Define the operating boundary
A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.
The most important distinction is between a label and an operational capability. A provider may document FHIR API gateway and orchestration while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.
What a demonstration should prove
- Begin with representative source records and a named policy, standard, or controlled rule.
- Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
- Identify who can change rules, who can approve or reject, and how accountability is preserved.
- Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
- Export the resulting record and reconcile it with downstream systems and retained obligations.
Authority and operating context
FHIR R4 4.0.1
FHIR R4 defines resources, RESTful interactions, data types, terminology bindings, conformance artifacts, security considerations, and exchange patterns. It includes the first normative FHIR content and remains the base for major U.S. implementation guides. Buyers must distinguish base R4 support from support for a named profile or implementation guide. FHIR R4 does not establish production connectivity, semantic quality, authorization design, or conformity for a particular product.
FHIR R5 5.0.0
FHIR R5 is HL7's current overall published release and adds substantial content beyond R4. HL7 labels the release trial use while individual artifacts can have their own standards status. The newest overall release and the dominant regulatory implementation baseline are not the same thing. Buyers need an explicit version-transition plan rather than treating current FHIR as one undifferentiated feature.
US Core 9.0.0
US Core defines U.S. FHIR profiles, interactions, search expectations, and guidance for exchanging common clinical data. Version 9.0.0 remains based on FHIR R4 and incorporates current USCDI-oriented development. US Core version support is more decision-useful than a generic FHIR statement. Current publication, regulatory adoption, and voluntary SVAP availability must be recorded separately.
HTI-5 Proposed Rule
HTI-5 proposes changes to the ONC Certification Program, information-blocking regulations, and standards-based API foundations. Its provisions remain proposals as of the seed date. The proposal can inform scenario planning, but vendors and buyers must not describe proposed removals or new API provisions as settled current requirements.
CMS-9115-F
CMS-9115-F requires specified payers to maintain FHIR-based Patient Access APIs for claims, encounter, cost, and maintained clinical data, and establishes other interoperability and provider-notification provisions. The rule created a durable payer API market while leaving data scope, patient authorization, app privacy, testing, operations, and implementation-guide choices as material implementation decisions.
CMS-0057-F
CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions. The rule makes versioned FHIR implementation, bulk data, member permission, endpoint discovery, data lineage, and production operations central payer interoperability requirements.
SMART App Launch 2.2.0
SMART App Launch defines discovery, authorization, scopes, token exchange, and app-launch patterns for applications accessing FHIR APIs from within or outside an EHR workflow. A buyer needs evidence for the exact SMART version, supported launch contexts, scopes, client registration, user and system authorization, and operational token controls.
PDex 2.1.0
PDex profiles FHIR-based exchange of clinical, claims, encounter, and prior-authorization information among payers, patients, and providers and introduces bulk APIs for provider and payer-to-payer access. PDex is central to current payer data-exchange architecture, but buyers must track its US Core dependencies, API role, bulk behavior, member permission, and relationship to separate CARIN and Da Vinci guides.
CARIN Blue Button 2.2.0
CARIN Blue Button defines FHIR profiles for consumer-directed exchange of claims and encounter information using the Common Payer Consumer Data Set. The 2026 release creates a current version-control question for payer and app implementations; support must be stated by version rather than as a generic Blue Button claim.
Operating domains
Standards version and conformance control
Risk that organizations treat a standard as a timeless feature, combine incompatible versions or profiles, misstate certification or conformance, and release interfaces without reproducible evidence for the exact artifacts in use.
Operational reliability and observability
Risk that interfaces and networks appear implemented but fail silently, degrade, duplicate, delay, or lose data because monitoring, ownership, replay, escalation, maintenance, and service evidence are incomplete.
Information access, blocking, and workflow use
Risk that organizations cannot deliver electronic health information in an authorized, timely, usable manner—or mistake technical delivery for satisfaction of access, exchange, use, clinical, or operational responsibilities.
Evidence and comparison limits
Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.
Buyer questions
- What exact outcome and evidence should FHIR API gateway and orchestration produce?
- Which source, version, and customer facts govern the workflow?
- Which decisions remain human and who is accountable for them?
- What is native, configured, integrated, service-delivered, or planned?
- How does a changed source affect open and historical records?
Recent changes
CMS refreshes interoperability API frequently asked questions — Readiness records should be separated by API, implementation guide, source system, responsible party, test status, production status, and exception process.
HL7 publishes US Core 9.0.0 — FHIR platform and integration claims should identify both the base FHIR release and the exact US Core guide version, supported profiles, tests, and production status.