Why is Interoperability in Healthcare Important?

October 29, 2021

As you may already know, the Centers for Medicare and Medicaid Services, or the government agency commonly referred to as “CMS,” developed a roadmap to improve interoperability and health information access for patients, providers, and payers. So why is interoperability important? Read more for a guide on how new CMS regulations promoting interoperability in the healthcare industry will affect your company, and most importantly, how to get help adjusting to the requirements.


What is Interoperability in the Healthcare Context?

Essentially, interoperability means the ability of computer systems or healthcare entities to exchange and make use of information. In the context of the medical industry, interoperability means to enable the sharing of payer, patient or provider related information to simplify tasks and improve the delivery of care. 


For a long time, HIPAA has protected patients’ rights to access their health information. The May 2020 Interoperability and Patient Access final rule takes this a step further, by implementing data standards for sharing, eliminating conditions that would block information and protecting the patients’ right to know whether their health information is exchanged in a way that ensures their privacy and security.


What is the Interoperability and Patient Access Final Rule?

As of July 1, 2021, two key CMS policies from the Interoperability and Patient Access final rule are in effect. One policy requires hospitals with certain electronic health record (EHR) capabilities to send admission, discharge, and transfer notifications to other providers. The second requires Medicare, Medicaid and CHIP managed care organizations support sharing Provider Directory information via standard APIs (Application Programming Interfaces). These regulations will certainly change how healthcare information is exchanged between payers, providers, and patients. Ideally, they will lead to greater efficiency standards end-to-end.


As part of the Interoperability and Patient Access final rule, a payer has the right to ask third-party application developers whether their privacy policy specifies secondary data uses. CMS has also partnered with federal agencies such as the Office for Civil Rights (OCR) and the Federal Trade Commission (FTC) in their efforts to protect patients’ right to the privacy of their health data.


Due to the impact of the Covid-19 pandemic, in September 2021, CMS announced that it would “not take enforcement action against certain payers for the payer-to-payer data exchange provision of the May 2020 Interoperability and Patient Access final rule” until future rulemaking was finalized. This announcement represented CMS’ decision to exercise its discretion in enforcing the payer-to-payer policy temporarily. However, it had no effect on any existing regulatory requirements or implementation timelines previously provided by CMS. Is your company prepared to implement solutions to the new CMS regulations? 


How Should My Company Deal with the Interoperability and Patient Access Final Rule?

CMS has identified Health Level 7® (HL7) Fast Healthcare Interoperability Resources® (FHIR) Release 4.0.1 as “the foundational standard to support data exchange” via APIs (Application Programming Interfaces). Basically, CMS has now adopted the standards for FHIR-based APIs to support the privacy and security of patient information. Below, we’ll briefly break down the API requirements and how they will work:


The Patient Access API: As of January 1, 2021, CMS-regulated payers, i.e., MA organizations, Medicaid Fee-for-Service (FFS) programs, Medicaid managed care plans, CHIP FFS programs, CHIP managed care entities, and QHP issuers are now required to implement and maintain a secure API that allows patients to access their claims, clinical information, and other information, like payment amounts through third-party applications of their choice. The goal is to offer patients a more complete understanding of their interactions with the healthcare system. CMS has stated their goal in enacting the patient access API requirement is to promote improved patient decision-making and, in turn, better health outcomes.


The Provider Directory API: As of January 1, 2021, CMS-regulated payers noted above (except QHP issuers on the FFEs) are now required to make provider directory information publicly available through a standards-based API. CMS has stated its goal with this requirement is to “encourage innovation by allowing third-party application developers to access information so they can create services that help patients find providers for care and treatment, as well as help clinicians find other providers for care coordination, in the most user-friendly and intuitive ways possible.”


The Payer-to-Payer Data Exchange: As of January 1, 2022, CMS-regulated payers will be required to deliver patient health data at the request of the patient. CMS’ goal in enacting this requirement is to allow patients to have information portability when they move from payer to payer, as well as the creation of a collective and complete health record for patients to hold on to. The data required for delivery by payers to patients has been specifically outlined in the U.S. Core Data for Interoperability (USCDI) version 1 data set.


What Happens if My Company is Not in Compliance with the Interoperability and Patient Access Final Rule?

CMS has announced that it will publicly report clinicians, hospitals, and critical access hospitals that it finds might be blocking the transfer of information mandated by the Interoperability and Patient Access Final Rule. Providers must list or update their digital contact information in the National Plan and Provider Enumeration System (NPPES). Providers should provide their digital contact information, including secure digital endpoints such as a Direct Address and/or an FHIR API endpoint.

 

Implementing a Process for Compliance with the Interoperability and Patient Access Final Rule Doesn’t Have to be Difficult.

The Kona Kai Corporation is staying on top of advancements in guidelines, directives, and the latest technology. KKC has the dedicated resources to help organizations adopt and implement HL7® /FHIR standards. They have invested significant time in understanding what these standards are, and how to leverage them to help companies automate or streamline their systems.

 

KKC can guide your company in its objective to establish a system complying with the new CMS regulations enacted as part of the Interoperability and Patient Access Final Rule. KKC can also see this process through comprehensive implementation.[PB1]  KKC is your partner through your adaptation to new regulations, and we’re always here to help. Contact us for more information.


INSIGHTS

By Paul Benvenuto August 19, 2026
AI is changing workforce training from a one-time project into a continuous business capability. For decades, enterprise technology transformations have followed a predictable pattern. A new system is implemented, then employees learn how to use it. Productivity dips for a while, then recovers as the organization adapts. Whether it was a CRM implementation, ERP modernization, a claims platform replacement, or a core banking upgrade, the skills gap eventually disappeared because the technology itself stopped changing. AI is different. Unlike traditional enterprise software, AI capabilities continue to evolve after implementation. New models are released, AI agents become more capable, and workflows change faster than most organizations can retrain employees. The result is a workforce that isn't simply learning a new system, but continuously adapting to one. That fundamentally changes how organizations should think about workforce readiness. Recent research from the World Economic Forum and Microsoft's Work Trend Index suggests many organizations already recognize the challenge. Are enterprises doing enough to prepare for a skills gap that may never close? AI Changes the Rules for Workforce Training Traditional enterprise software had a finish line. Once employees learned the new system, their knowledge remained valuable for years. Training programs could be planned, measured, completed, and archived because the technology itself remained relatively stable. AI doesn't offer that stability. Employees who learned effective prompting techniques six months ago may now be using AI agents. Teams that started with document generation may now be automating entire workflows. Capabilities continue to expand, changing what effective work looks like almost as quickly as organizations can document it. That means workforce readiness can no longer be viewed as a milestone that follows implementation, as it needs to become part of day-to-day operations. The AI Skills Gap Doesn't End After Go-Live The challenge isn't simply that AI is changing jobs. It's that AI itself keeps changing. Foundation models continue to improve. New copilots are released. AI agents take on increasingly sophisticated tasks. Features that didn't exist six months ago become standard workflow tomorrow. Employees aren’t learning one “system” because they need to continuously adapt to new capabilities. Someone who learned the most effective way to use AI six months ago may already be working differently today. Traditional training models weren't designed for that pace of change. AI Is Reshaping the Workforce Faster Than Organizations Can Respond The World Economic Forum's Future of Jobs Report 2025 highlights just how significant this challenge has become.
By Paul Benvenuto July 31, 2026
PwC's April 2026 AI Performance Study surveyed 1,217 senior executives across 25 sectors and found something that should reframe how every regulated organization talks about AI investment: nearly three quarters of AI's economic value is being captured by just one fifth of organizations. Not because that top fifth has better models. PwC is specific about the differentiator: those organizations are 1.7 times more likely to have a Responsible AI framework and 1.5 times more likely to have a cross functional AI governance board. Their employees trust AI outputs at twice the rate of everyone else's. The value gap is structural, not a matter of who bought the better tool. That finding lands differently once you connect it to where trust actually comes from. It doesn't come from a more sophisticated model. It comes from knowing where your data originated, who touched it along the way, and what controls sat around it the entire time.  McKinsey's June 2026 research on AI data readiness makes the case that most organizations manage data like a storage problem when they should be managing it like a supply chain. A single PDF can expand into extracted text, tables, images, metadata, sensitivity tags, and quality scores, each one an intermediate artifact that AI systems reuse and recombine downstream. A small error introduced upstream doesn't stay small. It propagates. This matters more in regulated industries than almost anywhere else, because the data causing the most exposure is usually the data getting the least attention. Structured fields get governed. Clinical notes, claim narratives, loan officer comments, and audit trails, the unstructured stuff, usually don't, even though AI systems depend on it heavily. Gartner and IDC both put the share of enterprise data that is unstructured at somewhere around 80 to 90 percent. McKinsey's own research doesn't cite that specific figure, but makes the same underlying point: unstructured content is where AI systems draw the most context, and where governance attention is thinnest. None of this is an argument for waiting until your data is perfect before you deploy anything. PwC's 2026 Digital Trends in Operations Survey argues directly against that instinct: AI can help bridge data gaps, particularly through agents that reason using whatever data is actually available. The real mandate isn't clean data as a prerequisite. It's disciplined governance and iterative improvement running in parallel with deployment, calibrated to how much risk a given use case actually carries. So what does that look like in practice for a CIO or CDO sitting inside a regulated organization right now? A few diagnostic questions worth asking before your next AI initiative launches: Where does data quality actually break down in your pipeline, and does anyone own fixing it? Is lineage visible for the data feeding your highest risk AI use cases, or is it assumed? Where do unstructured assets, like clinical notes, policy documents, and loan files, enter your systems without any governance attached? Have you defined what "good enough" data quality means for each use case, calibrated to its actual risk profile, rather than applying one standard everywhere? Answering those honestly is uncomfortable in most organizations, because the answer is usually "we don't fully know." That's the point. You cannot govern what you cannot see, and you cannot trust an AI output built on a data foundation nobody has actually traced. The organizations in PwC's top 20 percent didn't get there by waiting for perfect data or by buying a better model. They got there by treating governance as a financial performance variable, not a compliance checkbox, and by building the lineage and controls that make trust possible at scale. Kona Kai's data supply chain assessment is built to answer exactly these questions before tool selection, not after. If you're not certain where your organization would land on that list, that uncertainty is worth resolving now. Get in touch to talk through what the assessment covers. Sources: PwC 2026 AI Performance Study, April 13, 2026 (74%/20% figure and 1.7x/1.5x/2x multipliers confirmed directly at pwc.com); McKinsey, AI Data Readiness: The Key to Scaling Impact, June 2026; Gartner and IDC estimates for the 80-90% unstructured data share; PwC 2026 Digital Trends in Operations Survey.
By Paul Benvenuto July 29, 2026
Every governance and workflow framework most organizations are running today was built for AI that waits for a human to ask it something. Agentic AI doesn't wait. It initiates, executes, and chains actions across systems on its own, and the workflows built around human initiated, human reviewed steps simply don't have
By Paul Benvenuto July 27, 2026
Education was the number one way companies say they adjusted their talent strategy in response to AI. And yet most organizations still treat training as an event. A workshop. A certificate. A box that gets checked once and never revisited.
By Paul Benvenuto July 20, 2026
Most organizations think they have AI governance because someone in legal drafted a policy and got it signed off. They don't. A policy sitting in a shared drive doesn't know where your AI is actually running. It doesn't flag it when a model drifts. It doesn't do a single thing when an employee routes a client file thro
By Paul Benvenuto July 20, 2026
Governance, people, data, and process are not sequential steps. They are four load-bearing walls, and in regulated industries, a crack in any one of them shows up as risk somewhere else. Here is where each pillar actually breaks down today, and what the data says about the gap between where most organizations sit and w
By Carly Whitte July 1, 2026
AI success depends on more than technology. Governance, regulation, and operational oversight are helping organizations turn AI pilots into scalable business capabilities.
By Carly Whitte June 27, 2026
Healthcare AI adoption depends on more than technology. Governance, accountability, and AI readiness determine whether AI delivers measurable business value.
By Carly Whitte May 24, 2026
AI-powered “vibe coding” is accelerating enterprise software creation, but governance and security controls are struggling to keep pace. Learn the hidden risks of AI-generated applications and why responsible AI governance is critical for scalable enterprise adoption.
By Carly Whitte May 6, 2026
Why does AI adoption stall in healthcare? Discover how accountability, governance, and risk management influence success beyond change management.