AHLA's Speaking of Health Law
The American Health Law Association (AHLA) is the largest nonprofit, nonpartisan educational organization devoted to legal issues in the health care field. AHLA's Speaking of Health Law podcasts offer thoughtful analysis and insightful commentary on the legal and policy issues affecting the American health care system.
AHLA's Speaking of Health Law
Information Blocking Enforcement on the Horizon: Compliance Under the 21st Century Cures Act
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
HHS has been implementing rulemaking related to information blocking since the passage of the 21st Century Cures Act a decade ago, and providers have taken note. Dennis Sapien-Pangindian, Founding Attorney, DSP Advocates PC, and Ammon Fillmore, Associate Chief Legal Officer for Information & Technology, AdventHealth, discuss what information blocking is and why it has become a real enforcement issue, the legal framework and compliance risks, the status of OIG enforcement, provider implementation and operational considerations, and compliance readiness. Dennis wrote an AHLA Briefing on this topic. From AHLA’s Fraud and Abuse Practice Group.
Watch this episode: https://www.youtube.com/watch?v=VncxN4TXIgI
Read Dennis’ Briefing: https://www.americanhealthlaw.org/content-library/publications/briefings/4e306a62-dd7b-449d-b143-b64a163a9c5d/Information-Blocking-Enforcement-on-the-Horizon-Co
Learn more about AHLA’s Fraud and Abuse Practice Group: https://www.americanhealthlaw.org/practice-groups/practice-groups/fraud-and-abuse
Essential Legal Updates, Now in Audio
AHLA's popular Health Law Daily email newsletter is now a daily podcast, exclusively for AHLA Comprehensive members. Get all your health law news from the major media outlets on this podcast! To subscribe and add this private podcast feed to your podcast app, go to americanhealthlaw.org/dailypodcast.
Stay At the Forefront of Health Legal Education
Learn more about AHLA and the educational resources available to the health law community at https://www.americanhealthlaw.org/.
This episode of AHLA Speaking of Health Law is brought to you by AHLA members and donors like you. For more information, visit americanhealthlaw.org.
SPEAKER_01Hello, everyone. Welcome to the podcast. My name is Dennis Sapian Pang and Dian. I am the founding attorney at DSP Advocates. And I'm here today to talk with you all about a briefing that I had written for the AHLA's fraud and abuse practice group. The title was Information Blocking Enforcement on the Horizon: Compliance Considerations under the 21st Century Cures Act. A nice, easy breezy title by uh a very lawyerly short title. Uh uh and with me today I have uh Amin Fillmore. Um and uh Amin, would you like to introduce yourself?
SPEAKER_03Yeah, Dennis, thanks for letting me join you today on the podcast. And uh again, uh this is something that I'm passionate about. You and I have had conversations about this for a number of years now. But uh I'm Amin Fillmore, I'm the Associate Chief Legal Officer for Information Technology for Advent Health, a nonprofit health system that operates across nine different states in the US. And suffice us to say, this is something that we have been watching for a number of years and working through. So it's exciting to be here and join you again. Uh, before we jump into it, I just want to offer a quick disclaimer, right? Obviously, Dennis and I are both attorneys. Uh form any type of attorney-client relationship, as well as uh on my part, the opinions that I may express, those are my own and not necessarily representative of Advent Help. But uh Dennis, and unless you've got anything else, you want to jump into it?
SPEAKER_01Sure, definitely. Um, I mean, I'm thinking that maybe we can start with just the the the basics, right? Like what is information blocking? Why should we care about it? All that stuff. And then uh, you know, like I said, I'm really happy that you're here because uh I think you can have really good on the ground, uh really good on-the-ground perspective on this. Um, so you know, I I think we could just probably take it back from the beginning, right? Uh information blocking. What 10 years? Yeah.
SPEAKER_03Like it's hard to think about that, but it was literally like we've been dealing with information blocking for 10 years, um, in in some form, or the rule and the discussions predate that. But like boy, boil it down for us, right? Um, there's so many crevices, but like at a fundamental level, walk us through, Dennis. What what's what's information blocking?
