Emerging Litigation Podcast
Litigators and other professionals share their thoughts on ELP about new legal theories, new areas of litigation, and how existing (sometimes old) laws are being asked to respond to emerging risks. The podcast is designed for plaintiff attorneys, defense counsel, corporations, risk professionals, litigation support companies, law students, or anyone interested in the law. The host is Tom Hagy, long-time legal news writer and enthusiast. He is former editor and publisher of Mealey's Litigation Reports, Founder and Editor-in-Chief of HB Litigation, co-owner of Critical Legal Content, and Editor-in-Chief of multiple legal blogs for clients. Contact him at Editor@LitigationConferences.com.
Emerging Litigation Podcast
HIPAA Meets Social Media Marketing with Liz Heddleston and Leah Stiegler
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, I get to speak with Liz Heddleston and Leah Stiegler of Woods Rogers about a healthcare compliance issue that many organizations may be underestimating: the HIPAA risks created by modern marketing practices.
Healthcare providers increasingly rely on social media, patient testimonials, online success stories, influencers, user-generated content, and even AI-assisted marketing tools to build visibility and connect with patients. But as recent enforcement activity demonstrates, these efforts can create significant HIPAA exposure when protected health information is disclosed without proper authorization.
Our conversation uses the recent OCR enforcement action involving Cadia Healthcare Facilities as a starting point. OCR alleged that patient names, photographs, and treatment information were publicly shared through online success stories without valid written HIPAA authorizations. The resulting settlement serves as a reminder that positive intent, patient enthusiasm, and informal consent do not eliminate HIPAA obligations.
Liz and Leah help unpack what went wrong in the Cadia matter and explain why healthcare organizations should be paying close attention. We discuss:
- Common misconceptions about de-identification
- The growing risks associated with social media and AI-generated content
- The compliance challenges created by marketing vendors, agencies, and influencers
- Where OCR enforcement may be headed next
One of the key themes throughout the discussion is that HIPAA compliance is no longer just an IT or cybersecurity issue. As healthcare organizations expand their digital presence, privacy compliance must become part of the content creation and marketing process itself.
Whether you're a healthcare executive, compliance officer, in-house counsel, privacy professional, marketer, or outside advisor, this conversation offers practical guidance on navigating the intersection of healthcare privacy, digital marketing, and regulatory risk.
Jump in to hear Liz and Leah's insights on HIPAA compliance, healthcare marketing, and the emerging risks organizations should be addressing before an enforcement action brings them into focus.
______________________________________
Thanks for listening!
If you like what you hear please give us a rating. You'd be amazed at how much that helps.
If you have questions for Tom or would like to participate, you can reach him at Editor@LitigationConferences.com.
Ask him about creating this kind of content for your firm -- podcasts, webinars, blogs, articles, papers, and more.
Digital Marketing Hits HIPAA Reality
Tom HagyHello and welcome to the Emerging Litigation Podcast. I'm your host, Tom Hagy. So healthcare marketing is undergoing a rapid transformation. Traditional advertising channels are giving way to digital first strategies built around social media, online testimonials, influencer partnerships, influencers for those you know like me, and uh user-generated content also like me for healthcare organizations. This is pretty new, but I don't know. It's been expanded, let's just say it's been accelerated like a lot of things. The shift offers new opportunities to build trust and visibility for healthcare organizations, but it also introduces otherwise we wouldn't be here, serious compliance risks in this time under HIPAA. Recent enforcement action by the U.S. Department of Health and Human Services Office for Civil Rights against Kadia Healthcare Facilities puts those risks into sharp focus. And we're going to use that as the jump-off point for our conversation today. I'm happy to be joined by Liz Heddleston and Leah Stiegler. They are principals at Woods Rogers. They're experienced advisors to healthcare organizations on HIPAA compliance, privacy, and regulatory risk. The practice focuses on helping providers, business associates, and healthcare adjacent organizations navigate privacy allegations in increasingly complex digital and operational environments that they're in. I think we're all in those. Liz and Leah regularly counsel clients on HIPAA enforcement actions, breach response and enforcement training, compliance challenges that arise at the intersection of healthcare, marketing, and technology. What do you think? We have schlubs on the Emerging Litigation Podcast on emerging health care privacy issues. I just adjusted my seat, put myself in my seat. My wife tells me not to do that, including digital marketing practices, social media risk, and evolving OCR enforcement priorities. I'm proud to say. This
The Cadia Settlement Explained
Tom Hagyis like a monster truck rally. So to set the stage, I have introduced you already and I've told listeners generally what we're talking about. We're talking about HIPAA and privacy and things like that. But in September of 2025, the OCR announced a settlement with Cadia Healthcare facilities. They investigated allegations that they were posting patient success stories, which is something that a lot of companies do, law firms do it, publishers do it. They, you know, this is something we did that was uh really great, you want to know about it. So they put these online and they I guess inadvertently published some details that disclose protected health information. So talk about what what Cadia did wrong and what the OCR is doing.
Liz HeddlestonAbsolutely. They yeah, they did a few things wrong here, and and that's why we ended up with this um this settlement amount. Cadia, you know, as a starting point, they're a provider of rehabilitation, build nursing, long-term care services. So they're healthcare entity. Um, and and because they're a healthcare entity, they're a covered entity and they must comply with HIPAA. But, you know, they're a business too, and like any business, they're they're doing their um their social media marketing and all of that. So in this case, like you said, Tom, um they were posting these patient success stories. And from what we can gather from the, you know, information OCR has put out there, these social media posts included the patient's name, some information about their conditions, their treatment and recovery. You know, I imagine that they were very positive and inspiring. But at the at the end of the day, what OCR is saying is they did this without complying with HIPAA. So what they did is they didn't have these patients sign valid um HIPAA authorizations that basically say, you know, we consent to you, KDS, my uh my information about my health in an online, in a you know, online format. So that was kind of mistake uh number one is well, first that they posted this information um and didn't really, I don't we don't know exactly what was happening, whether they realized it was PHI or not, but they posted it and then and they didn't have these valid HIPAA HIPAA authorizations, which they have to be in writing and they have to have, you know, all these elements required by HIPAA. So we don't we don't know all of the facts. It's possible that the patients at the time were very well aware of the social media campaign, that many of them were cool with it. They might have verbally consented. Again, we don't have all the details, but in situations like this, you might even have a provider have them sign like a two-sentence, yes, you can post my image online. But unfortunately, something like that doesn't comply with TIPA. Um and I think Leah wants to chime in.
Leah StieglerYeah, good.
When A Resident Photo Becomes PHI
Leah StieglerI think the point, Liz, about, you know, probably a lot of the patients were generally okay with that in in the sense that maybe for a while there was some low risk there. When working with assisted living or or nursing facilities, oftentimes, you know, the companies refer to the individuals living there as residents, not patients. And so there's also that, I don't know if it's just using that term in a way too, that you don't necessarily think of it as, oh, there might we might need to, from a HIPAA perspective, the you know, we can't market it the same way. And I'd say even my um my sister-in-law, her grandmother was at a facility and I remember going out to dinner with her and she was like, Oh, look at they're doing crafts today because they were doing these, you know, Instagram and TikTok videos of the residents. And sometimes it wasn't like the residents were sharing health information, they were just videos of the residents maybe dancing to dancing to something or having a chess tournament. So from your perspective, Liz, is it even just would it cover, would HIPAA be triggered even just so showcasing someone living there as a resident slash patient? Or does it also have to be content that shares health information?
Liz HeddlestonYeah, so it's a fact-specific analysis, but basically, yeah, simply identifying someone as a patient or a resident of a healthcare entity, a rehab facility, a skilled nursing facility, that alone is PHI. The definition of PHI under HIPAA is very broad and simply demographic information alone, you know, that combined with the fact that they're a patient, that is enough to be considered PHI under HIPAA. So yeah, you could be posting, you know, residents playing chess at a rehab facility, but the post is probably, you know, it includes the name of the rehab facility. So there's this assumption, yes, they are they are patients or residents there. And even though it's focusing on the social aspects, um, that's still, you know, from my perspective and and from what I've seen into how HHS approaches that, that's still considered PHI. And you have to, you know, you can disclose it. You just you have to get the patients to sign, you know, a written authorization saying it's okay. And again, it's not just any little, you know, two-sentence consent form. It's gotta be the HIPAA compliant authorization that has the elements that HIPAA requires.
Tom HagyYeah. You mentioned they were filming them also dancing. What if you're an embarrassingly bad dancer? Is that covered? Is that something you don't want to disclose?
Leah StieglerThat's probably how the the patient complaint got started, actually.
Tom HagyI bet that is it.
Leah StieglerThey were using learning the square dance. And actually, it's funny, I could say I could speak to this uh as a not just as a lawyer speaking on this topic, but as a victim of the PHI disclosure, not because of my poor dancing, but actually.
Tom HagyOh, I thought that's where you were going.
