Artificial Intelligence in Healthcare
Artificial Intelligence

Part 3:  AI & Risk to Empathy, Compassion and Trust in Healthcare

Impact of Artificial Intelligence (AI) on Patient-Centered Care


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023 and Part 2 – Who Regulates Healthcare AI?.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest published by AIHC.  The COVID pandemic has proven that patients like telehealth and means other than face-to-face encounters for routine health needs.  But can AI replace the empathy, compassion and trust instilled during a personal encounter with a health care professional?  This article explores recent research on the topic of AI and patient-centered outcomes research.


As AI is integrated into patient care and medical coding, billing and accounts receivable management, will we risk the human connection of empathy and compassion which builds trust in the physician-patient relationship?  I embarked on a short research project to explore this topic and share my findings with AIHC members and affiliates.


Empathy, compassion and trust are fundamental values of a patient-centered, relational model of health care.  As Artificial Intelligence (AI) is advancing the delivery of health care and improving the diagnosis and treatment of our patients, is this promising technology providing greater efficiency and more free time for health-care professionals to focus on the human side of care, including fostering trust relationships and engaging with patients with empathy and compassion?  Or is it freeing time to see more patients to increase the revenue stream?


A June 2023 abstract was posted to the National Institutes of Health (NIH) National Library of Medicine, entitled “Artificial Intelligence in Health: Enhancing a Return to Patient-Centered Communication.”  The authors emphasize concerns around AI in the delivery of health care; concerns related to ethics, privacy, data representation and the potential of eliminating physicians. 


The article states “However, AI cannot replicate a physician's knowledge and understanding of the patient as a person and the conditions in which he or she lives. Therefore, provider-patient communication will be paramount in providing safe and effective health care.”


In April 2023, the NIH posted “The impact of artificial intelligence on the person-centered, doctor-patient relationship: some problems and solutions”.  The authors agree AI is a solution to freeing up of time for doctors and facilitating person-centered doctor-patient relationships. However, “… there is very little concrete evidence on their impact on the doctor-patient relationship or on how to ensure that they are implemented in a way which is beneficial for person-centered care.” 

  • Patient-centered outcomes research (PCOR) compares the impact of two or more preventive, diagnostic, treatment, or health care delivery approaches on health outcomes, including those that are meaningful to patients. 

In light of the given the importance of empathy and compassion in the practice of person-centered care, they conducted a literature review and found that besides empathy and compassion, shared decision-making, and trust relationships emerged as key values.


Using AI tools can have a positive impact on person-centered doctor-patient relationships, according to the article, when:

  1. using AI tools in an assistive role; and
  2. adapting medical education.

“Artificial intelligence and the doctor-patient relationship expanding the paradigm of shared decision making” is a June 2023 NIH article emphasizes how AI based clinical decision support systems (CDSS) are rapidly becoming more prevalent in healthcare, playing an important role in diagnostic and treatment processes. For this reason, AI-based CDSS has an impact on the doctor-patient relationship, shaping their decisions with its suggestions.


The article poses that we may be on the verge of a paradigm shift, where the doctor-patient relationship is no longer a dual relationship, but a triad. AI implementations may instead foster the inappropriate paradigm of paternalism. Understanding how AI relates to doctors and influences doctor-patient communication is essential to promote more ethical medical practice. Both doctors' and patients' autonomy need to be considered in the light of AI.


A successful AI case related to patient-centered outcomes was located on HealthIT.gov, the website for the Office of the National Coordinator for Health Information Technology (ONC).   ONC completed a project in September 2021 “Training Data for Machine Learning to Enhance Patient-Centered Outcomes Research Data Infrastructure.” 


Through this project, ONC in partnership with NIH and the National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK), advanced the application of AI/ML in patient-centered outcomes research (PCOR) by generating high quality training datasets for a chronic kidney disease (CKD) use case – predicting mortality within the first 90 days of dialysis. This case was selected because mortality in the first 90 days of dialysis initiation in ESKD/ESRD patients remains notably high and included joint clinician-patient informed decision making. PCOR researchers can build off the foundational work completed through this project and extend the application of these methods to a wider array of use cases and advance the application of ML to enhance PCOR infrastructure.


Conclusion


Working in health care requires adapting to constant change as technology and software advancements force not only providers, but IT professionals and health care administrators to stay ahead of what is coming.


It is important to be fiscally responsible, however, do we want to live in a world where we can only speak to a machine regarding questions about our medical bills, or discuss our concerns regarding a treatment plan?  Where is the humanity in that?


We must move forward with integrating AI into our lives.  But, moving forward, it is important to re-evaluate whether and how empathy, compassion and trust could be incorporated and practiced within a health-care system where artificial intelligence is increasingly used. Most importantly, society needs to re-examine what kind of health care it ought to promote.


