Skip to main content
Category: Regulatory Framework

Trusted Exchange Framework and Common Agreement

Also known as: TEFCA, Trusted Exchange Framework and Common Agreement™, TEFCA®
Simply put

TEFCA is a nationwide framework in the United States designed to make it easier and more consistent for health information networks, providers, health plans, individuals, and other stakeholders to share electronic health information with one another. It combines a set of common principles with a legal agreement so that different networks can connect and exchange records across the country. Participation is generally voluntary, and TEFCA is a governance and interoperability framework rather than a HIPAA compliance requirement.

Formal definition

TEFCA is a governance framework and multilateral agreement structure intended to scale the bi-directional exchange of electronic health information (EHI) nationwide across health information networks (HINs) and among providers, health plans, individuals, and other stakeholders. It comprises two components: the Trusted Exchange Framework, which sets out common non-binding principles for trusted exchange, and the Common Agreement, which defines the legal terms and conditions governing participation. TEFCA supports a defined set of exchange purposes and establishes standardized principles for interoperable exchange. Practitioners should note that TEFCA is distinct from HIPAA; it is not enforced by HHS OCR as a compliance mandate, and participation in TEFCA does not by itself establish HIPAA compliance. Organizations remain subject to applicable HIPAA Privacy, Security, and Breach Notification Rule obligations, as well as any additional state-law or other framework requirements. Specific version details, publication dates, and current participation terms should be verified against the official TEFCA governance materials, as such details are updated over time.

Why it matters

For years, the exchange of electronic health information across the United States has been fragmented, with different health information networks operating under distinct legal agreements and technical arrangements that did not always connect to one another. TEFCA matters because it aims to reduce this fragmentation by establishing a common set of principles and a shared legal agreement, making it more feasible for networks, providers, health plans, individuals, and other stakeholders to exchange records nationwide without negotiating separate one-off arrangements for each connection.

For compliance professionals, the most important point is what TEFCA is not. TEFCA is a governance and interoperability framework, not a HIPAA compliance requirement. It is not enforced by HHS OCR, and participating in TEFCA does not, by itself, establish HIPAA compliance. Organizations that join must still meet all applicable HIPAA Privacy, Security, and Breach Notification Rule obligations, and may face additional requirements under state law or other frameworks. Treating TEFCA participation as a substitute for a HIPAA compliance program would be a significant misunderstanding of its scope.

Because participation is generally voluntary, organizations should evaluate TEFCA on its interoperability merits rather than as a regulatory obligation. The framework can support broader data sharing for defined exchange purposes, but the specific terms of participation, supported purposes, and governance requirements are updated over time. Compliance and IT teams should therefore verify current details against the official TEFCA governance materials before making participation or architecture decisions.

Who it's relevant to

Privacy and Security Officers
Officers evaluating TEFCA participation should understand that it does not replace the organization's HIPAA obligations. Applicable Privacy, Security, and Breach Notification Rule requirements continue to apply regardless of participation, and state law or other frameworks may impose additional obligations. TEFCA should be assessed as a governance and interoperability decision layered on top of, not in place of, an existing compliance program.
Health Information Network Operators
Because TEFCA is designed to scale EHI exchange nationwide across HINs, network operators are among the most directly affected stakeholders. They should review the current Common Agreement terms and Trusted Exchange Framework principles against the official governance materials, as participation terms and supported exchange purposes are updated over time.
Healthcare Providers and Health Plans
Providers and health plans identified as intended TEFCA stakeholders may benefit from more consistent, nationwide access to health records for defined exchange purposes. Participation is generally voluntary, so these organizations should weigh the interoperability benefits against their existing agreements and confirm that participation aligns with their ongoing HIPAA and other regulatory responsibilities.
Compliance and Legal Teams
Legal and compliance staff should focus on the distinction between TEFCA and HIPAA, since TEFCA is a legal agreement and governance framework rather than a compliance mandate enforced by HHS OCR. They should verify the specific legal terms, current version details, and participation obligations against the official TEFCA governance materials before advising on entry into the Common Agreement.
Health IT and Interoperability Staff
Technical teams responsible for exchange infrastructure should understand TEFCA's role in enabling bi-directional exchange across networks under a common framework. Because supported exchange purposes and technical participation requirements are updated periodically, IT staff should base architecture and integration planning on the current published governance materials.

Inside TEFCA

Trusted Exchange Framework (TEF)
A set of non-binding, foundational principles intended to facilitate trust among health information networks. It articulates general goals for nationwide interoperability rather than imposing directly enforceable legal obligations.
Common Agreement (CA)
The contractual and technical framework that operationalizes the principles in the TEF, establishing the terms under which participating networks and their participants exchange health information.
Qualified Health Information Networks (QHINs)
Networks that voluntarily agree to the Common Agreement and serve as connective infrastructure for exchange among participants and subparticipants. Participation is generally voluntary rather than legally mandated.
Voluntary participation model
TEFCA is designed as an opt-in framework. Entities choose whether to join, and joining is not itself a HIPAA requirement.
Relationship to HIPAA
TEFCA operates alongside HIPAA. Covered entities and business associates participating in exchange remain subject to their existing HIPAA Privacy Rule, Security Rule, and Breach Notification Rule obligations; TEFCA participation does not replace those obligations. Readers should verify current governance details against official ONC/HHS guidance.

