7 September 2026

California's Data Exchange Framework has been law since 2022, and its core deadlines have already come and gone; most hospitals, medical groups, and health plans were required to start exchanging patient data by January 31, 2024, and smaller practices by January 31, 2026. For a California healthcare organization, a Patient Record Retrieval API in California is the technical mechanism that turns that legal obligation into a working system: a secure, programmatic way to pull a patient's records from outside organizations the moment they're needed, instead of chasing down a fax or a phone call.
This guide explains how a Patient Record Retrieval API in California works in practice, what California's DxF mandate actually requires, and how to evaluate whether to build this capability in-house or connect through a Qualified Health Information Organization (QHIO).
A Patient Record Retrieval API in California is a secure software interface that lets a healthcare organization's EHR or clinical system request and receive a patient's records from another organization's system, without manual data entry or faxing. Instead of a staff member calling another clinic for records, the API sends a structured query typically using the FHIR standard and returns a consolidated, machine-readable record in seconds. In California, this capability is increasingly tied to CalHHS DxF compliance, because the framework requires signatories to exchange or provide access to health information with other mandated organizations in near real time.
The distinction that matters for California providers: a Patient Record Retrieval API in California is not the same thing as an EHR. It's the connective layer that lets EHRs from different vendors, at different organizations, talk to each other.
Most articles about California's data exchange mandate treat it as something on the horizon. It isn't. The compliance dates are already behind most of the healthcare system, which changes the urgency for any organization still relying on fax-based record requests.
Under AB 133 and the CalHHS Data Exchange Framework, signatories were required to sign the Data Sharing Agreement (DSA) by January 31, 2023, and then begin actively exchanging health and social services information by one of two dates:
Both deadlines have now passed. A smaller California practice that hasn't yet stood up a real patient record retrieval workflow is already out of compliance with its data exchange obligation, not just behind on a future requirement.
The enforcement mechanism is public accountability, not an immediate fine. Starting January 1, 2027, the Department of Health Care Access and Information (HCAI) is required to publish and maintain a public list of entities it identifies as non-compliant with the DSA execution requirement. For a practice, an IPA, or a medical group, appearing on a state-published non-compliance list carries reputational and referral-network risk well beyond the regulatory exposure itself — payers, hospital systems, and larger medical groups increasingly expect their network partners to be DxF-compliant before routing patients or data to them.
This is the practical reason a Patient Record Retrieval API in California has moved from "nice to have" to a near-term operational requirement for California providers of every size.
The mechanism is worth explaining plainly, because most of the confusion around DxF compliance comes from treating "data exchange" as an abstraction rather than a specific technical process.
There are two primary paths a patient record retrieval API uses to pull records, and a well-built system uses both.
Carequality record lookup works by querying a shared national network. When your API sends a request for a specific patient — matched by demographics like name, date of birth, and often a patient identifier — Carequality-connected organizations across the country that hold records for that patient respond automatically, without a person on either end manually locating and sending the file. This is how a California provider can pull a patient's history from an out-of-state hospital system without a phone call.
Direct messaging is the fallback for organizations not yet connected to Carequality or a similar network. It functions more like secure, structured email between provider organizations — still faster and more reliable than fax, but requiring the sending organization to actively push the record rather than responding to an automated query. A patient record retrieval API that only supports Carequality lookup will hit gaps; one that combines both methods closes them.
A typical patient record retrieval sequence looks like this:
The value isn't just speed — it's that the record arrives structured and matched to the correct patient, reducing the manual reconciliation work that otherwise falls on clinical staff.
California providers generally have two paths to a working patient record retrieval capability: build direct API connections themselves, or connect through a Qualified Health Information Organization (QHIO) that already maintains those connections.
| Factor | Build In-House | Connect Through a QHIO |
|---|---|---|
| Time to first working connection | 6–18 months typical | Weeks, in most cases |
| Carequality network access | Requires separate onboarding and certification | Included via QHIO's existing connection |
| DxF Data Sharing Agreement support | Legal and compliance burden sits fully with the practice | QHIO typically supports DSA execution and ongoing compliance |
| Ongoing maintenance | Internal IT team must maintain uptime, security patches, format updates | Maintained by the QHIO as part of the service |
| Security certification | Practice must independently pursue and maintain HITRUST/HIPAA posture | Inherits the QHIO's certified security infrastructure |
| Best fit for | Large health systems with dedicated interoperability engineering teams | Practices, medical groups, and IPAs without in-house integration engineering |
For most California physician practices, medical groups, and IPAs, the in-house path isn't a realistic use of clinical or administrative budget — the engineering lift to build and maintain Carequality-grade connections rivals what a dedicated health IT vendor already runs at scale.
