Information technology and healthcare trends reshaping connected care

tablet, ipad, read, screen, swipe, to touch, assign, point, gadget, modern, internet, finger, digital, technology, contact, communication, connection, electronics, dates, device, data, typing, input, information, commercial, to undertake, entrepreneur, work, tablet, tablet, tablet, tablet, ipad, ipad, ipad, ipad, ipad, internet, data, information

Why the connection matters now

Information technology and healthcare are now tightly linked in day-to-day operations. IT affects how clinicians document encounters, how payers exchange prior authorization data, how medical devices connect to hospital networks, how telemedicine is delivered, and how organizations protect patient information during cyber incidents. The key shift is not simply that healthcare has gone digital. Digital systems are now part of clinical reliability, patient access, regulatory compliance, and device safety.

Several verified signals show the scale of this change. The Assistant Secretary for Technology Policy/Office of the National Coordinator for Health Information Technology reported that 95% of office-based physicians used some form of EHR in 2024, while 91% used a certified EHR. CDC/NCHS reported that 80% of office-based physicians used telemedicine in 2024, below pandemic-era levels but still central to care delivery. CMS, HHS OCR, and FDA have also issued or updated rules and guidance affecting interoperability, cybersecurity, clinical decision support, and device software. (healthit.gov)

organization chart, businessman, production planning, steering, structural organization, work process, business administration, work organization, flow of information, information logistics, information management, business informatics, logistics, technology, hand, touch, finger, man, organization chart, organization chart, organization chart, organization chart, organization chart, structural organization

For teams working in healthcare technology, the practical question is straightforward: which IT changes are creating measurable value, and which ones are adding new operational or safety risk?

From digitized records to workflow infrastructure

The electronic health record remains the core infrastructure layer for healthcare IT. It holds diagnoses, notes, orders, medications, lab results, imaging references, and administrative data. Its role, however, has expanded well beyond digital documentation. An EHR is now a workflow engine, a data source for analytics, a patient access channel, a connection point for APIs, and, in some settings, a platform that may embed decision support or AI-enabled functions.

ONC’s 2008–2024 physician EHR data shows why the market has moved beyond basic adoption. In 2008, 42% of office-based physicians used any EHR. By 2024, 95% used any EHR and 91% used a certified EHR. That does not mean every practice has the same digital capacity. The same ONC data shows solo physicians had lower EHR adoption than large groups, with 86.1% using any EHR and 79.9% using a certified EHR. Practices with 51 or more physicians reported 99.1% any EHR use and 98.5% certified EHR use. (healthit.gov)

This gap matters because many health IT improvements assume reliable digital infrastructure. A large health system may have the staff, vendor leverage, cybersecurity program, and integration budget to support APIs, cloud hosting, analytics, and device connectivity. A smaller clinic may depend on a narrower set of vendor tools and have less capacity to validate new integrations or manage security changes. In practice, the health IT divide is shifting from who has an EHR to who can safely and effectively use the EHR as a connected platform.

Interoperability is becoming an operating requirement

For years, interoperability was often treated as a policy goal. It is now moving into more concrete operating requirements. CMS released the Interoperability and Prior Authorization Final Rule on January 17, 2024. The rule requires impacted payers to implement and maintain certain HL7 FHIR APIs to improve healthcare data exchange and streamline prior authorization. Some operational provisions begin January 1, 2026, while many API development and enhancement requirements generally apply beginning January 1, 2027, depending on payer type. (cms.gov)

The practical impact is significant. Prior authorization has historically involved portals, phone calls, faxes, fragmented documentation, and delayed decisions. FHIR-based payer APIs do not automatically remove all administrative burden, but they create a technical path for more consistent data exchange among payers, providers, and patients. For vendors and healthcare organizations, the issue is no longer only whether an API exists. It is whether the API supports usable workflows, clear patient permissions, reliable identity matching, and auditable data movement.

