HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

Capability record

TEFCA And QHIN Connectivity

TEFCA And QHIN Connectivity is treated as a decision-bearing workflow, not a checkbox. The maintained record connects documented organization positioning to authority context, operating domains, buyer questions, and evidence limitations.

Define the operating boundary

A useful definition names the triggering event, required inputs, governing source, accountable owner, decision or action, exception path, evidence retained, and downstream handoff. Buyers should adapt those elements to their own population, jurisdictions, policies, systems, and control model before writing requirements.

The most important distinction is between a label and an operational capability. A provider may document TEFCA and QHIN connectivity while depending on customer-supplied policy, licensed content, third-party data, integration partners, manual review, or services. The demonstration should expose those dependencies rather than hiding them behind a completed interface.

What a demonstration should prove

  1. Begin with representative source records and a named policy, standard, or controlled rule.
  2. Show the normal path, an ambiguous case, missing data, an exception, an override, and a material source change.
  3. Identify who can change rules, who can approve or reject, and how accountability is preserved.
  4. Trace every output back to inputs, versions, timestamps, user actions, and governing evidence.
  5. Export the resulting record and reconcile it with downstream systems and retained obligations.

Authority and operating context

HTI-2 Final Rule

HTI-2 finalizes TEFCA-related definitions, establishes 45 CFR Part 172 provisions supporting TEFCA reliability, privacy, security, trust, and transparency, and leaves the TEFCA Manner Exception unchanged. The final rule makes regulatory status and formal network governance a first-class buying question. It also demonstrates why withdrawn proposals cannot be presented as current requirements.

TEFCA Common Agreement v2.1

The Common Agreement establishes the legal and governance foundation for nationwide exchange among QHINs, Participants, and Subparticipants, with operating detail supplied by the QTF and standard operating procedures. A TEFCA buying decision must identify the contracted path, participant role, exchange purpose, downstream obligations, technical services, and operating procedures rather than relying on a generic connectivity label.

QTF v2.1

The QTF defines technical and functional requirements for QHIN-to-QHIN exchange and works with the Common Agreement and operating procedures to support nationwide exchange. Organizations should distinguish QHIN-level technical duties from the services a QHIN exposes to Participants and the separate interfaces a participant uses internally.

Operating domains

Consent, privacy, purpose, and data segmentation

Risk that technically available information is exchanged without appropriate authority, purpose, restriction, segmentation, patient preference, or evidence—or withheld because policy and technology cannot express a lawful path.

Network coverage, routing, and discovery

Risk that a buyer mistakes network scale, participant counts, connector catalogs, or designation for a usable path to the needed organization, endpoint, data, exchange purpose, and response behavior.

Security, authorization, and trust

Risk that exchange credentials, certificates, clients, users, systems, scopes, directories, and trust relationships are weakly governed, overbroad, stale, or poorly monitored across organizational boundaries.

Evidence and comparison limits

Official provider documentation can establish product positioning. Provider confirmation can clarify package or availability. Independent observation requires a disclosed scenario, environment, date, inputs, and reproducible result. None of those sources alone establishes buyer-specific legal, clinical, regulatory, quality, or operational fitness.

Buyer questions

  • What exact outcome and evidence should TEFCA and QHIN connectivity produce?
  • Which source, version, and customer facts govern the workflow?
  • Which decisions remain human and who is accountable for them?
  • What is native, configured, integrated, service-delivered, or planned?
  • How does a changed source affect open and historical records?

Recent changes

HHS reports more than one billion records exchanged through TEFCA — TEFCA has become a material exchange channel, but buyers still need organization-specific evidence for reach, exchange purpose, data quality, operating performance, and governance.

ASTP/ONC confirms HTI-2 final scope and withdrawn proposals — Compliance summaries and product roadmaps must remove broad proposed provisions that did not become final requirements and add TEFCA governance controls where applicable.

Oracle Health Information Network becomes a designated QHIN — The designation expands participation options but does not establish that every Oracle customer, exchange purpose, or workflow is connected in production.

TEFCA RCE publishes QHIN Technical Framework 2.1 — QHINs, participants, subparticipants, and vendors need versioned impact assessment, coordinated testing, control mapping, and release evidence.

Netsmart becomes a designated QHIN — The designation broadens market reach while leaving organization-specific connectivity, sensitive-data policy, production use, and coverage to be verified.