Proposed Section 6225 Attestation Format (PDF)
Attestation format proposal link on cms.gov
Proposed Section 6225 Attestation Format (PDF)
Attestation format proposal link on cms.gov
B. Requirements at Section 6225 of the Consolidated Appropriations Act, 2026 Section 6225 of the Consolidated Appropriations Act, 2026 (CAA, 2026), Public Law 119-75, enacted on February 3, 2026, amends section 1833(t) of the Act by adding new paragraph (23). In brief, section 6225 of the CAA, 2026 will prohibit Medicare payments under the OPPS beginning January 1, 2028, unless off-campus outpatient departments of a provider bill using a separate National Provider Identifier (NPI) and the main provider has submitted an attestation that the departments meet the provisions at § 413.65. As noted previously, although provider compliance with provider-based rules is mandatory, payment had not been conditioned on verification of such compliance. Section 1833(t)(23)(A) of the Act, as added by section 6225 of the CAA, 2026, specifies that no payment may be made under that subsection (or under an applicable payment system pursuant to paragraph (21) of section 1833(t) of the Act) for items and services furnished on or after January 1, 2028, by an off-campus outpatient department of a provider unless that department has obtained, and the items and services are billed under, an NPI that is separate from the NPI of the main provider; the main provider has submitted to the Secretary, during the 2-year period ( printed page 41981) ending on the date such items and services are furnished, an initial provider-based status attestation that the off-campus outpatient department is compliant with the requirements described in section § 413.65 (or a successor regulation); and the main provider has submitted a subsequent attestation within the timeframe specified by the Secretary. The initial attestation may include an attestation submitted in accordance with existing § 413.65(b)(3) until the Secretary establishes the new attestation submission process, which is discussed further below. New section 1833(t)(23)(B)(i) of the Act requires the Secretary, through notice and comment rulemaking, to establish a process for each provider with an off-campus outpatient department to submit an initial and subsequent attestation, for the review of each such attestation and for the determination, through site visits, remote audits, or other means (as determined appropriate by the Secretary), whether each off-campus outpatient department is compliant with the requirements described in subparagraph (A). In addition, new section 1833(t)(23)(C) of the Act defines an “off-campus outpatient department of a provider” for purposes of paragraph (23) as a department of a provider (as defined in § 413.65) that is not located on the campus (also defined in § 413.65) of the main provider or is not within the distance described in such definition of campus from a remote location of a hospital (also defined in § 413.65).
This is the federal register version of the Section 6225 approach.
B. Requirements at Section 6225 of the Consolidated Appropriations Act, 2026 Section 6225 of the Consolidated Appropriations Act, 2026 (CAA, 2026), Public Law 119-75, enacted on February 3, 2026, amends section 1833(t) of the Act by adding new paragraph (23). In brief, section 6225 of the CAA, 2026 will prohibit Medicare payments under the OPPS beginning January 1, 2028, unless off-campus outpatient departments of a provider bill using a separate National Provider Identifier (NPI) and the main provider has submitted an attestation that the departments meet the provisions at § 413.65. As noted previously, although provider compliance with provider-based rules is mandatory, payment had not been conditioned on verification of such compliance. Section 1833(t)(23)(A) of the Act, as added by section 6225 of the CAA, 2026, specifies that no payment may be made under that subsection (or under an applicable payment system pursuant to paragraph (21) of section 1833(t) of the Act) for items and services furnished on or after January 1, 2028, by an off-campus outpatient department of a provider unless that department has obtained, and the items and services are billed under, an NPI that is separate from the NPI of the main provider; the main provider has submitted to the Secretary, during the 2-year period ending on the date such items and services are furnished, an initial provider-based status attestation that the off-campus outpatient department is compliant with the requirements described in section § 413.65 (or a successor regulation); and the main provider has submitted a subsequent attestation within the timeframe specified by the Secretary. The initial attestation may include an attestation submitted in accordance with existing § 413.65(b)(3) until the Secretary establishes the new attestation submission process, which is discussed further below. New section 1833(t)(23)(B)(i) of the Act requires the Secretary, through notice and comment rulemaking, to establish a process for each provider with an off-campus outpatient department to submit an initial and subsequent attestation, for the review of each such attestation and for the determination, through site visits, remote audits, or other means (as determined appropriate by the Secretary), whether each off-campus outpatient department is compliant with the requirements described in subparagraph (A). In addition, new section 1833(t)(23)(C) of the Act defines an “off-campus outpatient department of a provider” for purposes of paragraph (23) as a department of a provider (as defined in § 413.65) that is not located on the campus (also defined in § 413.65) of the main provider or is not within the distance described in such definition of campus from a remote location of a hospital (also defined in § 413.65).
This is the proposed language for handling Section 6225
Certain transmissions, including of paper, via facsimile, and of voice, via telephone, are not considered to be transmissions via electronic media if the information being exchanged did not exist in electronic form immediately before the transmission.
The current definition of "electronic media" excludes Fax for anything that was not digital immediately before transmission.
The problem with faxes
Fred Trotter (me) analysis of the security of Fax from 2010
protected health information stored, whether intentionally or not, in photocopier, facsimile, and other devices is subject to the Privacy and Security Rules.
Change indicating that digital copies of patient records stored in the memory of fax machines was covered under HIPAA
This modification clarifies that a facsimile machine accepting a hardcopy document for transmission is not a covered transmission even though the document may have originated from printing from an electronic file.
Discussing print then scan-over-fax
Regarding the comment on the active work on a National Directory FHIR IG, we thank this commenter for pointing this out. Because we have not required the publication of individual provider-level identifiers, we are not considering this IG for the endpoint publication use case in our Program. We emphasize again that because we have finalized an approach in § 170.404(b)(2) that references the base FHIR standard, Certified API Developers have the flexibility to consider using “Organization” and “Endpoint” FHIR resources profiles, such as the profiles in the National Directory FHIR IG, to meet those requirements.
Specifically mentioning the NDH FHIR workgroup and the NPD implmentation in terms of meeting requirements.
Response. We appreciate commenters' input and suggestions for clarity. We intend for these additional organization details to be used by app developers to help them map organizations to endpoints which, in turn, helps patients find the organization(s) they want to allow an app to access data from. We clarify that facility or organization level identifiers are sufficient to satisfy our proposed publication requirements. Facility level identifiers, for the purposes of certification to these Endpoint publication requirements, include identifiers such as: a National Provider Identifier (NPI), Clinical Laboratory Improvement Amendments (CLIA) number, CMS Certification Number (CCN), or other health system ID. Support for one of these identifier types is sufficient, meaning Certified API Developers are not required to publish individual NPIs as a floor for certification. Different identifiers may be used depending on the customers a Certified API Developer has. We have updated our regulatory text at § 170.404(b)(2)(ii)(B) to more clearly state that “[e]ach Organization resource must contain the organization's name, location, and facility identifier.”
Patients finding data from EHRs that hold their data requires either NPI, CLIA, or CCN. They are not required to publish "individual" NPIs. But they have to have ONPI or something else that we can link to.
will still be required to publish organization details such as name, location, and facility identifier.
While the organization standard in general will be somewhat relaxed. "name, location and identifier" are still required.
A Study of the Cost of CareProvided in Physician-Owned HospitalsCompared to Traditional HospitalsAnalysis of 20 High-Cost Diagnostic RelatedGroups Using 2019 Medicare Claims DataRobert H. Aseltine Jr., PhDDirector, Center for Population HealthUConn HealthConsultant to the Physicians AdvocacyInstitute and The Physicians FoundationGregory J. Matthews, PhDDirector, Center for Data Science and ConsultingLoyola University ChicagoConsultant to the Physicians AdvocacyInstitute and The Physicians Foundation
cost of care analysis from physician owned hospitals
Bill introduced to allow physician-owned hospitals in rural areas
At least in some cases the AMA supports physician owned hospitals
Keeping the Brakes on Physician-owned Hospitals is Best for Patients
The AHA is against physician owned hospitals.
Ownership of Hospitals
This is an ASPE analysis of of common ownership of hospitals
Physician-Owned Hospitals Seize Their Moment
Article on quality differences at physician owned hospitals
Physician-Owned Hospitals
This page discussed the already exempted physician owned hospitals, as well as those that are applying for exemptions.
About Erowid
Erowid is the largest online repository of psychoactive illicit drug use experience chronicles.
Subpart D—Standard Unique Health Identifier for Health Care Providers
This is the current NPI standard from HIPAA which now explicitly mentions the NPI by name.
Under such system, the Secretary may impose appropriate fees on such physicians to cover the costs of investigation and recertification activities with respect to the issuance of the identifiers.
Specific language in the law allowing for fees for issuing identifiers.
(c) Code Sets.-- ``(1) In general.--The Secretary shall adopt standards that-- ``(A) select code sets for appropriate data elements for the transactions referred to in subsection (a)(1) from among the code sets that have been developed by private and public entities; or ``(B) establish code sets for such data elements if no code sets for the data elements have been developed. ``(2) Distribution.--The Secretary shall establish efficient and low-cost procedures for distribution (including electronic distribution) of code sets and modifications made to such code sets under section 1174(b).
This is the HIPPA right to identify codesets etc.
(1) In general.--The Secretary shall adopt standards for transactions, and data elements for such transactions, to enable health information to be exchanged electronically, that are appropriate for-- ``(A) the financial and administrative transactions described in paragraph (2); and ``(B) other financial and administrative transactions determined appropriate by the Secretary, consistent with the goals of improving the operation of the health care system and reducing administrative costs. ``(2) Transactions.--The transactions referred to in paragraph (1)(A) are transactions with respect to the following: ``(A) Health claims or equivalent encounter information. ``(B) Health claims attachments. ``(C) Enrollment and disenrollment in a health plan. ``(D) Eligibility for a health plan. ``(E) Health care payment and remittance advice. ``(F) Health plan premium payments. ``(G) First report of injury. ``(H) Health claim status. ``(I) Referral certification and authorization.
This is the "standards for transactions" part of HIPAA. This gives HHS/CMS the right to dictate FHIR or X12, for different transactions.
(b) Unique Health Identifiers.-- ``(1) In general.--The Secretary shall adopt standards providing for a standard unique health identifier for each individual, employer, health plan, and health care provider for use in the health care system. In carrying out the preceding sentence for each health plan and health care provider, the Secretary shall take into account multiple uses for identifiers and multiple locations and specialty classifications for health care providers. ``(2) Use of identifiers.--The standards adopted under paragraph (1) shall specify the purposes for which a unique health identifier may be used.
This is the specific legal basis for the enumeration of NPIs and plans.
