A patient collapses in a Phoenix emergency department. She’s from Ohio. Her cardiology history, her medication list, the stent placed eighteen months ago: all of it exists in a chart somewhere, and none of it is in front of the physician deciding what to do in the next ten minutes.
For twenty years the industry’s answer to that problem was to build more networks. Regional HIEs, vendor networks, national frameworks, point-to-point interfaces. The result was interoperability that worked beautifully inside each network and unpredictably between them. Whether the Phoenix physician got those Ohio records depended less on technology than on whether two organizations happened to share a legal agreement.
TEFCA is the attempt to fix the legal layer rather than the technical one. That distinction is the whole point, and it’s the part most explainers skip.
This guide covers what TEFCA is, how data actually moves through it, what changed in TEFCA 2.0, how it relates to information blocking rules, and where it still comes up short.
What is TEFCA?
TEFCA is the Trusted Exchange Framework and Common Agreement: a nationwide set of legal terms and technical rules that lets healthcare organizations exchange data with each other after signing one agreement instead of hundreds.
It exists because Congress told it to. Section 4003 of the 21st Century Cures Act (2016) directed the Office of the National Coordinator for Health IT to develop a trusted exchange framework and common agreement for nationwide interoperability. ONC, now the Assistant Secretary for Technology Policy (ASTP/ONC) after a 2024 reorganization, designated The Sequoia Project as the Recognized Coordinating Entity in 2019. Sequoia runs the day-to-day program: onboarding, dispute resolution, and the rulebook.
Put plainly: TEFCA healthcare data exchange swaps a web of bilateral contracts for one shared rulebook. The core promise is sometimes called “connect once, connect to all.” Sign the agreement, connect through one network, and you inherit trusted connections to every other organization in the framework.
The Four Pieces of the TEFCA Framework
People use “TEFCA framework” loosely. It’s actually four distinct documents, and knowing which one governs what saves a lot of confusion:
- The Trusted Exchange Framework (TEF) is the principles document. Non-binding, aspirational, short. Almost nobody needs to read it twice.
- The Common Agreement (CA) is the binding contract. QHINs sign it with the RCE, and its terms flow downstream to every Participant and Subparticipant. This is the document that does the real work.
- The QHIN Technical Framework (QTF) specifies the technical requirements: transaction patterns, security, identity, message formats.
- Standard Operating Procedures (SOPs) cover the operational detail: how exchange purposes work, cybersecurity expectations, how disputes get handled, how organizations onboard.
The SOP layer matters more than it sounds. Moving requirements into SOPs lets Sequoia change operational rules without renegotiating a contract with every QHIN, which is why the program can evolve faster than a federal rulemaking cycle.
What TEFCA is Not?
Three clarifications that head off most misconceptions:
- TEFCA is not a network. It’s a set of rules that networks agree to follow. Data doesn’t flow “through TEFCA” any more than a wire transfer flows through banking law.
- TEFCA is not mandatory. Participation is voluntary. No provider or payer is legally required to join.
- TEFCA is not a replacement for HIPAA. HIPAA still governs permitted uses and disclosures. TEFCA adds contractual obligations on top, and it extends similar privacy and security duties to non-HIPAA entities that participate.
How TEFCA Works: QHINs, Participants, and Subparticipants
TEFCA data exchange runs through a tiered structure. Each tier has different obligations, and the tier you occupy determines your cost, your control, and your compliance burden.
The Exchange Hierarchy
ASTP/ONC sets policy. The Sequoia Project administers the program as RCE.
QHINs (Qualified Health Information Networks) sit at the top of the operational stack. A QHIN signs the Common Agreement directly, connects to every other QHIN, and routes queries and responses across the network. Becoming a QHIN is demanding: technical testing, security review, financial and operational vetting, and an obligation to serve a broad participant base rather than a single corporate parent.
Participants connect through a QHIN. Most health systems, large medical groups, payers, and HIE organizations land here.
Subparticipants connect through a Participant. A small practice connecting through its EHR vendor’s network, or a clinic connecting through a regional HIE, is typically a Subparticipant. Obligations flow down by contract, so a Subparticipant is bound by Common Agreement terms even though it never signed the Common Agreement.
Individuals access their own records through Individual Access Services, delivered by an IAS Provider.
Who the QHINs Are
The first five QHINs were designated in December 2023: eHealth Exchange, Epic Nexus, Health Gorilla, KONZA National Network, and MedAllies. CommonWell Health Alliance, Kno2, and Availity followed.
As of early 2026 there were roughly eight designated QHINs, with additional candidates working through onboarding. The list changes, so check the Sequoia Project’s current designation page before making a selection decision.
The mix tells you something useful. You have an EHR vendor network (Epic Nexus), a payer-oriented clearinghouse (Availity), API-first data companies (Health Gorilla, Kno2), legacy national networks (eHealth Exchange, CommonWell), and a public-health-leaning regional network (KONZA). Your choice of QHIN is a strategic decision, not a commodity procurement. A provider organization optimizing for treatment queries and a payer optimizing for risk adjustment data will find very different fits.
TEFCA Exchange Purposes
An Exchange Purpose (XP) is the permitted reason for a request. Every TEFCA transaction carries one, and the XP determines whether a responder is obligated to answer.
The defined exchange purposes are:
- Treatment, which covers clinical care and is the highest-volume XP by a wide margin
- Payment
- Health Care Operations
- Public Health
- Government Benefits Determination
- Individual Access Services (IAS), which lets a person request their own records
The word to watch is obligation. Some exchange purposes carry a required response, meaning a Participant must answer a valid query. Others are permitted but optional. The specific obligations, and their phase-in dates, live in the Exchange Purpose SOP rather than in the Common Agreement itself.
This is where TEFCA gets politically interesting. Providers broadly accepted required response for Treatment. Extending required response into Payment and Health Care Operations drew real objections, because those XPs let payers pull clinical data for uses including utilization review and quality reporting. Provider groups argued they were being conscripted into supplying data that would be used against them in payment decisions. Payers argued they already have HIPAA rights to that data and were merely getting a better pipe.
Both positions are defensible. Neither side considers the matter closed.
TEFCA 2.0: What Changed?
Common Agreement Version 2.0 and QTF 2.0 were published in July 2024, roughly two and a half years after version 1.0. TEFCA 2.0 was less a rewrite than a shift in architecture and governance.
1. FHIR Moved From Optional to Required
Version 1.0 ran overwhelmingly on document-based exchange: IHE profiles moving C-CDA documents. That works for “send me this patient’s chart summary.” It works poorly for “give me this patient’s last four A1c values.”
TEFCA 2.0 committed the program to FHIR-based exchange, implemented as Facilitated FHIR, in which the QHIN handles record location and identity resolution and then the parties exchange FHIR resources more directly. Sequoia published a FHIR Roadmap with staged milestones running into 2026 and beyond.
This is the most consequential change in TEFCA 2.0. Document exchange satisfies the letter of interoperability. Granular FHIR queries are what actually enable computable data: population analytics, risk adjustment, clinical decision support, quality measurement. Anyone evaluating TEFCA for anything beyond chart retrieval should be reading the FHIR Roadmap, not the marketing material.
2. Governance Moved into SOPs
Version 2.0 pulled substantial operational detail out of the contract and into SOPs. Less elegant, far more practical. It means requirements can be updated without a multi-party contract amendment.
3. Exchange Purpose Obligations Broadened
TEFCA 2.0 expanded which exchange purposes QHINs must support and tightened the phase-in schedule, including Payment, Health Care Operations, and Public Health alongside Treatment and Individual Access Services.
4. Security Expectations Hardened
Version 2.0 formalized cybersecurity obligations, added a Cybersecurity Council, and clarified incident reporting duties. Given that a QHIN sits astride nationwide clinical data flows, this was overdue rather than innovative.
TEFCA and Information Blocking
TEFCA and the information blocking rules are separate regulations that lean on each other.
Under ASTP/ONC’s HTI-1 final rule (published December 2023, effective 2024), the information blocking exceptions include a TEFCA Manner Exception. In broad terms, if an actor and a requestor are both TEFCA participants and the actor fulfills the request via TEFCA, that can satisfy the manner in which the request must be met, even if the requestor asked for a different method.
Read the actual conditions before relying on this. The exception is narrower than the summaries suggest, and it does not convert TEFCA participation into blanket information blocking protection. It also does not make TEFCA mandatory. What it does is give organizations a defensible, standardized way to respond, which is a meaningful compliance advantage in practice.
Subsequent ASTP/ONC rulemaking through 2024 and 2025 continued adjusting information blocking definitions and certification requirements. Confirm current requirements against the published rules rather than secondary coverage, because this area has moved repeatedly.
TEFCA vs. Carequality, CommonWell, and eHealth Exchange
The most common question about TEFCA is why it exists when national exchange networks already did.
The short answer: the older frameworks solved technical connectivity. They did not solve universal legal trust.
- Carequality provided a trust framework and legal terms that let networks connect to each other. Effective, widely adopted, and governed by its own participants rather than by federal designation.
- CommonWell Health Alliance operated as a vendor-founded network with record locator services, and is now itself a QHIN.
- eHealth Exchange grew out of the federal Nationwide Health Information Network and carried heavy federal agency participation. Also now a QHIN.
Those frameworks overlapped, competed, and required organizations to join several to achieve broad reach. TEFCA’s contribution is a single floor of legal trust with federal backing, which the prior arrangements could not provide because no participant had standing to impose one.
Practically, the older networks did not disappear. Several became QHINs, and their existing exchange continues alongside TEFCA flows. Expect consolidation over time, but verify current status directly, because network relationships in this space have shifted more than once and continue to.
Who Actually Benefits From TEFCA?
1. Health Systems and Providers
The concrete win is record retrieval for unaffiliated patients: the transfer from a hospital across the state, the traveler in the ED, the new patient with a decade of history somewhere else. Broader query reach means fewer repeated tests and less clinical guesswork.
The concrete cost is responding to queries you’d rather not answer, particularly under Payment and Health Care Operations, plus onboarding effort and QHIN fees.
2. Health Plans
Payers get a standardized path to clinical data for risk adjustment, HEDIS and Star measure abstraction, utilization review, and care management. Chart chases are among the most expensive manual workflows in payer operations, and TEFCA offers a credible alternative to fax-and-courier retrieval.
It is not a solved problem yet. Document-based responses still require abstraction, coverage is uneven, and Facilitated FHIR is where the real efficiency lives. Payers should be planning against the FHIR timeline rather than the current state.
3. Public Health
Public Health as a named exchange purpose gives agencies a standing pathway for case reporting, registry submission, and outbreak investigation. The pandemic made the cost of ad hoc public health data plumbing painfully clear.
4. Digital Health and Health IT Vendors
For vendors, TEFCA is a distribution question. Connecting through a QHIN as a Participant, or offering Subparticipant connectivity to customers, can replace dozens of bespoke integrations. Vendors building patient-facing products should look closely at Individual Access Services, which is the most direct route to patient-authorized record aggregation at national scale.
5. Patients
IAS is the patient-facing piece: request your own records through an app, without filing a written request at every provider you’ve seen. Adoption has been slower than the framework’s authors hoped, and identity proofing requirements are a genuine friction point, but this is the tier with the most headroom.
How to Join TEFCA?
The process is more tractable than the acronym density suggests.
- Decide your tier. Almost no one should pursue QHIN status. The realistic question is Participant or Subparticipant. Participant gives more control and costs more; Subparticipant is faster and cheaper with less say.
- Pick your QHIN. Evaluate on exchange purposes supported, FHIR readiness and roadmap, existing network reach in your service area, pricing model, and whether your EHR already has a path. If you run Epic, Epic Nexus is the obvious first conversation, but obvious is not automatically correct.
- Work the legal terms. Review the flow-down obligations carefully. Common Agreement terms bind you contractually even at Subparticipant level, and they include privacy, security, breach notification, and audit duties.
- Plan the technical work. Patient identity matching, C-CDA generation quality, FHIR endpoint readiness, consent management, and audit logging. Identity matching is where most implementations struggle, and it deserves attention early rather than at go-live.
- Build the response side. Organizations consistently underestimate this. You are not just querying; you are obligated to respond. That means a policy for handling incoming requests by exchange purpose, and someone accountable for it.
- Govern it. Assign ownership for exchange purpose policy, consent handling, and audit review. TEFCA obligations are ongoing, not a project with an end date.
Where TEFCA Still Falls Short?
An honest assessment has to include the gaps.
- Voluntary participation limits reach. A framework that nobody must join will have holes, and the holes tend to be in exactly the under-resourced settings where data is hardest to get.
- Document-based exchange remains dominant. Until Facilitated FHIR is widely implemented, much TEFCA traffic delivers PDFs and C-CDAs that still require human abstraction. The pipe improved; the payload often did not.
- Data quality is not addressed. TEFCA governs whether data moves. It has little to say about whether the C-CDA you receive is a well-structured summary or a 90-page document dump with the relevant note buried on page 62.
- Patient identity matching is unsolved nationally. Without a national patient identifier, matching relies on demographic algorithms that fail at the margins, and the margins are where patients get hurt.
- The Payment and Health Care Operations question is unresolved. Required response for these purposes remains contested, and reasonable people continue to disagree.
- Cost falls unevenly. QHIN and Participant fees are easier for large systems to absorb than for federally qualified health centers, rural hospitals, and independent practices.
- Consent handling is complicated by state law. Behavioral health, substance use disorder records under 42 CFR Part 2, HIV status, and reproductive health data carry state-specific and federal restrictions that a national framework cannot fully harmonize.
TEFCA in 2026 and Beyond
Three things worth watching.
FHIR milestones. The Facilitated FHIR timeline is the single best indicator of whether TEFCA becomes infrastructure or stays a document retrieval utility. Track actual QHIN implementations against the roadmap, not announcements.
Federal policy alignment. In mid-2025 CMS announced a voluntary interoperability commitment involving a large group of health IT companies, payers, and providers, focused on patient-facing digital tools and data sharing. It runs alongside TEFCA rather than replacing it, and the relationship between these initiatives is still taking shape. This is an area where things have moved quickly, so verify current status.
Consolidation. With multiple QHINs competing and legacy frameworks converging, some consolidation is likely. Pick a QHIN with a plausible independent future, and read your exit terms.
Frequently Asked Questions
What is TEFCA in healthcare?
TEFCA is the nationwide legal and technical framework that lets healthcare organizations share patient data after signing a single agreement rather than negotiating separate contracts with every partner. In day-to-day terms, it is how a hospital in one state can pull records from a clinic in another without a preexisting relationship between them.
What does TEFCA stand for?
Trusted Exchange Framework and Common Agreement. It was mandated by Section 4003 of the 21st Century Cures Act and is administered by The Sequoia Project as Recognized Coordinating Entity under ASTP/ONC.
Is TEFCA mandatory?
No. Participation is voluntary for providers, payers, and vendors. Information blocking rules create indirect pressure by making TEFCA a defensible way to fulfill requests, but they do not require joining.
What is a QHIN?
A Qualified Health Information Network: an organization designated to sign the Common Agreement directly, connect to all other QHINs, and route exchange for its Participants. As of early 2026 there were roughly eight designated QHINs.
What is the difference between TEFCA and Carequality?
Carequality is a participant-governed trust framework that connects networks to each other. TEFCA is federally mandated, administered by a designated coordinating entity, and establishes a single nationwide floor of legal trust. Several organizations participate in both, and some Carequality-connected networks are now QHINs.
What changed in TEFCA 2.0?
Common Agreement 2.0 and QTF 2.0, published in July 2024, committed the program to FHIR-based exchange through Facilitated FHIR, moved operational requirements into SOPs, broadened exchange purpose support obligations, and strengthened cybersecurity requirements.
Does TEFCA use FHIR?
Increasingly. Version 1.0 exchange was predominantly document-based using IHE profiles and C-CDA. TEFCA 2.0 requires FHIR support on a staged timeline defined in Sequoia’s FHIR Roadmap.
Can patients use TEFCA to get their own records?
Yes, through Individual Access Services. A patient uses an IAS Provider application, completes identity proofing, and requests records from participating organizations. Availability depends on which IAS applications and providers are live.
How much does joining TEFCA cost?
There is no published standard price. Fees vary by QHIN, by tier, and by negotiated terms, and many EHR and HIE arrangements bundle connectivity into existing contracts. Get quotes from multiple QHINs.
Does TEFCA replace HIPAA?
No. HIPAA continues to govern permitted uses and disclosures. TEFCA adds contractual obligations and extends comparable privacy and security duties to participating entities that HIPAA does not otherwise cover.
What to Do Next
If you are evaluating TEFCA, the useful first step is not reading the Common Agreement. It’s answering one question: are you joining primarily to query, or primarily because you’ll be obligated to respond?
Organizations that join to query build a business case around avoided duplicate testing, faster transfers, and cheaper record retrieval. Organizations that join because responding is coming anyway should focus on response infrastructure, exchange purpose policy, and C-CDA quality, because that is where the effort will actually land.
Then get concrete: ask your EHR vendor which QHIN they support and on what timeline, ask two QHINs for pricing and FHIR roadmaps, and ask your privacy officer how you’ll handle consent for sensitive data categories under your state’s law. Those three conversations will tell you more than another month of reading.