Guide

PI with a small EHR: the required base and the exclusions

Summary

Promoting Interoperability is the MIPS category that grades whether a practice's certified EHR is actually being used to exchange information — a required base of measures covering a security risk analysis, e-prescribing, health information exchange, patient electronic access, and an information-blocking attestation. A small EHR that supports these functions can usually meet the base with routine use rather than special configuration. Clinicians below the low-volume threshold, or facing a genuine hardship, may be excluded from reporting PI at all.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

What Promoting Interoperability actually grades

Promoting Interoperability, or PI, is the MIPS performance category that measures whether a practice is actually using its certified EHR to exchange health information — not whether the practice owns one. A small EHR that supports the required functions can usually meet PI's base through routine daily use, without any special configuration project, because the base measures track things most modern certified systems already do by default: securing the record, sending prescriptions electronically, exchanging information with other providers, and giving patients electronic access to their own records.

PI is scored separately from MIPS Quality, so a strong quality-measure showing doesn't offset a weak PI score, and the two categories are worth tracking independently rather than assuming one covers for the other.

The required base: five things a small EHR has to actually do

The PI category's required base centers on a small set of measures every reporting clinician has to complete, regardless of specialty: a security risk analysis, e-prescribing through the certified system, health information exchange with other providers, patient electronic access to their record, and an attestation that the practice has not engaged in information blocking. Missing any required base measure typically zeroes out the entire PI category score, which makes the base worth checking first, before optimizing anything else.

For a solo, the practical work is less about adding new capability and more about confirming the EHR already in use actually performs each function and that the practice can document having done so — a risk analysis conducted and dated, prescriptions sent electronically rather than by fax as the default, a portal patients can actually log into. A certified EHR that technically has these features but where they've never been turned on or used doesn't satisfy the measure; use is what's being measured, not ownership.

The security risk analysis measure

The security risk analysis required for PI is the same risk analysis HIPAA's Security Rule requires as the foundation for its administrative, physical, and technical safeguards, scaled to the size of the practice 1. A solo doesn't need a separate PI-specific analysis and a separate HIPAA-compliance analysis — one properly conducted and documented risk analysis satisfies both.

ONC and OCR publish a free Security Risk Assessment tool sized specifically for small practices to conduct this analysis without hiring a consultant 2. Complete it annually or whenever something material changes — a new EHR, a new portal vendor, a new remote-access setup — and keep the dated output on file, since the documentation itself, not just the fact of having thought about security, is what a review would ask to see.

Health information exchange and the information-blocking attestation

The health information exchange measure asks whether the practice sends and receives clinical information electronically with other providers, rather than by fax or mailed records — the kind of exchange TEFCA is designed to make more uniform as its network-to-network framework matures nationally 3. A small EHR with basic Direct-messaging or a connected health information exchange typically covers this without additional cost.

Separately, PI requires attesting that the practice has not engaged in information blocking — interfering with a patient's or another provider's access to electronic health information without falling under one of the rule's defined exceptions 4. For most solos this attestation is straightforward: providing patients timely portal access and responding to legitimate records requests without unreasonable delay keeps a practice on the right side of it. The exceptions exist for genuine cases — a security concern, a preventing-harm situation — not for routine inconvenience.

Vendor terms worth checking before relying on the EHR for PI

Before assuming a small EHR handles PI's exchange requirements out of the box, check what the vendor contract actually commits to for data exchange, export, and any health-information-exchange connection — some of this functionality is a paid add-on rather than a baseline feature, and finding that out mid-reporting-period is worse than finding it out during vendor selection 5.

If the exchange connection routes through a separate health information exchange network or a third-party interoperability service, that vendor is very likely a business associate handling PHI on the practice's behalf, which means a business associate agreement needs to be in place before data starts flowing through it, not after 1. A solo adding a new interoperability connection for PI purposes should treat it as a vendor decision with contract and compliance steps, not a simple technical toggle.

Who's excluded from reporting PI at all

Some clinicians don't have to report PI, or MIPS at all, because of how their practice is structured or sized. Falling under the MIPS low-volume threshold based on Medicare patient count or billed charges can exclude a clinician from the entire program, PI included, and a genuine hardship — an EHR outage, a disaster, a solo-specific circumstance beyond the practice's control — can support a hardship exception excusing the category specifically.

These exclusions aren't automatic; each has its own qualifying criteria and, in most cases, its own application or attestation process rather than a status the practice simply assumes it has. Confirm exclusion eligibility before reporting season rather than skipping PI on the assumption of qualifying and finding out afterward that the practice was actually required to report.

Where PI fits among the other MIPS categories

PI is one of several MIPS performance categories a clinician navigates alongside Quality, and the choices interact: a specialty-shaped MIPS Value Pathway groups a narrower set of measures around a clinical theme, a qualified registry or QCDR changes how quality data gets reported, and opting in when below the low-volume threshold changes both requirements and payment risk across every category at once, not just PI.

The practical order of operations is to confirm the required PI base is genuinely satisfied first, since a zeroed PI score drags down the overall MIPS composite regardless of how well Quality performs, and only then optimize the rest of the reporting strategy — which measures to report, which pathway to use, whether a registry makes the data easier to pull — around a PI foundation that's already secure.

Common questions

Usually not, if it's a certified system already in routine use. PI's base measures — security risk analysis, e-prescribing, health information exchange, patient access, information-blocking attestation — track functions most certified EHRs support by default. The work is confirming these functions are actually turned on and used, and documented as such, rather than adding new capability.

No. PI's required security risk analysis is the same risk analysis the HIPAA Security Rule requires as the basis for its safeguards. One properly conducted and dated analysis, covering the practice at its current scale, satisfies both the PI measure and the underlying HIPAA obligation — there's no need to run two separate assessments.

Missing a required base measure typically zeroes out the entire Promoting Interoperability category score, which then drags down the overall MIPS composite score regardless of strong performance elsewhere. Check the base measures first, before optimizing any other part of PI or Quality reporting, since a base failure undoes the value of everything else.

Clinicians falling under the MIPS low-volume threshold based on Medicare patient count or billed charges can be excluded from the entire program, PI included, and a documented hardship can support an exception for the category specifically. Neither exclusion is automatic — confirm eligibility and complete any required attestation before reporting season rather than assuming it applies.

Interfering with a patient's or another provider's access to electronic health information without a defined exception applying — most commonly, unreasonably delaying portal access or a legitimate records request. For most solos, providing timely patient portal access and responding to records requests without unnecessary delay is enough to satisfy the attestation honestly.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's risk-analysis foundation is the same analysis PI's security risk analysis measure requires, and that a vendor handling PHI is a business associate requiring a BAA.
  2. 2.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThat a free, small-practice-sized tool exists to conduct the risk analysis PI's security risk analysis measure requires.
  3. 3.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. linkThat TEFCA establishes a national framework for network-to-network health information exchange, the landscape the PI exchange measure sits inside.
  4. 4.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. linkThat the information-blocking rule prohibits interfering with access to electronic health information subject to eight defined exceptions, the standard PI's attestation measure covers.
  5. 5.Office of the National Coordinator (2016). EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print. HealthIT.gov (ONC). linkThat EHR contracts should be checked for whether exchange and export functionality is baseline or a paid add-on before relying on it for PI reporting.

https://www.gale.care/for-providers/cdq-promoting-interoperability · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)