An official website of the United States government

Here’s how you know

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

ASTP Logo
Skip Navigation
  • Topics
      • Featured
        • Featured

        • Certification of Health IT

          Ensures health IT meets standards for functionality, security, and interoperability.

        • Information Blocking

          Regulations ensuring health data is shared appropriately without improper barriers.

        • Interoperability

          Enables secure and seamless exchange of electronic health information among authorized users.

        • Health Information Technology Advisory Committee (HITAC)

          Advises on policies, standards, and implementation specifications for health data and technology.

        • United States Core Data for Interoperability (USCDI)

          Offers a standardized set of health data classes and constituent data elements for nationwide, interoperable health information exchange.

        • Trusted Exchange Framework & Common Agreement (TEFCA)

          Operates as a nationwide framework for the interoperability of electronic health information.

      • Artificial Intelligence
        • Artificial Intelligence

        • Artificial Intelligence (AI) at HHS

          HHS’ list of AI use cases is publicly available to search and reference. In addition to AI use case summaries, the inventory also includes information on data, IT infrastructure, internal governance, and much more.

      • Care Continuum
        • Care Continuum

          Explore the roles of health information and technology in broad healthcare settings, supporting seamless, coordinated patient care from prevention through recovery.

        • Care Settings

        • Behavioral Health

          Health information, policies, and technology supporting integrated care for mental health and substance use disorders.

        • Emergency Medical Services

          Rapid response and communication during health emergencies through health information and technology.

        • Long-Term & Post-Acute Care

          Health information and technology facilitating coordinated care beyond acute settings.

        • Maternal & Pediatric Care

          Technology addressing unique health needs of mothers and children.

        • Pharmacy & PDMP

          Electronic tools tracking controlled substance prescriptions to improve patient safety.

        • Public Health

          Using health information and technology to prevent disease, diagnose health conditions, and promote population health.

        • Clinical Topics

        • Clinical Quality & Safety

          Optimal care through measuring results, prioritizing improvements, and implementing and monitoring results.

        • Usability & Provider Burden

          Promotes health information and technology usability to reduce clinician burden and enhance patient care.

      • Interoperability
        • Interoperability

          Promotes standardized exchange and use of electronic health data to improve patient care, coordination, and public health outcomes.

        • Health IT Interoperability

          Enables secure and seamless exchange of electronic health information among authorized users.

        • Trusted Exchange Framework & Common Agreement (TEFCA)

          Facilitates secure, nationwide electronic health information sharing to connect providers, patients, public health agencies, and payers.

        • Certification of Health IT

          Provides certification criteria for developers of health IT modules that ensures health IT products meet the standards for functionality, security, and interoperability.

        • Standards & Technology

          Advance healthcare quality and safety through standardized health IT and secure health data exchange.

        • Information Blocking

          Prevents practices that interfere with the access, exchange, or use of electronic health information, as defined by the Cures Act.

        • Interoperability Standards Platform

          Serves as a homepage for tools and resources for understanding and using health IT standards and technologies.

        • Investments

          Support interoperability improvements nationwide.

        • Health IT & Health Information Exchange Basics

          Enable secure electronic sharing and access of patient health information, supporting healthcare providers and patients across care settings.

        • Patient Access to Health Records

          Ensure patients have secure and convenient access to their health records, supported by healthcare providers and health IT developers under HIPAA.

      • Policy
          • Policy

            Outlines federal regulations and strategic initiatives guiding effective use and secure exchange of electronic health information.

            • Legislation

              Delivers improvements in the delivery and experience of health care while enhancing health outcomes by leveraging health information technology.

            • Regulations

              Supports the adoption and promotion of standards-based health information.

            • TEFCA

              Operates as a nationwide framework for the interoperability of electronic health information.

            • HHS Health IT Alignment Program

              Coordinates health data and technology initiatives across HHS to enhance interoperability and effectiveness.

            • Health Information Technology Advisory Committee (HITAC)

              Advises on policies, standards, and implementation specifications for health data and technology.

            • Privacy & Security

              Protects electronic health information security through policy.

          • Rulemaking

          • HTI Rules

            Health data interoperability regulations ensuring secure, effective technology use.

          • Information Blocking

            Policies to prevent practices interfering with the access, exchange, and use of electronic health information.

          • Certification Program Rules

            Ensures health IT meets standards for functionality, security, and interoperability.

      • Research & Analysis
        • Research & Analysis

          Interactive datasets related to health IT data analysis, providing insights into adoption and use.

        • Dashboards

          Gives data-driven insight on how dashboards are driving health IT adoption and how they have helped users to meet federal healthcare incentives or programs.

        • Data Briefs

          Provides health IT adoption and use statistics derived from surveys and administrative data and in-depth analysis of health IT policies and programs.

        • Datasets

          Grants access to raw datasets from ASTP related to health IT adoption, health IT capabilities and other topics.

        • Quick Stats

          Streamlines data into visualizations of key data and summarizes the latest statistics, facts and figures about health IT.

        • About Health IT Research & Analysis

          Provides information about how health IT data are collected, analyzed, and published.

  • Resources & Tools
      • Featured
        • Featured Resources & Tools

          Highlights key tools and guidance supporting effective health IT implementation, interoperability, patient engagement, and compliance with federal standards.

        • Interoperability Standards

          ASTP’s initiatives in health data standards enable secure electronic health data exchange.

        • TEFCA Resources

          Data sheets, videos, and documents to guide users of the TEFCA framework and exchange.

        • Implementation Resources

          Technical resources and tools supporting healthcare providers, clinicians, and developers of health IT products.

        • Health IT Playbook

          Strategies, recommendations, and best practices for implementing and using health data and technology.

        • Security Risk Assessment Tool

          Desktop application supporting providers conducting HIPAA security risk assessments.

        • Patient Engagement Playbook

          Practical reference tool for clinicians, staff, and other innovators around the world to improve patient engagement.

        • Certified Health IT Product List (CHPL)

          A comprehensive and authoritative listing of successfully tested and certified health IT modules.

        • Conformance Test Tools & Edge Testing Tool

          Resources for developers implementing standards to enable health information interoperability.

        • Health IT Feedback Form

          Users can submit feedback regarding health data and technology usability, interoperability, and compliance issues.

      • Resources
        • Resources

          Collection of practical materials, videos, educational tools, and user guides designed to support successful implementation and adoption of health IT systems.

        • Get It, Check It, Use It Guide

          A guide for patients and caregivers who want to access, review, and use their health records.

        • Video Resources

          A repository of informational videos created by ASTP.

        • Health IT Curriculum Resources for Educators

          Instructional materials to help healthcare workers stay current in the changing healthcare environment and deliver care more effectively.

        • Fact Sheets

          A repository of fact sheets created by ASTP.

      • Tools & Technology
          • Implementation

          • Certified Health IT Product List

            A comprehensive and authoritative listing of successfully tested and certified health IT modules.

          • Electronic Clinical Quality Improvement Resource Center

            Provides common standards and shared technologies to monitor and analyze the quality of health care and patient outcomes.

          • Security Risk Assessment Tool

            Desktop application supporting providers conducting HIPAA security risk assessments.

          • Tools

          • Edge Testing Tool

            A centralized collection of testing tools and resources supporting health IT developers and users fully evaluating specific technical standards.

          • Conformance Test Tools

            ONC-approved conformance resources supporting developers implementing standards to enable health information interoperability.

          • Get It, Check It, Use It Guide

            A guide for patients and caregivers who want to access, review, and use their health records.

