Compliance in Healthcare
Corporate Compliance, HIPAA

Privacy, Interoperability, and Trust in 2026

HIPAA Notice of Privacy Practices, 42 CFR Part 2, and USCDI v3 Compliance Risk 

Written by Dr. Stacey Atkins, PhD, MSW, LMSW, CPC, CIGE 

Healthcare organizations entering 2026 face a convergence of heightened privacy enforcement and expanded interoperability obligations. Two major regulatory developments drive this shift:

  1. The February 16, 2026 deadline to update HIPAA Notices of Privacy Practices (NPPs) to reflect revised 42 CFR Part 2 requirements, and
  2. The January 1, 2026 mandate to comply with United States Core Data for Interoperability (USCDI) Version 3 standards. 

This article provides an executive and auditor-facing analysis of these intersecting requirements, examining enforcement risk, patient rights, data governance challenges, and operational compliance implications. Practical guidance is offered to support governing boards, executive leaders, and compliance professionals in aligning privacy, interoperability, and health IT strategies.

The information in this article is not intended as legal or consulting advice and should be used for educational purposes only.

Introduction

The healthcare compliance environment in 2026 reflects a deliberate regulatory emphasis on transparency, data access, and accountability balanced against strengthened privacy protections. Federal agencies have clearly signaled that interoperability and privacy are no longer siloed compliance domains but interdependent elements of patient trust and regulatory oversight.

As highlighted in the January 2026 Compliance Newsletter published by the American Institute of Healthcare Compliance, healthcare organizations must simultaneously address expanded HIPAA privacy obligations and mandatory interoperability standards. This convergence significantly elevates compliance risk for entities that fail to align governance, policy, and operational workflows.

HIPAA Notice of Privacy Practices: February 16, 2026 Enforcement Deadline

February 16, 2026 marks the enforcement deadline for updates to HIPAA Notices of Privacy Practices required under the February 2024 Final Rule modifying 42 CFR Part 2. These revisions align substance use disorder (SUD) privacy protections with HIPAA and subject violations to civil monetary penalties and corrective action plans.

Historically, Part 2 violations carried limited enforcement risk. Under the revised framework, failure to update NPPs or operationalize revised patient rights may be interpreted as systemic noncompliance.

Expanded Patient Rights Under Revised 42 CFR Part 2

The revised Part 2 framework introduces significant patient rights that must be clearly disclosed through updated NPPs. These include single-consent authorization for future disclosures, enhanced rights to request privacy protections, and explicit restrictions on the use of SUD records in legal proceedings. Compliance programs must ensure alignment across registration, consent management, EHR configuration, and workforce training to avoid inadvertent violations.

USCDI Version 3: Mandatory Interoperability in 2026

Already in effect, as of January 1, 2026, compliance with USCDI Version 3 became mandatory for certified EHR systems and health IT vendors.

This requirement expands the scope of standardized data exchange to include social determinants of health, health equity data, and expanded insurance information.  Failure to meet USCDI v3 standards may expose organizations to information blocking allegations, certification issues, and contractual noncompliance with payers and federal programs.

Intersection of Privacy and Interoperability

The intersection of privacy and interoperability represents one of the most complex compliance challenges facing healthcare organizations in 2026. Federal policy has deliberately accelerated health information exchange to improve care coordination, reduce administrative burden, and advance health equity. Simultaneously, regulators have strengthened patient privacy rights—particularly for sensitive data such as substance use disorder (SUD) information—recognizing that trust is foundational to patient engagement and data accuracy.

USCDI Version 3 expands the categories of data eligible for exchange, including social determinants of health, health equity stratifiers, and expanded clinical and insurance data elements. While these data sets are critical to population health and value-based care initiatives, they also increase the likelihood of inappropriate disclosure if consent and access controls are not precisely aligned. The revised 42 CFR Part 2 framework reinforces that interoperability does not negate privacy obligations; rather, it heightens the expectation that organizations implement granular, enforceable safeguards.

A Dual-Risk Environment - From an enforcement perspective, regulators have made clear that information blocking prohibitions do not override privacy protections. Organizations that indiscriminately share data without honoring consent restrictions—particularly for Part 2-protected information—may face simultaneous exposure under HIPAA, Part 2, and information blocking regulations. This creates a dual-risk environment in which both over-restriction and over-disclosure may trigger regulatory scrutiny.

