Back to insights
Health data20 August 2026Research note

Interoperability begins where data transport ends

Why usable longitudinal health records require semantic agreement, identity and provenance, computable consent, and workflow adoption beyond an API connection.

Institutional analysis1,022 wordsBy Ram Labs ResearchEvidence reviewed 20 August 2026
Principal finding

An exchange is not interoperable merely because a payload arrives. Information becomes operationally interoperable only when receiving systems can interpret it, bind it to the correct person and provenance, enforce current permissions, and use it safely in a real decision.

70% all four exchange domains

US non-federal acute-care hospitals reporting at least sometimes sending, receiving, finding, and integrating external information in 2023.

Evidence[1]
43% routine interoperability

Hospitals reporting routine engagement across all four domains in 2023, up from 29% in 2021.

Evidence[1]
71% / 42% available / often used

Hospitals reporting necessary external information routinely available versus clinicians often using it at the point of care.

Evidence[1]
16% / 17% extended-care reach

Hospitals sending summaries to most or all long-term/post-acute-care providers and behavioral-health providers, respectively.

Evidence[1]

Transport, integration, and use are different states

Interoperability is often declared when two systems can exchange a document or call an API. That establishes transport. A safe receiving system must also parse the payload, understand codes and units, reconcile identity, preserve provenance, apply access policy, incorporate the information into workflow, and support correction. Each step can fail independently. A scanned summary may be readable but not computable; a structured result may carry a local code that changes meaning; an integrated medication list may duplicate discontinued therapies.

The 2023 US hospital survey makes this distinction measurable. Seventy percent of non-federal acute-care hospitals reported at least sometimes engaging in all four tracked domains: send, receive, find, and integrate. Only 43% did so routinely. Seventy-one percent said necessary external information was routinely available, while 42% said clinicians often used it at the point of care. These are self-reported hospital measures in one country, but the gap between availability and use is a useful engineering signal.

Evidence[1]

FHIR is a grammar, not a complete agreement

HL7 FHIR defines resources and interfaces for exchanging health information using established web patterns. Its normative foundation enables systems to represent objects such as Patient and Observation and to expose RESTful interactions. That common grammar is valuable, but base resources are intentionally general. Implementations still need profiles, terminology bindings, required fields, cardinality constraints, search behavior, version policy, and conformance testing for a specific use case. Two syntactically valid implementations can remain semantically incompatible.

A laboratory should therefore begin with an exchange contract. It names the decision supported, minimum dataset, source of truth, terminology and unit systems, permissible extensions, identifier rules, timestamp semantics, provenance fields, error responses, and service-level objectives. Test fixtures should include missing values, contradictory records, unit conversions, amended results, merged identities, revoked permissions, and late-arriving data. Conformance is demonstrated against these cases, not inferred from use of the FHIR label.

Evidence[2]

Identity and provenance are clinical safety functions

A perfectly coded result attached to the wrong person is not interoperable. Identity resolution must handle demographic change, transliteration, multiple identifiers, newborns, duplicate records, and jurisdictional constraints without relying on a universal identifier that may not exist. Matching policies need calibrated thresholds, human review for ambiguous cases, merge and unmerge procedures, and auditable correction. Error rates should be measured by subgroup and setting because naming conventions and data quality vary.

Provenance answers a different set of questions: who created or transformed the record, when, under which system and method, and whether it supersedes an earlier value. Derived variables should link to inputs and algorithm version. Clinical documents need author, attester, facility, and status. Audit logs record access and change, but should not be mistaken for proof that the underlying observation is true. Together, identity and provenance allow a recipient to judge fitness for a particular decision and to trace an error to its source.

Evidence[2][4]

The long tail defines system quality

Exchange is strongest between organizations with resources and established relationships. In the 2023 US data, only 16% of hospitals reported sending summaries to most or all long-term and post-acute-care providers, and 17% reported the same for behavioral-health providers. Smaller, rural, critical-access, and independent hospitals also reported less routine interoperability than better-resourced peers. A design optimized for a tertiary network can therefore widen discontinuity at exactly the transitions where medication, functional, and behavioral context matter.

Equity requirements belong in procurement and testing. Systems should support low-bandwidth and intermittent environments, affordable implementation profiles, multiple languages and scripts, assisted access, and organizations without large interface teams. Data-minimization and segmentation controls must not render essential information invisible in emergencies. The OECD’s health-data-governance recommendation places availability for public-interest purposes alongside privacy and security, emphasizing that governance must enable responsible use rather than choose between access and protection.

Evidence[1][4]

Measure the handoff, not the interface count

A rigorous programme evaluates an end-to-end handoff. Technical measures include delivery completeness, terminology-conformance rate, identity-match precision and recall, latency, and policy-decision correctness. Operational measures include reconciliation time, information found without duplicate work, and failure recovery. Clinical safety measures include wrong-patient events, missed or duplicated medications, delayed escalation, and corrections reaching downstream copies. Patient measures include access, comprehension, consent changes honored, and burden of repairing records.

WHO’s digital-health strategy, extended through 2027, identifies interoperability, governance, equitable access, and workforce capacity as linked foundations. That linkage is decisive. An API can reduce friction, but only institutions, shared standards, trained users, and accountable policy turn exchange into continuity. The mature claim is not that a platform unifies all health data. It is that a specified information set moved between named parties, under a valid authorization, retained its meaning and provenance, and measurably improved a defined handoff.

Evidence[1][6]
Research boundary

Scope and limitations

The hospital statistics are US self-reported survey estimates and should not be generalized to other countries or interpreted as patient-outcome effects. FHIR conformance does not by itself satisfy local privacy, consent, medical-record, or cybersecurity law; the Consent resource cited is Trial Use. Legal bases and access rights differ by jurisdiction. The proposed measures are an engineering framework, not legal advice, and deployments require local clinical, patient, standards, security, and regulatory participation.

Evidence base

References

Source review: 20 August 2026. Quantitative values retain their original definitions, periods, and boundaries.

  1. 01
    Interoperable Exchange of Patient Health Information Among U.S. Hospitals: 2023

    Office of the National Coordinator for Health IT · 2024

    healthit.gov
  2. 02
    FHIR R4 RESTful API and base resource specification

    HL7 International · 2019

    hl7.org
  3. 03
    FHIR R5 Consent resource

    HL7 International · 2023

    hl7.org
  4. 04
    Health Data Governance for the Digital Age

    OECD · 2022

    www.oecd.org
  5. 05
    Individuals’ Right under HIPAA to Access their Health Information

    US Department of Health and Human Services · 2025

    www.hhs.gov
  6. 06
    World Health Assembly extends the Global Strategy on Digital Health to 2027

    World Health Organization · 2025

    www.who.int