Concept Version 0.3 · Stakeholder Review

Healthcare information that outlives an outage.

NPRR is a proposed national, participatory capability that preserves longitudinal patient information and keeps it available to patients and appropriately authorized care teams—even when the organization that originated it cannot respond.

Technology-neutral · Patient-centered · Standards-based · Resilient by design

The defining idea

Break the dependency between the source of a record and the continuing availability of the patient’s information.

NPRR complements—not replaces—EHRs, health information exchanges, and the TEFCA/QHIN ecosystem. Its national value lies in durable preservation, identity correlation, authorized retrieval, organizational recovery, and continuity during disruption.

Concept foundations

A continuity layer designed around people, trust, and collaboration.

Participation is encouraged rather than mandated. Every additional participant strengthens the completeness and resilience of the national capability.

01

Patient-centered access

Once appropriately identified, patients retain access to their own information and may authorize organizations or individuals to access it.

02

National identity correlation

An NPID, MPI, and authorized cross-reference functions connect local identifiers without confusing identity matching with permission.

03

Durable preservation

Preserved information remains available independently of the originating organization’s operational state.

04

Authorized exchange

Access is purpose-bound, minimum-necessary, traceable, and comprehensively audited across organizational boundaries.

05

Recovery and resilience

Participating organizations can recover contributed information after ransomware, corruption, disaster, or infrastructure loss.

06

Technology neutrality

The Concept defines mission, outcomes, principles, and capabilities without selecting vendors, platforms, databases, or hosting models.

Canonical resilience scenario

Hospital A is offline. The patient’s history is not.

A
Information is preserved

Hospital A previously contributes or preserves patient information through NPRR.

!
A severe disruption occurs

Ransomware, infrastructure loss, disaster, corruption, or another event takes Hospital A’s services offline.

B
Authorized care continues

Hospital B retrieves all or an authorized subset of the preserved information through the TEFCA/NPRR ecosystem.

The authority for access can derive from patient authorization, treatment rules, emergency authority, or pre-established governance—and must not inherently depend on Hospital A being online at disaster time.

Nationwide clinical-prior prefetching

More relevant history, ready before care.

Authorized facilities can configure algorithms to discover and retrieve clinically relevant prior studies from participating organizations nationwide. DICOM provides imaging discovery and retrieval, while FHIR and TEFCA-supported mechanisms supply clinical and workflow context.

The intended outcome is simple: clinicians receive a broader inventory of relevant historical priors in time to improve comparison and treatment decisions.

Clinically relevantRules may consider modality, anatomy, diagnosis, procedure, study age, and the scheduled encounter.
Purpose-boundEvery request needs a valid authorization and purpose-of-use basis; identity correlation alone never grants access.
Minimum necessaryControls prevent speculative bulk collection and retrieval unrelated to anticipated care.
Fully traceableFacility, patient, purpose, criteria, source, records transferred, authorization, and disposition are auditable.

Law, standards & assurance references

Grounded in healthcare law, national exchange foundations, and recognized standards.

HIPAA is presented as an applicable legal and regulatory framework. FedRAMP High, DoD IL5, and CMMC Level 2 are Concept-level security benchmarks—not claims of certification or a prescribed platform.

Program document path

From national mission to implementable design.

Each stage resolves the decisions appropriate to its level while preserving traceability to the approved Concept.

Current

Concept

Defines mission, value, principles, capabilities, and boundaries. Version 0.3 is prepared for stakeholder review.

Next

Proposal

Defines governance, program case, participation, funding, adoption, and delivery approach.

Then

Detailed Architecture

Defines implementable technical and operational design after Proposal approval.

Ongoing

Supporting Documents

Requirements, decisions, security plans, policies, roadmaps, and operating procedures.

Primary source

Read the complete NPRR Concept.

The full document includes the settled Concept positions, governance principles, scope boundaries, success outcomes, and the agenda for Proposal and later work.

Download Concept v0.3 PDF
Status
Working Concept Draft
Audience
Stakeholder Review
Version
0.3
Date
September 2026
Length
13 pages
Author
BSG, Inc.