Employer H1N1 Virus Risk Management Requires Employer Care To Manage Virus Risks Without Violating Employment Discrimination or Other Laws

November 30, 2009

As the Centers for Disease Control (CDC) continues cautioning Americans to expect a resurgence of the H1N1 virus, employers should continue to take prudent steps to defend their organization and their workers against a widespread H1N1 outbreak and the attendant lost time, health and disability costs, OSHA and other liability exposures and other personal and financial consequences likely to result from an outbreak. 

Employers wishing to deter the spread of the disease in their workplace should educate workers about these recommendations and consider taking steps to encourage workers to comply with these recommendations. When planning or taking steps to protect their workplaces from the H1N1 virus pandemic or other outbreaks of communicable diseases, however, employers must use care to avoid violating the Americans With Disabilities Act or other employment laws.

Preventing, Recognizing & Mitigating Risks of H1N1

Although the number of reported cases of H1N1 virus cases has declined in many states in recent weeks, CDC officials are warning American’s that the crisis is not over yet.  CDC officials last week warned Americans to expect H1N1 infection to rise as the holiday approaches and the winter progresses. With flu activity already higher than what is seen during the peak of many regular flu seasons and the H1NA virus accounting for almost all of the flu viruses identified so for this season,  Accordingly,  the CDC continues to encourage Americans to be alert for symptoms of H1N1 or other flu and to take other precautions including to get vaccinated.

Employers should continue to encourage workers and their families to take precautions to avoid catching the virus, to be on the watch for H1N1 virus or other flu infection and to respond appropriately if they, members of their families or others in the workplace exhibit these symptoms.   To help promote health habits within their workforce, many businesses may want to download and circulate to employees and families the free resources published by the CDC here.  Businesses and other concerned parties also can track governmental reports about the swine flu and other pandemic concerns at here.   

For those not already suffering from the virus and particularly for those at higher risk, the CDC continues to recommend vaccination. People recommended by the CDC to receive the vaccine as soon possible include:  health care workers; pregnant women; people ages 25 through 64 with chronic medical conditions, such as asthma, heart disease, or diabetes; anyone from 6 months through 24 years of age; and people living with or caring for infants under 6 months old.  As the vaccine becomes available, many employers are encouraging workers and their families to get vaccinated by offering vaccination clinics at or near their worksites, arranging for health plan coverage for vaccinations with reduced or no co-payments or deductibles, and/or sharing information about government sponsored or other vaccination clinics. 

While the CDC says getting employees and their families to get a flu shot remains the best defense against a flu outbreak, it also says getting employees and family members to consistently practice good health habits like covering a cough and washing hands also is another important key to prevent the spread of germs and prevent the spread of respiratory illnesses like the flu.  Employers should encourage employees and their families to take the following steps: 

  • Avoid close contact with people who are sick. When you are sick, keep your distance from others to protect them from getting sick too;
  • Stay home when you are sick to help prevent others from catching your illness;
  •  Cover your mouth and nose;
  • Cover your mouth and nose with a tissue when coughing or sneezing. It may prevent those around you from getting sick;
  • Clean your hands to protect yourself from germs;
  • Avoid touching your eyes, nose or mouth;
  • Germs are often spread when a person touches something that is contaminated with germs and then touches his or her eyes, nose, or mouth; and
  • Practice other good health habits.  Get plenty of sleep, be physically active, manage your stress, drink plenty of fluids, and eat nutritious food.

Employers also should encourage workers and their families to be alert to possible signs of H1N1 or other flu symptoms and to respond appropriately to possible infection.  According to the CDC, all types of flu including H1NA typically include many common symptoms, including:

  • Fever
  • Coughing and/or sore throat
  • Runny or stuffy nose
  • Headaches and/or body aches
  • Chills
  • Fatigue

Patients suffering from H1N1 flu usually report these same symptoms, but the symptoms often are more severe. In addition to the above symptoms, a number of H1N1 flu cases reported vomiting and diarrhea.

CDC recommends individuals diagnosed with H1N1 flu should:

  • Stay home and avoid contact with others for at least 24 hours after a fever (100°F or 37.8°C) is gone without the use of fever reducing medicine except to get medical care or for other things that must be done that no one else can do;
  • Avoid close contact with others, especially those who might easily get the flu, such as people age 65 years and older, people of any age with chronic medical conditions (such as asthma, diabetes, or heart disease), pregnant women, young children, and infants;
  • Clean hands with soap and water or an alcohol-based hand rub often, especially after using tissues or coughing/sneezing into your hands;
  • Cover coughs and sneezes;
  • Wear a facemask when sharing common spaces with other household members to help prevent spreading the virus to others. This is especially important if other household members are at high risk for complications from influenza;
  • Drink clear fluids such as water, broth, sports drinks, or electrolyte beverages made for infants to prevent becoming dehydrated;
  • Get plenty of rest;
  • Follow doctor’s orders; and
  • Watch for signs for a need for immediate medical attention. Suffers should get medical attention right away if the sufferer has difficulty breathing or chest pain,  purple or blue discoloration of the lips, is vomiting and unable to keep liquids down, or shows signs of dehydration, such as feeling dizzy when standing or being unable to urinate.

In seeking to contain the spread of the virus within their workplace, employers also should be sensitive to workplace policies or practices that may pressure employees with a contagious disease to report to work despite an illness and consider whether the employer should adjust these policies temporarily or permanently in light of the ongoing pandemic.  For instance, financial pressures and the design and enforcement of policies regarding working from home and/or qualifying for paid or unpaid time off significantly impact the decisions employees make about whether to come to work when first experiencing symptoms of illness.  Employers of workers who travel extensively – may wish to delay or restrict travel for some period. 

Employers Must Employment Discrimination & Other Legal Compliance Risks

Many employers may want to evaluate and appropriately revise existing policies with an eye to better defending their workforce against a major outbreak.  Whether or not the disease afflicts any of its workers, businesses can anticipate the swine flu outbreak will impact their operations – either as a result of occurrences affecting their own or other businesses or from workflow disruptions resulting from safeguards that the business or other businesses implement to minimize swine flu risks for its workforce or its customers.  Many businesses also will want to prepare backup staffing and production strategies to prepare for disruptions likely to result if a significant outbreak occurs. 

Employers planning for or dealing with an H1N1 or other epidemic in their workplace should exercise care to avoid violating the nondiscrimination and medical records confidentiality provisions of the Americans with Disabilities Act (ADA) and/or the Genetic Information Nondiscrimination Act (GINA), the Family & Medical Leave Act of 1990 (FMLA), the Fair Labor Standards Act (FLSA) and applicable state wage and hour laws, and other employment and privacy laws.

Improperly designed or administered medical inquiries, testing, vaccination mandates and other policies or practices intended to prevent the spread of disease may expose an employer to disability discrimination liability under the ADA or GINA.  For instance, the ADA generally prohibits an employer from making disability-related inquiries and requiring medical examinations of employees, except under limited circumstances permitted by the ADA. Likewise, improperly designed or communicated employer inquiries into family medical status which could be construed as inquiring about family medical history also may raise exposures under genetic information nondiscrimination and privacy mandates of GINA that took effect November 21, 2009.

During employment, the ADA prohibits employee disability-related inquiries or medical examinations unless they are job-related and consistent with business necessity. Generally, a disability-related inquiry or medical examination of an employee is job-related and consistent with business necessity when an employer has a reasonable belief, based on objective evidence, that:

  • An employee’s ability to perform essential job functions will be impaired by a medical condition; or
  • An employee will pose a direct threat due to a medical condition.

This reasonable belief “must be based on objective evidence obtained, or reasonably available to the employer, prior to making a disability-related inquiry or requiring a medical examination.”

Additionally, the ADA prohibits employers from making disability-related inquiries and conducting medical examinations of applicants before a conditional offer of employment is made.  It permits employers to make disability-related inquiries and conduct medical examinations if all entering employees in the same job category are subject to the same inquiries and examinations.   All information about applicants or employees obtained through disability-related inquiries or medical examinations must be kept confidential. Information regarding the medical condition or history of an employee must be collected and maintained on separate forms and in separate medical files and be treated as a confidential medical record.  The EEOC Pandemic Preparedness In The Workplace and The Americans With Disabilities Act Guidance makes clear that employer inquiries and other H1N GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” is likely to present a liability trap door for many unsuspecting employers H1N1 and other epidemic planning and response activities should be carefully crafted to avoid violating these proscriptions.

GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” also could present a liability trap door for some employers designing pandemic or other workplace wellness, disease management or other programs.  GINA defines “genetic information” broadly as including not only information about genetic tests about an individual or his family member as well as information about the “manifestation of a disease or disorder in family members of such individual, GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.  For more information about the new GINA genetic information employment discrimination rules, see here.

As part of their pandemic planning, employers also generally should review their existing wage and hour and leave of absence practices.  Employers should ensure that their existing or planned practices for providing paid or unpaid leave are designed to comply with the FLSA and other wage and hour and federal and state leave of absence laws. Employers also should review and update family and medical leave act and other sick leave policies, group health plan medical coverage continuation rules and notices and other associated policies and plans for compliance with existing regulatory requirements, which have been subject to a range of statutory and regulatory amendments in recent years.  If considering allowing or requiring employees to work from home, employers also need to implement appropriate safeguards to monitor and manage employee performance, to protect the employer’s ability to comply with applicable wage and hour, worker’s compensation, OSHA and other safety, privacy and other legal and operational requirements. 

Businesses, health care providers, schools, government agencies and others concerned about preparing to cope with pandemic or other infectious disease challenges also may want to review the publication “Planning for the Pandemic” authored by Curran Tomko Tarski LLP partner Cynthia Marcotte Stamer available at hereFLU.gov is a one-stop resource with the latest updates on the H1N1 flu. An additional resource is CDC INFO, 1-800-CDC-INFO (1-800-232-4636), which offers services in English and Spanish, 24 hours a day, 7 days a week.  Schools, health care organizations, restaurants and other businesses whose operations involve significant interaction with the public also may need to take special precautions.  These and other businesses may want to consult the special resources posted  here

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer.  Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, health and other employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Examples of other recent updates you may have missed include:

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer. All rights reserved. 


New GINA Genetic Information Based Employment Discrimination & Confidentiality Mandates Take Effect

November 24, 2009

Updated Employment Poster, Policies & Procedures Required Immediately

Employers, unions, employment agencies, employment training agencies and their agents face significant new employment discrimination liability risks if they violate new genetic information-based employment non-discrimination or fail to comply with genetic information confidentiality requirements that took effect under Title II of the Genetic Information Nondiscrimination Act (GINA) on Saturday, November 21, 2009.  Employers need immediately to update their employment posters, carefully audit their existing records and practices to identify existing information and practices that may create special risks under GINA and take appropriate action to comply with the GINA rules. Employers needing an updated poster can find a copy on the Equal Employment Opportunity Commission website here.

Under the newly effective employment provisions of Title II of GINA, Federal law now prohibits employers of 15 or more employees and certain other entities from using individuals’ “genetic information” when making hiring, firing, job placement, or promotion decisions, requires “genetic information” be kept separately and confidential, and prohibits retaliation. 

When assessing their risk under GINA, employers should be careful not to overlook or underestimate the genetic information collected or possessed by their organizations and the risks attendant to this information.  Many employers will be surprised by the breadth of the depth of “genetic information.”   GINA defines “genetic information” broadly as including not only information about genetic tests about an individual or his family member as well as information about the “manifestation of a disease or disorder in family members of such individual.   GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.  Pending issuance of regulatory guidance, GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” is likely to present a liability trap door for many unsuspecting employers.

Failing to properly address GINA compliance could expose employers to substantial risk.  Violation of the employment provisions of Title II subjects an employer to potentially significant civil judgments like those that generally are available for race, sex, and other federal employment discrimination claims covered by the Civil Rights Act.  Accordingly, employers and others who have not already done so should act quickly to review and update their policies and procedures to manage their new compliance and liability exposures under GINA Title II.

While the agency responsible for construing and enforcing Title II of GINA, the Equal Employment Opportunity Commission (EEOC), to date has published only limited guidance about it, the absence of this final guidance should not be read by employers as a sign their compliance may be delayed.  While not yet issued in final form, proposed regulations interpreting Title II of GINA accessible here published by the EEOC in March, 2009  and a subsequently released factsheet accessible here published by the EEOC in May, 2009 titled “Background Information for EEOC Notice of Proposed Rulemaking On Title II of the Genetic Information Nondiscrimination Act of 2008” provide insights about how the EEOC may be expected to view its provisions.   While many employers have delayed taking action to update their policies and procedures in hopes that final guidance would be forthcoming before Title II took effect, time has now run out.  Accordingly, employers who have not already done so should act quickly to implement all necessary changes to position themselves to defend against a potential claim that their organization may have violated GINA Title II. 

Employment-Related Genetic Information Nondiscrimination Rules In Focus

Applicable to employers, unions, employment agencies, employment training agencies and their agencies based on genetic information by employers, Title II imposes sweeping prohibitions against employment discrimination based on genetic information.  Title II generally has three components:

Employment Discrimination Prohibited.  Section 202 of GINA makes it illegal for an employer:

  • To fail or refuse to hire, or to discharge, any employee, or otherwise to discriminate against any employee with respect to the compensation, terms, conditions, or privileges of employment of the employee, because of genetic information with respect to the employee;
  • To limit, segregate, or classify the employees of the employer in any way that would deprive or tend to deprive any employee of employment opportunities or otherwise adversely affect the status of the employee as an employee, because of genetic information with respect to the employee; or
  • To request, require, or purchase genetic information with respect to an employee or a family member of the employee except as specifically permitted by GINA and otherwise applicable law.

GINA §§ 203 and 204 extend similar prohibitions to employment agencies, labor unions and training programs.

Confidentiality Mandates. Under GINA § 206, an employer, employment agency, labor organization, or joint labor-management committee that possesses genetic information about an employee or member must protect the confidentiality of that information.  Under its provisions, employers and other covered entities must:

  •  Treat the genetic information as a confidential medical record of the employee or member and maintain it on separate forms and in separate medical files in the same manner as required for other medical records required to be maintained as confidential by Americans With Disabilities Act § 102(d)(3)(B); and
  • Only disclose it in the narrow circumstances specifically allowed by GINA.

Anti-Retaliation.  GINA also prohibits retaliation or other discrimination against any individual because such individual has opposed any act or practice prohibited by GINA, for making a charge, testifying or assisting or participating in any manner in an investigation, proceeding, or hearing under GINA. 

GINA’s Additional Group Health Plan Nondiscrimination & Privacy Rules Also Require Attention

In addition to taking appropriate steps to comply with the employment rules of Title II of GINA, employers and their group health plan fiduciaries and service providers also should ensure that the group health plan has been appropriately updated to comply with the group health plan nondiscrimination and privacy mandates of Title I of GINA. 

Effective for all group health plan years beginning on or after May 21, 2009, GINA’s new restrictions on the collection and use of genetic information by group health plans added under Title I of GINA are accomplished through the expansion of a series of already existing group health plan nondiscrimination and privacy rules.  GINA’s group health plan provisions amend and expand the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), Title VII of the Civil Rights Act, the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of information that falls within its broad definition of “genetic information” by  group health plans.  For individual health insurers, GINA’s restrictions take effect May 22, 2009.  The broad definition of the term “genetic information” in GINA will require group health plan sponsors and insurers to carefully review and update their group health plan documents, communications, policies and practices to comply with forthcoming implementing regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure in a series of areas.  

In this respect, wellness and disease management programs are likely to require special scrutiny and attention. GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of group health plan health assessment and other wellness and disease management programs which provide financial incentives or condition eligibility on the provision of family health histories or other information that could be construed as genetic information.  The implications of these GINA prohibitions are further complicated by recent changes in the disability nondiscrimination rules and guidance under the Americans With Disabilities Act.

Title I of GINA generally prohibits group health plans from collecting genetic information for underwriting or eligibility purposes.  It also expands already existing federal rules prohibiting group health plans from discriminating among individuals for purposes of determining eligibility or setting premiums based on health status previously enacted as part of HIPAA.   These existing rules already prohibit group health plans and health insurance issuers from discriminating based on health related factors including genetic information for purposes of determining eligibility or premiums. GINA expands these existing nondiscrimination requirements to further regulate group health plan’s use and collection of genetic information.   Under GINA’s nondiscrimination rules, group health plans and health insurers may not:

  • Request, require or purchase genetic information for underwriting purposes or in advance of an individual’s enrollment;
  • Adjust premiums or contribution amounts of the group based on genetic information;
  • Request or require an individual or family member to undergo a genetic test except in limited situations specifically allowed by GINA;
  • Impose a preexisting condition exclusion based solely on genetic information, in the absence of a diagnosis of a condition;
  • Discriminate against individuals in eligibility and continued eligibility for benefits based on genetic information; or
  • Discriminate against individuals in premium or contribution rates under the plan or coverage based on genetic information, although such a plan or issuer may adjust premium rates for an employer based on the manifestation of a disease or disorder of an individual enrolled in the plan.

GINA also prohibits insurers providing individual health insurance from establishing rules for eligibility, adjusting premiums or contribution amounts for an individual, imposing preexisting condition exclusions based on, requesting or requiring individuals or family members to undergo genetic testing.

Of particular concern to many plan sponsors and fiduciaries are the potential implications of these new rules on existing wellness and disease management features group health plans. Of particular concern is how regulators will treat the collection of family medical history and certain other information as part of health risk assessments used in connection with these programs. Although official guidance is still pending, many are concerned that regulators will construe certain commonly used practices of requiring covered persons to provide family medical histories or other genetic information through health risk assessments (HRAs) to qualify for certain financial incentives as a prohibited underwriting practice under GINA.  Even where health risk assessments are not used, however, most group health plan sponsors should anticipate that GINA will require specific amendments to their plan documents, communications and processes.

Taking timely action to comply with these nondiscrimination and collection prohibitions is important.  Under amendments to ERISA made by GINA, group health plan noncompliance can create significant liability for both the plan and its sponsor.  Participants or beneficiaries will be able to sue noncompliant group health plans for damages and equitable relief.  If the participant or beneficiary can show an alleged violation would result in irreparable harm to the individual’s health, the participant or beneficiary may not have to exhaust certain otherwise applicable Department of Labor administrative remedies before bringing suit.  In addition to these private remedies, GINA also authorizes the imposition of penalties against employers and other sponsors of group health plans that violate applicable requirements of GINA of up to $500,000. The minimum penalties generally are set at the greater of $100 per day or a minimum penalty amount ranging from $2,500 for de minimus violations corrected before the health plan received notice of noncompliance to $15,000 in cases in which the violations are more than de minimus.  GINA also includes language allowing the Secretary of Labor to reduce otherwise applicable penalties for violations that could not have been identified through the exercise of due diligence or when the plan corrects the violation quickly.

GINA Amendments To Health Plan Privacy Rules Under HIPAA

In addition to its nondiscrimination rules, GINA also amends HIPAA to make clear that “genetic information” as defined by HIPAA is protected health information protected by HIPAA’s Privacy & Security Standards of HIPAA. This means that it will require that all genetic information be treated as protected health information subject to the Privacy and Security Standards applicable to group health plans covered by HIPAA. Although the statutory provisions that accomplish these changes are deceptively simple, compliance with these requirements likely will require group health plans and their business associates to amend existing privacy policies, notices and practices to appropriately restrict disclosures for underwriting, operations and certain other uses to withstand scrutiny under the GINA privacy rule amendments. 

When contemplating these changes, many plan sponsors and administrators also will want to consider and begin preparing to comply with other refinements to their existing privacy and security practices required in response to HIPAA privacy and security rule amendments enacted as part of the HITECH Act provisions of the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) provisions of the American Recovery and Reinvestment Act of 2009 (ARRA).  As GINA specifies that violations of its privacy rule restrictions trigger the same sanctions as other privacy rule violations, group health plans and their business associates also should give due consideration to these penalty exposures.  The HITECH Act amended and increased civil penalties for HIPAA privacy violations in many circumstances effective February 17, 2009.  

GINA’s fractured assignment of responsibility and authority to develop, implement and enforce regulatory guidance of its genetic information rules can create confusion for parties involved in compliance efforts. Because the group health plan requirements of Title I of GINA are refinements to the group health plan privacy and nondiscrimination rules previously enacted as part of HIPAA, GINA specifically assigned authority to construe and enforce its group health plan requirements to the agencies responsible for the interpretation and enforcement of those original rules:  (1) the Department of Labor Employee Benefit Security Administration (EBSA); (2)  the Internal Revenue Services (IRS), and (3) the Department of Health & Human Services. 

These three agencies in early October published the interim final regulations construing the group health plan manatees of Title II of GINA, which are available for review here.  Group health plans, their employer and other sponsors, fiduciaries and service providers should act quickly to review and update their group health plan documents, procedures and other materials to comply with these new mandates.

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer.  Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, health and other employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer. All rights reserved. 


EEOC Prepares To Broaden “Disability” Definition Under ADA Regulations

September 18, 2009

Proposed regulations modifying existing Equal Employment Opportunity Commission (EEOC) rules concerning the conditions that an individual must meet to qualify as having a “disability” for purposes of claiming protection under the Americans with Disabilities Act (ADA) are expected to be published in the Federal Register the week of September 21, 2009.

On September 16, 2009, the EEOC announced that Commissioners had approved a Notice of Proposed Rulemaking (Proposed Regulation) which would make several significant changes to the its current regulatory definition of the term “disability” for purposes of the ADA.  The EEOC announced this week that the Proposed Regulation is expected to be published in the Federal Register the week of September 21, 2009.  Interested persons will have 60 days from the publication date of the Proposed Rule to submit comments to the EEOC concerning the Proposed Regulation.

Why The Change?

The proposed changes are intended to respond to amendments enacted under the ADA Amendments Act (ADAAA), which took effect January 1, 2009.   Enacted on September 25, 2008, the ADAAA made a number of significant changes to the definition of “disability” in the ADA as well as directed EEOC to amend its existing ADA regulation to reflect the changes made by the ADAAA.

The ADAAA amendments to the ADA definition of “disability” make it easier for certain individuals alleging employment discrimination based on disability to establish disability status under the ADA’s definition of “disability” by overruling various Supreme Court holdings and portions of EEOC’s existing ADA regulations considered by many members of Congress as too narrowly applying the definition of “disability.”  

While the ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment, provisions of the ADAAA that took effect on January 1, 2009 change the required interpretation of these terms.  Under the ADAAA, “major life activities” now include both many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating), as well as major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”). 

In addition to these clarifications, the ADAAA also broadens the reach of the ADA’s definition of “disability” in various other respects.  For instance, the ADAAA:

  • Asserts that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
    Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
  • Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
  • Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.

As part of the required implementation of its provisions, the ADAAA also mandates that the EEOC revise that portion of its existing regulations defining the term “substantially limits” and “major life activities” to comport to the changes enacted by the ADAAA.  In response to this statutory direction, the Proposed Regulation to be published next week proposes changes both to the ADA regulation itself and to the Interpretive Guidance (also known as the Appendix) that was published at the same time as the original ADA regulation. See 29 C.F.R. section 1630.  The Appendix provides further explanation from the EEOC on how its ADA regulations should be interpreted.

About The New Guidance and Proposed Regulations

In anticipation of the publication of the Proposed Regulation, the EEOC on September 16, 2009 sought to provided a peek into its new post-ADAAA construction of the ADA definition of disability by releasing its “Questions and Answers on the Notice of Proposed Rulemaking for the ADA Amendments Act of 2008” Questions and answers on the Notice of Proposed Rulingmaking for the ADA Amendments Act of 2008 (the “Q&As”). 

The Q&As and other EEOC statements released this week indicate that the Proposed Regulation will emphasize that the definition of disability — an impairment that poses a substantial limitation in a major life activity — must be construed broadly. It will provide that that major life activities include “major bodily functions;” that mitigating measures, such as medications and devices that people use to reduce or eliminate the effects of an impairment, are not to be considered when determining whether someone has a disability; and that impairments that are episodic or in remission, such as epilepsy, cancer, and many kinds of psychiatric impairments, are disabilities if they would “substantially limit” major life activities when active. The regulation also will provides a streamlined means through which persons claiming disability may demonstrate a substantial limitation in the major life activity of working, and implements the ADAAA’s new standard for determining whether someone is “regarded as” having a disability.

