Skip to main content
v2026.11,610 entries · CC-BY 4.0

Syndromic Surveillance Reporting for Hospitals: The ED Feed, NSSP Onboarding, and the CMS Measure

A hospital syndromic surveillance feed carries near-real-time ED registration and triage data to a public health agency. This guide covers the NSSP Priority 1/2/3 data elements and their completeness thresholds, the Engage-Connect-Validate-Operate onboarding sequence, and the CMS Public Health and Clinical Data Exchange objective that scores it, including the active engagement options and their one-period clock.

Ask about Syndromic Surveillance Reporting for Hospitals: The ED Feed, NSSP Onboarding, and the CMS Measure

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A syndromic surveillance feed is the one public health data stream a hospital sends before anyone knows what the patient has. It carries no diagnosis requirement, no case definition and no clinician decision to report. It is a near-real-time copy of emergency department registration and triage traffic — chief complaint text, admit reason, age, ZIP code, patient class, visit identifier — pushed to a public health agency on a batch schedule so an epidemiologist can see a shape in the data days before laboratory confirmation exists.

For a hospital, that stream is simultaneously three things: an infection prevention asset, an IT integration project with a specific transport and validation sequence, and a scored measure inside the Medicare Promoting Interoperability Program. This guide covers all three, and it is deliberate about which source governs which: the message content and onboarding steps come from CDC’s National Syndromic Surveillance Program (NSSP), and the attestation requirements come from CMS regulation and the annual IPPS rules — not from CDC.

Syndromic surveillance is not electronic case reporting, and not NHSN

These three get conflated constantly, including inside hospitals that already do all of them. They are separate mechanisms with separate triggers, separate standards and separate measures.

Mechanism Trigger What is sent Timing
Syndromic surveillance Every qualifying encounter — no diagnosis needed De-identified registration/triage data: chief complaint, admit reason, diagnosis codes if present, demographics, disposition Continuous batch, typically every 15 to 60 minutes
Electronic case reporting (eCR) A reportable condition is suspected or diagnosed A structured case report on a specific patient with a specific condition Event-driven, per case
NHSN HAI surveillance An infection meeting a CDC surveillance definition Numerator events plus denominator device- or patient-days, adjudicated by an infection preventionist Monthly, retrospective

The practical consequence: syndromic surveillance is the only one of the three that is not adjudicated by a human. Nobody in your infection prevention department decides which visits go into the feed. That is why data-element completeness, not clinical judgment, is the entire quality problem — and why the CDC thresholds below are stated as percentages rather than as case definitions. It is also why an epidemic curve built from syndromic data uses visit date rather than onset or specimen date: the feed does not know onset.

Syndromic surveillance is likewise distinct from the counted, defined HAI measures — CLABSI, CAUTI and ventilator-associated events — which run on NHSN’s own definitions and reporting calendar, and from measure-based reporting such as SEP-1. If your organisation’s public health reporting inventory has one line item called “reporting to the health department,” it is almost certainly hiding at least four separate obligations. See the patient safety cluster for how these fit together.

What an ED syndromic feed actually sends

NSSP publishes a data-element prioritisation job aid that assigns every element in a syndromic message to Priority 1, 2 or 3, and maps each to its location in the HL7 v2.5.1 message. Priority level, not the message standard’s own optionality, is what determines whether a facility can reach and hold production status.

Priority 1 — the minimum to reach production

CDC describes Priority 1 elements as “the minimum required to perform surveillance activities.” A facility must hold these to a minimum standard of completeness and validity to achieve and keep production status. The elements, with the HL7 locations CDC’s job aid assigns them:

Data element HL7 location (per CDC) Usage
Admit_Date_Time PV1-44.1 R
Admit_Reason_Description PV2-3.2, PV2-3 RE
C_Chief_Complaint OBX or PV2-3 CRE
Chief_Complaint_Text OBX-2, 3, 5 RE
C_Unique_Patient_ID PID-3.1 CR
C_Patient_Class / Patient_Class_Code PV1-2.1 (or calculated) CR / R
C_Patient_Age, C_Patient_Age_Years OBX-2, 3, 5 CRE
Patient_Zip PID-11.5 RE
Diagnosis_Code, Diagnosis_Description DG1-3.1 / DG1-3.4, DG1-3.2 / DG1-3.5 RE
Facility_Type_Code, C_FacType_Patient_Class OBX-2, 3, 5 R / CR
C_Facility_ID EVN-7.2, MSH-4.2 or MSH-4.1 CR
Sending_Facility_ID MSH-4.2 or MSH-4.1 R
Treating_Facility_ID EVN-7.2 R
Visit_ID PV1-19.1 R
Trigger_Event MSH-9.2 R
Processing_ID MSH-11.1 R
C_Death PID-30.1 CRE

