California 2019-2020 Regular Session

California Assembly Bill AB648 Compare Versions

OldNewDifferences
1-Amended IN Assembly January 23, 2020 Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019 CALIFORNIA LEGISLATURE 20192020 REGULAR SESSION Assembly Bill No. 648Introduced by Assembly Member NazarianFebruary 15, 2019An act to add Section 1367.13 to the Health and Safety Code, to add Section 10127.6 to the Insurance Code, and to add Section 436 to the Labor Code, relating to wellness programs.LEGISLATIVE COUNSEL'S DIGESTAB 648, as amended, Nazarian. Wellness programs.(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would prohibit health care service plans and insurers from sharing any personal information or data collected through a wellness program, except as specified, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, program, such as requiring a health care service plan or insurer to provide an individual information post a written explanation that is reasonably likely to be understood by an individual on its internet website concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor. retaliation.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information post a written explanation that is reasonably likely to be understood by an employee on its internet website concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose The bill would make a violation of these requirements an infraction, thereby imposing a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES Bill TextThe people of the State of California do enact as follows:SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019. known, and may be cited, as the Wellness Program Protection Act.SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
1+Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019 CALIFORNIA LEGISLATURE 20192020 REGULAR SESSION Assembly Bill No. 648Introduced by Assembly Member NazarianFebruary 15, 2019An act to add Section 1367.13 to the Health and Safety Code, to add Section 10127.6 to the Insurance Code, and to add Section 436 to the Labor Code, relating to wellness programs.LEGISLATIVE COUNSEL'S DIGESTAB 648, as amended, Nazarian. Wellness programs.(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would, among other things, would prohibit health care service plans and insurers from offering an incentive or reward to an enrollee or member, or insured (individual), based on adherence to sharing any personal information or data collected through a wellness program, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, such as requiring a health care service plan or insurer to provide an individual information concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment or offering an incentive or reward to an employee based on adherence to and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES Bill TextThe people of the State of California do enact as follows:SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019.SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
22
3- Amended IN Assembly January 23, 2020 Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019 CALIFORNIA LEGISLATURE 20192020 REGULAR SESSION Assembly Bill No. 648Introduced by Assembly Member NazarianFebruary 15, 2019An act to add Section 1367.13 to the Health and Safety Code, to add Section 10127.6 to the Insurance Code, and to add Section 436 to the Labor Code, relating to wellness programs.LEGISLATIVE COUNSEL'S DIGESTAB 648, as amended, Nazarian. Wellness programs.(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would prohibit health care service plans and insurers from sharing any personal information or data collected through a wellness program, except as specified, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, program, such as requiring a health care service plan or insurer to provide an individual information post a written explanation that is reasonably likely to be understood by an individual on its internet website concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor. retaliation.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information post a written explanation that is reasonably likely to be understood by an employee on its internet website concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose The bill would make a violation of these requirements an infraction, thereby imposing a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES
3+ Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019 CALIFORNIA LEGISLATURE 20192020 REGULAR SESSION Assembly Bill No. 648Introduced by Assembly Member NazarianFebruary 15, 2019An act to add Section 1367.13 to the Health and Safety Code, to add Section 10127.6 to the Insurance Code, and to add Section 436 to the Labor Code, relating to wellness programs.LEGISLATIVE COUNSEL'S DIGESTAB 648, as amended, Nazarian. Wellness programs.(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would, among other things, would prohibit health care service plans and insurers from offering an incentive or reward to an enrollee or member, or insured (individual), based on adherence to sharing any personal information or data collected through a wellness program, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, such as requiring a health care service plan or insurer to provide an individual information concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment or offering an incentive or reward to an employee based on adherence to and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES
44
5- Amended IN Assembly January 23, 2020 Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019
5+ Amended IN Assembly March 28, 2019 Amended IN Assembly March 12, 2019
66
7-Amended IN Assembly January 23, 2020
87 Amended IN Assembly March 28, 2019
98 Amended IN Assembly March 12, 2019
109
1110 CALIFORNIA LEGISLATURE 20192020 REGULAR SESSION
1211
13- Assembly Bill
14-
15-No. 648
12+Assembly Bill No. 648
1613
1714 Introduced by Assembly Member NazarianFebruary 15, 2019
1815
1916 Introduced by Assembly Member Nazarian
2017 February 15, 2019
2118
2219 An act to add Section 1367.13 to the Health and Safety Code, to add Section 10127.6 to the Insurance Code, and to add Section 436 to the Labor Code, relating to wellness programs.
