Why now — a once-per-decade regulatory window
Five federal mandates rebuild the EMR — between 2026 and 2027
Last updated: Jun 25, 2026 · every claim links to a primary government source below.
TL;DR
Between Jan 2026 and Jan 2027, five federal rules force every EMR onto FHIR, the new USCDI v3 data standard, the national TEFCA exchange, and payer prior-authorization APIs. Incumbents must retrofit decades of legacy to comply; REV is built native to all of it. This isn't a forecast — it's already moving: TEFCA exchange went from 10M records (Jan 2025) to ~500M across 11 QHINs and ~71,000 sites, and CMS projects ~$15B in prior-auth savings. The catch: a 1–5 clinician practice can't fund FHIR, payer-API, and certification uplifts alone — so it buys a platform that's compliant out of the box.
The five mandates
Each forces a capability REV ships natively. Incumbents have to bolt these onto legacy stacks; we start here.
| When | Rule | What it forces | Why REV wins | Status |
|---|---|---|---|---|
| Jan 1, 2026 | USCDI v3 (under HTI-1) |
New required common data set — adds SDOH, SOGI, insurance, more clinical elements; only v3 is available in the cert program. | Native to USCDI v3 — no "v1→v3" migration project. | In effect |
| Jan 1, 2026 | HTI-1 cert baseline | USCDI v3 + SMART v2 + FHIR US Core 6.1.0 + patient privacy controls become the certification floor; Insights Condition reporting begins (capture 2026 → first report Jul 2027). | Built to the new criteria from day one; clean data model makes the transparency reporting trivial. | In effect ONC enforcement discretion during transition |
| Live now | TEFCA (national exchange) |
The national "network of networks" for health-data exchange, run through Qualified Health Information Networks (QHINs). | TEFCA-connected from day one — a 1-clinician practice gets nationwide record exchange with no point-to-point builds. | Live 11 QHINs · ~71k sites · ~500M records |
| FY 2026 (eff. Oct 1, 2025) |
HTI-4 | Certification criteria for electronic prior authorization (FHIR), e-prescribing, and real-time prescription benefit (drug cost + PA-required at the point of prescribing). | ePA + RTPB are core REV modules, not bolt-ons — straight at the denial/PA pain. | Final cert standards phase to Jan 1, 2028 |
| Jan 1, 2027 | CMS-0057-F (payer APIs) |
Impacted payers must run FHIR Prior Authorization, Provider Access, Payer-to-Payer, and Patient Access APIs; PA decision timeframes tighten from 2026. | FHIR-native platform plugs straight into payer APIs for real-time eligibility / PA / status — "paid correctly the first time." | Final ~$15B est. savings / 10 yr |
Note on slide 3: the deck's "Mar 2026 — HTI-1 enforcement begins" should read Jan 1, 2026 (the compliance date), and the TEFCA reach is better stated as ~71,000 sites (HHS) than "10,600+." Everything else on the slide is accurate.
Why this is REV's window
- Every incumbent must retrofit. USCDI v3, SMART v2, FHIR APIs, ePA, and payer-API connectivity have to be grafted onto EMR stacks built before any of it existed. We get to start native.
- Small practices can't fund the uplift alone. FHIR, payer-API, and re-certification work is real engineering — out of reach for a 1–5 clinician practice, the largest underserved segment in ambulatory health IT.
- The compliant default wins the segment. A platform that is FHIR-native, AI-native, and TEFCA-connected on day one is the easy "yes" exactly as these deadlines land.
- The tailwind is measurable. ~50× TEFCA record-exchange growth in a year and a CMS-scored ~$15B prior-auth savings mean the rails are being laid now — not "someday."
Founder talk-track (visible only with ?admin=rev-playground-2026)
- Open: "Five federal mandates between 2026 and 2027 force every EMR to rebuild on FHIR, payer APIs, and national exchange. Incumbents retrofit; we're native — and the small practice can't fund it alone, so it buys us."
- If 'is this real?': "These are finalized CMS/ONC rules and a live national network — TEFCA went 10M→500M records in a year across 11 QHINs and 71,000 sites. The receipts are on CMS.gov and HHS.gov."
- If 'won't this get deregulated?': "Enforcement posture flexes; the standards are locked. Even the deregulatory actions keep FHIR/USCDI as the baseline. The direction is one-way."
- Close: "This is a once-per-decade reset of the EMR. Being native at the moment of the reset is the whole opportunity."
What we actually have to build — the CEO version
In one line: we build REV on the same standards the mandates require — FHIR as our native data model, an open certified API platform, a national-exchange (TEFCA) connection at launch, the prior-auth automation stack, and the payer-API integrations. Compliance becomes a feature we ship once into the core, and every practice inherits it for free. The same work is a multi-year retrofit for incumbents on legacy stacks.
- 1 · Speak FHIR natively. Our medical record is FHIR + USCDI v3 — not a legacy database we export to FHIR. No translation tax, no migration project, ever.
- 2 · Be an open, certified platform. ONC-certified FHIR APIs and SMART/OAuth app launch so patients, providers, and third-party apps connect securely — and we pass federal certification.
