Hawaii 2025 Regular Session

Hawaii House Bill HR194 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 HOUSE OF REPRESENTATIVES H.R. NO. 194 THIRTY-THIRD LEGISLATURE, 2025 STATE OF HAWAII HOUSE RESOLUTION strongly supporting and recommending the implementation of the revised 2025 hawaii patient bill of rights.
22
33 HOUSE OF REPRESENTATIVES H.R. NO. 194
44 THIRTY-THIRD LEGISLATURE, 2025
55 STATE OF HAWAII
66
77 HOUSE OF REPRESENTATIVES
88
99 H.R. NO.
1010
1111 194
1212
1313 THIRTY-THIRD LEGISLATURE, 2025
1414
1515
1616
1717 STATE OF HAWAII
1818
1919
2020
2121
2222
2323
2424
2525
2626
2727
2828
2929 HOUSE RESOLUTION
3030
3131
3232
3333
3434
3535 strongly supporting and recommending the implementation of the revised 2025 hawaii patient bill of rights.
3636
3737
3838
3939
4040
4141
4242
4343 WHEREAS, Hawaii pioneered employer-supported health insurance through the Prepaid Health Care Act of 1974; however, the State continues to face severe physician, nurse, and dentist shortages, with over thirty-five percent of the population residing in federally designated Health Professional Shortage Areas--the highest percentage in the nation; and WHEREAS, the University of Hawaii Health Research Center found that forty-two percent of surveyed physicians reported patient harm or serious adverse events attributable to prior authorization delays or denials, emphasizing a need for streamlined insurance processes; and WHEREAS, recent increases in claims denials, particularly those driven by automated or artificial intelligence (AI)-based systems, underscore the necessity for greater transparency, specialist review, and patient-friendly appeals mechanisms; and WHEREAS, the original Hawaii Patient Bill of Rights, enacted over twenty-five years ago, now requires substantial updates to address modern challenges, such as AI-driven denials, telehealth accessibility, data-offshoring risks, and persistent network inadequacies on the neighbor islands and in rural areas; and WHEREAS, patients, health care providers, and cybersecurity experts cite the need for robust data protection measures that accommodate legitimate offshoring services while maintaining Health Insurance Portability and Accountability Act-equivalent safeguards, timely breach notifications, and strong enforcement; and WHEREAS, the Insurance Commissioner's office needs expanded authority, resources, and reporting mechanisms to effectively audit, investigate, and sanction noncompliant insurers or billing entities, ensuring consistent and accountable enforcement of patients' rights; and WHEREAS, the Revised 2025 Hawaii Patient Bill of Rights is an essential modernization step that prioritizes patient autonomy, transparent healthcare, timely access, robust data protection, AI accountability, and real enforcement--all while recognizing the practical realities of insurers, providers, and patients in a rapidly evolving healthcare landscape; now, therefore, BE IT RESOLVED by the House of Representatives of the Thirty-third Legislature of the State of Hawaii, Regular Session of 2025, that this body strongly supports and recommends the implementation of the following Revised 2025 Hawaii Patient Bill of Rights: Foreword and Definitions 1. Purpose: This Bill of Rights modernizes patient protections to address AI-based coverage decisions, data security risks, and ongoing provider shortages in Hawaii. 2. Definitions: o AI or Automated Decision System: Any algorithmic or software-based platform that can autonomously generate or recommend coverage determinations without direct human supervision. o HIPAA-equivalent Security: A standard of data protection meeting or exceeding requirements set forth in 45 C.F.R. Parts 160 and 164 (HIPAA Privacy and Security Rules). o Urgent vs. Non-Urgent: Urgent requests are those where delays could seriously jeopardize a patient's health, life, or overall well-being; non-urgent requests include all other prior authorizations not qualifying as urgent. 1. Clear Information Patients must receive clear, written (and, if necessary, translated) explanations from their health insurance plan regarding covered and non-covered services, presented at a reading level understandable to the average enrollee. 2. Provider Directory All insurers must maintain and publicly post an up-to-date, accurate, and easily accessible directory of in-network providers, updated at least quarterly, listing each provider's specialty, languages spoken, telehealth availability, and current patient capacity. 3. Specialist Referrals All patients must be able to obtain timely specialist referrals without undue administrative barriers or delays. Insurers shall clearly communicate referral steps and expedite such referrals in urgent or complex cases. 4. Emergency Care No insurer may deny coverage for legitimate emergency services based on retrospective review. If a patient believes in good faith that their life or health is endangered, they have the right to seek immediate emergency care without facing post-service coverage denials. 