Interoperability, essentially the ability of different technologies to speak with one another, is a key concept in the advancement of modernized digital health information exchange across a variety of health-related settings nationwide. Health information systems in part use health information technology (IT), a broad category of tools that may encompass electronic health records (EHRs), patient portals, medical imaging, and remote patient monitoring. Health IT may be used in a variety of ways in health-related settings, from underpinning individual patient care to population health improvement efforts such as disease tracking.
Interoperable health IT can potentially allow for the rapid, seamless, and secure exchange of authorized digital health information between parties without special effort on the part of those exchanging it. Ultimately, a system of interoperable health IT may create an infrastructure that supports a learning health system. In a learning health system, a single longitudinal record of a patient's care over the course of their lifetime can follow them from provider to provider, state to state. Such a system allows continuous learning cycles that can produce innovative knowledge that in turn improves health outcomes.
Many offices and operating divisions within the U.S. Department of Health and Human Services (HHS) collaborate to further digital health information interoperability efforts, including primarily the Office of the National Coordinator for Health Information Technology (ONC) and the Centers for Medicare & Medicaid Services. Multiple other HHS actors, such as the Centers for Disease Control and Prevention and the Office of Inspector General, serve roles as well.
Digital health information interoperability in the United States is a long-term initiative spanning multiple decades. Modern digital health information interoperability has been advanced by a variety of laws and regulations building upon one another. In tandem with other supporting efforts, at least five laws and 18 regulations (either proposed or final) have largely shaped the present state of digital health information interoperability nationwide.
As goals for interoperability become more expansive and complex, in part due to technological innovations, federal actors have continued to face barriers slowing health information exchange at the national level. Because interoperability relies on intersecting efforts, barriers to developing it may compound one another.
This report focuses primarily on digital health information interoperability through the lens of ONC efforts to promote interoperability among EHRs, consistent with historical HHS interoperability efforts.
Interoperability is a key concept in the advancement of modernized digital health information exchange across a variety of health-related settings. Statutorily defined as the "ability of two or more health information systems or components to exchange clinical and other information and to use the information that has been exchanged using common standards," interoperability is intended "to provide access to longitudinal information for health care providers in order to facilitate coordinated care and improved patient outcomes."1 Health information technology (IT) is a broad category of technology that encompasses "hardware, software, integrated technologies or related licenses, intellectual property, upgrades, or packaged solutions sold as services that are designed for or support the use by health care entities or patients for the electronic creation, maintenance, access, or exchange of health information."2
Within the context of health IT in particular, interoperability is in part statutorily defined as health IT that "enables the secure exchange of electronic health information with, and use of electronic health information from, other health information technology without special effort on the part of the user" and "allows for complete access, exchange, and use of all electronically accessible health information for authorized use."3 Health IT may be used in various ways in health-related settings, from underpinning individual patient care to population health improvement efforts such as disease tracking.4 Examples of health IT include electronic health records (EHRs), patient portals, medical imaging, and remote patient monitoring.5
This report focuses primarily on interoperability in the context of EHRs, consistent with specific historical U.S. Department of Health and Human Service (HHS) interoperability efforts. Essentially, EHRs are computerized versions of patients' paper charts that, in part due to their digital format, allow for actions and capabilities in health-related settings that exceed traditional paper records. One of the defining features of EHRs is that they can be managed by authorized providers and staff across multiple locations, potentially creating a centralized, standardized record for patients. EHRs can contain a variety of patient information (e.g., medical history, allergies, test results). Apart from storing information, EHRs can offer tools that help providers make decisions about patient care, automate workflow, oversee the accuracy of entered patient information, and adapt to changing payer and patient needs.6
This report provides an overview of selected federal actors and policy developments, including both laws and regulations related to digital health information interoperability, as well as selected barriers to interoperability and related legislative considerations.
Fully interoperable health IT may allow for the rapid, seamless, and secure exchange of authorized digital health information between parties without special effort on the part of those exchanging it. Ultimately, a system of interoperable health IT can create an infrastructure that supports a learning health system, or "an ecosystem where all stakeholders can securely, effectively, and efficiently contribute, share and analyze data" (see Figure 1).7 Such a system may allow for continuous learning cycles that can produce innovative knowledge that in turn could improve health outcomes.8 Parties involved in a learning health system may include stakeholders in clinical and public health settings, laboratories, researchers, and community-based organizations, among others.9 To achieve this type of system, multiple components (e.g., EHRs, health information exchanges [HIEs]/health information networks [HINs]) and efforts (e.g., health IT standardization) must build upon one another and work in tandem at many organizational levels (e.g., medical institutions, local governments, federal agencies).
Using health IT (and EHRs in particular) rather than nondigital processes or paper health records in a health care setting such as a provider's medical practice can give patients greater control over their care and health information, allowing them to access it whenever they wish and potentially add to it or flag corrections.10 Additionally, many EHRs have the capability to assist providers with patient care decisionmaking, potentially reducing errors during patient care and speeding its delivery.11
At a higher level, interoperable EHRs may be exchanged through HIEs/HINs. An HIE/HIN is an entity that "determines, controls, or has the discretion to administer any requirement, policy, or agreement that permits, enables, or requires the use of any technology or services for access, exchange, or use of electronic health information" between unaffiliated parties for purposes of treatment, payment, or health care operations.12 HIEs/HINs may vary in size; for example, they may operate and connect different parties (health care providers, public health professionals, and patients) at a local, regional, or larger level. While the term HIE may refer to an entity, it is also used to refer to the act of exchanging electronic health information among parties, often including those who participate in HIE/HIN organizations.13 The interoperable exchange of standardized digital health information can offer myriad benefits, including enhanced care coordination and communication between different providers, improved patient safety and reduced errors during care, increased efficiency and reduced costs in health care nationally, improved public and population health management, and patient empowerment and engagement in their own care.14
When standardized electronic health information is exchanged at a national level (often facilitated by interconnected HINs/HIEs) across different health care domains, a learning health system may be achieved. As envisioned by the Office of the National Coordinator for Health Information Technology (ONC), in a learning health system, a single longitudinal record of a patient's care over the course of their lifetime can follow them from provider to provider, state to state.15 Such a system could allow for the integration of data from a variety of sources, including EHRs, wearables, and other medical devices.16 A fully interoperable health IT infrastructure could also potentially facilitate public health functions such as disaster response and higher quality research and value-based payment practices through better data aggregation.17 More high-quality research could in turn inform better clinical guidelines, more targeted public health policy, and customized individual patient care.18 Such a learning health system could, ONC asserts, lower health care costs, improve population health, empower consumers, and drive innovation.19
|
Source: Adapted by CRS from ONC, Connecting Health and Care for the Nation: A 10-Year Vision to Achieve an Interoperable Health IT Infrastructure, June 2014, p. 2, https://healthit.gov/wp-content/uploads/2017/07/ONC10yearInteroperabilityConceptPaper.pdf. Notes: IT = information technology. |
While a fully interoperable health IT system may offer many benefits, the process of realizing such a system is ongoing. Over the years, barriers to a fully interoperable health IT system have persisted, including deficits in funding, expertise, technical support, and trust across the health care continuum.20
Many offices and operating divisions within HHS collaborate to further digital health information interoperability efforts, including primarily ONC21 and the Centers for Medicare & Medicaid Services (CMS). Multiple other HHS actors, such as the Centers for Disease Control and Prevention (CDC) and the Office of Inspector General (OIG) serve roles as well.
ONC is a staff division within the HHS Office of the Secretary that leads and coordinates digital health information interoperability efforts nationwide.22 More generally, ONC is tasked with advancing health IT policy, standards, and certification to support better health care and lower costs.23 ONC's mission is to systemically improve the American people's health "through the access, exchange, and use of data."24
The National Health Information Technology Coordinator position was initially established by Executive Order 13335 in 2004 "to provide leadership for the development and nationwide implementation of an interoperable health information technology infrastructure to improve the quality and efficiency of health care."25 Thereafter, the Office for the National Coordinator for Health Information Technology was legislatively mandated by the Health Information Technology for Economic and Clinical Health (HITECH) Act (P.L. 111-5) in 2009.26 ONC's duties were further augmented and amended by the Medicare Access and CHIP Reauthorization Act (MACRA; P.L. 114-10) in 2015 and the 21st Century Cures Act (Cures Act; P.L. 114-255) in 2016.27 Under MACRA, ONC was delegated the task of promoting EHR system interoperability. Under the Cures Act, additional key ONC initiatives and powers were authorized, including the creation of a network-to-network exchange of health information via the Trusted Exchange Framework and Common Agreement (TEFCA).28
CMS is an operating division within HHS that oversees programs that provide health coverage to over 160 million individuals through Medicare, Medicaid, the Children's Health Insurance Program (CHIP) and the Health Insurance Marketplace.29 CMS has been active in federal digital health information interoperability efforts, often working in tandem with ONC. CMS envisions that interoperability can empower patients and providers by enabling the secure exchange, access, and use of digital health information, thus leading to more efficient and effective health care.30
In 2009, the HITECH Act provided CMS with financial resources to incentivize and guide the development and adoption of a nationwide health IT infrastructure.31 Thereafter, in 2011, CMS initiated the Medicare and Medicaid EHR Incentive Programs, which provided incentive payments to eligible professionals and hospitals that adopted and demonstrated meaningful use of certified EHR technologies (CEHRT).32 Under MACRA in 2015, the Medicare EHR Incentive Program for eligible professionals was directed to sunset at the close of 2018, with similar provisions folded into a newly created quality program.33 However, the Medicare EHR Incentive Program continued for eligible hospitals, though it and the Medicaid EHR Incentive Program were renamed the Medicare and Medicaid Promoting Interoperability Programs in April 2018.34 At the close of 2021, the Medicaid Promoting Interoperability Program ended.35 The Medicare Promoting Interoperability Program continues for eligible hospitals as of the writing of this report. In addition to the promoting interoperability programs, CMS has worked with federal partners on various interoperability initiatives.36 For example, in 2010, CMS first launched its Blue Button Initiative, an online tool that allowed Medicare beneficiaries to access and download their digital health information.37 In 2012, leadership of the Blue Button Initiative was passed to ONC.38
On May 16, 2025, CMS and ONC published a request for information (RFI) "regarding the market of digital health products for Medicare beneficiaries as well as the state of data interoperability and broader health technology infrastructure," with comments due by June 16, 2025.39 On July 30, 2025, during a White House "Make Health Tech Great Again" event hosted with CMS, CMS announced its Health Tech Ecosystem initiative, which seeks to "modernize the nation's digital health ecosystem with a focus on empowering Medicare beneficiaries through greater access to innovative health technology."40 As a part of this initiative, CMS has called upon the health care industry "to voluntarily align around a shared framework for data and access that empowers people, improves care, and accelerates progress."41 Subsequently, CMS released its Interoperability Framework, which outlines the criteria for data sharing principles and the types of entities that may participate in it.42 In April 2026, it also launched its related Medicare App Library, a directory of "vetted digital health care options" that meet Health Tech Ecosystem interoperability expectations and focus on several specified use cases.43
A variety of other offices and programs within HHS collaborate on interoperability efforts as well. For example, CDC works with ONC to advance public health data interoperability.44 This effort is intended to ensure that public health data can be seamlessly shared across the country, thus enabling better preparation for, and responses to, health threats such as pandemics. To this end, CDC and ONC are working on establishing consistent system requirements across the public health sector and accelerating data modernization efforts.45
In turn, OIG, a unit within HHS responsible for independent oversight of the agency, has promulgated and enforces a rule establishing civil money penalties for certain parties that knowingly engage in "any practice that is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information" (i.e., information blocking).46 OIG performs this work in close collaboration with ONC to facilitate digital health information interoperability.
Digital health information interoperability in the United States is a long-term initiative spanning multiple decades. Modern digital health information interoperability has been underpinned by various laws and regulations building upon one another. In tandem with other supporting efforts, five laws and 18 regulations (either proposed or final) have largely shaped the present state of digital health information interoperability.
Legislation regarding digital health information interoperability has advanced it incrementally since 1996. Congress began by requiring the establishment of foundational standards for electronic record keeping and claims processing, then progressed to establishing ONC and encouraging the adoption of health IT. Thereafter, efforts focused on developing a regulatory framework and promoting active exchange and use of health IT. Most recently, enacted law has required measures to support truly seamless and secure digital health information interoperability on a national scale.
In an initial step toward promoting health IT, and subsequently digital health information interoperability, Congress enacted HIPAA (P.L. 104-191). HIPAA was enacted primarily to "improve the availability and continuity of health insurance coverage; promote long-term care insurance and the use of health savings accounts; and combat waste, fraud, and abuse, particularly in Medicare and Medicaid." 47 People are generally most familiar with HIPAA in the context of its Privacy, Security, and Breach Notification Rules.48 However, the Privacy and Security Rules were promulgated pursuant to HIPAA's "Administrative Simplification" subtitle.49 This subtitle generally required the HHS Secretary "to develop standards supporting the growth of electronic record keeping and claims processing."50 HIPAA's "Administrative Simplification" subtitle, in combination with its subsequent Privacy and Security Rules, "helped lay the groundwork for the development of a National Health Information Network and the widespread adoption of interoperable EHRs."51
Following HIPAA, Congress enacted the HITECH Act in 2009.52 The HITECH Act contains provisions "intended to promote the widespread adoption of … [health IT] to support the electronic sharing of clinical data among hospitals, physicians, and other health care stakeholders."53 Broadly, the HITECH Act addresses the promotion of health IT, the testing of health IT, grants and loans funding, efforts relating to the privacy of protected health information, and Medicaid and Medicare incentives for the adoption and meaningful use of CEHRT, among other things.
To promote health IT, the HITECH Act formally established the Office of the National Coordinator for Health Information Technology (originally ONCHIT), to be headed by the National Coordinator, who was tasked with supporting the "development of a nationwide health information technology infrastructure that allows for the electronic use and exchange of information."54 Additionally, the HITECH Act created the HIT Policy Committee ("to make policy recommendations to the National Coordinator related to the implementation of a nationwide health information technology infrastructure") and the HIT Standards Committee ("to recommend to the National Coordinator standards, implementation specifications, and certification criteria for the electronic exchange and use of health information").55 The HITECH Act also articulates the goal of "utilization of an electronic health record for each person in the United States by 2014."56 The HITECH Act authorized the creation of a voluntary certification program for health IT to be run by ONC, in consultation with the Director of the National Institute of Standards and Technology (NIST).57 Furthermore, the HITECH Act includes various study and report writing requirements.58
Regarding the testing of health IT, the HITECH Act in part tasked the Director of NIST with testing standards and implementation specifications developed, harmonized, or recognized by the HIT Standards Committee.59 The HITECH Act also authorized funding for various grants and loans (including for extension centers and demonstration programs) to, among other things, strengthen health IT infrastructure, aid in health IT implementation, promote health IT, facilitate the widespread adoption of CEHRT, and support health IT-related education for health professionals and certain students.60 Related to the privacy of protected health information, the HITECH Act also, in part, expanded protections, applying certain HIPAA security and privacy provisions to business associates (in addition to covered entities) and directing the HHS Secretary to promulgate the Breach Notification Rule.61
In addition, in relation to incentivizing the adoption and meaningful use of CEHRT among eligible professionals and hospitals, the HITECH Act in part also authorized what became the Medicare and Medicaid EHR Incentive Programs (for rates of EHR adoption for nonfederal acute care hospitals and office-based physicians, see Figure 2 and Figure 3, respectively).62
| Figure 2. Nonfederal Acute Care Hospital EHR Adoption, 2008-2024 Figure is interactive in HTML report version. |
||
| <script type="text/javascript">//Revised to update theme, 9/23/2026
$(function () {
$('#IAG-93530678').bind('mousedown', function () { /* saveRptHighChartClick(); */ });
//##### CRS THEME CODE START #####//
//##### CRS Highcharts Theme v1.3 (9/23/2026) #####//
const fontFamily = 'system-ui, -apple-system, Segoe UI, Roboto, "Helvetica Neue", Arial, "Noto Sans", "Liberation Sans", sans-serif';
Highcharts.setOptions({
colors: ['#0C90FC', '#003865', '#F1B434', '#7060A8', '#6CC8BD', '#757048', '#B4C7D0', '#D36127'],
chart: {
backgroundColor: 'white',
style: {
fontFamily
}
},
title: {
style: {
color: 'black',
fontSize: '14px',
fontWeight: 'bold',
fontFamily
} },
subtitle: { style: {
color: 'black',
fontSize: '12.5px',
fontFamily
}},
credits: { enabled: false },
legend: {
verticalAlign: 'top',
itemMarginBottom: 7,
itemStyle: {
color: 'black',
fontFamily,
fontSize: '12.5px',
textDecoration: 'none'
}
},
xAxis: {
title: {
style: {
fontWeight: 'bold',
color: 'black',
fontFamily,
fontSize: '12.5px'
},
y: 8
},
labels: {
style: {
color: 'black',
fontFamily,
fontSize: '12.5px'
}
},
lineColor: 'black',
lineWidth: 0.5
},
yAxis: {
title: {
style: {
fontWeight: 'bold',
color: 'black',
fontFamily,
fontSize: '12.5px'
}
},
labels: {
style: {
color: 'black',
fontFamily,
fontSize: '12.5px'
}
}
},
tooltip: {
headerFormat: '{point.key} ', style: { color: 'black', fontFamily, fontSize: '12.5px' }, //borderColor: undefined, }, annotations: { labelOptions: { shape: 'rect', backgroundColor: 'transparent', borderWidth: 0, style: { color: 'black', fontFamily, fontSize: '12.5px' } } }, caption: { style: { fontFamily: fontFamily, fontSize: '12.5px', color: 'black' } }, plotOptions: { series: { dataLabels: { style: { fontFamily, fontSize: '12.5px' } } } }, lang: {thousandsSep: ',' }, credits: { enabled: false}, exporting: { enabled: false} }); //##### CRS THEME CODE END #####// //#### HIGHCHART LIBRARIES ####// var files = ["https://code.highcharts.com/highcharts.js", "https://code.highcharts.com/modules/series-label.js","https://code.highcharts.com/modules/exporting.js", "https://code.highcharts.com/highcharts-more.js","https://code.highcharts.com/modules/accessibility.js"], loaded = 0; if (typeof window["HighchartsEditor"] === "undefined") { window.HighchartsEditor = { ondone: [cl], hasWrapped: false, hasLoaded: false }; include(files[0]); } else { if (window.HighchartsEditor.hasLoaded) { cl(); } else { window.HighchartsEditor.ondone.push(cl); } } function isScriptAlreadyIncluded(src) { var scripts = document.getElementsByTagName("script"); for (var i = 0; i < scripts.length; i++) { if (scripts[i].hasAttribute("src")) { if ((scripts[i].getAttribute("src") || "").indexOf(src) >= 0 || (scripts[i].getAttribute("src") === "http://code.highcharts.com/highcharts.js" && src === "https://code.highcharts.com/stock/highstock.js")) { return true; } } } return false; } function check() { if (loaded === files.length) { for (var i = 0; i < window.HighchartsEditor.ondone.length; i++) { try { window.HighchartsEditor.ondone[i](); } catch (e) { console.error(e); } } window.HighchartsEditor.hasLoaded = true; } } function include(script) { function next() { ++loaded; if (loaded < files.length) { include(files[loaded]); } check(); } if (isScriptAlreadyIncluded(script)) { return next(); } var sc = document.createElement("script"); sc.src = script; sc.type = "text/javascript"; sc.onload = function () { next(); }; document.head.appendChild(sc); } function each(a, fn) { if (typeof a.forEach !== "undefined") { a.forEach(fn); } else { for (var i = 0; i < a.length; i++) { if (fn) { fn(a[i]); } } } } var inc = {}, incl = []; each(document.querySelectorAll("script"), function (t) { inc[t.src.substr(0, t.src.indexOf("?"))] = 1; }); function cl() { if (typeof window["Highcharts"] !== "undefined") { //#### HIGHCHART LIBRARIES END ####// //#### START chart elements before Highcharts container ####// //#### END chart elements before the Highcharts container ####// var options = { //#### START code inside Highcharts.chart('container', { ####// title: { text: null }, accessibility: { description: 'A line graph showing the percentages of non-federal acute care hospitals from 2008 to 2024' }, subtitle: { text: null }, yAxis: { min: 0, max: 100, title: { text: 'Percent of Non-Federal Acute Care Hospitals', rotation: -89.9 }, labels: { format: '{value}%' } }, xAxis: { tickInterval: 1, labels: { formatter: function() { return '' + this.value; }, }, categories: [ '2008', '2010', '2012', '2014', '2016', '2018', '2020', '2022', '2024' ], tickLength: 8, tickWidth: 1, crosshair: true }, legend:{ enabled: true, layout: 'horizontal', align: 'center' }, plotOptions: { series: { lineWidth: 2, connectNulls: true, label: { enabled: false, connectorAllowed: false, style: { fontSize: '17px' } }, marker: { enabled: true, symbol: 'circle', radius: 4 }, } }, tooltip: { shared: true, useHTML: true, headerFormat: '{point.key}' + '', pointFormatter: function () { // Hide Any EHR at 2012 if ( this.series.name === 'Any EHR' && this.point.category === '2012' ) { return ''; } const value = this.y === 0 ? '0' : this.y.toFixed(1) + '%'; return ( '' + '' + '' + '' ); }, footerFormat: '
|
||
|
Source: Adapted by CRS from ONC, Non-Federal Acute Care Hospital Electronic Health Record Adoption, 2008-2024, Data Brief No. 83, June 2026, https://healthit.gov/data/data-briefs/non-federal-acute-care-hospital-electronic-health-record-adoption-2008-2024/. Notes: EHR = electronic health record. "Any EHR" refers to hospitals that reported using "fully electronic" or "partially electronic" systems to record patient health information. "Partially electronic" means the hospital used electronic and paper methods; "fully electronic" means the hospital used only electronic methods. "Certified EHR" refers to hospitals possessing EHR technologies that meet the "technological capability, functionality, and security requirements adopted by [HHS]." |
| Figure 3. Office-Based Physician EHR Adoption, 2008-2024 Figure is interactive in HTML report version. |
||
| <script type="text/javascript">//Revised to update theme, 9/23/2026
$(function () {
$('#IAG-2401546986').bind('mousedown', function () { /* saveRptHighChartClick(); */ });
//##### CRS THEME CODE START #####//
//##### CRS Highcharts Theme v1.3 (9/23/2026) #####//
const fontFamily = 'system-ui, -apple-system, Segoe UI, Roboto, "Helvetica Neue", Arial, "Noto Sans", "Liberation Sans", sans-serif';
Highcharts.setOptions({
colors: ['#0C90FC', '#003865', '#F1B434', '#7060A8', '#6CC8BD', '#757048', '#B4C7D0', '#D36127'],
chart: {
backgroundColor: 'white',
style: {
fontFamily
}
},
title: {
style: {
color: 'black',
fontSize: '14px',
fontWeight: 'bold',
fontFamily
} },
subtitle: { style: {
color: 'black',
fontSize: '12.5px',
fontFamily
}},
credits: { enabled: false },
legend: {
verticalAlign: 'top',
itemMarginBottom: 7,
itemStyle: {
color: 'black',
fontFamily,
fontSize: '12.5px',
textDecoration: 'none'
}
},
xAxis: {
title: {
style: {
fontWeight: 'bold',
color: 'black',
fontFamily,
fontSize: '12.5px'
},
y: 8
},
labels: {
style: {
color: 'black',
fontFamily,
fontSize: '12.5px'
}
},
lineColor: 'black',
lineWidth: 0.5
},
yAxis: {
title: {
style: {
fontWeight: 'bold',
color: 'black',
fontFamily,
fontSize: '12.5px'
}
},
labels: {
style: {
color: 'black',
fontFamily,
fontSize: '12.5px'
}
}
},
tooltip: {
