The HITECH Act established specific marketing restrictions that tighten the rules set by HIPAA regarding the use of protected health information (PHI). The Act provides that covered entities must obtain prior written authorization from individuals before using their PHI for marketing purposes unless specific exceptions apply.
A Report on Patient Privacy notes, “...a communication is not considered “marketing,” and consequently does not require authorization, if it falls under one of the three HIPAA exceptions for treatment, payment and/or health care operations (TPO):
(1) It describes a health-related product or service (or payment for a product or service) that is provided by, or included in a plan of benefits of, the CE making the communication;
(2) It is made for treatment; or
(3) It is made for case management or care coordination, or to direct or recommend alternative treatments, therapies, health care providers, or settings of care to the individual.”
The HITECH Act expands the definition of marketing to include any communication about a product or service that encourages recipients to purchase or use that product or service. This definition aligns with the Privacy Rule, which requires covered entities to obtain valid authorization from individuals before using their PHI for marketing purposes.
The HITECH Act also introduces stricter requirements by specifying that if a healthcare organization receives any form of financial remuneration for communication, whether it pertains to treatment or healthcare operations, it must obtain prior written consent from the patient.
When healthcare organizations receive a payment for sending an email about a new treatment or service, they must first obtain explicit consent from the patient. The Act therefore narrows the exceptions previously allowed under HIPAA to provide stricter guidelines for healthcare organizations in common marketing areas like email campaigns. The end goal is centering patient privacy through improved consent mechanisms in a way that often forces healthcare organizations to limit the scope and frequency of even HIPAA compliant email marketing efforts compared to other sectors.
The treatment, payment, or healthcare operations exception refers to the provisions under HIPAA that allow healthcare organizations to use and disclose PHI without patient authorization for specific purposes.
Explicit consent is the clear and affirmative agreement from a patient allowing a healthcare provider to use PHI for specific purposes, particularly in marketing communications.
Failing to obtain explicit consent before using a patient's PHI for marketing purposes can lead to financial penalties being imposed by the Department of Health and Human Services (HHS).