WSR 26-08-005
PROPOSED RULES
HEALTH CARE AUTHORITY
[Filed March 18, 2026, 4:03 p.m.]
Original Notice.
Preproposal statement of inquiry was filed as WSR 26-03-046.
Title of Rule and Other Identifying Information: WAC 182-70-010, Purpose, 182-70-030 Additional definitions authorized by chapter 43.371 RCW, 182-70-230 Review of data requests, 182-70-450 Data vendor and lead organization compliance with privacy and security requirements, 182-70-500 Additional definitions related to the format for the calculation and display of data, 182-70-520 Elements to safeguard the use of data, 182-70-600 Cause for penalties, 182-70-625 Monetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses, 182-70-630 Nonmonetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses, 182-70-705 When an audit may be commenced, and 182-70-510 Data formatting rules apply to proprietary financial information.
Hearing Location(s): On May 5, 2026, at 10:00 a.m. The health care authority (HCA) holds public hearings virtually without a physical meeting place. Virtual public hearings are held via Microsoft Teams webinar. To attend, you must register in advance at https://events.gcc.teams.microsoft.com/event/a7e1db2f-8653-4873-abe2-190fbeb7269b@11d0e217-264e-400a-8ba0-57dcc127d72d. After registering, you will receive a confirmation email containing information about joining the public hearing. You will be able to join the public hearing through most standard internet browsers; you do not need to install Microsoft Teams.
Date of Intended Adoption: Not sooner than May 6, 2026.
Submit Written Comments to: HCA Rules Coordinator, P.O. Box 42716, Olympia, WA 98504-2716, email arc@hca.wa.gov, fax 360-586-9727, beginning March 19, 2026, 8:00 a.m., by May 5, 2026, 11:59 p.m.
Assistance for Persons with Disabilities: Contact Jessica Nguyen, phone 360-725-1174, fax 360-586-9727, TTY telecommunication relay service 711, email arc@hca.wa.gov, by April 17, 2026.
Purpose of the Proposal and Its Anticipated Effects, Including Any Changes in Existing Rules: HCA is amending chapter 182-70 WAC to remove use of the term "proprietary financial information" and to add the provision that HCA may act as the lead organization to coordinate and manage the all payer health care claims database. These amendments are intended to comply with changes to the enabling legislation (chapter 43.371 RCW) made during the 2025 legislative session (chapter 305, Laws of 2025 (EHB 1382)). HCA is also amending WAC 182-70-520 to improve clarity.
Reasons Supporting Proposal: See purpose.
Statutory Authority for Adoption: RCW 41.05.021, 41.05.160, and 43.371.070.
Statute Being Implemented: RCW 41.05.021 and 41.05.160.
Rule is not necessitated by federal law, federal or state court decision.
Name of Proponent: HCA, governmental.
Name of Agency Personnel Responsible for Drafting: Brian Jensen, P.O. Box 42716, Olympia, WA 98504-2716, 360-725-0815; Implementation and Enforcement: Lorie Geryk, P.O. Box 45502, Olympia, WA 98504-5502, 360-725-1598.
A school district fiscal impact statement is not required under RCW 28A.305.135.
A cost-benefit analysis is not required under RCW 34.05.328. RCW 34.05.328 does not apply to HCA rules unless requested by the joint administrative rules review committee or applied voluntarily.
This rule proposal, or portions of the proposal, is exempt from requirements of the Regulatory Fairness Act because the proposal:
Is exempt under RCW 19.85.025(3) as the rule content is explicitly and specifically dictated by statute.
Explanation of exemptions: HCA is amending chapter 182-70 WAC to remove use of the term "proprietary financial information" and to add the provision that HCA may act as the lead organization to coordinate and manage the all payer health care claims database. These amendments are required by changes to the enabling legislation (chapter 43.371 RCW) made during the 2025 legislative session (chapter 305, Laws of 2025 (EHB 1382)).
Scope of exemption for rule proposal:
Is partially exempt:
Explanation of partial exemptions: [No information supplied by agency.]
The proposed rule does not impose more-than-minor costs on businesses. Following is a summary of the agency's analysis showing how costs were calculated. In addition to rule changes dictated by statute, HCA is making amendments to improve clarity. HCA determined these amendments do not change the rules' impact. HCA sent a survey to over 2,700 industry stakeholders requesting a response if a stakeholder believed a proposed rule change would impose compliance costs. HCA received no responses.
March 18, 2026
Wendy Barcus
Rules Coordinator
RDS-6983.3
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-010Purpose.
(1) Chapter 43.371 RCW establishes the framework for the creation and administration of a statewide all-payer health care claims database.
(2) RCW 43.371.020 directs the health care authority to establish a statewide all-payer health care claims database to support transparent public reporting of health care information. The authority ((shall))may act as the lead organization or select a lead organization to coordinate and manage the database. The lead organization ((shall))must also contract with a data vendor to perform data collection, processing, aggregation, extracts, and analytics.
(3) RCW 43.371.070 mandates that the director of the health care authority adopt rules necessary to implement chapter 43.371 RCW. In addition, RCW 43.371.010 and 43.371.050 direct the adoption of specific rules by the director.
(4) The purpose of this chapter is to implement chapter 43.371 RCW, to facilitate the creation and administration of the Washington statewide all-payer health care claims database.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-030Additional definitions authorized by chapter 43.371 RCW.
The following additional definitions apply throughout this chapter unless the context clearly indicates another meaning.
"Authority" means the Washington state health care authority.
"Capitation payment" means a payment model where providers receive a payment on a per "covered person" basis, for specified calendar periods, for the coverage of specified health care services regardless of whether the patient obtains care. Capitation payments include, but are not limited to, global capitation arrangements that cover a comprehensive set of health care services, partial capitation arrangements for subsets of services, and care management payments.
"Claim" means a request or demand on a carrier, third-party administrator, or the state labor and industries program for payment of a benefit.
"Claimant" means a person who files a workers compensation claim with the Washington state department of labor and industries.
"Coinsurance" means the percentage or amount an enrolled member pays towards the cost of a covered service.
"Copayment" means the fixed dollar amount a member pays to a health care provider at the time a covered service is provided or the full cost of a service when that is less than the fixed dollar amount.
"Data management plan" or "DMP" means a formal document that outlines how a data requestor will handle the WA-APCD data to ensure privacy and security both during and after the project.
"Data policy committee" or "DPC" is the advisory committee required by RCW 43.371.020 (5)(h) to provide advice related to data policy development.
"Data release committee" or "DRC" is the advisory committee required by RCW 43.371.020 (5)(h) to establish a data release process and to provide advice regarding formal data release requests.
"Data submission guide" means the document that contains data submission requirements including, but not limited to, required fields, file layouts, file components, edit specifications, instructions and other technical specifications.
"Data use agreement" or "DUA" means the legally binding document signed by either the lead organization and the data requestor, or the authority and the data requestor, or the authority and a Washington state agency, that defines the terms and conditions under which access to and use of the WA-APCD data is authorized, how the data will be secured and protected, and how the data will be destroyed at the end of the agreement term.
"Days" means calendar days.
"Deductible" means the total dollar amount an enrolled member pays on an incurred claim toward the cost of specified covered services designated by the policy or plan over an established period of time before the carrier or third-party administrator makes any payments under an insurance policy or health benefit plan.
"Director" means the director of the health care authority.
"Fee-for-service equivalent" means the amount that would have been paid by the payer for a specified service if the service had not been capitated or paid under an alternative payment formula like treatment episodes, or the fee amount reflected in the payer's internal fee schedule(s) for services that are not paid on a fee-for-service basis.
"Fee-for-service payment" means a payment model where providers receive a negotiated or payer-specified rate for a specific health care service provided to a patient.
"Health benefits plan" or "health plan" has the same meaning as in RCW 48.43.005.
"Health care" means care, services, or supplies related to the prevention, cure or treatment of illness, injury or disease of an individual, which includes medical, pharmaceutical or dental care. Health care includes, but is not limited to:
(a) Preventive, diagnostic, therapeutic, rehabilitative, maintenance, or palliative care, and counseling, service, assessment, or procedure with respect to the physical or mental condition, or functional status, of an individual or that affects the structure or function of the body; and
(b) Sale or dispensing of a drug, device, equipment, or other item in accordance with a prescription.
