Showing posts with label ONC. Show all posts
Showing posts with label ONC. Show all posts

Monday, April 25, 2016

Help Inform the Department of Health and Human Services’ (HHS) Measurement of Interoperability

The ONC asking for your input on ways to measure the progress toward a future where health information is flowing between providers and patients to supports a health system that provides better care, smarter spending, and healthier people. The Medicare Access and CHIP Reauthorization Act of 2015 (MACRA) declares it a national objective to achieve the widespread exchange of health information through the use of interoperable certified electronic health records and directs HHS to establish metrics in consultation with you – the health IT community – to see if that objective has been met.

The Federal Health IT Strategic Plan is a collaboration with over 35 federal partners and the public which focuses federal offices that use or influence the use of health information technology on person-centered care, advancement of science, and overall health. The central theme of the Strategic Plan is ensuring health data flows seamlessly and securely to create a learning-based, person-centered health system.

Similarly, the Nationwide Interoperability Roadmap was an effort by the Office of the National Coordinator for Health Information Technology (ONC) in collaboration with the private sector, states, and federal partners to identify near-term actions to advance an interoperable health system.

Combined with the recent announcements of private sector market leaders to make EHR information flow more efficiently, these efforts all help to support the flow of health information when and where it is needed for patient care. (See our 3/1/16 post “Health Groups Aim to Make Medical Records Easier to Access” here.)

The ONC is issuing a request for information for your thoughts on how to measure interoperability and ensure HHS is keeping pace with the objectives laid out in the Roadmap and the Federal Health IT Strategic plan to measure the broad health information ecosystem, including individuals and non-health settings. Specifically, the ONC is asking for input on:

1.       What populations and elements of information flow should we measure?
2.      How can we use current data sources and associated metrics to address the MACRA requirements?
3.      What other data sources and metrics should HHS consider to measure interoperability more broadly?


The public comment period closes on June 3, 2016. View and download the request for information here and view the original posting here

Thursday, April 14, 2016

Health IT Interoperability Remains Elusive

To assess the state of HIT, Modern Healthcare conducted a survey in 2015, known as the 25th annual Modern Healthcare Survey of Executive Opinions on Key Health Information Technology Issues. The results on interoperability of EHRs were disappointing. Only 11% of respondents to the survey said their organizations were able to routinely exchange electronic patient information with other providers across the country.

That meager showing comes 11 years after President George W. Bush created the Office of the National Coordinator for Health In-formation Technology with a mandate to implement a “nationwide interoperable health information technology infrastructure.

Only 17% of respondents to the 2015 survey indicated their hospitals and physician offices can move patient records around their home states. Just 21% reported they can exchange records within their regions. In contrast, 21% of respondents said they aren't exchanging electronic information at all, either within or outside of their organizations.

Still, an overwhelming majority of respondents (71%) were optimistic they'll be able to exchange a “core data set” of patient information nationally by the end of 2017 in keeping with a goal set in the ONC's “interoperability road map” released in January 2015. And 72% of those taking our survey opined that achieving nationwide interoperability would be of either high value (23%) or moderate value (49%) to their organizations. The road map signaled a shift in emphasis by federal health IT policymakers away from EHR adoption and toward health information exchange.

The original article by Joseph Conn can be found at the following address: http://www.modernhealthcare.com/article/20150411/MAGAZINE/304119986

Monday, April 11, 2016

Electronic Health Records: Top 10 Healthcare Milestone of the Past 40 Years

In a recent article, Modern Healthcare named the top healthcare milestones of the past 40 years.  The top 10 milestones include electronic medical records, as called for by President George W. Bush in his 2004 State of the Union address. President Bush called for universal, portable, electronic health records within a decade.

On April 26, 2004, President George W. Bush formally launched the federal drive to widely disseminate health information technology to improve patient care. The next day, by executive order, Bush created the Office of the National Coordinator for Health Information Technology within HHS. A few days later, HHS Secretary Tommy Thompson named Dr. David Brailer the first ONC leader.

Bush said the ONC should work with private sector healthcare organizations as well as all federal agencies with a hand in healthcare. The goal of the newly-created ONC was to begin work on a national HIT strategy to promote the adoption and use of interoperable electronic health records to enhance clinical decision-making, improve quality, lower costs, reduce errors, improve coordination of care and ensure the privacy and security of patient data.

However, the Bush years of the ONC did not provide funding for the agency. Instead, the ONC was financed by reshuffling HHS' administrative funds. Despite this, adoption of EHRs has tripled in the first 10 years of the ONC and the concept health information exchange is now commonplace.

The second era of the ONC is the big-money Obama era starting with the 2009 American Recovery and Reinvestment Act, with its $2 billion for ONC grant programs. The incentive payment program for adoption of EHRs has paid out $21.6 billion so far.

There are critics of the strong federal role in HIT development, calling the EHR incentive program a market-disrupting “Frankenstein.”

Ross Koppel, a professor of sociology at the University of Pennsylvania medical school, said federal policymakers erred in thinking that “more HIT equals better care and safer care. That assumption has been defeated by their desire to push the technology long before it was ready.” What has resulted, he said, “is a captured market in which vendors create inferior products that the clinicians are obliged to purchase.”

Yet, EHR has still come a long way. Before the ONC, caveat emptor ruled for EHR buyers. Today, virtually all EHR systems sold are tested and certified against a list of functional criteria developed by the ONC. Before the ONC and the EHR incentive program, fewer than 4% of nonfederal U.S. hospitals had EHR systems with computerized physician-order entry. Today, 90% of hospitals have CPOE. Previously, less than 20% of office-based physicians had any kind of an EHR; today, more than 78% do.