It is the purpose of this subtitle to improve the Medicare program under title XVIII of the Social Security Act, the medicaid program under title XIX of such Act, and the efficiency and effectiveness of the health care system, by encouraging the development of a health information system through the establishment of standards and requirements for the electronic transmission of certain health information.
This is the place where the constraints for the HIPAA administrative rule is defined.
Regulations.-- (1) In <<NOTE: Regulations.>> general.--If legislation governing standards with respect to the privacy of individually identifiable health information transmitted in connection with the transactions described in section 1173(a) of the Social Security Act (as added by section 262) is not enacted by the date that is 36 months after the date of the enactment of this Act, the Secretary of Health and Human Services shall promulgate final regulations containing such standards not later than the date that is 42 months after the date of the enactment of this Act. Such regulations shall address at least the subjects described in subsection (b). (2) Preemption.--A regulation promulgated under paragraph (1) shall not supercede a contrary provision of State law, if the provision of State law imposes requirements, standards, or implementation specifications that are more stringent than the requirements, standards, or implementation specifications imposed under the regulation.
This is the "trigger clause" in HIPAA that caused HHS to create the Privacy and Security Rules.
NPPES health care provider data that are required to be disclosed under the FOIA will be available as a downloadable file on a Web site.
There is an explicit requirement to have data that is FOIA available from NPPES publicly available for download.
In accordance with the requirements of the Privacy Act of 1974, CMS is proposing to modify or alter existing system of records titled “National Provider System,” System No. 09-70-0008.
This is a SORN change notice for NPPES
To an individual or organization fora research, demonstration, evaluation,or epidemiological project related to theprevention of disease or disability, therestoration or maintenance of health, orfor the purposes of determining,evaluating and/or assessing cost,effectiveness, and/or the quality ofhealth care services provided.
The research use case in the original NPPES SORN.
National Provider Identifier Standard (NPI)
The homepage for the NPI standard
NPS DATA ELEMENTS
Originally defined NPPES data elements
We agree with commentersthat it would be costly to collect,validate, and maintain certification andschool information.
Current decision not to include school-level credential data
The NPI may also be used for anyother lawful purpose requiring theunique identification of a health careprovider.
NPI can be used to uniquely identify healthcare provider for any purpose
HHS will exercise overallresponsibility for oversight andmanagement of the NPS.
At the level of the rule, HHS is responsible for NPPES
The NPS will be designed to be easyto use. The design will employ the latesttechnological advances whereverfeasible for capturing health careprovider data and making informationavailable to users.
This is a specific mandate to keep NPPES up-to-date technologically.
Communicate to the NPS anychanges to its required data elements inthe NPS within 30 days of the change.
Providers are required to provide updates to NPPES within 30 days of the change.
A strong majority ofcommenters supported our proposalthat the NPI be intelligence-free.
This is where the "intelligence-free" mandate comes from
We find the statedadvantages of a 10-position numericidentifier convincing. We have revisedproposed § 142.402 (now § 162.406(a))to provide that the NPI will be a 10position numeric identifier, with the10th position being an ISO standardcheck digit.
NPI mandated to be a 10 digit code with a check digit as per the ISO standard.
A health care provider’s NPI willnot be deactivated if that health careprovider is sanctioned or barred fromone or more health plans.
Deactivation parameters
We do not consider individuals whoare health care providers (that is, theymeet our definition of ‘‘health careprovider’’ at § 160.103) and who aremembers or employees of anorganization health care provider to be‘‘subparts’’ of those organization healthcare providers, as described earlier inthis section.
Employed individuals are not organizational sub-parts.
We define two categories of healthcare providers for enumerationpurposes. A data element, the ‘‘Entitytype code,’’ in the NPS record for eachhealth care provider will indicate theappropriate category.• NPIs with an ‘‘Entity type code’’ of1 will be issued to health care providerswho are individual human beings.Examples of health care providers withan ‘‘Entity type code’’ of 1 arephysicians, dentists, nurses,chiropractors, pharmacists, and physicaltherapists.• NPIs with an ‘‘Entity type code’’ of2 will be issued to health care providersother than individual human beings,that is, organizations. Examples ofhealth care provider organizations withan ‘‘Entity type code’’ of 2 are: hospitals;home health agencies; clinics; nursinghomes; residential treatment centers;laboratories; ambulance companies;group practices; health maintenanceorganizations; suppliers of durablemedical equipment, supplies related tohealth care, prosthetics, and orthotics;and pharmacies
Type 1 (individual) and Type 2 (organizational) are mandated here.
We decided not toestablish sub-IDs because our decisionsregarding which entities would beeligible to receive NPIs (includingseparate physical locations and subpartsof certain kinds of organization healthcare providers) obviate the need forthem. Sub-IDs may be useful as a laterimplementation feature that wouldsupport EDI routing or other purposes.We will consider an expansion at a latertime to include them, if we determinethat they would be beneficial.
Personal NPIs cannot have "sub" ids. However, they could in the future according to this rule.
For purposes of this rule, weconsider group health care providers tobe organization health care providers.
Group healthcare providers are organzations for the purpose of the NPI rule.
that the organization healthcare provider is a legal entity and is thecovered entity under HIPAA if it (or asubpart or component) transmits healthinformation in electronic form
This is the connection between an organization, legal entity, sub-parts and being a covered entity.
