21st Century Cures Act Final Rules:
Description: 21st Century Cures Act Final Rules: Interoperability Patient Access Rule And The Information Blocking Rule Presentation Date: Thursday April 29, 2021 Part One of a Two-Part Series for CMG Presenter: Jennifer Cox, J.D. Cox Osowiecki, LLC
Related Topics
Download Presentation
"21st Century Cures Act Final Rules:" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.
Presentation Transcript
slide1. 21st Century Cures Act Final Rules:Interoperability & Patient Access Rule And TheInformation Blocking Rule Presentation Date: Thursday April 29, 2021
Part One of a Two-Part Series for CMG
Presenter: Jennifer Cox, J.D.
Cox & Osowiecki, LLC 1 ©2021 Cox & Osowiecki, LLC<br>
slide2. Overview Cures Act, Two Final Rules The Cures Act is a federal law passed by Congress in December 2016 (P.L. 114-255), during the Obama administration, but most sections of the law did not take effect for years because they lacked required agency regulations
Two separate core rules, from two different agencies (CMS and ONC), are covered in this program series
Both rules affect providers, but the impact varies by type of provider
Understanding the significant distinctions, and their respective impacts, will help compliance planning and implementation
There has been very little guidance from the federal government on how to comply with the rules, providers will need to make some educated guesses on compliance strategies
(Pro tip: do not confuse the Cures Act with the Cares Act. It’s an easy mistake.) ©2021 Cox & Osowiecki, LLC 2<br>
slide3. Two Rules: Program Syllabus Details This program covers two core regulations that were published May 1, 2020 (during the height of the pandemic). They are:
CMS Final Rule “Interoperability and Patient Access” - the program includes a top line review of the CMS rule
Significant hospital requirements, but very few direct requirements for physician practices, but there are some
Misnamed to a degree in that it does not supply a patient access framework that applies to providers – its patient access framework is directed at specific government payers
ONC Final Rule “Interoperability, Information Blocking, and the Office of the National Coordinator (ONC) Health IT Certification Program”
Detailed review of the information blocking provisions of the ONC Final Rule
Step-by-step analysis of the eight (8) information blocking exceptions that should be incorporated into practices and polices 3 ©2021 Cox & Osowiecki, LLC<br>
slide4. 21st Century Cures CMS Rule (CMS-9115-F) CMS Final Rule: Interoperability and Patient Access final rule (CMS-9115-F) (effective dates vary – spread across 2021 and 2022)
Most sections of the CMS Rule apply only to these designated government payers, government health insurance programs, and federally approved health plans:
Medicare Advantage (MA), Medicaid, CHIP, Qualified Health Plan (QHP) issuers on the Federally-facilitated Exchanges (FFEs)
Those rule sections are: Patient Access API; Provider Directory API; Payer-to-Payer Data Exchange; Improving the Dually Eligible Experience by Increasing the Frequency of Federal-State Data Exchanges
Two sections apply to all providers, including physician practices:
Public Reporting and Information Blocking
Provider Digital Contact Information
One section applies to hospitals only: Admission, Discharge, and Transfer Event Notifications
Physician practices should be aware that this is hospital-only
It will cause an increase in incoming data to certain providers 4 ©2021 Cox & Osowiecki, LLC<br>
slide5. CMS: Public Reporting and Information Blocking This applies to physicians:
For physicians: a ‘‘No’’ response given to any of the three prevention of information blocking attestation statements for Merit-Based Incentive Payment System (MIPS) will result in an indicator on Physician Compare of information blocking
Targeted for implementation “early 2021” – using 2019 Promoting Interoperability attestation year data
There is no specific penalty listed for non-compliance, but the Rule’s commentary specifically notes:
“…section 3022(b)(2)(B) of the PHSA, which provides that any health care provider determined by the Office of the Inspector General (OIG) to have committed information blocking shall be referred to the appropriate agency to be subject to appropriate disincentives using authorities under applicable federal law, as the Secretary sets forth through notice and comment rulemaking.” 5 ©2021 Cox & Osowiecki, LLC<br>
slide6. CMS: Provider Digital Contact Information This applies to physicians:
Cures Act requires HHS to establish a provider digital contact information index, and allows use of an existing database - CMS plans to use the National Plan and Provider Enumeration System (NPPES) to meet this requirement
NPPES system: can capture Direct Address, a FHIR server URL, and query endpoints associated with a health information exchange; has the ability to maintain information about the type of contact information providers and organizations are associated with and the preferred uses for each address (providers can maintain their own unique information or associate themselves with information shared among a group of providers); and has a public API, which can be used to obtain the digital contact information stored in NPPES 6 ©2021 Cox & Osowiecki, LLC<br>
slide7. CMS: Provider Digital Contact Information This applies to physicians:
Providers can review and update their NPPES NPI Registry Profile:
https://nppes.cms.hhs.gov
Providers should include secure endpoint, Direct Address contact information at a minimum (no personal email; FHIR endpoint preferred)
Targeted for end of first quarter of 2021, CMS may (will?) begin posting the names of providers who fail to list their digital contact information in the National Plan and Provider Enumeration System (NPPES)
At this time CMS is not establishing a penalty for failure to report digital contact information. The Agency stated that it may consider penalties as well as incentives in future rulemaking. Instead, CMS finalized its policy to publicly report the names and NPIs of providers that do not include digital contact information in NPPES 7 ©2021 Cox & Osowiecki, LLC<br>
slide8. New Hospital Requirement: Send E-notifications Starting May 1, 2021, hospitals must make a reasonable effort to send real-time ADT notifications to applicable post-acute providers; primary care practitioners, practice groups and entities; and any other entity identified by the patient as being responsible for patient’s primary care that need the information for treatment, care coordination, or quality improvement activities
Real-time notifications must contain at least patient name, treating practitioner name, and sending institution name
For each registration, discharge, or transfer to or from the hospital’s emergency department and/or admission, discharge or transfer to or from the hospital’s inpatient services
Can be sent directly, or through an intermediary
Collateral effect: Primary care physicians (and likely other providers) will receive far more of these messages than they do now
Physician practices need a plan to handle, process these notifications ©2021 Cox & Osowiecki, LLC 8<br>
slide9. Next up: ONC Information Blocking Rule The ONC Information Blocking Rule is the most important change to health information since HIPAA started.
Compliance with the ONC Information Blocking Rule
is expected beginning April 5, 2021.
Fair Warning: You may feel frustrated as we go through the rule and unpack the components. The rule is unnecessarily complicated and not well-aligned with HIPAA or state records laws. 9 ©2021 Cox & Osowiecki, LLC<br>
slide10. Good News About The Information Blocking Rule Eventually, health data will flow more easily through a variety of readily available technologies; patients will have better and quicker access to allow them to engage in their care; research will flourish; population health and public health will be able to rely on data driven planning, evidence and experts. 10 ©2021 Cox & Osowiecki, LLC<br>
slide11. More Good News!! Penalties for healthcare providers do not currently include civil monetary penalties (i.e., no obvious mechanism for fines), although violations could lead to referrals to other oversight agencies and related penalties for violations of other laws or program requirements. 11 ©2021 Cox & Osowiecki, LLC<br>
slide12. Not-So-Good News At this stage the landscape is highly conceptual, drastically different than current practice, and is misaligned with HIPAA. We have insufficient regulatory guidance, making it virtually impossible to know how to correctly manage operations, revise policies, and adjust practices in order to comply.
(Also, the ongoing pandemic requires significant attention and resources for providers and the government, making Cures Act readiness harder to prioritize. 12 ©2021 Cox & Osowiecki, LLC<br>
slide13. Who Has To Comply With Information Blocking? Information Blocking affects three categories of entities called “Actors”:
Healthcare Providers (without regard to their HIPAA status**)
Health Information Exchanges and Health Information Networks (HIE/HIN)
This is very broadly defined, it is not only official or declared HIEs
Essentially, it can be any entity that helps two or more providers exchange data
Applies to a HIPAA business associate if the BAA plays an exchange role
Health IT developers, who offer Certified Electronic Health Record Technology (CEHRT)
**An Actor retains its HIPAA status (e.g., covered entity, business associate) and must comply with both HIPAA and Cures Rules simultaneously. Providers that are not governed by HIPAA still have to comply with information blocking rules. 13 ©2021 Cox & Osowiecki, LLC<br>
slide14. Information Blocking Basics An Actor is “Information Blocking” if it has practices that are:
“likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information”
If you fail to provide access, without delay, to a person who is permitted to have access under HIPAA and other laws, you can be accused of information blocking 14 ©2021 Cox & Osowiecki, LLC<br>
slide15. ONC Information Blocking – Concept Information blocking rules assume that if a patient, or any other entity or individual is permitted by HIPAA to access records, they should be given access without delay, using almost any technology the requester chooses
Technology choices are described in the ONC Rule, and include third party Application Programming Interface (APIs)
The data involved go well beyond treatment, payment, and operations (HIPAA TPO) and include any other HIPAA “permitted” access
The access request does not need to be triggered by, or even known to a patient
There are eight very specific exceptions, with complex implementation standards, detailing how data requests that you do not fulfill might escape being information blocking 15 ©2021 Cox & Osowiecki, LLC<br>
slide16. Intersection With HIPAA Information Blocking rules necessarily change how providers will approach access requests and release of records
Under current practice, and consistent with HIPAA, there are a multitude of circumstances for which you might deny (or even ignore) a “voluntary” request for data from a non-patient
E.g., public health voluntary requests, or a request from a provider with whom you are unfamiliar
Under information blocking you cannot safely deny (or ignore) the request, and will need significant documentation if you do not fulfill the request
Information Blocking talks about “patient preference” but is decidedly less interested in patient consent or authorizations, unless:
Consent or authorization is mandatory under HIPAA, or another (privacy) law
Or you have woven the consent or authorization process into a policy that revolves around and is focused on the eight exceptions in the information blocking rule 16 ©2021 Cox & Osowiecki, LLC<br>
slide17. What Data Are Subject To Information Blocking Electronic Health Information, or EHI
Until June 2022, EHI is the data in the United States Core Data for Interoperability (“USCDI” – specifically USCDI v.1); starting June 2022, Information Blocking applies to the entire HIPAA designated record set
HIPAA already requires providers to release the entire Designated Record Set
EHI does not include de-identified data (using HIPAA de-identification standards)
The USCDI is a core set of data elements. USCDI replaces the nomenclature “Common Clinical Data Set”. Previously Continuity of Care Documents (CCDs) were routinely derived from the Common Clinical Data Set data framework, and now CCDs will be routinely derived from the USCDI data set.
With a few additions in USCDI, including:
Clinical Notes: structured and unstructured
You may have heard the term “Open Notes”
Provenance: author, author time stamp, author organization 17 ©2021 Cox & Osowiecki, LLC<br>
slide18. USCDI vs CCDs 18 *Address includes both current and previous, as well as e-mail address. ©2021 Cox & Osowiecki, LLC<br>
slide19. Key Data Terms Overlap – But Are Not All Identical Designated Record Set has the same definition in HIPAA and Information Blocking:
“Designated record set” means:
(1) medical or billing records maintained by healthcare providers;
(2) enrollment, payment, claims adjudication, and/or case or medical records maintained by health plans; or
(3) information relevant to covered entities to make decisions about individuals
Other Terms: 19 ©2021 Cox & Osowiecki, LLC<br>
slide20. HIPAA Still Drives Direct Access Release Information Blocking is designed to provide more routes of access for patients (e.g., APIs, quicker access, less hassle) – patients choose how they want to access or ingest ePHI and EHI
Patients already have a very strong right to access their own records (HIPAA 45 CFR 164.524)
There are very few times when you can deny patients access to their own records, for example:
Safety hold
Not part of designated record set
In some cases, HIPAA-defined “psychotherapy notes”
Information Blocking Rule does NOT limit patients’ HIPAA rights to access their own records
DO NOT interpret any part of Information Blocking as making it harder for patients to access their own records; do not add fees; do not add paperwork; do not add consent features – patient access should be the same or easier 20 ©2021 Cox & Osowiecki, LLC<br>
slide21. Assessing Information Blocking Information Blocking is assessed on a case-by-case basis and is complaint-based
Assessment: Did the Actor interfere with – put hurdles in the way of – a valid requester getting the data? The hurdles can be technical or administrative, in policy or practice, intended or unintended. The assessment of whether information blocking occurred includes the features and functions for hardware and software within the Actor’s control.
You must always follow HIPAA
You must always follow state law prohibitions (if allowed by HIPAA)
You must always follow other federal laws for privacy (e.g., 42 CFR part 2 protecting Substance Use Disorder records)
If a case-specific assessment indicates there was interference, but one of the eight available exceptions applies, then the episode will not be information blocking 21 ©2021 Cox & Osowiecki, LLC<br>
slide22. Information Blocking -- Eight Exceptions Five exceptions that might excuse a complete denial of access, exchange or use:
Preventing Harm Exception
Privacy Exception
Security Exception
Infeasibility Exception
Health IT Performance Exception
Three exceptions that allow modification or additional features (i.e., allows some level of interference) when providing access, exchange or use:
Content and Manner Exception
Fees Exception
Licensing Exception
You can read pages and pages of detailed, official commentary and guidance in the May 1, 2020 Federal Register on pages 25820-25900:
https://www.govinfo.gov/content/pkg/FR-2020-05-01/pdf/2020-07419.pdf 22 ©2021 Cox & Osowiecki, LLC<br>
slide23. Warning On The Exceptions: The Devil Is In the Details You will need to reduce some of the exceptions to written policies
When you draft those policies, you need to pay careful attention to the extensive criteria for each exception – the rule and the interpretive guidance from the rule (use the federal register link)
You will need to crosswalk with your HIPAA policies
Your internal analysis may require a more specific review, and multi-disciplinary input (clinical, legal/compliance, HIM, information systems, information security, etc.)
Most of the exceptions require application in a non-discriminatory manner for like-requesters
This is meant to stop providers form favoring their own system or blocking out competitors
Goals of the Information Blocking Rule include: to change providers’ thinking so that operationally you favor flow of data, you share data if/when it’s not prohibited by law to do so, you de-emphasize the perception that you should aggressively protect data, you accept that you do not own the data 23 ©2021 Cox & Osowiecki, LLC<br>
slide24. Ingesting And Utilizing the Exceptions The following is a high-level overview to introduce the exceptions.
You will need to drill down to assess for your operations, policies, and practices.
This is not a one-size fits all situation.
There is no plug-in or template. 24 ©2021 Cox & Osowiecki, LLC<br>
slide25. Preventing Harm Exception [45 CFR 171.201] Preventing Harm Exception: It will not be information blocking for an Actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain (extensive) conditions are met. Key conditions:
The Actor must hold a reasonable belief that the interference/practice will substantially reduce a risk of harm and the interference/practice must be no broader than necessary
The Actor’s practice must satisfy at least one condition of each part of the rule:
Type of risk must be either a safety issue based on professional judgment or based on a perceived flaw in the data (e.g., mismatched or corrupt file)
Type of harm must be within HIPAA denial of access rule
Implementation basis: the practice is either based on an organizational policy or a determination specific to the facts and circumstances 25 ©2021 Cox & Osowiecki, LLC<br>
slide26. Preventing Harm Exception Considerations Do not overuse the “harm” exception
The circumstances under which this would be appropriate and still HIPAA compliant will be rare
It is confined to those very limited instances where denial of access would be appropriate based on a true safety concern, or the data are irretrievably flawed
You will need a policy to functionalize this – be sure to leave sufficient flexibility for case-by-case professional judgment determinations
There is significant industry chatter about how this applies to withholding or delaying release of lab results
Follow OCR’s HIPAA FAQs on release (and CLIA, as applicable)
Do not delay lab results release any longer than what you already have in place 26 ©2021 Cox & Osowiecki, LLC<br>
slide27. Preventing Harm Exception Examples Appropriate use of the exception:
A patient requests their entire record. The facility releases only part of the record, holding back specific portions because:
Psychiatrist concludes, based on her professional judgment and in conformity with the institution’s HIPAA policies and documentation procedures, that a patient should not receive specific care entries in their designated record set record because receipt of those entries by the patient would likely cause significant risk that the patient would injure themselves or others.
Inappropriate or suspect use of the exception:
A patient requests their entire record. The facility refuses release and locks down the record per policy because:
The record is full of recent reports, labs, and provider notes that contain really bad news, and the patient is not yet aware. Physicians in the facility prefer to give patients “bad news” in person. The patient will not be given access to their information until they are able to speak directly with their provider who ordered the test. (That likely violates both HIPAA and Information Blocking.) 27 ©2021 Cox & Osowiecki, LLC<br>
slide28. Privacy Exception [45 CFR 171.202] Privacy Exception: It will not be information blocking if an Actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain (extensive) conditions are met. Key conditions:
A legal pre-condition is not yet met (e.g., state law requires specific consent before release)
Applied in non-discriminatory manner, either:
Based on written policy
Based on individual assessment of the circumstance
If a necessary consent or authorization is the issue, you must:
Facilitate and/or provide reasonable assistance in obtaining a valid form
Not encourage or induce the individual to withhold the consent or authorization 28 ©2021 Cox & Osowiecki, LLC<br>
slide29. Privacy Exception (cont.) [45 CFR 171.202] To effect the patient’s privacy choices
Patient requests a privacy restriction or special handling and you agree (you are only required to agree to restrictions in certain HIPAA defined circumstances)
You document the request in a reasonable time
The agreed-to practice is implemented in a non-discriminatory manner
You must not encourage or induce the individual to make the restriction request
There is no patient right of access
Psychotherapy notes or information compiled for civil, criminal, or administrative action or proceeding [HIPAA 45 CFR 164.524(a)(1)]
No right of review for denial of access [HIPAA 45 CFR 164.524(a)(2)] 29 ©2021 Cox & Osowiecki, LLC<br>
slide30. Privacy Exception Examples Appropriate use of the exception:
The patient’s dermatologist requests the entire record. The provider, a mental health facility, releases only part of the record, holding back specific portions because:
Under state law, those held back portions require the patient’s consent to release.
There is no clinical reason that the information in the held back portions would be needed by the dermatologist.
Inappropriate or suspect use of the exception:
A patient’s surgeon requests the entire record. The facility refuses release because:
The patient has not provided an authorization.
The facility policy is to require patient sign off on disclosures, even for treatment, when the requester is not in an affiliated or approved practice.
If the surgeon were in a practice affiliated with the facility, the surgeon would have access to the entire record.
Note: It’s also potentially Information Blocking to encourage patients to allow your providers access (as trusted users) but infer that patients should be more choosy when agreeing to access by other providers. 30 ©2021 Cox & Osowiecki, LLC<br>
slide31. Security Exception [45 CFR 171.203] Security Exception: It will not be information blocking for an Actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain (extensive) conditions are met. The interference/practice must be:
Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
Tailored to the specific security risk being addressed; AND
Implemented in a consistent and non-discriminatory manner, where the implementation must be either:
Based on a written policy, or
If not per policy, then “based on the particularized facts and circumstances” and
Necessary to mitigate the risk; and
There are no reasonable alternatives that would be less of an interference (similar analysis to addressable specification choices under HIPAA Security Rule). 31 ©2021 Cox & Osowiecki, LLC<br>
slide32. Security Exception Examples Appropriate use of the exception:
The patient’s dermatologist requests a physician practice send the entire record using a “Share-Stuff”** app which uses an open access over the internet method. The physician practice refuses the request because:
There is no way to confirm the security of the “Share-Stuff” route, and IT staff research indicates that the product has severe, known security limitations that likely jeopardize the integrity and security of the data
The app is not recommended for health care data (even by the app itself)
The refusal is documented, consistent with policy, and other e-access options are offered to the dermatologist
Inappropriate or suspect use of the exception:
The patient’s dermatologist requests the entire record from the physician practice. The practice refuses the request because:
The patient’s dermatologist wants records sent using secure email or secure FHIR endpoint, and refuses to use a web-based portal that the primary care office instructs the dermatologist to use.
But, the practice frequently sends records to providers through secure email or a FHIR endpoint, and is always willing to do so when the provider making the request is affiliated with the practice’s health care system.
** Share-Stuff is a fictionalized name used for example only; there is no intention to refer to any actual app. 32 ©2021 Cox & Osowiecki, LLC<br>
slide33. Q&A Questions? 33 ©2021 Cox & Osowiecki, LLC<br>
slide34. Other Parts of the ONC Final Rule ONC Cures Final Rule contains significant changes to:
2015 edition CEHRT criteria
ONC HIT Certification Program
Highlights:
Export and transport standards updated
USCDI adoption, implementation changes
API standards and specifications set (FHIR Release 4 required)
Emphasis on leveraging the SVAP process (Standards Version Advancement Process
TEFCA not mandated; too new to be a requirement 34 ©2021 Cox & Osowiecki, LLC<br>
slide35. ONC and CMS 21st Century Cures Rules Resources CMS Interoperability Final Rule – this CMS site is frequently updated and contains a massive amount of information about implementation for the CMS Final Rule:
https://www.cms.gov/Regulations-and-Guidance/Guidance/Interoperability/index
ONC Information Blocking Final Rule:
https://www.healthit.gov/curesrule/
https://www.healthit.gov/sites/default/files/cures/2020-03/InformationBlockingExceptions.pdf
https://www.healthit.gov/isa/sites/isa/files/2020-03/USCDI-Version1-2020-Final-Standard.pdf
https://www.healthit.gov/isa/united-states-core-data-interoperability-uscdi 35 ©2021 Cox & Osowiecki, LLC<br>
Part One of a Two-Part Series for CMG
Presenter: Jennifer Cox, J.D.
Cox & Osowiecki, LLC 1 ©2021 Cox & Osowiecki, LLC<br>
slide2. Overview Cures Act, Two Final Rules The Cures Act is a federal law passed by Congress in December 2016 (P.L. 114-255), during the Obama administration, but most sections of the law did not take effect for years because they lacked required agency regulations
Two separate core rules, from two different agencies (CMS and ONC), are covered in this program series
Both rules affect providers, but the impact varies by type of provider
Understanding the significant distinctions, and their respective impacts, will help compliance planning and implementation
There has been very little guidance from the federal government on how to comply with the rules, providers will need to make some educated guesses on compliance strategies
(Pro tip: do not confuse the Cures Act with the Cares Act. It’s an easy mistake.) ©2021 Cox & Osowiecki, LLC 2<br>
slide3. Two Rules: Program Syllabus Details This program covers two core regulations that were published May 1, 2020 (during the height of the pandemic). They are:
CMS Final Rule “Interoperability and Patient Access” - the program includes a top line review of the CMS rule
Significant hospital requirements, but very few direct requirements for physician practices, but there are some
Misnamed to a degree in that it does not supply a patient access framework that applies to providers – its patient access framework is directed at specific government payers
ONC Final Rule “Interoperability, Information Blocking, and the Office of the National Coordinator (ONC) Health IT Certification Program”
Detailed review of the information blocking provisions of the ONC Final Rule
Step-by-step analysis of the eight (8) information blocking exceptions that should be incorporated into practices and polices 3 ©2021 Cox & Osowiecki, LLC<br>
slide4. 21st Century Cures CMS Rule (CMS-9115-F) CMS Final Rule: Interoperability and Patient Access final rule (CMS-9115-F) (effective dates vary – spread across 2021 and 2022)
Most sections of the CMS Rule apply only to these designated government payers, government health insurance programs, and federally approved health plans:
Medicare Advantage (MA), Medicaid, CHIP, Qualified Health Plan (QHP) issuers on the Federally-facilitated Exchanges (FFEs)
Those rule sections are: Patient Access API; Provider Directory API; Payer-to-Payer Data Exchange; Improving the Dually Eligible Experience by Increasing the Frequency of Federal-State Data Exchanges
Two sections apply to all providers, including physician practices:
Public Reporting and Information Blocking
Provider Digital Contact Information
One section applies to hospitals only: Admission, Discharge, and Transfer Event Notifications
Physician practices should be aware that this is hospital-only
It will cause an increase in incoming data to certain providers 4 ©2021 Cox & Osowiecki, LLC<br>
slide5. CMS: Public Reporting and Information Blocking This applies to physicians:
For physicians: a ‘‘No’’ response given to any of the three prevention of information blocking attestation statements for Merit-Based Incentive Payment System (MIPS) will result in an indicator on Physician Compare of information blocking
Targeted for implementation “early 2021” – using 2019 Promoting Interoperability attestation year data
There is no specific penalty listed for non-compliance, but the Rule’s commentary specifically notes:
“…section 3022(b)(2)(B) of the PHSA, which provides that any health care provider determined by the Office of the Inspector General (OIG) to have committed information blocking shall be referred to the appropriate agency to be subject to appropriate disincentives using authorities under applicable federal law, as the Secretary sets forth through notice and comment rulemaking.” 5 ©2021 Cox & Osowiecki, LLC<br>
slide6. CMS: Provider Digital Contact Information This applies to physicians:
Cures Act requires HHS to establish a provider digital contact information index, and allows use of an existing database - CMS plans to use the National Plan and Provider Enumeration System (NPPES) to meet this requirement
NPPES system: can capture Direct Address, a FHIR server URL, and query endpoints associated with a health information exchange; has the ability to maintain information about the type of contact information providers and organizations are associated with and the preferred uses for each address (providers can maintain their own unique information or associate themselves with information shared among a group of providers); and has a public API, which can be used to obtain the digital contact information stored in NPPES 6 ©2021 Cox & Osowiecki, LLC<br>
slide7. CMS: Provider Digital Contact Information This applies to physicians:
Providers can review and update their NPPES NPI Registry Profile:
https://nppes.cms.hhs.gov
Providers should include secure endpoint, Direct Address contact information at a minimum (no personal email; FHIR endpoint preferred)
Targeted for end of first quarter of 2021, CMS may (will?) begin posting the names of providers who fail to list their digital contact information in the National Plan and Provider Enumeration System (NPPES)
At this time CMS is not establishing a penalty for failure to report digital contact information. The Agency stated that it may consider penalties as well as incentives in future rulemaking. Instead, CMS finalized its policy to publicly report the names and NPIs of providers that do not include digital contact information in NPPES 7 ©2021 Cox & Osowiecki, LLC<br>
slide8. New Hospital Requirement: Send E-notifications Starting May 1, 2021, hospitals must make a reasonable effort to send real-time ADT notifications to applicable post-acute providers; primary care practitioners, practice groups and entities; and any other entity identified by the patient as being responsible for patient’s primary care that need the information for treatment, care coordination, or quality improvement activities
Real-time notifications must contain at least patient name, treating practitioner name, and sending institution name
For each registration, discharge, or transfer to or from the hospital’s emergency department and/or admission, discharge or transfer to or from the hospital’s inpatient services
Can be sent directly, or through an intermediary
Collateral effect: Primary care physicians (and likely other providers) will receive far more of these messages than they do now
Physician practices need a plan to handle, process these notifications ©2021 Cox & Osowiecki, LLC 8<br>
slide9. Next up: ONC Information Blocking Rule The ONC Information Blocking Rule is the most important change to health information since HIPAA started.
Compliance with the ONC Information Blocking Rule
is expected beginning April 5, 2021.
Fair Warning: You may feel frustrated as we go through the rule and unpack the components. The rule is unnecessarily complicated and not well-aligned with HIPAA or state records laws. 9 ©2021 Cox & Osowiecki, LLC<br>
slide10. Good News About The Information Blocking Rule Eventually, health data will flow more easily through a variety of readily available technologies; patients will have better and quicker access to allow them to engage in their care; research will flourish; population health and public health will be able to rely on data driven planning, evidence and experts. 10 ©2021 Cox & Osowiecki, LLC<br>
slide11. More Good News!! Penalties for healthcare providers do not currently include civil monetary penalties (i.e., no obvious mechanism for fines), although violations could lead to referrals to other oversight agencies and related penalties for violations of other laws or program requirements. 11 ©2021 Cox & Osowiecki, LLC<br>
slide12. Not-So-Good News At this stage the landscape is highly conceptual, drastically different than current practice, and is misaligned with HIPAA. We have insufficient regulatory guidance, making it virtually impossible to know how to correctly manage operations, revise policies, and adjust practices in order to comply.
(Also, the ongoing pandemic requires significant attention and resources for providers and the government, making Cures Act readiness harder to prioritize. 12 ©2021 Cox & Osowiecki, LLC<br>
slide13. Who Has To Comply With Information Blocking? Information Blocking affects three categories of entities called “Actors”:
Healthcare Providers (without regard to their HIPAA status**)
Health Information Exchanges and Health Information Networks (HIE/HIN)
This is very broadly defined, it is not only official or declared HIEs
Essentially, it can be any entity that helps two or more providers exchange data
Applies to a HIPAA business associate if the BAA plays an exchange role
Health IT developers, who offer Certified Electronic Health Record Technology (CEHRT)
**An Actor retains its HIPAA status (e.g., covered entity, business associate) and must comply with both HIPAA and Cures Rules simultaneously. Providers that are not governed by HIPAA still have to comply with information blocking rules. 13 ©2021 Cox & Osowiecki, LLC<br>
slide14. Information Blocking Basics An Actor is “Information Blocking” if it has practices that are:
“likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information”
If you fail to provide access, without delay, to a person who is permitted to have access under HIPAA and other laws, you can be accused of information blocking 14 ©2021 Cox & Osowiecki, LLC<br>
slide15. ONC Information Blocking – Concept Information blocking rules assume that if a patient, or any other entity or individual is permitted by HIPAA to access records, they should be given access without delay, using almost any technology the requester chooses
Technology choices are described in the ONC Rule, and include third party Application Programming Interface (APIs)
The data involved go well beyond treatment, payment, and operations (HIPAA TPO) and include any other HIPAA “permitted” access
The access request does not need to be triggered by, or even known to a patient
There are eight very specific exceptions, with complex implementation standards, detailing how data requests that you do not fulfill might escape being information blocking 15 ©2021 Cox & Osowiecki, LLC<br>
slide16. Intersection With HIPAA Information Blocking rules necessarily change how providers will approach access requests and release of records
Under current practice, and consistent with HIPAA, there are a multitude of circumstances for which you might deny (or even ignore) a “voluntary” request for data from a non-patient
E.g., public health voluntary requests, or a request from a provider with whom you are unfamiliar
Under information blocking you cannot safely deny (or ignore) the request, and will need significant documentation if you do not fulfill the request
Information Blocking talks about “patient preference” but is decidedly less interested in patient consent or authorizations, unless:
Consent or authorization is mandatory under HIPAA, or another (privacy) law
Or you have woven the consent or authorization process into a policy that revolves around and is focused on the eight exceptions in the information blocking rule 16 ©2021 Cox & Osowiecki, LLC<br>
slide17. What Data Are Subject To Information Blocking Electronic Health Information, or EHI
Until June 2022, EHI is the data in the United States Core Data for Interoperability (“USCDI” – specifically USCDI v.1); starting June 2022, Information Blocking applies to the entire HIPAA designated record set
HIPAA already requires providers to release the entire Designated Record Set
EHI does not include de-identified data (using HIPAA de-identification standards)
The USCDI is a core set of data elements. USCDI replaces the nomenclature “Common Clinical Data Set”. Previously Continuity of Care Documents (CCDs) were routinely derived from the Common Clinical Data Set data framework, and now CCDs will be routinely derived from the USCDI data set.
