breaches of HIPAA whether through negligence per se or other common law torts.[55]
C. State Statutory Recoveries for HIPAA Violations
Apart from common law tort claims, fourteen states have created a statutory cause of action for HIPAA violations.[56] For example, West Virginia is a model state to explore the effect of both common law and statutory recoveries for HIPAA violations,[57] and will provide the exemplars for this discussion.[58] The West Virginia statute was enacted in 1983,[59] and the state’s highest court further elaborated on this statute by reaffirming a patient’s ongoing right to sue over a HIPAA violation because both a well-recognized common law and statutory right existed under state law.[60] As a result, these states[61] protect privacy by allowing individuals a private cause of action as long as the statute mandates more privacy provisions than HIPAA to avoid federal preemption issues. HIPAA contains a preemption provision mandating that HIPAA supersede any contrary provision of state law.[62] Some courts have grappled with the idea of HIPAA preemption if the states were to create common law or statutory causes of action.West Virginia’s highest court has led the way in litigation and explanation of HIPAA preemption, iterating that HIPPA does not preempt state statutory causes of action for the wrongful disclosure of PHI.[63] In order for HIPAA to preempt any state statute, the state law must be contrary to HIPAA.[64] A law is not contrary if the state law is more stringent than a HIPAA standard, requirement, or implementation.[65] In R.K. v. St. Mary’s Medical Center, Inc., the West Virginia court held “such state-law claims compliment [sic] HIPAA by enhancing the penalties for its violation and thereby encouraging HIPAA compliance.”[66] The plaintiff, R.K., filed state law claims after disclosing otherwise-undisclosed personal information to hospital employees in order to seek treatment.[67] While hospitalized, hospital employees accessed R.K.’s record without permission and relayed PHI to his estranged wife and her divorce lawyer.[68] R.K. initiated state law claims including, but not limited to, breach of confidentiality and invasion of privacy.[69]While the circuit court stated HIPAA preempted these claims, [70] the higher court disagreed, analyzing Yath v. Fairview Clinics, N.P.,[71] involving a state statutory cause of action. Here, the defendant’s clinic tested the plaintiff, Yath, for a sexually-transmitted disease.[72] A clinic assistant accessed his records and disclosed the information to Yath’s husband. Yath sued for wrongful disclosure of medical information in violation of the Minnesota statute by improperly releasing PHI.[73] While lower courts determined HIPAA preempted the state statute, the Minnesota Court of Appeals held that the statute was not preempted because it is not “contrary” to HIPAA.[74] The defendants could comply with both HIPAA and the statute since both laws are “complementary,” not “contradictory” as the laws obtained the same goal of safeguarding patient PHI.[75] The West Virginia Supreme Court of Appeals elaborates that though the remedies in Minnesota Statute § 144.335 and HIPAA are not identical, [76] the differences are merely functional. [77] Both statutes primarily prohibit mishandling of PHI, but HIPAA focuses on criminal liability and civil fines while § 144.335 permits compensatory damages. As such, states like West Virginia allow HIPAA to establish the privacy protection floor, and states may enforce more stringent laws without preemption.As a result, states like West Virginia approve both complementary statutory and common law claims for HIPAA breaches. At the end of the day, however, each individual state must make this decision. “Raising up causes of action where a statute has not created them may be a proper function for common-law courts, but not for federal tribunals.”[78]
D. Kentucky Does Not Recognize a State Common Law or Statutory Cause of Action for HIPAA Violations
Kentucky has yet to recognize any common law private cause of action for HIPAA violations using HIPAA regulations as the standard of care.[79] Alternatively, Kentucky appears to statutorily provide recovery for individuals injured by violations of any statute via KRS § 446.070.[80] This statute allows an aggrieved party to recover for a violation of another statute if that particular statute provides no civil remedy, and the aggrieved person is within the class of persons the statute is meant to protect.[81]In Yeager v. Dickerson, the court addresses whether the plaintiff has a cause of action via KRS § 446.070 against her attorneys for disclosure of medical information.[82] Yeager, executrix of her daughter’s estate, alleged a violation of HIPAA when her daughter died from a drug overdose after release of her PHI at her child’s custody hearing.[83] Because Congress has not expressly intended a private right under HIPAA, the Kentucky Court of Appeals held that KRS § 446.070 does not confer a private civil remedy for such violations.[84] According to the court, the “any statute” language appearing in KRS § 446.070 is limited to state statutes only and exempts federal statutes in which Congress has not intended a remedy to be conferred.[85] The court further stated that even if the General Assembly had intended a right under the state statute where Congress had not, HIPAA would preempt Kentucky state law.[86] The court also has not recognized any common law tort claims for plaintiffs since the claims are grounded in HIPPA.[87] This leaves Kentuckians wondering what rights they can exercise after a HIPAA violation occurs.
