Every healthcare organization working with CMS-0057 requirements must choose its own path to compliance: build a solution entirely in-house, purchase a ready-made solution from a vendor, or use a hybrid approach.
Many organizations have already made this choice for CMS-9115. Some decided to build their own FHIR server and enterprise data store, and many preferred to stay the course for CMS-0057 rather than starting from scratch. Typically, these are technically advanced organizations that possess both the resources and the desire to own and manage what they have built.
However, deploying a FHIR API for CMS-0057 is not the hardest part. The complexity lies in everything that is not written in the rules but must still work: building an operational network of endpoints for Payer-to-Payer Data Exchange, connecting providers and driving adoption for both Provider Access and electronic Prior Authorization (ePA), and routing ePA requests through multiple Utilization Management (UM) vendors so that the end-to-end workflow functions across all lines of business. It is this operational layer—not the APIs themselves—that is the source of the real complexity of CMS-0057.
And that is exactly the problem we broke down in detail during our recent webinar with Point of Care Partners titled "Compliance Without Rebuilding." During the session, we introduced our 1up Gateway solution as a viable option.
The response during the webinar and in the weeks that followed showed that this solution hit the mark. Below are the answers to the questions we heard most often.
Q: What is 1up Gateway and how does it work for CMS-0057?
A: 1up Gateway is a deployment model that sits in front of a healthcare organization's own FHIR infrastructure and handles all external interactions. It works the same way for any CMS-0057 products the organization uses: whether it is 1up Payer-to-Payer Data Exchange, 1up Provider Access, 1up Electronic Prior Authorization, 1up Patient Access, or the full CMS-0057 suite. The organization's infrastructure remains in place and continues to serve as the system of record; 1up Gateway acts as a compliance layer in front of it.
In practice, this means that 1up handles tasks that do not directly touch your data, such as verifying and connecting external payers, providers, and applications; creating and maintaining the network endpoints and systems required to ensure the health of each workflow; managing member consent; and preparing reporting for CMS so that organizations can easily submit usage data each year.
The advantage is clear: your team retains control over the data and infrastructure decisions that brought you to where you are today, while 1up takes on the operational complexity and compliance issues so that these APIs actually work and deliver ROI, rather than just formally meeting requirements.
Q: Do we need a one-time data dump, or can 1up Gateway access our FHIR API directly?
A: In the 1up Gateway model, a direct connection to your existing API is standard. 1up Gateway works as a connectivity layer, not as a data ingestion pipeline. When a request comes in from a provider or another payer, 1up Gateway authenticates it, queries your FHIR server in real-time, and returns the response. We do not store any data on our platform; we simply pass it through to you.
Q: What authentication methods does 1up support?
A: In general, any that your security team requires. For the connection between 1up and your internal systems, we support OAuth2 and mTLS in combination with allow-listed IP addresses, if that is part of your existing security policy. We do not ask you to implement a new security model just for the sake of a 1up Gateway deployment.
For member authentication, for example in 1up Patient Access, we support integration with identity providers via standard protocols such as SAML and OIDC, including parallel operation with multiple providers if your organization uses more than one in a production environment.
Q: What visibility into network activity and compliance reporting do you provide?
A: Even without using the full 1up Platform, deploying 1up Gateway provides real visibility through the 1up Console. You can view network connections, explore usage reports, and track the execution status of each request, seeing immediately what succeeded, what failed, and why. Some features you do not get compared to a full 1up Platform deployment include the Member Directory and Longitudinal Member Profiles, as both of these components require storing your member data on our platform.
Q: What happens if a member's previous payer is not connected to the 1up Network?
A: The workflow does not stop—it simply continues in whatever capacity is possible. The system captures the consent of the member and their specified previous payer, logs the lack of a connection as an exception, and routes that exception through a defined path for subsequent handling, rather than just ignoring it. Over time, however, such cases should become rare. We are actively expanding the 1up Network with the goal of connecting to every payer's endpoint, which will eventually make this issue irrelevant.
Q: Does the 7-day Payer-to-Payer data exchange period under CMS-0057 count from the time of enrollment or from the time consent is received?
A: The seven-day period is not a fixed date tied to the calendar. It is tied to consent.
Members can provide their consent even before their coverage becomes active, for example, during the open enrollment period in the fall. But the seven-day countdown to the actual data request begins on the later of two dates: the coverage start date or the date consent is received. For a member who gave consent in October for coverage starting January 1, the countdown only begins on January 1. For a member who gave consent later, after coverage has already begun, the countdown begins from that later date.
In other words, it is a rolling schedule: each member's window opens on their own schedule based on the later date between coverage start and consent date, rather than on a single date common to everyone at the beginning of the plan year.
Q: How does 1upHealth stay up to date with CMS regulatory changes?
A: Regulatory requirements are constantly changing. The CMS-9115 rule has already been supplemented twice: CMS-0057 changed the initial Patient Access requirements, and CMS-4208-F2 updated the Provider Directory requirements. And the proposed CMS-0062 rule will expand prior authorization requirements once it is finalized.
The ecosystem you are connecting to will also evolve. New payers will emerge, others will leave, connections to new EHR vendors and provider portals will be required, and you may decide to expand or change the list of UM vendors you work with.
1upHealth is the company that stays ahead of these changes for all our clients. Our team constantly monitors the regulatory landscape and the state of the ecosystem, evolving existing solutions and building new ones as CMS requirements and the entire ecosystem change, so your team doesn't have to take on that complexity.
We also take responsibility for ongoing network management and maintenance: monitoring and maintaining the health of every connection, as well as adding or removing endpoints as the ecosystem changes. Our goal is to maintain connections to all major EHRs, portals, and UM vendors while remaining vendor-agnostic, so your organization has the flexibility to change parts of its own ecosystem over time without any disruption.
Watch the full 1up Gateway webinar
Want the full context on these issues? Watch the recording of the session "Compliance Without the Rebuild." In this on-demand webinar, we take a closer look at the gap between CMS-0057 compliance and operational readiness, and provide a live demonstration of the 1up Gateway model.