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Artificial Intelligence in Healthcare
Artificial Intelligence

Part 2: Who Regulates Healthcare AI?

Artificial Intelligence & Regulatory Compliance


Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article follows Part 1 - Basics of Artificial Intelligence (AI) and Healthcare Compliance published by AIHC on June 6, 2023.  AI is advancing rapidly, so we encourage you to reference the new Artificial Intelligence article category for the latest articles.  As stated in Part 1, the Office of the National Coordinator for Health Information Technology (ONC) and the Agency for Healthcare Research and Quality (AHRQ), with support from the Robert Wood Johnson Foundation, turned to an independent group of scientists and academics to consider how AI might shape the future of public health, community health, and healthcare delivery.  The question remains, how will the use of AI be regulated for health care use?


Artificial Intelligence/Machine Learning has gained heightened attention globally.  Augmented Intelligence has been embraced as a concept by physician organizations to underscore that emerging AI systems are designed to aid humans in clinical decision-making, implementation and administration to scale healthcare, according to Act Online Key Terminology for AI in Health.


Although the United States is making progress in developing domestic AI regulation, including with the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the existing laws and regulations that apply to AI systems is still a work-in-progress.  The goals are to protect people from unsafe or ineffective systems. 


So, Who Regulates Healthcare AI?


What seems like a simple question is really a complex situation.  This article only scratches the surface of various regulatory agencies involved in the regulation of AI.  The Health & Human Services (HHS) response to OMB Memorandum 21-06 “Guidance for Regulation of Artificial Intelligence Applications” was drafted in November 2020 and is directed to the heads of all Executive Branch departments and agencies, including independent regulatory agencies.  Much has happened since then.


On April 25, 2023, the Federal Trade Commission (FTC), the Civil Rights Division of the U.S. Department of Justice (DOJ), the Consumer Financial Protection Bureau (CFPB), and the U.S. Equal Employment Opportunity Commission (EEOC) released a joint statement highlighting their commitment to "vigorously use [their] collective authorities to protect individuals" with respect to artificial intelligence and automated systems (AI), which have the potential to negatively impact civil rights, fair competition, consumer protection, and equal opportunity.


The joint statement from the DOJ, FTC, CFPB, and EEOC signifies a growing awareness and concern among federal agencies about the potential risks and challenges posed by AI and automated systems. As AI continues to become more integrated into all aspects of daily life, the importance of addressing potential biases, transparency issues, and flawed design becomes increasingly critical.


Federal Trade Commission (FTC) Raises Concerns


The FTC’s mission is to protect consumers and competition through preventing anticompetitive, deceptive and unfair business practices.  This is achieved through law enforcement, advocacy, and education without unduly burdening legitimate business activity.  The FTC Act’s prohibition on deceptive or unfair conduct can apply if you make, sell, or use a tool that is effectively designed to deceive – even if that’s not its intended or sole purpose. The FTC’s action should help protect healthcare organizations by limiting deceptive or exaggerated promises of what a medical device or AI software can actually do.  It’s not uncommon for advertisers to say that some new-fangled technology makes their product better – perhaps to justify a higher price or influence labor decisions.


On May 18, 2023, the FTC issued a warning that the increasing use of consumers’ biometric information and related technologies, including those powered by machine learning, raises significant consumer privacy and data security concerns and the potential for bias and discrimination. Biometric information refers to data that depict or describe physical, biological, or behavioral traits, characteristics, or measurements of or relating to an identified or identifiable person’s body.


The Federal Drug Administration & AI


The Food & Drug Administration (FDA) released a discussion paper in 2019 and then an action plan on January 21, 2021 regarding Artificial Intelligence and Machine Learning, or AI/ML.  This action plan describes a multi-pronged approach to advance the Agency’s oversight of AI/ML-based medical software.  Then, in April 2023, the FDA is publishing a draft guidance, "Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence/Machine Learning (AI/ML)-Enabled Device Software Functions."

  • This draft guidance proposes a science-based approach to ensuring that AI/ML-enabled devices can be safely, effectively, and rapidly modified, updated, and improved in response to new data.

The approach the FDA is proposing in this draft guidance would put safe and effective advancements in the hands of health care providers and users faster, increasing the pace of medical device innovation in the United States and enabling more personalized medicine.

  • This means, for example, that diagnostic devices could be built to adapt to the data and needs of individual health care facilities and that therapeutic devices could be built to learn and adapt to deliver treatments according to individual users' particular characteristics and needs.

National Institute of Standards and Technology (NIST) AI Risk Management Framework


Released on January 26, 2023, NIST’s AI Risk Management Framework or “AI RMF” which is intended to be used voluntarily to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.  The Framework was developed through a consensus-driven, open, transparent, and collaborative process with the intention to build on, align with, and support AI risk management efforts by others.


