Key takeaways

  • ONC’s HTI-5 proposed rule, released in December 2025, would remove most C-CDA-based certification criteria in favor of a FHIR-first regulatory structure, according to certification body Drummond Group’s own analysis of the rule.
  • The FHIR Standardized API criterion is explicitly retained under HTI-5 and described as the foundation ONC plans to build future requirements on.
  • The American Hospital Association formally objected to the pace of this shift, noting that many rural and underserved providers still depend heavily on C-CDA-based exchange.
  • Current ONC test method documentation still shows C-CDA creation performance criteria required through at least December 2027 under existing rules, so this is a phased shift, not an immediate cutoff.
  • C-CDA and FHIR were built to solve different problems: C-CDA delivers a complete document, like a full continuity of care record, while FHIR exposes discrete, queryable data elements through an API.
  • New regulatory investment, including the FHIR-based electronic prior authorization criteria finalized under HTI-4, is going almost entirely toward FHIR, not C-CDA.
  • The practical answer for most organizations is to build new capability on FHIR while keeping C-CDA support intact for the networks and partners that still depend on it.
C-CDA FHIR HTI-5 certification changes

This question used to be mostly theoretical. Teams debated it in architecture meetings while both formats sat comfortably inside the ONC certification program, required side by side. That comfort is gone. ONC’s HTI-5 proposed rule, released in December 2025, would strip out most of the certification criteria built around C-CDA, and the public comment period on it closed in February 2026.

That timing matters for anyone deciding where to put the engineering budget this year. C-CDA is not disappearing overnight, and the American Hospital Association has formally asked regulators to slow the transition down. But the direction of travel is no longer ambiguous, and a health IT roadmap built as if both formats carry equal long-term weight is now out of step with where the regulatory program is heading.

This article compares what C-CDA and FHIR are each actually built for, what the current rulemaking says about C-CDA’s future, and where that leaves an organization deciding what to invest in next.

Why is this suddenly a live regulatory question, not just a technical debate?

For most of the last decade, C-CDA and FHIR coexisted comfortably inside the ONC certification program. Health IT modules had to support both, and the debate over which one mattered more stayed mostly academic, since certification required both regardless of preference.

ONC’s HTI-5 proposed rule changes that. It proposes removing 34 of the program’s 60 certification criteria, and among them are several of the core criteria governing CDA-based document exchange, according to Drummond Group’s analysis of the rule. ONC’s own stated reasoning is that these requirements have been largely superseded by the growing adoption of FHIR-based interoperability approaches.

What is C-CDA built for, and where does it still matter?

C-CDA is a document-based standard. It produces a complete, structured clinical document, a continuity of care document, a discharge summary, a referral note, meant to travel as a single package between systems and be read as a whole.

That document-centric model is exactly what national exchange networks like Carequality and CommonWell were built around, and it remains the backbone of how a large share of real clinical data moves between organizations today. Rural and smaller provider organizations in particular tend to rely on this kind of exchange, which is precisely the concern the American Hospital Association raised in its comments on HTI-5.

What is FHIR built for, and why is ONC building around it?

FHIR takes the opposite approach. Instead of a complete document, it exposes discrete resources, a single medication, a single lab result, a single diagnosis, each independently accessible through a modern, RESTful API. An application can request exactly the data element it needs, rather than parsing an entire document to find it.

C-CDA vs. FHIR at a glance
Factor C-CDA FHIR
Data model Complete structured document Discrete, independently queryable resources
Access method Document exchange, often via Direct or XDR/XDM RESTful API
Best suited for A full clinical snapshot, like a continuity of care record Targeted, specific data requests from an application
Regulatory direction Certification criteria proposed for removal under HTI-5 Explicitly retained and expanded, including new prior authorization criteria
Common use today National networks like Carequality and CommonWell Patient access apps, provider-facing apps, emerging ePA workflows

The FHIR Standardized API criterion is explicitly retained under HTI-5, and ONC and certification bodies describe it as the foundation the program plans to keep building on. New regulatory requirements, including the electronic prior authorization criteria finalized under HTI-4, are FHIR-based rather than document-based, which signals clearly where future rulemaking is headed.

What does the HTI-5 proposed rule actually say about C-CDA's future?

HTI-5 specifically proposes removing several CDA-based certification criteria, including Clinical Information Reconciliation and Incorporation and the Security Tags criteria tied to summary of care documents. ONC’s stated view is that FHIR-based interoperability has matured enough to make these particular requirements redundant.

This is a proposed rule, not a final one. As of this writing, ONC has not issued a final rule, and the agency has indicated it will build flexibility into the timeline given the uncertainty. Current certification test documentation still shows some C-CDA creation performance requirements extending through December 2027 under existing regulations, so any transition will happen in stages rather than all at once.

Why is the industry pushing back on removing C-CDA quickly?

The American Hospital Association’s comment letter on HTI-5 raises a specific, practical concern: many providers, particularly in rural and underserved areas, remain dependent on C-CDA-based exchange for their day-to-day interoperability needs, and removing certification requirements around it risks leaving that exchange method without the same regulatory backing.

HTI-5's proposal vs. the industry response
HTI-5 proposalIndustry response
Remove most C-CDA-based certification criteriaAHA asks ONC to maintain C-CDA criteria given continued reliance by rural providers
Move toward a FHIR-first certification structureAHA supports the direction but asks for a longer, more realistic transition timeline
No fixed timeline stated for full transitionIndustry groups request at least 24 months after any final rule before enforcement

So which format should an organization actually invest in?

FHIR is clearly where new regulatory requirements, new use cases, and new API-based products are heading. An organization building anything new, a patient-facing app, a provider integration, a prior authorization workflow, should build it on FHIR from the start.

That does not mean C-CDA support should be removed from existing systems. It remains a real, active requirement for exchanging data with the networks and partner organizations that still rely on it, and current certification timelines confirm it is staying in place for at least the next couple of years under existing rules. The practical answer looks a lot like the same posture organizations should take toward legacy HL7 v2 infrastructure: build the future on the new standard, and keep the older one running for as long as the partners around it still depend on it.

C-CDA FHIR data exchange comparison

What should organizations building new health IT do right now?

  • Build new capability on FHIR by default, since that is where regulatory investment and API-based use cases are concentrated.
  • Keep existing C-CDA generation and consumption intact, rather than deprecating it ahead of any final rule or partner readiness.
  • Track the HTI-5 final rule closely, since the actual removal timeline and any transition period will shape how quickly C-CDA obligations can realistically wind down.
  • Confirm which of your exchange partners still depend on C-CDA, particularly smaller or rural organizations, before assuming document-based exchange is optional.
  • Avoid treating this as an either-or decision, since the realistic path for most organizations is running both formats in parallel for years, not choosing one and abandoning the other.

Where does this leave organizations planning their next investment?

The regulatory direction is not ambiguous anymore. FHIR is where ONC is building, where new certification criteria are landing, and where new use cases like electronic prior authorization are being defined. Any organization planning new health IT investment should build there.

C-CDA is not obsolete, and treating it that way right now would be premature given the current certification timeline and the volume of real exchange still running through document-based networks. The realistic strategy is the same one that applies to legacy HL7 v2 infrastructure: invest in the future standard without pulling support for the one still carrying real traffic today.

For a related look at how this same coexistence strategy applies to legacy interface engines, see HL7 v2 isn’t going away: here’s how to modernize without replacing your existing systems.

FAQs

No. HTI-5 is a proposed rule, not a final one, and current certification documentation still shows some C-CDA requirements extending through December 2027. Any removal will happen in phases.

ONC's stated position is that FHIR-based interoperability has matured enough to make certain C-CDA-based certification criteria redundant, not that C-CDA itself has no remaining use, particularly for the exchange networks still built around it.

Because many providers, especially in rural and underserved areas, still depend on C-CDA-based exchange for daily interoperability, and the AHA is asking for a longer, more realistic transition timeline rather than opposing the shift to FHIR outright.

Generally no, for new development. FHIR is where new regulatory requirements and API-based use cases are concentrated, including the newer prior authorization criteria. C-CDA support matters more for compatibility with existing partners than for new product design.

It is the certification criterion ONC has explicitly retained and described as the foundation for future rulemaking, which is a clear signal that FHIR-based API access, not document exchange, is where the certification program is headed.

Likely several years. Between the current certification timeline, the uncertain final rule, and the pace at which smaller provider organizations can transition, both formats are likely to coexist across most exchange networks for the foreseeable future.

ISO 27001:2022 Certified

Aigilx health specializes in developing Interoperability solutions to create a healthcare ecosystem and aids in the delivery of efficient, patient-centric and population-focused healthcare.

Graphics

Follow Us

Email: contact@aigilxhealth.com