Federal Health IT Office to Refer TEFCA Violators to Justice Department
WASHINGTON — The Office of the National Coordinator for Health Information Technology (ONC) announced in late June that it is escalating its enforcement of the Trusted Exchange Framework and Common Agreement (TEFCA), signaling it will now refer non-compliant participants and other “bad actors” to the U.S. Department of Justice for potential investigation and prosecution.
This policy shift marks a significant hardening of the federal government's stance on health data interoperability and represents a new level of legal risk for thousands of healthcare providers, health information networks, and technology vendors connected to the national data-sharing network. The announcement coincided with the ONC celebrating a milestone of over one billion health records being exchanged through the network, framing the new enforcement measures as a necessary step to ensure the integrity and security of the maturing ecosystem.
TEFCA was established under the 21st Century Cures Act to create a universal policy and technical floor for health information exchange across the country. It aims to break down data silos between disparate electronic health record (EHR) systems, allowing patient information to flow more freely and securely between providers, payers, and public health agencies. The framework is operationalized through a network of designated Qualified Health Information Networks (QHINs) that agree to abide by a common set of rules.
The ONC has been designated as the oversight body for the framework, responsible for ensuring QHINs and their participants adhere to the terms of the Common Agreement. Until now, compliance efforts were largely focused on cooperation and corrective action plans. The introduction of DOJ referrals elevates the consequences of non-compliance from administrative penalties to the possibility of facing federal civil or even criminal charges.
This change directly affects not only the dozen or so designated QHINs but also the thousands of smaller entities that connect through them, including hospitals, physician practices, laboratories, pharmacies, and software developers. Any organization participating in the TEFCA network is now subject to this heightened scrutiny. According to the ONC, the referrals will be targeted at entities engaged in serious misconduct, such as blocking information, committing fraud, or demonstrating a willful disregard for TEFCA's rules of engagement.
A referral to the Department of Justice could trigger investigations under a variety of federal statutes. For example, if information blocking leads to fraudulent billing, it could fall under the False Claims Act, which carries steep financial penalties. Egregious privacy or security violations could also invite scrutiny under the Health Insurance Portability and Accountability Act (HIPAA), but the DOJ’s involvement opens the door to broader enforcement powers and more severe sanctions than the ONC can levy on its own.
The move is seen by industry analysts as a signal that the initial adoption phase of TEFCA is concluding and the era of strict enforcement is beginning. As the volume of sensitive patient data flowing through the network grows, federal regulators are making it clear that the framework is not merely a set of voluntary guidelines but a regulated environment with serious consequences for non-adherence. This mirrors the evolution of other data-centric regulatory regimes, where oversight and penalties increase as the systems become more critical to the industry's function.
For small and mid-sized businesses in the healthcare sector, this new enforcement posture necessitates an immediate review of their data exchange practices and compliance protocols. It is no longer sufficient to simply be connected to a QHIN; organizations must be able to actively demonstrate and document their adherence to the Common Agreement’s requirements regarding data security, privacy, and permissible uses of information. This requires a shift from viewing interoperability as a technical IT project to treating it as a core component of corporate governance and risk management.
In our experience, many mid-sized healthcare providers and technology firms treat interoperability compliance as a purely technical checklist, overlooking the significant financial and legal risks involved. This ONC announcement is a clear warning that the grace period is over. A DOJ referral can trigger costly investigations that disrupt operations, drain resources, and inflict lasting reputational damage, which in turn can severely impact a company's ability to raise capital or secure strategic partnerships. This is precisely where proactive financial risk management becomes critical. Businesses must move beyond the IT department to quantify the potential financial impact of non-compliance and implement robust internal controls and audit processes to mitigate that exposure before a federal review is ever initiated. For companies looking to assess and manage the financial risks associated with these evolving data-sharing mandates, C&S Finance Group LLC provides essential guidance at csfinancegroup.com.
The healthcare industry will now be closely watching for the first public actions resulting from this new policy. The nature and frequency of any DOJ referrals will set the tone for TEFCA enforcement going forward and will likely spur a new wave of investment in compliance infrastructure among participants seeking to avoid federal scrutiny.