The General Assembly recently enacted amendments to the Freedom of Information Act (FOIA) that become effective on January 1, 2024 and will apply to public bodies that are also “covered entities” under HIPAA. P.A. 103-554.

First, the Act amends the definition of “private information” in FOIA to clarify that this exemption applies to electronic medical records and all information (including demographic information) that is contained within or extracted from an electronic medical records system operated or maintained by a public body that is also a “covered entity” under HIPAA.

Second, the Act adds a new exemption 7(1)(pp) that exempts from disclosure protected health information (PHI) that is maintained by a HIPAA covered entity.