Read that list for what it does not contain. There is no patient name, no full date of birth, no street address, no clinician note. The identifying content is a facility-scoped patient identifier, a visit identifier and a five-digit ZIP. The analytic content is overwhelmingly the free-text chief complaint plus a coded diagnosis when one exists at the time of the message — which is why chief-complaint text quality, not diagnosis coding, is where syndromic signal is won or lost.

Priority 2 and Priority 3

Priority 2 elements are “also useful for surveillance activities and may be required by sites before a facility can move to production.” NSSP requires Priority 2 elements to meet minimum completeness and validity standards within 12 months of a facility achieving production status — a deadline that is easy to miss because it falls after the go-live everyone celebrates. Priority 2 covers discharge disposition and discharge date/time, administrative sex, reported age and age units, race and ethnicity, patient city/state/county/country, medical record number, message and recorded date/times, admit reason code, diagnosis type, and the message version identifier.

Priority 3 is mostly optional and NSSP does not require it to be populated. It is where the clinically richest fields live: triage notes, initial acuity, initial temperature and pulse oximetry, blood pressure, clinical impression, initial evaluation note, travel history, medication and problem lists, smoking status, height and weight, procedure codes, and the treating physician identifier. A jurisdiction that wants respiratory-season severity signal will usually be asking for Priority 3 fields, and it will be asking your EHR team, not CDC.

The message standard

The current published standard is the PHIN Messaging Guide for Syndromic Surveillance: Emergency Department, Urgent Care, Inpatient and Ambulatory Care Settings, Release 2.0 (April 2015), together with its erratum dated 21 April 2015, built on HL7 v2.5.1 and backward-compatible with v2.3.1. It covers ADT trigger events A01, A03, A04 and A08, with an optional ORU^R01 notation for laboratory data. A newer HL7 Version 2.5.1 Implementation Guide: Syndromic Surveillance, Release 1 — US Realm was published as a Standard for Trial Use in July 2019 and is listed by CDC as available for early adoption rather than as the certification standard; it draws on ICD-10-CM, SNOMED CT, LOINC, RxNorm, UCUM and CPT-4. Before onboarding, messages must pass the NIST HL7 v2.5.1 Syndromic Surveillance validation tool. Vocabulary bindings come from CDC’s PHIN Vocabulary Access and Distribution System (VADS).

We do not reproduce the message structure here. HL7 v2.5.1 is a copyrighted standard distributed through HL7 International; the segment and field identifiers above are cited as locators from CDC’s own public mapping, and any implementer needs the licensed guide itself.

The NSSP onboarding sequence

Three roles carry the work, and confusing them is the most common reason a hospital’s onboarding stalls:

  • Facility — the organisation submitting data. CDC notes this can also be an EHR vendor or a health information exchange acting on the hospital’s behalf.
  • Site — the public health authority that acts as administrative hub for a group of facilities.
  • Site administrator — the primary public health contact at each site, who runs onboarding and acts as liaison to NSSP. If you do not know yours, CDC’s instruction is to ask your state or local health department, or open an NSSP Service Desk ticket.

Onboarding runs as pre-onboarding planning followed by four named phases: Engage, Connect, Validate, Operate. Both facility and site acknowledge the process by completing a BOPA (BioSense Platform Onboarding Process Acknowledgement) form, and a Feed Profile records the contacts who receive automated system alerts.

Connect — transport decisions you make once

Two transport methods are accepted. SFTP is CDC’s stated preference and uses outbound port 22; PHINMS (the Public Health Information Network Messaging System) uses outbound port 443 and is limited to public health agencies and facilities that already have PHINMS installations exchanging with CDC or a PHINMS partner. CDC’s own decision prompts are worth borrowing verbatim for the firewall conversation: is local support available, is permission required to install, and will firewall rules be affected. A connection routed through an HIE or another non-standard path will differ, and CDC directs those cases to the onboarding team.

Authentication for a new SFTP feed uses an SSH key pair requested through the NSSP Service Desk; PHINMS authentication is likewise requested through the Service Desk. The feed is configured against a staging (onboarding) environment first, and the phase closes with a “hello world” test upload to the feed’s incoming directory to confirm receipt. Common tooling: WinSCP, FileZilla, or the SFTP capability already present in an interface engine such as Rhapsody or Mirth.

