HIPAA Compliance
HIPAA

The Final Rule: Information Blocking

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS

This article addresses the Information Blocking Final Rule regarding enforcement, associated Civil Monetary Penalties (CMPs) and entities subject to these penalties.  This article is subsequent to the original article “HIPAA, The Cures Act and Information Blocking Compliance” and Article on Right of Access Vs Information Blocking Part 1 and Part 2.

On September 14, 2023, the Office of Inspector General (OIG) posted the Final Rule “Fraud & Abuse; Information Blocking; OIG’s Civil Money Penalty Rules” describing enforcement of the Information Blocking rule.

“Actors” Subject to Penalty

Blocking health information interoperability is prohibited by “Actors”, which are health information networks, HIEs, health information technology developers of certified health IT, and health care providers.  Information blocking is defined in § 171.103.  In the context of information blocking, the Cures Act authorizes Civil Monetary Penalties or CMPs for any practice that is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information (EHI) if the practice is conducted by an entity subject to penalty.

How to Determine if Information is EHI

The image below is from HealthIT.gov:

So, what is NOT EHI?

  1. Psychotherapy notes as defined in 45 CFR 164.501
  2. Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding
  3. Individually identifiable health information in education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g
  4. Individually identifiable health information in records described at 20 U.S.C. 1232g(a)(4)(B)(iv)
  5. Individually identifiable health information in employment records held by a covered entity in its role as employer
  6. Individually identifiable health information regarding a person who has been deceased for more than 50 years
  7. De-identified protected health information as defined under 45 CFR 164.514

What is meant by “interfere”?

Interfere with or interference related to information blocking of EHI means to prevent, materially discourage, or otherwise inhibit and applies to:

  • Health Care Provider - Entities offering certified health IT;
  • Health IT developers of certified health information technology (IT); and
  • Health information exchange (HIE); or Health information networks (HIN) and an entity that knows or should know that the practice is likely to interfere with, prevent, or materially discourage the access, exchange, or use of EHI;

The 3 categories of “Actors” listed above which are subject to enforcement penalties are explained in more detail below.

Health Care Provider

A health care provider is a: hospital; skilled nursing facility; nursing facility; home health entity or other long term care facility; health care clinic; community mental health center; renal dialysis facility; blood center; ambulatory surgical center; emergency medical services provider; federally qualified health center; group practice; pharmacist; pharmacy; laboratory; physician; practitioner; provider operated by or under contract with the Indian Health Service (HIS) or by an Indian tribe, tribal organization, or urban Indian organization; rural health clinic; covered entity under 42 U.S.C. 256b; ambulatory surgical center; therapist; and any other category of health care facility, entity, practitioner, or clinician determined appropriate by the HHS Secretary. 

  • The full definition of “health care provider” is available in the Public Health Service Act (42 U.S.C. 300jj).
  • For healthcare providers, the law applies the standard of whether they know that the practice is unreasonable and is likely to interfere with the access, exchange, or use of EHI.

Health IT developer of certified health IT

This is in reference to an individual or entity, other than a health care provider, that self-develops health IT for its own use, that develops or offers health information technology (as that term is defined in 42 U.S.C. 300jj(5)) and which has, at the time it engages in a practice that is the subject of an information blocking claim, one or more Health IT Modules certified under a program for the voluntary certification of health information technology that is kept or recognized by the National Coordinator pursuant to 42 U.S.C. 300jj–11(c)(5) (ONC Health IT Certification Program).

Health Information Network or Health Information Exchange

Health information network or health information exchange means an individual or entity that determines, controls, or has the discretion to administer any requirement, policy, or agreement that permits, enables, or requires the use of any technology or services for access, exchange, or use of electronic health information:

  • Among more than two unaffiliated individuals or entities (other than the individual or entity to which this definition might apply) that are enabled to exchange with each other; and
  • That is for a treatment, payment, or health care operations purpose, as such terms are defined in 45 CFR 164.501 regardless of whether such individuals or entities are subject to the requirements of 45 CFR parts 160 and 164.

Enforcement

The final rule also explains OIG's approach to enforcement, with focus on information blocking allegations that pose greater risk to patients, providers, and health care programs, as well as OIG's anticipated consultation and coordination with the Office of the National Coordinator for Health Information Technology (ONC) and other agencies, as appropriate, in reviewing and investigating allegations of information blocking.

The Cures Act identified ways for ONC, OCR, and OIG to consult, refer, and coordinate on information blocking claims.

Information Blocking Investigations and Enforcement for Entities Subject to Civil Monetary Penalties

  1. OIG receives an information blocking complaint;
  2. OIG uses its enforcement priorities to assess complaints;
  3. OIG opens an information blocking case leading to the next step;
  4. OIG investigating the complaint by gathering facts, conducting interviews, document requests, etc. 
    • OIG may consult with ONC to assess facts and information blocking regulations
    • Case closed if OIG concludes information blocking was not committed
  5. OIG provides an opportunity to the entity to discuss OIG’s investigation;
  6. If OIG concludes the entity committed information blocking, a demand letter is sent to the entity;
  7. Entity has the opportunity to appeal OIG’s imposition of the penalty.

Whether OIG's or ONC's authority is appropriate to address a claim of information blocking will depend on the facts and circumstances of the allegation and the results of an investigation. For example, ONC and OIG may initially agree that a claim is most appropriately evaluated through an OIG investigation.

ONC has authority to take action against an individual or entity that is a developer participating in the ONC Health IT Certification Program. 45 CFR 170.580.

OIG has authority to impose CMPs against a health IT developer of certified health IT, which includes developers participating in the ONC Health IT Certification Program. Thus, an individual or entity that meets the definition of health IT developer of certified health IT could be subject to CMPs, termination of certification or other action under the ONC Health IT Certification Program review process, or both. 85 FR 25789, May 1, 2020.

Conclusion

The ONC Final Rule implements certain Cures Act information blocking provisions, including defining terms and establishing reasonable and necessary activities that do not constitute information blocking or “exceptions” to the definition of information blocking.  I recommend reading the additional articles referenced below to gain a better understanding of the eight exceptions to the Rule.  Also, visit the ONC Information Blocking Portal designed for individuals to file a complaint regarding Information Blocking and/or HIPAA violations made by covered entities or business associates.

Additional Resources to Reference:

Learn the basics of the 2021 Information Blocking Rule “HIPAA, The Cures Act & Information Blocking Compliance” which explains the original inception date and outlines exceptions to the Rule

Know the difference between a Right of Access Violation versus Information Blocking:

  • Is the Violation Right of Access or Information Blocking? Part 1 of 2
  • Is the Violation Right of Access or Information Blocking?  Part 2 of 2

Information Blocking page; Office of the National Coordinator for Health Information Technology (ONC) on HealthIT.gov

Information Blocking Portal


Online Training in HIPAA Privacy/Security with a lesson addressing Interoperability, Right of Access, Information Blocking and Artificial Intelligence

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved 

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking?  Part 2 of 2

Written by: A. Michi McClure, J.D., an AIHC member and Volunteer on the CEU Education Committee   

This article follows Part 1 on the topic of understanding potential HIPAA violations when releasing information.  Is it Right of Access or Information Blocking?  Both have penalties. If you haven’t yet, read Part 1. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

Right of Access Initiative 

An individuals’ right to access their Health Information is located at 45 CFR § 164.524 as part of the HIPAA rule. It provides individuals to exercise the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103.  The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.  On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS).

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are a continuation from the information provided in Part 1, demonstrating a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

To whom can the information be released?

In addition to the individual, the following individuals or entities may be allowed access to PHI under certain circumstances:

  1. Personal representatives: Individuals may designate a personal representative, such as a legal guardian, healthcare proxy, or other authorized person, to act on their behalf in obtaining access to their PHI.
  2. Parents and guardians: Parents or legal guardians may access the PHI of their minor children or children for whom they are legal guardians.
  3. Healthcare providers: Other healthcare providers may be granted access to an individual's PHI for the purpose of providing treatment or coordinating care.
  4. Business associates: Business associates that provide services to covered entities, such as billing or transcription services, may be allowed access to PHI to perform their services.

EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. Authorized parties may include:

  1. Other healthcare providers: Healthcare providers may be authorized to access an individual's EHI for the purpose of providing treatment or coordinating care.
  2. Health plans: Health plans may be authorized to access an individual's EHI for the purpose of administering benefits and coordinating care.
  3. Caregivers and family members: Caregivers and family members may be authorized to access an individual's EHI with the individual's consent or as authorized by law.
  4. Researchers: Researchers may be authorized to access de-identified EHI for research purposes, subject to certain privacy and security requirements.
  5. Public health authorities: Public health authorities may be authorized to access EHI for the purpose of monitoring and responding to public health threats.

May the request be denied?

A covered entity may deny a request for access to protected health information (PHI) under certain limited circumstances. The covered entity must provide a written denial and explanation of the denial to the individual, along with information on how to request a review of the denial. The limited circumstances under which a request for access may be denied include:

  1. Psychotherapy notes: Covered entities are not required to provide access to psychotherapy notes, which are notes recorded by a mental health professional documenting or analyzing the contents of a counseling session.
  2. Information compiled for legal proceedings: Covered entities may deny access to information that is created for the purpose of legal proceedings, such as attorney-client privileged communications.
  3. Information prohibited by law: Covered entities may deny access to PHI if providing access would be prohibited by another law.
  4. Information that may cause harm: Covered entities may deny access to PHI if they reasonably believe that providing access would endanger the life or physical safety of the individual or another person.

Under the information blocking rule, healthcare providers and other covered entities may only deny a request for access to EHI under certain limited circumstances. The exceptions under which a request for access may be denied include:

  1. Preventing harm: A healthcare provider may limit the access to EHI if they believe that providing access could reasonably result in harm to the individual or another person.
  2. Privacy: A healthcare provider may limit access to EHI if they reasonably believe that providing access would violate the privacy of another person.
  3. Security: A healthcare provider may limit access to EHI if they reasonably believe that providing access would pose a security risk to the EHI or to other systems that are part of the electronic health record ecosystem.
  4. Infeasibility: A healthcare provider may limit access to EHI if the request is not technically feasible or if providing access would require unreasonable effort or resources.

If access is denied, the healthcare provider must also provide information on how to file a complaint.

Fees allowed to be charged to the patient?

Yes, covered entities under HIPAA Privacy Rule may charge a reasonable, cost-based fee for providing individuals with access to their protected health information (PHI).

  • The fee may only include the cost of labor for copying the PHI, supplies for creating the paper or electronic copy, and postage if the individual has requested that the PHI be mailed to them.
  • The fee may not include the cost of searching for and retrieving the PHI or any other associated administrative costs.

Covered entities are required to inform individuals of the fee in advance.

  • The fee may not be a barrier to individuals accessing their PHI. Covered entities must also provide access to the PHI in the format requested by the individual if it is readily producible in that format.

It's important to note that there are some situations where fees cannot be charged, such as when an individual requests access to their PHI for the purposes of filing a complaint with the HHS or if the covered entity fails to provide the individual with access to their PHI in a timely manner. Some state laws may limit or prohibit the fees that can be charged for providing access to PHI.

No, under the information blocking rule, healthcare providers and other covered entities may not charge fees that are not reasonably necessary for accessing, exchanging, or using EHI.

  • This means that if an individual requests access to their EHI or for their EHI to be transmitted to another entity, covered entities are generally not allowed to charge fees that are higher than the cost of labor and resources required to fulfill the request.

Additionally, if a covered entity charges fees for any other services or products related to EHI, such as an EHR system, the fee must be reasonably related to the actual cost of providing the service or product. The covered entity must also provide a detailed explanation of the fees and how they were calculated and must make the fees publicly available.

It's important to note that there are some circumstances where a covered entity may be able to charge fees that are higher than the cost of labor and resources, such as when the request is complex or involves large amounts of EHI. However, these fees must be reasonable, and the covered entity must provide an itemized bill explaining the fees.

Please review Part 1 for more information. 

We also encourage consulting with your malpractice Risk Attorney.  Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs.  If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

Is the Violation Right of Access or Information Blocking? Part 1 of 2

Written by: A. Michi McClure, J.D. an AIHC member and Volunteer on the CEU Education Committee   

The right of access and information blocking are both related to the access and exchange of health information, but they are different in several key ways. HIPAA Privacy/Security and Compliance Officers and Health Information Management professionals need to know the difference. 

 

Right of Access Initiative 

Individuals’ Right under HIPAA to Access their Health Information 45 CFR § 164.524

This initiative helps to empower individuals to take control of their own health information, allowing them to better manage their healthcare and make informed decisions about their health. By ensuring that individuals have access to their own health information, this initiative also helps to improve the quality and continuity of care, while also protecting the privacy and security of that information.

The right of access is a requirement under HIPAA that individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. This includes electronic protected health information (ePHI).

ePHI is defined in HIPAA regulation as any protected health information (PHI) that is created, stored, transmitted, or received in any electronic format or media. The right of access also includes the right to request that their PHI be transmitted to another entity, such as another healthcare provider or a personal health record (PHR). Covered entities must provide individuals with timely access to their PHI and may only deny access under certain limited circumstances.

Information Blocking

The exact regulatory definition of Information Blocking can be found in the Code of Federal Regulations in 45 CFR 171.103

Information blocking is a practice in which a healthcare provider, health plan, or other covered entity intentionally interferes with the access, exchange, or use of electronic health information. The information blocking rule, which was established under the 21st Century Cures Act, requires covered entities to make EHI available for access and exchange in a way that is secure, timely, and appropriate to the circumstances.

The ultimate goal of the Information Blocking Act is to promote greater collaboration and coordination among healthcare providers and other stakeholders, which can lead to improved quality of care, better patient outcomes, and more efficient use of healthcare resources. By breaking down barriers to the exchange of health information, this legislation aims to facilitate the development and implementation of innovative healthcare solutions that can improve the overall health of the population.

On October 6, 2022, the definition of electronic health information (EHI) expanded to include all of the digital components of an organization’s designated record set (DRS). Prior to this date the definition of EHI was limited to the data elements represented in the United States Core Data for Interoperability (USCDI) v1.

Covered entities may not use information blocking practices to prevent or interfere with access, exchange, or use of EHI, except in certain limited circumstances.

Confused?

While both the right of access and information blocking are designed to promote the access and exchange of health information, the right of access focuses on individuals' access to their own PHI, while information blocking focuses on the sharing of EHI between covered entities.

Additionally, the right of access is a long-standing requirement under HIPAA, while information blocking is a more recent requirement under the 21st Century Cures Act.

It is important to differentiate between Right of Access and Information Blocking to ensure your organization is compliant to both rules as well as any applicable State privacy regulations.  The charts below are provided as a comparison of similarities and differences between the two.

Aspect

Right of Access

Information Blocking

What it is:

The HIPAA requirement to provide individuals with access to their own PHI contained in one or more designated record sets maintained by a covered entity.

A provision in the 21st Century Cures Act intended to minimize the interference of the ability of authorized persons to access, exchange, or use Electronic Health Information.

Enforcement date:

The HIPAA Privacy Rule was first enforced in the United States on April 14, 2003. The Office for Civil Rights (OCR) began an enforcement initiative in 2019.

First enforced in the United States on September 1, 2023.

Goal:

To give individuals greater control over their own health information. This initiative:

  • Ensures individuals the right to access their own medical records and to receive copies of those records in a timely manner, without undue delay or cost.
  • Provides individuals the right to request access to their health information held by covered entities, such as healthcare providers, health plans, and healthcare clearinghouses.
    • These entities must provide individuals with their requested information in the format and manner requested by the individual if it is readily producible in that format. This information can include medical and billing records, as well as other health information such as test results and imaging reports.

The goal of the Information Blocking Act, also known as the 21st Century Cures Act, is:

  • To improve the interoperability of electronic health records (EHRs) and other health information technology (HIT) systems in the United States.
  • Aims to promote the secure and efficient sharing of health information among healthcare providers, patients, and other stakeholders in the healthcare system.
  • Prohibits healthcare providers, health IT developers, and health information exchanges from engaging in practices that prevent or discourage the access, exchange, or use of electronic health information. This includes actions such as charging excessive fees for access to health information, creating technical barriers to the sharing of health information, and imposing unreasonable delays on the release of health information.

When must records be provided:

Covered entities, such as healthcare providers and health plans, are generally required to provide patients with access to their protected health information (PHI) upon request, unless an exception applies.

Specifically, a covered entity must provide access to PHI within 30 days of receiving a request from the individual, unless the covered entity provides a written explanation of the delay and the reason for the delay and extends the time-period by an additional 30 days.