Though ONC has had several previous directors and initiatives, Dr. Karen DeSalvo, the current Coordinator, succinctly sums up the ONC’s overarching goal: “Everyone is trying to solve these same three issues—capturing data, freeing it appropriately and then putting it to use.”


The original article by Joseph Conn can be found at the following address: http://www.modernhealthcare.com/article/20140405/MAGAZINE/304059980

Monday, March 14, 2016

Trends in Consumer Access and Use of Electronic Health Information

In ONC Data Brief 30, trends in consumer access and use of electronic health information are examined. Over the past few years, a number of policy changes have been put in place to increase individuals' access to their personal electronic health information. HIPAA was modified to clarify that if an individual's health information is available electronically, individuals have a right to obtain that information electronically. In Stage 2 Meaningful Use, CMS requires eligible providers and hospitals participating in the Medicare and Medicaid EHR Incentive Program to use certified EHR technology with the capability for patients to electronically view, download and transmit (VDT) their health information electronically. From 2011 to 2014, participation in the Blue Button Initiative, a public-private partnership to increase consumer access and use of their health data grew from 30 organizations to more than 650. This brief provides national estimates of consumers' access and use of their electronic health information based upon nationally representative surveys conducted from 2012 to 2014.


The data reveal 9 major trends:

1.       Individuals' electronic access to their medical records increased significantly in 2014. In 2014, nearly 4 in 10 Americans were offered electronic access to their medical record. The proportion of Americans offered online access to their medical records rose by more than a third between 2013 and 2014.
2.      In 2014, over half of individuals who were offered access viewed their record at least once within the last year. About one-third of individuals accessed their medical record one to two times in 2014 whereas about one-fifth of individuals accessed their online record once or twice in 2013. In both 2013 and 2014, about one in ten individuals accessed their online medical record more than 6 times over a one-year period.
3.      Almost all individuals report having access to laboratory results within their online medical record. Among individuals using online medical records, more than 90% report having laboratory test results in their record. Among individuals who have used an online medical record, almost 8 in 10 report having a list of health and medical problems in their online medical record. Approximately three-quarters of individuals report having access to a current list of medications within their online medical record.
4.      Individuals most commonly use online medical records for monitoring health. In both 2013 and 2014, about seven in ten individuals who accessed their online medical record, used it to monitor their health. Approximately one-third of individuals downloaded information from their online medical record in 2014; rates of downloading were similar in 2013. Rates of sharing information with at least one other individual or party decreased between 2013 and 2014; however, these decreases were not significant. In both 2013 and 2014, about one in ten individuals used their online medical records to correct medical records. In both 2013 and 2014 about one in ten individuals used their online medical records to transmit their data to somewhere else, such as a PHR or app.
5.      In 2014, 8 in 10 individuals who accessed their medical record online considered the information useful. In 2014, fewer than 5% of individuals who had used an online medical record within the last year considered it 'not useful.' Between 2013 and 2014, there was a significant increase in the proportion of individuals who were neutral about the usefulness of their online medical record. The proportion of individuals who considered their online medical records as 'not useful' and as 'useful' significantly declined between 2013 and 2014.
6.      Lack of need remains the top reason for not accessing an online medical record. In both 2013 and 2014, about three-quarters of individuals who did not access their online medical record indicated they didn't access it because that they did not have a need to use it. About one in ten individuals who did not access their online medical record indicated it was because they had more than one online record. Although not a statistically significant difference, fewer individuals noted privacy or security concerns in 2014 as a reason for not accessing their online medical record compared to 2013.
7.      Over one-quarter of individuals either didn't believe they had a right or were unaware of their right to an electronic copy of their medical record. Almost three-quarters of individuals of individuals were aware of their right to access their medical record electronically. Individuals who were aware of their right to access their medical record electronically were offered online access to their medical record by their health insurer or health care provider at significantly higher rates compared to individuals who were not aware or did not believe they had a right to an electronic copy of their medical record were offered online access.
8.     In 2014, almost one-in-five individuals whose health care provider had an EHR requested their health care provider electronically exchange their medical record. Over two-thirds of individuals report their health care provider has an EHR. Across all individuals nationwide, regardless of whether their provider has an EHR or not, over one-in-ten individuals (12%) requested their health care provider electronically send their medical record to another health care provider.
9.      Among individuals who visited a health care provider within the past year, over one-third experienced at least one gap in information exchange in 2014. Although there was a decline in the proportion of individuals who experienced at least one gap in information exchange between 2012 and 2014, these do not represent significant changes. Having to recount one's medical history because the health care provider did not receive records from another health care provider is consistently the most common gap in information exchange experienced by individuals between 2012 and 2014. Other common gaps in information exchange that remain issues in 2014 relate to test results; this includes having to bring test results with you to an appointment (15%) and having to wait for test results longer than you thought reasonable (11%).

In short, there is a significant opportunity for consumer outreach to increase individuals' awareness regarding electronic access and use of online medical records. Individuals' who were aware of their right to a copy of their electronic medical record had significantly higher rates of being offered online access compared to those who were unaware or incorrectly believed they didn't have this right. A lack of need remains the most frequently cited reason for not accessing an online medical record. Illustrating the value of using an online medical record to manage one's health and address information gaps among providers could increase usage among those individuals who cited a lack of need as a reason for not accessing an online medical record.


What do you make of the results? Has your organization promoted electronic access and use of online medical records by patients? Do you think there are any potential problems with allowing patients open online access? Let us know in the comments below.

Monday, March 7, 2016

Disparities in Individuals' Access and Use of Health Information Technology

ONC Data Brief 34, published last month, examined the disparities in individuals’ access and use of health information technology in 2014. Findings from nationally representative surveys show that individuals' use of information technology (IT) for health needs increased significantly between 2013 and 2014. Prior analysis revealed that disparities in online access of medical records and use of IT for health-related needs existed by certain socio-demographic characteristics and geographic settings in 2013.