Recently NIST launched the Trustworthy and Responsible AI Resource Center (AIRC), which will facilitate implementation of, and international alignment with, the AI RMF.  We recommend watching the introduction video:  https://www.nist.gov/video/introduction-nist-ai-risk-management-framework-ai-rmf-10-explainer-video


For healthcare HIPAA covered entities, NIST is likely a familiar organization to you.  NIST published prior documents related to AI.  The initial draft of the AI RMF was published March 17, 2022 and a second draft on August 18, 2022.


The Health Insurance Portability and Accountability Act (HIPAA)

Public Law 104-191


The Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules (45 C.F.R. Parts 160 and 164, Subparts A, C, and E). One of the ways that OCR carries out this responsibility is to investigate complaints.  As health care organizations evolve with the use of AI, there is increased potential for cyber criminals to exploit vulnerabilities.


At the present, there are two exclusions existing in the HIPAA Privacy Rule that allow Covered Entities to share Protected Health Information (PHI) with device vendors and other organizations without the authorization of the individual(s) to whom the PHI relates. The two exclusions can be found in 45 CFR §164.512(b)(1) and 45 CFR §164.512(i)(1). Respectively, they relate to:

  • Disclosures to vendors regulated by the Federal Drug Administration are permitted by the Privacy Rule for the “purpose of activities related to the quality, safety or effectiveness of such FDA-regulated product or activity”.   The FDA regulates the sale of all medical device products, including personal health devices that transmit data to AI-driven healthcare solutions as described above.
  • PHI can also be disclosed without authorization for research purposes without being de-identified if the disclosure is approved by an Institutional Review Board or Privacy Board. In such circumstances, the disclosed PHI must remain in the possession of the Covered Entity and the disclosure(s) can only be for the purpose of preparatory research (i.e., programming a “Supervised Learning Algorithm”).


Conclusion


Simply stated, a shift to AI calls for new skills.  It warrants increased knowledge of HIPAA privacy, security and anticipating other legal issues surrounding it’s use in healthcare.


Needless to say, it is important to maintain a robust HIPAA program and utilize information from the National Institute of Standards and Technology (NIST) AI Risk Management Framework as mentioned above.


In the context of HIPAA, healthcare data, and AI technologies, AI developers and vendors should consider that HIPAA only provides a federal floor of privacy and security standards. Often, other state and federal laws can apply that pre-empt HIPAA – particularly with regard to healthcare adjacent data – or apply to more organizations than Covered Entities and Business Associates.  Also, many Managed Service Providers (MSP) companies providing services to healthcare organizations should be aware of AI applications and security vulnerabilities.


If your organization plans or is using AI for medical diagnostics, reference the annual joint publication by the U.S. Government Accountability Office (GAO) and the National Academy of Medicine published each September entitled “Technology Assessment – Artificial Intelligence in Health Care – Benefits and Challenges of Machine Learning Technologies for Medical Diagnostics”.   A new publication is posted each year: https://www.gao.gov/products/gao-22-104629


AIHC will continue to post articles related to artificial intelligence with regards to healthcare compliance.  Click Here for additional articles on various HIPAA topics.  Click Here for articles relating to Artificial Intelligence. Visit the AIHC Certifications page with online compliance learning opportunities.

Read More
Telehealth
HIPAA, Telehealth

Audio-Video Telehealth, Mobile Device Management & You

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS


This article addresses how to track telehealth policies while addressing HIPAA compliance and mobile device management as the United States enters into a post-pandemic era. The information is an overview and should not be used as legal or consulting advice. Health care providers need to look toward long-term telehealth policies, ensure compliance and realize there is remaining work to be done. 


Scroll to the end of this article for “Basic Telehealth Terminology” if you are new to telehealth or if you are a mobile device app developer!


Most Providers Utilize Audio-Only Telehealth


More than two-thirds of providers utilizing telehealth use audio-only, according to a recent Telehealth Survey conducted November 2021 through December 2021 by the American Medical Association (AMA). According to this survey, 85% of physician respondents indicate they currently use telehealth. Those reporting a decrease in use since first offering it, now indicate doing a mix of in-person and virtual care. Of physician’s using telehealth, the trend indicates 93% are conducting live, interactive video visits with patients and 69% are doing audio-only visits.  


Considering this survey and other reports on audio-video services, concerns seem to focus on potential overutilization, equity and quality of care. 


A concern expressed to AIHC, by our Compliance and HIPAA Officer members, surrounds mobile devices used by providers and practice managers and the organization’s responsibility to comply with applicable rules, regulations and mobile device policies.


So, how do policies apply? 

 

If your providers use a mobile device to access an organization’s internal network or system, the owner of that network or system’s policies and procedures apply to your use of the mobile device to gain such access. It is your organization’s responsibility to understand and follow the organization’s policies and procedures.


