From moving messages to enabling services
Health information exchange has often been built one connection at a time. That approach can move data, but it is expensive to scale and difficult to govern consistently.
FHIR APIs, TEFCA, and electronic prior authorization point toward a more reusable model. Together, they can support patient access, care coordination, payer-provider exchange, public health, and more efficient administrative workflows.
The objective is not exchange for its own sake. It is information that arrives with enough meaning, context, security, and timeliness to support a real decision.
FHIR creates a common API vocabulary
Fast Healthcare Interoperability Resources, or FHIR, organizes health information into modular resources and makes it available through modern web APIs. Implementation guides define how those resources are used for particular workflows.
FHIR lowers the cost of building reusable integrations, but a FHIR endpoint alone does not guarantee interoperability. Organizations still need consistent terminology, identity matching, provenance, authorization, version management, documentation, and conformance testing.
- Treat APIs as products with owners, service levels, roadmaps, and support.
- Adopt relevant implementation guides instead of inventing local profiles.
- Validate coded meaning and workflow behavior, not only message syntax.
- Publish clear developer documentation and test environments.
- Monitor latency, failures, usage, data quality, and security events.
TEFCA provides a nationwide exchange framework
The Trusted Exchange Framework and Common Agreement establishes common principles, terms, and technical expectations for nationwide health information exchange through Qualified Health Information Networks.
TEFCA can reduce the need for every organization to negotiate a separate legal and technical relationship with every other participant. In 2026, HHS reported that exchange through TEFCA had reached nearly 500 million health records, reflecting growing national-scale use.
Participation still requires operational readiness. Organizations must align identity, permitted purposes, directory information, security, privacy, data quality, incident response, and local governance with the exchange framework.
Electronic prior authorization connects clinical and administrative work
Prior authorization is a useful test of interoperability because it crosses payer rules, provider workflows, clinical documentation, patient communication, and time-sensitive decisions.
CMS’s Interoperability and Prior Authorization final rule requires impacted payers to implement and maintain specified FHIR APIs, including a Prior Authorization API, and establishes operational requirements intended to improve transparency and response times. Some operational provisions begin in 2026, while API requirements generally apply in 2027.
In 2026, CMS also proposed additional interoperability standards for prior authorization of drugs. Because that action is a proposed rule, organizations should track its status and avoid treating proposed requirements as final obligations.

Design the end-to-end workflow
An API can return a successful response while a patient still waits. Teams should map the complete journey: determining whether authorization is required, assembling documentation, submitting the request, receiving a decision, resolving missing information, appealing when appropriate, and communicating status.
The workflow should surface requirements early, reuse existing clinical data where appropriate, minimize duplicate entry, and make the state of each request visible. Exceptions need named owners and clear escalation paths.
- Make authorization requirements discoverable at the point of planning.
- Request only the minimum information needed for the decision.
- Return structured reasons when more information is required or a request is denied.
- Notify patients and staff in plain language at meaningful milestones.
- Measure total elapsed time, manual touches, resubmissions, and abandonment.
Build trust into exchange
Healthcare data carries different sensitivities, purposes, and restrictions. Strong interoperability architecture combines authentication, authorization, encryption, audit logging, purpose-of-use controls, consent where applicable, segmentation, and incident response.
Trust also depends on accuracy. Organizations should manage source attribution, update timing, duplicate records, terminology mapping, and correction workflows. Users need to understand where information came from and whether it is complete enough for the decision at hand.
Patient access must be secure without becoming unnecessarily difficult. Identity proofing, delegated access, accessibility, language support, and recovery paths all shape whether an exchange capability works equitably.
A shared capability roadmap
Instead of funding each interface as a separate project, HHS organizations can invest in shared capabilities: enterprise API management, identity, consent, terminology, directories, eventing, observability, testing, and data-quality services.
A capability roadmap should connect regulatory milestones to mission value. Compliance may establish the minimum, but the same foundations can support care coordination, benefits administration, public health reporting, research, and patient-facing services.
- Inventory current exchange relationships and duplicated interfaces.
- Prioritize high-volume, high-burden, and high-risk workflows.
- Establish standards governance with clinical and program participation.
- Test with partners and representative users before production deadlines.
- Measure whether exchange changes decisions, burden, access, and outcomes.
Conclusion
FHIR, TEFCA, and electronic prior authorization are complementary building blocks. APIs provide reusable technical access, TEFCA provides a national exchange framework, and prior authorization applies interoperability to a consequential workflow.
Their promise will be realized when organizations manage them as public-service infrastructure—secure, well governed, measurable, and designed around the people waiting for information to move.

