Picture this: a patient with a suspicious mole sits in a dermatologist's office. The dermatologist needs the biopsy report from the patient's primary care clinic, but the two systems don't talk. So the patient is handed a paper form and told to fax it herself. She forgets. Three weeks later, she's back for a second appointment, and the doctor still hasn't seen the report. This isn't a rare scenario—it happens every day in hospitals across America, even though 96% of non-federal acute care hospitals have certified health IT (ONC / HHS, Report to Congress). We've spent billions on EHRs, yet we still can't move a PDF when it counts. That's not a tech glitch; it's a choice. And it's a choice that's bleeding you dry—in penalties, in referrals, and in trust.
The Old Excuses Are Gone
For years, the default excuse was that sharing data was too hard. "The standards aren't mature," they'd say. "Security is too risky." But those arguments died when the 21st Century Cures Act made information blocking illegal—for providers, developers, and HIEs alike (ONC / HHS, Information Blocking). Then TEFCA came along, creating a national network-of-networks, and the first QHINs went live in December 2023 (ONC / HHS, TEFCA). FHIR R4, the modern standard, has been out since 2018 and is now required for patient access APIs (Federal Register, CMS Interoperability and Patient Access Final Rule). The infrastructure is here. The only remaining obstacle is your own reluctance to change.
More Than a Tech Problem: It's Your Business Model
You might think sharing data means losing control. But let's look at the flip side: if you don't share, you're actively blocking patient access—and that triggers OIG investigations. Penalties can reach $2.19 million per violation for willful neglect (Federal Register, 2026 HIPAA CMP Adjustment). That's not a slap on the wrist; it's a budget-killer. And patients notice. A patient who can't get their records easily will go elsewhere. In the MIPS program, 25% of your score is tied to Promoting Interoperability, and you need a performance threshold of 75 points for the 2026 performance period (Federal Register, CY 2026 Physician Fee Schedule). That's real money. But there's a bigger opportunity hiding in plain sight: when you share data, you become a hub in the network, not a silo. You attract referrals, improve care coordination, and even generate new revenue through data analytics services. The hospitals that embrace interoperability will be the ones that thrive in the value-based care era.
What About Security? Let's Talk Real Risks
You might be thinking, "Sure, but if I open up my data, I'm exposing my patients' PHI and risking HIPAA violations." It's a legitimate concern. The HIPAA Security Rule requires administrative, physical, and technical safeguards, including access control and audit controls (eCFR 45 CFR Part 164 Subpart C). But here's the thing: HIPAA doesn't require you to hoard data—it requires you to protect it. You can share data securely using encryption, authentication, and robust audit trails. The real risk is not sharing: if you're an information blocker, you're violating federal law, and penalties can reach up to $2.19 million per violation for willful neglect (Federal Register, 2026 HIPAA CMP Adjustment). And don't forget, patients have a right to their own data under HIPAA, and they can request it anytime. So the question isn't whether to share—it's how to share securely. The answer is to use standards like FHIR and to comply with TEFCA's security requirements.
Start Here: Your Action Plan
Stop making excuses. Start by implementing FHIR APIs. The US Core Implementation Guide, based on FHIR R4, defines the minimum data elements you need to support patient access (US Core Implementation Guide). Adopt USCDI v3, which expands the core data set to 94 data elements across 19 classes—more than enough to support meaningful exchange (ONC Standards Bulletin 2022-2). And get connected to TEFCA. The Sequoia Project is the Recognized Coordinating Entity, and the first QHINs are already live (ONC / HHS, TEFCA). You don't have to build everything from scratch; you can leverage existing networks and tools.
Here's a quick checklist to get started:
- Assess your current data-sharing capabilities against USCDI v3 and FHIR R4.
- Identify your information blocking risks: review your policies, vendor contracts, and patient access processes.
- Join a QHIN or connect via a vendor that supports TEFCA exchange.
Quick tip: Don't wait for the ONC certification deadline of January 1, 2026, to adopt USCDI v3—start now to get ahead of the curve (ONC / HHS, HTI-1 Final Rule).
If I Were in Your Shoes
If I were you, I'd make interoperability a board-level priority. Assign a chief interoperability officer. Set a 12-month goal to have your FHIR APIs live and your data flowing through TEFCA. Invest in data governance and security, but don't let fear of breaches paralyze you. The future is open, and the only way to survive is to share. Remember, the Cures Act made sharing the expected norm (ONC / HHS, Information Blocking). The question is whether you'll be a leader or a laggard.
Sources
- ONC / HHS (Report to Congress) - https://healthit.gov/news/onc-outlines-health-it-interoperability-progress-report-congress/
- ONC / HHS (Information Blocking) - https://www.healthit.gov/topic/information-blocking
- ONC / HHS (TEFCA) - https://www.healthit.gov/topic/interoperability/policy/trusted-exchange-framework-and-common-agreement-tefca
- Federal Register (CMS Interoperability and Patient Access Final Rule) - https://www.federalregister.gov/documents/2020/05/01/2020-05050/medicare-and-medicaid-programs-patient-protection-and-affordable-care-act-interoperability-and
- Federal Register (CY 2026 Physician Fee Schedule) - https://www.federalregister.gov/documents/2025/11/05/2025-19787
- ONC Standards Bulletin 2022-2 (USCDI v3) - https://healthit.gov/standards-onc-technology/onc-standards-bulletin/onc-standards-bulletin-2022-2/
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!