To navigate this tension, healthcare organizations must adopt a privacy-by-design approach to interoperability, ensuring that consent management, data segmentation, and role-based access controls are embedded into health IT workflows. Interoperability initiatives that proceed without explicit privacy governance risk eroding patient trust and undermining regulatory compliance objectives.

Ensuring Trust Through Privacy-Centered Interoperability

Trust is not an abstract concept in healthcare compliance; it is an operational outcome shaped by transparency, consistency, and respect for patient autonomy. As data exchange expands, patients are increasingly aware of how their information is used, shared, and protected.

Failure to demonstrate meaningful privacy protections may result in patients withholding information, declining treatment, or disengaging from care altogether—particularly in behavioral health and substance use contexts.

Practical, trust-building strategies include:

Transparent and Understandable NPPs - Updated Notices of Privacy Practices should move beyond regulatory minimums to clearly explain how sensitive information is shared through interoperable systems, what choices patients have, and how consent is honored across care settings. Plain-language explanations reinforce trust and reduce confusion at registration and intake.

Consent Integrity Across Systems - Organizations should validate that consent decisions captured at intake are consistently enforced across EHRs, health information exchanges, and third-party platforms. Inconsistent application of consent restrictions is a frequent source of patient complaints and audit findings.

Data Minimization and Purpose Limitation - Even when data sharing is permitted, organizations should limit disclosures to the minimum necessary to achieve clinical or operational objectives. Demonstrating restraint reinforces patient confidence that interoperability serves care—not convenience.

Patient Access and Engagement - Providing patients timely access to their own records, including disclosures and consent history, supports transparency and aligns with broader federal access initiatives. Patients who understand how their data moves through the system are more likely to trust it.

Workforce Accountability - Trust is undermined when staff lack clarity regarding privacy obligations. Targeted training that addresses real-world scenarios—such as responding to data requests involving SUD information—helps prevent inadvertent violations and reinforces organizational commitment to privacy.

These practices position privacy not as a barrier to interoperability, but as a prerequisite for sustainable data exchange.

Governance, Audit, and Enforcement Risk

Regulators increasingly evaluate privacy and interoperability compliance through a governance lens. Surveyors and auditors may assess leadership awareness of regulatory changes, oversight of data-sharing activities, and the effectiveness of training and monitoring programs.

Failure to demonstrate executive oversight may result in enforcement actions by OCR or CMS.

Operationalizing Compliance: Best Practices

To mitigate compliance risk, organizations should:

  • Update NPPs well in advance of enforcement deadlines;
  • Align consent workflows with interoperability requirements;
  • Validate EHR configurations; and
  • Conduct targeted workforce training.

Routine audits of data-sharing practices and consent management processes are critical to sustaining compliance.

Conclusion

The convergence of revised HIPAA privacy requirements strengthened 42 CFR Part 2 protections, and mandatory USCDI Version 3 interoperability standards reflects a broader regulatory recalibration of healthcare data governance. Federal agencies have signaled that access, transparency, and accountability must advance in parallel—not in competition. In this environment, privacy failures are no longer isolated compliance issues; they represent systemic governance risks with direct implications for patient trust, enforcement exposure, and organizational credibility.

Healthcare organizations entering 2026 must recognize that interoperability initiatives amplify privacy obligations rather than dilute them. Updated Notices of Privacy Practices, consent management workflows, and health IT configurations serve as visible indicators of organizational integrity. Regulators and auditors increasingly assess not only whether policies exist, but whether leadership understands how privacy and interoperability intersect operationally.

Organizations that proactively integrate privacy-by-design principles into interoperability strategies will be best positioned to navigate enforcement risk, avoid information blocking missteps, and sustain patient trust. This requires active governing body oversight, cross-functional collaboration between compliance, IT, legal, and clinical leaders, and continuous monitoring of evolving regulatory guidance.

Ultimately, trust is the currency of interoperable healthcare. Organizations that demonstrate respect for patient autonomy while advancing responsible data exchange will not only meet regulatory expectations but also strengthen care quality, engagement, and resilience in an increasingly data-driven healthcare system.

About the Author - Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • American Institute of Healthcare Compliance. (2026). January 2026 compliance newsletter. https://dev-main.aihc-assn.org
  • U.S. Department of Health and Human Services, Office for Civil Rights. (2024). Final rule modifying 42 CFR Part 2. https://www.hhs.gov/ocr
  • Centers for Medicare & Medicaid Services. (2025). United States Core Data for Interoperability (USCDI) Version 3. https://www.cms.gov

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved 

Read More
HIPAA Compliance
HIPAA

Part 3: The Pros and Cons of Interoperability Frameworks in Health Care

Written by: Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC and Dr. Tami M. Harris, DM, PMP, LSSBB 

Introduction 

Interoperability frameworks are the connective tissue of modern healthcare data exchange, defining how systems communicate, the structure of the data, and how information flows securely across organizations.

As healthcare organizations – including hospitals, payers, clinicians, and technology vendors – face significant challenges to deliver care in an environment dominated by fragmented data, siloed and competing systems, the push to standardize how information is exchanged has taken center stage. These frameworks offer a pathway toward a more connected healthcare ecosystem—one where patient medical records are transmitted securely, providers have timely access to essential information, and organizations can reduce the inefficiencies that drive patient care, increased costs, lost or duplication of data, and delays.

In the AIHC Part 1 Article on Interoperability: CMS Interoperability Framework Project: Should We Be Concerned?  A comprehensive overview dives into  the Problem with System Fragmentation in Healthcare and Security Concerns in the CMS Interoperability Framework Project (Part 1).

In the AIHC Part 2 Article: Interoperability and System Fragmentation in Healthcare, the contributing writers discuss Communication, Compliance, and Strategies for Successful Integration Interoperability and System Fragmentation in Healthcare (Part 2).

In this AIHC Part 3 Article, we will now walk the readers through the Pros and Cons of Interoperability Frameworks in Healthcare. As AI, Revenue Cycle Management (RCM) automation, payer auditing, and value-based care accelerate, these frameworks are rapidly becoming the backbone of national healthcare operations.

But like any key technology standard, these frameworks come with real advantages—and real trade-offs. Below is a practical, balanced breakdown that leaders should understand before deciding to adopt or move forward with how they will integrate these systems.

Pros & Cons - Let’s Start with the Pros

1. Exchange of Data Between Systems

Data Exchange interoperability frameworks, such as Health Level 7 (HL7), Fast Healthcare Interoperability Resources (FHIR), and Trusted Exchange Framework and Common Agreement (TEFCA), will help reduce fragmentation by providing a common language for AI-Powered Electronic Medical Record (EMR) systems, RCM platforms, and payer applications.

According to the Centers for Medicare & Medicaid Services (CMS), the Voluntary Interoperability Frameworks are designed to enhance manual back-and-forth, enable faster claims processing, reduce denials, and improve clinical decision-making.

Why it matters - Unconnected systems, duplicate documentation, and lost data cost hospitals millions of dollars every year. Current CMS estimates indicate that interoperability frameworks can shrink those losses by streamlining data exchange and minimizing manual errors. Integrating data into EHRs demonstrates the growing impact of interoperability frameworks on reducing fragmentation.

2. Stronger Clinical Quality and Patient Safety

With data flowing unimpeded, clinicians have a complete picture of labs, meds, allergies, imaging, and histories—regardless of where care was delivered. This improves the accuracy of care, reduces avoidable errors, and supports real-time decision-support tools.

A Forward-Thinking Angle - AI-enabled audits in Clinical Documentation Improvement (CDI) and RCM are most effective when built on interoperable data. Interoperability should be the prerequisite for advanced analytics and real-time clinical decision support.

3. Reduce Operational Waste and Administrative Burden

Implementing CMS Voluntary Frameworks, such as CMS 9115-f , automates and streamlines much of the documentation exchange, eliminating repetitive reconciliation, data entry, and faxing.

The CMS Interoperability and Patient Access Final Rule require payers to use FHIR-based APIs for data exchange, which has proven to reduce prior authorization response times and administrative costs for providers.

Impact - Minimize human touchpoints → fewer mistakes → shorter AR cycles → more cash collected faster.

