Reproductive Health Privacy Rule Lawsuit May Signal Shift in Balance of Power

By: Andrew Mahler, JD, CIPP/US, AI Governance Professional (AIGP), CHC, CHPC, CHRC
Vice President, Consulting Services, Privacy & Compliance

On September 4, 2024, the State of Texas filed a lawsuit in the U.S. District Court, Northern District of Texas, against the U.S. Department of Health and Human Services (HHS), challenging both the HIPAA Final Rule to Support Reproductive Health Care Privacy (issued April 22, 2024) and the HIPAA Privacy Rule (issued December 28, 2000). While Texas takes primary aim at the HIPAA Final Rule to Support Reproductive Health Care Privacy, it goes further by asking the Court to vacate and set aside both the 2000 Privacy Rule and the 2024 Privacy Rule and permanently enjoin HHS from enforcing the Rules. Notably, the lawsuit was filed in the Northern District of Texas, which recently vacated the HHS/OCR Bulletin on the Use of Online Tracking Technologies.

Texas argues that the Privacy Rule and the 2024 Privacy Rule violate the Administrative Procedure Act as contrary to the HIPAA statute and exceeding the authority granted by Congress. The lawsuit asserts that HHS “promulgated the 2024 Privacy Rule to obstruct states’ ability to enforce their own laws on abortion and other matters that HHS categorizes as ‘reproductive health care;” citing to “at least one instance” involving a covered entity in Texas that has cited the 2024 Privacy Rule as a reason for not complying with a subpoena.

The case could have significant implications for the balance of power between federal health privacy regulations and states’ authority to investigate potential legal violations, particularly in the context of reproductive health care. The outcome is likely to be closely watched by other states, healthcare providers, and privacy advocates nationwide, as it may set a precedent for future challenges to federal regulations that limit state investigative powers.

Reach out to Andrew with your comments and questions at andrew.mahler@clearwatersecurity.com.

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

Potential Oracle Cloud Breach

Potential Oracle Cloud Breach

A significant concern has emerged involving Oracle Cloud services. Reports have surfaced regarding the alleged sale of 6 million records extracted from Oracle Cloud’s Single Sign-On (SSO) and LDAP directories.
Are You Ready For Quantum Day in Healthcare?

Are You Ready For Quantum Day in Healthcare?

From AI-driven diagnostics to wearable smart devices and telehealth breakthroughs, rapid digital transformation drives modern healthcare service delivery. From what was once a tech-resistant industry — and one where many legacy systems still play critical roles in operations — healthcare tech adoption has radically evolved since pre-COVID. With all these breakthroughs and benefits, many covered entities and business associates struggle to keep pace with the increased risk these innovations introduce into the modern healthcare ecosystem. The more technologies, web apps, smart devices, and cloud services your organization adopts, the greater chance of a cyber breach.

Connect
With Us


Let us know who referred you, if you went to an event, found us in search, or liked one of our LinkedIn posts.