A patient sees a primary care doctor, gets referred to a specialist across town, has bloodwork done at a separate lab, and picks up a prescription from a pharmacy that has no direct connection to any of them. In a poorly connected system, none of these organizations automatically knows what the others are doing.
The scale of this fragmentation problem is significant: research published in health policy journals has found that the average Medicare patient sees roughly two primary care physicians and five specialists across four different practices each year, and a substantial share of those encounters occur without the treating physician having full visibility into care delivered elsewhere, contributing to an estimated $25 to $45 billion in unnecessary duplicate testing and avoidable complications annually, according to various health economics analyses.
That is the practical problem interoperability tries to solve. Healthcare needs information to move between organizations so patients receive coordinated care, but sensitive information also cannot move carelessly without appropriate safeguards. Both requirements have to be satisfied at once, and the federal government has invested heavily in solving this problem: since the 2009 HITECH Act allocated more than $35 billion in incentive payments to encourage electronic health record adoption, hospital EHR adoption has climbed from under 10 percent in 2008 to well over 96 percent today according to ONC tracking data, yet true interoperability, meaning systems that can actually exchange meaningful clinical data with each other, has lagged well behind that adoption curve.
The Real Problem Interoperability Is Trying to Solve
Consider a patient with a chronic condition who sees a primary care physician, a specialist, and occasionally visits an emergency room. Without reliable information exchange, this creates duplicated tests because previous results are not visible, missing medication histories that increase the risk of dangerous drug interactions, and delayed information that slows down care during urgent situations.
Fragmented records mean each provider is working from an incomplete picture rather than the full clinical story, and studies of emergency department care have found that physicians report needing outside records they cannot readily access in a meaningful share of visits involving patients with complex or chronic conditions.
Interoperability Has More Than One Layer
Technical interoperability refers to whether systems can physically connect and exchange data at all. Syntactic interoperability means the data exchanged follows a common format that receiving systems can parse. Semantic interoperability goes further, ensuring that both systems understand the meaning of the data in the same way, so a diagnosis code means the same thing on both ends of the exchange.
Organizational and policy interoperability addresses whether the participating organizations have agreed on governance, trust, and legal frameworks that allow exchange to happen responsibly. Two systems being technically connected does not guarantee meaningful information exchange if these other layers are missing. A hospital and a clinic can have compatible software while still failing to exchange clinically useful information because of mismatched terminology or absent data-sharing agreements, a gap ONC has repeatedly identified as more common in practice than pure technical incompatibility.
The Standards That Make Exchange Possible
Application programming interfaces, commonly called APIs, allow different software systems to request and receive data from each other in a structured way. FHIR, which stands for Fast Healthcare Interoperability Resources, is a widely adopted standard that defines how health data should be structured and exchanged through these APIs, and its adoption has grown dramatically since its introduction in 2014; ONC now requires certified EHR technology to support FHIR-based APIs, and the vast majority of hospitals nationwide report having FHIR-enabled patient access APIs in place following the 2020 Cures Act final rule.
USCDI, the United States Core Data for Interoperability, defines a standardized set of health data classes and elements that systems are expected to be able to exchange, with the dataset expanding in scope through annual updates as ONC adds new data classes like clinical notes and social determinants of health information.
TEFCA, the Trusted Exchange Framework and Common Agreement, functions as a nationwide framework intended to support secure exchange across organizational boundaries. The Office of the National Coordinator for Health IT describes TEFCA as a network of networks, designed so that participating organizations can exchange health information broadly rather than negotiating separate agreements with every other healthcare entity individually.
Since its first Qualified Health Information Networks went live in the mid-2020s, TEFCA participation has grown to cover a rapidly increasing share of the hospitals and providers nationwide, though full nationwide coverage remains a work in progress.
Why More Data Sharing Can Increase Privacy Risk
Every new connection between systems is also a new access pathway, and more pathways mean more places where something can go wrong. Identity matching errors, where one patient’s data gets mistakenly linked to another patient’s record, inappropriate access by authorized users viewing information beyond their need, misdirected data sent to the wrong recipient, and excessive permissions granted to third-party applications all become more likely as exchange expands.
Studies of patient matching accuracy have found error rates within a single health system can run from under 1 percent to well over 20 percent depending on the matching algorithm and data quality involved, a gap that widens considerably when matching patients across different organizations entirely.
Role-based access, which limits what each type of user can view based on their job function, and minimum necessary principles, which limit access to only what a specific purpose requires, help manage this expanded risk without shutting down beneficial data sharing altogether.
