Why interoperability’s next chapter will be defined by trust
CMS-0057-F will reveal whether healthcare has built the governance, accountability and operational foundations to support connected care.

For years, healthcare's interoperability conversation has centered on a single question: Can our systems exchange data? That question is finally changing.
As the January 1, 2027, deadline for CMS-0057-F approaches, healthcare organizations are racing to implement FHIR APIs, modernize prior authorization workflows, and improve data exchange between payers and providers. Those technical milestones matter, but they are only part of the story.
Unlike previous interoperability initiatives, CMS-0057-F arrives at a moment when healthcare's digital ecosystem is far more complex. Data now moves across providers, payers, digital health applications, consumer-facing tools and, increasingly, AI-enabled workflows. At the same time, cybersecurity incidents, legal disputes surrounding health data access and growing public scrutiny have elevated trust from a technical concern to a strategic one.
The more important question is no longer whether healthcare can exchange data. It is whether healthcare has built data-sharing ecosystems that organizations, clinicians, patients and partners can trust.
Interoperability has always been about more than moving information from one system to another. Its real purpose has been ensuring the right information reaches the right people, for the right purpose, at the right time. As data sharing expands across thousands of organizations, those expectations become significantly more difficult to meet.
Healthcare is entering a new phase where success depends not only on connectivity, but also on confidence.
APIs create access; trust requires governance
FHIR has transformed healthcare interoperability by making data exchange faster, more standardized and more accessible. CMS-0057-F accelerates that progress by requiring APIs must support patient access, provider access, payer-to-payer exchange, provider directories and electronic prior authorization.
While those requirements establish how information moves, they do not answer equally important operational questions, particularly who is authorized to access health data? How are permissions managed as organizations, partners and applications evolve? How is data usage monitored and audited? Who is accountable when information moves across multiple organizations?
Answering those questions requires capabilities that sit beneath every API. Identity management determines whether organizations know who, or what, is requesting data. Authorization ensures information is shared only with appropriate users and applications. Auditability provides visibility into how data is accessed and used. Governance establishes the policies that guide those decisions consistently across partners and care settings.
None of these capabilities are new. What's changing is the scale at which they must operate. As CMS-0057-F expands data sharing across healthcare, organizations can no longer rely on manual oversight or isolated governance processes. Trust must become operational.
Trust lives beneath the API
Much of the industry's attention remains focused on implementing APIs. The greater challenge lies in the infrastructure supporting them. Trusted interoperability depends on capabilities that patients rarely see but organizations rely on every day – identity resolution, authorization, governance, observability, security and operational ownership.
Historically, interoperability projects have been measured by technical milestones. Was the interface deployed? Did the API connect? Did the data arrive successfully? Those metrics remain important, but they no longer tell the whole story.
As healthcare becomes increasingly interconnected, organizations will also be measured by the confidence others place in their data-sharing practices. Can partners understand who has access to information? Can patients trust how their information is being used? Can executives quickly demonstrate accountability when questions arise?
The organizations that answer those questions confidently won't necessarily have the most sophisticated APIs, but they will have the strongest governance frameworks supporting them.
Cybersecurity incidents have demonstrated how dependent healthcare has become on shared digital infrastructure. Ongoing legal disputes surrounding health data access continue to raise important questions about transparency, stewardship and accountability.
Although these situations differ significantly, they point toward the same conclusion -- interoperability succeeds only when participants trust the ecosystem supporting it.
AI raises the stakes even higher
The industry's investment in AI makes this conversation even more urgent.
AI applications depend on timely, accurate and trustworthy information flowing across clinical, operational and financial systems. Poor governance doesn't simply affect interoperability; it affects the quality of AI-generated recommendations, automated workflows and clinical decision support.
AI also changes the nature of interoperability itself. For years, healthcare systems primarily exchanged data when clinicians, administrators or patients requested it. Increasingly, software will participate in those exchanges as well, summarizing records, supporting prior authorization, coordinating workflows, identifying patients for intervention, and assisting operational decision-making.
That evolution doesn't lessen the importance of interoperability. It amplifies it.
Every AI recommendation depends on trusted data. Every automated workflow depends on consistent governance. Every intelligent application depends on organizations having confidence in the infrastructure beneath it. In that sense, CMS-0057-F is doing more than preparing healthcare for better interoperability. It is helping establish the conditions required for responsible AI adoption at scale.
The organizations that realize the greatest value from AI are unlikely to be those with the largest number of pilots. They will be the ones that have already invested in trusted data infrastructure, clear governance models and operational accountability.
The executive conversation must change
CMS-0057-F should not be viewed as the finish line for interoperability. It is a milestone in healthcare's broader transition toward connected, data-driven care.
Executive leaders should certainly ask whether their organizations will meet the technical requirements of the rule. They should also ask more fundamental questions. Does our governance model scale as data sharing expands? Can we demonstrate how data is accessed, shared and protected? Can we establish accountability across an increasingly connected ecosystem? Are we building interoperability that organizations will trust, not only today, but as AI, automation and new models of care continue to evolve?
Those questions will define interoperability long after January 1 has passed.
Healthcare has spent the past two decades proving that connected care is technically possible. The next decade will determine whether healthcare can make connected care consistently trustworthy. That (not API implementation alone) will ultimately define the success of interoperability's next chapter.
Sagnik Bhattacharya is CEO of Rhapsody, a technology company specalizing in agent-ready interoperability, helping healthcare organizations build the data and integration infrastructure needed to power AI and connected care.