2026 Pediatric Health Information Technology Supplement: Immunization Information Systems

Introduction

The U.S. Department of Health and Human Services (HHS) Office of the National Coordinator for Health IT (ONC) developed the 2026 Pediatric Health Information Technology Supplement: Immunization Information Systems (this Supplement) to help developers and clinicians understand the landscape of immunization data exchange between electronic health records (EHRs) and Immunization Information Systems (IIS).

This Supplement explains IIS standards and expands the 2026 Pediatric Health Information Technology: Developer Informational Resource recommendation to synchronize immunization histories with IIS. This Supplement also describes the technical implementation standards for the collection, integration, or sharing of immunization data, leveraging the Health Level Seven® (HL7®) International Fast Healthcare Interoperability Resources (FHIR®) standard and requirements of the ONC Health IT Certification Program (Certification Program).

Overview

HHS defines IIS, also known as immunization registries, as “confidential and population-based computerized databases that record immunization doses administered by providers to people that live within a given geopolitical area.” IIS may perform or support the following functions:

  • Consolidation of Records: IIS combine immunization data from multiple sources into a single record and provide official immunization records for school, day care, travel, employment, and other entry requirements.
  • Clinical Decision Support: IIS may help parents, caregivers, guardians, or pediatric clinicians determine when immunizations are due or provide reminders if immunizations have been missed.
  • Data Exchange: IIS are capable of exchanging immunization data directly or through an intermediary, including a Health Information Exchange (HIE). Data exchange between IIS and other information systems supports timely immunizations, record consolidation, and efficient immunization data sharing by clinicians.
  • Public Health Benefit: Jurisdictions can leverage immunization data to understand vaccination patterns at the community level.

For foundational IIS concepts and standards, see the Centers for Disease Control and Prevention (CDC) and Public Health Informatics Institute’s IIS Learning Hub.

Technical Implementation and Standards

CDC’s IIS Functional Standards v5.0 (CDC Functional Standards) describes the CDC Functional Standards, the accompanying IIS programmatic goal, guidance statements, and supporting resources guiding IIS direction and progress. CDC Functional Standards include 18 functional standard definitions and associated guidance statements organized into the following program goals:

  • Goal A. Establish and maintain a secure, confidential IIS
  • Goal B. Continuously improve IIS data quality
  • Goal C. Promote electronic data exchange between the IIS and its partners and providers
  • Goal D. Ensure the delivery of immunization services reflects current Advisory Committee on Immunization Practices (ACIP) recommendations
  • Goal E. Ensure appropriate user access to data
  • Goal F. Support the generation and use of IIS data through various channels and formats
  • Goal G. Support federal and jurisdictional vaccine program requirements
  • Goal H. Support response efforts for vaccine-preventable disease outbreaks and other public health emergencies
  • Goal I. Participate in and prioritize emerging technologies and standards

To meet CDC Functional Standards, each IIS must have data elements to record patient demographics and vaccination events. CDC has identified and defined core data elements in the Core Data Elements For IIS Functional Standards v4.0 (CDC IIS). Core data elements are being updated to align with Functional Standards v5.0, released on July 1, 2025. Developers may monitor the core data elements for v5.0 updates published in 2025. IIS must be able to record the core data elements, which fall into two categories:

  • Patient Demographic Data: Includes data elements such as patient name, date of birth, gender, complete address, county of residence, and mother’s name.
  • Vaccination Event Data: Includes data elements such as vaccine administration date, type, lot number, manufacturer, and details about the administering provider and facility.

IIS can store data elements received by external systems (e.g., EHRs, billing systems, vital records). While many data elements are standardized, specific standards and data quality requirements vary by system type and jurisdiction. External systems are expected to transmit data as determined by local IIS guidelines. States maintain different requirements for demographics for data aggregation, consent, and privacy.

Several technical standards supporting immunization data exchange and clinical decision-making include:

IIS and EHRs Data Exchange

When building certified health IT products and EHRs, developers may enable bidirectional data exchange by connecting to an intermediary, including an HIE. The connectivity between IIS and HIEs aligns with CDC Functional Standards, including standards for enhanced public health reporting; improved quality and completeness of patient demographics; improved identification of vaccination patterns; and consolidated patient records to improve care delivery and coordination.

Data exchange is successful when IIS implement the same standards and implementation guides used by HIEs, EHRs, and other certified health IT products, including:

Synchronization and Inbound/Outbound IIS Protocols

Implementing bidirectional synchronization between EHRs and IIS typically involves the following mechanisms:

  • Push (Notification) Mechanism: enables a system to proactively notify another system of a new or updated individual data element.
  • Pull (Query) Mechanism: allows an entity to request and retrieve individual data elements from another data source on demand.
  • Bulk Data Exchange Mechanism: facilitates the transfer of large volumes of immunization data between systems for periodic synchronization or initial system set-up.
    • Example: Exporting all immunization records for a county over one week using HL7 FHIR Bulk Data Access or other file-based import/export processes. This is useful when a persistent live connection is not available and helps establish a baseline dataset before switching to real-time, event-based synchronization.

