A Q&A with Chris Morrison
For years, the information blocking provisions of the 21st Century Cures Act remained largely in the background of healthcare compliance discussions. Most organizations were aware of the requirements, but relatively few viewed them as an immediate enforcement concern. That is beginning to change.
Federal agencies have signaled a growing focus on information blocking compliance, and healthcare organizations should expect increased scrutiny around how electronic health information is accessed and shared.
In this Q&A, Chris Morrison, Director of Governance and Compliance at Harmony Healthcare IT, shares his perspective on the evolving enforcement landscape and how health systems can strengthen their compliance posture.
Q: Information blocking has been law since 2016. What’s actually changing right now, and why?
CM: A few things are converging. HHS leadership directed the department last fall to devote additional resources to information blocking enforcement, and the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT (ASTP/ONC) and HHS Office of Inspector General (OIG) followed with public communications making clear that enforcement is active and increasing.
Q: What penalties can organizations face for noncompliance?
CM: The consequences can be significant. Organizations may lose meaningful EHR user status, receive a zero score in the Promoting Interoperability performance category of MIPS, or face other impacts tied to federal programs. For ACOs, information blocking violations can create additional consequences, including removal from the Shared Savings Program and the loss of associated incentive payments.
Q: What’s the most common way a hospital or health system unintentionally ends up in information blocking territory?
CM: In many cases, the issue isn’t an intentional refusal to share information. It’s an organization’s inability to provide information quickly and efficiently when it’s requested. Delays, incomplete responses, or unnecessary barriers can all create compliance risk, particularly when they cannot be justified under one of the recognized exceptions.
Legacy systems are a common contributor to this problem. When staff must log into multiple systems, rely on specialized knowledge, or manually assemble records from disparate sources, fulfilling requests becomes more difficult and time-consuming.
Q: What should IT and HIM leaders be doing right now to reduce their risk?
CM: Take inventory of every legacy system still holding ePHI and consider how release requests against that data are fulfilled by your organization. Is information scattered in disparate systems? Does staff need to manually search several systems to assemble a record? Does fulfilling a request depend on specialized knowledge or access that only a handful of employees still possess?
If the answer to any of those questions is yes, consolidation should be a priority. A comprehensive, secure, searchable archive can simplify access to historical information, reduce reliance on aging systems, and support more consistent fulfillment of information requests. In addition to the operational and cost benefits, it can help organizations reduce their exposure to information blocking risk.
Concerned that legacy systems may be creating information blocking risk? Contact Harmony Healthcare IT to discuss strategies for centralizing historical data, simplifying access, and reducing compliance exposure.
Chris Morrison is Director of Governance & Compliance at Harmony Healthcare IT.