Preprint
Article

This version is not peer-reviewed.

Who Governs the Endpoints? Pharmacy Data, Patient Autonomy, and the Governance of AI-Mediated Health Information Exchange

Submitted:

10 July 2026

Posted:

30 July 2026

You are already at the latest version

Abstract
Federal policy has made standardized application programming interfaces (APIs) the backbone of health information exchange (HIE), and pharmacy is increasingly a full participant through electronic prescribing, the pharmacist electronic care plan, and emerging FHIR-based clinical documentation. Proposals for artificial-intelligence (AI) systems capable of querying electronic health records and pharmacy management systems through such interfaces raise pressing questions about patient autonomy and privacy. This paper argues that those questions are best understood as questions of governance rather than of transport technology. The effect of API-mediated HIE on autonomy is bimodal: a patient-mediated architecture, in which the individual authorizes access, functions as an instrument of data portability and exit and is strongly autonomy-enhancing, whereas an institution-mediated architecture, in which the patient is the object rather than the principal of exchange, tends to erode the interests it nominally serves. Drawing on the political economy of pharmacy intermediation, the semantics of medication data, and the law-and-economics of entitlements, the analysis explains why institutional incentives favor the second path absent deliberate design, and proposes six governance principles: (1) first-class individual access; (2) regulation of inferences as protected health information; (3) query visibility; (4) judicial authorization for state access; (5) provenance; and (6) prevention of single-point choke points. These principles are directed at keeping the pharmacist and the patient the principals of an exchange conducted in the patient's name.
Keywords: 
;  ;  ;  ;  ;  ;  ;  ;  ;  

1. Introduction

Community pharmacy is no longer only a dispensing enterprise. Pharmacists increasingly deliver and document clinical services—medication therapy management, immunization, point-of-care testing, and chronic-disease support—and the infrastructure for sharing that work is maturing. Electronic prescribing over the National Council for Prescription Drug Programs (NCPDP) SCRIPT standard is universal. The Pharmacist electronic Care (eCare) Plan provides a structured, shareable record of pharmacist assessments and interventions; and Health Level Seven (HL7) Fast Healthcare Interoperability Resources (FHIR) interfaces, mandated for certified electronic health record (EHR) systems under the 21st Century Cures Act, are extending computable medication data across settings [1,2,3]. The aspiration behind these developments is both practical and sound, and includes better-coordinated care, fewer duplicative or conflicting therapies, more complete medication reconciliation, and a practical ability for patients to assemble and direct their own records [4,5].
Against this backdrop, proposals have emerged for artificial-intelligence (AI) systems capable of querying EHRs and pharmacy management systems through standardized interfaces—mining medication histories, dispensing records, and clinical notes at scale to support care and to settle remuneration. Such a system might be operated by a neutral intermediary functioning as a conduit rather than a repository, with vetted and licensed users restricted to pharmacists and pharmacies acting for clinical and payment purposes. These design choices are sensible starting points, and they foreclose several of the most obvious risks. They do not, however, settle the questions that matter most, because those questions arise at a different level than the technology.
Most discussion of medication-data privacy proceeds at the level of the individual record and the discrete transmission: was a disclosure authorized, was a data set properly de-identified, did a transfer satisfy minimum-necessary requirements? Those questions remain important, but the consequential ones now concern governance—who may query the system, for which purposes, with what visibility to the patient, and with what recourse when an inference drawn from medication data is wrong or is turned to a use the patient never anticipated? These are questions about the rules that govern endpoints, not about any single packet of data in motion.
This paper advances three claims. First, the risk that API-mediated exchange poses for patient autonomy and privacy is not fixed by the transport standard. It is bimodal, and which mode obtains depends on design choices now being made in technical specifications and administrative procedures that few pharmacists and fewer patients will ever read. Second, the two modes can be named. In a patient-mediated architecture, the individual holds the authorization keys, and the interface serves data portability and exit, on balance the most autonomy-enhancing development in health information in a generation. In an institution-mediated architecture, access runs among payers, intermediaries, and providers with the patient as the object rather than the principal of exchange, and this architecture, left undesigned, tends to erode the autonomy it is meant to serve. Third, the political economy of pharmacy predictably favors the second path unless the first is deliberately protected, because the parties who benefit from comprehensive institutional access are concentrated and organized while the patients and independent practices that bear the diffuse costs are not [6].
The argument proceeds as follows. Section 2 establishes the baseline against which any pharmacy API should be measured. Section 3 isolates what an AI-mediated interface genuinely changes. Section 4 examines the semantic layer of medication data, where inference quality and contestability are determined. Section 5 turns to the political economy of pharmacy intermediation. Section 6 develops the distinction between the pharmacist and patient as principals and the patient as object and locates it in a live regulatory controversy. Section 7 offers governance principles, and Section 8 concludes. The throughline is that the interface is the least decisive variable in the system and the governance of endpoints the most decisive.

