HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

2026 research note

Standards, policy, and adoption crosswalk

A version-aware map from FHIR, US Core, USCDI, SMART, TEFCA, Direct, CMS API rules, and ONC policy to operating responsibilities.

HEALTH INTEROPERABILITY REVIEWStandards, policy, and adoption crosswalkMethod and limitations included
Executive summary

A version-aware map from FHIR, US Core, USCDI, SMART, TEFCA, Direct, CMS API rules, and ONC policy to operating responsibilities.

The maintained dataset joins 41 organization records, 21 normalized capabilities, 11 operating models, 18 authority records, and 10 operating domains. Counts describe the research corpus; they are not a market-size or quality score.

The authority records

FHIR R4 4.0.1

International; adopted or referenced by specific programs and implementation guides · Published and actively implemented. FHIR R4 defines resources, RESTful interactions, data types, terminology bindings, conformance artifacts, security considerations, and exchange patterns. It includes the first normative FHIR content and remains the base for major U.S. implementation guides.

FHIR R5 5.0.0

International; adoption depends on program and implementation context · Current overall published FHIR release; labeled trial use as a release. FHIR R5 is HL7's current overall published release and adds substantial content beyond R4. HL7 labels the release trial use while individual artifacts can have their own standards status.

US Core 9.0.0

United States realm · Current published version. US Core defines U.S. FHIR profiles, interactions, search expectations, and guidance for exchanging common clinical data. Version 9.0.0 remains based on FHIR R4 and incorporates current USCDI-oriented development.

USCDI v6

United States · Published July 2025; approved through the 2026 Standards Version Advancement Process for voluntary use beginning August 29, 2026. USCDI v6 defines an expanded national set of health-data classes and elements intended to support interoperable exchange. Publication, regulatory adoption, and voluntary certification advancement are distinct status records.

HTI-1 Final Rule

United States · Final and effective. HTI-1 updates the ONC Health IT Certification Program, adopts USCDI v3 as the baseline from January 1, 2026, revises information-blocking provisions, adds algorithm-transparency requirements, and creates interoperability-focused reporting metrics.

HTI-2 Final Rule

United States · Final; selected proposals finalized and remaining unfinalized proposals withdrawn. HTI-2 finalizes TEFCA-related definitions, establishes 45 CFR Part 172 provisions supporting TEFCA reliability, privacy, security, trust, and transparency, and leaves the TEFCA Manner Exception unchanged.

HTI-3 Final Rule

United States · Final. HTI-3 adds a definition of reproductive health care for information-blocking regulations, revises the Privacy and Infeasibility Exceptions, and creates a Protecting Care Access Exception.

HTI-5 Proposed Rule

United States · Proposed, not final. HTI-5 proposes changes to the ONC Certification Program, information-blocking regulations, and standards-based API foundations. Its provisions remain proposals as of the seed date.

CMS-9115-F

United States; specified Medicare Advantage, Medicaid, CHIP, federally facilitated exchange, and provider provisions · Final and in force. CMS-9115-F requires specified payers to maintain FHIR-based Patient Access APIs for claims, encounter, cost, and maintained clinical data, and establishes other interoperability and provider-notification provisions.

CMS-0057-F

United States; specified Medicare Advantage, Medicaid, CHIP, and federally facilitated exchange payer programs · Final and effective with phased compliance dates. CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions.

TEFCA Common Agreement v2.1

United States nationwide exchange framework · Current published Common Agreement version. The Common Agreement establishes the legal and governance foundation for nationwide exchange among QHINs, Participants, and Subparticipants, with operating detail supplied by the QTF and standard operating procedures.

QTF v2.1

United States nationwide exchange framework · Current published QTF version referenced in the January 2026 TEFCA document set. The QTF defines technical and functional requirements for QHIN-to-QHIN exchange and works with the Common Agreement and operating procedures to support nationwide exchange.

SMART App Launch 2.2.0

International with broad U.S. adoption · Current published version. SMART App Launch defines discovery, authorization, scopes, token exchange, and app-launch patterns for applications accessing FHIR APIs from within or outside an EHR workflow.

Bulk Data Access 3.0.0

International · Current published version. The Bulk Data Access guide defines asynchronous export patterns for large FHIR datasets, including system-, patient-, and group-level workflows and associated authorization considerations.

PDex 2.1.0

United States realm · Current published version. PDex profiles FHIR-based exchange of clinical, claims, encounter, and prior-authorization information among payers, patients, and providers and introduces bulk APIs for provider and payer-to-payer access.

CARIN Blue Button 2.2.0

United States realm · Current published version. CARIN Blue Button defines FHIR profiles for consumer-directed exchange of claims and encounter information using the Common Payer Consumer Data Set.

