If a North Dakota provider is charged with performing an abortion, can the provider disclose the patient's protected health information to mount an affirmative defense?
Apply this to your situation
This page answers the general question as of 2022. Ezel answers yours: what it means for your facts, under current North Dakota law, with citations.
Plain-English summary
After Dobbs v. Jackson Women's Health Organization (2022) returned abortion regulation to the states, North Dakota's pre-existing felony statute (N.D.C.C. § 12.1-31-12) was active. Two state legislators asked the AG whether a defendant charged under that statute could lawfully disclose a patient's protected health information (PHI) to prove an affirmative defense, like that the abortion was necessary to prevent the death of the pregnant patient, or to terminate a pregnancy resulting from sexual assault.
The AG declined to answer eight of the nine questions in the request because they were either factual (rather than legal) or part of pending litigation. He answered only the HIPAA question: state and federal law do not preclude a defendant from disclosing a patient's PHI in order to assert an affirmative defense, so long as the Privacy Rule's disclosure requirements are met.
The HIPAA Privacy Rule allows disclosure of PHI under several mechanisms relevant to this context:
- Health care operations (45 C.F.R. § 164.506(b), defined in § 164.501). Health care operations include "conducting or arranging for legal services." HHS guidance specifically applies this to litigation involving the covered entity as a party.
- Valid patient authorization (45 C.F.R. § 164.508). The authorization must be voluntary (no conditioning of treatment) and can be revoked.
- Court order, subpoena, or other lawful process in litigation (45 C.F.R. § 164.512(e)), with notice or qualified protective order safeguards.
The opinion is jurisdictionally narrow and explicitly governs the actions of public officials "until such time as the question presented is decided by the courts" (N.D.C.C. § 54-12-01).
What this means for you
If you are a healthcare provider charged under § 12.1-31-12
The opinion concludes that HIPAA does not prevent a defendant from disclosing PHI to assert an affirmative defense, so long as the disclosure complies with the Privacy Rule. The opinion identifies three relevant mechanisms: "health care operations" disclosures under 45 C.F.R. § 164.506(b) and § 164.501 (which include "conducting or arranging for legal services"); valid patient authorization under § 164.508; and judicial-process disclosures under § 164.512(e).
If you are general counsel for a covered entity
The opinion treats the Privacy Rule's mechanisms as the controlling framework rather than state law alone. The opinion does not address the validity of the underlying abortion statute, the scope of the affirmative defenses themselves, or the constitutionality questions raised in the legislators' request (questions 1-3 and 5-9), all of which the AG declined to address.
If you are a patient or member of the public
The opinion is limited to the HIPAA disclosure question. The opinion expressly notes under N.D.C.C. § 54-12-01 that it "governs the actions of public officials until such time as the question presented is decided by the courts."
Common questions
Q: What are the affirmative defenses in § 12.1-31-12(3)?
A: (a) the abortion was necessary in professional judgment to prevent the patient's death; (b) the abortion was to terminate a pregnancy resulting from gross sexual imposition, sexual imposition, sexual abuse of a ward, or incest; (c) the individual was acting within the scope of a regulated profession and under physician direction.
Q: Does this opinion address the constitutionality of the abortion statute?
A: No. The AG declined to address questions 1-3 and 5-9, citing pending litigation and the factual nature of some questions. Only the HIPAA question (question 4) is addressed.
Q: Can a provider just send the records to a defense lawyer?
A: No. The Privacy Rule has specific mechanisms (health care operations, authorization, lawful process) and each has detailed requirements. Casual transmission outside those mechanisms is a violation.
Q: What's the "health care operations" path?
A: 45 C.F.R. § 164.506(b) allows a covered entity to use or disclose PHI for its own health care operations without authorization, and § 164.501 includes "legal services" related to the entity's covered functions. HHS guidance (FAQ 705) confirms this can apply when a covered entity is a party to litigation. No case law directly applies this to the felony-abortion-defense context, so providers should expect arguments about scope.
Q: What about patient consent?
A: A patient may revoke consent at any time under 45 C.F.R. § 164.508(b)(5). Providers cannot condition treatment on a patient signing an authorization (with limited exceptions).
Background and statutory framework
HIPAA (Health Insurance Portability and Accountability Act of 1996) and the HITECH Act govern privacy of individually identifiable health information. The Privacy Rule (45 C.F.R. parts 160 and 164) implements those statutes for "covered entities" (health plans, clearinghouses, and electronic-transaction providers).
The Privacy Rule's general rule is that PHI cannot be used or disclosed without authorization or a specific exception. The exceptions relevant here are health care operations (§ 164.506), authorizations (§ 164.508), and judicial/administrative proceedings (§ 164.512(e)). Each comes with its own procedural requirements.
N.D.C.C. § 12.1-31-12 is North Dakota's felony abortion statute, with three statutory affirmative defenses. Some defenses (medical necessity, sexual assault origin) may require disclosure of patient PHI to prove; the AG concluded HIPAA does not block that disclosure if Privacy Rule mechanisms are followed.
Citations and references
Statutes and regulations:
- N.D.C.C. § 12.1-31-12
- HIPAA Privacy Rule, 45 C.F.R. § 164.500 et seq.
- HHS HIPAA FAQ 705 (covered entity in legal proceeding)
Request and conclusion (from landing page)
November 16, 2022
Issued to: Representatives Karla Rose Hanson and Zachary Ista
Request: Does state or federal law preclude a defendant from disclosing a patient’s PHI?
Conclusion: Although a patient’s PHI may not be required to prove an affirmative defense in all cases, it is reasonable to anticipate some defendants would need to disclose a patient’s PHI to satisfy the elements of one or more affirmative defenses under the statute. State and federal law do not preclude a defendant from disclosing a patient’s PHI in order to assert an affirmative defense to N.D.C.C. § 12.1-31-12, however, the requirements of the applicable disclosure provision under the HIPAA Privacy Rule need to be met prior to disclosure.
2022-L-06
Source
- Landing page: https://attorneygeneral.nd.gov/hipaa-does-not-prohibit-disclosure-of-protected-health-information-in-order-to-assert-affirmative-defenses-to-abortion-law/
- Original PDF: https://attorneygeneral.nd.gov/wp-content/uploads/2022/12/2022-L-06.pdf
Original opinion text
STATE OF NORTH DAKOTA
OFFICE OF ATTORNEY GENERAL
www.attorneygeneral.nd.gov
(701) 328-2210
Drew H. Wrigley
ATTORNEY GENERAL
LETTER OPINION
2022-L-06
Representative Karla Rose Hanson
District 44
1114 Fifth Street North
Fargo, ND 58102-3713
Representative Zachary Ista
District 43
3850 15" Avenue South
Grand Forks, ND 58201-3727
Dear Representatives Hanson and Ista:
Thank you for your letter requesting an opinion on several questions related to statutes governing
abortion, specifically North Dakota Century Code (N.D.C.C.) § 12.1-31-12 and N.D.C.C. ch. 14-
02.1'. These statutes and similar statutes throughout the United States are currently the subject of
litigation. Additionally, the answers to some of these questions would require a determination of
factual issues. Therefore, I must respectfully decline to address questions 1 through 3 and 5 through
9 of your opinion request. Question 4 asks whether state or federal law would preclude a defendant
from disclosing a patient’s protected health information (“PHI”) in order to assert an affirmative
defense. In my opinion, state and federal law do not preclude a defendant from disclosing a
patient’s PHI in order to assert an affirmative defense so long as the applicable requirements are
met.
ANALYSIS
Section 12.1-31-12(2), N.D.C.C., makes it a class C felony for ‘“‘a person, other than the pregnant
female upon whom the abortion was performed, to perform an abortion.” Subsection 3 then lists the
following affirmative defenses to the felony:
a. That the abortion was necessary in professional judgment and was intended to
prevent the death of the pregnant female.
b. That the abortion was to terminate a pregnancy that resulted from gross sexual
imposition, sexual imposition, sexual abuse of a ward, or incest, as those offenses
are defined in chapter 12.1-20.
'N.D.C.C. ch. 14-02.1 is commonly referred to as the Abortion Control Act.
LETTER OPINION 2022-L-06
November 15, 2022
Page 2
c. That the individual was acting within the scope of that individual's regulated
profession and under the direction of or at the direction of a physician.
Question 4 of your request for an opinion asks whether a defendant would be prohibited from
disclosing the PHI of a patient who received an abortion when asserting the affirmative defenses
listed in N.D.C.C. § 12.1-31-12(3). Although the patient’s PHI may not be required to prove an
affirmative defense in all cases, it is reasonable to anticipate some defendants would need to
disclose a patient’s PHI to satisfy the elements of one or more affirmative defenses under the
statute.
The principal laws related to the privacy and disclosure of PHI are the Health Insurance Portability
and Accountability Act of 1996 (HIPAA)’ and the Health Information Technology for Economic
and Clinical Health Act (HITECH Act)’. The Secretary of the U.S. Dept. of Health and Human
Services is required under HIPAA to promulgate privacy regulations governing individually
identifiable health information.4 The HIPAA Privacy Rule (Privacy Rule) was published in the
Code of Federal Regulations on December 28, 2000 and was later modified as necessary.» The
application of the Privacy Rule to any given situation is extremely fact-dependent and complex.
However, I will address generally the interplay of the Privacy Rule and the assertion of the
affirmative defenses noted above.
The Privacy Rule applies to covered entities, which include health plans, health care clearinghouses,
and health care providers that transmit any health information in electronic form in connection with
certain transactions.° Assuming a defendant charged under N.D.C.C. § 12.1-31-12 or related laws is
a “covered entity” or the information needed for an affirmative defense is held by a “covered
entity,” the defendant would be able to disclose the PHI only as allowed under the Privacy Rule.