2. The Baseline: Medication Data Already Circulate Widely

A common intuition holds that medication data are private by default and that each new mode of exchange incrementally erodes that privacy. For the data most relevant here, the intuition is largely mistaken, and beginning with it distorts the assessment. Prescription and claims data have been aggregated and commercialized at scale for decades through pharmacy switches, clearinghouses, and data vendors, and the practice enjoys substantial constitutional protection. In Sorrell v. IMS Health, the Supreme Court held that a Vermont statute restricting the sale of prescriber-identifiable prescribing data burdened protected speech, effectively constitutionalizing an established market in such information [7]. Whatever one makes of that decision, it describes the actual baseline. A substantial secondary market in medication-related data already operates, largely outside the patient's awareness.
The federal privacy framework constrains this baseline less than is often assumed. The Health Insurance Portability and Accountability Act (HIPAA) permits disclosures for treatment, payment, and health care operations without individual authorization, and these permitted purposes function in practice as a broad default rule of disclosure among covered entities and their business associates [8]. HIPAA's reach is defined by the status of the entity holding the data rather than the sensitivity of the data itself; once medication information passes to an entity that is neither a covered entity nor a business associate, the residual protections are a patchwork of Section 5 of the Federal Trade Commission Act and uneven state law [9]. The resulting coverage gaps and the regulatory arbitrage they invite are well documented, as health-relevant inference migrates toward the least-regulated holders [10].
Two implications follow. The first is comparative: because the existing environment is one of extensive institutional flow rather than robust privacy, the meaningful comparison for any proposed pharmacy API is not exchange versus privacy but which pattern of access. A standardized interface can entrench the prevailing asymmetry, in which large institutional actors hold the most complete longitudinal picture of a patient's medication use and the patient holds the least, or it can begin to correct that asymmetry by giving the patient a practical means of assembling and directing the same data. The transport layer is compatible with either outcome; governance decides between them.
The second implication concerns contextual integrity. Even where each disclosure is lawful, the aggregate flow can breach the norms under which patients furnished their information. Information disclosed to fill a prescription carries expectations about onward use that are violated when it is recombined for unrelated analytic purposes, regardless of whether any single transfer was permitted [11]. The unit of analysis must therefore move from the discrete transmission to the pattern of use, precisely the level at which endpoint governance operates.

3. What an AI-Mediated Interface Actually Changes

Since medication data already circulate, what does an AI-mediated interface genuinely change? Three shifts are analytically distinct and consequential.
The first is the decline of practical obscurity. Friction has functioned as an unplanned privacy protection: assembling a complete longitudinal medication record for one patient was costly enough that comprehensive assembly was done in bulk and approximately rather than precisely and on demand. Standardized interfaces drive the marginal cost of individual-level, on-demand assembly toward zero. That protection was never principled, and its erosion is partly the point of interoperability; however, it should be recognized, because removing it converts a theoretical capacity for comprehensive assembly into an operational one [12]. The same reduction in friction that lets a patient consolidate a scattered medication history into one application lets an institutional actor do so as well, and governance must decide which actors gain the capability and under what constraints.
The second shift is from records to inferential capacity. When data are exposed in computable form, the meaningful unit of exposure is no longer the document but the set of inferences derivable from it, and dispensing data are unusually inference-dense. A fill history can support reasonably confident inferences about diagnosis, prognosis, reproductive status, and behavioral-health treatment with no clinical narrative attached [13]. Consent and minimum-necessary frameworks were built to govern the release of records. They have little to say about the release of inferential capacity, and that gap is where durable concern resides. The point is not that inference is illegitimate—much of it is clinically valuable, and pharmacists rely on it daily—but that an inferred attribute can follow a patient into insurance, employment, and other settings while enjoying few of the protections that attach to the underlying record.
The third shift is the persistence of infrastructure beyond its originating purpose. Capabilities built for one objective remain available for objectives that attach later. Prescription drug monitoring programs are the most studied instance in pharmacy: designed as clinical tools to inform dispensing, they became, in many jurisdictions, instruments of law-enforcement access, often without the warrant that comparable information would otherwise require [14]. The post-Dobbs environment has made the general phenomenon concrete for medication histories, which acquire evidentiary salience in unrelated proceedings. Constitutional doctrine has begun to register the difficulty. In Carpenter v. United States, the Court declined to extend the third-party doctrine to comprehensive cell-site location records, citing their depth and involuntariness [15]. A longitudinal medication history assembled through a standardized interface shares those features, which suggests that the warrant question for such records is open rather than settled. None of this discussion counsels against building the infrastructure, but it counsels designing the governance of access before later uses are determined by whoever later demands them.
These observations bear directly on the conduit framing. An interface that merely transmits is, under HIPAA, a narrow category. However, the moment a system parses, normalizes, matches, and runs inference, it is using protected information rather than merely moving it, and the operator is a business associate with full obligations regardless of whether data are retained [8]. “No storage,” moreover, is a spectrum. Caches, logs, and—above all—any data used to train or tune the AI layer constitute retention, since a model that improves from the data passing through it has stored that data in its parameters. Even a true conduit accumulates the query graph—which pharmacy queried which patient, when, and how often—and for medication data that traffic pattern is independently revealing, exposing sensitive treatment without a single clinical datum being retained.

4. The Semantic Layer of Medication Data

Beneath the legal and economic questions lies a technical substrate central to the autonomy stakes and especially consequential in pharmacy. The semantic layer at which heterogeneous medication data are mapped into common form so that inference can operate. Pharmacy management systems represent drugs and directions using NCPDP transaction standards with RxNorm and National Drug Code (NDC) identifiers, while EHRs encode medications and problems using Health Language 7 (HL7) and FHIR US Core profiles with SNOMED CT and LOINC, frequently supplemented by local codes [1,16]. An AI system consuming both must reconcile these representations, and the reconciliation is imperfect in ways pharmacists will recognize.
Several failure modes are routine. Directions for use require normalization that is frequently approximated or worse, leaky. Compounded preparations often lack clean RxNorm concept identifiers. Value sets for clinically important constructs such as drug therapy problems remain immature and inconsistently applied, so that the same problem is coded differently, or not at all, across systems [17]. Medication lists conflate ordered, dispensed, discontinued, and administered states, so that what a model reads as a single coherent regimen may be an artifact of four different recording conventions. A pharmacist interprets these as artifacts to be reconciled with clinical judgment. A model trained on the same data is liable to encode them as ground truth and to emit adherence flags, risk scores, or diversion predictions that carry an unearned appearance of objectivity [18].
The governance consequence is that control of the mapping is, increasingly, control of the inference. The crosswalks among NCPDP, RxNorm, NDC, and the EHR terminologies, and the value sets that define constructs such as drug therapy problems, are the point at which medication data become computable. Whoever maintains them as a proprietary asset rather than a shared resource holds a quiet but decisive form of power over what the data are taken to mean. Work to standardize the community-based pharmacy clinical record and to convert pharmacist documents such as the Pharmacist Consultation Note and the electronic care plan between Consolidated Clinical Document Architecture and FHIR representations is, in this light, not merely technical housekeeping. It determines whether pharmacist-generated knowledge is faithfully represented or systematically distorted as it crosses system boundaries [2,3].
These dynamics reflect the dispersed and contextual character of clinical knowledge. Hayek's observation that the knowledge relevant to economic life is local rather than concentrated applies directly. An inference engine operating across many pharmacy and clinical systems confronts exactly the aggregation problem Hayek described, and the mapping artifacts it must resolve are the informational analogue of the unique circumstances of time and place [19]. They also situate pharmacy data within the broader transformation that Stehr termed the “knowledge society,” in which specialized knowledge becomes the primary structuring resource and the rules governing its control become correspondingly consequential [20]. The present author has examined elsewhere how this framework applies to genomic medicine, where probabilistic risk classification reorganizes the relationship between individuals, their information, and institutional authority, and where the governance of knowledge—rather than the science itself—determines whether the result enhances or diminishes autonomy [21]. The same holds for medication data where the locus of value, and therefore of contest, is migrating from the data to the inferential layer built upon them.
A final requirement at this layer is provenance. A system that maps and matches in transit but retains nothing leaves no record of the transformations it applied, so an erroneous inference cannot be traced to its source. For a pharmacist acting on a system's output—adjusting therapy, declining a fill, flagging an interaction—the difference between a defensible clinical decision and an unexaminable one is the availability of a provenance trail. This constitutes a signed record of what transformation produced a given result, returned with the result even when the underlying data are not retained. Provenance is the precondition of contestability, and contestability is the precondition of accountability.

5. Political Economy: Benefit Managers, Vendors, and the Pharmacist as Intermediary

Why predict that, absent deliberate design, the institution-mediated path will prevail? The answer lies in a familiar structure of collective action. The benefits of comprehensive institutional access concentrate on a small number of organized actors—pharmacy benefit managers (PBMs), large pharmacy-system vendors and networks, and analytics firms—each with the resources and incentive to shape the rules. The costs fall diffusely on patients and on independent and community practices that lack the means to participate in standard-setting or rulemaking. Olson's analysis predicts that the concentrated interest will systematically outcompete the diffuse one in such settings, and the prediction is not cynical. It follows from the asymmetric returns to organizing [6]. Stigler's account of regulation as a good that organized interests acquire describes the same dynamic from the supply side [22].
Several features of the pharmacy landscape illustrate the dynamic without imputing any bad faith. Consider the designated intermediary. A framework that channels exchange through a small number of qualified networks creates a natural point of leverage, and the governing rules can favor incumbents. The Trusted Exchange Framework and Common Agreement (TEFCA) includes a manner exception under which an actor's decision to fulfill a request only through a qualified network is not treated as information blocking when certain conditions are met, an exception unavailable, by its terms, when the requestor is an individual seeking data outside the network [23]. Whatever its rationale, the structural effect is to privilege institution-to-institution exchange over patient-directed access, and the point generalizes. Certification and conformance requirements reasonable in isolation can, in aggregate, function as a moat that only well-capitalized participants cross, a particular hazard for independent pharmacies operating on thin margins.
A second feature is the licensing paradox. Vetting participants addresses a genuine problem, which is the risk of bad actors gaining access to sensitive data. But a credential that becomes the practical precondition for participating in modern pharmacy data exchange is also a gate, and gates can be operated to competitive advantage. If access to longitudinal medication data through a particular conduit becomes the effective means of practicing contemporary pharmacy, then eligibility criteria, fee schedules, and technical conformance become instruments that can include or exclude. The safeguard and the barrier are the same mechanism seen from two sides. A design that takes the safeguard seriously must take the barrier seriously too, through transparent and cost-based fees, non-discrimination requirements, and a meaningful appeals process.
A third feature is purpose expansion through the payment aperture. Exchange for clinical care is a reasonably bounded purpose. Exchange for remuneration is not, because it imports the full apparatus of utilization management, eligibility verification, adherence measurement, and network performance scoring. Recent rulemaking extending certified-interface requirements into electronic prior authorization and real-time prescription benefit transactions wires payment-purpose flows into the same endpoints that carry clinical exchange [24]. The licensed users of such a system may be pharmacists, but contractual obligations to payers can make them compelled intermediaries. A benefit manager need not hold a license itself if its network agreements require participating pharmacies to run targeted queries and report the results. Effective purpose limitation must therefore bind the downstream use of outputs, not merely the point of access, or the restriction of access to pharmacists becomes a formality rather than a constraint.
None of this implies that intermediaries, credentials, or payment-related exchange are illegitimate. Each serves a real function, and the claim is narrower. The institutional incentives in pharmacy run predictably toward concentration and toward the institution-mediated architecture, so a governance regime that wishes to preserve the patient-mediated architecture—and to protect the pharmacist's standing within it—must do so by design rather than by trusting that it will emerge on its own.

6. Two Architectures: The Pharmacist and Patient as Principals Versus the Patient as Object

The autonomy consequences of API-mediated exchange turn on a single distinction: whether the patient is the principal who directs the flow of data or the object about whom data flows among other parties. The distinction corresponds to different technical arrangements, default rules, and distributions of control, and it is the variable that most determines whether a system enlarges or contracts autonomy.
In a patient-mediated architecture, the individual authorizes an application to retrieve their data and to share it as they choose. The Cures Act individual-access right and the SMART authorization framework make this concrete. A patient can, in principle, take their complete medication history to any pharmacist or clinician without seeking an institution's permission for each transfer [4,25]. Understood correctly, this is data portability functioning as an exit right, and it is strongly autonomy-enhancing. Its significance is clearest against the baseline of Section 2. The realistic alternative to patient-directed flow is not the absence of flow but its monopolization by the institutional actors already equipped to assemble it. A regime without robust individual access is not more private. It is one in which the patient has the least access to their own medication information of any party in the system.
The pharmacist occupies a revealing dual position in this architecture. As a licensed clinical user, the pharmacist is precisely the kind of trusted professional to whom a patient might rationally delegate the assembly and interpretation of their medication record as an agent of the patient's autonomy. As a party bound by network contracts, the same pharmacist can be enlisted as a conduit through which payers obtain and act upon medication intelligence. Which role predominates is not determined by the pharmacist's intentions but by the governance of the system, that is, whether the queries the pharmacist runs serve the patient before them or reports upward to parties the patient cannot see.
In an institution-mediated architecture, by contrast, data moves among payers, intermediaries, and providers according to permitted purposes, with the patient typically absent from and unaware of the transaction. Because treatment and payment are permitted purposes, the legal baseline for such exchange is patient silence rather than consent. A system that assembles cross-institutional medication intelligence about a person, queryable on demand by any credentialed participant, differs in kind from the occasional faxed record it replaces, and patients are likely to experience it as different once they become aware of it. Szasz's critique of the medicalization of social control, whatever one makes of its broader claims, supplies a useful caution. An information architecture that a person can neither see into nor exit raises autonomy concerns regardless of the benevolence of its stated purpose [26]. The caution does not condemn institutional exchange, much of which is necessary and beneficial. It identifies the features, opacity to the patient and the absence of an exit, that convert beneficial exchange into something harder to justify.
A current controversy shows how live these questions are. The entity administering the national exchange framework (TEFCA) has proposed a revised standard operating procedure for individual access that would modify the patient-matching methodology used to fulfill individual requests. Provider organizations have urged delay, citing the risk of misidentification and unauthorized disclosure and their own obligations to verify identity before releasing protected information [27]. The disagreement is genuine and the patient-safety concerns are not pretextual. But the episode also shows a recurring pattern worth naming neutrally. Arguments framed in the vocabulary of protecting patients can operate, in effect, to slow patient-directed access while leaving institution-to-institution exchange comparatively unencumbered. The design of such procedures is where the balance between the two architectures is struck, and these technical instruments deserve the scrutiny ordinarily reserved for primary legislation.
Mill's harm principle offers a serviceable organizing distinction [28]. Flows that a competent patient directs over their own medication information are, in the relevant sense, self-regarding, and the presumption should favor enabling them. Flows directed at a patient by third parties, for those parties' purposes, are other-regarding and call for justification proportional to their consequences. Contemporary exchange-purpose frameworks do not draw this line cleanly. They treat patient-directed access as one purpose among several rather than as the presumptively favored case. Redrawing the line so that patient-directed flow is first-class, and institution-directed flow the case requiring justification, would align the governance of endpoints with the autonomy interests the system is meant to serve.

