HEALTH INFORMATION TECHNOLOGY PROMOTION ACT OF 2006 -- (House of Representatives - July 27, 2006)
BREAK IN TRANSCRIPT
Mr. DOGGETT. Mr. Chairman, during the 12 years that Republicans have controlled this House, they have done very little to address the real concerns of families confronted with a health care crisis. This afternoon during rush hour, some family, in fact probably many families, will suffer a severe auto accident on the way home.
Perhaps a mom will be found to have breast cancer, or a child a serious childhood disease. And as these health care challenges emerge, tens of thousands of families across America will end up not only driven into despair but into bankruptcy.
And yet Republicans have not offered real solutions to address those kinds of problems. Recognizing their failures earlier this year, both Senate and House Republican leaders declared there would be a ``health care week.'' Well, the Senate took up their ``health care week,'' and every old, retread Republican proposal that they had was rejected.
So I guess too embarrassed to have ``health care week'' here in the House, even though they declared it, the Republicans canceled ``health care week,'' just like they have canceled so many of the commitments that they made back in 1994 to the American people.
And what they have left as their one new idea for the crisis that American families face in health care is this pitiful proposal. They have discovered that the answer to the problems American families face with health care is not what the American families thought was their problem about getting access to affordable, quality health care. No, it is bad handwriting. Yes. We all know the legendary bad handwriting of physicians that is the subject of cartoons and stories.
But by golly, they are solving that. All of these physicians, and the hospitals and the clinics, will be using electronic records and solve that penmanship problem. Well, that is not a bad idea. It is just that they do not put their money where their mouth is.
They tell the physicians and the clinics, you figure out how to pay for this technology. And in the process of this transformation, once again, as they have done with our library records and our phone records and our veterans records, they couldn't really care less about privacy.
Think about whether you want your psychiatric records, your prescription records on the Internet for other people to see. Because this legislation does not provide the guarantee of privacy. And so fearful are they of a true debate about protecting the privacy rights of Americans to their medical records, to their health care records, that may affect their future employment, that may affect their future family relations, that may affect their ability to get insurance.
So fearful are they of a debate about that, they refuse to let us offer even one amendment to address patient privacy.
BREAK IN TRANSCRIPT
Mr. DOGGETT. Mr. Speaker, I have a motion to recommit at the desk.
The SPEAKER pro tempore. Is the gentlemen opposed to the bill?
Mr. DOGGETT. I certainly am, Mr. Speaker.
The SPEAKER pro tempore. The Clerk will report the motion to recommit.
The Clerk read as follows:
Mr. Doggett moves to recommit the bill H.R. 4157 to the Committees on Energy and Commerce and Ways and Means with instructions to report the same back to the House forthwith with the following amendment:
Amend section 205 to read as follows:
SEC. 205. PRIVACY AND SECURITY PROTECTIONS.
(a) In General.--The Secretary of Health and Human Services shall provide for standards for health information technology (as such term is used in this Act) that include the following privacy and security protections:
(1) Except as provided in succeeding paragraphs, each entity must--
(A) expressly recognize the individual's right to privacy and security with respect to the electronic disclosure of such information;
(B) permit individuals to exercise their right to privacy and security in the electronic disclosure of such information to another entity by obtaining the individual's written or electronic informed consent, which consent may authorize multiple disclosures; and
(C) permit an individual to prohibit access to certain categories of individuals (as defined by the Secretary) of particularly sensitive information, including data relating to infection with the human immunodeficiency virus (HIV), to mental health, to sexually transmitted diseases, to reproductive health, to domestic violence, to substance abuse treatment, to genetic testing or information, to diabetes, and other information as defined by the Secretary after consent has been provided under subparagraph (B).
(2) Informed consent may be inferred, in the absence of a contrary indication by the individual--
(A) to the extent necessary to provide treatment and obtain payment for health care in emergency situations;
(B) to the extent necessary to provide treatment and payment where the health care provider is required by law to treat the individual;
(C) if the health care provider is unable to obtain consent due to substantial barriers to communicating with the individual and the provider reasonably infers from the circumstances, based upon the exercise of professional judgment, that the individual does not object to the disclosure or that the disclosure is in the best interest of the individual; and
(D) to the extent that the information is necessary to carry out or otherwise implement a medical practitioner's order or prescription for health services, medical devices or supplies, or pharmaceuticals.
