TEFCA - Trusted Exchange Framework and Common Agreement
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Conformance
Per TEFCA (Trusted Exchange Framework and Common Agreement) under ONC: conformance. Requirements include (a) Common Agreement adherence + (b) Qualified Health Information Network (QHIN) onboarding + (c) participant + sub-participant agreement + (d) cooperate with RCE (Recognized Coordinating Entity).
- TEFCA evidence for TEFCAREC-1
- QHIN + Information Blocking partial
Exchange
Per TEFCA: exchange purposes including treatment + payment + healthcare operations + public health + government benefits determination + individual access + research + plus Information Blocking compliance.
- TEFCA evidence for TEFCAREC-3
- QHIN + Information Blocking partial
Identity
Per TEFCA: identity proofing per NIST SP 800-63 + authentication for individual access.
- TEFCA evidence for TEFCAREC-4
- QHIN + Information Blocking partial
Privacy and Security
Per TEFCA: privacy + security including HIPAA + Minimum Necessary Standard + appropriate safeguards + encryption + access control.
- TEFCA evidence for TEFCAREC-2
- QHIN + Information Blocking partial
TEFCA: Exchange Purposes
Support the Government Benefits Determination exchange purpose enabling authorised government entities to obtain information necessary for eligibility, enrolment, and benefits administration, with appropriate consent and notice as required.
- Government Benefits XP procedure
- Consent capture and revocation records
- Authorised entity verification
- Disclosure logs
- Consumer notices
- Consent capture missing or stale
- Authorised entity verification not refreshed
- Consumer notices missing in non-English languages
- Disclosure logs incomplete
Support the Health Care Operations exchange purpose for permitted activities such as quality assessment, care coordination, and population health management, with appropriate scoping and controls.
- Operations XP procedure
- Scope and filter controls documentation
- Bulk query approval workflows
- Audit logs for population queries
- Participant attestations
- Bulk operations queries not scoped or approved
- No filtering by minimum necessary
- Audit trail does not show requestor purpose
- Limits on frequency or volume not set
Support the Individual Access Services exchange purpose enabling individuals to obtain copies of their electronic health information through Individual Access Service providers, including identity proofing at IAL2.
- IAS provider procedures
- NIST 800-63-3 IAL2 identity proofing evidence
- Consumer facing notices
- Access request fulfilment logs
- Complaint handling records
- Identity proofing below IAL2
- Notices fail readability tests
- No complaint channel for consumers
- Fulfilment times exceed regulatory targets
Support the Public Health exchange purpose enabling authorised public health authorities to send and receive electronic health information for purposes such as disease surveillance, immunisation, and emergency response.
- Public Health XP procedure
- Public Health Authority verification records
- Reporting workflow diagrams
- PHA participant agreements
- Emergency activation playbooks
- PHA identity and authority not verified at onboarding
- No emergency activation tested
- Reporting workflows manual
- Data quality issues not surfaced to PHA
Support the Payment exchange purpose for permitted activities by health plans, providers, and their business associates, including minimum necessary controls and required documentation under the Common Agreement.
- Payment XP procedure
- Minimum necessary determination logs
- Payer participation agreements
- Transaction audit logs
- Disclosure accounting outputs
- No minimum necessary controls applied to payer queries
- Audit logs do not capture purpose
- Payers granted broader access than scoped
- Disclosure accounting not produced on request
Support the Treatment exchange purpose as defined in the Common Agreement and the Standard Operating Procedure for Exchange Purposes, including responding to and initiating queries for treatment of an individual.
- Treatment XP runbook
- Provider directory and verification process
- Query and response transaction logs
- Participant attestations for Treatment
- Use case test scripts
- Provider verification relies on self attestation only
- No logging of denied or filtered responses
- Treatment purpose conflated with operations
- Use case test coverage incomplete
TEFCA: Operations and Compliance
Submit annual compliance attestations and operational reports to the RCE covering security posture, exchange volumes by purpose, incidents, and remediation status as required by the Common Agreement.
- Annual attestation package
- Quarterly operational reports
- Incident summary report
- Remediation tracker
- Executive sign off records
- Attestation submitted late
- Operational metrics inconsistent quarter to quarter
- Incidents understated or omitted
- Remediation items perpetually open
Ensure exchange activities conducted under TEFCA do not constitute information blocking under the ONC Cures Act, applying the eight exceptions appropriately and maintaining documentation of practices and decisions.
- Information blocking policy
- Exception application decision logs
- Training records for exchange staff
- Internal audit of denied or restricted exchanges
- Self assessment against the eight exceptions
- Denied requests not documented
- Staff unaware of exception criteria
- No audit of denial patterns
- Reliance on outdated guidance
Meet the operational service level requirements set in the QTF including system availability, response times, planned maintenance windows, and incident notification thresholds.
- SLA performance dashboards
- Availability reports
- Maintenance window calendar and notices
- Incident notifications sent within required time
- Capacity planning documentation
- No real time monitoring of SLA metrics
- Maintenance windows exceed limits in QTF
- Incident notifications delayed beyond required window
- Capacity headroom not tracked
Maintain accurate QHIN directory entries, endpoint metadata, and participant rosters required for routing and discovery, including timely updates when participants join, leave, or change capabilities.
- Directory entry change log
- Endpoint metadata files (FHIR, IHE)
- Roster validation reports
- Participant change request workflow
- Directory accuracy SLAs
- Stale endpoint metadata causing routing failures
- Roster updates lag by weeks
- No automated validation of directory entries
- Capability metadata inconsistent with actual implementation
TEFCA: Participant Onboarding and Offboarding
Onboard Participants and Subparticipants under the QHIN flowdown agreement structure, verifying identity, capability, and compliance posture before granting exchange access.
- Participant agreement template with flowdown clauses
- Onboarding checklist
- Verification evidence (NPI, OCR, regulator status)
- Capability assessment forms
- Access provisioning logs
- Flowdown clauses missing or weaker than required
- Verification relies on unverified self attestation
- Onboarding shortcuts during pilots
- No periodic recertification of participants
Define and execute offboarding, suspension, and termination processes for Participants and Subparticipants, including data handling, notice obligations, and continuity arrangements.
- Offboarding procedure
- Suspension criteria and decision logs
- Termination notices
- Data deletion or return certifications
- Continuity arrangements for downstream parties
- No clear criteria for suspension
- Offboarding leaves directory entries active
- Data deletion not certified
- Downstream Subparticipants not notified
TEFCA: QHIN Designation and Governance
Participate in QHIN governance forums established by the RCE, including the QHIN Caucus and working groups, and meet obligations for cooperation, escalation handling, and dispute resolution.
- QHIN Caucus attendance records
- Working group participation logs
- Dispute resolution case files
- RCE escalation records
- Annual governance report
- Inconsistent attendance at QHIN Caucus
- Disputes escalated late or not at all
- No internal point of contact for governance
- Working group commitments missed
Establish and maintain the technical, operational, and organisational capabilities required to qualify as a Qualified Health Information Network under the Common Agreement, including network operations, participant management, and compliance with the QHIN Technical Framework.
- Signed Common Agreement v2.0
- QHIN Onboarding and Designation Plan
- QHIN Technical Framework conformance attestation
- Network operations runbook
- Participant agreement template
- Incomplete conformance to QTF version in effect
- No documented participant tiering structure
- Operational support hours not aligned with SLA
- Missing attestation evidence for designation criteria
Complete the application, pre-production testing, and designation processes governed by the Recognized Coordinating Entity, including submission of required documentation, demonstration of technical capabilities, and remediation of identified findings.
- RCE application package
- Pre-production test results
- Findings remediation log
- Designation letter from RCE
- Ongoing monitoring submissions
- Application gaps deferred without remediation date
- Pre-production testing limited to a subset of exchange purposes
- No annual recertification plan
- Missing security control attestations
TEFCA: Security, Authentication and Privacy
Implement and maintain the security controls required by the Common Agreement and the QTF, including HITRUST or equivalent third party security framework attestation, vulnerability management, and incident response.
