Dr. Simran Mittal, Sr. AVP of MedTech at CitiusTech
Health systems and Payers have spent two decades and considerable capital wiring themselves to exchange data including bilateral interfaces, regional HIEs, national networks, etc. Yet, they still spend millions annually chasing records by fax, portal, and phone. TEFCA, the Trusted Exchange Framework and Common Agreement, is the first serious attempt to replace that patchwork with a single nationwide operating model: connect once, exchange with everyone, under one set of technical, legal, and governance rules.
The business case is real: lower record-retrieval cost, faster payer-provider workflows, and a data foundation for value-based care and AI. But capturing it requires coordinating connectivity, patient identity, authentication, data quality, provenance, and governance across environments no single organization controls. That coordination, not connectivity, is where TEFCA programs succeed or fail.
How the exchange works
At the center of TEFCA are Qualified Health Information Networks, or QHINs. Under the Common Agreement, they connect Participants and Sub-participants to a nationwide network, allowing organizations to exchange data without negotiating individual connections with every counterparty. The QHIN Technical Framework defines the functional and technical requirements for that exchange.
TEFCA currently accommodates three broad exchange patterns:
QHIN Query, through which an organization searches for and retrieves available patient information. QHIN Message Delivery, which supports the directed transmission of information to a known recipient. Facilitated FHIR Exchange, which enables more granular, API-based access between participating organizations.These modalities allow organizations to combine established document exchange with newer API-based workflows rather than attempt an immediate replacement of existing infrastructure.
However, joining a QHIN does not make an organization interoperable by default. The organization must still determine which systems will respond to requests, what information they can reliably provide, how exchange purposes will be validated and how QHIN obligations flow into internal policies and downstream partner agreements.
APIs change the unit of exchange
Much of today’s cross-network exchange remains document-centric. IHE workflows support patient discovery and document retrieval, but receiving systems must still reconcile, parse and incorporate those documents into clinical workflows.
Facilitated FHIR introduces a different model. An authorized application can request specific resources, such as medications, observations, or immunizations, rather than retrieve an entire clinical document.
This supports more responsive use cases, including clinical decision support, patient applications and public health reporting. It also requires discoverable FHIR endpoints, compatible implementation guides, consistent resource profiles, OAuth-based authorization and scope negotiation, together with the capacity to respond reliably to API traffic at operational scale.
FHIR also does not eliminate older formats. Many organizations will continue receiving information through C-CDA and HL7 v2 while exposing selected data through FHIR APIs. Their architecture must therefore support conversion, reconciliation and provenance across several representations of the same clinical information.
Identity matching remains a distributed problem
TEFCA does not establish a universal national patient identifier. Patient discovery continues to depend on demographic data, local master patient indexes, and the matching methods used by different networks and organizations.
In document-based exchange, an initiating organization may send demographics through an IHE Cross-Community Patient Discovery workflow. Responding networks apply their own matching logic and return possible patient identifiers. In FHIR-based exchange, the $match operation provides a standardized way to submit patient demographics and obtain potential matches.
Standardizing the request does not standardize the quality of the underlying data. Inconsistent demographic data and formatting across systems can cause false positives or missed matches, with even minor discrepancies becoming operationally significant at national scale.
Healthcare organizations will need measurable policies for match confidence, ambiguous results, duplicate records, and manual review. They should also examine whether registration processes capture the demographic attributes required by their QHIN and whether identity corrections propagate across connected systems.
The operational question is not simply whether the organization has an enterprise master patient index. It is whether identity data remains accurate as it moves through every system involved in TEFCA exchange.
Security becomes federated trust
TEFCA creates a shared trust framework, but each organization must still decide who can access its data and under what conditions.
Digital certificates verify organizational identity, mutual authentication confirms both parties, and Transport Layer Security protects information in transit. SAML, OAuth and SMART on FHIR support authentication and access control. SSRAA adds trusted information about the requester, role and purpose of exchange.
This is more complex than securing a direct connection between two known organizations. A request may come through another network and several contractual layers. The receiving organization must validate external credentials while applying its own privacy, consent and access policies.
Security teams will need answers to questions that are partly technical and partly governed:
Which external identities and credentials will the organization trust? How will exchange purpose and requester role influence authorization? How will certificates, keys and endpoint registrations be maintained? What happens when credentials are compromised or an organization leaves the network? How will access be limited without creating unnecessary barriers to permitted exchange?As TEFCA’s technical and security requirements evolve, organizations will need ongoing governance, not a one-time compliance exercise.
Provenance and standardization must preserve meaning
TEFCA requires organizations to track who accessed or supplied data, what was exchanged, when, why and from which source. The challenge increases when data changes format or comes from multiple systems. A laboratory result may begin as an HL7 v2 message, be mapped into a canonical data model, converted into a FHIR Observation and then incorporated into another system. Without clear tracking, the receiving organization may know where the resource came from, but not how the original data changed.
Provenance therefore needs to be designed into ingestion, transformation, and exchange pipelines, with clear ownership for creating, linking and retaining audit records.
Standardization brings a similar challenge. USCDI defines common data classes and elements, but organizations still need to map source data to required terminologies, C-CDA sections and US Core FHIR profiles. They also need to address missing values, local codes and inconsistent units.
Strong TEFCA adoption depends on both clear provenance and data-quality checks for completeness, consistency, and clinical usefulness.
| BOX: Practical readiness assessment for TEFCA |
| Connectivity readiness: network resilience, endpoint management, capacity, and recovery. Data readiness: identity quality, terminology alignment, USCDI mapping, and transformation controls. Trust readiness: authentication, authorization, certificates, consent, and auditability. Operating readiness: ownership, monitoring, incident management, change control, and governance. |
Preparing for exchange at national scale
TEFCA delivers infrastructure healthcare has historically lacked: a common trust model, nationwide connectivity, and a path from document exchange toward scalable FHIR APIs. But the network only determines who you can reach — the returns depend on what your organization does beneath it.
Organizations that treat TEFCA as a connection project will reach the network and still struggle to trust or use what moves through it. Those that invest in identity, data quality, provenance, and operating governance together will convert exchange into measurable outcomes: fewer manual retrievals, faster authorizations, cleaner quality reporting, and external data reliable enough to feed clinical decisions and AI.
The practical starting point is an honest readiness assessment sequenced against the exchange purposes that touch your margins first. The networks can connect. The question is whether your data, once it arrives, can be believed and used.
About Dr. Simran Mittal | Senior Assistant Vice President – MedTech, CitiusTech
Dr. Simran Mittal has over 20 years of experience in healthcare and technology and leads strategy consulting for Medical Technology, focusing on digital transformation initiatives for medical devices, medical imaging, and next-generation healthcare systems and solutions at CitiusTech.


Bengali (Bangladesh) ·
English (United States) ·