5. Explanation of Illness, Options, and Patient Autonomy 5.1 Right to Understand Care: Patients are entitled to a clear explanation of their diagnosis, treatment options (including the option to decline treatment), and potential outcomes or risks from their healthcare provider, ensuring fully informed consent. 5.2 Right to Accept or Decline Treatment: Every mentally competent patient (or as decided by their legal health care proxy) has the right to accept, receive, reject, or discontinue any legal medical care, treatment, or prescribed medication from any legally licensed medical provider, and the right to not have that decision denied, prevented, restricted, or impeded by other persons. 6. Appeals and External Review 6.1 Notice and Forms: Whenever coverage is denied, insurers must provide a universal external review request form and a step-by-step guide (in print or digital form) explaining how to appeal. 6.2 Online FAQ and Hotline: Insurers shall maintain an online FAQ regarding appeals, alongside a toll-free hotline to assist patients. 6.3 Enforcement: The Insurance Commissioner may impose financial penalties or other administrative measures on insurers failing to publicize or comply with state and federal appeals requirements. 7. Network Adequacy, Telehealth, and Rural Access 7.1 Coverage in Shortage Areas: Patients in federally designated Health Professional Shortage Areas must have timely access to primary and specialty care. 7.2 Reporting Requirements: Insurers shall submit quarterly reports detailing provider-to-patient ratios, average wait times, and referral outcomesdisaggregated by region or island. 7.3 Telehealth Provisions: Telehealth services, if legally permissible within a provider's scope of practice, shall be covered at parity with in-person services to mitigate access barriers. 7.4. Prohibition of Burdensome Prior Authorization: Prior authorization procedures in shortage areas must not unduly limit provider productivity or delay critical patient care. 8. Transparent and Timely Prior Authorization 8.1 Turnaround Times: o Urgent Requests: One business day for a decision. o Non-Urgent Requests: Three business days for a decision. 8.2 AI Oversight: o If AI or an automated decision system initiates a denial, that denial must be reviewed and co-signed by a board-certified specialist in the relevant field before being finalized. o Patients and providers shall be notified in writing when AI is used at any stage of the coverage determination. 8.3 Data Tracking: Insurers must compile and submit monthly data on prior authorization approval/denial rates, average processing times, and the percentage of AI-based denials overturned on appeal. 9. Data Protection and Privacy 9.1 HIPAA-equivalent Safeguards: All accredited health plans or billing entities, whether located onshore or offshore, must uphold HIPAA-level security measures when storing or transmitting personally identifiable patient data (including Social Security numbers, medical ID numbers, etc.). 9.2 Offshoring Accountability: o Prior to offshoring data, an entity must file an attestation with the Insurance Commissioner confirming that any overseas subcontractors adhere to encryption, breach notification, audit logging, and confidentiality protocols. o Entities shall undergo random audits or produce security certifications upon request. 9.3 Breach Notification and Penalties: In the event of a suspected or actual data breach, the entity must notify affected patients and the Insurance Commissioner within 72 hours, implementing a corrective action plan. Repeated or willful violations may result in fines, revocation of accreditation, or other sanctions. 10. Enforcement and Oversight 10.1 Authority of the Insurance Commissioner: o Empowered to audit, investigate, and enforce all provisions of this Bill of Rights. o May impose fines, clawbacks, revocation of accreditation, and other appropriate remedies for noncompliance. 10.2 Annual Public Report: o The Insurance Commissioner shall publish an annual report detailing enforcement actions, complaint data, AI usage rates, denial statistics, and any data breaches or security infractions. o The report shall include trend analyses (e.g., median time-to-decision for prior authorizations, telehealth adoption rates, network adequacy improvements). 10.3 Multidisciplinary Advisory Group: o Composed of physicians, cybersecurity experts, patient advocates, telehealth specialists, and others. o Convenes periodically to review compliance, recommend updates, and study emerging issues (e.g., advanced AI, new data-security threats). 11. Anti-Retaliation and Support for Providers 11.1 Anti-Retaliation: Insurers, health plans, or affiliated entities shall not retaliate against providers (e.g., network exclusion or contract termination) for filing formal complaints, submitting testimony, or participating in external reviews concerning the insurer's compliance with this Bill of Rights. 11.2 Technical Assistance: The Insurance Commissioner, in collaboration with the Department of Health, shall explore or establish technical support programs to help smaller or rural practices adopt secure data systems, comply with prior authorization reporting, and integrate telehealth services effectively. 12. Phased Implementation 12.1 Immediate Effect: Provisions related to patient communications (Items 1 to 6), emergency care, and urgent prior authorizations (Item 8.1) shall take effect immediately upon enactment. 12.2 Data Offshoring and AI Protocols: Insurers may have six to twelve months from the date of enactment to fully implement or certify AI oversight processes and offshore data security compliance (excluding Social Security numbers and medical ID numbers, which must be protected immediately). 12.3 Follow-up Review: Within one year of implementation, the Insurance Commissioner shall submit a progress report to the Legislature with recommendations for any further legislative refinements.; and BE IT FURTHER RESOLVED that all insurers, health care providers, and billing entities are strongly encouraged to begin voluntary compliance with these updated patient protections prior to any mandatory deadlines in order to foster a collaborative and smooth transition; and BE IT FURTHER RESOLVED that ongoing stakeholder input will be sought to address outstanding issues, such as payment parity, facility fees, and self-insured plan coverage, which may require additional state or federal action; and BE IT FURTHER RESOLVED that certified copies of this Resolution be transmitted to the Governor, Director of Health, Director of Commerce and Consumer Affairs, and Insurance Commissioner. OFFERED BY: _____________________________
4444
4545 WHEREAS, Hawaii pioneered employer-supported health insurance through the Prepaid Health Care Act of 1974; however, the State continues to face severe physician, nurse, and dentist shortages, with over thirty-five percent of the population residing in federally designated Health Professional Shortage Areas--the highest percentage in the nation; and
4646
4747
4848
4949 WHEREAS, the University of Hawaii Health Research Center found that forty-two percent of surveyed physicians reported patient harm or serious adverse events attributable to prior authorization delays or denials, emphasizing a need for streamlined insurance processes; and
5050
5151
5252
5353 WHEREAS, recent increases in claims denials, particularly those driven by automated or artificial intelligence (AI)-based systems, underscore the necessity for greater transparency, specialist review, and patient-friendly appeals mechanisms; and
5454
5555
5656
5757 WHEREAS, the original Hawaii Patient Bill of Rights, enacted over twenty-five years ago, now requires substantial updates to address modern challenges, such as AI-driven denials, telehealth accessibility, data-offshoring risks, and persistent network inadequacies on the neighbor islands and in rural areas; and
5858
5959
6060
6161 WHEREAS, patients, health care providers, and cybersecurity experts cite the need for robust data protection measures that accommodate legitimate offshoring services while maintaining Health Insurance Portability and Accountability Act-equivalent safeguards, timely breach notifications, and strong enforcement; and
6262
6363
6464
6565 WHEREAS, the Insurance Commissioner's office needs expanded authority, resources, and reporting mechanisms to effectively audit, investigate, and sanction noncompliant insurers or billing entities, ensuring consistent and accountable enforcement of patients' rights; and
6666
6767
6868
6969 WHEREAS, the Revised 2025 Hawaii Patient Bill of Rights is an essential modernization step that prioritizes patient autonomy, transparent healthcare, timely access, robust data protection, AI accountability, and real enforcement--all while recognizing the practical realities of insurers, providers, and patients in a rapidly evolving healthcare landscape; now, therefore,
7070
7171
7272
7373 BE IT RESOLVED by the House of Representatives of the Thirty-third Legislature of the State of Hawaii, Regular Session of 2025, that this body strongly supports and recommends the implementation of the following Revised 2025 Hawaii Patient Bill of Rights:
7474
7575
7676
7777 Foreword and Definitions
7878
7979
8080
8181 1. Purpose: This Bill of Rights modernizes patient protections to address AI-based coverage decisions, data security risks, and ongoing provider shortages in Hawaii.
8282
8383
8484
8585 2. Definitions:
8686
8787
8888
8989 o AI or Automated Decision System: Any algorithmic or software-based platform that can autonomously generate or recommend coverage determinations without direct human supervision.
9090
9191 o HIPAA-equivalent Security: A standard of data protection meeting or exceeding requirements set forth in 45 C.F.R. Parts 160 and 164 (HIPAA Privacy and Security Rules).
9292
9393 o Urgent vs. Non-Urgent: Urgent requests are those where delays could seriously jeopardize a patient's health, life, or overall well-being; non-urgent requests include all other prior authorizations not qualifying as urgent.
