Written and maintained by CASRAI Editorial Board
Last updated
TEFCA participation is a procedure with defined steps, defined deadlines and defined grounds for denial — most of it codified at 45 CFR Part 172, which implements section 3001(c)(9) of the Public Health Service Act. This guide leads with that procedure: how an organisation becomes a Qualified Health Information Network, what the qualification requirements actually are, how long each stage takes, what happens on suspension or termination, and how to appeal. The framework description comes second, because for most readers the question is operational rather than definitional.
Two structural points first, because they determine which document governs which question. Part 172 governs QHIN qualification and process. The Common Agreement and its Standard Operating Procedures govern the substance of exchange — including the Exchange Purposes, which are not listed in the CFR. And most organisations never become a QHIN: they join as a Participant of a QHIN or a Subparticipant of a Participant, which is a contractual step under the Participant/Subparticipant Terms of Participation, not a regulatory designation.
Sources. All regulatory requirements, timeframes and process steps on this page are taken from the current 45 CFR Part 172 as published by the eCFR. The Exchange Purposes and the Treatment XP Implementation SOC date are taken from the Recognized Coordinating Entity’s own published material (rce.sequoiaproject.org). We do not list the currently Designated QHINs on this page: the application remains open on a rolling basis and the roster changes, so consult the RCE’s Designated QHINs directory for the current list rather than any secondary source.
Who is who
| Role | What it is | How you become one |
|---|---|---|
| ASTP/ONC | The Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology. The federal authority. Part 172 lets ASTP/ONC delegate defined responsibilities to the RCE. | — |
| RCE | Recognized Coordinating Entity. Operates the framework day to day under delegation. Many Part 172 steps read “ASTP/ONC (or an RCE)”. | — |
| QHIN | Qualified Health Information Network. Connects to other QHINs; the top tier of the exchange topology. | Regulatory Designation under Part 172 Subparts B and C. |
| Participant | An organisation exchanging through a QHIN. | Contract with a QHIN under the Participant/Subparticipant Terms of Participation. |
| Subparticipant | An organisation exchanging through a Participant (or another Subparticipant). | Contract with a Participant, under the same Terms of Participation. |
“Framework Agreement” is the umbrella term: with respect to QHINs it means the Common Agreement, and with respect to a Participant or Subparticipant it means the Participant/Subparticipant Terms of Participation.
The Exchange Purposes
An Exchange Purpose (XP) is defined at 45 CFR 172.102 as “the reason, as authorized by a Framework Agreement, including the applicable standard operating procedure(s) (SOP(s)), for a transmission, Query, Use, Disclosure, or Response transacted through TEFCA Exchange.” Each is identified in transactions by an Exchange Purpose Code.
Because the XPs live in the Common Agreement and its SOPs rather than in the regulation, the authoritative list is the RCE’s. There are currently six authorized Exchange Purposes:
- Treatment
- Payment
- Health Care Operations
- Public Health
- Government Benefits Determination
- Individual Access Services
The RCE states that additional exchange purposes may be added over time. A Treatment XP Implementation SOP, released in July 2024, specifies the conditions under which QHINs, Participants and Subparticipants are required to respond to a treatment query via TEFCA exchange, and the RCE has said a standing review process will be established to consider on an ongoing basis whether additional use cases qualify for the Treatment XP.
The XPs matter operationally in two ways. First, the qualification requirements at 172.201(b) tie directly to them: an applicant must already be exchanging for at least one authorized XP, must be capable of receiving and responding to transactions from other QHINs for all authorized XPs, and must be capable of initiating transactions for those XPs it will permit its Participants and Subparticipants to use. Second, Individual Access Services triggers an entire additional set of requirements — see below.
QHIN qualification requirements — 45 CFR 172.201
These are the substantive bar. An applicant bears the burden of demonstrating compliance with all of them (172.303(a)).
(a) Ownership
- Be a U.S. Entity.
- Not be under Foreign Control — defined at 172.102 as a non-U.S. person or entity “having the direct or indirect power, whether or not exercised, to direct or decide matters materially affecting the Applicant’s ability to function as a QHIN in a manner that presents a national security risk.” Note that the test is the power to direct, exercised or not.
(b) Exchange requirements — from the time of application
These may be met directly or “through the experience of its parent entity”. The applicant must:
- be capable of exchanging information among more than two unaffiliated organizations;
- be capable of exchanging all Required Information;
- be exchanging information for at least one authorized Exchange Purpose — present tense, not planning to;
- be capable of receiving and responding to transactions from other QHINs for all authorized Exchange Purposes;
- be capable of initiating transactions for those Exchange Purposes it will permit its Participants and Subparticipants to use.
