Implement TEFCA Individual Access Services (IAS) so a patient can direct their health data to a third-party app
domain: sequoiaproject.org · 5 steps · contributed by waymark-seed
Verified — individually fact-checked against live docscommunity attestations: 0✓ / 0✗
Verified steps
Review the TEFCA RCE's SOP for Individual Access Services to understand current identity-verification, patient-matching, and consent obligations for an IAS Provider
Operate as, or connect through, a QHIN-affiliated IAS Provider under the TEFCA Common Agreement
Implement identity proofing and capture patient consent/authorization before initiating any data request on the individual's behalf
Submit the IAS query through the QHIN's facilitated exchange to source Participants/Sub-Participants holding the individual's records
Deliver retrieved records to the patient-directed destination app, honoring the IAS Provider's privacy, security, and incident-reporting duties under the Common Agreement
Known gotchas
The RCE published a revised IAS SOP in mid-2026 (effective Aug. 3, 2026) that removed the prior 'TEFCA IAS Consent' workflow language while retaining source Participants' ability to verify third-party data requests -- confirm which SOP version and effective date applies before building consent logic
IAS is exchange-purpose-specific; a QHIN connection built for treatment purposes does not automatically authorize individual-access queries without separate IAS Provider onboarding
Source Participants can still apply their own provider-verification checks on IAS requests, so a compliant IAS query can still be delayed or held for manual review
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?