<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HC5EBE82E28BB4DB485C6775886A3CC20" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 4613 IH: Ensuring Patient Access to Healthcare Records Act of 2017</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2017-12-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4613</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20171211">December 11, 2017</action-date><action-desc><sponsor name-id="M001159">Mrs. McMorris Rodgers</sponsor> (for herself, <cosponsor name-id="K000376">Mr. Kelly of Pennsylvania</cosponsor>, <cosponsor name-id="H001067">Mr. Hudson</cosponsor>, <cosponsor name-id="B001243">Mrs. Blackburn</cosponsor>, <cosponsor name-id="L000576">Mr. Long</cosponsor>, <cosponsor name-id="B001293">Mr. Bishop of Michigan</cosponsor>, <cosponsor name-id="P000594">Mr. Paulsen</cosponsor>, and <cosponsor name-id="K000391">Mr. Krishnamoorthi</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name>, and in addition to the Committee on <committee-name committee-id="HWM00">Ways and Means</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such
			 provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To allow the use of claims, eligibility, and payment data to produce reports, analyses, and
			 presentations to benefit Medicare, and other similar health insurance
			 programs, entities, researchers, and health care providers, to help
			 develop cost saving approaches, standards, and reference materials and to
			 support medical care and improved payment models.</official-title></form>
	<legis-body id="HC2AA5F875CED4106852F48D003E78557" style="OLC">
 <section id="HD45D0C2AA4E148F1A7615AC9022B6B80" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Ensuring Patient Access to Healthcare Records Act of 2017</short-title></quote>.</text> </section><section id="HF2B537088E7C48C2A3725B3A32BEA175"><enum>2.</enum><header>Promotion of access to data, via research and user friendly presentations and applications</header> <subsection id="H9C2B142EF64B4DDFA047D9318F33683E"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle D of the Health Information Technology for Economic and Clinical Health Act (<external-xref legal-doc="usc" parsable-cite="usc/42/17921">42 U.S.C. 17921</external-xref> et seq.) is amended by adding at the end the following:</text>
				<quoted-block display-inline="no-display-inline" id="H93C79F282D594BB784FF255296820FF7" style="OLC">
					<part id="H8963A158E67C43AABC77D3496E2D2038" style="OLC"><enum>3</enum><header>Health care clearinghouses; data processing to empower patients and improve the health care system</header>
						<section id="HC04269774EBF4821834C8F08CC6FAC69"><enum>13451.</enum><header>Modernizing the role of clearinghouses in health care</header>
							<subsection id="HBF9773A8A5A8401BA91F6E791CD0D2F5"><enum>(a)</enum><header>Efforts To promote access to and leveraging of health information</header>
 <paragraph id="H035348D24BEE4D0493C676CC0521A095"><enum>(1)</enum><header>In general</header><text>The Secretary shall, through the updating of existing policies and development of policies that support dynamic technology solutions, promote patient access to information related to their care, including real world outcomes and economic data (including claims, eligibility, and payment data), in a manner that would ensure that such information is available in a form convenient for the patient, in a reasonable manner, and without burdening the health care provider involved.</text>
 </paragraph><paragraph id="H5F15A45B7A9848CFA4FF59803FDDCF51"><enum>(2)</enum><header>Requirement</header><text>Activities carried out under paragraph (1) shall include the development of policies to enable covered entities with access to health information to—</text>
 <subparagraph id="H1EC3DF904DAF4183BD08DB9106AE5C38"><enum>(A)</enum><text>provide patient access to information related to their care, including real world outcomes and economic data;</text>
 </subparagraph><subparagraph id="H335534299FC44CB683B8D207F8B25874"><enum>(B)</enum><text>develop, in accordance with HIPAA-related provisions (as defined in subsection (j)), patient engagement tools, reports, analyses, and presentations based on population health, epidemiological, and health services outcomes data, that may demonstrate a fiscal or treatment benefit to patients and health plan enrollees; and</text>
 </subparagraph><subparagraph id="H793AE4F9A0974335A31DA834B8017B64"><enum>(C)</enum><text display-inline="yes-display-inline">promote transparency regarding the use and disclosure of health information by health care clearinghouses in accordance with the notice provisions of subsection (e).</text>
