Fri, Sep 18
HealthMatics
Trending
AI in Healthcare/Hospital M&A/Healthcare Cybersecurity/Digital Health/Revenue Cycle/Health Policy/AI in Healthcare/Hospital M&A/Healthcare Cybersecurity/Digital Health/Revenue Cycle/Health Policy
Health IT

TEFCA query volume doubles as federal agencies and AI agents pile in

The national exchange network passed one billion records in June 2026, roughly three months after 500 million, and the fastest-growing requestors are not the treating clinicians CIOs budgeted for.

The HealthMatics Desk
7 min read
System with various wires managing access to centralized resource of server in data center
Photo: Brett Sayles

TEFCA query volume is now the fastest-moving number in health IT, and almost nobody budgeted for it. HHS announced in late June 2026 that the network had passed one billion health records exchanged, roughly three months after ONC put the figure at nearly 500 million in March. The composition of that traffic matters more than the milestone: the heaviest new requestors include federal agencies, individuals exercising access rights, and increasingly autonomous retrieval agents. Health systems joined as participants. They are now operating as responders on a national utility they never staffed.

The volume curve moved faster than the planning cycle

Most health systems signed TEFCA participation agreements as a defensive move. It was an information-blocking hedge, a box to check with the board, and the operational model in the business case assumed treatment-purpose queries flowing between clinicians at a predictable clip. The finance assumption was equally simple: query volume would track something like referral patterns and patient migration in the service area.

That assumption is now stale. Doubling cumulative volume in a single quarter is not the shape of provider-to-provider treatment exchange maturing on schedule. It is the shape of new requestor classes coming online at scale. Becker's ran a TEFCA update on July 1 and other trade outlets followed within a day, which is usually the signal that a story has moved from policy watchers to operators.

The uncomfortable structural fact underneath the growth: responder-side obligations scale with other people's demand, not your own. A health system that sends few queries can still field enormous inbound volume. Cost, latency, identity-matching accuracy and audit retention all land internally, with no offsetting revenue line.

Responder obligations scale with other people's demand, not your own volume. The cost lands on the health system with no offsetting revenue.

Federal requestors changed the traffic mix

The Social Security Administration joined the TEFCA network in February 2026 to speed disability benefit determinations. That single change introduced a non-clinical, high-volume, deadline-driven requestor into an ecosystem designed around clinical care coordination. Disability adjudication does not resemble a specialist pulling a prior imaging report. It is bulk, systematic and indifferent to your peak hours.

CMS has been pushing in the same direction. Its Health Tech Ecosystem initiative, launched in August 2025, marked its first year with eight new pledge categories, expanding the set of participants and use cases pointed at shared infrastructure. Add individual access requests, which grow with every consumer app that offers to assemble a longitudinal record, and the treatment-purpose share of the pie shrinks even as the absolute number keeps climbing.

On the vendor side, Epic has signaled that Open@Epic will return in 2026 as data sharing accelerates. More published surface area means more integrators, and more integrators means more query origination points aimed at the same responder infrastructure.

Agentic AI turns a query into a session

The hardest operational question is one most log architectures cannot currently answer: can you tell a human requestor from an autonomous agent? A clinician pulling records generates a handful of queries in a defined episode. An AI agent assembling context for a summarization, prior authorization or care gap workflow may fan out across dozens of requests, retry on partial matches, and repeat the pattern for every patient in a panel.

Healthcare IT News captured the broader tension in an August 1, 2026 piece noting that AI ambitions are outpacing healthcare's infrastructure. TEFCA is where that gap becomes concrete. If purpose-of-use codes and participant identifiers do not distinguish agentic retrieval from human-initiated lookup, health systems lose the ability to do capacity planning, rate limiting or meaningful abuse detection.

This is not an argument for blocking. It is an argument for instrumentation. You cannot govern what you cannot see in your own audit trail, and reconstructing intent after a security review has started is a bad time to discover the gap.

HTI-5 shifts assurance work back onto internal teams

Running in the opposite direction from the volume growth is the deregulatory track. ONC's HTI-5 proposed rule, published in the Federal Register on December 29, 2025 and framed around deregulatory action, would relax portions of the health IT certification criteria. Healthcare IT News reported that ASTP/ONC is seeking that relaxation directly. The AHA filed comments on the interoperability proposed rule in February 2026.

For CIOs, the practical translation is straightforward. Certification is a form of outsourced assurance. When a criterion is relaxed or removed, the testing, validation and documentation that a vendor previously absorbed does not disappear. It migrates to whoever still needs the guarantee, which is the health system holding the patient relationship and the breach liability.

So the two trends compound rather than offset. Inbound query volume is rising, and the baseline conformance floor beneath the software handling that volume may be lowered at the same time. Any Q4 technology plan that treats these as separate agenda items is understating the combined exposure.

What belongs on the Q4 board agenda

Start with ownership. TEFCA response performance is currently orphaned in many organizations, sitting between the integration team, the HIM department and the privacy office, with no named executive accountable for uptime, response latency or match rates. Assign it the way you would assign any other externally visible service commitment.

Then get the unit economics. Ask for the per-query cost trend over the last four quarters, broken out by requestor class where the data allows. If the answer is that nobody tracks cost per query, that is the finding. The same exercise should surface how much of the growth is treatment purpose versus individual access versus federal and other non-clinical requestors.

Finally, test the logs. Pick a week of inbound traffic and ask whether the audit record can separate human-initiated queries from automated retrieval, and whether identity-matching failures are being counted rather than silently retried. Those three answers, ownership, cost trend and log fidelity, are enough to tell a board whether the organization is participating in national exchange or simply absorbing it.