Required Response

Employers face increasing exposure to disability claims as a result of the ADAAA amendments, new genetic information nondiscrimination rules enacted under the Genetic Information Nondiscrimination Act (GINA), and a heightened emphasis on disabilities discrimination law enforcement by the Obama Administration.  In light of this rising exposure, employers and others covered by the ADA should evaluate their existing practices in light of the Q&As and make adjustments, submit comments regarding the Proposed Regulations or both as part of their efforts to manage their organization’s ADA liability exposure.  Because the ADAAA already is in effect, employers already face the possibility of being called upon to defend their hiring and employment practices under the amended ADAAA definition of disability, even though the EEOC has not issued final guidance.  For this reason, it is important that employers take timely action both to update relevant written policies and procedures, as well as to change hiring and other operational processes, conduct training, implement appropriate oversight and monitoring and take other steps to mitigate these exposures.

If you have questions about or need assistance evaluating, commenting on or responding to the  Proposed Regulations, the Q&As, or other employment, compensation, employee benefit, workplace health and safety, corporate ethics and compliance practices, concerns or claims, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer.  Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group, Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation and employee benefit, workplace safety, and other labor and employment, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, employee benefit and other personnel and staffing matters for more than 20 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.   For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here

Other Information & Resources

We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.  Some other recent updates that may be of interested include the following, which you can access by clicking on the article title:

For important information concerning this communication click here.   If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.

©2009 Cynthia Marcotte Stamer. All rights reserved. 


Register Now For HITECH Act Health Data Security & Breach Update: Learn What You Must Do This Month To Comply With New Health Data Breach Regulations

September 2, 2009

September 10, 2009 – Noon to 1:30 P.M. Central Time       Participate In Person or Via Remote!

Health care providers, health plans, health clearinghouses and their business associates (Covered Entities) must comply with the new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) by September 23, 2009. 

Catch up on what the Breach Rule means for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time for a registration fee of $45.00. Registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For information about registering for this program or other questions here,

The Breach Rule requires Covered Entities to notify affected individuals following a “breach” of “unsecured” protected health information. Just published August 24th, the Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).  The briefing will cover:

  • Who must comply, health plans, employers, others?
  • What your organization must do
  • How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
  • What is considered a breach of unsecured protected health information
  • What steps must a covered entity take if a breach of unsecured protected information happens
  • What liabilities do covered entities face for non-compliance
  • What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
  • How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
  • Other recent developments
  • Practical tips for assessing, planning, moving to and defending compliance
  • Participant questions
  • More

About The Presenter

The program will be presented by Curran Tomko and Tarski LLP Health Care & Employee Benefits Practice Leader and Partner Cynthia Marcotte Stamer.  Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts.  Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, a ABA Joint Committee on Employee Benefits Council Representative, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.

Other Helpful Resources & Other Information 

If you find this of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.net.

©2009 Solutions Law Press.   All rights reserved.


ADAAA Amendment Broader ADA “Disability” Definition Not Retroactive, Employer Action Needed To Manage Post 1/1/2009 Risks

August 25, 2009

Provisions of the ADA Amendments Act (ADAAA) that expand the definition of “disability” under the Americans with Disabilities Act (ADA) “in favor of broad coverage of individuals” do not apply to actions taken before effective date of the ADAAA, January 1, 2009, according to a recent decision of the U.S. Circuit Court of Appeals for the District of Columbia. While the holding provides some comfort for employers in relation to pre-January 1, 2009 actions, employers need to take appropriate steps to mitigate disability claim risks for actions on or after the January 1, 2009 effective date of the ADAAA.

As signed into law on September 25, 2008, the ADAAA amended the definition of “disability” for purposes of the disability discrimination prohibitions of the ADA to make it easier for an individual seeking protection under the ADA to establish that that has a disability within the meaning of the ADA.  The ADAAA retains the ADA’s basic definition of “disability” as an impairment that substantially limits one or more major life activities, a record of such an impairment, or being regarded as having such an impairment. However, provisions of the ADAAA that took effect January 1, 2009 change the way that these statutory terms should be interpreted in several ways. Most significantly, the Act:

  • Directs EEOC to revise that portion of its regulations defining the term “substantially limits;”
  • Expands the definition of “major life activities” by including two non-exhaustive lists: (1) The first list includes many activities that the EEOC has recognized (e.g., walking) as well as activities that EEOC has not specifically recognized (e.g., reading, bending, and communicating); and (2) The second list includes major bodily functions (e.g., “functions of the immune system, normal cell growth, digestive, bowel, bladder, neurological, brain, respiratory, circulatory, endocrine, and reproductive functions”);
  • States that mitigating measures other than “ordinary eyeglasses or contact lenses” shall not be considered in assessing whether an individual has a disability;
  • Clarifies that an impairment that is episodic or in remission is a disability if it would substantially limit a major life activity when active;
  • Changes the definition of “regarded as” so that it no longer requires a showing that the employer perceived the individual to be substantially limited in a major life activity, and instead says that an applicant or employee is “regarded as” disabled if he or she is subject to an action prohibited by the ADA (e.g., failure to hire or termination) based on an impairment that is not transitory and minor; and
  • Provides that individuals covered only under the “regarded as” prong are not entitled to reasonable accommodation.

The ADAAA also emphasizes that the definition of disability should be construed in favor of broad coverage of individuals to the maximum extent permitted by the terms of the ADA and generally shall not require extensive analysis.

In Lytes v. DC Water and Sewer Authority, D.C. Cir. No. 08-7002 (July 21, 2009), the D.C. Court of Appeals considered and rejected the retroactivity argument made by Lytes in his appeal from a trial court’s finding that he was not disabled under the ADA.  As the ADAAA took effect while his action was pending, Lytes sought to convince the Appeals Court to apply the ADAAA amended definition retroactively.  Contending that the ADAAA amendment merely clarified the existing law under the ADA, Lytes argued that the Court should apply the broader definition of disability when considering the legality of his termination from employment in 2004.

Rejecting Lytes’ retroactivity argument, the Court of Appeals ruled that the ADAAA amendment of the definition of “disability” under the ADA applies only on a prospective basis based on its finding that Congress had clearly provided that the ADAAA amendments only would apply to post-December 31, 2008 actions. Accordingly, the Court of Appeals affirmed the District Court’s finding that Lytes termination in 2004 did not violate the ADA as then effective as his lack of disabled status under the then-applicable definition of disability meant he was not entitled to accommodation.

In adopting these changes, Congress expressly sought to overrule existing employer-friendly judicial precedent construing the current provisions of the ADA and to require the Equal Employment Opportunity Commission (EEOC) to update its existing guidance to confirm with the ADAAA Amendments.

Violations of the ADA can expose businesses to substantial liability. Violations of the ADA may be prosecuted by the EEOC or by private lawsuits.  Employees or applicants that can prove they were subjected to prohibited disability discrimination under the ADA generally can recover actual damages, attorneys’ fees, and up to $300,000 of exemplary damages (depending on the size of the employer).   

While the Lytes decision indicates that businesses will not be required to defend pre-2009 actions under the amended disability standards enacted by the ADAAA, businesses should prepare to meet new challenges in defending ADA claims arising from actions taken after December 31, 2008.  The ADAAA amendments make it likely that businesses generally will face more disability claims from a broader range of employees and will possess fewer legal shields to defend themselves against these claims. These changes will make it easier for certain employees to qualify as disabled under the ADA.  Consequently, businesses should act strategically to mitigate their ADA exposures in anticipation of these changes.  

To help mitigate the expanded employment liability risks created by the ADAAA amendments, businesses generally should act cautiously when dealing with applicants or employees with actual, perceived, or claimed physical or mental impairments to minimize exposures under the ADA.  Management should exercise caution to carefully and appropriate the potential legal significance of physical or mental impairments or conditions that might be less significant in severity or scope, correctable through the use of eyeglasses, hearing aids, daily medications or other adaptive devices, or that otherwise have been assumed by management to fall outside the ADA’s scope. Employers should no longer assume, for instance, that a visually impaired employee won’t qualify as disabled because eyeglasses can substantially correct the employee’s visual impairment. 

Likewise, businesses should be prepared for the EEOC and the courts to treat a broader range of disabilities, including those much more limited in severity and life activity restriction, to qualify as disabling for purposes of the Act. Businesses should assume that a greater number of employees with such conditions are likely to seek to use the ADA as a basis for challenging hiring, promotion and other employment decisions.  For this reason, businesses generally should tighten job performance and other employment recordkeeping to enhance their ability to demonstrate nondiscriminatory business justifications for the employment decisions made by the businesses.

Businesses also should consider tightening their documentation regarding their procedures and processes governing the  collection and handling records and communications that may contain information regarding an applicant’s physical or mental impairment, such as medical absences, worker’s compensation claims, emergency information, or other records containing health status or condition related information.  The ADA generally requires that these records be maintained in separate confidential files and disclosed only to individuals with a need to know under circumstances allowed by the ADA. 

