Sensitive Data Management: The Need for Standards to Catch Up to Policy

By The EHR Association Sensitive Data Management Task Force

This is the first in an occasional blog series focused on framing the work that lies ahead to establish clear, consistent, computable standards governing the management of sensitive data.

Health information is personal. It is also essential to the provision of safe, coordinated, high-quality care. Stakeholders across the health IT ecosystem are intimately familiar with managing the tension between ensuring the right information is available to the right people at the right time and also respecting patient privacy, legal restrictions, and patients’ expectations about how their information will be used and disclosed.

While the tension is not new, the pace, complexity, and variability of the rules being applied to sensitive health information are.

Healthcare organizations and health IT developers are facing a growing patchwork of federal and state requirements governing the disclosure of certain categories of health data. Some are longstanding, such as protections related to substance use disorder treatment, behavioral health, HIV status, genetic information, adolescent care, and other sensitive clinical domains. Others have taken on new urgency, in part due to the Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization, as states have adopted divergent approaches to reproductive healthcare, gender-affirming care, and related data disclosure requirements.

Recognizing the transition from a legal or policy issue to one that more concretely requires decisions about standards and implementation, the EHR Association established the Sensitive Data Management Task Force. Its purpose is not to take a position on the underlying policy debates that are giving rise to particular privacy requirements. Rather, our focus is on a principle that should be widely shared: patients should have meaningful control over the disclosure of their health information, and health IT systems should support that control in ways that are scalable, interoperable, clinically safe, and consistent with applicable law.

The challenge is that all the tools needed to do so reliably are not yet available.

Where We Are Today

The health IT community is not starting from zero on this work, which is something we analyzed in our 2024 Privacy & Consent Management Landscape and Challenges to Scale blog series (part one and part two). Important standards and implementation specifications already form part of the foundation for sensitive data management, e.g., initial security label definitions and guidance on how to tag transactions and documents with such labels.

While they are meaningful building blocks, they are not a complete solution. Data tagging with security labels is relevant, but the ability alone is not nearly sufficient to make sensitive data management work at scale.

Broader success requires more than the ability to tag a document, suppress a note, or redact a field. What’s needed is an end-to-end framework that can identify sensitive information, associate it with appropriate metadata, connect that metadata to computable policy rules from jurisdictions, incorporate patient permissions and restrictions, and communicate obligations consistently across the patient’s data holders in a way that other systems can understand and act upon.

That is a much harder problem.

Why It’s So Difficult

Sensitive data is not always obvious. Context matters.

A data element may be sensitive due to its scope, nature, or other factors, such as patient age, care setting, jurisdiction, recipient, purpose of use, the patient’s expressed preference, or the combination of several otherwise ordinary data elements. In some cases, sensitivity may be inferred only when information is viewed in context.

That creates difficult questions for health IT developers, providers, health information networks, and policymakers.

  • At what level should data be tagged: the document, section, encounter, order, result, FHIR resource, individual data element, or some combination of these?
  • Who defines the value sets that determine whether information belongs in a sensitive category?
  • How should state-specific privacy rules be translated into computable logic?
  • How should systems represent and exchange patient consent, revocation, authorization, or disclosure restrictions?
  • What should happen when a receiving system cannot interpret or enforce a label? Or has no access to the official source of the applicable privacy rules or patient consent rules?
  • How should systems preserve privacy protections while managing patient safety?

These questions are not theoretical. They determine whether protections can be applied consistently as sensitive data is shared across a patient’s multiple data holders.

Without clearer standards and implementation guidance, organizations are left to solve the problem locally. That means custom logic, manual workflows, inconsistent interpretations, and uneven downstream enforcement. It also means a greater burden on providers and less certainty for patients, with increased potential to under-share data to avoid over-sharing, or to over-share due to inconsistent interpretation of non-computable rules.

Clearly, that is not a sustainable model.

Patient Control Requires Technical Infrastructure

It is easy to say that patients should control the disclosure of their health information. It is much harder to operationalize that principle in a complex, multi-state, multi-system health care environment.

Patient control depends on technical infrastructure.

Systems must capture patient instructions in a structured way. They must determine which data is subject to those instructions, apply the relevant privacy rule or disclosure restriction, and share those restrictions with other data holders. They must do so by carefully weighing privacy considerations against the patient safety risks of restricting clinician access to information needed for safe and effective care.

This is where the gap between policy intent and technical capability becomes most visible.

Policymakers may reasonably expect that sensitive information can be segmented and protected. Patients may reasonably expect that their preferences and legal protections will follow their data. Providers may reasonably expect that certified health IT can help them comply with applicable requirements. Developers may reasonably expect that standards will be mature enough to implement consistently.

Today, however, those expectations are not well aligned with the current state of the standards required to deliver the work and use the functionality effectively.

The Work Ahead

The EHR Association and the Sensitive Data Management Task Force believe the industry needs a shared understanding of the capabilities required for consistent sensitive data management, including:

  • common terminology for categories of sensitive data;
  • standardized approaches to data segmentation and security labeling;
  • clearer links among sensitive data definitions, value sets, consent frameworks, and computable privacy rules;
  • implementation guidance that reflects real EHR workflows;
  • testing expectations that support consistent system behavior;
  • and policy guidance that recognizes both patient privacy and patient safety.

No single stakeholder can solve this independently. EHR developers can implement standards, but the standards must be sufficiently mature, specific, and testable before that point. Policymakers can define legal obligations, but those obligations must be translatable into operational workflows and computable requirements. Providers can establish policies and train staff, but they need technology that supports those policies at scale. Patients can express preferences and authorizations, but systems must be able to capture, honor, and reliably transmit them.

This is precisely the kind of problem that requires collaboration across standards bodies, regulators, developers, providers, health information networks, and patient advocates.

Building Confidence and Trust

The industry has made significant progress on interoperability. But trusted interoperability requires more than moving data from one system to another. It requires confidence that data will be used and disclosed appropriately once it has moved.

Patients should be able to trust that their health information will be handled in a manner consistent with their rights, expectations, and applicable law. Clinicians should have access to the most complete record needed to provide safe care. Developers and policymakers should be able to trust that privacy requirements can be implemented through clear, consistent, computable standards.

That is work the industry needs to do together.

Leave a comment

Share your thoughts on this topic!

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Categories

  • Follow EHRA on Twitter

  • Enter your email address to follow this blog and receive notifications of new posts by email.

    Join 206 other subscribers
  • Contact Us

    Kasey Nicholoff
    staff @ ehra.org

    Amanda Patanow
    Communications and Media
    ehracomms @ npccs.com