“Data liquidity is ensuring that information is available when we need it, where we need it,” Molly Prieto, Principal Deputy Director, Office of Standards, Certification, and Analysis at the Office of the National Coordinator for Health IT (ONC), told a federal healthcare IT forum — framing a shift in emphasis from choosing technologies to building an integrated digital environment that moves information, not siloed systems.
ONC: Data liquidity, TEFCA, and preparing for interoperability requirements
The ONC has recast modernization around making health information usable and trustworthy when and where it is needed. Prieto described the agency’s priorities as standards-based interoperability that enables secure exchange among providers, patients, and organizations. Central to that work is advancing the Trusted Exchange Framework and Common Agreement (TEFCA), designed to create a nationwide network for health information exchange.
As adoption of exchange capabilities increases, the ONC is shifting attention from simply growing the volume of exchanges to improving quality, usability, and accessibility of data. The agency is also preparing the healthcare ecosystem for upcoming interoperability requirements specifically called out by the ONC: electronic prior authorization and real-time prescription benefit information. These initiatives aim to reduce manual processes and improve transparency for patients and providers.
DHA: Embedding cybersecurity and deploying AI-enabled workflows
Pat Flanders, Chief Information Officer at the Defense Health Agency (DHA), described a modernization path driven by both clinical care and operational readiness. “Cyber can’t be bolted on. It needs to be part of your design,” he said, signaling that security and mission requirements are being integrated from the start rather than added afterward.
The DHA has moved to incorporate AI into day-to-day healthcare workflows to free clinicians from administrative burden. The agency has deployed ambient listening capabilities and an accredited large language model environment called Ask Sage that is cleared for protected health information, enabling AI-assisted workflows while aiming to meet rigorous security expectations — the agency noted these capabilities must satisfy “Department of War security standards.” Looking forward, the DHA emphasized intelligent automation, secure AI adoption, and technologies that support clinicians and patients while preserving operational readiness.
CMS: User-centered digital experiences and balancing innovation with reliability
At the Centers for Medicare & Medicaid Services (CMS), Kathryn Wetherby, Acting Director of the IT Capital Planning Group, described modernization from the citizen’s vantage point. CMS is focused on making digital interactions more user-friendly and on shifting care models from reactive episodes toward prevention and continuity supported by data and analytics. “Technology is an enabler. We don’t build technology for technology’s sake. We build it because we are solving a problem,” Wetherby said.
CMS highlighted specific modernization levers: expanding telemedicine, remote monitoring, identity verification, and digital services to improve access for underserved populations. The agency emphasized governance, transparency, and human-centered design as guardrails while introducing AI and advanced analytics so patients gain visibility, access, and control over their information.
Cloudflare: Distributed architectures, edge processing, and identity-based security
Kim Kilty, Senior Manager, Federal Civilian, at Cloudflare, outlined how infrastructure and security must evolve as federal healthcare adopts cloud and AI. Kilty argued the sector is moving away from centralized networks toward distributed environments that place users, data, and applications across multiple locations. “It isn’t just moving data to the cloud; it’s moving secure access and intelligent processing to the edge, closer to the patient and closer to where care is delivered,” she said.
Cloudflare emphasized identity-based access, secure connectivity, and edge protection as essential controls. By bringing security and processing closer to users, the company framed distributed architectures as a way to strengthen resilience, reduce latency, and improve performance for clinicians and patients as digital services expand.
What this means for technologists, policymakers, and patients
- Technologists and security teams — Expect implementation focus to shift from point solutions to architectures: standards-based interoperability (TEFCA), identity-based access, edge processing, and embedded security will guide procurement and design decisions.
- Policymakers and regulators — Will likely monitor TEFCA adoption, interoperability rule implementation (electronic prior authorization and real-time prescription benefits), and governance frameworks for AI and PHI-approved models like Ask Sage to balance innovation with reliability.
- Patients and clinicians — Stand to gain reduced administrative burden, more transparent prescription and prior authorization processes, and quicker, more localized digital services — assuming quality, usability, and trust measures keep pace with technical rollout.
The consistent through-line from the ONC, DHA, CMS, and Cloudflare at the webinar was that healthcare modernization is less about which tool comes next and more about how technologies are woven into an interoperable, secure, and human-centered fabric. The agencies named concrete steps — TEFCA expansion, electronic prior authorization, real-time prescription benefit information, accredited AI environments such as Ask Sage, and distributed edge security — but the success of those steps will hinge on measurable improvements in data quality, usability, and governance.
As federal healthcare moves into this next phase, a central question remains: can agencies scale interoperable, secure, and patient-centered services — from TEFCA-backed exchanges to edge-enabled AI — while maintaining the trust and governance those services require?