Before selecting a vendor for patient record retrieval, verify the following:
"DxF compliance only applies to hospitals." It doesn't. Physician organizations, medical groups, skilled nursing facilities, clinical labs, and even smaller physician practices with fewer than 25 physicians are named signatories under the framework, just on a later implementation timeline.
"Connecting to a data exchange network means losing control of patient data." A patient record retrieval API doesn't grant blanket access to a practice's records — it responds to specific, matched patient queries under the terms of the DxF Data Sharing Agreement and applicable consent rules, not open data sharing.
"A patient portal already covers this requirement." A patient-facing portal lets an individual view their own records; it doesn't fulfill the organization-to-organization exchange obligation the DxF mandates, which requires systems to respond to other providers' queries automatically.
A mid-sized California medical group — roughly 20 physicians across three locations — had grown through acquisition and inherited three separate EHR systems, none of which communicated with each other or with outside hospital systems. Staff manually requested outside records by fax, with a typical turnaround of three to five business days, and the group had signed its DSA but had no functioning method to actually exchange data ahead of its January 2026 implementation deadline.
After connecting through a QHIO-based patient record retrieval API, the group's clinicians began receiving consolidated outside records — visit summaries, medications, and recent labs — within the existing EHR workflow at the point of scheduling, typically before the patient's visit rather than days afterward. Administrative staff time previously spent chasing records by phone and fax was redirected to other intake work, and the group's DxF implementation was brought current without hiring additional IT staff. The specific gains will vary by practice size and record volume, but the pattern — fragmented systems consolidated into one automated retrieval workflow — is typical of what a QHIO connection resolves.
Long Health is a California-based, HITRUST r2 certified health data exchange company and designated Qualified Health Information Organization (QHIO), built specifically around the state's own CalHHS Data Exchange Framework rather than adapted from a generic national platform. Its patient record retrieval API connects directly to the Carequality network, with direct-messaging as a fallback for records outside that network, and the platform is HIPAA compliant with encryption in transit and at rest.
Beyond raw record retrieval, Long Health assists California practices with CalHHS Data Sharing Agreement execution and supports organizations working through their DxF implementation obligations. The company is a member of NVIDIA Inception, reflecting its focus on applying AI to the harder problem sitting downstream of record retrieval: reconciling and structuring the records once they arrive. That capability connects naturally to Long Health's broader product set AI Scribe for real-time clinical documentation, and AI-driven medical record summarization for organizations retrieving large patient histories and needing them distilled into a usable clinical summary rather than a stack of disconnected documents.
For California healthcare organizations still relying on fax and phone calls to move patient records, the compliance clock isn't ahead of them anymore — it's behind them. A patient record retrieval API, connected through a QHIO like Long Health, closes that gap without requiring a practice to build and maintain its own Carequality infrastructure.
No. The DSA is the legal commitment to exchange data under CalHHS's framework; the API is the technical mechanism that fulfills that commitment. A practice needs both — the signed agreement and a working retrieval system — to be fully DxF-compliant.
An HIE is typically a regional network that organizations join to share data locally. A patient record retrieval API can query an HIE, but it can also query the broader Carequality network nationally, giving a California practice access to records from organizations well outside any single regional HIE's footprint.
Yes. QHIO-based platforms are typically priced and configured to serve practices of any size, since the underlying Carequality connection and compliance infrastructure is shared across all connected organizations rather than built separately per client.
A well-built patient record retrieval API includes a direct-messaging fallback, allowing the requesting organization to send a structured request directly to the holding organization even without a live Carequality connection.
Retrieval for treatment, payment, and healthcare operations generally follows existing HIPAA permitted-use rules rather than requiring new patient authorization for each request, though practices should confirm consent handling specifics with their compliance counsel and vendor.
Through a QHIO connection, most practices are exchanging data within weeks of onboarding, compared to the six-to-eighteen-month timeline typical of building direct Carequality connections in-house.