Health Information Exchange: What Can a Pharmacy Access?
Pharmacy Practice

Health Information Exchange: What Can a Pharmacy Access?

Understand HIE access, the difference between sending and querying records, and what a pharmacy can learn when an exchange returns incomplete information.

October 10, 2026
6 min read

Health information exchange (HIE) lets healthcare organizations securely share patient information electronically. For a pharmacy, that can mean receiving a clinical summary or looking up available records from other providers. What your team can see depends on the exchange service, your pharmacy's participation and user permissions, and the information its connected sources supply.

Sending data to an HIE and being able to search it are separate capabilities. North Carolina makes that distinction explicit: its submission-only pharmacy agreement supports one-way reporting but prohibits query access, while full participation enables additional services. That difference is useful when you're deciding whether a connection will help a pharmacist obtain outside records for a clinical encounter.

Sending, searching and patient-shared records

ONC describes health information exchange as electronic sharing among providers, including pharmacists, and patients. People also use HIE to refer to the organization or network that operates an exchange. It isn't one universal patient database.

The Health IT Playbook describes three ways information can move. In directed exchange, a provider sends information to a known recipient, such as a clinic sending a care summary to a pharmacy. In query-based exchange, an authorized user searches for or requests available records from other providers. In consumer-mediated exchange, the patient gathers and shares their own information, for example by providing records from a patient portal.

Those routes solve different access problems. A pharmacy waiting for a particular clinic's report may need a directed message. A pharmacist trying to locate records from several connected organizations may use a query service. A patient-provided copy can help when the pharmacy doesn't have a direct connection to the source. Receiving one document doesn't give the pharmacy ongoing search access to the sender's chart.

HIE, EHR and CCD describe different things

An EHR is the system a provider uses to maintain clinical records. An HIE supports sharing information between organizations and systems. A continuity of care document, or CCD, is a standardized patient summary that can be shared through an exchange or another supported route. The exchange may return other document types or individual data elements as well.

A portal can display outside information without importing it into the pharmacy's own record. An integrated connection may bring supported data into the clinical system, but viewing, importing and reconciling that information are different capabilities. Establish which one the proposed connection provides. The EMR and EHR explainer covers record-system terminology; the pharmacist eCare Plan overview explains a separate care-planning document.

What North Carolina's pharmacy agreements allow

NC HealthConnex offers two pharmacy participation agreements. The submission-only agreement lets a pharmacy send the specified claims data through a one-way connection. It prohibits the other exchange services, including querying records and using clinical registries. The full agreement allows pharmacies to use the wider NC HealthConnex service offering.

A full participant can request Clinical Portal access and arrange staff training through the pharmacy onboarding process. NC HIEA says the pharmacy's data-submission connection doesn't have to be live before it begins using those services.

The NC HealthConnex Clinical Portal lets appropriately assigned clinician users view available information such as allergies, medications, problems, laboratory results and immunization history. The pharmacy's Participant Account Administrator arranges credentials and appropriate roles. These are North Carolina's arrangements; another exchange may use different agreements, services and account requirements.

A missing laboratory result changes the next step

Consider a hypothetical pharmacy preparing a clinical consultation. The patient reports a recent laboratory test at a clinic, and the pharmacist needs the result to understand the encounter. The pharmacy already sends data to an exchange.

If that pharmacy has only North Carolina's submission-only agreement, its outgoing connection doesn't provide a way to query the clinic's records. The pharmacist needs another approved route to the result, such as requesting it from the clinic, while the organization separately considers whether full participation fits its needs.

Now suppose the pharmacy is a full participant and the pharmacist has an appropriate Clinical Portal account. The search returns an older laboratory report but no result from the recent visit. NC HIEA expressly cautions that a facility's participation doesn't guarantee a particular patient's data will be visible. Use the older report for the date it documents; the missing newer result still needs to be obtained.

Confirm the patient match and the report's source and date. If the missing result affects the consultation, request it from the clinic or use a patient-provided copy through an approved process. A permission error or a restricted record goes to the account administrator or privacy owner. Don't treat a failed or incomplete search as a clinical finding.

How to evaluate an exchange connection

Start with the records your clinical service actually needs and the organizations that produce them. ONC's participation guidance points to regional and national exchanges and existing health IT vendors as possible connection routes. Ask whether the pharmacy can receive documents, query outside sources, send its own records, or use a combination. Confirm whether staff work in a separate portal or within their clinical system, and what setup and ongoing fees apply.

Then check whether the relevant clinics, hospitals and laboratories contribute the needed information through that route. A connection that delivers encounter notifications may be useful, but it doesn't establish access to the full report you need. Request a demonstration of the specific record type and access method using sample data.

Patient choice and access rules also vary. ONC's consent guidance explains that privacy requirements and exchange policies affect what can be shared. Have the organization's privacy lead resolve the applicable consent or restriction rules before building a service around assumed access.

TEFCA, the Trusted Exchange Framework and Common Agreement, supports exchange across participating networks under a shared framework. It can broaden the routes available through a participating organization, but the pharmacy still needs a supported connection and appropriate access. Ask the exchange or software provider what is available to your organization today.

Where DocStation fits in the pharmacy's record

DocStation maintains the pharmacy's longitudinal patient record, including medications, conditions, allergies, labs and vitals, alongside clinical notes and medical claims. Its supported dispensing-system integrations and CSV imports provide specific ways to bring information into that record. File attachments can retain a received report with the relevant documentation.

For an outside-record connection, confirm the particular network, data types and access method with the vendor and exchange operator; a dispensing-system integration doesn't by itself establish HIE query access. Keep the source report available when documenting the consultation so another team member can distinguish the outside finding from the pharmacy's assessment.

Automation

Connect incoming data to the work that follows

Use dispensing, health plan, and CSV data to trigger the work that happens beyond the prescription.