Skip to main content
Category: Regulatory Framework

United States Core Data for Interoperability

Also known as: USCDI, US Core Data for Interoperability
Simply put

The United States Core Data for Interoperability (USCDI) is a standardized set of health data classes and the specific data elements within them, intended to support nationwide, interoperable exchange of health information. It gives health IT developers, clinicians, and health information systems a common baseline of data to build and share, helping different systems work together more consistently. USCDI is published in successive versions (for example, versions 1, 2, and 3), and readers should confirm which version applies to their use case against current ONC/HealthIT.gov guidance.

Formal definition

USCDI is a standardized set of health data classes and constituent data elements established to enable nationwide, interoperable health information exchange. It organizes data into defined classes with associated data elements and serves as a roadmap for health IT developers to build products and solutions that support consistent data exchange. USCDI is maintained and updated over time through published versions; the specific data classes and elements vary by version, so practitioners should reference the applicable version and its authoritative definitions. Note that USCDI is a data content standard and is distinct from the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules; conformance to USCDI does not itself establish HIPAA compliance, and any implementation involving protected health information remains subject to applicable HIPAA obligations, which readers should evaluate separately.

Why it matters

USCDI addresses a persistent challenge in healthcare: different health IT systems often store and describe the same clinical information in incompatible ways, making it difficult to exchange data reliably across organizations. By defining a common baseline of health data classes and constituent data elements, USCDI gives developers, clinicians, and health information systems a shared vocabulary to build toward, which supports more consistent nationwide interoperability. For compliance and IT professionals, this matters because interoperable data exchange increasingly underpins care coordination, patient access to records, and the systems that must simultaneously satisfy regulatory obligations.

Because USCDI serves as a roadmap for health IT developers to build products and solutions, its versioned structure has practical consequences: the data classes and elements differ from version to version, so a system aligned to one version may not carry the same expectations as one aligned to a later version. Readers should confirm which version applies to their use case against current ONC/HealthIT.gov guidance rather than assuming a single fixed standard.

It is important to keep USCDI in its proper scope. USCDI is a data content standard describing what data should be exchangeable; it is distinct from the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. Conformance to USCDI does not by itself establish HIPAA compliance. Any implementation that involves protected health information remains subject to applicable HIPAA obligations, which must be evaluated separately, and additional requirements may arise under other frameworks or state law.

Who it's relevant to

Health IT Developers
USCDI provides a standardized set of data classes and elements that serves as a roadmap for building products and solutions capable of consistent, interoperable data exchange. Developers should track which USCDI version applies to their products and verify the authoritative definitions against current ONC/HealthIT.gov guidance.
Clinicians and Health Information Systems
As members of the healthcare ecosystem that exchanges data, clinicians and the systems they rely on benefit from a common baseline that helps different systems work together more consistently, supporting care coordination and record exchange.
Compliance, Privacy, and Security Officers
USCDI is a data content standard, not a HIPAA rule. Compliance officers should recognize that conformance to USCDI does not by itself establish HIPAA compliance, and any implementation involving protected health information remains subject to applicable HIPAA Privacy, Security, Breach Notification, and Enforcement Rule obligations, which must be evaluated separately.
Health IT Procurement and Governance Teams
Teams selecting or governing health IT should confirm which USCDI version a system aligns to, since data classes and elements vary by version. Version applicability should be verified against current ONC/HealthIT.gov guidance, and additional obligations may apply under HIPAA, the HITECH Act, or state law.

Inside USCDI

Standardized Data Classes and Elements
USCDI is a standardized set of health data classes (such as patient demographics, laboratory results, medications, allergies, and clinical notes) and the specific constituent data elements within each class, defined to support nationwide, interoperable health information exchange.
Data Classes
Broad groupings of related information (for example, a class covering allergies and intolerances or a class covering problems). Each data class organizes one or more individual data elements under a common category.
Data Elements
The most granular units within USCDI (such as a specific medication name, a lab test result value, or a patient's date of birth) that are intended to be exchanged consistently across systems.
Versioning Structure
USCDI is published in successive versions, with new data classes and elements added over time through a defined update process. Practitioners should confirm which USCDI version applies to a given requirement or certification criterion against current official guidance, as specific version numbers and their contents change.
Relationship to Interoperability Requirements
USCDI functions as a baseline data standard referenced by certain federal interoperability and certification programs. It defines what data should be exchangeable, not necessarily the transport or security mechanisms used to move that data.

Common questions

Answers to the questions practitioners most commonly ask about USCDI.

