HIPAA Compliance
HIPAA

Part 2: Interoperability and System Fragmentation in Healthcare

Communication, Compliance, and Strategies for Successful Integration Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The healthcare industry continues to face significant fragmentation, as disparate systems and siloed data limit effective care coordination. Interoperability standards such as Fast Healthcare Interoperability Resources (FHIR) and regulatory requirements under the 21st Century Cures Act, HIPAA, and CMS interoperability mandates are reshaping the compliance landscape. Yet achieving interoperability is not only a technical challenge but also a communication and compliance imperative.

This article examines the compliance risks associated with fragmentation and explores communication strategies for healthcare leaders. Key areas include:

  1. educating internal teams on compliance-related adoption of FHIR standards;
  2. framing Health Information Exchanges (HIEs) and cloud-based platforms as compliance safeguards against information blocking and OCR investigations; and
  3. aligning staff expectations, training, and accountability during technology rollouts.

A compliance lens reinforces that interoperability is not optional—it is a regulatory obligation tied to patient rights, organizational risk management, and quality of care.

Introduction

Fragmentation in healthcare undermines not only care delivery but also compliance. When disparate systems fail to exchange data, organizations risk violating federal mandates related to patient access, privacy, and data sharing. The 21st Century Cures Act Final Rule requires organizations to provide patients with immediate electronic access to their records, while HIPAA’s Right of Access standard reinforces patients’ legal rights to their health information. Failure to comply may trigger Office for Civil Rights (OCR) investigations, penalties, or settlements (Office for Civil Rights [OCR], 2022).

Improved interoperability through standards like FHIR, Health Information Exchanges (HIEs), and cloud-based systems offers an opportunity to reduce compliance risk and strengthen organizational integrity. However, success depends on how effectively compliance leaders communicate changes, engage stakeholders, and align workflows with regulatory requirements.

The Compliance Risks of Fragmentation

System fragmentation is not merely an operational inconvenience—it directly impacts compliance.

Examples include:

  • HIPAA Violations: Incomplete or inaccessible patient records increase the likelihood of Privacy and Security Rule breaches.
  • Information Blocking: Under the ONC Cures Act Final Rule, organizations that delay or restrict information exchange risk penalties (ONC, 2020).
  • Claims and Billing Errors: Disconnected systems make it harder to validate documentation, increasing false claims liability.
  • Audit Vulnerability: Fragmented workflows create inconsistent documentation trails, raising red flags during audits.

From a compliance standpoint, breaking down silos is both a regulatory necessity and a risk management strategy.

Communicating FHIR Adoption Through a Compliance Lens

FHIR APIs are central to the ONC’s interoperability framework, enabling standardized, patient-directed data sharing. For compliance teams, communicating FHIR adoption requires balancing technical education with regulatory framing.

Compliance challenges:

  • Misunderstanding FHIR as a 'technology upgrade' instead of a compliance requirement.
  • Lack of clarity on how FHIR supports HIPAA Right of Access and ONC information blocking provisions.
  • Resistance from staff unfamiliar with regulatory consequences of noncompliance.

Communication strategies:

  • Regulatory Framing: Position FHIR adoption as a compliance mandate tied to federal law, not optional IT innovation.
  • Policy Alignment: Provide updated compliance policies showing how FHIR workflows safeguard patient rights.
  • Cross-Functional Briefings: Engage compliance, IT, and clinical teams together to prevent siloed communication.

By making compliance central to the conversation, staff understand that interoperability is not just about efficiency—it is about avoiding penalties and protecting patient trust.

Cloud-Based Platforms and HIEs: Compliance Safeguards, Not Just Technology

Cloud platforms and HIEs expand data access across organizational boundaries. From a compliance perspective, these tools mitigate risks of information blocking and improve adherence to patient access laws.

Compliance benefits:

  • Audit Readiness: Centralized data improves traceability for regulatory reviews.
  • HIPAA Safeguards: Cloud vendors increasingly offer compliance-certified environments with robust encryption and BAAs (business associate agreements).
  • Patient-Centered Compliance: HIEs reduce delays in record sharing, directly supporting Right of Access standards.

Communication priorities:

  • Stress that cloud and HIE adoption is not only about efficiency, but also about reducing exposure to OCR penalties.
  • Clarify shared accountability between providers, payers, and vendors for maintaining compliance safeguards.
  • Use compliance case studies (e.g., OCR enforcement actions) to illustrate the risks of fragmented systems.

Framing cloud and HIE adoption as compliance risk mitigation ensures leadership buy-in and reduces resistance to sharing data.

Managing Staff Expectations and Training During Rollouts

System-wide rollouts require a compliance-centered training approach. Staff must not only learn technical workflows but also understand the compliance stakes tied to their responsibilities.

Compliance-driven communication strategies include:

  1. Mandatory Training: Incorporating interoperability requirements into annual compliance training to emphasize regulatory obligations.
  2. Expectation Management: Clearly communicating that delays or barriers in sharing data could constitute information blocking.
  3. Super-User Networks: Assigning compliance-trained 'champions' to monitor adherence to workflows and escalate issues.
  4. Policy Updates: Linking rollout communication to policy changes in HIPAA access, data governance, and security protocols.

When staff view interoperability as part of their compliance role—not just an IT task—they are more likely to integrate it into daily practice.

Discussion - The intersection of interoperability and compliance is where organizational risk management, patient rights, and clinical efficiency converge. Communication breakdowns perpetuate system fragmentation, which can escalate into compliance violations. Conversely, transparent communication strategies—emphasizing regulation, patient safety, and organizational accountability—align stakeholders and promote sustainable interoperability.

Compliance leaders serve as translators between regulators, IT professionals, and clinicians. Their role is not only to enforce standards but also to ensure that staff understand why interoperability matters: to safeguard patients, maintain regulatory standing, and strengthen organizational trust.

Conclusion

Fragmentation is more than a technological problem; it is a compliance vulnerability. Interoperability initiatives such as FHIR adoption, HIE participation, and cloud migration reduce fragmentation but require strong communication strategies to succeed. From a compliance lens, effective communication ensures that staff recognize interoperability as a regulatory requirement, not an optional upgrade.

Ultimately, interoperability is a cornerstone of healthcare compliance and patient rights. By embedding compliance in communication, training, and strategy, organizations can break down data silos, mitigate risk, and deliver safer, more coordinated care.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • Adler-Milstein, J., Holmgren, A. J., & Kralovic, P. (2021). The impact of electronic health record interoperability on care quality and patient safety. Health Affairs, 40(9), 1427–1435. https://doi.org/10.1377/hlthaff.2021.00234
  • Cresswell, K., & Sheikh, A. (2017). Organizational issues in the implementation and adoption of health information technology innovations: An interpretive review. International Journal of Medical Informatics, 100, 63–76. https://doi.org/10.1016/j.ijmedinf.2017.01.001
  • Lin, S. C., Jha, A. K., & Adler-Milstein, J. (2020). Electronic health records and health care quality: Current evidence and future directions. Annual Review of Medicine, 71, 35–50. https://doi.org/10.1146/annurev-med-052218-020647
  • Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899–908. https://doi.org/10.1093/jamia/ocv189
  • Office for Civil Rights (OCR). (2022). Enforcement highlights: Right of Access Initiative. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html
  • Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program final rule. Federal Register, 85(85), 25642–25961.
  • Vest, J. R., Ancker, J. S., & Bates, D. W. (2019). Health information exchange: Persistent challenges and new strategies. Journal of the American Medical Informatics Association, 26(4), 325–331. https://doi.org/10.1093/jamia/ocy135

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 1: CMS Interoperability Framework Project: Should We Be Concerned?

Part 1: The Problem with System Fragmentation in Healthcare and Security Concerns 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 


The CMS Interoperability Framework is a call to action for health data networks that want to make what should already work actually work—by voluntarily meeting the CMS Interoperability Framework criteria to be designated as a CMS-Aligned Network.

This is a voluntary blueprint for modern health data exchange that puts patients and providers first. It is open, standards-based, and market-friendly so that the industry can stop theoretical debates and start delivering real results. CMS is offering shared infrastructure and clearly defined criteria for 2026.

The CMS Interoperability Framework doesn't mean centralizing all medical record data in a single location in the US. CMS is aligning networks to allow different types of health data sources, including health information networks, exchanges and other health technology platforms, to align with CMS goals for interoperability. The focus is on making it easier for different healthcare systems and applications to share and exchange medical information securely and efficiently. Here's what that means in simpler terms:

Think of it like different computer programs speaking the same language.

Currently, many healthcare systems use different formats and ways of organizing data. The CMS Interoperability Framework aims to establish common standards, especially using FHIR APIs, so that systems can understand and exchange information smoothly, regardless of where the data is stored.

  • A FHIR (Fast Healthcare Interoperability Resources) API is a standardized interface for exchanging health information between different healthcare systems using modern, web-based principles.
  • It acts as a shared "menu" that allows different software applications and platforms to "speak the same language," enabling them to request, retrieve, and share data like patient records, lab results, and other administrative or clinical information in a consistent format (JSON or XML).

It empowers patients and providers with access to medical information.

  • The framework promotes patient access to their health records through apps of their choice and makes it easier for providers to access the full patient history at the point of care.

It's a roadmap and a call to action, not a central database.

  • CMS is encouraging healthcare organizations, including networks, EHR systems, providers, and payers, to adopt common standards for data exchange, improving overall data sharing across the fragmented healthcare landscape.

It emphasizes data availability and standards, but it doesn't create a national repository.

  • The focus is on making it easier to share data between existing systems and promoting the use of standards like FHIR APIs and USCDI (United States Core Data for Interoperability).

So, instead of physically pulling all medical records into one place, the CMS Interoperability Framework is about creating a more connected system that allows patient data to flow securely between different locations and organizations, ultimately benefiting patient care and efficiency.

CMS Interoperability and the Risks of Sharing Patient Data with Big Tech Companies

The Centers for Medicare & Medicaid Services (CMS) has launched an ambitious Health Technology Ecosystem initiative aimed at creating a public-private partnership that facilitates seamless data exchange among patients, providers, and payers. As stated on the CMS website, Making Health Tech Great Again is a bold step toward modernizing our digital health ecosystem.

While details and operational aspects are still being finalized, partnerships have been publicly announced with major tech companies like Amazon, Apple, Google, Microsoft AI, OpenAI, and others, which signal a transformative shift in how healthcare data is accessed and shared. On July 30, 2025 CMS.gov posted a Press Release White House, Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem which states “More than 60 companies pledged to work collaboratively to deliver results for the American people in the first quarter of 2026. Twenty-one networks pledged to meet the CMS Interoperability Framework criteria to become CMS Aligned Networks. Eleven health systems or providers committed to participate and support patient use, and seven EHRs committed to facilitate data exchange and help “kill the clipboard.” At the same time, these collaborations also raise critical questions about data privacy, security, and governance.

