Thought Leadership1up Gateway

1up Gateway FAQ: How to Meet CMS-0057 Compliance Without Rebuilding Your FHIR Infrastructure

Every health plan navigating CMS-0057 must choose its own path to compliance: build it entirely in-house, buy a turnkey vendor solution, or land on a hybrid of the two.

Plans already made that choice once for CMS-9115. Some of them chose to build their own FHIR server and enterprise data warehouse, and many have decided to stay the course for CMS-0057 rather than start over. These tend to be technically sophisticated organizations with both the resources and the appetite to own and manage what they’ve built.

However, standing up CMS-0057’s FHIR APIs themselves isn’t the hard part. What’s complicated is everything the rule doesn’t spell out but still has to work, including building an operational network of endpoints for Payer-to-Payer Data Exchange, onboarding providers and driving adoption for both Provider Access and Electronic Prior Authorization (ePA), and routing ePA requests across multiple utilization management (UM) vendors so the end-to-end workflow actually functions across lines of business. That operational layer — not the APIs themselves — is where CMS-0057’s real complexity lives.

And that’s exactly the challenge we dug into at our recent webinar with Point of Care Partners, “Compliance Without the Rebuild”. Partway through the session, we introduced our 1up Gateway solution as a possible solution.

The response, live and in the weeks since, told us this solution hit a nerve. Below are the questions we heard most, answered directly.

Q: What is the 1up Gateway and how does it work for CMS-0057?

A: The 1up Gateway is a deployment model that sits in front of a health plan’s own FHIR infrastructure and handles everything external-facing on top of it. It works the same way across whichever CMS-0057 products a health plan runs, whether that’s 1up Payer-to-Payer Data Exchange, 1up Provider Access, 1up Electronic Prior Authorization, 1up Patient Access, or the full CMS-0057 suite. The plan’s infrastructure stays where it is and remains the system of record; the 1up Gateway operates as the compliance layer in front of it.

In practice, that means 1up takes on the pieces that don’t touch your data directly, like vetting and onboarding external payers, providers, and applications; building and maintaining the network endpoints and systems necessary to make each workflow actually function; managing member consent; and handling CMS reporting, so it’s simple for plans to submit their usage data every year. 

The benefit is straightforward: your team keeps ownership of the data and the infrastructure decisions that got you this far, and 1up takes on the operational and compliance complexity of making those APIs work in earnest, so they actually drive ROI instead of just checking a compliance box. 

Q: Do we need a one-time data dump, or can the 1up Gateway pull our FHIR API directly?

A: In the 1up Gateway model, connecting directly to your existing API is the default. The 1up Gateway operates as a connection layer, not a data ingestion pipeline. When a request comes in, whether from a provider or another payer, the 1up Gateway authenticates the request, queries your FHIR server in real time, and returns the response. We don’t store any data on our platform; we simply pass it through to you.

Q: What authentication methods does 1up support?

A: Generally, whatever your security team requires. For the connection between 1up and your backend systems, we support OAuth2, and mTLS, layered with IP allowlisting where that’s part of your existing posture. We’re not asking you to adopt a new security model just to stand up a 1up Gateway deployment. 

For member-facing authentication, such as 1up Patient Access, we support identity provider integration through standard protocols like SAML and OIDC, including running multiple identity providers in parallel if your organization operates more than one in production.

Q: What visibility do you get into network activity and compliance reporting?

A: Even without the full 1up Platform underneath it, a 1up Gateway deployment gives you real visibility through the 1up Console. You can view your network connections, review usage reporting, and track job status for every request, seeing at a glance what succeeded, what failed, and why. A few things you don’t get compared to a full 1up Platform deployment include the Member Directory and Longitudinal Member Profiles, both of which require your member data to be stored on our platform.

Q: What happens if a member’s prior payer isn’t connected to the 1up Network?

A: The workflow doesn’t stall out — it just moves forward on the parts it can. The system captures the member’s consent and their stated prior payer, logs the missing connection as an exception, and routes that exception to a defined follow-up path instead of letting it disappear. However, this should become a rarer occurrence over time. We’re actively growing the 1up Network, with the goal of connecting to every payer endpoint, making this concern obsolete, eventually.

Q: Does the CMS-0057 Payer-to-Payer Data Exchange 7-day window start at enrollment or consent?

A: The seven-day window isn’t a fixed date tied to the calendar. It’s tied to consent. 

Members can give their consent before their coverage is even active, during open enrollment in the fall, for example. But the seven-day countdown to actually request the data doesn’t start until whichever comes later: the date coverage begins, or the date consent comes in. A member who opts in during October for coverage starting January 1 doesn’t start the clock until January 1. A member who opts in later, after their coverage has already started, starts the clock on that later date instead.

In other words, it’s rolling: each member’s window opens on its own timeline, whichever comes later between their coverage start date and their consent date, not on a single date that applies to everyone at the start of the plan year.

Q: How does 1upHealth stay current as CMS regulatory requirements evolve?

A: Compliance regulations are constantly evolving. CMS-9115 has already been amended twice, with CMS-0057 changing the original Patient Access requirements, and CMS-4208-F2 updating Provider Directory. And the proposed CMS-0062 rule would expand Prior Authorization requirements once finalized.

The ecosystem you’re connecting to will keep evolving too. New payers will come online while others drop off, new EHR vendors and provider portals will need connections, and you may decide to expand or change which UM vendors you work with.

1upHealth is the one staying ahead of that curve for all our customers. Our team continually monitors the regulatory and ecosystem landscape, evolving our existing solutions and building new ones as CMS requirements and the broader ecosystem change, so your team doesn’t have to absorb that complexity yourselves.

We’re also on the hook for ongoing network management and maintenance: monitoring and maintaining the health of every connection, and adding or removing endpoints as the ecosystem shifts. Our goal is to maintain connections to all the major EHRs, portals, and UM vendors, staying vendor-agnostic throughout, so your organization has the flexibility to change parts of your own ecosystem over time without disruption.

Watch the Full 1up Gateway Webinar

Want the full context behind these questions? Watch the recorded session,Compliance Without the Rebuild”. The on-demand webinar goes deeper into the gap between CMS-0057 compliance and operational readiness, and we walk through the 1up Gateway model live.

Other Posts You May Like​