Summary of FY26 Senate Appropriations Bill
Read a detailed summary of the FY26 Senate Appropriations Bill, which was released on July 31.
Read a detailed summary of the FY26 Senate Appropriations Bill, which was released on July 31.
The Senate released its version of the FY25 LHHS appropriation bill on August 1, 2024, with significant changes in proposed public health funding than the House's proposed bill.
ASTHO Legislative Prospectus | Previewing 2025 state legislative actions on data modernization and privacy.
Learn about the importance of exploring intermediaries that work alongside existing data platforms in addressing ongoing public health challenges.
What Public Health Leaders Need to Know About HTI-2 Proposed Rule How Proposed HTI-2 Rule Will Benefit Public Health Data Exchange Lillian Colasurdo, Lana McKinney, Alexandra Woodward Read how the HTI-2 rule improves upon HTI-1 standards and criteria for data exchange among public health, health care, and data providers to benefit public health. On July 10, 2024 HHS’s Assistant Secretary for Technology Policy/Office of the National Coordinator of Health Information Technology (ASTP) published the proposed rule: Health Data, Technology, and Interoperability: Patient Engagement, Information Sharing, and Public Health Interoperability (HTI-2). This rule, which advances interoperability and supports access, exchange, and use of electronic health information (EHI), represents a significant step towards strengthening public health data infrastructure and promotes interoperability between health care and public health entities. It proposes significant changes impacting public health agencies (PHAs) and removing barriers to EHI exchange, while attempting to streamline health IT processes. Background Two of the most significant federal laws passed in the past fifteen years for health data exchange are the Health Information Technology for Economic and Clinical Health (HITECH) Act and the 21st Century Cures Act. Together, these laws provided ASTP with authority to set standards for and certify heath information technology. ASTP’s certification program mandates that electronic health records (EHR) comply with the new standards and eligible providers and hospitals must use certified technology to be fully reimbursed by the Centers for Medicare & Medicaid Services. Additionally, these laws grant ASTP rulemaking authority. Earlier this year, ASTP finalized the HTI-1 rule, taking substantial steps toward improving public health and health care data exchange. This rule requires EHR systems to support either HL7 Clinical Document Architecture (CDA) or Fast Healthcare Interoperability Resources (FHIR) standards for electronic case reporting, both of which enhance the data quality and timeliness for public health reporting. HTI-1 also directs EHR developers to track and report on the amount of data electronically submitted to Immunization Information Systems (IISs); that information helps improve vaccine product distribution and availability. While the rule sets the stage for a future transition to a FHIR-based approach for case reporting, there must be an adequate transition period for public health agencies. While HTI-1 took significant steps toward improving the way data is exchanged, primarily in the health care setting, the proposed rule HTI-2 aims to expand these standards to further benefit public health. The HTI-2 expands upon the interoperability standards established in HTI-1 and aims to improve interoperability by revising the ONC Health IT Certification Program. It specifically proposes two new sets of certification criteria for IT developers that will benefit public health entities and payers. Public health agencies face many barriers to efficiently exchanging data with health care providers and other entities including lack of common data standards, inconsistent reporting requirements, limited system interoperability, and inadequate public health data infrastructure. HTI-2 addresses these challenges by establishing certification criteria for public health technologies, creating a common floor to support data exchange. In addition, HTI-2 introduces changes to the Information Blocking Rule and provides transparency to Trusted Exchange Framework and Common Agreement (TEFCA) requirements. Micky Tripathi - What PH Leaders Must About HTI-2 Proposed Rule Key HTI-2 Provisions Certification Criteria, Standardizing Application Programming Interfaces (APIs) HTI-2 proposes four standards and certification criteria that may impact public health systems. Depending on the criteria, ASTP proposes that many of them be implemented by the beginning of 2027 and 2028. Updating naming conventions and standards for existing functional criteria. There are currently nine functional (or “f”) criteria EHRs must meet to exchange data with public health agencies. The updated naming conventions and standards point EHR vendors and public health systems to the latest standards for implementation. Additionally, these updates include two new criteria for birth reporting and bi-directional exchange with a prescription drug monitoring program. Establishing new certification “f” criteria for Health IT so Public Health certified systems can receive, validate, parse, and filter standardized data. These functions will apply to immunization, syndromic, laboratory, cancer pathology, case, birth, and prescription drug monitoring program data. Adopting the United States Core Data for Interoperability (USCDI) version 4, a standardized set of health data classes and elements for interoperable health information exchange. Version 4 includes several new data elements relevant to public health, such as health status assessments (e.g., alcohol and substance use). Standardizing HL7 FHIR-based API for public health data exchange by creating new certification criteria to support ongoing development and transition to FHIR for patient and population-level data exchange. CDC and ASTP have noted potential benefits of increasing public health access to critical data while reducing the reporting burden on both health care organizations and developers. HTI-2 proposes similar certification standards and alignment for reporting to payers that comply with existing CMS API requirements. Information Blocking Updates The Information Blocking Rule requires that patients have timely access to their own electronic health records and prohibits health care providers and networks, HIEs, and developers from interfering with said access. When a public health agency serves as a provider, it is crucial to ensure that patients can access records in compliance with the existing rule. HTI-2 clarifies what constitutes “interfering” with the access and exchange and provides a non-exhaustive list of examples. HTI-2 also proposes a new exception to information blocking—the Protected Care Access Exception—that would “apply to acts or omissions likely to interfere with access, exchange, or use of particular EHI that an actor believes could create a risk of exposing patients, care providers, and other persons who assist in access or delivery of health care to potential administrative, civil, or criminal investigations or other actions on certain bases.” This exception is particularly relevant for jurisdictions with more restrictive laws for sharing reproductive health data. TEFCA Governance Rules As ASTP and its Recognized Coordinating Entity (RCE), the Sequoia Project, seek to establish standards for implementing the Trusted Exchange Framework and Common Agreement (TEFCA), the proposed HTI-2 rule would codify one portion of the framework by establishing the qualifications for Qualified Health Information Networks (QHINs), onboarding and designation processes, the attestation process, termination and appeal rights, and ASTP’s formal authority to delegate responsibility to the RCE. Conclusion The HTI-2 proposed rule represents a significant step towards strengthening public health data infrastructure and promotes interoperability between health care and public health entities. It is specifically designed to “address gaps in public health data and help the nation become response-ready, promote health equity, and improve health outcomes for all.” The Joint Public Health Informatics Taskforce (JPHIT), coordinated by ASTHO and consisting of 14 member organizations including public health associations, gathered comments and input from constituent members and submitted consolidated feedback on the proposed rule in October and awaits responses and the final rule from ASTP. OE22-2203 PHIG article yes
ASTHO has several members from the territories and Freely Associated States—jurisdictions with unique challenges, and do not fall under the category of a state or federal district. This post is a brief look at some of the public health related legislation introduced during recent legislative sessions.
This June marked the 40-year anniversary of the first five cases of what later became known as AIDS reported in CDC’s Morbidity and Mortality Weekly Report. Since then, more than 32 million people have died from the disease worldwide and nearly 38 million currently live with the HIV virus (including 1.2 million people in the United States). Over that period, tremendous strides have been made in HIV testing, prevention strategies, and treatment of individuals living with the virus to ensure that they can lead healthier and longer lives. While these advancements have led to significant progress in reducing HIV/AIDS-related deaths and new infection rates, HIV/AIDS continues to be a persistent problem in the United States. The federal government and state legislatures are taking significant steps toward ending the HIV epidemic, including steps to reduce new infections, combating stigma, and advancing access to care and HIV prevention
As a truly historic year comes to an end, many public health policy issues received a considerable amount of attention in 2020. Subjects such as the pandemic that will live on in infamy, racial health disparities, and the future of the Affordable Care Act, are just a few of the major health issues that took center stage on Capitol Hill this year.
Sustaining DMI: A State Health Official’s Guide to Enhanced Funding Sustainable financing strategies for state health officials to support data modernization and Medicaid. What is the relationship between a state’s Medicaid program and its public health data system? Although state implementation of the Medicaid program (Title XIX of the Social Security Act) varies, each state’s program has enrollment and claims data on Medicaid participants, including demographic data on race and ethnicity, age, and service utilization, such as vaccines received. At the same time, a state’s public health system needs to collect, analyze, and report diverse data from public health initiatives and related programs to support its goals to protect and improve the health of individuals and communities by promoting healthy lifestyles, researching and encouraging disease and injury prevention, and detecting, preventing, and responding to infectious diseases. A state’s Medicaid program and public health agency can collaborate to implement a sustained data modernization initiative (DMI) that combines Medicaid and public health data and integrates these data into the state’s health-related data ecosystem. A sustained DMI can yield various improvements to a state’s health-related data ecosystem, such as improved data quality, public health reporting, data storage and resiliency, and analytics to respond to pandemics. It can also set the stage for data sharing with additional data system partners, which can further improve the state’s health-related data ecosystem. Why is sustainable funding necessary to continue DMIs? Sustainable funding to support personnel, processes, and technology is imperative to the continued success of a DMI. Stable funding can increase state Medicaid and public health agencies’ likelihood of recruiting and retaining personnel with advanced degrees, such as biostatisticians and epidemiologists, by enabling the agencies to offer compensation packages that are competitive with job market rates. Stable funding also enables the agencies to maintain and refine new and existing data-sharing processes, and it ensures that technology is maintained and upgraded appropriately to meet evolving needs. Medicaid funding is a potentially large and stable funding stream that can support the personnel, processes, and technology in a DMI that focuses on integrating Medicaid and public health. However, public health funding has historically been an unstable patchwork of federal, state, local, and private funding streams and mechanisms, largely because of changing economic and political priorities and the perceived risk level and severity of major public health threats. What sustainable financing strategies can support the personnel, processes, and technology needed to continue DMIs? State health officials can use the following three strategies when pursuing Medicaid funding to sustain a DMI: Blend and braid funding sources. Optimize existing and potential funding streams by blending or braiding administrative approaches to grow and maintain programs. To blend funding sources, program officials combine funding into a single stream, which results in a loss of award-specific requirements and thus requires statutory authority. In contrast, braiding funds allows program officers to direct funds toward a single strategy or initiative while preserving funding requirements (Box 1). Callout 1 - Resource - Sustaining DMI: A S/THOs Guide to Enhanced Funding Support personnel by using cost allocation through the Advance Planning Document (APD) process or the Administrative Cost Allocation Plan. A DMI team often has people with specialized skills, such as clinical and technical experts, compliance or legal officers, and financial experts. The salary for these people may be cost-allocated via the APD process or the Administrative Cost Allocation Plan described in Social Security Act Section 1903(a)(7) (Box 2). To illustrate, the Administrative Cost Allocation Plan provides 50 percent match for costs that meet a series of requirements to cover personnel costs. In addition to this strategy, state health officials can cover salary costs through blending and braiding approaches. Callout 2 - Resource - Sustaining DMI: A S/THOs Guide to Enhanced Funding Align public health functions with Medicaid business and technical functions. To explore whether a state Medicaid agency could access enhanced federal funding to support public health, a state public health agency must approach the state’s Medicaid program collaboratively and design and implement a DMI that does the following: Meets the Conditions for Enhanced Funding and couples any technical system improvements with measurable outcomes that improve public health and the Medicaid program. Investigates the extent to which the public health technical functions (for example, health care provider enrollment) align with similar Medicaid business functions. Confirms the extent to which the public health functions and Medicaid Enterprise Systems share or could share (that is, reuse) core technical components to support common business functions. Callout 3 - Resource - Sustaining DMI: A S/THOs Guide to Enhanced Funding After this investigation is complete, the state Medicaid agency should explore cost allocation models that apportion costs with the benefits received (Box 3). Box 4 provides examples of public health use cases that successfully acquired enhanced Medicaid funding. Callout 4 - Resource - Sustaining DMI: A S/THOs Guide to Enhanced Funding website yes
Sustaining DMI: Medicaid Advanced Planning Document Process How state Medicaid agencies can request enhanced federal funding for Medicaid Enterprise Systems and related activities. Why is the Advanced Planning Document process important? Based on information from the Government Accountability Office (GAO), the Centers for Medicare & Medicaid Services (CMS), and the Federal Register, the Advanced Planning Document (APD) process is a procedure through which states develop a plan of action for their Medicaid information technology (Medicaid IT) projects. These plans are for designing, implementing, or operating Medicaid Enterprise Systems (MES) projects. State Medicaid agencies (SMAs) submit completed APDs to CMS—specifically a designated state officer in the Center for Medicaid and Children’s Health Insurance Program (CHIP) Services (CMCS) Data and Systems Group (DSG)—to request federal financial participation for their activities. The state officer reviews APDs to assess whether states’ requests for federal financial participation for designing, developing, implementing, or maintaining MES activities contribute to the economic and efficient operation of Medicaid and meet specific technical and operational criteria defined in statute, regulation, or sub-regulatory guidance. A state that receives federal financial participation can see increased access to stable federal funding to support MES activities. In addition, APDs are used to monitor a state’s project performance and outcomes. What are the three types of APDs? There are three types of APDs: Planning, Implementation, and Operational (Table 1). Table - Resource - Sustaining DMI: Medicaid Advanced Planning Document Process What are the major steps for states in the APD process? To request enhanced federal funding for MES, SMAs must complete the APD template that aligns with where they are in the development of their project (for example, design or maintenance) and submit it to the designated CMCS DSG state officer. The APD process contains five major steps and can take many months to complete: Meet with key state contacts and decision-makers. Based on information from the Public Health Informatics Institute’s information and tip sheets, before developing the APD, the SMA should identify and engage key state contacts and decision makers to solicit their input about the proposed project and secure their and their staff’s collaboration to complete and submit the APD to the CMCS DSG state officer. The state health agency (SHA) should work closely with the SMA during this process to ensure that they provide needed support to the SMA. For example, the SHA may gather information for the SMA to include in the APD or advise on how to complete particular sections of the APD. During this process, the SMA and SHA should consult with their respective agency leadership to discuss the type of technological solutions Public Health maintains, Public Health’s relationship with the state Medicaid program, and the opportunity to align systems to reduce overall state costs and improve state efficiency through the APD process. The SMA and SHA should also engage the MES lead, who can offer critical information about current MES components and component certification needed to complete the APD. In addition, GAO recommends states involve their chief information official in overseeing Medicaid IT projects because they can play a critical role in decision making related to IT budgets, management, and oversight. Next, the SMA and SHA should engage the CMCS DSG state officer to develop a strong understanding of how the APD can support the Medicaid program and serve a public health interest. Coordinating with the state project management office can help integrate the diverse parties and processes needed to develop and submit the APD for approval. It can also help ensure that states develop a comprehensive and flexible timeline for the APD process, stay aware of approaching deadlines, and meet ad hoc requirements. Develop the appropriate APD. Next, based on 45 C.F.R. § 95.610(c), the SMA and SHA should identify which of the three types of APDs to submit to the CMCS DSG state officer. Planning APDs are recommended for large and complex projects, such as statewide projects. However, if a state can identify a clear and easy pathway to integrate a public health information technology system with a current MES procurement or development phase, it can forgo developing a Planning APD and directly develop or update an existing Implementation APD. For example, if a state is looking to integrate its counties’ public health data into its MES at once, it should develop a Planning APD as the project is large and affects all counties in the state. However, if a state already has most of its counties’ public health data in its MES but is looking to add a single county’s data to its MES using the same process it previously and successfully used to add the other counties’ data, it may not need to submit a Planning APD. If a state has already successfully integrated its counties’ public health data into its MES and is looking to make major technology upgrades and improvements, it should submit an Operational APD. Regardless of the type of APD the state submits, the SMA and SHA should work together to ensure the request meets the Conditions for Enhanced Funding (see separate document Conditions for Enhanced Funding: The Basics). Submit the APD for approval and be available for revisions. Based on information from CMS, GAO, and the Office of Child Support and Enforcement, the state should then submit the APD to the designated CMCS DSG state officer. The SMA and SHA should plan to receive questions and revision requests from the CMCS DSG state officer and ensure that the state has staff capacity to answer questions and revise and resubmit. Approval conditions can be found at 45 C.F.R. § 307.15, but approval criteria might vary by Medicaid IT project and other factors. If approved, implement the plan. Next, the state can carry out the plan described in its Planning and Implementation APDs. After the Medicaid IT project has been operating for at least six months, states can request system certification from CMS. According to CMS, certification is required to receive the enhanced 75 percent federal financial participation for operations. The certification process includes states submitting to CMS an intake form, a certification request letter, and supplemental materials with information on its system. CMS may then start its review to assess whether the state’s system meets certification requirements. If approved, monitor and report progress and submit other APDs as needed. Based on 45 C.F.R. § 95.610(c) and 45 C.F.R. § Part 95 Subpart F and information from CMS, CMCS, Office of Child Support and Enforcement, as the state continues with its Medicaid IT project, it should adhere to monitoring and reporting requirements for enhanced federal funding. It also should submit annual APDs as required. If the state wants to make any major changes to the Medicaid IT project in concept, scope, cost allocation approach, timeline, and other key areas, it must develop and submit an as-needed APD. An as-needed APD is due no later than 60 days after the occurrence of the change. State examples: Medicaid Enterprise System projects Based on information from Alvarez & Marsel, state MES projects will vary based on factors such as the maturity of a state’s technology infrastructure, its specific data needs, and its available resources. As such, projects to design, implement, or operate MES can range in size, complexity, and timeline. For example, the Alabama MES Modernization Program, the Wyoming Integrated Next Generation System Project, and the Florida Health Care Connections project all seek to transform their singular Medicaid Management Information Systems (MMIS) into modular, multi-vendor MES, but differ in approach. In addition, Arizonia and Hawaii are collaborating to modernize their shared MES. For more information on state MES projects, see the Medicaid Enterprise System Solution/Module Contract Status Report. This webpage lists states’ MMIS and Eligibility and Enrollment contract information for their MES projects. It also lists contact information for state officers to reach out to learn more about states’ MES projects. website yes
This ASTHO blog discusses the benefits and risks of AI in healthcare and federal legislation, including privacy, bias, and safety concerns.
In May 2021, President Biden released full details of the fiscal year 2022 budget. Overall, the budget request combines President Biden's American Jobs Plan, his American Families Plan, and funding priorities for the Pentagon and domestic agencies, for a projected total of $6 trillion. Read more about what the president is proposing in this post.
Public health data collection and surveillance systems by health departments are in dire need of modernization. Though the public health community began developing a path to modernization over the last decade, attention to this issue from policy makers has sharply increased with the current response to the COVID-19 pandemic. Not only are current systems siloed, they rely on labor intensive processes to detect and facilitate a response to various public health threats.
Neonatal Abstinence Syndrome (NAS) has become more prevalent in the United States, with the hospitalization rate increasing from 2.9 to 7.3 hospitalizations per 1,000 newborn births between 2009 and 2017. NAS occurs in newborns who experience withdrawal from substances they were exposed to during pregnancy. While NAS is most often associated with exposure to opioids (e.g., Neonatal Opioid Withdrawal Syndrome), it can also be caused by exposure to other drugs such as cocaine, amphetamines, or barbiturates. Infants with NAS experience withdrawal symptoms including tremors, irritability, poor feeding, vomiting, dehydration, and increased sweating. These symptoms usually appear within 72 hours of birth.
