TEFCA — Trusted Exchange Framework and Common Agreement
The Trusted Exchange Framework and Common Agreement (TEFCA), developed by the Office of the National Coordinator for Health IT (ONC) under the 21st Century Cures Act, establishes a universal governance framework for nationwide health information exchange. TEFCA enables interoperable exchange of electronic health information among Qualified Health Information Networks (QHINs). Version 2.0 effective 2024 with operational exchanges beginning.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Compliance
| Code | Title |
|---|---|
| TEFCA-COMP-01 | Annual Compliance Attestation and Reporting |
| TEFCA-COMP-02 | Information Blocking Compliance |
Exchange Purposes
| Code | Title |
|---|---|
| TEFCA-EP-GOV | Exchange Purpose Government Benefits Determination |
| TEFCA-EP-HCO | Exchange Purpose Health Care Operations |
| TEFCA-EP-IA | Exchange Purpose Individual Access Services |
| TEFCA-EP-PH | Exchange Purpose Public Health |
| TEFCA-EP-PMT | Exchange Purpose Payment |
| TEFCA-EP-TR | Exchange Purpose Treatment |
Exchange Purposes and Use
| Code | Title |
|---|---|
| CA-5 | Plan of Action and Milestones |
| CA-6 | Authorization |
| CA-7 | Continuous Monitoring |
| CA-8 | Penetration Testing |
| CA-9 | Internal System Connections |
Governance
| Code | Title |
|---|---|
| TEFCA-GOV-01 | Governance and Cooperation Among QHINs |
Interoperability
| Code | Title |
|---|---|
| TEFCA-INT-FHIR | FHIR Implementation for TEFCA Exchange |
| TEFCA-INT-IHE | IHE Profile Implementation for TEFCA Exchange |
Operations
| Code | Title |
|---|---|
| TEFCA-OP-01 | Service Level Agreements and Availability |
| TEFCA-OP-02 | QHIN Directory and Endpoint Management |
Participant Management
| Code | Title |
|---|---|
| TEFCA-PART-01 | Participant and Subparticipant Onboarding |
| TEFCA-PART-02 | Participant Offboarding and Suspension |
Privacy and Security Requirements
| Code | Title |
|---|---|
| CA-10 | Selects and Develops Control Activities |
| CA-11 | Selects and Develops General Controls over Technology |
| CA-12 | Deploys Through Policies and Procedures |
| CA-13 | Minimum Necessary Standard |
QHIN Designation
| Code | Title |
|---|---|
| TEFCA-QHIN-01 | Qualified Health Information Network Designation Criteria |
| TEFCA-QHIN-02 | QHIN Application and Designation Process |
QHIN Designation and Obligations
| Code | Title |
|---|---|
| CA-1 | Policy and Procedures |
| CA-2 | Control Assessments |
| CA-3 | Information Exchange |
| CA-4 | QHIN Technical Compliance |
Security and Privacy
| Code | Title |
|---|---|
| TEFCA-SEC-01 | QHIN Security Requirements |
| TEFCA-SEC-02 | Authentication and Mutual TLS |
| TEFCA-SEC-03 | Privacy and Notice Obligations |
Technical Framework (QTF)
| Code | Title |
|---|---|
| QTF-1 | Patient Identity Resolution |
| QTF-2 | Message Exchange Standards |
| QTF-3 | Authentication and Authorisation |
| QTF-4 | Performance and Availability |
| QTF-5 | Audit and Logging |
Trusted Exchange Framework Principles
| Code | Title |
|---|---|
| TEF-1 | Standardisation |
| TEF-2 | Openness and Transparency |
| TEF-3 | Cooperation and Non-Discrimination |
| TEF-4 | Privacy, Security, and Safety |
| TEF-5 | Access and Equity |
Your Compliance Coverage
If you comply with TEFCA — Trusted Exchange Framework and Common Agreement, you already cover:
Azure Security Benchmark
21%
9 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
21%
9 controls mapped
Compare →EU Maritime Single Window Environment Regulation (EU) 2019/1239
19%
8 controls mapped
Compare →+ 639 more: 6th Anti-Money Laundering Directive (AMLD6, Directive (EU) 2018/1673) (19%), ILO Nursing Personnel Convention C149 (1977) (19%)
See all 642 mapped frameworks ↓Maps to 642 other frameworks
Frequently Asked Questions
What is TEFCA — Trusted Exchange Framework and Common Agreement?
TEFCA — Trusted Exchange Framework and Common Agreement is a compliance framework from United States (ONC) with 13 domains and 43 controls. The Trusted Exchange Framework and Common Agreement (TEFCA), developed by the Office of the National Coordinator for Health IT (ONC) under the 21st Century Cures Act, establishes a universal governance framework for nationwide health information exchange. TEFCA enables interoperable exchange of electronic health information among Qualified Health Information Networks (QHINs). Version 2.0 effective 2024 with operational exchanges beginning. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does TEFCA — Trusted Exchange Framework and Common Agreement have?
TEFCA — Trusted Exchange Framework and Common Agreement has 43 controls organised across 13 domains. The largest domains are Exchange Purposes (6 controls), Exchange Purposes and Use (5 controls), Technical Framework (QTF) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does TEFCA — Trusted Exchange Framework and Common Agreement map to?
TEFCA — Trusted Exchange Framework and Common Agreement maps to 642 other compliance frameworks. The top mapping partners are Azure Security Benchmark (21% coverage), TISAX — Trusted Information Security Assessment Exchange (21% coverage), EU Maritime Single Window Environment Regulation (EU) 2019/1239 (19% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with TEFCA — Trusted Exchange Framework and Common Agreement compliance?
Start your TEFCA — Trusted Exchange Framework and Common Agreement compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about TEFCA — Trusted Exchange Framework and Common Agreement requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required