Community Health
Community Healthcare

The Impact of Section 1557 Final Rule on Healthcare

Written by Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS    

The 2024 Final Rule for Section 1557 of the Affordable Care Act (ACA) was issued by the Department of Health and Human Services (HHS) on April 26, 2024. The effective date was July 5, 2024. The American Institute of Healthcare Compliance (AIHC) Volunteer Education Committee has written this article in response to several requests for more information on the Final Rule, which aims to ensure that all people have non-discriminatory access to healthcare. It applies to health programs and activities that receive federal financial assistance, known as covered entities.

Introduction

The Final Rule applies to all health insurance issuers that are recipients of federal financial assistance, which includes Medicare Parts C and D payments, as well as state Medicaid agencies and the health insurance federal and state Marketplaces (and all plans offered by issuers that participate in those Marketplaces that receive federal financial assistance).

Those covered by the rule may include hospitals, health clinics, health insurance issuers, state Medicaid agencies, community health centers, physicians’ practices, and home health care agencies.

Section 1557 makes it unlawful for health care providers, including doctors' practices and hospitals that receive federal financial assistance, to refuse to treat—or to otherwise discriminate against—an individual based on a number of characteristics, including:

  • Race
  • Color
  • National origin
  • Age
  • Disability
  • Sex, which includes sexual orientation and gender identity

Effective date is July 5, 2024.

Most of the implementing regulations in the new rule are effective 60 days (July 5, 2024) after publication in the Federal Register, which was on May 6, 2024. Some provisions impacting health insurance plan design won’t become effective until the plan year beginning after January 1, 2025, and other provisions where entities might need additional time to amend current practices also have later effective dates.

  • The Final Rule does not apply to employment practices, including the provision of employee health benefits.

Overview of the 2024 Final Rule for Section 1557 legislation

1. Strengthening Anti-Discrimination Protections

  • Expanded Protections: Include protections against discrimination based on gender identity and sexual orientation.
  • Clarification of Existing Protections: Clearly define what constitutes discrimination in health care settings.

2. Improving Access to Health Care Services

  • Equitable Access: Ensure that all individuals can access health care services without discrimination.
  • Language Access Requirements: Mandate language assistance services for individuals with limited English proficiency.

3. Enhancing Patient Rights

  • Empowerment of Patients: Provide clear mechanisms for individuals to report discrimination and seek remedies.
  • Informed Consent: Ensure patients are fully informed of their rights and available services.

4. Data Collection and Transparency

  • Demographic Data Collection: Encourage the collection of data to monitor health disparities and promote health equity.
  • Reporting Requirements: Establish guidelines for reporting discrimination and health outcomes.

5. Promoting Inclusive Health Care Environments

  • Cultural Competency Training: Require training for health care providers to better serve diverse populations.
  • Creating Safe Spaces: Implement policies to foster welcoming environments for all individuals, especially marginalized groups.

6. Clarifying Responsibilities for Covered Entities

  • Defining Obligations: Clearly outline the responsibilities of health care providers and insurers under the law.
  • Guidance for Compliance: Provide resources and guidance to help entities comply with the updated regulations.

7. Addressing Current Health Care Challenges

  • Response to Emerging Issues: Adapt the regulations to address current challenges, including those highlighted by the COVID-19 pandemic.
  • Focus on Health Equity: Tackle systemic inequalities in health care access and outcomes.
  • Artificial Intelligence (AI) and Nondiscrimination 

The government recognizes the potential impact of artificial intelligence (AI) in health programs and activities. Therefore, the rule clarifies that nondiscrimination in health programs and activities continues to apply to the use of AI, clinical algorithms, predictive analytics, and other tools. This clarification serves to support the October 30, 2023, Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. Specifically, the rule:

  • Applies the nondiscrimination principles under Section 1557 to the use of patient care decision support tools in clinical care.
  • Requires those covered by the rule to take steps to identify and mitigate discrimination when they use AI and other forms of decision support tools for care.

However, as of January 2025, this Executive Order has been rescinded.

How Covered Entities Must Comply

According to guidance issued by OCR, covered entities should:

  • Provide services and programs in the most integrated setting appropriate to the needs of the qualified individual with a disability
  • Ensure that programs, services, activities, and facilities are accessible
  • Make reasonable modifications in their policies, practices, and procedures to avoid discrimination on the basis of disability, unless it would result in a fundamental alteration of the program
  • Provide auxiliary aids to persons with disabilities, at no additional cost, where necessary to afford an equal opportunity to participate in or benefit from a program or activity
  • Designate a responsible employee to coordinate their efforts to comply with Section 504 and the ADA
  • Adopt grievance procedures to handle complaints of disability discrimination in their programs and activities
  • Provide notice that indicates:
    • That the covered entity does not discriminate on the basis of disability
    • How to contact the employee who coordinates the covered entity's efforts to comply with the law
    • Information about the grievance procedures

Consequences for Violating a Patient’s Rights under Section 1557

The Office for Civil Rights (OCR) enforces Section 1557 of the Affordable Care Act (Section 1557), which prohibits discrimination on the basis of race, color, national origin, age, disability, or sex (including pregnancy, sexual orientation, gender identity, and sex characteristics), in covered health programs or activities. 42 U.S.C. 18116.

Section 1557 has been in effect since the enactment of the ACA in 2010. Since that time, the OCR has been receiving and investigating discrimination complaints under Section 1557.

If an individual believes s/he has been subject to discrimination in health care or health coverage, they may file a complaint with OCR under Section 1557. OCR has a toll-free number and will guide individuals through the complaint process. OCR’s complaint forms are available in a variety of languages. Individuals can file a complaint online via OCR’s Complaint Portal.

If OCR determines that it has jurisdiction, OCR will investigate the complaint or, in some cases, refer the complaint to an agency with joint jurisdiction. When OCR identifies a violation or compliance concern, it will work with the recipient to achieve compliance with the law. Depending on the scope of the changes required, complaints can be resolved through voluntary compliance letters or agreements requiring the recipient to develop policies, monitoring, notification, and training, which also resolve the specific incidents alleged in the complaint. If voluntary compliance cannot be achieved, OCR can issue a formal findings letter and refer the case to DOJ or begin administrative proceedings to revoke federal funds.

In the News - Imaging Network Violates Section 504 and Section 1557

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) recently announced a settlement with the New Jersey Imaging Network (“Network”) to resolve a civil rights complaint from an individual who uses a wheelchair, and was denied mammography because of her disability, based on Section 504 of the Rehabilitation Act (Section 504) and Section 1557 of the Affordable Care Act (Section 1557), which prohibit discrimination on the basis of disability. Together, these laws protect people with disabilities from discrimination in any program or activity receiving funding from HHS. The Network has only 45 calendar days to modify policies and procedures to comply, and in addition:

Document requests for mobility assistance or other reasonable accommodations; provide patients with a description of available accommodations; and notify patients of their rights under the law.

  • Develop a process for individualized assessment of patients who may require reasonable accommodations.
  • Train its staff on the new policies to ensure employees understand practices and procedures for interacting with and accommodating individuals with disabilities, techniques for safely assisting individuals with limited mobility to ensure their safe access to and use of medical equipment and examination tables, and The New Jersey Imaging Network’s various non-discrimination and non-retaliation obligations.
  • Notify patients, staff and the public of rights and protections afforded them by federal law and how to file a discrimination disability-based complaint with HHS.

OCR is monitoring the settlement action for the next 2 years. Click Here for the OCR & New Jersey Imaging Network Resolution Agreement. 

Conclusion

This 2024 Final Rule for Section 1557 legislation aims to bolster anti-discrimination measures in health care, ensuring equitable access to services, protecting patient rights, and promoting a culture of inclusivity within health care settings. This rule reflects a commitment to address health disparities and improve the overall quality of care for all individuals. 

View the Final Rule “Nondiscrimination in Health Programs and Activities” in the Federal Register – a Rule by the Centers for Medicare & Medicaid Services posted 05/06/2024.

About the Authors

Corliss Collins, BSHIM, RHIT, CRCR, CSM, CCA, CBCS, CPDC is Principal & Managing Consultant, P3 Quality LLC, Founder and serves on the AIHC Volunteer Education Committee.

Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS serves as the Board Chair of AIHC and oversees the Volunteer Education Committee.

Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Reproductive Health & the New Final Rule

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS of the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare education organization.       

HIPAA Reproductive Health Provisions Now Vacated

In June 2025, a Texas court struck down most of the new HIPAA rules protecting reproductive health information, meaning those specific prohibitions and disclosure requirements are largely gone. 

The court found the rule went beyond HIPAA's scope by trying to achieve political goals, interfering with state laws, and improperly redefining terms like "person" and "public health".  The Court stated that while HIPAA gives authority to HHS to promulgate regulations protecting “individually identifiable health information,” the law does not give authority to “distinguish between types of health information” to accomplish a political agenda. The Court also argued that the Rule unlawfully limits state public health laws.

Impact - The rule's restrictions on sharing reproductive health data for criminal/civil investigations and the requirement for attestations from data requesters were nullified.  Covered entities must remove reproductive health language but must update NPPs to reflect new SUD protections by that 2026 date, as those requirements remain in effect. 

What is this Final Rule?

The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and Disclosures of Information Relating to Reproductive Health Care, aka Final Rule became effective June, 2024.

The Final Rule applies to Protected Health Information (PHI) related to lawful reproductive health care, including care that is protected by federal law, such as the Emergency Medical Treatment and Active Labor Act (EMTALA) or the U.S. Constitution. The rule also applies when care is provided by someone other than the recipient of the request.

As stated by the Office of Civil Rights (OCR), the government HIPAA enforcement agency, access to comprehensive reproductive health care services, including abortion care and other sexual and reproductive care, is essential to individual health and well-being.

Defining Reproductive Health Care

The 2024 HIPAA Final Rule defines reproductive health care as "health care that affects the health of an individual in all matters relating to the reproductive system and to its functions and processes". This definition is broad and intentional, and may include services related to sterilization and fertility, such as vasectomies, male hormone therapy, and erectile dysfunction treatments.

The rule specifically states: “Reproductive Health Care means health care, as defined in this section, that affects the health of an individual in all matters relating to the reproductive system and to its functions and processes. This definition shall not be construed to set forth a standard of care for or regulate what constitutes clinically appropriate reproductive health care.”

Who is Required to Comply with the Final Rule?

Regulated entities are required to comply, which are better known as HIPAA Covered Entities and their Business Associates, such as:

  • Health plans;
  • Health care clearinghouses;
  • Most health care providers; and
  • Their business associates

What are the Deadlines for Compliance?

  • Published at the Federal Register on April 26, 2024.
  • Effective date is June 25, 2024.
  • Compliance date, the date persons subject to this regulation must comply with the applicable requirements of this final Rule, is December 23, 2024, except for the Notice of Privacy Practices.
  • Compliance date for the Notice of Privacy Practices is February 16, 2026.

The rule became effective on June 25, 2024, and those subject to the regulation must comply by December 23, 2024, except for the applicable requirements of the Notice of Privacy Practices (NPP) for Protected Health Information  45 CFR 164.520 in this final rule. The Final Rule requires covered health care providers, health plans, and health care clearinghouses to revise their NPPs to support reproductive health care privacy.

Persons subject to providing an NPP to patients and subject to this regulation, are required to comply with the applicable requirements of 45 CFR 164.520 in this final rule by February 16, 2026.

What are the Key Provisions to the Rule?

It applies to the protection of reproductive health care information which encompasses abortion, birth control, and in vitro fertilization with the goal of strengthening patient-provider confidentiality and promoting trust between individuals and their health care providers. There are several provisions to the Final Rule which are, in short:

  • Presumption of lawfulness - The rule presumes that reproductive health care provided by someone other than the regulated entity is lawful, unless the recipient has actual knowledge that it is not or the requestor can demonstrate unlawfulness.
  • Prohibition on use or disclosure - The rule prohibits covered health care providers, health plans, and health care clearinghouses from using or disclosing protected health information (PHI) to investigate or impose liability on people for seeking, obtaining, providing, or facilitating lawful reproductive health care.
  • Attestation requirement - The rule requires regulated entities to obtain an attestation from the requestor that a requested use or disclosure of PHI is not for a prohibited purpose.