Validate — where the real thresholds sit

This is the phase that determines whether the project finishes. Its concrete requirements:

  1. File format and naming convention must be valid. Files whose name or batch/message structure is wrong are not processed at all — they do not generate a data-quality finding, they simply do not land.
  2. Set the batch schedule. CDC’s preference is transmission in 15- to 60-minute increments; the floor is at least once every 24 hours. Anything slower than that is not a syndromic feed in any useful sense.
  3. Confirm the data contain no more than the minimum allowable PII and that elements are mapped correctly. This is the step where a hospital privacy office should be a named participant, not a downstream reviewer.
  4. Meet the completeness and validity minimums. Priority 1 elements carry an 80% threshold. Priority 2 elements are assessed within 12 months of completing onboarding to production. Sites may impose their own additional minimums on top of NSSP’s.
  5. Activate in the Master Facility Table. Once data meet both NSSP and site minimums, the facility’s status is set to Active in the MFT. The NSSP onboarding team runs a final validation and either approves or declines the activation request, returning rejected information to the site for review.
  6. Repoint the feed to production and begin live data flow.

Operate — and the deactivation rule nobody plans for

Production is not the end state; it is a state you can lose. CDC’s onboarding guidance is explicit that facilities which fail to send data for visits occurring in the past 90 days can be deactivated. An ED that changes registration workflow, migrates EHR instances, or lets an interface engine job fail silently over a holiday period can therefore fall out of production without anyone in the hospital noticing — while the CMS measure that depends on it is still being attested to. Build the feed’s liveness into the same monitoring that covers your other clinical interfaces, and name an owner for the alert address in the Feed Profile.

How this satisfies a Promoting Interoperability objective

Here is the part most published guidance gets wrong, because it cites a paragraph of the Code of Federal Regulations that no longer governs.

Where the requirement actually lives now

The Syndromic Surveillance Reporting measure sits under the Public Health and Clinical Data Exchange objective. Search the CFR for it and you will land on 42 CFR 495.24, whose paragraph (e)(8) enumerates the measures in full. But read that section’s own applicability statement: paragraph (e) applies to eligible hospitals and CAHs attesting to CMS for 2019 through 2022. Paragraph (f) is what applies for 2023 and subsequent years — and paragraph (f) does not enumerate the measures at all. It requires only that hospitals “meet all objectives and associated measures selected by CMS under section 1886(n)(3) of the Act for an EHR reporting period.”

The practical implication: for a Medicare-attesting hospital today, the operative measure specification is in the annual IPPS final rule and CMS’s published specification sheets, not in the CFR. The same is true of the programme’s other major reporting duty: the electronic clinical quality measures a hospital must submit are not among the scored objectives at all, and their count and composition are set each year by the IPPS rule. This is not a technicality. The CFR text at 495.24(e)(8)(ii)(A) still says the measure covers syndromic data “from an urgent care setting” for CYs 2019 through 2021, switching to “an emergency department setting (POS 23)” only for CY 2022; and the Stage 3 paragraph (c)(8)(ii)(B), which applies to a different attestation path, still says urgent care. A hospital reading the CFR alone can arrive at a setting scope that does not match what it is being scored on.

Paragraph (f) does carry the scoring thresholds: a total score of at least 60 points in 2023 and 2024, at least 70 points in 2025, and at least 80 points in 2026 and subsequent years. It also gives CMS discretionary authority, beginning with the CY 2026 reporting period, to suppress an affected measure — either awarding maximum points if the measure is still reported, or excluding it from the meaningful-EHR-user determination if it is not — where circumstances such as out-of-date or conflicting technical standards, or the technical and operational capacity of required partners, would make the score misleading.

The CY 2026 measure set

Per the FY 2026 IPPS/LTCH PPS final rule, there are eight measures under the objective. Six are required: Immunization Registry Reporting, Syndromic Surveillance Reporting, Electronic Case Reporting, Electronic Laboratory Reporting, Antimicrobial Use Surveillance, and Antimicrobial Resistance Surveillance. Two are optional bonus measures: Public Health Registry Reporting and Clinical Data Registry Reporting.

