2024 Connecticut General Statutes
Title 17b - Social Services
Chapter 319o - Department of Social Services
Section 17b-59e. - Electronic health record systems. Connection to State-wide Health Information Exchange. When sharing of information is not required. No provider liability when data breach, ransomware or hacking is experienced by the exchange. Deadline for connection to and participation in the exchange.

Universal Citation:
CT Gen Stat § 17b-59e. (2024)
Learn more This media-neutral citation is based on the American Association of Law Libraries Universal Citation Guide and is not necessarily the official citation.

(a) For purposes of this section:

(1) “Health care provider” means any individual, corporation, facility or institution licensed by the state to provide health care services; and

(2) “Electronic health record system” means a computer-based information system that is used to create, collect, store, manipulate, share, exchange or make available electronic health records for the purposes of the delivery of patient care.

(b) Not later than one year after commencement of the operation of the State-wide Health Information Exchange, each hospital licensed under chapter 368v and clinical laboratory licensed under section 19a-565 shall maintain an electronic health record system capable of connecting to and participating in the State-wide Health Information Exchange and shall apply to begin the process of connecting to, and participating in, the State-wide Health Information Exchange.

(c) Not later than two years after commencement of the operation of the State-wide Health Information Exchange, (1) each health care provider with an electronic health record system capable of connecting to, and participating in, the State-wide Health Information Exchange shall apply to begin the process of connecting to, and participating in, the State-wide Health Information Exchange, and (2) each health care provider without an electronic health record system capable of connecting to, and participating in, the State-wide Health Information Exchange shall be capable of sending and receiving secure messages that comply with the Direct Project specifications published by the federal Office of the National Coordinator for Health Information Technology. A health care provider shall not be required to connect with the State-wide Health Information Exchange if the provider (A) possesses no patient medical records, or (B) is an individual licensed by the state that exclusively practices as an employee of a covered entity, as defined by the Health Insurance Portability and Accountability Act of 1996, P.L. 104-191, as amended from time to time, and such covered entity is legally responsible for decisions regarding the safeguarding, release or exchange of health information and medical records, in which case such covered entity is responsible for compliance with the provisions of this section.

(d) Nothing in this section shall be construed to require a health care provider to share patient information with the State-wide Health Information Exchange if (1) sharing such information is prohibited by state or federal privacy and security laws, or (2) affirmative consent from the patient is legally required and such consent has not been obtained.

(e) No health care provider shall be liable for any private or public claim related directly to a data breach, ransomware or hacking experienced by the State-wide Health Information Exchange, provided a health care provider shall be liable for any failure to comply with applicable state and federal data privacy and security laws and regulations in sharing information with and connecting to the exchange. Any health care provider that would violate any other law by sharing information with or connecting to the exchange shall not be required to share such information with or connect to the exchange.

(f) The Commissioner of Health Strategy shall adopt regulations in accordance with the provisions of chapter 54 that set forth requirements necessary to implement the provisions of this section. The commissioner may implement policies and procedures necessary to administer the provisions of this section while in the process of adopting such policies and procedures in regulation form, provided commissioner holds a public hearing at least thirty days prior to implementing such policies and procedures and publishes notice of intention to adopt the regulations on the Office of Health Strategy's Internet web site and the eRegulations System not later than twenty days after implementing such policies and procedures. Policies and procedures implemented pursuant to this subsection shall be valid until the time such regulations are effective.

(g) Not later than eighteen months after the date of implementation of policies and procedures pursuant to subsection (f) of this section, each health care provider shall be connected to and actively participating in the State-wide Health Information Exchange. As used in this subsection, (1) “connection” includes, but is not limited to, onboarding with the exchange, and (2) “participation” means the active sharing of medical records with the exchange in accordance with applicable law including, but not limited to, the Health Insurance Portability and Accountability Act of 1996, P.L. 104-191, as amended from time to time, and 42 CFR 2.

(P.A. 15-146, S. 22; June. Sp. Sess. P.A. 17-2, S. 126; P.A. 22-58, S. 38; P.A. 24-19, S. 22; 24-81, S. 181.)

History: P.A. 15-146 effective June 30, 2015; June Sp. Sess. P.A. 17-2 amended Subsec. (c) by designating existing provisions re applying to connect to and participate in State-wide Health Information Exchange as Subdiv. (1), and adding Subdiv. (2) re health care provider without electronic health record system capable of participating in the State-wide Health Information Exchange, effective October 31, 2017; P.A. 22-58 added Subsec. (d) re executive director of Office of Health Strategy's authority to adopt regulations and policies and procedures, effective May 23, 2022; P.A. 24-19 amended Subsec. (c) to prohibit provider from being required to connect with State-wide Health Information Exchange if provider possesses no medical records or exclusively practices as employee of covered entity and covered entity is responsible for health information and medical records, added new Subsec. (d) re not requiring provider to share patient information with exchange if prohibited under privacy and security laws or affirmative consent is required from patient but has not been obtained, added Subsec. (e) re prohibiting provider from being liable for claim related directly to data breach, ransomware or hacking of exchange, redesignated existing Subsec. (d) as Subsec. (f) and added Subsec. (g) re deadline for connecting to and actively participating in exchange, effective July 1, 2024; P.A. 24-81 amended Subsec. (d) by replacing references to executive director of the Office of Health Strategy with references to Commissioner of Health Strategy, effective May 30, 2024.

Disclaimer: These codes may not be the most recent version. Connecticut may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the state site. Please check official sources.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.