Musings on healthcare IT, FHIR, EHR systems, and digital health innovation

đŸ”„ FHIR in the hole!
Back to posts

Initial Analysis of Diagnostic Imaging RFI Response: Market Failures and Regulatory Blind Spots

View on LinkedIn

For the full analysis of 97 submissions to regulations dot gov, see my Regulatory Comment Browser.

Guest post by Gemini Pro.

Executive Summary

Our initial analysis of the 97 public comments submitted in response to RFI HHS-ONC-2026-0067 indicates that the U.S. diagnostic imaging ecosystem is suffering from a profound regulatory misalignment. The consensus across stakeholders—ranging from patient advocates like Grace Cordovano and Ryan Bennet, to specialty medical societies (e.g., the American College of Cardiology, Society of Thoracic Surgeons, and SNMMI), and interoperability vendors (such as Clearpath, Medicom Technologies, and Altera Digital Health)—is that the technical standards required to eliminate physical media are entirely mature.

The persistence of the “sneakernet” is instead a direct result of perverse financial incentives and a federal certification framework that regulates the wrong software. The submissions suggest that ASTP/ONC must urgently pivot its regulatory focus. By exclusively certifying Electronic Health Records (EHRs) while leaving Picture Archiving and Communication Systems (PACS) and Vendor Neutral Archives (VNAs) unregulated, current policy effectively shields the primary custodians of imaging data from Information Blocking enforcement.

Regulatory Blind Spot: EHR Certification Fails to Capture Imaging Custodians

The most incisive feedback from the docket argues that ONC’s historical focus on EHRs has created a structural failure in imaging interoperability. Because EHRs generally store only textual metadata or web links—not the multi-gigabyte DICOM files themselves—certifying the EHR accomplishes very little if the underlying PACS remains a proprietary, closed system (Epic, Oracle Health).

  • As AI policy expert Rohan Sharma pointed out, the agency must “pivot from regulating the viewer (EHR) to standardizing the server (PACS).”
  • Microsoft warned that simply adding a ‘Diagnostic Imaging Reference’ to USCDI v7 without mandating API access at the PACS level “risks functioning as a ‘bridge to nowhere’—providing metadata that identifies studies without enabling applications to retrieve and use the underlying imaging data.”
  • The HIMSS Electronic Health Record Association (EHRA) emphasized the unfairness of this asymmetry, noting that EHR developers cannot be held accountable for data extraction capabilities that are wholly controlled by third-party imaging vendors. CIOs from CHIME and imaging informaticists from SIIM fiercely echoed this sentiment, demanding a “mini-certification” specifically for PACS.

Semantic Liquidity vs. Referential Viewing: The Clinical Danger of Down-Sampled Data

A sharp divide exists between how tech platforms view “access” and what clinicians actually require for safe patient care. Many current patient portals satisfy interoperability by providing a compressed JPEG or a static PDF. Clinical commenters from tertiary referral centers (Memorial Sloan Kettering, Cleveland Clinic) assert that this practice is not just inadequate, but actively dangerous.

  • Loss of Diagnostic Utility: Southern New England Healthcare (SoNE) highlighted that a JPEG render permanently compresses the bandwidth of an image, stripping the clinician’s ability to “re-window” a scan to detect lung nodules. Mike Sloyan of UCLA Health IT compared providing JPEGs to surgeons to “providing access to notes where every 4th word was redacted.”
  • The Shift to Computable Assays: The Quantitative Medical Imaging Coalition (QMIC) provocatively argues that medical imaging must no longer be viewed as “pictures” but as computable assays akin to lab tests. Stripping DICOM metadata (e.g., PET SUV values, radiation dosages) destroys the metrological integrity required for precision medicine and AI model training.
  • Diagnostic Anchoring: An Anonymous Patient astutely noted that when full diagnostic datasets are withheld, receiving clinicians are forced to rely solely on the prior facility’s narrative report, creating a dangerous cycle of “diagnostic anchoring” where errors are repeated because the underlying evidence is concealed.

Economic Disincentives: Duplicate Imaging as a Revenue Stream and API Rent-Seeking

The docket makes clear that we are not failing to share data because it is technically difficult; we are failing because it is highly profitable to hoard it. Industry estimates cited by MediMint and David Rocha suggest up to $30 billion is wasted annually on redundant imaging.

  • The Fee-for-Service Barrier: Health IT architect Rick Gregory offered a blunt assessment: “accepting prior imaging from outside organizations can negatively impact a health system’s own reimbursement schedules by reducing the need for repeat imaging.” Until CMS aligns financial models to penalize redundant scans, health systems have a rational economic incentive to maintain friction—a dynamic also highlighted by Radiology Partners.
  • Predatory Tollbooths: Vendors are utilizing proprietary formats to force secondary providers and developers to pay integration fees. The Health Innovation Alliance (HIA) explicitly urged the ONC to categorize “charging prohibitive fees for third-party apps to access imaging metadata” as an Information Blocking violation.

