You have seventeen days. The CMS Quality Payment Program submission window for the 2025 performance year closes March 31, 2026, and somewhere in your office a spreadsheet with patient names, MRNs, dates of service, and clinical flags is moving between a practice manager and a registry vendor. That spreadsheet is why quality measures in healthcare belong on your compliance work plan and not only your revenue work plan. This guide covers how measure data actually leaves your practice, which recipients require a Business Associate Agreement, what "minimum necessary" means when an abstractor asks for the whole chart, and what to do when a patient asks for the data you reported.

Who Reports, To Whom, and By When

Short answer for the person searching at 4:45 p.m.: a quality measure is a standardized calculation — a numerator, a denominator, and a set of exclusions — applied to your patient population to produce a score. Clinicians and staff generate the underlying data during care and documentation. Your practice, or a vendor acting for it, extracts and transmits that data to a payer or program.

The four common destinations:

  • CMS, under the Merit-based Incentive Payment System (MIPS) or an MVP. Clinicians exceeding the low-volume threshold are generally required to report. The submission window runs January 1 through March 31 following the performance year, and the payment adjustment lands two years out — 2025 performance affects 2027 Medicare Part B payment.
  • Commercial and Medicaid health plans, through HEDIS and plan-specific programs, often with a spring chart-chase season.
  • Specialty registries and QCDRs, which aggregate clinical data across practices and submit on your behalf.
  • ACOs, IPAs, and management services organizations, which pull data continuously to manage shared-savings performance.

Traditional MIPS asks for six quality measures, including at least one outcome or high-priority measure, with a data completeness threshold CMS sets each year. Confirm the current thresholds, weights, and measure specifications on the CMS Quality Payment Program site rather than reusing last year's numbers — they move.

Quality Measures in Healthcare Are a Data Export Problem

Strip away the scoring and every quality program is the same operational event: identified patient data leaves your building on a schedule. Treat it that way and the compliance obligations become obvious.

Path 1: eCQMs pulled directly from your EHR

Electronic clinical quality measures are calculated from structured fields already in the record. The export is usually a QRDA file. Two things to verify: which staff account has the export permission, and whether the file lands in a shared drive, a desktop downloads folder, or someone's email. Measure logic and value sets live at the eCQI Resource Center; your job is knowing where the output goes after the button is pressed.

Path 2: Qualified registries and QCDRs

This is your highest-volume PHI disclosure of the year for many practices, and it is a business associate relationship. The registry receives patient-level data, holds it, analyzes it, and transmits on your behalf. No BAA, no lawful disclosure.

Path 3: Claims-based measures

Small practices may report certain measures through Medicare Part B claims using quality data codes appended to the claim. Nothing extra leaves the building — the data rides existing billing transactions. The administrative question is whether your billing staff and clinicians have a documented process for when those supplemental codes get appended and who verifies them. Measure and code selection is a clinical documentation decision made by the treating clinician; your role is building the workflow that captures and audits it, not deciding which code fits a given encounter.

Path 4: Manual abstraction and payer chart chases

Someone from a health plan — or a vendor working for the plan — asks for records on fifty patients. This is the path most likely to generate a complaint, because it is the one where staff improvise.

The Chart Chase: What You Can Send Without an Authorization

HIPAA permits a covered entity to disclose PHI to another covered entity for that entity's health care operations when both have or had a relationship with the individual, the PHI pertains to that relationship, and the disclosure is for quality assessment and improvement, outcomes evaluation, or similar activities. HEDIS abstraction fits squarely inside that permission. You do not need patient authorization, and you do not sign a BAA with the health plan — the plan is not your business associate.

What you should require before releasing anything:

  1. Proof the requester works for the plan. If a third-party abstraction vendor calls, ask for the plan's letter of authorization naming that vendor. The vendor is the plan's business associate, not yours, and the plan's BAA is what makes the handoff lawful.
  2. A defined patient list and measure set. "All records for these members" is not a measure-scoped request.
  3. A secure transport method. Portal upload or secure file transfer. Not a fax to a number someone read over the phone, and not an unencrypted attachment.
  4. A log entry. Date, requester, patient count, measure, method, staff member.

Treatment, payment, and operations disclosures are excluded from the accounting of disclosures a patient can request — but log them anyway. When a patient calls to ask why a health plan has their chart, you want an answer in under five minutes.

Minimum necessary still applies

Health care operations disclosures are subject to the minimum necessary standard. An abstractor working a diabetes measure needs specific results and dates, not the behavioral health consult note. Give your release-of-information staff a written rule: pull the fields the measure specification names, and escalate anything broader to the privacy officer. HHS guidance on the minimum necessary requirement is short enough to attach to the SOP.

The Vendor Inventory You Probably Have Wrong

Sit down with your quality reporting workflow and list every entity that touches identified data. Most practices find more names than they expected:

  • The qualified registry or QCDR
  • The analytics or population health platform your ACO requires
  • The EHR vendor and any reporting module licensed separately
  • A billing company appending quality data codes
  • An outside consultant who logs in to review measure performance
  • The health information exchange feeding gaps-in-care data
  • Cloud storage where extract files sit between generation and submission

Each of these needs a signed, current Business Associate Agreement — and the consultant with a read-only login counts, because access to PHI is access to PHI regardless of whether they download anything. If your quality vendor list is longer than your BAA folder, close that gap before submission season, not after. A six-step wizard that produces a signature-ready Business Associate Agreement with PDF and DOCX export will get a new registry or analytics vendor papered the same afternoon, as a one-time purchase rather than another subscription line.

CMS itself is a different case. Submitting to the Quality Payment Program is a disclosure to a government program, not a business associate arrangement. Do not send CMS a BAA and do not wait on one.

De-Identification, Dashboards, and Small Denominators

Your quality vendor sends a monthly dashboard. It shows a measure with a denominator of four, broken out by clinician and ZIP code. That is not de-identified data in any meaningful sense — anyone in the practice can name those four patients, and so can anyone with the ZIP code list.

HIPAA recognizes two de-identification methods: Safe Harbor removal of eighteen identifier categories, and expert determination. Review the HHS de-identification guidance before anyone forwards a performance report outside the practice. Practical rules for your reporting staff:

  • Suppress cells below a threshold your practice sets in writing — many organizations use eleven — before any external sharing.
  • Treat clinician-level performance data as confidential personnel and quality material with a defined distribution list.
  • Do not paste dashboard screenshots into board decks, marketing material, or payer negotiations without suppression review.

When Measure Data Becomes a Records Request

A patient asks for "everything you used to score my care." Your designated record set includes records used to make decisions about that individual — chart notes, results, and the source data behind measure calculations. Aggregate scores and internal performance analytics generally are not part of the designated record set, but the underlying encounter documentation is.

You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date. If the data lives with your registry vendor, your BAA needs to say the vendor will return or make available PHI in the designated record set within a timeframe that lets you meet the 30 days — a vendor that answers in fifteen business days has just consumed half your clock.

A Twelve-Month Operating Calendar With Names Attached

January–March. Reporting lead validates prior-year data and submits. Privacy officer confirms every vendor in the submission chain has a current BAA on file before any extract is generated. Compliance lead files the submission receipt.

April–June. Payer chart-chase season. Release-of-information staff run every request through the verification checklist above. Privacy officer spot-audits ten requests for scope and transport.

July–September. Mid-year performance review. Reporting lead confirms measure specifications for the current year, since specifications change annually and a measure retired in the final rule will silently score zero. Practice administrator reviews new vendor contracts against the quality workflow map.

October–December. Read the final rule. Update the measure set with clinical leadership. Run a tabletop: what happens if the registry vendor reports a breach in February, mid-submission?

Continuously. Retain quality reporting documentation for six years — CMS expects it for data validation audits, and HIPAA requires six-year retention of compliance documentation independently. Store it somewhere a departing employee cannot take with them.

Five Failure Modes Worth Checking This Week

  1. The unpapered analytics tool. A clinician signed up for a free measure-tracking platform and uploaded a patient list. No BAA, no risk analysis entry, no one knows.
  2. The extract sitting in a downloads folder. Generated last March, never deleted, on a laptop that left with a former biller.
  3. The unverified abstractor. Front desk released forty charts to a caller who said "I'm with the health plan" and produced nothing in writing.
  4. The over-broad chart pull. Full chart sent when the measure needed two lab values and a date.
  5. The stale BAA. Signed in 2018 with a registry that has since been acquired, renamed, and moved its infrastructure.

Any of these can surface as a reportable incident. Breaches affecting 500 or more individuals are published on the HHS breach portal, and vendor-side incidents involving aggregated clinical data are a recurring category there.

Next Step

Before your next submission cycle, map the quality data flow end to end and match every node to a signed agreement. Where one is missing, generate a Business Associate Agreement you can send for signature the same day. If the exercise surfaces gaps beyond contracts — an outdated risk analysis, policies that never mentioned registry reporting — the broader HIPAA risk analysis and policy document set covers that ground. Quality measures in healthcare will keep pulling PHI out of your charts every year; the only variable is whether the paperwork keeps up.