The TEFCAverse was set ablaze the past few days as the Trump administration hired a relative unknown federal IT contractor, Alliance Global Tech, to provide audit, review and compliance support for up to $5.62 million, beating out 3 other unknown firms. This is a somewhat unexpected contract! What does it mean?
Not a Coup
Immediate social media immediately pondered whether this was the ONC pulling the RCE rug out, but this contract is separate and unrelated to the Sequoia Project’s award for TEFCA governance. While the current period does end in August, ONC has renewed Sequoia each of the last two summers and the options run to 2028. Given a ceiling bump landed in May, it seems likely Sequoia rolls forward.
If the raison d'être for this move is not a coup of the queen, what is it? Start with what it isn't: volume. The press releases from the government point to scaling of data exchange as a primary motivator (hitting 1 billion total this summer), but realistically that traffic is still minuscule compared to older networks like Carequality and CommonWell, which routinely see 1.5 billion a month (and rising). A billion cumulative records doesn't summon a federal auditor.
What summons one is conflict. Scaling these networks has come with controversy and conflict. Since the advent of the Epic v. Particle dispute two years ago, we’ve seen tension build and accusations fly in every direction, with QHINs, vendors, and providers each cast as the bad actor depending on who's telling it. And so this move has many catalysts:
Antitrust in the foreground. Particle's subsequent suit against Epic, now past a motion to dismiss, put a federal court behind the question of who gets to gatekeep network access and on what pretext.
Increased focus on information blocking. OIG and ONC's September 2025 enforcement alert promised to intensify enforcement and dedicate new resources, backed by OIG civil penalties of up to $1 million per violation and ONC's power to ban developers from the Certification Program or pull a product's certification.
Organized provider pressure. The January letter from 60-plus health systems demanding independent vetting of participants, fraud monitoring, and a government-run dispute process.
A messy fraud case. Epic’s suit against Health Gorilla alleges shell companies with fake NPIs pulled records through the treatment pathway, a “Hydra” that has spawned nearly a dozen underlying breach cases.
Calls for independent review. Health Gorilla's March letter to ASTP/ONC asked for a federally overseen, industry-funded credentialing authority to centralize participant vetting and monitoring, arguing governance had been left to private actors who are both market competitors and gatekeepers. He later adjusted to an SEC-style policing function (aspirational given the SEC has an annual $1.4 billion budget).
So with information blocking and antitrust on one side of the scale and fraud on the other, the ONC is balancing concerns and appointing an auditor. The language of the official press release is appropriately vague at where the gun is pointed, though:
As ONC identifies any behaviors on the network that are potentially civilly or criminally actionable, including information blocking and fraud, we will refer them to the appropriate Executive Branch agencies for investigation, including the HHS Office for Civil Rights, HHS Office of Inspector General, and the Department of Justice.
So the rationale holds. ONC needs someone to be pounding the pavement, knocking on QHIN doors and asking who's really on the other end of these queries. It's the investigator they chose that gives one pause.
The Unexpected Choice
Alliance Global Tech is not an everyday name in interoperability, nor in health technology. They are a 55-person federal IT contractor whose stated specialties are cybersecurity, cloud, and data analytics, but whose real inventory is credentials. Government is the one industry that can outperform healthare on the acronyms scale and to their credit, AGT holds (roughly) every government adjacent acronym known to mankind:
SBA 8(a): A Small Business Administration program for firms owned by “socially and economically disadvantaged” individuals. It’s the on-ramp: certified firms can receive federal contracts on a set-aside or sole-source basis, without full open competition.
GSA MAS: The GSA Multiple Award Schedule, a pre-negotiated governmentwide catalog. Holding a Schedule means agencies can hand you task orders off the menu instead of running a fresh procurement each time. This is the vehicle the TEFCA order was placed against.
CMMI ML3: Capability Maturity Model Integration, Level 3 (of 5). An appraisal of how standardized and documented a firm’s processes are.
ISO 27001: An international standard for information-security management systems. A credential about having documented security controls in place.