Should we be concerned?

The CMS Health Tech Ecosystem initiative is overseen by the CMS Senior Advisor for Technology and supported by senior officials at the Department of Health and Human Services (HHS). Its mission is to promote a secure patient-centered digital healthcare system that would allow for ease of distribution, exchange, portability, and use of electronic health information. Fundamentally, this initiative seeks to improve patient access and enhance the efficiency of the healthcare industry. Its aim is to connect healthcare data sets that are currently siloed across disparate systems so that patients, providers, and healthcare payers will have reliable access to electronic medical records through a voluntary alignment. However, what lessons can be learned from the Change Healthcare breach?

Security Risks and Lessons Learned from the Change Healthcare Breach

A significant reminder of the vulnerabilities in extensive healthcare data systems is the February 2024 ransomware attack on Change Healthcare. Threat actors exploited the business associate’s lack of multifactor authentication, gaining unauthorized remote access via stolen credentials. Insufficient third-party vendor security postures create both upstream and downstream vulnerabilities across the healthcare ecosystem.

In the Change Healthcare breach, inadequate security controls resulted in widespread disruptions, including delays in medical treatments and prescriptions, stalled claims processing and reimbursements, and fragmented financial and operational access and delivery. These events underscore the need for comprehensive data governance, continuous security monitoring, and resilient infrastructure to safeguard protected health information (PHI). Most importantly, the lessons learned highlight the criticality of data confidentiality, integrity, and availability to ensure trust and continuity in patient care.

Along those lines, it is meaningful to act as informed advocates and to engage in mission-aligned questions, such as:

  • What minimum security standards must CMS’s third-party vendors and data brokers meet to safeguard data protection?
  • How is patient transparency ensured, and how is informed consent managed across diverse platforms?
  • Who holds accountability for data misuse or breaches, and what oversight mechanisms are in place to ensure compliance?

Conclusion

CMS's initiative for a more connected and patient-centered healthcare system offers significant benefits. But the public/private voluntary alignment must be grounded in data governance, responsible management of sensitive information, and a foundation of trust, transparency, and robust security—particularly in an innovative landscape shaped by public/private partnerships.

Please watch for Part 2: Interoperability and System Fragmentation in Healthcare: Communication, Compliance, and Strategies for Successful Integration, written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Artificial Intelligence, Extinction-Level Threat or Solution?

Written by the AIHC Education Department    


This article provides an overview of how the media and government are reacting to the potential of artificial intelligence (AI) and potential threats associated with this advanced technology.  Please read other AI articles published by the American Institute of Healthcare Compliance regarding how AI can advance quality of care, how AI is regulated, use of AI and HIPAA privacy/security, to name a few topics.

A Government-Commissioned Report Released February 2024

The U.S. State Department commissioned the first-ever assessment of proliferation and security risk from weaponized and misaligned AI. In February 2024, Gladstone AI, a four-person company which runs technical briefings on AI for government employees, completed that assessment. It includes an analysis of catastrophic AI risks, and a first-of-its-kind, government-wide Action Plan for what we can do about them entitled “An Action Plan to Increase the Safety and Security of Advanced AI.”

According to Time in a March 11, 2024 exclusive, U.S. Must Move ‘Decisively’ to Avert ‘Extinction-Level’ Threat From AI, the Gladstone AI report recommends a threshold should be set by a new federal AI agency which would require AI companies to obtain government permission to train and deploy new models above a certain lower threshold.

We can argue that there needs to be some type of controls to guide artificial intelligence, but hopefully the government will dive deeper, and quickly seek additional recommendations.  The government commission for this report from Gladstone AI was made in 2022.  According to the Time article, “The rise of advanced AI and AGI [artificial general intelligence] has the potential to destabilize global security in ways reminiscent of the introduction of nuclear weapons. AGI is a hypothetical technology that could perform most tasks at or above the level of a human. Such systems do not currently exist, but the leading AI labs are working toward them and many expect AGI to arrive within the next five years or less.”

As technology advances, so do cyber criminals 

When it comes to cyberattacks and cyber extortion (ransomware attacks), health care organization continue to suffer as prime targets and continue to struggle to recover after an attack.  

Threat actors (cyber criminals or extortionists) are leveraging AI to their advantage, which can be used as a potent weapon.  According to the National Cyber Security Centre (United Kingdom), artificial intelligence (AI) is expected to increase the global ransomware threat over the next two years. “AI enables relatively unskilled threat actors to carry out more effective access and information-gathering operations. This enhanced access, combined with the improved targeting of victims afforded by AI, will contribute to the global ransomware threat in the next two years.”

Using AI to Secure Healthcare Data

Government agencies are harnessing the power of AI for threat intelligence and defense. This involves using AI algorithms to analyze vast datasets, identify potential threats, and predict cyberattacks before they occur.  For now, health care organizations and business associates can access cybersecurity guidance through various agencies.

America’s cyber defense agency CISA (Cybersecurity & Infrastructure Security Agency).  CISA provides information on AI under Cybersecurity Best Practices on their website: https://www.cisa.gov/ai.

Artificial Intelligence, Cybersecurity and the Health Sector July 13, 2023 from the Office of Information Security and Health Sector Cybersecurity Coordination Center.  This PPT addresses:

  • What is artificial intelligence?
  • How does it work?
  • What does it mean for cybersecurity, especially for healthcare?
  • What can be done to remain secure, given AI-enhanced cyberthreats?

