District of Columbia APCD Submission and Privacy Requirements for Independent FQHCs
Overview of District of Columbia APCD Status
Where the District stands today
As of August 27, 2026, the District of Columbia does not operate a state all-payer claims database (APCD). The District has explored an APCD and, more recently, engaged stakeholders on a potential District-wide approach, but no law or rule currently requires payer or provider submission to a DC-run APCD.
What this means for independent FQHCs
Independent FQHCs in DC do not have direct APCD submission obligations at this time. Your required data flows remain those in existing contracts and statutes—claims and encounter reporting to DC Medicaid and managed care plans, quality reporting tied to HRSA, and any reporting explicitly required by payers or grantors.
Practical readiness steps
- Standardize core identifiers (NPI, TIN, taxonomy, plan IDs) and maintain clean eligibility, claims, and provider files; this simplifies any future payer-driven APCD submissions.
- Align file layouts with widely used claim formats and common data elements to reduce transformation work if DC establishes an APCD later.
- Designate a data steward, document data lineage, and retain data dictionaries and edit logs to demonstrate data quality if new submission requirements emerge.
HIPAA Compliance for Independent FQHCs
Covered entity responsibilities and PHI
Independent FQHCs are HIPAA covered entities. You must protect Protected Health Information (PHI) under the Privacy, Security, and Breach Notification Rules, apply the minimum necessary standard for uses and disclosures, issue and maintain an up-to-date Notice of Privacy Practices, and ensure appropriate role-based access to PHI.
Business Associate Agreements
Execute and manage Business Associate Agreements with every vendor or partner that creates, receives, maintains, or transmits PHI for your clinic (for example, EHR hosting, billing, cloud storage, analytics, call centers). BAAs must bind subcontractors, set permitted uses, require safeguard implementation, address breach reporting, and outline return or destruction of PHI at contract termination.
Mental health and SUD overlays
If your FQHC provides behavioral health or substance use disorder services, apply the strictest rule among HIPAA, 42 CFR Part 2, and District of Columbia mental health confidentiality law. Use granular consent, data segmentation, and “need-to-know” controls to avoid improper redisclosure.
Health benefits plan confidentiality
When exchanging information with health benefits plans and District programs, maintain confidentiality and follow any required Business Associate Agreements or data use terms specified by District law and contracts. Verify that disclosures are either authorized by the patient, required by law, or permitted for treatment, payment, or health care operations.
Consumer Health Information Privacy Protection Act (CHIPPA)
Purpose and scope
The Consumer Health Information Privacy Protection Act (CHIPPA) was introduced to cover non-HIPAA consumer health data—such as information collected by apps, wearables, and nontraditional health services—by requiring clear privacy notices, consent-based collection and sharing, limits on sale of consumer health data, and restrictions on geofencing around health care locations.
Current status and implications
CHIPPA was introduced on July 12, 2024, but did not become law before the end of the prior Council period. In the 2025–2026 Council period, separate proposals have continued the policy discussion around Consumer Health Data Privacy. Until a new law is enacted, FQHCs should treat non-HIPAA health data with heightened caution and align practices with the strongest available standards.
Recommended actions now
- Inventory any non-HIPAA health data you handle (for example, website trackers, patient-facing apps, community outreach tools) and apply CHIPPA-like controls: data minimization, explicit consent, and clear consumer-facing disclosures.
- Disable unnecessary tracking technologies on patient-facing pages and implement consent banners where appropriate.
- Adopt internal review for any third-party SDKs or pixels that could transmit health-related signals.
Data Sharing Regulations and Use of Health Information
District data-sharing framework
DC’s Data-Sharing and Information Coordination framework permits District agencies and contracted service providers to use and, in certain cases, disclose health and human services information for defined purposes without prior consent, as long as another law does not prohibit it. You must still follow HIPAA, 42 CFR Part 2, and District confidentiality laws.
Participating in the DC Health Information Exchange
CRISP DC serves as the District’s designated Health Information Exchange. You may exchange PHI for treatment, payment, and operations consistent with HIPAA and DC HIE policies. For Part 2 data, use CRISP DC’s eConsent tools or other approved mechanisms to obtain and honor patient consent before disclosure.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Health Information Disclosure Regulations in practice
- Verify every disclosure’s legal basis: patient authorization, TPO, or “required by law.”
- Document disclosures where required and apply the minimum necessary standard when it applies.
- Train staff on heightened protections for behavioral health and SUD data and on DC-specific confidentiality rules.
Security Safeguards and Confidentiality Requirements
Security Rule baseline controls
Conduct and document an enterprise-wide risk analysis, implement administrative, physical, and technical safeguards, and maintain risk management plans. Prioritize multifactor authentication, encryption at rest and in transit, timely patching, access logging, endpoint protection, and secure backups with recovery testing.
Data Security Safeguards tailored to FQHCs
- Segment SUD and mental health records where feasible; apply “break-the-glass” workflows and auditing for sensitive access.
- Formalize vendor risk management: security due diligence, least-privilege access, BAA terms, and data return/destruction on exit.
- Run privacy and security drills (incident response tabletop exercises) and maintain a breach notification playbook.
Confidentiality overlays under DC law
DC mental health confidentiality requirements and federal Part 2 rules impose additional obligations beyond HIPAA. Ensure disclosures carry required statements, maintain disclosure logs when applicable, and promptly notify the appropriate authority if a prohibited disclosure occurs.
Credentials and Auditing Standards for Independent FQHCs
Credentialing and privileging
HRSA requires credentialing and privileging of all clinical staff in alignment with the Health Center Program Compliance Manual and Site Visit Protocol. Perform primary source verification, National Practitioner Data Bank queries, and recredentialing and reprivileging on required cycles. Include clinical supervisors and trainers even if they do not provide direct patient care, as policy requires.
Audit readiness
- Maintain complete, current credentialing and privileging files with checklists, verification dates, and decision memos.
- Perform periodic internal audits to confirm timely recredentialing, complete primary source verification, and active licenses and certifications.
- Map HRSA Operational Site Visit evidence to your policies and files; close gaps with corrective action plans and monitor completion.
Uniform Credentialing and Recredentialing Procedures
District requirements and Credentialing Intermediaries Compliance
Under District law, health insurers and credentialing intermediaries must accept the uniform credentialing form—the CAQH Provider Application—as the sole application for provider credentialing and recredentialing. Plans and intermediaries are expected to process through CAQH rather than requiring duplicative forms.
How independent FQHCs can streamline paneling
- Keep CAQH profiles complete, verified, and reattested on schedule; ensure malpractice, DEA, CDS, board status, hospital privileges, and work history are current.
- Use a master roster to track payer effective dates and recredentialing cycles; reconcile against payer rosters and 835 remittances.
- Escalate if a plan or intermediary requests noncompliant paperwork; reference the District’s uniform credentialing requirements in your response.
Conclusion
Today, DC has no APCD submission mandate for independent FQHCs. Your core obligations center on HIPAA-compliant PHI handling, honoring DC confidentiality overlays and Part 2, participating responsibly in the DC HIE, and maintaining rigorous credentialing, privileging, and audit readiness. Monitor the Council’s consumer health data proposals and any APCD developments, and align your privacy program and data quality practices now so you can adapt quickly if new rules take effect.
FAQs.
What are the APCD data submission requirements for independent FQHCs in DC?
None at this time. The District does not operate a state APCD, so FQHCs have no direct APCD submission duty. Continue all required reporting to DC Medicaid, managed care plans, HRSA, and grantors, and monitor for any future DC APCD legislation or rulemaking that could shift payer reporting expectations.
How does HIPAA apply to independent FQHCs in DC?
FQHCs are HIPAA covered entities and must protect PHI under the Privacy, Security, and Breach Notification Rules, apply minimum necessary for applicable uses and disclosures, maintain BAAs with vendors handling PHI (including subcontractors), and layer on stricter protections for mental health and substance use disorder data under DC law and 42 CFR Part 2.
What protections does CHIPPA provide for non-HIPAA health data?
As introduced, CHIPPA would regulate consumer health data outside HIPAA by requiring clear privacy notices, consent-based collection and sharing, limits on data sale, and geofencing restrictions near health care locations. CHIPPA did not become law before the prior Council period ended, so treat its provisions as best practices until new DC legislation is enacted.
What are the rules for sharing health and human services information in DC?
District law allows agencies and contracted providers to use and, in certain cases, disclose health and human services information for defined operational purposes without prior consent, provided no other law prohibits the disclosure. You must still comply with HIPAA, 42 CFR Part 2, and DC confidentiality statutes, apply minimum necessary when it applies, and document or obtain consent where required.
Table of Contents
- Overview of District of Columbia APCD Status
- HIPAA Compliance for Independent FQHCs
- Consumer Health Information Privacy Protection Act (CHIPPA)
- Data Sharing Regulations and Use of Health Information
- Security Safeguards and Confidentiality Requirements
- Credentials and Auditing Standards for Independent FQHCs
- Uniform Credentialing and Recredentialing Procedures
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.