HEALTH INTEROPERABILITYREVIEW

Move data. Preserve meaning. Prove the exchange.

Operating domain

Operating domain: Network coverage, routing, and discovery

Risk that a buyer mistakes network scale, participant counts, connector catalogs, or designation for a usable path to the needed organization, endpoint, data, exchange purpose, and response behavior.

What this domain asks

Risk that a buyer mistakes network scale, participant counts, connector catalogs, or designation for a usable path to the needed organization, endpoint, data, exchange purpose, and response behavior.

The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.

Buyer questions

  • Which legal entity, site, endpoint, and exchange purpose are live?
  • How is the route discovered and kept current?
  • What happens when multiple networks or paths overlap?
  • Which data classes and response obligations apply?
  • How are failed, misrouted, duplicated, and unanswered requests handled?
  • What source supports every reach or volume claim?

Mapped workflows

Direct Secure Messaging

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for Direct secure messaging within this domain.

Query-Based Document Exchange

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for query-based document exchange within this domain.

TEFCA And QHIN Connectivity

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for TEFCA and QHIN connectivity within this domain.

Provider Directory And Endpoint Discovery

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for provider directory and endpoint discovery within this domain.

Payer And Claims Data Exchange

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for payer and claims data exchange within this domain.

Public-Health Reporting And Bidirectional Exchange

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for public-health reporting and bidirectional exchange within this domain.

Operational Monitoring And Exception Management

A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for operational monitoring and exception management within this domain.

Authority context

CMS-9115-F

CMS-9115-F requires specified payers to maintain FHIR-based Patient Access APIs for claims, encounter, cost, and maintained clinical data, and establishes other interoperability and provider-notification provisions.

CMS-0057-F

CMS-0057-F expands Patient Access API content and requires Provider Access, Payer-to-Payer, and Prior Authorization APIs for impacted payers, with associated privacy, opt-in or opt-out, metrics, and operational provisions.

TEFCA Common Agreement v2.1

The Common Agreement establishes the legal and governance foundation for nationwide exchange among QHINs, Participants, and Subparticipants, with operating detail supplied by the QTF and standard operating procedures.

QTF v2.1

The QTF defines technical and functional requirements for QHIN-to-QHIN exchange and works with the Common Agreement and operating procedures to support nationwide exchange.

The Direct Standard Version 1.3

The Direct Standard specifies a secure, authenticated, scalable method for sending health information to known recipients using profiled internet messaging, public-key infrastructure, certificate discovery, trust, and delivery notifications.

Relevant operating models

Evidence boundary

Health Interoperability Review provides market, standards, policy, and operating research. It does not provide patient-specific medical advice, determine an individual's rights or coverage, certify product conformity, authorize a disclosure, or replace legal, privacy, security, clinical, or implementation review. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.