The health data sharing initiative promoted by the Trump administration is expected to have a positive impact on healthcare information interoperability, but experts point out that the plan currently lacks specific details, and challenges such as data security, under-resourced healthcare institutions, and slow technology adoption may become obstacles to its success.

The plan was announced at the White House late last month by leaders of the U.S. Department of Health and Human Services (HHS) and the Centers for Medicare & Medicaid Services (CMS), aiming to improve the long-standing challenge of healthcare data exchange through partnerships with more than 60 companies, including Amazon, Google, Epic, and UnitedHealth.

The plan includes two major focus areas: encouraging adoption of a voluntary data sharing blueprint called the "CMS Interoperability Framework," and increasing access to digital health tools such as chronic disease management and care navigation products. CMS stated that these companies have committed to "deliver results for the American people" in the first quarter of next year.

However, experts believe this timeline is quite tight, and although the plan has set standards for the interoperability framework, the specific operational details remain unclear. Beth Mosier, director of the healthcare M&A team at consulting firm West Monroe, said: "In my view, most of the work relies on these 60 signatory companies, but I'm not sure how it will all be accomplished. It seems like 'you volunteer to join, then figure it out yourself.' So, I think there is still much to be defined in terms of specific operations."

Improving data sharing does no harm

Nevertheless, experts believe that given the healthcare industry's long-standing challenges in data sharing, the plan's goals are commendable. Interoperability and information sharing are long-standing industry problems, with data silos making it difficult for information to flow between healthcare institutions, compounded by reliance on outdated technologies such as fax machines.

Mosier noted that many patients may receive care from multiple healthcare institutions that use separate patient portals, so consumers have to piece together their health data from multiple sources. Making it easier for patients to access all their information may help them make data-driven healthcare decisions.

Alex Nisenbaum, a partner at law firm Blank Rome, said the plan is unlikely to harm interoperability, and CMS, as the largest payer in the U.S., processing more than 1 billion Medicare claims annually, its participation could promote data sharing and accessibility.

Jennifer Goldsack, CEO of the Digital Medicine Society, added that as the industry works to shift toward value-based payment models and adopt artificial intelligence tools, the ease of data flow is more important than ever. AI requires large amounts of data for training, and healthcare providers need data to adequately predict risk in value-based care.

Goldsack believes that these companies' participation in collaboration with CMS and other signatory companies may carry lower risk than going it alone. Additionally, the high visibility of the plan and its signatory companies may incentivize them to stay committed. "If someone later wants to 'take their toys and leave the sandbox,' that would be ugly. So, I expect there will be some commercial pressure to see it through."

High barriers to patient access

Nisenbaum said the "million-dollar question" is how the plan will work in practice. One possibility is that the data sharing commitments could build on and enhance the Trusted Exchange Framework and Common Agreement (TEFCA), a governance framework that went live at the end of 2023. TEFCA has gained momentum in recent years, with 10 organizations now designated as Qualified Health Information Networks (QHINs), up from 5 at launch.

Several QHINs, including CommonWell Health Alliance, eClinicalWorks, eHealth Exchange, and Health Gorilla, have committed to implementing the interoperability framework and becoming CMS-aligned networks. However, Nisenbaum noted that the new plan emphasizes putting data into patients' hands, while TEFCA focuses more on sharing between healthcare institutions to improve care coordination.

Mosier said expectations for patient data access are quite high. Some of the standards under the CMS framework include ensuring patients can access electronic health information through apps of their choice, and accessing claims, explanation of benefits, prior authorizations, and clinical data from current and past payers. She noted: "'Bring your own device' (BYOD) is basically what they're talking about, but that concept has almost never been elegantly solved in healthcare. Patient portals and provider portals exist for a reason... Supporting whatever devices everyone might bring is a significant commitment."

Mosier added that even if data is structured and complete, it may be difficult to understand. For example, lab results can be confusing without clinician explanation. "For most people, digesting and absorbing complex medical data is really hard. I think this will create another layer of support needs for healthcare consumers."

Data security and technology barriers

Experts say health data sharing also faces many challenges, including provider resistance to adopting new technologies and concerns about data privacy. The Trump administration wants networks to use the Fast Healthcare Interoperability Resources (FHIR) standard to facilitate data access, which defines rules for how health data is exchanged between computer systems, regardless of how information is stored.

However, Mosier noted that adopting FHIR can be challenging. Providers may implement the standard in different ways and use different versions of FHIR, and as versions change, exchange can become complex. Data security is another major concern. Nisenbaum said some applications responsible for giving patients control over their health data may not be subject to HIPAA privacy and security laws. "I think this will place responsibility on patients to truly understand the commitments these companies are making regarding the collection, use, and disclosure of health information."

This can be difficult for patients. A 2022 survey by the American Medical Association found that only 20% of respondents said they knew which companies and individuals could access their health data. Additionally, companies also bear their own burden in navigating the complex and fragmented landscape of data privacy laws. Many states have their own data laws, and some have health-specific requirements, such as California's Confidentiality of Medical Information Act.

Nisenbaum believes the plan could prompt more states to enact their own privacy legislation, because it only takes a few players using data for questionable purposes, such as advertising, to trigger regulatory scrutiny. "Most states don't have comprehensive privacy laws, right? So, if the federal government doesn't pass relevant legislation (which it hasn't succeeded in doing for years), there is still room for regulation."

Can under-resourced providers participate?

Several health systems and providers, including Cleveland Clinic, Intermountain Health, and Providence, have signed commitments to participate in CMS-aligned networks and electronically receive patient data. However, compared to the total number of health systems operating in the U.S., the number of participating providers is relatively small.

Nisenbaum noted that several of these are large providers, which is not surprising, because small physician practices are often "dragged along" in technology adoption. Managing technological change in healthcare organizations can be challenging, and small practices typically rely on their vendors to meet data sharing requirements.

Goldsack said the experience of large institutions may not apply to health systems with fewer resources, such as rural or financially struggling institutions. These systems often lack the capacity to participate in working groups, causing their unique challenges to be overlooked. "Rural hospitals don't have chief innovation officers, chief digital officers, chief AI officers, or chief technology officers. It's usually the CEO squeezing it in on a Thursday night, and the technology budget is very limited."

Next steps

Goldsack said the plan currently has clear goals and brings together a large number of signatory organizations. Mosier believes one indicator of the plan's progress could revolve around how participating companies incorporate the plan into their development plans. "If we keep hearing Amazon and UnitedHealth talking about this and their actions, that will point in one direction; if it becomes a big deal but we hear little about it three to five months from now, that will say something else."