headerFormat: '{point.key} ', style: { color: 'black', fontFamily, fontSize: '12.5px' }, //borderColor: undefined, }, annotations: { labelOptions: { shape: 'rect', backgroundColor: 'transparent', borderWidth: 0, style: { color: 'black', fontFamily, fontSize: '12.5px' } } }, caption: { style: { fontFamily: fontFamily, fontSize: '12.5px', color: 'black' } }, plotOptions: { series: { dataLabels: { style: { fontFamily, fontSize: '12.5px' } } } }, lang: {thousandsSep: ',' }, credits: { enabled: false}, exporting: { enabled: false} }); //##### CRS THEME CODE END #####// //#### HIGHCHART LIBRARIES ####// var files = ["https://code.highcharts.com/highcharts.js","https://code.highcharts.com/highcharts-more.js","https://code.highcharts.com/modules/accessibility.js"], loaded = 0; if (typeof window["HighchartsEditor"] === "undefined") { window.HighchartsEditor = { ondone: [cl], hasWrapped: false, hasLoaded: false }; include(files[0]); } else { if (window.HighchartsEditor.hasLoaded) { cl(); } else { window.HighchartsEditor.ondone.push(cl); } } function isScriptAlreadyIncluded(src) { var scripts = document.getElementsByTagName("script"); for (var i = 0; i < scripts.length; i++) { if (scripts[i].hasAttribute("src")) { if ((scripts[i].getAttribute("src") || "").indexOf(src) >= 0 || (scripts[i].getAttribute("src") === "http://code.highcharts.com/highcharts.js" && src === "https://code.highcharts.com/stock/highstock.js")) { return true; } } } return false; } function check() { if (loaded === files.length) { for (var i = 0; i < window.HighchartsEditor.ondone.length; i++) { try { window.HighchartsEditor.ondone[i](); } catch (e) { console.error(e); } } window.HighchartsEditor.hasLoaded = true; } } function include(script) { function next() { ++loaded; if (loaded < files.length) { include(files[loaded]); } check(); } if (isScriptAlreadyIncluded(script)) { return next(); } var sc = document.createElement("script"); sc.src = script; sc.type = "text/javascript"; sc.onload = function () { next(); }; document.head.appendChild(sc); } function each(a, fn) { if (typeof a.forEach !== "undefined") { a.forEach(fn); } else { for (var i = 0; i < a.length; i++) { if (fn) { fn(a[i]); } } } } var inc = {}, incl = []; each(document.querySelectorAll("script"), function (t) { inc[t.src.substr(0, t.src.indexOf("?"))] = 1; }); function cl() { if (typeof window["Highcharts"] !== "undefined") { //#### HIGHCHART LIBRARIES END ####// //#### START chart elements before Highcharts container ####// //#### END chart elements before the Highcharts container ####// var options = { //#### START code inside Highcharts.chart('container', { ####// title: { text: null }, accessibility: { description: 'A line graph showing the percentage of office-based physicians within any EHR and Certified EHR categories from 2008 thru 2024.' }, subtitle: { text: null }, yAxis: { min: 0, max: 100, title: { text: 'Percent of Office-Based Physicians', rotation: -89.9 }, labels: { format: '{value}%' } }, xAxis: { tickInterval: 1, labels: { formatter: function() { return '' + this.value; }, }, categories: [ '2008', '2010', '2012', '2014', '2016', '2018', '2020', '2022', '2024' ], tickLength: 8, tickWidth: 1, crosshair: true }, legend:{ enabled: true, layout: 'horizontal', align: 'center' }, plotOptions: { series: { lineWidth: 2, connectNulls: true, label: { enabled: false, connectorAllowed: false, style: { fontSize: '17px' } }, marker: { enabled: true, symbol: 'circle', radius: 4 }, } }, tooltip: { shared: true, useHTML: true, headerFormat: '{point.key}', pointFormatter: function () { const value = this.y === 0 ? '0' : this.y.toFixed(1) + '%'; return ''; }, footerFormat: '
|
||
|
Source: Adapted by CRS from ONC, Office-Based Physician Electronic Health Record Adoption, 2008-2024, Data Brief No. 84, June 2026, https://healthit.gov/data/data-briefs/office-based-physician-electronic-health-record-adoption-2008-2024/. Notes: EHR = electronic health record. "Any EHR" refers to "any non-billing electronic system used to document patient care." "Certified EHR" refers to "an EHR that is certified to meet [HHS] health IT certification requirements." |
Section 618 of FDASIA directed the Commissioner of the Food and Drug Administration (FDA), in consultation with the National Coordinator of ONC and the Chairman of the Federal Communications Commission (FCC), to publish on each organization's website a report on a proposed strategy and recommendations for a risk-based health IT regulatory framework that "promotes innovation, protects patient safety, and avoids regulatory duplication."63 Pursuant to this, the HIT Policy Committee convened a FDASIA workgroup and issued recommendations to the enumerated organizations.64 A report for public comment fulfilling this requirement was published in April 2014.65 The proposed strategy and recommendations in the report are predicated on the assumption that "risk and corresponding controls should focus on health IT functionality," not on a particular technology platform type, in part to "advance a framework that is relevant to current functionalities and technologies yet sufficiently flexible to accommodate the future and rapid evolution of health IT."66
In 2015, MACRA directed, among other things, that the Medicare EHR Incentive Program for eligible professionals be transitioned from a standalone initiative to a component of a new CMS initiative: the Quality Payment Program (QPP).67 The QPP provides Medicare clinicians with increased reimbursement payments for high-value, high-quality care, while lowering reimbursement payments for clinicians who do not achieve certain performance standards.68 Clinicians participating in QPP may choose between two tracks, based on various factors: the Advanced Alternative Payment Models (APMs) or the Merit-based Incentive Payment System (MIPS).69 Under MACRA, the Medicare EHR Incentive Program for eligible professionals was adapted to become one of four MIPS performance categories, which are evaluated together to determine a participating clinician's reimbursement payment.70
Additionally, a MACRA provision states that "Congress declares it a national objective to achieve widespread exchange of health information through interoperable certified EHR technology nationwide by December 31, 2018," marking a shift from focus on EHR adoption to more active data exchange and use.71 To this end, MACRA required the HHS Secretary to devise metrics to measure the progress of achieving the widespread exchange of health information through interoperable CEHRT nationwide, noting that if this objective was not met by the close of 2018, the HHS Secretary must submit a report to Congress by the close of 2019 identifying barriers and recommendations for accomplishing it.72
In 2016, under parts of Title IV ("Delivery") of the Cures Act, the HHS Secretary was tasked with implementing multiple provisions intended to improve interoperability, prevent information blocking, and enhance the usability, accessibility, privacy, and security of health IT.73
First, the Cures Act directed the HHS Secretary to establish a goal for reducing regulatory and administrative burdens related to EHRs and to develop a strategy and recommendations to accomplish this goal.74 Next, the Cures Act directed ONC to encourage the voluntary certification of health IT in specified medical specialties and sites of service that lacked such technologies and to develop voluntary certification criteria suited to health IT used by pediatric health providers.75 The Cures Act also required the HHS Secretary to submit a report to ONC regarding Medicare and Medicaid EHR Incentive Programs statistics to facilitate standards adoption and associated practices.76
Second, the Cures Act directed the HHS Secretary to promulgate a rule requiring health IT developers, as a condition of certification and maintenance of certification, to attest that they are (1) not impeding the proper flow of information regarding health IT and electronic health information (i.e., information blocking), (2) publishing application programming interfaces (APIs) for various uses, and (3) successfully testing the real world applications of interoperability technologies in their intended marketing settings.77 Additionally, the Cures Act established certain Medicare EHR payment adjustment hardship exceptions for hospitals and eligible professionals whose EHR technologies had been decertified, and for eligible professionals eligible for merit-based incentive payments.78 Furthermore, the Cures Act established an EHR reporting program, informed by relevant stakeholders, to transparently report on the performance of CEHRTs.79 As a condition of maintaining certification for their EHR products, developers must report on measures pertaining to their certified product's security, usability, and interoperability, among other things.80
Third, the Cures Act defined interoperability in the context of health IT and directed the National Coordinator, in collaboration with others, to support the full network-to-network exchange of health information via the establishment of a voluntary trusted exchange framework and common agreement among HINs nationally.81 Next, the Cures Act directed the HHS Secretary to create a digital directory for health professionals and health facilities so that providers could be contacted and health information could be exchanged.82 Additionally, the Cures Act combined the HIT Standards Committee and HIT Policy Committee created under the HITECH Act into one body: the Health Information Technology Advisory Committee (HITAC).83 Generally, HITAC is tasked with "recommend[ing] to the National Coordinator … policies, and … standards, implementation specifications, and certification criteria, relating to the implementation of a health information technology infrastructure, nationally and locally, that advances the electronic access, exchange, and use of health information."84
Fourth, the Cures Act defined and prohibited information blocking, subject to certain exceptions that the HHS Secretary was tasked with outlining in regulation.85 The Cures Act also granted the HHS Office of Inspector General (OIG) authority to investigate claims of information blocking.86 If OIG determines health IT developers, HINs, or HIEs engaged in information blocking, civil money penalties are authorized.87 If OIG determines providers engaged in information blocking, OIG must refer the provider to the appropriate agency for the application of appropriate disincentives, as outlined by the HHS Secretary in rulemaking.88 Additionally, the Cures Act directed the National Coordinator, in consultation with the Office for Civil Rights (OCR), to issue guidance on common barriers to the trusted exchange of electronic health information, and allowed for the National Coordinator and OCR to refer instances of refusing to exchange health information under certain circumstances to OIG.89 ONC is directed to share information regarding claims and investigations with OIG, and is allowed to share such information with the Federal Trade Commission (FTC).90 ONC is also tasked with creating a process for the public to report on issues with interoperability and information blocking.91
Fifth, the Cures Act required certified EHRs be able to transmit data to (and where applicable, accept data from) registries, including clinician-led clinical data registries, that have also been certified as capable of receiving and accepting data from (and where applicable, transmitting data to) certified EHRs.92 The Cures Act also applied federal privilege and confidentiality protections for certain information reported to patient safety organizations to health IT developers who report and conduct patient safety activities related to the improvement of clinical care through the use of health IT.93
Sixth, the Cures Act required the HHS Secretary to encourage partnerships between HIEs, networks, health care providers, health plans, and other appropriate entities to offer "patients access to their electronic health information in a single, longitudinal format that is easy to understand, secure, and may be updated automatically."94 Additionally, the HHS Secretary, coordinating with OCR, must educate health care providers regarding the use of HIEs and similar platforms to provide patients with access to their electronic health information.95 In turn, the HHS Secretary, in coordination with OCR, must issue guidance to educate HIEs about best practices for providing patients with such data.96 The Cures Act also tasked the National Coordinator and OCR with promoting patient access to health information in a user-friendly format. OCR, in consultation with the National Coordinator, is directed to educate different parties regarding patients' rights to access and protect personal health information under HIPAA as well. ONC is also allowed to leverage certification criteria, standards, and implementation specifications to support patients' access to their electronic health information.97
Finally, the Cures Act required the Government Accountability Office (GAO) study and write reports on two separate topics: (1) patient matching and (2) patient access to health information.98
Numerous regulations have been promulgated to advance digital health information interoperability. HHS offices and operating divisions, particularly ONC and CMS, have focused on developing the ONC Health IT Certification Program (the Certification Program) and incentive programs under CMS. More recently, regulations have emphasized advancing interoperability through addressing barriers, such as information blocking, and by encouraging the use of more advanced technological tools, including APIs and artificial intelligence (AI).
