Language Selection

Get healthy now with MedBeds!
Click here to book your session

Protect your whole family with Orgo-Life® Quantum MedBed Energy Technology® devices.

Advertising by Adpathway

         

 Advertising by Adpathway

Understanding TEFCA Oversight: New Measures and Implications for Healthcare Data Exchange

4 days ago 18

PROTECT YOUR DNA WITH QUANTUM TECHNOLOGY

Orgo-Life the new way to the future

  Advertising by Adpathway

Recently, the Office of the National Coordinator for Health Information Technology (ONC) at the U.S. Department of Health and Human Services (HHS) announced new oversight measures for the Trusted Exchange Framework and Common Agreement (TEFCA), which has now facilitated the exchange of more than 1 billion health records.  

Healthcare Innovation spoke with Melissa Soliz, an attorney and partner specializing in Health Data Privacy, Interoperability, and Technology at Phoenix-based Coppersmith Brockelman PLC, to learn more about what these updates mean for healthcare providers and payers.

Could you walk me through the new oversight measures for TEFCA?

There are a number of new oversight measures that are in the works right now. Earlier this month, the administration announced that there's going to be a third-party auditor. They have tapped Alliance Global Tech to provide auditing, review, and compliance support. The idea is that they're going to be a neutral third party who's going to come in to essentially verify that the Qualified Health Information Networks (QHINs) and other participants and sub-participants are following the rules of the road for TEFCA for health information exchange.

The whole reason why this is happening now is really a direct reaction to some of the interoperability litigation. We have a lot of the QHINS….essentially suing each other. Some are alleging fraud, others are alleging information blocking behavior. TEFCA created this framework. We're all saying we agree to do these things. And we're all signing contracts saying we're going to do it and follow these standard operating procedures. But the reality is that it just creates a trust framework. There's no verify. That's what this auditor is supposed to come in and do. It's to create that verification so that the trust is validated for our data suppliers, so the providers that are sharing the data, so that there can be some sense that there's no fraud occurring on the network. Or if there is fraud occurring on the network, it's going to get rooted out. What this auditor is supposed to be doing is, if they find conduct that amounts to fraud or information blocking, they're to route it to the appropriate government authority.

My understanding is that this third-party auditor is just providing that independent review. The way TEFCA is set up right now, with its governance structure and these QHINS, participants, and sub-participants, is that they have different caucuses. You have direct competitors monitoring each other. You can see the problems that are created when you have direct competitors monitoring each other or responsible for auditing each other. Then you also have this issue of making sure that people follow the rules, because if one person is loosey-goosey with the rules and you're a competitor, what are you driven to do?

Could you tell me what these updates mean for healthcare providers and payers? What are some of the legal implications?

TEFCA, the Trusted Exchange Framework and Common Agreement, is essentially paper. It's an idea that's expressed in contracts and standard operating procedures. It is all voluntary. None of this is mandated by law.

You ask about the impact on providers and payers. Do both have the option of participating in TEFCA? Yes, but where is the clinical data really coming from? It comes from the provider community. The payer community right now is not contributing data into TEFCA. The risk of compliance falls on the data suppliers because the contracts are structured so that everybody has to comply with applicable law. The data suppliers are ultimately responsible for ensuring that, if they send out data in response to a request from one of these networks, all legal preconditions have been met. If they haven't, guess who's responsible for reporting the data breach? It's the healthcare providers.

If we do not have verifiable trust in the frameworks, our data suppliers will be the ones holding the bag, and we have seen this happen in litigation. For healthcare providers, there's a real risk in participating in health information exchange (HIE) unless we have really good structures in place to make sure that when the data goes out, it is for an authorized purpose, permitted under the laws that apply to the data sources. Because if it doesn't, those providers are going to be the ones who have to do the breach reporting to individuals and to the government. It's going to be those providers that are going to be subject to these data breach lawsuits.

Payers aren't really contributing data right now. This is one of the reasons payers sometimes give for not contributing their data: the risk is too high when talking about potential exposure to patient privacy and the risks that it creates for them.

Do you see this changing at all, especially with the third-party auditor coming in?

It might, but this is a big might. It depends on how this gets implemented. Now, this particular auditor…they are an unknown quantity, and that's good and bad. It's good in the sense that they're truly independent. They are not another player in the marketplace, monitoring other players in the marketplace. But this is an incredibly complex regulatory and technical infrastructure. Do they have the subject matter expertise to do this? The administration has awarded them quite a large contract to do this. I think it's going to come down to who they hire. Are they going to get the right subject-matter expertise there to do the auditing and monitoring in a way that everybody in this community feels like they know what they're doing? And the other piece is, is it just going to be monitoring for compliance? If the auditor does these things, but then there is no enforcement or no action, we're going to be exactly where we were. We're not going to see what we need to see in order to give providers and payers the certainty that this is a safe and trusted network.

Would you like to see additional oversight?

There are definitely many organizations in the community calling for oversight. Now, is that oversight this third party? You're going to have a variety of different opinions on that. What I think we need to be having a conversation about is how we can better protect our healthcare providers. I really think we need to have some actual safe harbor protections for providers. This is also known in the legal community as qualified immunity. I think that piece really needs to happen to make sure we don't lose vendor-agnostic nationwide health information exchange (HIE). That's where I would like to see some movement, and I don't know if there's movement there yet.

Epic and its customers filed a lawsuit about TEFCA data sharing. What are your thoughts on this?

That is an important piece of litigation. There are a lot of important pieces of interoperability litigation, and something that we're watching really closely, both me and my practice, but also the industry. The outcome of that litigation will have ramifications for interoperability across the board, not just with TEFCA but also with other data-sharing frameworks. My takeaway there is to watch the litigation. Watch the other interoperability litigation as well. It's going to be the court rulings that really drive how we interpret these laws and contracts.

What advice do you have for healthcare providers?

I personally believe in interoperability and nationwide health information exchange. I think this is a thing that is good for our healthcare system, for patients, and also for just having cost-effective care. I think providers should participate. But what do you do to make sure you're doing it in a way that's protective of your organization and protective of the data that we are sharing?

First and foremost, I think it means partnering with the right QHIN or participant or sub-participant who is going to work with you to understand what data systems are being set up for participation in TEFCA that matter.

Right now, under TEFCA, the only one you have to respond to is what's called TEFCA Required Treatment (T-TRTMNT), and it has a lot of requirements. There's a lot of vetting that has to happen before somebody can be signed up to query a healthcare provider for TEFCA Required Treatment. You can either be set up to only respond to TEFCA Required Treatment or general Treatment (T-TREAT). Under the framework agreements, you don't have to respond to just general Treatment. You can choose to respond only to TEFCA Required Treatment, where you have a higher level of vetting in place before the person on the other side can query your network for that.

I would say to healthcare providers, with the technology company that's signing you up, have a very detailed conversation about configuring the systems to send the data back.

I want folks to know that there are new standard operating procedures (SOPs). There are two that are forthcoming. One is called Inquiries and Investigations, and the other is called Restricted Participation Status. Not only are we having this third-party auditor within TEFCA governance itself, but we are also going to have more detailed SOPs that explain the investigation and inquiry process, and what's going to happen if we find bad actors as part of the recognized coordinated entity (RCE), which is Sequoia Project's governance of TEFCA.

Read Entire Article

         

        

Start the new Vibrations with a Medbed Franchise today!  

Protect your whole family with Quantum Orgo-Life® devices

  Advertising by Adpathway