Your Last 180-Day PI Window Has Started. Is Your Evidence Ready?

July 5 has passed. That means the last possible 180-day performance period for 2026 MIPS Promoting Interoperability has started.

For many practices, this is the moment when PI shifts from “we need to get ready” to “we need to prove we are ready.”

That difference matters.

Promoting Interoperability is not scored on effort, intent, or whether your EHR dashboard looks calm. It is scored based on data, attestations, certified technology, and evidence supporting your reporting period. If your practice is now inside its PI performance period, the work should already be happening. The question is whether your documentation can support it.

At Chirpy Bird, we want practices to treat this week as a proof checkpoint rather than a panic moment. Panic is not a compliance strategy, even if it is very popular in July.

Why the 180-Day PI Window Matters Now

For the 2026 performance year, MIPS Promoting Interoperability requires practices to collect data for all required measures during the same minimum continuous 180-day period in the calendar year, unless an exclusion applies.

That means your reporting period is not just a date range on a spreadsheet.

It is the window where your practice must show that the required PI activity happened, your certified EHR technology supported it, and your documentation can prove it.

If July 5 was your start date, your PI performance period runs through December 31, 2026. There is no extra room at the end of the year to “make up” a missing reporting period. The runway is now active.

This is the time to check whether the plane is actually on it.

PI Is Built During the Reporting Period, Not During Submission

Many practices treat Promoting Interoperability as a submission season issue. We understand why. Submission is when the pressure feels visible.

But PI risk usually starts much earlier.

It starts when the practice does not confirm its CEHRT setup. It grows when measure workflows are not being captured correctly. It gets worse when public health reporting status is unclear. Then it becomes expensive when the team discovers, months later, that the evidence file does not match the score they expected.

Submission season does not create these problems. It reveals them.

That is why July matters.

If you are now inside the performance period, you should not wait until the end of the year to ask whether your evidence supports your PI strategy. The right question is not, “Can we submit later?”

The right question is, “Are we collecting and preserving the proof right now?”

Confirm Your CEHRT Readiness First

The first step is simple but often skipped.

Confirm that your certified electronic health record technology, or CEHRT, was ready on the first day of your PI performance period.

CEHRT means your EHR technology meets certification criteria set by the Office of the National Coordinator for Health IT. In plain English, it means your system must support the certified functions needed for PI reporting.

Your practice should confirm three things:

  1. CEHRT functionality was in place on day one of the reporting period.

  2. Your EHR is on track to meet certification requirements by the last day of the reporting period.

  3. Your CMS EHR Certification ID from CHPL is available for submission.

CHPL stands for the Certified Health IT Product List. It is the source used to identify certified health IT products and generate the CMS EHR Certification ID.

Do not assume your vendor has this handled. Ask. Verify. Save the confirmation.

A vendor statement may help, but your practice still owns the reporting risk.

Check Whether Your Measures Are Actually Capturing Data

Promoting Interoperability includes objectives such as electronic prescribing, health information exchange, provider-to-patient exchange, public health and clinical data exchange, and the protection of patient health information.

Under those objectives, practices must report the required measures unless an exclusion applies.

This is where platform readiness meets workflow reality.

Your EHR may be capable of capturing the data, but that does not mean your staff workflows are producing clean, complete, reportable data. A function can exist in the system and still fail in daily use. This is the tiny little gremlin that lives between “the EHR can do it” and “the practice can prove it.”

During the first week of the reporting period, review:

  • Are the required PI measures turned on and configured correctly?

  • Are staff using the correct workflows?

  • Are reports producing expected results?

  • Are the numerator and denominator values reasonable?

  • Are exclusions documented, if claimed?

  • Are measure owners assigned?

  • Are reports saved at regular intervals?

Do not wait until December to find out that a workflow was technically available but operationally ignored.

Build the PI Evidence File Now

Your PI evidence file should not live in five inboxes, two vendor portals, and one person’s memory.

Create a single location for your PI proof file now. This can be a secure shared folder, compliance tracker, or reporting workbook. The format matters less than the discipline.

Your file should include:

  • Reporting period start and end dates

  • CEHRT documentation

  • CMS EHR Certification ID from CHPL

  • Vendor confirmations

  • Required measure reports

  • Exclusion documentation, if applicable

  • Security Risk Analysis documentation

  • Security Risk Management activity records

  • SAFER Guide self-assessment evidence

  • Public health reporting documentation

  • Attestation support

  • Internal notes showing who reviewed each item and when

This is not paperwork for paperwork’s sake.

This is how your practice protects the score behind the submission.

If CMS or another reviewer asks for support later, you do not want your compliance plan to begin with, “Let me check with Karen.” Karen may be wonderful. Karen should not be the audit trail.

Do Not Treat Security as a Side Quest

For 2026, the Security Risk Analysis measure deserves special attention.

Practices must complete both parts of the requirement. That includes conducting or reviewing a security risk analysis on CEHRT functionality and implementing security risk management activities to reduce risks and vulnerabilities under the HIPAA Security Rule.

That second part matters.

A Security Risk Analysis is not just a document that says, “We looked around and found some risks.” It should connect to action. Your practice should be able to show how it reviewed risk and what it did to manage or reduce that risk.