Pursuant to the authorization of the Certification Program by the HITECH Act, ONC promulgated the Temporary Certification Program for Health IT Final Rule on June 24, 2010.99 Under authority granted to ONC via the Public Health Service Act (PHSA), Section 3001(c)(5), as added by the HITECH Act, this rule established a temporary program to authorize organizations to test and certify complete EHRs and EHR modules.100 A temporary program was created so that professionals and hospitals eligible for the Medicare and Medicaid EHR Incentive Programs would have CEHRT available in time to demonstrate meaningful use under the start of the incentive programs, thus allowing them to qualify for incentive payments.101
Promulgated on July 28, 2010, by CMS, the Medicare and Medicaid Programs; EHR Incentive Program Final Rule set forth parameters and requirements for the programs, including the initial criteria eligible professionals and hospitals would need to meet to demonstrate meaningful use, and thus qualify for incentive payments.102 This final rule outlined that meaningful use of certified EHR technology would be defined and implemented in a phased approach, with criteria for meeting meaningful use becoming more robust over time.103 This rule predicted a total of three stages for meaningful use demonstration under the programs.104 Thus, this final rule outlined meaningful use criteria for Stage 1, beginning in 2011, which focused on
electronically capturing health information in a structured format; using that information to track key clinical conditions and communicating that information for care coordination purposes…; implementing clinical decision support tools to facilitate disease and medication management; using EHRs to engage patients and families and reporting clinical quality measures and public health information.105
On July 28, 2010, ONC promulgated the Health IT: Initial Set of Standards, Implementation Specifications, and Certification Criteria for EHR Technology Final Rule.106 This final rule completed the adoption of an initial set of requirements for CEHRT, additionally harmonizing these requirements with the meaningful use Stage 1 objectives and measures outlined in CMS's Medicare and Medicaid Program; EHR Incentive Program Final Rule.107
On January 7, 2011, ONC promulgated the Establishment of the Permanent Certification Program for Health IT Final Rule.108 This final rule established a permanent health IT certification program under ONC, intended to take the place of the temporary health IT certification program established in ONC's Temporary Certification Program for Health IT Final Rule.109 While the temporary certification program focused on authorizing organizations to certify technologies such as complete EHRs and EHR modules, this final rule noted that the final certification program may focus on authorizing organizations to certify additional types of health IT as well.110
On September 4, 2012, CMS promulgated the Medicare and Medicaid Programs; EHR Incentive Program-Stage 2 Final Rule.111 This final rule laid out requirements for eligible professionals and hospitals participating in the Medicare and Medicaid EHR Incentive Programs to demonstrate meaningful use under Stage 2 of the programs, beginning in 2014.112 The final rule also outlined downward payment adjustments for eligible entities participating in the programs that failed to demonstrate meaningful use of CEHRT.113 This final rule made several revisions to meaningful use Stage 1 criteria as well.114
ONC promulgated the 2015 Edition Final Rule on October 16, 2015.115 This rule finalized a new edition of certification requirements and a definition for 2015 Edition Base EHR.116 It also modified the Certification Program to encompass more types of health IT.117 The 2015 Edition requirements established the minimum capabilities, standards, and implementation specifications CEHRT needed to meet to support meaningful use by eligible professionals and hospitals under the Medicare and Medicaid EHR Incentive Programs upon the 2015 Edition's implementation in these programs.118
The EHR Incentive Programs Stage 3 and Modifications Final Rule was issued by CMS on October 16, 2015.119 This final rule outlined requirements that eligible professionals and eligible hospitals needed to meet to qualify for incentive payments under the Medicare and Medicaid EHR Incentive Programs and avoid downward payment adjustments under the Medicare EHR Incentive Program.120 It also removed reporting requirements for clinical quality measures that were no longer relevant to the programs.121 Additionally, the final rule laid out requirements for demonstrating meaningful use under Stage 3, set to be optional for participants in 2017 and then mandatory in 2018.122
ONC promulgated the Certification Program Final Rule on October 19, 2016.123 This final rule modified and added new requirements to the ONC Health IT Certification Program, including providing ONC with a regulatory framework for directly reviewing certified health IT and taking oversight actions when necessary.124 The final rule also put in place measures for ONC to directly authorize and oversee accredited testing laboratories under the program and for greater public transparency of certified health IT surveillance results.125
ONC promulgated the Cures Act Final Rule on May 1, 2020, intended to advance interoperability and support the access, exchange, and use of electronic health information.126 To that end, the final rule implemented certain provisions of the Cures Act, including (1) Conditions and Maintenance of Certification requirements for health IT developers under the Certification Program, (2) the voluntary certification of health IT for pediatric care settings, and (3) a description of reasonable and necessary activities that do not constitute information blocking (i.e., exceptions to information blocking).127 The final rule also contained certain modifications to the 2015 Edition health IT certification criteria and Certification Program.128 Additionally, the final rule established API requirements, in part to enable patients' access to their health information without special effort.129
On May 1, 2020, CMS promulgated the Interoperability and Patient Access Final Rule, meant to increase access to health information and support interoperability.130 The final rule requires that certain CMS-regulated payers implement and maintain a Patient Access API. This API is to be secure and standards-based, allowing patients easy access through applications of their choice to their data, including pertaining to claims, encounters, and clinical information.131 Additionally, the final rule stipulates that certain CMS-regulated payers implement and maintain a Provider Directory API. This API is to be standards-based and publicly display provider directory information, including provider names, addresses, phone numbers, and specialties.132 The final rule requires that CMS-regulated payers exchange specified patient clinical data at a patient's request, enabling patients to carry their data with them from payer to payer (payer-to-payer data exchange).133 The final rule also increased the frequency of certain data sharing between states and CMS and initiated the public reporting of specified parties who may be information blocking or not sharing updated digital contact information.134
OIG promulgated the Information Blocking CMP Final Rule on July 3, 2023.135 Among other things, this final rule, as required by the Cures Act, implemented CMPs for certain parties (including certified health IT developers, those offering certified health IT, and HIEs/HINs) whom OIG investigated and found to be engaged in information blocking.136 The final rule also outlined OIG's risk-based enforcement approach to allegations of information blocking, in consultation with ONC and other agencies, as appropriate.137
On January 9, 2024, ONC promulgated the HTI-1 Final Rule, the first in a series of final rules specifically focused on health data, technology, and interoperability (HTI).138 This final rule introduced the Insights Condition and Maintenance of Certification, thus implementing the EHR Reporting Program provision of the Cures Act.139 It also updated multiple certification criteria and standards under the program, including a revised "decision support interventions" criterion (to increase algorithm transparency) and the adoption of a new baseline version of the United States Core Data for Interoperability (USCDI) standard.140 Additionally, the final rule revised certain measures and definitions related to information blocking to better support appropriate information sharing.141
CMS promulgated the Advancing Interoperability and Improving Prior Authorization Final Rule on February 8, 2024, intended to improve the electronic exchange of health care data and streamline prior authorization processes.142 This final rule in part requires that certain payers add select information about prior authorization to the data available on the Patient Access API (initially required under the 2020 Advancing Interoperability and Patient Access Final Rule).143 Payers required to have a Patient Access API must also begin reporting on usage metrics to CMS under this final rule. Furthermore, this final rule requires that certain payers implement a Provider Access API. This API is to facilitate the sharing of specified patient data, including some prior authorization information, with appropriate in-network providers.144 Additionally, this final rule requires that certain payers establish Payer-to-Payer APIs. This API is meant to make available specified patient data within the past five years between payers to improve care continuity when a patient changes payers.145 The Payer-to-Payer API is also intended to enable continued patient access to their own data.146 The final rule also requires that certain payers make available a Prior Authorization API. This API is to contain a list of a payer's covered items and services and prior authorization documentation requirements.147 Providers will be able to view this information, which is intended to alleviate administrative burden.148 The final rule also requires specified measures to improve the prior authorization process generally; for example, certain payers must send providers notices when they make a prior authorization decision, including specific reasons for request denials.149
On July 1, 2024, CMS and ONC promulgated the Disincentives Final Rule.150 This final rule implements the Cures Act provision requiring that health care providers found to be information blocking be subject to appropriate disincentives.151 Specifically, this final rule establishes that certain health care providers (who are also Medicare-enrolled providers or suppliers) found to be information blocking by OIG be subject to specified disincentives, including financial penalties under several CMS programs.152 It also details the process through which OIG investigates information blocking claims and refers violative providers to appropriate agencies for disincentives.153 Additionally, this final rule establishes a process to notify the public of providers and other health care actors found to be information blocking by OIG.154
ONC promulgated the HTI-2 Final Rule on December 16, 2024.155 This final rule implements certain provisions of the Cures Act related to TEFCA, especially as it pertains to qualified HINs (QHINs), to increase transparency, reliability, privacy, security, and trust.156 Additionally, this final rule codifies certain TEFCA-related definitions into information blocking regulations.157 The final rule also makes several administrative updates and corrections to the Certification Program.158
On December 17, 2024, ONC promulgated the HTI-3 Final Rule.159 This final rule revises two existing exceptions to information blocking and creates a new one: the Protecting Care Access Exception.160 The Protecting Care Access Exception allows actors, under certain circumstances, to withhold information if they have a good faith belief that the information sought could expose persons seeking, obtaining, providing, or facilitating lawful reproductive health care to legal action based purely upon the fact that they sought, obtained, provided, or facilitated lawful reproductive health care.161
ONC promulgated the HTI-4 Final Rule on August 4, 2025, as a component of a larger CMS final rule.162 The HTI-4 Final Rule adds and revises multiple Certification Program certification criteria and related standards pertaining to electronic prescribing, real-time prescription benefit checks, electronic prior authorization, and API functionality.163
On December 29, 2025, ONC promulgated the HTI-5 Proposed Rule.164 This rule proposes to remove 34 and revise 7 of the 60 certification criteria under the Certification Program, in order to decrease the administrative burden and costs for health IT developers and clinicians and to better support the adoption of a Fast Healthcare Interoperability Resources (FHIR)-based API ecosystem.165 In some cases, ONC proposes that the removal or revision of certification criteria may be accompanied by the removal of associated standards; for example, reducing the scope of the "decision support interventions" certification criterion introduced by HTI-1.166 Additionally, ONC proposes removing and descoping measures associated with the Insights Condition and Maintenance of Certification requirements under HTI-1.167 The proposed rule states that revisions to the information blocking provisions are being considered to make clear that autonomous systems, including AI, may access, exchange, and use electronic health information.168 The proposed rule also contemplates removing or revising multiple information blocking exceptions to prevent misuse.169
Barriers to the interoperability of digital health information are manifold and complex. Specific barriers encountered may depend on which parties and use cases are involved, among other factors. Regardless, stakeholders have identified several cross-cutting themes that Congress may consider:
These selected issues are discussed in greater detail below, along with potential considerations facing policymakers.170
Within the health care ecosystem, certain subsectors, specialties, and institutions have not advanced uniformly in their adoption of interoperability.
For example, public health subsector data have historically been siloed from health care, in part because public health systems rely on outdated health IT and nonstandardized data.171 A facet of these issues is examined in ONC's June 2026 data brief about the flow of public health reporting from health care providers to public health agencies (PHAs), as enabled by state, local, and regional health information organizations (HIOs), which may also offer data support services to PHAs.172 The data brief drew information from the 2025 National Survey of Health Information Organizations, to which 76 HIOs responded.173 HIOs play a key role in facilitating the bidirectional exchange of public health data between health care providers and PHAs, and many HIOs receive data from PHAs in turn.174 While a majority of HIOs surveyed reported being at least somewhat prepared to support PHAs in future public health emergencies, many reported both major and minor perceived barriers to PHA connectivity.175 Major barriers to PHA connectivity included the perception that PHAs had other priorities, lacked funding, and were unable to receive or process messages.176 Minor barriers to PHA connectivity included the perception that PHAs lacked necessary staffing, required data use agreements, and faced technical limitations.177 Furthermore, HIOs reported that many PHAs relied on less efficient means of information exchange, including accessing data for patients individually via portals rather than through standards-based APIs capable of simultaneously exchanging information for multiple patients.178 The brief notes that such barriers may hinder HIOs' abilities to effectively support PHAs during future public health emergencies.179
As another example, behavioral health settings lag behind other medical settings in the adoption and use of interoperable health IT. Behavioral health facilities typically have less access to modern health IT than nonfederal acute care hospitals, largely because the HITECH Act did not provide incentive payments to substance use and mental health treatment facilities to adopt and use certified EHRs.180 In an April 2026 ONC data brief, ONC drew on data from the 2024 National Substance Use and Mental Health Services Survey and found that, while the majority of behavioral health facilities use EHRs to record patient information, actual exchange of this data is more limited among such facilities.181 According to ONC, barriers to health information exchange in behavioral health settings may include technical, workforce, cost, and privacy concerns.182 Additionally, the data indicated that 19% of such surveyed facilities reported participating in an HIE, while 67% reported having no knowledge of an HIE in their service area.183 ONC found that facilities participating in HIEs were more likely to actively search for patient health information.184
Other factors may influence interoperability at the institutional level as well. For example, smaller, rural, and independent hospitals and providers tend to experience greater barriers to interoperability compared with other hospitals and providers.185 These discrepancies are often attributed to greater financial and technological resource restraints on such hospitals and providers, complicating the adoption and maintenance of interoperable technologies and subsequent health information exchange.186
Across the care continuum, barriers to interoperability related to uneven adoption and use of health IT include a lack of funding, expertise, and technical support. To address uneven adoption and use of interoperable health IT across the health care continuum, Congress may consider asking ONC how Congress may best support health information exchange initiatives such as TEFCA. Additionally, Congress may consider increasing funding and support for efforts related to bolstering the health IT work force and expanding technical support for interoperability to health care actors, especially in areas of health care that have historically lagged in adoption and use of interoperable health IT. Congress may also choose not to act and allow ONC and related agencies to continue existing regulatory work.
Information blocking is defined as a "practice that except as required by law or covered by an exception … is likely to interfere with access, exchange, or use of electronic health information" when committed by a health IT developer of certified health IT, HINs/HIEs, and health care providers.187 There are currently 10 exceptions to information blocking, as defined in rulemaking.188 These current exceptions broadly fall into three categories: exceptions that involve not fulfilling requests to access, exchange, or use of electronic health information; exceptions that involve procedures for fulfilling requests to access, exchange, or use electronic health information; and exceptions that involve practices related to actors' participation in TEFCA.189 If the conditions of one of these exceptions are met, an actor who withholds electronic health information will not have committed information blocking. ONC has made a concerted effort to combat information blocking.190 Those who believe they have been subject to information blocking may submit a claim to ONC via its online Report Information Blocking Portal (Portal).191 Once a claim of information blocking has been received by ONC, it is shared with OIG for investigation. If an actor is found to have committed information blocking, they may be subject to CMPs or referred to the appropriate agencies for disincentives application, as outlined in rulemaking.192
Despite these measures, information blocking continues to be a significant barrier to digital health information interoperability. In a June 2026 data brief, ONC examined levels of information blocking as perceived by HIOs between 2019 and 2025.193 The brief notes that "because HIOs enable interoperable exchange between healthcare organizations, they are uniquely positioned to directly observe and share their insights on various practices that they perceive to be possible information blocking, including practices of developers of certified health IT, health care providers, and other networks."194 The brief's findings indicate that mechanisms for information blocking may depend on the actor involved.195 For example, the data showed that developers and providers, according to HIOs, seemingly relied on specific business, market, or other organizational constructs to justify perceived information blocking.196 Regarding developers, HIOs most commonly reported pricing and unreasonable fees as means of information blocking.197 In turn, HIOs reported that hospitals and health systems tended to cite strategic affiliations, such as organization and ownership structures, to justify perceived information blocking.198 However, the findings do show that while most HIOs report possible information blocking, the practice seems to be limited to a small number of actors.199 Developers of certified health IT were the actors most commonly reported by HIOs.200
In a separate July 2026 data report, ONC analyzed claims of information blocking submitted to the portal since April 5, 2021.201 In total, ONC received 2,389 submissions through the portal.202 Of these submissions, 110 did not appear to be claims of potential information blocking (e.g., they were submissions asking general policy questions), leaving 2,279 possible claims of information blocking.203 The majority of claims to the portal were submitted by patients alleging information blocking by other actors.204 Overall, most submissions claiming information blocking were filed about health care providers.205
Information blocking may occur in good and bad faith. Many health care stakeholders report confusion regarding how information blocking and its exceptions apply, especially as they intersect with HIPAA requirements.206 This confusion can further complicate other interoperability initiatives such as TEFCA. To address information blocking, Congress may consider clarifying language in the HIPAA Privacy Rule, directing ONC to produce additional educational materials for stakeholders regarding what constitutes information blocking and how to report it, or directing ONC to further broaden information blocking disincentives to more actors, including providers who do not participate in CMS programs. Additionally, in past years, ONC has requested authority from Congress to issue binding advisory opinions in advance on whether certain scenarios, as submitted by requesters, would constitute information blocking.207 At this time, ONC lacks such authority. Congress may also choose not to act and allow ONC and related agencies to continue existing efforts.
TEFCA is an ONC initiative meant to de-silo the exchange of health information data on a nationwide scale. It seeks to create a nationwide "network-of-networks" for health information exchange under which all participants adhere to a universal floor for interoperability (i.e., all participants must meet common requirements).208 TEFCA comprises three documents: the Common Agreement (a legal contract signed by participating entities, known as qualified health information networks [QHINs]), the Trusted Exchange Framework (a document that defines the principles, standards, and specifications underlying TEFCA), and the QHIN Technical Framework (a document that focuses on technical requirements for exchange among QHINs and other participants).209 ONC contracts with a Recognized Coordinating Entity (RCE, currently the Sequoia Project) to oversee and provide a governing approach for participant QHINs.210 QHINs are HINs that have voluntarily applied, been onboarded, and designated as able to exchange information under TEFCA. They must also have signed the Common Agreement. At the time of this report's publication, there are 11 designated QHINs under TEFCA that may exchange information with one another.211 Each of these designated QHINs have an existing network of participants (some of which in turn have subparticipants) of their own that they bring with them into TEFCA (see Figure 4).212 Entities connected through this network-of-networks may include health apps and technology vendors, federal agencies, HIEs/HINs, health plans and other payers, individuals (including patients), providers, and public health agencies, among others.213 There are currently six authorized reasons (with the possibility that more will be added in future), or exchange purposes, for which data may be securely shared or requested through TEFCA: government benefits determination, health care operations, individual access services, payment, public health, and treatment.214
|
Source: Adapted by CRS from ONC, Trusted Exchange Framework and Common Agreement (TEFCA), November 2023, p. 1, https://healthit.gov/wp-content/uploads/2023/11/TEFCA_2-Pager_Digital_508.pdf. Notes: ONC = Office of the National Coordinator for Health Information Technology; RCE = Recognized Coordinating Entity; QHIN = qualified health information network. |
TEFCA officially went live in December 2023.215 Since its launch, rates of participation have been of great interest given the initiative's voluntary nature and the need for widespread buy-in across the health care ecosystem for it to succeed. On June 26, 2026, HHS announced that more than 1 billion health records had been exchanged through TEFCA.216 The Sequoia Project, at the time of this report's publication, cited more than 21,000 organizations live on TEFCA.217 Despite the current adoption and use of TEFCA, the goal of nationwide interoperability has been impeded by what some perceive as a lack of trust among organizations.218 TEFCA policies intersect with those related to information blocking and the HIPAA Privacy Rule.219 Interpretive differences regarding language in HIPAA have led some organizations to be wary of sharing information across TEFCA, a rationale similarly cited in some cases of perceived information blocking.220 In addition, a lack of trust has led some TEFCA organizations to question what others in TEFCA are doing with the information that has been exchanged. For example, in January 2026, one QHIN (Epic) sued another (Health Gorilla), alleging it had inappropriately allowed other companies to access and monetize patient medical records exchanged in part through TEFCA.221
On June 11, 2026, the House Committee on Appropriations published a report to accompany H.R. 9260.222 In it, the House Committee on Appropriations expressed support for ONC using resources to "vet organizations seeking to join TEFCA."223 According to the report, "this vetting should include, but is not limited to, strengthening eligibility verification procedures for applications, reviewing publicly available business descriptions, implementing ongoing compliance monitoring and auditing mechanisms, and coordinating with other Federal agencies, as appropriate, to assess security and fraud risks."224
In the same June 26, 2026, press release that announced over 1 billion health records shared via TEFCA, HHS announced new actions taken by ONC to strengthen the security of TEFCA.225 Specifically, the press release stated that "ONC has awarded a new contract to strengthen oversight of the network and verify that organizations participating in TEFCA follow required policies and procedures. ONC is also conducting additional reviews of … QHINs … and their participants to help ensure compliance with TEFCA's rules and operating requirements."226 The contract was awarded to Alliance Global Tech, Inc. (AGT), for audit, review, and compliance support services, with the contract slated to last from June 25, 2026, to June 24, 2027.227
Stakeholders in TEFCA have asserted that the greatest barriers to the initiative are not technological but, rather, related to trust.228 To address these barriers, Congress may consider supporting efforts to unify interpretations of the HIPAA rules among parties involved in TEFCA, as well as with information blocking regulations and requirements under TEFCA; requiring ONC publish a report with an implementation plan for greater oversight and auditing of organizations participating in TEFCA; or pursuing measures to mitigate information blocking. Congress may also choose not to act and allow ONC and its contractors to further develop existing efforts.
Tension has long existed between efforts to modernize the regulation of health IT and efforts to deregulate it. In 2010, ONC launched its voluntary Certification Program.229 Under the Certification Program, organizations authorized by ONC test health IT products (voluntarily presented by health IT developers) for conformity with various standards and certification criteria and certify health IT as meeting those requirements.230 These standards and certification criteria facilitate interoperability between the health IT products certified under the program. Though the Certification Program is voluntary, participants in certain CMS programs are required to use EHRs certified under the program. This incentivizes health care settings to preferentially adopt certified EHRs, which in turn incentivizes health IT developers to have their health IT products certified. The various requirements and certification criteria that health IT products must meet under the Certification Program are set by ONC via rulemaking.231 This rulemaking also sets requirements for health IT developers voluntarily participating in the Certification Program.232 Once a health IT product has been certified, it is listed on the CHPL website, an authoritative, comprehensive compilation of tested and certified health IT under the Certification Program that is updated at least once a week.233 Under the Certification Program, there are also Conditions and Maintenance of Certification requirements. These reflect initial and ongoing requirements that health IT developers and certified health IT products must meet, even after initial certification is granted.234
To ensure continued conformance with the Certification Program, ongoing surveillance of health IT is conducted after certification.235 If a certified health IT product is found to no longer meet the Certification Program's requirements, that product is considered nonconformant.236 Developers of a nonconformant product must subsequently submit a corrective action plan (CAP) to correct deficiencies identified. If these deficiencies are not corrected, the product's certification may be suspended or withdrawn.237 Such steps are also reported on the CHPL website.238 Under certain circumstances, ONC will sometimes directly review certified health IT, including for potential nonconformities.239 If, during a direct ONC review, nonconformities are identified, a health IT developer may submit a CAP; if issues are not addressed, ONC may suspend or terminate relevant health IT certifications or issue a certification ban on the responsible health IT developer.240 Banned health IT developers are also listed on the CHPL website.241
Though the Certification Program is iteratively updated, there have been concerns that it lags relative to current and emerging technologies. Additionally, some health IT developers have alleged that the current Certification Program process is too burdensome.242 Recently, the HTI-5 Proposed Rule suggested deregulatory actions related to the Certification Program.243 Under the Certification Program, there are currently 60 certification criteria.244 Certification criteria describe outcome-focused, functional requirements for health IT.245 These certification criteria pertain to, and are grouped under, the following categories: clinical, care coordination, clinical quality measures, privacy and security, patient engagement, public health, design and performance, transport methods and other protocols, and modular API capabilities.246 Among other things, the HTI-5 Proposed Rule suggests removing 34 of the current certification criteria and revising seven to decrease burden and costs for health IT developers and clinicians and to better support the adoption of a FHIR-based API ecosystem.247 The rule also proposes to revise or remove measures or requirements for several of the Conditions and Maintenance of Certification requirements under the Certification Program.248 Furthermore, it proposes the revision or removal of multiple information blocking exceptions or associated conditions.249 In the HTI-5 Proposed Rule, ONC explains that these proposed revisions are anticipated to be responsive to public feedback regarding flaws in the current Certification Program, account for current and future technologies, streamline redundant requirements, and promote health IT innovation.250 Public comment on, and reactions to, the proposed rule have been mixed. Generally, stakeholders seem supportive of goals to reduce burden and modernize the Certification Program.251 However, some stakeholders feel that deregulation is premature and, rather than modernizing the Certification Program, increases confusion around it.252 These stakeholders often suggest keeping and modernizing many of the current certification criteria (especially those related to privacy, security, and AI transparency) rather than eliminating them.253 A number of stakeholders have also expressed interest in a phased, clear approach to implementing the measures proposed, both to reduce confusion and avoid inadvertently shifting regulatory burden.254
Currently, the Certification Program is a fundamental building block for nationwide interoperability efforts. To address possible confusion and concerns regarding revisions to it, Congress may consider supporting deregulatory efforts or modernization through revision of existing requirements. Additionally, Congress may consider directing ONC to accompany upcoming rules altering the Certification Program with implementation plans to smooth transitions. Congress may also consider requiring ONC to publish impact assessments for specified certification criteria (especially those related to privacy, security, and AI transparency) if they are eliminated from the Certification Program to gauge whether congressional goals are met in their absence. Alternatively, Congress may choose not to act and allow ONC to continue existing regulatory work regarding the Certification Program at its discretion.
The interoperability of digital health information has evolved over time. From its beginning in 1996 with HIPAA to ongoing rulemaking efforts through the present, this effort has been advanced by numerous federal actors. As goals for interoperability become more expansive and complex, in part due to technological innovations, federal actors have continued to combat barriers slowing health information exchange at the national level. The nature of barriers to digital health information interoperability may compound one another. For example, uneven adoption and use of health IT may lead to information blocking, which may in turn disrupt TEFCA. Implementing nationwide digital health information interoperability faces critical barriers, including potential deficits in funding, expertise, technical support, and trust across the health care continuum.
