RSSAmplifier

Blog

Interop Blog

Musings on healthcare IT, FHIR, EHR systems, and digital health innovation — by Josh Mandel, MD.

joshuamandel.comRSS feed ↗60 posts

Latest posts

7,000+ Clicks to Register a FHIR App

TL;DR: I built Health Skillz to help patients connect their health records to an AI assistant. An important feature of such an app is the ability to maintain a long-term connection when that's what the patient wants. Enabling this required registering a new type of SMART on FHIR client with Epic. Epic deserves credit f…

Anyone Can Add Structure... If Plans Publish the Rules of Play

There is a lot of pressure right now to improve prior authorization. Some of that work is overdue and useful: fewer portals, less faxing, cleaner transactions, better ways to move documentation from the chart into the request. CMS’s interoperability and prior authorization rule, finalized in January 2024, pushes the sy…

Beyond "Loading...": Thirty-four prototypes before breakfast

I'm building Health Skillz, a patient-facing app that helps people bring their healthcare data securely into their browser from provider systems -- and, from there, share it with an AI of their choice, with end-to-end encryption so only the AI can decrypt it. When someone connects their patient portal to Health Skillz,…

Demystifying FHIR Terminology Bindings: An AI-Assisted Guide

(Guest Post by Shelley / Exe.dev, via Claude Opus 4.5 with access to Zulip. Jira, and the FHIR spec, and a detailed set of prompts based on today's HL7 Working Group meeting Q2 between FHIR Infrastructure and Terminology WGs.) Subject: How binding strength, additional bindings, and CodeableConcept work together—and how…

FHIR meets Ralph Wiggum (or: Agents Can Find Spec Bugs!)

The Hype The "Ralph Wiggum loop" went viral in early 2026. Named after the Simpsons character, the idea is dead simple: run an AI agent in a loop until done, reset context each session, preserve progress externally. Plugins spawned. Twitter argued about token costs. I was skeptical. Then I watched Claude Opus 4.5 write…

From MCP Server to AI Skill: A Simpler, More Powerful Way to Analyze Federal Regulation Comments

Last summer I shared an MCP server that let AI tools query public comments on federal regulations. It worked — but hosting and maintaining it was a pain. Today I'm replacing it with something better. The MCP problem The MCP server required a running backend (I hosted on Fly.io with a scale-to-zero VM), had payload size…

Granting Permission to Yourself: American Medical Records Requests are Often Absurd

Imagine walking into your local public library to check out a book, only to be handed a third-party disclosure form designed for an insurance company. You write your own name in the "Authorized Recipient" box. You declare your "Purpose" for wanting to read the book. You ask two strangers in the lobby to co-sign your re…

Health Skillz: Why I Built My Own Health Record Connector for Claude.ai & Codex

TL;DR: I built Health Skillz, a Claude Skill that fetches your health records directly from your patient portal using SMART on FHIR. It pulls all your structured data (labs, meds, conditions) plus the full text of clinical notes, encrypts everything end-to-end, and lets Claude analyze it. To try it: download the skill,…

How I Used AI Agents to Assess the State of EHI Export

This is the technical companion to "I Graded Every EHR's Patient Data Export Documentation." That post says what I found; this one says how I found it. From 10,000 pages to 217 vendors Last year I built a tool to read 10,000 pages of public comments on the CMS Health Tech Ecosystem RFI. The approach was a feed-forward…

HTI-5 Analysis: A Battle is Brewing Over AI Agents as EHR Users

Guest post from Gemini Pro analyzing HTI-5 comments on the theme of artificial intelligence / robotic process automation, sourced from my regulations.gov comment browser on HTI-5. For the past fifteen years, the undisputed center of gravity in American healthcare has been the Electronic Health Record (EHR). Following a…

HTI-5: Deregulation, Rhetoric, and Architectural Gaps

The latest proposed rule from ASTP/ONC frames a significant deregulation of the Health IT Certification Program as a necessary pivot toward a "FHIR-forward future." The document uses the rhetoric of modernization to justify the removal of long-standing requirements for legacy standards like C-CDA and Direct, and I'm ge…

I Built an AI Skill to Help Patients Request Their EHI Export

Every patient in the US has the right to a complete electronic copy of their medical record. Since December 2023, every certified EHR system has been required to support a feature called “EHI Export” that produces exactly this: a bulk export of all structured data in a patient’s chart. This is different from (deeper th…

I Graded 265 EHRs on the "Export Everything" Requirement. (Median grade was D.)