Leah StieglerNo, uh when I was growing up, or my orthodontist used to have everyone's photos, you know, uh with their smile, the before and after pictures, um, you know, pictured up on the wall. And I came in one day and I was like, oh, what what happened to my photo? You know, I was like, actually, my ego was hit by the fact that they took down my before and after photo for HIPAA reasons, we're not allowed to post it anymore, right? So even, even Liz, is it enough? I mean, in that that scenario, right? I was kind of consenting verbally by way of saying, yeah, you can take my picture. I mean, would that not be enough? It's not enough.
Liz HeddlestonYeah. It's enough for certain other types of disclosures under HIPAA, like, you know, if you're getting treated and you bring, you know, another family member to treatment and they're in the room, there's kind of you can verbally say, yes, you can share my PHI with that family member. But when it comes to publicly sharing PHI, whether it's on the in the wall of an orthodontic office or obviously online, verbal consent is just not enough. And I think OCR was very clear with that. And to the point of the bad dancing, and and Leah's point here, you know, and a lot of times in this scenario, probably a lot of the patients were were generally okay with it. But then you've got the one who wasn't. And they complained to HHS OCR. Every patient has a right to do that. It is very easy. You go online, you fill out a complaint form. And HHS OCR has an obligation to investigate that. And so that's how we see where we see a lot of the enforcement coming from. And
Patterns, Breach Notices, Training Gaps
Liz Heddlestonin these kinds of situations, it's that one patient who's not cool with it. And then you've got HHS looking over your shoulder, and then they're doing the investigation. And in this case, they found out it wasn't just this one-off social media success story. It was 150 times, right? So that was another thing that went wrong here. It wasn't a one-off mistake that they kind of corrected. It was a pattern, and HHS OCR is big on patterns. So it happened, I think it was 150 times. So they were doing it a lot. And then the other kind of problem of what went wrong here is once they discovered what happened, and I'm putting all this together kind of from the settlement and they had like a resolution agreement that's online. But once they found out what happened, so they they did the immediate corrective action, which is they took the post down. So that's good, right? You've done some damage control, but they didn't follow the HIPAA breach notification rule. So they didn't take that next step that says, okay, we had an impermissible disclosure of PHI. We shared all this PHI online without patient consent, you know, as required by HIPAA. So they did not, they did not treat it as a breach under the HIPAA breach notification rule and issue the letters that you're required to do in those kind of situations. And so there were, you know, quite a few things here I think that went wrong. And then the other issue cited in kind of the resolution agreement is it basically implied that they didn't have compliant HIPAA policies. So that's kind of how underlying kind of how some of this probably came about. Um, and you know, they cited the need for some additional training going forward.
Leah StieglerAnd I think I think that's really important because in a setting like that, it's very common for the clinical employees, anyone who's maybe a medtech, LPC, nurse, the clinical employees to have HIPAA compliance training. But you don't always think about having giving that kind of training to the back office employees, maybe your HR team, or in this case, your marketing team. And so there was probably a gap to some degree in from an informational standpoint. The marketing team was, you know, doing a great job marketing these stories, probably brought in a lot of residents doing what they're supposed to be doing, just without the HIPAA compliant process.
Liz HeddlestonAbsolutely. Yeah. And I think we we what we see in pretty much, you know, all of the HIPAA settlements is you're organizations really have to take an NRY, enterprise-wide approach now with HIPAA compliance because of the way PHI flows through organizations. It's really just not confined clinical and and uh frontline, like Leah mentions. You know, it's PHI is used often for marketing purposes. So we have to be broad in how we think about HIPAA compliance and not have a siloed approach, but really be holistic to kind of prevent situations like this from happening.
Tom HagySo I guess
Vendors, BAAs, And Marketing Contracts
Tom Hagywhen you when you say it needs to be looked at in a broad way, so it's beyond employees because they're I know we all aspire to be social media influencers, while Leah uh may be already, but that these are third parties, these are not, these are contractors, they're not employees. So does anything change?
Liz HeddlestonAaron Powell Yeah, good question. So yeah, my impression from the Cadia settlement was this was, I think, the internal marketing team, although I I'm not sure they got into detail. But and you know, increasingly healthcare organizations are outsourcing marketing or relying on third-party vendors for marketing because they have, you know, more specialized expertise. So when you do that, when you share PHI with a vendor for a marketing type purpose, the covered entity, the healthcare entity, is still kind of legally on the hook for those disclosures and how their vendor uses PHI for marketing purposes. So yeah, it adds another layer sort of to the HIPAA compliance analysis.
Leah StieglerYeah. You probably mean one thing for companies to keep in mind is when they're healthcare companies, especially when they're use working with outside vendors is to make sure that their contracts with those third parties do address stuff like that, does address stuff like this, including maybe an indemnification clause. But even beyond just HIPAA um compliance, requiring HIPAA compliance with your third-party vendors, you know, just uh in general, if if those marketing vendors come in and they're taking videos or photos of even employees, then there also are are other consents that you need as well. And so getting sort of we're we live in the NIL world, not just in terms of athletes, but even with employees, obviously with patients, you can't just necessarily use someone's name, image, and likeness without proper disclosures and consents.
Liz HeddlestonYeah, absolutely. And from a HIPAA standpoint, if you hire an outside vendor to do marketing on behalf of you, the healthcare entity, they might legally be a business associate. So they're then gonna have their own HIPAA compliance obligations, and you have to have a business associate agreement in place. And, you know, I'm uh fine seeing with some of my clients, you have a lot of people kind of in the ecosystem now in marketing and doing it across industries. And some folks don't, they're gonna hold themselves out as they're not gonna understand the regulatory side of the healthcare industry, that what you can do in another context, you know, for a restaurant or some other kind of business, you can't do that in the healthcare context without, you know, the proper patient consent. So what that comes back to is the healthcare entity is really responsible for vetting its vendors and for the legal analysis around are they a business associate? If so, we need to make sure the PHI is shared in a compliant manner. You can't just rely on the representations of the vendors. I had a client recently come to me and was like, we have this vendor that wants to help us manage all of our online reviews and they want us to respond this way. And I was like, no, you can't do it that way. Like, um, but it was just not in line with the way that what HHS and HIPAA um requires in responding for to online reviews.
Tom HagyThat's not in line with a lot of things, I think.
Leah StieglerYeah, what would that have even looked like? It's like it's like a physical therapy practice or a medical practice, and someone writes an online review and was like, you know, my knee was never the same. And then the third-party vendor comments back and was like, it wasn't our fault, it was because you didn't comply with your PT, you know, on a regular basis. I mean, the kind of thing has happened.
Liz HeddlestonThere have been HIPAA examples where medical practices have shared PHI in their responses to online reviews, and they've had to pay thousands of dollars. I mean, and people even acknowledging in the review that that individual was a patient without kind of responding substantively can be an issue. So there's just a lot of hot water areas. There's a lot you can do with marketing, that's okay. Um, but you just you have to vet it under the HIPAA analysis, and you you really can't um rely on the representations of the vendors, especially the ones who are kind of newer and less sophisticated.
Tom HagyWow. Yeah. I could just that could just go so many ways. Your D you know your knee wasn't that great to begin with. Yeah.
Leah StieglerMaybe if you want to wait, you know, and you would be Yeah.
Tom HagyGood God. Yeah. Um maybe you should dance more. No, the I guess I went through this a little bit. I'll I'll I'll make this relevant, trust me. So I I'm a grandfather now. I've got a my daughter had a baby on Christmas. We're very happy. So naturally I take pictures of the baby and I put them up on Facebook. My daughter immediately said, very nicely, you know, would you mind taking that down? You know? I'm like, that was her version of a HIPAA violation, I think, because you know, I I don't want my baby's picture ending up on like whatever advertising or or or whatever because of her her name, image, and likeness. But I thought, well, if I don't put her name on there, haven't I de-identified her? Plus she's a baby, you know, and she's gonna look different.
Leah StieglerBut uh They all look kind of the same.
Tom HagyShe's she doesn't, Leah. She is absolutely gorgeous. Oh my god. All right, I'll send you I'll send you a picture and you just don't share it. But anyway, so I've I thought I um anonymized it or de-identified
De-Identification Safe Harbor Basics
Tom Hagyit. If you so how does that work? Uh if you just remove someone's name, does that uh get you in compliance with HIPAA?
Liz HeddlestonYeah, no, it does not.
Tom HagyThat's my favorite answer. Yeah, no.
Liz HeddlestonNo, it doesn't. So yeah, in in in kind of your scenario, assuming it was in the healthcare context, the full-faced photo of an individual even without the name, that that can be PHI. So yeah, there's kind of a misconception that if it doesn't contain the name, it's not individually identifiable, it's not PHI. But it's actually really the definition of PHI is very broad. So if you can reasonably identify that individual even indirectly, um, that can be considered PHI. And in fact, to you know, ensure that it's not PHI, you have this sort of safe harbor under HIPAA, the de-identification standard. Do you want me to get into that yet?
Tom HagyYes, please.
Liz HeddlestonUnder the de-identification standard, you are kind of in the safe zone. So you can share this data because it's no longer considered PHI. But it's pretty hard to meet the de-identification standard. There's two ways to meet it. The first, safe harbor, is removing 18 different specific identifiers that are identified in the regs. These are things like name, full face photo, geographic identifiers, like you know, zip code, um, things like that. So if you strip the data uh, or if your data doesn't contain any of those elements, then it's considered de-identified and you're safe. And there's 18 different elements you have to ensure that you stripped out. So that's why Yeah, go ahead.
Leah StieglerWhat if my orthodontist had just instead of taking a picture of my face, just the bore before and after of my mouth, would that probably have worked?
Liz HeddlestonThat's like kind of getting in the gray zone. So yeah. So if it's if it is, you know, just a partial of your face and there's not anything on like a face tattoo or something to be clear for these audio listeners that I do not have a face tattoo. But if you have a face tattoo, you know, and they know you're in what so and so town, you can identify someone just by showing their mouth to get Uh you know, I'm but um what I'm getting at is it's a fact specific analysis. So you might be in a safer zone if it's enough not a full face photo and there's no it doesn't say anything more specific than just this is a partial image of the before and after of the mouth. Um sorry. My face tattoo was sort of the there can be exceptions, you know. If there's something very distinguishing about that photo, you know, nowadays it's it's a known smile, like like Mike Tyson, everyone knows Mike Tyson's smile, right?
Leah StieglerSo if we just had his, if his Dorthodontis just had his mouth, that'd probably be a hypocrite.
Liz HeddlestonYeah, and I could identify that, I'm sure.
Tom HagyWait, no, he's a celebrity. Can we still no mind? But if you were good if you're going to get a face tattoo, Leah, what would it be?
Leah StieglerThat's a really good question.
Tom HagyYou don't have to answer. That would be private.
Leah StieglerThat would be private. I don't know. It's probably some kind of cool like snake around my on around the side of my face. You know, only on one side, so if I had to stay professional, I could always just look to my right or something.
Tom HagyThat's right. Yeah, that's a good idea. Yeah. Or you could just put the emerging litigation podcast logo. Uh I'll pay, I'll pay for that.
Leah StieglerThat's interesting.
Tom HagyNever mind. What were you gonna say?
Employee Snooping And Presumed Breaches
Leah StieglerI was gonna say um an interesting HIPAA breach so situation that Liz helped me out with. So Liz and I work together a lot because as you can imagine, oftentimes at healthcare uh places, it's employees who are breaching HIPAA in some manner. But we had we had an interesting one where an employee, um, the the employee's husband, who they were going through a separation, she ended up accessing his medical information through like their their charts because she was an employee there. And so, you know, even if and there was no evidence that that information was ever like used in any way, right? So that that that that the knowledge of his health information was ever used in any way, but it was still, Liz, right? It was still a HIPAA breach or potentially a HIPAA breach in the sense so the person accessing it doesn't have to actually use it or market off of it or monetize the information, you know, and obviously in in the KDA healthcare situation, they were using it for marketing purposes, but even if it's just access alone, right, that triggers HIPAA.
Liz HeddlestonYeah, I mean that trick triggers the definition of a breach under HIPAA. Um, and that's the classic employee snooping situation, which I'm sure you deal with on the HR side all the time. And it's a classic scenario under HIPAA where, you know, you have an individual who has access to the EHR, but they can only look at charts for purposes within their job. They can't, you know, snoop into their, you know, separating husband's EHR. So I forget what your original question was. But yes, access, that kind of inappropriate, impermissible access triggers a definition of a breach. There is some sort of legal analysis you you have to go through sometimes to determine if you have notification obligations, but it is a presumed breach unless you meet, you know, this low probability of compromise standard. But in a situation like that, you know, it's very likely an indiv an employee who has might use that in an inappropriate manner. So you kind of have to presume it's a breach unless you have these facts that show, hey, there's really a low probability of compromise here. Trevor Burrus, Jr.
Tom HagyOkay. And then we did talk about, uh we had it queued up to talk about, and I think you address it though, working with vendors and influencers as opposed to uh in-house, in-house folks. But I think you you made the point that in the contracts with vendors and things, you have to be aware of HIPAA compliance and comply with those rules. Was there anything else to say about that or like you covered it?
Liz HeddlestonI I
Influencer Reshares And Metadata Risk
Speaker 1had a thought based on your baby photo sharing example that I wanted to link back to around social media influencers.
Tom HagyDo it.
Liz HeddlestonSo patients have a right to share their own health information all over the internet if they want to. You can post everything you want about your cancer journey or on Facebook or whatever. Um, what where you run into an issue with a healthcare entity is so say the hospital media team wants to reshare the social media, local social media influencers' patient success story. That resharing can be without the written consent of that patient, that could be a HIPAA violation. So it's kind of a new frontier. You have to be careful. So the social media influencer patient, they put it out there publicly. That doesn't mean the healthcare entity can then reshare that post on their own platform. That's taking it into HIPAA territory.
Leah StieglerThat's so wild because you would think that, you know, if my mom shared a patient success story of herself, right? I could reshare it, no problem, but the actual entity itself couldn't without potentially having to go through the HIPAA compliance requirements.
Liz HeddlestonIf we're the entity is sharing it as a, hey, this is our patient, and we're we're sharing their resharing their story. You know, yeah, could you can you share a general like a celebrity is posting about their health issue or a cause? You know, they're not your, you're not holding them out as your patient. That's different. But it's just kind of there's with um social media influencing and and just the digital ecosystem, I think there's a lot of ways you can run afoul of HIPAA if you're not careful and if you don't have your guard up. And that gets back to what we talked about earlier is to not silo HIPAA compliance, but to really have the me the marketing folks, the business folks trained and just know when to raise the red flag, when to say, hey, we need to put a pause, we need to talk to our compliance team, our legal team. And I mean, that's kind of one of the big takeaways, I think, from all of this.
Leah StieglerRight. Basically, grandbaby can share her own experience about seeing birth in a particular hospital, but Tom, you can't.
Tom HagyYeah.
Speaker 2I just had the hospital.
Tom HagyYeah, I'm just not doing it anymore. Yeah. I really want to, though. Too bad. Okay, so I can send it to people individually. No, so but I guess but the fix, uh Liz, to your point, if somebody sees that somebody else has shared their good story, it wouldn't seem to be a difficult fix to contact the person and get them to say it's okay to use it.
Liz HeddlestonAbsolutely. Practically, that's the practical workaround. You can a hundred percent do it if you get their written authorization to do it. So you can do it, but you need to comply with HIPAA when you do when you do that. And when I say you, the healthcare entity, covered in the right.
Tom HagyYou didn't mean me personally.
Liz HeddlestonBut yeah, so it's you know, you there's a lot of avenues for using PHI in marketing, but you know, at the end of the day, HIPAA is about protecting privacy and giving patients a right over how it's used. So you you really have to honor that. And that's why that, you know, HIPAA has these strong um consent or HIPAA written authorization rules. They really, you know, it's it's like you really understand what PHI we're gonna disclose, the reason we're gonna disclose it, you know, that you have the right to revoke your consent. You really have to jump through those hoops so that the patient is kind of informed and it's not just a casual consent because once it's online, it's gonna be up there forever, you know. So it's that's that's kind of what the heart of it is is getting at with it.
Tom HagyYeah. And I guess too, um, I don't know, because I was just talking to somebody else about digital evidence. Um so I'm wondering, does PHI also uh cover metadata? I mean, excuse me, did I say PHI? No. Did uh with the with these HIPAA, did I say this right? Let me ask the question again. If there's metadata on a photo that has identified information, but it's not obvious to most people. Does that ever come up? Does the metadata disclose?
Liz HeddlestonMetadata could if it's disclosed and some third party can access it, it absolutely can be considered PHI if it provides additional information around the patient or yeah. So absolutely, I mean, there's been um a lot around like how a patient's IP address when they visit a healthcare entity's website, that alone can identify an individual. So that can be considered PHI because yeah, there's some litigation around this right now, but it's a pretty broad definition. Um, so you do have to be careful.
Tom HagyYeah. Okay.
Leah StieglerOne thing I think is important to note is that HIPAA does not cover employee medical information, assuming the employee is not a patient. So this is constantly confused in my world, in the employment world, where you know, an employee will submit a request for reasonable accommodation under the Americans with Disabilities Act, or the employee will request leave for medical reason under Family Medical Leave Act. Frequently, managers or even very experienced HR professionals will say, Well, I can't discuss this with other executives or something because of HIPAA, because of HIPAA. No, HIPAA is applies to a healthcare entity's protection of information of health-related information to patients. It's actually the Americans with Disabilities Act and maybe some other even state laws that cover protection of employee medical information. But it's commonly confused.
