HIPAA Security Rule Part One: Proposed Overhaul Closes Some Gaps, Opens Others

By the EHR Association Privacy & Security Workgroup

This three-part blog series shares the EHR Association’s stance on OCR’s proposed changes to the HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information. Part one is focused on our overarching concerns and issues with proposed definitions.

Proposed changes to the existing HIPAA Security Rule, released as HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information, include some long-overdue updates. However, the resources and costs required by healthcare provider organizations, health IT developers, and other regulated entities to comply with the sweeping changes will be too great for many to bear.

That was one of several important messages we shared with the HHS Office of Civil Rights (OCR) in our comment letter on the proposed rule

(more…)

Core Issues for Federal AI Regulations

By Tina Joros, JD (Veradigm), Chair, and Stephen Speicher, MD, MS (Flatiron Health), Vice Chair, EHR Association AI Task Force

The regulatory landscape for AI is on the cusp of dramatic change. As we await the release of the AI Action Plan called for in the January 2025 Removing Barriers to American AI Innovation Executive Order and as federal agencies review their existing AI policies, we have seen an influx of proposed laws at the state level to address concerns about the use of AI in healthcare technology. This increase in state-level activity may lead to regulatory fragmentation that makes it more complex for EHR vendors and health systems to build and support AI tools designed to help advance patient care.

This increased focus on AI is highly relevant to EHR Association members who continue to deploy software capabilities that comply with EHR certification program transparency requirements for the use of Decision Support Interventions (DSI) involving AI and machine learning (ML) capabilities. Most of our member companies are also developing, piloting, or have already deployed generative AI solutions that can be leveraged to resolve many challenges confronting the healthcare industry.

(more…)

Finding the Right Balance: Smart Deregulation in Health IT

by Leigh Burchell (Altera Digital Health), Chair, EHR Association Executive Committee

The current administration has made deregulation a central policy priority, aiming to reduce burden and costs in as many sectors of the economy as possible, including health care. This is exemplified by the January 2025 Executive Order 14192: Unleashing Prosperity Through Deregulation, which requires federal agencies to eliminate ten regulations for each new one introduced. 

As the trade association for health IT developers, we believe that smart deregulation should focus on removing outdated, redundant, and low-value requirements with ASTP/ONC and CMS playing a role more focused on driving improvements in standardized interoperability and health data exchange. Health IT regulation should support—not hinder—the industry’s collective ability to deliver safe, effective, and innovative technology solutions, without compromising the progress made or devaluing the investments in health IT over the last fifteen years. As always, we remain committed to working alongside federal agencies within the construct of a regulatory environment that benefits providers, developers, and—most importantly—patients.

(more…)

Patient Safety Awareness Week: Patient Safety is a Public Health Concern

While progress has been made in the realm of patient safety over the past two decades, medical harm remains a leading cause of death worldwide, making it a public health concern. As many as 250,000 to 400,000 US deaths annually are blamed on errors or preventable harm, and an estimated 40% of patients experience mostly preventable harm in ambulatory and primary care settings.

Embracing this year’s Patient Safety Awareness Week (March 9-15) theme, Moving the Needle, allows healthcare-related organizations – including EHR and other health IT developers – to focus on continuous improvement and ensure that patient safety becomes part of standard practice.

(more…)

EHR Association’s Statement on HHS Strategic Plan for AI In Healthcare

By the EHR Association AI Task Force

On January 10, 2025, the Assistant Secretary of Technology Policy (ASTP) released the U.S. Department of Health and Human Services (HHS) Strategic Plan for the Use of Artificial Intelligence in Health, Human Services, and Public Health.

In the press release announcing its release, HHS described the Strategic Plan as establishing both the strategic framework and operational roadmap for responsibly leveraging emerging technologies to enhance HHS’s core mission while maintaining its commitment to safety, effectiveness, equity, and access. It also outlines the ways HHS will deliver on its goal of being a global leader in innovating and adopting responsible AI that achieves unparalleled advances in the health and well-being of all Americans.

We need to ensure that Americans are safeguarded from risks. Deployment and adoption of AI should benefit the American people, and we must hold stakeholders across the ecosystem accountable to achieve this goal.

“At HHS, we are optimistic about the transformational potential of AI,” said Deputy Secretary Andrea Palm. “These technologies hold unparalleled ability to drive innovation through accelerating scientific breakthroughs, improving medical product safety and effectiveness, improving health outcomes through care delivery, increasing access to human services, and optimizing public health. However, our optimism is tempered with a deep sense of responsibility. We need to ensure that Americans are safeguarded from risks. Deployment and adoption of AI should benefit the American people, and we must hold stakeholders across the ecosystem accountable to achieve this goal.”

Key Plan Points

The Strategic Plan outlines how HHS will mobilize an approach to improve the quality, safety, efficiency, accessibility, equitability, and outcomes in health and human services through the innovative, safe, and responsible use of AI by focusing on four key goals:

  1. Catalyze health AI innovation and adoption to unlock new ways to use AI to improve people’s lives;
  2. Promote trustworthy AI development and ethical and responsible use to avoid potential harm;
  3. Democratize AI technologies and resources to promote equitable access for all; and
  4. Cultivate AI-empowered workforces and organizational cultures to allow staff to make the best use of AI.

HHS says it will adopt a dynamic approach to AI to stay ahead of its rapid evolution while addressing emerging challenges that include Plan updates, continuous risk assessment, stakeholder engagement, and the implementation of robust safeguards that ensure ethical and equitable AI use.

The EHR Association Stance

The EHR Association AI Task Force shares the following thoughts on areas of the Strategic Plan that are of specific interest to the Association’s member companies and the providers who utilize their EHR and other health IT.

We are pleased to see plans to leverage USCDI, USCDI+, HL7, FHIR, and other data standards, along with a focus on TEFCA as a potential transport for information that may be utilized in AI workflows for training or insights. Leveraging the standardized data that already exists in many EHRs will accelerate development of solutions speaking a ‘common language’, as well as the opportunity to benefit from novel AI technologies in the future.

“We are pleased to see plans to leverage USCDI, USCDI+, HL7, FHIR, and other data standards, along with a focus on TEFCA as a potential transport for information that may be utilized in AI workflows for training or insights. Leveraging the standardized data that already exists in many EHRs will accelerate development of solutions speaking a ‘common language’, as well as the opportunity to benefit from novel AI technologies in the future. We are also encouraged to see the ‘human in the loop’ concept throughout the Strategic Plan as a strategy to mitigate risk, particularly at this state of AI maturity,” says Tina Joros (Veradigm), Chair, EHR Association AI Task Force.

When it comes to the expanded scope of HHS responsibilities to appropriately guide safe AI development as outlined in the Plan, Joros notes that “HHS acknowledges that healthcare stakeholders will increasingly use AI technologies and tools that fall outside the scope of FDA regulation or ASTP/ONC authority, including the HTI-1 regulation.”

She adds, “We support conversations about where additional authority may be necessary for HHS to offer meaningful incentives to create uniform standards across the entirety of the healthcare AI ecosystem and not just Certified Health IT. To the extent these incentives also extend to providers using Certified Health IT, they have the potential to spur adoption of AI and build a trusted, transparent system that will help mitigate the risk and cost of adopting new technologies.”

The recognition of the opportunity that exists through artificial intelligence in administrative workflows is a great callout. Innovation in this space can safely improve burnout, as well as the overall cost of healthcare delivery, and thus should be prioritized by policymakers and software developers.

The Association also commends HHS for recognizing the clinical risk inherent in the use of AI in healthcare. AI Task Force Vice Chair Stephen Speicher, MD (Flatiron Health), states: “It is important to take a risk-based approach to developing and deploying AI directly into the healthcare ecosystem. In the AI Strategic Plan, HHS appropriately recognizes the risks that can stem from using AI in high-risk clinical workflows, including diagnosis and treatment, as well as apprehensions about the topic felt by some providers and patients. The recognition of the opportunity that exists through artificial intelligence in administrative workflows is a great callout. Innovation in this space can safely improve burnout, as well as the overall cost of healthcare delivery, and thus should be prioritized by policymakers and software developers.”

Dr. Speicher also acknowledges the potential for AI to widen the technological divide that exists in the U.S. healthcare system and the importance of prioritizing equitable access to AI innovation across the ecosystem.

“A technological divide exists in healthcare in this country, with large high-volume centers in major cities frequently outpacing smaller centers caring for underserved communities,” he says. “We must ensure the deployment of AI technology in healthcare is accessible to small private practices as well as large academic medical centers and health systems to ensure that health equity improves over time in all care settings. Failing to prioritize this, as HHS calls out, risks a further divide in the quality of care available to individuals based on race, ethnicity, zip code, and other demographic factors.”

Electronic Health Record Association Announces Leadership Team and Priorities for FY25

The HIMSS Electronic Health Record (EHR) Association announced today that Leigh Burchell, Vice President of Policy and Government Affairs at Altera Digital Health, was elected Chair of its Executive Committee during elections for leadership terms that began Jan. 1, 2025. Burchell previously served as Chair of the trade association from 2015 to 2016. 

After serving as Chair this past year, Stephanie Jamison, Senior Director of Regulatory and Government Affairs with Greenway Health, has transitioned to Vice Chair of the trade association. The EHR Association’s 29 member companies serve most of the nation’s hospitals and ambulatory care organizations using EHRs and other health information and technology to deliver high-quality, efficient care to their patients. 

(more…)
  • Categories

  • Follow EHRA on Twitter

  • Enter your email address to follow this blog and receive notifications of new posts by email.

    Join 197 other subscribers
  • Contact Us

    Kasey Nicholoff
    staff @ ehra.org

    Amanda Patanow
    Communications and Media
    ehracomms @ npccs.com