III. Solution: Kentucky Should Implement a State Statutory Cause of Action for HIPAA Violations
As it exists, Kentucky provides no private cause of action through KRS § 446.070 for persons harmed by PHI disclosure.[88] This legislative void can only be fully remedied by the Kentucky Legislature enacting a statute specifically allowing a private cause of action for HIPAA violations. For guidance, Kentucky should look to neighboring states, particularly West Virginia, due to similarities between the two states’ medical landscapes. Although Kentucky is more populous and has had different jurisprudence on the subject than West Virginia, these should not stand in the way of Kentucky’s recognition of privacy rights.
A. Proposed Legislation for Recovery under a Kentucky State Statute
Private litigation on a federal scale might overwhelm the effectiveness of HIPAA, but other states have taken charge of regulating medical privacy. In fact, prior to HIPAA, states were the primary regulators of privacy concerns via the common law, statutes, and regulations.[89] The Yeager Court rationalized correctly that even if a private right of action existed, it would be preempted.[90] This is accurate because HIPAA establishes the floor for privacy protection and Kentucky has not yet expanded it further.[91] To circumvent preemption and better protect Kentuckians, legislators must be willing to enact “strong health privacy laws”[92] to redress those harmed.Even after HIPAA’s adoption, HHS explained, “[w]e believed then, and still believe, that there is an urgent need for legislation to establish comprehensive privacy standards for all those who pay and provide for health care, and those who receive information from them.”[93] This concept illuminates the idea that all fifty states should enact legislation to heighten privacy laws to better protect citizens rather than wholly relying on HIPAA to restore justice to aggrieved plaintiffs.[94]This is an alarming problem after the ACA because persons may already distrust the healthcare system due to previously limited access.[95] By enacting a state statutory provision in which KRS § 446.070 will allow recovery, rural Kentuckians may be more apt to trust and seek out healthcare they once could not afford. These persons must not live in fear of Kentucky forgoing individual privacy protection because redress is unavailable.While Kentucky courts have rebuked a private cause of action,[96] implementing a state statute would allow the courts to analyze it as a matter of first impression and partake in shaping the common law associated with the statute. Kentucky can look to West Virginia, its neighbor, for guidance since West Virginia implemented higher safeguards to protect its residents.[97] Little case law exists in Kentucky and West Virginia regarding state rights of action for HIPAA violations. However, in the available case law, Kentucky and West Virginia rationalize the subject comparably.[98] In fact, the only difference between the two states is solely the existing precedent, as the two states have strikingly similar medical landscapes. Precedent is the only barrier that stands between Kentucky and a state private cause of action—a barrier that the ACA will inevitably break down.
B. Comparison: The Kentucky and West Virginia Courts Rationalize Similarly
In Kentucky, Yeager held that the state statute regarding privacy for health care recipients did not confer a private right of action for HIPAA violations.[99] Authority in neighboring West Virginia from the Supreme Court of Appeals, however, is contrary to the Kentucky holding.[100] The courts’ rationale is quite similar, but the respective precedent is distinctive: West Virginia reaffirmed a patient’s ongoing right to sue where Kentucky has not yet initially recognized a patient’s right to sue.First, both courts recognize that HIPAA does not create a federal private right of action for aggrieved persons.[101] Second, neither Kentucky nor West Virginia specifically held that HIPAA preempts a state from recognizing a cause of action for disclosure of PHI.[102] Instead, the courts address whether HIPAA preempts particular statutes. As discussed in West Virginia, HIPAA would preempt state law, including statutory and common law, only if the state law would disallow compliance with both state and federal requirements or if the state law is contrary[103] and stands as an obstacle to HIPAA’s execution.[104]If the courts have already rationalized similarly, Kentucky should consider consulting other jurisdictions in at least allowing a statutory right of recovery in combination with KRS § 446.070 for aggrieved individuals. Preemption would also not be an obstacle, despite Kentucky courts’ rationale, because it is entirely possible for both the OCR to enforce HIPAA through civil and criminal fines and Kentucky to recognize a private cause of action focusing on individual recovery. Both proceedings could occur autonomously without affecting the other. Further, a state right of action would complement HIPAA’s floor by assisting and strengthening incentives to protect PHI with the expansion of the ACA.As one court stated, “[i]t is, to say the least, difficult to believe that Congress would, without comment, remove all means of judicial recourse for those injured by illegal conduct.”[105] While Kentucky has already taken strides to protect its own residents through adoption of the first state-based exchange for the ACA, it has fallen behind West Virginia and other states that have recognized a common law cause of action and others with statutory causes of action due to the toothless fear of preemption and outdated precedent in the time of the ACA.
C. Comparison: Kentucky and West Virginia have Comparable Medical Landscapes
Similar medical landscapes are important when advocating for one state government to adopt another’s remedies. This section statistically compares West Virginia and Kentucky to illustrate few differences exist between them. Kentucky conclusively has more uninsured individuals and more Medicaid recipients yet has no state cause of action like West Virginia. These statistics support Kentucky adopting West Virginia’s approach to redressing breaches.The implementation of the ACA has the potential to extend coverage to as many as 285,931 uninsured West Virginians.[106] West Virginia’s estimated 2013 population was 1,854,304, with 714,605 of those individuals living in rural areas.[107] Through the ACA Marketplace, 42% of adults (about 112,000) and 11% of children (roughly 30,000) will receive Medicaid, 23% of individuals will be eligible for tax credits (62,000), and 23% may gain coverage without financial assistance.[108] Of those uninsured individuals eligible for coverage, 259,000 (91%) are White, 16,461 (6%) are African-American, 2,850 (1%) are Latino or Hispanic, and 1,208 (0.4%) are Asian American or Pacific Islander.[109] At least 799,000 non-elderly individuals, including 91,098 children, have pre-existing health conditions who may now receive healthcare because of the ACA.[110]In comparison, Kentucky, with 647,000 uninsured, was the first state to adopt a state-based exchange for the ACA.[111] As of 2013, Kentucky had an estimated population of 4,395,295, of which 1,837,294 living in rural areas.[112] Through the ACA Marketplace, 45% of adults (about 291,000) and 9% of children (roughly 59,000) will receive Medicaid, 22% of individuals will be eligible for tax credits (145,000), and 24% may gain coverage without financial assistance.[113] Of those uninsured individuals eligible for coverage, 513,688 (83%) are White, 77,280 (12%) are African American, 18,272 (3%) are Latino or Hispanic, and 4,158 (1%) are Asian American or Pacific Islander.[114] At least 1,894,874 non-elderly Kentuckians, including 241,403 children, have pre-existing conditions.[115]The above statistics illuminate that Kentucky has more individuals, more uninsured, and a greater number of Medicaid expansion recipients than West Virginia. Both have high rural populations where poverty can be a perpetual cycle and healthcare a commodity. The majority of uninsured are Caucasian, suggesting this is not a racial discrepancy, but rather a rampant, non-discriminatory issue. This prompts the question why Kentucky has not led the way in protecting Kentuckians from privacy violations like its very similar neighbor, West Virginia? After West Virginia’s adoption of both a common law and statutory cause of action protecting its citizens, Kentucky has few arguments for first implementing the ACA yet refusing to fully protect Kentuckians from HIPAA violations that may increase due to the state’s adoption of the ACA.
IV. Conclusion
While Kentucky is an advocate for providing healthcare via the ACA, Kentucky continues to ignore each person’s individual privacy rights within the medical sphere by providing no redress to Kentuckians hurt by PHI disclosures. As a result, Kentucky lacks the self-interest to fully protect its citizens because citizens desire redress when Kentucky recognizes no right. Neighboring state courts have begun utilizing HIPAA as evidence of the standard of care for other common law torts while others allow statutory causes of actions for HIPAA violations. Kentucky offers neither. This note advocates for Kentucky to implement legislation to strengthen HIPAA regulations by allowing a state private cause of action for Kentuckians hurt or affected by PHI disclosures. Kentucky should look to other states with private causes of action, such as West Virginia, for guidance. This private cause of action will more uniformly protect and guarantee Kentuckians’ privacy via state redress.
[1] J.D., May 2015, University of Kentucky College of Law.
[2] See Mary Branham, State Success & Federal Missteps, The Council of State Governments, http://www.csg.org/pubs/capitolideas/2014_jan_feb/healthcareexchanges.aspx (last visited Jan. 19, 2014). For information regarding the exchange, see Patient Protection and Affordable Care Act (ACA), Pub. L. No. 111-148, 124 Stat. 119 (2010).
[3] Steve Beshear, My State Needs ObamaCare. Now., Ny Times (Sept. 26, 2013), http://www.nytimes.com/2013/09/27/opinion/my-state-needs-obamacare-now.html.
[4] Health Insurance Portability and Accountability Act (HIPAA), Pub. L. No. 104-191, 110 Stat. 1936 (codified as scattered sections of 18, 26, 29, 42 U.S.C. (2000)).
[5] McMillen v. Ky. Dep’t. of Corr., 233 S.W.3d 203, 205 (Ky. Ct. App. 2007).
[6] Young v. Carran, 289 S.W.3d 586, 589 (Ky. Ct. App. 2008) (articulating Kentucky’s lack of common law or statutory private cause of action for HIPAA violations).
[7] See Ky. Rev. Stat. Ann. § 446.070 (2013); T & M Jewelry, Inc. v. Hicks ex rel. Hicks, 189 S.W.3d 526, 530 (Ky. 2006); Alderman v. Bradley, 957 S.W.2d 264, 266-67 (Ky. 1997); Yeager v. Dickerson, 391 S.W.3d 388, 393 (Ky. Ct. App. 2013).
[8] See Alexander v. Sandoval, 532 U.S. 275, 275 (2001) (holding that there is no private right of action to enforce disparate-impact regulations promulgated under Title VI of Civil Rights Act of 1964.”); Acara v. Banks, 470 F.3d 569, 571 (5th Cir. 2006) (holding no private cause of action for disclosure of PHI during a deposition); Johnson v. Quander, 370 F. Supp. 2d 79, 100 (D.D.C. 2005) (holding that a convicted robber had no private cause of action under HIPAA when challenging the DNA Act because the Secretary of HHS only had that right); Univ. of Colo. Hosp. v. Denver Pub. Co., 340 F. Supp. 2d 1142, 1145 (D. Colo. 2004) (finding no HIPAA private cause of action because the statute created enforcement means for aggrieved persons); O'Donnell v. Blue Cross Blue Shield of Wyo., 173 F. Supp. 2d 1176, 1179-80 (D. Wyo. 2001) (holding no express or implied private cause of action exists in HIPAA).
[9] Yeager, 391 S.W.3d at 394.
[10] Bob Herman, HIPAA May Form Basis for State Law Private Cause of Action, Becker’s Hosp. Review (June 24, 2011), http://www.beckershospitalreview.com/healthcare-information-technology/hipaa-may-form-basis-for-state-law-private-cause-of-action.html.
[11] Beshear, supra note 2.
[12] See supra notes 18-23 and accompanying text.
[13] About the Law, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/healthcare/rights/ (last visited Jan. 20, 2014).
[14] Individual Health Insurance Coverage, AHIP Coverage (Oct. 12, 2010), http://www.ahipcoverage.com/2010/10/12/individual-health-insurance-coverage/; Small Business Health Care Tax Credit for Small Employers, IRS (Dec. 19, 2013), http://www.irs.gov/uac/Small-Business-Health-Care-Tax-Credit-for-Small-Employers.
[15] While tax reimbursement participants will also comprise a large number of individuals the ACA will help, this paper will primarily focus on Medicaid recipients as this individuals are most likely gaining access for the first time.
[16] Nat'l Fed'n of Indep. Bus. v. Sebelius, 132 S. Ct. 2566, 2575, (2012); Key Features of the Affordable Care Act by Year, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/healthcare/facts/timeline/timeline-text.html (last visited Jan. 20, 2014).
[17] See The Affordable Care Act-What It Means in Rural America, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/healthcare/facts/factsheets/2013/09/rural09202013.html (last visited Jan. 20, 2014).
[18] A Healthier Kentucky: Health Insurance Coverage for Every Kentuckian, Governor of Kentucky Steve Beshear, http://governor.ky.gov/healthierky/Pages/default.aspx (last visited Jan. 20, 2014) [hereinafter A Healthier Kentucky].
[19] Id.
[20] Stephanie McCrummen, In Rural Kentucky, Health-Care Debate Takes Back Seat as the Long-Uninsured Line Up, The Washington Post, (Nov. 23, 2013), http://www.washingtonpost.com/national/in-rural-kentucky-health-care-debate-takes-back-seat-as-people-sign-up-for-insurance/2013/11/23/449dc6e0-5465-11e3-9e2c-e1d01116fd98_story.html. Furthermore, as of March 20, 2014, 321,932 Kentuckians had enrolled through Kynect and 257,477 of these individuals qualified under the Medicaid expansion. More than 321,000 Now Enrolled Through Kynect as March 31 Deadline Approaches, Kentucky.gov (Mar. 21, 2014), http://kentucky.gov/Pages/Activity-Stream.aspx?viewMode=ViewDetailInNewPage&eventID=&activityType=PressRelease.
[21] Beshear, supra note 2.
[22] Id. (“[Kentucky] ranks among the worst, if not the worst, in almost every major health category, including smoking, cancer deaths, preventable hospitalizations, premature death, heart disease and diabetes.”).
[23] Enforcement Highlights, U.S. Dep’t of Health and Human Serv. (Dec. 31, 2013), http://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/12312013.html.
[24] HIPAA, Pub. L. No. 104-191, 110 Stat. 1936 (codified as scattered sections of 18, 26, 29, 42 U.S.C. (2000)).
[25] See id. § 261.
[26] 42 U.S.C. § 1320d-2(d)(2)(A-C) (2014).
[27] See 45 C.F.R. § 160.103(4)(iv)(1-3) (2014).
[28] American Recovery and Reinvestment Act of 2009 (ARRA), Pub. L. No. 111-5, 123 Stat. 226 (Feb. 17, 2009), codified at 42 U.S.C. §§300jj et seq.; §17901 et seq.
