Skip to main content
Public Health Reports logoLink to Public Health Reports
. 2015 Jul-Aug;130(4):400–403. doi: 10.1177/003335491513000419

Regulation of Information Technology in Behavioral Health

Melissa M Goldstein 1,
PMCID: PMC4547569  PMID: 26346328

The potential for information technology (IT)-based therapeutic tools (e.g., mobile phone applications [apps] and portable sensors that connect to mobile devices) to enhance behavioral health at both the individual and population levels is great, although their use can present challenges. This installment of Law and the Public's Health focuses on one of the most complex challenges: how to regulate these tools to address issues of privacy and security. These questions arise as the use of IT in behavioral health care grows more widespread and sophisticated, and the number and types of entities involved in managing behavioral health information increase. How the legal environment should respond to this transformation in behavioral health treatment and management has emerged as a significant question in health information law.

BACKGROUND

Protecting the privacy and security of health information is a public health priority in the United States due to the harm that can occur when such information is disclosed inappropriately.1 Discrimination, particularly by employers or insurers, as well as stigma and embarrassment, are all serious potential consequences related to the unauthorized disclosure of sensitive health information.2 In the area of behavioral health interventions in particular, privacy concerns can be a significant barrier to accessing treatment.3

Recent technological advancements that enable health information to be shared electronically offer considerable promise for monitoring and responding to individuals' health behavior in real time, with the development of tools that may function as clinician extenders and allow tailoring to individual profiles and behavior trajectories.4 The associated explosion in the availability and collection of health information, however, makes privacy and security concerns even more salient.5

For example, consider a hypothetical mobile phone app developed to provide cognitive behavioral therapy for depression. The app collects, shares, and analyzes video and audio recordings from a patient's phone, as well as photos, text messaging data, data from sensors (including global positioning system sensors and accelerometers), and data from connected tools such as sleep monitors.6 At the individual treatment level and in public health outreach settings, this app could provide valuable information to treatment teams, while also presenting opportunities for valuable aggregate data collection and sharing at the population health level. At each data collection point, however, and wherever data are stored or shared, entities such as device manufacturers, mobile network operators, app developers, data storage companies, or data analytics companies may also be accessing patient information, thereby presenting potential privacy and security issues.

HEALTH INFORMATION PRIVACY AND SECURITY LAW

HIPAA

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the primary federal law protecting the privacy and security of health information.7 HIPAA sets a privacy floor and preempts less stringent state laws. Any state laws that provide greater protection than HIPAA remain in force.8

The HIPAA Privacy and Security Rules9 address the circumstances under which a patient's individually identifiable health information (i.e., protected health information [PHI])10 can be disclosed, and the security measures that holders of health information should have in place. The regulations apply only to “covered entities,” which are health plans, health care clearinghouses, and health care providers that transmit health information electronically for specific purposes, including those related to health care claims and health plans.10

Generally, the Privacy Rule allows disclosure of PHI without patient authorization for the purposes of treatment, payment, or health care operations,11 which include activities such as quality assessment or compliance audits. Additionally, a covered entity is permitted to disclose PHI in certain other circumstances, including disclosures for public health purposes or to comply with state or federal laws.12

Contractors and other organizations that conduct business on behalf of covered entities and that create, receive, maintain, or access PHI are considered “business associates” by HIPAA and must comply with all provisions of the Security Rule and most provisions of the Privacy Rule.9 Thus, entities that gain access to PHI, such as mobile app software vendors, may be considered business associates if they act on behalf of covered entities. As such, they may be responsible for complying with HIPAA.

Because HIPAA only applies to certain organizations, however, health IT products that are not offered by covered entities or their business associates, but that still collect or access health information (e.g., mobile health apps marketed directly to consumers), do not have to comply with the regulations, thereby exhibiting a regulatory gap in HIPAA's protection of identifiable health data.13 In the absence of an overarching federal privacy law that provides baseline privacy protections to individuals, this gap is currently covered in part by agencies outside the U.S. Department of Health and Human Services.

42 C.F.R. Part 2

Some behavioral health information is also subject to 42 C.F.R. Part 2 (hereinafter, Part 2),1416 federal regulations that address the disclosure of personal information related to substance use treatment. Part 2 applies to entities holding themselves out as substance use treatment providers who receive support from the federal government.17 The regulations protect any information from a Part 2 program that indicates directly or indirectly that a patient is a participant or has a current or past drug or alcohol problem.18

With limited exceptions (e.g., medical emergencies),19 a patient's written consent is required to release information related to Part 2 treatment, and whenever such information is released, a statement prohibiting its redisclosure must accompany the information.20 These requirements, which are more stringent than HIPAA's, were adopted because of the sensitivity of substance use treatment information, the stigma associated with it, and the strong public health interest in encouraging individuals with substance use issues to seek treatment.21

REGULATING MOBILE OR WEB-BASED TECHNOLOGIES

There is growing legal activity aimed at addressing the use of IT in consumer-facing products and services, including mobile health apps, health-related websites and Web-based services, and portable sensors that connect to mobile devices. Regulators include the Federal Trade Commission (FTC), the U.S. Food and Drug Administration (FDA), the National Telecommunications and Information Administration, the Federal Communications Commission, and some states. In general, these agencies' efforts have emphasized industry self-regulation and transparency and have been guided by the Fair Information Practice Principles (FIPPS) (i.e., transparency and notice, individual consent, purpose specification, data minimization, use limitation, data integrity, security safeguards, and auditing).22 Key themes have emerged, such as enabling informed consumer choice through the provision of appropriate notice, expanding the types of personally identifying information that should be protected, and focusing on the collection of consumer data by third parties, including the communication of such activity to consumers.