Common questions

Answers to the questions practitioners most commonly ask about TEFCA.

Is TEFCA part of HIPAA, or does participating in TEFCA make my organization HIPAA compliant?
No. TEFCA is a distinct framework for nationwide health information exchange established under the authority of the 21st Century Cures Act and administered through the coordination of the Office of the National Coordinator for Health IT (ONC), not the HIPAA rules enforced by HHS OCR. Participating in TEFCA does not by itself establish HIPAA compliance. Organizations that are covered entities or business associates remain subject to their independent HIPAA Privacy, Security, and Breach Notification Rule obligations regardless of TEFCA participation. Readers should treat TEFCA and HIPAA as separate compliance considerations and verify their obligations under each against current guidance.
Does TEFCA replace or override my existing HIPAA obligations when exchanging data through the network?
No. TEFCA does not replace or supersede HIPAA. Exchanging protected health information through a TEFCA-connected network generally does not relieve a covered entity or business associate of its HIPAA Privacy and Security Rule responsibilities. Where PHI moves electronically, the Security Rule's requirements for electronic PHI continue to apply, and the Privacy Rule continues to govern permitted uses and disclosures. State law and the HITECH Act may also impose additional requirements. TEFCA sets terms and technical conditions for participation in a trusted exchange; it operates alongside, not in place of, existing regulatory duties.
How do participants typically connect to and participate in TEFCA?
Participation in TEFCA is generally structured through networks that are recognized under the framework, with participating organizations connecting through these designated networks rather than joining a single central system directly. Specific onboarding steps, technical requirements, and the roles of the various types of participating entities are defined in the governing agreement and supporting documentation. Because these arrangements and the entities involved can change over time, organizations should confirm current participation pathways and requirements against the applicable TEFCA documentation and their chosen network's terms.
What should we address in agreements before exchanging data through a TEFCA-connected network?
Organizations should generally review how HIPAA obligations flow through their contractual relationships, including whether a business associate agreement is required with any vendor or network that creates, receives, maintains, or transmits PHI on their behalf. Participation typically also involves accepting the terms of the governing TEFCA agreement and any downstream participation terms. Legal and compliance review should confirm how permitted purposes for exchange, data use limitations, and breach responsibilities are allocated. Specific contractual terms should be verified against the current governing agreement and reviewed by qualified counsel.
How does TEFCA interact with our HIPAA Security Rule safeguards?
TEFCA participation does not remove the need for HIPAA Security Rule safeguards where electronic PHI is involved. Organizations should continue to implement and maintain administrative, physical, and technical safeguards, including required and addressable implementation specifications, recognizing that addressable does not mean optional. Any technical requirements associated with a TEFCA-connected network generally operate in addition to, not as a substitute for, the organization's own Security Rule risk analysis and safeguard obligations. Confirm applicable technical specifications against current TEFCA documentation.
How should we handle breach and incident considerations for data exchanged through TEFCA?
Covered entities and business associates generally remain responsible for their HIPAA Breach Notification Rule obligations for PHI they handle, and participation in a trusted exchange does not by itself transfer or eliminate those duties. Breach responsibilities among participating organizations are typically addressed through the governing agreement and any applicable business associate agreements, so organizations should confirm how notification and responsibility are allocated in their specific arrangements. Breach thresholds and notification requirements are matters of current HIPAA guidance and, where applicable, state law, and should be verified against those authorities.

Common misconceptions

Participating in TEFCA satisfies or replaces an organization's HIPAA compliance obligations.
TEFCA is a framework for trusted exchange and does not substitute for HIPAA compliance. Covered entities and business associates that participate remain independently responsible for their obligations under the HIPAA Privacy, Security, and Breach Notification Rules.
TEFCA is a legal mandate that all covered entities and business associates must join.
Participation in TEFCA is generally voluntary and opt-in. It is not a statutory requirement imposed on every entity that handles PHI; obligations to join do not arise directly from HIPAA.
The Trusted Exchange Framework itself imposes directly enforceable requirements on participants.
The Trusted Exchange Framework is a set of non-binding foundational principles. Enforceable terms flow through the Common Agreement and related contractual arrangements that participants voluntarily accept, not from the principles alone.

Best practices

Treat any decision to participate in TEFCA as a supplement to, not a replacement for, your existing HIPAA Privacy Rule, Security Rule, and Breach Notification Rule programs.
Before joining, review the current Common Agreement terms and confirm how they interact with your existing business associate agreements and internal policies.
Verify the current governance structure, QHIN requirements, and framework details against official ONC/HHS sources, since these evolve over time.
Assess whether exchange activities under TEFCA introduce new flows of PHI or ePHI that should be reflected in your risk analysis and safeguards.
Confirm that participation does not alter your independent breach notification responsibilities, and document how breaches arising from exchange would be identified and reported.
Consult legal counsel to evaluate how state law, the HITECH Act, or other frameworks may impose obligations beyond both HIPAA and the Common Agreement.