Technology empowers only when power changes hands.
A digital use case earns the word empowerment only when a person gains usable capability without inheriting unsupported work, cost, safety risk, privacy exposure, or exclusion.
A portal account, app download, connected sensor, message channel, online choice menu, or data export can create access without creating agency. The feature may exist while the person cannot understand the information, correct an error, complete the task, reach a clinician, delegate safely, or leave without losing care.
Empowerment is an operating state, not a product category or engagement metric. Power changes hands when a person can do something consequential, understands the limits, controls participation, can obtain support, and has a safe route when technology fails.
The Agency Transfer Test evaluates one bounded patient job, such as obtaining a result, correcting a medicine list, choosing a treatment, sending a home reading, authorizing a caregiver, exporting a record, recovering identity, or escalating a concerning symptom. It does not score an entire platform with one number.
For each job, the Agency Transfer Map records the capability, evidence boundary, patient and caregiver work, clinical closure, inclusion path, data power, outcome proof, and four counterweights: burden, cost, safety risk, and exclusion. The model is editorial, not a government, legal, accreditation, certification, FDA, or CMS term.
This job-level test can be used alongside the site’s existing guidance on personal health management online, patient engagement through telehealth, interoperable patient health information, and clinical AI in healthcare. Those broader capabilities become patient-empowering only when a person can complete the intended task, understand the limits, control the data relationship, obtain help, and reach a safe care-equivalent route.
Technology empowers only when it transfers a usable capability, preserves a care-equivalent path for people who cannot or do not use it, connects signals to an accountable clinical response, and gives the person real power to understand, correct, choose, act, share, revoke, export, exit, and escalate.
This model rejects unsupported self-service. Moving scheduling, monitoring, documentation, interpretation, troubleshooting, supply management, or coordination onto patients and caregivers can reduce organizational work and increase total burden. Agency gain and burden must remain visible side by side.
The thirteen tests below move from the empowerment state and map through records, exchange, home signals, claims, burden, identity, data choice, accessibility, contracting, and final measurement.
Start with power, not the feature.
Name the power to be transferred: obtain and understand information; correct or contribute information; choose among real options; act to complete a care task; share or delegate authority; or exit and escalate. A use case may transfer more than one, but each needs its own evidence.
State the patient population, clinical context, bounded job, current barrier, institutional capability, proposed transfer, responsible team, and intended patient outcome. Separate a convenience feature from a clinical pathway whose failure can delay or harm care.
Do not use activation, login, message sent, device shipped, data displayed, form started, or option viewed as proof of empowerment. These are delivery or adoption events. The patient job may still fail before action or clinical closure.
Include the right to decline. A person who must use a digital channel to preserve ordinary access has not gained choice. Define a nondigital route with comparable care quality, urgency, cost transparency, language and disability access, and continuity.
Set local release conditions and stop triggers. Serious safety concern, unstaffed alerts, inaccessible critical task, identity lockout, deceptive consent, missing urgent route, rising burden, or unequal completion can justify pause or redesign even when use grows.
Map one patient job from intention to clinical closure.
The map follows a single job across the patient, caregiver, technology, organization, payer, partner, and clinical team. It shows where power changes hands, where work accumulates, where a decision returns to the institution, and what closes the loop.
Begin with the patient’s intended outcome, not the screen sequence. “Understand whether this result needs action” is a job. “Open the result tab” is a feature interaction. “Correct the medicine list before surgery” is a job. “Submit a portal form” is one possible step.
Observe real attempts across supported modes and conditions. Include new users, complex records, proxy access, low connectivity, assistive technology, language support, identity recovery, changed insurance, device failure, outside data, and urgent symptoms.
Mark every staffed destination. A message, reading, correction request, prior-authorization question, or symptom report needs a named receiving team, disclosed local response window, disposition, escalation, and urgent alternative. An inbox is not a care model.
Use the map to remove work before adding instruction. Simplify steps, reconcile sources, eliminate duplicate entry, improve accessibility, prefill safely, connect support, and close handoffs. Training cannot repair a structurally unfinishable job.
