What this domain asks
Risk that organizations cannot deliver electronic health information in an authorized, timely, usable manner—or mistake technical delivery for satisfaction of access, exchange, use, clinical, or operational responsibilities.
The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.
Buyer questions
- Which actor, data, requester, and requested manner are in scope?
- How are requests tracked from receipt through delivery or exception?
- What technical and policy alternatives are available?
- How is the receiving party able to interpret and use the information?
- How are failures, complaints, and corrections investigated?
- Which provisions are final and which remain proposed?
Mapped workflows
FHIR API Gateway And Orchestration
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for FHIR API gateway and orchestration within this domain.
SMART On FHIR Authorization
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for SMART on FHIR authorization within this domain.
Bulk Data Access And Export
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for bulk data access and export within this domain.
C-CDA Document Exchange
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for C-CDA document exchange within this domain.
Direct Secure Messaging
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for Direct secure messaging within this domain.
Query-Based Document Exchange
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for query-based document exchange within this domain.
Consent, Authorization, And Data Segmentation
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for consent, authorization, and data segmentation within this domain.
Data Quality, Lineage, And Provenance
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for data quality, lineage, and provenance within this domain.
Operational Monitoring And Exception Management
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for operational monitoring and exception management within this domain.
Authority context
HTI-1 Final Rule
HTI-1 updates the ONC Health IT Certification Program, adopts USCDI v3 as the baseline from January 1, 2026, revises information-blocking provisions, adds algorithm-transparency requirements, and creates interoperability-focused reporting metrics.
HTI-2 Final Rule
HTI-2 finalizes TEFCA-related definitions, establishes 45 CFR Part 172 provisions supporting TEFCA reliability, privacy, security, trust, and transparency, and leaves the TEFCA Manner Exception unchanged.
HTI-3 Final Rule
HTI-3 adds a definition of reproductive health care for information-blocking regulations, revises the Privacy and Infeasibility Exceptions, and creates a Protecting Care Access Exception.
HTI-5 Proposed Rule
HTI-5 proposes changes to the ONC Certification Program, information-blocking regulations, and standards-based API foundations. Its provisions remain proposals as of the seed date.
CMS-9115-F
CMS-9115-F requires specified payers to maintain FHIR-based Patient Access APIs for claims, encounter, cost, and maintained clinical data, and establishes other interoperability and provider-notification provisions.
Relevant operating models
- Qualified Health Information Network
- Health Information Network And Exchange Framework
- Enterprise Interoperability And Integration Platform
- FHIR Server, API, And Compliance Platform
- Clinical Data Network And Record-Retrieval Platform
Evidence boundary
Health Interoperability Review provides market, standards, policy, and operating research. It does not provide patient-specific medical advice, determine an individual's rights or coverage, certify product conformity, authorize a disclosure, or replace legal, privacy, security, clinical, or implementation review. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.