Dorsey Health Law
Oregon Expands Prohibition on the Corporate Practice of Medicine, Severely Restricting Management Services Organizations
On June 9, 2025, Oregon Governor, Tina Kotek, signed SB 951[1] into law, making Oregon’s “corporate practice of medicine” doctrine one of the country’s most restrictive. SB 951 places numerous restrictions on the relationships between management services organizations and clinician practices, which will impact many of the written arrangements and techniques that management services organizations and clinician practices currently use. SB 951 also places new and/or clarified restrictions on professional medical corporation structuring and the use of certain restrictive covenants in contracts among health industry parties. This blog post provides a general overview of these new restrictions. Key Definitions Here are key definitions that help clarify the scope of SB 951: “Management services organization” or “MSO” is defined as an entity that provides management services to a professional medical entity in return for monetary compensation under a written agreement. “Management services” is broadly defined and includes payroll, human resources, employment screening, employee relations, and other administrative or business services. “Medical licensee” or “licensee” is defined as an individual who is licensed in Oregon to practice medicine or naturopathic medicine or as a nurse practitioner or physician assistant. “Professional medical entity” is defined as an Oregon professional corporation organized for the purpose of practicing medicine, practicing naturopathic medicine, or allowing physicians, nurse practitioners and physician assistants to jointly render healthcare services, or a limited liability company, partnership limited liability partnership or partnership organized for a medical purpose that is authorized to transact business in Oregon.[2] Restrictions on MSOs MSOs, including their shareholders, directors, members, managers, officers and employees (collectively, “agents”), may not, with certain exceptions: own or control a majority of; be a director, officer, employee or independent contractor of, or receive compensation from the MSO to manage; or exercise a proxy, right or power to vote the shares of; a professional medical entity with which it has a management services agreement (“MSA”). Additionally, MSOs and their agents may not, with certain exceptions: control or enter into agreements to, or otherwise permit a non-licensee to, control or restrict the sale or transfer of a professional medical entity’s ownership interests or assets; issue, or cause a professional medical entity to issue, ownership interests in the professional medical entity or a subsidiary or affiliate of the professional medical entity; pay dividends from a professional medical entity’s ownership interests; acquire, or finance the acquisition of, a majority of a professional medical entity’s ownership interests; or exercise de facto control over a professional medical entity’s administrative, business or clinical operations in a manner that affects the professional medical entity’s clinical decision making or the nature and quality of its medical care, which includes, but is not limited to, hiring or setting compensation for licensees, setting clinical or billing and collection policies, and negotiating agreements with third-party payors and other third parties that are not employees of the professional medical entity. So, what can an MSO still do? SB 951 clarifies that the restrictions still permit an MSO to: enter into agreements to control or restrict the transfer or sale of a professional medical entity’s ownership interests or assets for cause, including, but not limited to, an owner’s loss of their professional license, exclusion from a federal health care program, breach of the MSA or death; provide management services as long as the MSO is not exercising de facto control over a professional medical entity’s operations in a manner that affects the professional medical entity’s clinical decision making or the nature and quality of its medical care; purchase, lease or take assignment of a right to possess a professional medical entity’s assets in an arms’-length transaction with a willing seller, lessor or assignor; provide support and consultation on any business operations matters, such as accounting, facilities management and compliance with applicable laws; advise a professional medical entity’s participation in payor arrangements, value-based arrangements or vendor agreements; collect quality metrics as required by law or one of the professional medical entity’s agreements; and set criteria for reimbursement under an agreement between a professional medical entity and a payor. Any MSA provision that violates any of the above restrictions is void and unenforceable. Additionally, professional medical entities and licensees have a private right of action against MSOs and the MSO’s agents, and damages may include actual damages, an injunction or other equitable relief, punitive damages and attorneys’ fees. Existing MSOs and professional medical entities conducting business in Oregon have until January 1, 2029 to comply with these restrictions. However, new MSOs and professional medical entities planning to conduct business in Oregon, including those involved in a sale or transfer of ownership, must comply with these restrictions by January 1, 2026. Restrictions on Professional Medical Corporations SB 951 also imposes restrictions on professional medical corporations (“PCs”), with certain exceptions. PCs’ articles, bylaws and other organizational arrangements may not allow for the removal of any director or officer without a majority vote of licensee-shareholders or licensee-directors, except for cause. Additionally, PCs may only replenish or transfer control over their operations through a valid shareholder agreement that is solely among and for the benefit of a majority of shareholders who are physicians licensed in Oregon. These restrictions apply to any agreements that are entered into or renewed on or after June 9, 2025. Non-Competition, Non-Disclosure and Non-Disparagement Agreements Lastly, non-competition agreements with professional licensees that restrict the practice of medicine or nursing as well as non-disclosure and non-disparagement agreements between an MSO, hospital or hospital-affiliated clinic and an employed licensee are void and unenforceable, with certain exceptions. These restrictions also apply to any agreements that are entered into or renewed on or after June 9, 2025. The Big Picture Notably, as of 2022, OHA requires notice of and reviews material health care transactions. This, along with the passage of SB 951, indicates Oregon’s strong focus on its regulation and oversight of the “corporate practice of medicine.” And Oregon is not alone. These are recent developments in a long history of state concerns with the separation of corporations and unlicensed individuals and healthcare professional’s medical decision making and patients’ care (i.e., the corporate practice of medicine) and, more recently, private equity involvement in health care. SB 951 materially reinforces and expands Oregon’s “corporate practice of medicine” doctrine and impacts not only MSAs but other MSO-practice relationships, MSO and PC governance and agreements with restrictive covenants. SB 951 raises difficult issues such as the permitted scope of an MSO’s authority if the requirement is to avoid control that affects the professional medical entity’s clinical decision making or the nature and quality of medical care. Given the wide-reaching implications of this new law and to ensure compliance with SB 951 by the applicable compliance dates, existing MSOs and clinician practices conducting business in Oregon will need to review and likely revise their current business models, practices, and written agreements as necessary, and new MSOs and clinician practices planning to conduct business in Oregon will need to closely review their proposed business models and practices. Please contact the authors or your regular Dorsey attorney with any questions about how these restrictions could affect your current business model or any contemplated transactions. [1] https://olis.oregonlegislature.gov/liz/2025R1/Downloads/MeasureDocument/SB951/Enrolled. [2] While this law does not currently apply to other healthcare providers. Oregon House Majority Leader, Ben Bowman, predicts that future legislative sessions will likely address the expansion of this law to other healthcare providers, such as hospitals and dentists.
June 25, 2025
HIPAA’s 2024 Reproductive Health Rule is Vacated Nationwide – One Year After Going Into Effect
On June 18, 2025, a Texas court issued a ruling that vacated, on a nationwide basis, the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (the “Reproductive Health Rule”), just one year after the rule went into effect. In Purl v. United States Department of Health and Human Services, No. 2:24-CV-228-Z (N.D. Tex. June 18, 2025), plaintiffs, Dr. Carmen Purl and her medical clinic, challenged the validity of the Department of Health and Human Services (“HHS”) Reproductive Health Rule on the grounds that the rulemaking exceeded HHS’ statutory authority and unlawfully restricted state-mandated reporting obligations, particularly in the context of child abuse investigations. The plaintiffs argued that federal law 42 U.S.C. § 1320d-7(b) provides that "[n]othing in [HIPAA] shall be construed to invalidate or limit the authority, power, or procedures established under any law providing for the reporting of disease or injury, child abuse, birth, or death, public health surveillance, or public health investigation or intervention." Dr. Purl and her medical clinic argued that the Reproductive Health Rule did just that: it unlawfully impeded Texas’ state-mandated reporting of child abuse and public health investigations—in contravention of 42 U.S.C. § 1320d-7(b)—by interfering with health care providers’ ability to make such reporting if the reporting involved the broadly defined term “reproductive health care”. As the court noted, the Administrative Procedure Act states: courts must "hold unlawful and set aside" agency actions that are "not in accordance with law" or are "in excess of statutory jurisdiction, authority, or limitations, or short of statutory right" (5 U.S.C. § 706(2)(A), (C)). Accordingly, the court held that HHS acted outside of the bounds of its statutorily delegated authority and in contravention of federal law because the Reproductive Health Rule 1) "unlawfully 'limits' state public health laws," 2) "impermissibly redefines 'person' and 'public health,' in contravention of Federal law and 'in excess of statutory authority,'" and 3) was adopted without authority expressly delegated by Congress. The Reproductive Health Rule went into effect on June 25, 2024, with a compliance deadline of December 23, 2024. The Reproductive Health Rule amended the Health Insurance Portability and Accountability Act (“HIPAA”) regulations by adding a class of protected health information (“PHI”) that carried heightened protection, called “reproductive health information”. The Reproductive Health Rule was issued by HHS in reaction to the U.S. Supreme Court case, Dobbs v. Jackson Women's Health Organization, 597 U.S. 215 (2022), which overturned the federal right to an abortion, returning authority to regulate abortion to the states. Given widespread concerns that state abortion restrictions could interfere with individuals’ willingness to seek reproductive health care, HHS responded to Dobbs by amending HIPAA’s Privacy Rule to limit the circumstances under which “reproductive health information” could be disclosed for certain non-healthcare purposes. Specifically, under the Reproductive Health Rule, HIPAA-regulated entities were not allowed to disclose “reproductive health information” for the following purposes: (i) To conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care, where such health care is lawful under the circumstances in which it is provided; or (ii) The identification of any person for the purpose of conducting such investigation or imposing such liability. HIPAA-regulated entities were required to obtain a written attestation from persons requesting PHI related to reproductive healthcare in situations involving health oversight, judicial or administrative proceedings, law enforcement and disclosures regarding decedents such as disclosures to coroners and medical examiners. Compliance with the Reproductive Health Rule entailed HIPAA-regulated entities adopting new policies and procedures, conducting internal training, and often required education of any third parties who were presented with an attestation in response to their requests for PHI. With the ruling in Purl, just one year after the Reproductive Health Rule went into effect, HIPAA-regulated entities that implemented new policies and procedures in accordance with the Reproductive Health Rule can now terminate those policies and procedures immediately, with the exception of a future compliance obligation related to a separate topic that was included as part of the Reproductive Health Rule: patient notification about substance use disorder treatment records. Notably, the Reproductive Health Rule also requires that HIPAA-regulated entities amend their Notice of Privacy Practices (“NPP”) by February 16, 2026 to reflect changes in the uses and disclosures of substance use disorder treatment records in light of changes in federal substance use disorder regulations at 42 C.F.R. Part 2 (the “Part 2 NPP Requirement”). The Purl decision severed the Part 2 NPP Requirements from its order vacating the Reproductive Health Rule, and therefore, HIPAA-regulated entities are still required to amend their NPPs pertaining to substance use disorder regulations by February 16, 2026. Please contact this author or your regular Dorsey & Whitney LLP attorney to discuss this legal development.
June 23, 2025
Significant New Healthcare Privacy and Cybersecurity Developments
As the federal government continues to take action in response to events impacting the healthcare landscape, stakeholders must ensure that they are staying up-to-date with health information privacy and security developments in the healthcare industry. This blog post summarizes two recent significant actions: a new HIPAA final rule and proposed federal cybersecurity legislation. New HIPAA Final Rule The U.S. Department of Health and Human Services (“HHS”) has expressed concern about patient trust in the privacy of health care information since the U.S. Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization in 2022. Most recently, on April 22, 2024, HHS’s Office for Civil Rights (“OCR”) issued a new final regulation under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy Rule: HIPAA Privacy Rule to Support Reproductive Health Care Privacy. The final rule strengthens privacy protections for sensitive information about reproductive health care by: Prohibiting covered entities and their business associates from using or disclosing protected health information (“PHI”) for the purpose of an investigation into or proceeding against an individual or entity who seeks, obtains, provides, or facilitates lawful reproductive health care, which includes providing information on or paying for any such services. This prohibition does not apply in situations of suspected abuse, neglect, or endangerment. Prohibiting covered entities and their business associates from identifying any individual or entity for the purpose of any such investigation or proceeding. Requiring covered entities and their business associates to obtain a signed attestation when they receive a request for PHI potentially related to reproductive health care for the purpose of health oversight activities, judicial or administrative proceedings, law enforcement, or coroner or medical examiner disclosures. The attestation must include the individual or class of individuals whose PHI is requested, the covered entity or business associate, the requestor, a statement that the PHI will not be used or disclosed for any prohibited purpose, and a statement acknowledging the criminal penalties for any violation of the Privacy Rule. Prohibiting a provider from refusing to treat a person as the personal representative of a patient merely because they provided or facilitated reproductive health care for a patient. Requiring covered entities to revise their Notice of Privacy Practices. The final rule is scheduled for publication in the Federal Register on April 26, 2024. It will become effective 60 days after publication, with compliance to occur by February 16, 2026 for the Notice of Privacy Practices requirement and within 240 days after publication for all other requirements. As the compliance dates quickly approach, covered entities and business associates must ensure alignment of their policies, practices, and Notices of Privacy Practices with this new final rule. Covered entities and business associates may also need to revise their business associate agreements, to the extent that such agreements would permit a business associate’s use or disclosure of PHI that is prohibited under the new rule. Proposed Federal Cybersecurity Legislation The healthcare industry has seen a recent increase in cybersecurity incidents. According to OCR, over the past few years, the number of large breaches reported and the number of individuals affected by those breaches have doubled. Now, following the Change Healthcare breach, Congress is considering new legislation: Health Care Cybersecurity Improvement Act of 2024 (S.B. 4054). On March 22, 2024, Senator Mark R. Warner (D-VA), introduced the proposed federal legislation, which has been referred to the Senate Committee on Finance. Sen. Warner, who is a member of the Committee on Finance and co-founder and co-chair of the Senate Cybersecurity Caucus, is a well-known advocate of enhanced cybersecurity in the healthcare industry. The proposed legislation charges the Secretary of HHS with setting minimum cybersecurity standards for Medicare’s Accelerated Payment Program and Advance Payments Program. During the COVID-19 public health emergency, the Centers for Medicare and Medicaid Services offered accelerated and advance payments to assist in disruptions to claims payments due to the public health emergency. Under the Health Care Cybersecurity Improvement Act of 2024, if a participating Part A hospital or one of its intermediaries does not meet the set standards, the hospital will not receive accelerated payments under the Accelerated Payment Program where a cybersecurity incident caused the disrupted operations or cash flow problems. Similarly, if a participating Part B provider or one of its intermediaries does not meet the set standards, the provider will not receive advance payments under the Advance Payments Program where a cybersecurity incident caused the delayed claims payments by health insurance companies. Notably, the accelerated and advance payments are only for Medicare Part A and Part B claims payments. Currently, the bill is still in the early stages of the legislative process, and, if the law were enacted, enforcement would not occur until two years after its enactment. However, given the continuing prevalence of cybersecurity incidents in the healthcare industry, additional detailed HIPAA Security Rule cybersecurity guidance, as well as emerging state agency activity (such as New York’s proposed cybersecurity regulations for hospitals), now is the time for healthcare providers and other covered entities and business associates to focus on HIPAA Security Rule compliance to protect against hacking, ransomware and other cybersecurity attacks, and the resulting disruptions to clinical care. If you have any questions about the HIPAA Privacy Rule or Security Rule, proposed cybersecurity legislation, or their potential impact on you or your organization, please contact the authors or your regular Dorsey attorney.
April 29, 2024

