Patient-centered access
Once appropriately identified, patients retain access to their own information and may authorize organizations or individuals to access it.
Concept Version 0.4 · Stakeholder Review
NPRR is a proposed national, participatory capability that preserves longitudinal patient information and keeps it available to patients and appropriately authorized care teams—even when the organization that originated it cannot respond.
Technology-neutral · Patient-centered · Standards-based · Resistant to misuse
The defining idea
Concept foundations
Participation is encouraged rather than mandated. Every additional participant strengthens the completeness and resilience of the national capability.
Once appropriately identified, patients retain access to their own information and may authorize organizations or individuals to access it.
An NPID, MPI, and authorized cross-reference functions connect local identifiers without confusing identity matching with permission.
Preserved information remains available independently of the originating organization’s operational state.
Access is purpose-bound, minimum-necessary, traceable, and comprehensively audited across organizational boundaries.
Participating organizations can recover contributed information after ransomware, corruption, disaster, or infrastructure loss.
The Concept defines mission, outcomes, principles, and capabilities without selecting vendors, platforms, databases, or hosting models.
Canonical resilience scenario
Hospital A previously contributes or preserves patient information through NPRR.
Ransomware, infrastructure loss, disaster, corruption, or another event takes Hospital A’s services offline.
Hospital B retrieves all or an authorized subset of the preserved information through the TEFCA/NPRR ecosystem.
Nationwide clinical-prior prefetching
Authorized facilities can configure algorithms to discover and retrieve clinically relevant prior studies from participating organizations nationwide. DICOM provides imaging discovery and retrieval, while FHIR and TEFCA-supported mechanisms supply clinical and workflow context.
The intended outcome is simple: clinicians receive a broader inventory of relevant historical priors in time to improve comparison and treatment decisions.
Version 0.4 trust requirements
No agency, operator, administrator, funder, regulator, hosting provider, contractor, or security organization receives unrestricted access merely because it supports or oversees NPRR.
Participation remains voluntary. Later architecture work must evaluate distributed control, customer-controlled cryptographic keys, zero-trust access, immutable external audit, segmentation, portability, and recovery without selecting a particular cloud or vendor in the Concept.
Law, standards & assurance references
HIPAA is presented as an applicable legal and regulatory framework. FedRAMP High, DoD IL5, and CMMC Level 2 are Concept-level security benchmarks—not claims of certification or a prescribed platform.
The governed nationwide exchange foundation that NPRR extends and participates in—not a competing network.
Official RCE resourcesHHS explains TEFCA’s goals, benefits, exchange purposes, governance roles, and direction as a nationwide network-of-networks.
HHS Office of the National CoordinatorA high-assurance federal cloud security benchmark referenced for the program’s intended rigor.
FedRAMP.govA benchmark for protecting sensitive unclassified mission information in applicable government environments.
DoD Cyber ExchangeA cybersecurity maturity reference associated with safeguarding controlled unclassified information.
DoD CIO CMMC programThe preferred standards-based mechanism for clinical-data exchange where supported and appropriate.
HL7 FHIR specificationThe primary and continuing interface for medical-imaging storage, discovery, and retrieval—not a legacy interface.
Current DICOM StandardThe federal legal and regulatory framework governing privacy, security, breach notification, and permitted uses and disclosures of protected health information.
Official HHS HIPAA guidanceProgram document path
Each stage resolves the decisions appropriate to its level while preserving traceability to the approved Concept.
Defines mission, value, principles, capabilities, and boundaries. Version 0.4 is prepared for stakeholder review.
Defines governance, program case, participation, funding, adoption, and delivery approach.
Defines implementable technical and operational design after Proposal approval.
Requirements, decisions, security plans, policies, roadmaps, and operating procedures.
Primary source
The full document includes the settled Concept positions, governance principles, protections against foreseeable misuse, scope boundaries, success outcomes, and the agenda for Proposal and later work.
Download Concept v0.4 PDFContact NPRR
Questions, concerns, and constructive challenges are welcome—especially from patients, clinicians, healthcare organizations, privacy advocates, standards bodies, and public-sector stakeholders.
Your information is used only to prepare an email in your own email application. This website does not store or transmit your form entries.