- Third party security attestation (NIST CSF, ISO 27001, SOC 2 Type II, or equivalent)
- Vulnerability scan reports and remediation logs
- Incident response plan
- Tabletop exercise records
- Encryption key management procedures
- Attestation scoped to a subset of the QHIN environment
- Critical vulnerabilities open beyond SLA
- Tabletop exercises not held annually
- Key management procedures undocumented
Implement mutual TLS authentication and approved digital certificates for QHIN to QHIN exchange, with certificate lifecycle management, revocation handling, and chain of trust validation.
- Certificate inventory with expiry dates
- mTLS configuration evidence
- Certificate Authority and trust bundle documentation
- Revocation handling procedure
- Annual cryptography review
- Certificates approaching expiry without renewal workflow
- Trust bundle not refreshed
- Revocation lists not consulted on every handshake
- Weak ciphers permitted by configuration
Provide privacy notices, manage consent and opt-out where applicable, and apply the Common Agreement privacy obligations to all data exchanged, including special protections for sensitive categories.
- Public privacy notice
- Consent and opt out workflow documentation
- Sensitive category handling rules (substance use, behavioural health, reproductive)
- Privacy training records
- DPIA or equivalent privacy impact analyses
- Notice not translated for non-English speakers
- Opt out not honoured downstream
- Sensitive category data not segmented
- No periodic privacy training
TEFCA: Technical Interoperability
Support the FHIR exchange path under the Common Agreement, including the USCDI v3 or higher dataset, SMART on FHIR authorisation patterns, and HL7 FHIR R4 conformance.
- FHIR Capability Statement
- USCDI coverage matrix
- SMART App Launch test results
- FHIR Implementation Guide conformance reports
- Inferno test outputs
- USCDI elements missing or stub values returned
- SMART scopes not aligned with TEFCA requirements
- FHIR profiles unpublished
- Inferno failures not remediated
Support the IHE-based exchange path including XCA, XCPD, XDR, and ATNA profiles required by the QTF for document level exchange between QHINs and participants.
- IHE Connectathon test results
- XCA and XCPD configuration evidence
- Document metadata mappings
- ATNA audit log samples
- CCDA validation reports
- CCDA documents fail CDA validation
- Audit logs missing required fields
- Document metadata inconsistent across QHINs
- Connectathon participation lapsed
Trusted Exchange Framework Principles
Health information networks must adopt common technical standards to enable consistent and reliable health data exchange.
- Trusted Exchange Framework principles attestation
- Public posting of participation criteria and fees
- Annual report on principle adherence
- Governance committee minutes evidencing principle review
- Principle attestation not refreshed annually
- Limited transparency on dispute outcomes
- Disparate treatment of smaller participants
Exchange practices must be open and transparent regarding policies, procedures, and data handling practices.
- Trusted Exchange Framework principles attestation
- Public posting of participation criteria and fees
- Annual report on principle adherence
- Governance committee minutes evidencing principle review
- Principle attestation not refreshed annually
- Limited transparency on dispute outcomes
- Disparate treatment of smaller participants
HINs must cooperate with each other and not discriminate against exchange partners based on competitive considerations.
- Trusted Exchange Framework principles attestation
- Public posting of participation criteria and fees
- Annual report on principle adherence
- Governance committee minutes evidencing principle review
- Principle attestation not refreshed annually
- Limited transparency on dispute outcomes
- Disparate treatment of smaller participants
All exchange activities must adhere to privacy and security safeguards to protect health information.
- Trusted Exchange Framework principles attestation
- Public posting of participation criteria and fees
- Annual report on principle adherence
- Governance committee minutes evidencing principle review
- Principle attestation not refreshed annually
- Limited transparency on dispute outcomes
- Disparate treatment of smaller participants
Health information exchange must promote equitable access and not create barriers for underserved populations.
- Trusted Exchange Framework principles attestation
- Public posting of participation criteria and fees
- Annual report on principle adherence
- Governance committee minutes evidencing principle review
- Principle attestation not refreshed annually
- Limited transparency on dispute outcomes
- Disparate treatment of smaller participants
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the TEFCA - Trusted Exchange Framework and Common Agreement framework page.