Federal rules increasingly compel data to flow. This lesson covers information blocking, the FHIR API mandates, and the prior authorization rule.
For decades, data sharing was voluntary, and much of it did not happen. Federal rules have changed that, moving interoperability from a good idea to a legal requirement. Anyone building value-based analytics needs to know these rules, because they increasingly determine what data you are entitled to and what your organization must provide.
Information blocking
The most consequential shift is the prohibition on information blocking.
Worth remembering: federal rules now prohibit information blocking, practices by health care providers, technology developers, and exchanges that knowingly interfere with the access, exchange, or use of electronic health information. This flipped the default. Withholding data that should flow is no longer a business choice; it is a rule violation. Combined with the requirement that patients be able to access their own electronic health information through FHIR APIs at no cost, the effect is to make data sharing the expected baseline rather than a favor.
The FHIR API mandates
Layered on top are requirements that data be made available through modern APIs. Certified electronic health records must offer standardized FHIR APIs for patient and population access, and payers face parallel requirements. The direction is unmistakably FHIR-first: the government is standardizing on FHIR as the way health data moves, which is why building your analytics around it is a safe long-term bet.
The prior authorization rule (CMS-0057-F)
A major recent rule, the CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), targets both data flow and the prior-authorization friction the utilization-management course covered. Its requirements phase in:
- Operationally (from 2026): impacted payers must meet faster prior-authorization turnaround times, 72 hours for urgent requests and 7 calendar days for standard ones.
- Technically (by 2027): impacted payers must implement several FHIR APIs, including a Prior Authorization API and a Payer-to-Payer API, so that authorization and patient data move electronically rather than by fax and phone.
A moving target
One honest caveat for anyone relying on these rules: interoperability policy is actively evolving, with ongoing deregulatory and rule-refinement activity as recently as 2025 and 2026. The direction, FHIR-first, information sharing as the default, has been durable, but specific requirements and timelines shift. As with the Medicaid course’s guidance example, verify the current rule before relying on a specific provision.
Key takeaways
- Information blocking rules prohibit knowingly interfering with the flow of electronic health information, making data sharing the default.
- Federal rules increasingly require FHIR APIs for patient, population, and payer data access, a FHIR-first direction.
- CMS-0057-F adds prior-authorization turnaround requirements (from 2026) and FHIR APIs including a Prior Authorization and Payer-to-Payer API (by 2027); verify current timelines, since the policy is evolving.
Sources
Check your understanding
What does the federal information blocking rule prohibit?
Information blocking rules make it unlawful to knowingly impede the appropriate flow of electronic health information, shifting data sharing from optional to required.