"Lead organization" means the entity selected by the health care authority to coordinate and manage the database as provided in chapter 43.371 RCW.
"Malicious intent" means the person acted willfully or intentionally to cause harm, without legal justification.
"Member" means a person covered by a health plan including an enrollee, subscriber, policyholder, beneficiary of a group plan, or individual covered by any other health plan.
"Person" means an individual; group of individuals however organized; public or private corporation, including profit and nonprofit corporations; a partnership; joint venture; public and private institution of higher education; a state, local, and federal agency; and a local or tribal government.
(("PFI" means the proprietary financial information as defined in RCW 43.371.010(12).))
"PHI" means protected health information as defined in the Health Insurance Portability and Accountability Act (HIPAA). Incorporating this definition from HIPAA, does not, in any manner, intend or incorporate any other HIPAA rule not otherwise applicable to the WA-APCD.
"Subscriber" means the insured individual who pays the premium or whose employment makes him or her eligible for coverage under an insurance policy or member of a health benefit plan.
"WA-APCD" means the statewide all payer health care claims database authorized in chapter 43.371 RCW.
"WA-APCD program director" means the individual designated by the authority as responsible for the oversight and management of the operations of the statewide all payer health care claims database authorized in chapter 43.371 RCW.
"Washington covered person" means any eligible member and all covered dependents where the covered person is a Washington state resident, or the state of Washington has primary jurisdiction, and whose laws, rules and regulations govern the members' and dependents' insurance policy or health benefit plan.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-230Review of data requests.
(1) The lead organization must establish a transparent process for the review of data requests, which includes a process for public review for specific requests. The process must include a timeline for processing requests, and notification procedures to keep the requestor updated on the progress of the review. The process must also include the ability for the public to comment on requests that include the release of protected health information ((or proprietary financial information or both)). The authority ((shall have))has final approval over the process and criteria used for review of data requests and all subsequent changes.
(2) The lead organization must post on the WA-APCD website all requests that include the release of protected health information ((or proprietary financial information,)) and the schedule for the receipt of public comment on the request. The time frame for public comment should not be less than ((fourteen))14 calendar days. The lead organization must post the final decision for the request within seven days after the decision is made.
(3) The lead organization has the responsibility to convene the DRC when needed to review data requests and make a recommendation to the lead organization as to whether to approve or deny a data request. The lead organization must establish an annual meeting schedule for DRC and post the schedule on the website. The DRC must review requests for identifiable data and provide a recommendation regarding data release. The lead organization may request the DRC to review other data requests. The review must include a technical review of the data management plan by an expert on the DRC, staff from the office of chief information officer, or other technical expert. The DRC may recommend that the requestor provide additional information before a final decision can be rendered, approve the data release in whole or in part, or deny the release. For researchers who are required in RCW 43.371.050 (4)(a) to have IRB approval, the DRC may recommend provisional approval subject to the receipt of an IRB approval letter and protocol and submittal of a copy of the IRB letter to the lead organization.
(4) The lead organization may only deny a data request based on a reason set forth in WAC 182-70-280.
(5) The lead organization must notify the requestor of the final decision. The notification should include the process available for review or appeal of the decision.
(6) The lead organization must post all data requests and final decisions on the WA-APCD website maintained by the lead organization.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-450Data vendor and lead organization compliance with privacy and security requirements.
(1) To ensure compliance with privacy and security requirements, the data vendor must immediately report to the authority and the office of the state chief information security officer any data breach of the WA-APCD or knowledge that a data recipient is not complying with confidentiality requirements in accordance with health care authority-approved data breach notification procedures. The data vendor may not unilaterally disclose any information related to a breach of the WA-APCD without written permission from the authority and the state chief information security officer.
(2) Upon receiving approval from the authority and the state chief information security officer, the data vendor must notify the data supplier if the data it supplied has been the subject of a data breach for which the reporting requirements in subsection (1) of this section apply. The data vendor is responsible for complying with the applicable notification provisions in state and federal law.