C-CDA 5.0.0

United States realm · Current published version. C-CDA 5.0.0 consolidates U.S. clinical document templates and current guidance while remaining based on the underlying CDA R2 document standard. It uses FHIR tooling to represent templates but does not turn CDA documents into FHIR resources.

The Direct Standard Version 1.3

United States healthcare exchange ecosystem · Published and actively implemented. The Direct Standard specifies a secure, authenticated, scalable method for sending health information to known recipients using profiled internet messaging, public-key infrastructure, certificate discovery, trust, and delivery notifications.

The operating-domain lens

Standards version and conformance control

Risk that organizations treat a standard as a timeless feature, combine incompatible versions or profiles, misstate certification or conformance, and release interfaces without reproducible evidence for the exact artifacts in use. The crosswalk links 7 capabilities and 5 authority records.

Patient identity and record linkage

Risk that records are missed, duplicated, or linked to the wrong person because demographic data, identifiers, algorithms, thresholds, human adjudication, and correction workflows do not align across sources and purposes. The crosswalk links 5 capabilities and 3 authority records.

Semantic integrity and terminology

Risk that data move successfully but lose or distort meaning because codes, units, value sets, local terms, context, negation, status, and version provenance are incomplete or transformed incorrectly. The crosswalk links 6 capabilities and 3 authority records.

Consent, privacy, purpose, and data segmentation

Risk that technically available information is exchanged without appropriate authority, purpose, restriction, segmentation, patient preference, or evidence—or withheld because policy and technology cannot express a lawful path. The crosswalk links 7 capabilities and 5 authority records.

Network coverage, routing, and discovery

Risk that a buyer mistakes network scale, participant counts, connector catalogs, or designation for a usable path to the needed organization, endpoint, data, exchange purpose, and response behavior. The crosswalk links 7 capabilities and 5 authority records.

Data quality, completeness, and provenance

Risk that exchanged information lacks source, time, status, authorship, context, completeness, or transformation history, preventing the receiving organization from evaluating whether and how to use it. The crosswalk links 7 capabilities and 4 authority records.

Security, authorization, and trust

Risk that exchange credentials, certificates, clients, users, systems, scopes, directories, and trust relationships are weakly governed, overbroad, stale, or poorly monitored across organizational boundaries. The crosswalk links 7 capabilities and 4 authority records.

Operational reliability and observability

Risk that interfaces and networks appear implemented but fail silently, degrade, duplicate, delay, or lose data because monitoring, ownership, replay, escalation, maintenance, and service evidence are incomplete. The crosswalk links 10 capabilities and 4 authority records.

Public-health and community exchange

Risk that provider, HIE, and public-health systems cannot exchange timely, complete, standardized, and actionable information across routine reporting, surveillance, registry, response, and bidirectional workflows. The crosswalk links 9 capabilities and 3 authority records.

Information access, blocking, and workflow use

Risk that organizations cannot deliver electronic health information in an authorized, timely, usable manner—or mistake technical delivery for satisfaction of access, exchange, use, clinical, or operational responsibilities. The crosswalk links 9 capabilities and 5 authority records.

How to use the crosswalk

Determine applicability with qualified owners, identify affected records and workflows, map each expectation to an accountable decision and retained evidence, then use capability and organization pages to frame a technology evaluation. A mapping is editorial navigation—not a conformity or legal conclusion.

Methodology

  1. Define the market boundary, exclusions, operating models, and capability taxonomy before classifying organizations.
  2. Require an approved official source for organization inclusion and each documented capability.
  3. Keep authority sources, provider claims, independent observations, editorial synthesis, and unknowns in separate evidence states.
  4. Use one primary operating model per organization while retaining adjacent scope in the narrative record.
  5. Preserve source URLs, review dates, material changes, limitations, and correction history.

Limitations

  • The maintained population is substantial but not claimed to be a complete global market.
  • Official public documentation may omit available capabilities or lag product and service changes.
  • Documented positioning does not measure product depth, configured availability, independent performance, implementation effort, customer outcome, or commercial terms.
  • Authority mappings are editorial research aids and do not establish buyer-specific applicability or product conformity.
  • No organization may purchase inclusion, classification, finding, or correction outcome.

Reproducibility and updates

The report is reproduced from the provider registry, normalized facts and evidence, authority and domain records, and the publication taxonomy. A material change requires a dated source and editorial explanation. Historical values remain available through the change ledger rather than disappearing when the current record changes.

Research boundary

Health Interoperability Review provides market, standards, policy, and operating research. It does not provide patient-specific medical advice, determine an individual's rights or coverage, certify product conformity, authorize a disclosure, or replace legal, privacy, security, clinical, or implementation review.