Evaluate the function the patient actually uses.
Regulatory status, risk, evidence, privacy, support, and clinical consequence can differ by function inside one product. A general wellness feature, symptom assessment, clinical decision function, connected measurement, record viewer, messaging channel, and treatment tool should not inherit one broad claim.
Write the intended user, patient job, clinical context, input, output, claim, action, response, failure mode, and boundary with care. Ask what the function does, what the organization says it does, and what the person may reasonably believe it does.
Use the FDA Digital Health Policy Navigator as an official educational tool for exploring whether a function may fall within device policy. It does not make a formal device determination or prescribe design, testing, implementation, coverage, or clinical use.
The January 2026 FDA general wellness guidance depends on function and intended use. A product fitting a low-risk wellness policy is not thereby proven clinically effective, authorized for a medical claim, covered by insurance, accessible, or beneficial in one organization.
Preserve an evidence-to-claim file at release and through change. A new population, sensor, model, threshold, interface, claim, response workflow, vendor, data source, or use setting can reopen the boundary and require review.
Turn record access into usable and correctable information.
Access is a foundational patient power, but a displayed record can remain fragmented, delayed, difficult to interpret, inaccessible, or hard to correct. Design the bounded job around what the person needs to understand or do with the information.
For covered entities and designated-record-set information within HIPAA scope, the individual right of access creates important rights and processes, subject to scope, exceptions, and current guidance. It does not guarantee that every app contains every record or that all consumer-app data fall under HIPAA.
HHS frames access as “Get It, Check It, Use It.” Keep the current legal scope and Ciox-related caveats precise. Distinguish access rights, correction processes, app permission, proxy access, and organizational conveniences rather than describing one portal as the complete right.
Measure the completed job: information successfully obtained, understood within its limits, used for the intended decision, and corrected or escalated when wrong. Downloads and views show activity; they do not prove comprehension, accuracy, or action.
Connect concerning information to a staffed destination. State the response window and urgent alternative. A result comment box, automated explanation, or correction form should not imply real-time clinical monitoring when no team is assigned.
Transfer data power without promising a complete record.
Exchange can reduce the work of assembling information across providers, payers, apps, and networks. It can also fail through identity mismatch, unavailable source, unsupported purpose, incomplete data, delayed update, duplicate record, inaccessible format, or a connection the receiving workflow does not use.
Define the patient job: gather a record for a new clinician, compare medicines, check authorization status, share information with an app, obtain prior records before a procedure, or another bounded purpose. State which sources, data classes, dates, and organizations are expected, then show what remains missing.
TEFCA offers a national exchange framework that can support Individual Access Services exchange. Participation, connectivity, patient matching, permitted purpose, source availability, and data quality still matter. Do not promise a universally complete, current, correctly matched record solely because a TEFCA route exists.
Information blocking has defined actors, electronic health information, knowledge, interference, and exception analysis. Ordinary portal friction, incomplete data, a poor interface, or a delayed response is not automatically an information-blocking violation. Route suspected issues for fact-specific review while correcting the patient experience.
CMS interoperability and prior-authorization requirements apply to specified impacted payers with different provisions and dates. Certain operations began in 2026 and most API requirements begin in 2027. The specified prior-authorization API concerns non-drug items and services; April 2026 drug policy remains proposed.
Give every home signal a staffed destination.
A connected measurement, symptom check, message, photograph, questionnaire, or device alert can move observation into daily life. It becomes patient power only when the person knows what to do, the signal reaches a named team, and the care pathway responds within a disclosed local window.
Define eligible patients, clinical purpose, device or input, expected use, measurement quality, signal rule, staffing, hours, receiver, triage, disposition, escalation, urgent alternative, missed-reading response, supplies, replacement, technical support, and exit.
Never imply continuous monitoring when the service is not continuously staffed. Disclose hours, expected response, urgent symptoms, emergency route, technical downtime, travel or connectivity limits, and what happens when data do not arrive.
Measure signals with a named receiver and disposition inside the disclosed local window, plus missed, late, duplicate, stale, false, and clinically irrelevant alerts. Pair response with patient workload, outcome, access, safety, subgroup reach, and staff burden.
The CMS ACCESS model began July 5, 2026 as a voluntary ten-year Original Medicare model test for selected chronic-condition tracks and technology-supported care. It is not a proven, permanent, universal, or required model, and participation does not establish local effectiveness.
Do not convert regulatory status into an empowerment claim.
Clearance, approval, enforcement discretion, guidance fit, pilot selection, payer model participation, marketplace availability, and local procurement answer different questions. None automatically proves that a person gained agency, the clinical workflow is staffed, the outcome improved, or cost and burden fell.
Build a claim ladder from the exact function: what it is permitted or positioned to do; what evidence supports performance; what the organization has validated locally; what the patient can successfully do; and what clinical or patient outcome has been observed within scope.
FDA announced the first participant in the TEMPO digital-health-device pilot on July 22, 2026. The pilot concerns selected manufacturers, devices, uses, and enforcement discretion. Effectiveness has not yet been evaluated, and participation is not clearance, approval, coverage, or a provider mandate.
A low-risk general wellness function may sit outside certain device-policy concerns and still require truthful claims, accessible design, privacy review, cybersecurity, usability, evidence, and a safe clinical boundary. Policy category does not answer whether the patient can act successfully.
Approve patient-facing language with the same precision as procurement. Explain what the function does, does not do, who reviews information, response time, urgent alternative, data use, cost, support, and exit. Reopen approval when the feature, evidence, workflow, vendor, or claim changes.
Measure the work transferred with the power.
Technology can move work from schedulers, nurses, records teams, payers, and service centers into homes. Patients and caregivers may enroll, verify identity, enter data, charge devices, maintain connectivity, interpret instructions, troubleshoot, purchase supplies, coordinate responses, and repeat information across systems.
Count minutes, steps, decisions, devices, passwords, messages, calls, retries, forms, travel, supplies, data use, subscription, out-of-pocket cost, caregiver work, and days to completion. Observe the tail, not only the median, and separate organization effort saved from total work created.
Ask which work is meaningful agency and which is administrative transfer. Recording a personal goal may increase control. Re-entering demographics already held by the organization, chasing an unanswered message, or solving an integration failure does not.
Provide proactive support for high-consequence tasks. Offer setup, test completion, device replacement, supplies, connectivity help, language and disability support, caregiver training, identity recovery, and a human route. Do not wait for the most burdened people to generate a complaint.
Stop or revise when agency gain does not justify burden, the nondigital route is inferior, caregivers absorb unsafe responsibility, clinical teams cannot respond, cost shifts unpredictably, or excluded groups have materially lower completion or outcomes.
Protect identity without making care depend on perfect credentials.
Digital identity can unlock records, messages, payment, proxy access, device setup, and exchange. It can also lock out a patient after a phone change, name mismatch, forgotten credential, disability barrier, compromised account, unavailable document, or support failure.
Define enrollment, identity proofing, authentication, account recovery, device loss, fraud response, shared-device use, proxy invitation, legal-representative review, delegation, revocation, audit, emergency access, and nondigital care. Match assurance and friction to the risk of the actual function.
Consent, HIPAA authorization, app permission, proxy access, power of attorney, personal representative status, and caregiver participation are not interchangeable. Identify the applicable authority, scope, data, task, duration, and revocation route rather than using one broad “consent” switch.
NIST SP 800-63 Revision 4 provides current federal digital-identity guidance. It is voluntary outside its federal scope unless adopted by an applicable authority or contract, and it does not create a hospital mandate or prove the clinical identity relationship by itself.
Measure enrollment and recovery completion, time to first successful action, lockout, fraud, proxy success, revocation, help needed, channel parity, and care delay. A secure system that predictably blocks authorized patients from necessary care needs redesign and a safe alternate.
Let people share, revoke, export, and leave.
