P3N Policy #3 Certification Policy and Process
Customize your policy alerts
Sign up for Pennsylvania Insurance Department Policy P3N Policy #3 Certification Policy and Process alerts
Get alerted when Policy P3N Policy #3 Certification Policy and Process changes without checking for updates manually.
Monitor payer policy activity
Governs certification, provisional certification, onboarding, and annual recertification of Health Information Organizations (HIOs) as Certified Participants (CPs) connecting to the Pennsylvania Patient & Provider Network (P3N); applies to PA eHealth and all current and prospective CPs.
No material clinical or coverage changes in this revision.
Certification and Recertification Requirements
Certification and Recertification Criteria
Certification and recertification of Health Information Organizations (HIOs) as Certified Participants (CPs) are granted only when the following documentation, eligibility checks, provisional steps, and completion conditions are met; recertification follows the timeline and remediation steps below.
ALL of the following
- Applicants must submit the Certification Package including the P3N Application for Participation, the Uniform Participant Agreement (PAR), P3N Technical Requirements, P3N Policies, a third-party Security Audit and HIPAA Risk Assessment, and proof of insurance as required by the PAR.
(See required documents list)
ALL of the following
- PA eHealth will review the submitted documentation for completeness and appropriate signatures within ten (10) business days.
PA eHealth validates the application, attestations to comply with Technical Requirements and P3N Policies, and that the PAR is signed by an authorized official.
Provisional Certified Participant (if application sufficient)
- If the application is deemed sufficient, PA eHealth will notify the applicant of provisional certification and notify the Health Information Exchange Trust Community Committee (HIETCC).
Provisional status allows technical discussions and access to the test environment but does not permit production connectivity until PAR is fully executed.
- PA eHealth will review relevant portions of the application with HIETCC at the next HIETCC meeting; the applicant will be invited to attend.
ALL of the following
- The PAR has been fully executed.
- The P3N Application for Certification and all associated documents have been reviewed and approved as to compliance.
- The organization has provided an executive summary of the third-party Security Audit and HIPAA Risk Assessment (see Policy #10 for proof of security certification).
- The organization has produced proof of insurance in compliance with the PAR.
- The HIO has completed interoperability testing and production validation testing.
ALL of the following
- PAR renews automatically annually pending recertification; PA eHealth will notify the CP at least 120 days prior to the end of the current certification period that recertification is required.
- The CP must submit any changes from the original application, proof of insurance as required by the PAR, and evidence of its most recent third-party Security Audit and HIPAA risk assessment dated within 12 months of the renewal date. The CP has 60 calendar days to submit this information; if more time is required, the CP must notify PA eHealth within 30 days to request an extension.
- Upon receipt of updated documentation, PA eHealth will have 30 days to review and authorize the CP for recertification, using the same steps outlined for initial review. If approved, PA eHealth will notify the CP within 5 days and the PAR will renew for an additional year.
ALL of the following
- If PA eHealth discovers issues during recertification, it will confer with the CP and the CP will be given the opportunity to address and correct deficiencies.
- If the CP is not approved for recertification, PA eHealth will notify the CP within 5 days. If notice is provided prior to the end of the certification year, the CP shall be given up to 90 days to correct any issues.
- If recertification is not approved and issues remain unresolved, the CP will be disconnected from the P3N, shared data may be removed, and the PAR will be suspended or terminated per its terms. Disputes will be handled via the PAR dispute resolution process.
ALL of the following
- Provisional certification permits technical onboarding and testing but not production connectivity until the PAR is fully executed and all certification conditions are met.
- Refer to Policy #10 (Security Policy) for detailed proof-of-security-certification requirements.
Application, Certification, and Recertification Actions
Application review and provisional certification
PA eHealth will review the submitted Application for Participation and supporting documentation for completeness and appropriate signatures within ten (10) business days. If questions arise, PA eHealth will arrange a conversation with the applying HIO. If the application is deemed sufficient, PA eHealth may notify the applicant of provisional certification and will notify the Health Information Exchange Trust Community Committee (HIETCC); provisional certification permits technical discussions, test environment access, and invitation to the next HIETCC meeting but does not permit production connectivity until required steps are complete.
- PA eHealth reviews for completeness and appropriate signatures within ten (10) business days.
- PA eHealth will arrange discussions with the applying HIO if issues arise.
- If sufficient, PA eHealth notifies applicant of provisional certification and notifies HIETCC.
- Provisional status allows technical discussions and access to test environment but not production until PAR is fully executed.
Certification completion conditions
An HIO will be considered certified only after the PAR has been fully executed; the P3N Application for Certification and all associated documents have been reviewed and approved for compliance; an executive summary of the third-party Security Audit and HIPAA Risk Assessment has been provided; proof of insurance in compliance with the PAR has been provided; and interoperability and production validation testing have been completed.
- PAR fully executed.
- Application and associated documents reviewed and approved for compliance.
- Executive summary of third-party Security Audit and HIPAA Risk Assessment provided.
- Proof of insurance compliant with the PAR provided.
- Interoperability testing and production validation testing completed.
Recertification failure consequences
If recertification is not approved, PA eHealth will notify the CP within five (5) days and the CP shall be given up to ninety (90) days to correct any issues if notice is provided prior to the end of the certification year; unresolved or uncorrected issues may result in disconnection from the P3N, removal of shared data, and suspension or termination of the PAR per its terms.
- PA eHealth will notify CP of non-approval within five (5) days.
- CP has up to ninety (90) days to correct issues if notice is before the certification year ends.
- If not approved after correction period, CP will be disconnected from the P3N, shared data may be removed, and PAR suspended or terminated.
- Disputes are handled using the PAR dispute resolution process.
Key Terms and Acronyms
OpenPayer is powered by Trek Health's payer performance platform. Trek continuously ingests, validates, and normalizes Transparency in Coverage data alongside payer policies and other commercial payer data to create a structured payer intelligence foundation. OpenPayer uses this foundation to deliver personalized search results, dynamically generated policy pages, and tailored policy monitoring based on each user's payers, specialties, billing codes, and areas of interest. The same intelligence powers broader payer performance workflows, including reimbursement benchmarking, contract evaluation, payer negotiations, and financial decision-making.