2320
2421 LEGISLATIVE COUNSEL'S DIGEST
2522
2623 ## LEGISLATIVE COUNSEL'S DIGEST
2724
2825 AB 648, as amended, Nazarian. Wellness programs.
2926
30-(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would prohibit health care service plans and insurers from sharing any personal information or data collected through a wellness program, except as specified, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, program, such as requiring a health care service plan or insurer to provide an individual information post a written explanation that is reasonably likely to be understood by an individual on its internet website concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor. retaliation.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information post a written explanation that is reasonably likely to be understood by an employee on its internet website concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose The bill would make a violation of these requirements an infraction, thereby imposing a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.
27+(1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.This bill would, among other things, would prohibit health care service plans and insurers from offering an incentive or reward to an enrollee or member, or insured (individual), based on adherence to sharing any personal information or data collected through a wellness program, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, such as requiring a health care service plan or insurer to provide an individual information concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor.This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment or offering an incentive or reward to an employee based on adherence to and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.Because a willful violation of these requirements would be a crime, the bill would impose a state-mandated local program.(3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.
3128
3229 (1) Existing federal law, the federal Patient Protection and Affordable Care Act (PPACA), enacted various health care coverage market reforms that took effect January 1, 2014. Among other things, PPACA sets forth various requirements related to wellness programs, which encompass programs of health promotion or disease prevention.
3330
3431 Existing law, the Knox-Keene Health Care Service Plan Act of 1975, provides for the licensure and regulation of health care service plans by the Department of Managed Health Care (department) and makes a willful violation of the act a crime. Existing law also provides for the regulation of various insurers by the Department of Insurance, headed by the Insurance Commissioner. Existing law authorizes the director of the department and the commissioner to adopt regulations for purposes of implementing various provisions of law, as specified.
3532
36-This bill would prohibit health care service plans and insurers from sharing any personal information or data collected through a wellness program, except as specified, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, program, such as requiring a health care service plan or insurer to provide an individual information post a written explanation that is reasonably likely to be understood by an individual on its internet website concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.
33+This bill would, among other things, would prohibit health care service plans and insurers from offering an incentive or reward to an enrollee or member, or insured (individual), based on adherence to sharing any personal information or data collected through a wellness program, and would prohibit health care service plans or insurers from taking any adverse action, as defined, against an enrollee or member, or insured (individual), if the action of the health care service plans or insurers is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program. The bill would establish and impose upon health care service plans and insurers various requirements related to a wellness programs, such as requiring a health care service plan or insurer to provide an individual information concerning its policies and practices pertaining to wellness programs, as specified. The bill would require a health care service plan or insurer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an individual to only information that is reasonably necessary to operate a wellness program, and would extend various requirements, to the extent that they are applicable, to any entity that the health care service plan or insurer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would authorize the commissioner to assess penalties on an insurer for any violation of these provisions, as specified. The bill would authorize the director and commissioner to adopt regulations to conform to federal law in the event that the provisions conflict with federal law.
3734
3835 Because a willful violation of these requirements relative to health care service plans would be a crime, the bill would impose a state-mandated local program.
3936
40-(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor. retaliation.
37+(2) Existing law establishes the Division of Labor Standards Enforcement, headed by the Labor Commissioner, within the Department of Industrial Relations, for the purpose of enforcing labor laws, including those relating to employer retaliation, and makes a person who violates specified requirements guilty of a misdemeanor.