4. Better Compliance with Federal Requirements

The goal is to minimize risk by leveraging the Assistant Secretary for Technology Policy and the Office of the National Coordinator for HealthIT’s (ASTP/ONC) Interoperability Frameworks, such as HL7, FHIR, CMS interoperability rules, and TEFCA, by aligning organizations with regulatory expectations for data access, patient API rights, and cross-network exchange.

TEFCA, launched in 2024, establishes a nationwide framework for secure health information exchange, connecting providers, payers, and public health agencies. Compliance with TEFCA and FHIR standards is now required for participation in federal programs and for avoiding penalties.

Bottom line - Staying compliant now avoids future penalties and positions organizations to participate in larger national data networks.

5. Fuel for AI, Predictive Analytics, and RCM Algorithms

AI models thrive on clean, structured, standardized data (Federal Register, Health Data).
Interoperability frameworks give organizations the quality inputs needed for:

  • Automated Claims Integrity Checks
  • Audit Ready Data Pipelines
  • Predictive RCM Drift Alerts
  • CDI optimization
  • Denials Prediction

The FDA and CMS are piloting FHIR-based submissions for real-world data, enabling advanced analytics and predictive modeling for population health and revenue cycle management.

Forward-Looking Reality - Organizations that implement interoperable data models today are better positioned to lead tomorrow’s AI-enhanced revenue cycle and clinical innovation.

The Cons

1. High Upfront Cost and Long Implementation Time

Implementing interoperability is not a simple upgrade. Many organizations underestimate the scale and cost, leading to project delays and budget overruns. Interoperability initiatives require:

  • API Integration
  • Data Mapping
  • Security Upgrades
  • Staff Training
  • Vendor coordination
  • Workflow Redesign

Truth - Interoperability is not a plug-and-play upgrade—it will be transformational.

2. Legacy System Limitations

Legacy systems often; lack support for modern APIs, contemporary data formats, or real-time exchange. These outdated platforms create bottlenecks, limit adoption, and increased maintenance costs.

Real-World Impact - Even if one part of the RCM process is modernized, the weakest legacy interface can undermine the entire process.

3. Cybersecurity Risks Rise with Connectivity

Expanding connectivity through APIs and cross-organizational networks increases the risk of cyber threats. The U.S. Department of Health & Human Services (HHS) emphasizes that interoperability must be paired with robust cybersecurity measures to protect sensitive health information.

Forward risk - AI-powered cyberattacks target health care's interconnected data ecosystems. Interoperability without hardened defenses is dangerous.

Organizations will need to ensure stronger access controls, encryption, and incident response plans are in place for threat prevention.

4. Vendor Resistance and Proprietary Barriers

Some vendors still rely on closed or proprietary systems to “lock in” clients, making interoperability expensive or technically challenging. This practice can significantly hinder the seamless exchange of health information across organizations.

The ONC has repeatedly identified proprietary interfaces and lack of standardized APIs as major obstacles to nationwide interoperability. Proprietary health IT systems continue to present significant challenges to data sharing. These systems often require organizations to invest in costly custom integrations, which can result in persistent information silos.

Result - Organizations can get stuck negotiating costly interface fees or dealing with partial data exchange, which not only increases operational expenses but also limits the ability to provide coordinated, high-quality care.

5. Variation in Standards and Inconsistent Adoption

Even with frameworks like FHIR (HL7 FHIR) or TEFCA (TEFCA Governance), vendor implement differently.  There are variations in:

  • API Maturity
  • Profiles
  • Optional Fields Versioning
  • Create Ongoing Friction

Reality - Interoperability is only as strong as the weakest implementation in the network. The ONC Interoperability Standards Advisory underscores the need for consistent implementation and highlights gaps in adoption across the industry.

Summary: A High-Level Strategic View

Interoperability frameworks are rapidly becoming the backbone of a modern, connected healthcare ecosystem, offering benefits that extend well beyond simple data exchange —yet their impact is far from one-dimensional. Throughout this three-part AIHC series, we have explored the real and persistent challenges of system fragmentation, the security vulnerabilities exposed by national initiatives such as the CMS Interoperability Framework Project, and the practical strategies organizations can use to navigate and overcome communication and compliance barriers.

In this Part 3 article, we explored the significant advantages and real trade-offs that interoperability frameworks bring. These standards promise faster access to patient information, improved care coordination, and greater operational efficiency.  At the same time, it is important to realize that these benefits of interoperability in healthcare require rigorous governance, robust security, disciplined integration planning, and adaptability to evolving federal and state requirements, including market pressures Understand Interoperability in Healthcare.