|
AGT |
Alliance Global Tech, Inc. |
|
API |
Application programming interface |
|
ASTP |
Assistant Secretary for Technology Policy |
|
CDC |
Centers for Disease Control and Prevention |
|
CEHRT |
Certified EHR technologies |
|
CHIP |
Children's Health Insurance Program |
|
CMP |
Civil money penalty |
|
CMS |
Centers for Medicare & Medicaid Services |
|
EHR |
Electronic health record |
|
FDA |
Food and Drug Administration |
|
FDASIA |
Food and Drug Administration Safety and Innovation Act of 2012 |
|
FHIR |
Fast Healthcare Interoperability Resources |
|
GAO |
Government Accountability Office |
|
HHS |
U.S. Department of Health and Human Services |
|
HIE |
Health information exchange |
|
HIN |
Health information network |
|
HIO |
Health information organization |
|
HIPAA |
Health Insurance Portability and Accountability Act of 1996 |
|
HITAC |
Health Information Technology Advisory Committee |
|
HITECH |
Health Information Technology for Economic and Clinical Health |
|
HTI |
Health data, technology, and interoperability |
|
IT |
Information technology |
|
MACRA |
Medicare Access and CHIP Reauthorization Act |
|
MIPS |
Merit-based Incentive Payment System |
|
OCR |
Office for Civil Rights |
|
OIG |
Office of Inspector General |
|
ONC |
Office of the National Coordinator for Health Information Technology |
|
PHA |
Public health agency |
|
PHSA |
Public Health Service Act |
|
QHIN |
Qualified health information network |
|
QPP |
Quality Payment Program |
|
RCE |
Recognized Coordinating Entity |
|
TEFCA |
Trusted Exchange Framework and Common Agreement |
|
USCDI |
United States Core Data for Interoperability |
| 1. |
Medicare Access and CHIP Reauthorization Act of 2015 (MACRA; P.L. 114-10) §106(b)(1)(B)(ii). |
| 2. |
Public Health Service Act (PHSA) §3000(5), as added by the Health Information Technology for Economic and Clinical Health Act (HITECH Act; P.L. 111-5) §13101. |
| 3. |
PHSA §3000(9), as added by the 21st Century Cures Act (Cures Act; P.L. 114-255) §4003(a)(2). |
| 4. |
Office of the National Coordinator for Health Information Technology (ONC), 2020-2025 Federal Health IT Strategic Plan, October 2020, p. 6, https://web.archive.org/web/20250204003626/https://www.healthit.gov/sites/default/files/page/2020-10/Federal%20Health%20IT%20Strategic%20Plan_2020_2025.pdf. |
| 5. |
ONC, "Benefits of Health IT," April 1, 2026, https://healthit.gov/health-it-basics/benefits-health-it/. |
| 6. |
ONC, "Electronic Health Records and Their Benefits," December 10, 2025, https://healthit.gov/health-it-basics/benefits-ehrs/. |
| 7. |
ONC, Connecting Health and Care for the Nation: A Shared Nationwide Interoperability Roadmap (Final Version 1.0), October 2015, p. xi, https://healthit.gov/wp-content/uploads/2017/07/nationwide-interoperability-roadmap-final-version-1.0.pdf. |
| 8. |
ONC, Connecting Health and Care for the Nation: A Shared Roadmap. |
| 9. |
ONC, Connecting Health and Care for the Nation: A Shared Roadmap. |
| 10. |
ONC, "Electronic Health Records and Their Benefits." |
| 11. |
ONC, "Electronic Health Records and Their Benefits." |
| 12. |
45 C.F.R. §171.102. |
| 13. |
ONC, "About Health Information Exchange," April 22, 2026, https://healthit.gov/health-it-basics/hie/. |
| 14. |
ONC, "Health Information Exchange Benefits," December 10, 2025, https://healthit.gov/health-it-basics/hie-benefits/. |
| 15. |
ONC, Connecting Health and Care for the Nation: A Shared Roadmap, p. vi. |
| 16. |
ONC, Connecting Health and Care for the Nation: A 10-Year Vision to Achieve an Interoperable Health IT Infrastructure, June 2014, p. 7, https://healthit.gov/wp-content/uploads/2017/07/ONC10yearInteroperabilityConceptPaper.pdf. |
| 17. |
ONC, Connecting Health and Care for the Nation: A 10-Year Vision, p. 3. |
| 18. |
ONC, Connecting Health and Care for the Nation: A 10-Year Vision, p. 2. |
| 19. |
ONC, Connecting Health and Care for the Nation: A 10-Year Vision, p. 3. |
| 20. |
For a more in-depth discussion of these barriers, see the "Selected Policy Considerations" section. |
| 21. |
Due to several reorganizations, from July 2024 to March 2026, ONC was referred to as the Assistant Secretary for Technology Policy (ASTP)/ONC. HHS, HHS Reorganizes Technology, Cybersecurity, Data, and Artificial Intelligence Strategy and Policy Functions, July 25, 2024, https://www.hhs.gov/about/news/2024/07/25/hhs-reorganizes-technology-cybersecurity-data-artificial-intelligence-strategy-policy-functions.html; HHS, HHS Aligns Health Technology Leadership to Deliver Data Liquidity, Affordability, and an AI-Enabled Health Care System for Americans, March 31, 2026, https://www.hhs.gov/press-room/hhs-health-tech-leadership-deliver-data-liquidity-affordability-ai-enabled-health-care-system.html. |
| 22. |
ONC, "About ONC," June 17, 2026, https://healthit.gov/about/; ONC, "Interoperability," July 27, 2026, https://www.healthit.gov/topic/interoperability. |
| 23. |
ONC, "About ONC"; HHS, HHS Aligns Health Technology Leadership. |
| 24. |
ONC, "About ONC." |
| 25. |
Executive Order 13335 of April 27, 2004, "Incentives for the Use of Health Information Technology and Establishing the Position of the National Health Information Technology Coordinator," 69 Federal Register 24059, April 30, 2004, https://www.federalregister.gov/documents/2004/04/30/04-10024/incentives-for-the-use-of-health-information-technology-and-establishing-the-position-of-the. |
| 26. |
PHSA §3001, as added by the HITECH Act §13101. For more information about the HITECH Act, see the "HITECH Act" section. |
| 27. |
For more information regarding MACRA and the Cures Act, see the "MACRA" and "Cures Act" sections. |
| 28. |
Cures Act §4003(b). For more information about TEFCA, see the "TEFCA" section. |
| 29. |
CMS, "About Us," https://www.cms.gov/about-cms; HHS, Fiscal Year 2027 Centers for Medicare &Medicaid Services: Justification of Estimates for Appropriations Committees, p. 1, https://www.cms.gov/files/document/fy-2027-justification-estimates-appropriations-committees.pdf. |
| 30. |
CMS, "CMS Interoperability," March 16, 2026, https://www.cms.gov/priorities/key-initiatives/burden-reduction/interoperability/cms-interoperability. |
| 31. |
HITECH Act, Division B, Title IV, §4101, §4102, and §4201. |
| 32. |
CMS, "Promoting Interoperability Programs," November 24, 2025, https://www.cms.gov/medicare/regulations-guidance/promoting-interoperability-programs. For more information about the certification process for EHRs via the ONC Health IT Certification Program (Certification Program), see the "Lag in Governance" section. |
| 33. |
For more information on this quality program established under MACRA, see the "MACRA" section. |
| 34. |
CMS, "Promoting Interoperability Programs," July 1, 2024, https://web.archive.org/web/20240719111647/https://www.cms.gov/medicare/regulations-guidance/promoting-interoperability-programs. |
| 35. |
CMS, "Promoting Interoperability Programs," November 24, 2025. |
| 36. |
CMS, "Interoperability," July 29, 2025, https://www.cms.gov/priorities/burden-reduction/overview/interoperability. |
| 37. |
Aneesh Chopra, White House Office of Science and Technology Policy, "'Blue Button' Provides Access to Downloadable Personal Health Data," Latest News (blog), The White House, October 7, 2010, https://obamawhitehouse.archives.gov/blog/2010/10/07/blue-button-provides-access-downloadable-personal-health-data. |
| 38. |
Lygeia Ricciardi, "The Blue Button Movement: Kicking Off National Health IT Week with Consumer Engagement," September 12, 2013, https://www.healthit.gov/buzz-blog/consumer/blue-button-movement-kicking-national-health-week-consumer-engagement; ONC, "Blue Button, December 8, 2025, https://www.healthit.gov/topic/patient-access-information-individuals-get-it-check-it-use-it/blue-button. |
| 39. |
CMS, ONC, "Request for Information; Health Technology Ecosystem," 90 Federal Register 21034, May 16, 2025, https://www.govinfo.gov/content/pkg/FR-2025-05-16/pdf/2025-08701.pdf. |
| 40. |
CMS, "White House, Tech Leaders Commit to Create Patient-Centric Healthcare Ecosystem," press release, July 30, 2025, https://www.cms.gov/newsroom/press-releases/white-house-tech-leaders-commit-create-patient-centric-healthcare-ecosystem; CMS, "Health Technology Ecosystem," April 15, 2026, https://www.cms.gov/health-tech-ecosystem. |
| 41. |
CMS, "Health Technology Ecosystem." |
| 42. |
CMS, "Interoperability Framework," July 31, 2025, https://www.cms.gov/health-technology-ecosystem/interoperability-framework. |
| 43. |
CMS, "Medicare App Library," July 29, 2026, https://www.cms.gov/initiatives/health-technology-ecosystem/overview/medicare-app-library. |
| 44. |
CDC, "Public Health Data Interoperability," https://www.cdc.gov/data-interoperability/php/index.html; CDC, "About Public Health Data Interoperability," December 30, 2025, https://www.cdc.gov/data-interoperability/php/about/index.html. |
| 45. |
CDC, "About Public Health Data Interoperability." |
| 46. |
OIG, HHS-OIG Fiscal Year 2027 Justification of Estimates for Congress, pp. 6, 18, https://oig.hhs.gov/documents/budget/11569/FY_2027_CJ.pdf; OIG, "Grants, Contracts, and Other Agreements: Fraud and Abuse; Information Blocking; Office of Inspector General's Civil Money Penalty Rules," 88 Federal Register 42820, 42821, July 3, 2023, https://www.govinfo.gov/content/pkg/FR-2023-07-03/pdf/2023-13851.pdf. For more information about information blocking, see the "Information Blocking" section. |
| 47. |
CRS In Focus IF12759, The HIPAA Privacy Rule: Overview and Issues. |
| 48. |
For more information about the HIPAA rules, see CRS In Focus IF12759, The HIPAA Privacy Rule: Overview and Issues, and CRS In Focus IF12591, Cybersecurity and Digital Health Information (see "HIPAA Security Rule" and "HIPAA Breach Notification Rule" sections). |
| 49. |
P.L. 104-191, Title II, Subtitle F, §§261-264. For more information about "Administrative Simplification," see CRS In Focus IF12352, Office of the National Coordinator for Health Information Technology (ONC). |
| 50. |
CRS Report R40161, The Health Information Technology for Economic and Clinical Health (HITECH) Act. |
| 51. |
CRS Report R40161, The Health Information Technology for Economic and Clinical Health (HITECH) Act. |
| 52. |
The HITECH Act specifically is Title XIII of Division A and Title IV of Division B of P.L. 111-5. |
| 53. |
CRS Report R40161, The Health Information Technology for Economic and Clinical Health (HITECH) Act. |
| 54. |
PHSA §3001(b), as added by the HITECH Act, Division A, Title XIII, §13101. |
| 55. |
HITECH Act, Division A, Title XIII, §13101. |
| 56. |
PHSA §3001(c)(3)(A)(ii), as added by the HITECH Act, Division A, Title XIII, §13101. |
| 57. |
PHSA §3001(c)(5), as added by the HITECH Act, Division A, Title XIII, §13101. This later became the ONC Health IT Certification Program (the Certification Program). For more information about the Certification Program, see the "Lag in Governance" section. |
| 58. |
HITECH Act, Division A, Title XIII, §13113. |
| 59. |
HITECH Act, Division A, Title XIII, §13201. |
| 60. |
HITECH Act, Division A, Title XIII, §13301. |
| 61. |
HITECH Act, Division A, Title XIII, §13401, §13402(j), and §13404. |
| 62. |
HITECH Act, Division B, Title IV, §4101, §4102, and §4201. |
| 63. |
FDASIA §618(a). |
| 64. |
ONC, "Health IT Legislation," March 31, 2026, https://healthit.gov/legislation/. |
| 65. |
FDA, FCC, ONC, FDASIA Health IT Report: Proposed Strategy and Recommendations for a Risk-Based Framework, April 2014, https://healthit.gov/wp-content/uploads/2025/06/fdasiahealthitreport_final.pdf. |
| 66. |
FDA, FCC, ONC, FDASIA Health IT Report, p. 3. |
| 67. |
MACRA §101(b)(1). |
| 68. |
ONC, "Health IT Legislation." The QPP itself was launched in 2017. QPP, "About QPP," https://qpp.cms.gov/get-started/what-is-qpp/about-qpp. |
| 69. |
ONC, "Health IT Legislation"; CMS, "Quality Payment Program," September 10, 2024, https://www.cms.gov/medicare/quality/value-based-programs/quality-payment-program. |
| 70. |
MACRA §101(c). For a more information on MACRA §101 and the provision's background, see the "Section 101: Repealing the Sustainable Growth Rate and Improving Medicare Payment for Physicians' Services" section of CRS Report R43962, The Medicare Access and CHIP Reauthorization Act of 2015 (MACRA; P.L. 114-10). |
| 71. |
MACRA §106(b)(1)(A). |
| 72. |
MACRA §106(b)(1)(C) – (D). For more information on MACRA §106(b), see the "Section 106(b): Promoting Interoperability of Electronic Health Record Systems" section in CRS Report R43962, The Medicare Access and CHIP Reauthorization Act of 2015 (MACRA; P.L. 114-10). |
| 73. |
