HomeFrameworksHealthcare & Human ServicesTEFCA

Framework  Healthcare & Human Services

TEFCA

The Trusted Exchange Framework and Common Agreement is the federal framework, created under the 21st Century Cures Act, for nationwide exchange of electronic health information. The Office of the National Coordinator (now the Assistant Secretary for Technology Policy) sets policy, and The Sequoia Project, as Recognized Coordinating Entity, administers it.

Networks that meet the requirements sign the Common Agreement and are designated Qualified Health Information Networks; the first QHINs were designated in December 2023. Health systems, vendors, and payers join as Participants or Subparticipants by signing flow-down agreements with a QHIN.

A QHIN must be a U.S. entity, complete the application and onboarding process (about twelve months, including a twelve-month provisional period), pass conformance testing against the QHIN Technical Framework, and hold third-party security certification; the RCE has designated HITRUST r2 as the accepted certification.

In writing, a QHIN needs the signed Common Agreement, its governance and participation policies, privacy and security policies meeting the Common Agreement and applicable standard operating procedures, the security certification report, incident response and breach notification procedures, and records showing compliance with the exchange purposes and individual access rules.

AI-compiled
Share
Sponsored
TEFCA
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with TEFCA
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Participation is voluntary. Requirements bind health information networks that seek QHIN designation and, through flow-down terms, the Participants and Subparticipants that connect through them. Certified health IT developers face related information sharing obligations under separate ONC rules.

What the assessor asks to see

The RCE and assessors ask for the signed Common Agreement and U.S. ownership questionnaire, governance documents and participation policies, the QHIN Technical Framework test results, the HITRUST r2 certification report, privacy and security policies and the risk assessment, incident response and breach notification procedures with records, audit logging evidence, Participant and Subparticipant agreements with flow-down terms, and records of exchange purpose handling and individual access services.

Key dates

Common Agreement version 1 published January 2022; first QHINs designated December 2023; Common Agreement version 2.x and updated SOPs issued in 2024 and 2025. The QHIN Onboarding and Designation SOP was updated in January 2025 (version 3).

Assessors

Who assesses TEFCA

The RCE reviews applications, oversees conformance testing, and monitors QHINs. Security certification is assessed by HITRUST authorized external assessor firms under the HITRUST r2 program. There is no other third-party certifier for TEFCA itself.

Accredited by The RCE, under ONC/ASTP oversight, designates QHINs. HITRUST authorizes its external assessor firms.

No firm has claimed a TEFCA assessor listing yet. Claim yours →

Consultants

Who helps with TEFCA

Health information exchange consultancies, HITRUST assessor firms, and the QHINs themselves, which onboard Participants. Engagements for prospective QHINs run through the RCE's five-phase application and onboarding process; for Participants, the work is contracting, technical connection, and policy alignment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a TEFCA consultant listing yet. Claim yours →

Software

Tools for TEFCA

Tools that name this framework in their own material.

No firm has claimed a TEFCA tool listing yet. Claim yours →

Related reading

  1. Understanding TEFCA: A National Step Toward InteroperabilityA nonprofit health information exchange explains the network-of-networks design and what joining through a QHIN actually changes for a provider.Contexture
  2. A Technical Guide to TEFCA IntegrationDeveloper-level walkthrough of participation models, QHIN connectivity, exchange purposes and the security obligations that come with each.Medplum

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for TEFCA

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with TEFCA

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.