SPEAKER_01Sure. It's so information blocking as defined by the 21st Century Cures Act and the regulations, it generally means any practice that is likely to interfere with the what is it, access exchange or use of electronic health information, EHI. Now, uh it impacts different types of actors, and we can kind of get into that because uh depending on how you're defined as an actor, just different standards of intent that's applicable to them, right? That the government has to prove in order to show a violation. Uh, but you know, it's generally meant to capture uh, you know, you know, back in what is it, 2015, uh the Office of the National Coordinator for Health IT wrote a report for Congress uh outlining what this conduct is. They essentially said there's these these health IT developers and and and actors out there that are actually inhibiting the the exchange of of EHI because what we really want, right, is an empowered uh uh patient population to be able to control their EHI, I guess. And and but you know, for various anti-competitive reasons that that ONC laid out, there's various practices there that that try to stymie that. Um yeah.
SPEAKER_03So okay, but this is where I think a lot of sometimes the you know attorneys stumble on. Like, why did we even need information blocking? We have HIPAA, right? So Health Insurance Portability Act 1996, right? As amended, we get the high-tech act. We are already sharing information, correct? I think a lot of folks went, why do we even need, or why did Congress believe that we needed information blocking? Because we were already sharing or information sharing can happen, right? So what why why did they bring in info blocking on top of HIPAA?
SPEAKER_01Sure. I mean, I it goes back to the advancement uh uh and adoption of EHR technology, right? Uh sure you can get access to your medical records and and there is some overlap. There is potential overlap, right, between a HIPAA violation and uh information blocking violation that you could potentially see that happening. And actually, the 21st Century Cures Act has built-in provisions there where you know, if there's a clarification that the Office of Civil Rights for HHS can can clean up for people, then you know, OIG or the regulators can defer to them to do that. Uh but it with the adoption of EHRs, you can imagine that there's, you know, think of it as, and not to knock any brands out there, but think of it as like the Apple ecosystem, right? Like it actually makes it very difficult to transfer to Android sometimes uh when you're switching phones or different models or things like that. So in the same way, uh you can imagine that there's patients that may be captive to specific providers or specific entities because they it's difficult to get their electronic health records uh transferred over, uh regardless of the HIPAA laws notwithstanding, right?
SPEAKER_03So uh I think that this is like you're telling me we got to put up with blue bubbles and green bubbles on text messages. That's so we we we have to interoperate. Like that's uh I love the the example of Apple. And I use Apple. Um I have family members that are on Android, right? But but what I'm hearing is right, uh the idea of information blocking was sorry, it doesn't matter that you're on different tech platforms, we're gonna essentially uh prod with carrots and sticks to find ways to make sure that blue bubbles and green bubbles can both uh you know uh coexist interoperably.
SPEAKER_01Exactly, right. And I I mean I bully my oldest brother to death about being the only one in the family who uses Android. And so uh I'm not being sponsored by the colour. Anywhere, but um but that's exactly the point, right? We we i we we believe it's in in the at least the government believed and Congress believes that it's in the public's best interest to have the adoption of EHR, but also the the interoperability of EHR.
SPEAKER_03So yeah, well, so you mentioned earlier, right? So we've got different actors to whom information blocking applies. And I think a lot of folks are familiar in the HIPAA world with covered entities, right? So we have obviously healthcare providers, health plans, and then right, we we have the the clearing houses. Info blocking is a little different though, right? Like we've got different sets of actors, and you outlined this really well in the the the argument in your your article around who is an actor. It uh those those aren't one and the same, right? Like HIPAA deals with covered entities, but then we have this new world of actors under information blocking, not one and the same. So who's information blocking is going to apply to whom? Who who are the people that really need to right now write uh you know, hit hit pause and then potentially hit record on this to say, great, uh who are actors and and who has to comply with info blocking?
SPEAKER_01Great, yeah, that's a that's a great question. So uh you have first and foremost, you're health IT developers of certified EHR technology, right? When I say certified, I mean certified by HHS Office of the National Coordinator for Health IT slash the assistant secretary for uh uh you know, all that stuff.
SPEAKER_03It's an evolving name, right?
SPEAKER_01Exactly, yeah.
SPEAKER_03They're trying on different things, they're trying different, it's it's good, right? They exactly they're they continue to to to grow, like uh, you know, genuinely, yeah.
SPEAKER_01We love our alphabet soup in in the government, right? And so uh so health IT developers of certified EHR technology, health information exchanges, health information networks, HIEs, H INs, and also healthcare providers at large. Um, and there's uh uh uh you know uh yeah, so those three actors are implicated, I guess, by the information blocking rules. But I think the best way to think about an actor is within two buckets, right? Uh especially when it comes to information blocking enforcement.
SPEAKER_02Yeah.
SPEAKER_01Uh are you subject to a civil monetary penalty or are you subject to what's called provider disincentives, right? So developers, HINs, HIEs, they can be subject to up to a million dollars per violation. Uh and and healthcare providers, though, uh, they can, as you know, if they're just a healthcare provider and they've committed information blocking, the Office of the Inspector General can refer them for what's called provider disincentives. So they take various forms, right? They could be uh penalized uh by uh uh uh being prohibited from participating in an ACO or having your MIP score uh uh uh affected, uh things like that. So um it's a little uh uh less toothy, uh, but it's really meant to utilize the structures that are already in place to disincentivize information blocking by providers. I think what's important though to note though, is that if you're a healthcare provider, that doesn't mean you cannot be a developer or an H I N or H I E. And we can talk about that.
SPEAKER_03Right. No, that's that is such a good point. It's not an either or. It's very possible for you to be a healthcare provider, and especially right, it's a question that that in my current role that I'm always looking at and going, okay, uh, when someone comes and makes a request from uh uh for EHI, right, uh, what hat am I wearing? Right, depending on whether we are potentially making available certain technology, right? Um, whether we have control of that technology, that it's not a right out of the gate. Well, because I build Medicare and Medicaid and have an NPI and meet the statutory definition of a healthcare provider, that I'm always going to be uh a healthcare provider. And so it really requires that that careful analysis because again, uh a million dollars per fine or you know, per per instance. And I mean, have we gotten I you know, there's still a lot of moving pieces around this. Have we gotten clarity around that really? Like so when they say a million dollars, is it for every single record, right? Or every single time somebody makes a request, or is it holistic, right? I know I'm kind of jumping to the enforcement side of it, but but you you you raise the issue of civil monetary penalties being a million potentially a pop. That that that gets attention pretty quick.
SPEAKER_01Sure. It's so it's up to a million dollars. I think that's the first thing. Um, and and uh, you know, when we uh so I uh background for me, I used to actually be in the inspector general's office and I worked on these rules. And I remember when we were considering how to apply these penalties, you know, you could imagine uh uh, you know, these things either stacking up or if there's a whole range of conduct, then a million bucks could just be a uh uh um, you know, the the price of the cost of doing business sometimes that people will just factor in. So the depending on how they apply uh the million dollars per violation can have a significant impact. Unfortunately, we don't have any examples of enforcement activity, but what we do have is uh OIG's stated enforcement priorities, right? What they're gonna look at. And we also have the factors that come into play when they are applying CMPs. And those are very similar to the same actors if you're ever familiar with OIG CMP authorities generally, it's pretty much the same type, right? So factors that OIG considers the nature and duration of the conduct, you know, the level of intent, the harm actually, the harm it caused, uh, whether the it was a pattern or a practice or just a single instance. And uh to the extent of, you know, during the investigation, whether or not uh a target or defendant was uh cooperative or taking any uh remedial measures. So that's that's generally what OIG considers with applying when applying CMPs across the board, and that's not gonna be any different here. Um yeah.
SPEAKER_03So I'm gonna follow that up with another question because right, help lawyers uh I feel like you know, there's a there's the old joke, right? Of uh, you know, what the two things that are certain, right? Death and taxes. Help lawyers, I think, add a third category to that, and that's Stark, right? Like we're always uh it's always something that we're thinking about, right? Andy, kick back in Stark. Um so when you listed, you started talking about like OIG enforcement priorities, that leads my mind to kind of go towards uh we're really not in the same rounds as Stark where they're not looking, you know, where where it's a strict liability, right? Uh is is intent not only right it there's a side of intent, and it and you're right that it's a gets a little bit more nebulous, but from like a high level, is intent part of the rubric for information blocking, or is it basically look, strict liability? If you do it, you're do it. You're you know, uh potentially you're in you're in penalty territory.
