How best to solve healthcare’s next interoperability challenge
Today’s trust mechanisms for data interchange need to evolve, because they largely were designed for a smaller exchange environment.

Healthcare has spent the better part of two decades focused on moving data.
We've built networks; we've adopted standards; we've invested heavily in interoperability. Today, healthcare organizations exchange billions of records every year through health information networks, clearinghouses, APIs and other digital channels. That progress has been remarkable.
However, one surprisingly basic problem remains largely unsolved. How do you really know who is on the other end of the connection?
The question sounds simple, but as healthcare moves toward more direct, API-based exchange, it is becoming one of the most important trust challenges facing the industry.
Currently, most healthcare exchange relies on intermediaries. Organizations connect through trusted brokers. Those models work, but they often leave participants with only a limited understanding of who is ultimately behind a request and what authority they have to make it. And if transactions need to flow without the benefit of these intermediaries, how can the connection be trusted?
Organizations increasingly need to know not only who is requesting information, but why they are requesting it and whether they are authorized to do so. In other words, healthcare needs more than organizational identity. It needs organizational identity combined with delegated authority. This is true even within networks.
Why existing approaches aren't enough
Healthcare has made genuine progress on individual identity. Credential service providers can verify that a person is who they claim to be, and authentication mechanisms can confirm that the same individual returns on subsequent visits. Those capabilities are critical for patients to control how their data moves with an app of their choosing as is required of EHR companies by federal law and being driven further by CMS in the Health Tech Ecosystem efforts.
But most healthcare exchanges are not carried out by an individual acting entirely on their own behalf. A clinician accessing records is typically acting in the context of a clinical organization. A payer communicating on the network is acting in the context of a particular health plan product. A software application connecting through an API is ultimately operating on behalf of a legal entity, and that entity is an important detail to know. Understanding which organization stands behind a request is not always straightforward.
Healthcare already has identifiers; in fact, it has lots of them. Providers have National Provider Identifiers (NPIs) and organizational NPIs that don’t map directly to organizations but instead to billing groups. Organizations have tax identification numbers. Exchange participants use digital certificates. Networks maintain directories and onboarding processes that associate proprietary identifiers to organization names. However, none of these mechanisms fully solve the organizational identity problem.
Take something as simple as a hospital name. There are dozens of hospitals across the country with similar or identical names. Knowing you're connected to "St. Mary's Hospital" may not tell you very much. Which St. Mary's? Which parent organization owns it? Is it part of a larger health system? Which business unit is involved in the transaction? In many cases, the more important question is not simply who you're dealing with, but where that entity sits within a broader corporate structure and who ultimately owns or controls it. And most exchange participants aren’t aware of anything beyond the name.
Those distinctions matter when trust decisions need to be made. NPIs, tax IDs and digital certificates all serve important purposes, but none were designed to function as a comprehensive organizational trust layer. They identify providers, billing groups or technical endpoints, but they do not consistently communicate organizational relationships, delegated authority, ownership structures or exchange context.
The result is that trust often depends on layers of manual verification, business agreements, onboarding processes and directory maintenance.
The 'spreadsheet in the sky' problem
One analogy I often use is that network directories function as a kind of “spreadsheet in the sky,” where organizational identity and authorization are both managed. The information may initially be accurate, but keeping it current is difficult.
Organizations merge; business units change; new subsidiaries are created; ownership structures evolve. Every change requires updates across multiple systems, networks and directories. And while the healthcare industry has done an admirable job maintaining these trust relationships, the process remains highly manual.
In many cases, the same organizations are being verified repeatedly by different networks using largely the same information. Each network has its own processes, which vary in terms of rigor. As a result, trust can erode in network-to-network contexts.
Conducting each unique onboarding process, verifying each participant and establishing each relationship requires time, resources and ongoing maintenance. The system works, but often through persistence rather than efficiency. As the number of participants and exchange relationships grows, however, that model becomes increasingly difficult to scale and is fundamentally fragile.
Why this matters now
For years, healthcare has worked around these issues through trusted intermediaries and established business relationships. But today's interoperability environment is changing that equation.
FHIR-based APIs, the Trusted Exchange Framework and Common Agreement (TEFCA), consumer-directed exchange and new regulatory requirements are creating a future in which organizations may need to establish new trust relationships far more frequently and at a much larger scale than ever before.
The Centers for Medicare & Medicaid Services (CMS) Interoperability and Prior Authorization Final Rule (CMS-0057-F) is a good example. The rule creates new requirements for payer-to-payer, provider-to-payer and consumer-to-payer data exchange using standardized APIs. The technical mechanism for exchanging data is largely understood. The more difficult question is often determining who is connecting, which organization they represent and what authority they have to request or receive information.
Most organizations can manually establish a handful of trusted relationships – the challenge emerges when that handful becomes hundreds or even thousands. It’s not that healthcare lacks trust; it’s that today's trust mechanisms were largely designed for a smaller, more interconnected exchange environment.
Intermediaries have traditionally handled one class of data. The query networks handle data almost exclusively for treatment purposes. Clearinghouses are focused almost exclusively on the administrative transaction set. As exchange partners become more diverse and an explicit requirement to operate without an intermediary is established, the "Who’s who" question becomes much more difficult to answer.
The missing piece: Delegated authority
When people think about identity, they often focus on answering a single question: “Who are you?”
Increasingly, healthcare must answer a second question as well: “Why are you authorized to act?” This will depend upon that context previously discussed.
At DirectTrust, we oversee a network that has solved part of this problem for push messaging and referrals. Senders can know reliably who they are sending to, and receivers can know who is sending, but it is still difficult to disambiguate organizations in our directory using only a name in a search. Even looking at the digital certificate, the organizational name may not be unique enough or recognizable enough. In any case, today we don’t support delegated authority except with regard to participation in the trust community.
That delegated authority distinction becomes particularly important in modern digital exchange. A request may originate from a person, an application or an automated process acting on behalf of an organization. It thus becomes critical to understand not only who is making a request, but what authority has been delegated to them. When a patient uses a health app, they are operating on their own behalf, but the health app actually is making the connection. If the patient’s family member or non-family caregiver is in the app, how does the data holder know the patient has authorized this?
Delegated authority sits at the heart of many emerging trust challenges. Organizations need confidence that the entity requesting information is who it claims to be. They also need confidence that the individual or entity has the appropriate authority to participate in the transaction. Without that second layer, identity alone may not be enough.
Looking ahead
Healthcare has made substantial progress solving how data moves. The next challenge is establishing confidence in who is sending it, who is receiving it and what authority they possess to participate in the exchange. This extends beyond technology, touching governance, trust, authorization and accountability across the healthcare ecosystem.
The good news is that healthcare may not need to invent an entirely new solution. Existing approaches developed outside healthcare are already demonstrating how organizational identity and delegated authority can be established at scale.
In my next article, I'll explore why the Legal Entity Identifier (LEI) and Verifiable Legal Entity Identifier (vLEI) model may provide a practical path forward.
Scott Stuewe is president and CEO of DirectTrust, driving strategy, visibility and growth of DirectTrust’s focus areas of community, accreditation, standards development and trust services.