A caveat up front: Evaluating EHI export documentation is hard. Vendors' published specs are often limited, cryptic, or use product-specific terminology that's unfamiliar even to domain experts. AI-assisted analysis facilitates best-effort understanding, but it can be wrong in the details. I can't manually review all 6…

I registered Health Skillz at 500 Epic sites... then couldn't connect

This is a follow-up to 7,000+ Clicks to Register a FHIR App. That post covered the work of getting a confidential SMART on FHIR client registered at 500 Epic organizations. This post covers what happened next. --- My automation script ran; the management portal said "Keys enabled" for Health Skillz at 496 organizations…

Initial Analysis of Diagnostic Imaging RFI Response: Market Failures and Regulatory Blind Spots

For the full analysis of 97 submissions to regulations dot gov, see my Regulatory Comment Browser. Guest post by Gemini Pro. Executive Summary Our initial analysis of the 97 public comments submitted in response to RFI HHS-ONC-2026-0067 indicates that the U.S. diagnostic imaging ecosystem is suffering from a profound r…

Open Data, Agents, and the Next Era of Prior Authorization in CMS-0057-F

The CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) sets the right goals: reduce administrative burden, speed access to care, and save an estimated $15 billion over ten years. The required functionality (looking up a member's plan; identifying documentation requirements; submitting prior authorizat…

Patient-Directed Notifications in Nationwide Health Data Networks

(Guest post authored by ChatGPT 5.2 Pro -- if you think this slop, call me out!) Legal, Trust, and Architectural Considerations Executive summary There is growing interest in enabling patient-directed applications to receive notifications (e.g., “new data available,” “new encounter occurred”) across all sites where an…

Real-Time Notifications at Scale: A Brokered Approach for CMS-Aligned Networks

The CMS Interoperability Framework asks CMS-Aligned Networks to deliver appointment and encounter notifications using FHIR Subscriptions. While provider-level FHIR Subscriptions would be great (and I hope to see them land in HTI-6!), they aren't a solution to this CMS requirement because... You can't subscribe individu…

SMART Permission Tickets: Argonaut Launch!

Tomorrow, we are launching a new Argonaut project: SMART Permission Tickets. The goal is to define a standard way for authorization decisions to travel to data holders in a portable, machine-readable, and verifiable form. The friction we are trying to solve Today, SMART on FHIR authorization requires deep involvement a…

Sub-Agents Are Getting Easier

When a task is too big for one context window, the answer (in mid-January 2026) is more agents, not a bigger window. I needed to prepare for an HL7 workgroup meeting with 208 open ballot issues. Realistically, nobody reviews all of these ahead of time; you triage on the fly during the meeting. With eleven agents runnin…

The Battle for Health Data Moves to the Fine Print

To unleash healthcare innovation, the federal government is targeting “unconscionable” contracts. But in trying to slay tech Goliaths, regulators may accidentally upend the entire system. Generated from all comments mentioning "unconscionable terms." In the modern healthcare economy, the most formidable barrier to your…

The Value Was Never the Framework

Back in 2016, I pushed back against the idea of "Custom Resources" in FHIR. My objection wasn't about chaos or control. It was about using the right tool for the job. If your wanted to design a new API outside of the standards process, technologies like OpenAPI and JSON Schema were simply better. They were purpose-buil…

Your C-CDA Is Exquisitely Unlikely to Be a Satisfactory EHI Export

Under §170.315(b)(10), certified health IT must be able to export all electronic health information stored by the product. Not a summary/highlights, but everything: billing, insurance, specialty clinical data, administrative records used for decision-making, anything in the Designated Record Set that's stored electroni…

Authorization as a Network Scaling Problem

When we designed the SMART Backend Services specification, we deliberately left flexibility for implementers to handle authorization logic below the OAuth layer. There were good reasons for this - we needed to get the standard through, we needed to accommodate different deployment models, and frankly we didn't have con…

Beyond the Care Gap List: Outreach Lottery

A thought experiment on making healthcare outreach smarter and more balanced. --- Every Monday morning, clinics across the country print out the "care gaps" list—a long spreadsheet of patients overdue for screenings, check-ins, or medication reviews. Dedicated professionals work diligently to address these gaps, aiming…

Can $50B for Rural Health Drive a New Wave of Interoperability?

