Tech Adoption

Is Healthcare Ready for the Future? Tech Adoption Insights

Posted 28 Feb 2022 · Updated 14 Sept 2026 · 5 min read

The familiar story about healthcare and technology is that the industry is years behind, still shuffling paper, still faxing, still waiting for the digital era to arrive. Federal survey data says the opposite. Digitization happened, and it happened almost everywhere. The paperwork problem simply outlived the paper.

TL;DR

Healthcare technology adoption is effectively complete. Over 99% of US hospitals use certified EHRs. The remaining problem is not adoption but routine interoperability and usability, which is why fax and clunky workflows still survive in 2026.

How far has healthcare technology adoption actually come?

Digitization is essentially finished. As of 2024, more than 99% of US non-federal acute care hospitals and 91% of office-based physicians had adopted a certified Electronic Health Record (EHR), the digital version of a patient's chart, according to the Assistant Secretary for Technology Policy (ASTP/ONC), the federal office that tracks health IT adoption. In 2008, fewer than one in ten hospitals used a fully electronic system.

Worth being precise about: the common claim that only a handful of healthcare organizations have implemented EMR or EHR systems is no longer accurate anywhere in US acute care. The industry did adopt the technology. What it did not do is make the technology talk to itself, or make it pleasant to use.

Those two failures define healthcare IT in 2026, and the interoperability numbers show the gap plainly. ASTP/ONC tracks four exchange behaviours: finding, sending, receiving and integrating outside patient records. In 2023, 70% of hospitals did all four at least sometimes, but only 43% did all four routinely, up from 28% in 2018. By 2025, 76% of hospitals reported engaging in all four domains. Adoption is near-universal. Habitual, dependable exchange is not.

Why do fax machines survive in a fully digital industry?

Because the fax number is the one address every organization still answers.

When two hospitals run different EHRs and their systems cannot reliably exchange a summary of care, someone prints it and faxes it. The most recent federal figures on exchange methods found that roughly seven in ten hospitals used mail or fax to send (71%) and receive (68%) summary-of-care records in 2019, making it the single most common method at the time. Vendor surveys quote much higher current figures, often 80–90% of providers, but those come from companies selling fax or fax-replacement services and are better treated as directional than measured.

Ask clinicians why they still fax and the usual answer is confidentiality. That is part of it, and it is not irrational: a fax produces a point-to-point transmission with a timestamped confirmation, and it does not depend on the recipient's IT department having built anything. But security is no longer the honest justification. Interoperability is. Fax persists because it is the lowest common denominator that always works, not because it is the safest option available.

The same logic explains why other legacy tools outlive their obituaries. We covered the equivalent argument for pagers and how they work in healthcare, which survive on exactly the same reasoning.

It is also worth being precise in the other direction: fax is not a compliance shield. A misdialled fax number is one of the more mundane ways protected health information gets disclosed, and paper sitting in a shared output tray is not encrypted at rest by any definition.

What does the security excuse actually cost?

Healthcare was again the most expensive industry for data breaches in IBM's Cost of a Data Breach Report 2026, at an average of $6.64 million per breach. That is down from $7.42 million in the previous year's report, but still the highest of the 17 sectors studied, and IBM attributes the sector's position to the value of patient identity data and long incident lifecycles.

The point is not that digital is dangerous. It is that "we use fax because digital is risky" has the risk model backwards. The breaches driving that $6.64 million average are not happening because a clinic sent a referral through an encrypted app.

What would actually improve healthcare IT?

Four changes carry most of the weight. They are ordered here by how much evidence currently supports them.

Can ambient AI documentation really fix the admin burden?

Partly, and the honest answer depends on which benefit you are measuring. Administrative load is the burnout engine, and ambient AI scribes, tools that listen to the visit and draft the clinical note, are the fastest-adopted clinical use of generative AI. The well-being evidence is reasonably strong.

The largest published look at this is a multicenter quality improvement study of 263 physicians and advanced practice practitioners across six US health systems, published in JAMA Network Open in October 2025. After 30 days using an ambient scribe, the share of ambulatory clinicians meeting the burnout cutoff fell from 51.9% to 38.8%, with improvements in cognitive task load, after-hours documentation and attention to patients.

Worth being precise about: that study was a quality improvement project without a control group, relying on self-reported measures, so it cannot fully separate the tool from novelty and expectation effects. Time savings are also far more modest than vendor marketing implies. A 2026 multi-site study of roughly 1,800 clinicians found around 16 minutes saved per eight hours of patient care, and a randomized crossover trial in JAMIA comparing two scribe products reported single-digit daily minute savings. There is currently no good evidence that ambient scribes reduce clinical errors; treat that claim as unproven.

What can actually replace the fax machine?

Secure clinical messaging solves the wrong half of the problem if it only works inside one organization. The realistic path is layered: HIPAA-conscious team messaging for internal coordination, and standards-based exchange for records that cross organizational lines.

Clinical Exchange Methods Compared
Method Reaches other organizations Encrypted in transit Structured, usable data Realistic role in 2026
Physical fax machine Yes, universally No No, image only Fallback of last resort
Cloud fax service Yes, universally Yes No, unless OCR'd Bridge while APIs mature
Secure clinical messaging app Only where both parties are on it Yes Partly Internal teams, handoffs, on-call
Direct secure messaging (HISP) Between certified systems Yes Yes, structured summaries Referrals, transitions of care
FHIR API exchange Where both systems expose APIs Yes Yes, fully structured The destination; uneven today

The honest read: fax volume falls when the alternative reaches the same recipients, not when clinicians are told fax is embarrassing. If you are evaluating the internal messaging layer, our complete guide to encrypted text messaging in healthcare covers what to check before committing to a platform.

Is regulation finally forcing interoperability?

Yes, and the most consequential near-term driver is the CMS Interoperability and Prior Authorization final rule (CMS-0057-F), a federal rule requiring health plans to modernize data exchange and prior authorization. Its operational provisions took effect on 1 January 2026: impacted payers must decide expedited prior authorization requests within 72 hours and standard requests within 7 calendar days, and must give specific denial reasons. By 1 January 2027, those payers must run four HL7 FHIR (Fast Healthcare Interoperability Resources) APIs in production: Patient Access, Provider Access, Payer-to-Payer and Prior Authorization. CMS estimates roughly $15 billion in savings over ten years, mostly from taking friction out of prior authorization.

This matters to clinicians who will never read a rule number, because prior authorization is one of the largest remaining fax-and-phone workflows in American medicine.

Why do clinicians reject new IT systems?

Not because they are technophobic. Because the tools add clicks. The 2026 ambient scribe evidence makes the point neatly: the biggest benefits went to clinicians who were coached on how to work with the tool, while unsupported users showed inconsistent use and smaller gains. Training is not the soft part of a rollout. It is the part that determines whether the software works at all. Consumer-grade interface design and real on-the-job support are the difference between a tool that removes friction and one that relocates it. For a sense of what clinicians actually keep using, see our roundup of digital tools every healthcare worker should know about.

What about the new HIPAA rules you may have read about?

Worth being accurate here, because a lot of published content is not. In December 2024, the HHS Office for Civil Rights issued a Notice of Proposed Rulemaking to modernize the HIPAA Security Rule, the federal standard governing protection of electronic protected health information. The proposal would mandate encryption at rest and in transit, require multi-factor authentication and asset inventories, and remove the "addressable" category that let organizations document their way out of controls. It was published in the Federal Register on 6 January 2025, and the comment period closed on 7 March 2025.

It is still a proposed rule. As of mid-2026 no final rule has been issued, the Office of Management and Budget's regulatory agenda now targets July 2027 for final action, more than 100 hospital and provider groups have asked HHS to withdraw the proposal, and the existing Security Rule remains in force in the meantime. Anything describing "2026 HIPAA encryption requirements" as current law is wrong.

So, is healthcare ready for the future?

Readiness is no longer about whether the systems exist. They exist, they are certified, and nearly every encounter in the country is documented electronically. Readiness now means three narrower things: whether records move routinely rather than occasionally, whether the software costs clinicians fewer minutes than it saves, and whether the security story is based on the actual threat model rather than on habit.

"What technology could improve conditions in healthcare?" is the question the industry has been asking for a decade. The more useful version of it now is narrower: which of the tools already sitting in the building are being used properly?