The data reveal 5 major trends:

1.       Individuals whose provider had an EHR were offered online access to their medical record at three times the rate of those whose provider does not. In 2014, individuals whose provider had an EHR had significantly higher rates of using IT for health needs compared to individuals whose provider did not have an EHR. The percent of individuals offered access to online medical records, emailing providers, and looking up test results online increased between 2013 and 2014; however, the rate of increase was greater among those whose provider had an EHR.
2.      Individuals with lower incomes and less education had significantly lower rates of being offered online access to their health information. While about half of individuals with incomes of $100,000 or more were offered online access to their health information, only about one-quarter of individuals with less than a $25,000 annual income were offered online access. Individuals with more than a four year college degree were offered online access at about twice the rate as individuals who had a high school degree or less.
3.      Individuals who had difficulty speaking English were offered online access to their medical records at significantly lower rates. While 39% of individuals who spoke English very well or well were offered online access to their medical record, only 15% of individuals who didn't speak English well and only 5% of those who didn't speak English at all were offered online access to their medical record. Almost twice as many white, non-Hispanic individuals were offered online access to their medical record as compared to Hispanic individuals.
4.      Among individuals offered online access to their medical record, those with higher incomes and more education were more likely to view their record. Individuals with annual incomes of at least $50,000 had significantly higher rates of viewing their online medical record compared to individuals with incomes less than $25,000. While almost two-thirds of individuals with annual incomes higher than $100,000 viewed their online medical record at least once within the past year, only about one-third of individuals with incomes less than $25,000 viewed their record within the past year. Individuals with a high school degree or less had significantly lower rates of viewing their online medical record compared to individuals with more than a four-year college degree. Individuals with a four-year college degree or more education were over twice as likely to view their online medical record compared to those without a high school degree.
5.      Individuals with more education and higher income use certain types of IT for health-related needs at significantly higher rates. Individuals 50-59 years of age had significantly higher rates of text-messaging and emailing their provider, looking up online test results, and using a mobile health application compared to individuals 70 years or older. Individuals with no disabilities had significantly higher rates of emailing their provider and using a mobile health application than individuals with a disability. Individuals residing in rural areas have significantly lower rates of emailing their provider, looking up test results online and using a smart phone health application compared to individuals residing in suburban settings.

What do you make of the results? Do your experiences with patients reflect the data above? Let us know in the comments below.

Friday, March 4, 2016

ONC Blog Series Part 4: Quality Assessment/Quality Improvement and Population-Based Activities Examples

The fourth and final installment of the ONC’s four-part blog series on HIPAA, “The Real HIPAA: Quality Assessment/Quality Improvement and Population-Based Activities Examples,” focuses once again on illustrating the interoperability of HIPAA through examples. The examples are a continuation of Part 3 and are taken directly from the ONC’s blog post.


Example 4: Quality Assessment/Quality Improvement – 45 CFR 164.506(c)(5)

Providers participating in the ACO/OHCA may permit the ACO quality committee to access the Protected Health Information (PHI) needed for the quality assessment. An Accountable Care Organization (ACO) that consists of multiple providers operating as an Organized Health Care Arrangement (OHCA) has a quality committee made up of professionals from within the ACO. In order to improve patient health and meet Medicare’s quality improvement requirements, the quality committee plans to obtain and review treatment and health outcomes of ACO patients who experienced hospital-acquired infections and surgical errors.

Where the ACO is not operated as an OHCA, but the quality committee is evaluating care quality on behalf of the individual providers in the ACO, the providers participating in the ACO may permit the ACO quality committee to access the necessary PHI for the quality assessment, but only for patients whom the requesting and disclosing providers have in common, pursuant to 164.506(c)(4), instead for all the patients in the ACO.
In both instances, (OHCA and non-OHCA), access to, or disclosure of, electronic PHI can be made using Certified EHR Technology, so long as the HIPAA Security Rule is complied with.


Example 5: Quality Assessment/Quality Improvement – 45 CFR 164.506(c)(1) and (c)(4)
As part of a quality review, a health care provider may need to know the health outcome of a patient that the provider treated but no longer has contact with (e.g., patient was transferred to another provider). The provider may query a Health Information Exchange (HIE) for the relevant health outcomes of the individual, or the provider could directly ask the subsequent provider for information.


Example 6: Population-Based Activities – 45 CFR 164.506(c)(1) and (c)(4)A provider that has treated the patient and is responding to this query may use Certified EHR Technology to send the relevant information directly to the requesting health care provider, or may disclose to the requesting provider using the HIE. Disclosure of electronic PHI by Certified EHR Technology or other electronic means requires HIPAA Security Rule compliance. This scenario also works for health plans with a relationship with the patient; it is not limited to providers.
Unaffiliated hospitals in the same community often see the same patients and may not be able to tell whether a patient’s hospital-acquired infection resulted from care received at the current treating hospital or from a prior visit to a separate hospital in the community.

The hospitals that have treated or are treating the patient may use Certified EHR Technology to share relevant PHI to try to determine the source and/or cause of the infection in order to prevent further infections.

Disclosure of electronic PHI by Certified EHR Technology or other means requires HIPAA Security Rule compliance.


This post concludes the four-part series on HIPAA.

Tuesday, February 23, 2016

ONC Blog Series Part 3: Care Coordination, Care Planning, and Case Management Examples Under HIPAA

In the third installment of ONC’s four-part blog series on HIPAA, care coordination, care planning, and case management are in focus. Blog post Part 3: “The Real HIPAA: Care Coordination, Care Planning, and Case Management Examples” gives additional practical examples of exchange for Treatment and exchange for Health Care Operations. The following examples are taken directly from the ONC’s post.

Example 1: Care Coordination – 45 CFR 164.506(c)(2)

A hospital is preparing to discharge a patient who will need ongoing, facility-based care. The inpatient facility needs to identify a rehabilitation facility to accept the patient. Prospective facilities will need Protected Health Information (PHI) about the patient to determine whether they can provide the right care.

The current hospital may disclose the relevant PHI to prospective facilities without first obtaining the patient’s written authorization. The disclosing hospital may use Certified EHR Technology, so long as the disclosure is done in a manner that meets the HIPAA Security Rule.

This disclosure is a treatment disclosure (in anticipation of future treatment of the patient by the rehabilitation facility) and thus, may be carried out under 45 CFR 164.506(c)(2).

But, you might wonder, because the PHI came from the inpatient facility, will the inpatient facility be held responsible under HIPAA for what the rehabilitation facilities do with the PHI once they have received it in a permissible way under HIPAA?

Under HIPAA, the inpatient facility is responsible only for complying with HIPAA in disclosing the PHI to the rehabilitation facility in a permitted and secure manner. This includes sending the PHI securely and taking reasonable steps to send it to the right address. After the rehabilitation facility has received the PHI in accordance with HIPAA, the rehabilitation facility, as a covered entity itself, is responsible for safeguarding the PHI and otherwise complying with HIPAA, including with respect to any breaches that occur. The responsibility of the sending provider was to send it securely to the right address; the sending provider is not responsible for its security once received by another covered entity or the recipient covered entity’s business associate (BA).


Example 2: Care Planning By a Provider – 45 CFR 164.506(c)(1) and (c)(2)

A provider wants to ensure that her patients have a comprehensive care plan after they are discharged from the hospital. The provider hires a care planning company (i.e., its BA) to develop these plans for her patients.

To develop the plan, the care planning company requests pertinent PHI about each patient from the patients’ other providers, such as the hospitals to which the patients have been admitted for the same or similar medical care and the patients’ health plans. Each of these covered entities may disclose the relevant PHI for care planning purposes using Certified EHR Technology. Disclosure of electronic PHI by such technology or other electronic method requires HIPAA Security Rule compliance.

In this scenario, a business associate agreement (BAA) is only required between the covered entity that hires the care planning company and that company. The covered entities who permissibly disclose PHI in this scenario may do so directly to the provider’s care planning company for the provider’s care planning purposes (without the need to execute their own BAA) just as they could share this information directly with the provider. Electronic PHI disclosed in this scenario, for example using Certified EHR Technology, must be disclosed consistent with the HIPAA Security Rule.


Example 3: Case Management by a Payer – 45 CFR 164.506(c)(1) and (c)(4)

A health plan hires a health care management company to provide semi-monthly nutritional advice and coaching to their diabetic and pre-diabetic members. The care management company is a BA of the health plan. In order to provide appropriate nutritional advice and coaching, the health care management company needs additional information about these individuals to ensure the advice is consistent with the treatment they receive from their providers.

The health care management company may query the relevant providers to obtain information that could impact the nutritional advice. Providers may respond to the query using Certified EHR Technology and may disclose PHI necessary for the case management purpose for which the nutritional coach was hired by the health plan. Disclosure of electronic PHI by Certified EHR Technology or other method requires HIPAA Security Rule compliance.

In this scenario, the disclosures by the providers to the nutritional coach are for the Health Care Operations (“population-based activities relating to improving health or reducing costs” and “case management”) of the health plan, and therefore are Permissible Disclosures under HIPAA. Likewise, a BAA is only required between the health plan covered entity and the health care management company it hired. The providers may make permissible disclosures of PHI to that company without a BAA between the discloser and that company.


Once again, the providers sharing PHI with the health care management company hired by the health plan are not responsible under HIPAA for what that company or the health plan subsequently does with the information once it has been sent for a permissible reason and in a secure manner.

Monday, February 22, 2016

Trends in Consumer Concerns Regarding Privacy and Security of Health Records

The ONC’s newest data brief examines trends in individuals’ perceptions regarding privacy and security of medical records and exchange of health information. Using data from a nationwide survey administered from 2012-2014, the ONC now summarizes the trends in consumers’ attitudes toward privacy and security concerns and preferences regarding electronic health records (EHR) and health information exchange (HIE).

The data reveal 6 major trends:

1.       Individuals' concerns about the privacy and security of both paper and electronic medical records declined significantly between 2013 and 2014 from 75% very or somewhat concerned to 58% very or somewhat concerned. This is a statistically significant difference (p < .05).
2.      In 2014, a similar number of individuals - about one in five - expressed lack of concern about both the privacy and the security of their medical records. The proportion of individuals who were "very concerned" about the privacy of their medical records decreased by about fifteen percentage points between 2013 and 2014. This is a statistically significant difference (p < 0.05).
3.      Individuals' concerns regarding the privacy and security of their medical record do not significantly differ by whether they have an electronic versus paper medical record. There were no statistically significant differences between paper versus electronic health records.
4.      Between 2012 and 2014, at least three-quarters of individuals supported their health care providers' use of EHRs despite any potential privacy or security concerns.
5.      Individuals' concerns regarding unauthorized viewing of medical records when sent by fax or electronic means declined significantly between 2013 and 2014. Between 2013 and 2014, concerns regarding having medical records sent by fax declined by 20% and concerns regarding medical records sent by electronic means declined by 16%. This is a statistically significant difference (p < 0.05).
6.      Between 2012 and 2014, at least 7 in 10 individuals have supported electronically exchanging their health records despite potential privacy or security concerns. There are no significant differences between years (p < 0.05).

In summary, as EHR adoption and HIE increased among hospitals and physicians, consumers' concerns regarding HIE and the privacy and security of medical records declined. However, it is important to note that these perceptions reflect individuals' points of view prior to announcement in 2015 of several large health care information breaches. Additionally, it is unclear as to whether the significant decreases in concerns between 2013 and 2014 are an anomaly or whether this represents the beginning of a trend towards decreasing privacy and security concerns.