ASTP/ONC’s HTI-2 and HTI-4 updates point in the same direction. HTI-2, last updated by ONC in April 2026, finalizes TEFCA-related provisions intended to support reliable, private, secure, and trusted exchange of electronic health information. HTI-4, effective October 1, 2025, adds or revises certification criteria for electronic prescribing, real-time prescription benefit information, electronic prior authorization, and related API functionality. ONC materials also state that certified health IT modules for electronic prescribing must support updated standards by December 31, 2027. (healthit.gov)

Area Verified signal Why it matters
EHR foundation 95% of office-based physicians used any EHR in 2024. Digital records are now the baseline for most health IT workflows.
Telemedicine 80% of office-based physicians used telemedicine in 2024. Virtual care remains part of routine access, even after pandemic peaks.
Prior authorization CMS API requirements generally phase in through 2026 and 2027. Administrative exchange is becoming a standards-based IT problem.
Device cybersecurity FDA issued final cybersecurity guidance for medical device premarket submissions in February 2026. Connected devices must be evaluated as networked software assets.
HIPAA security HHS OCR issued a proposed HIPAA Security Rule update on December 27, 2024. Cyber controls are being tied more directly to health information protection.

Telemedicine is stabilizing rather than disappearing

Telemedicine shows how healthcare IT changes after rapid adoption. During the pandemic, many organizations deployed virtual care quickly. By 2024, use had declined from the peak, but it remained a mainstream delivery channel. CDC/NCHS reported that telemedicine use among office-based physicians fell from 86.5% in 2021 to 80.0% in 2024. The decline was larger among surgical specialists and in non-metropolitan areas, while primary care remained comparatively high at 86.2% in 2024. (cdc.gov)

This pattern suggests a more mature phase. Telemedicine is no longer only an emergency substitute for in-person care. It is becoming a service line that must be matched to clinical need, broadband access, reimbursement rules, patient preference, documentation requirements, and device integration. Remote follow-up, medication management, behavioral health, chronic disease check-ins, and post-discharge communication may benefit from virtual workflows. Procedures, physical examinations, imaging-dependent encounters, and high-risk diagnostic decisions may still require in-person care.

Healthcare technology teams should evaluate telemedicine as a workflow ecosystem, not just a video visit tool. Scheduling, consent, identity verification, interpreter access, device data, clinical documentation, billing, and escalation pathways all influence whether virtual care improves access or simply creates another disconnected channel.

Connected devices and software expand the clinical IT perimeter

Medical equipment used to be managed mainly as biomedical hardware. That distinction is fading. Monitors, infusion systems, imaging platforms, implantable devices, wearable sensors, diagnostic software, and clinical applications may connect to hospital networks, cloud services, EHRs, or vendor maintenance systems. The FDA notes that connected medical devices can improve care but also introduce cybersecurity risks that may affect device safety and effectiveness. (fda.gov)

FDA’s February 2026 final guidance on medical device cybersecurity makes this shift explicit. The guidance addresses cybersecurity device design, labeling, and documentation for premarket submissions involving devices with cybersecurity risk, and it supersedes the June 2025 version. For manufacturers, cybersecurity is not merely a postmarket IT support issue. It is part of design control, risk management, threat modeling, software maintenance, and communication with users. (fda.gov) See also: clinical equipment.

The software side is also evolving. FDA issued final guidance in August 2025 on predetermined change control plans for AI-enabled device software functions. The agency describes these plans as a way to support iterative improvement while maintaining reasonable assurance of safety and effectiveness. FDA also issued draft guidance in January 2025 on lifecycle management and marketing submissions for AI-enabled device software functions, and final guidance in January 2026 clarifying clinical decision support software policy. (fda.gov)

For healthcare providers, procurement and governance now need to cover more than purchase price and clinical features. Technology teams should ask how a connected device authenticates users, receives patches, logs events, segments network traffic, exports data, handles downtime, and communicates security advisories. They should also clarify whether software output is informational, decision-supporting, or part of a regulated device function.

Cybersecurity is now a patient safety issue

Cybersecurity in healthcare used to be framed mainly as a privacy and compliance concern. That remains true, but recent events have made the patient safety dimension harder to separate from security operations. HHS OCR issued a proposed HIPAA Security Rule update on December 27, 2024, describing the proposal as the first major Security Rule update since 2013. OCR stated that large breach reports increased 102% from 2018 to 2023, while the number of individuals affected by large breaches increased 1002% over the same period. OCR also reported that more than 167 million individuals were affected by large breaches in 2023. (hhs.gov)

The Change Healthcare incident showed how a technology outage can affect the broader delivery system. HHS OCR’s March 14, 2025 FAQ states that it opened investigations of Change Healthcare and UnitedHealth Group because of the incident’s unprecedented impact on patient care and privacy. A separate American Hospital Association survey of nearly 1,000 hospitals, collected March 9–12, 2024, reported that 74% of responding hospitals experienced direct patient care impact, and nearly 40% reported patients having difficulty accessing care because of delays in processing utilization requirements such as prior authorization. (hhs.gov)

The operational takeaway is that resilience has to be designed across clinical, financial, and administrative workflows. Backups are necessary, but they are not enough. Organizations need asset inventories, vendor dependency maps, network segmentation, multifactor authentication, tested downtime procedures, alternative claims and prescribing workflows, and communication plans for patients and staff. Cybersecurity is not only about preventing unauthorized access; it is also about sustaining care when a critical technology partner fails.

A practical roadmap for healthcare technology teams

Healthcare organizations do not need to chase every new platform. They need a disciplined roadmap that connects technology choices to patient care, operational continuity, and compliance. The following priorities are especially relevant through 2026 and 2027.

  • Map the real workflow before buying technology. Document how clinicians, patients, payers, pharmacies, labs, and device teams exchange information today. Gaps often appear at handoffs, not in the core application.
  • Treat interoperability as governance, not only integration. APIs require data standards, consent models, identity management, testing, monitoring, and clear ownership when transactions fail.
  • Include connected devices in the security perimeter. Medical equipment should be part of asset inventory, vulnerability management, network segmentation, and incident response planning.
  • Separate AI promise from validated use. AI-enabled software should be assessed for intended use, training data limits, monitoring needs, clinician oversight, and regulatory status.
  • Plan for downtime as a clinical scenario. If scheduling, EHR access, pharmacy routing, prior authorization, or claims systems are unavailable, staff need tested alternatives before an incident occurs.
  • Measure adoption by outcomes, not installation. A tool that is installed but ignored, duplicated, or unsafe under pressure has not improved care delivery.

The common thread is accountability. Information technology can reduce friction, improve access, and support safer decisions only when healthcare organizations manage it as part of the care model. Poorly governed IT can create new administrative burden, hidden safety risk, and dependence on fragile third-party systems.

Frequently asked questions

What does information technology mean in healthcare?

In healthcare, information technology includes the systems used to create, store, exchange, analyze, and protect health information. Examples include EHRs, telemedicine platforms, clinical decision support, patient portals, payer APIs, cybersecurity tools, cloud infrastructure, connected medical devices, and analytics systems.

How does interoperability improve healthcare delivery?

Interoperability helps different systems exchange usable information. When implemented well, it can reduce duplicate data entry, support care coordination, give patients better access to records, and make administrative processes such as prior authorization more transparent. The benefit depends on workflow design, data quality, and governance.

Are connected medical devices part of healthcare IT?

Yes. When medical devices connect to networks, EHRs, vendor systems, or cloud platforms, they become part of the healthcare IT environment. That does not remove their clinical or regulatory identity as medical devices, but it does mean they need cybersecurity, software maintenance, access control, and incident response planning.

What should healthcare technology leaders watch next?

Key areas to watch include CMS interoperability and prior authorization implementation dates, ONC certification updates, FDA software and cybersecurity guidance, HIPAA Security Rule developments, and the operational resilience of critical third-party vendors. The most successful organizations will connect these requirements to practical workflow redesign rather than treating them as separate compliance tasks.