ONC, "Health IT Legislation." |
| 74. |
Cures Act §4001(a). |
| 75. |
Cures Act §4001(b). |
| 76. |
Cures Act §4001(c). |
| 77. |
Cures Act §4002(a). For more information regarding APIs, see ONC, The FHIR API, https://healthit.gov/wp-content/uploads/2021/04/FHIR-API-Fact-Sheet.pdf. |
| 78. |
Cures Act §4002(b). |
| 79. |
Cures Act §4002(c). |
| 80. |
Cures Act §4002(c). |
| 81. |
Cures Act §4003(a) – (b). |
| 82. |
Cures Act §4003(c). |
| 83. |
Cures Act §4003(e). |
| 84. |
Cures Act §4003(e). |
| 85. |
Cures Act §4004. For more information regarding information blocking, see the "Information Blocking" section. |
| 86. |
Cures Act §4004. |
| 87. |
Cures Act §4004. |
| 88. |
Cures Act §4004. |
| 89. |
Cures Act §4004. |
| 90. |
Cures Act §4004. |
| 91. |
Cures Act §4004. |
| 92. |
Cures Act §4005(a). |
| 93. |
Cures Act §4005(c). |
| 94. |
Cures Act §4006(a). |
| 95. |
Cures Act §4006(a). |
| 96. |
Cures Act §4006(a). |
| 97. |
Cures Act §4006(a). |
| 98. |
Cures Act §4007 and Cures Act §4008. For more information on Cures Act §§4001-4008, see the "Sections 4001-4008. Policies to Promote the Adoption and Use of EHR Technology" section in CRS Report R44720, The 21st Century Cures Act (Division A of P.L. 114-255). |
| 99. |
ONC, "Establishment of the Temporary Certification Program for Health Information Technology," 75 Federal Register 36158, June 24, 2010, https://www.govinfo.gov/content/pkg/FR-2010-06-24/pdf/2010-14999.pdf. |
| 100. |
ONC, "Temporary Certification Program for Health IT," 75 Federal Register 36158, 36158. |
| 101. |
ONC, "Temporary Certification Program for Health IT," 75 Federal Register 36158, 36158. |
| 102. |
CMS, "Medicare and Medicaid Programs; Electronic Health Record Incentive Program," 75 Federal Register 44314, July 28, 2010, https://www.govinfo.gov/content/pkg/FR-2010-07-28/pdf/2010-17207.pdf. |
| 103. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program," 75 Federal Register 44314, 44321. |
| 104. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program," 75 Federal Register 44314, 44321. |
| 105. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program," 75 Federal Register 44314, 44321; ONC, Connecting Health and Care for the Nation: A Shared Interoperability Roadmap - Final Version 1.0, 2015, p. vii, https://healthit.gov/wp-content/uploads/2017/07/nationwide-interoperability-roadmap-final-version-1.0.pdf. |
| 106. |
ONC, "Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology," 75 Federal Register 44590, July 28, 2010, https://www.govinfo.gov/content/pkg/FR-2010-07-28/pdf/2010-17210.pdf. |
| 107. |
ONC, "Health IT: Initial Set of Standards, Implementation Specifications, and Certification Criteria for EHR Technology," 75 Federal Register 44590, 44590. |
| 108. |
ONC, "Establishment of the Permanent Certification Program for Health Information Technology," 76 Federal Register 1262, January 7, 2011, https://www.govinfo.gov/content/pkg/FR-2011-01-07/pdf/2010-33174.pdf. |
| 109. |
ONC, "Establishment of the Permanent Certification Program for Health IT," 76 Federal Register 1262, 1262. |
| 110. |
ONC, "Establishment of the Permanent Certification Program for Health IT," 76 Federal Register 1262, 1262. |
| 111. |
CMS, "Medicare and Medicaid Programs; Electronic Health Record Incentive Program-Stage 2," 77 Federal Register 53968, September 4, 2012, https://www.govinfo.gov/content/pkg/FR-2012-09-04/pdf/2012-21050.pdf. |
| 112. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program-Stage 2," 77 Federal Register 53968, 53968, 53969. |
| 113. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program-Stage 2," 77 Federal Register 53968, 53968, 53969, 53970. |
| 114. |
CMS, "Medicare and Medicaid Programs; EHR Incentive Program-Stage 2," 77 Federal Register 53968, 53968. |
| 115. |
ONC, "2015 Edition Health Information Technology (Health IT) Certification Criteria, 2015 Edition Base Electronic Health Record (EHR) Definition, and ONC Health IT Certification Program Modifications," 80 Federal Register 62602, October 16, 2015, https://www.govinfo.gov/content/pkg/FR-2015-10-16/pdf/2015-25597.pdf. |
| 116. |
ONC, "2015 Edition," 80 Federal Register 62602, 62602. |
| 117. |
ONC, "2015 Edition," 80 Federal Register 62602, 62602. |
| 118. |
ONC, "2015 Edition," 80 Federal Register 62602, 62602. |
| 119. |
CMS, "Medicare and Medicaid Programs; Electronic Health Record Incentive Program-Stage 3 and Modifications to Meaningful Use in 2015 Through 2017," 80 Federal Register 62762, October 16, 2015, https://www.govinfo.gov/content/pkg/FR-2015-10-16/pdf/2015-25595.pdf. |
| 120. |
CMS, "EHR Incentive Programs Stage 3 and Modifications," 80 Federal Register 62762, 62762. |
| 121. |
CMS, "EHR Incentive Programs Stage 3 and Modifications," 80 Federal Register 62762, 62762. |
| 122. |
CMS, "EHR Incentive Programs Stage 3 and Modifications," 80 Federal Register 62762, 62762. |
| 123. |
ONC, "ONC Health IT Certification Program: Enhanced Oversight and Accountability," 81 Federal Register 72404, October 19, 2016, https://www.govinfo.gov/content/pkg/FR-2016-10-19/pdf/2016-24908.pdf. |
| 124. |
ONC, "Certification Program," 81 Federal Register 72404, 72404. |
| 125. |
ONC, "Certification Program," 81 Federal Register 72404, 72404. |
| 126. |
ONC, "21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program," 85 Federal Register 25642, May 1, 2020, https://www.govinfo.gov/content/pkg/FR-2020-05-01/pdf/2020-07419.pdf. |
| 127. |
ONC, "Cures Act," 85 Federal Register 25642, 25642. |
| 128. |
ONC, "Cures Act," 85 Federal Register 25642, 25642. |
| 129. |
ONC, "Cures Act," 85 Federal Register 25642, 25644. |
| 130. |
CMS, "Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Interoperability and Patient Access for Medicare Advantage Organization and Medicaid Managed Care Plans, State Medicaid Agencies, CHIP Agencies and CHIP Managed Care Entities, Issuers of Qualified Health Plans on the Federally-Facilitated Exchanges, and Health Care Providers," 85 Federal Register 25510, May 1, 2020, https://www.govinfo.gov/content/pkg/FR-2020-05-01/pdf/2020-05050.pdf. |
| 131. |
CMS, "Interoperability and Patient Access," 85 Federal Register 25510, 25513. |
| 132. |
CMS, "Interoperability and Patient Access," 85 Federal Register 25510, 25513. |
| 133. |
CMS, "Interoperability and Patient Access," 85 Federal Register 25510, 25513. |
| 134. |
CMS, "Interoperability and Patient Access," 85 Federal Register 25510, 25513, 25514. |
| 135. |
OIG, "Grants, Contracts, and Other Agreements: Fraud and Abuse; Information Blocking; Office of Inspector General's Civil Money Penalty Rules," 88 Federal Register 42820, July 3, 2023, https://www.govinfo.gov/content/pkg/FR-2023-07-03/pdf/2023-13851.pdf. |
| 136. |
OIG, "Information Blocking CMP," 88 Federal Register 42820, 42820, 42821. |
| 137. |
OIG, "Information Blocking CMP," 88 Federal Register 42820, 42820. |
| 138. |
ONC, "Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing," 89 Federal Register 1192, January 9, 2024, https://www.govinfo.gov/content/pkg/FR-2024-01-09/pdf/2023-28857.pdf. |
| 139. |
ONC, "HTI-1," 89 Federal Register 1192, 1192. |
| 140. |
ONC, "HTI-1," 89 Federal Register 1192, 1192. For more information regarding the USCDI, see ONC, "ONC Standards Bulletin 2026-1," July 23, 2026, https://healthit.gov/standards-and-technology/onc-standards-bulletin/onc-standards-bulletin-2026-1/. |
| 141. |
ONC, "HTI-1," 89 Federal Register 1192, 1192. |
| 142. |
CMS, "Medicare and Medicaid Programs; Patient Protection and Affordable Care Act; Advancing Interoperability and Improving Prior Authorization Processes for Medicare Advantage Organizations, Medicaid Managed Care Plans, State Medicaid Agencies, Children's Health Insurance Program (CHIP) Agencies and CHIP Managed Care Entities, Issuers of Qualified Health Plans on the Federally-Facilitated Exchanges, Merit-Based Incentive Payment System (MIPS) Eligible Clinicians, and Eligible Hospitals and Critical Access Hospitals in the Medicare Promoting Interoperability Program," 89 Federal Register 8758, February 8, 2024, https://www.govinfo.gov/content/pkg/FR-2024-02-08/pdf/2024-00895.pdf. |
| 143. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 144. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 145. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 146. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 147. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 148. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759. |
| 149. |
CMS, "Advancing Interoperability and Improving Prior Authorization," 89 Federal Register 8758, 8759, 8760. |
| 150. |
CMS and ONC, "21st Century Cures Act: Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking," 89 Federal Register 54662, July 1, 2024, https://www.govinfo.gov/content/pkg/FR-2024-07-01/pdf/2024-13793.pdf. |
| 151. |
CMS and ONC, "Disincentives," 89 Federal Register 54662, 54662. |
| 152. |
CMS and ONC, "Disincentives," 89 Federal Register 54662, 54663. |
| 153. |
CMS and ONC, "Disincentives," 89 Federal Register 54662, 54662. |
| 154. |
CMS and ONC, "Disincentives," 89 Federal Register 54662, 54662. |
| 155. |
ONC, "Health Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement (TEFCA)," 89 Federal Register 101772, December 16, 2024, https://www.govinfo.gov/content/pkg/FR-2024-12-16/pdf/2024-29163.pdf. |
| 156. |
ONC, "HTI-2," 89 Federal Register, 101772, 101773. |
| 157. |
ONC, "HTI-2," 89 Federal Register, 101772, 101773. |
| 158. |
ONC, "HTI-2," 89 Federal Register, 101772, 101773. |
| 159. |
ONC, "Health Data, Technology, and Interoperability: Protecting Care Access," 89 Federal Register 102512, December 17, 2024, https://www.govinfo.gov/content/pkg/FR-2024-12-17/pdf/2024-29683.pdf. |
| 160. |
ONC, "HTI-3," 89 Federal Register 102512, 102512. |
| 161. |
ONC, "HTI-3," 89 Federal Register 102512, 102535. |
| 162. |
CMS and ONC, "Medicare Program; Hospital Inpatient Prospective Payment Systems for Acute Care Hospitals (IPPS) and the Long-Term Care Hospital Prospective Payment System and Policy Changes and Fiscal Year (FY) 2026 Rates; Changes to the FY 2025 IPPS Rates Due to Court Decision; Requirements for Quality Programs; and Other Policy Changes; Health Data, Technology, and Interoperability: Electronic Prescribing, Real-Time Prescription Benefit and Electronic Prior Authorization," 90 Federal Register 36536, August 4, 2025, https://www.govinfo.gov/content/pkg/FR-2025-08-04/pdf/2025-14681.pdf. |
| 163. |
CMS and ONC, "HTI-4," 90 Federal Register 36536, 36541-36542. |
| 164. |
ONC, "Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity," 90 Federal Register 60970, December 29, 2025, https://www.govinfo.gov/content/pkg/FR-2025-12-29/pdf/2025-23896.pdf. |
| 165. |
ONC, "HTI-5," 90 Federal Register 60970, 60972-60973. For more information regarding FHIR APIs, see footnote 77. See also ONC, "HL7 FHIR," January 21, 2026, https://healthit.gov/interoperability/investments/fhir/. |
| 166. |
ONC, "HTI-5," 90 Federal Register 60970, 60973. |
| 167. |
ONC, "HTI-5," 90 Federal Register 60970, 60973. |
| 168. |
ONC, "HTI-5," 90 Federal Register 60970, 60973. |
| 169. |
ONC, "HTI-5," 90 Federal Register 60970, 60973-60974. |
| 170. |
This report discusses selected thematic issues specific to digital health information interoperability and does not discuss cybersecurity generally. For more information about cybersecurity and digital health information, see CRS In Focus IF12591, Cybersecurity and Digital Health Information. |
| 171. |
CDC, "About Public Health Data Interoperability," December 30, 2025, https://www.cdc.gov/data-interoperability/php/about/index.html. |
| 172. |
ONC has defined HIOs as types of HINs at the state, local, and regional levels that provide health information exchange services to a variety of unaffiliated member entities, not including local proprietary or enterprise networks. Chelsea Richwine et al., "Assessing the Value of Health Information Exchange Organizations to Hospital Interoperability," Health Affairs Scholar, vol. 3, no. 7 (July 2025), p. 1, https://doi.org/10.1093/haschl/qxaf133; ONC, Health Information Exchange Organization Capabilities to Support Public Health Data Exchange, Data Brief No. 86, June 2026, https://healthit.gov/data/data-briefs/health-information-exchange-organization-capabilities-to-support-public-health-data-exchange/; ONC, Trends in State, Local, and Regional Health Information Organizations' Experiences of Perceived Information Blocking, 2019-2025, Data Brief No. 85, June 2026, https://healthit.gov/data/data-briefs/trends-in-health-information-organizations-experiences-of-perceived-information-blocking-2019-2025/. |