									</subparagraph></paragraph></subsection><subsection id="HFF753F1E4E9642B7B2C2693FC9886C31"><enum>(b)</enum><header>Treatment as covered entity for specified functions</header>
 <paragraph id="H14DAD8070552442BA1757FC94C8D83DA"><enum>(1)</enum><header>In general</header><text>With respect to the use and disclosure of protected health information, the Secretary shall—</text> <subparagraph id="H2FAD805A3E3B42E0B4CA5B199540D6D6"><enum>(A)</enum><text>not consider health care clearinghouses that engage in the functions described in paragraph (3) to be business associates, including subcontractor business associates, under HIPAA-related provisions (as defined in subsection (j)(3)) regardless of the role of such clearinghouses in collecting or receiving the information; and</text>
 </subparagraph><subparagraph id="HC0DAF251FEAA48C38E2F961D9E71F828"><enum>(B)</enum><text>consider such clearinghouses to be covered entities under such provisions of law for all purposes.</text> </subparagraph><continuation-text continuation-text-level="paragraph">Such clearinghouses shall not be considered business associates, or subcontractor business associates, for translation of data into and out of standard format, analytic, cloud computing, or any other purpose.</continuation-text></paragraph><paragraph id="HD418F4D3353649E2B163E978E5310B3B"><enum>(2)</enum><header>Data accuracy and security requirement</header><text>In order to use health data as authorized by this section, a clearinghouse or other covered entity engaging in activities authorized under this section shall be certified to have the necessary expertise and technical infrastructure to ensure the accuracy and security of such claims, eligibility, and payment data through receipt of an accreditation by the Electronic Healthcare Network Accreditation Commission, or by an equivalent accreditation program determined appropriate by the Secretary.</text>
								</paragraph><paragraph id="HCAC7867905BB48E9B045ADA0C9146D80"><enum>(3)</enum><header>Enhancing treatment, quality improvement, research, public health efforts and other functions</header>
 <subparagraph id="H4960EC40DB894B3CA27241C5230AC957"><enum>(A)</enum><header>Equivalent authority to other covered entities</header><text>Subject to paragraph (2), a health care clearinghouse shall—</text> <clause id="H55D7D88B8689412B93C95D62A73DB9B7"><enum>(i)</enum><text>in addition to carrying out claims processing functions, be permitted to use and disclose protected health information without obtaining individual authorization to the same extent as other covered entities, including for purposes of treatment, payment, health care operations as permitted by section 164.506 of title 45, Code of Federal Regulations, research, and public health as permitted by section 164.512 of title 45, Code of Federal Regulations, and creating de-identified information as permitted by section 164.502(d) of title 45, Code of Federal Regulations; and</text>
 </clause><clause id="H1F4715BBDE45402D8D1A367BF3469ABA"><enum>(ii)</enum><text>use or disclose protected health information as required by section 164.502(a)(2) of title 45, Code of Federal Regulations.</text>
										</clause></subparagraph><subparagraph id="HFB27DE05618B4ADC9E398451032410B3"><enum>(B)</enum><header>Additional authority</header>
 <clause id="HDFB465947A7E489DB3BE3B5638311430"><enum>(i)</enum><text>A health care clearinghouse shall be permitted to provide an individual or the personal representative of such individual access to the protected health information of such individual as described in subsection (d).</text>
 </clause><clause id="HD202FBB467E84E86841849FC92C1FD5E"><enum>(ii)</enum><text display-inline="yes-display-inline">All covered entities, including a health care clearinghouse, shall, subject to subsection (c)(2), be permitted to—</text>
 <subclause id="HABCBE4C73E2C4595B77F2C9D7F3E40F5"><enum>(I)</enum><text>on behalf of covered entities, use and disclose protected health information for health care operations purposes (as defined by section 164.501 of title 45, Code of Federal Regulations) without respect to whether the recipient of the information has or had a relationship with the individual;</text>
 </subclause><subclause id="HC65A77B1B95946A58B181DB5350FE1DB"><enum>(II)</enum><text>upon the request of a covered entity, benchmark (as defined by the Secretary pursuant to rulemaking) the operations of such covered entity against the operations of one or more other covered entities that have elected to participate in such bench­mark­ing; and</text>