As AI in RCM automation, payer oversight, and value-based care continue to accelerate, interoperability will become increasingly critical. Operational leadership that succeeds will be those who embrace connectivity with strategic foresight—leveraging the advantages while proactively managing the associated risks. 

Interoperability should be viewed not just as a technology requirement; it should be considered the de facto strategy and standard that will shape how healthcare delivers value, safeguards patients, and competes in a data-driven future.

About the Authors

Corliss Collins, BSHIM, RHIT, CRCR, CCA, CAIMC, CAIP, CSM, CBCS, CPDC, is the Founder, Principal & Managing AI Consultant of P3 Quality, a Healthcare Tech Consulting Company. She is a Certified Artificial Intelligence Professional (CAIP) and a Certified Artificial Intelligence Medical Coder (CAIMC). In her current leadership role, she extracts and diagnoses core Drift in AI Medical Coding Models, thereby closing AI-Driven financial, quality, and compliance gaps. Corliss is also a published author of Artificial Intelligence, Rise, Survive, & Thrive In An AI-Powered World. She also serves on the AIHC Volunteer Education Committee.

Dr. Tami M. Harris, DM, PMP, LSSBB, is the Founder & Chief Operating Officer of H & H Consulting Group, Inc. With a doctorate in Management, she is recognized as a certified Lean Six Sigma Black Belt and Project Management Professional, reflecting a commitment to operational excellence and continuous improvement. In her current capacity as Portfolio Director for Middle and Back-office Revenue Cycle Management (RCM) AI Automation and Transformation, she leads strategic advisory initiatives, oversees practice leadership, and drives client engagement delivery to generate new value-streams through technology.

References:

  1. American Health Information Management Association. (2024). TEFCA Overview. AHIMA. https://www.ahima.org/
  2. Centers for Medicare & Medicaid Services (CMS). Interoperability and Patient Access Final Rule (CMS-9115-F). https://www.cms.gov/cms-9115-f
  3. Food and Drug Administration. (2025). Exploration of Health Level Seven Fast Healthcare Interoperability Resources for Use in Study Data Created From Real-World Data Sources for Submission to the Food and Drug Administration; Establishment of a Public Docket; Request for Comments. Federal Register, 90(77), 17067–17069. https://www.federalregister.gov/documents/2025/04/23/2025-06967/exploration-of-health-level-seven-fast-healthcare-interoperability-resources-for-use-in-study-data
  4. HL7 International. FHIR Overview. https://www.hl7.org/fhir/
  5. National Academy of Medicine. Proposing Interoperability Standards for Healthcare. https://www.federalregister.gov/algoritm-transparency
  6. Office of the National Coordinator for Health Information Technology (ONC). Interoperability Standards Advisory (ISA). https://www.healthit.gov/isa
  7. The Sequoia Project. TEFCA Framework and Common Agreement. https://sequoiaproject.org/tefca/
  8. Understand the four levels of Interoperability in Healthcare. www.wolterskluwer.com
  9. U.S. Department of Health & Human Services. (2024). Cybersecurity Program. https://www.hhs.gov/about/agencies/asa/ocio/cybersecurity/index.html

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 2: Interoperability and System Fragmentation in Healthcare

Communication, Compliance, and Strategies for Successful Integration Written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The healthcare industry continues to face significant fragmentation, as disparate systems and siloed data limit effective care coordination. Interoperability standards such as Fast Healthcare Interoperability Resources (FHIR) and regulatory requirements under the 21st Century Cures Act, HIPAA, and CMS interoperability mandates are reshaping the compliance landscape. Yet achieving interoperability is not only a technical challenge but also a communication and compliance imperative.

This article examines the compliance risks associated with fragmentation and explores communication strategies for healthcare leaders. Key areas include:

  1. educating internal teams on compliance-related adoption of FHIR standards;
  2. framing Health Information Exchanges (HIEs) and cloud-based platforms as compliance safeguards against information blocking and OCR investigations; and
  3. aligning staff expectations, training, and accountability during technology rollouts.

A compliance lens reinforces that interoperability is not optional—it is a regulatory obligation tied to patient rights, organizational risk management, and quality of care.

