Is the Epic Care Everywhere Network HIPAA Compliant? A Practical Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is the Epic Care Everywhere Network HIPAA Compliant? A Practical Checklist

Kevin Henry

HIPAA

August 16, 2026

7 minutes read
Share this article
Is the Epic Care Everywhere Network HIPAA Compliant? A Practical Checklist

Overview of Epic Care Everywhere

Epic Care Everywhere enables participating healthcare organizations to discover, request, and retrieve clinical records for a specific patient across care sites. The exchange is designed for treatment, care coordination, and transitions of care, supporting near real-time access to summaries, labs, imaging reports, medications, allergies, and problem lists.

Whether the network is “HIPAA compliant” depends on how your organization configures, governs, and uses it. Care Everywhere provides technical and workflow capabilities that support Health Information Exchange (HIE) Compliance, while covered entities and business associates remain responsible for policies, training, and enforcement.

Practical checklist

  • Define your Care Everywhere use cases and map them to HIPAA-permitted purposes (primarily treatment).
  • Document roles and responsibilities for HIPAA compliance across legal, privacy, security, and clinical operations.
  • Verify participation agreements and business associate arrangements align with your disclosure practices.
  • Establish identity management and patient matching procedures to avoid misidentification.
  • Publish user guidelines describing when and how Protected Health Information (PHI) may be accessed via the network.

HIPAA Regulatory Requirements

HIPAA’s Privacy Rule governs permitted uses and disclosures of PHI, including disclosures for treatment, payment, and healthcare operations. The Security Rule requires administrative, physical, and technical safeguards to protect electronic PHI, such as risk analysis, access management, and audit controls. Breach Notification obligations apply when unsecured PHI is compromised.

The “minimum necessary” standard does not apply to disclosures for treatment, but it does apply to many other uses and to workforce access. Your governance should reflect this distinction and ensure users retrieve and use only what is appropriate for their role.

Practical checklist

  • Identify the legal basis for each exchange (e.g., treatment vs. Patient Authorization Requirements).
  • Complete and maintain a HIPAA risk analysis for all Care Everywhere workflows and endpoints.
  • Execute and periodically review BAAs and participation terms with connected parties, as applicable.
  • Implement workforce training on permitted uses, minimum necessary, and sanctions for misuse.
  • Enable audit controls to record queries, disclosures, and user actions for security review and, when applicable, accounting of disclosures.

Under HIPAA, disclosures for treatment typically do not require patient authorization. However, state laws, organizational policy, and certain federal rules may require consent or explicit authorization before sharing specific data. Care Everywhere workflows can capture consent status and display restrictions at the point of access.

Examples include 42 CFR Part 2 programs, psychotherapy notes, and state-specific protections (e.g., adolescent confidentiality, HIV/STI, reproductive health). Emergency access (“break-the-glass”) may be allowed with justification and enhanced auditing when immediate treatment is necessary.

Practical checklist

  • Adopt a clear consent model (opt-in, opt-out, or hybrid) and record it in the patient chart.
  • Implement Patient Authorization Requirements for restricted data (e.g., Part 2, psychotherapy notes) and enforce them at query time.
  • Display consent indicators and Sensitive Data Restrictions to end users before retrieval.
  • Enable emergency access with reason capture and automatic audit flags.
  • Provide patient education materials explaining network sharing and how to change consent preferences.

Data Security and Transmission Protocols

Care Everywhere exchanges typically use strong encryption in transit (e.g., TLS with certificate-based trust) and endpoint authentication to protect PHI. When organizations use Direct Project Protocols for push exchange, messages employ S/MIME for encryption and signing, with trust bundles governing who can send and receive securely.

Within your environment, enforce Data Access Controls such as role-based access, least privilege, unique user IDs, session timeouts, and multi-factor authentication for remote or high-risk access. Maintain audit logging across all exchange events and integrate alerts for anomalous activity.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Practical checklist

  • Validate mutual TLS and certificate management for all exchange endpoints.
  • For Direct Project Protocols, manage addresses and trust bundles; test encryption and digital signatures.
  • Encrypt PHI at rest on servers and mobile devices; secure backups and disaster recovery replicas.
  • Enforce least-privilege roles, MFA where appropriate, and automatic logoff.
  • Retain immutable audit logs for an approved period and review them routinely.

Data Sharing Limitations and Exceptions

Not all data should or can be shared. Sensitive Data Restrictions may be required for psychotherapy notes, substance use disorder treatment records from Part 2 programs, and state-protected categories such as adolescent information or certain sexual and reproductive health services. Your policies must specify when authorization is needed and how restrictions are presented to users.

Beyond legal limits, organizations may apply clinical governance—such as suppressing draft or unverified documents, restricting staff notes not intended for external disclosure, or avoiding transmission of overly large attachments that do not add treatment value.

Practical checklist

  • Define which document types, sections, or codes are excluded by default and under what conditions they may be released.
  • Segment restricted data so it is visible only when required criteria (e.g., patient authorization) are met.
  • Display clear indicators when data is blocked and provide a process to request access with proper justification.
  • Periodically review exceptions to ensure they align with current laws and organizational policy.

Interoperability Standards and Network Scope

Care Everywhere leverages widely used standards to exchange information. These include HL7 C-CDA documents for clinical summaries, FHIR APIs for discrete data where available, and Interoperability Standards XCA XDS.b for cross-community query and document retrieval. Many organizations also use Direct Project Protocols for secure, push-style transitions of care.

The network’s effective scope depends on your trading partners, regional and national connections, and your matching and trust configurations. Understand which external systems you can reach, what content they publish, and how results are reconciled into the chart to maintain HIE Compliance and data quality.

Practical checklist

  • Inventory your exchange pathways (Care Everywhere, HIEs, national frameworks) and their standards support.
  • Test XCA/XDS.b queries, C-CDA content quality, and FHIR endpoints for accuracy and completeness.
  • Define reconciliation rules to prevent duplicate problems, meds, and allergies.
  • Measure match rates and implement workflows to resolve potential patient identity mismatches.
  • Monitor uptime, error logs, and message queues to catch connectivity or content issues early.

Compliance Monitoring and Audit Practices

Continuous monitoring validates that access to PHI remains appropriate and documented. Use automated audits to track who queried, what was retrieved, and why. Correlate exchange logs with user role, location, and encounter context to spot anomalies or inappropriate lookups.

Establish a compliance lifecycle: policy management, workforce training, routine risk assessments, vendor oversight, and sanctions for violations. Simulate incidents to test your breach response plan and ensure you can investigate, contain, notify, and improve controls.

Practical checklist

  • Review access and disclosure logs on a scheduled cadence with documented follow-up actions.
  • Run targeted audits for VIP patients, employee records, and unusually high query volumes.
  • Align retention schedules for logs and disclosures with legal and regulatory requirements.
  • Track corrective actions, user re-training, and system changes after each audit finding.
  • Reassess risks and controls whenever workflows, regulations, or endpoints change.

Bottom line: Epic Care Everywhere can support HIPAA-aligned exchange when you pair the technology with robust consent management, Sensitive Data Restrictions, strong Data Access Controls, secure transport, and disciplined auditing. Compliance ultimately rests with your organization’s governance and execution.

FAQs.

For HIPAA, disclosures for treatment generally do not require patient authorization. However, your state may require HIE consent, and certain categories—such as 42 CFR Part 2 records or psychotherapy notes—often require explicit, documented authorization. Configure consent capture, display status to users, and block restricted data unless the proper authorization is present.

How does Epic ensure PHI security during exchanges?

Care Everywhere exchanges use encrypted transport (e.g., TLS with certificates) and endpoint authentication; Direct Project Protocols use S/MIME for message-level security. Within your environment, enforce Data Access Controls, logging, and monitoring to protect Protected Health Information (PHI) before, during, and after transmission.

What types of data are excluded from Care Everywhere sharing?

Exclusions depend on law and policy. Commonly restricted items include psychotherapy notes, substance use disorder treatment information from Part 2 programs without valid consent, and state-protected categories (e.g., certain adolescent or HIV/STI data). Organizations may also suppress drafts or internal notes not intended for external disclosure.

Does Care Everywhere comply fully with HIPAA privacy rules?

The platform provides capabilities that support HIPAA compliance, but compliance is achieved by how your organization configures, governs, and uses it. With appropriate policies, consent workflows, Sensitive Data Restrictions, secure transport, and rigorous auditing, Care Everywhere can be operated in a HIPAA-aligned manner.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles