Summary
- Thomas Keane (Assistant Secretary for Technology Policy and National Coordinator for Health Information Technology, U.S. Department of Health and Human Services) announced HHS is issuing notices of potential non-conformity to penalize entities for illegal health information blocking.
- Keane testified that the Trusted Exchange Framework and Common Agreement now supports 500 million record exchanges, facilitating "data liquidity" to ensure medical records follow patients across different providers.
- Sen. Marshall (R-KS) challenged Keane on insurance companies using prior authorization to delay care, leading Keane to highlight new standards for real-time electronic approvals at the point of care.
- Sen. Cassidy (R-LA) criticized previous enforcement failures regarding data hoarding, while Sen. Alsobrooks (D-MD) raised concerns about maintaining centralized oversight and patient safety guardrails during the transition to AI.
- This hearing underscores a shift toward aggressive enforcement of interoperability standards and the need for updated cybersecurity frameworks to protect rural hospitals from increasing ransomware threats.
Topics Discussed
Transcript
Opening Statements
The Senate Committee on Health, Education, Labor, and Pensions will please come to order. Increasingly, patient care happens outside the exam room. Any of us can pull up our health records, make an appointment, refill a prescription on our phones, and that is a huge advantage to patients and doctors, saying that as a person who is a doctor and who has been a patient. And so digital access to our health records allows doctors and hospitals to share a patient's information so quickly. And it's at least convenient and in some circumstances life-saving. Whether you're out of town and need to go to the emergency room, or maybe you want a second opinion or to see a specialist, having easy digital access to health information makes the process work better. In 2009, Congress established the Office of the National Coordinator, ONC, to transition the health care system to a fully digital system. Today we'll hear from ONC on their work to standardize health information sharing and put patients in the driver's seat. We've made a lot of progress on this, but there is more to do. There continues to be the issue of information blocking, which I think our witness will speak to, where one party blocks another from sharing data, even with the patient's consent. Now, frankly, on that, I'm looking forward to hear what you have to say, because hospitals tell me that they are transferring back and forth. And patients will tell me sometimes not the case. And doctors will tell me sometimes not the case. And so I don't know if it's something which is improving, what the relative balance of, but I look forward to your kind of illuminating that. I'll note that the Biden administration did not respond to a single case of information blocking. So maybe that means there's absolutely none of it going on, or maybe it just wasn't enforced. But again, I'm hearing different things. Now, I practiced medicine for over 25 years. Ideally, you have all the information you can get to treat the patient well, and that's why I and others led efforts to outlaw information blocking in the 21st Century Cures Act, and I thank the Trump administration for acting upon this. Dr. Keane, who's here today, is working with HHS Secretary Robert Kennedy to investigate allegations of information blocking and taking appropriate action. We must also consider how Congress can continue to modernize patient access to information. ONC created the Trusted Exchange Framework and Common Agreement, or TEFCA, to standardize health information sharing and to give the patient the power of access. Just last month, almost 500 million health records were exchanged through TEFCA in a secure and protected manner. Improving ways to exchange information is pro-patient and delivers better care. So we must redouble efforts to make sure that bad actors don't use TEFCA for their own goals. Now, for all of us, for I as a physician, patients are the priority. We're living in a digital age. For that, there are advantages and disadvantages. This committee should expand those advantages and to limit the disadvantages with the goal of putting the patient first. That's why I introduced the Health Information Privacy Reform Act. The committee also last week passed on a bipartisan basis my Healthcare Cybersecurity and Resiliency Act to respond to continuing threats of cyberattacks. Protecting patient information is bipartisan and essential to deliver modern care. I look forward to discussing how we can do that. Senator Kaine, are you going to make a statement for...
I am not.
Okay. So with that, I'll introduce our witness and we will hear the testimony. We're joined today by Dr. Thomas Keane, a medical doctor, Assistant Secretary for Technology Policy and the National Coordinator for Health Information Technology at the Department of Health and Human Services. He previously served in the first Trump administration in a variety of roles, including at ONC and supporting COVID-19 provider relief efforts. Dr. Keane is a clinician and engineer by training, previously practicing as a radiologist as well as a software developer. He received his MD from the Albany Medical College and his MBA from the University of Chicago Booth School of Business. Thank you for being with us, Dr. Keane.
Witness Testimony: Dr. Thomas Keane
Thank you, Chairman Cassidy. Are you guys able to hear me?
Yeah, you got the red button on?
Perfect. Chairman Cassidy, Ranking Member Sanders, and distinguished members of this committee, thank you for the opportunity to provide testimony on the work that HHS is doing to improve outcomes for all Americans through the exchange, access, and use of health data. Before I joined government, I worked as an interventional radiologist. I practiced medicine in rural Ohio as well as in big cities like Chicago. I have experienced firsthand the persistent challenges and the incredible advancements that characterize the last 20 years of health information exchange. I am glad to report to this committee that we have made tremendous progress during my tenure. I appreciate the work this committee has done over the years to make this possible. As the Assistant Secretary for Technology Policy and National Coordinator for Health Information Technology, I lead nationwide efforts to advance health information technology and also lead efforts to expand electronic health information exchange. My top priority is data liquidity. My office is singularly focused on how technology can make health care more affordable and can enable a patient-centered health system where medical records follow the patient. Core to addressing affordability is our work to develop a trusted nationwide infrastructure for secure health data exchange. Since Secretary Kennedy took office, we have implemented provisions of the 21st Century Cures Act and grown the Trusted Exchange Framework and Common Agreement. TEFCA, as it is known, is an interoperability network which allows nationwide health information exchange. TEFCA now connects more than 70,000 locations and has supported exchange for nearly 500 million health records, up from 10 million when Secretary Kennedy took office. TEFCA reinforces participants' existing obligations to comply with privacy and security rules, including HIPAA and applicable state laws. Technology alone though is not enough. Despite technological advancements and improved exchange infrastructure through TEFCA, information does not always move the way it is supposed to, the way that any patient or clinician would expect. One of the biggest obstacles to data liquidity is information blocking. We are quarter of the way through the 21st century and information blocking is unacceptable. In September 2025, Secretary Kennedy announced a major enforcement initiative. On February 11, I announced that my office is in the process of issuing notices of potential non-conformity to potential violators of the information blocking regulations. As this work continues, we are collaborating closely with the Office of Inspector General so that bad actors face meaningful consequences and so that patient data isn't hoarded in silos. For too long health care has been too expensive with uneven access to high-quality care. In July 2025, we published a final rule which gives doctors unprecedented real-time access to prescription drug information, allowing prescribers to identify the most appropriate, cost-effective treatment for patients, while preventing health insurers from blocking physician-approved care. Showing a doctor the drug cost at the time of prescribing results in hundreds of dollars of savings for common medications and thousands of dollars in savings for specialty medications. For a senior on a fixed income, the ability of a prescriber to choose a covered low-cost drug can mean the difference between skipping a prescription and being able to afford an essential medication. Nearly every hospital and ambulatory care provider uses health technology certified through the ONC Health IT Certification Program. In December 2025, we published a proposed rule to streamline outdated certification criteria, reduce regulatory burden, and recenter the program on modern standards of interoperability. An open, interoperable health data ecosystem invites entrepreneurship, drives innovation, and cements American leadership and competitiveness in the expanding digital health marketplace. In conclusion, our efforts are aimed at a simple but ambitious goal: a health system where people can see, manage, and share their health information as easily as they manage their finances or travel itineraries. In the not-so-distant future, an individual with multiple chronic conditions can keep all of their health information in one secure digital place and share it instantly with a new provider, a caregiver, or even a secure trusted app, no matter where they live or where they receive care. With continued support from Congress, ASTP will turn this person-centered, data-driven vision into an everyday reality for people and families across the country. I look forward to your questions.
Thank you, sir. I will defer to Dr. Marshall.
Prior Authorization and Administrative Burden
Thank you, Dr. Cassidy, and welcome Dr. Keane. Appreciate, great to see you again. The number one complaint I get from patients, especially patients on Medicare Advantage, is how their health care is delayed because of how Medicare Advantage is manipulating prior authorization. They're literally using it to delay their care. Prior authorization is the number one administrative concern of physicians as well. I want to say thanks for what you've done to help us so far on the technical aspect of getting our bill to where it is right now. The Improving Seniors' Timely Access to Care Act is on the just sitting there on the doorstep waiting to be passed by this Congress. But maybe you could just give us a little update on what you and the administration have done to go ahead in this process and working on prior authorization.
Yeah, thank you for the question, Senator Marshall. As I spoke of in my opening statement, back in July 2025, we finalized our HTI-4 final rule. That undertook two provisions to make health care more affordable and to decrease administrative burden on both patients and providers. One of these provisions was to adopt standards to allow electronic prior authorization to occur in real time at the point of care, so that adjudications of prior authorization could happen while the patient is in the doctor's office and the proper care could be selected. We promulgated a number of standards that allow electronic health records to communicate with insurance companies in real time and between the insurance companies and the doctor's office, the electronic prior authorization can happen. Of course, promulgating the standards is only the first step. And we've been working very closely with our colleagues at CMS. As you know, CMS had a number of insurers undertake pledges to make sure that prior authorization adjudications occur in real time for approximately 80 percent of prior authorizations. I believe the pledge date is 1/1/27. So we are working very closely with our colleagues at CMS to make sure that the standards not only exist, but that they're adopted in the market and actually implemented.
What are the barriers that you see going forward to really bring this so patients don't have this challenge? What are the barriers, I guess?
Thank you for the question. With the standards in place on both the payer and provider side, the barriers is getting them to talk. And that's a little bit like herding cats. But what we've found is that both the insurers and the electronic health record companies are very committed to meeting the pledge. I don't think anybody wins from the prior authorization system as it currently exists. It creates about $20 billion in provider burden over 10 years, about $2 billion a year. And from what the insurers tell us, they approve the vast majority of prior authorizations and is a very high administrative cost for them as well. Getting the insurers and getting the electronic health records to actually communicate through the standards so that they can find each other, so that they can talk to each other, so that the information that's reflected in the standards is actually accurate and up to date is the biggest challenge, but we've found great partners in both the insurers and the electronic health record providers and we will continue to work with them.
You know, Dr. Cassidy and I both went through this, going through going from pencil and a script pad to medical electronic medical records, and we could sit in our office and email the pharmacy of your choice, and it was one of the greatest things I ever saw, talk about, you know, simplistic. But on the why that worked is because the pharmacies were very motivated to make it work. Do you feel like these big oligopolies that are insurance companies are willing to cooperate? Are they wanting to cooperate, or are they throwing up more and more barriers as you try to implement this?
Well, that's thank you for the question. At least in our experience, they are identifying where the choke points are and are identifying solutions to those choke points. You talk about the pharmacy issues and how they were resolved a little bit by email. In the HTI-1 rule, we also adopted standards for real-time prescription benefit determination. This means increasingly at the point of care, doctors will not only be able to choose a therapeutically appropriate drug for a patient, doctors will also be able to see what the alternatives, the therapeutically appropriate alternatives are, and what the costs of those alternatives are for that particular patient based on where the patient is in their insurance plan. The ability to choose what is not only a therapeutically appropriate alternative but also a cost-effective alternative for the patient is really a game changer. You'll have fewer instances of a doctor getting a call from the patient in the pharmacy parking lot saying I couldn't afford my prescription, and that's going to improve adherence and improve outcomes for patients. So we've gone beyond the email, and hopefully we will get to a point where you just press a button and the best alternative for a patient based on both efficacy and cost will be proffered.