What do you make of the results? Has your organization faced any consumer concerns over using one medical record-keeping format over another? Let us know in the comments below.






Tuesday, February 16, 2016

ONC Blog Series Part 2: Permitted Uses and Disclosures in HIPAA

In our continuing coverage of the ONC’s four-part blog series, we focus today on Part 2: “The Real HIPAA: Permitted Uses and Disclosures.” This blog post summarizes the new ONC fact sheets on HIPAA Permitted Uses and Disclosures for exchange, developed in conjunction with the Office for Civil Rights.

The HIPAA Privacy Rule defines when, under federal law, a covered entity may use or disclose an individual’s Protected Health Information (PHI). In general, a covered entity may only use or disclose PHI if either: (1) the HIPAA Privacy Rule specifically permits or requires it; or (2) the individual who is the subject of the information gives authorization in writing.

The HIPAA Privacy Rule specifically permits a use or disclosure of PHI for the covered entity that collected or created it for its own treatment, payment, and health care operations activities. Similarly, HIPAA also permits the covered entity that collected or created the PHI to disclose it to another covered entity for treatment, payment, and in some cases, the health care operations of the recipient covered entity.

If the covered entity wishes to use or disclose the PHI for something other than treatment, payment, or health care operations, it must obtain patient authorization to do so, unless the use or disclosure is permitted by another provision of the HIPAA Privacy Rule. One important such rule is when a patient requests a copy of her PHI, and asks that it be sent somewhere else.

OCR recently clarified that, when an individual requests a copy of her PHI and asks that it be sent directly to a third party, a provider must comply except in very narrow circumstances.

In regards to the national priority of interoperability, nationwide interoperable health information technology (health IT) will help make the right electronic health information available to the right people at the right time for patient care and health, no matter the care setting, organization, or technology supporting the information exchange. HIPAA’s Permitted Uses and Disclosure are rules that run “in the background” in support of this important nationwide goal. These background rules are made transparent to individuals through Notices of Privacy Practices. And, as to privacy protections, the HIPAA Privacy Rule applies the same whether the PHI is on a piece of paper or is electronic. (The Security Rule, in contrast, applies only to electronic PHI.)

ONC has released two new fact sheets to breakdown HIPAA’s permitted uses and disclosures.


As discussed in the Exchange for Treatment fact sheet, under HIPAA, a covered entity provider can disclose PHI to another covered entity provider for the treatment activities of the recipient health care provider, without needing patient consent or authorization. Treatment is broadly defined. It includes making and receiving referrals; coordination or management of health care and related services by a provider, even through a hired third party (for example, a nutritionist); and several other functions.

Likewise, a covered entity can disclose PHI to another covered entity (CE) or that CE’s business associate (BA) for the following subset of health care operations activities of the recipient covered entity without needing patient consent or authorization:
  • Conducting quality assessment and improvement activities
  • Developing clinical guidelines
  • Conducting patient safety activities as defined in applicable regulations
  • Conducting population-based activities relating to improving health or reducing health care cost
  • Developing protocols
  • Conducting case management and care coordination (including care planning)
  • Contacting health care providers and patients with information about treatment alternatives
  • Reviewing qualifications of health care professionals
  • Evaluating performance of providers and/or health plans
  • Conducting training programs or credentialing activities
  • Supporting fraud and abuse detection and compliance programs.

In general, before a covered entity can share PHI with another covered entity for one of the reasons noted above, the following three requirements must also be met:

  1. Both covered entities must have or have had a relationship with the patient (can be a past or present patient)
  2. The PHI requested must pertain to the relationship
  3. The discloser must disclose only the minimum information necessary for the health care operation at hand.
Under HIPAA’s minimum necessary provisions, a provider must make reasonable efforts to limit PHI to the minimum necessary to accomplish the purpose of the use, disclosure or request.  If the covered entities are in an “Organized Health Care Arrangement,” or “OHCA,” as defined in the HIPAA Privacy Rule (45 CFR 160.103), additional capabilities may exist for interoperable exchange of PHI.

Friday, February 12, 2016

ONC Blog Series Part 1: HIPAA and Interoperability

In February 2016, The Office of the National Coordinator for Health Information Technology (ONC) launched a new four-part blog series to explain the permitted uses of health information under HIPAA. The series emphasizes that HIPAA not only protects personal health information from misuse, it also enables personal health information to be accessed, used or disclosed interoperably, when and where it is needed for patient care.

We begin our coverage of the four-part series with Part 1: The Real HIPAA Supports Interoperability. This introductory post establishes HIPAA as serving the dual functions of protecting personal health information from misuse and also enabling personal health information to be used between Covered Entities (CE) under specific conditions.

ONC released two new fact sheets which give numerous examples of when electronic health information can be exchanged without first requiring an authorization or a writing of some type from the patient, so long as other protections or conditions are met. HIPAA provides many pathways for permissibly exchanging Protected Health Information (PHI).


The new fact sheets remind stakeholders through practical, real-life scenarios, that HIPAA supports interoperability because it gives providers permission to share PHI for patient care, quality improvement, population health, and other activities.

Next week, the blog series will continue to delve further into Permitted Uses and Disclosures. As per ONC, Blog #2 will be background on HIPAA’s Permitted Uses and Disclosures: what they are, and how they advance the national goal of interoperability. Blog #3 will give examples of exchange of health information for Care Coordination, Care Planning, and Case Management, both between providers, and between provider and payers. Finally, Blog #4 will give examples of interoperable, permissible exchange of PHI for Quality Assurance and Population-Based Activities, including via a health information exchange.

Tuesday, November 4, 2014

Politico Reports: ONC Releases Meaningful Use Stage 2 Attestation Rates

Attestation rates for Stage 2 of meaningful use remained low at the end of September, according to data released ahead of today's Health IT Policy Committee meeting. The figures, contained as footnotes in an ONC data analytics update, show that 4,656 doctors and other eligible providers and 258 hospitals had attested to Stage 2. This is an increase over the end of August but still only a rounding error out of 480,000-plus eligible providers and hospitals. The low figures reflect problems that electronic health records vendors and providers have had achieving Stage 2. 

CMS relaxed the rules on reporting Stage 2 attestation earlier in the year, and provider groups have been pressing to reduce the one-year reporting period to 90 days in 2015. We have a feeling that a GOP-controlled Congress may try to do something about this.

ONC's analysis of the Sept. 30 attestation data showed disappointing levels of accomplishment in meeting some of the most important categories of Stage 2. For example, 87 percent of eligible providers who attested to Stage 2 received exclusions from showing they could electronically send summaries of care. Of those who did not receive exclusions, only 18 percent were able to send electronic summaries 80 percent of the time or more. A total of 55 percent were able to file summaries electronically 30 percent or less of the time. Scores for the "view, download or transmit" category, a measure of physicians' capacity to share data with patients, were even worse. Although 65 percent of the attesters' patients had online access to records, only 10 percent of these providers were able to get patients to download their records more than half the time.

A similarly small percentage sent patient reminders on a regular basis. In its analysis of hospitals, ONC found that only 10 percent got out electronic care summaries to patients more than half the time, and less than 15 percent were able to get more than 20 percent of their patients to view, download or transmit their records. However, as ONC pointed out, the figures represented a somewhat improved picture from analyses it did over the summer.

Many individuals are concerned about the privacy of their medical records, but that doesn't keep most of them from giving information to health care providers, according to survey results to be released at the meeting. In a survey of more than 2,000 people conducted in 2012-13 for ONC, 75 percent were "very or somewhat concerned" about the privacy of information in EHRs. But only eight percent said those concerns would cause them to withhold information from health care providers.


Thursday, February 27, 2014

Patient Identification and Matching Report Released by ONC

The Office of the National Coordinator for Health Information Technology (ONC) released the final version of the Patient Identification and Matching Report. The report evaluated best practices and current trends in using electronic health record systems to accurately identify patients and exchange information between providers, patients, and caregivers. Mistakes in properly identifying patient health records put patient safety at risk and has resulted in too many patient deaths. 

The drafting process for the report included an industry environmental scan with input from stakeholders at meetings, on calls, and requests for submitted comments and recommendations. NAHAM was an active participant throughout the drafting process and provided recommendations focused on improving patient safety that are featured in the report. NAHAM's recommendations can be found on page 76 of the report. 

The report resulted in 10 findings that ONC will use as they move forward with the process of improving electronic health record systems and patient matching to improve patient safety.The findings are below.

Findings

1. Standardized patient identifying attributes should be required in the relevant exchange transactions. 

2. Any changes to patient data attributes in exchange transactions should be coordinated with organizations working on parallel efforts to standardize healthcare transactions. 

3. Certification criteria should be introduced that require certified EHR technology (CEHRT) to capture the data attributes that would be required in the standardized patient identifying attributes.

4. The ability of additional, non-traditional data attributes to improve patient matching should be studied. 

5. Certification criteria should not be created for patient matching algorithms or require organizations to utilize a specific type of algorithm. 

6. Certification criteria that requires CEHRT that performs patient matching to demonstrate the ability to generate and provide to end users reports that detail potential duplicate patient records should be considered. 

7. Build on the initial best practices that emerged during the environmental scan by convening industry stakeholders to consider a more formal structure for establishing best practices for the matching process and data governance. 

8. Work with the industry to develop best practices and policies to encourage consumers to keep their information current and accurate. 

9. Work with healthcare professional associations and the Safety Assurance Factors for EHR Resilience (SAFER) Guide initiative to develop and disseminate education and training materials detail best practices for accurately capturing and consistently verifying patient data attributes. 

10. Continue collaborating with federal agencies and the industry on improving patient identification and matching processes. 






Thursday, March 15, 2012

More Than 70 Percent of Attested EHRs are Dually Certified by CCHIT

More than two-thirds (71 percent) of the complete electronic health records (EHRs) of providers and hospitals that have successfully attested to federal meaningful use criteria and qualified for incentives through the American Recovery and Reinvestment Act (ARRA) are dually certified under both the ONC-ATCB and the CCHIT Certified® programs of the Certification Commission for Health Information Technology, says a news release from CCHIT. According to the latest figures from the Centers for Medicare & Medicaid Services (CMS), approximately 22,000 eligible providers and hospitals with complete EHRs have successfully attested.

“These early adopters have the advantage of complete EHRs that not only meet the meaningful use requirements established by the Office of the National Coordinator for HIT (ONC), but also have been tested against the more rigorous clinical scenarios for functionality, interoperability and safety required by the independent CCHIT Certified program,” said Karen M. Bell, MD, chair, CCHIT. “It’s no surprise that the vast majority of physicians and other providers are choosing tried and true CCHIT Certified products that have been proven over the years to support their unique business and patient care needs.”

CCHIT continues to certify EHR products in both programs. Some health IT companies previously certified by CCHIT in the ONC-ATCB program are now returning to become CCHIT Certified. The CCHIT Certified program includes both “core” and “optional” certifications. Currently, optional, add-on certifications for specialty care or special patient populations include behavioral health, cardiovascular medicine, child health, dermatology, clinical research, oncology and women’s health.

“Moving forward, CCHIT will continue to review and upgrade its independently developed, comprehensive programs to ensure that EHR certification keeps pace with advances in the field, and meets the various information technology needs of health care providers in the future,” Bell said.

A letter from Dr. Bell with a deeper analysis of these results as they pertain to office-based providers is available at CCHIT’s blog EHR Decisions.

Source: CCHIT News Release

Wednesday, March 7, 2012

ONC Requests Input on Safeguarding Health Info on Mobile Devices

The ONC Office of the Chief Privacy Officer (OCPO), along with the HHS Office for Civil Rights (OCR), invites members of the public to provide input on mobile devices' uses and the current and emerging privacy and security best practices regarding protecting and securing health information while using mobile devices.

In conjunction with the input gathered during the Mobile Devices Roundtable: Safeguarding Health Information event, public input will help inform the development of an effective and practical way to bring awareness and understanding to those in the clinical sector regarding protecting and securing health information while using mobile devices.

ONC is seeking your input. The public comment period will remain open until Friday, March 30, 2012.

For more information, please click here.

Source: ONC News Release

Tuesday, March 6, 2012

NeHC Releases 2012 Stakeholder Survey Results

National eHealth Collaborative (NeHC) released the results of the 2012 NeHC Stakeholder Survey, featuring responses related to health information exchange, consumer engagement and other NeHC programs. NeHC previewed the results at HIMSS12 during its stakeholder meet-up and other strategic meetings.

Coming on the heels of the release of the proposed rule for meaningful use Stage 2, survey results provide insights into perceptions of stakeholders related to barriers to health information exchange (HIE) and the importance of consumer engagement to transforming healthcare, which relate to some of the core measures that physicians and hospitals must meet in order to be eligible for Stage 2 meaningful use incentives. Stakeholders believe that the most important benefits of HIE include care coordination, ensuring that patients and providers have the right information available when needed to support patient care, and improving quality and efficiency. In addition, stakeholders believe that consumer engagement will be very important or important to transforming healthcare and achieving better outcomes.

“It is both interesting and enlightening to understand what stakeholders are thinking related to core strategic priorities for NeHC including education, HIE, and consumer engagement,” said NeHC CEO Kate Berry. “This type of information can help inform our programs to ensure we emphasize the areas of greatest need to encourage progress toward widespread deployment of HIT and HIE to improve patient care.”

Highlights from the survey are included below:
“What are the most important benefits of health information exchange?” (Respondents were asked to select three)
73% - Better care coordination
65% - Providers and patients have the right information available when needed
39% - Improved efficiency
37% - Improved quality

“What are the biggest challenges to achieving widespread health information exchange?” (Respondents were asked to select three)
61% - Funding and sustainability
53% - Interoperability standards
46% - Provider adoption
46% - Disparate electronic medical record systems
34% - Privacy and security

“How important is patient/consumer engagement to transforming healthcare?”
95% - Very important or Important
5% - Somewhat important

“What Health IT topics are of greatest interest to you?”(Respondents were asked to select all that apply)
60% - Interoperability standards
57% - Meaningful use
51% - Examples of HIE
49% - Health IT policy updates
49% - Healthcare reform
44% - Privacy and security

For a full reporting of the top survey results click here.

NeHC conducted the survey from February 13-17. The questionnaire was distributed to over 7,000 stakeholders with a response rate of 3 percent.

NeHC intends to use survey results and additional stakeholder feedback to inform its continued work with HIE, consumer engagement through the Consumer Consortium on eHealth, and with planning future NeHC University education programs.

Source: NeHC News Release

Friday, February 24, 2012

ONC, CMS Release Meaningful Use Proposed Regulations; Public Comment Requested

The Department of Health and Human Services released two notices of proposed rulemaking (NPRMs) related to Stage 2 Meaningful Use: the Medicare and Medicaid EHR Incentive Programs that detail proposed expectations for providers and the Standards & Certification Criteria (S&CC) that delineate proposed requirements for certified EHR products.

The announcement of the second stage of the three stage process, reflects the desire to create ambitious, but achievable goals that enable eligible professionals and hospitals to make incremental progress in adopting and implementing electronic health records (EHRs). The three stages are:
- Stage 1 (which began in 2011 and remains the starting point for all providers): "meaningful use" consists of transferring data to EHRs and being able to share information, including electronic copies and visit summaries for patients.
- Stage 2 (to be implemented in 2014 under the proposed rule): "meaningful use" includes standards such as online access for patients to their health information and electronic health information exchange between providers.
- Stage 3 (expected to be implemented in 2016): "meaningful use" includes demonstrating that the quality of health care has been improved.

The proposed rules focus on using EHRs to improve health and health care while reducing the burden on physicians and hospitals where possible. CMS' proposed rule would specify the Stage 2 criteria that eligible providers must meet in order to qualify for Medicare and/or Medicaid EHR incentive payments. It also would specify Medicare payment adjustments that, beginning in 2015, providers will face if they fail to demonstrate meaningful use of certified EHR technology and to meet other program participation requirements. In addition, as announced in a November 2011 "We Can't Wait" announcement, Stage 1 has been extended an additional year for providers who attested in 2011 – meaning that these providers will have to attest to Stage 2 in 2014, instead of in 2013.

The proposed rule announced by ONC identifies standards and criteria for the certification of EHR technology, so eligible professionals and hospitals can be sure that the systems they adopt are capable of performing the required functions to demonstrate either stage of meaningful use that would be in effect starting in 2014. Together, these rules will encourage even more providers to participate and support more coordinated, patient-centered care.

The NPRMs represent proposals; public comment is open for 60 days after publication in the Federal Register. Final rules are expected to be released this summer.

For more information on the Stage 2 Meaningful Use NPRM, visit www.healthit.gov/providers-professionals/meaningful-use-stage-2.

