In May, the Centers for Medicare & Medicaid Services (CMS) published a request for information (RFI) in the Federal Register. We wrote about that RFI here. The agency gathered public feedback on the landscape of digital health products available to Medicare beneficiaries and the overall state of data interoperability and health technology infrastructure.
The CMS health tech RFI garnered over 1,300 comments, including from health insurance trade organizations AHIP and the Alliance of Community Health Plans as well as numerous large health insurers.
Here is a look at some common themes among the health insurance industry comments in response to the CMS health tech RFI:
Accelerating Interoperability and FHIR-Based Data Exchange
There is a strong consensus on the need for seamless, secure, and standardized data flow across the healthcare ecosystem. For example, the BCBSA promoted the cost savings the health system can achieve with value-based care (VBC). However, it lamented the lack of seamless, secure data sharing necessary for VBC, saying, “Unfortunately, VBC is hindered today by fragmented data systems, limitations to interoperability, and access to timely, actionable information. Providers often lack timely access to key data, such as discharge summaries, referrals, or lab results, leading to gaps in care coordination and missed opportunities for interventions. Health plans may receive hospitalization data weeks after treatment, making it hard to support timely follow-up or manage high-risk patients. The inconsistent implementation of Application Programming Interfaces (APIs) limits effective data sharing across EHR systems.”
To help, health plans widely support accelerating the adoption of FHIR-based APIs as the standard for data exchange, particularly for prior authorization. They would like to move away from outdated document-based exchange methods. For example, The Cigna Group pushed for APIs, stating, “…we recommend phasing out document-based exchange in TEFCA exchange and instead requiring exchange via Health Level 7® (HL7®) Fast Healthcare Interoperability Resources® (FHIR®) application programming interfaces (APIs) as soon as possible. We urge ASTP to operationalize the prior authorization use case and begin requiring responses via FHIR APIs no later than January 1, 2026.”
AHIP was similarly supportive of FHIR-based APIs, stating, “ASTP should phase out document-based exchange (e.g., IHE) and require exchange via FHIR APIs as soon as practicable.”
How can CMS encourage the use of these APIs? Several entities called for CMS to implement incentives to drive provider utilization of these APIs, noting that current incentives are insufficient. For example, Humana suggested, “Requiring payers to develop standardized APIs without adopting strong incentives to drive utilization is an inefficient approach to interoperability. …we urge the agency to consider transitioning the Electronic Prior Authorization measure from an attestation-based measure to a performance-based measure as originally proposed in the Promoting Interoperability and Prior Authorization rule.”
Establishing a National Provider Directory
There is overwhelming support for a centralized, comprehensive national provider directory that acts as a “single source of truth” among health plans. Benefits cited include reducing administrative burden for providers and payers, improving data accuracy, and enabling better patient access to care.
Plans also advocated for the directory to include FHIR endpoints and utilize digital identity credentials, ideally managed by a federal entity in a public-private partnership. For example, The Cigna Group said, “The Cigna Group believes there would be significant value for payers in a nationwide provider directory that includes FHIR endpoints and utilizes digital identity credentials, provided the directory is appropriately modeled. Such a directory should be housed and maintained by a coordinating entity (i.e., the Recognized Coordinating Entity® (RCE®)) that is responsible for regularly adding entries and maintaining the accuracy and comprehensiveness of the entries.”
The health insurance industry also raised concerns about current directory inaccuracies, the lack of enforcement for provider updates, and the risk of a new directory merely adding to existing data sources without streamlining. For example, the ACHP noted: “Many ACHP member companies have found that the quality of the data provided from a physician’s office or group depends on who answers the request. One ACHP member company noted that it can receive different information depending on whether it speaks with a general administrative staffer, the credentialing department, or the billing department. Depending on who responds, knowledge of the practice or their interpretation of health plans’ data requests varies. This variation in responses makes it exceedingly difficult to verify information and correct inaccurate data. Unless a national provider directory addresses these current issues, it may achieve the same fate as existing payer directories – inaccurate or incomplete data.
Reducing Administrative Burden and Streamlining Processes
A major recurring theme is the desire to streamline and simplify administrative processes like prior authorization, provider credentialing, medical record requests, and quality reporting. Per Point32Health, “Despite the fact that the vast majority of Medicare providers have invested in electronic health records, provider administrative burden remains significant and problematic. The positive potential of EHR adoption has been undermined because remote access to EHRs usually isn’t granted to payors at all, or only at an additional cost. In some cases, this is because the EHR vendors require providers to purchase additional licenses if payors access the EHR remotely. As a result, providers must continue to use faxes and other outdated modes to communicate with health plans.”
This streamlining is seen as crucial for reducing administrative overhead and clinician burnout. In the case of EHR technology, the capability already exists to grant payers access.
Insurers asked to reduce the regulatory burden and redundant efforts while unburdening technology budgets. Point32Health used the M3P program as an example, “Insurers are regulated by numerous Agencies of the Federal Government – and even within HHS, individual departments have differing priorities. Ultimately, most of these regulations drain the budgets of payor technology departments. This means that payors must allocate scarce technology resources to initiatives that their members neither want nor ultimately use. For instance, individual health plans spent millions of dollars implementing the Medicare Prescription Payment Plan (MPPP). At this time, member participation is less than 1%, according to estimates by Milliman. This is especially problematic for regional not-for-profit health plans.”
Advancing Value-Based Care (VBC) Through Technology
There is strong support for leveraging health technology, including AI and digital health tools, to advance VBC models, improve health outcomes, and manage costs. For example, UnitedHealth Group proposed the following: “Launch a national AI-enabled value-based care innovation waiver program within the Centers for Medicare & Medicaid Services (CMS) that functions as a public-private innovation sandbox, empowering Medicare Advantage plans and value-based providers to pilot and scale AI-powered models with fast-track agency review and approvals (e.g., address the need for retrospective chart review vs. real-time risk adjustment).
Organizations also emphasized the need for specific EHR capabilities to support VBC workflows and for financial and operational incentives to encourage the adoption of VBC-enabling technologies. For example, SCAN Group recommended that CMS create a “VBC-Ready EMR Certification” framework that would be, “Similar to Promoting Interoperability or ONC certification.”
This framework would help define minimum capabilities such as team-based documentation, goal-oriented care plans, quality measure capture, and population health tools.
Several comments also highlight the importance of timely, comprehensive, and standardized data for effective VBC, including clinical data, claims data, and social determinants of health . According to AHIP, “Data is needed across several types of organizations in the ecosystem such as providers, payers, states, public health agencies, community-based organizations, and the like. Essential data types include:
- Claims data to support financial calculations, attribution, quality measurement, and monitoring utilization trends
- Clinical care documentation in EHRs to manage chronic conditions and coordinate care, enable care gap identification and population health analytics, and support interventions
- Admit, Discharge, and/or Transfer (ADT) feeds to assist with proactive care coordination, reduce avoidable readmissions, and improve care continuity
- e-Prescribing data to improve medication reconciliation
- Pharmacy coverage benefit inquiry/response to encourage cost-effective prescriptions and medication adherence
- Patient-reported data to support improved patient satisfaction and patient empowerment
- Patient access API to support data portability and improve transparency
- Quality measure reporting to tie financial incentives to quality performance and enable continuous improvement in quality outcomes”
Ensuring Data Privacy and Security
Several health insurance entities expressed concern regarding patient data privacy and cybersecurity, especially when data moves outside HIPAA-regulated entities, such as to third-party applications.
AHIP specifically expressed the need for a national privacy framework to protect consumer health data not currently covered by HIPAA and for guidelines for digital identity credentials, saying, “We urge HHS to work with Congress to enact a national privacy law to protect patients that leverages existing enforcement mechanisms, retains the HIPAA Privacy and Security Rules as the governing privacy framework for health care information held by health plans and providers, robustly protects consumer health data not currently covered by HIPAA, prevents the proliferation of conflicting state privacy laws, and does not include private right of action.”
Many also recommended establishing safe harbor protections for entities that comply with data sharing regulations to encourage participation without undue liability. For example, UnitedHealth Group suggested that CMS, “The safe harbor would address situations where a data breach results from the actions of an entity that is transferring information (such as an HIE) and not the provider or other participant that is sending or receiving the data. This safe harbor should cover all entities that share data that are in compliance with applicable law and the Common Agreement and have the authorized identity token and valid consent as provided by a certified CSP.”
Digital Identity Credentials
Support exists for implementing standardized digital identity credentials for patients, providers, and caregivers to enhance secure data exchange and patient matching. For example, the ACHP said, “Maintaining proprietary login systems is costly and creates friction for members, especially those navigating across multiple health systems or insurers. Patient identification is fragmented across payers and providers, leading to delays in care coordination, duplicate records, and fragmented care planning. We however have concerns regarding the implementation costs and the collection of extensive personal information which may be perceived as intrusive and consequently slow uptake. CMS should provide clear guidance and incentives to address these barriers.”
Coordination and Support for Smaller Entities
Many comments emphasize the need for enhanced coordination across federal agencies and departments to align policies and processes related to health data interoperability and technology adoption. The Cigna Group stated, “The Cigna Group recommends that HHS continue to strengthen coordination across the Department – as well as other departments within the federal government – on issues related to health data interoperability. This includes the implementation and utilization of APIs and incentivizing the use of APIs through TEFCA exchange, which will make the TEFCA framework more useful and valuable to the payer community. All agencies within HHS should align policies and processes regarding API implementation, with ASTP acting as the central coordinator to ensure consistency in definitions, timing, incentives, etc. This unified approach will foster a more seamless and standardized environment for data exchange, enabling payers to leverage APIs more effectively and driving broader adoption and integration. Enhanced coordination will also support harmonized policies and initiatives across HHS (and the broader federal government), reducing redundancy and promoting a cohesive strategy for advancing health data interoperability.”
Several organizations highlight the resource constraints faced by smaller and rural providers, as well as local non-profit health plans, and urge CMS to provide grants, technical assistance, or subsidies to help them invest in necessary health IT infrastructure and participate in data exchange initiatives. Scan Group suggested that CMS should, “Offer grants, subsidies, or shared services to help small clinics, rural health centers, and FQHCs integrate with their state’s IIS without high implementation costs.”
The ACHP shared similar comments, “Small organizations like independent providers and non-profit, local plans struggle to invest the necessary resources to realize the level of coordination and interoperability needed to participate in these networks. CMS should consider ways to offer support and resources to these organizations so that they can contribute meaningful data in this process.”
Next Steps
Looking ahead, stakeholders anticipate several overarching actions and developments stemming from this CMS health tech RFI process:
Continued Rulemaking and Policy Development
HHS expects to use the feedback to address existing regulations and processes that hinder progress and to continue its regular rulemaking process for new technical standards, providing the industry an opportunity to comment before finalization.
Cross-Agency and Federal-State Collaboration
The feedback could also lead to enhanced federal policy leadership in collaboration with state efforts, particularly concerning artificial intelligence and prior authorization, to prevent data fragmentation and align policies.
Strategic Goal Setting
CMS and ASTP/ONC likely will prioritize specific strategic goals related to health technology and value-based care, with the expectation that they will develop actions to align with these goals.
Phased Implementation for Key Initiatives
For significant undertakings, a phased approach is likely, starting with core data elements and eventually expanding to include more provider types and data. This phased approach is intended to build trust and ensure comprehensive adoption through public-private partnerships.
Learn More:
American Hospital Association Comments
Certifi’s health insurance premium billing and payment solutions help healthcare payers improve member satisfaction while reducing administrative costs.

