EHRA questions rationale of added TEFCA security protocols

In its comments to the ONC on the draft QHIN, Participant and Subparticipant Additional Requirements SOP, the EHR Association recommends workforce authentication requirements be applied only to the Qualified Health Information Network workforce, with specific consideration given to participants and sub-participants who are not HIPAA-covered entities.

WHY IT MATTERS

The Office of the National Coordinator for Health Information Technology (ONC) is accepting comments on proposed requirements for QHINs, participants and sub-participants under its Trusted Exchange Framework and Common Agreement developed by the enlisted Sequoia project.

In its January 13 letter, EHRA indicated that the need and benefit of added requirements are unclear and suggested narrowing the scope for workforce authentication requirements and auditing standards.

“Auditing standards should align with those in place under the ONC Certification Program,” the association said.

“We note that Carequality does not have such authentication requirements, nor has identified the need to do so.”

In addition to noting the substantial end-user workflow changes that would be required, the association of vendors also said healthcare providers as covered entities can determine what authentication methods are appropriate for their workforces under HIPAA, based on their understanding of their risks.

If there is a need to require additional authentication, “we suggest that it be done consistently through regulatory processes to ensure [protected health information] meets the same standards and procedures wherever it flows, within an organization, within a network or outside a network.”

Other comments on definitions and standards are in the spirit of specifying TEFCA actors and focusing on QHIN and non-covered entities more specifically, says EHRA.

The association said it is also concerned that the multi- or two-single-factor authentication requirement for the entire workforce across QHINs, participants and sub-participants is “too broad to be feasible in the current exchange environment.”

Other than specific use cases like eprescribing controlled substances, “Organizations are otherwise not required to deploy the proposed approaches, and there is no reason to consider [TEFCA information] any different from other information that a covered entity currently manages and provides access to users with current controls.”

Where all participants need to manage PHI, the standard operating procedures should align with existing requirements for managing PHI where TEF is not part of the fabric, EHRA said.

THE LARGER TREND

The number of planned QHIN applicants is growing, including ambulatory IT and electronic health record vendors, ushering in greater interoperability for healthcare.

The eHealth Exchange in its QHIN partnership announcement said in August it was eager to enhance interoperability under TEFCA.

“This will provide a seamless experience for the organizations coming forward with intentions to participate in this federally endorsed framework for patient data sharing,” the organization had said.

ON THE RECORD

“We suggest aligning the requirement to adhere to ASTM E2147-18 with ONC’s Certification Criterion §170.314(d)(2), which references § 170.210(e)(1), which in turn references § 170.210(h) – ASTM E2147-18 (incorporated by reference in § 170.299),” said EHRA in its letter.

“We note that § 170.210(e)(1) specifically identifies specific sections in ASTM E2147-18.” 

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS publication.

Read More
Qiana Ramage

Latest

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Newsletter

Don't miss

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Kehlani at 30: How ‘Folded’ Changed Everything | Billboard Women In Music 2026

MusicBillboard Women in Music 2026 Impact Award recipient...

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand