
CMS’s launch of the Medicare App Library marks an important step forward for consumer-directed healthcare. For years, interoperability efforts across the industry focused primarily on enabling patients to access and share their health information more easily. The App Library reflects how far the industry has come in making that vision more practical and accessible.
It also signals a broader shift. Health data is increasingly moving beyond traditional provider and payer environments into a growing network of digital health applications and consumer-facing tools. As that happens, conversations around interoperability are naturally expanding beyond access alone to include transparency, accountability, privacy, and trust.
Moving Beyond Access
The Medicare App Library has the potential to help patients better understand and evaluate digital health applications available to them. That is a meaningful development for healthcare consumers, developers, providers, and payers alike.
Standards such as FHIR have helped create the technical foundation for this kind of application-based access at scale. CMS deserves credit for continuing to advance patient access initiatives and supporting greater portability of health information across the healthcare ecosystem.
At the same time, easier access to data also creates new questions for organizations participating in consumer-directed exchange. Once health information begins moving between multiple applications, platforms, and third-party services, it becomes increasingly important to establish clear expectations around transparency and responsible data use.
The Role of the CARIN Code of Conduct
The CARIN Code of Conduct was developed to help address part of that challenge by establishing expectations for organizations participating in consumer-directed exchange. The Code focuses on areas such as transparency, privacy practices, and responsible handling of consumer data.
That kind of guidance is important as the digital health app ecosystem continues to expand. Patients and healthcare organizations alike benefit from greater consistency around how applications communicate data practices and operational expectations.
Accreditation programs can help build on that foundation by assessing conformance to the CARIN Code requirements. Programs such as those offered through DirectTrust provide independent validation against the criteria established within the Code itself, helping create additional trust signals for organizations and consumers evaluating app participation in the marketplace.
Importantly, accreditation against the CARIN Code is not intended to evaluate every aspect of application security or privacy risk nor should any single accreditation be viewed as a universal measure of overall application trustworthiness. Healthcare organizations continue to operate in a highly dynamic threat environment, and different assurance programs evaluate different aspects of operational, security, privacy, and governance maturity.
Additional accreditation and assessment programs, including Privacy and Security accreditations, Health App accreditations, and HITRUST Assessments, can build on this foundation to provide broader oversight and evaluation. Together, these efforts help move the industry from stated compliance toward greater accountability and transparency.
As app libraries continue to evolve, visible trust signals may help consumers and organizations more confidently evaluate available options.
A Changing Risk Environment
The expansion of consumer-directed exchange is also changing the healthcare risk model.
Historically, healthcare data exchange often occurred between regulated organizations operating within more defined environments. In many cases, those organizations were subject to HIPAA and other established healthcare privacy and security requirements.
Today, patient-directed exchange may involve a wide range of third-party applications with varying levels of operational maturity, governance, and security oversight. Importantly, not every consumer-facing application is subject to HIPAA. As a result, patients may encounter different privacy practices, data-sharing policies, and protections depending on the application they choose to authorize.
Patients may not always understand how their information could be used, shared, or stored once it leaves a covered entity and enters a consumer-authorized application environment. Providers and payers may also have more limited visibility into downstream data use after information has been shared.
None of this diminishes the importance of patient access or consumer choice, but it does reinforce the need for clearer transparency, stronger accountability models, and practical ways to communicate trust signals across a rapidly growing app ecosystem.
Operational Considerations for Providers and Payers
Healthcare organizations are already seeing increased volumes of app-based data requests. That creates additional operational pressure to respond efficiently while continuing to manage privacy, security, and compliance responsibilities appropriately.
As organizations evaluate app participation and data-sharing relationships, questions are evolving beyond simple interoperability readiness. Increasingly, providers and payers are asking how they should evaluate the applications requesting access to patient data and what forms of validation or oversight may already exist.
Technical interoperability standards alone are not designed to answer those questions. FHIR enables data exchange, but broader trust and assurance considerations often require additional operational validation, governance processes, and ongoing oversight mechanisms.
The Next Phase of Consumer-Directed Healthcare
The good news is that many of the foundational pieces needed to support this next phase are already developing in parallel. CMS initiatives, the CARIN Code of Conduct, accreditation programs, and broader assurance models all contribute important pieces toward a more transparent and accountable digital health ecosystem.
The next opportunity for the industry is to make those trust signals more visible and understandable for both consumers and healthcare organizations evaluating digital health applications.
As consumer-directed exchange continues to grow, organizations that prioritize transparency, validation, and responsible data stewardship will be better positioned to build confidence in the next generation of digital health experiences.
About Kathryn Ayers Wickenhauser
Kathryn Ayers Wickenhauser, MBA, FACHDM, CHPC is Chief Strategy Officer of DirectTrust.

