Bill Text: CA AB1751 | 2017-2018 | Regular Session | Chaptered


Bill Title: Controlled substances: CURES database.

Spectrum: Partisan Bill (Democrat 1-0)

Status: (Passed) 2018-09-18 - Chaptered by Secretary of State - Chapter 478, Statutes of 2018. [AB1751 Detail]

Download: California-2017-AB1751-Chaptered.html

Assembly Bill No. 1751
CHAPTER 478

An act to amend Section 1798.24 of the Civil Code, and to amend Section 11165 of the Health and Safety Code, relating to controlled substances.

[ Approved by Governor  September 18, 2018. Filed with Secretary of State  September 18, 2018. ]

LEGISLATIVE COUNSEL'S DIGEST


AB 1751, Low. Controlled substances: CURES database.
Existing law classifies certain controlled substances into designated schedules. Existing law requires the Department of Justice to maintain the Controlled Substance Utilization Review and Evaluation System (CURES) for the electronic monitoring of the prescribing and dispensing of Schedule II, Schedule III, and Schedule IV controlled substances by a health care practitioner authorized to prescribe, order, administer, furnish, or dispense a Schedule II, Schedule III, or Schedule IV controlled substance.
This bill would require the department, no later than July 1, 2020, to adopt regulations regarding the access and use of the information within CURES by consulting with stakeholders, and addressing certain processes, purposes, and conditions in the regulations. The bill would authorize the department, once final regulations have been issued, to enter into an agreement with any entity operating an interstate data sharing hub, or any agency operating a prescription drug monitoring program in another state, for purposes of interstate data sharing of prescription drug monitoring program information, as specified. The bill would require any agreement entered into by the department for those purposes to ensure that all access to data obtained from CURES and the handling of data contained within CURES comply with California law and meet the same patient privacy, audit, and data security standards employed and required for direct access to CURES.
The bill would make conforming changes to related provisions concerning exceptions to the prohibition on a state agency from disclosing personal information.
This bill would incorporate additional changes to Section 11165 of the Health and Safety Code proposed by AB 1753 to be operative only if this bill and AB 1753 are enacted and this bill is enacted last.
Vote: MAJORITY   Appropriation: NO   Fiscal Committee: YES   Local Program: NO  

The people of the State of California do enact as follows:


SECTION 1.

 Section 1798.24 of the Civil Code is amended to read:

1798.24.
 An agency shall not disclose any personal information in a manner that would link the information disclosed to the individual to whom it pertains unless the information is disclosed, as follows:
(a) To the individual to whom the information pertains.
(b) With the prior written voluntary consent of the individual to whom the information pertains, but only if that consent has been obtained not more than 30 days before the disclosure, or in the time limit agreed to by the individual in the written consent.
(c) To the duly appointed guardian or conservator of the individual or a person representing the individual if it can be proven with reasonable certainty through the possession of agency forms, documents, or correspondence that this person is the authorized representative of the individual to whom the information pertains.
(d) To those officers, employees, attorneys, agents, or volunteers of the agency that has custody of the information if the disclosure is relevant and necessary in the ordinary course of the performance of their official duties and is related to the purpose for which the information was acquired.
(e) To a person, or to another agency if the transfer is necessary for the transferee agency to perform its constitutional or statutory duties, and the use is compatible with a purpose for which the information was collected and the use or transfer is in accordance with Section 1798.25. With respect to information transferred from a law enforcement or regulatory agency, or information transferred to another law enforcement or regulatory agency, a use is compatible if the use of the information requested is needed in an investigation of unlawful activity under the jurisdiction of the requesting agency or for licensing, certification, or regulatory purposes by that agency.
(f) To a governmental entity if required by state or federal law.
(g) Pursuant to the California Public Records Act (Chapter 3.5 (commencing with Section 6250) of Division 7 of Title 1 of the Government Code).
(h) To a person who has provided the agency with advance, adequate written assurance that the information will be used solely for statistical research or reporting purposes, but only if the information to be disclosed is in a form that will not identify any individual.
(i) Pursuant to a determination by the agency that maintains information that compelling circumstances exist that affect the health or safety of an individual, if upon the disclosure notification is transmitted to the individual to whom the information pertains at his or her last known address. Disclosure shall not be made if it is in conflict with other state or federal laws.
(j) To the State Archives as a record that has sufficient historical or other value to warrant its continued preservation by the California state government, or for evaluation by the Director of General Services or his or her designee to determine whether the record has further administrative, legal, or fiscal value.
(k) To any person pursuant to a subpoena, court order, or other compulsory legal process if, before the disclosure, the agency reasonably attempts to notify the individual to whom the record pertains, and if the notification is not prohibited by law.
(l) To any person pursuant to a search warrant.
(m) Pursuant to Article 3 (commencing with Section 1800) of Chapter 1 of Division 2 of the Vehicle Code.
(n) For the sole purpose of verifying and paying government health care service claims made pursuant to Division 9 (commencing with Section 10000) of the Welfare and Institutions Code.
(o) To a law enforcement or regulatory agency when required for an investigation of unlawful activity or for licensing, certification, or regulatory purposes, unless the disclosure is otherwise prohibited by law.
(p) To another person or governmental organization to the extent necessary to obtain information from the person or governmental organization for an investigation by the agency of a failure to comply with a specific state law that the agency is responsible for enforcing.
(q) To an adopted person and is limited to general background information pertaining to the adopted person’s biological parents, if the information does not include or reveal the identity of the biological parents.
(r) To a child or a grandchild of an adopted person and disclosure is limited to medically necessary information pertaining to the adopted person’s biological parents. However, the information, or the process for obtaining the information, shall not include or reveal the identity of the biological parents. The State Department of Social Services shall adopt regulations governing the release of information pursuant to this subdivision. The regulations shall require licensed adoption agencies to provide the same services provided by the department as established by this subdivision.
(s) To a committee of the Legislature or to a Member of the Legislature, or his or her staff if authorized in writing by the member, if the member has permission to obtain the information from the individual to whom it pertains or if the member provides reasonable assurance that he or she is acting on behalf of the individual.
(t) (1) To the University of California, a nonprofit educational institution, or, in the case of education-related data, another nonprofit entity, conducting scientific research, if the request for information is approved by the Committee for the Protection of Human Subjects (CPHS) for the California Health and Human Services Agency (CHHSA) or an institutional review board, as authorized in paragraphs (4) and (5). The approval shall include a review and determination that all the following criteria have been satisfied:
(A) The researcher has provided a plan sufficient to protect personal information from improper use and disclosures, including sufficient administrative, physical, and technical safeguards to protect personal information from reasonable anticipated threats to the security or confidentiality of the information.
(B) The researcher has provided a sufficient plan to destroy or return all personal information as soon as it is no longer needed for the research project, unless the researcher has demonstrated an ongoing need for the personal information for the research project and has provided a long-term plan sufficient to protect the confidentiality of that information.
(C) The researcher has provided sufficient written assurances that the personal information will not be reused or disclosed to any other person or entity, or used in any manner, not approved in the research protocol, except as required by law or for authorized oversight of the research project.
(2) The CPHS or institutional review board shall, at a minimum, accomplish all of the following as part of its review and approval of the research project for the purpose of protecting personal information held in agency databases:
(A) Determine whether the requested personal information is needed to conduct the research.
(B) Permit access to personal information only if it is needed for the research project.
(C) Permit access only to the minimum necessary personal information needed for the research project.
(D) Require the assignment of unique subject codes that are not derived from personal information in lieu of social security numbers if the research can still be conducted without social security numbers.
(E) If feasible, and if cost, time, and technical expertise permit, require the agency to conduct a portion of the data processing for the researcher to minimize the release of personal information.
(3) Reasonable costs to the agency associated with the agency’s process of protecting personal information under the conditions of CPHS approval may be billed to the researcher, including, but not limited to, the agency’s costs for conducting a portion of the data processing for the researcher, removing personal information, encrypting or otherwise securing personal information, or assigning subject codes.
(4) The CPHS may enter into written agreements to enable other institutional review boards to provide the data security approvals required by this subdivision, if the data security requirements set forth in this subdivision are satisfied.
(5) Pursuant to paragraph (4), the CPHS shall enter into a written agreement with the institutional review board established pursuant to former Section 49079.6 of the Education Code. The agreement shall authorize, commencing July 1, 2010, or the date upon which the written agreement is executed, whichever is later, that board to provide the data security approvals required by this subdivision, if the data security requirements set forth in this subdivision and the act specified in subdivision (a) of Section 49079.5 of the Education Code are satisfied.
(u) To an insurer if authorized by Chapter 5 (commencing with Section 10900) of Division 4 of the Vehicle Code.
(v) Pursuant to Section 450, 452, 8009, or 18396 of the Financial Code.
(w) For the sole purpose of participation in interstate data sharing of prescription drug monitoring program information pursuant to the California Uniform Controlled Substances Act (Division 10 (commencing with Section 11000) of the Health and Safety Code), if disclosure is limited to prescription drug monitoring program information.
This article does not require the disclosure of personal information to the individual to whom the information pertains if that information may otherwise be withheld as set forth in Section 1798.40.

SEC. 2.

 Section 11165 of the Health and Safety Code is amended to read:

11165.
 (a) To assist health care practitioners in their efforts to ensure appropriate prescribing, ordering, administering, furnishing, and dispensing of controlled substances, law enforcement and regulatory agencies in their efforts to control the diversion and resultant abuse of Schedule II, Schedule III, and Schedule IV controlled substances, and for statistical analysis, education, and research, the Department of Justice shall, contingent upon the availability of adequate funds in the CURES Fund, maintain the Controlled Substance Utilization Review and Evaluation System (CURES) for the electronic monitoring of, and Internet access to information regarding, the prescribing and dispensing of Schedule II, Schedule III, and Schedule IV controlled substances by all practitioners authorized to prescribe, order, administer, furnish, or dispense these controlled substances.
(b) The Department of Justice may seek and use grant funds to pay the costs incurred by the operation and maintenance of CURES. The department shall annually report to the Legislature and make available to the public the amount and source of funds it receives for support of CURES.
(c) (1) The operation of CURES shall comply with all applicable federal and state privacy and security laws and regulations.
(2) (A) CURES shall operate under existing provisions of law to safeguard the privacy and confidentiality of patients. Data obtained from CURES shall only be provided to appropriate state, local, and federal public agencies for disciplinary, civil, or criminal purposes and to other agencies or entities, as determined by the Department of Justice, for the purpose of educating practitioners and others in lieu of disciplinary, civil, or criminal actions. Data may be provided to public or private entities, as approved by the Department of Justice, for educational, peer review, statistical, or research purposes, if patient information, including any information that may identify the patient, is not compromised. Further, data disclosed to any individual or agency as described in this subdivision shall not be disclosed, sold, or transferred to any third party, unless authorized by, or pursuant to, state and federal privacy and security laws and regulations. The Department of Justice shall establish policies, procedures, and regulations regarding the use, access, evaluation, management, implementation, operation, storage, disclosure, and security of the information within CURES, consistent with this subdivision.
(B) Notwithstanding subparagraph (A), a regulatory board whose licensees do not prescribe, order, administer, furnish, or dispense controlled substances shall not be provided data obtained from CURES.
(3) The Department of Justice shall, no later than July 1, 2020, adopt regulations regarding the access and use of the information within CURES. The Department of Justice shall consult with all stakeholders identified by the department during the rulemaking process. The regulations shall, at a minimum, address all of the following in a manner consistent with this chapter:
(A) The process for approving, denying, and disapproving individuals or entities seeking access to information in CURES.
(B) The purposes for which a health care practitioner may access information in CURES.
(C) The conditions under which a warrant, subpoena, or court order is required for a law enforcement agency to obtain information from CURES as part of a criminal investigation.
(D) The process by which information in CURES may be provided for educational, peer review, statistical, or research purposes.
(4) In accordance with federal and state privacy laws and regulations, a health care practitioner may provide a patient with a copy of the patient’s CURES patient activity report as long as no additional CURES data are provided and keep a copy of the report in the patient’s medical record in compliance with subdivision (d) of Section 11165.1.
(d) For each prescription for a Schedule II, Schedule III, or Schedule IV controlled substance, as defined in the controlled substances schedules in federal law and regulations, specifically Sections 1308.12, 1308.13, and 1308.14, respectively, of Title 21 of the Code of Federal Regulations, the dispensing pharmacy, clinic, or other dispenser shall report the following information to the Department of Justice as soon as reasonably possible, but not more than seven days after the date a controlled substance is dispensed, in a format specified by the Department of Justice:
(1) Full name, address, and, if available, telephone number of the ultimate user or research subject, or contact information as determined by the Secretary of the United States Department of Health and Human Services, and the gender, and date of birth of the ultimate user.
(2) The prescriber’s category of licensure, license number, national provider identifier (NPI) number, the federal controlled substance registration number, and the state medical license number of any prescriber using the federal controlled substance registration number of a government-exempt facility, if provided.
(3) Pharmacy prescription number, license number, NPI number, and federal controlled substance registration number.
(4) National Drug Code (NDC) number of the controlled substance dispensed.
(5) Quantity of the controlled substance dispensed.
(6) International Statistical Classification of Diseases, 9th revision (ICD-9) or 10th revision (ICD-10) Code, if available.
(7) Number of refills ordered.
(8) Whether the drug was dispensed as a refill of a prescription or as a first-time request.
(9) Date of origin of the prescription.
(10) Date of dispensing of the prescription.
(e) The Department of Justice may invite stakeholders to assist, advise, and make recommendations on the establishment of rules and regulations necessary to ensure the proper administration and enforcement of the CURES database. All prescriber and dispenser invitees shall be licensed by one of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, in active practice in California, and a regular user of CURES.
(f) The Department of Justice shall, prior to upgrading CURES, consult with prescribers licensed by one of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, one or more of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, and any other stakeholder identified by the department, for the purpose of identifying desirable capabilities and upgrades to the CURES Prescription Drug Monitoring Program (PDMP).
(g) The Department of Justice may establish a process to educate authorized subscribers of the CURES PDMP on how to access and use the CURES PDMP.
(h) (1) The Department of Justice may enter into an agreement with any entity operating an interstate data sharing hub, or any agency operating a prescription drug monitoring program in another state, for purposes of interstate data sharing of prescription drug monitoring program information.
(2) Data obtained from CURES may be provided to authorized users of another state’s prescription drug monitoring program, as determined by the Department of Justice pursuant to subdivision (c), if the entity operating the interstate data sharing hub, and the prescription drug monitoring program of that state, as applicable, have entered into an agreement with the Department of Justice for interstate data sharing of prescription drug monitoring program information.
(3) Any agreement entered into by the Department of Justice for purposes of interstate data sharing of prescription drug monitoring program information shall ensure that all access to data obtained from CURES and the handling of data contained within CURES comply with California law, including regulations, and meet the same patient privacy, audit, and data security standards employed and required for direct access to CURES.
(4) For purposes of interstate data sharing of CURES information pursuant to this subdivision, an authorized user of another state’s prescription drug monitoring program shall not be required to register with CURES, if he or she is registered and in good standing with that state’s prescription drug monitoring program.
(5) The Department of Justice shall not enter into an agreement pursuant to this subdivision until the department has issued final regulations regarding the access and use of the information within CURES as required by paragraph (3) of subdivision (c).

SEC. 2.5.

 Section 11165 of the Health and Safety Code is amended to read:

11165.
 (a) To assist health care practitioners in their efforts to ensure appropriate prescribing, ordering, administering, furnishing, and dispensing of controlled substances, law enforcement and regulatory agencies in their efforts to control the diversion and resultant abuse of Schedule II, Schedule III, and Schedule IV controlled substances, and for statistical analysis, education, and research, the Department of Justice shall, contingent upon the availability of adequate funds in the CURES Fund, maintain the Controlled Substance Utilization Review and Evaluation System (CURES) for the electronic monitoring of, and Internet access to information regarding, the prescribing and dispensing of Schedule II, Schedule III, and Schedule IV controlled substances by all practitioners authorized to prescribe, order, administer, furnish, or dispense these controlled substances.
(b) The Department of Justice may seek and use grant funds to pay the costs incurred by the operation and maintenance of CURES. The department shall annually report to the Legislature and make available to the public the amount and source of funds it receives for support of CURES.
(c) (1) The operation of CURES shall comply with all applicable federal and state privacy and security laws and regulations.
(2) (A) CURES shall operate under existing provisions of law to safeguard the privacy and confidentiality of patients. Data obtained from CURES shall only be provided to appropriate state, local, and federal public agencies for disciplinary, civil, or criminal purposes and to other agencies or entities, as determined by the Department of Justice, for the purpose of educating practitioners and others in lieu of disciplinary, civil, or criminal actions. Data may be provided to public or private entities, as approved by the Department of Justice, for educational, peer review, statistical, or research purposes, if patient information, including any information that may identify the patient, is not compromised. Further, data disclosed to any individual or agency as described in this subdivision shall not be disclosed, sold, or transferred to any third party, unless authorized by, or pursuant to, state and federal privacy and security laws and regulations. The Department of Justice shall establish policies, procedures, and regulations regarding the use, access, evaluation, management, implementation, operation, storage, disclosure, and security of the information within CURES, consistent with this subdivision.
(B) Notwithstanding subparagraph (A), a regulatory board whose licensees do not prescribe, order, administer, furnish, or dispense controlled substances shall not be provided data obtained from CURES.
(3) The Department of Justice shall, no later than July 1, 2020, adopt regulations regarding the access and use of the information within CURES. The Department of Justice shall consult with all stakeholders identified by the department during the rulemaking process. The regulations shall, at a minimum, address all of the following in a manner consistent with this chapter:
(A) The process for approving, denying, and disapproving individuals or entities seeking access to information in CURES.
(B) The purposes for which a health care practitioner may access information in CURES.
(C) The conditions under which a warrant, subpoena, or court order is required for a law enforcement agency to obtain information from CURES as part of a criminal investigation.
(D) The process by which information in CURES may be provided for educational, peer review, statistical, or research purposes.
(4) In accordance with federal and state privacy laws and regulations, a health care practitioner may provide a patient with a copy of the patient’s CURES patient activity report as long as no additional CURES data are provided and keep a copy of the report in the patient’s medical record in compliance with subdivision (d) of Section 11165.1.
(d) For each prescription for a Schedule II, Schedule III, or Schedule IV controlled substance, as defined in the controlled substances schedules in federal law and regulations, specifically Sections 1308.12, 1308.13, and 1308.14, respectively, of Title 21 of the Code of Federal Regulations, the dispensing pharmacy, clinic, or other dispenser shall report the following information to the Department of Justice as soon as reasonably possible, but not more than seven days after the date a controlled substance is dispensed, in a format specified by the Department of Justice:
(1) Full name, address, and, if available, telephone number of the ultimate user or research subject, or contact information as determined by the Secretary of the United States Department of Health and Human Services, and the gender, and date of birth of the ultimate user.
(2) The prescriber’s category of licensure, license number, national provider identifier (NPI) number, the federal controlled substance registration number, and the state medical license number of any prescriber using the federal controlled substance registration number of a government-exempt facility, if provided.
(3) Pharmacy prescription number, license number, NPI number, and federal controlled substance registration number.
(4) National Drug Code (NDC) number of the controlled substance dispensed.
(5) Quantity of the controlled substance dispensed.
(6) International Statistical Classification of Diseases, 9th revision (ICD-9) or 10th revision (ICD-10) Code, if available.
(7) Number of refills ordered.
(8) Whether the drug was dispensed as a refill of a prescription or as a first-time request.
(9) Date of origin of the prescription.
(10) Date of dispensing of the prescription.
(11) The serial number for the corresponding prescription form, if applicable.
(e) The Department of Justice may invite stakeholders to assist, advise, and make recommendations on the establishment of rules and regulations necessary to ensure the proper administration and enforcement of the CURES database. All prescriber and dispenser invitees shall be licensed by one of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, in active practice in California, and a regular user of CURES.
(f) The Department of Justice shall, prior to upgrading CURES, consult with prescribers licensed by one of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, one or more of the boards or committees identified in subdivision (d) of Section 208 of the Business and Professions Code, and any other stakeholder identified by the department, for the purpose of identifying desirable capabilities and upgrades to the CURES Prescription Drug Monitoring Program (PDMP).
(g) The Department of Justice may establish a process to educate authorized subscribers of the CURES PDMP on how to access and use the CURES PDMP.
(h) (1) The Department of Justice may enter into an agreement with any entity operating an interstate data sharing hub, or any agency operating a prescription drug monitoring program in another state, for purposes of interstate data sharing of prescription drug monitoring program information.
(2) Data obtained from CURES may be provided to authorized users of another state’s prescription drug monitoring program, as determined by the Department of Justice pursuant to subdivision (c), if the entity operating the interstate data sharing hub, and the prescription drug monitoring program of that state, as applicable, have entered into an agreement with the Department of Justice for interstate data sharing of prescription drug monitoring program information.
(3) Any agreement entered into by the Department of Justice for purposes of interstate data sharing of prescription drug monitoring program information shall ensure that all access to data obtained from CURES and the handling of data contained within CURES comply with California law, including regulations, and meet the same patient privacy, audit, and data security standards employed and required for direct access to CURES.
(4) For purposes of interstate data sharing of CURES information pursuant to this subdivision, an authorized user of another state’s prescription drug monitoring program shall not be required to register with CURES, if he or she is registered and in good standing with that state’s prescription drug monitoring program.
(5) The Department of Justice shall not enter into an agreement pursuant to this subdivision until the department has issued final regulations regarding the access and use of the information within CURES as required by paragraph (3) of subdivision (c).

SEC. 3.

 Section 2.5 of this bill incorporates amendments to Section 11165 of the Health and Safety Code proposed by both this bill and Assembly Bill 1753. That section of this bill shall only become operative if (1) both bills are enacted and become effective on or before January 1, 2019, (2) each bill amends Section 11165 of the Health and Safety Code, and (3) this bill is enacted after Assembly Bill 1753, in which case Section 2 of this bill shall not become operative.
feedback