Key Takeaways

  1. EHR adoption is done. Over 99% of US non-federal acute care hospitals and 91% of office-based physicians had a certified EHR as of 2024.
  2. Interoperability is the real gap: only 43% of hospitals routinely exchanged records across all four tracked domains in 2023.
  3. Fax survives because of reach, not security. It is unencrypted, and misdirected faxes are a routine disclosure risk.
  4. Ambient AI scribes have solid evidence for reducing burnout, weaker evidence for saving time, and no established evidence for reducing errors.
  5. CMS-0057-F is already live operationally, with four required FHIR APIs due 1 January 2027, the biggest external push toward real data exchange.
  6. The proposed HIPAA Security Rule update is not law yet; final action is currently pencilled in for July 2027.
Chart Less. Care More.

The documentation is the bottleneck. Not your team.

HosTalky brings secure team messaging and AI-assisted clinical documentation into one place, so the minutes you spend on the record go back to the people in front of you.

Explore HosTalky AI Scribe

FAQs

Do most hospitals still use paper records?

+

No. As of 2024, over 99% of U.S. non-federal acute care hospitals and 91% of office-based physicians had adopted a certified electronic health record, according to ASTP/ONC. Paper and fax persist for records moving between organizations, not for documentation inside them.

Why is fax still used in healthcare in 2026?

+

Mainly interoperability, not security. Every provider, lab, pharmacy and payer can receive a fax, while structured electronic exchange only works when both systems support it and are configured for it. Only 43% of hospitals routinely engaged in all four domains of electronic exchange in 2023, so fax remains the reliable fallback.

Is fax more HIPAA-compliant than secure messaging?

+

No. HIPAA does not endorse specific technologies; it requires appropriate safeguards. Fax transmissions are unencrypted and misdirected faxes are a common source of accidental disclosure, while encrypted messaging platforms built for healthcare can meet Security Rule expectations through access controls and audit logs.

Do AI scribes really reduce documentation time?

+

They reduce it, but less than marketing suggests. Published studies show modest and variable time savings, around 16 minutes per eight hours of patient care in one 2026 multi-site study. The stronger and more consistent finding is improved clinician well-being: burnout fell from 51.9% to 38.8% after 30 days in a 2025 JAMA Network Open multicenter study.

What is CMS-0057-F and does it affect clinicians?

+

It is the CMS Interoperability and Prior Authorization final rule. Operational requirements began on 1 January 2026, including 72-hour expedited and 7-calendar-day standard prior authorization decisions with specific denial reasons. Four FHIR APIs must be live by 1 January 2027. Clinicians feel it mainly through faster, less manual prior authorization.

Are the new HIPAA Security Rule encryption requirements in effect?

+

Not yet. The proposal was published on 6 January 2025 and remains a proposed rule; the Office of Management and Budget's agenda now targets July 2027 for final action. The current HIPAA Security Rule stays in effect until then.

Sources & References

▾
Assistant Secretary for Technology Policy / Office of the National Coordinator for Health IT. National Trends in Hospital and Physician Adoption of Electronic Health Records. HealthIT.gov Quickstats.
Office of the National Coordinator for Health IT. Interoperable Exchange of Patient Health Information Among U.S. Hospitals: 2023. ONC Data Brief No. 71, May 2024.
ASTP/ONC. Electronic Health Information Exchange by Hospitals. HealthIT.gov Quickstats.
Barker, W. & Chang, W. Hospital Electronic Health Record Adoption, 2008–2024. ONC Data Brief No. 83, June 2026.
Olson, K. D., et al. (2025). Use of Ambient AI Scribes to Reduce Administrative Burden and Professional Burnout. JAMA Network Open, 8(10):e2534976.
Chowdhury, A., et al. (2026). Comparing ambient scribes: a randomized crossover clinical trial addressing ambient scribe technologies' impact on physician burnout. Journal of the American Medical Informatics Association, 33(5):990–999.
Centers for Medicare & Medicaid Services. CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) Fact Sheet.
U.S. Department of Health and Human Services, Office for Civil Rights. HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity for Electronic Protected Health Information, factsheet.
IBM & Ponemon Institute. Cost of a Data Breach Report 2026, released 29 July 2026.


Written by

Johnny Ramirez

View all articles by Johnny ->