Initial Analysis of Diagnostic Imaging RFI Response: Market Failures and Regulatory Blind Spots
View on LinkedIn
For the full analysis of 97 submissions to regulations dot gov, see my Regulatory Comment Browser.
Guest post by Gemini Pro.
Executive Summary
Our initial analysis of the 97 public comments submitted in response to RFI HHS-ONC-2026-0067 indicates that the U.S. diagnostic imaging ecosystem is suffering from a profound regulatory misalignment. The consensus across stakeholdersâranging from patient advocates like Grace Cordovano and Ryan Bennet, to specialty medical societies (e.g., the American College of Cardiology, Society of Thoracic Surgeons, and SNMMI), and interoperability vendors (such as Clearpath, Medicom Technologies, and Altera Digital Health)âis that the technical standards required to eliminate physical media are entirely mature.
The persistence of the âsneakernetâ is instead a direct result of perverse financial incentives and a federal certification framework that regulates the wrong software. The submissions suggest that ASTP/ONC must urgently pivot its regulatory focus. By exclusively certifying Electronic Health Records (EHRs) while leaving Picture Archiving and Communication Systems (PACS) and Vendor Neutral Archives (VNAs) unregulated, current policy effectively shields the primary custodians of imaging data from Information Blocking enforcement.
Regulatory Blind Spot: EHR Certification Fails to Capture Imaging Custodians
The most incisive feedback from the docket argues that ONCâs historical focus on EHRs has created a structural failure in imaging interoperability. Because EHRs generally store only textual metadata or web linksânot the multi-gigabyte DICOM files themselvesâcertifying the EHR accomplishes very little if the underlying PACS remains a proprietary, closed system (Epic, Oracle Health).
- As AI policy expert Rohan Sharma pointed out, the agency must âpivot from regulating the viewer (EHR) to standardizing the server (PACS).â
- Microsoft warned that simply adding a âDiagnostic Imaging Referenceâ to USCDI v7 without mandating API access at the PACS level ârisks functioning as a âbridge to nowhereââproviding metadata that identifies studies without enabling applications to retrieve and use the underlying imaging data.â
- The HIMSS Electronic Health Record Association (EHRA) emphasized the unfairness of this asymmetry, noting that EHR developers cannot be held accountable for data extraction capabilities that are wholly controlled by third-party imaging vendors. CIOs from CHIME and imaging informaticists from SIIM fiercely echoed this sentiment, demanding a âmini-certificationâ specifically for PACS.
Semantic Liquidity vs. Referential Viewing: The Clinical Danger of Down-Sampled Data
A sharp divide exists between how tech platforms view âaccessâ and what clinicians actually require for safe patient care. Many current patient portals satisfy interoperability by providing a compressed JPEG or a static PDF. Clinical commenters from tertiary referral centers (Memorial Sloan Kettering, Cleveland Clinic) assert that this practice is not just inadequate, but actively dangerous.
- Loss of Diagnostic Utility: Southern New England Healthcare (SoNE) highlighted that a JPEG render permanently compresses the bandwidth of an image, stripping the clinicianâs ability to âre-windowâ a scan to detect lung nodules. Mike Sloyan of UCLA Health IT compared providing JPEGs to surgeons to âproviding access to notes where every 4th word was redacted.â
- The Shift to Computable Assays: The Quantitative Medical Imaging Coalition (QMIC) provocatively argues that medical imaging must no longer be viewed as âpicturesâ but as computable assays akin to lab tests. Stripping DICOM metadata (e.g., PET SUV values, radiation dosages) destroys the metrological integrity required for precision medicine and AI model training.
- Diagnostic Anchoring: An Anonymous Patient astutely noted that when full diagnostic datasets are withheld, receiving clinicians are forced to rely solely on the prior facilityâs narrative report, creating a dangerous cycle of âdiagnostic anchoringâ where errors are repeated because the underlying evidence is concealed.
Economic Disincentives: Duplicate Imaging as a Revenue Stream and API Rent-Seeking
The docket makes clear that we are not failing to share data because it is technically difficult; we are failing because it is highly profitable to hoard it. Industry estimates cited by MediMint and David Rocha suggest up to $30 billion is wasted annually on redundant imaging.
- The Fee-for-Service Barrier: Health IT architect Rick Gregory offered a blunt assessment: âaccepting prior imaging from outside organizations can negatively impact a health systemâs own reimbursement schedules by reducing the need for repeat imaging.â Until CMS aligns financial models to penalize redundant scans, health systems have a rational economic incentive to maintain frictionâa dynamic also highlighted by Radiology Partners.
- Predatory Tollbooths: Vendors are utilizing proprietary formats to force secondary providers and developers to pay integration fees. The Health Innovation Alliance (HIA) explicitly urged the ONC to categorize âcharging prohibitive fees for third-party apps to access imaging metadataâ as an Information Blocking violation.
Weaponization of HIPAA and the Need for Centralized Authorization
Healthcare facilities frequently cite HIPAA, data breach liability, and internal security policies as reasons to deny electronic transfers (Houston Methodist, Mercy Health Services). Commenters broadly view this as a pretext, pointing out the hypocrisy of facilities that refuse API connections but willingly hand patients entirely unencrypted CDs, which the HealthMark Group notes still account for two-thirds of radiological image sharing.
- Security as an Excuse: The Oncology Nursing Society noted that facilities routinely âcite internal security policies, patient privacy concerns, or uncertainty about sharing dataâ to justify maintaining manual workflows. Patient platform mymedicalimages.com forcefully countered: âDo not hide behind HIPAA while using weaker practices in the default workflow.â
- The Authorization Nightmare: Because legacy PACS systems were not built for the web, they lack the identity management required for secure sharing. If ASTP/ONC forces them to build it independently, patients and providers will be subjected to a fragmented, multi-login nightmare just to view an x-ray.
Strategic Policy Recommendations: The âDelegated Authorizationâ Architecture
To break the current market stalemate without forcing massive architectural rebuilds, ASTP/ONC must adopt a bifurcated regulatory architecture that decouples identity/authorization from data delivery.
1. Establish âData Custodianâ Certification for PACS/VNAs To prevent the EHRâs metadata from becoming a âbridge to nowhere,â ASTP/ONC must introduce a focused, lightweight âmini-certificationâ specifically for the imaging systems that actually house the multi-gigabyte files.
- Consensus: This is a rare point of absolute agreement bridging historic market rivals. EHR developers like Epic, Oracle Health, and the EHRA demand it so they arenât held liable for PACS functionality. Big Tech network operators like Microsoft demand it. CIOs and informaticists from CHIME and SIIM demand it. And imaging interoperability vendors like Clearpath and Medicom demand it to break the proprietary silos.
- Action: Require PACS, VNAs, and CVIS to expose standard DICOMweb APIs (WADO-RS, QIDO-RS) for full-fidelity image retrieval.
- Action: Require these Data Custodians to accept and honor the delegated authorization (SMART token) passed to them by the Base EHR. The imaging system simply serves the pixels; it does not manage the login. This ensures any returned API link is programmatically dereferenceable.
2. Leverage Base EHRs for Identity and Access Policy (Part 170) Forcing imaging systems to recreate the complex, organization-specific identity management and access control rules already built into EHRs is a massive administrative barrier. Instead, ASTP/ONC should require Base EHRs to act as a unified authorization authority.
- Support: SMART Health IT at Boston Childrenâs Hospital argued that a unified authorization flow prevents a fractured user experience. Rick Gregory, mymedicalimages.com, and BJC Health heavily supported anchoring imaging in the SMART on FHIR framework to bring it into a governance model that is auditable and patient-participatory.
- Action: Mandate that certified EHRs support the USCDI Diagnostic Imaging Reference using the FHIR ImagingStudy resource.
- Action: Require EHRs to issue SMART App Launch v2 tokens (OAuth 2.0) with specific imaging access scopes (e.g., patient/ImagingStudy.rs).
3. Define âDiagnostic Qualityâ as the Regulatory Baseline To close the loophole where vendors satisfy interoperability rules by serving low-resolution thumbnails, ASTP/ONC must define the technical floor.
- Action: Promulgate guidance establishing that providing a down-sampled reference image (e.g., JPEG) or a non-downloadable portal link does not satisfy Information Blocking requirements when a requesting specialist or patient requires the full DICOM payload. (Supported by UI Health and QMIC).
4. Attack Physical Media via Information Blocking Enforcement (Part 171) ASTP/ONC must aggressively target the âsneakernetâ as a compliance violation rather than a mere technical inconvenience.
- Action: Issue an immediate regulatory update or FAQ explicitly stating that requiring a patient or provider to rely on physical media (CDs/DVDs/USBs) when an electronic API pathway (like DICOMweb) is technically feasible constitutes an interference practice under the Information Blocking rule. (Supported by Clearpath and Medicom Technologies).
Conclusion: As Radiology Partners summarized, the agency must âview information blocking not as an administrative issue but as a clinical safety barrier.â By decoupling access policy (managed by the EHR) from data delivery (served by certified PACS), ASTP/ONC can eliminate the silos without breaking the existing architecture. The industry has the tools to solve this; they are waiting for the regulatory mandate.