          • Quick Links

          • Certification & Testing
          • USCDI
          • USCDI+
          • Interoperability Standards Platform (ISP)
          • FHIR
          • ASTP Standards Bulletins
          • Patient ID & Matching Adopted Standards for HHS
  • News & Events
      • Media Center
      • News
      • Events
      • Featured Blogs & News

      • TEFCAâ„¢, America’s National Interoperability Network, Reaches Nearly 500 Million Health Records Exchanged as HHS Leverages Technology and AI to Lower Costs and Reduce Burden

        TEFCA™, America’s National Interoperability Network, Reaches Nearly 500 Million Health Records Exchanged as HHS Leverages Technology and AI to Lower Costs and Reduce Burden

        Source: ASTP/ONC Today, HHS, through the Office of the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health…

        TEFCA’s growing, are you in? Take a look at who’s participating in TEFCA Exchange

        TEFCA’s growing, are you in? Take a look at who’s participating in TEFCA Exchange

        We are pleased to announce that the beta version of an interactive, searchable map for TEFCAâ„¢ participation is now available. The map released today is another example of our commitment to transparency.

  • About
      • Overview
        • About ASTP

          Mission, role, and responsibilities of ASTP.

        • Leadership

          Profiles of ASTP’s senior leadership team.

        • History

          Timeline of ASTP’s evolution and key milestones.

        • Budget & Performance

          Financial reports and performance accountability.

        • Investments

          Strategic investments in programs, policies, and technology.

        • Reports to Congress

          Annual health data and technology progress updates to Congress.

      • Careers
        • Careers at ASTP

          View opportunities with ASTP.

        • Working at ASTP

          Overview of workplace culture and employee experience.

      • Contact
        • Contact Us

          Reach ASTP with general inquiries.

        • Health IT Feedback Form

          Users can submit feedback regarding health data and technology usability, interoperability, and compliance issues.

        • Report Issue with Certified Health IT

          Complaint process to resolve any issues of potential noncompliance with certification requirements.

        • Information Blocking Claim

          Form to report alleged information blocking practices.

        • Speaker Request

          Form to request ASTP experts for speaking engagements.

      • Funding Opportunities
        • Funding Announcements

          ASTP’s contractors and grantees play a valuable role in helping promote better health care for Americans by fostering interoperable health data and technology.

        • Grants Management & Process

          Learn about opportunities for funding through grants and cooperative agreements.

  • Blog
Popular searches: certifications information blocking interoperability

Health IT Research & Analysis

    • Data Types
    • Categories
    • Sort By
Datasets iconDatasets

State Health IT Privacy and Consent Laws and Policies

Date Range

September, 2016

Last Updated

June 2015

  • state-health-it-privacy-consent-law-policies [CSV – 129.57 KB]
  • Documentation
Link to Page Icon Link to Page
  • Overview
  • Methods and Notes
Source

US state public records and databases

Data

https://www.healthit.gov/data/open-api?source=state-health-it-privacy-consent-law-policies.csv
*This data is API accessible. See /api for documentation and guidance on how to use the API.

This data was collected by the Office of the National Coordinator for Health IT in coordination with Clinovations and the George Washington University Milken Institute of Public Health. ONC and its partners collected the data through research of state government and health information organization websites. The dataset provides policy and law details for four distinct policies or laws, and, where available, hyperlinks to official state records or websites. These four policies or laws are: 1) State Health Information Exchange (HIE) Consent Policies; 2) State-Sponsored HIE Consent Policies; 3) State Laws Requiring Authorization to Disclose Mental Health Information for Treatment, Payment, and Health Care Operations (TPO); and 4) State Laws that Apply a Minimum Necessary Standard to Treatment Disclosures of Mental Health Information.

