TEFCA and the interoperability imperative: what health systems need to prepare
Photo by Sergei Gussev on Unsplash
insight

TEFCA and the interoperability imperative: what health systems need to prepare

By Jason Alan Snyder·April 27, 2026

TEFCA will connect every major health network in the US through a common trust framework, but connectivity without data integrity creates new risks. Health systems that prepare only for technical compliance will find that TEFCA interoperability exposes every upstream data quality problem they have been ignoring.

TEFCA connects networks. It does not fix the data flowing through them.

The Trusted Exchange Framework and Common Agreement, finalized by ONC and managed by the Sequoia Project as the Recognized Coordinating Entity, establishes a national floor for health data exchange. As of early 2025, seven Qualified Health Information Networks (QHINs) are live, with more applying. The promise is straightforward: any provider, payer, or public health agency connected to a QHIN can query and receive patient data from any other QHIN participant without a custom point-to-point interface.

That promise is real. But it carries a problem that most implementation teams are not discussing openly.

What TEFCA actually requires

TEFCA defines six permitted exchange purposes: treatment, payment, health care operations, public health, government benefits determination, and individual access. Each QHIN must enforce the Common Agreement's privacy, security, and technical requirements on every participant in its network.

The technical layer runs on FHIR R4 and HL7 standards. The trust layer runs on organizational agreements, identity proofing, and audit obligations. QHINs must verify that participants meet baseline security and privacy requirements before granting access.

Notice what is missing from that list: any requirement that the data itself is accurate, complete, timely, or fit for the purpose it will be used for.

The interoperability gap nobody is staffing for

TEFCA solves the connectivity problem. It does not solve the data trust problem.

When a health system receives a TEFCA query response containing a patient's medication list from three different networks, it gets three lists. Those lists may conflict. Medications may be coded differently. Timestamps may reflect when data was entered, not when the medication was prescribed. Provenance metadata, if it exists at all, varies by source system.

Before TEFCA, health systems could blame data silos for incomplete records. After TEFCA, those silos dissolve, and every inconsistency becomes visible. A system deploying clinical AI on TEFCA-sourced data now trains or infers on records assembled from dozens of source systems with no standardized integrity scoring.

This is the gap. TEFCA interoperability gives you more data. It does not give you better data.

Key statistics

DTI dimension weights: what matters most for TEFCA-sourced records
DTI dimension weights: what matters most for TEFCA-sourced records

Five numbers that frame the TEFCA data trust challenge:

  • 7 QHINs are currently designated under TEFCA, with additional applicants under review by the Sequoia Project as of Q1 2025.
  • Over 70% of US hospitals now participate in a health information exchange, but fewer than 30% report confidence in the quality of externally sourced data (ONC data brief, 2024).
  • 42 CFR Part 2 substance use disorder data now flows under modified rules as of the 2024 final rule, creating new consent reconciliation requirements for every TEFCA participant handling SUD records.
  • 95% time reduction is what SuperTruth achieved scoring 105,000 diagnostic records for imaware, reducing standardization from 3 weeks to 2 hours. TEFCA-sourced records need the same treatment at the point of ingestion.
  • 8 dimensions of data trust, weighted and scored 0 to 100, define whether a health record is fit for clinical AI use. Provenance alone accounts for 25% of that score.
  • Where TEFCA breaks without a trust layer

    Three specific failure modes will emerge as TEFCA adoption scales:

    Consent fragmentation. A patient may have consented to data sharing at one institution under one set of terms and opted out of research use at another. TEFCA does not reconcile consent semantics across networks. When that patient's aggregated record lands in an AI training pipeline, consent governance breaks unless each record carries machine-readable consent metadata.

    Provenance collapse. TEFCA-sourced records arrive with transport-layer metadata, but chain of custody from the original source system is often incomplete. A lab result that passed through an HIE, a QHIN, and an EHR integration engine has been transformed at least three times. Each transformation is a provenance gap.

    Recency mismatch. Exchange latency varies by QHIN and participant. A query may return a medication list that was current when it was cached but is now 90 days stale. Clinical decision support tools that treat TEFCA responses as current state will make errors.

    What health systems should build now

    Data standardization time: before and after DTI scoring (imaware case study)
    %7Breturn%20value%20%2B%20'%25'%7D%22%7D%7D%7D%7D%7D) Data standardization time: before and after DTI scoring (imaware case study)

    TEFCA readiness is not just a network onboarding project. It is a data trust infrastructure project.

    Health systems preparing for TEFCA-sourced data should implement three capabilities before scaling AI on interoperable records:

  • Ingest-time scoring. Every record arriving through a QHIN connection should receive a trust score before it enters a clinical or analytical workflow. This means scoring provenance, consent, recency, and concordance at the point of ingestion, not after a model has already consumed the data.
  • DTI floor enforcement. Not all TEFCA-sourced records are fit for all uses. A record scoring below 60 on the Data Trust Index may be adequate for population health reporting but unfit for clinical AI training. Systems need configurable trust floors by use case.
  • Consent reconciliation. Aggregated records from multiple TEFCA sources carry multiple consent states. Systems need automated consent governance that flags conflicts before records move downstream.
  • The hospital systems already building this infrastructure will be the ones that turn TEFCA from a compliance checkbox into a clinical advantage.

    The regulatory trajectory

    ONC has signaled that TEFCA participation will eventually become a condition of certification for health IT products. CMS is watching TEFCA adoption as a potential lever for value-based care program requirements. The FDA's emerging AI guidance already expects provenance documentation for training data.

    These three regulatory vectors converge on the same requirement: data that moves through interoperable networks must carry verifiable trust metadata. TEFCA provides the pipes. Health systems must provide the trust layer.

    SuperTruth scores incoming EHR data at the point of ingestion, before it reaches a model. The DTI Engine evaluates every TEFCA-sourced record across 8 trust dimensions, flagging provenance gaps, consent conflicts, and recency failures before they contaminate clinical AI or trigger audit findings. If your system is deploying clinical AI on interoperable data and needs to answer an auditor's questions about what you trained on, contact Louis Simeonidis at louis@supertruth.ai or (215) 918-4140.

    Further reading:

  • DTI™ Engine
  • Health systems solution
  • Siloed health data: the infrastructure problem nobody has solved yet
  • The eight dimensions of health data trust: a practical guide
  • What HIPAA does not tell you about data trust
  • Jason Alan Snyder

    Jason Alan Snyder

    Co-founder of SuperTruth and Artists & Robots, and an inventor on the Data Trust Index patents. Twenty-plus years building technology inside Interpublic Group. He writes here nearly every day on data trust, provenance, and what AI should be allowed to act on, and publishes essays on his Substack.

    About SuperTruth · LinkedIn · Substack · jasonalansnyder.com

    See it in practice

    EHR data scored before any AI model sees it.

    DTI integrates with Epic, Oracle Health, and all major EHR systems.

    See our health systems solution
    Share