Practice Insider · Issue 17

The EHR export criterion has two halves, and only one has to run without the vendor

The export obligation inside a certification criterion, the mid-year code update practices keep missing, a compliance date that slipped a year, and the two Medicare payment numbers that point in opposite directions. Every figure here was read from the Code of Federal Regulations, the United States Code, the Federal Register and the CMS ICD-10 page on build day.

September 2026 For solo and small-group owners Unsubscribe anytime
What does your practice need help with?
Credentialing · Billing & RCM · Financing · Practice Consulting · Other help

Get Practice Insider free

Join independent practice owners reading it every week. Enter your email and the next issue lands in your inbox.

No spam. One email a week. Your address is never sold.

You are subscribed. Check your inbox for a confirmation.

Issue 17 · September 2026

The EHR export criterion has two halves, and only one has to run without the vendor

The lead: the EHR export that has to run without the vendor, and the one that does not

A practice asks its EHR vendor for a copy of a patient record in a form some other system can read, and the reply comes back as a scope of work with a price on it. For certified health IT, part of that capability was settled years ago inside a certification criterion, and the sentence that settles it is unusually blunt.

A user must be able to execute this capability at any time the user chooses and without subsequent developer assistance to operate.

That is 45 CFR 170.315(b)(10)(i)(B), and the capability it governs is the single patient export: an export file with all of a single patient's electronic health information that can be stored at the time of certification by the product, electronic and in a computable format. The obligation to carry that capability at all sits one part over, in the Conditions of Certification. Under 45 CFR 170.402(a)(4), a health IT developer of a certified Health IT Module that is part of a health IT product which electronically stores EHI must certify to the certification criterion at 170.315(b)(10). Under 170.402(b)(2)(ii), on and after December 31, 2023, that developer must provide all of its customers of certified health IT with the health IT certified to that criterion. That deadline is not approaching. It passed.

The criterion has a second half, and reading the two halves against each other is where the useful part sits. Paragraph (b)(10)(ii) is the patient population export, and it asks the product to create an export of all the electronic health information that can be stored at the time of certification by the product, also electronic and in a computable format. What paragraph (ii) does not carry is the sentence quoted above. The guarantee that a user can run the export whenever the user chooses, with no further help from the developer, is written into the single patient half only. The export a practice reaches for when it is changing systems is the half the criterion never promised it could run by itself.

Two limits belong on the same page. The criterion tells the developer to restrict who may create single patient export files, either to a specific set of identified users or as a system administrative function, so the capability lives in somebody's hands at the practice or in nobody's. And the scope word is EHI, defined at 45 CFR 171.102 as electronic protected health information to the extent that it would be included in a designated record set, with psychotherapy notes and litigation material carved out. The criterion measures that scope by what the product could store at the time of certification, which is a statement about the certified product and not a promise about every field in one practice's instance today.

What to check this week

Three questions, in order. First, is the practice's system a certified Health IT Module at all, which is a fact to read off the certification program's public product list rather than off a sales page, because none of this reaches software that was never certified. Second, who at the practice sits on the identified-user list or holds the administrative function that can run the single patient export, and has anyone ever run it once to see what comes out. Third, ask the vendor in writing what the patient population export costs and how long it takes, because that is the half where the answer is commercial rather than certified. A migration conversation runs differently once those three answers exist on paper. The EHR and practice software hub covers how a system change gets scoped and where data control sits in an evaluation.

Three things worth knowing

Coding: the October code set stopped being the year's last one

CMS posts the FY 2027 ICD-10-CM files for discharges and patient encounters occurring from October 1, 2026 through September 30, 2027, which is the shape practices are used to. The two fiscal years before it did not hold that shape. The same CMS page lists a separate FY 2026 ICD-10-CM file set for use from April 1, 2026 through September 30, 2026, and a separate FY 2025 set for use from April 1, 2025 through September 30, 2025, each with its own code descriptions, addendum and code tables. ICD-10-PCS for FY 2027 is already posted only for discharges occurring from October 1, 2026 through March 31, 2027.

For a physician or dental office the set that matters is ICD-10-CM rather than PCS, and the FY 2027 CM posting currently runs the full year. The point is what happened in the two years before it. A mid-year diagnosis code update is something CMS now does, so an October download is no longer a safe assumption about the following spring.

Compliance: the practice website deadline moved a year, and the duty under it did not

45 CFR 84.84(b) sets when a recipient of HHS financial assistance has to meet a technical standard for its web content and mobile apps. Beginning May 11, 2027, a recipient with fifteen or more employees has to comply with Level A and Level AA success criteria and conformance requirements specified in WCAG 2.1, and beginning May 10, 2028 the same applies to a recipient with fewer than fifteen employees. Both dates sit one year later than the 2024 rule set them. An HHS interim final rule published May 11, 2026 made the change in a single line: the compliance date for recipients with fifteen (15) or more employees is extended from May 11, 2026, to May 11, 2027.