We accommodate this language byrequiring covered health care providersto obtain NPIs for subparts of theirorganizations that would otherwisemeet the tests for being a covered healthcare provider themselves if they wereseparate legal entities, and permittinghealth care providers to obtain NPIs forsubparts that do not meet these tests butotherwise qualify for assignment of anNPI.
Organization subparts are intended to address specific legal obligations regard organizational provider locations.
Therefore, because these kinds ofentities are not health care providers,they will not be eligible for NPIs.
A clearinghouse does not get an NPI.
Only those entitiesthat (1) meet the definition of healthcare provider at § 160.103, and (2)transmit health information inelectronic form on their own behalf, orthat use a business associate to transmithealth information in electronic form ontheir behalf, in connection with atransaction for which the Secretary hasadopted a standard (a coveredtransaction) are health care providerswho are required to comply with theHIPAA regulations.
But if you move healthcare data around, based on covered transactions, you -do- need an NPI
The fact that a healthcare provider obtains an NPI does notimpose covered entity status on thathealth care provider.
Having an NPI does not make you HIPAA covered.
Our general rule is that allhealth care providers, as we define thatterm in the regulations, will be eligibleto receive NPIs
All healthcare providers are eligible to receive NPIs assuming they have been identified as a healthcare provider in any HHS regulation
National ProviderSystem (NPS)
NPS was the original name for NPPES in the regulation.
HIPAA Administrative Simplification:Standard Unique Health Identifier forHealth Care Providers
This in the NPI Final Rule, which establishes the details of what NPPES is an how it works.
Notice: Redaction of Teaming Data
This was the original docgraph retraction notice.
We did not know it at the time, but the "Update Oct 5 2012" message that we took a screen-shot of would be the only acknowledgement that CMS ever made about the problem.
DocGraph Teaming data update
This is the second post on the DocGraph retraction. It documents the fact that CMS would not collaborate with us to ensure that the data they were releasing was correct, but the data was released and "looked right".
outpatient
Epic goes head to head with Kaiser in CA
How I hunt down fake degrees and zombie universities
This article could be helpful in term of methodology
The KXAN team said they found at least 49 doctors who had disciplinary actions in other states — including having their medical licenses suspended, revoked or surrendered — who were still practicing or able to in Texas.
The core problem with credentialing in states with lax medical board information.
HAY, BRADLEY GLENN
Medical Board record for Bradley_Glenn_Hay shows his license being suspended and hospital credential loss in 2018.
Medical License suspension for Bradley_Glenn_Hay
BRADLEY GLENN HAY M.D.
Bradley_Glenn_Hay NPPES record
ROMAN GERARD PEPLINSKI M.D.
NPPES record for Roman Peplinski
Roman Peplinski
Roman_Peplinski
RAYNALDO RIVERA ORTIZ
NPPES Record for Raynaldo_Rivera_Ortiz
Raynaldo Rivera Ortiz
Raynaldo Rivera Ortiz a Texas anesthesiologist, injecting drugs meant for patients. Sentenced to prison.
DUNTSCH, CHRISTOPHER DANIEL
This is the voluntarily surrendered medical license of Christopher Duntsch
CHRISTOPHER D DUNTSCH
NPPES record for Christopher_Duntsch which has him still listed as having medical licensing in Tennessee.
Christopher Daniel Duntsch
Wikipage for spinal surgeon Christopher Duntsch who faked credentials and was still allowed to move around Dallas hospitals as a spinal surgeon before being caught.
cron monitoring service
Guidance on National Provider Identifier (NPI) Enumeration; 45 Code of Federal Regulations(CFR) § 162.412(b)
This guidance details the rules for "getting additional NPIs" in order to work with non-government payers.
It emphasizes that payers may no require an individual to get an additional NPI.
It highlights the rules for payers to require organizational subpart NPIs (this is a feature of organizational NPIs)
At least one of the following elements must be present: PractitionerRole.practitioner PractitionerRole.organization PractitionerRole.healthcareService PractitionerRole.location
You do not need to have all of these. But you do need one of them
Binding: Care Team Member Function (extensible): Indicates specific responsibility of an individual within the care team, such as Primary physician, Team coordinator, Caregiver, etc.
This is where function at location is stored.
Limitations of UsingCMS Data to IdentifyPrivate Equity andOther OwnershipReport to the Ranking Member,Committee on Ways and Means, Houseof RepresentativesSeptember 2023GAO-23-106163United States Government Accountability Office
This has implications for the use of the open ownership files in ndh.
The Network profile is based on USCore Organization Profile.
This is where the NDH documents that a network is a type of organization.
The Network profile is based on USCore Organization, since there was no contradiction between the USCore profile and the Plan-Net requirements.
As a result of this paragraph, the json container for a Network in the PlanNet API is actually an "Organization" that
The Data Quality Act: History and Purpose
This article gives the political background of the data quality act, including the note that the PRA has the same requirements as the data quality act, but without a timeline.
Information for which ICANN has responsibility includes the WHOIS databases. ICANN has been given specific responsibilities for these databases under: 1) their contract with the U.S. government’s Department of Commerce to perform the technical management of the Internet; and 2) their Memorandum of Understanding with the Department of Commerce.
Accordint to this ICANN is subject to the information quality act (also called the data quality act).
Not sure if this continues to be true.
INFORMATIONQUALITY ACTActions Needed toImprove Transparencyand Reporting ofCorrection Requests
In 2015 the GOA reported on how well the Information Quality Act was being implemented.