(3) To ensure compliance with privacy and security requirements, the lead organization must:
(a) Conduct follow-up with data recipients of PHI ((or PFI)) on a schedule developed by the lead organization;
(b) Request data recipients share any manuscripts, reports, or products with lead organization and the authority;
(c)(i) Require data recipients to complete a project completion form, attesting that the project has terminated and data have been destroyed in accordance with the data use agreement;
(ii) Require the data recipient to provide the written verification that the data has been destroyed in a manner no less stringent than is required in WAC 182-70-440(4).
(d) Track all requests and research projects and follow up with the data recipient when the research or project is expected to be completed; and
(e) Follow up and require written verification that data is destroyed.
AMENDATORY SECTION(Amending WSR 19-24-090, filed 12/3/19, effective 1/1/20)
WAC 182-70-500Additional definitions related to the format for the calculation and display of data.
The following additional definitions apply throughout this chapter unless the context clearly indicates another meaning. These definitions are related to the rules regarding the format for the calculation and display of ((cost)) data.
(1) "Aggregate ((cost)) data" means data collected from individual-level records that are maintained in a form that does not permit the identification of individual records.
(2) "Arithmetic mean" means the sum of a set of values, divided by the number of values in the set.
(3) "Average" means the arithmetic mean.
(4) "Cell size suppression" means a method used to report data that restricts or suppresses disclosure of subsets of data to protect the identity and privacy of data subjects and to avoid the risk of identification of individuals or providers in small population groups.
(5) "Median" means the middle value of a list of values where the values have been sorted in size order. If the list has an even number of values, the median is the arithmetic mean of the two middle values.
(6) "Outlier" means an observation that is well outside of the expected range of values in a study or experiment, and which is often discarded from the data set.
(7) "Proportion" means a comparative relation between things or magnitudes as to size, quantity, number, or ratio.
(8) "Range" is the largest value in the set of numbers minus the smallest value in the set. Often, a range is expressed to denote a particular span, e.g., 25th to 75th percentile range. Note that as a statistical term, the range is a single number, not a range of numbers.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-520Elements to safeguard the use of ((proprietary financial information))data.
All reports, analytics or other information drawn from the WA-APCD that an approved WA-APCD data ((user as defined in WAC 182-70-510(1)))recipient under WAC 182-70-250 shares with any third party ((shall))must comply with the following restrictions and best practices to protect patient privacy and ensure data integrity.
(1) ((Allowed amount))Aggregate health care and cost data may be made available for public use.
(2) ((Allowed amount data shall be provider or payer deidentified.
(3) Provider-specific allowed amount data shall be suppressed if that payer accounts for more than fifty percent of that provider's patient market share that payer deidentified data could readily be payer reidentified.
(4))) Absolute or relative allowed cost, utilization, or outcome information ((shall))must be communicated in ways that mitigate the potential to mislead data users including, but not limited to:
(a) Use of median cost ((mitigates))or utilization rates to mitigate the impact of outlier cases;
(b) Reporting of cost variation statistics ((()), such as ranges, confidence intervals(())), or standard deviations, to illustrate the typical distribution ((of costs)) around a point estimate;
(c) Application of categorization, stratification or risk-adjustment techniques ((make))to enable like-comparisons of patient populations;
(d) Minimum case volume rules and/or reporting of volume alerts to inform users to the ((universe or sample underlying the cost result))underlying sample size and potential instability; and
(e) Compliance with cell size suppression rules ((are followed whereby cells containing cost data based on a number of patients or providers that is below a minimum threshold count is suppressed))for proportions, rates, and aggregates, ensuring no percentages, ratios, or derivations reveal suppressed cells.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-600Causes for penalties.
(1) The authority may impose penalties for the inappropriate disclosure or use of direct patient identifiers((,))and indirect patient identifiers((, and proprietary financial information)) received from, provided to, or contained in the WA-APCD.
(2) Any penalty imposed pursuant to this subchapter and in accordance with RCW 43.371.050 ((shall))must be in addition to and does not prevent the assessment of penalties authorized by state or federal law, contract, or court order.
