
HHS HIPAA updates
HHS prioritizes patient-centric healthcare, enhancing interoperability and access to health information while addressing privacy concerns and technology disparities.
The end of summer has been busy for the U.S. Department of Health and Human Service (HHS). First, on July 30, 2025, HHS (through the Centers for Medicare and Medicaid Services (CMS))
The Administration’s efforts focus on two broad areas: promoting a CMS Interoperability Framework to easily and seamlessly share information between patients and providers, and increasing the availability of personalized tools so that patients have the information and resources they need to make better health decisions.
“The Office of Civil Rights (OCR) supports actions that improve the timeliness in providing individuals with access to their electronic protected health information, without sacrificing health information privacy and security,” said OCR Director Paula M. Stannard. “If an individual receives another individual’s electronic protected health information in error, generally, OCR’s primary HIPAA enforcement interests are ensuring that the affected individual and HHS receive timely HIPAA breach notification.”
The focus on patient-centered care is not new. One of the primary
Second, HHS – Office for Civil Rights released two FAQs, which serve to clarify rights and responsibilities. The
A covered health care provider may disclose PHI for the treatment activities of another health care provider without the individual’s authorization where both providers are treating the individual through a value-based care arrangement (e.g., an accountable care organization).
A health plan may disclose PHI to a health care provider without the individual’s authorization to enable the health care provider to provide treatment as part of a value-based care arrangement.
What is notably absent is the express mention of value-based enterprises (VBEs), which came on the scene in late-2020 and were
The
- With limited exceptions, the HIPAA Privacy Rule gives individuals the right to access, upon request, the medical and health information (protected health information or PHI) about them in one or more designated record sets maintained by or for the individuals’ health care providers and health plans (HIPAA covered entities). See 45 CFR 164.524. Designated record sets include medical records, billing records, payment and claims records, health plan enrollment records, case management records, as well as other records used, in whole or in part, by or for a covered entity to make decisions about individuals. See 45 CFR 164.501.
- Individuals do not have a right to access PHI about them that is not part of a designated record set because this information is not used to make decisions about individuals. This may include certain quality assessment or improvement records, patient safety activity records, or business planning, development, and management records that are used for business decisions more generally rather than to make decisions about individuals. For example, peer review files, practitioner or provider performance evaluations, quality control records used to improve customer service, and formulary development records may be generated from and include an individual’s PHI but may not be in the covered entity’s designated record set(s) to which the individual has access. However, the underlying PHI from the individual’s medical or payment records used to generate such information remains part of the designated record set and subject to access by the individual.
- Individuals also do not have a right to access the psychotherapy notes that a mental health professional maintains separately from the individual’s medical record and that document or analyze the contents of a counseling session with the individual.
In sum, the FAQs are a good review and may be used to refine existing policies and procedures for existing covered entities. As for the interoperability and patient access initiatives announced by CMS, there is a lot of complexity that covered entities and business associates alike need to understand and appreciate that not all patients will have electronic access for a variety of reasons.
Newsletter
Optimize your practice with the Physicians Practice newsletter, offering management pearls, leadership tips, and business strategies tailored for practice administrators and physicians of any specialty.














