HHS OIG Establishes Final Rule for Information Blocking Enforcement 

On July 3, 2023, a final rule establishing the penalties for information blocking, which according to the HealthIT.gov site refers to practices that are “likely to interfere with the access, exchange, or use of electronic health information (EHI),” was published in the Federal Register. The final rule will primarily be enforced by the Department of Health and Human Services Office of Inspector General (HHS OIG) through a complaint-driven investigation process that can result in civil money penalties (CMPs) of up to one million dollars per violation. The entities currently subject to such penalties include health IT developers of certified health IT, entities offering certified health IT, and health information exchanges and health information networks, but not health care providers. 

COMPLAINTS 

The filing of a Complaint can be performed by “all sources,” according to a website set up by HHS OIG that enables online filings and provides information concerning an agency Hotline. HHS OIG states that it receives a “high volume of complaints,” and that not every submission will result in an investigation. Although not required to disclose their identity, individuals who file complaints are required to provide information concerning the individual or business related to the complaint, a narrative explaining the activity in question’s nature, scope and time frame, and information concerning individuals who might be capable of corroborating the allegations being reported. 

ASSESSMENT 

HHS OIG says that complaints will be assessed based on “enforcement priorities,” which according to the preamble of the final rule are anticipated to be the same as those initially set out in the prior proposed rule.  

However, the agency states that such enforcement priorities are “not dispositive,” and that each allegation must be assessed individually. Factors OIG says it may consider include the following: 

  • The volume of claims relating to the same (or similar) conduct by the same actor; 
  • Patient harm that is “not specific to individual harm, but … may broadly encompass harm to a patient, population, community, or the public;” 
  • Instances where actual knowledge is present, although the agency states that information blocking can occur absent this; and 
  • Instances of information blocking that are related to “anti-competitive conduct or unreasonable business practices.”  

As to entities who receive grants or have contracts or other agreements with HHS, CMPs can be issued for such things as “knowingly presenting or causing to be presented a specified claim … that a person knows or should know is false or fraudulent,” and “failing to grant timely access, upon reasonable request, to OIG for the purposes of audits, investigations, evaluations or other statutory functions of OIG,” in relation to the grants, contracts, or other agreements.  

In the preamble of the final rule, HHS OIG states that it anticipates coordinating closely with the Office of the National Coordinator for Health Information Technology (ONC), which may “serve as a technical consultant,” and also notes that the 21st Century Cures Act identified ways for it to coordinate on information blocking claims with the Department of Health and Human Services Office for Civil Rights (HHS OCR). 

ENFORCEMENT 

Entities 

First, it should be noted again that the final rule does not address “OIG investigations of potential information blocking by healthcare providers,” with it being stated that HHS is “developing a separate notice of proposed rulemaking to establish appropriate disincentives” for such entities.  

As to the entities that are covered, a “Health IT developer of certified health IT” refers to an individual or entity, other than a health care provider that self-develops health IT for its own use, that develops or offers health information technology (as that term is defined in 42 U.S.C.300jj(5)) and which has, at the time it engages in a practice that is the subject of an information blocking claim, one or more Health IT Modules certified under a program for the voluntary certification of health information technology that is kept or recognized by the National Coordinator pursuant to 42 U.S.C. 300jj-11(c)(5)(ONC Health Certification Program). 

A “health information network or health information exchange” is defined as “an individual or entity that determines, controls, or has the discretion to administer any requirement, policy, or agreement that permits, enables, or requires the use of any technology or services for access, exchange, or use of electronic health information among more than two unaffiliated entities that are enabled to exchange with each other; and [t]hat is for a treatment, payment or health care operations purpose, as such terms are defined in 45 CFR 164.501 regardless of whether such individuals are subject to the requirements of 45 CFR parts 160 and 164.”

Determination of CMP Amounts 

The final rule states that “determination of the CMP amounts shall consider factors such as the nature and extent of the information blocking and harm resulting from such information blocking including, where applicable, the number of patients affected, the number of providers affected, and the number of days the information blocking persisted.”  As noted above, CMPs may not exceed one million dollars per violation. 

Agencies Involved in Enforcement 

It should be noted that an individual or entity that meets the definition of health IT developer of certified health IT could be subject to enforcement efforts from both HHS OIG and ONC. As is noted in the final rule, “ONC has the authority to take action against an individual or entity that is a developer participating in the ONC Health IT Certification Program,” and “OIG has authority to impose CMPs against a health IT developer of certified health IT, which includes developers participating in the ONC Health IT Certification Program.” Such overlap allows not only CMPs, but potential termination of certification or other action under ONC’s program.  

Additionally, both HHS OIG and ONC can coordinate with the Federal Trade Commission (FTC), when information blocking claims involve or are related to anti-competitive conduct.  

According to the Document Details of the final rule, the effective dates of the rule listed are August 2, 2023, and September 1, 2023. 



Categories: DATA ACCESS & INTEROPERABILITY

Leave a Reply

Discover more from Digital Healthcare Law

Subscribe now to keep reading and get access to the full archive.

Continue reading