Your team should ask:

  • Did we complete or review a Security Risk Analysis for the 2026 performance year?

  • Did it include CEHRT functionality?

  • Did we identify risks and vulnerabilities?

  • Did we document security risk management activities?

  • Did we assign owners and timelines?

  • Did leadership review the results?

  • Can we produce the evidence if asked?

If the answer is unclear, do not wait. Security documentation can take time to organize, and vague memories do not age well in compliance.

Complete the SAFER Guide Self-Assessment

The 2026 PI requirements also include the annual self-assessment using the 2025 High Priority Practices SAFER Guide.

The SAFER Guide is designed to help healthcare organizations assess EHR safety practices. For PI, the important point is that the self-assessment must be completed within the calendar year of the performance period.

This should not be treated as a checkbox that someone clicks at the end of the year while holding a lukewarm coffee and hoping for mercy.

Use it as a real operational review.

Ask your team:

  • Who owns the SAFER Guide self-assessment?

  • Has the correct 2025 High Priority Practices Guide been used?

  • Are responses documented?

  • Are gaps assigned for follow-up?

  • Are notes saved in the PI evidence file?

  • Can leadership show that the review happened?

The SAFER Guide requirement connects EHR use, patient safety, and compliance. That makes it more than an administrative task. It is a practical way to identify where technology and workflow may put the practice at risk.

Verify Public Health Reporting Status

Public health reporting can look deceptively simple from the outside.

A practice may think, “Our interface is active,” or “Our vendor handles that,” and move on.

That is not enough.

Your team should confirm the public health and clinical data exchange measures that apply to your practice. You should also document your status, communications, exclusions, and evidence of active engagement, where required.

Ask:

  • Which public health reporting measures apply?

  • Are the required interfaces active?

  • Do we have proof of registration, testing, production status, or active engagement?

  • Are communications from public health agencies or registries saved?

  • Are exclusions supported with documentation?

  • Is the evidence dated and tied to the reporting period?

If your answer is “the vendor knows,” that may be a starting point. It is not the evidence file.

Reweighting Should Be Verified, Not Assumed

Some practices qualify for PI reweighting because of special status or approved hardship exceptions. That can help.

But reweighting is not a blanket permission slip to ignore PI.

If your practice believes PI does not apply, confirm why. Document the status, source, reporting path, and decision. If your practice is part of an ACO, APP reporting pathway, specialty group, or small practice category, make sure the assumption matches the actual reporting requirements.

Also, remember this: submitting qualifying PI data can affect reweighting. That means a practice should understand the scoring impact before it submits.

Do not rely on hallway wisdom.

“We are probably exempt” is not a strategy. It is a sentence that gets more expensive with age.

What Your Practice Should Do This Week

Now that the reporting period has started, use this week to complete a practical PI readiness review.

Start with these steps:

  1. Confirm your reporting period - Document the start date, end date, reporting path, and responsible team members.

  2. Verify CEHRT and CHPL information - Confirm CEHRT functionality, certification status, vendor documentation, and CMS EHR Certification ID.

  3. Run early measure reports - Review whether PI measure data is being captured as expected.

  4. Check staff workflows - Make sure the workflows used in daily practice match the workflows required for reporting.

  5. Review security documentation - Confirm both the Security Risk Analysis and security risk management activities.

  6. Complete or schedule the SAFER Guide self-assessment - Assign ownership and save evidence.

  7. Verify public health reporting - Collect proof of active engagement, registration, testing, production status, or exclusions.

  8. Create the PI evidence file - Store documentation in one secure place with clear labels and dates.

  9. Review reweighting assumptions - Confirm whether reweighting applies and how it affects your scoring strategy.

  10. Get a second set of eyes - If anything is unclear, ask for help now.

This is not about perfection. It is about finding the weak spots while there is still time to manage them.

When to Book a PI Second Opinion

A PI Second Opinion is useful when your team is not fully confident that the evidence supports the reporting strategy.

Consider booking one if:

  • You are not sure your July 5 start date was ready

  • Your CEHRT or CHPL information is unclear

  • Your measure reports do not look right

  • Your public health reporting status depends on vendor assumptions

  • Your SRA is complete, but risk management documentation is weak

  • Your SAFER Guide review has not started

  • Your reweighting assumptions have not been verified

  • Your evidence file is scattered or incomplete

  • Your practice manager is carrying the whole PI process in their head

That last one is common. It is also unfair to the practice manager and risky for the practice.

Promoting Interoperability should be managed as an evidence-based compliance process, not as a heroic memory exercise.

The Bottom Line

The last 180-day PI window has started.

That does not mean your practice should panic. It means your practice should verify.

Your score will depend on more than whether the work happened. It will depend on whether your practice can prove the work occurred during the correct reporting period, using the right technology, and with the right documentation.

July is the right time to review your PI evidence, check your CEHRT setup, confirm your reporting-period proof, and organize your documentation before small gaps become larger problems.

If you are not fully confident that your PI proof matches your PI plan, book a PI Second Opinion with Chirpy Bird before the runway closes.

Previous
Previous

OCR Is Watching: The Risk Analysis Initiative & What It Means for Your Practice

Next
Next

The Operational Blind Spots Hurting Performance