Under the information blocking rule, EHI must be made accessible to individuals, their personal representatives, and other authorized parties, without unreasonable delay and in the manner requested by the individual, except in certain limited circumstances. These circumstances are listed below in the following chart.

It's important to note that a healthcare provider must provide a clear explanation for any limitations on access to EHI and must make a good faith effort to provide access to as much EHI as possible.

Healthcare providers are also required to make available any information blocking policies or procedures that they have in place, and to provide patients with information on how to file a complaint if they believe that their access to EHI has been improperly limited or blocked.

What information is subject to?

Under HIPAA, individuals have the right to access and obtain a copy of their protected health information (PHI) that is maintained by covered entities, such as healthcare providers and health plans. PHI is broadly defined as any information, including demographic information, that:

  1. Relates to the individual's past, present, or future physical or mental health or condition;
  2. Relates to the provision of healthcare to the individual; or
  3. Identifies the individual or could reasonably be used to identify the individual.

Some examples of PHI that are subject to the right of access include:

  • Medical and clinical records, including diagnoses, test results, and treatment plans;
  • Billing and insurance information;
  • Prescription and medication records;
  • Immunization records;
  • Lab reports;
  • Radiology images;
  • Health insurance enrollment and coverage information; and
  • Personal demographic information, such as name, address, and social security number, if it is included in the individual's health record.

Under the information blocking rule, electronic health information (EHI) is subject to the right of access and exchange. EHI is defined as:

  • Electronic protected health information (ePHI) that is created, stored, transmitted, or received by a covered entity or business associate that is subject to HIPAA.

Some examples of EHI that are subject to the information blocking rule include:

  1. Clinical notes, including progress notes and operative notes;
  2. Diagnostic imaging, including X-rays, MRIs, and CT scans;
  3. Laboratory test results;
  4. Pathology reports;
  5. Medication lists and prescription histories;
  6. Immunization records;
  7. Vital signs and other clinical measurements;
  8. Patient demographic information, such as name, address, and social security number, if it is included in the EHI.

Penalties?

YES

The right of access initiative is enforced by the Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS). OCR can investigate complaints of noncompliance and may take enforcement actions against covered entities that violate the right of access requirements.

  • If OCR determines that a covered entity has violated the right of access requirements, the covered entity may be subject to civil monetary penalties, which can range from $100 to $50,000 per violation, depending on the severity of the violation.
  • The maximum annual penalty for all violations of an identical requirement or prohibition is $1.5 million.

In addition to civil monetary penalties, OCR may require the covered entity to develop a corrective action plan and to monitor the covered entity's compliance.

It's important to note that individuals also have the right to file a complaint with OCR if they believe that a covered entity has violated their right of access. OCR may investigate complaints and take enforcement actions as appropriate.

YES

There are penalties for violating the information blocking rule which is enforced by the Office of the National Coordinator for Health Information Technology (ONC) and the Department of Health and Human Services (HHS). Covered entities that engage in information blocking practices may be subject to enforcement actions, which can include:

  1. Civil monetary penalties: The HHS may impose civil monetary penalties of up to $1 million per violation for each instance of information blocking.
  2. The maximum annual penalty for all violations of an identical requirement or prohibition is $5 million.
  3. Disincentives for health information exchange: The HHS may also take steps to limit or restrict a covered entity's participation in certain health information exchange programs or to exclude the entity from certain government healthcare programs.
  4. Publication of violators: The ONC may publish the names of covered entities that have engaged in information blocking practices, which can harm the entity's reputation and public image.

In Summary 


It is important to respect patient access to information while protecting confidential information. This can be a daunting task for any size organization. After reviewing the information above and you still have questions, consider additional training in HIPAA and release of information.

Additional and important aspects of this topic not covered in this article is information excluded from both Right of Access and Information Blocking rules, when the request may be denied, to whom the information can be released and allowable (and unallowable) fees a patient can be charged. These topics will be covered in Part 2.

We also encourage consulting with your malpractice Risk Attorney. Your insurance company WANTS your organization to seek advice BEFORE an incident or investigation from a complaint occurs. If consulting with your malpractice company isn’t an option, it is highly advised to seek legal advice from a HIPAA privacy expert.

Copyright © 2023 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More