Source: HHS News Release

Tuesday, February 21, 2012

HIE Set to Expand

Electronic Health Information Exchanges that allow the secure sharing of patient health information between providers is set to grow considerably in coming years because of new service and payment models that are being adopted said panelists at a recent Brookings Institution presentation.

Policy Megachange and Health Information Exchanges featured panelists Janet Marchibroda, Chair of the Health Information Technology Initiative of The Health Project at the Bipartisan Policy Center; John Piescik of the Strategy and Engagement Center Center for Transforming Health at The MITRE Corporation; P. Jon White, Director Health IT and Acting Director, Center for Primary Care, Prevention and Clinical Partnerships Agency for Healthcare Research Quality (AHRQ); and Claudia Williams, Director of the State Health Information Exchange Office of the National Coordinator (ONC) U.S. Department of Health and Human Services (HHS).

Panelists agreed that HIEs would expand. “[O]ur goal is to get information moving to
support patient care in a secure way," said Claudia Williams of ONC. "Our goal is not necessarily to support a particular model or particular approach, but to see the percentage of transitions that are supported by the information that's needed, of lab results going to doctors electronically and of patients able to get their own information. We need to see these measures really take
off.”

"We've got a business case on the horizon with payment reform and delivery system
reform and for the first time talking with a whole host of folks that maybe weren't there 2 years ago," agreed Janet Marchiboda. "...whether it's providers, physician practices, hospitals, labs or vendors, I see an appetite for coming to agreement around a set of policies and standards. We'd have to talk about how far down you go, but principles and policies for getting to exchange even
on a voluntary basis that could be something that could inform what the federal government adopts over the long-term."

The Brookings Institution released a paper called Health Information Exchanges and Megachange in conjuction with the presentation.

Additional information about the presentation, including an audio webcast of the presentation may be accessed here.

Source: CQ HealthBeat (subscription required)

Friday, February 17, 2012

HHS: Progress With HIT

The U.S. Department of Health and Human Services’ (HHS) Secretary Kathleen Sebelius announced the number of hospitals using health information technology (IT) has more than doubled in the last two years. She also announced new data showing nearly 2,000 hospitals and more than 41,000 doctors have received $3.1 billion in incentive payments for ensuring meaningful use of health IT, particularly certified Electronic Health Records (EHR).

Secretary Sebelius is in Kansas City, Missouri visiting Metropolitan Community College-Penn Valley Health Science Institute to make this announcement and discuss the growth of professional jobs in the health information technology field.

“Health IT is the foundation for a truly 21st century health system where we pay for the right care, not just more care,” said Secretary Sebelius. “Health care professionals and hospitals are taking advantage of this unprecedented opportunity to begin using smarter, new technology that improves care and creates the jobs we need for an economy built to last.”

The announcement details information from a new survey conducted by the American Hospital Association and reported by the HHS Office of the National Coordinator for Health IT which found that the percentage of U.S. hospitals that had adopted EHRs has more than doubled from 16 to 35 percent between 2009 and 2011. And, 85 percent of hospitals now report that by 2015 they intend to take advantage of the incentive payments made available through the Medicare and Medicaid EHR Incentive Programs.

The announcement also highlights new data from the Centers for Medicare & Medicaid Services (CMS) detailing $3.12 billion in incentive payments the agency has made to physicians, hospitals, and other health care providers who have started to meaningfully use EHRs to improve the quality of patient care. In January alone, CMS provided $519 million to eligible providers. EHR incentive payments can total as much as $44,000 under the Medicare EHR Incentive Program and $63,750 under the Medicaid EHR Incentive Program.

According to the Bureau of Labor Statistics, the number of health IT jobs across the country is expected to increase by 20 percent from 2008 to 2018, a pace much faster than the average for all occupations through 2018. In conjunction with her announcement, Secretary Sebelius will tour the Penn Valley Community College Health Science Institute, which trains students for careers in this growing industry. She will also participate in a roundtable discussion with Community College leaders, students training in the health IT field, health care providers, patients and area employers about the importance of health information technology training in both improving patient outcomes and creating jobs.

The Obama administration provides financial support to eligible health care professionals and hospitals to make the switch to health IT and certified EHRs through the Medicare and Medicaid EHR Incentive Programs. These programs are funded by the HITECH Act provisions of the 2009 Recovery Act. The administration has also created a nationwide network of 62 Regional Extension Centers to provide technical guidance and resources to help eligible health care providers participate in the EHR Incentive Programs and meaningfully use certified EHRs.

To meet the demand for workers with health IT experience and training, the Obama Administration has also launched four workforce training programs. Training is provided through 82 community colleges and nine universities nationwide. As of January 2012, over 9,000 community college students have been trained for health IT careers and another 8,706 students have enrolled. And as of February 2012, participating universities have enrolled over 1,200 students and graduated nearly 600 post-graduate and masters-level health IT professionals, with over 1,700 expected to graduate by the summer of 2013.

Two other workforce training programs have resulted in the development of a health IT workforce curriculum and a health IT worker competency examination. The health IT workforce curriculum offers colleges and universities in all 50 states innovative health IT teaching materials at no cost to instructors. And, since its release in May, 2011, over 2,000 individuals have taken the HIT Pro Exam, a competency examination designed to show employers that job-seekers have attained a proficient level of knowledge and skills in health IT.

Health IT can help keep information private and secure. In addition, federal laws require key persons and organizations that handle health information to have policies and security safeguards in place to protect health information—whether it is stored on paper or electronically.

For more information on how health IT can lead to safer, better, and more efficient care, visit http://www.healthit.gov/

For more information about the Medicare and Medicaid EHR Incentive Programs, see http://www.cms.gov/EHRIncentivePrograms

For more information about the HHS Recovery Act health IT programs see http://www.hhs.gov/recovery/announcements/by_topic.html#hit

Source: HHS News Release