The sentence in that rule that gets skipped is the one keeping the extra year from being free. Regardless of the compliance dates, recipients have an ongoing obligation to ensure that their programs and activities offered using web content and mobile apps are accessible to individuals with disabilities in accordance with their other obligations under section 504. What moved is the date a named technical standard becomes enforceable, and what did not move is the duty underneath it. Whether any of this reaches a given practice turns first on whether the practice is a recipient of federal financial assistance from HHS, which is a question about its funding rather than about its website.

Billing: Medicare is barred from paying early, and the promptness standard is not about one claim

Two numbers govern how fast a Part B claim can pay, and they point in opposite directions. The first is a prohibition. Under 42 U.S.C. 1395u(c)(3), a contractor's agreement has to provide that no payment shall be issued, mailed, or otherwise transmitted with respect to any claim submitted under this subchapter within the applicable number of calendar days after the date on which the claim is received. The statute then fixes that number at, with respect to claims submitted electronically as prescribed by the Secretary, 13 days, and with respect to claims submitted otherwise, 28 days. A clean electronic claim received today cannot pay inside that window however clean it is.

The second number runs the other way and is softer than its reputation. The same section requires payment within 30 calendar days on not less than 95 percent of all claims submitted under this part that are clean claims, with interest owed when a clean claim misses that date. The standard is measured across a contractor's claim volume rather than promised on any one claim, so a single claim sitting at day 40 is not by itself evidence that anything was breached.

One for the back pocket

The fax machine behind the front desk has a regulatory address. HIPAA's definitions section, 45 CFR 160.103, defines electronic media, and the paragraph on transmission media closes with a carve-out: certain transmissions, including of paper, via facsimile, and of voice, via telephone, are not considered to be transmissions via electronic media if the information being exchanged did not exist in electronic form immediately before the transmission.

Follow that through the rest of the rulebook and the effect turns structural, but narrowly. The Security Rule is scoped by 45 CFR 164.302 to compliance with respect to electronic protected health information, and that term is defined by pointing back at protected health information transmitted by electronic media or maintained in it. A transmission the definitions push outside electronic media is not, on that basis, a transmission of electronic protected health information, so the technical safeguards that made email a project, encryption and access controls and transmission security, have nothing to attach to for that transmission specifically. That is a carve-out from the transmitted-by limb only; the same information can still be electronic protected health information, and still draw those safeguards, once it is maintained in electronic form, since the definition reaches records maintained in electronic media as well as those transmitted by it. The boundary that sent one piece of office equipment to the compliance committee ran just outside the transmission, not outside the underlying electronic record.

The tail of that sentence is the part the shorthand drops. The carve-out holds only where the information did not exist in electronic form immediately before the transmission. A page printed off the EHR and fed into a fax machine, or a fax generated from a workstation, does not sit comfortably inside that condition. A practice treating fax as a HIPAA-free lane on the strength of the first half of the rule is relying on a qualifier it never read to the end.

Putting this issue to work

Export rights, code table ownership, website obligations and A/R expectations are all things a practice sets once and then stops looking at. The decision tools on GetPracticeHelp are free, take about two minutes each, and ask for no email address.

Browse the decision tools →

On the numbers: the single patient and patient population export requirements, the without-developer-assistance sentence, the computable format requirement and the restriction on who may run an export are 45 CFR 170.315(b)(10)(i) and (ii); the obligation to certify to that criterion and to provide it to every customer of certified health IT on and after December 31, 2023 are 45 CFR 170.402(a)(4) and (b)(2)(ii); EHI is defined at 45 CFR 171.102. The ICD-10-CM and ICD-10-PCS file windows, including the April 1, 2025 and April 1, 2026 ICD-10-CM sets, were read from the CMS ICD-10 codes page on build day; no code count from trade coverage is used here. The accessibility dates and the WCAG 2.1 conformance levels are 45 CFR 84.84(b), and the one-year extension is the HHS interim final rule at FR Doc 2026-09266, 91 FR 25496, published May 11, 2026, whose preamble at 91 FR 25501 also supplies the sentence about the continuing obligation. The payment floor and the promptness standard are 42 U.S.C. 1395u(c)(3) and (c)(2). One arithmetic note: the statute states a prohibition on paying within 13 days, so the fourteenth day after receipt is the earliest day a payment can be issued on an electronic claim; 13 is the figure the statute states and 14 is the consequence, and the copy quotes the stated figure. The electronic media carve-out and the definitions of protected health information and electronic protected health information are 45 CFR 160.103, and the Security Rule's scope is 45 CFR 164.302. Whether the accessibility rule reaches a particular practice turns on whether that practice is a recipient of federal financial assistance from HHS, which this issue does not and cannot decide for any reader. State law, payer contracts and vendor agreements layer additional and often tighter terms on top of every federal figure here. Treat these as the federal text to check a specific situation against, not as a conclusion about that situation.

Before you act on any number here: Practice Insider gives general operational guidance on running an independent practice. It is not legal, compliance, tax or financial advice. Confirm any certification question, software contract term, coding decision, accessibility obligation or Medicare payment question with qualified healthcare counsel, your own advisors, the vendor or the payer before acting on it. Certification requirements reach certified health IT only, the accessibility rule reaches recipients of federal financial assistance from HHS, code files change on dates CMS sets, and payment timing turns on facts specific to each claim, so verify current requirements against your own situation before making a decision.