[29] Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in § 164.501 of this subchapter) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, performs, or assists in the performance of: (A) a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing, benefit management, practice management, and repricing; or (B) Any other function or activity regulated by this subchapter; or (ii) Provides, other than in the capacity of a member of the workforce of such covered entity, legal, actuarial, accounting, consulting, data aggregation (as defined in § 164.501 of this subchapter), management, administrative, accreditation, or financial services to or for such covered entity, or to or for an organized health care arrangement in which the covered entity participates, where the provision of the service involves the disclosure of protected health information from such covered entity or arrangement, or from another business associate of such covered entity or arrangement, to the person. 45 C.F.R. § 160.103(1)(i-ii) (2014).
[30] It also expanded the maximum fine to $50,000 per violation depending on the culpability level, capping maximum amounts for repeated offenses at $1,500,000 per year for aggregate violations. See HIPAA Enforcement after the Recovery Act, Hall, Render, Killian, Heath & Lyman (March 30, 2009), http://www.hallrender.com/library/articles/1085/033009___Enforcement_after_the_Recovery_Act.pdf. However, HIPAA allows an exception to fines if the violation was due to reasonable cause. 42 USC § 1320d-5(a)(1)(B) (2014). HITECH also proposed allowing individuals to share a percentage of recovery or settlement; HHS had until 2012 to issue the regulation, but this does not appear to have occurred yet. Chris Dimick, HIPAA Violation? Sue me, J. of AHIMA (Mar. 1, 2011), http://journal.ahima.org/2011/03/01/hipaa-violation-sue-me/.
[31] See 45 C.F.R. § 164.502(a) (2014) (explaining general rules on violations and permitted uses of PHI). A “breach” is defined by HHS as “an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information.” Breach Notification Rule, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/index.html (last visited Mar. 19, 2014).
[32] See, e.g., 42 U.S.C. § 1320d-5(a)(1)(A), (B) (2014).
[33] How OCR Enforces the HIPAA Privacy & Security Rules, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/ocr/privacy/hipaa/enforcement/process/howocrenforces.html (last visited Jan. 17, 2014) [hereinafter How OCR Enforces].
[34] See 42 U.S.C. § 1320d-5(c)(2) (2014); How OCR Enforces, supra note 32.
[35] How OCR Enforces, supra note 32.
[36] 42 U.S.C. § 1320d-5(a)(2)-(3) (2014).
[37] Id. § 1320d-6; How OCR Enforces, supra note 32.
[38] How OCR Enforces, supra note 32.
[39] Id.
[40] Id. Further, in 2012, HHS reported that 10,454 individuals filed complaints to the OCR, indicating that complaints are not at a minimum. See Health Information Privacy Complaints Received by Calendar Year, U.S. Dep’t of Health and Human Serv., http://www.hhs.gov/ocr/privacy/hipaa/enforcement/data/complaintsyear.html (last visited Jan. 17, 2014) [hereinafter Privacy Complaints] (providing a bar graph to show increasing numbers of HIPAA complaints each year).
[41] Instead, Congress limited enforcement to the Secretary of Health and Human Services, which indicates it did not intend to create private rights of action in individuals aggrieved by HIPAA breaches. Social Security Act, § 1171, 42 U.S.C. § 1320d); Acara v. Banks, 470 F.3d 569, 571 (5th Cir. 2006).
[42] After the HITECH expansion, state attorney generals are now allowed to bring civil damage claims against entities that breach HIPAA, but this does not affect an individual’s right to sue. Dimick, supra note 29. Even then, the attorney generals may be overwhelmed as well and only choose to take the most devastating and detrimental cases.
[43] See, e.g., Acara, 470 F.3d at 569.
[44] See infra Sections II.B-C.
[45] See Individual Right of Action for Medical Records Access: 50 State Comparison, Robert Wood Johnson Found. (Jan. 20, 2014), http://www.healthinfolaw.org/comparative-analysis/individual-right-action-medical-records-access-50-state-comparison [hereinafter 50 State Comparison].
[46] Touche Ross & Co. v. Redington, 442 U.S. 560, 568 (1979) (citation omitted).
[47] See Alexander v. Sandoval, 532 U.S. 275, 275 (2001) (holding that there is no private right of action to enforce disparate-impact regulations promulgated under Title VI of Civil Rights Act of 1964.”); Acara, 470 F.3d at 570 (holding no private cause of action for disclosure of PHI during a deposition); Johnson v. Quander, 370 F. Supp. 2d 79, 100 (D.D.C. 2005) (holding that a convicted robber had no private cause of action under HIPAA when challenging the DNA Act because the Secretary of HHS only had that right); Univ. of Colo. Hosp. v. Denver Pub. Co., 340 F. Supp. 2d 1142, 1145 (D. Colo. 2004) (finding no HIPAA private cause of action because the statute created enforcement means for aggrieved persons); O'Donnell v. Blue Cross Blue Shield of Wyo., 173 F. Supp. 2d 1176, 1179-80 (D. Wyo. 2001) (holding no express or implied private cause of action exists in HIPAA).