AIHC recommends training healthcare executives, managers and key workforce members in HIPAA privacy and security – training online available at: https://dev-main.aihc-assn.org/courses/hipaa-privacy-security-course/

AIHC is a Licensing/Certification Partner with the Centers for Medicare & Medicaid Services (CMS)

https://www.cms.gov/training-education/medicare-learning-network/partnerships#Licensing


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 3:  AI & Risk to Empathy, Compassion and Trust in Healthcare

Impact of Artificial Intelligence (AI) on Patient-Centered Care


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023 and Part 2 – Who Regulates Healthcare AI?.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest published by AIHC.  The COVID pandemic has proven that patients like telehealth and means other than face-to-face encounters for routine health needs.  But can AI replace the empathy, compassion and trust instilled during a personal encounter with a health care professional?  This article explores recent research on the topic of AI and patient-centered outcomes research.


As AI is integrated into patient care and medical coding, billing and accounts receivable management, will we risk the human connection of empathy and compassion which builds trust in the physician-patient relationship?  I embarked on a short research project to explore this topic and share my findings with AIHC members and affiliates.


Empathy, compassion and trust are fundamental values of a patient-centered, relational model of health care.  As Artificial Intelligence (AI) is advancing the delivery of health care and improving the diagnosis and treatment of our patients, is this promising technology providing greater efficiency and more free time for health-care professionals to focus on the human side of care, including fostering trust relationships and engaging with patients with empathy and compassion?  Or is it freeing time to see more patients to increase the revenue stream?


A June 2023 abstract was posted to the National Institutes of Health (NIH) National Library of Medicine, entitled “Artificial Intelligence in Health: Enhancing a Return to Patient-Centered Communication.”  The authors emphasize concerns around AI in the delivery of health care; concerns related to ethics, privacy, data representation and the potential of eliminating physicians. 


The article states “However, AI cannot replicate a physician's knowledge and understanding of the patient as a person and the conditions in which he or she lives. Therefore, provider-patient communication will be paramount in providing safe and effective health care.”


In April 2023, the NIH posted “The impact of artificial intelligence on the person-centered, doctor-patient relationship: some problems and solutions”.  The authors agree AI is a solution to freeing up of time for doctors and facilitating person-centered doctor-patient relationships. However, “… there is very little concrete evidence on their impact on the doctor-patient relationship or on how to ensure that they are implemented in a way which is beneficial for person-centered care.” 

  • Patient-centered outcomes research (PCOR) compares the impact of two or more preventive, diagnostic, treatment, or health care delivery approaches on health outcomes, including those that are meaningful to patients. 

In light of the given the importance of empathy and compassion in the practice of person-centered care, they conducted a literature review and found that besides empathy and compassion, shared decision-making, and trust relationships emerged as key values.


Using AI tools can have a positive impact on person-centered doctor-patient relationships, according to the article, when:

  1. using AI tools in an assistive role; and
  2. adapting medical education.

“Artificial intelligence and the doctor-patient relationship expanding the paradigm of shared decision making” is a June 2023 NIH article emphasizes how AI based clinical decision support systems (CDSS) are rapidly becoming more prevalent in healthcare, playing an important role in diagnostic and treatment processes. For this reason, AI-based CDSS has an impact on the doctor-patient relationship, shaping their decisions with its suggestions.


The article poses that we may be on the verge of a paradigm shift, where the doctor-patient relationship is no longer a dual relationship, but a triad. AI implementations may instead foster the inappropriate paradigm of paternalism. Understanding how AI relates to doctors and influences doctor-patient communication is essential to promote more ethical medical practice. Both doctors' and patients' autonomy need to be considered in the light of AI.


A successful AI case related to patient-centered outcomes was located on HealthIT.gov, the website for the Office of the National Coordinator for Health Information Technology (ONC).   ONC completed a project in September 2021 “Training Data for Machine Learning to Enhance Patient-Centered Outcomes Research Data Infrastructure.” 


Through this project, ONC in partnership with NIH and the National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK), advanced the application of AI/ML in patient-centered outcomes research (PCOR) by generating high quality training datasets for a chronic kidney disease (CKD) use case – predicting mortality within the first 90 days of dialysis. This case was selected because mortality in the first 90 days of dialysis initiation in ESKD/ESRD patients remains notably high and included joint clinician-patient informed decision making. PCOR researchers can build off the foundational work completed through this project and extend the application of these methods to a wider array of use cases and advance the application of ML to enhance PCOR infrastructure.


Conclusion


Working in health care requires adapting to constant change as technology and software advancements force not only providers, but IT professionals and health care administrators to stay ahead of what is coming.


It is important to be fiscally responsible, however, do we want to live in a world where we can only speak to a machine regarding questions about our medical bills, or discuss our concerns regarding a treatment plan?  Where is the humanity in that?


We must move forward with integrating AI into our lives.  But, moving forward, it is important to re-evaluate whether and how empathy, compassion and trust could be incorporated and practiced within a health-care system where artificial intelligence is increasingly used. Most importantly, society needs to re-examine what kind of health care it ought to promote.


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Telehealth
HIPAA, Telehealth

Audio-Video Telehealth, Mobile Device Management & You

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS


This article addresses how to track telehealth policies while addressing HIPAA compliance and mobile device management as the United States enters into a post-pandemic era. The information is an overview and should not be used as legal or consulting advice. Health care providers need to look toward long-term telehealth policies, ensure compliance and realize there is remaining work to be done. 