 </subclause><subclause id="HB511EDD758464D46BD1B6B0580225CC5"><enum>(III)</enum><text>use and disclose protected health information to facilitate clinical trial recruitment, except that in the case the covered entity provides a consumer-facing portal or website that informs individuals of clinical trials conducted by the covered entity, the covered entity shall secure opt-in consent from the individual, or the individual’s personal representative, prior to contacting an individual regarding such clinical trials unless such covered entity already has a relationship with the individual.</text>
 </subclause></clause></subparagraph><subparagraph id="H527BC23045F445E68C183A34D796E300"><enum>(C)</enum><header>Clarification</header><text display-inline="yes-display-inline">Nothing in this paragraph shall expand the authority of a health care clearinghouse or any other covered entity to use or disclose protected health information for marketing purposes under sections 164.501 and 164.508(a)(3) of title 45, Code of Federal Regulations.</text>
									</subparagraph></paragraph></subsection><subsection id="HBD47F6F478F74EDB9AAC47BA3B7B4271"><enum>(c)</enum><header>Authorities relating to data processing</header>
 <paragraph id="H9EFA8B7E7DD94F8397FE54DA06013DA0"><enum>(1)</enum><header>In general</header><text>In carrying out HIPAA-related provisions, the Secretary shall permit a health care clearinghouse to aggregate protected health information, within the clearinghouse and among other clearinghouses, that the clearinghouse possesses in order to carry out the functions described in subsection (b)(3). Subject to section 164.502(a)(5)(i) of title 45, Code of Federal Regulations, a health care clearinghouse may carry out the functions described in subsection (b)(3) without obtaining individual authorization under section 164.508 of title 45, Code of Federal Regulations.</text>
 </paragraph><paragraph id="H4DD08FCE4ADE4A7E81667646BA2D5E9B"><enum>(2)</enum><header>Privacy</header><text>For purposes of clauses (ii) through (iv) of subsection (b)(3)(B), with respect to any report, analysis, or presentation provided by the covered entity to a third party, such report, analysis, or presentation—</text>
 <subparagraph id="H8D4AF55B19FF41C683580E741578A963"><enum>(A)</enum><text>shall include only de-identified data; or</text> </subparagraph><subparagraph id="HA892F87524A2485F935C7554A88B249F"><enum>(B)</enum><text>shall include, subject to a qualifying data use agreement (as defined in subsection (j)), protected health information.</text>
									</subparagraph></paragraph><paragraph id="H22E395A05B1A4434A7C602D7ED8E6D99"><enum>(3)</enum><header>Clarification; Fee permitted</header>
 <subparagraph id="HD567F2FB5CF0480D8303A83882056E92"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Nothing in this paragraph shall be construed as affecting an individual’s right to access claims and payment records in HIPAA standard format, in accordance with section 164.524 of title 45, Code of Federal Regulations.</text>
 </subparagraph><subparagraph id="H41DE02BFC7DC48F1B4F19CBABAF32522"><enum>(B)</enum><header>Fee permitted</header><text>If an individual or a personal representative of the individual requests a copy of records in HIPAA standard format a health care clearinghouse may charge a reasonable, cost-based fee so far as such fee is in accordance with section 164.524(c)(4) of title 45, Code of Federal Regulations.</text>
									</subparagraph></paragraph></subsection><subsection id="HD60A007DC6BA48E48C8E030F2271B37E"><enum>(d)</enum><header>Comprehensive records at the request of an individual</header>
 <paragraph id="H8119464F84194525BFA5BCBDC254A7F1"><enum>(1)</enum><header>In general</header><text>When a health care clearinghouse receives a written request from an individual or the personal representative of the individual for the protected health information of the individual, the clearinghouse shall provide to the individual a comprehensive record of such information (across health care providers and health plans and longitudinal in scope), unless the clearinghouse determines in its sole discretion that providing a comprehensive record is not technologically feasible.</text>
 </paragraph><paragraph id="HBBE08284751A42C0B300FAD7589BF972"><enum>(2)</enum><header>Purchase from other clearinghouses</header><text>In preparing a comprehensive record for an individual under paragraph (1), a health care clearinghouse may, with the permission of the individual, purchase the protected health information of the individual from one or more other health clearinghouses (and the amount of such purchase may be included in a fee that is fair market value, as defined in subsection (j)(2), charged to the individual.</text>
 </paragraph></subsection><subsection id="H28D754C747E245D698512C3CD5DEBA0A"><enum>(e)</enum><header>Situations not involving direct interaction with individuals</header><text display-inline="yes-display-inline">Sections 164.400 through 164.414 (relating to breach notification) and sections 164.520 through 164.528 (relating to individual rights) of title 45, Code of Federal Regulations, shall apply to a health care clearinghouse that engages in the functions described in subsection (b)(3) to the extent that such clearinghouse has current contact information pursuant to direct interaction with the individual involved. If the clearinghouse does not have direct interaction with the individual involved, the clearinghouse shall provide notice of any breach of unsecured protected health information to the covered entity that does have direct interaction with the individual involved. The clearinghouse shall not be required to report a breach if the protected health information is rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the guidance issued under section 13402(h)(2). The clearinghouse shall also provide a notice of privacy practices on its website.</text>
							</subsection><subsection id="HE9BEF2DC55854886941ACCD1747B8DF6"><enum>(f)</enum><header>Transition</header>
 <paragraph id="H144E8EB8FBCE46C090D431F696DE3291"><enum>(1)</enum><header>In general</header><text>Except where specifically stated, nothing in this section shall be construed to apply to clearinghouses to the exclusion of other covered entities or to provide a health care clearinghouse greater authority to use and disclose protected health information than that provided to another covered entity.</text>
 </paragraph><paragraph id="H628F0291C3D64F65827A08EBDE84A0C8"><enum>(2)</enum><header>Existing agreements</header><text>With respect to agreements entered into by a health care clearinghouse prior to the date of enactment of this section, a provision of such an agreement that conflicts with this section shall not have any legal force or effect. The preceding sentence may not be construed as affecting any provision of an agreement that does not conflict with this section.</text>
 </paragraph></subsection><subsection id="H19A04F57640E4641850F721EEBCACB1F"><enum>(g)</enum><header>Safe harbor and clarification of liability</header><text>In the case of a health care clearinghouse that engages in a function described in subsection (b), only that clearinghouse may be held liable for a violation of a HIPAA-related provision (and a covered entity that provided data or data access to the clearinghouse shall not be liable for such violations).</text>
 </subsection><subsection id="HC20BC791033B4EA3A01297D50BDD767D"><enum>(h)</enum><header>Enforcement</header><text>Section 13410(a)(2) shall apply to this section in the same manner as such section applies to parts 1 and 2.</text>
							</subsection><subsection id="HD1137AA2AAB84B41B5A47BC2EA411A2D"><enum>(i)</enum><header>Relation to other laws</header>
 <paragraph id="H7D20C3AB5AFF471F98290336194A8C26"><enum>(1)</enum><header>Application of HITECH rule</header><text>Section 13421 shall apply to this section in the same manner as such section applies to parts 1 and 2, except to the extent that such section 13421 concerns section 1178(a)(2)(B) of the Social Security Act.</text>
 </paragraph><paragraph id="HAB425DD78DF640E39EAFB392D833A46E"><enum>(2)</enum><header>State laws regarding unfair or deceptive acts or practices</header><text>This part shall not be construed to preempt the law of any State that prohibits unfair or deceptive acts or practices or limit the authority of State attorneys general to enforce such laws.</text>
 </paragraph></subsection><subsection id="H0500D9DFCA8C4A9DB9EA9605ADECE624"><enum>(j)</enum><header>Definitions</header><text>In this part:</text> <paragraph id="HF3056FB06E6A4B7DBA2F52D450FD496B"><enum>(1)</enum><header>De-identified</header><text>The term <term>de-identified</term>, with respect to health information, means such information that is not individually identifiable as determined in accordance with the standards under section 164.514(b) of title 45, Code of Federal Regulations.</text>
