The Standard

The Official Blog of Health Level Seven® International

visit HL7.org 

Beyond the Consent Form: Building Trust for Healthcare Data Exchange

[fa icon="calendar"] Sep 2, 2026, 4:14:05 PM / by FAST Project Management Team


FAST logo cropped

Our recent HL7 FAST webinar, “Building the Consent Trust Stack: Scaling Privacy, Patient Choice and Data Exchange Across Healthcare,” reinforced an important point for our industry:

Computable consent is more than converting a paper form into structured digital data; it provides the infrastructure for trusted, policy-aware data exchange.

As healthcare becomes increasingly connected across providers, payers, HIEs, national networks, state ecosystems, and consumer applications, we face a fundamental challenge: How do we enable information to move while ensuring that all data holders understand and consistently apply the patient’s choices, applicable privacy laws, and other conditions governing the use and disclosure of that information?

That challenge is becoming more urgent as federal and state privacy requirements continue to intersect with sensitive information such as behavioral health, substance use disorder, reproductive health, and other categories of data. At the same time, patients increasingly expect greater control over what is shared, with whom, for what purpose, and for how long. Manual workflows and scanned consent forms were never designed to support that environment. Automation is essential to sharing large volumes of data with the right, authorized parties: providers, payers, caregivers, researchers, and others.

Consent Must Become Operational

FAST Consent Co-Lead Mohammad Jafari walked through the architecture required to move from capturing a patient's preference to enforcing that preference within a data-access workflow.

A scalable environment must discover applicable patient consent, validate whether it remains active, determine whether patient consent is required for the transaction, request patient consent when it does not exist, evaluate the resulting permissions in the context of applicable privacy rules and other policies, and ultimately connect those decisions to authorization and enforcement.

This is where the distinction between simply having consent and having computable consent becomes critical.

The FAST Scalable Consent Management approach defines the exchange patterns needed to manage the consent lifecycle across systems; it does not define or prescribe the content of the consent itself. These patterns support requesting, reviewing, and recording a patient’s consent decision—whether the underlying consent content is computable or non-computable—as well as revocation, delegation, provenance, auditing, and communication of consent-status changes across repositories throughout the ecosystem.

One particularly important capability now being finalized is the use of FHIR Subscriptions for consent events. Rather than organizations repeatedly checking whether a consent has changed, systems can be notified when consent is granted, revoked, replaced, delegated, or expires. This allows EHRs, HIEs, payers, networks, and applications to remain synchronized with the patient's current decision, ensuring the patient’s consent preferences are consistent throughout their care journey. FAST plans to continue testing this capability at the September HL7 Connectathon.

Standards Alone Cannot Solve A Policy Problem

Mel Soliz and Kevin Day, representing The Sequoia Project's Privacy and Consent Workgroup, reinforced another critical piece of the puzzle: computable consent exists at the intersection of privacy laws, policy, technology and operations.

States have legitimate authority to establish their own privacy protections. The interoperability challenge arises when those protections—and the patient consent decisions governed by them—cannot be represented consistently in a computable format that systems can interpret and apply.

The Sequoia Project's work is helping address that disconnect by developing guidance that allows states to preserve their policy autonomy while aligning sensitive-data requirements with nationally reusable technical approaches.

Kevin also emphasized the need to move from theory to implementation through specific workflows, including operationalizing consent for 42 CFR Part 2 information across multiple organizations and an HIE. Such real-world scenarios are essential because consent must work across people, workflows, policies, and technology—not just within an API specification.

Another emerging issue is equally important: identity alone is not enough.

Knowing who someone is does not automatically tell a system what they are legally authorized to do on another person's behalf. Parents, guardians, personal representatives, caregivers and others may have very different rights. Scalable digital healthcare will therefore require us to communicate both identity and authority consistently across networks.

Sensitive Data Requires More Than A Consent Flag

Hans Buitendijk expanded the conversation into the broader standards environment and the Cross Work Group (CGP) efforts on sensitive data and how to express privacy and patient consent in a fully computable format using FHIR resources.

A data holder ultimately must evaluate multiple things at once:

    • Who is requesting the information?
    • What information is being requested?
    • What jurisdictional privacy rules apply?
    • What has the patient authorized?
    • Does information need to be withheld, filtered, or tagged?