[48] Alexander, 532 U.S. at 286-87 ("Without [statutory intent], a cause of action does not exist and courts may not create one, no matter how desirable that might be as a policy matter, or how compatible with the statute.").
[49] See Acara, 470 F.3d at 572.
[50] HIPAA enforcement has consistently been at a minimum. For example, between 2003 and 2011, the OCR received over 25,000 complaints, but only imposed a formal civil fine in one of these cases. The OCR settled six of these cases. HHS referred 495 cases to the Department of Justice, resulting in only sixteen prosecutions. Rachel Grunberger, Senate Hearings Focus on Lack of HIPAA Enforcement, Final HITECH Rule, Inside Privacy (Dec. 22, 2011), http://www.insideprivacy.com/senate-hearings-focus-on-lack-of-hipaa-enforcement-final-hitech-rule/.
[51] See, e.g., Byrne v. Avery Ctr. for Obstetrics & Gynecology, P.C., 102 A.3d 32, 42 (Conn. Super. Ct. 2014) (holding HIPAA may be used as the standard of care for a negligence claim and HIPAA does not preempt this type of claim); Doe 1631 v. Quest Diagnostics, Inc., 395 S.W.3d 8, 18-19 (Mo. 2013) (allowing a breach of fiduciary claim against defendant after its phlebotomist faxed HIV results without the patient’s permission); R.K. v. St. Mary's Med. Ctr., Inc., 735 S.E.2d 715, 723 (W. Va. 2012) (holding HIPAA may be used as the standard of care for a negligence claim); Sorensen v. Barbuto, 143 P.3d 295, 299 n.2 (Utah Ct. App. 2006) (holding plaintiff established an action for negligent breach of confidentiality by relying on standards within HIPAA); I.S. v. Washington Univ., No. 4:11CV235SNLJ, 2011 WL 2433585, at *2 (E.D. Mo. June 14, 2011) (“[T]he Court finds that Count III may stand as a state claim for negligence per se despite its exclusive reliance upon HIPAA.”); K.V. v. Women's Healthcare Network, LLC, 07-0228-CV-W-DW, 2007 WL 1655734, at *1 (W.D. Mo. June 6, 2007) (explaining that the negligence per se claim based on HIPAA violation was a state-law claim); Acosta v. Byrum, 638 S.E.2d 246, 253 (N.C. Ct. App. 2006) (allowing plaintiff to reference HIPAA as baseline evidence of appropriate medical standard of care needed as an element of negligence); Harmon v. Maury Cnty., Tenn., No. 1:05 CV 0026, 2005 WL 2133697, at *3 (M.D. Tenn. Aug. 31, 2005).
[52] Young v. Carran, 289 S.W.3d 586, 588-89 (Ky. Ct. App. 2008) (citation omitted).
[53] State supreme courts wrote two of these notable decisions, demonstrating that at least two states’ highest courts have recognized HIPAA as proof of the standard of care for common law tort claims. See, e.g., Sorensen, 143 P.3d at 299 n.2; R.K., 735 S.E.2d at 723.
[54] It appears that plaintiffs must still prove damages proximately caused by the defendant’s actions, and damages must be legally cognizable. See Alagia, Day, Trautwein & Smith v. Broadbent, 882 S.W.2d 121, 126 (Ky. 1994).
[55] For example, Ohio’s Supreme Court in 1999 held that “an independent tort exists for the unauthorized, unprivileged disclosure to a third party of nonpublic medical information that a physician or hospital has learned within a physician-patient relationship" and "a third party can be held liable for inducing the unauthorized, unprivileged disclosure.” Biddle v. Warren Gen. Hosp., 715 N.E.2d 518, 523, 528 (Ohio 1999). This tort only applied to the confidential relationship between the physician and the patient, however. Recognizing the shortcomings of this tort and the growing problem of inadvertent disclosure with other entities before HITECH, the same court created a separate tort solely related to medical records that applies to a broader range of persons not limited to physicians. See Hageman v. Sw. Gen. Health Ctr., 893 N.E.2d 153, 157-58 (Ohio 2008).
[56] See 50 State Comparison, supra note 44 (illustrating California, Delaware, Illinois, Louisiana, Maryland, Massachusetts, Montana, New Hampshire, New York, Tennessee, Washington, West Virginia, Wisconsin, and Wyoming have private causes of action).
[57] See R.K., 735 S.E.2d at 715.
[58] See infra notes 83-109 and accompanying text (explaining the similarities between West Virginia and Kentucky).
[59] The statute explains that “[t]he provisions of this article may be enforced by a patient, authorized agent or authorized representative, and any health care provider found to be in violation of this article shall pay any attorney fees and costs, including court costs incurred in the course of such enforcement.” W. Va. Code § 16-29-1(d) (2011 & Supp. 2014); W. Va. Code § 29B-1-6 (2012) (“Any custodian of any public records who willfully violates the provisions of this article is guilty of a misdemeanor and, upon conviction thereof, shall be fined not less than two hundred dollars nor more than one thousand dollars, or be imprisoned in the county jail for not more than twenty days, or, in the discretion of the court, by both fine and imprisonment.”).
[60] See R.K., 735 S.E.2d at 724.
[61] See 50 State Comparison, supra note 44.[62] 42 U.S.C. § 1320d-7 (2014), which states in part: (1) General rule, Except as provided in paragraph (2), a provision or requirement under this part, or a standard or implementation specification adopted or established under sections 1320d-1 through 1320d-3 of this title, shall supersede any contrary provision of State law, including a provision of State law that requires medical or health plan records (including billing information) to be maintained or transmitted in written rather than electronic form. (2) Exceptions, A provision or requirement under this part, or a standard or implementation specification adopted or established under sections 1320d-1 through 1320d-3 of this title, shall not supersede a contrary provision of State law, if the provision of State law... (B) subject to section 264(c)(2) of the Health Insurance Portability and Accountability Act of 1996 [42 USCS § 1320d-2 note], relates to the privacy of individually identifiable health information (emphasis added).
[63] See R.K., 735 S.E.2d at 724.
[64] See 45 C.F.R. § 160.203(a) (2014).
[65] See id. § 160.203(b).
[66] R.K., 735 S.E.2d at 724.
[67] Id. at 717.
[68] Id.
[69] Id. at 718 (iterating claims for outrageous conduct, intentional infliction of emotional distress, negligent infliction of emotional distress, negligent entrustment, breach of confidentiality, invasion of privacy, and punitive damages).
[70] Id. at 719.
[71] 767 N.W.2d 34 (Minn. Ct. App. 2009).
[72] Id. at 38.
[73] Minn. Stat. § 144.335 (2006) (repealed 2007), available at https://www.revisor.mn.gov/statutes/?year=2006&id=144.335 (providing for a private cause of action for the wrongful disclosure of an individual’s medical records); Yath v. Fairview Clinics, 767 N.W.2d 34, 39 (Minn. Ct. App. 2009).
[74] 45 C.F.R § 160.202 (2014); R.K. v. St. Mary's Med. Ctr., Inc., 735 S.E.2d 715, 721 (W. Va. 2012) (“Just because a distinction exists does not make [a state statute] ‘contrary’ to HIPAA. A state law is ‘contrary’ to HIPAA if a health care provider ‘would find it impossible to comply with both the State and federal requirements’ or if the state law is ‘an obstacle to the accomplishment and execution of the full purposes’ of HIPAA.’”).
[75] R.K., 735 S.E.2d at 722-23 (“The stated purpose of HIPAA is to improve the Medicare and Medicaid programs and ‘the efficiency and effectiveness of the health care system, by encouraging the development of a health information system through the establishment of standards and requirements for the electronic transmission of certain health information.’ . . . Rather than creating an ‘obstacle’ to HIPAA, [Minn. Stat. § 144.334] supports at least one of HIPAA’s goals by establishing another disincentive to wrongfully disclose a patient’s health care record.”).
[76] See 45 U.S.C. §1320d-5 (2014) (imposing criminal penalties); Minn. Stat. § 144.335(3a(e)) (2006) (imposing compensatory damages in a civil action).
[77] See R.K., 735 S.E.2d at 722 (“The difference in remedy is functional only, in that a HIPAA violation subjects a person to criminal penalties.”).
[78] Lampf v. Gilbertson, 501 U.S. 350, 365 (1991) (Scalia, J., concurring in part and concurring in judgment).
[79] See, e.g., Young v. Carran, 289 S.W.3d 586, 589 (Ky. Ct. App. 2008).
[80] See Ky. Rev. Stat. Ann. § 446.070 (2013).
[81] See Yeager v. Dickerson, 391 S.W.3d 388, 393 (Ky. Ct. App. 2013).
[82] Id. at 390.
[83] Id. at 391.
[84] Id. at 394.
[85] Id. “[T]he General Assembly did not intend [KRS § 466.070] ‘to embrace the whole of federal laws and the laws of other states and thereby confer a private civil remedy for such a vast array of violations.’” (citation omitted).
[86] Id.
[87] 50 State Comparison, supra note 44 (utilizing a nationwide map to explain Kentucky has not allowed tort claims).
