This question used to be mostly theoretical. Teams debated it in architecture meetings while both formats sat comfortably inside the ONC certification program, required side by side. That comfort is gone. ONC’s HTI-5 proposed rule, released in December 2025, would strip out most of the certification criteria built around C-CDA, and the public comment period on it closed in February 2026.
That timing matters for anyone deciding where to put the engineering budget this year. C-CDA is not disappearing overnight, and the American Hospital Association has formally asked regulators to slow the transition down. But the direction of travel is no longer ambiguous, and a health IT roadmap built as if both formats carry equal long-term weight is now out of step with where the regulatory program is heading.
This article compares what C-CDA and FHIR are each actually built for, what the current rulemaking says about C-CDA’s future, and where that leaves an organization deciding what to invest in next.
For most of the last decade, C-CDA and FHIR coexisted comfortably inside the ONC certification program. Health IT modules had to support both, and the debate over which one mattered more stayed mostly academic, since certification required both regardless of preference.
ONC’s HTI-5 proposed rule changes that. It proposes removing 34 of the program’s 60 certification criteria, and among them are several of the core criteria governing CDA-based document exchange, according to Drummond Group’s analysis of the rule. ONC’s own stated reasoning is that these requirements have been largely superseded by the growing adoption of FHIR-based interoperability approaches.
C-CDA is a document-based standard. It produces a complete, structured clinical document, a continuity of care document, a discharge summary, a referral note, meant to travel as a single package between systems and be read as a whole.
That document-centric model is exactly what national exchange networks like Carequality and CommonWell were built around, and it remains the backbone of how a large share of real clinical data moves between organizations today. Rural and smaller provider organizations in particular tend to rely on this kind of exchange, which is precisely the concern the American Hospital Association raised in its comments on HTI-5.
FHIR takes the opposite approach. Instead of a complete document, it exposes discrete resources, a single medication, a single lab result, a single diagnosis, each independently accessible through a modern, RESTful API. An application can request exactly the data element it needs, rather than parsing an entire document to find it.
| Factor | C-CDA | FHIR |
|---|---|---|
| Data model | Complete structured document | Discrete, independently queryable resources |
| Access method | Document exchange, often via Direct or XDR/XDM | RESTful API |
| Best suited for | A full clinical snapshot, like a continuity of care record | Targeted, specific data requests from an application |
| Regulatory direction | Certification criteria proposed for removal under HTI-5 | Explicitly retained and expanded, including new prior authorization criteria |
| Common use today | National networks like Carequality and CommonWell | Patient access apps, provider-facing apps, emerging ePA workflows |
The FHIR Standardized API criterion is explicitly retained under HTI-5, and ONC and certification bodies describe it as the foundation the program plans to keep building on. New regulatory requirements, including the electronic prior authorization criteria finalized under HTI-4, are FHIR-based rather than document-based, which signals clearly where future rulemaking is headed.
HTI-5 specifically proposes removing several CDA-based certification criteria, including Clinical Information Reconciliation and Incorporation and the Security Tags criteria tied to summary of care documents. ONC’s stated view is that FHIR-based interoperability has matured enough to make these particular requirements redundant.
This is a proposed rule, not a final one. As of this writing, ONC has not issued a final rule, and the agency has indicated it will build flexibility into the timeline given the uncertainty. Current certification test documentation still shows some C-CDA creation performance requirements extending through December 2027 under existing regulations, so any transition will happen in stages rather than all at once.
The American Hospital Association’s comment letter on HTI-5 raises a specific, practical concern: many providers, particularly in rural and underserved areas, remain dependent on C-CDA-based exchange for their day-to-day interoperability needs, and removing certification requirements around it risks leaving that exchange method without the same regulatory backing.
| HTI-5 proposal | Industry response |
|---|---|
| Remove most C-CDA-based certification criteria | AHA asks ONC to maintain C-CDA criteria given continued reliance by rural providers |
| Move toward a FHIR-first certification structure | AHA supports the direction but asks for a longer, more realistic transition timeline |
| No fixed timeline stated for full transition | Industry groups request at least 24 months after any final rule before enforcement |
FHIR is clearly where new regulatory requirements, new use cases, and new API-based products are heading. An organization building anything new, a patient-facing app, a provider integration, a prior authorization workflow, should build it on FHIR from the start.
That does not mean C-CDA support should be removed from existing systems. It remains a real, active requirement for exchanging data with the networks and partner organizations that still rely on it, and current certification timelines confirm it is staying in place for at least the next couple of years under existing rules. The practical answer looks a lot like the same posture organizations should take toward legacy HL7 v2 infrastructure: build the future on the new standard, and keep the older one running for as long as the partners around it still depend on it.
The regulatory direction is not ambiguous anymore. FHIR is where ONC is building, where new certification criteria are landing, and where new use cases like electronic prior authorization are being defined. Any organization planning new health IT investment should build there.
C-CDA is not obsolete, and treating it that way right now would be premature given the current certification timeline and the volume of real exchange still running through document-based networks. The realistic strategy is the same one that applies to legacy HL7 v2 infrastructure: invest in the future standard without pulling support for the one still carrying real traffic today.
For a related look at how this same coexistence strategy applies to legacy interface engines, see HL7 v2 isn’t going away: here’s how to modernize without replacing your existing systems.








No. HTI-5 is a proposed rule, not a final one, and current certification documentation still shows some C-CDA requirements extending through December 2027. Any removal will happen in phases.
ONC's stated position is that FHIR-based interoperability has matured enough to make certain C-CDA-based certification criteria redundant, not that C-CDA itself has no remaining use, particularly for the exchange networks still built around it.
Because many providers, especially in rural and underserved areas, still depend on C-CDA-based exchange for daily interoperability, and the AHA is asking for a longer, more realistic transition timeline rather than opposing the shift to FHIR outright.
Generally no, for new development. FHIR is where new regulatory requirements and API-based use cases are concentrated, including the newer prior authorization criteria. C-CDA support matters more for compatibility with existing partners than for new product design.
It is the certification criterion ONC has explicitly retained and described as the foundation for future rulemaking, which is a clear signal that FHIR-based API access, not document exchange, is where the certification program is headed.
Likely several years. Between the current certification timeline, the uncertain final rule, and the pace at which smaller provider organizations can transition, both formats are likely to coexist across most exchange networks for the foreseeable future.
ISO 27001:2022 Certified
Aigilx health specializes in developing Interoperability solutions to create a healthcare ecosystem and aids in the delivery of efficient, patient-centric and population-focused healthcare.