Introduction

Fragmentation in healthcare undermines not only care delivery but also compliance. When disparate systems fail to exchange data, organizations risk violating federal mandates related to patient access, privacy, and data sharing. The 21st Century Cures Act Final Rule requires organizations to provide patients with immediate electronic access to their records, while HIPAA’s Right of Access standard reinforces patients’ legal rights to their health information. Failure to comply may trigger Office for Civil Rights (OCR) investigations, penalties, or settlements (Office for Civil Rights [OCR], 2022).

Improved interoperability through standards like FHIR, Health Information Exchanges (HIEs), and cloud-based systems offers an opportunity to reduce compliance risk and strengthen organizational integrity. However, success depends on how effectively compliance leaders communicate changes, engage stakeholders, and align workflows with regulatory requirements.

The Compliance Risks of Fragmentation

System fragmentation is not merely an operational inconvenience—it directly impacts compliance.

Examples include:

  • HIPAA Violations: Incomplete or inaccessible patient records increase the likelihood of Privacy and Security Rule breaches.
  • Information Blocking: Under the ONC Cures Act Final Rule, organizations that delay or restrict information exchange risk penalties (ONC, 2020).
  • Claims and Billing Errors: Disconnected systems make it harder to validate documentation, increasing false claims liability.
  • Audit Vulnerability: Fragmented workflows create inconsistent documentation trails, raising red flags during audits.

From a compliance standpoint, breaking down silos is both a regulatory necessity and a risk management strategy.

Communicating FHIR Adoption Through a Compliance Lens

FHIR APIs are central to the ONC’s interoperability framework, enabling standardized, patient-directed data sharing. For compliance teams, communicating FHIR adoption requires balancing technical education with regulatory framing.

Compliance challenges:

  • Misunderstanding FHIR as a 'technology upgrade' instead of a compliance requirement.
  • Lack of clarity on how FHIR supports HIPAA Right of Access and ONC information blocking provisions.
  • Resistance from staff unfamiliar with regulatory consequences of noncompliance.

Communication strategies:

  • Regulatory Framing: Position FHIR adoption as a compliance mandate tied to federal law, not optional IT innovation.
  • Policy Alignment: Provide updated compliance policies showing how FHIR workflows safeguard patient rights.
  • Cross-Functional Briefings: Engage compliance, IT, and clinical teams together to prevent siloed communication.

By making compliance central to the conversation, staff understand that interoperability is not just about efficiency—it is about avoiding penalties and protecting patient trust.

Cloud-Based Platforms and HIEs: Compliance Safeguards, Not Just Technology

Cloud platforms and HIEs expand data access across organizational boundaries. From a compliance perspective, these tools mitigate risks of information blocking and improve adherence to patient access laws.

Compliance benefits:

  • Audit Readiness: Centralized data improves traceability for regulatory reviews.
  • HIPAA Safeguards: Cloud vendors increasingly offer compliance-certified environments with robust encryption and BAAs (business associate agreements).
  • Patient-Centered Compliance: HIEs reduce delays in record sharing, directly supporting Right of Access standards.

Communication priorities:

  • Stress that cloud and HIE adoption is not only about efficiency, but also about reducing exposure to OCR penalties.
  • Clarify shared accountability between providers, payers, and vendors for maintaining compliance safeguards.
  • Use compliance case studies (e.g., OCR enforcement actions) to illustrate the risks of fragmented systems.

Framing cloud and HIE adoption as compliance risk mitigation ensures leadership buy-in and reduces resistance to sharing data.

Managing Staff Expectations and Training During Rollouts

System-wide rollouts require a compliance-centered training approach. Staff must not only learn technical workflows but also understand the compliance stakes tied to their responsibilities.

Compliance-driven communication strategies include:

  1. Mandatory Training: Incorporating interoperability requirements into annual compliance training to emphasize regulatory obligations.
  2. Expectation Management: Clearly communicating that delays or barriers in sharing data could constitute information blocking.
  3. Super-User Networks: Assigning compliance-trained 'champions' to monitor adherence to workflows and escalate issues.
  4. Policy Updates: Linking rollout communication to policy changes in HIPAA access, data governance, and security protocols.

When staff view interoperability as part of their compliance role—not just an IT task—they are more likely to integrate it into daily practice.

Discussion - The intersection of interoperability and compliance is where organizational risk management, patient rights, and clinical efficiency converge. Communication breakdowns perpetuate system fragmentation, which can escalate into compliance violations. Conversely, transparent communication strategies—emphasizing regulation, patient safety, and organizational accountability—align stakeholders and promote sustainable interoperability.

Compliance leaders serve as translators between regulators, IT professionals, and clinicians. Their role is not only to enforce standards but also to ensure that staff understand why interoperability matters: to safeguard patients, maintain regulatory standing, and strengthen organizational trust.

Conclusion

Fragmentation is more than a technological problem; it is a compliance vulnerability. Interoperability initiatives such as FHIR adoption, HIE participation, and cloud migration reduce fragmentation but require strong communication strategies to succeed. From a compliance lens, effective communication ensures that staff recognize interoperability as a regulatory requirement, not an optional upgrade.

Ultimately, interoperability is a cornerstone of healthcare compliance and patient rights. By embedding compliance in communication, training, and strategy, organizations can break down data silos, mitigate risk, and deliver safer, more coordinated care.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

  • Adler-Milstein, J., Holmgren, A. J., & Kralovic, P. (2021). The impact of electronic health record interoperability on care quality and patient safety. Health Affairs, 40(9), 1427–1435. https://doi.org/10.1377/hlthaff.2021.00234
  • Cresswell, K., & Sheikh, A. (2017). Organizational issues in the implementation and adoption of health information technology innovations: An interpretive review. International Journal of Medical Informatics, 100, 63–76. https://doi.org/10.1016/j.ijmedinf.2017.01.001
  • Lin, S. C., Jha, A. K., & Adler-Milstein, J. (2020). Electronic health records and health care quality: Current evidence and future directions. Annual Review of Medicine, 71, 35–50. https://doi.org/10.1146/annurev-med-052218-020647
  • Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899–908. https://doi.org/10.1093/jamia/ocv189
  • Office for Civil Rights (OCR). (2022). Enforcement highlights: Right of Access Initiative. U.S. Department of Health and Human Services. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/data/enforcement-highlights/index.html
  • Office of the National Coordinator for Health Information Technology (ONC). (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program final rule. Federal Register, 85(85), 25642–25961.
  • Vest, J. R., Ancker, J. S., & Bates, D. W. (2019). Health information exchange: Persistent challenges and new strategies. Journal of the American Medical Informatics Association, 26(4), 325–331. https://doi.org/10.1093/jamia/ocy135

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

Part 1: CMS Interoperability Framework Project: Should We Be Concerned?

Part 1: The Problem with System Fragmentation in Healthcare and Security Concerns 

Co-authored by Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC and Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS 


The CMS Interoperability Framework is a call to action for health data networks that want to make what should already work actually work—by voluntarily meeting the CMS Interoperability Framework criteria to be designated as a CMS-Aligned Network.

This is a voluntary blueprint for modern health data exchange that puts patients and providers first. It is open, standards-based, and market-friendly so that the industry can stop theoretical debates and start delivering real results. CMS is offering shared infrastructure and clearly defined criteria for 2026.

The CMS Interoperability Framework doesn't mean centralizing all medical record data in a single location in the US. CMS is aligning networks to allow different types of health data sources, including health information networks, exchanges and other health technology platforms, to align with CMS goals for interoperability. The focus is on making it easier for different healthcare systems and applications to share and exchange medical information securely and efficiently. Here's what that means in simpler terms:

Think of it like different computer programs speaking the same language.

Currently, many healthcare systems use different formats and ways of organizing data. The CMS Interoperability Framework aims to establish common standards, especially using FHIR APIs, so that systems can understand and exchange information smoothly, regardless of where the data is stored.

  • A FHIR (Fast Healthcare Interoperability Resources) API is a standardized interface for exchanging health information between different healthcare systems using modern, web-based principles.
  • It acts as a shared "menu" that allows different software applications and platforms to "speak the same language," enabling them to request, retrieve, and share data like patient records, lab results, and other administrative or clinical information in a consistent format (JSON or XML).

It empowers patients and providers with access to medical information.

  • The framework promotes patient access to their health records through apps of their choice and makes it easier for providers to access the full patient history at the point of care.

