Stop treating your EHR as a digital chart. That advice is wrong. The moment you think of it as a chart, you accept messy, inconsistent, and incomplete data as normal. That's a recipe for failed interoperability, lousy quality scores, and compliance headaches. If you're a health system CIO, a CMIO, or a practice manager, your real job is to treat clinical data as a product. That means owning its structure, semantics, and flow. Here's how to do it, using a concrete scenario.
Imagine You're the CMIO of a 200-Bed Hospital
You've got a certified EHR. Like 96 percent of U.S. non-federal acute care hospitals, you adopted health IT certified under the ONC Health IT Certification Program (ONC / HHS Report to Congress). Your physicians are mostly on board—about 4 in 5 office-based physicians have adopted a certified EHR. But your data is a mess. Lab results come in as PDFs. Imaging reports are faxed. Medications are free-text. You're bleeding time and money. You need a plan.
First, stop blaming the EHR vendor. The problem is your data governance. You need to define a minimum data set. That's where USCDI comes in. ONC released USCDI v3 on July 19, 2022, expanding the standard from 52 data elements in 16 classes to 94 data elements in 19 classes (ONC Standards Bulletin 2022-2). Under the HTI-1 final rule, USCDI v3 becomes the baseline for certified health IT on January 1, 2026. You have a deadline. Use it. Map every clinical system to those 94 elements. If a system can't produce them, replace it or build an interface.
Second, get serious about terminology. You can't exchange what you can't name consistently. SNOMED CT is the designated standard for clinical terms in U.S. federal systems, and NLM is the U.S. National Release Center (NLM SNOMED CT). LOINC is the international standard for lab observations and measurements, stewarded by the Regenstrief Institute (LOINC). RxNorm normalizes drug names and links to pharmacy vocabularies (NLM RxNorm). Pick these three. Enforce them at the point of entry. No free-text diagnoses. No local lab codes. This is not optional if you want to report quality measures or participate in TEFCA.
Third, choose your interoperability transport wisely. HL7 Version 2 was first published in 1987 and is still used by more than 95% of U.S. healthcare organizations (HL7 International). It's great for high-throughput legacy workflows. But for new apps—patient access, population health, mobile—FHIR is the answer. FHIR R4, published December 27, 2018, was the first release with normative content (HL7 FHIR Version History). The US Core Implementation Guide, based on FHIR R4, defines the minimum profiles for patient data access (US Core Implementation Guide). If you're building a Patient Access API to comply with the CMS Interoperability and Patient Access final rule, you must use FHIR Release 4.0.1 (Federal Register CMS-9115-F). Don't fight it. Use FHIR for new stuff, keep V2 for legacy, and bridge them with a interface engine.
| Option | Best For | Key Standard | Your Action |
|---|---|---|---|
| HL7 V2 | High-volume legacy messaging (ADT, orders, results) | V2.7 (2011) | Maintain and wrap with FHIR facade |
| HL7 CDA | Clinical documents (discharge summaries, imaging reports) | CDA R2 | Use for document exchange where required |
| FHIR R4 | APIs, mobile apps, patient access, cloud | US Core IG (v9.0.0) | Build all new interfaces on FHIR R4 |
Security and Privacy Are Not Afterthoughts
You're a covered entity under HIPAA if you transmit health information electronically in connection with a standard transaction (45 CFR 160.103). That means you must comply with the Security Rule. You need administrative safeguards (policies, training), physical safeguards (facility security), and technical safeguards (access controls, encryption). The Access Control standard at 45 CFR 164.312(a) requires unique user identification, emergency access procedures, automatic logoff, and encryption/decryption. Encryption is addressable, but you should implement it. The Breach Notification Rule requires you to notify individuals within 60 days of discovering a breach (45 CFR 164.404). And the penalty caps are real: as of January 28, 2026, the maximum penalty per violation is $73,011 for Tiers 1-3 and $2,190,294 for Tier 4 (Federal Register 2026 HIPAA CMP Adjustment). That's per violation, per year. Don't risk it.
Use NIST resources. NIST SP 800-66 Rev. 2, published February 2024, is a cybersecurity resource guide for implementing the HIPAA Security Rule (NIST SP 800-66 Rev. 2). It supersedes the 2008 version. It won't replace the rule, but it gives you a practical framework. Pair it with NIST SP 800-53 Rev. 5 for a control catalog. This is how you build a defensible security program.
Put It All Together: A Data Product Roadmap
Start with a data governance council. Include clinical, IT, compliance, and analytics. Assign data stewards for each domain: labs, meds, problems, documents. Adopt USCDI v3 as your minimum data set. Map every source system to it. Implement SNOMED CT, LOINC, and RxNorm at the point of care. For exchange, use HL7 V2 for legacy and FHIR R4 for new. Build a Patient Access API using FHIR R4 to meet CMS requirements. Implement the HIPAA Security Rule with NIST guidance. Monitor for information blocking—the Cures Act makes sharing the expected norm, and exceptions are narrow (ONC Information Blocking). Finally, measure your progress. Track data completeness, terminology coverage, and API uptime. Treat these as product metrics. Review them monthly.
Your reward? Better quality scores. MIPS performance threshold for 2026 is 75 points, and the Promoting Interoperability category is 25 percent of your score (Federal Register CY 2026 Physician Fee Schedule). Clean data makes that easier. You'll also be ready for TEFCA, the nationwide network-of-networks that went live in December 2023 with the first QHINs (ONC TEFCA). And you'll avoid penalties. Most importantly, you'll improve patient care. That's the point.
Takeaway: Stop thinking of your EHR as a digital filing cabinet. Treat clinical data as a product you manage, with standards, governance, and metrics. Start with USCDI v3, enforce SNOMED CT, LOINC, and RxNorm, choose FHIR R4 for new interfaces, and secure it all with the HIPAA Security Rule. Your future self—and your patients—will thank you.
Sources
- ONC / HHS (Report to Congress) - https://healthit.gov/news/onc-outlines-health-it-interoperability-progress-report-congress/
- ONC Standards Bulletin 2022-2 (USCDI v3) - https://healthit.gov/standards-onc-technology/onc-standards-bulletin/onc-standards-bulletin-2022-2/
- HL7 International - https://www.hl7.org/fhir/
- NIST SP 800-66 Rev. 2 (HIPAA Security Resource Guide) - https://csrc.nist.gov/pubs/sp/800/66/r2/final
- Federal Register (2026 HIPAA CMP Adjustment) - https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- Federal Register (CY 2026 Physician Fee Schedule) - https://www.federalregister.gov/documents/2025/11/05/2025-19787
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!