As part of this process, businesses also should carefully review their employment records, group health plan, family leave, disability accommodation, and other existing policies and practices to comply with, and manage exposure under the new genetic information nondiscrimination and privacy rules enacted as part of the Genetic Information and Nondiscrimination Act (GINA) signed into law by President Bush on May 21, 2008.  Effective November 21, 2009, Title VII of GINA amends the Civil Rights Act to prohibit employment discrimination based on genetic information and restricts the ability of employers and their health plans to require, collect or retain certain genetic information. Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Employees can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws.  For instance, GINA’s employment related provisions include rules that will:

  • Prohibit employers and employment agencies from discriminating based on genetic information in hiring, termination or referral decisions or in other decisions regarding compensation, terms, conditions or privileges of employment;
  • Prohibit employers and employment agencies from limiting, segregating or classifying employees so as to deny employment opportunities to an employee based on genetic information;
  • Bar labor organizations from excluding, expelling or otherwise discriminating against individuals based on genetic information;
  • Prohibit employers, employment agencies and labor organizations from requesting, requiring or purchasing genetic information of an employee or an employee’s family member except as allowed by GINA to satisfy certification requirements of family and medical leave laws, to monitor the biological effects of toxic substances in the workplace or other conditions specifically allowed by GINA;
  • Prohibit employers, labor organizations and joint labor-management committees from discriminating in any decisions related to admission or employment in training or retraining programs, including apprenticeships based on genetic information;
  • Mandate that in the narrow situations where limited cases where genetic information is obtained by a covered entity, it maintain the information on separate forms in separate medical files, treat the information as a confidential medical record, and not disclosure the genetic information except in those situations specifically allowed by GINA;
  • Prohibit any person from retaliating against an individual for opposing an act or practice made unlawful by GINA; and
  • Regulate the collection, use, access and disclosure of genetic information by employer sponsored and certain other health plans.

These employment provisions of GINA are in addition to amendments to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act that are effective for group health plan for plan years beginning after May 20, 2009.

If you have any questions or need help reviewing and updating your organization’s employment and/or employee practices in response to the ADAAA, GINA or other applicable laws, or if we may be of assistance with regard to any other workforce management, employee benefits or compensation matters, please do not hesitate to contact the author of this update, Curran Tomko Tarksi LLP Labor & Employment Practice Chair Cynthia Marcotte Stamer at 214.270.2402.

About The Author

Management attorney and consultant Cynthia Marcotte Stamer helps businesses, governments and associations solve problems, develop and implement strategies to manage people, processes, and regulatory exposures to achieve their business and operational objectives and manage legal, operational and other risks. Board certified in labor and employment law by the Texas Board of Legal Specialization, with more than 20 years human resource and employee benefits experience, Ms. Stamer helps businesses manage their people-related risks and the performance of their internal and external workforce though appropriate human resources, employee benefit, worker’s compensation, insurance, outsourcing and risk management strategies domestically and internationally. Recognized in the International Who’s Who of Professionals and bearing the Martindale Hubble AV-Rating, Ms. Stamer also is a highly regarded author and speaker, who regularly conducts management and other training on a wide range of labor and employment, employee benefit, human resources, internal controls and other related risk management matters.  Her writings frequently are published by the American Bar Association (ABA), Aspen Publishers, Bureau of National Affairs, the American Health Lawyers Association, SHRM, World At Work, Government Institutes, Inc., Atlantic Information Services, Employee Benefit News, and many others. For a listing of some of these publications and programs, see here. Her insights on human resources risk management matters also have been quoted in The Wall Street Journal, various publications of The Bureau of National Affairs and Aspen Publishing, the Dallas Morning News, Spencer Publications, Health Leaders, Business Insurance, the Dallas and Houston Business Journals and a host of other publications. Chair of the ABA RPTE Employee Benefit and Other Compensation Committee, a council member of the ABA Joint Committee on Employee Benefits, and the Legislative Chair of the Dallas Human Resources Management Association Government Affairs Committee, she also serves in leadership positions in numerous human resources, corporate compliance, and other professional and civic organizations. For more details about Ms. Stamer’s experience and other credentials, contact Ms. Stamer, information about workshops and other training, selected publications and other human resources related information, see here or contact Ms. Stamer via telephone at 214.270.2402 or via e-mail here.

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles published in this electronic Solutions Law publication available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@solutionslawyer.net.

©2009 Cynthia Marcotte Stamer.   All rights reserved. 


Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23

August 24, 2009

Employer and other health plans, health care providers, health clearinghouses and their business associates must start complying with new federal data breach notification rules on September 23, 2009.   

The new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here  in today’s Federal Register requires health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) covered under the personal health information privacy and security rules of the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information.The Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA). 

You are invited to catch up on what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9 2009 from Noon to 1:30 P.M. Central Time.  

HITECH Act Data Breach and Unsecured PHI Rules 

Published in the August 24, 2009 Federal Register, the new Breach Regulation implements the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, when a breach of “unsecured protected health information” happens and the form, manner, and timing of that notification. Covered Entities must begin complying with the new Breach Regulation on September 23, 2009.

Part of a series of new HHS rules implementing recent changes to HIPAA enacted under the HITECH Act to strengthen existing federally mandates requiring Covered Entities to safeguard protected health information, the Breach Regulation will obligate Covered Entities and business associates to provide certain notifications following a breach of “protected health information” that not secured at the time of the breach through the use of a technology or methodology meeting minimum standards issued by HHS pursuant to other provisions of the HITECH Act.

Under the HITECH Act, the breach notification obligations contained in the Breach Notification only apply to a breach of “unsecured protected health information.” The Breach Regulation exempts breaches of protected health information that qualify as “secured” under separately issued HHS and Federal Trade Commission (FTC) standards for encryption and destruction of protected health information from its breach notification requirements.  

 For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the Covered Entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  Earlier this year, HHS and the FTC issued interim rules defining the minimum encryption and destruction technologies and methodologies that Covered Entities must use to render protected health information unusable, unreadable, or indecipherable to unauthorized individuals for purposes of determining when protected health information is “unsecured” for purposes of the HITECH Act.  Concurrent with its publication of the Breach Regulation, HHS also released guidance updating and clarifying this previously issued guidance. 

Read the Breach Regulation here .  To review the HITECH Act Breach Notification Guidance and Request for Information, see here .

Register For September 9, 2009  “HITECH Act Health Data Security & Breach Update”

Interested persons are invited to register here now  to learn what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For questions or other information about this program, e-mail here.

Conducted by Curran Tomko and Tarski LLP Partner Cynthia Marcotte Stamer, the briefing will cover: 

  • Who must comply
  • What your organization must do
  • How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
  • What is considered a breach of unsecured protected health information
  • What steps must a covered entity take if a breach of unsecured protected information happens
  • What liabilities do covered entities face for non-compliance
  • What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
  • How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
  •  Other recent developments
  • Practical tips for assessing, planning, moving to and defending compliance
  • Participant questions
  • More

About The Presenter

The program will be presented by Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.  Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. 

 Past Chair of the ABA Health Law Section Managed Care & Insurance Section and currently the Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Section and a Council Representative of the ABA Joint Committee On Employee Benefits, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.

Other Helpful Resources & Other Information

If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.com.

©2009 Cynthia Marcotte Stamer.   All rights reserved. 


Health Plans Must Comply with New HHS Interim Final Data Breach Rules Beginning September 24; Register to Participate In September 10th Briefing on New Rules In Person or Via Telephone

August 20, 2009

Employers and other health plan sponsors, fiduciaries, insurers and service providers need to move quickly to prepare to comply with  “breach notification” regulations issued by the U.S. Department of Health and Human Services (HHS) yesterday (August 19, 2009).  The new data breach regulations will require health plans, as well as  health care providers, business associates and other covered entities (Covered Entities) under the personal health information privacy and security rules of the Health Insurance Portability & Accountability  (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information. Scheduled for publication in the Federal Register on August 24, 2009, the new breach notification regulations are part of a series of new rules that implement new electronic personal health information data security and data breach notification requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).  Covered entities must begin complying with the new rules no later than September 24, 2009.

Curran Tomko Tarski, LLP Health Practice leader Cynthia Marcotte Stamer will conduct a briefing on these new protected health information data security and data breach rules on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201.  For more information, e-mail here.

 HITECH Act Data Breach and Unsecured PHI Rules

The new data breach notification rules are part of a series of recent HIPAA enacted under the HITECH Act to strengthen the federal rules requiring HIPAA covered entities to safeguard electronic and certain other protected health information. Enhanced data security and data breach rules added as part of these HITECH Act amendments obligate  covered entities and business associates to provide certain notifications following a breach of “unsecured”  “protected health information” within the meaning of HIPAA, as amended.  “Unsecured protected health information” is defined as protected health information that is not secured through the use of a technology or methodology specified by the HHS Secretary.

The new data breach regulations implement the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, of a breach and the form, manner, and timing of that notification.  For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the covered entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act.  HHS and the Federal Trade Commission previously issued certain initial guidance concerning the HITECH Act standards for determining when electronic personal health information qualifies as secure.  To help further define when electronic health information is treated as “unsecured” and therefore subject to the breach notification requirements, the data breach rules also update and clarify the previously issued existing HHS guidance specifying encryption and destruction as the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals published earlier this year by HHS to for purposes of determining when protected health information will be considered “unsecured” for purposes of the HITECH Act data breach rules.  Entities subject to the HHS and FTC regulations that secure health information as specified by the guidance through encryption or destruction are relieved from having to notify in the event of a breach of such information.  

The HHS interim final regulations are effective September 24, 2009, which is the date 30 days after the date they will be published on the Federal Register and include a 60-day public comment period. To review the interim final data breach regulations, see here.  To review the HITECH Act Breach Notification Guidance and Request for Information, see here.

For More Information

The author of this article, Curran Tomko and Tarski LLP Labor and Employment and Health Care Practice Chair Cynthia Marcotte Stamer has extensive experience advising and assisting employer and other health plan sponsors, insurers, managed care providers and other health and insurance industry clients about HIPAA and other privacy and data security matters, as well as a diverse range of health care, employment, and emplyee benefit policy, regulatory, compliance, risk management and operational concerns. 

Current Chair of the American Bar Association (ABA) Real Property, Trusts & Estates Employee Benefit & Other Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, past chair of the American Bar Association Health Law Section Managed Care & Insurance Section, Martindale Hubble AV-rated and recognized in International Who’s Who of Professionals, Ms. Stamer continuously advises health care providers, health care payers and administrators, employers, governments and others about health care, insurance, human resources, privacy and data security, technology, and other legal and operational concerns.  A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer also writes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters.  She currently serves as the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010.  Examples of her other works include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of others.  Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service Privacy Report, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a various other national and local publications.  For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.  

We hope that this information is useful to you.  If you need assistance monitoring, evaluating or responding to these or other proposed health care or other regulatory reforms or with other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or your other favorite Curran Tomko Tarski LLP Partner.

We also encourage you and others to join the discussion about these and other health care reform proposals and concerns by joining the Coalition for Responsible Health Care Reform Group on Linkedin, registering to receive these updates here.

Other Helpful Resources & Other Information

We hope that this information is useful to you.   If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Solutions Law Press Health Care Update publication available here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please register to receive this Solutions Law Press Health Care Update here and be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.

For important information concerning this communication click here.  If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.

©2009 Cynthia Marcotte Stamer.  All rights reserved. 


Registration Open For June 23 Dallas HR 2009 Health Plan Eligibility Update Program

June 9, 2009

Amid soaring health care costs and tightening corporate budgets, employers and other group health plan sponsors, fiduciaries and administrations now also must update their group health plan eligibility and enrollment practices to comply with the American Recovery and Reinvestment Act of 2009 (the “Stimulus Bill”), COBRA subsidy mandates, HIPAA special enrollment rule amendments and a host of other changes to federal eligibility mandates that already have or will take effect this year.  Meanwhile, employers must keep a careful watch on Congress as it considers enacting sweeping health care reforms that are likely to place more obligations on employers.

Health plan eligibility design and administration plays a critical role in controlling health benefit costs and is a leading and growing source of health plan legal risk for employers, fiduciaries and administrators.  Understanding and properly managing these concerns is imperative for employers and others sponsoring or administering these programs.

Stamer Discusses Health Plan Eligibility Rules June 23

Cynthia Marcotte Stamer will explain newly effective COBRA Subsidy Rules, genetic information nondiscrimination rules and other recent and impending changes to federal health plan eligibility mandates will be explained on June 23, 2009 during a 2009 Health Plan Eligibility Update briefing hosted by the Dallas Human Resources Management Association including:

Cynthia Stamer will explain to attendees what they need to know and do about:

  • New Stimulus Bill COBRA Subsidy Rules and other special COBRA rules that took effect on February 17
  • New GINA group health plan information scheduled to take place in 2009
  • Changes to HIPAA special enrollment and nondiscrimination rules
  • Implications for group health plans based on recent changes to FMLA and USERRA regulations
  • Medicare, Medicaid and CHIP nondiscrimination rules
  • Impending college student continuation mandates
  • And more….

Get  details or register on line here or by telephoning Dallas Human Resources Management Association at 214-631-8775.

Stamer’s Health Plan Experience Extensive

The immediate past Chair of the American Bar Association’s Managed Care & Insurance Section, Cynthia Marcotte Stamer is a highly regarded legal advisor, author and speaker recognized both nationally and internationally for her expertise in the areas of health benefits and other human resource compliance matters. Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization, “Cindy” recently joined Curran Tomko Tarski, LLP as the Chair of its Labor & Employment and Health Care Practices April 1, 2009.

The Managing Editor of Solutions Law Press and an Editorial Advisory Board Member and author for Employee Benefit News and other publications, Ms. Stamer is a widely published author and popular speaker. In addition to hundreds of publications on health plan and other human resources, employee benefit and internal controls issues, Ms. Stamer is the author of the “Health Plan Eligibility Toolkit.” Her work has been featured and published by the American Bar Association, BNA, SHRM, World At Work, Employee Benefit News and the American Health Lawyers Association. Her insights on human resources risk management matters have been quoted in The Wall Street Journal, the Dallas Business Journal, Managed Care Executive, HealthLeaders, Business Insurance, Employee Benefit News and the Dallas Morning News.

Ms. Stamer also serves in a number of professional leadership roles including the leadership council of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Real Property, Probate & Trust Section and Employee Benefits & Compensation Group.

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other health plan and other employee benefit,  labor and employment, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer via e-mail here, or by calling (214) 270-2402.  For additional information about the experience, services, publications and involvements of Ms. Stamer specifically or to access some of her many publications, see here,   For more information and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website.

We hope that this information is useful to you. For additional information about the experience, services, publications and involvements of Ms. Stamer specifically or to access some of her many publications, see here,   For more information and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website.

You can register to receive future updates and information about upcoming programs, access other publications by Ms. Stamer and access other helpful resources here.  If you or someone else you know would like to receive updates about developments on these and other human resources and employee benefits concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here.  If you would prefer not to receive these updates, please send a reply e-mail with “Remove” in the subject line to support@SolutionsLawyer.net. You also can register to participate in the distribution of these updates by registering to participate in the Solutions Law Press HR & Benefits Update Blog here.

 ©2009 Cynthia Marcotte Stamer. All rights reserved.


New GINA Health Plan Nondiscrimination Rules Effective For Plan Years Beginning On or After Today

May 21, 2009

New restrictions on the collection, use and disclosure of genetic information applicable to employer and union-sponsored group health plans enacted under Title I of the Genetic Information Nondiscrimination Act of 2008, Public Law No. 110-233 (GINA) for group health plan years that begin on or after today (May 21, 2009). For non-calendar year plans with plan years beginning between June 1 and December 1, the effective date occurs on first day of their 2009 plan year. For example, the effective date will be June 1, 2009 for a plan with a 2009 plan year that begins June 1.  For calendar year plans, the compliance deadline is January 1, 2010.   All employer-sponsored group health plans are required to comply with GINA.  There are no small group exceptions.

GINA In A Nutshell

GINA amended federal law to include specific prohibitions against certain discrimination based on genetic information by group health plans and health insurers (Title I) and to prohibit discrimination based on genetic information by employers of 15 or more employees (Title II).