Scroll to the end of this article for “Basic Telehealth Terminology” if you are new to telehealth or if you are a mobile device app developer!


Most Providers Utilize Audio-Only Telehealth


More than two-thirds of providers utilizing telehealth use audio-only, according to a recent Telehealth Survey conducted November 2021 through December 2021 by the American Medical Association (AMA). According to this survey, 85% of physician respondents indicate they currently use telehealth. Those reporting a decrease in use since first offering it, now indicate doing a mix of in-person and virtual care. Of physician’s using telehealth, the trend indicates 93% are conducting live, interactive video visits with patients and 69% are doing audio-only visits.  


Considering this survey and other reports on audio-video services, concerns seem to focus on potential overutilization, equity and quality of care. 


A concern expressed to AIHC, by our Compliance and HIPAA Officer members, surrounds mobile devices used by providers and practice managers and the organization’s responsibility to comply with applicable rules, regulations and mobile device policies.


So, how do policies apply? 

 

If your providers use a mobile device to access an organization’s internal network or system, the owner of that network or system’s policies and procedures apply to your use of the mobile device to gain such access. It is your organization’s responsibility to understand and follow the organization’s policies and procedures.


If an organization allows providers and professionals to use mobile devices for work, the organization should have reasonable and appropriate mobile device policies and procedures. The policies and procedures should describe any configuration requirements for mobile devices used by providers and professionals for work. It is your responsibility to understand and follow your organization’s mobile device policies and procedures. But, what about using personally owned mobile devices for work?

  • "Bring Your Own Device" or BYOD refers to using a personally owned mobile device for work. Providers should be reminded to let their organization know when they want to use a personally owned mobile device. Many organizations have centralized security management to make sure mobile devices accessing their internal networks or resources are compliant with their security policies. Centralized security management includes:

o Configuration requirements, such as installing remote disabling on all mobile devices; and


o Management practices, such as setting policy for individual users or a class of users on specific mobile devices.


It is the provider’s responsibility to understand and follow the organization’s mobile device policies and procedures. Registering the provider’s mobile device with the organization allows the organization to control who has access to its network or system and will keep unauthorized persons from accessing its network or systems.

  • Registering these mobile devices with your organization may also help the organization or law enforcement find your mobile device if it is lost or stolen. Providers should be directed to contact their organization’s Privacy Officer or Security Officer to register their mobile device.

Utilizing Step 4 from ONC’s 5-Step Process to Manage Mobile Devices Used by Health Care Providers & Professionals, the list of questions below is a way to take inventory of potential safeguards needed to address risk areas.


Mobile Device Management


 If your organization allows the use of mobile devices, what should the organization do about managing the use of mobile devices?


   o Has the organization identified all the mobile devices that are being used in the organization? How is the organization keeping track of them?


   o Has the organization assigned responsibility to check all mobile devices used for remote access, to find out if selected security/configuration settings are enabled?


   o Should there be a regular review and audit of the mobile devices? 


Misuse of Mobile Devices


 Does the organization have written procedures for addressing misuse of mobile devices?


   o If so, what are the consequences when a mobile device is misused and the incident poses risk of a data breach?


Should the Organization Allow BYOD?


 Is this a policy already in place, where providers are using their own devices?


   o Should the organization let providers and professionals use their personally owned mobile devices within the organization?


 Should providers and professionals be able to connect to the organization’s internal network or system with their personally owned mobile devices, either remotely or on site?


Restrictions on Mobile Device Use


 Does the organization restrict how providers and professionals can use mobile devices?


   o Can providers and professionals use mobile devices to access internal networks or systems, such as an EHR?


   o Are providers and professionals restricted from using mobile devices when they are away from the organization?


   o Can providers and professionals take their mobile devices home?


   o Should the organization allow texting or emailing of health information?


      Is there encryption allowing compliant texting and emailing from the mobile device?


Security/Configuration Settings for Mobile Devices


 Will the organization institute standard configuration and technical controls on all mobile devices used to access internal networks or systems, such as an EHR?


   o If so, is the organization's current mobile device configuration document, including connections to other systems/applications, inside and outside of the firewall.


Information Storage on Mobile Devices


 Are there restrictions on the type of information providers and professionals can store on mobile devices?


   o If so, where and for how long should the data be stored?


 Are providers and professionals allowed to download mobile applications to mobile devices? If so, what type(s) of applications are approved?


Recovery/Deactivation of Mobile Devices


 Does the organization have procedures to wipe or disable a mobile device that is lost or stolen?


 Does the organization have standard procedures to recover mobile devices from providers and professionals when their employment or association with the organization ends?


Mobile Device Training


Training is always a challenge, but if your organization cannot achieve effective training and compliance, you may need to reconsider how telehealth is delivered to your patient population.


 How is the organization training its workforce (management, doctors, nurses, and staff) on policies and procedures?


 How does the organization hold its workforce (management, doctors, nurses, and staff) accountable for non-compliance? 


What Additional Information Should I Know for Compliance?


Covered entities must comply with HIPAA Privacy and Security Rules to protect and secure health information, even when using mobile devices as described above. Taking it a step further, health care leaders are responsible to ensure that mobile device procedures and policies have been developed and properly implemented to protect the health information patients entrust to you.


Make Tracking Audio-Only Policy Easy


A great resource is utilizing the National Telehealth Policy Resource Center called “CCHP,” short for Center for Connected Health Policy. CCHP has been tracking audio-only policies across the country and offers access to state audio-only policies via CCHP’s Policy Finder Tool.