Designing Interoperability Around Privacy
Strong identity verification and authentication confirm that both the system and the person requesting data are legitimate. Authorization frameworks determine what a given user or system is permitted to access. Consent mechanisms, where applicable, respect patient preferences about how their information is shared.
Auditability creates a record of every access and disclosure, supporting accountability after the fact. Data minimization limits what gets shared to what is actually needed, encryption protects data in transit and at rest, and governance structures define who is responsible for what across a network of organizations. Vendor management and incident response planning round out a comprehensive approach, since a network is only as secure as its weakest connected participant.
Interoperability in the Patient Experience
Successful interoperability looks different depending on the situation. In an emergency, it means a treating physician can quickly access a patient’s allergies and current medications even if that patient has never been seen at that hospital before. When changing doctors, it means new records do not have to be manually requested and faxed from a previous provider, a process that historically could take days to weeks and, remarkably, fax machines remain in active use across a majority of U.S. hospitals for at least some record transfers even today, according to multiple health IT industry surveys.
For prescriptions, it means a pharmacy can see relevant clinical context rather than just a prescription order in isolation. For laboratory results, it means a specialist can view recent bloodwork from an unrelated provider instead of ordering a duplicate test. For chronic disease management, it means a care team spread across multiple organizations can work from a shared, current picture of the patient’s status. Patient access to their own information, often through a portal, is itself a key part of what interoperability is supposed to deliver, and patient portal adoption has grown substantially, with ONC survey data showing a majority of individuals offered portal access now use it at least once a year.
The Hardest Interoperability Problems Are Often Organizational
Technology gets much of the attention in interoperability discussions, but inconsistent workflows, misaligned incentives between organizations, legacy systems that predate modern data standards, data quality issues, terminology differences, a fragmented vendor ecosystem, hundreds of distinct certified EHR products remain in active use across the U.S. healthcare system, and unclear governance frequently cause more friction than any software limitation. Framing interoperability as purely a technical problem misses where much of the real difficulty lives.
What the Next Stage of Interoperability Should Accomplish
| Goal | What it means in practice |
|---|---|
| More standardized exchange | Consistent data formats across more organizations |
| Better patient access | Easier, more complete access to one’s own records |
| More usable data | Data that arrives structured and ready to use, not just present |
| Secure cross-organization workflows | Exchange that maintains privacy and security at scale |
| Public health and research use cases | Aggregated data supporting broader population health insights |
| Stronger privacy controls | Governance that keeps pace with expanding data access |
Interoperability does not mean unrestricted access to all patient information by anyone connected to a network. It means building systems where the right information reaches the right party, through the right safeguards, at the right time. The economic case for getting this right continues to grow alongside the technical one; some health system estimates suggest fully realized interoperability could save the U.S. healthcare system tens of billions of dollars annually through reduced duplicate testing, fewer preventable readmissions, and less administrative burden spent chasing down records that should have simply been available already.
Getting the technical layer right is necessary but not sufficient; the organizational and privacy layers ultimately determine whether interoperability actually improves patient care. As TEFCA participation expands and FHIR-based data exchange becomes the default rather than the exception across the industry, the gap between what is technically possible and what actually happens in daily clinical practice will be the space where the next decade of healthcare IT progress, or lack of it, plays out.
FAQ
Q: What is healthcare interoperability?
A: It refers to the ability of different healthcare systems and organizations to exchange, interpret, and use health information effectively across organizational boundaries.
Q: Why is interoperability important in healthcare?
A: It reduces duplicated testing, prevents missing medication histories, speeds up access to information during emergencies, and supports more coordinated care across providers.
Q: How does FHIR support interoperability?
A: FHIR provides a standardized format for structuring and exchanging health data through APIs, making it easier for different systems to communicate.
Q: What is TEFCA?
A: TEFCA is a nationwide framework intended to support secure health information exchange across organizational boundaries, functioning as a network of networks.
Q: Does interoperability make health data less private?
A: It can increase certain risks by creating more access pathways, which is why interoperability efforts must be paired with strong identity verification, access controls, and governance.
Q: Who controls interoperable health data?
A: Control is shared among the healthcare organizations that hold the data, the governance frameworks that regulate exchange, and, to varying degrees, the patients the data describes.
Q: What is semantic interoperability?
A: It means that systems exchanging data interpret that data’s meaning consistently, so a code or term represents the same clinical concept regardless of which system generated it.
Q: How can healthcare organizations share data securely?
A: Through strong authentication, role-based access controls, encryption, auditability, data minimization, and clear governance agreements between participating organizations.