SPEAKER_01Yeah, for for health lawyers that are in the lingo, right? I I think the best way to think about this is it's most more it's most analogous to the anti-kickback statute, more so than a Stark law. It's not uh a strict liability uh issue. And this is also where the type of actor you are determines uh the level of intent that's required by the government to prove. So if you're a health IT developer, if you're an H I N, if you're an HIE, uh the practice that you you're allegedly engaging in, if that actor knows or should know that their practice interferes with the access exchange or use of EHI, then they could be that's a violation, right? But for healthcare providers, there's a higher level of uh uh knowledge and uh uh there's a higher standard of knowledge that needs to be applied. They have to actually know that this practice uh uh interferes with the exchange of EHI. And I think that was meant to capture the fact that healthcare providers, their primary concern is to be a healthcare provider. They're they're they're taking care of patients, they're not health IT developers, you know, and and again, this goes back to thing. What are you? What are you doing? What hat are you wearing? And uh as a provider, you know, we want them focused on patient care. But developers, HINs, HIEs who are well versed in that space, they have a a lower burden of proof for the government to prove because you know they should know better, is effectively is what Congress is saying.
SPEAKER_03Um you use the great example of the anti-kickback statue, and I think that that fits really well, right? So just to kind of summarize and make sure, right, our our uh our listeners are tracking. So we're really not in a strict liability perspective. Um, it's more on terms with AKS, right? Automatically, my brain goes to well, right, so safe harbors, right? Yeah, we have safe harbors, right? They they you know, they they the you know they're they call them exceptions, right? Safe harbors. Uh you do a great job in the article of kind of starting to list them out. But um, and then and I should add that it's not a static list, right? We keep seeing new exceptions emerging, right? Uh, I hate to go back and use the example, walk back to start, but you look at what's start one to two to three, 3.5, etc. I'm not even sure where we're at now. We see evolution in these exceptions, but uh kind of walk me through some of those, or I guess our listeners. We've got our exceptions. Uh do I have to be in an exception to not be info blocking?
SPEAKER_01Uh no. Uh so this is where you know yeah. So the analogy, right? Like the government still has the burden of proof of showing a violation is actually occurring. So you can also get as close as possible to an exception or you know, make a defensible argument, but you know, the government still needs to demonstrate knowledge. I think that's where you can fall back on. Um, and and and so just because you don't naturally fit with an exception, the government still needs to prove an underlying violation, first and foremost. And whether or not the OIG uses its enforcement discretion to go after a case based on the facts at hand, that's gonna be up to OIG. You know, I think every year we've seen HHS put in its budget a request for authority to issue advisory opinions, um, much like how OIG does, right? To various, you know, kickback type scenarios. And uh I to date they haven't been given that authority. Uh, but uh if and when they do, I think again, it's gonna be very analogous to AKS in and how it's enforced, how we can get guidance as to what we can or cannot do in our practices. So yeah, and the only thing that throws off this analogy is that they use information blocking exceptions as opposed to safe harbors. But you know, uh, but think of it as a safe harbor.
SPEAKER_03Yeah, no, you're you are you're you're spot on with that, right? Because I think that there are some parts, and this is with any law, right? But there's parts of information blocking, right, where I think that it's it's pretty clear and it's it's fairly well established, you know, and there's very there's clean definitions. There's other areas, and it's not a critique, but there's a lot more ambiguity in there, right? So for example, uh you often see in the information blocking rules and well, the regulations talking about a request for electronic health information, right? There's not like a clean line item, hey, here's the definition, capital R for request, right? And so there's been lots of conversations over well, what constitutes a request for electronic health information? And you know, and it's one of those where I I I certainly don't have a singular definition other than you know, the way that I I've tried to approach it is what what's the spirit and the intent of the information blocking rules, right? So um, you know, there there's lots of different ways that you could probably try that we can articulate what's a request. But at the end of the day, I mean it's really one where it could be something as straightforward as look, a patient wants to access their records in a patient portal. I, you know, I think that the the industry has kind of collectively landed on and said, yeah, that that's a request. Uh APIs, right? An API call wanting to say, right, I want to connect my platform to your platform. I want to be able to make a request for EHI over that. But there's not like just a singular checklist of here's all the different ways that somebody can request information, right? And I think that that's where it becomes this constant effort of trying to stay ahead of the technology of how do people actually make a request for information.