Yeah, well thank you. Chairman, I'll yield back, and if we get a second round, maybe I'll get a couple more.
Senator Kaine.
Expanding EHR to Behavioral Health
I'm a little intimidated to be the only person with a mic in front of my face who's not an MD today, but but I'll wade in as an educated layperson. Call me Tom.
All right, Tom. Thank you.
I want to ask you sort of a technical question about the HITECH Act. My understanding is that prior to its passage, very few hospitals had switched over to electronic health records. The passage of the bill and the incentives that came with it have been very successful. According to the data that your agency provides, 96 percent of hospitals now use some kind of interoperable EHR, and that's largely attributable to the financial incentive. But the original legislation didn't cover all aspects of health care and social services. The HITECH Act limited the incentive payments to critical access and acute care hospitals but excluded important providers like behavioral health providers, long-term care facilities, and social service providers. Fifteen years later, the funding that incentivized the uptake is no longer available, and I'm concerned that others won't move to the EHR. So if you could, Dr. Keane, to start, talk to about talk to us about the rate of adoption of interoperable EHR by providers and facilities that were not included in the HITECH Act.
Thank you for the question, Senator. When I started in this position, I asked the career staff who've been moving all of these initiatives forward for 20 years what was something where we could really make an impact, and one of the first things surfaced was incorporating behavioral health providers into the health tech ecosystem and into the EHR system. So we have been laser-focused on making sure that all providers in the market get the benefits of electronic health records and electronic health data exchange. I can tell you a number of the initiatives that we're undertaking to try to address this. The first is our Behavioral Health Information Technology initiative, which is a $20 million initiative that we're doing with the Substance Abuse and Mental Health Services Administration. We developed what's called the US Core Data for Interoperability for Behavioral Health that allows for exchange of data between traditional medical providers, behavioral health providers, and even occupational health social service agencies and vocational service agencies. I'm sorry, occupational providers and vocational service agencies, as well as housing assistance agencies. We are currently running pilots in nine states, including 45 exchange partners. So for example, in one of the states, when a patient is discharged from having a behavioral health or substance use disorder crisis and they're going out into the community, we want to make sure that their medical information as well as their social needs are properly communicated to social service agencies, vocational health agencies, and the like.
How about long-term care facilities?
Currently there are electronic health records that particularly target long-term care facilities and that are specifically designed to allow data interchange with long-term care facilities. Our hope with our HTI-2 rule is that by pivoting our certification criteria from the older emphasis on workflow and baseline standards to a new focus on interoperability, that new solutions will enter the market that are affordable, innovative, and customized to providers such as long-term care providers.
I have one other topic I want to address, and that is it's very, very good to have these interoperable systems, but it is also important that the data that's there be shared. During the public health emergency of COVID, HHS required hospitals and providers to report COVID cases to public health agencies, and the CDC also launched a portal for electronic case reporting. That eCR is now a quality measure for Medicare. We couldn't have mounted the effective response to COVID without the requirement of data sharing. Some of those requirements went away when the public health emergency was ended. I have worked beginning with Senator Isakson, our friend who was such a great leader on this committee on public health data sharing, and I think there's more to do. I have a bill called the Improving Data in Public Health Act, which would direct CDC to establish standards for sharing public health data to protect, you know, confidential information, but to enable us to utilize the data to more effectively manage public health operations. What did we learn about the importance of electronic records and this sharing during the COVID-19 pandemic?
Thank you for the question, Senator, and appreciate your focus on public health reporting, and I think you raise very serious issues, and we appreciate your support on these. We learned a great deal about both the opportunities and the barriers to public health reporting. At ONC, we have developed a USCDI+ for public health data reporting. This is our US Core Data Set for Interoperability that captures public health data elements so that they can be effectively reported to public health agencies, to the CDC, from the electronic health records. The lack of data was one of the issues that we had in an adequate COVID response, but the agency has really picked up the ball, both myself and my predecessors, to make sure that this information is captured by electronic health records and is interoperable and computable, and we appreciate your focus.
And Mr. Chair, as I as I yield back to you, Hickenlooper and I were talking before he exited for a sec. We're two of the 30 people in the history of the US that have been a mayor, governor, and US senator, which is a tribute not to our judgment but to our survival skills. But one of the things we both see is, you know, when when a city health department has some data and then state or city or county, then state has some data, and then federal agencies have data, and then private providers have data, we know so there's so much knowledge out there, and yet the sharing of it is often very siloed, which means that the knowledge that we have is not really maximized in terms of the public health benefit it can attain. And I know those of you who are physicians completely get that. So one of the good things about this hearing is I think it helps us, you know, think about ways to knock down some of the silos so that we can more effectively use the the knowledge that we already have, but it's just spread so wide that we don't often do it in an effective way. I'm glad you called this hearing today.
AI Integration and Data Privacy
I'm glad you're an attorney. No, not really glad you're an attorney, but you are an attorney. So I'm glad you're here. So I'm going to ask this first question in light of what you just said. I'd be interested in your perspective. Dr. Keane, it seems as if the future promise of these records would include AI giving clinical support. I'm a practitioner in a rural area, and I automatically have all access to someone's record, and I get keep in mind they're taking this medicine, and if you give them this new medicine, there could be an interaction. But that suggests that I would have the ability to upload all of my information into a platform and give AI access to it. Are you with me?
Yes.
And it's a little bit of a variant of what Senator Kaine was just asking. How can we take this information, upload it, and allow it to be worked with by AI? Lots of implications here. Who's liable? Who gets to use the data that flows from it that might be for financial gain? What are the privacy issues? Have you all thought about these issues? Because ultimately the promise of AI is that it's able to make us healthier, at least in health care, and using medical records. So you must have thought about that. Your thoughts, please.
Yeah, thank you for the question, Chairman Cassidy. As you know, in December 2025, we put out a request for information on how AI can be safely and effectively deployed in the health care system so that it is aligned with current standards. We have so far received hundreds of responses and submissions that will help guide not only our policy in how AI can be deployed but also the policies of our sister agencies, and we're happy to share that information with Congress as well so that we can deploy this effectively and responsibly. As a radiologist, I can tell you I've been using AI for over 20 years. Of the 1,300 approved medical...
But that's different. That's different than what I'm describing. You're looking at an X-ray. I'm talking about me electing to put my data up to be managed. Right. Now would you have governance over this, or would FDA?
We provide patients consistent with HIPAA the ability to get access to their electronic health records. And within our TEFCA network, we have restrictions on what the individual access providers can do. So for example, they are not allowed to resell the data. They are not allowed to use the data for marketing. There are specific prohibitions against using the data in employment, credit, or insurance determinations. However, once a patient gets control of their information, they have freedom to do with it what they want.
So let me ask, if there's clinical decision-making support, okay, use this antihypertensive, not that blood pressure medicine. Is that you? Do you regulate that, or is FDA?
I believe that's the purview of the FDA. What we regulate is the ability to get a hold of that information. And there's great promise. You probably know that one of my colleagues at CMS, her daughter has a chronic disease and a rare disease, and she took her daughter's medical records and uploaded them into an AI chatbot, and the AI chatbot was able to do what the doctors she had been seeing could not, namely they found a clinical trial for her daughter to enroll in. But that of course required her to release that information to the chatbot, and she has the autonomy to do that. I know that Senator Marshall and you have both practiced medicine, and one of my habits is to go online and see what patients say about the procedures that I do, not necessarily that me as a physician have done, but the general category of procedure so I can see how to improve my approach to treating those patients. Of course, these patients are sharing their information freely.
So let me ask you this. The part of the health that information sharing, in the 21st Century Cures Act, we mandated that providers and EHR vendors use application programming interfaces to allow third-party apps to access the information on behalf of the patient. There have been allegations that that is also a point of blocking, that the ability to create connectivity is either not being done, or in some other way this provision is being abused. So thoughts about that, is that real or not, and how do we prevent both the blocking of the development of an API to be able to attach to download information for the benefit of the patient, or if somebody can successfully do so that that information is abused?
Yeah, thank you for the question, Senator. In our current engagement with the marketplace, we are finding different reports of how much this information is accessible. I recently was told by one provider of AI-augmented care to patients that they were able to pull approximately 90 percent of patient records. I've heard from others that they're able to pull far less. We've received into our information blocking complaint portal over 1,500 allegations of information blocking. We've shared that with the Office of Inspector General, and they are undertaking their process to investigate these complaints. We also, starting in February, have issued notices of potential non-conformity to potential information blockers to let them know that they may be in violation of the regulations. They will respond to us, and if they're found to be information blocking, we will put them on a corrective action plan. If they're not compliant with the corrective action plan, we can pull their certification, and they lose the opportunity to receive payment incentives.
And so you're actively pursuing this?
We are, we have actually pursued it. We've issued notices of non-conformity already.
Senator Hickenlooper.
Price Transparency and Market Competition
Thank you, Mr. Chair. Thank you, Dr. Keane, for being here and for all your public service. I want to take a moment just to recognize Senator Kaine here, who I understand was blowing smoke at me. I do want to reiterate that once you've been a mayor and then a governor of a state, you understand healthcare in a more granular way, and a lot of what your experience, what you've seen and learned and want to put into effect, I think we are immediately sympathetic to the needs for those improvements. In your testimony, you discuss some of the information exchange barriers that we're seeing between patients and caregivers, clinicians. I mean, I agree. We think about these large employers, people with 10,000 or many thousands of employees that they provide healthcare for, they bid it out to these large corporations, whether it's Cigna or UnitedHealthcare, whoever. But once that contract is awarded, it goes opaque. They can't see anything, so they, although they have a natural self-interest to try and lower costs and find savings and efficiencies between hospitals or clinics or pharmaceutical companies, they're not, they can't see the numbers. And I think that we have a major challenge with that lack of visibility and transparency with respect to prices. I think it makes it increasingly difficult for the companies and for patients, just individual citizens, to understand what they're paying for healthcare. So we've been proud to introduce the bipartisan Patients Deserve Price Tags Act with Senator Marshall, who's done a commendable, great job on that. And it does something really novel, but really something that shouldn't be novel. It requires the publication of real prices for healthcare procedures for patients, but also for employers whose real visibility and therefore competition will allow for the best prices possible. So you've discussed the benefit of real transparency and what that can do about costs and increasing medication adherence. Do you worry that the current level of opacity, I'm not sure if that's a real word, but the clouding over, the hiding of costs in our healthcare system does not currently allow us to benefit from the necessary competition, the natural inclination of competition to lower prices?
Yeah, Senator Hickenlooper, I share your concern, and we appreciate the Senate's focus on this. I should say I had the opportunity to practice medicine in the Banner hospitals just north of Denver, Greeley, Loveland, Fort Collins, and almost moved to Denver, so didn't quite work out, but I enjoyed my time.
You told me privately they had a miserable mayor. [Laughter.] He's still young, we might get him yet, you watch.
