Privacy Law Library

Rhode Island Health Information Exchange Act of 2008

RI HIE Act

Health · Data security

Creates Rhode Island's statewide electronic health information exchange and sets its privacy rules. Patients are included by default but may opt out of disclosure from the exchange (with exceptions for emergencies, public health, exchange operations and health-plan care management), and participating providers must tell patients about the exchange and the opt-out. Patients can obtain copies of their HIE data and disclosure reports.

Where
Rhode Island
Citation
R.I. Gen. Laws §§ 5-37.7-1 to 5-37.7-15
Status
In force
Last amended
2021-07-12
Enforced by
Rhode Island Department of Health (regulatory oversight); Attorney General and courts for penalties
People can sue
Yes
Penalties
Violators may be liable for actual and exemplary damages with discretionary attorney's fees; knowing and intentional violations are punishable by a fine up to $10,000 per patient per violation and/or up to one year in prison (§ 5-37.7-13). Waivers are void.
Applies to
  • The statewide health information exchange (HIE, CurrentCare) and the regional health information organization (RHIO) that operates it
  • Provider participants and data-submitting partners (including health plans) that share data through the HIE
  • Anyone who accesses, releases or obtains confidential health care information from the HIE

What a privacy notice must say

  • Provider participants that share data with the HIE must notify patients that data is shared to support care and explain that they may opt out, and may change that choice at any time.R.I. Gen. Laws § 5-37.7-7(c)

Rights it gives people

  • Patients may opt out of disclosure of their information from the HIE, except disclosures in emergencies, to public health authorities, to the RHIO for operations, and to health plans for care management or quality reporting.R.I. Gen. Laws §§ 5-37.7-4(c), 5-37.7-7(a)-(b)
  • Patients may obtain copies of their HIE information and disclosure reports, be notified of HIE breaches under ch. 11-49.3, change opt-out status, request amendment through a provider, and direct disclosure to representatives or non-participant providers.R.I. Gen. Laws § 5-37.7-10

Practices it requires

  • Health information may not be accessed, given, sold, transferred or relayed from the HIE except as state or federal law or the chapter specifically allows; subpoenas to the HIE require first seeking records from the source provider and a superior court determination.R.I. Gen. Laws § 5-37.7-7(d), (f)

Security duties

  • The HIE must authenticate recipients, limit identifiable data to those with a need to know, designate a security officer, give staff written confidentiality statements, and not retaliate against whistleblowers.R.I. Gen. Laws § 5-37.7-8

Other duties

  • The HIE and RHIO are bound by state law to HIPAA-compliant business associate agreement terms, including safeguards and use and disclosure limits.R.I. Gen. Laws § 5-37.7-4(g)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Department of Health HIE regulations (216-RICR) implementing opt-out procedures were not fetched. | Identification of the HIE as 'CurrentCare' is from general knowledge, not the statute.

Research reference, not legal advice.