SPEAKER_01Exactly. And and and I think this is where, in terms of the regulatory scheme, the analogy to AKS continues to apply. It's always going to be constantly updated based on new realities, based on new case scenarios, and as the the industry evolves itself, right? And so, um, and and and you know, uh, but it's really interesting because the reason I wrote this article, it was really to highlight OIG uh or HHS stating that they are, you know, this was in September of last year when they made the announcement that they were going to uh you know uh carry out a crackdown on information blocking, implement more resources. And actually, publicly you can see on OIG's website they're actually hiring more people right now in the in the council's office, specifically to the affirmative litigation branch and specifically for people with information or information blocking experience. So you could see they're they're starting to staff up.
SPEAKER_03And so is that hashtag HLA Career Center?
SPEAKER_01I know exactly, right?
SPEAKER_03Hashtag HLA Career Center, exactly.
SPEAKER_01Yeah, yeah. And so they are they're gearing up, and you know, these rules have been like you said, uh the statue came out in 2016, 10 years. We've been talking about this, yeah. And I feel like it's almost become like the second coming of crisis. When is enforcement actually happening, you know? And uh I think it's around the corner.
SPEAKER_03That's where it gets quirky, though, right? So um, and again, I you know, I I you know that this is a this is a total rabbit hole that that folks can can go down, right? But there's this kind of uh this you know interesting paradox of we technically have not seen any enforcement yet by the OIG, but yet there's probably I I'm just Going to ballpark this and uh folks can use Claude to fact check me later. Um, right, there's probably at least I I've been tracking, I think, at least six, seven different lawsuits where the information blocking regulations have been directly implicated, right? And uh intentionally I say this with no uh you know uh intent around one vendor is right, the other one is wrong or otherwise, but we're seeing litigation where, and it's often then commingled with antitrust claims or other tortuous business interference claims of saying vendors, HIT developers are saying they're leveraging information blocking laws to say, hey, you are tortuously interfering with my business. And so we've got by not connecting our systems, and so they're leveraging the information blocking laws as a potential hook for tort claims and other claims in state and federal courts. So it's it's one of those where yes, we haven't seen the OIG enforce anything yet, but there is no shortage of case law that's being developed around uh these cases. And I think it's it's important that folks be mindful of this because they're interpreting the exceptions, right? So we're not getting OIG issuing guidance and not a critique on them. They haven't brought an enforcement action, but we've got different state and federal courts that are interpreting what an exception may mean uh in relation to some of these vendor-v vendor cases.
SPEAKER_01Exactly. I think that's it's so interesting that we have judges going into this whole analysis. I don't know how much experience these judges have with health IT or just knowledge about the ecosystem. But uh and and I I I hate to beat this analogy to death, but kind of like the kickback statute, right? Like you could run into a scenario where the government states that one thing is a violation, but then judges, especially now with Chevron deference being gone, uh, judges are making a completely different interpretation. And uh it's I think something similar is on the horizon as well uh for information blocking, especially if OIG doesn't act soon and and have some precedent on the books.
SPEAKER_03Yeah. So I think that kind of goes to right. I mean, you counsel your clients on this. Um, I I talk with right with my health system and talk about this honestly, is it there's probably a week doesn't go by that I don't think about information blocking. And that's not just because I've been deep in this space, but it's one of those where anytime you're thinking about HIPAA, that's really the companion is if you're talking about HIPAA, then a lot of the time you're also talking or you should be thinking about what are the implications under information blocking laws. Because I'll tell you, one of the right, you and I have talked about this. Something that I think that there there becomes a bit of a an erroneous belief is thinking that information blocking authorizes you to share data when it otherwise wouldn't have been permissible, right? Like the commentary is really, really clear around this is like information blocking is not an affirmative defense for potentially sharing information, right? That you otherwise couldn't under HIPAA. And you know, an example where I keep seeing this come up is uh we're allowed to exchange electronic health information, right? There's a definition for that. Essentially, it's electronic information that's in the designated record set, right? Um, I'll see requests from uh outside law firms potentially looking at, you know, they're looking into medical malpractice claims or something similar, where they're go, they they will raise the issue and say, you have to provide me this information, you know, or you're in violation of the information blocking laws, and it's outside of what's considered EHI. And that's where it's been really interesting is to see is right, there's there's an erroneous belief, albeit you know, at times I don't think you know it's not intentional and being malicious for clarity, but it's like, no, this doesn't enable you to just share any information or compel to share in any information. It's pretty specific in what you're allowed to share.
SPEAKER_01Exactly. Yeah, and and you know, when I'm advising clients on this, and it's it's oftentimes it can be difficult again without further guidance or enforcement precedent, right? But when people are asking me, like, what do I do? What do I do? I go back to the seven elements of an effective compliance program and tailor it to your information blocking risks. So, I mean, uh, how are you sort of like operationalizing that on your end? Like from a provider perspective, like how are you looking at the thinking about these risks? How are you thinking about uh deploying uh resources to address them?
SPEAKER_03Yeah, it's so I think right out of the the the gate is it it requires a certain culture, right? And I think especially in those that have been around this, especially when information blocking really started to uh when the regulations went live, right? There was concern that all of this information was gonna get pushed out to patients. And is this gonna suddenly flood offices with concerned phone calls or others? And and I was one of those saying, hey, I that this potentially could be a problem, but I think right where we're a few years into it. Um I think patients have really gotten used to it, and it's almost now seen as hey, like we want this data, we want access to it. And I think it's really now very much we've tried to take an adopt the culture of, hey, patients have an expectation that they'll have visibility into this information. And so I think step one is hey, you really have got to go through and make sure that uh your administrative team, your IT team, your clinicians, that they understand that the intent of this is to not frustrate, but it's to actually really make this information uh available. And so I think that that's kind of step one, because if if if people can't buy into the idea that patients have the, you know, the the ability under HIPAA, a right to see this information, that that's gonna be like almost an insurmountable hurdle. You gotta build that that culture. And I think part of that then is is education, education and more education around it. Um, but I'll tell you, I think that one of the things that has really we've been trying to be very mindful of is it's not a one and done. Uh it's one of those where you you constantly are needing to keep this in mind. So to try and make more uh a more actionable point, right? So we talked about electronic health information. Electronic health information, right, is essentially PHI that's electronic, that's in the designated record set, right? Well, we've got a definition under HIPAA of the designated record set. We all know that there's uh, you know, uh there's a lot of latitude in that. Uh you know, fundamental question is I literally working on it this week is annually, I go back through and I look at our designated record set policy and say, what is in our what data elements are in our designated record set and what is outside of our designated record set and document it, right? So where because if I don't even understand what is EHI, and right, it's gonna be really hard for me if I get a request to be able to say, yep, that's gonna be subject to information blocking rules. This isn't. And so from a compliance perspective, uh you know, I I would encourage folks go back and continue on an annual basis, right? Part of your processes with your your compliance teams, your privacy teams, if you're a smaller office, right? Uh hopefully you're you're able to to to to have some resources that can help with that. Uh right, revisit that because you know, how often are we getting new types of data elements yearly? New types of data are being collected. And if you don't have a baseline of what's in and what's out of that designated record set, then you're automatically exposing yourself to, well, how do I know whether or not I can actually fulfill a request if I don't even have the inform, like if I don't even know what information you're potentially subject to it?
SPEAKER_01Yeah, it it just makes me think of, you know, know thyself, right? And right, yeah. And uh, but along that along that point, I'm just really curious because we talked about the two different buckets and the potential penalties or or disincentives. You you're at Advent Health, right? As a as a provider, though, how are you thinking about uh the risk that you may accidentally slip into the functional definition of a developer or an H I N H I. Um, how does that come across to your desk?