The Rural Health Transformation Program (part of the “One Big Beautiful Bill,” Public Law 119–21) dedicates $50 billion over five years. States must apply by the end of 2025 with a detailed plan. CMS will distribute half the money equally across approved states and half using a formula based on rural population, facili…

Fixing the "All or Nothing" Problem in Health Data Sharing: Experiments with Selective Disclosure for FHIR (SD-JWT)

The IETF recently published RFC 9901, standardizing Selective Disclosure for JSON Web Tokens (SD-JWT). This is a significant technical milestone for how we handle verifiable clinical information. I’ve focused throughout my career on the mechanics of sharing health data. As the lead author on the SMART Health Cards and…

Fulfilling the Cures Act: Conversational Interop as a "Successor Technology"

The 21st Century Cures Act set a clear north star: a patient’s electronic health information must be reachable “without special effort” through “APIs or their successor technologies.” Congress did not freeze the future on any single standard; it obligated the industry to keep removing friction from health data exchange…

Let's Talk about Appropriate Use Criteria

Few initiatives represent the gap between promise and reality quite like the Appropriate Use Criteria (AUC) program for advanced diagnostic imaging. The goal was unimpeachable: ensure that when a clinician orders a costly or high-radiation scan like a CT or MRI, the decision is backed by solid, evidence-based medicine.…

Privacy Reviews in Big Tech ... and TEFCA

Big tech companies spend a lot of time thinking about privacy design before they release anything that touches personal information. They don't just check if the data are secure; they look at everything from logs to links – even tiny clues that could in aggregate reveal too much. This post explores industry practices i…

Proposal: SMART Health Check-in Protocol

The CMS Interoperability Framework aims to "Kill the Clipboard," enabling patients to digitally share health records, insurance data, and other paperwork with providers. We already have robust data standards for this: SMART Health Cards (SHC) and SMART Health Links (SHL). These standards excel at modeling the data and…

Speeding Spec Development by Making AIs Argue

Speeding Spec Development by Making AIs Argue ============================================= Standards are supposed to bring clarity. Writing them is hard, getting them right is harder, and the feedback loop from implementation is the only thing that truly proves them out. The faster we can automate and accelerate that…

An Order to Harm

Based on https://joshuamandel.com/regulations.gov-comment-browser/AHRQ-2025-0002-0001//themes/4.4 "This will kill people." A physician at a community health center said this. He wasn't being dramatic. "I’m sick to my stomach," wrote another provider, "knowing I have to turn away my patients because of their 'legal stat…

Conversational Interoperability Takes Shape: A Read-Out from the HL7 Connectathon

Imagine two AI agents, one representing a clinician buried in paperwork, the other a remote registry for a rare disease, exchanging messages in plain English to figure out exactly what patient data needs to be shared—and in what format—before a report can be filed. No endless meetings, no custom APIs hammered out over…

My Latest Regulations.gov Comment analysis: ~Everyone Rejects HHS’s "Personal Responsibility and Work Opportunity" Reinterpretation

A July 2025 HHS reinterpretation of PRWORA (8 U.S.C. §1611) reverses nearly three decades of practice by newly classifying programs like Federally Qualified Health Centers and Head Start as “federal public benefits.” In practice, this would bar non‑qualified immigrants from those services except for narrow statutory ex…

Next Wave: AI for Public Comments

The Problem with Form Letters In prior work, I built a tool to analyze thousands of public comments. A core feature is a simple clustering algorithm that groups nearly identical submissions. This is crucial for dealing with "form letter" campaigns, where thousands of people submit the same templated text. By clustering…

The Prior Auth API is a Trap

The Da Vinci DTR Implementation Guide aims to reduce prior authorization friction by standardizing the format for asking and answering clinical questions. It is a well-engineered specification for a "computable clipboard," a significant improvement over the fax machines and proprietary portals in use today. The core pr…

The Prior Authorization (De)regulation Paradox

HHS wants to deregulate. The White House is clear: slash the number of federal regulations. Executive Order 14192 demands a "10-for-1" repeal ratio. Another order aims to deconstruct the "overbearing and burdensome administrative state" (Ensuring Lawful Governance). So when HHS issued a Request for Information (AHRQ-20…

Which healthcare regulations should we kill?

Yesterday, the comment period closed on the Agency for Healthcare Research and Quality RFI titled "Ensuring Lawful Regulation and Unleashing Innovation to Make America Healthy Again." The RFI asked stakeholders to pinpoint specific regulations that: Increase costs without benefits Impede innovation or competition Are o…

Analysis: "Reducing Medically Unnecessary Delays in Care Act"

Prior authorization imposes a barrier to timely care. While tech solutions (including conversational AI agents using FHIR, as I discussed last week) offer potential paths to streamline this, policy sets the operational parameters. The newly (re-)introduced "Reducing Medically Unnecessary Delays in Care Act of 2025" bil…

Better Browser APIs for Sharing SMART Health Cards, FHIR Bundles, and other Digital Credentials

Josh Mandel Explores New Presentation APIs for Digital Health Data. To hear my real voice, watch the YouTube demo below :-) This third-person article is an experiment working with LLM-prompted "objective analysis" of the full audio + video content. I think it's pretty cool, but I'd love your feedback on the format as w…

CMS RFI MCP: Now It's Your Turn to Analyze 10k Pages ;)

A few weeks ago, I shared an interactive dashboard summarizing public comments on the CMS Health Tech Ecosystem RFI. Now for the next step: make the underlying data more amenable to new, dynamic analyses. Toward this end, I'm sharing a data set, a tool, some sample prompts, and lessons learned along the way. 1. AI-Read…

Conversational Interop for Prior Auth (demo!)

What if, instead of pre-specifying every data field and every possible workflow step, we could enable conversations between capable systems? Today's live demo explores early steps toward this vision – using LLM agents with protocols like Agent-to-Agent (A2A) and Model Context Protocol (MCP) to connect directly to real…

Connect the Dots for Prior Auth: A2A && MCP?

Another day, another open protocol! In previous posts, we explored how agents can use MCP tools (grep, query, eval) to analyze EHR data fetched via SMART on FHIR (Theory to Practice), and envisioned a more conversational prior authorization (PA) workflow (Prior Auth is Friction). Today, perhaps a new puzzle has emerged…

Creating a "Living Manual" for EHI Export

It is a significant undertaking to maintain and document a modern EHR database spanning diverse clinical domains and workflows. It's no surprise that a database optimized for clinical care and hospital operations contains thousands of tables. In its native context, that complexity is a feature. But for patients, develo…

Deregulation of Certified Health IT: Cuts to Real World Testing

Personal note: The value proposition of regulation and deregulation is full of trade-offs. My personal take is that the Real World Testing cuts are a reasonable, pragmatic place to ease off on requirements, opening up time and attention for Certified Health IT products to focus on more pressing concerns. Still, I would…

EHR Association's Proposal Would Deregulate the Foundations of Patient Access and Population Management

A recent letter from the HIMSS Electronic Health Record (EHR) Association to ONC outlines recommendations ostensibly aimed at "Smart Deregulation in Health IT." While streamlining regulation is beneficial when done thoughtfully, the letter includes proposals that would dismantle critical data access capabilities mandat…

Designing for Delay: A Liaison UX for Prior Auth and Other Asynchronous Clinical Tasks

Clinical workflows are full of necessary steps that don't happen instantly. Think about prior authorization (PA) – a classic example – but also tasks like matching a patient to eligible clinical trials, or coordinating a complex specialty consult requiring information exchange. These processes are often asynchronous, i…

Evaluating FHIR's Evolution: AI-Assisted Analysis of R4→R6 Changes

As the FHIR community steers towards our R6 release, a key objective is to provide stable, mature resources. With the first normative ballot in the R6 publication sequence anticipated this fall, let's assess how FHIR is evolving. This post describes a quick experiment to automate analysis of FHIR's evolution from R4 to…

Healthcare's High-Tech Future Forgets One Thing: The Humans?

This is the first in a short series of articles drawing on themes, attestations, and conflicts surfaced in the CMS Health Tech Ecosystem RFI, which closes in two days. The article comes from the LLM-based analysis pipeline I'm putting together at https://github.com/jmandel/regulations.gov-comment-browser -- I'll have m…