Is USCDI a HIPAA requirement enforced by HHS OCR?
No. USCDI is a standardized set of health data classes and data elements associated with interoperability initiatives, not a component of the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. HHS OCR enforces HIPAA; USCDI generally arises in the context of interoperability and certified health IT programs rather than as a HIPAA compliance obligation. Adopting or supporting USCDI does not by itself establish HIPAA compliance, and HIPAA obligations continue to apply independently to protected health information in all its forms. Readers should verify the current scope and applicability of USCDI against the authoritative source that maintains it.
Does implementing USCDI mean an organization's ePHI is secure or compliant with the HIPAA Security Rule?
No. USCDI describes what data classes and elements are exchanged for interoperability; it does not define the administrative, physical, and technical safeguards required to protect electronic protected health information under the HIPAA Security Rule. Supporting USCDI data classes does not satisfy Security Rule requirements such as risk analysis or the required and addressable implementation specifications, and it does not guarantee that ePHI is secure or that breaches are prevented. Security Rule obligations must be addressed separately, and organizations should confirm requirements against the current regulatory text.
How does USCDI relate to the data an organization exchanges under HIPAA-permitted disclosures?
USCDI generally standardizes the structure and content of certain health data elements exchanged through interoperability, while HIPAA governs whether and how protected health information may be used or disclosed. In most cases these operate on different questions: USCDI addresses what standardized data is exchanged, and HIPAA's Privacy Rule addresses the permissibility of a given use or disclosure. Organizations should evaluate any exchange of USCDI-aligned data against applicable HIPAA permissions, minimum necessary considerations where relevant, and any additional state law requirements, verifying details against current guidance.
If a business associate handles USCDI data on our behalf, do our HIPAA obligations change?
The relationship framework under HIPAA typically remains the same regardless of whether the data aligns to USCDI. Where a business associate creates, receives, maintains, or transmits protected health information on behalf of a covered entity, obligations generally flow through a business associate agreement, and subcontractors may be bound in turn. USCDI alignment does not alter which party is a covered entity, business associate, or subcontractor, nor which obligations attach through those agreements. Organizations should confirm that appropriate agreements are in place based on the actual relationship and data involved.
Does HITRUST CSF certification demonstrate that we correctly implement USCDI?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; neither defines USCDI nor establishes HIPAA compliance by itself. HITRUST certification is not a legal requirement, and it does not substitute for evaluating whether interoperability data exchanges appropriately reflect USCDI or meet applicable HIPAA and interoperability obligations. Organizations pursuing HITRUST certification should treat USCDI alignment as a separate consideration and verify requirements against the current HITRUST CSF version and the authoritative USCDI source.
Where should an implementation team confirm the current USCDI data classes and elements?
Because USCDI is updated over time and its data classes and data elements can change across versions, implementation teams should confirm the applicable version and its contents against the authoritative source that maintains USCDI rather than relying on prior or summarized descriptions. This is particularly important where interoperability commitments, certified health IT program expectations, or contractual requirements reference a specific USCDI version. Teams should also assess whether state law or other frameworks impose additional requirements beyond what USCDI or HIPAA address.

Common misconceptions

USCDI is part of HIPAA or is enforced by HHS OCR as a HIPAA requirement.
USCDI is a data interoperability standard and is distinct from the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules that HHS OCR enforces. Exchanging USCDI data does not by itself satisfy HIPAA obligations; when USCDI data includes protected health information, the applicable HIPAA rules still apply separately. Readers should verify the specific programs that reference USCDI against current regulatory guidance.
USCDI is a fixed, unchanging list of data elements.
USCDI is maintained and updated across multiple versions, with data classes and elements added over time. The set of elements in scope depends on which version applies, so practitioners should confirm the relevant version and its contents against current official documentation rather than assuming a static list.
Supporting USCDI means an organization has satisfied its data security and privacy compliance obligations.
USCDI specifies what data should be interoperable; it is generally not a security or privacy control framework. Meeting USCDI does not establish HIPAA Security Rule or Privacy Rule compliance, nor does it substitute for controls under frameworks such as the HITRUST CSF. Where the data is ePHI, the HIPAA Security Rule safeguards and any additional state-law or HITECH requirements still apply.

Best practices

Identify and document which USCDI version applies to your applicable interoperability or certification requirement, and verify it against current official guidance, since the data classes and elements change across versions.
Treat USCDI as a data-content standard only, and separately confirm that any exchange of protected health information meets the applicable HIPAA Privacy and Security Rule obligations, including administrative, physical, and technical safeguards for ePHI.
Where USCDI data is shared with vendors or exchange partners, confirm that appropriate business associate agreements are in place when those relationships involve PHI, since HIPAA obligations attach through defined relationships rather than automatically to every party handling the data.
Do not treat conformance with USCDI, or certification under a private framework such as the HITRUST CSF, as by itself establishing HIPAA compliance; maintain a distinct HIPAA compliance program and map each obligation to its correct source.
Review state-law and HITECH Act considerations that may impose interoperability, access, or data-handling requirements beyond USCDI and beyond baseline HIPAA rules.
Establish a change-management process to reassess your data mappings and workflows when a new USCDI version is adopted, and confirm version-specific details against current authoritative documentation before implementation.