Trusted Exchange Framework and Common Agreement
TEFCA is a nationwide framework in the United States designed to make it easier and more consistent for health information networks, providers, health plans, individuals, and other stakeholders to share electronic health information with one another. It combines a set of common principles with a legal agreement so that different networks can connect and exchange records across the country. Participation is generally voluntary, and TEFCA is a governance and interoperability framework rather than a HIPAA compliance requirement.
TEFCA is a governance framework and multilateral agreement structure intended to scale the bi-directional exchange of electronic health information (EHI) nationwide across health information networks (HINs) and among providers, health plans, individuals, and other stakeholders. It comprises two components: the Trusted Exchange Framework, which sets out common non-binding principles for trusted exchange, and the Common Agreement, which defines the legal terms and conditions governing participation. TEFCA supports a defined set of exchange purposes and establishes standardized principles for interoperable exchange. Practitioners should note that TEFCA is distinct from HIPAA; it is not enforced by HHS OCR as a compliance mandate, and participation in TEFCA does not by itself establish HIPAA compliance. Organizations remain subject to applicable HIPAA Privacy, Security, and Breach Notification Rule obligations, as well as any additional state-law or other framework requirements. Specific version details, publication dates, and current participation terms should be verified against the official TEFCA governance materials, as such details are updated over time.
Why it matters
For years, the exchange of electronic health information across the United States has been fragmented, with different health information networks operating under distinct legal agreements and technical arrangements that did not always connect to one another. TEFCA matters because it aims to reduce this fragmentation by establishing a common set of principles and a shared legal agreement, making it more feasible for networks, providers, health plans, individuals, and other stakeholders to exchange records nationwide without negotiating separate one-off arrangements for each connection.
For compliance professionals, the most important point is what TEFCA is not. TEFCA is a governance and interoperability framework, not a HIPAA compliance requirement. It is not enforced by HHS OCR, and participating in TEFCA does not, by itself, establish HIPAA compliance. Organizations that join must still meet all applicable HIPAA Privacy, Security, and Breach Notification Rule obligations, and may face additional requirements under state law or other frameworks. Treating TEFCA participation as a substitute for a HIPAA compliance program would be a significant misunderstanding of its scope.
Because participation is generally voluntary, organizations should evaluate TEFCA on its interoperability merits rather than as a regulatory obligation. The framework can support broader data sharing for defined exchange purposes, but the specific terms of participation, supported purposes, and governance requirements are updated over time. Compliance and IT teams should therefore verify current details against the official TEFCA governance materials before making participation or architecture decisions.
Who it's relevant to
Inside TEFCA
Common questions
Answers to the questions practitioners most commonly ask about TEFCA.