FAST Scalable Consent Management enables requesting and sharing of the patient consent, while the HL7 CGP project and Shift initiatives focus on a common format and approach to express the actual privacy and patient consent rules in terms of vocabulary (Shift and HL7 Security Work Group), data set in scope of these rules (Shift), and expressing these rules for the data in its scope (HL7 CGP Work Group). The objective is not merely to record that a patient has consent documents, but to express these patient consents and jurisdictional privacy rules with the right granularity in a computable format, enabling all patients’ data holders to share data consistently and correctly in accordance with the applicable rules.

Patient Choice and Patient Safety Must Advance Together

Dr. Hannah Galvin and Shift brought the conversation back to the patient and clinical consequences of getting this wrong.

One of the most compelling observations from the webinar was that interoperability works very well today for patients willing to share everything. It works far less effectively for someone who has legitimate reasons to share some, but not all, of their information or when jurisdictions restrict sharing of certain data.

When patients cannot exercise meaningful choice, some may choose not to share at all, withhold information from clinicians, or even avoid care. But implementing granular controls also creates difficult clinical questions: What happens when withheld medication information could create a drug interaction? Should the recipient know information was redacted? What happens in an emergency? How should decision support behave?

Shift is tackling those questions by convening multidisciplinary experts to develop clinically informed use cases, establish consensus-driven implementation guidance through Delphi processes, build and maintain sensitive-data value sets, and engineer a proof-of-concept sandbox using synthetic data so organizations can test different granular sharing and consent scenarios before deploying in their own production environments.

Their work spans behavioral health, substance use disorder, reproductive health, social needs, intimate partner violence, maternal and infant health, genetics, and other situations where privacy, safety, and patient autonomy can intersect, across a number of different interoperability exchange transactions.

The Larger Lesson: Patient Consent Cannot Operate Alone

Perhaps the most important takeaway from today's discussion was the level of collaboration now developing across these efforts.

HL7 workgroups are advancing the standards for representing and protecting the information.

HL7 FAST is creating scalable consent exchange patterns and implementation guidance.

The Sequoia Project is bringing together the legal, governance, policy, and cross-network operational perspectives.

Shift is grounding the work in patient-centered clinical use cases, sensitive-data definitions in scope of privacy rules and certain patient consent and implementation testing.

Dr. Galvin summarized this convergence particularly well when describing how the organizations are increasingly working together across standards, governance, policy, operational alignment and scalable consent exchange.

Within FAST, Consent is part of a larger trust architecture.

Identity tells us who the individual or organization is.
Security establishes how trusted parties connect and authorize transactions.
The directory helps establish who the participants are and what they are.
Consent federates the patient's choices.
Testing demonstrates that these capabilities work together across organizations and networks.

That is the Consent Trust Stack.

The opportunity ahead is not to build another isolated consent solution. It is to establish a reusable trust infrastructure that enables patient choice, policy, and data exchange to travel together across the healthcare ecosystem.

That is how we move from digitizing consent forms to making consent operational at scale.

Thank you to Mohammad Jafari, Kevin Day, Mel Soliz, Hans Buitendijk, and Dr. Hannah Galvin, and to the FAST, HL7, Sequoia Project, and Shift communities for continuing to move this work from standards and policy into implementation.

The next phase is implementation, testing and adoption—and we need providers, payers, HIEs, states, networks, technology vendors and patient advocates at the table.

Learn more about the upcoming HL7 Connectathon: September 19-20, 2026 in Rockville, MD and join us for additional conversation and education.

Resources:

Join the FAST community via the HL7 FAST Confluence space,  and follow FAST on LinkedIn.

Topics: FHIR, interoperability, FHIR Accelerator, FAST, FHIR Implementation Guides, FHIR Community, FAST Scalable Consent Management, Data Privacy, Patient Choice

FAST Project Management Team

Written by FAST Project Management Team

The FHIR at Scale Taskforce (FAST) identifies HL7 Fast Healthcare Interoperability Resources (FHIR) scalability gaps, defines solutions to address current barriers, and identifies needed infrastructure for scalable FHIR solutions.

Lists by Topic

see all

Posts by Topic

see all