Onyx Blog
What We Heard at MESC 2026: Medicaid Interoperability, Consent and Trusted Health Data Exchange
At MESC 2026, two things were top of mind for most attendees: implementation of HR-1, and CMS Interoperability.
Many of our conversations about Medicaid interoperability focused on a practical question: what does it take to make health data exchange work across real organizations, networks and workflows?
Consent. Identity. Security. Purpose of use. Attachments. Payer-to-payer exchange.
None of these are new challenges. What stood out was how often they came together in the same conversations — and how much focus there is on building approaches that can work across states, health plans, technology partners and emerging models such as CMS-Aligned Networks.
A few themes stood out.
Consent can’t live only inside a single application or organization.
As payer-to-payer exchange expands, organizations need a way to understand what an individual has authorized as information moves across organizational boundaries.
That was a recurring theme in our MESC discussions, including conversations around payer-to-payer exchange and the FAST Consent approach.
The challenge is not simply capturing consent. It is maintaining the context around that consent — what was authorized, for what purpose and under what conditions — as the data is exchanged.
That becomes even more important as CMS-Aligned Networks and other network-based exchange models bring more participants into the same ecosystem.
The big change we are seeing develop is the transition from transactional consent to durable consent.
Moving data is only one part of interoperability.
Organizations also need confidence in who is requesting information, which organization they represent, what they are authorized to access and why the information is being requested.
Several MESC conversations touched these pieces of the trust model, including IAL2 authentication, FAST Security, organizational identity using verifiable Legal Entity Identifiers (vLEIs), and CMS-Aligned Network requirements.
I’ve written before about this idea of verifiable connectedness — allowing evidence of trusted relationships to travel with an organization rather than rebuilding trust from scratch for every new connection.
That thinking also extends to portable trust credentials and the role technologies such as vLEIs can play in establishing organizational identity across networks.
The more consistently these capabilities can be implemented, the less every state, health plan or technology partner has to establish a new trust model for every connection.
That is where standards around identity, security and purpose of use become just as important as the FHIR APIs carrying the data.
One of the clearest themes from MESC was the need to avoid solving the same interoperability problem differently organization by organization.
That came through particularly strongly in conversations around large healthcare attachments.
Organizations across the ecosystem are confronting the same technical challenges, and there is little value in creating dozens of different implementations to solve them.
Our discussions with the FAST Accelerator reinforced that point. FAST confirmed its intent to move forward with our Attachment Reference Exchange (ARex) draft Implementation Guide, creating an opportunity to establish a more repeatable standards-based approach to large attachment exchange.
The same principle applies to consent, identity and security.
In my recent piece on Completing the Chain of Trust for CMS-Aligned Networks, I looked at how Da Vinci and FAST Security can work together to support scalable payer interoperability. MESC reinforced the practical importance of that work: these components increasingly need to operate together, not as separate implementation exercises.
The more the industry can align around reusable approaches, the easier it becomes to scale interoperability across Medicaid programs, health plans and broader networks.
The takeaway from MESC wasn’t that the industry needs another interoperability framework.
It was that consent, identity, security, purpose of use and standards increasingly have to work together in real implementations.
FHIR provides the mechanism for exchanging data. Consent helps establish what an individual has authorized. Identity and security help establish who is participating. Purpose of use provides context for why information is being requested.
The work is in connecting those pieces.
For Medicaid programs and health plans, the opportunity is to build that infrastructure in ways that can be reused — across payer-to-payer exchange, CMS-Aligned Networks and the next set of interoperability requirements.
That is what will make trusted, standards-based health data exchange work at scale.
See how Onyx helps health plans operationalize CMS interoperability requirements across consent, identity, data exchange and compliance. Assess your current readiness with the Onyx CMS Compliance Readiness Check.