4138
42-This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information post a written explanation that is reasonably likely to be understood by an employee on its internet website concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, except as specified, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.
39+This bill would, among other things, prohibit an employer from requiring an employee to participate in a wellness program as a condition of employment or offering an incentive or reward to an employee based on adherence to and would prohibit an employer from taking any adverse action, as defined, against an employee if the action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program. The bill would establish and impose upon an employer various requirements related to a wellness program, such as requiring an employer to provide an employee information concerning its policies and practices pertaining to a wellness program. The bill would require an employer, for purposes of administering and operating a wellness program, to limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary for the programs operation, and would extend various requirements, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on their behalf. The bill would grant an employee various rights in relation to a wellness program, such as obtaining a copy of the employees records, including personal information that has been collected by the employer as part of a wellness program.
4340
44-Because a willful violation of these requirements would be a crime, the bill would impose
45-
46-
47-
48- The bill would make a violation of these requirements an infraction, thereby imposing a state-mandated local program.
41+Because a willful violation of these requirements would be a crime, the bill would impose a state-mandated local program.
4942
5043 (3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.
5144
5245 This bill would provide that no reimbursement is required by this act for a specified reason.
5346
5447 ## Digest Key
5548
5649 ## Bill Text
5750
58-The people of the State of California do enact as follows:SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019. known, and may be cited, as the Wellness Program Protection Act.SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
51+The people of the State of California do enact as follows:SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019.SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
5952
6053 The people of the State of California do enact as follows:
6154
6255 ## The people of the State of California do enact as follows:
6356
64-SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019. known, and may be cited, as the Wellness Program Protection Act.
57+SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019.
6558
66-SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019. known, and may be cited, as the Wellness Program Protection Act.
59+SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019.
6760
68-SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019. known, and may be cited, as the Wellness Program Protection Act.
61+SECTION 1. This act shall be known as, and may be cited as, the Making Wellness Programs Healthy for Consumers Act of 2019.
6962
7063 ### SECTION 1.
7164
72-SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
65+SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
7366
7467 SEC. 2. Section 1367.13 is added to the Health and Safety Code, to read:
7568
7669 ### SEC. 2.
7770
78-1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
71+1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
7972
80-1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
73+1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
8174
82-1367.13. (a) A health care service plan shall not do either of the following:(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e)(1)If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
75+1367.13. (a) A health care service plan shall not do any either of the following:(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.(B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an enrollee or member has the right to do both of the following:(1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.(d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.(e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.(g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the enrollee or member.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
8376
8477
8578
86-1367.13. (a) A health care service plan shall not do either of the following:
79+1367.13. (a) A health care service plan shall not do any either of the following:
80+
81+(1)Offer an incentive or reward to an enrollee or member based on adherence to a wellness program.
82+
83+
84+
85+(2)
86+
87+
8788
8889 (1) Retaliate or take any adverse action against an enrollee or member if the health care service plans action is in response to a matter related to a wellness program, such as an individuals election to not participate in a wellness program or the data collected through the wellness program about the enrollee or member.
90+
91+(3)
92+
93+
8994
9095 (2) Share any personal information or data collected through a wellness program.
9196
9297 (b) (1) (A) A health care service plan that collects personal information of an enrollee or member as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws, including, but not limited to, the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1 of the Civil Code), and the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191).
9398
94-(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an enrollee or member on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.
99+(B) A health care service plan shall provide an enrollee or member a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the rights of the enrollee or member concerning the wellness program under federal and state laws and regulations.
95100
96101 (2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, a health care service plan shall limit its collection, dissemination, retention, and use of any personal information of an enrollee or member to only information that is reasonably necessary to operate the wellness program.
97102
98103 (B) If an enrollee or member terminates their participation in a wellness program, or upon the conclusion of a wellness program, the health care service plan shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.
99104
100105 (c) With respect to a wellness program, an enrollee or member has the right to do both of the following:
101106
102107 (1) Obtain a copy of their records, including personal information that has been collected by the health care service plan, in a format accessible to the individual.