As AIHC advises, another resource is legal advice through your malpractice insurance company. At no additional charge, a risk attorney can be made available to help review which policies impact your type of practice and organization.


Free HIPAA Compliance Resources


Another reliable resource is found at HealthIT.gov, the official website of the Office of the National Coordinator for Health Information Technology, otherwise known as “ONC.” ONC offers basic guidance in these five steps 1) Decide; 2) Assess; 3) Identify; 4) Develop, Document and Implement; and 5) Train entitled “five steps organizations can take to manage mobile devices used by health care providers and professionals.”


Does Your Organization Have a Trained (Certified) HIPAA Privacy/Security Officer?


Your HIPAA Compliance Officer can serve as the best resource to help your organization navigate the telehealth and mobile device compliance issues facing your providers today. AIHC offers an online course covering both privacy and security with the option of certification (proctored and administered online).  The cost of certification is covered in the tuition price. Learn more.


It is highly recommended that mobile health app developers and Managed Service Providers (MSPs) have an in-house HIPAA Compliance Officer contributing input to ensure technology is compliant.


Are You a Mobile Health App Developer?


Integrating protections into your technology to create HIPAA compliant products is necessary for your company to succeed. Health care providers are subject to the HIPAA rules as covered entities to protect identifiable health information when it is created, received, maintained and/or transmitted. These protections are required under Federal and State Privacy, Security and Breach Notification Rules. A few basic resources to reference are:


The Office for Civil Rights (OCR) HIPAA website devotes a webpage under Special Topics entitled “Resources for Mobile Health Apps Developers.”


The Federal Trade Commission (FTC) offers a webpage entitled “Mobile Health Apps Interactive Tool” to help you locate federal laws to follow.


For Beginners - Basic Telehealth Concepts


Telehealth is also referred to as Telemedicine. It is the use of telecommunications technology to provide health care services to persons who are at some distance from the provider. This type of patient encounter involves a spectrum of technologies.


Coverage and payment for telehealth can include consultation, office visits, individual psychotherapy, pharmacologic management and other services delivered via an interactive audio and video telecommunications system.  

  • Providers are located at the distant site; and
  • Patients are located at the originating site.

Provider at the distant site - As stated above, providers are at the “distant site,” referring to where the provider is at time of service. The provider can communicate with the patient using an interactive audio and video telecommunication system that permits real-time communication with the beneficiary.


When telehealth is used, it is considered to be rendered at the physical location of the patient, and therefore a provider typically needs to be licensed in the patient’s state. During the COVID-19 public health emergency (PHE), many states waived this requirement or provided specific exceptions. Click Here for Cross-State Licensing information.


Medicaid programs often restrict the type of providers that can be reimbursed when delivering services via telehealth. During the COVID-19 PHE, the list of providers in Medicare and many state Medicaid programs expanded to include professionals such as occupational and physical therapists and speech-language pathologists. Federally Qualified Healthcare Centers (FQHCs) and Rural Health Clinics (RHCs) were also allowed to provide services in some cases. These policies are temporary and most will expire at the end of the PHE.


I also recommend utilizing the TELEHEALTH.HHS.GOV website for providers – “Getting Started with Telehealth.” This webpage provides many additional links to more resources your organization can use to navigate this complex topic.


Temporary telehealth policies during the PHE were implemented to provide improved access to health care during the COVID-19 pandemic. The federal government has been encouraging providers to use telehealth to conduct virtual appointments and has made the telehealth “rules” more flexible. For instance, audio-only delivery of care has rarely been reimbursed historically. But due to COVID and the PHE, temporary policies allow this modality to deliver some services.


The PHE is reviewed and potentially extended every 90 days. When the PHE ends, coverage for telehealth may change. Monitor these updates by using the CCPH website referenced earlier in this article found at https://www.cchpca.org/.

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More
    Telehealth
    Telehealth

    Telehealth Today: Challenges & Opportunities

    Written by: J Bradley  

    Read More
    General Compliance

    A Reemerging Threat in the Age of COVID-19 & Remote Healthcare

    Hacking With Worldwide Implications   

    Written by Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)   

    As HIPAA Privacy & Security Officers struggle to secure data due to the increase in our remote workforce, an important potential hack could be looming for unaware organizations.  Healthcare IT departments secure our computers and train us in the rules governing what can be accessed in effort to enforce HIPAA security. Nevertheless, are you unintentionally posing risk to the security of your company’s data? 

    This article is for all Covered Entities and Business Associates with a remote workforce or with providers accessing patient data remote on a mobile device and smaller organizations new to remote workers due to COVID-19.

    As Healthcare Technology advances, so do the skills of hackers!  People are trying to find ways to stay healthy during the pandemic.  What is one hack likely to occur that may escape our HIPAA Security Officer’s attention?  The wearing of activity trackers (also known as FitBits, smartwatches, and other wireless-enables wearable technology devices). According to USA Today, Smartwatch sales soared during the start of the Coronavirus crisis with Apple selling more than 3 times as many devices as its competitors (https://www.usatoday.com/story/tech/2020/05/07/smartwatch-shipments-rise-20-despite-pandemic-sales-led-apple/3086904001/).  

    Think I watch too many crime dramas?