 </paragraph><paragraph display-inline="no-display-inline" id="H22F35DE6AF0745F1ACECF7C94284E77B"><enum>(2)</enum><header>Fair market value</header><text display-inline="yes-display-inline">The term <term>fair market value</term> means the price that a person reasonably knowledgeable and interested in buying a given product or service would pay to a person reasonably knowledgeable and interested in selling the product or service.</text>
 </paragraph><paragraph id="HBD841B8A3BB24DBBB0B844C0780C9438"><enum>(3)</enum><header>Health care clearinghouse</header><text>The term <term>health care clearinghouse</term> has the meaning given such term in section 1171 of the Social Security Act.</text> </paragraph><paragraph id="HB09C59974CC84281A31BB721C3499BC1"><enum>(4)</enum><header>HIPAA-related provision</header><text>The term <term>HIPAA-related provision</term> means the provisions of each of the following:</text>
 <subparagraph id="H47D1C8B8BD4F416BB2E91FC931FFA075"><enum>(A)</enum><text>This subtitle.</text> </subparagraph><subparagraph id="H8C49F11133A3488CAB0C0128D04B2BE0"><enum>(B)</enum><text>Part C of title XI of the Social Security Act.</text>
 </subparagraph><subparagraph id="H3CBAA1CED38F4E4A95ED79F2ACD415D5"><enum>(C)</enum><text>Regulations promulgated pursuant to sections 262(a) and 264(c) of the Health Insurance Portability and Accountability Act of 1996 or this subtitle.</text>
 </subparagraph></paragraph><paragraph id="H36EF677216CB4F029EBAD6CDF1A01F36"><enum>(5)</enum><header>Individual</header><text>The term <term>individual</term>, with respect to protected health information, has the meaning applicable under section 160.103 of title 45, Code of Federal Regulations.</text>
 </paragraph><paragraph id="HD74DEB0CE3654F4DA73EF65E8BFCEDEA"><enum>(6)</enum><header>Qualifying data use agreement</header><text>The term <term>qualifying data use agreement</term> means an agreement, which may be electronic, that—</text> <subparagraph id="H068F83537F374B01923E73CEC27CC084"><enum>(A)</enum><text>establishes the permitted uses and disclosures of protected health information by the recipient;</text>
 </subparagraph><subparagraph id="H7D8F633A1D8F4D8EBE58D45352A3A5AF"><enum>(B)</enum><text>limits such uses and disclosures to the original purpose of disclosure under subsection (b)(3)(B); and</text>
 </subparagraph><subparagraph id="HD091F634F3E1499A9150EF661F84D922"><enum>(C)</enum><text>provides that the data recipient will—</text> <clause id="H986E50100BBA49FEB6CC6ABCC1328B42"><enum>(i)</enum><text>not use or further disclose the information other than as permitted by the qualifying data use agreement or as otherwise required by law;</text>
 </clause><clause id="H85C304FB351F4D51A60135FCD2455D7A"><enum>(ii)</enum><text>use appropriate safeguards to prevent use or disclosure of the information other than as provided for by the qualifying data use agreement; and</text>
 </clause><clause id="H23DADFB891DE4A419255FF1BECED3F84"><enum>(iii)</enum><text>ensure that any agents to whom it provides the data agree to the same restrictions and conditions that apply to the data recipient with respect to such information.</text></clause></subparagraph></paragraph></subsection></section></part><after-quoted-block>.</after-quoted-block></quoted-block>
 </subsection><subsection id="HD9264DD31637485B84EEEDE8720099A7"><enum>(b)</enum><header>Regulations</header><text>Not later than 180 days after the date of the enactment of this Act, the Secretary of Health and Human Services shall promulgate regulations to carry out the amendment made by subsection (a).</text>
 </subsection><subsection id="H24FAB12C7EEC476297C7031FD3C10E29"><enum>(c)</enum><header>Conforming amendment</header><text>Section 1171(2) of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d">42 U.S.C. 1320d(2)</external-xref>) is amended by inserting before the period the following: <quote>or receives a standard transaction from another entity and processes or facilitates the processing of health information into nonstandard format or nonstandard data content for the receiving entity. Such term also includes an entity that carries out such processing functions, transmits standard health care claims, transmits health care claim payments or provides advice on such, and transmits any standard transactions on behalf of a HIPAA-covered entity and in addition, engages in any authority of such entity described in subsection (b)(3) of section 13451 of the Health Information Technology for Economic and Clinical Health Act</quote>.</text>
			</subsection></section></legis-body></bill>