Beginning with the CY 2026 reporting period, CMS finalised a third optional bonus measure, Public Health Reporting Using TEFCA. To attest “yes,” a hospital must (1) be a signatory to a TEFCA Framework Agreement, (2) not be suspended under it, (3) submit health information using TEFCA to a public health agency consistent with one or more measures under the objective, (4) be in active engagement Option 2 for one or more of those measures, and (5) use CEHRT functions to exchange with the agency. The bonus is capped: a hospital may attest yes to more than one optional bonus measure but earns a maximum of 5 bonus points in total. CMS confirmed TEFCA is intended to complement rather than replace existing exchange arrangements.

Two of the required measures — Antimicrobial Use and Antimicrobial Resistance Surveillance — are reported through NHSN’s AUR module and belong to a different operational owner than the syndromic feed, usually the antimicrobial stewardship programme working from the same data your cumulative antibiogram draws on. Vaccine safety reporting via VAERS and blood safety reporting via NHSN Hemovigilance are separate again and do not count toward this objective.

“Active engagement” — the two options, and the clock on Option 1

Active engagement is the mechanism by which a measure with no percentage numerator gets scored. Through CY 2022 there were three options: completed registration, testing and validation, and production. In the FY 2023 IPPS/LTCH PPS final rule, CMS consolidated the first two and renamed the third, effective with the CY 2023 reporting period:

  • Option 1 — Pre-production and Validation. Combines completed registration to submit data with being in the process of testing and validation. CMS clarified that a hospital that has registered but not begun testing is still in Option 1, and should begin testing on receiving the agency’s invitation.
  • Option 2 — Validated Data Production. Testing and validation are complete and the hospital is electronically submitting production data.

Three consequences follow, and they are the operational core of the measure:

  1. You must report which option you are in, for each measure you report, beginning with the CY 2023 reporting period. This was not required before.
  2. Option 1 is time-limited to one EHR reporting period per measure. CMS’s own worked example: a hospital reporting Option 1 for Syndromic Surveillance Reporting in one reporting period must report Option 2 for the next reporting period in which it reports that measure, or it fails the objective. CMS finalised this limit with a delay — it applies beginning with the CY 2024 reporting period, not CY 2023.
  3. Switching agencies buys one additional period. If a hospital changes to a different public health agency or clinical data registry, it is permitted an additional reporting period at Option 1 to assist with onboarding to the new partner. The one-period limit assumes the same partner throughout.

Mapped onto the NSSP sequence above: Engage and Connect and most of Validate are Option 1. Option 2 begins when the Master Facility Table status is Active and the feed points at production. A hospital that budgets a year for onboarding and then discovers it has already burned its single Option 1 reporting period has a scoring problem it cannot fix retroactively.

The exclusions — and how CMS reads them

The regulation text at 42 CFR 495.24(e)(8)(iii)(A) allows a hospital to be excluded from the syndromic surveillance measure if it meets one or more of:

  1. For CYs 2019, 2020 and 2021, it does not have an emergency or urgent care department; for CY 2022, it does not have an emergency department.
  2. It operates in a jurisdiction where no public health agency has declared readiness to receive syndromic surveillance data from eligible hospitals or CAHs as of six months prior to the start of the EHR reporting period.

Parallel exclusions elsewhere in the section turn on a jurisdiction’s public health agency not being “capable of receiving data in the specific standards required to meet the CEHRT definition” at the start of the reporting period. That phrase looks like a technical-capability test. It is not, or not only. In the FY 2026 IPPS/LTCH PPS final rule, CMS stated that it interprets “capable of receiving data in the specific standards required” to mean that the public health agency in the hospital’s jurisdiction has the ability to advance, and has advanced, a hospital registered with it to Active Engagement Option 2: Validated Data Production.

That reading materially narrows the exclusion. An agency that can technically accept HL7 v2.5.1 messages but has never actually moved a registered hospital to validated production is, on CMS’s interpretation, not capable in the sense the exclusion requires. Conversely, a hospital claiming this exclusion should be able to evidence that its agency has not advanced anyone — which is an assertion about the agency’s onboarding record, not about your interface engine.

