Skip to content

Evidence request lists

TEFCA - Trusted Exchange Framework and Common Agreement

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Conformance

TEFCAREC-1
Common Agreement Conformance and Onboarding

Per TEFCA (Trusted Exchange Framework and Common Agreement) under ONC: conformance. Requirements include (a) Common Agreement adherence + (b) Qualified Health Information Network (QHIN) onboarding + (c) participant + sub-participant agreement + (d) cooperate with RCE (Recognized Coordinating Entity).

Artefacts an auditor will ask for
  • TEFCA evidence for TEFCAREC-1
Where this commonly fails
  • QHIN + Information Blocking partial

Exchange

TEFCAREC-3
Exchange Use Cases and Information Blocking

Per TEFCA: exchange purposes including treatment + payment + healthcare operations + public health + government benefits determination + individual access + research + plus Information Blocking compliance.

Artefacts an auditor will ask for
  • TEFCA evidence for TEFCAREC-3
Where this commonly fails
  • QHIN + Information Blocking partial

Identity

TEFCAREC-4
Identity Proofing and Authentication

Per TEFCA: identity proofing per NIST SP 800-63 + authentication for individual access.

Artefacts an auditor will ask for
  • TEFCA evidence for TEFCAREC-4
Where this commonly fails
  • QHIN + Information Blocking partial

Privacy and Security

TEFCAREC-2
Privacy, Security, Minimum Necessary

Per TEFCA: privacy + security including HIPAA + Minimum Necessary Standard + appropriate safeguards + encryption + access control.

Artefacts an auditor will ask for
  • TEFCA evidence for TEFCAREC-2
Where this commonly fails
  • QHIN + Information Blocking partial

TEFCA: Exchange Purposes

TEFCA-EP-GOV
Exchange Purpose Government Benefits Determination

Support the Government Benefits Determination exchange purpose enabling authorised government entities to obtain information necessary for eligibility, enrolment, and benefits administration, with appropriate consent and notice as required.

Artefacts an auditor will ask for
  • Government Benefits XP procedure
  • Consent capture and revocation records
  • Authorised entity verification
  • Disclosure logs
  • Consumer notices
Where this commonly fails
  • Consent capture missing or stale
  • Authorised entity verification not refreshed
  • Consumer notices missing in non-English languages
  • Disclosure logs incomplete
TEFCA-EP-HCO
Exchange Purpose Health Care Operations

Support the Health Care Operations exchange purpose for permitted activities such as quality assessment, care coordination, and population health management, with appropriate scoping and controls.

Artefacts an auditor will ask for
  • Operations XP procedure
  • Scope and filter controls documentation
  • Bulk query approval workflows
  • Audit logs for population queries
  • Participant attestations
Where this commonly fails
  • Bulk operations queries not scoped or approved
  • No filtering by minimum necessary
  • Audit trail does not show requestor purpose
  • Limits on frequency or volume not set
TEFCA-EP-IA
Exchange Purpose Individual Access Services

Support the Individual Access Services exchange purpose enabling individuals to obtain copies of their electronic health information through Individual Access Service providers, including identity proofing at IAL2.

Artefacts an auditor will ask for
  • IAS provider procedures
  • NIST 800-63-3 IAL2 identity proofing evidence
  • Consumer facing notices
  • Access request fulfilment logs
  • Complaint handling records
Where this commonly fails
  • Identity proofing below IAL2
  • Notices fail readability tests
  • No complaint channel for consumers
  • Fulfilment times exceed regulatory targets
TEFCA-EP-PH
Exchange Purpose Public Health

Support the Public Health exchange purpose enabling authorised public health authorities to send and receive electronic health information for purposes such as disease surveillance, immunisation, and emergency response.

Artefacts an auditor will ask for
  • Public Health XP procedure
  • Public Health Authority verification records
  • Reporting workflow diagrams
  • PHA participant agreements
  • Emergency activation playbooks
Where this commonly fails
  • PHA identity and authority not verified at onboarding
  • No emergency activation tested
  • Reporting workflows manual
  • Data quality issues not surfaced to PHA
TEFCA-EP-PMT
Exchange Purpose Payment

Support the Payment exchange purpose for permitted activities by health plans, providers, and their business associates, including minimum necessary controls and required documentation under the Common Agreement.

Artefacts an auditor will ask for
  • Payment XP procedure
  • Minimum necessary determination logs
  • Payer participation agreements
  • Transaction audit logs
  • Disclosure accounting outputs
Where this commonly fails
  • No minimum necessary controls applied to payer queries
  • Audit logs do not capture purpose
  • Payers granted broader access than scoped
  • Disclosure accounting not produced on request
TEFCA-EP-TR
Exchange Purpose Treatment

Support the Treatment exchange purpose as defined in the Common Agreement and the Standard Operating Procedure for Exchange Purposes, including responding to and initiating queries for treatment of an individual.

Artefacts an auditor will ask for
  • Treatment XP runbook
  • Provider directory and verification process
  • Query and response transaction logs
  • Participant attestations for Treatment
  • Use case test scripts
Where this commonly fails
  • Provider verification relies on self attestation only
  • No logging of denied or filtered responses
  • Treatment purpose conflated with operations
  • Use case test coverage incomplete

TEFCA: Operations and Compliance

TEFCA-COMP-01
Annual Compliance Attestation and Reporting

Submit annual compliance attestations and operational reports to the RCE covering security posture, exchange volumes by purpose, incidents, and remediation status as required by the Common Agreement.

Artefacts an auditor will ask for
  • Annual attestation package
  • Quarterly operational reports
  • Incident summary report
  • Remediation tracker
  • Executive sign off records
Where this commonly fails
  • Attestation submitted late
  • Operational metrics inconsistent quarter to quarter
  • Incidents understated or omitted
  • Remediation items perpetually open
TEFCA-COMP-02
Information Blocking Compliance

Ensure exchange activities conducted under TEFCA do not constitute information blocking under the ONC Cures Act, applying the eight exceptions appropriately and maintaining documentation of practices and decisions.

Artefacts an auditor will ask for
  • Information blocking policy
  • Exception application decision logs
  • Training records for exchange staff
  • Internal audit of denied or restricted exchanges
  • Self assessment against the eight exceptions
Where this commonly fails
  • Denied requests not documented
  • Staff unaware of exception criteria
  • No audit of denial patterns
  • Reliance on outdated guidance
TEFCA-OP-01
Service Level Agreements and Availability

Meet the operational service level requirements set in the QTF including system availability, response times, planned maintenance windows, and incident notification thresholds.

Artefacts an auditor will ask for
  • SLA performance dashboards
  • Availability reports
  • Maintenance window calendar and notices
  • Incident notifications sent within required time
  • Capacity planning documentation
Where this commonly fails
  • No real time monitoring of SLA metrics
  • Maintenance windows exceed limits in QTF
  • Incident notifications delayed beyond required window
  • Capacity headroom not tracked
TEFCA-OP-02
QHIN Directory and Endpoint Management

Maintain accurate QHIN directory entries, endpoint metadata, and participant rosters required for routing and discovery, including timely updates when participants join, leave, or change capabilities.

Artefacts an auditor will ask for
  • Directory entry change log
  • Endpoint metadata files (FHIR, IHE)
  • Roster validation reports
  • Participant change request workflow
  • Directory accuracy SLAs
Where this commonly fails
  • Stale endpoint metadata causing routing failures
  • Roster updates lag by weeks
  • No automated validation of directory entries
  • Capability metadata inconsistent with actual implementation

TEFCA: Participant Onboarding and Offboarding

TEFCA-PART-01
Participant and Subparticipant Onboarding

Onboard Participants and Subparticipants under the QHIN flowdown agreement structure, verifying identity, capability, and compliance posture before granting exchange access.

Artefacts an auditor will ask for
  • Participant agreement template with flowdown clauses
  • Onboarding checklist
  • Verification evidence (NPI, OCR, regulator status)
  • Capability assessment forms
  • Access provisioning logs
Where this commonly fails
  • Flowdown clauses missing or weaker than required
  • Verification relies on unverified self attestation
  • Onboarding shortcuts during pilots
  • No periodic recertification of participants
TEFCA-PART-02
Participant Offboarding and Suspension

Define and execute offboarding, suspension, and termination processes for Participants and Subparticipants, including data handling, notice obligations, and continuity arrangements.

Artefacts an auditor will ask for
  • Offboarding procedure
  • Suspension criteria and decision logs
  • Termination notices
  • Data deletion or return certifications
  • Continuity arrangements for downstream parties
Where this commonly fails
  • No clear criteria for suspension
  • Offboarding leaves directory entries active
  • Data deletion not certified
  • Downstream Subparticipants not notified

TEFCA: QHIN Designation and Governance

TEFCA-GOV-01
Governance and Cooperation Among QHINs

Participate in QHIN governance forums established by the RCE, including the QHIN Caucus and working groups, and meet obligations for cooperation, escalation handling, and dispute resolution.

Artefacts an auditor will ask for
  • QHIN Caucus attendance records
  • Working group participation logs
  • Dispute resolution case files
  • RCE escalation records
  • Annual governance report
Where this commonly fails
  • Inconsistent attendance at QHIN Caucus
  • Disputes escalated late or not at all
  • No internal point of contact for governance
  • Working group commitments missed
TEFCA-QHIN-01
Qualified Health Information Network Designation Criteria

Establish and maintain the technical, operational, and organisational capabilities required to qualify as a Qualified Health Information Network under the Common Agreement, including network operations, participant management, and compliance with the QHIN Technical Framework.

Artefacts an auditor will ask for
  • Signed Common Agreement v2.0
  • QHIN Onboarding and Designation Plan
  • QHIN Technical Framework conformance attestation
  • Network operations runbook
  • Participant agreement template
Where this commonly fails
  • Incomplete conformance to QTF version in effect
  • No documented participant tiering structure
  • Operational support hours not aligned with SLA
  • Missing attestation evidence for designation criteria
TEFCA-QHIN-02
QHIN Application and Designation Process

Complete the application, pre-production testing, and designation processes governed by the Recognized Coordinating Entity, including submission of required documentation, demonstration of technical capabilities, and remediation of identified findings.

Artefacts an auditor will ask for
  • RCE application package
  • Pre-production test results
  • Findings remediation log
  • Designation letter from RCE
  • Ongoing monitoring submissions
Where this commonly fails
  • Application gaps deferred without remediation date
  • Pre-production testing limited to a subset of exchange purposes
  • No annual recertification plan
  • Missing security control attestations

TEFCA: Security, Authentication and Privacy

TEFCA-SEC-01
QHIN Security Requirements

Implement and maintain the security controls required by the Common Agreement and the QTF, including HITRUST or equivalent third party security framework attestation, vulnerability management, and incident response.

Artefacts an auditor will ask for
  • Third party security attestation (NIST CSF, ISO 27001, SOC 2 Type II, or equivalent)
  • Vulnerability scan reports and remediation logs
  • Incident response plan
  • Tabletop exercise records
  • Encryption key management procedures
Where this commonly fails
  • Attestation scoped to a subset of the QHIN environment
  • Critical vulnerabilities open beyond SLA
  • Tabletop exercises not held annually
  • Key management procedures undocumented
TEFCA-SEC-02
Authentication and Mutual TLS

Implement mutual TLS authentication and approved digital certificates for QHIN to QHIN exchange, with certificate lifecycle management, revocation handling, and chain of trust validation.

Artefacts an auditor will ask for
  • Certificate inventory with expiry dates
  • mTLS configuration evidence
  • Certificate Authority and trust bundle documentation
  • Revocation handling procedure
  • Annual cryptography review
Where this commonly fails
  • Certificates approaching expiry without renewal workflow
  • Trust bundle not refreshed
  • Revocation lists not consulted on every handshake
  • Weak ciphers permitted by configuration
TEFCA-SEC-03
Privacy and Notice Obligations

Provide privacy notices, manage consent and opt-out where applicable, and apply the Common Agreement privacy obligations to all data exchanged, including special protections for sensitive categories.

Artefacts an auditor will ask for
  • Public privacy notice
  • Consent and opt out workflow documentation
  • Sensitive category handling rules (substance use, behavioural health, reproductive)
  • Privacy training records
  • DPIA or equivalent privacy impact analyses
Where this commonly fails
  • Notice not translated for non-English speakers
  • Opt out not honoured downstream
  • Sensitive category data not segmented
  • No periodic privacy training

TEFCA: Technical Interoperability

TEFCA-INT-FHIR
FHIR Implementation for TEFCA Exchange

Support the FHIR exchange path under the Common Agreement, including the USCDI v3 or higher dataset, SMART on FHIR authorisation patterns, and HL7 FHIR R4 conformance.

Artefacts an auditor will ask for
  • FHIR Capability Statement
  • USCDI coverage matrix
  • SMART App Launch test results
  • FHIR Implementation Guide conformance reports
  • Inferno test outputs
Where this commonly fails
  • USCDI elements missing or stub values returned
  • SMART scopes not aligned with TEFCA requirements
  • FHIR profiles unpublished
  • Inferno failures not remediated
TEFCA-INT-IHE
IHE Profile Implementation for TEFCA Exchange

Support the IHE-based exchange path including XCA, XCPD, XDR, and ATNA profiles required by the QTF for document level exchange between QHINs and participants.

Artefacts an auditor will ask for
  • IHE Connectathon test results
  • XCA and XCPD configuration evidence
  • Document metadata mappings
  • ATNA audit log samples
  • CCDA validation reports
Where this commonly fails
  • CCDA documents fail CDA validation
  • Audit logs missing required fields
  • Document metadata inconsistent across QHINs
  • Connectathon participation lapsed

Trusted Exchange Framework Principles

TEF-1
Standardisation

Health information networks must adopt common technical standards to enable consistent and reliable health data exchange.

Artefacts an auditor will ask for
  • Trusted Exchange Framework principles attestation
  • Public posting of participation criteria and fees
  • Annual report on principle adherence
  • Governance committee minutes evidencing principle review
Where this commonly fails
  • Principle attestation not refreshed annually
  • Limited transparency on dispute outcomes
  • Disparate treatment of smaller participants
TEF-2
Openness and Transparency

Exchange practices must be open and transparent regarding policies, procedures, and data handling practices.

Artefacts an auditor will ask for
  • Trusted Exchange Framework principles attestation
  • Public posting of participation criteria and fees
  • Annual report on principle adherence
  • Governance committee minutes evidencing principle review
Where this commonly fails
  • Principle attestation not refreshed annually
  • Limited transparency on dispute outcomes
  • Disparate treatment of smaller participants
TEF-3
Cooperation and Non-Discrimination

HINs must cooperate with each other and not discriminate against exchange partners based on competitive considerations.

Artefacts an auditor will ask for
  • Trusted Exchange Framework principles attestation
  • Public posting of participation criteria and fees
  • Annual report on principle adherence
  • Governance committee minutes evidencing principle review
Where this commonly fails
  • Principle attestation not refreshed annually
  • Limited transparency on dispute outcomes
  • Disparate treatment of smaller participants
TEF-4
Privacy, Security, and Safety

All exchange activities must adhere to privacy and security safeguards to protect health information.

Artefacts an auditor will ask for
  • Trusted Exchange Framework principles attestation
  • Public posting of participation criteria and fees
  • Annual report on principle adherence
  • Governance committee minutes evidencing principle review
Where this commonly fails
  • Principle attestation not refreshed annually
  • Limited transparency on dispute outcomes
  • Disparate treatment of smaller participants
TEF-5
Access and Equity

Health information exchange must promote equitable access and not create barriers for underserved populations.

Artefacts an auditor will ask for
  • Trusted Exchange Framework principles attestation
  • Public posting of participation criteria and fees
  • Annual report on principle adherence
  • Governance committee minutes evidencing principle review
Where this commonly fails
  • Principle attestation not refreshed annually
  • Limited transparency on dispute outcomes
  • Disparate treatment of smaller participants
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TEFCA - Trusted Exchange Framework and Common Agreement framework page.