Thank you for calling me young, you just made my day. Yes, obviously patients are empowered by price information, and to the extent that we can provide that price information at the point of care and allow for shared decision-making between the physician and the patient about what the most appropriate pharmacotherapy is, we will continue to do that. We are actually working with direct-to-consumer pricing information providers to try to get not only the information from the pharmacy benefit managers, but also the direct-to-consumer pricing into the electronic health records because, as you know, oftentimes the amount a patient will pay in a copay will actually exceed what they could purchase the drug for at a cash price. And so we believe that the more information the patient has, the better off they are and the better adherence is. And we appreciate your focus and Congress's focus on this issue. It's the one area of the economy where pricing is opaque, and we hope to change that.
Right, and it's a huge, by most measures, even the American Medical Association, it's a four, five, approaching $5 trillion spend every year. And when you think that 25 percent of that could be lack of efficiency or redundancy or in some cases fraud, that's a lot of money to capture. I mean, you're talking about over somewhere in the trillion dollars a year category, if that's accurate.
That's correct. The administrative burden related to healthcare is enormous, and there's no reason that this can't be automated even using existing technology. The first step is getting the data captured, and the second step is getting it exchanged by standards. Once that happens, things like prior authorization, price discovery, and other administrative functions, even scheduling an appointment, can be done in an automated fashion.
Well, I think you'll be great at implementing this bill once we get it passed. I'm out of time. The Republican budget reconciliation bill makes severe funding cuts to rural hospitals. I think that's widely recognized, a bunch of us are trying to figure out how to rectify that, but I will submit in writing some questions around how do we make sure that we get the funding to rural hospitals so that we don't see, have closures of hospitals and clinics in rural areas, one of the key backbones of our country.
Thank you, Senator Hickenlooper. I was a rural practitioner myself for a number of years in towns like Gallipolis, Ohio, and I understand the unique challenges that rural providers and patients face. And it's my hope that during my tenure we can leverage information technology to sort of close those gaps, and we'll be happy to provide whatever technical assistance you need on the legislation.
We'll make sure we stay in close touch. Thank you, I yield back.
Thank you, Senator Hickenlooper. Now Senator Alsobrooks.
Thank you so much, Mr. Chair. You know, digital tools and data systems are rapidly transforming healthcare in America. And when these technologies work well, they can help improve both the patient and provider experience. But when data systems fail, the consequences can be serious: delayed care, privacy risks, and clinicians spending more time navigating technology than caring for their patients. That means the policies governing these technologies should prioritize patient safety, clinical trust, and the integrity of our healthcare system. So as Congress considers the future of health data and next-generation care, we need to ask a basic question: are we strengthening the guardrails that protect patients or weakening them? Innovation without accountability does not build trust, and in healthcare, trust is everything. So Dr. Keane, you serve with Micky Tripathi, the former Assistant Secretary for Technology Policy.
He's my former boss.
Yes. And in 2024, HHS elevated the Office of the National Coordinator, creating the ASTP and expanded its authority to include technology, data, and AI policy and strategy for the department. This was a timely reprioritization following the February Change Healthcare data breach, which compromised the personal data of nearly 200 million Americans. The prior administration intended to move beyond a narrow focus on technical standards and better clarify the responsibility of disparate agencies for investing in technology, implementing it, and establishing regulations and payment policies, all to help better align our federal response and preparedness for emergency threats. The idea that as healthcare becomes more digital and data-driven, HHS would need a forward-looking office capable of shaping the policy framework for those technologies across the department. So would you share, please, why it was important to create a centralized system within the department to better coordinate policy efforts across operating divisions?
Thank you for the question, Senator. The Office of National Coordinator, ONC, has the coordinator as the main portion of its role. And our ability to convene and work with our partners across HHS to promulgate standards that protect patient privacy and safety, that prevent data breaches, is central to our mission. And we were doing this before the reorganization, and we're doing it after the reorganization. And we're doing everything we can to preserve patient privacy, security, and to make sure that all of the agencies are aligned around this. Now, the specific agency that deals with cybersecurity breaches is the Assistant Secretary for Preparedness and Response, and of course the FBI and the Cybersecurity and Infrastructure Security Agency. But we take these issues very seriously, as do you, and we appreciate your focus on them.
Thank you. So you know, I'm concerned that this administration is actually showing signs of kind of walking back from that progress and from the, you know, the will to align health agencies to best patients, to best protect patients. So does the department still believe, you know, well let me move to another question. I want to ask you about some guardrails. You know, we're seeing AI embedded directly into clinical software systems used by doctors and nurses, meaning these technologies are increasingly influencing diagnoses, treatment decisions, and care management. So what role do you believe ASTP should play in establishing guardrails that ensure these technologies are safe, transparent, and trustworthy for clinicians and patients?
Thank you for the question, Senator. As I was mentioning to Chairman Cassidy, as a radiologist I've been using AI for 20 years, and it has transformed the field. As a physician and as somebody who's helped select AI systems for radiology practices, we are absolutely forensic in examining what the AI is capable of doing, making sure that it helps us in our job, and making sure that it's safe for patients. We believe that we have a very real role in making sure that patient safety and privacy are protected by the AI systems that we oversee. This is why in December we put out an RFI asking the broad public, doctors, nurses, patients, EHR developers, and AI developers what the best approach to regulating AI is. And we intend to use the information we get from that RFI not only to inform our regulatory regime, but also to share with Congress and to share with our sister agencies at HHS.
Thank you so much. Well, do you believe that the current authorities across HHS are sufficiently growing the use of AI in clinical settings, or are these gaps in the federal framework that Congress should be paying attention to?
Thank you for the question. I believe that our RFI will surface that. I can't really comment on the authorities of the other agencies. I believe within our agency we have sufficient authorities to certify health IT and to manage the nationwide network that we oversee to make sure that the AI that's deployed is safe and effective. I can tell you we collaborate very closely with our colleagues at CMS, we collaborate closely with our colleagues at FDA, and we help inform their thinking about how their regulation should be promulgated, but I would let those agencies speak about what they're doing.
