Hawaii 2025 Regular Session

Hawaii Senate Bill SCR45 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 THE SENATE S.C.R. NO. 45 THIRTY-THIRD LEGISLATURE, 2025 STATE OF HAWAII SENATE CONCURRENT RESOLUTION strongly supporting and recommending the implementation of the revised 2025 hawaii patient bill of rights.
22
33 THE SENATE S.C.R. NO. 45
44 THIRTY-THIRD LEGISLATURE, 2025
55 STATE OF HAWAII
66
77 THE SENATE
88
99 S.C.R. NO.
1010
1111 45
1212
1313 THIRTY-THIRD LEGISLATURE, 2025
1414
1515
1616
1717 STATE OF HAWAII
1818
1919
2020
2121
2222
2323
2424
2525
2626
2727
2828
2929 SENATE CONCURRENT
3030
3131 RESOLUTION
3232
3333
3434
3535
3636
3737 strongly supporting and recommending the implementation of the revised 2025 hawaii patient bill of rights.
3838
3939
4040
4141
4242
4343
4444
4545 WHEREAS, Hawaii pioneered employer-supported health insurance through the Prepaid Health Care Act of 1974; however, the State continues to face severe physician, nurse, and dentist shortages, with over thirty-five percent of the population residing in federally designated Health Professional Shortage Areas--the highest percentage in the nation; and WHEREAS, the University of Hawaii Health Research Center found that forty-two percent of surveyed physicians reported patient harm or serious adverse events attributable to prior authorization delays or denials, emphasizing a need for streamlined insurance processes; and WHEREAS, recent increases in claims denials, particularly those driven by automated or artificial intelligence (AI)-based systems, underscore the necessity for greater transparency, specialist review, and patient-friendly appeals mechanisms; and WHEREAS, the original Hawaii Patient Bill of Rights, enacted over twenty-five years ago, now requires substantial updates to address modern challenges, such as AI-driven denials, telehealth accessibility, data-offshoring risks, and persistent network inadequacies on the neighbor islands and in rural areas; and WHEREAS, patients, health care providers, and cybersecurity experts cite the need for robust data protection measures that accommodate legitimate offshoring services while maintaining Health Insurance Portability and Accountability Act-equivalent safeguards, timely breach notifications, and strong enforcement; and WHEREAS, the Insurance Commissioner's office needs expanded authority, resources, and reporting mechanisms to effectively audit, investigate, and sanction noncompliant insurers or billing entities, ensuring consistent and accountable enforcement of patients' rights; and WHEREAS, the Revised 2025 Hawaii Patient Bill of Rights is an essential modernization step that prioritizes patient autonomy, transparent healthcare, timely access, robust data protection, AI accountability, and real enforcement--all while recognizing the practical realities of insurers, providers, and patients in a rapidly evolving healthcare landscape; now, therefore, BE IT RESOLVED by the Senate of the Thirty-third Legislature of the State of Hawaii, Regular Session of 2025, the House of Representatives concurring, that this body strongly supports and recommends the implementation of the following Revised 2025 Hawaii Patient Bill of Rights: Foreword and Definitions 1. Purpose: This Bill of Rights modernizes patient protections to address AI-based coverage decisions, data security risks, and ongoing provider shortages in Hawaii. 2. Definitions: o AI or Automated Decision System: Any algorithmic or software-based platform that can autonomously generate or recommend coverage determinations without direct human supervision. o HIPAA-equivalent Security: A standard of data protection meeting or exceeding requirements set forth in 45 C.F.R. Parts 160 and 164 (HIPAA Privacy and Security Rules). o Urgent vs. Non-Urgent: Urgent requests are those where delays could seriously jeopardize a patient's health, life, or overall well-being; non-urgent requests include all other prior authorizations not qualifying as urgent. 1. Clear Information Patients must receive clear, written (and, if necessary, translated) explanations from their health insurance plan regarding covered and non-covered services, presented at a reading level understandable to the average enrollee. 2. Provider Directory All insurers must maintain and publicly post an up-to-date, accurate, and easily accessible directory of in-network providers, updated at least quarterly, listing each provider's specialty, languages spoken, telehealth availability, and current patient capacity. 3. Specialist Referrals All patients must be able to obtain timely specialist referrals without undue administrative barriers or delays. Insurers shall clearly communicate referral steps and expedite such referrals in urgent or complex cases. 4. Emergency Care No insurer may deny coverage for legitimate emergency services based on retrospective review. If a patient believes in good faith that their life or health is endangered, they have the right to seek immediate emergency care without facing post-service coverage denials. 5. Explanation of Illness, Options, and Patient Autonomy 5.1 Right to Understand Care: Patients are entitled to a clear explanation of their diagnosis, treatment options (including the option to decline treatment), and potential outcomes or risks from their healthcare provider, ensuring fully informed consent. 5.2 Right to Accept or Decline Treatment: Every mentally competent patient (or as decided by their legal health care proxy) has the right to accept, receive, reject, or discontinue any legal medical care, treatment, or prescribed medication from any legally licensed medical provider, and the right to not have that decision denied, prevented, restricted, or impeded by other persons. 6. Appeals and External Review 6.1 Notice and Forms: Whenever coverage is denied, insurers must provide a universal external review request form and a step-by-step guide (in print or digital form) explaining how to appeal. 6.2 Online FAQ and Hotline: Insurers shall maintain an online FAQ regarding appeals, alongside a toll-free hotline to assist patients. 6.3 Enforcement: The Insurance Commissioner may impose financial penalties or other administrative measures on insurers failing to publicize or comply with state and federal appeals requirements. 7. Network Adequacy, Telehealth, and Rural Access 7.1 Coverage in Shortage Areas: Patients in federally designated Health Professional Shortage Areas must have timely access to primary and specialty care. 7.2 Reporting Requirements: Insurers shall submit quarterly reports detailing provider-to-patient ratios, average wait times, and referral outcomesdisaggregated by region or island. 7.3 Telehealth Provisions: Telehealth services, if legally permissible within a provider's scope of practice, shall be covered at parity with in-person services to mitigate access barriers. 7.4. Prohibition of Burdensome Prior Authorization: Prior authorization procedures in shortage areas must not unduly limit provider productivity or delay critical patient care. 8. Transparent and Timely Prior Authorization 8.1 Turnaround Times: o Urgent Requests: One business day for a decision. o Non-Urgent Requests: Three business days for a decision. 8.2 AI Oversight: o If AI or an automated decision system initiates a denial, that denial must be reviewed and co-signed by a board-certified specialist in the relevant field before being finalized. o Patients and providers shall be notified in writing when AI is used at any stage of the coverage determination. 8.3 Data Tracking: Insurers must compile and submit monthly data on prior authorization approval/denial rates, average processing times, and the percentage of AI-based denials overturned on appeal. 9. Data Protection and Privacy 9.1 HIPAA-equivalent Safeguards: All accredited health plans or billing entities, whether located onshore or offshore, must uphold HIPAA-level security measures when storing or transmitting personally identifiable patient data (including Social Security numbers, medical ID numbers, etc.). 9.2 Offshoring Accountability: o Prior to offshoring data, an entity must file an attestation with the Insurance Commissioner confirming that any overseas subcontractors adhere to encryption, breach notification, audit logging, and confidentiality protocols. o Entities shall undergo random audits or produce security certifications upon request. 9.3 Breach Notification and Penalties: In the event of a suspected or actual data breach, the entity must notify affected patients and the Insurance Commissioner within 72 hours, implementing a corrective action plan. Repeated or willful violations may result in fines, revocation of accreditation, or other sanctions. 10. Enforcement and Oversight 10.1 Authority of the Insurance Commissioner: o Empowered to audit, investigate, and enforce all provisions of this Bill of Rights. o May impose fines, clawbacks, revocation of accreditation, and other appropriate remedies for noncompliance. 10.2 Annual Public Report: o The Insurance Commissioner shall publish an annual report detailing enforcement actions, complaint data, AI usage rates, denial statistics, and any data breaches or security infractions. o The report shall include trend analyses (e.g., median time-to-decision for prior authorizations, telehealth adoption rates, network adequacy improvements). 10.3 Multidisciplinary Advisory Group: o Composed of physicians, cybersecurity experts, patient advocates, telehealth specialists, and others. o Convenes periodically to review compliance, recommend updates, and study emerging issues (e.g., advanced AI, new data-security threats). 11. Anti-Retaliation and Support for Providers 11.1 Anti-Retaliation: Insurers, health plans, or affiliated entities shall not retaliate against providers (e.g., network exclusion or contract termination) for filing formal complaints, submitting testimony, or participating in external reviews concerning the insurer's compliance with this Bill of Rights. 11.2 Technical Assistance: The Insurance Commissioner, in collaboration with the Department of Health, shall explore or establish technical support programs to help smaller or rural practices adopt secure data systems, comply with prior authorization reporting, and integrate telehealth services effectively. 12. Phased Implementation 12.1 Immediate Effect: Provisions related to patient communications (Items 1 to 6), emergency care, and urgent prior authorizations (Item 8.1) shall take effect immediately upon enactment. 12.2 Data Offshoring and AI Protocols: Insurers may have six to twelve months from the date of enactment to fully implement or certify AI oversight processes and offshore data security compliance (excluding Social Security numbers and medical ID numbers, which must be protected immediately). 12.3 Follow-up Review: Within one year of implementation, the Insurance Commissioner shall submit a progress report to the Legislature with recommendations for any further legislative refinements.; and BE IT FURTHER RESOLVED that all insurers, health care providers, and billing entities are strongly encouraged to begin voluntary compliance with these updated patient protections prior to any mandatory deadlines in order to foster a collaborative and smooth transition; and BE IT FURTHER RESOLVED that ongoing stakeholder input will be sought to address outstanding issues, such as payment parity, facility fees, and self-insured plan coverage, which may require additional state or federal action; and BE IT FURTHER RESOLVED that certified copies of this Concurrent Resolution be transmitted to the Governor, Director of Health, Director of Commerce and Consumer Affairs, and Insurance Commissioner. OFFERED BY: _____________________________
4646
4747 WHEREAS, Hawaii pioneered employer-supported health insurance through the Prepaid Health Care Act of 1974; however, the State continues to face severe physician, nurse, and dentist shortages, with over thirty-five percent of the population residing in federally designated Health Professional Shortage Areas--the highest percentage in the nation; and
4848
4949
5050
5151 WHEREAS, the University of Hawaii Health Research Center found that forty-two percent of surveyed physicians reported patient harm or serious adverse events attributable to prior authorization delays or denials, emphasizing a need for streamlined insurance processes; and
5252
5353
5454
5555 WHEREAS, recent increases in claims denials, particularly those driven by automated or artificial intelligence (AI)-based systems, underscore the necessity for greater transparency, specialist review, and patient-friendly appeals mechanisms; and
5656
5757
5858
5959 WHEREAS, the original Hawaii Patient Bill of Rights, enacted over twenty-five years ago, now requires substantial updates to address modern challenges, such as AI-driven denials, telehealth accessibility, data-offshoring risks, and persistent network inadequacies on the neighbor islands and in rural areas; and
6060
6161
6262
6363 WHEREAS, patients, health care providers, and cybersecurity experts cite the need for robust data protection measures that accommodate legitimate offshoring services while maintaining Health Insurance Portability and Accountability Act-equivalent safeguards, timely breach notifications, and strong enforcement; and
6464
6565
6666
6767 WHEREAS, the Insurance Commissioner's office needs expanded authority, resources, and reporting mechanisms to effectively audit, investigate, and sanction noncompliant insurers or billing entities, ensuring consistent and accountable enforcement of patients' rights; and
6868
6969
7070
7171 WHEREAS, the Revised 2025 Hawaii Patient Bill of Rights is an essential modernization step that prioritizes patient autonomy, transparent healthcare, timely access, robust data protection, AI accountability, and real enforcement--all while recognizing the practical realities of insurers, providers, and patients in a rapidly evolving healthcare landscape; now, therefore,
7272
7373
7474
7575 BE IT RESOLVED by the Senate of the Thirty-third Legislature of the State of Hawaii, Regular Session of 2025, the House of Representatives concurring, that this body strongly supports and recommends the implementation of the following Revised 2025 Hawaii Patient Bill of Rights:
7676
7777
7878
7979 Foreword and Definitions
8080
8181
8282
8383 1. Purpose: This Bill of Rights modernizes patient protections to address AI-based coverage decisions, data security risks, and ongoing provider shortages in Hawaii.
8484
8585
8686
8787 2. Definitions:
8888
8989
9090
9191 o AI or Automated Decision System: Any algorithmic or software-based platform that can autonomously generate or recommend coverage determinations without direct human supervision.
9292
9393 o HIPAA-equivalent Security: A standard of data protection meeting or exceeding requirements set forth in 45 C.F.R. Parts 160 and 164 (HIPAA Privacy and Security Rules).
9494
9595 o Urgent vs. Non-Urgent: Urgent requests are those where delays could seriously jeopardize a patient's health, life, or overall well-being; non-urgent requests include all other prior authorizations not qualifying as urgent.
9696
9797
9898
9999
100100
101101
102102
103103 1. Clear Information
104104
105105
106106
107107 Patients must receive clear, written (and, if necessary, translated) explanations from their health insurance plan regarding covered and non-covered services, presented at a reading level understandable to the average enrollee.
108108
109109
110110
111111
112112
113113
114114
115115 2. Provider Directory
116116
117117
118118
119119 All insurers must maintain and publicly post an up-to-date, accurate, and easily accessible directory of in-network providers, updated at least quarterly, listing each provider's specialty, languages spoken, telehealth availability, and current patient capacity.
120120
121121
122122
123123
124124
125125
126126
127127 3. Specialist Referrals
128128
129129
130130
131131 All patients must be able to obtain timely specialist referrals without undue administrative barriers or delays. Insurers shall clearly communicate referral steps and expedite such referrals in urgent or complex cases.
132132
133133
134134
135135
136136
137137
138138
139139 4. Emergency Care
140140
141141
142142
143143 No insurer may deny coverage for legitimate emergency services based on retrospective review. If a patient believes in good faith that their life or health is endangered, they have the right to seek immediate emergency care without facing post-service coverage denials.
144144
145145
146146
147147
148148
149149
150150
151151 5. Explanation of Illness, Options, and Patient Autonomy
152152
153153
154154
155155 5.1 Right to Understand Care: Patients are entitled to a clear explanation of their diagnosis, treatment options (including the option to decline treatment), and potential outcomes or risks from their healthcare provider, ensuring fully informed consent.
156156
157157
158158
159159 5.2 Right to Accept or Decline Treatment: Every mentally competent patient (or as decided by their legal health care proxy) has the right to accept, receive, reject, or discontinue any legal medical care, treatment, or prescribed medication from any legally licensed medical provider, and the right to not have that decision denied, prevented, restricted, or impeded by other persons.
160160
161161
162162
163163
164164
165165
166166
167167 6. Appeals and External Review
168168
169169
170170
171171 6.1 Notice and Forms: Whenever coverage is denied, insurers must provide a universal external review request form and a step-by-step guide (in print or digital form) explaining how to appeal.
172172
173173
174174
175175 6.2 Online FAQ and Hotline: Insurers shall maintain an online FAQ regarding appeals, alongside a toll-free hotline to assist patients.
176176
177177
178178
179179 6.3 Enforcement: The Insurance Commissioner may impose financial penalties or other administrative measures on insurers failing to publicize or comply with state and federal appeals requirements.
180180
181181
182182
183183
184184
185185
186186
187187 7. Network Adequacy, Telehealth, and Rural Access
188188
189189
190190
191191 7.1 Coverage in Shortage Areas: Patients in federally designated Health Professional Shortage Areas must have timely access to primary and specialty care.
192192
193193
194194
195195 7.2 Reporting Requirements: Insurers shall submit quarterly reports detailing provider-to-patient ratios, average wait times, and referral outcomesdisaggregated by region or island.
196196
197197
198198
199199 7.3 Telehealth Provisions: Telehealth services, if legally permissible within a provider's scope of practice, shall be covered at parity with in-person services to mitigate access barriers.
200200
201201
202202
203203 7.4. Prohibition of Burdensome Prior Authorization: Prior authorization procedures in shortage areas must not unduly limit provider productivity or delay critical patient care.
204204
205205
206206
207207
208208
209209
210210
211211 8. Transparent and Timely Prior Authorization
212212
213213
214214
215215 8.1 Turnaround Times:
216216
217217
218218
219219 o Urgent Requests: One business day for a decision.
220220
221221 o Non-Urgent Requests: Three business days for a decision.
222222
223223
224224
225225 8.2 AI Oversight:
226226
227227
228228
229229 o If AI or an automated decision system initiates a denial, that denial must be reviewed and co-signed by a board-certified specialist in the relevant field before being finalized.
230230
231231 o Patients and providers shall be notified in writing when AI is used at any stage of the coverage determination.
232232
233233
234234
235235 8.3 Data Tracking: Insurers must compile and submit monthly data on prior authorization approval/denial rates, average processing times, and the percentage of AI-based denials overturned on appeal.
236236
237237
238238
239239
240240
241241
242242
243243 9. Data Protection and Privacy
244244
245245
246246
247247 9.1 HIPAA-equivalent Safeguards: All accredited health plans or billing entities, whether located onshore or offshore, must uphold HIPAA-level security measures when storing or transmitting personally identifiable patient data (including Social Security numbers, medical ID numbers, etc.).
248248
249249
250250
251251 9.2 Offshoring Accountability:
252252
253253 o Prior to offshoring data, an entity must file an attestation with the Insurance Commissioner confirming that any overseas subcontractors adhere to encryption, breach notification, audit logging, and confidentiality protocols.
254254
255255 o Entities shall undergo random audits or produce security certifications upon request.
256256
257257
258258
259259 9.3 Breach Notification and Penalties: In the event of a suspected or actual data breach, the entity must notify affected patients and the Insurance Commissioner within 72 hours, implementing a corrective action plan. Repeated or willful violations may result in fines, revocation of accreditation, or other sanctions.
260260
261261
262262
263263
264264
265265
266266
267267 10. Enforcement and Oversight
268268
269269
270270
271271 10.1 Authority of the Insurance Commissioner:
272272
273273 o Empowered to audit, investigate, and enforce all provisions of this Bill of Rights.
274274
275275 o May impose fines, clawbacks, revocation of accreditation, and other appropriate remedies for noncompliance.
276276
277277
278278
279279 10.2 Annual Public Report:
280280
281281 o The Insurance Commissioner shall publish an annual report detailing enforcement actions, complaint data, AI usage rates, denial statistics, and any data breaches or security infractions.
282282
283283 o The report shall include trend analyses (e.g., median time-to-decision for prior authorizations, telehealth adoption rates, network adequacy improvements).
284284
285285
286286
287287 10.3 Multidisciplinary Advisory Group:
288288
289289 o Composed of physicians, cybersecurity experts, patient advocates, telehealth specialists, and others.
290290
291291 o Convenes periodically to review compliance, recommend updates, and study emerging issues (e.g., advanced AI, new data-security threats).
292292
293293
294294
295295
296296
297297
298298
299299 11. Anti-Retaliation and Support for Providers
300300
301301
302302
303303 11.1 Anti-Retaliation: Insurers, health plans, or affiliated entities shall not retaliate against providers (e.g., network exclusion or contract termination) for filing formal complaints, submitting testimony, or participating in external reviews concerning the insurer's compliance with this Bill of Rights.
304304
305305
306306
307307 11.2 Technical Assistance: The Insurance Commissioner, in collaboration with the Department of Health, shall explore or establish technical support programs to help smaller or rural practices adopt secure data systems, comply with prior authorization reporting, and integrate telehealth services effectively.
308308
309309
310310
311311
312312
313313
314314
315315 12. Phased Implementation
316316
317317
318318
319319 12.1 Immediate Effect: Provisions related to patient communications (Items 1 to 6), emergency care, and urgent prior authorizations (Item 8.1) shall take effect immediately upon enactment.
320320
321321
322322
323323 12.2 Data Offshoring and AI Protocols: Insurers may have six to twelve months from the date of enactment to fully implement or certify AI oversight processes and offshore data security compliance (excluding Social Security numbers and medical ID numbers, which must be protected immediately).
324324
325325
326326
327327 12.3 Follow-up Review: Within one year of implementation, the Insurance Commissioner shall submit a progress report to the Legislature with recommendations for any further legislative refinements.; and
328328
329329
330330
331331 BE IT FURTHER RESOLVED that all insurers, health care providers, and billing entities are strongly encouraged to begin voluntary compliance with these updated patient protections prior to any mandatory deadlines in order to foster a collaborative and smooth transition; and
332332
333333
334334
335335 BE IT FURTHER RESOLVED that ongoing stakeholder input will be sought to address outstanding issues, such as payment parity, facility fees, and self-insured plan coverage, which may require additional state or federal action; and
336336
337337
338338
339339 BE IT FURTHER RESOLVED that certified copies of this Concurrent Resolution be transmitted to the Governor, Director of Health, Director of Commerce and Consumer Affairs, and Insurance Commissioner.
340340
341341
342342
343343
344344
345345
346346
347347 OFFERED BY: _____________________________
348348
349349
350350
351351 OFFERED BY:
352352
353353 _____________________________
354354
355355
356356
357357
358358
359359
360360
361361 Report Title: Revised 2025 Hawaii Patient Bill of Rights
362362
363363 Report Title:
364364
365365 Revised 2025 Hawaii Patient Bill of Rights