The HIT Policy Committee, an advisory group to the Office of the National Coordinator for Health Information Technology, has recommended that ONC encourage the use of models for exchanging personal health information that do not expose any unencrypted PHI.

These models include direct exchange from message originator to message recipient, or exchange using an intermediary that only performs routing services and has no access to PHI.

Two other models for exchanging data give intermediaries access to unencrypted PHI, according to the committee. Consequently, clear policies are needed to limit retention of PHI. These models involve an intermediary having access to information, such as drug safety checks, but not changing the data in the message body; or opening up the message and changing its format or data.

Other policy committee recommendations include:

* The basic technical model for NHIN Direct, an initiative to simplify linking to the nationwide health information network, should not involve intermediary access to unencrypted PHI;

* ONC should play a role in establishing and enforcing requirements on authorized credentialing services providers that issue digital certificates and verify provider identities, with state governments also able to provide additional rules; and

* Regulations, guidance and/or best practices are necessary to educate patients about direct electronic exchange of health data.

The HIT Policy Committee on June 25 approved the message handling recommendations of its Tiger Team privacy and security workgroup, available here.

--Joseph Goedert


Register or login for access to this item and much more

All Health Data Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access