The FTC

Under Section 5 of the Federal Trade Commission Act, the FTC has the authority to prevent “unfair or deceptive” acts related to commercial activity.23 An act is considered unfair if it causes, or is likely to cause, substantial injury to a consumer that the consumer is not reasonably able to avoid, and that is not outweighed by benefits to the consumer.24,25 An act is considered deceptive if it involves a practice or representation that is likely to mislead a consumer acting reasonably and is also material to the consumer—that is, the practice or representation is likely to have kept the consumer from using the product had it not been misrepresented.25

Generally, FTC enforcement actions addressing deceptive acts in the consumer IT arena have emphasized the importance of following stated privacy policies, including policies and practices described in privacy notices posted on an entity's website, as well as user manuals.26,27 Violation of voluntary codes of conduct that an entity claims to follow could also lead to a deceptive practice enforcement action.28 Regarding unfair acts, recent FTC enforcement activities have focused on the security measures that entities employ to protect consumer information, as well as the manner in which entities allow third parties to access and use that information.29

The FTC has issued privacy guidance for mobile apps and app developers that focuses on privacy disclosures and the process of marketing such apps. The guidance stresses the importance of “just in time” notices (which prompt consumers for permission at the time personal information is about to be collected) and obtaining affirmative consent when sensitive information (e.g., health information) is being collected or shared with third parties.30

The FDA

Under the Food, Drug and Cosmetic Act, the FDA regulates devices that are intended for medical use, including software and hardware, for safety and efficacy.31 Whether or not a product is considered a medical device subject to FDA regulation depends primarily on the product's intended use, including how it is marketed. Generally, products intended for the diagnosis, cure, treatment, mitigation, or prevention of a medical condition are considered medical devices.31

Recent FDA guidance clarifies the types of health apps that the FDA will regulate, emphasizing that most would likely not be regulated. According to the guidance, the FDA will only regulate an app if it functions as a medical device (i.e., defined as “mobile medical apps”)—that is, it meets the definition of a device and it is either used as an accessory to a regulated medical device or it transforms a mobile platform into a regulated medical device, and it could pose a risk to patient safety if it did not function as intended.32 For example, the FDA might consider an app that analyzes electrocardiogram or other sensor data to detect heart problems to fall under its authority, but does not intend to regulate mobile apps that help patients with psychiatric conditions through delivery of messages or tips to improve coping skills; apps that provide education, reminders, or motivation to patients recovering from addiction; or general wellness apps.32,33

RECENT DEVELOPMENTS

As technology rapidly advances, regulators continue to work to keep pace with technology. Of particular note is the Substance Abuse and Mental Health Administration's activity regarding potential updates to Part 2. In June 2014, the agency held a listening session to seek public input on potential changes to the regulations, including measures important to population health, such as when data can be released for research, how the regulations work with prescription drug monitoring programs, and clarification that population health management and care coordination are appropriate third-party services for Part 2 programs.34 Although the agency's timing is not clear, any proposed changes will be released to the public with an opportunity for comment before finalization.

In addition, a diverse federal workgroup that includes the FDA, the Federal Communications Commission, and the Office of the National Coordinator for Health Information Technology within the U.S. Department of Health and Human Services is currently exploring the creation of a non-duplicative risk-based regulatory framework that protects patient safety in health IT, including mobile medical apps.35 With respect to privacy and security issues, the agencies have emphasized the importance of examining and considering network security risks and compliance with security standards as part of any resulting regulatory framework.36

Finally, the Obama Administration recently released the discussion draft of the Consumer Privacy Bill of Rights Act of 2015,37 which expands upon principles (based upon the FIPPS) outlined by the Administration in 2012.38 The proposal creates a comprehensive framework for national consumer privacy and is part of the Administration's effort to combat cyber threats while safeguarding consumer privacy and civil liberties.39

IMPLICATIONS FOR PUBLIC HEALTH POLICY AND PRACTICE

Although it has been estimated that the mobile health app market will increase annually by 25% for the foreseeable future,40 some lawmakers have pressed for affirmative deregulation in the area41 based upon the assumption, repeatedly echoed by industry, that broad regulation could increase the cost and time associated with technological development.42,43 Others argue, however, that regulation is a required facilitator for industry change—instead of hindering growth, providing a regulatory structure encourages interoperability and can support the evolution of existing markets instead of allowing disruptive new markets to displace older technologies.44

As regulators navigate the proper balance between innovation in the collection of health information and fair data practice controls, policy makers ultimately need to address the broader social consequences of pervasive health information collection, aggregation, and use.45 As we move forward, embracing the core principles of appropriately sharing health information, providing adequate notice and choice to patients, and ensuring proper security safeguards will help enable the use of IT within behavioral health care in a way that both protects the privacy and security of sensitive health information and inspires patient trust.13

REFERENCES


Articles from Public Health Reports are provided here courtesy of SAGE Publications

RESOURCES