Data FieldData Description
stateState // The state in which has the privacy and consent policies for exchange of personal health information or standards and authorization requirement.
state_abbreviationState abbreviation // State abbreviation
consent_authorization_policyType of policy // This dataset contains state policy information in four areas: 1) State Health Information Exchange (HIE) Consent Policies; 2) State-Sponsored HIE Consent Policies; 3) State Laws Requiring Authorization to Disclose Mental Health Information for Treatment, Payment, and Health Care Operations (TPO); 4) State Laws that Apply a Minimum Necessary Standard to Treatment Disclosures of Mental Health Information.
organization_launch_dateOrganization and launch date // Organizations that serve as the state-sponsored and designated entity for HIE for each of the 50 states plus the District of Columbia. The launch date for when the HIE was functional and operational is included.
type_of_consent_policyTypes of consent policy // The type of consent policy that the respective state-designated HIE has adopted. Broadly, these policies fall under two categories: opt-out -patients may be automatically enrolled in the HIE but are given the opportunity to opt out of having their information stored and/or disclosed by the HIE; and opt-in – patient consent is required in order for patient health information to be stored and/or disclosed by the HIE. However, some state policies fall outside of these two broad categories, in which case descriptions of the policies are included.
details_of_consent_policyDetails of consent policy // If available, this variable provides a description of the depth of the consent policy for each respective state-designated HIE organization and how it works.
patient_notification_methodsPatient notification methods // If available, this variable includes information on the methods and materials used by the respective state-designated HIE organizations to notify patients/consumers of their consent and/or privacy and security policies.
additional_informationAdditional information // Information and materials that provide additional insight and understanding regarding each respective state-designated HIE, their consent policies, and/or privacy and security policies.
websites_and_publicly_available_resourcesWebsite and publicly available resources // Website and publicly available resources
scope_of_consent_policyScope of consent policy // The breadth of the state HIE consent policy’s applicability. When a consent policy applies statewide, it usually applies in one of the following ways: 1) by giving rights to all patients in the state; 2) by requiring healthcare providers to abide by the consent policy; or 3) by requiring health information organizations in the state to abide by the consent policy. When a consent policy does not apply statewide, this column describes the organization(s) required to follow the state HIE consent policy.
source_of_consent_policySource of consent policy // The most authoritative source that articulates the patient consent policy: statute, regulation, or a state agency-produced policy document. A statute is a formal written enactment of the state legislative body that has the force of law. A regulation is a rule of order prescribed by an authorized body (e.g. state agency) that also has the force of law. A state-agency produced policy document provides guidance for the implementation or operation of a particular statute or regulation, but does not have the force of law. Statutes and regulations are the most authoritative sources of law in a state and must be complied with; state agency-produced policy document provide explanatory guidance to assist with compliance. The source is hyperlinked to the relevant statute, regulation, or policy document for that state.
source_of_consent_policy_urlSource of consent policy url // The web address for the state policy document referred to in the source of consent policy field.
state_involvement_in_creating_consent_policy_if_source_is_not_a_statute_regulationState’s involvement in creating consent policy if policy is not a state statute or regulation // For statutes and regulations, the source of the consent policy is clear (state legislatures and state agencies, respectively). For states where the most authoritative source articulating the consent policy is a state agency-produced policy document, this variable provides information on the connection between the state government and the agency or organization that produced the consent policy. The following types of policies are not considered to be produced by a state agency and as such are NOT included, even where the HIE is state-designated: Policies articulated by HIEs that are neither a state government entity nor actively run, overseen, or managed by a state government entity; Policies articulated by HIEs in states that only provide funding for HIE activities without conditioning the funding upon adherence to state-approved patient consent requirements; Policies articulated by HIEs in states where state actors may participate as stakeholders on the board of the state-designated HIE but do not have any powers of oversight or approval.
statewide_applicability_y_nStatewide applicability // Whether or not a state’s consent policy applies statewide [Yes/No] (i.e., to all HIEs operating in the state). Most state HIE consent policies that do not apply statewide only apply to the state-run HIEs in those states.
applies_minimum_necessary_standard_to_treatment_disclosuresApplies minimum necessary standard to treatment disclosures where mental health information is being disclosed // Whether or not a state applies the minimum necessary standard to treatment disclosures where mental health information is being disclosed (Yes/No). Under the HIPAA Privacy Rule, disclosures for treatment, payment, and healthcare operations (TPO) do not require patient authorization. The Privacy Rule also requires that most disclosures be limited to the “minimum [amount of protected health information] necessary” to achieve the purpose for which the information was released or requested. HIPAA does not apply this limitation to disclosures for treatment purposes. However, some states have enacted statutes or regulations that apply the minimum necessary standard to treatment disclosures where mental health information is being disclosed, which is a stronger standard than HIPAA and therefore is not preempted by federal law.
requires_authorization_for_one_or_more_tpo_disclosures_that_would_be_permitted_under_hipaa_without_authorizationRequires authorization for one or more TPO disclosures that would be permitted under HIPAA without authorization // Requires authorization for one or more TPO disclosures that would be permitted under HIPAA without authorization (Yes/No). Under the HIPAA Privacy Rule, disclosures for treatment, payment, and healthcare operations (TPO) do not require patient authorization. However, some states have enacted statutes or regulations that require authorization to disclose mental health information, either from the patient (or their representative in the case of incapacity) or from an authority like a mental health program director. This additional authorization requirement in the case of mental health information is a stronger standard than HIPAA and therefore is not preempted by federal law.
citation_of_statute_or_regulationCitation of statute or regulation // Statute or regulation enacted by state.
citation_of_statute_or_regulation_urlStatute or regulation url // The web address of the statute or regulation enacted by the state.
narrative_description_of_state_lawNarrative description of state law // Description of state law
definition_or_scope_of_information_material_covered_by_policyDefinition or scope of information material covered by policy // Definition or scope of information/material covered by application of minimum necessary requirement or additional authorization requirement.

State Health IT Privacy and Consent Laws and Policies were developed by Office of National Coordinator for Health IT in coordination with Clinovations and the George Washington University Milken Institute of Public Health. ONC and its partners collected the data through research of state government and health information organization websites. It is intended to provide information on state laws and policies governing patient consent for exchange of personal health information as well as standards and authorization required for the disclosure of patient mental health information.

Submit Feedback

Submit HealthIT.gov Feedback

Step 1 of 3

33%
Name(Required)
Please provide your email address for follow-up.
What kind of issue are you experiencing?(Required)
Select the type of issue you encountered. Select all that apply.
Where did you experience this issue?(Required)
Select the type of issue you encountered. Select all that apply.
Example: Google Chrome on PC or Safari on iPhone.

Page Information

What page did you find this issue? e.g. Interoperability, ASTP Blog
e.g. https://beta.healthit.gov/interoperability
Please provide a detailed description of the issue you experienced.
Drop files here or
Max. file size: 3 MB, Max. files: 3.
    If you have any screenshots or files related to the issue, please upload them here.

    Subscribe for Email Updates

    This field is for validation purposes and should be left unchanged.

    EXPLORE

    • Certification of Health IT
    • Information Blocking
    • Interoperability
    • Health Information Technology Advisory Committee (HITAC)
    • Patient Access to Health Records
    • TEFCA
    • Policy
    • Resources

    DATA

    • HealthData.gov
    • Health IT Research & Analysis

    NEWS & EVENTS

    • Media Center
    • ASTP Blog
    • News
    • Events

    ABOUT

    • About ASTP/ONC
    • Careers
    • Contact
    • Funding Opportunities
    ASTP Logo HHS
    Linkedin
    X
    YouTube
    • Privacy Policy
    • Website Disclaimers
    • Viewers & Players
    • GobiernoUSA.gov
    • HHS Vulnerability Disclosure Policy
    • Archived Content

    External Link Notice

    Welcome to HealthIT.gov!

    Thank you for visiting the HealthIT.gov website! We welcome your feedback using the "Submit Feedback" button at the bottom of the page to help us improve your experience!