[88] See supra notes 78-86 and accompanying text.
[89] See Joy L. Pritts, Altered States: State Health Privacy Laws and the Impact of the Federal Health Privacy Rule, 2 Yale J. Health Pol’y L. & Ethics 327(2002) [hereinafter Altered States]. Further, “there is still room for states to protect their own citizens by retaining or enacting health privacy protections that mirror and improve upon those in the [federal legislation].” Id. at 328.
[90] See Yeager v. Dickerson, 391 S.W.3d 388, 394 (Ky. Ct. App. 2013).
[91] See generally id. at 388 (articulating no private recovery for plaintiffs in Kentucky).
[92] Altered States, supra note 88, at 345.
[93] Standards for Privacy of Individually Identifiable Health Information, 64 Fed. Reg. 59,923 (Nov. 3, 1999) (to be codified at 45 C.F.R. pts. 160-64).
[94] Altered States, supra note 88, at 347 (“This approach, endorsed by the Privacy Protection Study Commission in the 1970s, ensures that the states will be able to enforce the law and protect their citizens.”) (citing Personal Privacy in an Information Society: The Report of the Privacy Protection Study Commission, U.S. Privacy Prot. Study Comm’n 276-90 (July 1977), available at http://epic.org/privacy/ppsc1977report).
[95] As an example, distrust for the state was so extreme that some rural Kentuckians thought that enrolling in the state-health insurance coverage involved implanting microchips into their arms. McCrummen, supra note 19.
[96] See generally Yeager, 391 S.W.3d at 388 (illustrating Kentucky case law against a private cause of action).
[97] See supra section II.C (articulating West Virginia common law and statutory scheme allowing individuals rights of recovery for disclosures of PHI).
[98] See Yeager, 391 S.W.3d at 388; R.K. v. St. Mary's Med. Ctr., Inc., 735 S.E.2d 715 (W. Va. 2012).
[99] See Yeager, 391 S.W.3d. at 394.
[100] See R.K., 735 S.E.2d at 724.
[101] Id. at 718; Yeager, 391 S.W.3d at 393.
[102] See R.K., 735 S.E.2d at 721; Yeager, 391 S.W.3d at 394.
[103] See 45 C.F.R § 160.202-.203 (2013).
[104] See R.K., 735 S.E.2d at 721-24 (discussing HIPAA preempting contrary state laws and disallowing any laws impeding HIPAA enforcement).
[105] Wash. Mut. Bank v. Superior Court, 75 Cal. App. 4th 773, 783 (1999) (citation omitted).
[106] The Uninsured in West Virginia, Addiction Tech. Transfer Ctr. Network, http://attcnetwork.org/regcenters/generalContent.asp?rcid=2&content=PARTCUSTOM (last visited Jan 20, 2014) [hereinafter The Uninsured in West Virginia].
[107] Living in rural areas increased the possibilities of being uninsured. See West Virginia, Rural Assistance Ctr. (Dec. 29, 2014), http://www.raconline.org/states/west-virginia.
[108] See How Will the Uninsured in West Virginia Fare Under the Affordable Care Act?, Kaiser Family Found., http://kff.org/health-reform/fact-sheet/state-profiles-uninsured-under-aca-west-virginia/ (last visited Jan. 20, 2014); Interactive: A State-by-State Look at How the Uninsured Fare Under the ACA, Kaiser Family Found., http://kff.org/interactive/uninsured-gap/ (last visited Jan. 19, 2014) (hereinafter Interactive).
[109] The Uninsured in West Virginia, supra note 105.
[110] 5 Years Later: How the Affordable Care Act is Working for West Virginia, U.S. DEP’T OF HEALTH AND HUMAN SERV., http://www.hhs.gov/healthcare/facts/bystate/wv.html (last visited Jan. 20, 2014).
[111] How Will the Uninsured in Kentucky Fare Under the Affordable Care Act?, Kaiser Family Foundation, http://kff.org/health-reform/fact-sheet/state-profiles-uninsured-under-aca-kentucky/ (last visited Jan. 19, 2014) (hereinafter Kaiser Kentucky).
[112] Kentucky, Rural Assistance Ctr. (Sept. 12, 2014), http://www.raconline.org/states/kentucky.
[113] Kaiser Kentucky, supra note 110; Interactive, supra note 107.
[114] How the Health Care Law is Making a Difference for the People in Kentucky, KY and Appalachia Public Health Training Ctr., http://www.uky.edu/kaphtc/resources/policy-development-and-program-planning/how-health-care-law-making-difference-people (last visited Jan. 20, 2014).
[115] 5 Years Later: How the Affordable Care Act is Working for Kentucky, U.S. DEP’T OF HEALTH AND HUMAN SERV., http://www.hhs.gov/healthcare/facts/bystate/wv.html (last visited Jan. 20, 2014).