Data power includes more than agreeing to a privacy notice. A person should understand which data the function collects or derives, who receives them, why, how long they persist, what happens if sharing stops, how to revoke access, how to export usable information, and how to leave without losing necessary care.
Map data from input through inference, transmission, storage, secondary use, support, supplier, export, deletion where applicable, and termination. Distinguish data controlled by a HIPAA covered entity or business associate from data held by consumer apps or other entities under different laws and policies.
The FTC Health Breach Notification Rule can apply to scoped personal-health-record and related entities outside HIPAA. The amended rule became effective July 29, 2024. It creates breach-notification duties within scope; it is not HIPAA, comprehensive privacy regulation, product certification, or proof of safe data governance.
Test export and exit before launch. A promised download may be incomplete, unreadable, missing provenance, too large, delayed, or unusable in the next service. An account may close while a vendor retains an active connection or unresolved clinical signal.
Do not make consent to optional data use a condition for necessary care unless a valid requirement supports it. Provide role-appropriate explanations, preserve choice, and separate care operations from research, marketing, model training, or other purposes where the authorities and expectations differ.
Release only when every supported path can complete the job.
Accessibility is not one audit at the edge of a release. A person must be able to discover, enroll, identify, navigate, perceive, understand, operate, correct, recover, contact support, receive response, and complete the clinical job with the technology and assistance actually available.
Test with disabled people and representative assistive technologies, input methods, zoom, reflow, contrast, captions, transcripts, language support, plain language, cognitive load, time limits, error recovery, authentication, documents, data visualizations, messages, devices, and support channels.
A May 2026 HHS interim final rule extended specific Section 504 web and mobile accessibility compliance dates for HHS funding recipients to May 11, 2027 for recipients with at least fifteen employees and May 10, 2028 for smaller recipients. Existing accessibility duties continue.
Apply the correct entity and scope. The HHS rule concerns recipients of HHS federal financial assistance and does not automatically govern every private app. Legal compliance also does not prove that the complete patient job or nondigital alternative is usable.
Treat materially lower completion, longer time, repeated error, unavailable support, or reduced clinical closure for an access mode as a release defect. Correct the pathway before requiring it for care.
Contract for support, change, and exit before dependency forms.
A vendor contract shapes patient agency through data rights, accessibility, identity, interfaces, response, support, device replacement, pricing, change notice, subcontractors, evidence, incident handling, portability, termination, and transition. Review these conditions before the function becomes embedded in care.
Translate the Agency Transfer Map into procurement requirements. The vendor supplies a product or service; the healthcare organization and partners still need a staffed care model, accessible channels, clinical oversight, patient communication, fallback, integration, outcome measurement, and stop authority.
Avoid outcome guarantees unsupported by evidence, but require usable evidence and audit rights proportionate to risk. Preserve access to incident, performance, accessibility, support, complaint, data-quality, change, and subcontractor information needed to protect patients.
Model total cost across organization, payer, patient, and caregiver. Include implementation, integration, staffing, device, supplies, connectivity, support, replacement, training, data management, accessibility, monitoring, incident, renewal, and exit. A free app can create an expensive care service.
Define suspension and rollback for safety, unstaffed response, privacy event, identity failure, accessibility barrier, vendor outage, evidence change, unexpected burden, or unequal outcome. Contract language should support the organization’s duty to act, not make correction commercially impossible.
Measure completed agency, not digital activity.
Use one measurement chain for the bounded job: eligible population, offer, choice, start, first successful action, completed patient job, clinical closure, patient goal or control, outcome, sustained use where relevant, burden, cost, safety, exclusion, and exit.
Report time to first successful action as a median and tail, not only an average. Track comprehension, tool limits, urgent-alternative understanding, correction age and closure, export or exchange success, completeness and freshness defects, signal disposition, identity recovery, proxy success, accessibility parity, nondigital parity, and post-release incidents.
ONC’s July 2025 brief using 2024 survey data reported that 65 percent of individuals nationally were offered and accessed an online record or portal. Among people who accessed a portal, 57 percent used an app. Separately, 59 percent of individuals nationally had multiple records or portals, while 7 percent used an organizing app. These are descriptive self-reports, not outcome causation.
The survey response rate was 27.31 percent, and national patterns do not prove local completion, agency, equity, safety, or benefit. Use external data to frame questions, then measure the specific patient job and evidence boundary in the local setting.
Keep agency gain, patient and caregiver burden, safety, exclusion, workforce load, and total cost in separate views. Do not let one composite score hide a serious access barrier or allow growing use to cancel an unstaffed clinical risk.
Conclusion: empowerment is a transfer of usable power.
Health technology can make information, decisions, actions, and care more reachable. It can also create another gate, move work home, expose data, fragment records, generate unstaffed signals, or make ordinary care depend on credentials, devices, and connectivity.
The Agency Transfer Test begins with one bounded patient job and six possible powers: obtain and understand; correct and contribute; choose; act; share and delegate; and exit and escalate. The Agency Transfer Map follows that job to clinical closure.
Every gain stays beside four counterweights: patient and caregiver work, cost, safety and privacy risk, and exclusion. A product does not earn the empowerment label by increasing logins, messages, downloads, device shipments, or choices displayed while the patient remains unable to complete the job.
Real power includes a staffed response, understandable limits, a care-equivalent nondigital path, identity recovery, proxy control, accessibility, correction, revocation, export, exit, urgent escalation, and the ability to change course without losing necessary care.
The final proof is simple to state and demanding to deliver: the person can act, the care loop closes, the burden is supportable, excluded people have an equal route, and the capability remains under the person’s meaningful control.
Sources and further reading
- HHS, Your Health Information Rights: Get It, Check It, Use It. Official individual-access guidance for covered-entity records within HIPAA scope, subject to designated-record-set boundaries, exceptions, and current Ciox-related caveats.
- ONC Data Brief 77, Individuals’ Access and Use of Patient Portals and Smartphone Health Apps, 2024. July 2025 descriptive self-report analysis with a 27.31 percent response rate, not causal outcome evidence.
- ONC, Information Blocking. Current official material on defined actors, electronic health information, knowledge, interference, and exceptions. Ordinary portal friction or incomplete records are not automatically information-blocking violations.
- ONC, Trusted Exchange Framework and Common Agreement. A national exchange framework that can support Individual Access Services. Connectivity does not guarantee universal participation, matching, complete data, freshness, or clinical use.
- CMS, Interoperability and Prior Authorization Final Rule CMS-0057-F. Requirements for specified impacted payers with varied 2026 and 2027 dates. The specified prior-authorization API concerns non-drug items and services.
- CMS Innovation Center, ACCESS Model. A voluntary ten-year Original Medicare model test launched July 5, 2026 for selected chronic-condition tracks. It is not proven, permanent, universal, or required.
- FDA, Participant Selected for TEMPO Digital Health Devices Pilot. The first participant was announced July 22, 2026. Selection and enforcement discretion are not clearance, approval, coverage, provider mandate, or effectiveness proof.
- FDA, General Wellness: Policy for Low Risk Devices. January 2026 function- and intended-use-dependent guidance. Policy fit does not establish clinical effectiveness, authorization for a medical claim, payment, or local benefit.
- FDA, Digital Health Policy Navigator. An official educational tool for exploring function-specific device-policy questions. It is not a formal device determination or design, testing, coverage, or implementation prescription.
- FTC, Health Breach Notification Rule. The amended rule took effect July 29, 2024 for scoped non-HIPAA personal-health-record and related entities. It is not HIPAA, comprehensive privacy regulation, or certification.
- HHS, Section 504 Web and Mobile Accessibility Compliance Dates. May 2026 interim final rule extending specified dates for HHS funding recipients to 2027 or 2028 by employee count; existing accessibility duties continue.
- NIST SP 800-63 Revision 4, Digital Identity Guidelines. Final federal digital-identity guidance from 2025. It is voluntary outside federal scope unless adopted and does not itself create a hospital mandate or clinical identity proof.