SeaPort NxG: The Navy’s primary vehicle for buying engineering and professional services. A seat at the table, not a meal. AGT holds a spot, but its entire output to date is a single $500 “minimum guarantee” task order, as far as I can tell.
CATS+: Consulting and Technical Services Plus. Worth noting because it’s the odd one out: a State of Maryland master contract, not a federal vehicle.
Their website, previously a glorious fever dream of patriotism, GovCon acronyms, and 2000s era HTML, is rapidly undergoing a somewhat sad AI design slop overhaul, leaving a host of broken links. However, critical to their ambitions regardless of form factor is that they enumerate every and any possible task the government might want.
Their contract history, at least as a prime, is not awe-inspiring. Their twenty-one prior prime awards run to televisions, switches, telephones, YubiKeys, battery backups, and a news-clipping service for the FCC, with a couple of small SAP and SAS orders as the high end. While they claim a long history with the CMS, it’s difficult to find traces of that, especially since their linked case study redirects back to the home page. The TEFCA audit job, at $1.26 million for year one, is several times larger than anything they have previously run as a prime, and the first that asks them to sit in judgment over a national network rather than ship hardware.
Look closer and the actual business shows itself: staffing. The day-to-day, at least as its leadership broadcasts it on LinkedIn, is a wall of recruiter reqs and consultant "hotlists," available bodies advertised by visa status with flexible rates and quick turnaround. The open roles skew to Florida DOT work-program SMEs, Workday testers, IRS Java engineers, and SQL Server DBAs rather than health information exchange, but you have to imagine that will change fast. This is a placement shop: win the vehicle, then source the people to fill it.
Speaking of which, the leadership page filled with NPCs is a power move:
If there was anything to really bring it all home, it’s the case studies, which wander from "Big Data" and "Healthcare in Artificial Intelligence" (quite the order reversal there) to "Tax Planning" and "Inheritance Frameworks," and manage a striking paucity of actual information across all of them:
Two of the healthcare "case studies" are undisguised job postings: the "Medical Assistant" study is a req for a Baltimore physician's office, blood-draws and EKGs, one year of experience.
The "Social Worker" study is stranger still, a youth economic-empowerment program serving 56 rural villages and 280 vulnerable youth across a set of tehsils, with MoUs and an ILO partner.
HIPAA is misspelled as HIPPA, repeatedly, on the site of the firm now auditing compliance for the nation's health data network.
One of Many
Look, I may sound critical, and that’s because I am. However, I’m also pragmatic and the pragmatic reality is that Alliance Global Tech is not an anomaly! Companies of that genus and species are endemic to the Beltway. Peruse a sampling here in awe of the middling design prowess mixed with true stock-photo gravitas:
The federal contracting demimonde may feel odd to the uninitiated civilian eye (including me), but is ultimately a fixture of the GovCon firmament. They exist because federal procurement is (intentionally or not) engineered to produce them by the rules Congress has put in place:
Washington reserves a fat slice of its contract dollars for small and disadvantaged businesses
SBA's 8(a) program and other programs are the on-ramp.
A firm earns the certification, lands a spot on a GSA Schedule, and from there can be handed task orders without a full open competition.
What it sells is eligibility and a clean past-performance record.
Subject-matter depth comes after the award, bolted on through hires and subcontractors who actually know the material. So a shop whose homepage talks cyber, cloud, and data analytics can win a TEFCA audit assignment on Monday and go recruiting for people who know nationwide networks on Tuesday. Inside the Beltway this is unremarkable. It looks strange only from the Puritanical view that we, the private industry bourgeois, hold with our Figma file worship and domain expertise snobbery.
The Upside
So why hand this to an outsider with no health-IT franchise? Because the franchise is the problem.
Every obvious candidate is already a player in the disputes it would referee. The QHINs are the ones being watched. The largest EHR vendor is a plaintiff in one fight and a defendant in another. Sequoia is staffed by industry insiders with history at various health tech companies and has been terrified of rocking the boat with aggressive action in either direction. An auditor drawn from inside the tent inherits loyalties and comes with biases.
