Existing federal law, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), establishes certain requirements relating to the provision of health insurance, including provisions relating to the confidentiality of health records. Existing state law, the Confidentiality of Medical Information Act, prohibits a provider of health care, a health care service plan, a contractor, a corporation and its subsidiaries and affiliates, or any business that offers software or hardware to consumers, including a mobile application or other related device, as defined, from intentionally sharing, selling, using for marketing, or otherwise using any medical information, as defined, for any purpose not necessary to provide health care services to a patient, except as provided.
This bill would prohibit a participating entity of a closed-loop
referral system (CLRS) from selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, social care information stored in or transmitted through a CLRS in exchange for monetary or other valuable consideration. consideration, except as specified. The bill would further prohibit a participating entity from using social care information stored in, or transmitted through, a CLRS for any purpose or purposes other than the social care purpose or purposes for which that social care information was collected or generated, except as specified. The bill would define “social care” to mean any care, services, goods, or supplies related to an individual’s social needs, including, but not limited to, support and assistance for
an individual’s food stability and nutritional needs, housing, transportation, economic stability, employment, education access and quality, childcare and family relationship needs, and environmental and physical safety. The bill would also define “social care information” to mean any information, in any form, that relates to the need for, payment for, or provision of, social care, and the individual’s personal information, as specified.