Weaponization of HIPAA and the Need for Centralized Authorization

Healthcare facilities frequently cite HIPAA, data breach liability, and internal security policies as reasons to deny electronic transfers (Houston Methodist, Mercy Health Services). Commenters broadly view this as a pretext, pointing out the hypocrisy of facilities that refuse API connections but willingly hand patients entirely unencrypted CDs, which the HealthMark Group notes still account for two-thirds of radiological image sharing.

  • Security as an Excuse: The Oncology Nursing Society noted that facilities routinely “cite internal security policies, patient privacy concerns, or uncertainty about sharing data” to justify maintaining manual workflows. Patient platform mymedicalimages.com forcefully countered: “Do not hide behind HIPAA while using weaker practices in the default workflow.”
  • The Authorization Nightmare: Because legacy PACS systems were not built for the web, they lack the identity management required for secure sharing. If ASTP/ONC forces them to build it independently, patients and providers will be subjected to a fragmented, multi-login nightmare just to view an x-ray.

Strategic Policy Recommendations: The “Delegated Authorization” Architecture

To break the current market stalemate without forcing massive architectural rebuilds, ASTP/ONC must adopt a bifurcated regulatory architecture that decouples identity/authorization from data delivery.

1. Establish “Data Custodian” Certification for PACS/VNAs To prevent the EHR’s metadata from becoming a “bridge to nowhere,” ASTP/ONC must introduce a focused, lightweight “mini-certification” specifically for the imaging systems that actually house the multi-gigabyte files.

  • Consensus: This is a rare point of absolute agreement bridging historic market rivals. EHR developers like Epic, Oracle Health, and the EHRA demand it so they aren’t held liable for PACS functionality. Big Tech network operators like Microsoft demand it. CIOs and informaticists from CHIME and SIIM demand it. And imaging interoperability vendors like Clearpath and Medicom demand it to break the proprietary silos.
  • Action: Require PACS, VNAs, and CVIS to expose standard DICOMweb APIs (WADO-RS, QIDO-RS) for full-fidelity image retrieval.
  • Action: Require these Data Custodians to accept and honor the delegated authorization (SMART token) passed to them by the Base EHR. The imaging system simply serves the pixels; it does not manage the login. This ensures any returned API link is programmatically dereferenceable.

2. Leverage Base EHRs for Identity and Access Policy (Part 170) Forcing imaging systems to recreate the complex, organization-specific identity management and access control rules already built into EHRs is a massive administrative barrier. Instead, ASTP/ONC should require Base EHRs to act as a unified authorization authority.

  • Support: SMART Health IT at Boston Children’s Hospital argued that a unified authorization flow prevents a fractured user experience. Rick Gregory, mymedicalimages.com, and BJC Health heavily supported anchoring imaging in the SMART on FHIR framework to bring it into a governance model that is auditable and patient-participatory.
  • Action: Mandate that certified EHRs support the USCDI Diagnostic Imaging Reference using the FHIR ImagingStudy resource.
  • Action: Require EHRs to issue SMART App Launch v2 tokens (OAuth 2.0) with specific imaging access scopes (e.g., patient/ImagingStudy.rs).

3. Define “Diagnostic Quality” as the Regulatory Baseline To close the loophole where vendors satisfy interoperability rules by serving low-resolution thumbnails, ASTP/ONC must define the technical floor.

  • Action: Promulgate guidance establishing that providing a down-sampled reference image (e.g., JPEG) or a non-downloadable portal link does not satisfy Information Blocking requirements when a requesting specialist or patient requires the full DICOM payload. (Supported by UI Health and QMIC).

4. Attack Physical Media via Information Blocking Enforcement (Part 171) ASTP/ONC must aggressively target the “sneakernet” as a compliance violation rather than a mere technical inconvenience.

  • Action: Issue an immediate regulatory update or FAQ explicitly stating that requiring a patient or provider to rely on physical media (CDs/DVDs/USBs) when an electronic API pathway (like DICOMweb) is technically feasible constitutes an interference practice under the Information Blocking rule. (Supported by Clearpath and Medicom Technologies).

Conclusion: As Radiology Partners summarized, the agency must “view information blocking not as an administrative issue but as a clinical safety barrier.” By decoupling access policy (managed by the EHR) from data delivery (served by certified PACS), ASTP/ONC can eliminate the silos without breaking the existing architecture. The industry has the tools to solve this; they are waiting for the regulatory mandate.