A readiness checklist

  1. Identify your site administrator at the state or local health department before doing anything technical.
  2. Establish which reporting period you will first attest Option 1 in, and work backwards — you get one.
  3. Confirm your EHR’s certified syndromic surveillance capability and run messages through the NIST validation tool before requesting a feed.
  4. Decide SFTP or PHINMS with your network team, and settle the outbound port (22 or 443) and firewall change in the same conversation.
  5. Get the privacy office into the Validate phase, on the minimum-allowable-PII step, not afterwards.
  6. Measure Priority 1 completeness against 80% on your own staging extract before submitting for validation. Chief complaint text and patient class are the usual failures.
  7. Diary the Priority 2 twelve-month deadline from your production go-live date.
  8. Add the feed to interface monitoring with the 90-day inactivity deactivation rule as the alarm condition.
  9. Record your active engagement option per measure in the same place you keep attestation evidence — you now report it, and it is auditable.
  10. Re-read the current IPPS final rule and CMS specification sheet each year rather than the CFR paragraph. The CFR stopped enumerating these measures for hospitals after CY 2022.

What this page does not assert

Two limits, stated plainly rather than papered over.

CDC source access. cdc.gov returns HTTP 403 to automated retrieval by every method tried. The NSSP material above was read from the RestoredCDC mirror of CDC’s pages, whose snapshot is dated 6 January 2025, and CDC’s own page dates on that material run from October 2020 to April 2024. NSSP has since reorganised its site. Treat the transport hostnames, service-desk routing and tooling references as directionally correct but confirm them with your site administrator or the NSSP Service Desk before configuring anything — those are exactly the details most likely to have moved. The thresholds and phase structure are more stable, but they too are CDC’s to change.

Message structure. We cite HL7 segment and field identifiers as locators from CDC’s public mapping and do not reproduce any part of the HL7 v2.5.1 standard or the PHIN messaging guide. Anyone building the interface needs the licensed guide; the element list above tells you what to ask your vendor for, not how to construct a message.

We have also not stated a national participation figure, an average onboarding duration, or a count of participating facilities. Figures of that kind circulate widely and we could not verify any of them against a primary source that is currently reachable.

Frequently asked questions

Is syndromic surveillance reporting mandatory for hospitals?

Not as a standalone federal mandate. It is one of six required measures under the Public Health and Clinical Data Exchange objective for eligible hospitals and CAHs attesting to the Medicare Promoting Interoperability Program, with exclusions available where the hospital has no emergency department or the jurisdiction’s public health agency has not declared readiness. Separately, state law may impose its own reporting requirement — check your jurisdiction, because the federal measure and the state requirement are not the same instrument.

What is the difference between NSSP and BioSense?

NSSP is CDC’s programme. The BioSense Platform is the cloud infrastructure NSSP operates — the thing your feed connects to, where facility status is managed in the Master Facility Table and where ESSENCE runs as the analytic front end used by public health analysts.

Does an urgent care clinic count?

It depends on the reporting period and the attestation path, which is precisely the trap. The CFR text for CYs 2019 through 2021 refers to an urgent care setting; for CY 2022 it refers to an emergency department setting (POS 23). For CY 2023 onward, the CFR delegates to CMS’s annual measure selection, so the current specification sheet governs. The NSSP messaging guide itself covers emergency department, urgent care, inpatient and ambulatory care settings — CDC’s technical scope is broader than the CMS measure’s scoring scope.

How often does the feed have to transmit?

CDC’s stated preference is batch transmission in 15- to 60-minute increments, with a floor of at least once every 24 hours. The near-real-time cadence is the point of the mechanism; a daily batch is technically compliant with the floor and analytically much weaker.

What happens if data quality drops after go-live?

Priority 1 elements carry an 80% completeness and validity threshold that applies to maintaining production status, not only to reaching it, and sites may set their own additional minimums. Separately, a facility that sends no data for visits occurring in the past 90 days can be deactivated. Both are recoverable, but both require re-engagement with the site administrator rather than a fix inside the hospital alone.

Can we use TEFCA instead of an SFTP feed?

Not as a substitute for the required measure’s underlying reporting, no. Beginning with CY 2026, using TEFCA for public health reporting is an optional bonus measure worth up to 5 points, available only when the hospital is already in active engagement Option 2, and CMS was explicit that it complements rather than replaces existing exchange methods. A hospital can also claim the bonus while using TEFCA to fulfil a required measure such as Electronic Case Reporting or Electronic Laboratory Reporting.

Who owns this in the hospital?

In practice it splits three ways and that is the failure mode. The interface and transport belong to IT or the integration team; data-element completeness belongs to whoever owns ED registration and triage documentation; and the attestation, including the active engagement option you report, belongs to whoever signs the Promoting Interoperability attestation. Assigning all three to the infection preventionist because the word “surveillance” appears in the name is a reliable way to miss the Option 1 clock.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →