Quick refresher: What is TEFCA?
TEFCA stands for Trusted Exchange Framework and Common Agreement. It’s a federal initiative (born from the 21st Century Cures Act) to create a nationwide “network of networks” for health information exchange. The idea:
Instead of dozens of separate HIEs and vendor networks with custom rules,
You get one set of “rules of the road” (the Common Agreement)
And a tiered network architecture built around Qualified Health Information Networks (QHINs) that connect everyone else (participants, sub-participants, etc.). HealthIT+1
TEFCA went live in late 2023. Since then:
As of mid-2025, over 10,000 organizations are live on TEFCA (QHINs, participants, sub-participants), representing more than 60,000 connection points.
More than 115 million documents have been exchanged through TEFCA since go-live, with volume rapidly accelerating. ASTP TEFCA RCE
In its first year alone, TEFCA handled roughly 7.8 million documents, and stakeholders now see it as a key infrastructure for public health, payers, and cross-network exchange. TechTarget
The Common Agreement has already gone through multiple versions (1.0, 1.1, 2.0, 2.1) to:
Incorporate modern standards like FHIR and newer USCDI versions
Clarify obligations for QHINs and their participants
Add and refine Standard Operating Procedures (SOPs) for specific “exchange purposes” such as public health. NCBI+3Baker Donelson+3Network for Public Health Law+3
2. The “latest ONC regulations” in a nutshell
Over the last two years, ONC (now situated within ASTP for regulatory purposes) has rolled out a sequence of rules under the Health Data, Technology, and Interoperability (HTI) umbrella, plus a TEFCA-specific final rule. Think of them as layers:
HTI-1 Final Rule (2024)
Published January 9, 2024, HTI-1 updates the ONC Health IT Certification Program and implements parts of the 21st Century Cures Act. Key themes: HealthIT+1
New certification requirements for EHRs and other certified health IT
Adoption of updated standards and USCDI versions
Changes to information blocking regs
A new “Insights” Condition and Maintenance of Certification, requiring certified developers to report metrics on interoperability, usability, security and more HIMSS
A major focus on algorithm transparency via the new Decision Support Interventions (DSI) certification criterion for predictive models and clinical decision support. Crowell Health Solutions Blog
HTI-2 Final Rule (TEFCA-focused, December 2024)
In December 2024, ONC issued HTI-2, a slimmer final rule centered around TEFCA. Fierce Healthcare+2HRS+2
Highlights:
Clarifies the TEFCA “Manner Exception” under information blocking: when it’s reasonable to satisfy data-sharing requests through TEFCA without being accused of blocking.
Codifies governance expectations for QHINs, participants, and sub-participants, including how TEFCA and non-TEFCA exchanges interact. HIMSS+1
Introduces administrative tweaks to certification where products are used in TEFCA-enabled exchange.
TEFCA Final Rule (December 16, 2024)
On December 16, 2024, HHS/ONC published the Health Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement (TEFCA) Final Rule. Federal Register+2GovInfo+2
This rule:
Formally embeds TEFCA concepts and definitions into federal regulation
Aligns information blocking policy with TEFCA by recognizing certain TEFCA-related activities as reasonable
Sets regulatory expectations around TEFCA participation, governance, and the role of QHINs.
HTI-3 “Protecting Care Access” Final Rule (December 17, 2024)
The next day, ONC issued HTI-3: Protecting Care Access, focused on information blocking and sensitive reproductive health information. American Medical Association+3Federal Register+3Ropes & Gray+3
Key pieces:
Creates a new “Protecting Care Access” information blocking exception:
Allows actors to withhold specific EHI when sharing it could expose a patient or provider to legal risk related to reproductive health care, as long as conditions are met. Federal Register+1
Clarifies “segmentation”: you can withhold specific parts of a record (e.g., certain meds, test results) to honor patient preferences or reduce legal risk, without automatically triggering an information blocking violation.
Additional 2025 activity
ONC has continued adding pieces in 2025, including rules that further update certification standards for:
e-prescribing
Real-time prescription benefit information
Electronic prior authorization, all designed to build on the HTI framework and make interoperability more practical in day-to-day care. AAMC
3. What this means for health tech companies
If you’re building EHRs, apps, APIs, AI tools, or any “health IT module,” the bar just got higher—but so did the opportunity.
a) Interoperability is now infrastructure, not a feature
Between TEFCA, updated USCDI versions, and FHIR expectations, the message from ONC is clear:
“You will be able to exchange data nationwide—reliably and consistently—or you won’t be in the game.”
Health tech teams should expect:
Stronger requirements to support standardized data elements (USCDI v3/v4) and FHIR APIs over time. Sirona Strategies+1
Customers (health systems, payers, public health) increasingly asking:
Are you TEFCA-connected?
Which QHIN(s) do you support?
How do you handle TEFCA exchange purposes and SOPs? Network for Public Health Law+1
If you’re not architecting with TEFCA participation in mind—directly or through a partner—you’re likely to feel pressure within the next 1–3 years.
b) Design around TEFCA + information blocking
HTI-2 and the TEFCA final rule emphasize how TEFCA participation can coexist with information blocking rules. HRS+1
For product teams, this means:
You may route some requests preferentially through TEFCA, especially where the TEFCA Manner Exception clearly applies.