With a few additions in USCDI, including:
Clinical Notes: structured and unstructured
You may have heard the term “Open Notes”
Provenance: author, author time stamp, author organization 17 ©2021 Cox & Osowiecki, LLC<br>
slide18. USCDI vs CCDs 18 *Address includes both current and previous, as well as e-mail address. ©2021 Cox & Osowiecki, LLC<br>
slide19. Key Data Terms Overlap – But Are Not All Identical Designated Record Set has the same definition in HIPAA and Information Blocking:
“Designated record set” means:
(1) medical or billing records maintained by healthcare providers;
(2) enrollment, payment, claims adjudication, and/or case or medical records maintained by health plans; or
(3) information relevant to covered entities to make decisions about individuals
Other Terms: 19 ©2021 Cox & Osowiecki, LLC<br>
slide20. HIPAA Still Drives Direct Access Release Information Blocking is designed to provide more routes of access for patients (e.g., APIs, quicker access, less hassle) – patients choose how they want to access or ingest ePHI and EHI
Patients already have a very strong right to access their own records (HIPAA 45 CFR 164.524)
There are very few times when you can deny patients access to their own records, for example:
Safety hold
Not part of designated record set
In some cases, HIPAA-defined “psychotherapy notes”
Information Blocking Rule does NOT limit patients’ HIPAA rights to access their own records
DO NOT interpret any part of Information Blocking as making it harder for patients to access their own records; do not add fees; do not add paperwork; do not add consent features – patient access should be the same or easier 20 ©2021 Cox & Osowiecki, LLC<br>
slide21. Assessing Information Blocking Information Blocking is assessed on a case-by-case basis and is complaint-based
Assessment: Did the Actor interfere with – put hurdles in the way of – a valid requester getting the data? The hurdles can be technical or administrative, in policy or practice, intended or unintended. The assessment of whether information blocking occurred includes the features and functions for hardware and software within the Actor’s control.
You must always follow HIPAA
You must always follow state law prohibitions (if allowed by HIPAA)
You must always follow other federal laws for privacy (e.g., 42 CFR part 2 protecting Substance Use Disorder records)
If a case-specific assessment indicates there was interference, but one of the eight available exceptions applies, then the episode will not be information blocking 21 ©2021 Cox & Osowiecki, LLC<br>
slide22. Information Blocking -- Eight Exceptions Five exceptions that might excuse a complete denial of access, exchange or use:
Preventing Harm Exception
Privacy Exception
Security Exception
Infeasibility Exception
Health IT Performance Exception
Three exceptions that allow modification or additional features (i.e., allows some level of interference) when providing access, exchange or use:
Content and Manner Exception
Fees Exception
Licensing Exception
You can read pages and pages of detailed, official commentary and guidance in the May 1, 2020 Federal Register on pages 25820-25900:
https://www.govinfo.gov/content/pkg/FR-2020-05-01/pdf/2020-07419.pdf 22 ©2021 Cox & Osowiecki, LLC<br>
slide23. Warning On The Exceptions: The Devil Is In the Details You will need to reduce some of the exceptions to written policies
When you draft those policies, you need to pay careful attention to the extensive criteria for each exception – the rule and the interpretive guidance from the rule (use the federal register link)
You will need to crosswalk with your HIPAA policies
Your internal analysis may require a more specific review, and multi-disciplinary input (clinical, legal/compliance, HIM, information systems, information security, etc.)
Most of the exceptions require application in a non-discriminatory manner for like-requesters
This is meant to stop providers form favoring their own system or blocking out competitors
Goals of the Information Blocking Rule include: to change providers’ thinking so that operationally you favor flow of data, you share data if/when it’s not prohibited by law to do so, you de-emphasize the perception that you should aggressively protect data, you accept that you do not own the data 23 ©2021 Cox & Osowiecki, LLC<br>
slide24. Ingesting And Utilizing the Exceptions The following is a high-level overview to introduce the exceptions.
You will need to drill down to assess for your operations, policies, and practices.
This is not a one-size fits all situation.
There is no plug-in or template. 24 ©2021 Cox & Osowiecki, LLC<br>
slide25. Preventing Harm Exception [45 CFR 171.201] Preventing Harm Exception: It will not be information blocking for an Actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain (extensive) conditions are met. Key conditions:
The Actor must hold a reasonable belief that the interference/practice will substantially reduce a risk of harm and the interference/practice must be no broader than necessary
The Actor’s practice must satisfy at least one condition of each part of the rule:
Type of risk must be either a safety issue based on professional judgment or based on a perceived flaw in the data (e.g., mismatched or corrupt file)
Type of harm must be within HIPAA denial of access rule
Implementation basis: the practice is either based on an organizational policy or a determination specific to the facts and circumstances 25 ©2021 Cox & Osowiecki, LLC<br>
slide26. Preventing Harm Exception Considerations Do not overuse the “harm” exception
The circumstances under which this would be appropriate and still HIPAA compliant will be rare
It is confined to those very limited instances where denial of access would be appropriate based on a true safety concern, or the data are irretrievably flawed
You will need a policy to functionalize this – be sure to leave sufficient flexibility for case-by-case professional judgment determinations
There is significant industry chatter about how this applies to withholding or delaying release of lab results
Follow OCR’s HIPAA FAQs on release (and CLIA, as applicable)
Do not delay lab results release any longer than what you already have in place 26 ©2021 Cox & Osowiecki, LLC<br>
slide27. Preventing Harm Exception Examples Appropriate use of the exception:
A patient requests their entire record. The facility releases only part of the record, holding back specific portions because:
Psychiatrist concludes, based on her professional judgment and in conformity with the institution’s HIPAA policies and documentation procedures, that a patient should not receive specific care entries in their designated record set record because receipt of those entries by the patient would likely cause significant risk that the patient would injure themselves or others.
Inappropriate or suspect use of the exception:
A patient requests their entire record. The facility refuses release and locks down the record per policy because:
The record is full of recent reports, labs, and provider notes that contain really bad news, and the patient is not yet aware. Physicians in the facility prefer to give patients “bad news” in person. The patient will not be given access to their information until they are able to speak directly with their provider who ordered the test. (That likely violates both HIPAA and Information Blocking.) 27 ©2021 Cox & Osowiecki, LLC<br>
slide28. Privacy Exception [45 CFR 171.202] Privacy Exception: It will not be information blocking if an Actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain (extensive) conditions are met. Key conditions:
A legal pre-condition is not yet met (e.g., state law requires specific consent before release)
Applied in non-discriminatory manner, either:
Based on written policy
Based on individual assessment of the circumstance
If a necessary consent or authorization is the issue, you must:
Facilitate and/or provide reasonable assistance in obtaining a valid form
Not encourage or induce the individual to withhold the consent or authorization 28 ©2021 Cox & Osowiecki, LLC<br>
slide29. Privacy Exception (cont.) [45 CFR 171.202] To effect the patient’s privacy choices
Patient requests a privacy restriction or special handling and you agree (you are only required to agree to restrictions in certain HIPAA defined circumstances)
You document the request in a reasonable time
The agreed-to practice is implemented in a non-discriminatory manner
You must not encourage or induce the individual to make the restriction request
There is no patient right of access
Psychotherapy notes or information compiled for civil, criminal, or administrative action or proceeding [HIPAA 45 CFR 164.524(a)(1)]
No right of review for denial of access [HIPAA 45 CFR 164.524(a)(2)] 29 ©2021 Cox & Osowiecki, LLC<br>
slide30. Privacy Exception Examples Appropriate use of the exception:
The patient’s dermatologist requests the entire record. The provider, a mental health facility, releases only part of the record, holding back specific portions because:
Under state law, those held back portions require the patient’s consent to release.
There is no clinical reason that the information in the held back portions would be needed by the dermatologist.
Inappropriate or suspect use of the exception:
A patient’s surgeon requests the entire record. The facility refuses release because:
The patient has not provided an authorization.
The facility policy is to require patient sign off on disclosures, even for treatment, when the requester is not in an affiliated or approved practice.
If the surgeon were in a practice affiliated with the facility, the surgeon would have access to the entire record.
Note: It’s also potentially Information Blocking to encourage patients to allow your providers access (as trusted users) but infer that patients should be more choosy when agreeing to access by other providers. 30 ©2021 Cox & Osowiecki, LLC<br>
slide31. Security Exception [45 CFR 171.203] Security Exception: It will not be information blocking for an Actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain (extensive) conditions are met. The interference/practice must be:
Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
Tailored to the specific security risk being addressed; AND
Implemented in a consistent and non-discriminatory manner, where the implementation must be either:
Based on a written policy, or
If not per policy, then “based on the particularized facts and circumstances” and
Necessary to mitigate the risk; and
There are no reasonable alternatives that would be less of an interference (similar analysis to addressable specification choices under HIPAA Security Rule). 31 ©2021 Cox & Osowiecki, LLC<br>
slide32. Security Exception Examples Appropriate use of the exception:
The patient’s dermatologist requests a physician practice send the entire record using a “Share-Stuff”** app which uses an open access over the internet method. The physician practice refuses the request because:
There is no way to confirm the security of the “Share-Stuff” route, and IT staff research indicates that the product has severe, known security limitations that likely jeopardize the integrity and security of the data
The app is not recommended for health care data (even by the app itself)
The refusal is documented, consistent with policy, and other e-access options are offered to the dermatologist
Inappropriate or suspect use of the exception:
The patient’s dermatologist requests the entire record from the physician practice. The practice refuses the request because:
The patient’s dermatologist wants records sent using secure email or secure FHIR endpoint, and refuses to use a web-based portal that the primary care office instructs the dermatologist to use.
But, the practice frequently sends records to providers through secure email or a FHIR endpoint, and is always willing to do so when the provider making the request is affiliated with the practice’s health care system.
** Share-Stuff is a fictionalized name used for example only; there is no intention to refer to any actual app. 32 ©2021 Cox & Osowiecki, LLC<br>
slide33. Q&A Questions? 33 ©2021 Cox & Osowiecki, LLC<br>
slide34. Other Parts of the ONC Final Rule ONC Cures Final Rule contains significant changes to:
2015 edition CEHRT criteria
ONC HIT Certification Program
Highlights:
Export and transport standards updated
USCDI adoption, implementation changes
API standards and specifications set (FHIR Release 4 required)
Emphasis on leveraging the SVAP process (Standards Version Advancement Process
TEFCA not mandated; too new to be a requirement 34 ©2021 Cox & Osowiecki, LLC<br>
slide35. ONC and CMS 21st Century Cures Rules Resources CMS Interoperability Final Rule – this CMS site is frequently updated and contains a massive amount of information about implementation for the CMS Final Rule:
https://www.cms.gov/Regulations-and-Guidance/Guidance/Interoperability/index
ONC Information Blocking Final Rule:
https://www.healthit.gov/curesrule/
https://www.healthit.gov/sites/default/files/cures/2020-03/InformationBlockingExceptions.pdf
https://www.healthit.gov/isa/sites/isa/files/2020-03/USCDI-Version1-2020-Final-Standard.pdf
https://www.healthit.gov/isa/united-states-core-data-interoperability-uscdi 35 ©2021 Cox & Osowiecki, LLC<br>