SPEAKER_03Yeah, so that's something that we think about, right? You know, in particular because it's you know, depending on the degree or the control that we may have in terms of acting as right, we're an epic community connect shop, right? In in those functions, um, whether or not, you know, we potentially, and there has been some guidance and some clarification around that, right? But I think it's one of those where we've taken a very proactive stance when we are starting to look at those situations is actively putting in the contract and having those level setting conversations with whoever we're we're contracting with, right? And documenting it, right? You talk about the seven effective elements of a compliance program, right? Going through and appropriately documenting, right, um, how we're addressing it, right? Understanding their concerns, and then hopefully trying to find ways to address it. Because I I think that a lot of the time when there's a request that comes in, uh it's rare that right out of the gate immediately, uh with probably the exception, right? I mean, it's the lion's share, play pay uh patient portals. But if someone's asking for information, it might take a couple turns of an email or a conversation to actually understand and level set. Like, I'm thinking that it's this, they're thinking that it's this, and we've got to have that conversation. And that really gets into that manner exception, right? Of hey, like, can we a lot of the time it's let's just sit down and talk real quick and level set what is your actual request and document that because if we're starting from different places, it almost always would end up in a point of frustration where you're going, well, that's technically infeasible when you haven't had that conversation to level set.
SPEAKER_01Right. And in terms of those exceptions, you know, uh you mentioned the manner exception. Is that pretty much like is that one of the the the what you anticipate being one of the largely used exceptions to justify practices in in your mind?
SPEAKER_03Yeah, I yes, right, because I think the manner exception really I see it as is probably the biggest like carrot and stick, right? It essentially says, look, if you guys can agree on uh a manner to do this, and you know, then then you're granted a lot of leeway, right? But if we can't agree on a manner, then there's kind of a a laundry list of different methodologies that you need to go through to make sure and see all the way down to potentially just doing a you know uh an XL, you know, EXL data transfer or STP file push for it, right? But it's one of those where again it's that level setting. And so I I think that manner exception is a big one. Uh I actually think another one uh that we're gonna see increasing issues around um is the security exception, because we right, we're we're entering this world of right. I I don't think that you can have an HIT podcast anymore and not use the word artificial intelligence, right? Right, right. But when we're gonna get into the world of where I can have automated agents that are potentially making requests, how that operates with the security and the privacy exception, right? Uh that's that's a whole new world that that we're getting into.
SPEAKER_01And like that's its own podcast right there.
SPEAKER_03I mean, oh yeah, so you and I have chatted about this. Like it's you know, uh, you know, I I simultaneously find myself cursing and applauding HIPAA because right, it's I mean, 1996, right, you know, early enactment, right, early 2000s, 2010-ish for high tech. It's held up remarkably well in its ability to to manage, but there's parts of it, right, that how it operates, right, with an individual access request or right, some of these others. We're in a whole new world with information blocking, HIPAA, and AI. So, right, my my mind trifts to how I saw the privacy and security exception in a pre open AI, pre-clawed, pre-agentic AI world. It's a little different now because, right. Um, I also think about to be honest, then, right, if you can suddenly make literally hundreds of thousands of API calls against my network uh to get data, like that takes a toll on our network, on resources, right? So we're we're in a whole new world where again, to your point is we're just having to constantly revisit this to comply with obviously the law, but the spirit and intent of the law. But then how do you do it in an increasing technologically challenging world?
SPEAKER_01Right. And and going back to I think your mention of of the manor exception and uh uh kind of working it out in a free market sort of environment, right? Um it just made me think like, how how are you, how is information blocking this regulatory scheme and all this, how has that impacted your interactions with vendors and and your vendor contracts and how you're reviewing them? Um how did how has that changed?
SPEAKER_03No, so that's no, that's a super good question because again, it it like it goes back to at a fundamental level, again, HIPAA, right? An HIT developer, right? Um, whether you're using eClinical works, you're using Epic, you know, Oracle Health, whomever you know it it may be, they're your business associate. And the the commentary in the original information blocking uh regulations is it's pretty clear that a business associate can't act outside of the scope of the authority that you as a covered entity have granted to that business associate. And so it's something, and it's in a conversation that that we have with those entities who qualify as an HIT developer, whether or not, right, they may be creating a tool that enables this, but that's very different from us saying you're helping us to have a tool to enable us to comply with information blocking versus we are empowering you to essentially act on our behalf to exchange that information. And so we we try to be very mindful that you know, as the covered entity, the burden is on us to make sure that we're appropriately, you know, for protecting it. So because again, right, it's not and I'm I'm not getting the the it word for word, but it's pretty clear in the commentary information blocking is not an affirmative defense to a HIPAA violation. And so it's a really fine line that we have to continue to walk with our HIT developers and our HIEs to make sure that uh right we are we're we're staying in the appropriate swim lanes, right? And just to kind of give you another example where it comes into play with state laws, right? So we're across nine different states. Different states have more restrictive privacy laws than than HIPAA, right? So take for example, Texas has laws around uh release of lab results uh regarding uh you know HIV tests, right? Not something under law that we just automatically push to the portal, right? Right for really good reason. And so it's one of those where when we're doing deployments, we're going through and we're really thinking and talking with our HIT developers to make sure that, okay, do you have the ability for us to potentially and permissibly throttle certain data elements from getting pushed, right? Because we've got more restrictive state state laws, right? Or miners or all of these others. And so there's a lot of technical questions where I would encourage you know the attorneys out there, dig in with the technology teams, have those conversations with the vendors, because we're often the ones that are in the best position to understand how those data elements can or can't be shared.
SPEAKER_01Those are all great points. You know, there's there's just so much to to consider and and uh and and and you know, so let's say someone is, oh, you know, they read the article, they hear this podcast, they're like, oh no, enforcement is around the corner. I haven't thought about information blocking at all because I didn't know what it was and there was no enforcement happening. So, like, if you're just getting out of the gate on this or getting caught up on this, where where would a a covered actor start?
SPEAKER_03That's that's a good question. So I'm biased as a covered actor, I'm gonna go with healthcare providers, right? Um, I think that you you first take a look at practically where the vast majority of I think requests or the lion share really are coming in or your patient portal. And so I think it's really going and looking at and saying, what's the inventory of how you know patients or requests are coming in? Right. So if you've got a patient portal, it's going through and starting to look and say, hey, am I getting this out or am I, you know, withholding information unknowingly and really kind of doing that diligence check? And then I think the other side of it is really going through and and starting with and having that inventory of what information do I have and what information can I share? I I think again, it starts off at that fundamental level is dust off that designated record set policy and understand what's in and what's out of your what's out of that policy.
SPEAKER_01Definitely. Yeah, and I think uh we're we're about coming up on time, but I really do appreciate having these conversations with you.
SPEAKER_03I mean, I think that you give such not our first, not our last, Dennis. Exactly.
SPEAKER_01You give such a valuable insight every single time I talk to you, and it's something new for me to think about. And uh yeah, this has just been something I think that we've been living and breathing for the past few years, but I don't think many health lawyers have been. Uh, and I I just think that that's gonna change uh very, very quickly.
SPEAKER_03Um yeah, and I think right, and is a final thought, right? I mean, it's something you and I have talked about is right, is we I I think it's important that our our attorney friends, you know, within the HLA community, right? Um, that that they're they're bringing in the right people that understand this and that they're recognizing that these issues really aren't just for the the the you know the wonky IT lawyers like myself that that sit down in the legal nerdery, right, thinking about this, right? You're doing MA work, you need to understand information blocking. You're you're doing a practice group acquisition, right, or a purchase agreement, you gotta understand where information blocking comes into this. You're doing software vendor purchases, like you mentioned, you know, you you know, information blocking comes into play. And so I sure appreciate the time we've spent together literally talking about going through and saying information blocking has a way of finding its way outside of the immediate of IT issues. And suddenly, you know, uh you're talking about was the diligence done for information blocking, you know, in an asset purchase agreement. And I think that the answer now is you've got to do it. So yeah, you uh we're gonna keep having these conversations.
SPEAKER_01Definitely. Well, well, thank you again for your time and just being a part of this podcast. Uh, for all you listeners, uh, refer you back to the the briefing by the the fraud and abuse practice group, information blocking enforcement on the horizon, compliance considerations and the 21st Century Cures Act. And uh, Ammon, thank you so much. Really appreciated it.
SPEAKER_03Likewise, Dennis, always a pleasure. And uh we'll talk soon. Thanks to all our listeners.
SPEAKER_01Thanks, y'all.
SPEAKER_00If you enjoyed this episode, be sure to subscribe to AHLA Speaking of Health Law wherever you get your podcast. For more information about AHLA and the educational resources available to the health law community, visit AmericanHealth Law.org. Stay updated on freaking healthcare. Stay up on Facebook Media, AHLA Health Law.