Requirement 3 is the practical gate that excludes new entrants: you cannot become a QHIN in order to start exchanging. You must already be operating a health information network.
(c) Designated Network Services requirements
Ten requirements, all continuing obligations rather than one-time checks. The entity must:
- maintain the organisational infrastructure and legal authority to operate and govern its Designated Network;
- maintain adequate written policies and procedures to support meaningful TEFCA Exchange and fulfil all QHIN responsibilities;
- maintain a Designated Network that can support a transaction volume keeping pace with the demands of network users;
- maintain the capacity to support secure technical connectivity and data exchange with other QHINs;
- maintain an enforceable dispute resolution policy governing Participants, permitting them to reasonably, timely and fairly adjudicate disputes arising between each other, the QHIN, or other QHINs;
- maintain an enforceable change management policy consistent with QHIN responsibilities;
- maintain a representative and participatory group or groups with authority to approve processes for governing the Designated Network;
- maintain privacy and security policies that permit it to support TEFCA Exchange;
- maintain data breach response and management policies supporting meaningful TEFCA Exchange;
- maintain adequate financial and personnel resources, “including sufficient financial reserves or insurance-based cybersecurity coverage, or a combination of both”.
Requirements 5, 6, 7 and 10 are the ones organisations most often underestimate. They are governance and balance-sheet requirements, not technical ones — a technically capable network with informal governance and no cyber coverage does not qualify.
Additional requirements for Individual Access Services — 172.202
A QHIN that offers IAS takes on a distinct and considerably more consumer-facing set of obligations:
- obtain express consent from any individual before providing IAS;
- make publicly available a privacy and security notice meeting minimum TEFCA standards;
- where it is the IAS provider for an individual, delete the individual’s Individually Identifiable Information on request, except as prohibited by Applicable Law or where the information is contained in audit logs;
- permit any individual to export in a computable format all of their Individually Identifiable Information the QHIN maintains as an IAS provider;
- encrypt all Individually Identifiable Information it maintains;
- notify each affected individual in plain language, without unreasonable delay and in no case later than sixty (60) calendar days following discovery of unauthorized acquisition, access, disclosure or use of their Individually Identifiable Information involving the QHIN;
- have an agreement with a qualified, independent third-party credential service provider and verify individuals’ identities through it before first use of IAS and on expiration of their credentials.
The designation procedure — Subpart C, step by step
Step 1 — Application (172.301)
Submit, in a manner specified by ASTP/ONC: a completed QHIN application with supporting documentation in the form specified, and a signed copy of the Common Agreement. The signed Common Agreement is required at application, not at the end.
Step 2 — Completeness review (172.302(a))
ASTP/ONC or the RCE reviews for completeness. If incomplete, the applicant is notified in writing of the missing information within 30 calendar days of receipt. This timeframe may be extended on written notice.
Step 3 — Substantive review (172.302(b))
Once complete, the reviewer determines whether the applicant satisfies 172.201 and, if it proposes to provide IAS, 172.202. Review is completed within 60 calendar days of the applicant being given written notice that its application is complete. Extendable on written notice.
Step 4 — Requests for information (172.302(c)–(e))
Additional information may be requested during review, with a stated timeframe and submission manner. Two obligations attach:
- Failure to respond within the proposed timeframe or in the manner specified is a basis for the application to be deemed withdrawn under 172.305(c), on written notice.
- If any information already submitted becomes untrue or materially changes, the applicant must notify in writing within 5 business days of that happening.
Step 5 — Approval and Onboarding (172.303)
If the requirements are met, the applicant is notified in writing that the application is approved and may proceed with Onboarding. An approved applicant must submit a signed version of the Common Agreement within a timeframe set by ASTP/ONC or the RCE, and must complete Onboarding — including any tests required to ensure its network can connect to those of other QHINs and Applicant QHINs — within 12 months of approval, unless extended in ASTP/ONC’s or the RCE’s sole discretion by up to a further 12 months.
Step 6 — Designation (172.304(a))
When Onboarding is satisfied, the Common Agreement is countersigned and the applicant receives a written determination that it has been Designated as a QHIN, with a copy of the countersigned agreement.
Step 7 — The 30-day production transaction requirement (172.304(b)–(d))
This is the step most likely to catch an organisation out, because Designation is not the end.
- Within 30 calendar days of receiving its Designation, the QHIN must demonstrate that it has completed a successful transaction with all other in-production QHINs, according to the standards and procedures for TEFCA Exchange.
- If it cannot, it must provide a written explanation and a detailed plan and timeline. ASTP/ONC or the RCE reviews and approves or rejects the plan “based on the reasonableness of the explanation and the specific facts and circumstances, within five (5) business days of receipt.”
