yourstate.us
45 CFR 172.202

§ 172.202 QHINs that offer Individual Access Services.

United States · 45 CFR — Public Welfare · Status: effective

Get this as JSONEmbed this
Cite this
Citation
45 CFR 172.202, § 172.202 QHINs that offer Individual Access Services, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/218204
Permanent ID
ys:prov:218204@1
SHA-256
33d72cb8ff581938f6bde216c63488ee7299232fa8b35727dde1376fcaa964a3

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

The following requirements apply to QHINs that offer Individual Access Services: (a) A QHIN must obtain express consent from any individual before providing Individual Access Services. (b) A QHIN must make publicly available a privacy and security notice that meets minimum TEFCA standards. (c) A QHIN, that is the IAS provider for an Individual, must delete the individual's Individually Identifiable Information maintained by the QHIN upon request by the individual except as prohibited by Applicable Law or where such information is contained in audit logs. (d) A QHIN must permit any Individual to export in a computable format all of the Individual's Individually Identifiable Information maintained by the QHIN as an Individual Access Services provider. (e) All Individually Identifiable Information the QHIN maintains must satisfy the following criteria: (1) All Individually Identifiable Information must be encrypted. (2) Without unreasonable delay and in no case later than sixty (60) calendar days following discovery of the unauthorized acquisition, access, Disclosure, or Use of Individually Identifiable Information, the QHIN must notify in plain language each Individual whose Individually Identifiable Information has been or is reasonably believed to have been affected by unauthorized acquisition, access, Disclosure, or Use involving the QHIN. (3) A QHIN must have an agreement with a qualified, independent third-party credential service provider and must verify, through the credential service provider, the identities of Individuals seeking Individual Access Services prior to the Individuals' first use of such services and upon expiration of their credentials.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.