    Unfortunately hackers are evolving at pace with technology and even the most innocuous and personal technology can be, and has been, hacked. This includes the immensely popular Fitbit. Like the personal cell phone most employees believe these devices are innocuous and will not be harmful if they get plugged in to the work computer. In this article I will cover a threat that faces the immensely popular personal health monitoring device. But be aware, this applies to any wearable technology device.

    The Fitbit continues to show how personal devices can be hacked, and proprietary medical information can be extracted and malicious software remotely downloaded. Even information that does not seem to show you the truth is far more concerning than crime dramas.

    In a November 14, 2018 article, Jennifer Falsetti wrote how the FitBit can be used, in this case by law enforcement!  At that time, in 2018 in Oklahoma there was a case of the missing jogger, Mollie Tibbetts. Tibbets went out for a jog, and never returned. Law enforcement desperately searched for her and Mollie was found not far from the road she frequently ran. The way investigators searched for Mollie was to the Fitbit tracker she was wearing at the time. Although cell phones had been used as location devices for years, the Fitbit added an element that gained rapid national attention. When  interviewed by Falsetti, Midwest City Police Chief Brandon Clabes had this to say. "These things have grown in the past few years where it's something we use quite often in our investigations. Both criminally and missing persons, these Fitbits have tracking devices inside which really is a safety factor for the individual that wears them because it tells us exactly where you are, and what time, and what place and it gives us the information to determine, especially on a missing persons case trying to locate you like the Mollie Tibbets case. It also helps us investigate crimes because people will tell us one thing but we can verify through GPS, through their Fitbit," said Clabes. 

    So how does this apply to HIPAA security?  Let me explain. The tracking capacity of the Fitbit answers many important, and valuable questions for healthcare hackers using the same technology that helped find Mollie Tibbetts: "When do they see their doctor? Where do they see their doctor? When are they home? When are they not home? What pharmacy do they use? What are they doing? Who else are they with while they're not at home?

    So, hackers can track information through your personal health device, but hackers can also feed malicious software into the device, and when plugged into any computer the malware will be downloaded. 

    The wearable device directly communicates with your phone. It's unsecure, and if you're within range of the device or multiple devices like it and you know what you're doing, you can start surveying and see who is out there. Although the range for this info-grab is only 10-30 feet or so, think of how many times you are in an area with multiple people within these parameters. Even during these initial reopening phases of COVID-19 in a given day there can be many. How many do you know? And are those people with their faces buried in their phones as innocent as they seem?

    A real life example of the ability to transfer malicious data was clearly displayed a few years back. Darlene Storm, regular writer for COMPUTERWORLD magazine in her column SECURITY IS SEXY October 26, 2015 wrote about an astounding act of research that caused concern in the security community and an aggressive counterattack by Fitbit. The event took place in 2015:

    • At the Hack.Lu 2015 security conference in Luxembourg, Fortinet researcher Axelle Apvrille presented a proof-of-concept vulnerability in Fitbit Flex fitness trackers; an attacker in close range needed only 10 seconds to wirelessly inject malicious code into a Fitbit Flex wristband via a Bluetooth connection. 
    • The foreign code could persist and then infect a PC or other devices to which the Fitbit Flex connects. 10 seconds. The portion which really arrested the attention of security-conscious audiences was when Apvrille demonstrated how Flex could be infected via Bluetooth. Granted, while the maximum bytes of foreign code to infect Fitbit are only 17, she pointed out that the Trojan capable of crashing Pentium in 1997 (the “FOOF bug”) was a mere four bytes and the Mini DOS virus was only 13 bytes.

    So what if the Bluetooth is the part infected? The Fitbit is remote and although hooked to the phone via Bluetooth, isn’t the threat contained? No. One of the scariest extensions of Apvrille’s results was that by infecting through Bluetooth, when the Fitbit gets plugged in to a computer, the computer gets the infection as well. At this point no one is likely to believe their information would be worth hacking. In a rare instance that may be true but consider: what if you have a medical condition and you are reporting data to your doctor based on Fitbit? And to keep it current you will have to plug it into your computer regularly. And maybe your information may not be worth stealing or selling; but what about the President of the United States? As of this article’s publication President Barack Obama wore a Fitbit Surge for 8 months (and he was noted to use his personal phone often). Fortinet, Aprville’s sponsor, explained three steps which would take the problem from research to active attack; two of which were conclusively proven:

    “There are three steps to seeing this go from ‘proof of concept’ to a problem in the wild:

    1.  Upload malicious code to any Fitbit wristband in close range.
    2. Automatically transmit the code from the Fitbit wristband to any computer that connects to it (via the Fitbit dongle).
    3. Have the code be executed by the connected computer.

    *Fortinet researchers demonstrated and verified steps 1 and 2. Step 3 would rely on exploiting a vulnerability in the computer to which the Fitbit wristband was synced, which was out of the scope of our research. To date, we are not aware of an exploit that would enable this third step, nor did we actively look for one. However, we would caution against working under the assumption there is no such exploit possible, now or in the future.”

    Despite the evidence Fitbit vehemently denied there was any vulnerability in their product, and my research to date has not located anything indicating Fitbit has changed its position. In addition, hackers attacked Fitbit itself. Cybercriminals used leaked email addresses and passwords from third-party sites to log into accounts of Fitbit wearable device users. Fitbit confirmed that once inside the accounts, the attackers changed details and attempted to defraud the company by ordering replacement items under the user's warranty. The attackers also reportedly had access to customer data, including GPS history, which shows where a person regularly runs or cycles, as well as data showing what time a person usually goes to sleep.