Please reference § 164.512 Uses and disclosures for which an authorization or opportunity to agree or object is not required and review the summary provided below.  This summary is taken from the Office for Civil Rights (OCR) “HIPAA Privacy Rule Final Rule to Support Reproductive Health Care Privacy: Fact Sheet”


What Specific Types of Use & Disclosures are Prohibited?

The Final Rule prohibitions of use/disclosure of reproductive PHI applies to either of the following activities:

  1. To conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care, where such health care is lawful under the circumstances in which it is provided.
  2. The identification of any person for the purpose of conducting such investigation or imposing such liability.

Under the Final Rule, the prohibition applies where a covered health care provider, health plan, or health care clearinghouse (covered entities) or business associate (collectively, “regulated entities”) has reasonably determined that one or more of the following conditions exists:

  • The reproductive health care is lawful under the law of the state in which such health care is provided under the circumstances in which it is provided.
    • For example, if a resident of one state traveled to another state to receive reproductive health care, such as an abortion, that is lawful in the state where such health care was provided.
  • The reproductive health care is protected, required, or authorized by Federal law, including the U.S. Constitution, regardless of the state in which such health care is provided.
    • For example, if use of the reproductive health care, such as contraception, is protected by the Constitution.
  • The reproductive health care was provided by a person other than the covered health care provider, health plan, or health care clearinghouse (or business associates) that receives the request for PHI and the presumption described below applies.

The Final Rule continues to permit regulated entities to use or disclose PHI for purposes otherwise permitted under the Privacy Rule where the request for the use or disclosure of PHI is not made to investigate or impose liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care.  OCR provides the following examples - a regulated entity:

  • Is permitted to continue to use or disclose PHI to defend themselves in an investigation or proceeding related to professional misconduct or negligence where the alleged professional misconduct or negligence involved the provision of reproductive health care.
  • Could continue to use or disclose PHI to defend any person in a criminal, civil, or administrative proceeding where liability could be imposed on that person for providing reproductive health care.
  • Could continue to use or disclose PHI to an Inspector General where the PHI is sought to conduct an audit for health oversight purposes.

Rule of Applicability

The prohibition applies:

  • Where the relevant activity is in connection with any person seeking, obtaining, providing, or facilitating reproductive health care and
  • The regulated entity that received the request for PHI has reasonably determined that one or more of the following conditions exists:
    • The reproductive health care is lawful under the law of the state in which such health care is provided under the circumstances in which it is provided.
    • The reproductive health care is protected, required, or authorized by Federal law, including the U.S. Constitution, under the circumstances in which such health care is provided, regardless of the state in which it is provided.
    • When the Presumption applies.

Presumption - Care Provided was Lawful

The Final Rule includes a presumption that the reproductive health care provided by a person other than the regulated entity receiving the request was lawful. In such cases, the reproductive health care is presumed to be lawful under the circumstances in which it was provided unless one of the following conditions are met:

  • The covered health care provider, health plan, or clearinghouse (or business associates) has actual knowledge that the reproductive health care was not lawful under the circumstances in which it was provided.
    • For example, an individual discloses to their doctor that they obtained reproductive health care from an unlicensed person and the doctor knows that the specific reproductive health care must be provided by a licensed health care provider.
  • The covered health care provider, health plan, or health care clearinghouse (or business associates) receives factual information from the person making the request for the use or disclosure of PHI that demonstrates a substantial factual basis that the reproductive health care was not lawful under the circumstances in which it was provided.
    • For example, a law enforcement official provides a health plan with evidence that the information being requested is reproductive health care that was provided by an unlicensed person where the law requires that such health care be provided by a licensed health care provider.

What is the New Form Requirement About?

Regulated Entities Must Obtain a Signed Attestation from the Requester Now

  • OCR has provided a “Model Attestation” for requested use or disclosure of PHI related to reproductive health care.  Download a copy of the model attestation from OCR. 

About the implementation of the Attestation Form - To implement the prohibition, the Final Rule requires when the regulated entity receives a request for PHI potentially related to reproductive health care, that the regulated entity obtain a signed attestation that the use or disclosure is not for a prohibited purpose. This attestation requirement applies when the request is for PHI for any of the following:

  • Health oversight activities
  • Judicial and administrative proceedings
  • Law enforcement purposes
  • Disclosures to coroners and medical examiners

Are There Penalties if the Requester Isn’t Compliant?

The requirement to obtain a signed attestation gives the regulated entity a way of obtaining written representations from persons requesting PHI that the request is not for a prohibited purpose.  This also creates a situation of putting the requester “on notice” of the potential criminal penalties for those who knowingly are in violation of HIPAA.  As of October 2023, the criminal penalties for violating HIPAA rules can include jail time and fines:

Tier 1: Reasonable cause or no knowledge of violation, up to 1 year in jail

Tier 2: Obtaining PHI under false pretenses, up to 5 years in jail

Tier 3: Obtaining PHI for personal gain or with malicious intent, up to 10 years in jail

Disclosures to Law Enforcement

The Privacy Rule permits uses or disclosures of PHI without an individual’s authorization only where such uses or disclosures are expressly permitted or required by the Privacy Rule

The Privacy Rule permits, but does not require, certain disclosures to law enforcement and others, subject to specific conditions. Thus, regulated entities such as covered health care providers, health plans, and health care clearinghouses and their business associates, including their workforce members, are only permitted to disclose PHI for law enforcement purposes where they suspect an individual of obtaining reproductive health care (lawful or otherwise) if the covered entity or business associate is required by law to do so and all applicable conditions are met.

Accordingly, under the Final Rule, such disclosure is only permitted where all three of the following conditions are met:

  1. The disclosure is not subject to the prohibition.
  2. The disclosure is required by law.
  3. The disclosure meets all applicable conditions of the Privacy Rule permission to use or disclose PHI as required by law.

45 CFR 164.512(f)(1)(ii) states:

Permitted disclosures: Pursuant to process and as otherwise required by law.  A covered entity may disclose protected health information:

(i) As required by law including laws that require the reporting of certain types of wounds or other physical injuries, except for laws subject to paragraph (b)(1)(ii) or (c)(1)(i) of this section; or

(ii) In compliance with and as limited by the relevant requirements of:

(A) A court order or court-ordered warrant, or a subpoena or summons issued by a judicial officer;

(B) A grand jury subpoena; or

(C) An administrative request for which response is required by law, including an administrative subpoena or summons, a civil or an authorized investigative demand, or similar process authorized under law, provided that:

(1) The information sought is relevant and material to a legitimate law enforcement inquiry;

(2) The request is specific and limited in scope to the extent reasonably practicable in light of the purpose for which the information is sought; and

(3) De-identified information could not reasonably be used.

According to OCR, examples would be:

  • A law enforcement official goes to a reproductive health care clinic and requests records of abortions performed at the clinic. If the request is not accompanied by a court order or other mandate enforceable in a court of law, the Privacy Rule would not permit the clinic to disclose PHI in response to the request. Therefore, such a disclosure would be impermissible and constitute a breach of unsecured PHI requiring notification to HHS and the individual affected. 
  • A law enforcement official presents a reproductive health care clinic with a court order requiring the clinic to produce PHI about an individual who has obtained an abortion. Because a court order is enforceable in a court of law, the Privacy Rule would permit but not require the clinic to disclose the requested PHI. The clinic may disclose only the PHI expressly authorized by the court order.

Disclosures to Avert a Serious Threat to Health or Safety

The Privacy Rule permits but does not require a covered entity, consistent with applicable law and standards of ethical conduct, to disclose PHI if the covered entity, in good faith, believes the use or disclosure is necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, and the disclosure is to a person or persons who are reasonably able to prevent or lessen the threat.

According to major professional societies, including the American Medical Association and American College of Obstetricians and Gynecologists, it would be inconsistent with professional standards of ethical conduct to make such a disclosure of PHI to law enforcement or others regarding an individual’s interest, intent, or prior experience with reproductive health care.

Example:

A pregnant individual in a state that bans abortion informs their health care provider that they intend to seek an abortion in another state where abortion is legal. The provider wants to report the statement to law enforcement to attempt to prevent the abortion from taking place. However, the Privacy Rule would not permit this disclosure of PHI to law enforcement under this permission for several reasons, including:

  • A statement indicating an individual’s intent to get a legal abortion, or any other care tied to pregnancy loss, ectopic pregnancy, or other complications related to or involving a pregnancy does not qualify as a “serious and imminent threat to the health or safety of a person or the public”. 
  • It generally would be inconsistent with professional ethical standards as it compromises the integrity of the patient–physician relationship and may increase the risk of harm to the individual.

Therefore, such a disclosure would be impermissible and constitute a breach of unsecured PHI requiring notification to HHS and the individual affected.

Consult with Legal Counsel & Malpractice Carrier
Due to the complexities of complying to the 2024 Final Rule, it is advised that regulated entities seek legal counsel and guidance regarding policies and procedures from your Risk Attorney through your malpractice insurance company.

About the Author, Joanne Byron

This article is sponsored by the American Institute of Healthcare Compliance (AIHC), a non-profit healthcare compliance training organization.  Joanne serves as Board Chair for AIHC and oversees the Volunteer Education Committee.


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

The Final Rule: Information Blocking

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS

This article addresses the Information Blocking Final Rule regarding enforcement, associated Civil Monetary Penalties (CMPs) and entities subject to these penalties.  This article is subsequent to the original article “HIPAA, The Cures Act and Information Blocking Compliance” and Article on Right of Access Vs Information Blocking Part 1 and Part 2.

On September 14, 2023, the Office of Inspector General (OIG) posted the Final Rule “Fraud & Abuse; Information Blocking; OIG’s Civil Money Penalty Rules” describing enforcement of the Information Blocking rule.

“Actors” Subject to Penalty

Blocking health information interoperability is prohibited by “Actors”, which are health information networks, HIEs, health information technology developers of certified health IT, and health care providers.  Information blocking is defined in § 171.103.  In the context of information blocking, the Cures Act authorizes Civil Monetary Penalties or CMPs for any practice that is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information (EHI) if the practice is conducted by an entity subject to penalty.

How to Determine if Information is EHI

The image below is from HealthIT.gov:

So, what is NOT EHI?

  1. Psychotherapy notes as defined in 45 CFR 164.501
  2. Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding
  3. Individually identifiable health information in education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g
  4. Individually identifiable health information in records described at 20 U.S.C. 1232g(a)(4)(B)(iv)
  5. Individually identifiable health information in employment records held by a covered entity in its role as employer
  6. Individually identifiable health information regarding a person who has been deceased for more than 50 years
  7. De-identified protected health information as defined under 45 CFR 164.514

What is meant by “interfere”?

Interfere with or interference related to information blocking of EHI means to prevent, materially discourage, or otherwise inhibit and applies to:

  • Health Care Provider - Entities offering certified health IT;
  • Health IT developers of certified health information technology (IT); and
  • Health information exchange (HIE); or Health information networks (HIN) and an entity that knows or should know that the practice is likely to interfere with, prevent, or materially discourage the access, exchange, or use of EHI;

The 3 categories of “Actors” listed above which are subject to enforcement penalties are explained in more detail below.

Health Care Provider

A health care provider is a: hospital; skilled nursing facility; nursing facility; home health entity or other long term care facility; health care clinic; community mental health center; renal dialysis facility; blood center; ambulatory surgical center; emergency medical services provider; federally qualified health center; group practice; pharmacist; pharmacy; laboratory; physician; practitioner; provider operated by or under contract with the Indian Health Service (HIS) or by an Indian tribe, tribal organization, or urban Indian organization; rural health clinic; covered entity under 42 U.S.C. 256b; ambulatory surgical center; therapist; and any other category of health care facility, entity, practitioner, or clinician determined appropriate by the HHS Secretary. 

  • The full definition of “health care provider” is available in the Public Health Service Act (42 U.S.C. 300jj).
  • For healthcare providers, the law applies the standard of whether they know that the practice is unreasonable and is likely to interfere with the access, exchange, or use of EHI.

Health IT developer of certified health IT

This is in reference to an individual or entity, other than a health care provider, that self-develops health IT for its own use, that develops or offers health information technology (as that term is defined in 42 U.S.C. 300jj(5)) and which has, at the time it engages in a practice that is the subject of an information blocking claim, one or more Health IT Modules certified under a program for the voluntary certification of health information technology that is kept or recognized by the National Coordinator pursuant to 42 U.S.C. 300jj–11(c)(5) (ONC Health IT Certification Program).

Health Information Network or Health Information Exchange

Health information network or health information exchange means an individual or entity that determines, controls, or has the discretion to administer any requirement, policy, or agreement that permits, enables, or requires the use of any technology or services for access, exchange, or use of electronic health information:

  • Among more than two unaffiliated individuals or entities (other than the individual or entity to which this definition might apply) that are enabled to exchange with each other; and
  • That is for a treatment, payment, or health care operations purpose, as such terms are defined in 45 CFR 164.501 regardless of whether such individuals or entities are subject to the requirements of 45 CFR parts 160 and 164.

Enforcement

The final rule also explains OIG's approach to enforcement, with focus on information blocking allegations that pose greater risk to patients, providers, and health care programs, as well as OIG's anticipated consultation and coordination with the Office of the National Coordinator for Health Information Technology (ONC) and other agencies, as appropriate, in reviewing and investigating allegations of information blocking.

The Cures Act identified ways for ONC, OCR, and OIG to consult, refer, and coordinate on information blocking claims.

Information Blocking Investigations and Enforcement for Entities Subject to Civil Monetary Penalties

  1. OIG receives an information blocking complaint;
  2. OIG uses its enforcement priorities to assess complaints;
  3. OIG opens an information blocking case leading to the next step;
  4. OIG investigating the complaint by gathering facts, conducting interviews, document requests, etc. 
    • OIG may consult with ONC to assess facts and information blocking regulations
    • Case closed if OIG concludes information blocking was not committed
  5. OIG provides an opportunity to the entity to discuss OIG’s investigation;
  6. If OIG concludes the entity committed information blocking, a demand letter is sent to the entity;
  7. Entity has the opportunity to appeal OIG’s imposition of the penalty.

Whether OIG's or ONC's authority is appropriate to address a claim of information blocking will depend on the facts and circumstances of the allegation and the results of an investigation. For example, ONC and OIG may initially agree that a claim is most appropriately evaluated through an OIG investigation.

ONC has authority to take action against an individual or entity that is a developer participating in the ONC Health IT Certification Program. 45 CFR 170.580.

OIG has authority to impose CMPs against a health IT developer of certified health IT, which includes developers participating in the ONC Health IT Certification Program. Thus, an individual or entity that meets the definition of health IT developer of certified health IT could be subject to CMPs, termination of certification or other action under the ONC Health IT Certification Program review process, or both. 85 FR 25789, May 1, 2020.

Conclusion

The ONC Final Rule implements certain Cures Act information blocking provisions, including defining terms and establishing reasonable and necessary activities that do not constitute information blocking or “exceptions” to the definition of information blocking.  I recommend reading the additional articles referenced below to gain a better understanding of the eight exceptions to the Rule.  Also, visit the ONC Information Blocking Portal designed for individuals to file a complaint regarding Information Blocking and/or HIPAA violations made by covered entities or business associates.

Additional Resources to Reference:

Learn the basics of the 2021 Information Blocking Rule “HIPAA, The Cures Act & Information Blocking Compliance” which explains the original inception date and outlines exceptions to the Rule

Know the difference between a Right of Access Violation versus Information Blocking:

  • Is the Violation Right of Access or Information Blocking? Part 1 of 2
  • Is the Violation Right of Access or Information Blocking?  Part 2 of 2

Information Blocking page; Office of the National Coordinator for Health Information Technology (ONC) on HealthIT.gov

Information Blocking Portal


Online Training in HIPAA Privacy/Security with a lesson addressing Interoperability, Right of Access, Information Blocking and Artificial Intelligence

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved 

Read More