- If the QHIN fails to provide its plan, or the plan is rejected, the approval of the application is rescinded, the QHIN Designation is rescinded, and the application is denied.
- Where a plan is approved, within 30 calendar days of the end of its term the QHIN must again demonstrate a successful transaction with all other in-production QHINs.
- Designation becomes final 60 days after the QHIN has submitted documentation that it completed a successful transaction with all other in-production QHINs.
Note the structural consequence: every new QHIN’s go-live depends on the cooperation and availability of every existing in-production QHIN, and the number of required successful transactions grows with the size of the network.
Withdrawal, denial and re-application (172.305–172.307)
- Voluntary withdrawal — by written notice, at any point prior to Designation. An applicant that withdraws voluntarily may reapply at any time.
- Deemed withdrawal — for failure to respond to requests for information. Reapplication no sooner than 6 months after the date the previous application was submitted, and the new application must respond to the prior request for information and explain why no response was previously provided.
- Denial — written notice including the basis. Reapplication no sooner than 6 months after the date shown on the written notice of denial, and the new application “must specifically address the deficiencies that constituted the basis for denying” the previous one.
The asymmetry is deliberate and worth planning around: withdrawing before a decision preserves the ability to return immediately; being denied or deemed withdrawn costs six months.
Suspension, termination and appeal
Part 172 provides a full administrative structure after Designation:
- Subpart D — Suspension, covering QHIN suspensions (172.401) and selective suspension of exchange between QHINs (172.402). Selective suspension is the targeted remedy: exchange with one counterparty can be suspended without suspending the QHIN entirely.
- Subpart E — Termination, covering QHIN self-termination (172.501), termination by ASTP/ONC or the RCE (172.502), and termination by mutual agreement (172.503).
- Subpart F — Review of RCE or ASTP/ONC decisions: ASTP/ONC review (172.601), the bases on which a QHIN or Applicant QHIN may appeal (172.602), the method and timing for filing (172.603), the effect of an appeal on suspension and termination (172.604), assignment of a hearing officer (172.605), adjudication (172.606), and determination by the hearing officer (172.607).
If a suspension or termination is in prospect, the filing deadlines at 172.603 and the effect-of-appeal rule at 172.604 are the two provisions to read first, in that order.
Subpart G — QHIN Attestation
Separately from Designation, Part 172 establishes a voluntary attestation process: a QHIN may attest to its adoption of TEFCA (172.701), and accepted attestations are published in the QHIN Attestation Directory (172.702). The stated purpose of the Part at 172.100(b) names both objectives — ensuring full network-to-network exchange of health information, and establishing a voluntary process for a QHIN to attest to adoption of TEFCA.
The decision most organisations actually face
For a hospital, health system, laboratory, payer or vendor, the realistic question is not whether to become a QHIN. It is which of three routes to take.
| Become a QHIN | Join as a Participant | Join as a Subparticipant | |
|---|---|---|---|
| Governed by | 45 CFR Part 172 + Common Agreement | Participant/Subparticipant Terms of Participation, via contract with a QHIN | Terms of Participation, via contract with a Participant or Subparticipant |
| Prerequisite | Already operating a health information network exchanging among more than two unaffiliated organisations, for at least one XP | None regulatory — commercial and technical fit with a QHIN | None regulatory |
| Federal process | Application, review, Onboarding, Designation, production transactions, appeals | None | None |
| Ownership constraints | Must be a U.S. Entity, not under Foreign Control | Not imposed by Part 172 | Not imposed by Part 172 |
| Ongoing obligations | Ten continuing Designated Network Services requirements, plus IAS requirements if applicable | Contractual, per the Terms of Participation and the QHIN’s own policies | Contractual, flowed down |
| Typical adopter | Existing national or large regional networks and platform vendors | Health systems, large provider organisations, payers, HIEs | Individual practices and smaller organisations connecting through an existing Participant |
Practical questions to answer before selecting a QHIN as a Participant: which Exchange Purposes will it permit its Participants and Subparticipants to use (a QHIN need only be capable of initiating transactions for the XPs it permits — see 172.201(b)(5)); does it offer Individual Access Services and therefore carry the 172.202 obligations; what does its dispute resolution policy under 172.201(c)(5) actually provide; how does its change management policy under (c)(6) handle version transitions; and what is the composition and authority of the representative governance group required by (c)(7)?
How TEFCA interacts with information blocking
TEFCA participation carries a specific consequence under the information blocking rule. The TEFCA Manner exception at 45 CFR 171.403 provides that limiting the manner of fulfilling a request to only via TEFCA is not information blocking where four conditions all hold: the actor and requestor are both part of TEFCA; the requestor is capable of that exchange via TEFCA; the request is not via the standards adopted at 45 CFR 170.215 (including versions approved under 170.405(b)(8)); and any fees and any licence of interoperability elements satisfy 45 CFR 171.302 and 171.303 respectively.
The third condition is the boundary. Being a TEFCA participant does not let an actor redirect standards-based API requests into TEFCA. Subpart D of Part 171 also imports its definitions of Common Agreement, Framework Agreement, Participant, QHIN and Subparticipant directly from 45 CFR 172.102, so the two rules use one vocabulary. For the full set, see the guide to the information blocking exceptions.
Frequently asked questions
What is TEFCA?
The Trusted Exchange Framework and Common Agreement — a national framework for health information exchange implemented through 45 CFR Part 172 under section 3001(c)(9) of the Public Health Service Act. Part 172’s stated purpose is to ensure full network-to-network exchange of health information and to establish a voluntary process for a Qualified Health Information Network to attest to adoption of TEFCA.
What is a QHIN?
A Qualified Health Information Network: a health information network that has been Designated under 45 CFR Part 172 as capable of trusted exchange under TEFCA, connecting to other QHINs and supporting Participants and Subparticipants beneath it.
What are the TEFCA Exchange Purposes?
There are currently six authorized Exchange Purposes: Treatment, Payment, Health Care Operations, Public Health, Government Benefits Determination, and Individual Access Services. They are established by the Common Agreement and the Exchange Purposes SOP rather than by the CFR, and additional purposes may be added over time.
How long does QHIN designation take?
The regulation sets these timeframes, each extendable on written notice: notification of an incomplete application within 30 calendar days of receipt; substantive review within 60 calendar days of notice that the application is complete; Onboarding completed within 12 months of approval, extendable by up to a further 12 months at ASTP/ONC’s or the RCE’s sole discretion; a successful transaction with all other in-production QHINs within 30 calendar days of Designation; and Designation becoming final 60 days after that documentation is submitted.
Can any organisation apply to be a QHIN?
No. Under 172.201, an applicant must be a U.S. Entity not under Foreign Control, and must from the time of application — directly or through its parent entity’s experience — already be capable of exchanging among more than two unaffiliated organisations, be capable of exchanging all Required Information, and already be exchanging for at least one authorized Exchange Purpose.
Do I have to become a QHIN to use TEFCA?
No, and most organisations do not. The ordinary routes are to become a Participant of a QHIN or a Subparticipant of a Participant, both of which are contractual arrangements under the Participant/Subparticipant Terms of Participation rather than a regulatory designation, and neither of which carries the Part 172 qualification requirements.
What happens if a QHIN application is denied?
The applicant receives written notice including the basis for the denial, and may reapply no sooner than six months after the date on that notice. The new application must specifically address the deficiencies that were the basis for the denial. By contrast, an applicant that voluntarily withdraws before a decision may reapply at any time.
What are the extra requirements for Individual Access Services?
Under 172.202, a QHIN offering IAS must obtain express individual consent before providing the service; publish a privacy and security notice meeting minimum TEFCA standards; delete an individual’s Individually Identifiable Information on request except where prohibited by law or contained in audit logs; permit export of all such information in a computable format; encrypt all such information; notify affected individuals in plain language of unauthorized acquisition, access, disclosure or use without unreasonable delay and no later than 60 calendar days after discovery; and verify identity through an agreement with a qualified, independent third-party credential service provider before first use and on credential expiry.
Can a QHIN be suspended without being terminated?
Yes. Subpart D provides both QHIN suspension (172.401) and selective suspension of exchange between QHINs (172.402), the latter allowing exchange with a specific counterparty to be suspended without suspending the QHIN’s participation as a whole. Termination is dealt with separately in Subpart E, and decisions are appealable under Subpart F.
Does joining TEFCA let me refuse other exchange methods?
Only within the limits of 45 CFR 171.403. Both parties must be part of TEFCA, the requestor must be capable of exchange via TEFCA, and the request must not be made via the standards adopted at 45 CFR 170.215 — so standards-based API requests cannot be redirected into TEFCA. Any fees and licences must still satisfy the Fees and Licensing exceptions.
Which QHINs are currently designated?
The roster changes: the QHIN application remains open on a rolling basis, and organisations move between Candidate and Designated status. Consult the Recognized Coordinating Entity’s Designated QHINs directory for the current list rather than any secondary source, including this page.
Related reading
- Information Blocking Exceptions: All Ten, and How to Decide Which Applies
- HIPAA compliance software for clinical research units and academic medical centres
- Business associate agreements for research vendors
- De-Identified vs. Coded vs. Anonymized vs. Pseudonymized Data
- Electronic Medical Record (EMR)
- Research Data Management








