TEFCA Concepts

In order to connect to TEFCA, you need to go through an extensive vetting and onboarding process. Here are some important concepts to understand as you do that.

Principal listings always belong to Covered Entities

The right to retrieve data under the primary TEFCA Treatment Purpose of Use (POU) is limited to Covered Entities (CEs) who are Healthcare Providers. The vetting process confirms your CE and Healthcare Provider so that you can establish a Principal listing. All TEFCA queries must be conducted by or on behalf of a Principal listing belonging to a CE.

Business Associates act as Delegates

Business Associates (BAs) can conduct queries on behalf of CEs that they serve. The CE that owns the Principal listing must instruct their QHIN to add the BA as a Delegate that is allowed to make requests on their behalf, in a process known as "Delegation of Authority". Note: The BA Delegate can be connected to the network via a different QHIN.

If the CE is fulfilling all of its reciprocity requirements through the Principal listing and contributing no additional data via the Delegate listing, it can append the Delegation of Authority with an "Initiator-Only Attestation" confirming that the secondary listing has no additional data to contribute to the networks.

Entrant Entity Vetting for T-TRTMNT

To engage in TEFCA Exchange using T-TRTMNT, we must provide evidence on your behalf that you are a HIPAA Covered Entity Health Care Provider.

This evidence includes the following items, as listed in the current Vetting SOP:

  • Entrant’s name (legal entity name)
  • Entrant’s DBA (if any)
  • Corporate Business Address
  • Entrant’s Website
    • ⚠️ Other QHINs will often review this website to confirm your Treatment use case and look for red flags
  • Site of Care Address (if applicable)
  • Type II National Provider Identifier (NPI) Number
  • A Federal Employer Identification Number (FEIN) (associated requirement)
  • Type of Health Care Provider
  • Evidence that the Entrant is a HIPAA Covered Entity Health Care Provider or
    Government Health Care Entity, including the HIPAA Covered Entity Healthcare
    Provider Evidence (as defined below)
  • A description of the triggers for T-TRTMNT Queries.

Covered Entity Evidence

TEFCA allows two tiers of Covered Entity evidence, and which tiers are accepted depends on the date of submission. Only one tier is required per submission — you don't need to submit both.

Tier 1 Evidence: HIPAA Covered Entity Health Care Provider Evidence

Tier 1 evidence is always accepted and has the shortest objection period

⚠️ Redaction required: the document must have all Protected Health Information (PHI) removed before it's submitted through the vetting mechanism.

  • A document showing that, within the last 90 days, the Entrant (or its Representative Entity) conducted one of these standard electronic health care transactions:
    • X12 270/271 – Health Care Eligibility Benefit Inquiry and Response
    • X12 835 – Health Care Claim Payment/Advice
    • X12 837 – Health Care Claim (professional, institutional, or dental, as applicable)
    • NCPDP Telecommunication Standard Version D.0 – Pharmacy Transactions

Tier 2 Evidence: HIPAA Covered Entity Health Care Provider Evidence

⚠️ Available only for submissions made before January 1, 2027

  • A link to the Entrant's listing in a directory maintained by the Centers for Medicare & Medicaid Services (CMS), such as:
    • Medicare Fee-for-Service Public Provider Enrollment
    • Medicare Inpatient Hospital Look-Up Tool
    • Medicare Physician & Other Practitioner Look-Up Tool
    • Medicare Physician & Other Practitioners by Provider
    • Medicare Part D Prescribers by Provider

Did this page help you?