9494
9595
9696
9797
9898
9999
100100
101101 1. Clear Information
102102
103103
104104
105105 Patients must receive clear, written (and, if necessary, translated) explanations from their health insurance plan regarding covered and non-covered services, presented at a reading level understandable to the average enrollee.
106106
107107
108108
109109
110110
111111
112112
113113 2. Provider Directory
114114
115115
116116
117117 All insurers must maintain and publicly post an up-to-date, accurate, and easily accessible directory of in-network providers, updated at least quarterly, listing each provider's specialty, languages spoken, telehealth availability, and current patient capacity.
118118
119119
120120
121121
122122
123123
124124
125125 3. Specialist Referrals
126126
127127
128128
129129 All patients must be able to obtain timely specialist referrals without undue administrative barriers or delays. Insurers shall clearly communicate referral steps and expedite such referrals in urgent or complex cases.
130130
131131
132132
133133
134134
135135
136136
137137 4. Emergency Care
138138
139139
140140
141141 No insurer may deny coverage for legitimate emergency services based on retrospective review. If a patient believes in good faith that their life or health is endangered, they have the right to seek immediate emergency care without facing post-service coverage denials.
142142
143143
144144
145145
146146
147147
148148
149149 5. Explanation of Illness, Options, and Patient Autonomy
150150
151151
152152
153153 5.1 Right to Understand Care: Patients are entitled to a clear explanation of their diagnosis, treatment options (including the option to decline treatment), and potential outcomes or risks from their healthcare provider, ensuring fully informed consent.
154154
155155
156156
157157 5.2 Right to Accept or Decline Treatment: Every mentally competent patient (or as decided by their legal health care proxy) has the right to accept, receive, reject, or discontinue any legal medical care, treatment, or prescribed medication from any legally licensed medical provider, and the right to not have that decision denied, prevented, restricted, or impeded by other persons.
158158
159159
160160
161161
162162
163163
164164
165165 6. Appeals and External Review
166166
167167
168168
169169 6.1 Notice and Forms: Whenever coverage is denied, insurers must provide a universal external review request form and a step-by-step guide (in print or digital form) explaining how to appeal.
170170
171171
172172
173173 6.2 Online FAQ and Hotline: Insurers shall maintain an online FAQ regarding appeals, alongside a toll-free hotline to assist patients.
174174
175175
176176
177177 6.3 Enforcement: The Insurance Commissioner may impose financial penalties or other administrative measures on insurers failing to publicize or comply with state and federal appeals requirements.
178178
179179
180180
181181
182182
183183
184184
185185 7. Network Adequacy, Telehealth, and Rural Access
186186
187187
188188
189189 7.1 Coverage in Shortage Areas: Patients in federally designated Health Professional Shortage Areas must have timely access to primary and specialty care.
190190
191191
192192
193193 7.2 Reporting Requirements: Insurers shall submit quarterly reports detailing provider-to-patient ratios, average wait times, and referral outcomesdisaggregated by region or island.
194194
195195
196196
197197 7.3 Telehealth Provisions: Telehealth services, if legally permissible within a provider's scope of practice, shall be covered at parity with in-person services to mitigate access barriers.
198198
199199
200200
201201 7.4. Prohibition of Burdensome Prior Authorization: Prior authorization procedures in shortage areas must not unduly limit provider productivity or delay critical patient care.
202202
203203
204204
205205
206206
207207
208208
209209 8. Transparent and Timely Prior Authorization
210210
211211
212212
213213 8.1 Turnaround Times:
214214
215215
216216
217217 o Urgent Requests: One business day for a decision.
218218
219219 o Non-Urgent Requests: Three business days for a decision.
220220
221221
222222
223223 8.2 AI Oversight:
224224
225225
226226
227227 o If AI or an automated decision system initiates a denial, that denial must be reviewed and co-signed by a board-certified specialist in the relevant field before being finalized.
228228
229229 o Patients and providers shall be notified in writing when AI is used at any stage of the coverage determination.
230230
231231
232232
233233 8.3 Data Tracking: Insurers must compile and submit monthly data on prior authorization approval/denial rates, average processing times, and the percentage of AI-based denials overturned on appeal.
234234
235235
236236
237237
238238
239239
240240
241241 9. Data Protection and Privacy
242242
243243
244244
245245 9.1 HIPAA-equivalent Safeguards: All accredited health plans or billing entities, whether located onshore or offshore, must uphold HIPAA-level security measures when storing or transmitting personally identifiable patient data (including Social Security numbers, medical ID numbers, etc.).
246246
247247
248248
249249 9.2 Offshoring Accountability:
250250
251251 o Prior to offshoring data, an entity must file an attestation with the Insurance Commissioner confirming that any overseas subcontractors adhere to encryption, breach notification, audit logging, and confidentiality protocols.
252252
253253 o Entities shall undergo random audits or produce security certifications upon request.
254254
255255
256256
257257 9.3 Breach Notification and Penalties: In the event of a suspected or actual data breach, the entity must notify affected patients and the Insurance Commissioner within 72 hours, implementing a corrective action plan. Repeated or willful violations may result in fines, revocation of accreditation, or other sanctions.
258258
259259
260260
261261
262262
263263
264264
265265 10. Enforcement and Oversight
266266
267267
268268
269269 10.1 Authority of the Insurance Commissioner:
270270
271271 o Empowered to audit, investigate, and enforce all provisions of this Bill of Rights.
272272
273273 o May impose fines, clawbacks, revocation of accreditation, and other appropriate remedies for noncompliance.
274274
275275
276276
277277 10.2 Annual Public Report:
278278
279279 o The Insurance Commissioner shall publish an annual report detailing enforcement actions, complaint data, AI usage rates, denial statistics, and any data breaches or security infractions.
280280
281281 o The report shall include trend analyses (e.g., median time-to-decision for prior authorizations, telehealth adoption rates, network adequacy improvements).
282282
283283
284284
285285 10.3 Multidisciplinary Advisory Group:
286286
287287 o Composed of physicians, cybersecurity experts, patient advocates, telehealth specialists, and others.
288288
289289 o Convenes periodically to review compliance, recommend updates, and study emerging issues (e.g., advanced AI, new data-security threats).
290290
291291
292292
293293
294294
295295
296296
297297 11. Anti-Retaliation and Support for Providers
298298
299299
300300
301301 11.1 Anti-Retaliation: Insurers, health plans, or affiliated entities shall not retaliate against providers (e.g., network exclusion or contract termination) for filing formal complaints, submitting testimony, or participating in external reviews concerning the insurer's compliance with this Bill of Rights.
302302
303303
304304
305305 11.2 Technical Assistance: The Insurance Commissioner, in collaboration with the Department of Health, shall explore or establish technical support programs to help smaller or rural practices adopt secure data systems, comply with prior authorization reporting, and integrate telehealth services effectively.
306306
307307
308308
309309
310310
311311
312312
313313 12. Phased Implementation
314314
315315
316316
317317 12.1 Immediate Effect: Provisions related to patient communications (Items 1 to 6), emergency care, and urgent prior authorizations (Item 8.1) shall take effect immediately upon enactment.
318318
319319
320320
321321 12.2 Data Offshoring and AI Protocols: Insurers may have six to twelve months from the date of enactment to fully implement or certify AI oversight processes and offshore data security compliance (excluding Social Security numbers and medical ID numbers, which must be protected immediately).
322322
323323
324324
325325 12.3 Follow-up Review: Within one year of implementation, the Insurance Commissioner shall submit a progress report to the Legislature with recommendations for any further legislative refinements.; and
326326
327327
328328
329329 BE IT FURTHER RESOLVED that all insurers, health care providers, and billing entities are strongly encouraged to begin voluntary compliance with these updated patient protections prior to any mandatory deadlines in order to foster a collaborative and smooth transition; and
330330
331331
332332
333333 BE IT FURTHER RESOLVED that ongoing stakeholder input will be sought to address outstanding issues, such as payment parity, facility fees, and self-insured plan coverage, which may require additional state or federal action; and
334334
335335
336336
337337 BE IT FURTHER RESOLVED that certified copies of this Resolution be transmitted to the Governor, Director of Health, Director of Commerce and Consumer Affairs, and Insurance Commissioner.
338338
339339
340340
341341
342342
343343
344344
345345 OFFERED BY: _____________________________
346346
347347
348348
349349 OFFERED BY:
350350
351351 _____________________________
352352
353353
354354
355355
356356
357357
358358
359359 Report Title: Revised 2025 Hawaii Patient Bill of Rights
360360
361361 Report Title:
362362
363363 Revised 2025 Hawaii Patient Bill of Rights