Thus a shop like Alliance Global Tech has the one qualification any organization you can think of structurally lacks: no priors. No QHIN relationship to protect, no vendor certification up for renewal, no committee seat, no real history as a customer, a vendor, a partner, or a competitor. For a role whose entire value is neutrality, a blank slate is close to a job requirement. Their neutrality, agnosticism, and ignorance of the past is a plus, not a minus. They can be ONC’s hammer, swung without fear of who is the target.
That is the charitable case. Being unconflicted is one thing, but also being competent is the hurdle they will have to now prove (especially given all the flags). The same detachment that keeps AGT clean also means it arrives knowing nothing about the network it now polices, on the steepest possible curve, in the ugliest and most complex corners of health IT. It seems entirely possible that larger more well-resourced incumbents and shady yet brilliant startups can perhaps outwit an auditor still learning what QHIN stands for.
But we have to have hope! Doing something is better than doing nothing. The government picked a new referee precisely because he has never played the game. We are about to learn whether that was wisdom, or whether ignorance is just ignorance.
Month in Review
Here is the monthly review. As a reminder, this is a regular round-up of the month’s posts and other content to surface things you may have missed across regulation, litigation, interoperability, and beyond.
Articles Published:
N/A
Video Content:
The Information Exchange: What Is Treatment? (Jun 09): Brad, Pryce, and I grade the five-page take-home exam Judge Buchwald handed Particle and Epic, working through what a payer platform is, whether payer/payvider/provider can be cleanly defined, and where treatment ends and operations begins.
Confessions of a Docket Watcher (Jun 25): An AHLA webinar recap with Mel Soliz and Amy Bagge-Smith walking the interop litigation docket since February: the Vyne v. Henry Schein read/write split, the prisoner’s dilemma among Health Gorilla’s sixteen co-defendants, and the Particle/Epic take-home exam.
Regulatory:
The Cold War Ends (Jun 16): On June 9, CMS stood up the Office of Health Technology and Products, consolidating its standards agenda under four groups and a single deputy administrator. The CMS Health Tech Ecosystem now has a hierarchy, staffing, and a mandate, ending the intra-agency cold war and graduating the voluntary pledge drive from side project to institution.
Un-hiding Regulations.gov: I built an open-source Chrome extension that fixes Regulations.gov’s clunky comment browser using data already in the site’s API. I also noted early CMS-0062 comments: King & Spalding laying APA groundwork against a new Open Payments provision, Vertex echoing his Jevons Paradox prior-auth warning, and an anonymous Wisconsin comment praising the administration while knocking Oracle.
Court cases:
Epic v. Health Gorilla: Prisoner’s Dilemma (Jun 05): Epic voluntarily dismissed SelfRx with prejudice, the second of sixteen defendants to exit. Where GuardDog folded under a permanent injunction after admitting a phony treatment purpose, SelfRx walked out insisting it barely touched Carequality, illustrating the collective-defense-against-individual-incentive bind facing the remaining co-defendants.
Fischman v. Epic: The Upset (Jun 10): Judge Fitzwater denied most of Epic’s motion to dismiss in the pro se, AI-assisted products-liability suit, predicting Texas would treat an EHR as a “product” and hold its vendor to a duty of care owed directly to patients. Two twists that should make every software vendor take notes.
The First Information Blocking Expert (Jun 17): IntusCare v. RTZ reaches pretrial with an August trial date and four Daubert motions set for July 2. The one to watch is RTZ’s regulatory expert Traci Creegan: with almost no prior art on what the Cures Act requires in practice, Intus argues much of her methodology is just interpretation of the law.
Custody Is Liability (Jun 23): Judge Beth Phillips denied the bulk of two motions to dismiss in the consolidated Oracle Health breach case, keeping Cerner and a long roster of hospitals in. The reasoning hands patients two routes to sue a vendor directly, and it potentially reaches not just EHRs, but any vendor that has ever signed a BAA.
AADJ v. Epic: The Retreat (Jun 24): AADJ’s opposition to Epic’s MTD demotes the disability and information-blocking counts that gave the case its flavor, leaving a core antitrust play. The surprise is that it cites Fischman’s products-liability win twice as antitrust authority for Epic’s “exclusive and ongoing architectural control.”
Epic Consults the Oracle (June 30): Epic issued a third-party subpoena to Oracle in Texas v. Epic, mostly seeking to show its behavior is standard across EHR vendors. However, the two final requests go further, probing whether Oracle seeded Paxton’s investigation. It wouldn’t be a real defense but would hand Epic a jury bias story and a preview of the State’s evidence.
EHRs:
EHR Access Diagrams: Epic (Jun 08): A layer-by-layer tour of every place the nation’s largest EHR exposes itself to external apps, prompted by reader questions after the May data-program diagrams for Cognizant and PointClickCare.
EHR Access Diagrams: athenahealth (Jun 11): The companion tour of healthcare’s most open ambulatory EHR. athena earns its developer-friendly reputation, but being decoupled rather than truly headless leaves gaps worth mapping.
Half Right About Epic (Jun 18): On Sharp Tech, Ben Thompson cast Epic as the archetype of an incumbent degrading its API just enough to check a box and keep customers locked into system-of-record pricing. Brendan agrees on where this lands but argues Thompson gets the road wrong, given how information blocking reshapes the API equation.
Is Epic’s Garden Plot a Failure? (Jun 22): Epic owns the enterprise (43.7% acute-care share), but the long tail of solo and small practices remains its white whale, chased through Community Connect, Hosting, Sonnet, and now Garden Plot. The SMS page count has crept from 24 to 28 in a year and hasn’t been updated since September, suggesting another miss, though probably not the last attempt.
EpicOps’ Long March to the General Ledger (Jun 26): Epic’s nascent ERP looks unstoppable, but the landscape is fractal, and in ERP land the data gravity and lock-in belong to Workday, Oracle, SAP, and Infor, with Epic the challenger. The modules Epic picked first sidestep those incumbents entirely, clearing the healthcare point solutions wedged between its EHR and the back office.
Industry Analysis
Proxy Access and the Next Quest (Jun 01): With direct patient API access maturing, the next workflow in the queue is equivalent access for designated proxies (family and caretakers). A patient-access on-ramp test surfaced early signs of it taking shape.
Cheerio, TEFCA (Jun 03): Britain’s proposed NHS Modernisation Bill includes a statutory Single Patient Record spanning GPs, hospitals, and social care. Sections 250E and 250F show how much more authority interoperability policy carries when legislation backs it, a useful comparative glance for the US.
The Arena Expands (Jun 12): Abridge skipped the iterative steps and announced an AI-native clinician intelligence platform spanning care delivery, payment, and evidence, with an Eli Lilly check and an NVIDIA-built foundation model. The model drew the headlines, but the bigger move is the land grab across nearly every clinical copilot job-to-be-done, plus a step into the back office. Let the bundle wars begin.
Cross-industry Comparisons:
Know Your Agent (KYA) (Jun 15): Visa Intelligent Commerce gives AI agents tokenized identities on its network, turning an anonymous “bot” into an accountable, trusted customer. Expect EHRs and other systems of record to pursue the same agentic identity layer this year so they can tell sanctioned agents from scrapers and govern, meter, and monetize the traffic.
Other News:
Dissecting Interface Anatomy: Epic vs athenahealth (Zen Healthcare): I’ll be joining James and Marilee to discuss the taxonomy of EHR Access Diagrams I did for Epic and athenahealth and what it means bigger picture for applications on July 22. So make sure to register and listen in.
External Media:
Thing I’m Excited About (HL7): I got interviewed at FHIR DevDays and went hype beast on my favorite two letter acronym ending in “I” - UI.
Posts I Liked:
PDX Health Tech Hangs - June Edition (Chris Brereton): My colleague and good friend Brad visited Portland in early June, so we got the crew in Portland together at Wayfinder Brewery. Make sure to message if you or anyone you know might be interested in joining the next meetup!































but bro....
99.9%
SYSTEMS UPTIME SLA