The Long View Revisited: What My 2015 Research on Patient Matching Still Teaches Us Identity, Consent, and Trust in an Era of Interconnected Health Data
By Timothy Godlove, Ph.D.
More than a decade ago, my colleague Adrian W. Ball and I examined a problem that was becoming increasingly important as healthcare organizations expanded the electronic exchange of patient information: How can we be confident that health information is being associated with the right person?
Our 2015 article, Patient Matching within a Health Information Exchange, published in Perspectives in Health Information Management, examined patient matching within health information exchanges (HIEs) and the privacy, security, consent, and patient-safety concerns surrounding the process.
Much has changed since 2015. Electronic health records have matured. Interoperability standards have advanced. Application programming interfaces have become increasingly important. Nationwide exchange frameworks are moving healthcare toward an environment in which information can follow patients across organizational and geographic boundaries.
Yet the fundamental issue we examined remains remarkably relevant:
Before healthcare organizations can securely exchange patient information, they must be confident they have identified the correct patient.
That sounds simple. It is not.
The Problem We Saw in 2015
Health information exchange depends on connecting records maintained by different healthcare organizations.
A patient may receive treatment from a primary care physician, hospital, specialist, laboratory, pharmacy, Department of Veterans Affairs facility, or other healthcare organization. Each organization may maintain information about that individual in a different electronic system.
For those records to be exchanged effectively, organizations must determine that records referring to similar individuals actually belong to the same person.
In our 2015 article, we described two fundamental prerequisites for health information exchange.
First, the organizations exchanging information must establish that they are dealing with the same patient.
Second, they must determine that the patient has consented to the appropriate exchange of information.
At the time, the Nationwide Health Information Network relied on automated patient-discovery processes that used demographic information such as names, dates of birth, gender, addresses, and other identifying information.
The weakness was straightforward: the underlying information was not always complete, standardized, or accurate.
A misspelled name, a changed address, a transposed number, a missing middle initial, a marriage-related name change, or inconsistent data-entry practices could interfere with matching.
That created two particularly important risks.
A false non-match occurs when two records for the same person are not linked.
A false match is potentially even more serious: information belonging to two different individuals is incorrectly associated.
The consequences go well beyond inconvenient database errors. An incorrect match can affect clinical decisions and patient safety, and create privacy and security problems by potentially exposing one person's health information to another person's record.
That led us to question whether automated demographic matching alone was the best way to establish identity across healthcare organizations.
Putting the Patient into the Process
Our proposed approach was different.
Rather than relying exclusively on healthcare organizations to determine identity through demographic matching, we proposed involving the patient directly in establishing identity and consent.
The patient would authenticate to participating electronic health record systems and use those established identities to confirm that the records belonged to the same person. At the same time, the patient could identify what health information they consented to share between participating organizations.
The concept brought together three functions that were often treated separately:
identity, consent, and information exchange.
We also suggested that the supporting software could provide patients with greater visibility into the exchange process, including the ability to see which information had been shared, when, and with whom.
Looking back from 2026, I believe that aspect of the argument is particularly significant.
Technology has advanced dramatically, but the larger question remains: How much visibility and control should individuals have over the digital identities and information associated with them?
That question now extends well beyond healthcare.
What Has Changed Since 2015?
The health information environment in 2026 is substantially more mature than the one we examined 11 years ago.
FHIR—Fast Healthcare Interoperability Resources—has helped establish modern standards for exchanging healthcare information through APIs. The United States Core Data for Interoperability (USCDI) provides standardized data elements supporting nationwide information exchange. Federal interoperability policy has also increasingly emphasized patients' ability to access their electronic health information.
Perhaps most significantly, the Trusted Exchange Framework and Common Agreement, or TEFCA, is establishing a nationwide framework for exchanging electronic health information across previously disconnected networks.
These developments represent enormous progress.
Instead of viewing health information exchange primarily as communication between individual healthcare organizations, we are increasingly moving toward an interconnected national information ecosystem.
That scale is striking. According to federal health IT officials, approximately 10 million documents had been exchanged through TEFCA before 2025. By the end of 2025, that number had grown to approximately 464 million documents.
But increased connectivity does not eliminate the identity problem.
It magnifies its importance.
Patient Matching Is Still a National Interoperability Issue
More than a decade after our article was published, federal health IT authorities continue to describe patient matching as a critical component of interoperability and the nation's health information technology infrastructure.
Today's approaches are considerably more sophisticated. Standardized demographic information, improved address standards, master patient indexes, record locator services, FHIR-based matching operations, and other identity management technologies can all contribute to better results.
Nevertheless, the underlying objective has not changed:
Connect the correct information to the correct person.
Current federal interoperability guidance continues to address patient names, addresses, demographic information, identity management, and patient-record matching.
Even TEFCA requires participating networks to be able to resolve requests that match demographic information to patient identities.
The technology is evolving.
The problem has not disappeared.
A Particularly Interesting Development: Digital Identity
One of the most interesting developments from the perspective of our 2015 research is the growing attention to digital identity.
Current federal health IT initiatives are examining approaches such as federated credentials, reusable identity tokens, privacy-preserving identifiers, and other methods to improve patient matching while reducing the burden on patients and healthcare organizations.
That direction echoes an important principle behind our original proposal.
We argued that the patient's established electronic identity could be part of the mechanism for connecting health records, rather than forcing organizations to infer identity solely from demographic characteristics.
I would not claim that today's digital identity approaches are identical to the architecture we proposed in 2015. Technology and standards have evolved substantially.
But the conceptual connection is difficult to overlook.
The industry continues to explore ways to make authenticated digital identity a stronger component of patient matching.
Consent and Transparency Matter Just as Much
Our article was also about something larger than matching algorithms.
It was about trust.
Healthcare information is among the most sensitive information an organization possesses. Patients reasonably expect that their records will be protected and that access will occur for legitimate purposes.
Technology can make information exchange nearly instantaneous. That does not automatically mean every technically possible exchange should occur without appropriate governance, authorization, security, and transparency.
Patients should understand how their information moves through the healthcare ecosystem.
They should have appropriate access to their own information.
They should have confidence that the information belongs to them.
And they should be able to trust the institutions and technologies responsible for protecting it.
The more interconnected healthcare becomes, the more important that trust becomes.
Artificial Intelligence Raises the Stakes Again
There is another dimension that was not central to our 2015 discussion: artificial intelligence.
Healthcare organizations are increasingly exploring AI for clinical decision support, analytics, operational efficiency, population health, and other applications.
AI systems depend heavily upon data.
That creates an important relationship between patient identity, data quality, and artificial intelligence.
If information is incorrectly associated with an individual, the problem is no longer confined to a single electronic record. Incorrectly matched or poor-quality data can influence analytics, automated recommendations, risk models, and other data-driven processes.
The familiar information-management principle still applies:
The quality of the output depends upon the quality and integrity of the underlying data.
As healthcare becomes more interconnected and increasingly dependent on sophisticated analytics and AI, accurate patient identification is part of the foundation upon which those capabilities depend.
The Long View
When Adrian Ball and I wrote Patient Matching within a Health Information Exchange in 2015, the immediate issue was how healthcare organizations could more accurately and securely establish patient identity while incorporating consent into health information exchange.
Eleven years later, the terminology, architectures, standards, and technologies have changed.
The NwHIN-era environment we examined has evolved into a much broader national interoperability ecosystem. FHIR has transformed the technical landscape. USCDI continues to standardize information exchange. TEFCA is connecting networks at a national scale. Digital identity technologies are evolving. Artificial intelligence is creating entirely new uses for health data.
But several principles have endured.
Identity matters.
Data quality matters.
Security matters.
Privacy matters.
Consent and transparency matter.
And most importantly, trust matters.
Technology can solve many problems, but expanding connectivity without simultaneously strengthening identity, governance, privacy, security, and trust can create new ones.
That may be the most important lesson from revisiting this research.
The technologies we use to exchange information will continue to change.
The responsibility to ensure that information is accurate, secure, appropriately shared, and connected to the right person will not.
________________________________________
Original Research
Godlove, T., & Ball, A. W. (2015). Patient Matching within a Health Information Exchange. Perspectives in Health Information Management, Spring 2015.