Myth: FHIR Has Made HL7 v2 Obsolete
You've heard it in every conference keynote: 'FHIR is the future, and HL7 v2 is the past.' That's only half right. FHIR is undeniably modern — it uses RESTful APIs and JSON, which developers love, and the latest release, R5, defines 157 discrete resources you can query like a database (HL7 FHIR Resource Index). But here's what the hype misses: HL7 v2 has been the workhorse of healthcare data exchange since 1987, and it's still used by more than 95% of U.S. healthcare organizations (HL7 International). That's not a legacy system waiting to die — it's the backbone of high-throughput workflows like ADT feeds and lab orders. FHIR is great for mobile apps and cloud-native builds, but if you rip out v2 tomorrow, your hospital's admissions would grind to a halt. The truth is they serve different jobs, and you'll likely need both.
Myth: If You Use an EHR, You're Interoperable
Just because you have a certified EHR doesn't mean you can share data with the next hospital down the road. Yes, 96% of U.S. non-federal acute care hospitals and about 4 in 5 office-based physicians use certified health IT (ONC Report to Congress). But 'adoption' and 'interoperability' are not the same thing. Your EHR might be a walled garden that only talks to its own kind. True interoperability means you can query a patient's record from another system using a standard like FHIR, or send a discharge summary as a CDA document. The Cures Act made information blocking illegal — it's a practice by an actor that likely interferes with access, exchange, or use of electronic health information (ONC Information Blocking) — but it doesn't force every vendor to make it easy. You need to actively test and push for real data exchange, not just assume your EHR does it.
Myth: HIPAA Only Applies to Big Hospitals
If you're a solo practitioner or a small clinic, you're still a covered entity if you transmit health information electronically in a covered transaction (45 CFR 160.103). And don't think you can dodge responsibility by outsourcing — your billing company or cloud host is a business associate, and you're on the hook for their actions too. The HIPAA Security Rule requires administrative, physical, and technical safeguards (45 CFR 164.308, 164.310, 164.312), and the penalties are not pocket change. For 2026, the maximum penalty for a willful neglect violation that you don't correct within 30 days is $2,190,294 (Federal Register 91 FR 3665). That's not a typo — over two million dollars. So, even if you're a three-person practice, you need to take HIPAA seriously. The HHS Office for Civil Rights doesn't care about your headcount.
Myth: You Must Share Everything, Everywhere, All at Once
The Cures Act says sharing electronic health information is the expected norm, and information blocking is illegal (ONC Information Blocking). But that doesn't mean you have to broadcast your entire patient record to the world. The HIPAA Privacy Rule's 'minimum necessary' standard requires you to make reasonable efforts to limit the information to what's needed for the purpose (45 CFR 164.502(b)). So, if a specialist asks for a patient's cardiology notes, you don't send the whole chart — you send the cardiology notes. And there are exceptions to information blocking, like preventing harm or protecting privacy. It's a balance: share what's needed, protect what's sensitive, and document your decisions. Don't let fear of a violation make you either a hoarder or a free-for-all data dump.
Myth: FHIR Is a Single Standard You Can Just Implement
FHIR is more of a framework than a one-size-fits-all standard. Even within FHIR, you have different versions — R4 was published in December 2018, and R5 in March 2023 (HL7 FHIR Version History). And then you have implementation guides like US Core, which is based on R4 and defines the minimum constraints for U.S. interoperability (US Core Implementation Guide). That's not to mention the terminology standards you need to map: LOINC for lab tests, SNOMED CT for clinical terms, and RxNorm for drugs (HL7 International). So, when someone says 'we'll just use FHIR,' ask which version, which profiles, and which terminologies. It's not plug-and-play; it's more like assembling a complex puzzle with pieces from different sets.
Myth: TEFCA Will Solve All Your Interoperability Woes
TEFCA — the Trusted Exchange Framework and Common Agreement — is ONC's network-of-networks vision, and yes, the first QHINs were designated in December 2023, so data is starting to flow (ONC TEFCA). But it's not a magic bullet. TEFCA is a framework for health information exchange, not a universal translator. It doesn't force every EHR to speak the same language; it sets up a common agreement and technical framework for QHINs to exchange data. You still need to implement the standards and map your data to make it work. And it's optional — not everyone has to join. So, while TEFCA is a step forward, don't assume it will fix all your integration headaches overnight. You still have to do the hard work of making your data interoperable at the ground level.
Myth: Audio-Only Telehealth Is a HIPAA Loophole
Some clinicians think that if they switch to audio-only visits, HIPAA doesn't apply because there's no video. That's wrong. The HIPAA Privacy Rule protects PHI in any medium, including audio (ONC HIPAA Basics). And the Security Rule applies to ePHI, which includes voice data stored or transmitted electronically. In fact, CMS has permanently allowed audio-only telehealth when the patient is in their home and can't or doesn't consent to video (CY 2025 Physician Fee Schedule). But that doesn't exempt you from HIPAA — it just means you can use audio-only as a modality. You still need to secure the connection, use encryption, and have a business associate agreement with your telehealth vendor. So, don't treat audio-only as a loophole; treat it as a normal telehealth service that happens to lack video, and apply the same safeguards.
What I'd Actually Do
Stop chasing the shiny new standard and start solving your actual data problems. If you're a hospital or a large practice, keep your HL7 v2 for high-volume, low-latency messages — it's proven and reliable. Build FHIR APIs for patient access and mobile apps, but use the US Core profiles and map your terminologies to LOINC, SNOMED CT, and RxNorm. And for heaven's sake, do a HIPAA risk analysis — not just a checkbox exercise, but a real one using NIST SP 800-66 as a guide. The penalties are real: up to $2.19 million for a single willful neglect violation. That's a lot of money that could go to better patient care instead of fines. Interoperability is not about picking a winner; it's about using the right tool for the job and securing your data at every step.
Sources
- ONC / HHS (Health IT) - https://www.healthit.gov/topic/health-it-basics
- HL7 International - https://www.hl7.org/fhir/
- ONC / HHS (Report to Congress) - https://healthit.gov/news/onc-outlines-health-it-interoperability-progress-report-congress/
- eCFR 45 CFR Part 164 Subpart C (Security Rule) - https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C
- Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- HL7 FHIR (Resource Index) - https://www.hl7.org/fhir/resourcelist.html
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!