Tom HagyYeah, I can see
OCR Priorities Plus AI And ChatGPT
Tom Hagywhy. Well, it seems like OCR is typically what we know it for is like, you know, focusing on data breaches and ransomware and things like that, with increasing use of social media and influencers and third-party marketers. The first question is, do you do you expect to see more of this? Or and and and then if so, what do you think healthcare leaders should be doing right now?
Liz HeddlestonYeah, so I do expect to see more of this. I think that HHS is attuned to the I do I think ransomware and those sorts of data breaches, they're gonna be continue to be kind of the bread and butter of the enforcement activity we see with HHS OCR. But I think that HHS is gonna continue to look at these sort of privacy breaches relating to social media and and marketing and things like that more. So I think, you know, it's it's sort of building on a couple years ago when they were looking at providers responding to online reviews and sharing PHI that way. Now they're they're looking at kind of patient success stories and social media marketing. So I think they're kind of this is sort of an example and a deterrent, but I think that they will continue to investigate that. I do have to caveat that with, you know, there have been significant thinning of like, you know, the federal agencies, including HHS OCR. So some of the manpower, you know, could impact just the the volume of activity. But even since those cuts, I'm still seeing very active HIPAA enforcement. You know, last week there were four settlements announced. They were all kind of bread and butter ransomware incidents. They were not high dollar or they weren't high profile change health care type breaches. They were run-of-the-mail ransomware impacting, you know, from 7,000 patients to maybe 100,000 patients. And um, they all, you know, they were settled with fairly significant financial settlements, 200,000, 300,000. So I mean, HHS is not slowing down. We are gonna continue to see a lot in the realm of ransomware and data breaches. But I think that, you know, these more kind of operational type disclosures, they're gonna continue to pay attention to that. And especially, you know, I'm waiting for the first one that's very AI oriented, because I'm sure that's coming. I think they are watching these kind of newer frontiers of how PHI kind of gets used in the digital ecosystem. And I do think we're gonna continue, you know, resources permit permitting to see enforcement action in those areas.
Leah StieglerI think what you just touched on, I think the new frontier on top of the operational one that we're looking at with Katie is, you know, a practitioner potentially putting in protected health information into Chat GPT, right? To have Chat GPT write the counseling notes or their supervision notes or whatever it may be and kind of going after it in that sense. You know, you use ChatGPT and you think, oh, no one's the ChatGPT world, no one's ever gonna know that I, there's a billions of people using it every day. No one's gonna know that I put this in here. But it's gonna take one person finding out or one patient finding out and for us to see an enforcement action. But even outside of OCR enforcement actions, I I don't I don't think HIPAA has a private right of action for individuals, but there are state law claims that people will try to bring in terms of of privacy breaches and confidentiality breaches or the name, image, and likeness issues as well. Uh so that's another thing to be mindful of. Absolutely.
Tom HagyYeah, chat GPT, putting confidential information into it. It also comes up in uh attorney client privilege and work product issues. It was just a decision about that. So, I mean, I use copilot a lot, and the engine for co-pilot on Microsoft is ChatGPT. Microsoft invests heavily in OpenAI, but um, it always tells you, you know, don't put anything confidential in here. You know, of course everybody listens to what uh they tell you on the web. So it it's tricky. You know, for the sake of uh is there anything else before I go on? Is there anything else you you wanted to add, Liz or Leah on the employment side? I think we covered everything really well.
Leah StieglerFor sure. No, I mean I'd say get those get those consents because we love to see the resident dancing videos. That makes our day so it doesn't, it's not that hard to pay a lawyer for an hour to get a proper consent form so that you can still showcase some really fun activities.
Tom HagyYeah. And if you're still doing you're still an independent living, I suggest private dance lessons just because that's what's coming, you know? When you do a uh hoe-down, what is that called? Barn dancing? I don't know what fragment is. How do let's see, I'm gonna handle the key takeaways.
Practical Takeaways And Closing
Tom HagySo do you want to paraphrase those for I mean, Liz, this is your your main thing. And then uh course, of course, uh you know, Leah, you could add a fourth on employment if you like. But do you want to take a stab at that? I don't want to read them. I can just I can introduce it. So, Liz, what should people generally take away from uh this podcast? And and then Leah will give you a shot too.