7. Governance Principles for Pharmacy Data Exchange

Pharmacy is a rule- and regulation-governed profession, plausibly the most rule-dense of all the clinical professions. Public protection is the statutory purpose of its practice acts, and patient welfare and advocacy are the stated commitments of its code of ethics. These are commitments the profession must vindicate institutionally, in precisely the rule-writing venues this section describes, rather than presume. Since the decisive choices are made at the level of rules, the constructive task is to specify the rules well. Buchanan's distinction between the constitutional stage, at which the rules of an order are chosen, and the operational stage, at which choices are made within them, frames the task precisely [29]. Pharmacy data governance is at a constitutional moment in this sense. The standard operating procedures, certification criteria, and licensing charters now being drafted will structure the operational choices of all who later participate. Treating these instruments as technical minutiae forfeits the constitutional stage to whoever happens to be in the room, which, for the reasons in Section 5, will tend to be the concentrated interest.
That this constitutional moment is unfolding largely out of public view can be stated institutionally rather than rhetorically. The operative rules of pharmacy data exchange are made in at least three venues that sit outside ordinary administrative process. First, technical standards drafted by private standards development organizations acquire legal force through incorporation by reference. Medicare Part D regulations designate specific versions of the NCPDP SCRIPT standard for electronic prescribing, and certification regulations adopt designated versions of the United States Core Data for Interoperability (USCDI) and FHIR-based interface specifications [30]. The balloting that shapes those texts occurs within member-funded organizations whose participants are predominantly vendors, payers, and processors. The resulting standards, though binding in effect, are in some cases available only to members or purchasers, a practice administrative-law scholars have criticized as placing access to binding law under private control [31]. Second, the procedures of the national exchange framework, including the standard operating procedure discussed in Section 6, are drafted and revised by a private coordinating entity without notice-and-comment rulemaking [27]. Third, the participation and licensing agreements that govern access to exchange networks are contracts visible chiefly to their signatories. None of these venues is illegitimate. Each exists for sound reasons of expertise and flexibility. Their combined effect, however, is that rules carrying first-order consequences for patient autonomy are adopted with a fraction of the participation and scrutiny that accompanies ordinary regulation, and the parties present in those venues are, for the reasons given in Section 5, the concentrated interests.
Two framings from law-and-economics help specify the entitlements at stake. Calabresi and Melamed's distinction between property rules, which require the holder's consent before an entitlement may be taken, and liability rules, which permit the taking subject to compensation, clarifies what HIPAA's permitted-purposes regime does. It operates as a liability rule, or less, allowing use without individual consent and generally without compensation [32]. Whether a property rule—ex ante patient authorization—is feasible depends on transaction costs, and here Coase's analysis is relevant because the two architectures differ dramatically in those costs [33]. Institution-mediated exchange achieves low transaction costs precisely by routing around the patient. In contrast, patient-mediated exchange, enabled by standardized individual-access interfaces, lowers the cost of obtaining consent enough to make a property-rule arrangement practical for a far wider range of uses than before. The initial assignment of the authorization right is therefore not neutral. It determines which architecture the system's default favors.
From these premises, five principles follow. First, individual access should be treated as a first-class right rather than one exchange purpose among many, with conformance requirements and fees that do not disadvantage patient-directed retrieval relative to institutional exchange. Second, inferences and derived classifications—adherence scores, risk flags, diversion predictions—should be governed as protected health information, so that a classification derived from protected data does not escape the protections attaching to the data from which it was produced. Third, query infrastructure should be visible to the patient, who should be able to learn who queried their medication information, when, and for what stated purpose, because visibility is the minimal precondition of accountability. Fourth, government and law-enforcement access to comprehensive longitudinal medication records assembled through these systems should require a warrant rather than a subpoena or administrative request, consistent with the direction of Carpenter and the sensitivity of the data. Fifth, no single intermediary should become an uncontestable choke point. This counsels common-carriage-style non-discrimination obligations and, more broadly, the polycentric governance that Ostrom's work commends—multiple overlapping centers of authority with monitoring, graduated sanctions, and avenues for contestation—rather than either a single state monopoly or a single private one [34].
These principles describe a recognizable architecture. First, authorization keys are held by the patient or at the point of care rather than at the network core. Second, each substantive transformation returns a signed provenance record even when the payload is not retained; the terminology crosswalks and value sets on which inference depends are maintained as a shared resource rather than a proprietary moat. Third, any neutral intermediary is structured for durable neutrality through cooperative governance and a prohibition on monetizing derived analytics. And foirth, restrictions on the use of outputs bind downstream payers by contract rather than stopping at the point of access. The standards work already under way in the pharmacy community—rubrics for the community-based pharmacy clinical record, FHIR implementation guides for pharmacist documents, and Connectathon testing—supplies the practical vehicle through which such principles can be embedded rather than merely asserted [2,3]. An architecture exhibiting these features would deliver the genuine benefits of interoperability while keeping the pharmacist and the patient the principals of the exchange; an architecture lacking them would deliver the same clinical conveniences while relocating control of the patient's medication record to the network's center.

8. Conclusions

The technology of pharmacy data exchange is, for present purposes, settled, however, the political economy of its governance is not. An API, including one mediated by AI, is compatible with an architecture that makes the patient the principal of their medication record and with one that makes the patient its object. The difference will be determined not by the transport standard but by the rules that govern endpoints. These rules are now being written in NCPDP and FHIR specifications, certification criteria, exchange-framework procedures, and licensing charters that attract little attention. That obscurity is itself the governance problem. The choices with the largest consequences for patient autonomy are being made in the instruments least subject to scrutiny, by the parties most organized to shape them.
The constructive response is neither to resist interoperability nor to assume its benefits will distribute themselves well, but to take the design of endpoint governance as seriously as the design of the interfaces by (1) treating individual access as a first-class right; govern inferences as PHI; (2) making query infrastructure visible to the patient; (3) requiring a warrant for government access to comprehensive records; and (4) preventing any single intermediary from becoming an uncontestable choke point. These principles do not obstruct the gains interoperability promises. They ask only that the pharmacist and the patient remain the principals of an exchange conducted in the patient's name, which is, in the end, the difference between an infrastructure of access and an infrastructure of accountability. The same logic animates the case for graduated medication access developed elsewhere. In both domains, the alternative to patient control is not the absence of a system but its control by others [35].

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Data Availability Statement

No new data were created or analyzed in this study.

Acknowledgments

During the preparation of this manuscript, the author used Claude Opus 4.8 (Anthropic, San Francisco, CA, USA) for structuring and drafting portions of the text, for formatting in-text citations and references according to MDPI style, and for organizing the reference list. The author has reviewed and edited the output and takes full responsibility for the content of this publication.

Conflicts of Interest

The author declares no conflicts of interest. The author chairs the Pharmacy Health Information Technology (PHIT) Pharmacy Systems Interoperability Work Group and holds committee roles related to pharmacy health information standards. These affiliations inform but do not financially benefit from the views expressed.

References

  1. Office of the National Coordinator for Health Information Technology. 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program. Fed. Regist. (Codified at 45 C.F.R. pts. 170, 171.). 2020, 85, 25642–25961. [Google Scholar]
  2. National Council for Prescription Drug Programs; Health Level Seven International. Pharmacist eCare Plan and SCRIPT Standard Implementation Specifications; NCPDP: Scottsdale, AZ, USA; HL7: Ann Arbor, MI, USA, 2023. [Google Scholar]
  3. Health Level Seven International. HL7 FHIR US Core Implementation Guide. HL7: Ann Arbor, MI, USA, 2023. Available online: https://www.hl7.org/fhir/us/core/ (accessed on 10 June 2026).
  4. Mandel, J.C.; Kreda, D.A.; Mandl, K.D.; Kohane, I.S.; Ramoni, R.B. SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. J. Am. Med. Inform. Assoc. 2016, 23, 899–908. [Google Scholar] [CrossRef] [PubMed]
  5. Mandl, K.D.; Kohane, I.S. Escaping the EHR trap—the future of health IT. N. Engl. J. Med. 2012, 366, 2240–2242. [Google Scholar] [CrossRef] [PubMed]
  6. Olson, M. The Logic of Collective Action: Public Goods and the Theory of Groups; Harvard University Press: Cambridge, MA, USA, 1965. [Google Scholar]
  7. Sorrell, v. IMS Health Inc., 564 U.S. 552. 2011. [Google Scholar] [CrossRef]
  8. U.S. Department of Health and Human Services. Standards for Privacy of Individually Identifiable Health Information. 45 C.F.R. § 164.506 (uses and disclosures for treatment, payment, and health care operations). see also 78 Fed. Regist. 5566 (2013) (conduit exception).
  9. Cohen, I.G.; Mello, M.M. HIPAA and protecting health information in the 21st century. JAMA 2018, 320, 231–232. [Google Scholar] [CrossRef] [PubMed]
  10. Terry, N.P. Regulatory disruption and arbitrage in health-care data protection. Yale J. Health Policy Law. Ethics 2017, 17, 143–208. Available online: http://hdl.handle.net/20.500.13051/5941. [PubMed]
  11. Nissenbaum, H. Privacy in Context: Technology, Policy, and the Integrity of Social Life; Stanford University Press: Stanford, CA, USA, 2010. [Google Scholar]
  12. Solove, D.J. A taxonomy of privacy. Univ. Pa. Law. Rev. 2006, 154, 477–564. [Google Scholar] [CrossRef]
  13. Price, W.N., II; Cohen, I.G. Privacy in the age of medical big data. Nat. Med. 2019, 25, 37–43. [Google Scholar] [CrossRef] [PubMed]
  14. Oliva, J.D. Prescription-drug policing: the right to health information privacy pre- and post-Carpenter. Duke Law. J. 2020, 69, 775–853. Available online: https://scholarship.law.duke.edu/dlj/vol69/iss4/1.
  15. Carpenter v. United States, 138 S. Ct. 2206. 2018.
  16. U.S. National Library of Medicine. RxNorm; NLM: Bethesda, MD, USA, 2024. Available online: https://www.nlm.nih.gov/research/umls/rxnorm/ (accessed on 10 June 2026).
  17. Cipolle, R.J.; Strand, L.M.; Morley, P.C. Pharmaceutical Care Practice: The Patient-Centered Approach to Medication Management, 3rd ed.; McGraw-Hill: New York, NY, USA, 2012. [Google Scholar]
  18. Pasquale, F. The Black Box Society: The Secret Algorithms That Control Money and Information; Harvard University Press: Cambridge, MA, USA, 2015. [Google Scholar]
  19. Hayek, F.A. The use of knowledge in society. Am. Econ. Rev. 1945, 35, 519–530. [Google Scholar]
  20. Stehr, N. Knowledge Societies; Sage: London, UK, 1994. [Google Scholar]
  21. Parrish, R.H., II. Genomic medicine and individual autonomy: reflections on knowledge societies and governmentality. Int. J. Environ. Res. Public Health 2026, 23, 234. [Google Scholar] [CrossRef] [PubMed]
  22. Stigler, G.J. The theory of economic regulation. Bell J. Econ. Manag. Sci. 1971, 2, 3–21. [Google Scholar] [CrossRef] [PubMed]
  23. Office of the National Coordinator for Health Information Technology. Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1). Fed. Regist. 45 C.F.R. § 171.403 (TEFCA manner exception). 2024, 89, 1192–1438. [Google Scholar]
  24. U.S. Department of Health and Human Services. Health Data, Technology, and Interoperability (HTI-4): Electronic Prescribing, Real-Time Prescription Benefit, and Electronic Prior Authorization. Final rule. 2026. Available online: https://www.healthit.gov/wp-content/uploads/2025/08/HTI-4-Final-Rule-Overview-Fact-Sheet_508.pdf.
  25. U.S. Department of Health and Human Services. Individuals' Right of Access to Protected Health Information. In 45 C.F.R. § 164.524.
  26. Szasz, T. Pharmacracy: Medicine and Politics in America; Praeger: Westport, CT, USA, 2001. [Google Scholar]
  27. American Hospital Association. Comment Letter on the TEFCA Individual Access Services Exchange Purpose Standard Operating Procedure, Version 3.0; The Sequoia Project, TEFCA Individual Access Services SOP, Version 3.0 (proposed 2026; implementation slated 2027); AHA: Washington, DC, USA, 24 April 2026. [Google Scholar]
  28. Mill, J.S. On Liberty; John W. Parker and Son: London, UK, 1859. [Google Scholar]
  29. Buchanan, J.M.; Tullock, G.; The Calculus of Consent: Logical Foundations of Constitutional Democracy; Buchanan, J.M. The domain of constitutional economics. In Const. Political Econ.; University of Michigan Press: Ann Arbor, MI, USA, 1962; Volume 1, pp. 1–18. [Google Scholar] [CrossRef]
  30. Centers for Medicare; Medicaid Services. Standards for Electronic Prescribing. 42 C.F.R. § 423.160 (adopting designated versions of the NCPDP SCRIPT standard for Medicare Part D electronic prescribing); see also 45 C.F.R. §§ 170.213, 170.215 (adopting USCDI and FHIR-based application programming interface standards for certification).
  31. Mendelson, N.A. Private control over access to the law: the perplexing federal regulatory use of private standards. Mich. Law. Rev. 2014, 112, 737–809. [Google Scholar] [CrossRef]
  32. Calabresi, G.; Melamed, A.D. Property rules, liability rules, and inalienability: one view of the cathedral. Harv. Law. Rev. 1972, 85, 1089–1128. [Google Scholar] [CrossRef]
  33. Coase, R.H. The problem of social cost. J. Law. Econ. 1960, 3, 1–44. [Google Scholar] [CrossRef]
  34. Ostrom, E. Governing the Commons: The Evolution of Institutions for Collective Action; Cambridge University Press: Cambridge, UK, 1990. [Google Scholar]
  35. Parrish, R.H., II. The Case for a Graduated Medication Access System. In Pharmacy (Basel); under review.
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2026 MDPI (Basel, Switzerland) unless otherwise stated

Accessibility

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings