Artificial Intelligence in Healthcare
Artificial Intelligence

Part 2: Who Regulates Healthcare AI?

Artificial Intelligence & Regulatory Compliance


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest articles.  As stated in Part 1, the Office of the National Coordinator for Health Information Technology (ONC) and the Agency for Healthcare Research and Quality (AHRQ), with support from the Robert Wood Johnson Foundation, turned to an independent group of scientists and academics to consider how AI might shape the future of public health, community health, and healthcare delivery.  The question remains, how will the use of AI be regulated for health care use?


Artificial Intelligence/Machine Learning has gained heightened attention globally.  Augmented Intelligence has been embraced as a concept by physician organizations to underscore that emerging AI systems are designed to aid humans in clinical decision-making, implementation and administration to scale healthcare, according to Act Online Key Terminology for AI in Health.


Although the United States is making progress in developing domestic AI regulation, including with the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the existing laws and regulations that apply to AI systems is still a work-in-progress.  The goals are to protect people from unsafe or ineffective systems. 


So, Who Regulates Healthcare AI?


What seems like a simple question is really a complex situation.  This article only scratches the surface of various regulatory agencies involved in the regulation of AI.  The Health & Human Services (HHS) response to OMB Memorandum 21-06 “Guidance for Regulation of Artificial Intelligence Applications” was drafted in November 2020 and is directed to the heads of all Executive Branch departments and agencies, including independent regulatory agencies.  Much has happened since then.


On April 25, 2023, the Federal Trade Commission (FTC), the Civil Rights Division of the U.S. Department of Justice (DOJ), the Consumer Financial Protection Bureau (CFPB), and the U.S. Equal Employment Opportunity Commission (EEOC) released a joint statement highlighting their commitment to "vigorously use [their] collective authorities to protect individuals" with respect to artificial intelligence and automated systems (AI), which have the potential to negatively impact civil rights, fair competition, consumer protection, and equal opportunity.


The joint statement from the DOJ, FTC, CFPB, and EEOC signifies a growing awareness and concern among federal agencies about the potential risks and challenges posed by AI and automated systems. As AI continues to become more integrated into all aspects of daily life, the importance of addressing potential biases, transparency issues, and flawed design becomes increasingly critical.


Federal Trade Commission (FTC) Raises Concerns


The FTC’s mission is to protect consumers and competition through preventing anticompetitive, deceptive and unfair business practices.  This is achieved through law enforcement, advocacy, and education without unduly burdening legitimate business activity.  The FTC Act’s prohibition on deceptive or unfair conduct can apply if you make, sell, or use a tool that is effectively designed to deceive – even if that’s not its intended or sole purpose. The FTC’s action should help protect healthcare organizations by limiting deceptive or exaggerated promises of what a medical device or AI software can actually do.  It’s not uncommon for advertisers to say that some new-fangled technology makes their product better – perhaps to justify a higher price or influence labor decisions.


On May 18, 2023, the FTC issued a warning that the increasing use of consumers’ biometric information and related technologies, including those powered by machine learning, raises significant consumer privacy and data security concerns and the potential for bias and discrimination. Biometric information refers to data that depict or describe physical, biological, or behavioral traits, characteristics, or measurements of or relating to an identified or identifiable person’s body.


The Federal Drug Administration & AI


The Food & Drug Administration (FDA) released a discussion paper in 2019 and then an action plan on January 21, 2021 regarding Artificial Intelligence and Machine Learning, or AI/ML.  This action plan describes a multi-pronged approach to advance the Agency’s oversight of AI/ML-based medical software.  Then, in April 2023, the FDA is publishing a draft guidance, "Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning (AI/ML)-Enabled Device Software Functions."

  • This draft guidance proposes a science-based approach to ensuring that AI/ML-enabled devices can be safely, effectively, and rapidly modified, updated, and improved in response to new data.

The approach the FDA is proposing in this draft guidance would put safe and effective advancements in the hands of health care providers and users faster, increasing the pace of medical device innovation in the United States and enabling more personalized medicine.

  • This means, for example, that diagnostic devices could be built to adapt to the data and needs of individual health care facilities and that therapeutic devices could be built to learn and adapt to deliver treatments according to individual users' particular characteristics and needs.

National Institute of Standards and Technology (NIST) AI Risk Management Framework


Released on January 26, 2023, NIST’s AI Risk Management Framework or “AI RMF” which is intended to be used voluntarily to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.  The Framework was developed through a consensus-driven, open, transparent, and collaborative process with the intention to build on, align with, and support AI risk management efforts by others.


Recently NIST launched the Trustworthy and Responsible AI Resource Center (AIRC), which will facilitate implementation of, and international alignment with, the AI RMF.  We recommend watching the introduction video:  https://www.nist.gov/video/introduction-nist-ai-risk-management-framework-ai-rmf-10-explainer-video


For healthcare HIPAA covered entities, NIST is likely a familiar organization to you.  NIST published prior documents related to AI.  The initial draft of the AI RMF was published March 17, 2022 and a second draft on August 18, 2022.


The Health Insurance Portability and Accountability Act (HIPAA)

Public Law 104-191


The Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160 and 164, Subparts A, C, and E). One of the ways that OCR carries out this responsibility is to investigate complaints.  As health care organizations evolve with the use of AI, there is increased potential for cyber criminals to exploit vulnerabilities.


At the present, there are two exclusions existing in the HIPAA Privacy Rule that allow Covered Entities to share Protected Health Information (PHI) with device vendors and other organizations without the authorization of the individual(s) to whom the PHI relates. The two exclusions can be found in 45 CFR §164.512(b)(1) and 45 CFR §164.512(i)(1). Respectively, they relate to:

  • Disclosures to vendors regulated by the Federal Drug Administration are permitted by the Privacy Rule for the “purpose of activities related to the quality, safety or effectiveness of such FDA-regulated product or activity”.   The FDA regulates the sale of all medical device products, including personal health devices that transmit data to AI-driven healthcare solutions as described above.
  • PHI can also be disclosed without authorization for research purposes without being de-identified if the disclosure is approved by an Institutional Review Board or Privacy Board. In such circumstances, the disclosed PHI must remain in the possession of the Covered Entity and the disclosure(s) can only be for the purpose of preparatory research (i.e., programming a “Supervised Learning Algorithm”).


Conclusion


Simply stated, a shift to AI calls for new skills.  It warrants increased knowledge of HIPAA privacy, security and anticipating other legal issues surrounding it’s use in healthcare.


Needless to say, it is important to maintain a robust HIPAA program and utilize information from the National Institute of Standards and Technology (NIST) AI Risk Management Framework as mentioned above.


In the context of HIPAA, healthcare data, and AI technologies, AI developers and vendors should consider that HIPAA only provides a federal floor of privacy and security standards. Often, other state and federal laws can apply that pre-empt HIPAA – particularly with regard to healthcare adjacent data – or apply to more organizations than Covered Entities and Business Associates.  Also, many Managed Service Providers (MSP) companies providing services to healthcare organizations should be aware of AI applications and security vulnerabilities.


If your organization plans or is using AI for medical diagnostics, reference the annual joint publication by the U.S. Government Accountability Office (GAO) and the National Academy of Medicine published each September entitled “Technology Assessment – Artificial Intelligence in Health Care – Benefits and Challenges of Machine Learning Technologies for Medical Diagnostics”.   A new publication is posted each year: https://www.gao.gov/products/gao-22-104629


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
HIPAA Compliance
HIPAA

How to Handle Passwords Like a Boss!

Written by: J. David Sims, CHITSP, CHMSP, Managing Partner at Security First IT, LLC; Board Member with the American Institute of Healthcare Compliance; Podcaster, Speaker, & HIPAA Instructor; Help Me with HIPAA Podcast Contributor and Federal HICP 405(d) Task Group & HIC-TCR Task Group




Cybersecurity starts with the basics, such as appropriately managing passwords within your organization. The Health Insurance Portability & Accountability Act (HIPAA) requires access controls and password management, which requires a top-down approach within your organization. Whether you are a Covered Entity or Business Associate, handle it like a boss!

In a recent article by Joanne Byron, she discussed one of the biggest challenges with proper password management… password sharing! In this article, I’m going to introduce you to some ways that you can overcome this challenge in your organization.

First, let’s start by setting three ground rules that I use for cybersecurity:

Rule #1 – Security is not convenient

Rule #2 – Security is not optional

Rule #3 – Security should not unnecessarily hinder the user

Understand that by design, security is there to hinder or stop an action. Think of your house for a minute. I have a sign in my yard advertising that I have monitored security in my home. I also have an alarm system, a deadbolt, a dog, and a shotgun. All these things represent different levels of security and incident response. They all cost me money and they are all inconvenient in some way. To protect my family, my most precious assets, is not optional. However, I can’t make this level of security so inconvenient that it doesn’t work. Therefore, I’ve ensured that these levels of security do not hinder my family’s ability to quickly enter and exit the home.