Liz HeddlestonYeah, so I think what we're some big takeaways are, you know, even if you have good intentions and you're putting out these patient success stories and they're positive, and you know, the the patients or the residents seem okay with it, that can still create HIPAA risk, right? You're still putting PHI out there, and you've got to make sure you have your HIPAA compliant written authorization in place. So your your good intentions, your benevolence, that's that's not not gonna be a defense. And I think paired with that is you really have to make sure you have an enterprise-wide approach to HIPAA compliance because PHI is really, it's not, it's not limited to the clinical side. It's flowing to the marketing teams, it's flowing to the business teams. So you really have to make sure you have the training and the policies in place so that they have the awareness to raise the red flag before putting up those positive stories without the HIPAA written authorization. So that's a big one. Digital marketing is going to kind of um expand your kind of risk areas because it's it's a little bit of a new frontier. There's players, vendors out there who don't really understand HIPAA. So you have to have, you just you have to be aware of the risks when you have or you're working with vendors and using PHI with digital marketing. So there are some new, new HIPAA risks you need to be aware of. And I think I already touched on it, but uh HHS OCR is big on HIPAA compliance is enterprise-wide. And pretty much every settlement um I see they're they're finding kind of systemic non-compliance with HIPAA. So just an overly narrow approach to HIPAA and not taking that holistic approach. And frankly, the way we share PHI and the way it flows in organizations, it's not paper anymore. That's decades ago. So it's really complex. And it's it's harder for organizations to understand how it's flowing even within their own organization and then to vendors. So you have to really um kind of keep up with that map how the PHI is flowing and how it's flowing outside of your organization and for what reasons and to whom, and just get a handle on that. And that's really going to help you with your HIPAA compliance.
Leah StieglerI'll just add from the employment perspective, train, train, train. Don't just train the clinical personnel, train the marketing admin, your in-house lawyers, train them all. Because another area you can uh litigation that you can face is in the negligent hiring or negligent retention area for if you've got an employee who's you know breached TIPA or disclosed improper health information and you're not properly taking an action as a company to discipline them or ensure no further harm, and that employee continues to do it, you're you're running a foul uh in the state common law area as well. So just be mindful of that.
Tom HagyOkay. You know, Leah, while while we were doing this, our my producer contacted your orthodontist and tell me if this is true or not that you went back in and you were taping up pictures of your face uh in the office. Is that did that did that happen?
Leah StieglerAt a young age, I knew I was a narcissist, you know? Because I had to have my face up there.
Tom HagyYou know, you must have a show business thing on. Look at you, you're podcasting and all this. You have your own microphone. I don't know. Maybe maybe you should have been, you know. Do you did you ever been do community theater or stand-up?
Leah StieglerOr you know I that's next. Uh I was in one play, I was in a Shakespeare play, and uh I think I was like Ophelia or something, and I um I uh I talked I to try to speak in Shakespeare speak, it every every sentence sounded like a question. And so I remember like the director being like, so not everything is a question, you know. But I was like, but I don't even know what I'm saying. So half the time my sentence is just like like where where they where they go down that road, you know. I don't know.
Tom HagyI don't know. I can't read them, so anyway. Anyway, Leah and Liz, thank you very much for doing this. I appreciate it. It's good information today.
Leah StieglerAwesome. Thanks for having us so much.
Tom HagyLiz, you survived your first podcast. You okay?
Liz HeddlestonI feel good.
Tom HagyYeah, you're gonna do more now.
Liz HeddlestonLeah and Tom was a blast. Yeah, you kick butt.
Tom HagyI'll use that as a I'll use that as a testimonial without your permission.
Leah StieglerTom and I talk about mainly irrelevant things.
Tom HagyYes.
Leah StieglerSo I'm glad you got in all the substance, Liz. That's very important.
Liz HeddlestonI'm here for the substance, but I enjoy all this.
Tom HagyYeah, we go off track, and it's mostly my fault, but it's it's really funny how Leah just follows right along with it. Most lawyers are like, okay, yeah. And so what the law really says. Yeah, one made a mistake of asking me about the pictures on my wall. Oops, sorry. He asked me about the pictures on my wall, and they're boxing pictures. So once he asked me, I was like, 15 minutes. I'm like, oh god, I'm still talking about Jack Dempsey. I moved on to Joe Frazier, who I loved, and how I really don't care for an MMA boxing, and whatever. Okay.
Leah StieglerThat's the thing.
Tom HagyBut again, thank you so much.
Leah StieglerYeah, anytime.
Tom HagyThat brings us to the end of this episode of the Emerging Litigation Podcast. Once again, I'm your host, Tom Hage. If you like what you hear, please give us a rating. That always helps. And also follow us on uh let's see, you can follow us on any major podcast platform, Apple, Spotify, all the rest. You can also check us out on YouTube for the video version and some clips and as well as Instagram and quite a few on LinkedIn as well. If you want to participate, give me a shout. My contact information is in the show notes. Thanks for watching.