The promise of seamless health information exchange across the United States has long been within reach, fueled by advancements in technology. Yet, despite the increasing capacity to connect patients and providers nationwide, a significant hurdle remains: trust. It’s not a matter of technological capability, but rather the complex interplay of human and institutional factors that are slowing the widespread adoption of interoperability. This challenge is at the heart of the implementation of the Trusted Exchange Framework and Common Agreement (TEFCA), a national initiative designed to establish a universal floor for health information exchange.
TEFCA operates within a “policy triangle,” balancing the permissions granted by the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, the expectations set by information blocking regulations, and the obligations defined by the TEFCA framework itself. HIPAA permits, but doesn’t require, sharing for treatment purposes. Information blocking regulations, stemming from the 21st Century Cures Act, shift the expectation towards proactive sharing of electronic health information. TEFCA, through its Common Agreement for Qualified Health Information Networks (QHINs) and Terms of Participation for all other participants, establishes clear requirements for data exchange. Still, even with these layers of policy, progress is hampered by what experts describe as “stranger danger” and “interpretative drift.”
The Challenge of Trust at Scale
TEFCA’s core ambition is to scale connectivity nationwide by fostering trust between parties that have never directly exchanged health information. This requires a shared understanding of key definitions and rigorous processes for network entry. Participants must invest in upfront work to ensure alignment and security. The TEFCA directory infrastructure includes safeguards to prevent unauthorized queries, and its governance structure provides mechanisms for identifying and addressing potential misuse of exchanged data. Despite these protections, the sheer scale of TEFCA inevitably leads participants to scrutinize the identities and intentions of those they are interacting with – the “strangers” to whom they are responding.
As of February 22, 2026, more than 60,000 locations are connected through TEFCA, demonstrating significant progress. The Sequoia Project’s TEFCA map provides a visual representation of this growing network. However, maintaining momentum requires addressing the underlying trust issues that impede seamless data flow.
Navigating the Nuances of “Treatment”
A seemingly straightforward principle – that any HIPAA-covered health care provider participating in TEFCA should be able to query another for treatment purposes and expect a response – is proving surprisingly complex. Representatives from QHINs, Participants, and Subparticipants are currently grappling with decades of differing interpretations surrounding the definition of “treatment” and who qualifies as a “health care provider” under HIPAA. These subtle variations in interpretation can significantly impact perceived risk and, willingness to participate in data exchange.
The crux of the issue lies in situations where a requester justifies a treatment query, but the responder, accountable under HIPAA for its disclosures, disagrees that the request falls within the definition of “treatment.” This disagreement creates an impasse, halting the exchange of vital information. For example, differing interpretations might arise regarding the scope of “treatment” to include preventative care, wellness programs, or coordination of care across different specialties.
Efforts to achieve interpretative consensus are underway, led by private sector colleagues involved in TEFCA’s implementation. Disciplined onboarding processes, coupled with fair auditing and dispute resolution mechanisms, are seen as crucial steps towards realizing TEFCA’s full potential. The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) plays a vital role in enforcing HIPAA regulations and investigating potential breaches, as demonstrated by their recent settlement with Cadia Healthcare Facilities regarding the disclosure of protected health information. This settlement, announced by HHS.gov, underscores the importance of adhering to HIPAA guidelines and protecting patient privacy.
The Role of Information Blocking
The 21st Century Cures Act introduced information blocking provisions, aiming to promote interoperability by discouraging practices that limit access to health information. These regulations, implemented by the Office of the National Coordinator for Health Information Technology (ONC), build upon the foundation laid by HIPAA and TEFCA. Information blocking is defined as practices that, except for reasonable and necessary activities, would likely prevent the exchange of health information. While the intent is to encourage sharing, the definition of “reasonable and necessary” can be subject to interpretation, adding another layer of complexity to the trust equation.
The interplay between HIPAA, information blocking regulations, and TEFCA creates a dynamic landscape for health information exchange. Successfully navigating this landscape requires a commitment to clarity, consistency, and collaboration among all stakeholders.
Looking Ahead: Machine Learning and Risk Assessment
Innovative technologies, such as machine learning, are emerging as potential tools to address the challenges of legal risk assessment in internet healthcare. Researchers are exploring the use of machine learning algorithms to analyze HIPAA data and identify potential compliance issues. A recent study published in Nature highlights the potential of these algorithms to streamline the risk assessment process and improve compliance with HIPAA regulations.
However, it’s crucial to recognize that technology alone cannot solve the trust deficit. Machine learning can assist in identifying potential risks, but it cannot replace the need for human judgment, ethical considerations, and a shared commitment to protecting patient privacy. The implementation of machine learning solutions must be carefully monitored to ensure fairness, transparency, and accountability.
Maryland’s New Data Privacy Act
The evolving landscape of data privacy is further underscored by new legislation like Maryland’s Online Data Privacy Act. As reported by Baker Donelson, this act introduces sweeping protections for consumer health data and has significant implications for healthcare providers, life sciences companies, and those utilizing artificial intelligence in healthcare. The act’s focus on data minimization, purpose limitation, and individual rights reflects a growing societal concern about the responsible use of health information.
The success of TEFCA, and the broader goal of nationwide health information interoperability, hinges on building and maintaining trust. This requires not only robust technical infrastructure and clear regulatory frameworks, but also a cultural shift towards greater transparency, collaboration, and a shared commitment to protecting patient privacy. The ongoing dialogue and refinement of interpretative guidelines, combined with the adoption of innovative technologies and a proactive approach to risk management, will be essential to overcoming the remaining hurdles and realizing the full benefits of a connected healthcare ecosystem.
The next key milestone for TEFCA will be the continued expansion of network participation and the ongoing refinement of its governance structure. Stakeholders are encouraged to stay informed about updates and participate in the ongoing discussions shaping the future of health information exchange. Share your thoughts and experiences in the comments below – your input is valuable as we work towards a more connected and interoperable healthcare system.
Worth a look