A telehealth company has admitted to improperly accessing patients’ medical records. GuardDog Telehealth purported to require access to patients’ medical records for treatment purposes; however, the records were accessed in order to provide data to law firms for potential lawsuits.
GuardDog Telehealth obtained access to patients’ medical records through a Health Information Exchange (HIE) network, using Health Gorilla’s interoperability platform to access the records. Health Gorilla is a Qualified Health Information Network (QHIN) under the Trusted Exchange Framework and Common Agreement (TEFCA), through which many companies access patients’ medical records. The network supports patient care and ensures efficient care coordination between healthcare providers.
Epic Systems, the health IT consultancy firm OCHIN, and three healthcare providers filed a lawsuit against Health Gorilla and others, alleging they were allowing “sham” medical practices to access health information exchanges through their interoperability platforms. After gaining access, the sham companies are alleged to have marketed their access to patient data to law firms, offering to help them find plaintiffs for class action lawsuits. In addition to GuardDog Telehealth, other companies accused of improper access included Mammoth Path Solution, RavillaMed, and Llamalab. According to the lawsuit, the sham companies were given connections to Carequality, TEFCA, and other HIEs, which allowed them to access patient records.
The lawsuit seeks immediate relief for fraud, aiding and abetting fraud, violations of the California Business and Professions Code, and the Federal Computer Fraud and Abuse Act. According to the lawsuit, almost 300,000 patient records were improperly accessed by the sham companies under the guise of treatment. Only GuardDog Telehealth has admitted to any wrongdoing.
Companies such as Health Gorilla are the gatekeepers and control who can access their frameworks and sensitive patient data through HIEs. They must therefore ensure that any participants are vetted before they are onboarded, and are accessing the framework for legitimate purposes. Health Gorilla vehemently denies the allegations and claims that Epic, a rival, is attempting to squash competition.
In a legal filing – stipulated judgment and permanent injunction – on Friday, Epic said it has obtained an admission from Health Gorilla client GuardDog Telehealth that patient records were accessed under the guise of providing chronic care management and remote patient monitoring, when those services were not provided. Instead, records were reviewed, summarized, and the data provided to law firms.
GuardDog Telehealth and Epic have reached an agreement and are seeking a court order permanently barring GuardDog Telehealth from requesting health records via the Carequality and TEFCA interoperability frameworks. GuardDog Telehealth has agreed to delete all patient records obtained from those frameworks within one week and will not use or disclose any patient information obtained from the HIEs. The agreement now awaits approval from the court.
Epic said the legal action against Health Gorilla and the other defendants will continue and that it would welcome discussions with other defendants regarding stipulated judgments and permanent injunctions. Health Gorilla maintains that GuardDog Telehealth did not inform it of any non-treatment uses of patient data and maintains that there has been no wrongdoing by Health Gorilla.
“GuardDog’s consent judgment has no legal impact on Health Gorilla, and is incomplete at best and misleading at worst. If you read carefully, GuardDog does not state it ever informed Health Gorilla of any non-treatment use of patient information, and we are prepared to demonstrate it did not,” explained Health Gorilla in a statement. “In addition, when Health Gorilla sought to investigate GuardDog along with the interoperability networks and several major health providers, GuardDog failed to respond and refused to cooperate. Epic’s lawsuit remains an attack on interoperability that threatens patient safety and efficient healthcare nationwide, made worse by misleading submissions like its agreement with GuardDog. Health Gorilla continues to fully comply with all applicable data-sharing frameworks, and we remain confident as we address these claims through the legal processes.”
Epic is also facing legal action of its own, with multiple class action lawsuits filed against it and other companies for failing to prevent Health Gorilla and its clients from connecting to the Epic Care Everywhere health information exchange. The lawsuits allege that Epic and others were negligent, as they either knew or should have known about the misuse of Care Everywhere to obtain patient information for non-treatment purposes, and that they failed to take timely corrective action.
The post GuardDog Telehealth Admits Improper Access to Medical Records appeared first on The HIPAA Journal.