If an organization allows providers and professionals to use mobile devices for work, the organization should have reasonable and appropriate mobile device policies and procedures. The policies and procedures should describe any configuration requirements for mobile devices used by providers and professionals for work. It is your responsibility to understand and follow your organization’s mobile device policies and procedures. But, what about using personally owned mobile devices for work?

  • "Bring Your Own Device" or BYOD refers to using a personally owned mobile device for work. Providers should be reminded to let their organization know when they want to use a personally owned mobile device. Many organizations have centralized security management to make sure mobile devices accessing their internal networks or resources are compliant with their security policies. Centralized security management includes:

o Configuration requirements, such as installing remote disabling on all mobile devices; and


o Management practices, such as setting policy for individual users or a class of users on specific mobile devices.


It is the provider’s responsibility to understand and follow the organization’s mobile device policies and procedures. Registering the provider’s mobile device with the organization allows the organization to control who has access to its network or system and will keep unauthorized persons from accessing its network or systems.

  • Registering these mobile devices with your organization may also help the organization or law enforcement find your mobile device if it is lost or stolen. Providers should be directed to contact their organization’s Privacy Officer or Security Officer to register their mobile device.

Utilizing Step 4 from ONC’s 5-Step Process to Manage Mobile Devices Used by Health Care Providers & Professionals, the list of questions below is a way to take inventory of potential safeguards needed to address risk areas.


Mobile Device Management


 If your organization allows the use of mobile devices, what should the organization do about managing the use of mobile devices?


   o Has the organization identified all the mobile devices that are being used in the organization? How is the organization keeping track of them?


   o Has the organization assigned responsibility to check all mobile devices used for remote access, to find out if selected security/configuration settings are enabled?


   o Should there be a regular review and audit of the mobile devices? 


Misuse of Mobile Devices


 Does the organization have written procedures for addressing misuse of mobile devices?


   o If so, what are the consequences when a mobile device is misused and the incident poses risk of a data breach?


Should the Organization Allow BYOD?


 Is this a policy already in place, where providers are using their own devices?


   o Should the organization let providers and professionals use their personally owned mobile devices within the organization?


 Should providers and professionals be able to connect to the organization’s internal network or system with their personally owned mobile devices, either remotely or on site?


Restrictions on Mobile Device Use


 Does the organization restrict how providers and professionals can use mobile devices?


   o Can providers and professionals use mobile devices to access internal networks or systems, such as an EHR?


   o Are providers and professionals restricted from using mobile devices when they are away from the organization?


   o Can providers and professionals take their mobile devices home?


   o Should the organization allow texting or emailing of health information?


      Is there encryption allowing compliant texting and emailing from the mobile device?


Security/Configuration Settings for Mobile Devices


 Will the organization institute standard configuration and technical controls on all mobile devices used to access internal networks or systems, such as an EHR?


   o If so, is the organization's current mobile device configuration document, including connections to other systems/applications, inside and outside of the firewall.


Information Storage on Mobile Devices


 Are there restrictions on the type of information providers and professionals can store on mobile devices?


   o If so, where and for how long should the data be stored?


 Are providers and professionals allowed to download mobile applications to mobile devices? If so, what type(s) of applications are approved?


Recovery/Deactivation of Mobile Devices


 Does the organization have procedures to wipe or disable a mobile device that is lost or stolen?


 Does the organization have standard procedures to recover mobile devices from providers and professionals when their employment or association with the organization ends?


Mobile Device Training


Training is always a challenge, but if your organization cannot achieve effective training and compliance, you may need to reconsider how telehealth is delivered to your patient population.


 How is the organization training its workforce (management, doctors, nurses, and staff) on policies and procedures?


 How does the organization hold its workforce (management, doctors, nurses, and staff) accountable for non-compliance? 


What Additional Information Should I Know for Compliance?


Covered entities must comply with HIPAA Privacy and Security Rules to protect and secure health information, even when using mobile devices as described above. Taking it a step further, health care leaders are responsible to ensure that mobile device procedures and policies have been developed and properly implemented to protect the health information patients entrust to you.


Make Tracking Audio-Only Policy Easy


A great resource is utilizing the National Telehealth Policy Resource Center called “CCHP,” short for Center for Connected Health Policy. CCHP has been tracking audio-only policies across the country and offers access to state audio-only policies via CCHP’s Policy Finder Tool.


As AIHC advises, another resource is legal advice through your malpractice insurance company. At no additional charge, a risk attorney can be made available to help review which policies impact your type of practice and organization.


