DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

West Virginia Supreme Court affirms HIPAA does not pre-empt state law tort claims for privacy violations

Posted on December 7, 2012 by Dissent

I seem to have missed a lawsuit that may be of interest to readers.  Back in September, Bordas & Bordas, PLLC  wrote:

… What if our private information is released without our permission? What if it falls into the hands of someone who can actually cause us harm?

These aren’t abstract or hypothetical questions. The danger is real, and there’s a case before the West Virginia Supreme Court that shows us just how real it is R.K. vs. St. Mary’s Medical Center, Inc., No. 11-0924.

Consider these facts. R.K. was admitted to St. Mary’s Medical Center for a psychiatric illness. R.K. was also going through a divorce. During his hospitalization, employees of the hospital illegally accessed his private medical records. To add insult to injury, they proceeded to provide copies of the records to R.K.’s wife and divorce attorney. R.K. sued the hospital, alleging a wide variety of state-law claims.

Amazingly, the hospital managed to get the lawsuit dismissed by arguing that since HIPAA doesn’t provide for a private cause of action, there can be no state-level private cause of action for a privacy violation of this kind.

That’s just plain wrong, of course, and R.K. appealed the dismissal in September.  Yesterday, Bordas & Bordas provided a welcome update:

You may remember that in R. K. vs. St. Mary’s Medical Center, Inc., 2012 WL 5834577, a hospital employee illegally accessed the plaintiff’s psychiatric records and then forwarded them to the plaintiff’s estranged wife and her divorce attorney. The plaintiff sued the hospital, claiming that state law provided a remedy for this scandalous behavior. The hospital asked the trial court to dismiss the case, arguing that HIPAA preempted any and all state laws relating to medical rights privacy. Because HIPAA itself didn’t provide a remedy the hospital was, in reality, asking for a free pass.

Thankfully, the West Virginia Supreme Court refused to accept the hospital’s bizarre argument. Even though HIPAA is meant to protect privacy rights, the hospital was twisting it to mean that HIPAA violations would go unpunished. This interpretation was rejected out of hand:

[S]tate common law claims for the wrongful disclosure of medical or personal health information are not inconsistent with HIPAA. Rather, …such state law claims complement HIPAA by enhancing the penalties for its violation and thereby encouraging HIPAA compliance. Accordingly, we now hold that common law tort claims based upon the wrongful disclosure of medical or personal health information are not preempted by the Health Insurance Portability and Accountability Act of 1996.

Here’s the court’s opinion of November 15 and Chief Justice Ketchum’s dissenting opinion.

Category: Health Data

Post navigation

← Stratfor hack update: Barrett Brown indicted
State Farm and Nationwide fail to convince WV Supreme Court to let them retain – and share – medical records obtained under protective orders →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.