惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Commits to openclaw:main
Recent Commits to openclaw:main
N
News | PayPal Newsroom
TaoSecurity Blog
TaoSecurity Blog
Google Online Security Blog
Google Online Security Blog
NISL@THU
NISL@THU
T
Threatpost
C
CXSECURITY Database RSS Feed - CXSecurity.com
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Engineering at Meta
Engineering at Meta
AWS News Blog
AWS News Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
P
Privacy International News Feed
B
Blog
PCI Perspectives
PCI Perspectives
Martin Fowler
Martin Fowler
Spread Privacy
Spread Privacy
P
Proofpoint News Feed
T
Tenable Blog
F
Fortinet All Blogs
G
GRAHAM CLULEY
V2EX - 技术
V2EX - 技术
C
Check Point Blog
Project Zero
Project Zero
P
Palo Alto Networks Blog
J
Java Code Geeks
W
WeLiveSecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
The Exploit Database - CXSecurity.com
博客园 - 司徒正美
P
Privacy & Cybersecurity Law Blog
S
SegmentFault 最新的问题
Last Week in AI
Last Week in AI
Forbes - Security
Forbes - Security
C
Cybersecurity and Infrastructure Security Agency CISA
Security Latest
Security Latest
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Vercel News
Vercel News
Recent Announcements
Recent Announcements
博客园 - Franky
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Recorded Future
Recorded Future
The Last Watchdog
The Last Watchdog
MongoDB | Blog
MongoDB | Blog
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
Cisco Talos Blog
Cisco Talos Blog
量子位
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

WhatIs

Hims & Hers launches AI agent for lab results Twilio revamps, updates customer engagement platform CISA launches critical infrastructure cyber resilience initiative Most patients find appointment scheduling, billing overly complex Teradata's latest targets putting agentic AI into production AHA, Joint Commission launch cyber resilience program Tableau in transition as AI forces BI vendors to evolve California hospitals sue Elevance over out-of-network penalty CMS Health Tech Ecosystem adds electronic prior auth pledge Atlassian MCP updates take aim at AI token usage Leapfrog: Hospitals improved in 17 patient safety measures United promises another 30% cut to prior auths in 2026 AI outperforms docs on clinical reasoning, but not ready for solo work ServiceNow's Autonomous CRM takes aim at Salesforce ServiceNow reintroduces itself as an AI 'security company' New Tableau leader talks vendor's evolution in era of AI Deloitte warns of a "bubble effect" caused by the GLP-1 boom Tableau repositions for AI, unveils new knowledge layer IBM Bob AI coding agent ships, HashiCorp AIOps previewed DOJ forms West Coast Strike Force to stop healthcare fraud Most people benefit from the ACA's free preventive services SAP acquisitions of Dremio, Prior Labs target AI development Bridging the gap: Legacy tools gain enterprise AI support Amazon Connect Talent: AWS enters AI interviewing market AHA, West Health launch health tech adoption initiative How are states preparing for Medicaid work requirements? Medical device security improves, but cyberattacks remain pervasive Weekly news roundup: Musk vs. Altman, Google’s Pentagon AI deal, China and EU hit Meta Skin substitute spending driven by patients, products, prices Clinical AI company Aidoc snags $150M in new funding Qlik's Capone departs after eight years as CEO OIG: CMS paid millions in improper virtual care payments FDA moves toward real-time review of clinical trial data FQHCs in low-income neighborhoods have lower cancer screening rates Solving quantum computing's longstanding no-cloning problem Qdrant boosts performance, reliability to meet AI needs Racial health disparities still impact U.S. as policy changes loom Agentforce Operations tackles workflow orchestration Boehringer's dual agonist obesity drug spurs up to 16.6% weight loss Legacy architecture, awareness gaps stifle microsegmentation adoption in healthcare AMA alerts officials of health plans' No Surprises Act abuse Latest SAS capabilities focus on fostering reliable AI Actian targets secure, compliant AI with new vector database Payers promise standardized electronic prior auths MIT EmTech: 2026 is the year AI goes to work As Claude Design debuts, Adobe users -- and buyers -- shrug GoodData joins agentic AI development mix with Agent Builder Comfort, affordability top drivers of digital mental health tool use CMS accelerates Medicare coverage for breakthrough medical devices Weekly news roundup: Tim Cook exits Apple, Meta layoffs intensify and Anthropic investigates Claude Merck inks $1 billion AI drug development deal with Google Cloud OCR settles four HIPAA investigations, prioritizes risk analysis OpenAI launches ChatGPT for Clinicians 90% of patients re-check AI chatbot health info with other sources Gemini Enterprise Agent Platform adds 'connective tissue' to Vertex AI AMA urges greater oversight of AI mental health chatbots CMS benches BALANCE Model for Medicare Former ransomware negotiator pleads guilty to BlackCat conspiracy New Google TPUs multiply AI infrastructure efficiency When brand-name drugs need a prior auth, brace for delays Google unveils data cloud purpose built for agentic AI Snowflake updates further goal of being control pane for AI UnitedHealthcare eliminates prior authorization for rural providers Yelp launches appointment scheduling button from Zocdoc Oracle takes steps toward CMS Health Tech Ecosystem goals OpenAI debuts AI model GPT-Rosalind to speed up drug discovery Which patient care access barriers deter cancer screening? Redis unveils Feature Form to improve AI, ML workloads Adobe defines its AI-powered customer experience platform How to escape agentification pilot purgatory for scalable AI New HSCC guidance tackles third-party AI risk Data quality, fast failures and quick wins key to AI success Stop Overpaying for Storage: A FinOps Guide for CIOs AWS launches AI-driven tool to speed up early-stage antibody discovery AMA: Clinician burnout in specialties persists as overall rates drop Mental health parity remains elusive in 43 states Before revenue cycle AI, payers and providers need to get along Edge and physical AI poised to upend enterprise networks Salesforce releases Agentforce dev tools, updates Agent Fabric Cyberattack continues to disrupt operations at Signature Healthcare FDA reminds sponsors, researchers to report clinical trial results AI arms race leading to prior auth problems, reimbursement cuts Abridge dives deeper into clinical decision support with NEJM, AMA AI provider search is here. How can health orgs stay visible? Judge dismisses No Surprises Act lawsuit against HaloMD What IT leaders should know from Nutanix .NEXT HubSpot builds answer engine optimization into its platform Sutter Health, MemorialCare face class action lawsuit over AI scribe use Latest Qlik tools target helping users achieve AI goals CMS taps Verily, Noom, 150+ others to participate in ACCESS model Starburst intros AI assistant to boost analysis, exploration Payers face faster prior authorization approvals under CMS proposal Lenovo deploys AI data agent for marketing, UX, e-commerce Cisco Galileo buy reflects blurring lines in AI observability CMS proposes 2.4% IPPS bump, joint replacement model expansion Patients unsure what to trust amid health information overload Nutanix expands flexibility by building out external storage Amazon Pharmacy adds Lilly's obesity pill with same-day delivery ServiceNow AI pricing change takes on enterprise ROI struggles Oracle's Sudha Raghavan on AI's infrastructure renaissance
AHA calls for TEFCA individual access SOP delay, citing patient privacy concerns
2026-04-28 · via WhatIs

gmast3r/istock via Getty Images

Jill Hughes

By

Published: 28 Apr 2026

The American Hospital Association published a letter to The Sequoia Project asking it to delay implementation of the TEFCA Individual Access Services Exchange Purpose Standard Operating Procedures version 3.0. The association cited patient privacy concerns, saying it could expose hospitals to data breaches and patient misidentification. Currently, the IAS XP SOP has an implementation deadline of Aug. 1, 2027. 

In its letter to Mariann Yeager, CEO of The Sequoia Project, the AHA acknowledged the importance of data interoperability and highlighted the value of TEFCA in supporting better patient safety and continuity of care.  

What's more, the AHA noted that its members recognize that IAS -- the pathway that enables patients to request their records through Qualified Health Information Networks rather than hospital portals -- can help patients make more informed decisions and promote engagement.  

"At the same time, the protection of patient data is foundational to patient trust in the health care system and, as such, the government has codified, through statute and regulation, actions certain entities must take to ensure such protection," the AHA stated.  

"Thus, any efforts to foster data exchange must be balanced with the existing statutory obligations to protect patient data." 

The AHA asserted that the proposals in the IAS XP SOP "do not contend with the statutory and regulatory obligations of hospitals and health systems to protect patient data," creating potential compliance and liability risks.  

The AHA instead recommended either establishing a safe harbor for providers who use this SOP for an IAS request or developing regulations that align the proposal with HIPAA. 

Understanding the IAS XP SOP proposal 

Digital health tools and apps can become IAS providers under TEFCA, enabling patients to use the apps of their choice to obtain copies of their medical records from TEFCA participants. This workflow is similar to how individuals can connect their bank and credit card accounts to a personal finance app to manage their budgets, Epic noted in a blog post. 

The IAS provider must sign a contract with a QHIN to become a TEFCA participant.  

The IAS XP SOP proposals in question outline the specific requirements that IAS providers are required to follow for individual identity verification when sending an IAS query, as well as identifying when a QHIN, participant or subparticipant is required to respond to an IAS query.  

Typical IAS workflows entail identity verification, patient matching and patient consent. 

The proposed IAS XP SOP contains three proposed approaches for entities within the TEFCA ecosystem to respond to IAS requests, touching on all threecomponents of the IAS workflow: 

  • Response Approach 1: Requires responding entities to respond to IAS requests using a FHIR credential-based login flow using specified demographic fields for patient matching. 

  • Response Approach 2a: Requires responding entities to respond to any valid IAS requests when the IAS provider has provided the new "TEFCA IAS Consent," or TIC, flow that verifies that the individual has consented to use the IAS. 

  • Response Approach 2b: Requires the responding entity to respond to IAS requests when the entity has determined a match consistent with its response policy, which may include fewer demographic fields or responding without requiring the TEFCA IAS Consent flow. 

These three approaches -- credential-based, consent-based or policy-driven -- were designed to support TEFCA's goals of information exchange while promoting flexibility and privacy. 

The AHA's stance 

The AHA argued that the proposed SOP relies on "untested consent and patient matching components, presenting significant compliance risks for responding nodes that are covered entities." 

Additionally, the AHA suggested that the Aug. 1, 2027, deadline does not provide enough time to build and test functionality and integrate workflows.  

"Approaches 2a and 2b reference a new proposed TIC process, whereby the third-party app would validate and verify that the individual has consented to use the IAS. TIC workflows do not currently exist and have not been tested," the AHA noted.  

"Most significantly, the proposed process has not been reconciled with the legal and regulatory obligations for responding nodes that are covered entities to verify requests for access and use of data." 

The AHA asserted that the TIC approaches could prevent providers from verifying the identity and authority of third-party entities requesting data, possibly putting them at risk of HIPAA violations. What's more, the proposals do not specifically address local privacy and consent requirements, which may vary by state. 

Additionally, the AHA took issue with the patient-matching methodologies in the IAS SOP workflow that would require manual entry of demographic data fields, which could lead to patient misidentification or data theft, it said. 

The AHA urged The Sequoia Project to work with regulators to create a statutory safe harbor that protects providers from liability for disclosures completed via these IAS approaches. Rather than move forward with the proposals as written, the AHA encouraged The Sequoia Project to issue requests for information and seek feedback from key stakeholders before finalizing the guidelines. 

"Should the Sequoia Project move forward with proposals without addressing these risks, we are concerned that providers will be disincentivized from participating in TEFCA, given these significant legal, compliance and patient care concerns," The AHA said. 

Jill Hughes has covered health tech news since 2021.

Dig Deeper on Interoperability in healthcare