IIS consent requirements differ across states and local jurisdictions. A well-designed consent management system streamlines data exchange by enabling electronic capturing, storing, maintaining, and sharing of consent across disparate settings. Interoperability ensures consent records can first be found and retrieved across different systems and then interpreted consistently which prevents redundant collection of consent due to inability to find existing ones. Computability means consent is machine-readable and can be programmatically evaluated without manual intervention to allow for automated enforcement of consent preferences. Consent management systems are designed with interfaces enabling clinicians, patients, guardians, or caregivers to digitally submit, view, manage, or revoke a pediatric patients’ consent when applicable. While there are no technical specifications tailored for IIS-related consent, there are examples of general privacy consents with existing specifications, including:

CDC recommends all IIS establish a written privacy policy, including: notifications to parents, guardians, or caregivers of pediatric patients on what information will be in an IIS and how it will be used; the option to participate in an IIS, aligning with jurisdictional laws; and disclosures of who can access IIS information.

Interoperability

For efficient data exchange to occur, EHRs, health IT systems, and IIS must consider interoperability of their data, especially across jurisdictions and states where standards, policies, and technical infrastructure may vary. HL7 FHIR offers significant promise by enabling modern APIs, reducing redundant queries, improving access to updated immunization data, and supporting diverse use cases (e.g., hospitals, pediatric clinics, schools). However, its adoption may present challenges for developers due to technical complexity of FHIR-based interfaces, the need to integrate with legacy systems, and the ability to conform with evolving national standards. A FHIR implementation for an IIS can support complex features, including bulk data APIs, Open Authorization 2.0 (OAuth 2.0), Substitutable Medical Applications and Reusable Technologies on FHIR (SMART on FHIR) authorization workflows, and artificial intelligence (AI) and machine learning (ML) integration for clinical decision support tools.

To help developers navigate these complexities, the Immunization Integration Program (IIP), a public-private partnership, provides resources and testing tools to advance interoperability between EHRs and IIS. Developers may reference how the IIP aligns with national standards and certification criteria to verify that their products meet immunization-related capabilities. The Certification Program recognizes IIP testing as an alternative method to demonstrate conformance with criterion 170.315(f)(1) Transmission to Immunization Registries. The testing is available at no cost to developers and includes conformance testing, guidance, and optional recognition.

Policy

Developers may reference the CDC IIS policy and legislation to ensure their products and EHRs comply with state-specific immunization policies. States and local laws codify IIS authority by directly authorizing operation or empowering public health authorities to collect immunization data. These legal frameworks vary by jurisdiction and may influence data sharing rules, consent requirements, and reporting obligations. Developers may need to ensure their health IT products enable accurate reporting of pediatric immunization data in compliance with the varying law of their home jurisdictions.

National initiatives, including the CDC Immunization Gateway (IZ Gateway), enhance data exchange and support interoperability for jurisdictional IIS and EHRs. The IZ Gateway provides developers with messaging and routing infrastructure, enabling secure immunization data exchange among jurisdictional IIS, between IIS and vaccine-providing organizations (e.g., Veterans Health Administration, physicians’ offices, and pharmacies), and direct access by patients to their own immunization record.

Considerations

Decision-Making

IIS are managed and accessed at the state or local jurisdiction level. Deploying modified or new functionalities in an IIS requires decision-making authority. These decisions can be made in the immunization program or by another state, local department, or agency. IIS may vary in their ability or authority to collect CDC core data elements. Developers may need to work with state or local jurisdictions and navigate multiple layers of approval (e.g., state attorney general, state or local department leadership working on privacy, security, or IT) to expand on the immunization data collected or exchanged. Understanding these constraints is important for developers integrating pediatric health IT systems with IIS. Close coordination with IIS program administrators and early planning around system capabilities may help mitigate challenges and support successful, standards-based implementation. Developers could design modifications or build new functionalities to deliver mutual benefits for both IIS and pediatric clinicians, fostering trust between them. Developers could design for flexible modifications by dynamically accommodating configurations and adjusting to shifting requirements across jurisdictions, avoiding hard-coded requirements. This ensures health IT products can adapt to updated information and a range of varying decisions.

Patient and Provider Access to IIS Data

IIS and EHRs provide avenues for parents, guardians, and caregivers of pediatric patients to access their child’s immunization data electronically (e.g., digital applications, web portals). To help close the access gap, HIEs in some jurisdictions facilitate electronic access to official immunization records for individuals and families.

Developers may collaborate with IIS managers in their state or local jurisdiction to determine how to integrate their health IT products with IIS to ensure compliance with jurisdictional reporting requirements, facilitate timely data access for pediatric clinicians and families, prevent duplicative vaccines, and support updates to immunization status in IIS and EHRs. Developers could ensure their products align with the Centers for Medicare and Medicaid Services’ (CMS) Merit-Based Incentive Program (MIPS) objectives for immunization data exchange and use. CMS MIPS, part of the CMS Quality Payment Program, ties Medicare payment adjustments to performance in key areas, including quality, interoperability, and improvement activities. CMS’ promoting interoperability performance category emphasizes health care adoption of certified health IT to exchange health information, including bidirectional immunization data reporting to IIS. Ensuring products meet these requirements helps pediatric clinicians satisfy CMS program criteria, avoiding payment penalties and enhancing the accuracy and timeliness of immunization data for improved pediatric patient care.

Other efforts provide pathways for direct user access to immunization records, including the SMART Health Cards Framework (framework) version 1.4.0. This framework allows parents, guardians, and caregivers to obtain a verifiable, portable copy of their child’s vaccination record in digital or paper format enabling them to move and present this data whenever and wherever they seek and obtain care, or for purposes outside of direct care, to include travel. SMART Health Cards are built on HL7 FHIR standards and support patient empowerment and data transparency but are only available in jurisdictions and states where IIS participate in the framework.

Conclusion

Developers may apply the recommendations in this IIS Supplement to strengthen interoperability and improve accuracy and timeliness of immunization data exchange between IIS and EHRs. These implementations can contribute to more coordinated care for pediatric patients, their care team, pediatric clinicians, and immunization and vaccine providers as immunization data flows seamlessly across systems.

Reference

  1. 2026 Pediatric Health Information Technology: Developer Informational Resource: https://healthit.gov/resources/2026-pediatric-health-information-technology-developer-informational-resource/
  2. CDC-ONC Industry Days Presentation – Leveraging FHIR for IIS Bulk Data and Modernization: https://www.cdcfoundation.org/Leveraging%20FHIR%20for%20IIS%20Bulk%20Data%20and%20Modernization%20-%20HLN%20Consulting,%20LLC.pdf?inline
  3. CDC Clinical Decision Support for Immunization: https://www.cdc.gov/iis/cdsi/index.html
  4. CDC Core Data Elements for IIS Functional Standard v4.0: https://www.cdc.gov/iis/core-data-elements/index.html https://www.healthit.gov/test-method/transmission-immunization-registries
  5. CDC Immunization Information Systems HL7 Standard Vaccine Administered Code Set: https://www2.cdc.gov/vaccines/iis/iisstandards/vaccines.asp?rpt=cvx
  6. CDC Immunization Information Systems Functional Standards: https://www.cdc.gov/iis/functional-standards/introduction.html
  7. CDC Immunization Information Systems Policy and Legislation: https://www.cdc.gov/iis/policy-legislation/index.html
  8. CDC Immunization Gateway Overview: https://www.cdc.gov/iis/iz-gateway/index.html
  9. CDC Immunization Information Systems Resources: https://www.cdc.gov/iis/about/index.html?CDC_AAref_Val=https://www.cdc.gov/vaccines/programs/iis/iz-gateway/overview.html
  10. CDC Vaccine Data Code Sets: https://www.cdc.gov/iis/code-sets/index.html 
  11. CDC Clinical Decision Support for Immunizations Specifications: https://www.cdc.gov/iis/downloads/cdsi-healthy-childhood-and-adult-test-cases-v4.43.xlsx; https://www.cdc.gov/vaccines/programs/iis/downloads/CDSi-Underlying-Conditions-Test-Cases-v4.5.xlsx
  12. Centers for Medicare & Medicaid Services Promoting Interoperability-Traditional Merit-based Incentive Payment System Requirements: https://qpp.cms.gov/mips/promoting-interoperability
  13. The Effect of Electronic Health Record and Immunization Information System Interoperability on Medical Practice Vaccination Workflow: https://pubmed.ncbi.nlm.nih.gov/39909398/
  14. Immunization Integration Program. https://www.himss.org/initiatives/partnership-and-alliance/immunization-integration-program/
  15. CDC-Public Health Informatics Institute Immunization Information Systems Learning Hub: https://phii.org/what-we-do/iis-hub/
  16. SMART Health Card Framework: https://spec.smarthealth.cards/
  17. SMART Health Card Developer Tools: https://github.com/smart-on-fhir/health-cards-dev-tools