Security is there to deter the bad guys and to keep out those who should not be in my home (like the in-laws).

Passwords are just one layer of security for your electronic Protected Health Information and other digital assets. It is also a layer of security that is heavily dependent on the user… the human. The human must follow your password policy so that proper passwords are created and used in the correct manner. However, like a flowing river, humans will often find the path of least resistance (or create one) to get their job done.

Therefore, it is so important to train employees on your password policy, why passwords matter, what can happen when passwords are shared, and so on. Equally important is that the organization should take reasonable measures to make using passwords not a huge hinderance. Let’s take a look at some solutions to help your team be password ninjas!

Password Managers

Password managers are a fantastic tool for… you guessed it… managing passwords! I could not do without a password manager. At last check, I had over 1700 unique passwords stored in my password manager.

Password managers offer an array of other benefits and services but at its core, a password manager allows you to store all your passwords in a single, secure place. Instead of having to remember dozens or hundreds of passwords, the user only has to remember the one password that opens their password manager. Think of it as a vault for your passwords.

Another feature of most password managers that I love is the ability for me to share a password with someone without giving them the password. There are a few ways this can be used. I can set up a user account for someone and program their password into the password manager so that they can login to the application using their own credentials, and they never see the password. This ensures that a user can’t use their credentials outside of the office to access anything business related.

This is also very helpful for those websites that do not allow for multiple user accounts, but you still need multiple users to access it and use it. I see this often in practices where a business website only gives the practice a single account to use. The practice uses the same username and password for every employee that needs access to that website. Even worse, when employees leave the practice the credentials are not changed, which allows the separated employee to assess the site from anywhere.

There are several additional benefits of a good password manager application, so investigate one for your organization. They are well worth the small investment.

Creating Passwords

Whether you use a password manager or not, you still must deal with creating secure, unique passwords. Remember, you do not want to have the same password used more than once. Using the same password for everything is like having one key for your house, your car, your office, as well as all your past houses, cars, and offices. Oh, and the key has your name and address on it. Can you see how important it is to use different passwords everywhere?

Before we continue, it is important for you to understand that the bad guys aren’t trying to login to your online accounts typing in one password at a time hoping to get lucky. The bad guys use software automation and databases of passwords to throw at your accounts. This is called a brute force attack.

They know that most people are lazy and use terrible passwords. The most common password is 123456. You may laugh, but this password has been exposed in breaches more than 23 million times. It seems that no matter how terrible of a password it is, people still use it. For these people convenience is a higher priority than security. I wonder if these same people leave their car and homes unlocked… because, yeah… fumbling for a key is not convenient either.

Just a few months ago, the cybersecurity world learned of a leaked list of passwords called RockYou2021. This massive list of breached passwords and passwords from other sources comprises an impressive list of 8.4 billion unique passwords. 8.4 billion!!! Is there a chance that a password you use will show up on a list that size? Yeah, most likely. Unless you are one of the smart ones that use good password creation practices.

Since I’ve already mentioned password managers, it is worth noting that most password managers come with a password generator built-in that allows you to select a few criteria for your password and presto, it creates a password for you to use. Whether you’re using a password manager or not, here are some criteria to consider for your secure password:

Size Matters

Length is more important than complexity. Forever and a day we’ve heard that password complexity is necessary. Well, after years of research, we’re finding that all that complexity lends itself to creating other problems.

Many users fulfill this complexity requirement the same way by simply capitalizing the first letter of the password and adding a 1 or ! to the end. If I just guessed 25% of your password, you should be relegated to using a manual typewriter for the next month. Your password should be at least 8 characters (I prefer 12 to 16) minimum. The longer the password, the harder it is for software to crack it.

Change Is Good, or Is It?

Consider eliminating or reducing periodic password resets. We are also finding out that having people change their passwords too often means that they can’t remember them. I can often tell how many times someone has changed their password by how many exclamations they have at the end. Every time there was a password change, they simply added an exclamation.

If you are using secure passwords, there is no need to change them unless they become compromised in any way. However, knowing if they are compromised becomes super important and your organization should subscribe to services that monitor your accounts for compromised credentials. This brings us to the next point.

You Made the List! That Sucks.

Every password should be checked against known “blacklists” that include dictionary words, repetitive or sequential strings, passwords taken in prior security breaches, variations on the site name, commonly used passphrases, or other words and patterns that cybercriminals are likely to guess. Using a password that is on a Blacklist makes the password almost useless. Imagine if your home had one of those digital keypads for keyless entry. Now, imagine that there was a list floating around your town that had your home’s key code. How would it make you feel that thousands of strangers can easily walk right into your home if they desire? Using a compromised password is much the same.

Lie… Seriously!

You know those password hints you had to create to set up your bank account? Chances are, those answers are fairly easy to get by just paying attention to your social media accounts and what you share online. Heck, the answers may even be able to be socially engineered out of you.

When presented with these password hints and security questions… lie like crazy! What’s my mother’s maiden name? NunYoBitNess!

Get creative and have fun with it but remember you may need to use these answers at some point to recover or reset your real password, so you need to keep this information. I hate to keep coming back to password managers, but most of them also allow you to keep secure notes in your vault (it’s not just for passwords).

What Do You Have? What Do You Know?

Multi-factor (MFA) or Two-factor (2FA) authentication requires users to authenticate themselves using something they know and something they have.

2FA has been around for a very long time. If you’ve ever used an ATM machine to get cash, you’ve used 2FA. You used your card (something you have) and your PIN (something you know).

Using 2FA will likely require that you use an “Authenticator” app. There are many available but stick with the known companies like Google, Microsoft, Authy, etc.

I highly recommend using 2FA everywhere it is available. Even if someone has your username and password, it will be difficult for them to get past your additional authentication methods.

Wrapping It Up

Now that you know how to create secure passwords, how to store them safely, and how to manage them properly, you are ready to go out into the world and show everyone in your organization how they too can handle passwords like a boss!

Want More Information on HIPAA Compliance?

Help Me With HIPAA is the most popular, longest running podcast of its kind. Patient care starts from the moment a person entrusts you with their personal information. Join Donna and David each week as they deliver HIPAA and humor in a way you've never experienced. Who says learning can't be fun? Not us!


Train Online in HIPAA Privacy & Security Compliance – Click Here for more information.


Only need short refresher courses or targeted training? Check out the AIHC HIPAA short courses.

Read More
HIPAA Compliance
HIPAA

Important Update: FTC Clarifies Health Breach Notification Rule- Healthcare Apps and Vendors Are Included

Written by: Susan Walberg, JD MPA CHC




As I have written in previous articles about HIPAA and health-tech, many apps in the marketplace have been largely unregulated with respect to the privacy and security of healthcare data. In order for healthcare-related apps to be regulated, for the most part they needed to be covered under HIPAA. As a result, only the apps that were directly related to providing or billing for healthcare services, or those companies’ ‘Business Associates,’ were required to put specific controls and notifications in place. All the rest were not. The Federal Trade Commission (FTC), the agency responsible for consumer protection, hasn’t really been on the radar in terms of regulatory oversight in this arena.


The many thousands of apps that are selected and used by consumers to manage illnesses, track fitness, and other health-related services do not fall under HIPAA’s requirements and were, for the most part, unregulated. All of this has changed with a September 15, 2021, Policy Statement by the FTC.


According to the Statement, the Health Breach Notification Rule "Helps to ensure that entities who are not covered by the Health Insurance Portability and Accountability Act (“HIPAA”) nevertheless face accountability when consumers’ sensitive health information is compromised.” The Breach Notification Rule is not new, but this clarification is, and signals likely enforcement of a rule that has largely gone unenforced to date. The push to regulate apps came from Congress, and further legislation is likely.


Who is Affected?


The FTC clarifies that vendors of ‘personal health records (PHRs) and PHR-related entities’ have to follow the breach notification procedures outlined in the Rule, which includes notification of consumers, the FTC, and even the media in some cases. These are not HIPAA ‘Covered Entities.’


The Rule covers vendors of PHRs that contain individually identifiable health information ‘created or received by health care providers.’ More specifically, PHRs are defined as an electronic record of “identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual.”


The part that may be misunderstood is who the FTC considers a ‘health care provider.’ The FTC considers the developer of a health app or connected device as a ‘health care provider’ because it “furnishes healthcare services or supplies.”


According to the recent Statement, and the definition itself, the rule applies to any app that is capable of drawing information from multiple sources, such as from a consumer and an application programming interface (API). What are some examples? The FTC cites a blood sugar monitoring app that gets information entered by the consumer but also accesses data from the phone, such as the calendar. So all those apps that were previously considered exempt, such as fitness trackers, now need to take note.


What is a Breach?


The second critical aspect of the Statement pertains to what constitutes a breach. While most people consider a breach to be an intrusion, ransomware, or an attack by a hacker, the FTC takes a broader view. Now, it has been clarified, a breach includes unauthorized access, including sharing of information without an individual’s authorization. This is potentially a very big deal for all those apps that fell outside of HIPAA and were not hesitant about sharing consumer data with advertisers, investor-companies, or ‘big tech,’ where such data is often used to build user profiles. If you read my previous article on this topic, it hasn’t been illegal to sell or share consumer information that consumers voluntarily enter into many healthcare apps (unless they fit within HIPAA). Those activities, if not authorized by the consumer, are considered a breach and the FTC has put everyone on notice that more active enforcement of this rule can be expected.  And the penalties? Penalties can be up to $43,792 per violation.


What to Do?


If you are an app developer or own a company involved in developing healthcare apps, you need to review the policies, consumer consent and authorizations, and the technical controls in place. Evaluate where you share consumer data. Look at any data sharing agreements and contracts where sharing data might be part of the deal.


Make sure you review the various rules and regulations that apply to you as well as the various guidance put out by the FTC.  You can find their guidance, enforcement activities, and press releases on their website, ftc.gov. If you’re not sure, get help in figuring out which laws and regulations apply to your organization.


Take note that this area of compliance and enforcement is changing rapidly. Technology got ahead of regulations, especially with changing needs due to COVID.  Check out my website at https://www.susanwalberg.com/

Read More
HIPAA Compliance
HIPAA

Healthcare Apps and Data Privacy/Security Risks

Written by Susan Walberg, JD MPA CHC




Healthcare apps have become increasingly prevalent, with people using them for counting steps, monitoring their calories, or linking to various medical devices, to name just a few examples. Since the COVID outbreak, however, and the explosion of telehealth as a healthcare option, these apps have proliferated at an insane rate. As of 2020, there were 325,000 healthcare apps on the market, with more coming all the time.


Whether you are a consumer who uses such apps, or a provider who wants to develop an app for patients to use, it’s important to understand some of the privacy and security risks that may accompany the use of such tools and what to watch out for.


What Are Healthcare Apps?


An ‘app’ is a small program that can be loaded onto a phone or mobile device to perform a specialized function. There are two main types of healthcare apps in terms of privacy and security regulations, and the rules governing them vary accordingly.


The first type are the applications that are used by your healthcare provider. They may be used to store your lab or radiology results or might be integrated with a medical device for tracking/monitoring purposes, such as an electrocardiography device that monitors heart activity. Or they may be used to coordinate your care.


The second type are personal or private healthcare apps, those that an individual can get at an app store to track and manage their diet, exercise, or specific health conditions. There are apps for mental health, diabetes, and, of course, COVID, to name just a few. Many of these apps are free.


Nothing in Life Is Free


First, let’s talk about those ‘free’ apps.


Free apps, how cool is that? Depending on your view, an application that tracks and shares your personal information might not really be ‘free’.


If you go online and look for a free app to help you count calories or manage your diet, for instance, the odds are good that there are advertisements on the app, right? Well, most of those ‘free’ apps, with the ads included, will be sharing your information with the advertisers and perhaps even with other companies, such as the ‘big tech’ companies or other stakeholders or investors.


You may expect this, and you might not care. After all, any online Google search leads to targeted Facebook ads relating to that same subject matter, as many of us have noticed. We may not like it, but we are getting used to the fact that our online activity is not really private.


But when you choose one of those apps, think about what information you are entering, because it is probably not private. How much of your medical information is being collected in order to help you manage your diabetes or exercise program? And do you know where that information might be shared? You may accept the fact that your use of the app is not private, just like your Google searches seem to have a direct pipeline to Facebook. But think about the data collected, because that’s not private either. And that’s not illegal in this situation.


But…But…HIPAA


How can this health information NOT be private? There must be regulations protecting your privacy, especially when it comes to your healthcare information, right? We hear all the time about HIPAA (The Health Insurance Portability and Accountability Act of 1996) and how your health information can’t be shared.


Just to be clear, in a nutshell, HIPAA only applies to those apps that are used and offered by your healthcare provider or insurance company (or some similar organization that is regulated by HIPAA). Those organizations are subject to the HIPAA Privacy and Security regulations (as well as the HITECH and Omnibus laws that followed), so any product they offer in conjunction with their regulated services would typically be subject to the same laws. This does not mean that if your doctor tells you there are apps in the marketplace to monitor your diabetes that they would be subject to HIPAA. But if your insurance company, for instance, offers you a tool as part of your plan that will help you manage a chronic health condition, HIPAA would generally apply. You may not be sure, so it’s important to ask.


If the app is, indeed, regulated under HIPAA, that means that privacy and data security controls must be in place. There should be a privacy/security policy that you can review, and you have specific rights with respect to your information and how it’s used. There are limitations around, for instance, how your data can be used or shared for marketing purposes. It also means that there must be a designated privacy and security ‘official’ who has oversight of compliance with these regulations. A company that provides a healthcare app to physician practices, insurance companies, or similar organizations would be considered a ‘Business Associate’ of that provider or insurance company, which means they are subject to the same requirements. HIPAA does provide a broad range of protections, but they are limited to those specific scenarios.


The reality is that few laws govern the privacy of information you voluntarily share in one of these publicly-available apps, so if you go online and pick an app to track or monitor your own health condition or information…most are not subject to privacy laws.


Apps Provided by Your Physician, Insurance Company, Etc.


The apps used by your doctor’s office or insurance company are subject to much tighter regulation, but also often contain more personal data. Especially with the increased use of telehealth services, provider’s offices are relying on various applications and platforms to facilitate the provision of healthcare services. These apps, and the companies that offer them, are covered under HIPAA as ‘Business Associates’ of the provider or insurance company if the app uses, stores, or transmits patient health information on behalf of the healthcare organization.


Due to COVID, the government has loosened up the privacy regulations in order to allow greater flexibility in providing telehealth services. While this is good news for providers and the patients needing those services, it also means more potential risk to protected health information (PHI). It’s important to keep in mind that, in addition to whatever information you enter online, a telehealth application likely has requested permission to access your calendar, camera, and microphone.


The good news is that, although providers may have been using some of the less secure apps in the beginning of COVID, just out of necessity, those providers who plan to continue providing telehealth services are working to ensure compliance with privacy and security requirements. App developers are busy developing apps to accommodate this changing market, and compliance is a top concern.


Apps as Mobile Devices


There is one type of application which is actually considered by the Food and Drug Administration (FDA) to be a medical device, in addition to being covered under HIPAA (because they are provided in conjunction with healthcare services). Those are the apps that are intended to be used ‘for the diagnosis of disease or other conditions, or the cure, mitigation, treatment, or prevention of disease, or is intended to affect the structure or any function of the body of man’ under section 201(h) of the Food, Drug, and Cosmetic Act. In general, if the purpose or function of the app is to assist in performing a medical device function, it will be treated as a medical device under the FDA. For instance, if the app can be run on a smart phone or other hand-held device and analyzes and interprets EKG waveforms to monitor cardiac irregularities, it would be considered analogous to those software programs that perform the same function and are otherwise regulated as a medical device.


The intent of the FDA is to ensure patient safety related to the use of those devices that could compromise or risk patient health. This oversight is limited to those devices marketed and offered to perform these medical device functions.


Although the FDA purview is not privacy or data security, the FDA jurisdiction is noteworthy in terms of regulatory oversight. For purposes of HIPAA, these devices would typically be subject to the Privacy and Security rules as they are used in conjunction with your provider or insurance company, as discussed above.


How Do You Know if Your Data Is Secure?


Apps in the marketplace that are available to help track health-related information should have a privacy policy, although at the current time it is not required by law for apps that are not considered a medical device or are subject to HIPAA. It is highly recommended that you find those policies and read them, even though some may be lengthy and not written clearly (might be overly technical or legalistic).


