Legal
Who Can Legally Perform Body Sculpting?
By Clint L. Nuckolls, JD, ByrdAdatto Body sculpting, also known as body contouring, has surged in popularity as individuals ...
Posted By Kate Harper, Wednesday, August 1, 2018
By Brad Adatto, JD, Partner, ByrdAdatto
Med spas and other aesthetic practices should be aware of the new California Consumer Privacy Act of 2018 recently passed and signed into law. With seemingly daily reports of data breaches or improper sharing of user data, consumer privacy is a growing concern. California is the latest State to take action to protect consumers' personal information and has passed a law that provides strong and broad protections to do so. Signed into law on June the 28, 2018, the California Consumer Privacy Act of 2018 ("Privacy Act") creates some of the strongest consumer privacy protections in the nation.
The Privacy Act creates a right for consumers to
These protections in turn create numerous compliance, notice, and penalty issues for businesses who collect information from California residents.
Businesses subject to the Privacy Act will need to provide proper notice of the types of information collected and the rights of the consumer under the act before any information is collected. Businesses also will need to ensure that their data collection and use practices involve only the types of information and uses that have been properly disclosed to the affected consumer.
Additionally, businesses will need to have trained personal to accept, verify, and respond to consumer requests within the statutory deadlines. And finally, businesses subject to the Privacy Act will need to have data systems capable of securely storing the information while providing for rapid and accurate access for requests, and to delete the information if requested.
Medical businesses who are covered under the Health Insurance Portability and Accountability Act ("HIPAA") or California's Confidentiality of Medical Information Act ("CMIA") have additional hurdles to overcome. The Privacy Act exempts "protected" or "health information" that is already covered under the prior laws. However, medical businesses will need to determine what information they have and comply with the Privacy Act for other types of information not covered by HIPAA or CMIA.
The safe and accurate handling of information and consumer requests will be critical to medical practices in particular as the Privacy Act creates substantial penalties for failure to maintain compliance, mishandling of information, and failure to respond appropriately to consumer requests. Luckily medical practices in California have some time to learn more about what is covered before being subjected to penalties, as the Privacy Act is slated to take effect on January 1, 2020.
Read the full text of the law here. If you have concerns on how the California Consumer Privacy Act of 2018 may impact your business consult a healthcare attorney familiar with California law.
AmSpa members may take advantage of their annual compliance consultation with the business, healthcare, and aesthetic law firm of ByrdAdatto. Become a member today to gain access to business and legal compliance tools to keep your practice profitable and on the right side of regulations.
Brad Adatto, JD, is a partner at ByrdAdatto, a business, healthcare, and aesthetic law firm that practices across the country. He has worked with physicians, physician groups, and other medical service providers in developing ambulatory surgical centers, in-office and freestanding ancillary service facilities, and other medical joint ventures. He regularly counsels clients with respect to federal and state health care regulations that impact investments, transactions, and contract terms, including Medicare fraud and abuse, anti-trust, anti-kickback, anti-referral, and private securities laws.
Related Tags
Medical spa news, blogs and updates sent directly to your inbox.
Legal
By Clint L. Nuckolls, JD, ByrdAdatto Body sculpting, also known as body contouring, has surged in popularity as individuals ...
Legal
By Eric Atienza, Assistant Director of Digital Marketing Technology, American Med Spa Association (AmSpa) Most platforms like Facebook, Instagram ...
Legal
By Eric Atienza, Assistant Director of Digital Marketing and Marketing Technology, American Med Spa Association (AmSpa) (UPDATE 10/14/24: In ...
Legal
By Patrick O’Brien, JD, General Counsel, American Med Spa Association (AmSpa) The Federal Trade Commission’s (FTC’s) rule that would ...