    A January 2018 article in Hackaday reported how Strava, a well known data monitoring service, followed Fitbit users’ data; in part monitoring GPS data. Even though Strava had a sound Privacy policy, the heatmap they built based on GPS data built visualizations using over 6 trillion data points and could be assembled into a fascinating gallery, but there was a downside. The weekend this article appeared an announcement on Twitter reported Strava’s heatmap also managed to highlight exercise activity by military/intelligence personnel around the world, including some suspected but unannounced facilities. Additionally, some mapped paths imply patrol and supply routes, knowledge security officers would prefer not to be shared with the entire world. What this glaringly brought to light was Strava’s redacted data sharing did not identify any individuals: but did or could not do the same for groups of individuals like active duty military personnel whose exercise regimens are clearly defined on these heat maps. 

    The biggest contributor (besides wearing a tracking device in general) to this situation is that data sharing is enabled by default and must be opted-out. This finding and report stands in a class of its own. That Fitbits can be hacked has been recognized for some time but to date the hacks have been localized. That this kind of data can be discovered globally caused enormous concern throughout every industry that demands privacy, confidentiality and seeks to safely compartmentalize proprietary data. I watched local news stations report on this event, and the article can be found at https://hackaday.com/tag/fitbit/.

    So, as a loyal workforce member, think about your healthcare organization; think about the daily, weekly, monthly, etc. volume and flow of electronic data. Now think of someone like The Centers for Medicare and Medicaid Services (CMS), Blue Cross and Blue Shield and even your state’s Worker Compensation groups. When an experienced hacker trawls the Internet for healthcare data and information the “hook” is bound to find its mark somewhere, and a breach is inevitable. This is where your IT security teams truly start their work.

    Security teams, as a rule, have far too many systems and too much tech landscaping to protect from hacks. They will use automated systems such as IPS (Intrusion Prevention Systems) and IDS (Intrusion Detection Systems) takeover to limit the damage. Because attacks and probes happen at very high volumes, manual reaction and protection cannot be accomplished individually. Human intervention typically comes after the threat has been identified. Determining the threat, point of entry, potential or caused damage, threat risk assessment and how to close the vulnerability so it cannot be reused and building effective firewalls are the tasks of the manpower part of the tech security equation.

    The security team will spend hours poring over documents, programs, systems, protocols, laws and, especially in health care, security breach reporting algorithms. See why TV hates reality now? Both sides in reality spend hours in very labor intensive work. The fastest part is done before and after the fact, automatically.

    We all know that there are instances where hackers and security do battle in real time: and they are fascinating even if you do not understand everything they do. They’re called Capture The Flag (CTF) games. People do NOT know anything-television shows try to convince them these battles occur in real time. This entire section is showing examples where these battles do happen: but they are closely monitored and security is tight.  

    CTFs are conducted in one of two ways. One, there is a Red Team contest where the hackers are given systems with no active defenses. The Red Team works against a set of protections they are given before the contest. The more familiar contest pits the Red Team (hackers) against the Blue Team (security forces). As one would anticipate, the Red team scores points for successful hacks and penetrations; and the Blue Team scores points through successful deflections of the attacks and securing/closing of discovered vulnerabilities.

    Why add this last story? It may be interesting but what does it have to do with hacking Fitbits? To demonstrate both the hackers and security forces are constantly evolving but the technology is there and has been successfully exploited for some time. When that hacker sits near you in the coffee shop, many person-hours have gone into trawling the Fitbit or smartwatch, its defaults, capabilities and vulnerabilities. Although the articles used here date back to 2015, be aware these problems are still considered to be real threats today and strict security precautions are the norm at most organizations. 

    Conclusion

    Never plug your phone or personal device into your work computer to recharge.  Notify your organization’s HIPAA Officer if wearing a FitBit, Smartwatch or other personal device which could pose a threat to the security of your organization’s system, even if you are working remote from home on your own computer which VPNs into the company’s systems.

    Follow your organization’s HIPAA policies and procedures at work, at home or working anywhere remote.

    Still not convinced that hacking is a problem?  I encourage you, I dare you to visit the U.S. Department of Health and Human Services Office for Civil Rights “Wall of Shame” at https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf and just look only at cases under investigation the volume just under the cause “Hacking/IT Incident” would be difficult to tally, there are so many. 

    Look at the Health Plans, small and large providers as well as Business Associates listed on the Wall of Shame due to large breaches under investigation. 

    The problem is current, it is relevant and with the ever increasing popularity of individual electronic devices coupled with great numbers of healthcare employees now working, basically unsupervised, from home the vulnerabilities of these devices will continue to rise and be exploited.

    About the Author

    Carl J Byron, CCS, CHA, CIFHA, CMDP, CPC, CRAS, ICDCTCM/PCS, OHCC and CPT/03 USAR FA (Ret)

    Carl is an experienced professional and contracted auditor with the military. His background includes HCC auditing for CMS, coding and auditing for a large global healthcare network, and serving as a compliance educator and speaker for AIHC. He currently volunteers as a subject matter expert for AIHC, a non-profit licensing and certification partner with CMS.  

    References:

    1. http://2015.hack.lu/talks/#geek-usages-for-your-fitbit-flex-tracker
    Read More
    Compliance in Healthcare
    Corporate Compliance

    The ADA and Accessibility in Health Care

    Written by: Compliance blogger

    Read More
    Telehealth
    HIPAA, Telehealth

    Telehealth, HIPAA, and Cybersecurity

    Written by: Compliance blogger

    Read More