(3) The following definitions apply to WAC 182-70-600 through 182-70-665.
(a) "Inappropriate disclosures" or "uses" are those that are inconsistent or in violation of the requirements in RCW 43.371.050. In addition, inappropriate disclosure or uses also include defamatory or malicious use and disclosure or use and disclosure with the intent to cause harm.
(b) "Protected information" is direct patient identifiers((,))and indirect patient identifiers ((and proprietary financial information)).
AMENDATORY SECTION(Amending WSR 19-24-090, filed 12/3/19, effective 1/1/20)
WAC 182-70-625Monetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses.
(1) If a person has been found to have made inappropriate disclosures or uses of ((direct patient identifiers, indirect patient identifiers, and proprietary financial))protected information received from the WA-APCD, the director may impose one or more of the following monetary penalties:
(a) A civil penalty determined pursuant to the criteria and requirements in this chapter;
(b) Cost, including reasonable investigative costs, that do not exceed the amount of any civil penalty;
(c) The cost of any audit performed that uncovered the violation, or was conducted as a result of investigating an alleged violation; and
(d) Up to three times the amount of financial gain received by the alleged violator or financial loss of any person whose protected information was inappropriately disclosed or used.
(2) The director ((shall))will include with the decision regarding the monetary penalty assessment, the director's reasoning for the specific penalty, or lack thereof, that is being assessed.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-630Nonmonetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses.
In addition to the monetary penalties set forth in WAC 182-70-625, if a person has been found to have made inappropriate disclosures or uses of ((direct patient identifiers, indirect patient identifiers, and proprietary financial))protected information received from the WA-APCD, the director may order the following nonmonetary penalties:
(1)(a) Direct WA-APCD program director to review the contract between the person and lead organization to determine whether the finding is a breach of that contract, and take appropriate action including requiring all WA-APCD data provided to be destroyed, termination of the contract, and seeking damages if the contract has been breached; or
(b) In lieu of (a) of this subsection, direct the lead organization to review whether the finding is also a breach of any contract between the person and the lead organization, and take appropriate action including requiring all WA-APCD data provided to be destroyed, termination of the contract, and seeking damages if the contract has been breached, unless the lead organization is the violator, in which case (a) of this subsection ((shall apply))applies.
(2) Demand the destruction of all WA-APCD data provided, whether stand alone or combined with other data, all data products, and derivatives produced from WA-APCD data, and in the person's custody or contract, including proof of the destruction in the form and manner as prescribed by the authority;
(3) Bar the person from receiving any data from the WA-APCD for a designated period of time; and
(4) Notify the funding entity of the violation, when the violation involves research funded by another entity, and any other regulatory agency that has oversight over the person or the data that the person requested.
AMENDATORY SECTION(Amending WSR 20-08-059, filed 3/25/20, effective 4/25/20)
WAC 182-70-705When an audit may be commenced.
(1) The authority may initiate a random audit to ensure compliance with data release requirements. A data requestor may not be subject to a random audit more frequently than once every three years.
(2) The authority may initiate an audit of a data supplier or data requestor upon notice that one of the following events has occurred:
(a) Reports from the data vendor that there is a material change, without justification or a reasonable basis for the change provided by the data supplier, in the number of claims submitted from a data supplier. Before submitting a report under this subsection, the data vendor should have worked with the data supplier to cure any inadvertent data submission issues.
(b) Reports from the data vendor that certain types of claims are missing for a data supplier.
(c) Notice that the data requestor or data user is publishing data in reports that are not compliant with data use agreements. Violations of the data use agreements are subject to penalties in accordance with the process set forth in this chapter.
(d) Notice that the data requestor or data user is publishing ((PFI or)) PHI not in compliance with state or federal requirements.
(e) Other occurrence that could indicate that the data supplier or data requestor is not in compliance with the requirements in law or rule regarding the WA-APCD.
REPEALER
The following section of the Washington Administrative Code is repealed:
WAC 182-70-510
Data formatting rules apply to proprietary financial information.