Centers for Medicare & Medicaid Services
This is the CMS IQA Guidelines page.
Best Practices for Data Standards
The source of open data standards as a matter of government policy.
Individuals and interactions over processes and tools Working software over comprehensive documentation Customer collaboration over contract negotiation Responding to change over following a plan
The "this over that" policy preferences.
This document details the subtle differences between the HIPAA privacy rule as it was released at the end of the Clinton administration, vs the revised version released early in the Bush administration.
This specifically discusses the differences between Treatments, Payment and Operations (TPO).
Marcy Wilder is the author of the HIPAA rules
This is a clone of a now-down page on HHS where President Clinton made remarks about privacy
News article on the release of the HIPAA privacy rules
This is the executive order from Bill Clinton regarding the use of EHR data for federal criminal investigations.
Inferno is the ONC system for doing FHIR testing
involved in the development of udap
The home page for udap
fhir_upap
This is a FHIR testing system
Their project would aim to get around the Paperwork Reduction Act approval rule by providing a toolkit on how to use only nine people to improve web design, called “Talk to 9.”
This is the paperwork reduction act hack
article on Susannah Fox's "hack the red tape" efforts. Including the talk to nine project.
This 2012 announcement for specific billing transaction standards.
A standard unique identifier for health plans;
This makes a promise for a standard unique identifier for health plans.
Network adequacy standards for QHPs
If there were penalties for violating the rules of updating an NPI I think this would be the place they would live.
This is the source of the JSON files at the payer websites that show the plan data for each healthcare.gov available plan which is an "Exchange Qualified Health Plan" or QHP for short
§ 170.213 United States Core Data for Interoperability. The Secretary adopts the following versions of the United States Core Data for Interoperability standard: (a) Standard. United States Core Data for Interoperability (USCDI), July 2020 Errata, Version 1 (v1) (incorporated by reference, see § 170.299). The adoption of this standard expires on January 1, 2026. (b) Standard. United States Core Data for Interoperability Version 3 (USCDI v3) (incorporated by reference, see § 170.299). [89 FR 1428, Jan. 9, 2024]
This page seems to indicate that many of the standards have a refernce back to USCDI both v1 and v3, with v1 expiring at the beginning of 2026.
Does this mean that USCDI is not mandating NPI until 2026.
comply with the content and vocabulary standard requirements
vocabulary standards
conduct routine testing and monitoring, and update as appropriate, to ensure the API functions properly
Requirement to test
must implement and maintain a standards-based Application Programming Interface (API)
Here it says that the MA plans must be "standards-based".
without special effort
This is the simple phrase that means it must be standards compliant.
This is the requirements for Medicare Advantage Payers to implement directories that explain coverage contents.
This page documents the various FHIR standards that are generally encorporated into other API standards.
In the Interoperability and Patient Access final rule (CMS-9115-F), CMS encouraged MA-PD plans to build a Provider Directory API that is conformant to the Health Level Seven International® (HL7®) PDex Plan-Net Implementation Guide (85 FR 25529).
Apparently PDex standard is "encouraged." but not required.
A possible new playbook for USDS, developed during COVID
CMS ASTP Response Provider Directory APIs with Issues
fhir payer ids that do not work.
CMS/ASTP RFI Response: Provider Directory API that works
This video shows payer fhir API that are functional
The TEFCA Common Agreement is the basis for health information exchange.
This page links to current and previous versions of the common agreement.
This is the SOP for RCE Directory Service Requirements
HIPAA at 25 — The lasting health privacy protections of the Clinton administration
This is the story of the conversion of HIPAA, a law with no privacy, interoperability or security details turned into the central privacy regulatory framework for healthcare data in the US.
Back in 1996, as HIPAA legislation was on the verge of passing with bi-partisan support, thorny privacy issues were threatening to scuttle the entire enterprise. A compromise was struck whereby Congress would give itself a deadline of three years to enact privacy legislation, and if it didn’t — the Department of Health and Human Services (HHS) Secretary would by default be required to issue privacy regulations. On the day that three years expired, I was the Deputy General Counsel at HHS and happened to be standing in my boss’ office when Secretary Donna E. Shalala walked in, smiled, and said, “Well, they missed the deadline, I guess you better get started.” The General Counsel, Harriet Rabb, turned to me and said, “I think this one is yours.” With that, I began advising an amazing team of policymakers at HHS as we went about drafting the first federal health privacy regulations in the United States.
This is the reason why the HIPAA law says almost nothing about interoperability and yet it created extensive privacy regulations and interoperability fundamental standards.
Transforming Health Care: The President’s Health Information Technology Plan
President GW Bush health information technology plan, which included the creation of the Office of the National Coordinator ONC. Released shortly after his state of the union a few months earlier.
When arriving at a physician’s office, new patients do not have to enter their personal information, allergies, medications, or medical history, since it is already available.
Specific interoperability goal outlined by president Bush
President Clinton Issues Strong New Consumer Protections to Ensure the Privacy of Medical Records
This is the press release from the Clinton whitehouse on the release of the HIPAA privacy rule.
to make medical records easier to see for those who should see them, and much harder to see for those who shouldn't.
Bill Clinton discussing in simple terms the portions of HIPAA designed to ensure the medical records would be interoperable in a secure fashion.
