Governance

Health Gorilla operates within established national trust frameworks to support secure, compliant, and reciprocal clinical data exchange at enterprise scale. Governance defines how organizations participate in exchange, the conditions under which data may be requested or shared, and the obligations that apply to all participants.

As a designated Qualified Health Information Network (QHIN) under the Trusted Exchange Framework and Common Agreement (TEFCA), Health Gorilla enforces governance requirements across TEFCA-aligned exchange and participates in additional nationwide frameworks, including Carequality, CommonWell, and eHealth Exchange. Governance is applied consistently across networks while respecting framework-specific rules, participant roles, and transaction types.

Purpose of Governance

Nationwide interoperability depends on shared rules and enforceable trust. Governance establishes the policies and oversight mechanisms that determine:

  • Who is eligible to participate in exchange
  • Which purposes of use are permitted
  • How data may be requested, shared, and contributed
  • What reciprocity or contribution obligations apply
  • How compliance is monitored and enforced

These controls protect patient privacy, promote responsible data sharing, and ensure that exchange activity remains predictable and auditable across organizations and networks.

Governance Scope

Health Gorilla's governance model spans multiple trust frameworks rather than relying on a single exchange model. While requirements vary by framework, governance consistently addresses:

  • Participant onboarding and eligibility
  • Credentialing and identity verification
  • Permitted purposes of use, most commonly treatment
  • Role-based responsibilities for requestors and responders
  • Audit and accountability requirements

Governance applies to all exchange activity routed through the platform, regardless of integration method or product workflow.

Participation Expectations

Organizations participating through Health Gorilla are expected to meet baseline requirements that support trusted and reciprocal exchange.

Typical expectations include:

  • Executing participation agreements with Health Gorilla and applicable exchange frameworks
  • Ensuring that all data requests align with permitted purposes of use
  • Maintaining compliance with the Health Insurance Portability and Accountability Act (HIPAA), TEFCA, and other applicable regulations
  • Contributing clinically meaningful data when required by the participation model or governing framework

Specific obligations depend on organizational role, enabled workflows, and applicable network rules.

Reciprocity and Contribution Alignment

Most nationwide exchange frameworks are built on reciprocity. Organizations that retrieve external clinical data are generally expected to contribute data in return, subject to framework rules and technical capability.

Health Gorilla aligns contribution behavior with the applicable trust framework by:

  • Enforcing contribution requirements based on participant role and configuration
  • Routing contributed data through the appropriate exchange network
  • Applying consistent validation, normalization, and provenance controls

This alignment ensures that retrieval and contribution obligations remain balanced and transparent across participating organizations.

Responder-Only Participation

Some organizations participate as responders without initiating outbound record retrievals. Where permitted by the governing framework, Health Gorilla supports responder-only participation models.

Responder-only participants:

  • Make data available for inbound queries from authorized requestors
  • Do not initiate outbound retrievals
  • Remain subject to the same governance, auditability, and compliance requirements as other participants

Responder-only configurations are enforced at the platform level to ensure consistent behavior and traceability.

Oversight and Compliance

Health Gorilla monitors exchange activity and enforces governance requirements through auditing, reporting, and corrective action processes aligned with applicable frameworks.

Oversight activities include:

  • Logging and auditability of all exchange activity
  • Periodic compliance reviews or reviews triggered by identified issues
  • Remediation requirements for noncompliance
  • Suspension or termination of participation for serious or unresolved violations
  • Required reporting and attestations to governing bodies, including the Recognized Coordinating Entity (RCE), where applicable

These measures help maintain trust, accountability, and regulatory alignment across nationwide interoperability networks.


What’s Next