PI with a small EHR: the required base and the exclusions
Summary
Promoting Interoperability is the MIPS category that grades whether a practice's certified EHR is actually being used to exchange information — a required base of measures covering a security risk analysis, e-prescribing, health information exchange, patient electronic access, and an information-blocking attestation. A small EHR that supports these functions can usually meet the base with routine use rather than special configuration. Clinicians below the low-volume threshold, or facing a genuine hardship, may be excluded from reporting PI at all.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
What Promoting Interoperability actually grades
Promoting Interoperability, or PI, is the MIPS performance category that measures whether a practice is actually using its certified EHR to exchange health information — not whether the practice owns one. A small EHR that supports the required functions can usually meet PI's base through routine daily use, without any special configuration project, because the base measures track things most modern certified systems already do by default: securing the record, sending prescriptions electronically, exchanging information with other providers, and giving patients electronic access to their own records.
PI is scored separately from MIPS Quality, so a strong quality-measure showing doesn't offset a weak PI score, and the two categories are worth tracking independently rather than assuming one covers for the other.
The required base: five things a small EHR has to actually do
The PI category's required base centers on a small set of measures every reporting clinician has to complete, regardless of specialty: a security risk analysis, e-prescribing through the certified system, health information exchange with other providers, patient electronic access to their record, and an attestation that the practice has not engaged in information blocking. Missing any required base measure typically zeroes out the entire PI category score, which makes the base worth checking first, before optimizing anything else.
For a solo, the practical work is less about adding new capability and more about confirming the EHR already in use actually performs each function and that the practice can document having done so — a risk analysis conducted and dated, prescriptions sent electronically rather than by fax as the default, a portal patients can actually log into. A certified EHR that technically has these features but where they've never been turned on or used doesn't satisfy the measure; use is what's being measured, not ownership.
The security risk analysis measure
The security risk analysis required for PI is the same risk analysis HIPAA's Security Rule requires as the foundation for its administrative, physical, and technical safeguards, scaled to the size of the practice 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule's risk-analysis foundation is the same analysis PI's security risk analysis measure requires, and that a vendor handling PHI is a business associate requiring a BAA.. A solo doesn't need a separate PI-specific analysis and a separate HIPAA-compliance analysis — one properly conducted and documented risk analysis satisfies both.
ONC and OCR publish a free Security Risk Assessment tool sized specifically for small practices to conduct this analysis without hiring a consultant 2Ref 2Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.That a free, small-practice-sized tool exists to conduct the risk analysis PI's security risk analysis measure requires.. Complete it annually or whenever something material changes — a new EHR, a new portal vendor, a new remote-access setup — and keep the dated output on file, since the documentation itself, not just the fact of having thought about security, is what a review would ask to see.
Health information exchange and the information-blocking attestation
The health information exchange measure asks whether the practice sends and receives clinical information electronically with other providers, rather than by fax or mailed records — the kind of exchange TEFCA is designed to make more uniform as its network-to-network framework matures nationally 3Ref 3Office of the National Coordinator / ASTP (2026).TEFCA — Office of the National Coordinator for Health Information Technology.That TEFCA establishes a national framework for network-to-network health information exchange, the landscape the PI exchange measure sits inside.. A small EHR with basic Direct-messaging or a connected health information exchange typically covers this without additional cost.
Separately, PI requires attesting that the practice has not engaged in information blocking — interfering with a patient's or another provider's access to electronic health information without falling under one of the rule's defined exceptions 4Ref 4Office of the National Coordinator / ASTP (2026).Information Blocking.That the information-blocking rule prohibits interfering with access to electronic health information subject to eight defined exceptions, the standard PI's attestation measure covers.. For most solos this attestation is straightforward: providing patients timely portal access and responding to legitimate records requests without unreasonable delay keeps a practice on the right side of it. The exceptions exist for genuine cases — a security concern, a preventing-harm situation — not for routine inconvenience.
Vendor terms worth checking before relying on the EHR for PI
Before assuming a small EHR handles PI's exchange requirements out of the box, check what the vendor contract actually commits to for data exchange, export, and any health-information-exchange connection — some of this functionality is a paid add-on rather than a baseline feature, and finding that out mid-reporting-period is worse than finding it out during vendor selection 5Ref 5Office of the National Coordinator (2016).EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print.That EHR contracts should be checked for whether exchange and export functionality is baseline or a paid add-on before relying on it for PI reporting..
If the exchange connection routes through a separate health information exchange network or a third-party interoperability service, that vendor is very likely a business associate handling PHI on the practice's behalf, which means a business associate agreement needs to be in place before data starts flowing through it, not after 1Ref 1HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule's risk-analysis foundation is the same analysis PI's security risk analysis measure requires, and that a vendor handling PHI is a business associate requiring a BAA.. A solo adding a new interoperability connection for PI purposes should treat it as a vendor decision with contract and compliance steps, not a simple technical toggle.
Who's excluded from reporting PI at all
Some clinicians don't have to report PI, or MIPS at all, because of how their practice is structured or sized. Falling under the MIPS low-volume threshold based on Medicare patient count or billed charges can exclude a clinician from the entire program, PI included, and a genuine hardship — an EHR outage, a disaster, a solo-specific circumstance beyond the practice's control — can support a hardship exception excusing the category specifically.
These exclusions aren't automatic; each has its own qualifying criteria and, in most cases, its own application or attestation process rather than a status the practice simply assumes it has. Confirm exclusion eligibility before reporting season rather than skipping PI on the assumption of qualifying and finding out afterward that the practice was actually required to report.
Where PI fits among the other MIPS categories
PI is one of several MIPS performance categories a clinician navigates alongside Quality, and the choices interact: a specialty-shaped MIPS Value Pathway groups a narrower set of measures around a clinical theme, a qualified registry or QCDR changes how quality data gets reported, and opting in when below the low-volume threshold changes both requirements and payment risk across every category at once, not just PI.
The practical order of operations is to confirm the required PI base is genuinely satisfied first, since a zeroed PI score drags down the overall MIPS composite regardless of how well Quality performs, and only then optimize the rest of the reporting strategy — which measures to report, which pathway to use, whether a registry makes the data easier to pull — around a PI foundation that's already secure.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's risk-analysis foundation is the same analysis PI's security risk analysis measure requires, and that a vendor handling PHI is a business associate requiring a BAA.
- 2.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓That a free, small-practice-sized tool exists to conduct the risk analysis PI's security risk analysis measure requires.
- 3.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. link ✓That TEFCA establishes a national framework for network-to-network health information exchange, the landscape the PI exchange measure sits inside.
- 4.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. link ✓That the information-blocking rule prohibits interfering with access to electronic health information subject to eight defined exceptions, the standard PI's attestation measure covers.
- 5.Office of the National Coordinator (2016). EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print. HealthIT.gov (ONC). link ✓That EHR contracts should be checked for whether exchange and export functionality is baseline or a paid add-on before relying on it for PI reporting.
https://www.gale.care/for-providers/cdq-promoting-interoperability · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.