These are the statements by President Bill Clinton on the release of the HIPAA Privacy Rule in 2000
has published application programming inter-faces and allows health information from such tech-nology to be accessed, exchanged, and used withoutspecial effort through the use of application program-ming interfaces or successor technology or standards,as provided for under applicable law, including pro-viding access to all data elements of a patient’s elec-tronic health record to the extent permissible underapplicable privacy laws
This is the section of the CURES act that specifically mandates API based interoperability.
enables the secure exchange of electronic healthinformation with, and use of electronic health informationfrom, other health information technology without specialeffort on the part of the user
This is the second clause in the CURES act that mandates general standards-based health information exchange using the "without special effort" clause
without special effort.
Ken Mandls JAMIA article highlying the CURES ACT rules on interop
CMS ANNOUNCES THE STANDARD UNIQUE HEALTH IDENTIFIER FOR HEALTH CARE PROVIDERS FOR USE IN STANDARD TRANSACTIONS UNDER HIPAA
This is the announcement of both NPI and NPPES
Online Medicare Cost Reportsand Custom Data Sets
Online Cost Report Data vendor
Cost Reports
The source for medicare hospital cost report data
340B and the Medicare Cost Report
Teh 340B program and medicare hospital cost report
Medicare Hospital Cost Report Analysis approach
Medicare Cost Report Data: Structure
Medicare Cost reports have a huge amount of hospital related data
Generic Product Identifier
This is a medication product grouper
This page discussed NDC and HCPCS code data
Welcome to BioPortal, the world's most comprehensive repository of biomedical ontologies
Medical Onotologies. They had to take out CPT codes a few years ago..
The DailyMed database
Daily med is the source of the XML drug label files
NBER affiliates can access this and other data through the NBER computing system
NBR has lots of old NDC data
The crosswalk for NPPES and PECOS taxonomy codes
The Health Care Provider Taxonomy code
The provider taxonomy codes in NPPES
Center for Medicare and Medicaid Services (CMS) National Plan and Provider Enumeration System (NPPES)
NPPES is included in the do not pay initiative.
Medicare and Medicaid Dual Eligible Data Book
Overview Of IPEDS Data
This can be used for medical school data
HHS Information Quality Guidelines
HHS Information Quality Guidelines
Data Optimization
Now retired Data Optimization effort
Data Quality Act
The Data Quality act has federal data strategy implications
Information Quality Guidelines
HHS Information Quality Guidelines
Confidential Information Protection and Statistical Efficiency Act
This has relevance for the Federal Data Strategy
Open Data Policy-Managing Information as an Asset
Obamas managing Information as an asset.
Managing Federal Information as a Strategic Resource
Obama managing Federal Information as a strategic resource.
Quality, Objectivity, Utility, and Integrity of Information Disseminated by Federal Agencie
The 2002 Guidelines has data strategy implications
E-Government 44 USC lOi note.Act of 2002
e-government act has implication and is referenced in federal data strategy
Making Open and Machine Readable the New Default for Government Information
Machine readable the new default
Federal DataStrategy
Phase I Federal Data Strategy Memorandum
Request for Agency Feedback on the Federal Data Strategy
Feedback request for federal data strategy
This project uses the NPPES API to load data into a Mongo DB.
import NPPES into MongoDB
Load NPPES and Taxonomy data into PostgreSQl and Oracle
python to Oracle/PostGreSQL importer for NPPES
NPI_Search_MSSQL_PHP
MicrosoftSQL NPPES import script
NPPES CSV Import and Sanitation Project - PHP, Symfony4, MySQL
NPPES Symfony php import script to MySQL
NPPES NPI + Postgres
NPPES to Postgress importer
Medicare Provider and Supplier Taxonomy Crosswalk
This is the crosswalk between the PECOS and NPPES provider type systems as a dataset
CROSSWALKMEDICARE PROVIDER/SUPPLIER to HEALTHCARE PROVIDER TAXONOM
This is the crosswalk between the NPPES and PECOS provider type systems.
If your taxonomy code is invalid or your taxonomy indicates you do not have the right to prescribe certain drugs, pharmacies using Express Scripts, Inc. (ESI)—our primary pharmacy network—will not fill your patients’ prescriptions.
This is a good example of how the NPPES taxonomy code is being relied on in the public.
The Complete History of the NPI Number The National Provider Identifier (NPI) is an under-appreciated marvel of the modern healthcare system.
This is a wonderful history of the NPI system.
NPI Fact SheetF o r H e a l t h C a r e P r o v i d e r sW h o A r e S o l e P r o p r i e t o r s
This is the NPI fact sheet from 2007 regarding sole-proprietors
This is the MLN Matters article that details the errors providers make as the enter data into NPPES. This version was updated in 2012
Part D plans must submit an electronic record, called a PDE record, toCMS for each covered prescription filled for their enrollees. CMSrequires that most PDE records contain an identifier for the drug’sprescriber. Acceptable prescriber identifiers include National ProviderIdentifiers (NPI), Drug Enforcement Administration (DEA) registrationnumbers, Unique Physician Identification Numbers (UPIN), and Statelicense numbers
This report calls for using NPI to correct mistaken provider identifiers in Part D programs.
US Department of Health and Human ServicesPrivacy Impact AssessmentDate Signed:12/22/2016OPDIV:CMSName:National Plan and Provider Enumeration System
The NPPES Privacy Impact Assesment.
National Standard Health CareProvider IdentifierAGENCY : Health Care FinancingAdministration (HCFA), HHS.ACTION: Proposed rule.SUMMARY : This rule proposes a standardfor a national health care provideridentifier and requirements concerningits use by health plans, health careclearinghouses, and health careproviders.
This is the proposed rule (not the final) for NPS the predecessor to NPPES.
the same name andNational Provider Identifier (NPI) (asrequired to be reported in this final rule)should be used consistently for allpayment lines and any subsequentupdates for the same individual.
Final rule from the Sunshine act details exactly how the NPI should be leveraged for reporting.
The name of the covered recipient.‘‘(ii) The business address of the covered recipientand, in the case of a covered recipient who is a physi-cian, the specialty and National Provider Identifierof the covered recipient.‘‘(iii) The amount of the payment or other transferof value.‘‘(iv) The dates on which the payment or othertransfer of value was provided to the covered recipient.‘‘(v) A description of the form of the payment orother transfer of value, indicated (as appropriate forall that apply) as—‘‘(I) cash or a cash equivalent;‘‘(II) in-kind items or services;‘‘(III) stock, a stock option, or any other owner-ship interest, dividend, profit, or other return oninvestment; or‘‘(IV) any other form of payment
This is the requirement in the Sunshine Act that reports of payments that physicians have recieved will not include the NPI of the Physician.
Department of Health and Human ServicesOFFICE OFINSPECTOR GENERALMPROVEMENTS EEDED TOE NSURE P ROVIDERE NUMERATION AND MEDICAREENROLLMENT DATA AREACCURATE , C OMPLETE , ANDONSISTENTDaniel R. LevinsonInspector GeneralMay 2013OEI-07-09-00440I NC
This is the OIG report on the failings of NPPES.
Of the 10,504 locations reviewed, providers should not have been listed at 33.14% (3,481) of thelocations (2,088 + 1,393, as shown in Table 5) either because the provider did not work at thelocation or because the provider did not accept the plan at the location. In 1,393 of theseinstances, the provider should not have been listed at any of the locations in the directory. Therewere 690 phone numbers that were wrong or disconnected and 364 incorrect addresses. Finally,there were 221 instances in which the provider was found not to be accepting new patients,although the directory indicated that the provider was accepting new patients. Table 5 provides abreakdown of deficiencies identified by CMS during the review process.
This is a review of Medicare Advantage Plans provider directories. It details multiple failings in these provider directories. NPPES is not directly mentioned, but is likely the source of the various business address problems in the data.
In accordance with the NPPES Data DisseminationNotice (CMS-6060), published May 30, 2007, certain information that you furnish will be publicly disclosed. The NPPES DataDissemination Notice can be found at https://www.cms.gov/Regulations-and-Guidance/Administrative-Simplification/NationalProvIdentStand/Downloads/NPPES_FOIA_Data-Elements_062007.pdf.
This is the link between the current NPPES paper form and the details about which data fields will be disseminated.
NATIONAL PROVIDER IDENTIFIER (NPI) APPLICATION/UPDATE FORM
This is the paper form version of NPPES. CMS-10114 is the form number. It was revised in 2021.
This is the letter to providers detailing what elements of NPPES would be disclosable.
The Centers for Medicare & Medicaid Services (CMS) is pleased to announce theavailability of a new identifier for use in the standard electronic health care transactions.The National Provider Identifier (NPI) will be the single provider identifier, replacir1g thedifferent provider identifiers you currently use for each health plan with which you dobusiness.
This is the 2005 letter to providers announcing the NPI standard.
The NCVHS has been briefed on theproposal for the National Provider Identifier(NPI), and we offer our strong support.
This is NCVHS, which is a committee that advises the HHS secretary on things, recommends the NPI standard based on briefings on the matter.
In the January 23, 2004 Federal Register (69 FR 3434), the U.S. Department of Health and Human Services (HHS) published a final rule establishing the standard for a unique health identifier for health care providers for use in the health care system and adopting the National Provider Identifier (NPI) as that standard (“2004 NPI final rule”). The rule also established the implementation specifications for obtaining and using the NPI. Since that time, pharmacies have encountered situations where they need to include the NPI of a prescribing health care provider in a pharmacy claim, but where the prescribing health care provider has been a noncovered health care provider who did not have an NPI because he or she was not required to obtain one. This situation has become particularly problematic in the Medicare Part D program. The addition to the NPI requirements addresses this issue.
This is where NPI became required for prescribing.
SORN 09-70-0555 System Name: National Plan and Provider Enumeration System" (NPPES), HHS/CMS/OFM.
This is the current SORN for NPPES. Does not appear to have changed since 2017.
Privacy Act of 1974; System of Records A Notice by the Health and Human Services Department on 02/14/2018
This is a list of SORNS that are impacted by a privacy change.. and it includes NPPES
Privacy Act of 1974; Report of a New Routine Use for Selected CMS Systems of Records A Notice by the Centers for Medicare & Medicaid Services on 05/29/2013
This is an addition of the use of NPPES to fight waste fraud and abuse. In 2013.
newsystem of records, called the ‘‘NationalProvider System (NPS),
This is the original SORN for the predecessor to NPPES: NPS.
modify or alter existing system of records titled “National Provider System,” System No. 09-70-0008
This is the first modification of the NPPES SORN. In 2010.
HIPAA Administrative Simplification: National Plan and Provider Enumeration System Data Dissemination
This is the regulations.gov version of the NPPES data dissemination notice. With this version it an be easier to see related documents and other content from the regulatory process.
