Cite as:42 U.S.C. 1320d-2
(a) Standards to enable electronic exchange

(1) In general

The Secretary shall adopt standards for transactions, and data elements for such transactions, to enable health information to be exchanged electronically, that are appropriate for-

(A) the financial and administrative transactions described in paragraph (2); and

(B) other financial and administrative transactions determined appropriate by the Secretary, consistent with the goals of improving the operation of the health care system and reducing administrative costs, and subject to the requirements under paragraph (5).

(2) Transactions

The transactions referred to in paragraph (1)(A) are transactions with respect to the following:

(A) Health claims or equivalent encounter information.

(B) Health claims attachments.

(C) Enrollment and disenrollment in a health plan.

(D) Eligibility for a health plan.

(E) Health care payment and remittance advice.

(F) Health plan premium payments.

(G) First report of injury.

(H) Health claim status.

(I) Referral certification and authorization.

(J) Electronic funds transfers.

(3) Accommodation of specific providers

The standards adopted by the Secretary under paragraph (1) shall accommodate the needs of different types of health care providers.

(4) Requirements for financial and administrative transactions

(A) In general

The standards and associated operating rules adopted by the Secretary shall-

(i) to the extent feasible and appropriate, enable determination of an individual's eligibility and financial responsibility for specific services prior to or at the point of care;

(ii) be comprehensive, requiring minimal augmentation by paper or other communications;

(iii) provide for timely acknowledgment, response, and status reporting that supports a transparent claims and denial management process (including adjudication and appeals); and

(iv) describe all data elements (including reason and remark codes) in unambiguous terms, require that such data elements be required or conditioned upon set values in other fields, and prohibit additional conditions (except where necessary to implement State or Federal law, or to protect against fraud and abuse).

(B) Reduction of clerical burden

In adopting standards and operating rules for the transactions referred to under paragraph (1), the Secretary shall seek to reduce the number and complexity of forms (including paper and electronic forms) and data entry required by patients and providers.

(5) Consideration of standardization of activities and items

(A) In general

For purposes of carrying out paragraph (1)(B), the Secretary shall solicit, not later than January 1, 2012, and not less than every 3 years thereafter, input from entities described in subparagraph (B) on-

(i) whether there could be greater uniformity in financial and administrative activities and items, as determined appropriate by the Secretary; and

(ii) whether such activities should be considered financial and administrative transactions (as described in paragraph (1)(B)) for which the adoption of standards and operating rules would improve the operation of the health care system and reduce administrative costs.

(B) Solicitation of input

For purposes of subparagraph (A), the Secretary shall seek input from-

(i) the National Committee on Vital and Health Statistics, the Health Information Technology Policy Committee, and the Health Information Technology Standards Committee; and

(ii) standard setting organizations and stakeholders, as determined appropriate by the Secretary.

(b) Unique health identifiers

(1) In general

The Secretary shall adopt standards providing for a standard unique health identifier for each individual, employer, health plan, and health care provider for use in the health care system. In carrying out the preceding sentence for each health plan and health care provider, the Secretary shall take into account multiple uses for identifiers and multiple locations and specialty classifications for health care providers.

(2) Use of identifiers

The standards adopted under paragraph (1) shall specify the purposes for which a unique health identifier may be used.

(c) Code sets

(1) In general

The Secretary shall adopt standards that-

(A) select code sets for appropriate data elements for the transactions referred to in subsection (a)(1) from among the code sets that have been developed by private and public entities; or

(B) establish code sets for such data elements if no code sets for the data elements have been developed.

(2) Distribution

The Secretary shall establish efficient and low-cost procedures for distribution (including electronic distribution) of code sets and modifications made to such code sets under section 1320d-3(b) of this title.

(d) Security standards for health information

(1) Security standards

The Secretary shall adopt security standards that-

(A) take into account-

(i) the technical capabilities of record systems used to maintain health information;

(ii) the costs of security measures;

(iii) the need for training persons who have access to health information;

(iv) the value of audit trails in computerized record systems; and

(v) the needs and capabilities of small health care providers and rural health care providers (as such providers are defined by the Secretary); and

(B) ensure that a health care clearinghouse, if it is part of a larger organization, has policies and security procedures which isolate the activities of the health care clearinghouse with respect to processing information in a manner that prevents unauthorized access to such information by such larger organization.

(2) Safeguards

Each person described in section 1320d-1(a) of this title who maintains or transmits health information shall maintain reasonable and appropriate administrative, technical, and physical safeguards-

(A) to ensure the integrity and confidentiality of the information;

(B) to protect against any reasonably anticipated-

(i) threats or hazards to the security or integrity of the information; and

(ii) unauthorized uses or disclosures of the information; and

(C) otherwise to ensure compliance with this part by the officers and employees of such person.

(e) Electronic signature

(1) Standards

The Secretary, in coordination with the Secretary of Commerce, shall adopt standards specifying procedures for the electronic transmission and authentication of signatures with respect to the transactions referred to in subsection (a)(1).

(2) Effect of compliance

Compliance with the standards adopted under paragraph (1) shall be deemed to satisfy Federal and State statutory requirements for written signatures with respect to the transactions referred to in subsection (a)(1).

(f) Transfer of information among health plans

The Secretary shall adopt standards for transferring among health plans appropriate standard data elements needed for the coordination of benefits, the sequential processing of claims, and other data elements for individuals who have more than one health plan.

(g) Operating rules

(1) In general

The Secretary shall adopt a single set of operating rules for each transaction referred to under subsection (a)(1) with the goal of creating as much uniformity in the implementation of the electronic standards as possible. Such operating rules shall be consensus-based and reflect the necessary business rules affecting health plans and health care providers and the manner in which they operate pursuant to standards issued under Health Insurance Portability and Accountability Act of 1996.

(2) Operating rules development

In adopting operating rules under this subsection, the Secretary shall consider recommendations for operating rules developed by a qualified nonprofit entity that meets the following requirements:

(A) The entity focuses its mission on administrative simplification.

(B) The entity demonstrates a multi-stakeholder and consensus-based process for development of operating rules, including representation by or participation from health plans, health care providers, vendors, relevant Federal agencies, and other standard development organizations.

(C) The entity has a public set of guiding principles that ensure the operating rules and process are open and transparent, and supports nondiscrimination and conflict of interest policies that demonstrate a commitment to open, fair, and nondiscriminatory practices.

(D) The entity builds on the transaction standards issued under Health Insurance Portability and Accountability Act of 1996.

(E) The entity allows for public review and updates of the operating rules.

(3) Review and recommendations

The National Committee on Vital and Health Statistics shall-

(A) advise the Secretary as to whether a nonprofit entity meets the requirements under paragraph (2);

(B) review the operating rules developed and recommended by such nonprofit entity;

(C) determine whether such operating rules represent a consensus view of the health care stakeholders and are consistent with and do not conflict with other existing standards;

(D) evaluate whether such operating rules are consistent with electronic standards adopted for health information technology; and

(E) submit to the Secretary a recommendation as to whether the Secretary should adopt such operating rules.

(4) Implementation

(A) In general

The Secretary shall adopt operating rules under this subsection, by regulation in accordance with subparagraph (C), following consideration of the operating rules developed by the non-profit entity described in paragraph (2) and the recommendation submitted by the National Committee on Vital and Health Statistics under paragraph (3)(E) and having ensured consultation with providers.

(B) Adoption requirements; effective dates

(i) Eligibility for a health plan and health claim status

The set of operating rules for eligibility for a health plan and health claim status transactions shall be adopted not later than July 1, 2011, in a manner ensuring that such operating rules are effective not later than January 1, 2013, and may allow for the use of a machine readable identification card.

