Finding an Interoperability Steward: FHIR and the GAO

Blog

In July, delivery teams and federal interoperability leads spent three days participating in the 7th Annual  CMS HL7 FHIR Connectathon testing real-world CMS use cases including Prior Authorization, Patient Access APIs, and payer interoperability workflows. However, in June, prior to the Connectathon, the GAO issued a report stating that the 100+ data sources agencies use to verify award and payment eligibility data have data quality problems and lack interoperability standards or a governing body to enforce them. These two developments landed weeks apart and look, at first glance, unrelated — one technical, one governance. But they are two sides of the same interoperability challenge: the FHIR Connectathon tests whether the standards work in real workflows, while the GAO report asks who is accountable for enforcing standards in the first place. Together they show that interoperability is as much an organizational problem as a technical one, bringing an important reminder of the breadth and complexity and tackling it.

While CMS is driving FHIR adoption across healthcare, facing the January 2027 deadline by which payers must implement standardized FHIR APIs, the GAO report underscored the need for Congress to assign an agency to implement interoperability standards specifically for eligibility data.

Testing FHIR Before the Deadline Hits

This year’s Connectathon had a more serious tone. With the January 1 deadline requiring agencies and their support contractors to be ready for FHIR looming closer, the importance of maximizing the opportunity for real-world testing was sensed by all. That urgency was reflected in the event’s outcomes. FHIR-based prior authorization was proven to be moving from pilot to production readiness, a shift that will drive sustained demand for API development, workflow automation, integration engineering, and DevSecOps support. More broadly, interoperability work was shown as operational rather than regulatory: the industry is no longer asking whether these capabilities can be built, but whether they can be delivered consistently, securely, and at scale. And, CMS continues to signal a “FHIR-first” strategy, pointing to ongoing need for API engineering, cloud-native integration, data interoperability, DevSecOps, and platform engineering.

These are precisely the areas where Samtek operates. At Samtek, with our AI-enabled cloud products, we support CMS from inside the environments where interoperability actually gets built, secured, and deployed. As prime on the CMS OIT COMET program, we help advance CMS’s hybrid and multi-cloud strategy, operationalizing modern cloud services across AWS, Azure Government, Azure Commercial, Google Cloud Platform, and Oracle Cloud Infrastructure.

Our team has helped more than 80 application teams onboard to the CMS Cloud, standing up 350+ standardized AWS accounts through our custom Service Provisioning Automation (SPA) platform while providing operational support to 300+ application teams. We take an API-first posture on our CMS Medicaid and CHIP work, treating APIs as the building blocks of every solution so systems, services, and partners can integrate cleanly across cloud providers. That multi-cloud foundation is exactly what payers and agencies depend on as they stand up standardized FHIR APIs ahead of the January 2027 deadline.

Finding an Interoperability Steward

The June GAO report looked at a different piece of the interoperability picture: the eligibility-verification data agencies use to determine which awards and payments to make. Agencies can draw upon over 100 federal data sources to verify recipient eligibility data across the award life cycle. After reviewing nine of those sources in depth, the GAO found data quality issues across all nine (missing, invalid, or duplicate data), and inconsistencies between sources in seven of them, including overlapping data.

For more than 30 years, laws and guidance have established general requirements related to interoperability, but none has ever assigned a specific agency the authority to define and enforce interoperability requirements for eligibility data government wide. According to GAO, this has resulted in fragmented, inconsistent data management that depends entirely on voluntary adoption.

GAO recommends that Congress consider giving Treasury explicit authority to lead government-wide interoperability requirements for eligibility data, a finding that highlights how critical strong governance and oversight are to achieving successful interoperability outcomes.

Where this Leaves Agencies and Their Partners

The organizations that emerge as driving forces will be the ones who value governance and intentional collaboration, treating interoperability as an organizational problem as much as a technical one, with named data owners, defined standards, and clear accountability for keeping data clean and shareable.

At Samtek, we see interoperability the way the GAO frames it: as much an organizational and governance challenge as a technical one. On our CMS Medicaid and CHIP DevSecOps and Cloud Navigator work, we have built the governance layer the GAO calls for, standardizing DevSecOps practices, defining data management, and establishing governance plans with clear risk accountability across mixed vendor teams. Interoperable data is only valuable when it’s also secure and trusted, which is why we operate a 24×7 Security Operations Center on the CMS CCSQ cloud with continuous monitoring across all FISMA systems, maintaining FISMA, NIST, FedRAMP, and ARS 5.0 compliance and sustaining zero unplanned ATO expirations.

That discipline produces measurable results: when the CMS OIT cloud relied on manual, spreadsheet-driven tracking of aging resources, we replaced it with a proactive, campaign-based governance model that reduced deprecated resources by 85% in a single year. Interoperability succeeds on that same foundation: named data owners, enforceable standards, and tracked accountability, not voluntary adoption.

Events like the Connectathon are essential because they demonstrate the importance of agencies, technology partners, implementers, developers, and program leaders coming together to test interoperability standards against actual workflows in their business. By identifying gaps, resolving challenges, and validating use cases before requirements take effect, interoperability becomes more of an operational reality. And the GAO report makes clear, successful interoperability outcomes will require strong governance and collaboration.

The agencies and payers that meet the 2027 deadline won’t be the ones with the best technology alone — they’ll be the ones who paired it with real governance: named data owners, enforceable standards, and clear accountability. That’s the work Samtek does inside CMS environments every day. If your organization is preparing for FHIR or wrestling with the eligibility-data governance gap the GAO describes, let’s talk about what an interoperability foundation built to last actually looks like.

FEATURED BLOGS

Investing in Growth & Maturity-2

Investing in Growth & Maturity

Sustainable growth requires maturity. For founder-led firms scaling in the federal market, that means investing in the people, processes, tools, and operating disciplines that convert growth into maturity. In this post, Samtek Founder & CEO Rupak Desai reflects on why investing in organizational maturity has been essential to the growth of Samtek.
Data Leaks_ Small Settings Can Have Major Security Impacts

Data Leaks: Small Settings Can Have Major Security Impacts

Reducing data leakage by avoiding small configuration mistakes or oversights can have a major impact on security and can help organizations reduce overall risk. Read this blog to learn how to avoid many real-world scenarios that involve data leaks by taking the time to consider the "small" things.
Building Influence Without Authority in Cloud-Native Teams

Building Influence Without Authority in Cloud-Native Teams

Modern technologists can build influence without formal authority. This blog explores ways to build influence, including treating credibility as currency, investing in other teams’ success, communicating in the language of the audience, leading with data, and using disagreement as a relationship asset.