Free HIPAA Compliance Resources


Another reliable resource is found at HealthIT.gov, the official website of the Office of the National Coordinator for Health Information Technology, otherwise known as “ONC.” ONC offers basic guidance in these five steps 1) Decide; 2) Assess; 3) Identify; 4) Develop, Document and Implement; and 5) Train entitled “five steps organizations can take to manage mobile devices used by health care providers and professionals.”


Does Your Organization Have a Trained (Certified) HIPAA Privacy/Security Officer?


Your HIPAA Compliance Officer can serve as the best resource to help your organization navigate the telehealth and mobile device compliance issues facing your providers today. AIHC offers an online course covering both privacy and security with the option of certification (proctored and administered online).  The cost of certification is covered in the tuition price. Learn more.


It is highly recommended that mobile health app developers and Managed Service Providers (MSPs) have an in-house HIPAA Compliance Officer contributing input to ensure technology is compliant.


Are You a Mobile Health App Developer?


Integrating protections into your technology to create HIPAA compliant products is necessary for your company to succeed. Health care providers are subject to the HIPAA rules as covered entities to protect identifiable health information when it is created, received, maintained and/or transmitted. These protections are required under Federal and State Privacy, Security and Breach Notification Rules. A few basic resources to reference are:


The Office for Civil Rights (OCR) HIPAA website devotes a webpage under Special Topics entitled “Resources for Mobile Health Apps Developers.”


The Federal Trade Commission (FTC) offers a webpage entitled “Mobile Health Apps Interactive Tool” to help you locate federal laws to follow.


For Beginners - Basic Telehealth Concepts


Telehealth is also referred to as Telemedicine. It is the use of telecommunications technology to provide health care services to persons who are at some distance from the provider. This type of patient encounter involves a spectrum of technologies.


Coverage and payment for telehealth can include consultation, office visits, individual psychotherapy, pharmacologic management and other services delivered via an interactive audio and video telecommunications system.  

  • Providers are located at the distant site; and
  • Patients are located at the originating site.

Provider at the distant site - As stated above, providers are at the “distant site,” referring to where the provider is at time of service. The provider can communicate with the patient using an interactive audio and video telecommunication system that permits real-time communication with the beneficiary.


When telehealth is used, it is considered to be rendered at the physical location of the patient, and therefore a provider typically needs to be licensed in the patient’s state. During the COVID-19 public health emergency (PHE), many states waived this requirement or provided specific exceptions. Click Here for Cross-State Licensing information.


Medicaid programs often restrict the type of providers that can be reimbursed when delivering services via telehealth. During the COVID-19 PHE, the list of providers in Medicare and many state Medicaid programs expanded to include professionals such as occupational and physical therapists and speech-language pathologists. Federally Qualified Healthcare Centers (FQHCs) and Rural Health Clinics (RHCs) were also allowed to provide services in some cases. These policies are temporary and most will expire at the end of the PHE.


I also recommend utilizing the TELEHEALTH.HHS.GOV website for providers – “Getting Started with Telehealth.” This webpage provides many additional links to more resources your organization can use to navigate this complex topic.


Temporary telehealth policies during the PHE were implemented to provide improved access to health care during the COVID-19 pandemic. The federal government has been encouraging providers to use telehealth to conduct virtual appointments and has made the telehealth “rules” more flexible. For instance, audio-only delivery of care has rarely been reimbursed historically. But due to COVID and the PHE, temporary policies allow this modality to deliver some services.


The PHE is reviewed and potentially extended every 90 days. When the PHE ends, coverage for telehealth may change. Monitor these updates by using the CCPH website referenced earlier in this article found at https://www.cchpca.org/.

Read More
HIPAA Compliance
HIPAA

HIPAA, The Cures Act and Information Blocking Compliance

Written by Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, OHCC, ICDCT-CM/PCS


The patient is at the center of the 21st Century Cures Act. Putting patients in charge of their health records is a key piece of patient control in health care, and patient control is at the center of HHS' work toward a value-based health care system. Patients need more power in their health care, and access to information is key to making that happen.


The Office of the National Coordinator for Health Information Technology (ONC) Cures Act Final Rule implements interoperability requirements outlined in the Cures Act.


HIPAA security requires covered entities to protect health information.  This information blocking practice is allowed except as required by law or as specified by the Secretary of Health and Humans Services as a reasonable and necessary activity.  However, it is likely to interfere with access, exchange and/or use of electronic health information (EHI). 

  • EHI is defined as the electronic protected health information (ePHI) in a designated record set (as defined in the Health Insurance Portability and Accountability Act (HIPAA) regulations) regardless of whether the records are used or maintained by or for a covered entity. The designated record set in a physician’s practice typically includes:
    • Medical records and billing records about individuals;
    • Other records used, in whole or in part, by physicians to make decisions about individuals

Why is this important to you?


All Actors will be subject to ONC’s Information Blocking rules and regulations on April 5, 2021.


For the first 24 months after publication of the Final Rule (currently until August 2, 2022), for the purposes of the information blocking definition, EHI is limited to the data elements represented in the US Core Data for Interoperability (USCDI) V1 standard adopted in the Final Rule.

  • EHR vendors are currently updating their products to support the access, exchange, and use of all data elements in the USCDI. This will take time and, for some smaller EHR vendors, may take several months.
  • After August 2, 2022, the definition of EHI expands to that of ePHI described above. At that time, all physicians will be required to make their patients’ ePHI available for access, exchange, and use.

Penalties - Because there are investigations, penalties and disincentives!  Actors that are subject to the information blocking regulations may be investigated by the HHS Office of Inspector General (OIG) if they are the subject of a claim of information blocking.

Further, actors found to have committed information blocking are subject to penalties:

  • Health IT developers of certified health IT, health information networks, and health information exchanges → Civil monetary penalties (CMPs) up to $1 million per violation
  • Health care providers → Appropriate disincentives to be established by the Secretary

Got Your Attention? 

What is behind the Information Blocking and Need to Comply?


The 21st Century Cures Act (Cures) is a landmark bipartisan health care innovation law enacted in December 2016. Cures includes provisions to promote health information interoperability and prohibit information blocking or “info blocking” by “Actors.”  Actors are considered:

  • Health Care Providers;
  • Health Information Networks (HIN) and Health Information Exchanges (HIE); and
  • Health information technology (IT) developers.

In March 2019, the Office of the National Coordinator for Health Information Technology (ONC) issued a Proposed Rule, 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. They released a final rule in March 2020 and published it in the Federal Register on May 1, 2020.


What are examples of practices that could constitute information blocking?


Section 4004 of the Cures Act specifies certain practices that could constitute information blocking:

  • Practices that restrict authorized access, exchange, or use under applicable state or federal law of such information for treatment and other permitted purposes under such applicable law, including transitions between certified health information technologies (health IT);
  • Implementing health IT in nonstandard ways that are likely to substantially increase the complexity or burden of accessing, exchanging, or using EHI;
  • Implementing health IT in ways that are likely to—
    • Restrict the access, exchange, or use of EHI with respect to exporting complete information sets or in transitioning between health IT systems; or
    • Lead to fraud, waste, or abuse, or impede innovations and advancements in health information access, exchange, and use, including care delivery enabled by health IT.

Additional examples of practices that could constitute information blocking can be found on the Office of the National Coordinator for Health Information Technology (ONC) website at: https://www.healthit.gov/curesrule/


Ah – there are Exceptions!

What are the information blocking exceptions?


Section 4004 of the Cures Act authorizes the Secretary of HHS to identify reasonable and necessary activities that do not constitute information blocking.  The exceptions support seamless and secure access, exchange, and use of EHI and offer actors certainty that practices that meet the conditions of an exception will not be considered information blocking.


A practice that does not meet the conditions of an exception would not automatically constitute information blocking. Such practices would not have guaranteed protection from civil monetary penalties or appropriate disincentives and would be evaluated on a case-by-case basis to determine whether information blocking has occurred.  Physicians must satisfy ALL applicable conditions of an exception at all relevant times to meet the exception as it relates to the access, exchange, and use of EHI. Each exception is limited to certain practices that clearly advance the aims of ONC’s Final Rule and are tailored to align with the following criteria:

  • Be reasonable and necessary
    These reasonable and necessary practices include providing appropriate protections to prevent harm to patients and others; promoting the privacy and security of EHI; promoting competition and innovation in health IT and its use to provide health care services to consumers, and to develop an efficient means of health care delivery; and allowing system downtime to implement upgrades, repairs, and other changes to health IT.
  • Address significant risk
    The exceptions are intended to address what ONC considers a “significant risk” and that Actors would otherwise avoid engaging in out of concern that such activities could be interpreted as info blocking.
  • Subject to strict conditions
    Each exception is subject to strict conditions to ensure practices are limited to those that are reasonable and necessary.

Exceptions are divided into two classes in the Cures Act Final Rule:

  • Exceptions that involve not fulfilling requests to access, exchange, or use EHI; and
  • Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI.

In the final rule, they have identified eight categories of reasonable and necessary activities that do not constitute information blocking, provided certain conditions are met (referred to as “exceptions”). The information below is a summary.  Go to healthIT.gov for more information.


Exceptions that involve not fulfilling requests to access, exchange, or use EHI


1.   Preventing Harm Exception


It will not be information blocking for an actor to engage in practices that are reasonable and necessary to prevent harm to a patient or another person, provided certain conditions are met.  This exception recognizes that the public interest in protecting patients and other persons against unreasonable risks of harm can justify practices that are likely to interfere with access, exchange, or use of EHI.