- 3 · Plug into the national network. Connect through a TEFCA QHIN at launch, so a 1-doctor practice gets nationwide records on day one — no point-to-point interfaces.
- 4 · Automate prior auth & prescribing. Implement the payer-facing prior-auth and e-prescribing standards so coverage rules surface in the room, PA is one click, and denials are prevented before they happen.
- 5 · Connect to the payer APIs. Consume the new CMS-mandated payer FHIR APIs for real-time eligibility, prior-auth status, and patient history.
Why it's a moat, not a cost: for us this is concentrated, up-front platform engineering — built once into the core and amortized across every practice. For incumbents it's grafting five new standards onto decades of legacy across millions of installed seats. We turn the compliance tax into our product.
Every little thing — the engineering checklist
The concrete build, by mandate. This is what "FHIR-native and certified from day one" actually means in implementation terms.
- A · Data & terminology (USCDI v3 / HTI-1)
- FHIR R4 resource model as the source of truth; US Core 6.1.0 profiles on every resource (Patient, Encounter, Condition, Observation, MedicationRequest, etc.)
- All USCDI v3 data classes & elements — incl. SDOH, sexual orientation/gender identity, encounter info, insurance/coverage
- Terminology services: LOINC (labs), SNOMED CT (problems), RxNorm (meds), ICD-10-CM (dx), CPT/HCPCS, CVX (immun.), plus USCDI value sets & "must-support" handling
- C-CDA R2.1 + Companion Guide R4.1 for document-based exchange; Provenance resources
- B · APIs, apps & ONC certification (HTI-1)
- §170.315(g)(10) Standardized API — FHIR R4 + US Core, SMART App Launch v2, OAuth2/OIDC, granular scopes, dynamic client registration
- Bulk Data / Flat FHIR ($export) for population-level access; single- and multi-patient APIs
- §170.315(b)(10) EHI export; §170.315(b)(11) Decision Support Interventions (DSI) with required source attributes
- SVAP standards-version management, real-world testing, and the Insights Condition reporting (capture 2026 → report 2027)
- Information-blocking compliance; patient consent & privacy / restriction controls
- C · National exchange (TEFCA)
- Connect as a Participant / Sub-participant under a designated QHIN (or via a QHIN partner)
- Support all exchange purposes: treatment, individual access, payment, healthcare operations, public health, gov-benefits determination
- IHE profiles (XCPD patient discovery, XCA query/retrieve, XDR) + the TEFCA facilitated-FHIR roadmap
- Master patient index / identity matching, consent management, audit logging
- D · Prior auth & e-prescribing (HTI-4 + CMS-0057-F)
- Da Vinci CRD (Coverage Requirements Discovery — CDS Hooks at order entry)
- Da Vinci DTR (Documentation Templates & Rules — FHIR Questionnaire + CQL auto-fill from the chart)
- Da Vinci PAS (Prior Auth Support — FHIR ↔ X12 278 bridge)
- Da Vinci PDex + US Drug Formulary; NCPDP SCRIPT e-prescribing + EPCS; NCPDP RTPB v13 (real-time prescription benefit)
- E · Consuming payer APIs (CMS-0057-F)
- Integrate the payer Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization FHIR APIs
- Provider attribution / roster management; bulk-FHIR ingestion; token & consent flows
- F · Security & ops (cross-cutting)
- HIPAA, SOC 2 Type II, OAuth2/OIDC, end-to-end encryption, full audit trail, BAAs
- Annual ONC attestation & real-world testing to keep certification current
Most of this lives once in the platform core. Because we build it native — rather than retrofitting it onto a legacy EMR — each item is a feature we ship, not a remediation project we repeat per release.
The new formats, with examples
A developer/user guide to every format above (FHIR US Core, USCDI v3, C-CDA, SMART, Bulk Data, Da Vinci CRD/DTR/PAS, NCPDP SCRIPT + RTPB, X12 278, TEFCA). Each one has an example you can open and a link to the spec.
Sources & real news
Primary government rules first, then independent reporting. Open any of them — this is all public record.
Primary — government
- ONC/ASTP — HTI-1 Final Rule (USCDI v3, SMART v2, Jan 1 2026)
- Federal Register — HTI-1 rule text
- ONC/ASTP — HTI-4 Final Rule (ePA, eRx, RTPB)
- CMS — CMS-0057-F fact sheet (payer APIs, Jan 1 2027)
- CMS — CMS-0057-F press release (~$15B / 10 yr)
- CMS — Moving Prior Authorization into the 21st Century
- HHS — TEFCA reaches ~500M records exchanged
- Sequoia Project (TEFCA RCE) — Designated QHINs (the 11)
- ONC — History & growth of TEFCA
Independent reporting
- Healthcare Dive — Administration finalizes HTI-4 (prior auth, e-prescribing)
- Fierce Healthcare — HHS locks in ePA + RTPB rule
- AMA — CMS prior-auth final rule explained
- Becker's — TEFCA reaches 500M records
- RISE Health — CMS estimates $15B savings
- McDermott+ — HTI-1 certification requirements
- Drummond Group — What HTI-4 means
All figures are public-record government data; REV's "why we win" reads are our interpretation of how these mandates favor an AI-native, FHIR-native platform serving small independent practices.