The Privacy Rule delineates several authorized uses and disclosures of PHI including some that
would allow a defendant to disclose a patient’s PHI in furtherance of an affirmative defense.’ This
opinion describes some of these applicable disclosure mechanisms but should not be considered an
exhaustive list of options for a defendant.
- Health Ins. Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936.
3 Passed by Congress as a section in the American Recovery and Reinvestment Act of 2009
(ARRA).
- Health Ins. Portability and Accountability Act of 1996, Pub. L. No. 104-191, §§ 261-264, 110 Stat.
1936.
Codified at 45 C.F.R. pts. 160 and 164 (2013).
645 C.F.R. § 160.103 (2014).
745 C.F.R. § 164.502 (2013).
LETTER OPINION 2022-L-06
November 15, 2022
Page 3
With or without an individual’s consent, a covered entity that holds an individual’s PHI may
disclose the PHI to carry out the covered entity’s health care operations.®? The Privacy Rule defines
“health care operations” narrowly, but the term includes “conducting or arranging for . . . legal
services” to the extent the activities are related to the covered entity’s covered functions.'° In a
guidance document, the U.S. Dept. of Health and Human Services applies the term “health care
operations” in the context of legal proceedings as follows:
Where a covered entity is a party to a legal proceeding, such as a plaintiff or defendant, the covered
entity may use or disclose protected health information for purposes of the litigation as part of its
health care operations. !!
As indicated in the guidance document, this type of disclosure generally occurs when a health care
provider is sued for malpractice or sues for payment of an outstanding bill. This office found no
cases analyzing a provider’s disclosure of PHI under the “health care operations” exception when
defending against a charge of performing an illegal abortion. Assuming the exception applies in
such cases, the provider would have to comply with all elements of the exception to avoid violating
the Privacy Rule.
Regardless of whether the “health care operations” exception applies, a provider may request an
individual’s legally valid authorization to disclose the individual’s PHI.' The authorization would
have to be voluntary because a health care provider generally is prohibited from conditioning
treatment or care on a patient’s execution of an authorization form.'? Additionally, a patient may
revoke an authorization to use the patient’s PHI at any time.' For HIPAA purposes, “consent” and
“authorization” are terms of art, and each has very specific requirements that must be met in order
for the document to be legally valid.
845 C.F.R. § 164.506(b) (2013).
- A factual determination would need to be made as to which covered entity is, in fact, the holder of
the PHI. For example, if a health care facility holds the records, an individual physician may not be
able to disclose the PHI in the records. Any disclosure under this provision must be of the minimum
amount of PHI necessary under the circumstances and must comply with other requirements of the
Privacy Rule.
145 C.F.R. § 164.501 (2013).
'! U.S. Dept. of Health and Hum. Services, HIPAA for Professionals: FAQ 705-May a covered
entity in a legal proceeding use or disclose PHI for the litigation, https://www.hhs.gov/hipaa/for-
professionals/faq/705/may-a-covered-entity-in-a-legal-proceeding-use-protected-health-
information/index.html.
2 See generally 45 C.F.R. § 164.508 (2013).
1345 C.F.R. § 164.508(b)(4) (2013).
4 45 CER. § 164.508 (b)(5) (2013).
LETTER OPINION 2022-L-06
November 15, 2022
Page 4
A covered entity also may disclose PHI during the course of a judicial or administrative proceeding
in response to an order of the court,'> subpoena, discovery request, or other lawful process, so long
as certain specific requirements are met.'® Courts frequently issue protective orders preventing
disclosure of the PHI to parties outside the legal proceeding.
It is my opinion that state and federal law do not preclude a defendant from disclosing a patient’s
PHI in order to assert an affirmative defense, so long as the applicable requirements are met.
Tew
Attorney General
This opinion is issued pursuant to N.D.C.C. § 54-12-01. It governs the actions of public officials
until such time as the question presented is decided by the courts.!7
'S 45 CFR. § 164.512(e)(1)(i) (2016).
'6 See 45 C.F.R. § 164.512(e)(1)(ii) (2016). These requirements include the covered entity receiving
assurances from the party seeking the information that “reasonable efforts have been made by such
party to ensure that the individual who is the subject of the [PHI] that has been requested has been
given notice of the request” and that “reasonable efforts have been made by such party to secure a
qualified protective order . . .” Each of these requirements is further clarified in 45 C.F.R. §
164.512(e)(1)(iii) (2016).
'" See State ex rel. Johnson v. Baker, 21 N.W.2d 355 (N.D. 1946).
Get today's answer for your situation
You just read a 2022 opinion on this question. Ezel checks the current North Dakota statutes and case law and answers your specific situation, with citations.
Opens in Ezel Pro. Every answer cites the law it relies on.