(3) The protections must prohibit the improper use and disclosure of individually identifiable health information by any entity.
(4) The protections must provide any individual a right to obtain damages and other relief against any entity for the entity's improper use or disclosure of individually identifiable health information.
(5) The protections must require the use of reasonable safeguards, including audit capabilities, encryption and other technologies that make data unusable to unauthorized persons, and other measures, against the risk of loss or unauthorized access, destruction, use, modification, or disclosure of individually identifiable health information.
(6) The protections must provide for notification to any individual whose individually identifiable health information has been lost, stolen, or used for an unauthorized purpose by the entity responsible for the information and notification by the entity to the Secretary.
(b) List of Entities.--The Secretary shall maintain a public list identifying entities whose health information has been lost, stolen, or used in an unauthorized purpose as described in subsection (a)(6) and how many patients were affected by such action.
(c) Construction.--Nothing in this section shall be construed as superseding, altering, or affecting (in whole or in part) any statute, regulation, order, or interpretation in effect in any State that affords any person privacy and security protections greater than that the privacy and security protections described in subsection (a), as determined by the Secretary.
Mr. DOGGETT (during the reading). Mr. Speaker, I ask unanimous consent that the motion to recommit be considered as read and printed in the RECORD.
The SPEAKER pro tempore. Is there objection to the request of the gentleman from Texas?
There was no objection.
The SPEAKER pro tempore. The gentleman is recognized for 5 minutes.
Mr. DOGGETT. Mr. Speaker, this is an important motion for a modest bill. It leaves this bill with an opportunity to move forward today with just one important change, and that is the addition of vital personal privacy protection of what should be genuinely personal medical records.
In my youth, there was a popular song called ``I Heard it Through the Grapevine.'' These days, it's ``I saw it on the Internet.'' In this busy world of busy bodies and identity theft and commercial snooping, I believe what a patient confides to a physician about an ailment, what a young couple tells a psychologist about their marriage, what prescription a pharmacist provides, that highly personal information should not be spread and read on the Internet.
The consequences of unwanted disclosure of personal health information is more than embarrassment or humiliation. It may mean the loss of a job or a promotion. It may mean that an individual refuses to confide necessary information to their doctor or avoids health care and critical medical tests because of fear that the information will be disclosed without her consent.
This Administration has shown little interest in personal privacy, whether it was the privacy of library records or phone conversations or veterans' records.
The Federal Government scored a D-plus on the 2005 Computer Security Report Card, with the Departments of Health and Human Services, Veterans Affairs, and Homeland Security scoring an F. And the Administration's record on health care privacy is even worse. As the Post disclosed last month, there have been 19,420 complaints during the Bush Administration about privacy violations. There have, during this Administration, been almost 20,000 complaints about invasions of privacy with medical records, and all of that has not resulted in a single civil fine anywhere in this country under the protections that are available there, and only two criminal cases out of that 20,000.
This is not an adequate performance, and that is why Dr. Deborah Peel, one of my Texas neighbors, and a host of professional and public health organizations have urged us to adopt meaningful privacy protections in this bill.
Mr. Speaker, I yield 1 minute to the gentleman from Rhode Island (Mr. Kennedy), who has been such an advocate on this.
Mr. KENNEDY of Rhode Island. Mr. Speaker, I want to ask a few questions to my colleagues about this privacy law.
Do you think it should be a violation of Federal health privacy law to be able to hack into an electronic database for health information? I think it should be against the law. But it is not against the law.
If a hospital employee accesses your health record, for example, for a famous movie star and sells it to a tabloid, do you think that is wrong? Well, that is not against the law now. If you can allow a hospital information to be accessible through an information network, this is now permissible.
All of these things are permissible under the HIPAA law. And if you do not like that, you are going to hate what this bill does to HIPAA, which is going to magnify it 100 times. There is going to be no protection for privacy whatsoever.
And that is why I ask all of you to join us in the motion to recommit. Your constituents will thank you for it if you vote for the motion to recommit.
Mr. DOGGETT. Mr. Speaker, I thank the gentleman, and I yield the balance of my time to the gentleman from Massachusetts (Mr. Markey), who has led the way on privacy issues across this country.
BREAK IN TRANSCRIPT
http://thomas.loc.gov/