Even if the apps have privacy policies, those policies might not be easy to find, and you might discover that the policy does state the ways in which they do share your information. There is no law against the sale or disclosure of data from independent apps to third parties and those apps are being funded somehow (data is valuable). In addition to data sharing, the privacy policy should explain how it safeguards your data. There should be information security measures in place to prevent breaches of your data. And lastly, even if the privacy policy sounds good, the app developer may not necessarily follow their own policies. This is not to say that an app developer is deliberately being deceptive; a developer or their sponsoring company may adopt a policy from another app they are familiar with or may bring in a consultant to write their policy, but the specific terms in the policy aren’t implemented during development. It can happen. And this isn’t limited to app developers; any organization can fall short of following its own policies. Many app developers have a technical or clinical background and may not fully understand the healthcare regulatory framework.


You can also check an app’s automatic settings and look for those that impact privacy, such as location tracking. Beware, though, that in some instances turning those options off will make it more difficult to use the app.


The bottom line here is caveat emptor…buyer beware. Especially if you’re not ‘buying’ and it’s ‘free’.


How Can Data Be Compromised?


Even when providers, insurance companies, and app developers are focused on compliance with the various privacy and security requirements, PHI can still be compromised, but it is less likely. Common mishaps occur in a number of ways:

  • Employee errors. Human errors can occur in any setting. It can be an employee discussing patient information out loud in a non-private setting, clicking on a link that allows a virus or ransomware attack, or accidentally entering an incorrect phone number and sending information to the wrong person. This isn’t limited to technology-related issues but privacy in general.
  • Poor access controls. There needs to be a solid process, that is followed religiously, to ensure that only individuals who need access are given access, and that former employees or business associates are promptly removed when they no longer have a need for access. This also includes business partners who have employees who need access in order to provide services to another company or practice. These employees need their own access, not a universal access that cannot be tracked.
  • Failure to monitor. Any organization that maintains PHI electronically should have a process for routinely reviewing who is accessing sensitive information and following up on any questionable access. Audit trails are part of any good security structure.
  • Failure to securely store data. Not only should data be stored in a secure manner, it should also be consistently destroyed/removed when applicable retention periods have expired.
  • Inadequate encryption.
  • Workstation and device security. Applications should time-out when not in use, rather than rely on users to remember to do so.
  • Failure to conduct a comprehensive risk assessment that includes the various apps and networked devices where PHI is stored or transmitted.
  • Increased remote workers. Employees working from home are more likely to use personal devices that don’t have proper levels of encryption and that are, by definition, less private due to the offsite location. Access is much harder to control and networks may not be secure.

The above issues do not pertain only to apps, but in general to information privacy and security, especially in the new era of increased telehealth services. Those issues are also the types of failures HIPAA was designed to prevent and would likely be considered violations, depending on the specific facts. If you are considering using an app or electronic platform where personal information will be entered, it’s recommended that you ask your provider or insurance company who is offering this tool what their privacy and security policies are. If their organization is using and recommending such a tool, they have almost certainly done the review of privacy and security controls. And if you are a provider considering using an app, or an app developer, the above list is for you. You should have designated ‘privacy and security officials’ who ensure the above risk areas are addressed.


What Are the Risks?


Most people care about the privacy of their health information just because it’s private and not other people’s business. But there are actual risks to consider, which users of these apps should understand:

  • Data is shared with third parties for sales and marketing, increasing the targeting of ads you receive.
  • Even information that is supposedly ‘de-identified’ can include enough information to make users identifiable, and it may be very sensitive information, for instance relating to mental health or substance abuse.
  • Medical identity theft, which can result in someone using your identity to receive free healthcare services or to file fraudulent claims. Healthcare data is valuable for those reasons, which is why it is often targeted by hackers.
  • Additional outside companies, such as Facebook or Google, may acquire the information and build user profiles. Once the information is out there in that environment, there is little control over it and it’s difficult to know who could access it or how it could be used.
  • Your PHI could be acquired by insurance companies or other healthcare companies that could use it against you in underwriting or pricing determinations. Who else would you not want knowing your private information? An employer? The possibilities are frightening, especially considering that once the information is out there, it’s out there. You can’t put the genie back in the bottle.

Conclusion


Telemedicine and the use of online applications has exploded in recent years, particularly in relation to the COVID pandemic and the resulting changes in the delivery of healthcare. The regulatory framework has not necessarily caught up to technology yet, so while HIPAA laws apply to some applications, many that are out there being used by consumers are not regulated in terms of protecting sensitive information. Health information can be bought and sold in the marketplace, it has a value for advertisers, thieves, and others.


For consumers, just be aware of the potential risks before you start using an app; check the app’s privacy and security policies and consider carefully what information you are comfortable exposing. If the app comes from your provider or insurance company, ask about the security controls and how they are protecting your data.


For providers, consider your own liability in terms of recommending an app and make sure your organization has done its due diligence to ensure proper security measures are in place. You should have your own privacy and security experts evaluate the tool before offering it to patients.


For app developers, be aware that technical security isn’t your only concern; you will want to have assistance from someone with healthcare privacy and security regulatory expertise. This will be something that potential clients and investors will be asking about.


Susan Walberg is a healthcare consultant who works with providers and healthcare start-ups. She can be reached at https://www.susanwalberg.com/

Read More
HIPAA Compliance
HIPAA

Scenarios That Can Lead to HIPAA Violations – Are you doing anything to avoid them?

Written by: Salman Rashid




HIPAA, which stands for the Health Insurance Portability and Accountability Act, is a monumental piece of legislation in the U.S. that was enacted in 1996 in order to reduce healthcare fraud and facilitate the transfer of worker’s coverage when they switch or leave jobs.


Decades later, with several new standards introduced within the law, this Act is now best known for protecting the privacy of patients and health plan members’ medical information and, as well as ensures that health information is kept secure and patients are notified whenever there’s a breach of information.


As beneficial as it may sound, HIPAA can be devastating for those who do not follow the rules. There are two types of entities that must abide by the rules and regulations of HIPAA. One is covered entities and the other is their business associates. A single instance of a HIPAA violation can range from thousands to millions of dollars. HIPAA violations are categorized into four tiers, the more severe and neglected the violations are, the higher the tier.


So today, we’ll discuss a few scenarios that can lead to a HIPAA violation so that you can take appropriate actions to comply with the law.


Common types of HIPAA violations


Shortfall in encryption

The risk of leaving Protected Health Information (PHI) unsecured is straightforward. Encryption adds layer of protection, including cybersecurity and all other best practices. Even if someone is somehow able to get their hands on PHI, whether by stealing or cyber hacking, they won’t be able to access the information if there’s an added layer of protection without the passcode. Even though encryption is not a strict HIPAA requirement, it is highly recommended because encryption can better protect PHI from prying eyes. Many progressive healthcare organizations have also implemented biometric patient identification solutions for enhanced protection.


Shortfall in training

individuals who might come into contact with PHI in the course of their work. However, it’s best to provide training for everyone in the organization so they understand the purpose of HIPAA and learn the best practices to better protect themselves from fines and penalties, as well as patients’ healthcare data. Often employees inadvertently access PHI or violate the law because they do now possess enough knowledge. It is recommended to train all the staff members on the law and the particular policies and procedures set forth by the organization.


Sharing or Gossiping PHI

Gossiping is an innate nature of all human beings. Especially healthcare workers may be tempted to discuss a patients’ medical case with their coworkers or in a place where conversations can be overheard. However, PHI should be off-limit unless the other person is involved in the patients’ health care. Healthcare workers with access to PHI should also be very careful about the information they share with others. Information might be shared out of curiosity, but the consequences are the same regardless of the intent. Sharing patients’ information on social media without the patients’ consent is also prohibited.


Disposing of medical records improperly

This is a very common scenario in many healthcare organizations where they dispose of PHI without shredding them first or in a place where it is visible or can easily be stolen. Either way, if PHI falls into the hands of the wrong person, there could be serious HIPAA consequences. Staff members should understand PHI contains valuable and sensitive information like financial numbers, social security numbers, etc., and should be shredded or destroyed before disposal, or wiped from the hard drive.


Avoiding HIPAA violations


There could be several other ways HIPAA can be violated. Staff members must be provided with up-to-date and frequent training so that they understand the purpose of HIPAA and avoid actions that can lead to a HIPAA violation. Healthcare organizations must also understand that HIPAA is not a one-time implementation. It requires continuous development, monitoring, and application. Part of it also includes conducting risk assessments to identify potential vulnerabilities and gaps within the practice to mitigate problems before a violation occurs. Many healthcare organizations also utilize HIPAA compliance software applications to streamline their efforts, some of which are simple, affordable, and very easy to implement and use.


Author Bio

Salman Rashid is an avid reader, loves writing on healthcare issues, and loves all things related to technology, especially PCs and smartphones. He’s also a Digital Marketing Analyst at RightPatient, a platform that helps enhance patient safety across hospitals. He can be contacted at salman@rightpatient.com.

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More