The New Frontier of Digital Proximity Tracing Association of state and territorial health officials, astho, public health, covid-19, contact tracing, case investigation, public health surveillance, infectious disease, proximity tracing, exposure notification, public health agencies, data privacy, public health official, state legislature, geolocation, health data, test positive for covid-19, personal data, data collected, health departments Jeffrey Ekoma Digital proximity tracing is the cutting-edge for tracking outbreaks of COVID-19, but many have concerns about data privacy. States have proposed legislation to balance the two. As state, local, territorial, and tribal (SLTT) health departments continue to cautiously reopen parts of their economy, they also continue to take necessary measures to prevent the spread of COVID-19. A major component of this work is traditional contact tracing, a staple of public health surveillance where public health workers track down and notify anyone who might have contact with someone who tested positive for an infectious disease. However, new strategies that would supplement traditional tracing have been gaining momentum. Google and Apple collaborated to create an application programming interface (API) platform for public health agencies interested in a new type of “proximity tracing” or “exposure notification.” The platforms are expected to assist in the creation of apps between software developers and public health jurisdictions. It specifically utilizes Bluetooth technology —readily available in cellular devices—to randomly generate temporary keys on a user’s device when a user downloads an exposure notification application. This then enables the application to alert an individual if they have been or potentially exposed to someone who also uses the application and who tested positive for COVID-19. It’s worth noting the platform created by Google and Apple does not collect location information or information of users who do not voluntarily mark themselves as being positive for COVID-19. There are other notable exposure notification apps being used by SLTTs including Care19, an app developed by ProudCrowd that’s currently being used in North Dakota and South Dakota. Also, CommCare, which is currently being used in New Jersey and was developed by Dimagi. As expected, the introduction and potential influx of these types of apps have brought many different concerns, primarily centered around data privacy and how the platforms and applications would protect, store, and safely discard information that it collects. This issue became of interest to Sen. Maria Cantwell, current ranking member of the Senate Committee on Commerce, Science, and Transportation. In response she drafted S. 3861 Exposure Notification Privacy Act, which proposes assistance to public health jurisdictions exploring exposure notification applications and technologies. The act would ensure that such platforms have the necessary capacity to protect the personal data of consumers, limit the type of data collected, as well as the type of entities that would have access to such data. In addition, the legislation also: reaffirms the role of public health officials in requiring their involvement in the development and deployment of exposure notification systems; requires that participation from individuals be on a voluntary basis and with consumer consent; limits the collection and use of data; prohibits commercial use of data; and permits participants to delete their data at any time; among other things. The legislation was recently co-introduced with Sens. Bill Cassidy and Amy Klobuchar, and received support from the Washington State Department of Health, Council of State and Territorial Epidemiologists, and the National Coalition of STD Directors. This legislation is currently pending in the Senate and it is unclear if it will be considered in the upcoming months. There is also movement in state legislatures to address the use of technology. In California, legislation (AB 660) was introduced that would require any state agency contract that uses a mobile device’s geolocation data for exposure notification to a communicable disease to include provisions requiring the contractor to inform the app user of the authorized purposes of the app and collected data. Another bill (AB 1782) introduced in the state would require public health entities and businesses offering exposure notification services to allow users to revoke consent for the collection, use, maintenance, or disclosure of the user’s information. Businesses that provide exposure notification services but are not affiliated with a public health entity would be required to disclose its non-affiliation. The bill would also require the encryption of data collected by the technology, limit the use of the data as well as the amount of time the data can be maintained, and require reported exposures be verified by a healthcare provider before notifying logged contacts of their potential exposure. In New York, companion bills were introduced (A 10583A and S 8448B) that would establish requirements for the collection and use of emergency health data and the use of technology for collecting data during the COVID-19 emergency. Specifically, the bill requires the disclosure of certain information to those who install and use data collecting apps on mobile devices, including information about the right to opt-in, the right to privacy, the app’s privacy policy, time limitations for maintaining the data, and the individual’s right to access the data. Unlike the bills in California, individuals in New York would be able to sue for violations of the law. Several SLTT’s are currently either exploring, developing, or implementing proximity tracing applications within their respective jurisdictions. It remains critical that SLTT health departments evaluate the implementation of any proximity tracing option, while concurrently evaluating pertinent data and privacy related issues that may arise with the collection and sharing of information from individuals. In the coming days, ASTHO plans to release a guide to assist health officials as they think through the critical functionalities, technological options, and implementation of these emerging technologies. ASTHO will continue to track and monitor legislation that seeks to address data and privacy concerns with proximity tracing and exposure notification applications. website yes