103108
104109 (2) Challenge the completeness and accuracy of any records, including personal information or data, related to the enrollee or member that has been collected by a health care service plan.
105110
106111 (d) A person who willfully violates any provision of this section shall be subject to the enforcement procedures set forth under Article 8 (commencing with Section 1390), and any other sanctions and penalties permitted by law.
107112
108113 (e) (1) If this section conflicts with federal law, the director may adopt regulations to conform to federal law.
109114
110-
111-
112-(2)
113-
114-
115-
116-(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.
115+(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.
117116
118117 (f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the health care service plan contracts with for purposes of administering or operating a wellness program on the health care service plans behalf.
119118
120119 (g) A health care service plan shall not share any personal information about the enrollee or member that is collected through a wellness program with the enrollees or members employer.
121120
122-(h) Notwithstanding paragraph (2) of subdivision (b), a health care service plan may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
123-
124-(i) Notwithstanding paragraph (2) of subdivision (a), a health care service plan may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
125-
126-(j) The provisions of this section do not apply to either of the following:
127-
128-(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.
129-
130-(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.
131-
132-(k) This section does not limit or restrict the disclosure of any personal information by a health care service plan if otherwise required by law.
133-
134-(h)
135-
136-
137-
138-(l) For purposes of this section, the following definitions apply:
121+(h) For purposes of this section, the following definitions apply:
139122
140123 (1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:
141124
142125 (A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.
143126
144127 (B) Executing functions of a wellness program for the benefit of the enrollee or member.
145128
146129 (C) Undertaking internal research for technological development and demonstration related to a wellness program.
147130
148131 (D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the health care service plan related to a wellness program.
149132
150133 (2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an enrollee or member. This includes information that the health care service plan receives from an enrollee or member either directly or indirectly, such as through observation of the enrollee or member.
151134
152-(3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.
135+(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.
153136
154137
155138
156-(A)Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.
139+(4)
157140
158141
159142
143+(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either an enrollee or member or their household.
144+
145+(A) Personal information includes, but is not limited to, an enrollees or members past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.
146+
160147 (B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an enrollee or member.
161-
162-
163148
164149 (ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.
165150
151+(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
166152
167-
168-(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
153+(5)
169154
170155
171156
172157 (4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.
173158
174-
175-
176-(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.
177-
178-(5)
159+(6)
179160
180161
181162
182-(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
163+(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by a health care service plan against an enrollee or member, including increasing a premium, if the health care service plans action is in response to a matter related to a wellness program, such as an enrollee or members election to not participate in a wellness program or the data collected through the wellness program about an enrollee or member.
183164
184-(5) Wellness program means a health care service plan-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
185-
186-SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
165+SEC. 3. Section 10127.6 is added to the Insurance Code, to read:10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
187166
188167 SEC. 3. Section 10127.6 is added to the Insurance Code, to read:
189168
190169 ### SEC. 3.
191170
192-10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
171+10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
193172
194-10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
173+10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
195174
196-10127.6. (a) An insurer shall not do either of the following:(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e)(1)If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2)(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.(h)(l) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior. (3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii)Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(4)Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(5)(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
175+10127.6. (a) An insurer shall not do any either of the following:(1)Offer an incentive or reward to an insured based on adherence to a wellness program.(2)(1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.(3)(2) Share any personal information or data collected through a wellness program.(b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.(2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(c) With respect to a wellness program, an insured has the right to do both of the following:(1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.(d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.(2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.(3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.(e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.(g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.(h) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the insured.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item. (4)(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.(ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)(4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
197176
198177
199178
200-10127.6. (a) An insurer shall not do either of the following:
179+10127.6. (a) An insurer shall not do any either of the following:
180+
181+(1)Offer an incentive or reward to an insured based on adherence to a wellness program.
182+
183+
184+
185+(2)
186+
187+
201188
202189 (1) Retaliate or take any adverse action against an insured if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about the insured.
190+
191+(3)
192+
193+
203194
204195 (2) Share any personal information or data collected through a wellness program.