But you still need a story for non-TEFCA exchange—you can’t simply say “we only ever share through TEFCA” if that becomes a practical barrier.
Expect more nuanced requirements from customers around logging, consent, auditing, and routing logic tied to TEFCA vs. non-TEFCA flows.
c) AI & decision support: transparency is no longer optional
HTI-1’s Decision Support Interventions (DSI) provisions are a big deal for any vendor building AI or predictive models that influence clinical decision-making: Crowell Health Solutions Blog+1
You’ll need to:
Provide structured metadata about models (intended use, data sources, training population, limitations).
Support transparency so clinicians can see why a model recommended a particular action.
Align with certification criteria that may require evaluation procedures, risk management, and clear labeling.
This shifts AI from “magic box in the background” to documented, auditable, and explainable infrastructure.
d) Reporting & telemetry: the “Insights” Condition
The HTI-1 Insights requirement means certified developers have to report metrics about how their products actually behave in the wild—interoperability, performance, usability, security, etc. HIMSS+1
For engineers and product leaders:
Instrument your systems now—usage analytics, error tracking, FHIR call success rates, data-exchange volumes.
Expect that customers will start asking for dashboards or reports that mirror or feed into ONC reporting obligations.
e) New opportunity areas
The rules also create new product spaces:
TEFCA connectivity services (QHIN “on-ramps”, routing hubs, consent orchestration)
Public health integration tools that take advantage of TEFCA SOPs for surveillance and reporting Network for Public Health Law+1
Prior auth and e-prescribing orchestration platforms aligned with new certification standards AAMC
Privacy and segmentation controls that help organizations implement the Protecting Care Access exception correctly. Federal Register+1
4. What this means for clinicians and health professionals
For clinicians, nurses, therapists, and allied professionals, the rules are less about code and more about how data shows up in the workflow—and what you’re responsible for.
a) More complete patient data, across more settings
As more organizations join TEFCA, it becomes more realistic that when a patient walks in:
You can pull their records from other networks and systems, not just local exchanges. TechTarget+1
This applies across hospitals, ambulatory, post-acute, some payers, and increasingly public health and behavioral health.
In practice, that should mean:
Less time chasing faxes and phone calls
More context at the point of care (history, meds, labs, care plans), especially for mobile populations and complex cases.
b) New responsibilities around information blocking
Clinicians (as “actors” under information blocking rules) need to be aware that:
Patients have strong rights to access and share their electronic health information (EHI).
Denying data access or dragging your feet can be viewed as information blocking, unless a recognized exception applies.
The Protecting Care Access (HTI-3) rule gives some relief in specific situations, especially around reproductive health care, but it also requires policies and documentation: Federal Register+2Ropes & Gray+2
You can withhold certain information when sharing it could expose a patient or provider to legal risk—but only under defined conditions and with clear reasoning.
Organizations will expect clinicians to understand when segmentation is appropriate and how to handle sensitive conversations with patients about data sharing.
c) AI and decision support will feel more “glass box” than “black box”
As vendors comply with the DSI transparency requirements, clinicians should start to see:
Decision support tools that explain their logic, inputs, and limitations more clearly. Crowell Health Solutions Blog+1
Labels and documentation that specify what a model is for—and what it’s not for.
That should empower clinicians to:
Judge whether a recommendation makes sense for a specific patient
Push back when the model is being used outside its intended context
Participate meaningfully in quality and safety discussions about AI tools.
d) Workflow changes: less hunting, more curating
The promise of TEFCA + HTI rules is: less time hunting for data, more time deciding what matters. But in the short term, clinicians may experience:
More information flowing in, not always well-filtered
New UI elements in the EHR for TEFCA queries, patient consent status, segmentation flags
Updated org policies and trainings on when you must share, when you may limit sharing, and how to document that decision. McDermott+2HealthIT+2
Professionals who get comfortable with these tools early will likely become informal leaders inside their organizations.
5. Practical next steps for each community
For health tech companies
Map your regulatory exposure.
Are you a certified health IT developer, a QHIN participant, a HIN, or an “actor” under information blocking rules? Many companies are more than one thing.
Build a TEFCA strategy.
Pick QHIN partners, define use cases (care coordination, public health, payer exchange), and design your routing and consent model.
Harden your AI governance.
Document every decision support intervention: training data, performance, intended use. Align with HTI-1 DSI transparency expectations.
Instrument everything.
Treat metrics and telemetry as a first-class product feature so you can meet the “Insights” reporting requirements and satisfy demanding enterprise customers.
Turn compliance into product value.
Market your TEFCA connectivity, information blocking-safe workflows, and AI transparency as differentiators—not just checkboxes.
For clinicians and health professionals
Learn your organization’s TEFCA and info-blocking policies.
Know when you’re expected to share, when you’re allowed to limit sharing, and how to document sensitive cases (especially around reproductive health).
Get comfortable pulling outside records.
Practice using TEFCA-enabled queries in your EHR. No