Pabau Engage inbox

Pabau Engage is here: every patient conversation in one inbox.

Learn more
Book a demo Book a demo
Operations & management

EHR interoperability: standards, challenges, and solutions

Avatar photo Despina Petrushevska
Last Updated: September 16, 2026
Reviewed by: Avatar photo Lucy Galloway

EHR interoperability is the ability of electronic health record systems to exchange, interpret, and use patient data across platforms, providers, and care settings. It works at four levels, rests on a handful of shared standards, and is now enforced by federal rules.

Certified software is close to universal. ONC’s final data brief on hospital adoption put certified EHR use at 99.4% of non-federal acute care hospitals in 2024. Connected records lag behind that figure, so practices still repeat tests, chase medication histories, and re-key referral data by hand.

This guide covers the four levels of interoperability, the standards behind them, the barriers private practices hit, and what the 2026 Promoting Interoperability measures require.

Key takeaways
Found our content helpful?

Key takeaways

EHR interoperability lets health systems exchange and use patient data across platforms without manual re-entry

Four levels exist: foundational, structural, semantic, and organizational, each addressing a different layer of data exchange

HL7 FHIR R4 is the ONC-mandated API standard under the 21st Century Cures Act, with information blocking rules in force

Data silos, implementation costs, and legacy system incompatibility remain the top barriers for independent practices

Pabau supports private practice interoperability through API-based integrations, centralized patient records, and digital documentation

What EHR interoperability means for your practice

Two systems talking to each other is only the starting point. When a patient sees a specialist, the primary care record has to travel with them. It also has to arrive in a format the specialist’s system can read and act on. Without that, clinicians order tests already done elsewhere, miss medication histories, and rebuild care plans from partial information. Our guide to EHR integration workflows covers how those connections get built.

The cost of poor exchange shows up in ordinary places. Staff re-key referral letters, and the front desk phones another practice for a medication list. A clinician orders a test the patient had six weeks ago. Those hours rarely get measured in an independent practice until they surface as revenue leakage or patient complaints.

The four levels of interoperability

The Healthcare Information and Management Systems Society (HIMSS) defines four levels of interoperability, each covering a distinct layer of health data exchange. Most practices operate at level one or two. Reaching levels three and four takes deliberate investment in standards and governance.

Level Name What it means Practical example
1 Foundational Systems can send and receive data, no interpretation required A lab sends a PDF result to an EHR inbox
2 Structural Data is formatted so the receiving system can parse its fields A C-CDA document maps patient demographics into the correct EHR fields
3 Semantic Both systems interpret data with the same meaning, using shared coding vocabularies An ICD-10 diagnosis code carries the same clinical meaning across two different EHRs
4 Organizational Governance, policy, and trust frameworks allow cross-organization exchange A hospital network and an independent practice share records under a data-sharing agreement

Most independent practices get foundational and structural interoperability from their EHR vendor. Semantic and organizational levels take more work. That means shared coding standards (SNOMED CT, LOINC, ICD-10), membership of a health information exchange (HIE), or data governance agreements with referring providers. Which rung you sit on decides who has to act next.

Four levels of EHR interoperability and who delivers each
Levels one and two arrive with a certified EHR, while levels three and four depend on coding discipline and signed agreements. Mapped from the HIMSS four-level model.

What connected records change for providers

Complete patient data at the point of care reduces preventable errors, and that is the clinical case. The operational case is just as strong. A practice that cannot receive structured data from referring providers re-enters it by hand, which costs time and introduces transcription errors.

  • Fewer medication errors: when medication lists travel with the patient, prescribers can spot dangerous interactions before writing the next prescription.
  • Fewer duplicate tests: a patient arriving at a specialist without lab results from their primary care provider often gets retested. Shared records make those results visible instead.
  • Faster referral workflows: a structured patient summary sent electronically beats a faxed PDF, and FHIR-enabled referral tools shorten the wait between referral and first appointment.
  • Lower administrative burden: staff spend less time on the phone chasing records when data moves between systems automatically. That time goes back to patient care.

For practice managers, the operational argument usually lands hardest. Poor exchange means your team does data entry that a properly configured system would handle, and that burden grows with patient volume.

The standards behind health data exchange

EHR interoperability standards are the shared technical languages that let different systems exchange data reliably. No single standard covers every case. Each was designed for a particular data type, which is why most EHR implementations support several at once.

Standard Full name Primary use Where you see it
HL7 v2 Health Level Seven version 2 Lab orders, ADT messages, pharmacy Legacy hospital systems still dominant in inpatient settings
HL7 FHIR R4 Fast Healthcare Interoperability Resources API-based patient data access, mobile apps ONC-mandated for certified EHR APIs; patient-facing apps
C-CDA Consolidated Clinical Document Architecture Clinical document exchange (summaries, referrals) Required by ONC for Meaningful Use and Promoting Interoperability
DICOM Digital Imaging and Communications in Medicine Medical imaging (X-ray, MRI, CT) Radiology systems; any practice sending imaging data

FHIR R4: the API standard behind patient data access

HL7 FHIR R4 is the ONC-mandated standard for patient data access APIs under the 21st Century Cures Act. Older HL7 versions needed custom integration work for every connection. FHIR uses RESTful APIs, the same approach behind consumer apps, so connections are quicker to build. The full specification is published by HL7 International.

FHIR APIs let patient access applications pull data straight from a certified EHR, with no manual export step. Patients can use approved health apps to view their own records, and referring providers can pull structured summaries programmatically. Any practice running certified EHR software already supports FHIR R4.

Pro Tip

Check whether your current EHR holds ONC certification under 45 CFR Part 170. Certified systems are required to expose FHIR R4 APIs, which means you may already have the foundation for broader interoperability without upgrading your software.

Common interoperability challenges in private practice

The barriers are not spread evenly. A smaller independent practice hits a different set of obstacles than a large hospital network, and the fixes differ with them.

  • Data silos: when each site or discipline runs a separate system with no shared data layer, records stay fragmented. One patient seen by a physician, a physiotherapist, and a dietitian can end up with three records that never meet. The fix starts with software built on open APIs rather than proprietary formats.
  • Lack of standardization: two EHRs can both claim HL7 compliance and still implement it differently, which causes mapping errors on transfer. Specialty practices running niche software written before modern interoperability rules hit this most often.
  • Privacy and security concerns: HIPAA (Health Insurance Portability and Accountability Act) requires appropriate safeguards in any data-sharing arrangement. Practices often hold back from connecting to external systems over perceived HIPAA risk, when documented safeguards are what make the connection defensible.
  • High implementation costs: integration engines, middleware, and custom API development all carry a price. A solo practitioner cannot always justify the spend without a clear return.
  • Information blocking: some EHR vendors limit data portability to raise switching costs. The 21st Century Cures Act makes that illegal under 45 CFR Part 171, though enforcement is still building.
  • Legacy system incompatibility: older EHR installations may not support modern API standards at all. You either upgrade or add a middleware layer to bridge them.

Interoperability solutions for private practices

Solving exchange rarely requires replacing the whole EHR. Several targeted approaches work well for independent and multi-specialty practices.

  • Adopt FHIR-based APIs: choose or upgrade to an EHR that exposes certified FHIR R4 APIs. Labs, imaging providers, and patient-facing apps can then connect without custom integration work.
  • Join a health information exchange (HIE): regional HIEs let participating providers share records under a governed trust framework. Many states run publicly funded HIEs that independent practices can join at low or no cost.
  • Use middleware and integration engines: platforms such as Mirth Connect and Rhapsody translate between systems that speak different standards. They earn their place where a legacy system cannot be replaced yet.
  • Standardize documentation: consistent use of ICD-10, SNOMED CT, and LOINC coding across the practice makes records portable even without an API connection.
  • Evaluate vendors on interoperability criteria: ask about ONC certification status, FHIR API availability, and data export formats before you sign. Treat resistance to data portability as a red flag.

Vendor choice is where most of this gets decided. If you are comparing systems, our guide to the best EMR software weighs them on certification, API access, and export options.

Regulatory framework: ONC, CMS, and the 21st Century Cures Act

US interoperability regulation has changed substantially since 2020. The 21st Century Cures Act, implemented through ONC’s Final Rule, set three binding requirements for every practice using a certified EHR. Those are FHIR R4 API access, a prohibition on information blocking, and certification requirements for EHR developers.

The CMS Promoting Interoperability Program attaches payment incentives and penalties to specific measures. The data itself is standardized too. Under the HTI-1 final rule, certified health IT has had to support USCDI version 3 since January 1, 2026. That version widens the required data set to social determinants of health and expanded demographic fields.

2026 Promoting Interoperability requirements: what practices need to know

The CMS Promoting Interoperability Program requires MIPS-eligible clinicians to report a defined set of measures each performance year. For 2026, CMS keeps its emphasis on electronic prescribing, health information exchange, provider-to-patient exchange through FHIR APIs, and public health reporting.

Compliance in 2026 comes down to four steps. Confirm your EHR is certified to the current edition, enable the patient access API, report every required measure, and keep the supporting documentation. The health information exchange measures are scored proportionally rather than against a fixed pass rate. Check the current measure specifications on CMS.gov before you report, since they are updated annually.

Requirement area Governing rule Who it affects Consequence of non-compliance
FHIR patient access API ONC Cures Act Final Rule EHR developers (flows to clinicians) ONC decertification of EHR product
Information blocking prohibition 45 CFR Part 171 Providers, developers, HIEs Civil monetary penalties up to $1M per violation for developers
MIPS Promoting Interoperability measures CMS MIPS program MIPS-eligible clinicians Negative MIPS payment adjustment
Summary of care exchange Promoting Interoperability Program MIPS-eligible clinicians Reduced MIPS composite score

EHR interoperability in day-to-day practice

These five scenarios show what changes once records move between systems on their own.

  • Hospital network referrals: Epic and Oracle Cerner are two of the largest EHR vendors in the US. Both use FHIR APIs to share patient summaries within a network. The receiving clinician sees the referring notes, medication list, and recent labs before the appointment starts.
  • State HIE data sharing: a cardiologist in a state with an active HIE can query the network for a patient’s recent emergency department visits. No phone call to the ED, no waiting on faxed records.
  • Lab result automation: practices connected to lab networks via HL7 FHIR receive structured results directly into the patient record. The result maps to the correct field and triggers any configured follow-up workflow.
  • Telehealth integrations: practices using telehealth software that connects to the main EHR document a video consult straight into the patient record. The next clinician sees it there.
  • Patient-controlled health apps: under the 21st Century Cures Act, patients can authorize third-party apps to pull their records from any ONC-certified EHR. Someone managing a chronic condition can gather records from several providers in one app.

Where EHR interoperability is heading

Three shifts are reshaping data exchange faster than most private practices can track.

TEFCA (Trusted Exchange Framework and Common Agreement) is ONC’s national interoperability framework, built as a single on-ramp for health data exchange across the US. A practice that joins a TEFCA-compliant Qualified Health Information Network (QHIN) reaches infrastructure that was previously the preserve of large hospital systems.

AI-driven data harmonization is being applied to the semantic problem at scale. Machine learning models can map inconsistent terminology, resolve duplicate patient records, and normalize data from different coding systems with far less manual review.

Value-based care data requirements are turning interoperability into a financial necessity. Payers increasingly tie reimbursement to outcomes data that only connected systems can collect. Practices that invest now are better placed to join alternative payment models as those expand.

Pro Tip

Review the ONC TEFCA webpage annually. As more Qualified Health Information Networks come online, joining one becomes the simplest route to national-level exchange for a practice without IT staff.

How Pabau supports data exchange for private practices

Private practices carry the same compliance requirements and patient expectations as large hospital systems, without the IT department. Practice management software like Pabau answers the first half of that problem. One practice management app holds appointments, clinical notes, forms, prescriptions, and communications against a single patient record.

Pabau’s API-based architecture supports integrations with labs, imaging providers, and third-party platforms. Digital intake forms capture structured patient data from first contact, replacing the unstructured PDFs that downstream systems cannot parse. Every clinician on the team reads the same record, whichever practitioner the patient saw last.

Audit trails and structured data export support MIPS reporting and state-level requirements. For a practice running several practitioners or locations, that internal foundation comes before any external data exchange is worth attempting.

Customizable consent and intake forms
Pabau’s consent and intake forms collect structured answers at booking, so referral summaries and clinical notes start from data other systems can read.

See how Pabau connects your practice data

Pabau gives private practices a centralized patient record with open API integrations. See how it simplifies data workflows across your team.

Pabau clinic management dashboard

Conclusion

Interoperability is now a small-practice problem as much as a hospital one. The same rules apply, patients expect the same continuity, and every handoff that loses data costs staff time to rebuild.

Most independent practices sit at foundational or structural exchange. Moving up means shared coding standards, an HIE membership, or an agreement with the practices that refer to you. Those are governance decisions, and no vendor can make them for you.

Put the internal record in order first, because external exchange is far harder from a fragmented starting point. Book a demo to see how Pabau centralizes patient records and API integrations for your practice.

Continue your research

Continue your research

Want to understand how EHR integration fits your practice’s tech stack? EHR integration workflows covers the connection points between practice management systems and external platforms.

Planning a move to a new system? EHR implementation walks through the stages, the data migration decisions, and the staff training that keeps a rollout on schedule.

Still pinning down the terminology? EHR meaning explains what an electronic health record holds and how it differs from an EMR.

Considering a move to paperless clinical records? Going paperless in your practice explains the workflow changes and compliance points involved.

Frequently asked questions

What is EHR interoperability?

EHR interoperability is the ability of electronic health record systems to exchange, interpret, and use patient data across platforms and care settings. It removes manual re-entry between systems. The four levels are foundational, structural, semantic, and organizational, and each covers a different layer of how data moves.

What are the main barriers to EHR interoperability?

The main barriers are data silos from incompatible systems and inconsistent implementation of HL7 and other protocols. Practices also face HIPAA-related caution about sharing data, high integration costs, vendor information blocking, and legacy systems that predate modern API standards.

What standards enable EHR interoperability?

The primary standards are HL7 FHIR R4, HL7 v2, C-CDA, and DICOM. FHIR R4 is the ONC-mandated API standard for patient data access, and HL7 v2 still carries lab and pharmacy messaging. C-CDA moves clinical documents, and DICOM handles medical imaging. Most certified EHRs support several at once.

What is the CMS Promoting Interoperability Program?

The CMS Promoting Interoperability Program is the part of MIPS that scores eligible clinicians on their use of certified EHR technology. Measures cover electronic prescribing, health information exchange, patient access through FHIR APIs, and public health reporting. Clinicians who do not report the required measures score zero in that category, which drags down the final MIPS score.

Does EHR interoperability apply to private practices and small practices?

Yes. Any practice using a certified EHR falls under the ONC information blocking rules, whatever its size. The FHIR API requirements of the 21st Century Cures Act apply the same way. MIPS-eligible clinicians in private practice also report Promoting Interoperability measures, with payment consequences attached.

Found our content helpful?
×