205196
206197 (b) (1) (A) An insurer that collects personal information of an insured as part of its administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.
207198
208-(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an insured on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.
199+(B) An insurer shall provide an insured a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the insureds rights concerning the wellness program under federal and state laws and regulations.
209200
210201 (2) (A) Notwithstanding any other law, for purposes of administering and operating a wellness program, an insurer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.
211202
212203 (B) If an insured terminates their participation in a wellness program, or upon the conclusion of a wellness program, the insurer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.
213204
214205 (c) With respect to a wellness program, an insured has the right to do both of the following:
215206
216207 (1) Obtain a copy of the insureds records, including personal information that has been collected by the insurer, in a format accessible to the insured.
217208
218209 (2) Challenge the completeness and accuracy of any records, including personal information or data, related to the insured that has been collected by the insurer.
219210
220211 (d) (1) In addition to any other remedy permitted by law, the commissioner may assess the administrative penalties specified in this section against an insurer for a violation of this section.
221212
222213 (2) An insurer that violates this section is liable for an administrative penalty of not more than two thousand five hundred dollars ($2,500) for the first violation and not more than five thousand dollars ($5,000) for each subsequent violation.
223214
224215 (3) An insurer that violates this section with a frequency that indicates a general business practice or commits a knowing violation of that section is liable for an administrative penalty of not less than fifteen thousand dollars ($15,000) and not more than one hundred thousand dollars ($100,000) for each violation.
225216
226217 (e) (1) If this section conflicts with federal law, the commissioner may adopt regulations to conform to federal law.
227218
228-
229-
230-(2)
231-
232-
233-
234-(e) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.
219+(2) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.
235220
236221 (f) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the insurer contracts with for purposes of administering or operating a wellness program on the insurers behalf.
237222
238223 (g) An insurer shall not share any personal information about the insured that is collected through a wellness program with the insureds employer.
239224
240-(h) Notwithstanding paragraph (2) of subdivision (b), an insurer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
241-
242-(i) Notwithstanding paragraph (2) of subdivision (a), an insurer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
243-
244-(j) The provisions of this section do not apply to either of the following:
245-
246-(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.
247-
248-(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.
249-
250-(k) This section does not limit or restrict the disclosure of any personal information by an insurer if otherwise required by law.
251-
252-(h)
253-
254-
255-
256-(l) For purposes of this section, the following definitions apply:
225+(h) For purposes of this section, the following definitions apply:
257226
258227 (1) Administration and operation of a wellness program means, but is not limited to, the use of personal information when reasonably necessary and proportionate to achieve one of the following purposes:
259228
260229 (A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.
261230
262231 (B) Executing functions of a wellness program for the benefit of the insured.
263232
264233 (C) Undertaking internal research for technological development and demonstration related to a wellness program.
265234
266235 (D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the insurer related to a wellness program.
267236
268237 (2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information pertaining to an insured. This includes information that the insurer receives from an insured either directly or indirectly, such as through the observation of an insureds behavior.
269238
270-(3)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.
239+(3)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.
271240
272241
273242
274-(A)Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.
243+(4)
275244
276245
277246
247+(3) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the insured or their household.
248+
249+(A) Personal information includes, but is not limited to, an insureds past, present, or future physical or mental health condition, common identifiers, including a name, address, birth date, social security number, or any other identification number, and protected health information.
250+
278251 (B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an insured.
279-
280-
281252
282253 (ii) Publicly available information means information that is lawfully made available pursuant to federal and state law.
283254
255+(iii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
284256
285-
286-(iii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
257+(5)
287258
288259
289260
290261 (4) Protected health information has the same definition as in Section 160.103 of Title 45 of the Code of Federal Regulations.
291262
292-
293-
294-(3) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.
295-
296-(5)
263+(6)
297264
298265
299266
300-(4) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
267+(5) Retaliatory or adverse action means, but is not limited to, an adverse action taken by an insurer against an insured, including increasing a premium on a policy, if the insurers action is in response to a matter related to a wellness program, such as an insureds election to not participate in a wellness program or the data collected through the wellness program about an insured.
301268
302-(5) Wellness program means an insurer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
303-
304-SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
269+SEC. 4. Section 436 is added to the Labor Code, to read:436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
305270
306271 SEC. 4. Section 436 is added to the Labor Code, to read:
307272
308273 ### SEC. 4.
309274
310-436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
275+436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
311276
312-436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
277+436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
313278
314-436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.(k) The provisions of this section do not apply to either of the following:(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.(i)(m) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B)(i)Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(5)Publicly available information means information that is lawfully made available pursuant to federal and state law.(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.(6)(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
279+436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.(3)(2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.(4)(3) An employer shall not share any personal information or data collected through a wellness program.(b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.(2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.(3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.(d) An employee has the right to do both of the following:(1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.(2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.(e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.(g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.(2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.(h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.(i) For purposes of this section, the following definitions apply:(1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:(A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.(B) Executing functions of a wellness program for the benefit of the employee.(C) Undertaking internal research for technological development and demonstration related to a wellness program.(D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.(2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.(3) Employer means either of the following:(A) Any person who directly employs 50 or more persons to perform services for a wage or salary.(B) The state and any political or civil subdivision of the state, a county, or a city.(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.(5)(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.(B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.(6)(5) Publicly available information means information that is lawfully made available pursuant to federal and state law.(7)(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
315280
316281
317282
318283 436. (a) (1) An employer shall not require an employee to participate in a wellness program as a condition of employment.
319284
285+(2)An employer shall not offer an incentive or reward to an employee based on adherence to a wellness program.
286+
287+
288+
289+(3)
290+
291+
292+
320293 (2) An employer shall not retaliate or take any adverse action against an employee if the employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about the employee.
294+
295+(4)
296+
297+
321298
322299 (3) An employer shall not share any personal information or data collected through a wellness program.
323300
324301 (b) An employer that collects the personal information of an employee as part of the administration and operation of a wellness program shall ensure compliance with state and federal privacy laws.
325302
326-(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, post a written explanation that is reasonably likely to be understood by an employee on its internet website about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.
303+(c) (1) An employer shall provide an employee a written explanation, in clear and easily understandable language, about the basis of the wellness program, a description about the data collection process and which data will be collected through the wellness program, policies and practices pertaining to the wellness program, and the employees rights concerning the wellness program under federal and state laws and regulations.
327304
328305 (2) Notwithstanding any other law, for purposes of administering and operating a wellness program, an employer shall limit its collection, dissemination, retention, and use of any personal information of an employee to only information that is reasonably necessary to operate the wellness program.
329306
330307 (3) If an employee terminates their participation in a wellness program, or upon the conclusion of a wellness program, the employer shall destroy any personal information received or collected through the wellness program, and shall order the destruction of this material.
331308
332309 (d) An employee has the right to do both of the following:
333310
334311 (1) Obtain a copy of the employees records, including personal information that has been collected by the employer, pertaining to a wellness program, in a format accessible to the employee.
335312
336313 (2) Challenge the completeness and accuracy of any records, including personal information or data, related to the employee that has been collected by the employer as part of a wellness program.
337314
338315 (e) Any person who believes that they have been discharged or otherwise discriminated against in violation of this section may file a complaint with the division within six months after the occurrence of the violation pursuant to Section 98.7.
339316
340-(f) Any Notwithstanding Section 433, a person who violates this section is guilty of a misdemeanor pursuant to Section 433. an infraction.
317+(f) Any person who violates this section is guilty of a misdemeanor pursuant to Section 433.
341318
342319 (g) (1) The requirements described in this section shall apply, to the extent that they are applicable, to any entity that the employer contracts with for purposes of administering or operating a wellness program on the employers behalf.
343320
344321 (2) The entity specified in paragraph (1) shall not share any personal information about the employee that is collected through a wellness program with the employer.
345322
346323 (h) The provisions of this section are severable. If any provision of this section or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.
347324
348-(i) Notwithstanding paragraphs (2) and (3) of subdivision (c), an employer may retain publicly available information or deidentified and aggregated information that is collected through a wellness program if this data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
349-
350-(j) Notwithstanding paragraph (3) of subdivision (a), an employer may share data that is collected through a wellness program with a third party if the data is either publicly available information or deidentified and aggregated information, and the data would be used for the purpose of conducting bona fide research relating to health care utilization and outcomes.
351-
352-(k) The provisions of this section do not apply to either of the following:
353-
354-(1) Any wellness program for licensed health care professionals administered or operated by a professional association or its affiliates or subsidiaries.
355-
356-(2) The personal information or data collected by a professional association or its affiliates or subsidiaries in relation to, or in support of, the administration or operation of a wellness program for licensed health care professionals.
357-
358-(l) This section does not limit or restrict the disclosure of any personal information by an employer if otherwise required by law.
359-
360-(i)
361-
362-
363-
364-(m) For purposes of this section, the following definitions apply:
325+(i) For purposes of this section, the following definitions apply:
365326
366327 (1) Administration and operation of a wellness program means, but is not limited to, the use of personal information, including health information, when reasonably necessary and proportionate to achieve one of the following purposes:
367328
368329 (A) Detecting and responding to security incidents arising from a wellness program and protecting against malicious, deceptive, fraudulent, or illegal activity related to a wellness program.
369330
370331 (B) Executing functions of a wellness program for the benefit of the employee.
371332
372333 (C) Undertaking internal research for technological development and demonstration related to a wellness program.
373334
374335 (D) Undertaking activities to verify or maintain the quality or safety of a service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, or to improve, upgrade, or enhance the service or device that is owned by, manufactured by, manufactured for, or controlled by the employer, related to a wellness program.
375336
376337 (2) Collects, collected, or collection means buying, renting, gathering, obtaining, receiving, or accessing, by any means, any personal information, including health information, pertaining to an employee. This includes information that the employer receives either directly or indirectly, such as through observation of the employee.
377338
378339 (3) Employer means either of the following:
379340
380341 (A) Any person who directly employs 50 or more persons to perform services for a wage or salary.
381342
382343 (B) The state and any political or civil subdivision of the state, a county, or a city.
383344
384-(4)Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.
345+(4)Incentive means, but is not limited to, a discounted premium, cash reward, or other tangible item.
385346
386347
387348
388-(A)Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.
349+(5)
389350
390351
391352
353+(4) Personal information means information that identifies or could reasonably be linked, directly or indirectly, with either the employee or their household.
354+
355+(A) Personal information includes, but is not limited to, an employees past, present, or future physical or mental health condition, and common identifiers, including a name, address, birth date, social security number, or any other identification number.
356+
392357 (B) (i) Personal information excludes any publicly available information, and excludes any deidentified or aggregate information about an employee.
393358
359+(ii) For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
394360
395-
396-(ii)For purposes of this section, the deidentification of personal information shall meet the requirements set forth in Section 164.514 of Title 45 of the Code of Federal Regulations.
361+(6)
397362
398363
399364
400365 (5) Publicly available information means information that is lawfully made available pursuant to federal and state law.
401366
402-
403-
404-(4) Personal information shall have the same meaning as defined in subdivision (o) of Section 1798.140 of the Civil Code.
405-
406-(6)
367+(7)
407368
408369
409370
410-(5) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
411-
412-(6) Wellness program means an employer-based program aimed at promoting health-related behaviors and disease prevention. A wellness program excludes care coordination by or between health care providers in the practice of medicine.
371+(6) Retaliatory or adverse action means, but is not limited to, an adverse employment action taken by an employer against an employee, including termination, fine, or suspension, if an employers action is in response to a matter related to a wellness program, such as an employees election to not participate in a wellness program or the data collected through the wellness program about an employee.
413372
414373 SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
415374
416375 SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
417376
418377 SEC. 5. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
419378
420379 ### SEC. 5.