| 173. |
A total of 87 HIOs were determined eligible for the survey. ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 174. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 175. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 176. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 177. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 178. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 179. |
ONC, HIO Capabilities to Support Public Health Data Exchange. |
| 180. |
ONC, Electronic Health Record Adoption and Exchange Capabilities Among Substance Use and Mental Health Treatment Facilities, 2024, Data Brief No. 82, April 2026, https://healthit.gov/data/data-briefs/electronic-health-record-adoption-and-exchange-capabilities-among-substance-use-and-mental-health-treatment-facilities-2024/. |
| 181. |
ONC, EHR Adoption and Exchange Capabilities Among Substance Use and Mental Health Treatment Facilities. |
| 182. |
ONC, EHR Adoption and Exchange Capabilities Among Substance Use and Mental Health Treatment Facilities. |
| 183. |
ONC, EHR Adoption and Exchange Capabilities Among Substance Use and Mental Health Treatment Facilities. |
| 184. |
ONC, EHR Adoption and Exchange Capabilities Among Substance Use and Mental Health Treatment Facilities. |
| 185. |
ONC, "The Digital Health Divide for Populations that have been Marginalized," November 13, 2023, https://healthit.gov/blog/health-information-exchange-2/the-digital-health-divide-for-populations-that-have-been-marginalized/; ONC, Interoperable Exchange of Patient Health Information Among U.S. Hospitals: 2023, Data Brief No. 71, May 2024, https://healthit.gov/data/data-briefs/interoperable-exchange-patient-health-information-among-us-hospitals-2023/. |
| 186. |
GAO, Electronic Health Information Exchange: Use Has Increased, but is Lower for Small and Rural Providers, GAO-23-105540, April 2023, pp. 19-20, 26-27, https://www.gao.gov/assets/gao-23-105540.pdf. |
| 187. |
45 C.F.R. §171.103. |
| 188. |
For a full list of current information blocking exceptions, see 45 C.F.R. Part 171, Subparts B, C, and D. |
| 189. |
ONC, "Information Blocking," April 8, 2026, https://healthit.gov/information-blocking/. |
| 190. |
See, for example, Fierce Healthcare, "HIMSS26: HHS Officials Offer Updates on Interoperability Efforts, Information Blocking Enforcement," March 12, 2026, https://www.fiercehealthcare.com/health-tech/himss26-hhs-officials-offer-updates-interoperability-efforts-information-blocking; HHS, "HHS Announces Crackdown on Health Data Blocking," press release, September 3, 2025, https://www.hhs.gov/press-room/hhs-crackdown-health-data-blocking.html. |
| 191. |
ONC, "Information Blocking Portal," https://inquiry.healthit.gov/support/plugins/servlet/desk/portal/6. |
| 192. |
ONC, "What Happens When a Claim is Submitted to the Information Blocking Portal?," https://healthit.gov/wp-content/uploads/2026/04/Information-Blocking-Portal-Process.pdf. For more information regarding these penalties and disincentives, see the "Information Blocking Civil Money Penalty (CMP) Final Rule" and "Disincentives Final Rule" sections. |
| 193. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 194. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 195. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 196. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 197. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 198. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 199. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 200. |
ONC, Trends in HIOs' Experiences of Perceived Information Blocking. |
| 201. |
ONC, "Information Blocking Claims: By the Numbers," quick stats, July 2026, https://healthit.gov/data/quickstats/information-blocking-claims-numbers/. |
| 202. |
ONC, "Information Blocking Claims." |
| 203. |
ONC, "Information Blocking Claims." |
| 204. |
ONC, "Information Blocking Claims." |
| 205. |
ONC, "Information Blocking Claims." |
| 206. |
See, e.g., Jill Hughes, "Misconceptions About HIPAA, Interoperability, Information Blocking," TechTarget, May 3, 2022, https://www.techtarget.com/healthtechsecurity/feature/Misconceptions-About-HIPAA-Interoperability-Information-Blocking; Hannah Nelson, "ASTP Highlights Ongoing Issues With Information Blocking," TechTarget, October 24, 2024, https://www.techtarget.com/searchhealthit/news/366614516/ASTP-highlights-ongoing-issues-with-information-blocking. |
| 207. |
ONC, Further Consolidated Appropriations Act, 2025 – ASTP Report to Congress on Cures Act Progress, September 2024, p. 20, https://healthit.gov/wp-content/uploads/2024/09/2024-Cures-Act_RTC_Word_508-1.pdf. |
| 208. |
ONC, Trusted Exchange Framework and Common Agreement (TEFCA), November 2023, p. 1, https://healthit.gov/wp-content/uploads/2023/11/TEFCA_2-Pager_Digital_508.pdf. |
| 209. |
ONC, Common Agreement for Nationwide Health Information Interoperability (Version 2.1), November 2024, https://healthit.gov/wp-content/uploads/2025/02/Common_Agreement_2.1.pdf; ONC, The Trusted Exchange Framework (TEF): Principles for Trusted Exchange, January 2022, https://healthit.gov/wp-content/uploads/2022/01/Trusted_Exchange_Framework_0122.pdf; The Sequoia Project, Trusted Exchange Framework and Common Agreement Qualified Health Information Network (QHIN) Technical Framework (QTF) (Version 2.0), 2024, https://healthit.gov/wp-content/uploads/2025/06/QTF-v2_508.pdf. |
| 210. |
The Sequoia Project, "RCE Homepage," https://rce.sequoiaproject.org/. |
| 211. |
The Sequoia Project, "Meet the Designated QHINs," https://rce.sequoiaproject.org/designated-qhins/. |
| 212. |
ONC, "TEFCA," June 9, 2026, https://healthit.gov/policy/tefca/. |
| 213. |
ONC, "Data Liquidity, Affordability, and Access: The History & Growth of TEFCA," February 11, 2026, https://healthit.gov/resources/data-liquidity-affordability-and-access-the-history-growth-of-tefca/. |
| 214. |
ONC, "Data Liquidity;" The Sequoia Project, "Exchange Purposes Explained," https://rce.sequoiaproject.org/exchange-purposes-explained/. |
| 215. |
Micky Tripathi and Mariann Yeager, "TEFCA Live! The Future of Network Interoperability is Here," HealthAffairs Forefront, December 12, 2023, https://www.healthaffairs.org/content/forefront/tefca-live-future-network-interoperability-here. |
| 216. |
HHS, "HHS Expands Secure Access to Health Records Through the TEFCA Network, Announces Milestone of One Billion Health Records Exchanged," press release, June 26, 2026, https://www.hhs.gov/press-room/onc-strengthens-tefca-one-billion-health-records-exchanged.html. |
| 217. |
The Sequoia Project, "RCE Homepage," https://rce.sequoiaproject.org/. |
| 218. |
ONC, "Why TEFCA's Hardest Problem Isn't Tech, It's Trust," December 1, 2025, https://healthit.gov/blog/tefca/why-tefcas-hardest-problem-isnt-tech-its-trust/. |
| 219. |
ONC, "Why TEFCA's Hardest Problem Isn't Tech, It's Trust." |
| 220. |
ONC, "Why TEFCA's Hardest Problem Isn't Tech, It's Trust." |
| 221. |
Heather Landi, "Epic's Lawsuit Against Health Gorilla Raises Broader Issues About the Future of Data Sharing, Industry Executives Say," Fierce Healthcare, January 16, 2026, https://www.fiercehealthcare.com/health-tech/epics-lawsuit-against-health-gorilla-raises-broader-issues-about-future-data-sharing. |
| 222. |
U.S. Congress, House Committee on Appropriations, Departments of Labor, Health, and Human Services, and Education, and Related Agencies Appropriations Bill, 2027: Report of the Committee on Appropriations House of Representatives Together With Minority Views, report to accompany H.R. 9260, 119th Cong., 2nd sess., H.Rept. 119-696, June 11, 2026. |
| 223. |
House Committee on Appropriations, Departments of Labor, Health, and Human Services, and Education, and Related Agencies Appropriations Bill, 2027, H.Rept. 119-696, p. 258. |
| 224. |
House Committee on Appropriations, Departments of Labor, Health, and Human Services, and Education, and Related Agencies Appropriations Bill, 2027, H.Rept. 119-696, p. 258. |
| 225. |
HHS, "HHS Expands Secure Access to Health Records Through the TEFCA Network." |
| 226. |
HHS, "HHS Expands Secure Access to Health Records Through the TEFCA Network." |
| 227. |
AGT, "AGT Awarded HHS/ONC TEFCA ARC Support Contract," https://agtbi.com/tefca-arc-contract-award/; USAspending.gov, "Contract to Alliance Global Tech Inc.," https://www.usaspending.gov/award/CONT_AWD_7571MN26F80064_7571_47QTCA21D003M_4732. |
| 228. |
See, for example, "Why TEFCA's Hardest Problem Isn't Tech, It's Trust," Grayson Miller, "Main Barriers to Achieving True Interoperability and How Organizations Can Overcome Them," Healthcare IT Today, September 18, 2025, https://www.healthcareittoday.com/2025/09/18/main-barriers-to-achieving-true-interoperability-and-how-organizations-can-overcome-them/. |
| 229. |
ONC, "About the ONC Health IT Certification Program," April 1, 2026, https://healthit.gov/certification-health-it/about-onc-health-it-certification-program/. |
| 230. |
ONC, ONC Health IT Certification Program: Overview, February 8, 2024, pp. 3-4, https://healthit.gov/wp-content/uploads/2025/02/PUBLICHealthITCertificationProgramOverview.pdf. |
| 231. |
ONC, ONC Health IT Certification Program, p. 4. |
| 232. |
ONC, ONC Health IT Certification Program, p. 4. |
| 233. |
ONC, ONC Health IT Certification Program, p. 5; ONC, "Welcomes to the Certified Health IT Product List," https://chpl.healthit.gov/#/search. |
| 234. |
ONC, ONC Health IT Certification Program, p. 7. |
| 235. |
ONC, ONC Health IT Certification Program, pp. 9-10. |
| 236. |
ONC, ONC Health IT Certification Program, p. 10. |
| 237. |
ONC, ONC Health IT Certification Program, p. 10. |
| 238. |
ONC, ONC Health IT Certification Program, p. 10. |
| 239. |
ONC, ONC Health IT Certification Program, pp. 10-11. |
| 240. |
ONC, ONC Health IT Certification Program, p. 11. |
| 241. |
ONC, "Developers Under Certification Ban," https://chpl.healthit.gov/#/banned-developers. |
| 242. |
See, for example, Andrea Fox, "ASTP/ONC Seeks Relaxation of Health IT Certification Criteria With HTI-5," Healthcare IT News, December 23, 2025, https://www.healthcareitnews.com/news/astponc-seeks-relaxation-health-it-certification-criteria-hti-5. |
| 243. |
See the "HTI-5 Proposed Rule" section. |
| 244. |
45 C.F.R. §170.315. |
| 245. |
45 C.F.R. §170.102; ONC, "Certification of Health IT," July 27, 2026, https://healthit.gov/certification-health-it/; ONC, "Certification Criteria," April 1, 2026, https://healthit.gov/certification-health-it/certification-criteria/. |
| 246. |
45 C.F.R. §170.315. |
| 247. |
ONC, "HTI-5," 90 Federal Register 60970, 60972-60973. |
| 248. |
ONC, "HTI-5," 90 Federal Register 60970, 60973. |
| 249. |
ONC, "HTI-5," 90 Federal Register 60970, 60973-60974. |
| 250. |
ONC, "HTI-5," 90 Federal Register 60970, 60971. |
| 251. |
See, for example, Andrea Fox, "AHA and EHRA Support Proposed HTI-5 Deregulation, but Air Concerns," Healthcare IT News, March 4, 2026, https://www.healthcareitnews.com/news/aha-and-ehra-support-proposed-hti-5-deregulation-air-concerns; Jill Hughes, "Industry Groups Weigh in on HTI-5 Proposed Rule," TechTarget, March 3, 2026, https://www.techtarget.com/searchhealthit/news/366639625/Industry-groups-weigh-in-on-HTI-5-proposed-rule; Emma Beavins, "HHS' Tech Office Proposes to Gut and Reset Health IT Policy," Fierce Healthcare, December 22, 2025, https://www.fiercehealthcare.com/health-tech/hhs-tech-arm-proposes-gut-and-reset-health-it-policy; HIMSS, "HIMSS Calls for Scalable Strategies for AI-Enabled Information Access: HTI-5 Public Comments," https://www.himss.org/news-center/himss-calls-for-scalable-strategies-for-ai-enabled-information-access-hti-5-public-comments/. |
| 252. |
See, for example, Andrea Fox, "AHA and EHRA Support Proposed HTI-5 Deregulation, but Air Concerns"; Jill Hughes, "Industry Groups Weigh in on HTI-5 Proposed Rule." |
| 253. |
See, for example, Andrea Fox, "AHA and EHRA Support Proposed HTI-5 Deregulation, but Air Concerns"; Jill Hughes, "Industry Groups Weigh in on HTI-5 Proposed Rule"; CHIME, "CHIME Submits Comments to ASTP/ONC on HTI-5 Proposed Rule," February 27, 2026, https://chimecentral.org/chime/resource-post/chime-submits-comments-to-astponc-on-hti5-proposed-rule. |
| 254. |
See, for example, Andrea Fox, "AHA and EHRA Support Proposed HTI-5 Deregulation, but Air Concerns"; Jill Hughes, "Industry Groups Weigh in on HTI-5 Proposed Rule"; HIMSS, "HIMSS Calls for Scalable Strategies for AI-Enabled Information Access: HTI-5 Public Comments"; CHIME, "CHIME Submits Comments to ASTP/ONC on HTI-5 Proposed Rule." |