The Future of Healthcare IT: Insights from the HTI-2 Proposed Rule
Subscribe to our newsletter
SubscribeSignificant changes are coming to the world of healthcare IT in the U.S. with the introduction of the Health Data, Technology, and Interoperability (HTI-2) proposed rule.
Released by the United States’ Office of the National Coordinator for Health Information Technology (ONC), these new set of proposals build on HTI-1 with a strong focus on standards-based APIs. The aim is to improve end-to-end interoperability between healthcare providers, public health organizations, and payers in the U.S., emphasizing the adoption of HL7 Fast Health Interoperability Resources (FHIR) standards to make this happen.
At 1067 pages, there’s a lot to unpack in the full document – so we’ve summarized the key aspects of the HTI-2 Proposed Rule and explore the enhancements and new standards that are set to reshape the U.S. healthcare ecosystem. Let’s dive in!
Adoption of USCDI v4
A major update is the inclusion of United States Core Data for Interoperability (USCDI) v4, which incorporates HL7 FHIR US Core Implementation Guide Version 7.0 and HL7 Consolidated CDA (C-CDA) Version 3.0.0.
This would introduce 20 new data elements for things like goals and preferences and Health Status Assessments – some of which are specifically relevant to behavioral health and marginalized and underserved communities.
By standardizing these data elements, USCDI v4 aims to facilitate better data interoperability across different care settings, address disparities in health outcomes, and improve the overall quality of healthcare.
Transition to SMART App Launch 2.2
The rule proposes adopting SMART App Launch Framework version 2.2.0, enhancing security and usability for apps connecting to FHIR-based APIs. It includes new specifications for app registration and token exchange, improving the overall ecosystem for patient and provider applications.
Under the HTI-2 Proposed Rule, Health IT Modules can use SMART v1, v2, or v2.2 until December 31, 2025. By January 1, 2026, modules must update to SMART v2 or v2.2 to stay certified. By January 1, 2028, all modules must adopt SMART v2.2, ensuring they meet the latest healthcare data interoperability standards.
Introducing Modular API Capabilities
HTI-2 also looks to introduce “Modular API Capabilities” as a new certification category, promoting a more flexible approach for health IT developers. This modular approach supports a variety of use cases in clinical, public health, and administrative areas, encouraging innovation and making it easier to meet different needs.
The proposal refines criteria for current capabilities such as dynamic client registration (which would enable automated and secure registration of apps that use FHIR APIs), and SMART App Launch user authorization.
New capabilities include “workflow triggers for decision support interventions,” adopting the CDS Hooks Release 2.0, “verifiable health records” using the SMART Health Cards Framework, and “event notifications” supported by the HL7 FHIR Subscriptions Framework.
Patient, Provider, and Payer APIs
One of the most exciting proposals is new certification criteria that align with CMS-established API requirements and recommendations, designed to make data exchange smoother among patients, providers, and payers.
These APIs aim to support more effective exchange of clinical, coverage, and prior authorization information to reduce administrative burdens, improve care coordination, and give patients easier access to their health data.
Specific APIs include:
- Patient access API: Enables patients to access their health and administrative information using health applications of their choice, including everything from payer drug formulary details to patient clinical, coverage, and claims information.
- Provider access API: Supports provider access to payer information, including patient clinical, coverage, and claims data.
- Payer-to-payer API: Supports electronic data exchange between payer systems, allowing patient information to follow them when they change insurance plans and enabling improved coordination of care.
- Prior authorization API: Supports electronic prior authorization by providers and payers, reducing the huge administrative burden associated with the current (mostly) manual prior authorization process.
- Provider directory API: Allows payers to publish information about providers that participate in their networks, helping patients to understand which providers, facilities, and pharmacies are covered by their current or future plans.
Enhancements for Public Health
The HTI-2 Proposed Rule supports and extends CDC’s Public Health Data Strategy (PHDS) with important additions, including the transition to FHIR-based exchange which will establish minimum capabilities for health IT systems.
Key updates include new standards for immunizations, syndromic surveillance, electronic lab reporting, and cancer registry reporting. There are also new criteria for birth reporting and bi-directional exchange with prescription drug monitoring programs (PDMP) are introduced.
An important addition is the proposal for new criterion for a standardized FHIR-based API for public health data exchange, which aims to facilitate the development and adoption of public health FHIR Implementation Guides (IGs), ensuring standardized and efficient data exchange. This API supports core FHIR capabilities like event notifications, bulk data export, and robust authorization.
Clarity on Information Blocking
There are some key changes in HTI-2 to information blocking regulations. Notably, two new information blocking exceptions have been added to address concerns about patient privacy, care access, and information sharing.
The new Protecting Care Access Exception lets actors restrict information sharing in certain circumstances to protect patient access to care. The Requestor Preferences Exception outlines when actors must honor an information sharing partner’s preferences on how much electronic health information (EHI) is made available to the partner.
Important Compliance Dates
The HTI-2 Proposed Rule outlines key compliance dates for health IT developers to update their systems according to new certification criteria, with updates required between 2026 and 2028.
Key Dates:
- By January 1, 2026: Updates are required for criteria related to health IT encryption, trusted connections, and protection of stored authentication credentials.
- By January 1, 2027: Updates are required for criteria related to the provider prior authorization API and public health reporting (such as antimicrobial use and resistance reporting, and health care surveys).
- By January 1, 2028: Updates are required for a broader range of criteria, covering inclusions such as multi-factor authentication, standardized API for public health data exchange, provider access API, electronic prescribing, patient engagement functionalities, and more.
If the proposal moves forward, 2028 is set to be an exciting year for health IT. With the convergence to FHIR standards and a whole bunch of new capabilities rolling into production, we can expect significant advancements in interoperability, efficiency, and patient care across the healthcare system.
A Step Forward for Interoperability
Everyone in healthcare agrees there’s room to improve interoperability, reduce admin burden, enhance care coordination, and give patients easier access to their health data. The HTI-2 Proposed Rule looks like a big step in that direction, and it’s great to see the ONC working closely with CMS and CDC, and the industry, to better understand what’s needed.
If you want to delve deeper into the new proposed rule, head over to healthit.gov/proposedrule. It will be published soon in the Federal Register and open for public comment for 60 days.
Concerned about what these changes might mean for your organization? Feel free to get in touch with one of our experts to see how we can support you.