Physicians must hold a reasonable belief that the practice will substantially reduce the risk of physical harm to a patient or another natural person and the practice is no broader than necessary to substantially reduce the risk of harm. Practices include:

  • Declining to share data that is corrupt, inaccurate, or erroneous.
  • Declining to share data arising from misidentifying a patient or mismatching a patient’s EHI.
  • Refraining from a disclosure that would endanger life or physical safety of a patient or another person.
    • The licensed provider who made the determination must have done so in the context of a current or prior clinician-patient relationship.

Patients may opt to appeal a physician’s use of the Harm Exception. Physicians must implement their practice in a way that allows for the patient whose EHI is affected to exercise their rights under HIPAA or any federal, state, or tribal law to have the determination reviewed and potentially reversed.


The practice must be consistent with a written organizational policy that is:

  • Based on relevant clinical, technical, other appropriate expertise;
  • Implemented in a consistent and non-discriminatory manner; and
  • Conforms each practice to the conditions in the harm exception.

2.   Privacy Exception


It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI in order to protect an individual’s privacy, provided certain conditions are met.  This exception recognizes that if an actor is permitted to provide access, exchange, or use of EHI under a privacy law, then the actor should provide that access, exchange, or use. However, an actor should not be required to use or disclose EHI in a way that is prohibited under state or federal privacy laws.


Sub-exceptions

  • Unsatisfied legal precondition to the release of EHI

a.  Physicians may withhold EHI if a state or federal privacy law imposes preconditions for providing access, exchange or use of EHI (e.g., a requirement to obtain a patient’s consent before disclosing the EHI), if their practice:


     i.   Is tailored to the applicable precondition;

    ii.   Implemented in consistent and non-discriminatory manner; and

   iii.   Either:

  • Conforms to physician’s written organizational policies; or
  • Is documented by a physician on a case-by-case basis
  • Certified health IT developer not covered by HIPAA
  • Denial of individual’s request for ePHI consistent with the HIPAA Privacy Rule

  • a.  HIPAA covered entity or business associate Actor may deny an individual’s request for EHI under the HIPAA Privacy Rule’s right of access if the Actor’s practice complies with the Privacy Rule’s “unreviewable grounds” for a denial of access.


         i.   Unreviewable grounds under Privacy Rule:

    • Certain requests made by inmates of correctional institutions;
    • Information created or obtained during research that includes treatment if certain conditions are met;
    • Denials permitted by the federal Privacy Act; and
    • Information obtained from non-health care providers pursuant to promises of confidentiality.

    Respecting an individual’s request not to share information


    a.  An Actor may decline to provide access, exchange, or use of EHI if it meets the following requirements intended to align with an individual’s HIPAA Privacy Rule right to request additional restriction:


         i.   Individual requests that the Actor not provide such access, exchange, or use of the EHI without any improper encouragement or inducement of the request by the Actor.


    3.   Security Exception


    It will not be information blocking for an actor to interfere with the access, exchange, or use of EHI in order to protect the security of EHI, provided certain conditions are met.  This exception is intended to cover all legitimate security practices by actors, but does not prescribe a maximum level of security or dictate a one-size-fits-all approach.


    General conditions — A practice is not info blocking if it is:

    • Directly related to safeguarding the confidentiality, integrity, and availability of EHI;
    • Tailored to the specific security risk being addressed; and
    • Implemented in a consistent and non-discriminatory manner.

    Actors and their security-related practices may satisfy proposed exception through:

    • Written organizational policies; or
    • Determinations on a case-by-case basis under particular facts and circumstances.

    A practice must meet both:

    • General conditions; and
    • Either the requirements for organizational policies or case-by-case determinations.

    For practices that do not implement an organizational security policy, an Actor must have decided in each case, based on the particular facts and circumstances, that:

    • The practice is necessary to mitigate the security risk to EHI; and
    • There are no reasonable alternatives to the practice that address the security risk that are less likely to interfere with, prevent, or materially discourage access, exchange, or use of EHI.

    4.   Infeasibility Exception


    It will not be information blocking if an actor does not fulfill a request to access, exchange, or use EHI due to the infeasibility of the request, provided certain conditions are met.  This exception recognizes that legitimate practical challenges may limit an actor’s ability to comply with requests for access, exchange, or use of EHI. An actor may not have—and may be unable to obtain—the requisite technological capabilities, legal rights, or other means necessary to enable access, exchange, or use.  To receive protection, the practice must meet one of the following conditions:

    • Uncontrollable Events: The Actor cannot fulfil the request for access, exchange, or use of EHI due to a natural or human-made disaster, public health emergency, public safety incident, war, terrorist attack, civil insurrection, strike or other labor unrest, telecommunication or internet service interruption or act of military, civil or regulatory authority.
    • Segmentation*: The Actor cannot fulfil the request for access, exchange, or use of EHI because the Actor cannot unambiguously segment the requested EHI from EHI that:
      • Cannot be made available due to a patient’s preference or because the EHI cannot be made available by law; or
      • May be withheld in accordance with the Preventing Harm Exception.
    • Infeasible Under the Circumstances: The Actor demonstrates, prior to responding to the request, through a contemporaneous written record or other documentation its consistent and non-discriminatory consideration of certain factors that led to its determination that complying with the request would be infeasible under the circumstances.

    * You may need to provide access to information that is not otherwise protected by federal or state privacy law (e.g., HIPAA Patient Right of Access). You should consider speaking with your compliance officer or practice manager about how to handle such situations. For example, you may still be required to print out an office note and hand redact protected information even if you claim the Infeasibility Exception.


    5.   Health IT Performance Exception


    It will not be information blocking for an actor to take reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT's performance for the benefit of the overall performance of the health IT, provided certain conditions are met.


    This exception recognizes that for health IT to perform properly and efficiently, it must be maintained, and in some instances improved, which may require that health IT be taken offline temporarily. Actors should not be deterred from taking reasonable and necessary measures to make health IT temporarily unavailable or to degrade the health IT’s performance for the benefit of the overall performance of health IT.  An Actor’s practice to maintain or improve health IT performance is not info blocking when the practice meets one of the four following conditions:

    • Maintenance and improvement to health IT (e.g., an EHR upgrade).
    • Consistent with existing service level agreements, where applicable.
    • Practices that prevent harm and comply with Preventing Harm Exception.
    • Security-related practices that comply with Security Exception.

    Exceptions that involve procedures for fulfilling requests to access, exchange, or use EHI


    6.   Content and Manner Exception


    This is an important exception for physicians who are limited by their EHR vendor’s ability to access, use, or exchange patient information. Physicians are encouraged to discuss the use of this exception with their EHR vendor.  If the burden on the Actor for fulfilling a request is so significant that the Actor chooses to not fulfil the request at all, the Actor could seek coverage under the Infeasibility Exception.


    It will not be information blocking for an actor to limit the content of its response to a request to access, exchange, or use EHI or the manner in which it fulfills a request to access, exchange, or use EHI, provided certain conditions are met.


    This exception provides clarity and flexibility to actors concerning the required content (i.e., scope of EHI) of an actor’s response to a request to access, exchange, or use EHI and the manner in which the actor may fulfill the request. This exception supports innovation and competition by allowing actors to first attempt to reach and maintain market negotiated terms for the access, exchange, and, use of EHI. This exception applies to practices that involve the Actor responding to a request with limited information and in a manner other than what was requested by the requestor.

    • Content:
      • For 24 months after final rule publication, the Actor must respond with the subset of EHI identified by the USCDI data elements.
      • After that date, the Actor must respond with all EHI in a designated record set (i.e., ePHI).
    • Manner of Response: The Actor must respond either:
      • In the manner requested; or
      • In an alternative manner.

    7.   Fees Exception


    It will not be information blocking for an actor to charge fees, including fees that result in a reasonable profit margin, for accessing, exchanging, or using EHI, provided certain conditions are met. This exception enables actors to charge fees related to the development of technologies and provision of services that enhance interoperability, while not protecting rent seeking, opportunistic fees, and exclusionary practices that interfere with access, exchange, or use of EHI.


    Fees may result in a reasonable profit. The exception excludes certain fees, such as those based on electronic access to EHI by the individual. ONC divided the Fee Exception into three conditions.

    • To qualify for this exception, the Actor’s practice must meet the “Basis of fees condition,” not include any of the fees addressed in the “Excluded fees condition,” and comply with the “Compliance with the Conditions of Certification condition” if the Actor is a health IT developer subject to ONC’s Conditions of Certification (CoC).
    • This exception will most likely be applicable to EHR vendors rather than physicians or other providers.

    8.   Licensing Exception


    It will not be information blocking for an actor to license interoperability elements for EHI to be accessed, exchanged, or used, provided certain conditions are met. This exception allows actors to protect the value of their innovations and charge reasonable royalties in order to earn returns on the investments they have made to develop, maintain, and update those innovations.


    Conclusion

    Information blocking can occur in many forms for both Actors and Patients. Physicians can experience information blocking when trying to access patient records from other providers, connecting their EHR systems to local health information exchanges, migrating from one EHR to another, and linking their EHRs with a clinical data registry.  Patients can also experience information blocking when trying to access their medical records or when sending their records to another provider.


    The new rules regulate EHR vendors, prohibiting them from blocking information. Like physicians, EHR vendors must comply with these regulations now.  Learn more by reviewing the resources provided below.


    Resources

    AIHC HIPAA Compliance Officer Training

    American Medical Association –

    ONC

    Read More