HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

Capability record

Data Quality, Lineage, And Provenance

Data Quality, Lineage, And Provenance is treated as a decision-bearing workflow, not a checkbox. The maintained record connects documented organization positioning to authority context, operating domains, buyer questions, and evidence limitations.

Define the operating boundary

A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.

The most important distinction is between a label and an operational capability. A provider may document data quality, lineage, and provenance while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.

What a demonstration should prove

  1. Begin with representative source records and a named policy, standard, or controlled rule.
  2. Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
  3. Identify who can change rules, who can approve or reject, and how accountability is preserved.
  4. Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
  5. Export the resulting record and reconcile it with downstream systems and retained obligations.

Authority and operating context

FHIR R5 5.0.0

FHIR R5 is HL7's current overall published release and adds substantial content beyond R4. HL7 labels the release trial use while individual artifacts can have their own standards status. The newest overall release and the dominant regulatory implementation baseline are not the same thing. Buyers need an explicit version-transition plan rather than treating current FHIR as one undifferentiated feature.

US Core 9.0.0

US Core defines U.S. FHIR profiles, interactions, search expectations, and guidance for exchanging common clinical data. Version 9.0.0 remains based on FHIR R4 and incorporates current USCDI-oriented development. US Core version support is more decision-useful than a generic FHIR statement. Current publication, regulatory adoption, and voluntary SVAP availability must be recorded separately.

USCDI v6

USCDI v6 defines an expanded national set of health-data classes and elements intended to support interoperable exchange. Publication, regulatory adoption, and voluntary certification advancement are distinct status records. USCDI version determines the content baseline around which profiles, certification, mapping, and exchange programs are designed. Buyers should demand a version-aware roadmap and evidence for missing or newly added elements.

HTI-1 Final Rule

HTI-1 updates the ONC Health IT Certification Program, adopts USCDI v3 as the baseline from January 1, 2026, revises information-blocking provisions, adds algorithm-transparency requirements, and creates interoperability-focused reporting metrics. HTI-1 connects standards versions to certification and reporting obligations. Product roadmaps must distinguish the adopted baseline from newer voluntarily advanced specifications.

HTI-3 Final Rule

HTI-3 adds a definition of reproductive health care for information-blocking regulations, revises the Privacy and Infeasibility Exceptions, and creates a Protecting Care Access Exception. Exchange technology must preserve policy context, purpose, restriction, decision, and evidence rather than assuming that technical availability alone determines whether information should be disclosed.

CMS-0057-F

CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions. The rule makes versioned FHIR implementation, bulk data, member permission, endpoint discovery, data lineage, and production operations central payer interoperability requirements.

Bulk Data Access 3.0.0

The Bulk Data Access guide defines asynchronous export patterns for large FHIR datasets, including system-, patient-, and group-level workflows and associated authorization considerations. Bulk export adds job orchestration, file security, filtering, deletion, monitoring, performance, and downstream stewardship requirements that are not answered by a synchronous FHIR API demo.

PDex 2.1.0

PDex profiles FHIR-based exchange of clinical, claims, encounter, and prior-authorization information among payers, patients, and providers and introduces bulk APIs for provider and payer-to-payer access. PDex is central to current payer data-exchange architecture, but buyers must track its US Core dependencies, API role, bulk behavior, member permission, and relationship to separate CARIN and Da Vinci guides.

CARIN Blue Button 2.2.0

CARIN Blue Button defines FHIR profiles for consumer-directed exchange of claims and encounter information using the Common Payer Consumer Data Set. The 2026 release creates a current version-control question for payer and app implementations; support must be stated by version rather than as a generic Blue Button claim.

C-CDA 5.0.0

C-CDA 5.0.0 consolidates U.S. clinical document templates and current guidance while remaining based on the underlying CDA R2 document standard. It uses FHIR tooling to represent templates but does not turn CDA documents into FHIR resources. Document exchange remains a large production reality alongside FHIR APIs. Buyers need version-aware parsing, generation, validation, provenance, and historical compatibility rather than a plan that assumes CDA has disappeared.

Operating domains

Patient identity and record linkage

Risk that records are missed, duplicated, or linked to the wrong person because demographic data, identifiers, algorithms, thresholds, human adjudication, and correction workflows do not align across sources and purposes.

Semantic integrity and terminology

Risk that data move successfully but lose or distort meaning because codes, units, value sets, local terms, context, negation, status, and version provenance are incomplete or transformed incorrectly.

Consent, privacy, purpose, and data segmentation

Risk that technically available information is exchanged without appropriate authority, purpose, restriction, segmentation, patient preference, or evidence—or withheld because policy and technology cannot express a lawful path.

Data quality, completeness, and provenance

Risk that exchanged information lacks source, time, status, authorship, context, completeness, or transformation history, preventing the receiving organization from evaluating whether and how to use it.

Operational reliability and observability

Risk that interfaces and networks appear implemented but fail silently, degrade, duplicate, delay, or lose data because monitoring, ownership, replay, escalation, maintenance, and service evidence are incomplete.

Public-health and community exchange

Risk that provider, HIE, and public-health systems cannot exchange timely, complete, standardized, and actionable information across routine reporting, surveillance, registry, response, and bidirectional workflows.

Information access, blocking, and workflow use

Risk that organizations cannot deliver electronic health information in an authorized, timely, usable manner—or mistake technical delivery for satisfaction of access, exchange, use, clinical, or operational responsibilities.

Evidence and comparison limits

Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.

Buyer questions

  • What exact outcome and evidence should data quality, lineage, and provenance produce?
  • Which source, version, and customer facts govern the workflow?
  • Which decisions remain human and who is accountable for them?
  • What is native, configured, integrated, service-delivered, or planned?
  • How does a changed source affect open and historical records?

Recent changes

ONC publishes national HIO public-health capability findings — Provider records should distinguish public-health connection from bidirectional production use, data quality, identity services, and operating support.

ASTP/ONC approves USCDI v6 through the 2026 SVAP — Developers and buyers need separate records for the mandatory baseline, voluntarily advanced version, and version actually deployed in a customer environment.

HL7 publishes C-CDA 5.0.0 — Enterprise exchange programs need explicit document-ingestion, validation, reconciliation, and extraction evidence in addition to FHIR API capability.

ASTP/ONC confirms HTI-2 final scope and withdrawn proposals — Compliance summaries and product roadmaps must remove broad proposed provisions that did not become final requirements and add TEFCA governance controls where applicable.

HTI-3 revises information-blocking exceptions — Exchange workflows need organization-specific policy, documentation, escalation, segmentation, and audit controls; technology alone cannot decide disclosure applicability.