Okay, thank you so much. I yield.
Senator Marshall.
Interoperability and Information Blocking Enforcement
Right, thank you Chairman, I'm enjoying this so much, I get a second round. I do think it's important to point out that we do have two bills between our Price Transparency Act and our prior authorization bill that would literally change the healthcare experience for Americans. And appreciate this committee's commitment to giving us a hearing very soon, a markup, excuse me, a markup on our Price Transparency Act and hope we can figure a way to get prior authorization across the finish line as well. I want to talk about interoperability for a second. Of all the, I think probably the biggest failure of EMR was interoperability. When I purchased, made the decision on which one for our hospital, a physician-owned hospital, they guaranteed me that yes, it'll be able to talk to all the others. But indeed we had a Dodge and the other hospitals had a Ford and there was Chevys and they didn't talk to each other. So we formed committees, we prayed about it, we threw money at it, and you know, when I left practice they still weren't talking to each other. And I'm still not convinced that they are. I'm frustrated that Department of Defense aren't all on the same EMR, VA as well, and I know they're trying to get there but just huge hurdles it sounds like to me. I can't believe that's not been accomplished. You would think that if you're going to take money from the federal government, Medicare, that it would be your responsibility to be able to communicate with CMS. And I think that's your goal, right?
Yes.
So I guess what's keeping us from doing that? And I know you're making progress. What are the challenges ahead of you? How are you dealing with people that, with organizations that are blocking?
Thank you. Pretty broad, sorry. That's fine. Thank you for the question, Senator. And I see you've had the same experience as a physician that I have of hearing one thing from sales people and finding another thing when you actually get their product. In order to make interoperability work, there have to be clear standards which we are constantly refining and which we are working with standards organizations to continue to develop. There have to be tools for conformance with those standards and we fund and actually operate our own conformance testing tools to make sure that for example, when we promulgate a FHIR standard in our regulation, that that FHIR standard is actually conformed to by all of the people who sign their certification attestations. Additionally, we have to make sure that people are not willfully engaging in information blocking. And that's why our efforts to enforce the information blocking regulations through issuing notices of potential non-conformance and through consultation with OIG can help prevent people who are willfully...
So there's probably what, three or four companies that control 80 or 90 percent of the EMRs out there. Are they, is there one that's not being cooperative? Is there what, what can we do to encourage them to help unlock their codes?
Yeah, we don't pick winners and losers and we work with the assumption at ASTP that everybody wants to be a good actor in the market. When and if we find that people are thought by their exchange partners to be information blocking, we inform them, we discuss with them what we think they're doing incorrectly, and if it comes to it then we issue a notice of non-conformity and we refer the case to the Office of Inspector General.
Have any of those cases went forward?
I can't comment on what the Office of Inspector General is doing because I'm barred from knowing. They're an independent agency.
Good enough. But you know, I certainly do think there's bad actors out there and you're too kind and I appreciate that. But I do think we need to start holding some of these companies accountable.
Some of them have these notices of non-conformity landing on their desk, so we'll see how they react.
Good. I think the maybe the last thing I'll talk about is my goal was that we truly have you and I, that it's my record, it's my medical record, a personalized medical record that I control. And I think you're making steps in that direction. But any ideas on how do we make that into a reality where it truly is my medical record and I don't have to call my doctor's office? I'm now in a setting in an emergency room in Washington, D.C. and all I got to do is say here's my app, here's my medical record and we'll email it to you, whatever we got to do.
Yeah, thank you for the question and thank you for the concern with this issue. The TEFCA network that we've stood up and have continued to grow and during Secretary Kennedy's tenure the number of documents exchanged have gone up by a factor of 50, has a particular exchange purpose called individual access services. And the idea is that consistent with the HIPAA rule, a patient is able to get that information in a form that they want, including on their phone, so that they are empowered by that information and so that they can share it with a caregiver, a provider, or an app. And the individual access services is being built out. We're doing everything we can to address the challenges of sharing across different systems, networks, organizations, geographies, and we're making real progress. And with continued support from the Senate and Congress, we should be able to get it to the point where everybody is empowered by their health records.
Can you be more specific? What can we do to put wind beneath your sails? Is it just financial resources?
What we're doing at ASTP is looking at increasing the number of demographic variables to allow more reliable patient matching. And we're also increasing the number of security controls so that people are more willing to share, so that in the event that there is a suspected breach, the information doesn't get compromised. One of the challenges that people are uncomfortable sharing the information because they don't want there to be improper sharing. So thank you.
Thank you, Dr. Marshall. And now Senator Murkowski.
Rural Health and Cybersecurity Threats
Thank you, Mr. Chairman. And Doctor, welcome. A lot of interest in your testimony this morning. I'm sorry I haven't been here for most of it, but my team has been following with great interest. In Alaska, as you well know, got a lot of territory to cover, populations are very spread out, small communities and access to providers is limited. And so we have been one of those that have pioneered a lot when it comes to telehealth and figuring things out that way. Part of the challenge though is in many parts of the state, it's tough to make all that technology work because we just, we're not connected like the rest of the country is. And so as you are working to push out these advancements, I would just ask that you keep in mind that those who stand to benefit most from digital health modernization may have the least capacity to do so. And so how we're knitting this all together is where I'm really very interested. We're looking at the Rural Health Transformation Fund, seeing a lot of promise to that, but also recognizing that we got a lot to do to just get to par with what many people in America have come to expect and to be able to receive on these devices. In addition to our geography, we are blessed to have more veterans per capita than any other state. And we are also very fortunate to be the home of 229 federally recognized tribes, more than half the tribes in the country. And of course both of these groups, the VA and the IHS, use government health systems. We talk a lot about the interoperability of our systems and in fact when you ask people how does this work, they kind of snort and like, yeah, we talk a lot about it, but the seamless integration is not really there. The question to you this morning is whether or not the multiple agencies have been engaged in this interoperability planning, the standards development that we're talking about, so that we've got broader alignment. Because what happens is if you're an Alaska Native in a village, you're not going to have access to IHS and so the provider that sees you there is not a VA provider, it's an IHS provider. Likewise, a non-native veteran in the village is seen in the IHS clinic. There's no boundaries there, which is great, but when we talk about systems, are we going to inadvertently possibly be creating some barriers? Do you think about this?
Thank you for the question, Senator. Hopefully not. I should mention this last Christmas I got a gift of salmon from the Wild Alaska Company, I think, and it's fantastic stuff.
Was it below the gift limit? [Laughter.]
It came from a family member.
That's exactly right. Given with love.
Yes. So I'd like to say that we have a good collaboration with the Indian Health Service. They are the first government organization to join TEFCA and we have worked very closely with them on their health IT modernization efforts. We meet with them I believe monthly and give routine consultations on workforce needs, staffing needs. We helped them pick their vendor as well as their contractor and we really are interested in ensuring the interoperability between the Indian Health Service and other providers. It is getting better and we'd be happy to work with your office to get more insights.
Well, I would appreciate just kind of knowing how things are advancing. And I value what you're saying about early engagement with IHS, I think that's really important. I'm also the chairman of the Senate Indian Affairs Committee and we talk a lot about tribal data privacy and sovereignty and a recognition that historically much of the data that comes from our tribal communities has been collected and managed by federal agencies or outside entities without the clear tribal governance that creates issues in and of itself. And so making sure that you are incorporating that or factoring that into the process along the way, again, I think is going to be very, very important for what we can do to anticipate better health outcomes for tribal members.
Yeah, we are very focused on the privacy and security protections in the TEFCA network and I would love to work with your office to see how we can really mature the data exchange with the tribes and the Indian Health Service. As a former rural practitioner, I'm really focused on making sure that this works for everybody.
Well, and if I might use this forum to invite further discussion with members of the Indian Affairs Committee on these issues of tribal health information and privacy concerns, I'd look forward to that. Mr. Chairman, thank you so much for inviting Dr. Keane to the hearing today.
Thank you, Senator Murkowski. And now Senator Hawley.
Thank you very much, Mr. Chairman. And thank you for giving me the opportunity to ask questions. Dr. Keane, thank you for your testimony and I'm sorry that I'm a bit late. Another committee hearing that is just going on and on, but it's great to be here with you. I want to talk to you if I could about cybersecurity at rural hospitals. In Missouri, 40 percent of our hospitals statewide are rural, that's over 70 of our hospitals. We have seen multiple cyberattacks, in fact over the last three years, 60 percent by one reckoning of rural hospitals in the country faced a cyberattack. That's a very big number. There was a hospital near my state, Spring Valley, Illinois, St. Margaret's Health, that was actually forced to close its doors after a ransomware attack in 2021. So can you tell us a bit more about how cyberattacks on rural hospitals directly affect quality of care for the patients that they serve?
Thank you for the question, Senator. There's no question that cybersecurity attacks on any hospital, but particularly the under-resourced hospitals that typically serve rural populations, how this can be devastating. In the programs that we administer, we are laser-focused on making sure that data is protected and that patients and that systems are secure. Our current HTI-5 rule is giving providers of electronic health record technology the opportunity to pivot away from box-checking cybersecurity requirements to be consistent with the risk-based framework under the HIPAA security rule. As you know, the HIPAA security rule requires transmission security, audit controls, access controls and the like. And we want hospitals to be able to adopt the most advanced sort of security postures to prevent these cyberattacks in the future. We would like the certification program to move at the pace of cybersecurity to assure that these sorts of attacks are rare if ever happen.
Let me just ask you in your own priorities in terms of in your role as the Assistant Secretary, how does rural hospital cybersecurity factor in? And you said you'd like to see the protocols be changed, be updated to move with the pace of the threat. I mean, tell us a little bit more about that. What are you doing to see that effectuated?
Yeah, so our HTI-5 rule is updating the certification criteria so that it can adopt the most modern standards for cybersecurity. So for example, in our current program, we ask people to say whether they use multi-factor authentication or not. And there are newer standards for cybersecurity that cannot be fished, something like the FIDO2 standard. And what we'd like to do is make sure that these newer standards can be adopted as they come out through our certification program. As a rural provider myself, I I was in a situation where a cybersecurity attack happened at my hospital in Zanesville, Ohio, that shut us down for a day and a half. So I've lived through it and I understand how serious these are and I understand the problems with ransomware attacks. The attacks will always become more sophisticated, so we have to make sure that our our cybersecurity posture and certification program keep up. And the flexibilities that we're introducing to be consistent with the HIPAA Security Rule will allow that to happen.
In June of this past year, Senator Hassan and I introduced a bill called the Rural Hospital Cybersecurity Enhancement Act, which this committee has passed unanimously. It's awaiting action on the floor of the Senate. What it does in part, in relevant part, is directs HHS to develop a comprehensive rural hospital cybersecurity workforce strategy, development strategy, that at a very minimum would consider public-private partnerships, development of training resources, and policy recommendations. Can I just help you, can I just ask you, would the development of a comprehensive workforce strategy like that help your office further its goals of improving quality of care and optimizing systems for for rural healthcare providers?
Thank you for the question, Senator, and thank you for the focus on cybersecurity and also rural healthcare providers. I did it for the entire first part of my career. Anything that the Senate can do to help us improve the cybersecurity posture of all hospitals and in particular rural and underserved hospitals would be helpful to HHS. And we're happy to provide technical assistance on any legislation that you're considering.
