What is Individual Access Services (IAS) under TEFCA?
TEFCA gives health data a single nationwide on-ramp. Individual Access Services is the lane built for the patient, and it is how patient-mediated access scales.
A patient's history is scattered across dozens of systems that were never built to talk to each other. For years, moving a record between any two of them meant a point-to-point integration, a data-sharing agreement, and a legal review, one pair at a time.
TEFCA is the framework meant to end that. And inside it is a lane built specifically for the person whose data it is.
What TEFCA is, quickly
TEFCA (the Trusted Exchange Framework and Common Agreement) is the federal on-ramp for nationwide health information exchange. Networks that meet the bar become QHINs (Qualified Health Information Networks). Connect through one, and you can exchange with the rest under a single common agreement instead of negotiating a contract with every network on your own.
TEFCA permits exchange only for a defined set of reasons, called exchange purposes. Most of them (treatment, payment, health care operations) are about organizations sharing data with each other. One is different.
Individual Access Services is the patient's lane
Individual Access Services (IAS) is the exchange purpose built for the individual. Under IAS, a person can access, inspect, and obtain a copy of their own health information through the network, and direct it wherever they want.
Because the request comes from a person and not an institution, the bar for proving who they are is high. IAS requires identity proofing to NIST IAL2 and authentication to AAL2, plus real transparency to the individual about what happens with their data.
Where IAS and the right of access meet
IAS is what the patient right of access looks like at network scale. The right of access says the record belongs to the patient. IAS is one of the paths that record can actually travel, nationwide, without a contract per source.
Patient-mediated access is built to clear that bar. The patient verifies their identity to IAL2 through a certified identity provider, authorizes the request once, and Hubble gathers their record across the systems they have touched and returns it in one normalized shape. Identity proofing, consent, and transparency are handled, not bolted on afterward.
Who it's for
If your product depends on a complete record and you want the individual-access path built to the standard, IAS is what you build to. You can test it yourself on test data.
Frequently asked questions
What is Individual Access Services (IAS) under TEFCA?
Individual Access Services (IAS) is the TEFCA exchange purpose built for the individual. It lets a person access, inspect, and obtain a copy of their own health information through the nationwide network, and direct it where they choose. It is the network-scale expression of the HIPAA right of access.
What is TEFCA?
TEFCA (the Trusted Exchange Framework and Common Agreement) is the federal framework for nationwide health information exchange. Networks that meet the bar become QHINs (Qualified Health Information Networks), and connecting through one lets you exchange with the rest under a single common agreement instead of one-off contracts.
What identity requirements does IAS have?
Because an IAS request comes from a person rather than an institution, the identity bar is high. It requires identity proofing to NIST IAL2 and authentication to AAL2, along with transparency to the individual about how their data is used.
How does Hubble support individual access under TEFCA?
Hubble's patient-mediated access is built to the individual-access bar. The patient verifies their identity to IAL2 through a certified identity provider, authorizes the request, and Hubble gathers their record across the systems they have touched and returns it in one normalized shape.