It's a roadmap and a call to action, not a central database.

  • CMS is encouraging healthcare organizations, including networks, EHR systems, providers, and payers, to adopt common standards for data exchange, improving overall data sharing across the fragmented healthcare landscape.

It emphasizes data availability and standards, but it doesn't create a national repository.

  • The focus is on making it easier to share data between existing systems and promoting the use of standards like FHIR APIs and USCDI (United States Core Data for Interoperability).

So, instead of physically pulling all medical records into one place, the CMS Interoperability Framework is about creating a more connected system that allows patient data to flow securely between different locations and organizations, ultimately benefiting patient care and efficiency.

CMS Interoperability and the Risks of Sharing Patient Data with Big Tech Companies

The Centers for Medicare & Medicaid Services (CMS) has launched an ambitious Health Technology Ecosystem initiative aimed at creating a public-private partnership that facilitates seamless data exchange among patients, providers, and payers. As stated on the CMS website, Making Health Tech Great Again is a bold step toward modernizing our digital health ecosystem.

While details and operational aspects are still being finalized, partnerships have been publicly announced with major tech companies like Amazon, Apple, Google, Microsoft AI, OpenAI, and others, which signal a transformative shift in how healthcare data is accessed and shared. On July 30, 2025 CMS.gov posted a Press Release White House, Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem which states “More than 60 companies pledged to work collaboratively to deliver results for the American people in the first quarter of 2026. Twenty-one networks pledged to meet the CMS Interoperability Framework criteria to become CMS Aligned Networks. Eleven health systems or providers committed to participate and support patient use, and seven EHRs committed to facilitate data exchange and help “kill the clipboard.” At the same time, these collaborations also raise critical questions about data privacy, security, and governance.

Should we be concerned?

The CMS Health Tech Ecosystem initiative is overseen by the CMS Senior Advisor for Technology and supported by senior officials at the Department of Health and Human Services (HHS). Its mission is to promote a secure patient-centered digital healthcare system that would allow for ease of distribution, exchange, portability, and use of electronic health information. Fundamentally, this initiative seeks to improve patient access and enhance the efficiency of the healthcare industry. Its aim is to connect healthcare data sets that are currently siloed across disparate systems so that patients, providers, and healthcare payers will have reliable access to electronic medical records through a voluntary alignment. However, what lessons can be learned from the Change Healthcare breach?

Security Risks and Lessons Learned from the Change Healthcare Breach

A significant reminder of the vulnerabilities in extensive healthcare data systems is the February 2024 ransomware attack on Change Healthcare. Threat actors exploited the business associate’s lack of multifactor authentication, gaining unauthorized remote access via stolen credentials. Insufficient third-party vendor security postures create both upstream and downstream vulnerabilities across the healthcare ecosystem.

In the Change Healthcare breach, inadequate security controls resulted in widespread disruptions, including delays in medical treatments and prescriptions, stalled claims processing and reimbursements, and fragmented financial and operational access and delivery. These events underscore the need for comprehensive data governance, continuous security monitoring, and resilient infrastructure to safeguard protected health information (PHI). Most importantly, the lessons learned highlight the criticality of data confidentiality, integrity, and availability to ensure trust and continuity in patient care.

Along those lines, it is meaningful to act as informed advocates and to engage in mission-aligned questions, such as:

  • What minimum security standards must CMS’s third-party vendors and data brokers meet to safeguard data protection?
  • How is patient transparency ensured, and how is informed consent managed across diverse platforms?
  • Who holds accountability for data misuse or breaches, and what oversight mechanisms are in place to ensure compliance?

Conclusion

CMS's initiative for a more connected and patient-centered healthcare system offers significant benefits. But the public/private voluntary alignment must be grounded in data governance, responsible management of sensitive information, and a foundation of trust, transparency, and robust security—particularly in an innovative landscape shaped by public/private partnerships.

Please watch for Part 2: Interoperability and System Fragmentation in Healthcare: Communication, Compliance, and Strategies for Successful Integration, written by Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE.

About the Authors

Lorianne Maria Sainsbury-Wong, Esq., CISSP, CIPP/US, CHPC, is a member of the AIHC Volunteer Education Committee. Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS, is the Chief Executive Officer at the American Institute of Healthcare Compliance.

References

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More