Good, very good. Thank you. Well, I hope to see the bill pass the full Senate soon and look forward to working with you on that and I'm sure other matters. Mr. Chairman, thank you again.
Thank you, Senator Hawley. I'll have a second round myself. First, I want to point out, by the way, Senator Hawley, the Infrastructure Investment and Jobs Act is now dispensing money to make sure that everyone has access to high-speed affordable internet. So the rural patient in Missouri and in Louisiana will now have access to telehealth, tele-mental health, etc. And so I do think that there is the operationalization of this is in the offing. So just to say that. And then Dr. Keane, we spoke earlier about administrative burdens. And I'm told that ASTP ONC has recently proposed a rule to remove 34 certification criteria required for health IT products. Some changes are for criteria no longer in effect. Others include those related to privacy and security. Now, what I don't know with the removal of these is it because they are merely a regulatory burden for people to bring in new products? Because sometimes regulations restrict market access. Or if the removal of these regulations mean that it will be less secure and fewer protections to privacy.
Thank you for the question, Chairman, and thank you for the opportunity to provide clarification. We believe that the pivot towards a more modern aligned certification program will allow for the most advanced cybersecurity posturing and the most advanced privacy protections to be introduced into the certification program. We did an assessment of all 60 certification criteria that we promulgate and we looked for ones that were outdated, that were redundant, that had become firm market baselines, or that were not widely adopted because people didn't certify to them. So for example...
Now, hang on, but not certifying does not necessarily mean it's not valid, correct?
That's correct. But if the uptake for a particular certification criterion is low, it's not having an impact on the market. And further, even if somebody certifies to the criteria, it doesn't mean that it's actually deployed. And I can give you a concrete example. I mean, you've practiced medicine for over two decades. And we have a criteria that asks EHR developers if they support multi-factor authentication. We don't require them to do that. We just ask them if they do. And about half do and about half don't. Very few actually deploy these in actual hospital settings. And as you know, having practiced, the reason is it's very hard to do multi-factor authentication in the actual physician workflow. There are very strong privacy and security protections within the hospitals themselves. One of them is you have to badge into the physician's office. Increasingly, hospitals are taking FIDO2 security postures, which are even more advanced than multi-factor authentication. All of the EHRs and all of the hospitals have to observe all of the strictures of the HIPAA Security Rule, which require, you know, transmission security, integrity controls, audit controls, access controls, and I won't bore you with things like Transport Layer Security 1.3. But as these as these technologies evolve, we want to make sure that the governing law, the HIPAA law, which is risk-based, is the one that everybody adheres to so that the latest and greatest technologies...
So it isn't that we're relaxing, but rather that we're modernizing.
Absolutely not. The HIPAA law still...
Well, let me ask you this. Yeah. Going stay on HIPAA. We talked about somebody uploading their personal health information to an AI platform that could then integrate their data. Under HIPAA, would that AI platform then be a covered entity with all of the protections to the patient's data that is implied by being a covered entity or not?
Thank you for the question. So CMMI just recently released, I believe, their ACCESS model, in which individual apps like the ones you're speaking of can actually enroll as Part B providers in Medicare to get some sort of compensation for using the app. And under those situations, those apps are covered entities and they're covered by HIPAA. But to the point that you're making, a large portion of the apps that people are uploading their data to are not covered entities and HIPAA doesn't apply to them.
So that we need do we need can that be done by rule? Because you mentioned earlier the need to make sure that privacy is protected.
100 percent in agreement.
And so there's not philosophically a difference between an app which is required to be HIPAA compliant and AI which is being uploaded to and then can use my data. And you said under TEFCA or whatever, it's not supposed to be commercialized or used for marketing. But again, if you put it up here in the AI, then it could be by somebody who was willing to push the envelope. Patients have autonomy on how their data is used. I think it's important that the patient understands how that data is going to be... Let me stop you though. My patient population and I find most patients are not aware of these issues. You and I live and breathe them. Yeah. But unless you're an engineer who's anal-compulsive, which by definition you're an engineer, you know what I'm going to say. Yeah. I'm redundant. Most people are not going to understand the implications of putting my genetic data up there, which then AI could then figure out who all my relatives are and then potentially redline my relatives for insurance because even though we have a law against it, somehow they can work around because they now have access to my genetic data. So I do think there's some some consumer safeguards that should be implemented, like a box that pops up. Your data uploaded will be, boom, boom, boom, now accessible for marketing unless you say not. Do you agree or disagree?
We we agree at ASTP that anything that improves the security and privacy posture of patients is something worth looking at and something that we support. Yeah, I can tell you that we are laser-focused on it in the programs that we administer and...
But but do you need new authorities for that or does Congress have to pass a law? And or is it even philosophically not where you are because a previous ONC director seemed to feel pretty much like a libertarian, the patient could do whatever they wanted with the data. And I'm thinking sure they can, but I don't know if they know what they're doing with their data.
Yeah, and as as somebody who's practiced medicine for two decades, I understand that patients don't always understand where their data is going. And I believe that anything that improves the security and privacy posture of...
But do you need more authority or can you do that with your current authority?
I don't think that we are able to regulate data that the patients have consented to be released. What I can say is that the standards that we promulgate create a clean surface on which any future regulation or legislation can actually act effectively.
Yeah. And by the way, let me emphasize, I'm a very much techno-optimist when it comes to AI. But you know the old principle that bad money drives out good. We can force people to go to the lowest common denominator, the the bad actor forcing the action of all others.
And we really hope that doesn't happen and we appreciate your focus on it.
Closing Remarks
For any Senator wishing to ask additional questions, questions for the records are due 5:00 p.m. Thursday, March 19th. Again, Dr. Keane, thank you for being here. Thank you so much, Chairman Cassidy. Thank you.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