HIPAA Administrative Simplification: National Plan and Provider Enumeration System Data Dissemination
The NPI Dissemination rule is what determines what is FOIA available from the NPPES data.
National Provider Identifier Standard (NPI): Educational Resources
This page makes reference to educational resources about the NPI system sent out to providers. This includes MLN Matters articles and NPI Roundtables.
Medicare NPI Implementation
This is the homepage for six different documents related to the transition between the old Medicare identifiers and the new NPI system.
National Plan and Provider Enumeration System (NPPES) Data Changes
This is the notice that caused NPPES to start to track gender identity. It also changed how individual providers could use address PO Boxes.
Prescription Drug Monitoring Program (PDMP)
The webpage for the Alabama Prescription Drug Monitoring Program.
n New Year’s Day 2020, I was zipping up my fleece to head outside when the phone in the kitchen rang. I picked it up to find a reporter on the line. “Dr. Fauci,” he said, “there’s something strange going on in Central China. I’m hearing that a bunch of people have some kind of pneumonia. I’m wondering, have you heard anything?”
Dr. Fauci first hears of COVID-19
HRSA MADE COVID-19UNINSURED PROGRAMPAYMENTS TO PROVIDERS ONBEHALF OF INDIVIDUALS WHOHAD HEALTH INSURANCECOVERAGE AND FOR SERVICESUNRELATED TO COVID-19
Protected health informationmeans individually identifiablehealth information:(1) Except as provided inparagraph (2) of this definition,that is:(i) Transmitted by electronicmedia;(ii) Maintained in electronicmedia; or(iii) Transmitted or maintainedin any other form or medium.
The definetion of PHI.. without regulatory exclusions. The exclusions being listed in the following section.
Individually identifiable healthinformation is information thatis a subset of health information,including demographicinformation collected from anindividual, and:(1) Is created or received by ahealth care provider, health plan,employer, or health careclearinghouse; and(2) Relates to the past, present,or future physical or mentalhealth or condition of anindividual; the provision ofhealth care to an individual; orthe past, present, or futurepayment for the provision ofhealth care to an individual; and(i) That identifies the individual;or(ii) With respect to which thereis a reasonable basis to believethe information can be used toidentify the individual
This is the definition of "Individually Identifiable Health Information". It is not clear from this section if this is equivalent to the "PII" concept. But it does indicate that it includes at least a subset of information that also counts as "PHI".
ii) A person that offers apersonal health record to one ormore individuals on behalf of acovered entity
A PHR is a covered entity if it offers its PHR "On Behalf Of" a covered entity.
February 25 telebriefing
Here is the briefing: https://www.cdc.gov/media/releases/2022/a0225-covid-19-update.html
On February 9,2020, using publicly available data, a senior health official from the U.S. Department of VeteransAffairs warned key senior officials that COVID-19 was more transmissible and deadlier thanH1N1 and the U.S. was only a “couple of weeks” behind the spread in China
A search fails to reveal these communications.
In its February 24, 2020supplemental funding request, the Office of Management and Budget wrote, “[t]o this point, noagency has been inhibited in response efforts due to resources or authorities.
Here is some reporting on this supplemental reporting request. But I am unable to find the funding request itself.
https://www.politico.com/news/2020/02/24/trump-coronavirus-budget-request-117275
The Strategic National Stockpile distributed the last of its PPE held for states on April 19,2020—the same day it made the decision to begin allocating PPE based on need, not population.
I cannot find this information in other places easily.
in May 2020 when the federal governmentdecided to extend a one-year federal PPE contract to that same PPE manufacturer, the companydeclined the contract offer
Have not been able to find record of this decline.
When one domestic PPE manufacturer sent multiple warnings and requests toramp up U.S. production throughout the months of January, February, and March 2020, thefederal government declined to engage
Have not been able to find this. Which PPE manufacturer? Are these warnings published?
conflicting internal accounts of not only whatwent wrong, but also the reasons for those failures
Begs the question. Why did the CDC efforts fail initially.
. Ultimately, the Trump Administration waited until March16, 2020—fifty-five days from the date of the first confirmed case—to implement its first widescale attempt at nationwide mitigation of viral spread.
Here is the link to the text of that announcement and a link to the Youtube video for that event.
Alex Azar declared a public health emergency
as early as mid-December 2019
The apparent source of this information is a study done by the CDC in Nov 2019.
initiating export bans on personalprotective equipment (PPE
Here is one such article on the EU banning the export of PPE.
Over the last 10 years, we’ve lost 360,000. These are people that have died from the flu — from what we call the flu. “Hey, did you get your flu shot?” And that’s something.
President Trump admitting that he was not aware that influenza was a public health problem.
The Johns Hopkins, I guess — is a highly respected, great place — they did a study, comprehensive: “The Countries Best and Worst Prepared for an Epidemic.” And the United States is now — we’re rated number one. We’re rated number one for being prepared
This study appears to be the Global Health Security Index 2019 report, which is hosted by Johns Hopkins School of Public Health along with the Nuclear Threat Initiative (NTI), with help from the Economist.
This is the annotation of the United States favorable score.
1 United States
Presumably, this is the score for Global Health Security Index, in which the United States scores as first, mere months before the COVID-19 pandemic began.
This score was referenced by Trump in an White House Press briefing on Feb 26, 2020.