Effective for all group health plan years beginning on or after May 21, 2009, GINA’s new restrictions on the collection and use of genetic information by group health plans added under Title I of GINA are accomplished through the expansion of a series of already existing group health plan nondiscrimination and privacy rules.  GINA’s group health plan provisions amend and expand the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), Title VII of the Civil Rights Act, the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of information that falls within its broad definition of “genetic information” by  group health plans.  For individual health insurers, GINA’s restrictions take effect May 22, 2009.  The broad definition of the term “genetic information” in GINA will require group health plan sponsors and insurers to carefully review and update their group health plan documents, communications, policies and practices to comply with forthcoming implementing regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure in a series of areas. 

Meanwhile, employers, unions and others face their own new prohibitions against genetic information based employment discrimination added by Title II of GINA, which take effect November 21, 2009. The Equal Employment Opportunity Commission (EEOC) published proposed regulations interpreting Title II of GINA in March, 2009.

Broad Definition of “Genetic Information”

The broad range of information included within GINA’s broad definition of “genetic information” means its new restrictions have a sweeping reach when applied to most group health plans.  GINA defines “genetic information to include with respect to any individual, information about:

  • Such individual’s genetic tests;
  • The genetic tests of family members of such individual; and
  • The manifestation of a disease or disorder in family members of such individual.

GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.

Pending issuance of regulatory guidance, GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of group health plan health assessment and other wellness and disease management programs which provide financial incentives or condition eligibility on the provision of family health histories or other information that could be construed as genetic information. 

Group Health Plan Genetic Testing Collection and Nondiscrimination Rules

Under GINA’s nondiscrimination rules, group health plans and health insurers may not:

  • Request, require or purchase genetic information for underwriting purposes or in advance of an individual’s enrollment;
  • Adjust premiums or contribution amounts of the group based on genetic information;
  • Request or require an individual or family member to undergo a genetic test except in limited situations specifically allowed by GINA;
  • Impose a preexisting condition exclusion based solely on genetic information, in the absence of a diagnosis of a condition;
  • Discriminate against individuals in eligibility and continued eligibility for benefits based on genetic information; or
  • Discriminate against individuals in premium or contribution rates under the plan or coverage based on genetic information, although such a plan or issuer may adjust premium rates for an employer based on the manifestation of a disease or disorder of an individual enrolled in the plan.

GINA also prohibits insurers providing individual health insurance from establishing rules for eligibility, adjusting premiums or contribution amounts for an individual, imposing preexisting condition exclusions based on, requesting or requiring individuals or family members to undergo genetic testing.

Of particular concern to many plan sponsors and fiduciaries are the potential implications of these new rules on existing wellness and disease management features group health plans. Of particular concern is how regulators will treat the collection of family medical history and certain other information as part of health risk assessments used in connection with these programs. Although official guidance is still pending, many are concerned that regulators will construe certain commonly used practices of requiring covered persons to provide family medical histories or other genetic information through health risk assessments (HRAs) to qualify for certain financial incentives as a prohibited underwriting practice under GINA.  Even where health risk assessments are not used, however, most group health plan sponsors should anticipate that GINA will require specific amendments to their plan documents, communications and processes.

Taking timely action to comply with these nondiscrimination and collection prohibitions is important.  Under amendments to ERISA made by GINA, group health plan noncompliance can create significant liability for both the plan and its sponsor.  Participants or beneficiaries will be able to sue noncompliant group health plans for damages and equitable relief.  If the participant or beneficiary can show an alleged violation would result in irreparable harm to the individual’s health, the participant or beneficiary may not have to exhaust certain otherwise applicable Department of Labor administrative remedies before bringing suit.  In addition to these private remedies, GINA also authorizes the imposition of penalties against employers and other sponsors of group health plans that violate applicable requirements of GINA of up to $500,000. The minimum penalties generally are set at the greater of $100 per day or a minimum penalty amount ranging from $2,500 for de minimus violations corrected before the health plan received notice of noncompliance to $15,000 in cases in which the violations are more than de minimus.  GINA also includes language allowing the Secretary of Labor to reduce otherwise applicable penalties for violations that could not have been identified through the exercise of due diligence or when the plan corrects the violation quickly.

GINA Amendments To Health Plan Privacy Rules Under HIPAA

In addition to its nondiscrimination rules, GINA also amends HIPAA to make clear that “genetic information” as defined by HIPAA is protected health information protected by HIPAA’s Privacy & Security Standards of HIPAA. This means that it will require that all genetic information be treated as protected health information subject to the Privacy and Security Standards applicable to group health plans covered by HIPAA. Although the statutory provisions that accomplish these changes are deceptively simple, compliance with these requirements likely will require group health plans and their business associates to amend existing privacy policies, notices and practices to appropriately restrict disclosures for underwriting, operations and certain other uses to withstand scrutiny under the GINA privacy rule amendments. 

The HITECH Act amended and increased civil penalties for HIPAA privacy violations in many circumstances effective February 17, 2009.   

Regulatory Guidance Status

 As the the deadline for compliance for post May 20, 2009 plan years is rapidly approaching, however, many group health plans and their sponsors will need forward with their compliance arrangements in the absence of regulatory guidance interpreting these requirements. 

GINA’s fractured assignment of responsibility and authority to develop, implement and enforce regulatory guidance of its genetic information rules can create confusion for parties involved in compliance efforts. Because the group health plan requirements of Title I of GINA are refinements to the group health plan privacy and nondiscrimination rules previously enacted as part of HIPAA, GINA specifically assigned authority to construe and enforce its group health plan requirements to the agencies responsible for the interpretation and enforcement of those original rules:

  • The Department of Labor Employee Benefit Security Administration (EBSA);
  • The Internal Revenue Services (IRS), and
  • The Department of Health & Human Services. 

While these three agencies previously published a request for public comments about issues under Title I’s provisions, see http://edocket.access.gpo.gov/2008/pdf/E8-24194.pdf, none of these three agencies as of May 20, 2009 has published interim or other regulations interpreting the GINA provisions within their scope of responsibility since the formal comments period ended December 9, 2009.  Although the EBSA Spring 2009 regulatory agenda reflected it intended to publish interim regulations by today and agency officials continue to indicate they intend to publish guidance “soon,” no guidance had been published as of May 20, 2009.

Even if the agencies issue guidance by the end of May plan sponsors and administrators of group health plans with new plan years beginning in the next 60 to 90 days are expressing concern that they will have inadequate time to complete compliance arrangements.  As a result, in addition to guidance about GINA’s requirements generally, some are hopeful that the guidance with include transition rules or other relief to allow more time to comply with the regulations when finally issued.  Regulators as of May 20, 2009 had not given any indication that they plan or perceive that they are authorized to provide such relief.

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney.  For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the http://www.cttlegal.com.

Other Information & Resources

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at e-mail, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney.  For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website or Cynthia Marcotte Stamer, P.C. Website.

We hope that this information is useful to you. You can register to receive future updates and information about upcoming programs, access other publications by Ms. Stamer and access other helpful resources at CynthiaStamer.com For additional information about Ms. Stamer and her experience, see here or contact Ms. Stamer directly. If you or someone else you know would like to receive updates about developments on these and other human resources and employee benefits concerns, please be sure that we have your Currant contact information – including your preferred e-mail- by creating or updating your profile at CynthiaStamer.com.  If you would prefer not to receive these updates, please send a reply e-mail with “Remove” in the subject line to support@SolutionsLawyer.net. You also can register to participate in the distribution of these updates by registering to participate in the Solutions Law Press HR & Benefits Update Blog here.

 ©Cynthia Marcotte Stamer. All rights reserved.


EEOC GIVES EMPLOYERS LIMITED EMPLOYER GUIDANCE ABOUT ADA ISSUES IN SWINE FLU RESPONSE

May 13, 2009

Recent concerns over the H1N1 Swine Flu (swine flu) pandemic and warnings of a possible resurgence of the swine flu pandemic or some other pandemic in the future is forcing many employers to question when concerns that an employee suffers from a contagious disease can justify the employer making inquires about the health of an employee or the exclusion of the employee from the workplace. New guidance set forth in the “U.S. Equal Employment Opportunity Commission ADA-Compliant Employer Preparedness For the H1N1 Flu Virus” (Guidance) published by the U.S. Department of Labor Equal Employment Opportunity Commission (EEOC) on May 4, 2009 provides some insights for employers about the EEOC’s perspective on these questions. 

The Guidance details the EEOC’s answers to certain basic questions about when the EEOC views certain workplace preparation strategies for responding to the 2009 flu virus as compliant with the Americans with Disabilities Act (ADA).  Employers considering updates to their current pandemic and infectious disease response plans are cautioned that in addition to potential ADA exposures, practices for periods after November 21, 2009 also generally must be tailored to comply with new restrictions on employer’s collection of and discrimination based on genetic information based on the Genetic Information Nondiscrimination Act of 2008 (GINA).  Proposed regulations interpreting the employment provisions of GINA published by the EEOC in March 2009 do not specifically address the implications of GINA on employer planning or response to pandemic concerns.

ADA Concerns Apply To Employers  Planning For & Applying Swine Flu Response 

Title I of the Americans with Disabilities Act (ADA) protects applicants and employees from disability discrimination. Among other things, the ADA regulates when and how employers may require a medical examination or request disability-related information from applicants and employees, regardless of whether the individual has a disability.  The Guidance confirms that the EEOC views this requirement as affecting when and how employers may request health information from applicants and employees regarding H1N1 flu virus.  

Effective January 1, 2009, Congress amended the Americans with Disabilities Act pursuant to the Americans with Disabilities Act Amendments Act of 2008 (ADAAA) to change the way that the ADA’s statutory definition of the term “disability” historically has been interpreted by certain courts.  The ADAAA amendments generally are intended and expected to make it easier for certain individuals to qualify as disabled under the ADA.  While the Guidance announces that the EEOC intends to revise its ADA regulations to reflect the broader group of persons protected as disabled under the ADAAA amendments, it also indicates that the EEOC does not perceive that the ADAAA changes the actions prohibited by the ADA as they relate to common pandemic planning and response activities.  Consequently, the Guidance states that the EEOC views the  guidance in “Disability-Related Inquiries & Medical Examinations of Employees Under the ADA” published by the EEOC in 2000 and its “Enforcement Guidance: Preemployment Disability-Related Questions & Medical Examinations” published in 1995 as setting forth the governing rules for medical testing, inquires and other pandemic response planning under the ADA.

Under the ADA, an employer’s ability to make disability-related inquiries or require medical examinations is analyzed in three stages: pre-offer, post-offer, and employment.

  • At the first stage (prior to an offer of employment), the ADA prohibits all disability-related inquiries and medical examinations, even if they are related to the job.
  • At the second stage (after an applicant is given a conditional job offer, but before s/he starts work), an employer may make disability-related inquiries and conduct medical examinations, regardless of whether they are related to the job, as long as it does so for all entering employees in the same job category.
  • At the third stage (after employment begins), an employer may make disability-related inquiries and require medical examinations only if they are job-related and consistent with business necessity.
  • The ADA requires employers to treat any medical information obtained from a disability-related inquiry or medical examination (including medical information from voluntary health or wellness programs), as well as any medical information voluntarily disclosed by an employee, as a confidential medical record. Employers may share such information only in limited circumstances with supervisors, managers, first aid and safety personnel, and government officials investigating compliance with the ADA.

Employers deviating from these requirements when administering their pandemic planning or response risk disability discrimination liability under the ADA unless they otherwise can defend their action under one of the exceptions to the ADA’s disability discrimination prohibitions.  When making post-offer inquiries or requiring post offer examinations or imposing other conditions for safety reasons, the Guidance and EEOC in unofficial discussions have emphasized the importance of the employer’s ability to demonstrate the job or safety relevance of the medical inquiry or examination based on credible scientific evidence such as the latest scientific evidence available from the World Health Organization (WHO) and the Centers for Disease Control and Prevention (CDC). 

Other than emphasizing the importance of acting appropriately in response to credible scientific evidence and pointing to preexisting guidance, the Guidance does not extensively address with specificity the circumstances under which the EEOC will view any particular action taken by an employer as defensible under the safety or other exceptions of the ADA.  Likewise, the Guidance does not discuss in any details the conditions, if any, under which the EEOC would view suffering, a history of suffering or association with or exposure to swine flu as qualifying an individual as disabled or perceived to be disabled for purposes of the ADA.  Consequently, employer must rely on other less specifically tailored guidance for purposes of assessing the defensibility of a proposed action on these grounds.

Planning for Absenteeism Under ADA

When planning for a possible pandemic, employers must be careful about when and how they ask employees about factors, including chronic medical conditions that may cause them to miss work in the event of a pandemic.  According to the Guidance, an employer may survey its workforce to gather personal information needed for pandemic preparation if the employer asks broad questions that are not limited to disability-related inquiries.  An inquiry would not be disability-related if it identified non-medical reasons for absence during a pandemic (e.g., mandatory school closures or curtailed public transportation) on an equal footing with medical reasons (e.g., chronic illnesses that weaken immunity). The Guidance includes a sample of what the EEOC views as ADA-compliant survey that could be given to all employees before a pandemic.

The Guidance also indicates that where appropriate safeguards are applied to comply with the ADA, it also may be appropriate for an employer under certain limited circumstances, to require entering employees to have a medical test post-offer to determine their exposure to the influenza virus.  According to the EEOC, the ADA permits an employer to require entering employees to undergo a job relevant medical examination after making a conditional offer of employment but before the individual starts work, if all entering employees in the same job category must undergo such an examination.  Thus, the Guidance reflects that the requirement by an employer as part of its pandemic influenza preparedness plan that all entering employees in the same job categories undergo the same post offer medical testing for the virus in accordance with recommendations by the WHO and the CDC in response to a new influenza virus may be ADA-compliant.

Infection Control in the Workplace Under the ADA

The Guidance also discusses the EEOC’s perceptions about the ADA implications of employer use of certain infection control practices in the workplace during a pandemic provided that the requirements are applied in a nondiscriminatory fashion consistent with the ADA.  For instance, the Guidance states that employers generally may apply with following infection control practices without implicating the ADA:

  • Require all employees to comply with certain infection control practices, such as regular hand washing, coughing and sneezing etiquette, and tissue usage and disposal without implicating the ADA;
  • May require employees to wear personal protective equipment provided that where an employee with a disability needs a related reasonable accommodation under the ADA (e.g., non-latex gloves, or gowns designed for individuals who use wheelchairs), employer provides these accommodations absent undue hardship;
  • Encourage or require employees to telework as an infection-control strategy, based on timely information from public health authorities about pandemic conditions or offer telework as a possible reasonable accommodation.  

In all cases, of course, the Guidance cautions that employers must not single out employees either to telework or to continue reporting to the workplace on a basis prohibited by the ADA or any of the other federal Equal Employment Opportunity laws.

Impending GINA Rules

 As signed into law, GINA amends Title VII of the Civil Rights Act, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of  “genetic information” by employers, employment agencies, labor organizations, joint labor-management committees, group health plans and insurers and their agents.  GINA’s group health plan restrictions are scheduled to take effect May 21, 2009.  The employment related genetic testing rules of GINA take affect November 21, 2009.  Employers and other covered entities will need to carefully review and timely update their pandemic and other infectious disease response practices as well as their group health plan, family leave, disability accommodation, and other existing policies in light of these new federal rules.

Although EEOC has not finalized its implementing regulations for GINA yet, employers should anticipate that GINA will impact their pandemic and other related practices.  The implications of GINA for employers and other entities covered by its provisions because of its broad definition of genetic information. 

Under GINA, “genetic information” is defined to mean with respect to any individual, information about:

  • Such individual’s genetic tests;
  • The genetic tests of family members of such individual; and
  • The manifestation of a disease or disorder in family members of such individual.

GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.

Pending issuance of final regulatory guidance, Gina’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of wellness and safety, leave, and other employment and benefit practices, particularly as apparently will reach a broader range of conditions than those currently protected under the disability discrimination prohibitions of the Americans With Disabilities Act (“ADA”).  

Depending on the contemplated inquiry or practice, certain inquiries or actions intended for use as part of an employer’s pandemic preparedness or response activities could fall within the scope of GINA’s protections. For this reason, employers also should consider the potential treatment of a proposed pandemic preparation or response activity intended to be applied after GINA takes effect in light of GINA.  Additionally, employers also should consider the risk that information collected under existing or previously applied pandemic or other infectious disease prevention and response activities might qualify for additional protection when GINA takes effect in November, 2009.

Other Resources

Businesses, health care providers, schools, government agencies and others concerned about preparing to cope with pandemic or other infectious disease challenges also may want to review the following resources authored by Curran Tomko Tarski LLP partner Cynthia Marcotte Stamer:

Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney.  For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the www.cttlegal.com.