
Healthcare Business Analyst
Healthcare Business Analyst for Interoperability: FHIR, USCDI, TEFCA, and Information Blocking
- FHIR
- TEFCA
- USCDI
- Information blocking
- CMS-0057
- HL7

The 21st Century Cures Act, ONC information-blocking rules, CMS Interoperability and Prior Authorization (CMS-0057), USCDI, FHIR R4, US Core, and TEFCA are regulated processes, not “IT projects.” A Healthcare Business Analyst who cannot say patient access versus provider access versus payer-to-payer is not ready. We pioneered that interview. We staff the people who write the use case, the consent overlay, and the UAT that proves the API is not a PDF behind a portal.
The process library we keep
- Patient access API and the identity proofing nobody budgeted
- Provider directory and the attribution fight
- Payer-to-payer exchange and 42 CFR Part 2 segmentation
- Electronic prior authorization as a FHIR workflow, not a portal
- Information-blocking exceptions written so legal and IT share one page
- USCDI versioning — not “the CCD” as a lifestyle

- 01
Name the use case
Patient, provider, payer. One sentence. One regulation.
- 02
Consent overlay
Part 2, minimum necessary, app attestation.
- 03
CapabilityStatement
The BA reads it. The developer does not hide it.
- 04
UAT that is not a PDF
The API returns USCDI. The portal is not the proof.
- 05
Exception file
If we block, we say why, in language OCR will read.
We staff Healthcare BAs next to FHIR developers and Epic/Cerner analysts. We do not staff “interop project managers” who cannot read a CapabilityStatement. Future: the same BA cell sitting with our Gen AI practice so a copilot never sees more than USCDI and the BAA allow.
Interop BA time that pays
A CapabilityStatement is a requirement
Patient access, provider access, payer-to-payer — three use cases, three identity and consent problems. USCDI is versioned. TEFCA is a QHIN conversation. Information-blocking exceptions are written for OCR, not for a Slack thread. The API is the proof; a PDF behind a portal is not. We staff BAs who read CapabilityStatements and sit with legal on Part 2 segmentation. Identity proofing is in the budget or the epic is a lie.
Future: the same BA cell with our Gen AI practice so a copilot never sees more than USCDI and the BAA allow. TEFCA and 0057 have dates. The reqs already do.
