The 21st Century Cures Act and its information-blocking provisions have pushed US EHR teams toward a particular shape of FHIR tooling. Patient access, third-party app access, bulk export, and audit trails all sit on FHIR endpoints now, and the tools you pick to build, test, and certify against those obligations matter more than they did a few years ago. The seven below are the FHIR tools US EHR development teams actually use in Cures Act work in 2026.
For FHIR primers and references, the rest of the site has surrounding material. The complete guide to FHIR-based EHR development for US healthcare in 2026 cornerstone covers the broader picture this list fits inside.
What Cures Act Work Asks of Your FHIR Tooling
The Cures Act information-blocking rules push EHRs to make data available to patients and third-party apps through FHIR APIs, without unreasonable barriers. That means the EHR has to expose USCDI-aligned resources, support SMART on FHIR app launches, handle Group-level $export for population data flows, and keep audit trails that satisfy federal compliance review.
A development team building or extending an EHR has to ship code that passes Cures Act certification, runs at production scale, and stays current as the rules tighten. The tools below are the ones that have proven themselves in that loop.
The 7 FHIR Tools to Know for Cures Act Work
These are the tools US EHR teams actually lean on:
- Inferno, the ONC-developed open-source FHIR conformance testing suite, used in formal Cures Act certification testing.
- HL7 FHIR Validator, the standard validation tool from HL7 that checks resources against US Core and other profile packs.
- Touchstone Project, the AEGIS test harness used by some certification work and by teams that want stronger conformance testing.
- SMART App Launcher, the open-source reference launcher for SMART on FHIR, used to validate app launches against the spec.
- Bulk Data Client and Server reference implementations, used for testing Group-level $export flows.
- US Core IG (US Core Implementation Guide), the canonical reference profile pack that anchors most Cures Act-aligned FHIR work.
- Aidbox or HAPI sandboxes configured to US Core, used as development targets where teams can iterate against the same profiles certification will use.
Each fits a different stage of the work. Inferno and Touchstone are for conformance testing. The HL7 Validator is for day-to-day resource validation. SMART App Launcher and the Bulk Data reference implementations exercise the launch and export flows. US Core IG is the reference content the rest depend on.
Where the Tools Fit in the Development Cycle
Early-stage development uses the HL7 Validator and a US Core-configured sandbox to keep resources conformant from the start. Mid-stage development brings in the SMART App Launcher and Bulk Data reference implementations to validate cross-cutting flows.
Pre-certification work focuses on Inferno (and optionally Touchstone) against the project's actual deployment, with iteration on whatever fails until the runs clear. Post-certification operations rely on continuous validation against US Core, ideally automated as part of the deployment pipeline so that drift is caught early.
The top 6 EHR development stacks for USCDI compliance in 2026 write-up covers the stacks these tools tend to sit on top of, which matters because conformance testing is easier on a stack that ships US Core support natively.
Where Teams Tend to Get Stuck
Three patterns trip up Cures Act-driven FHIR projects regularly. First, treating validation as a release-time check rather than a continuous one, which lets conformance drift accumulate. Second, testing against synthetic data that does not represent real production shapes, particularly for bulk export volume. Third, underestimating how much of the work is operational rather than developmental: audit logging, app registration flows, and consent management all need attention.
The monolithic EHRs vs FHIR-first modular stacks for US projects piece covers the architectural choices that shape how easy these realities are to handle.
Picking the Right Toolchain
A short filter sorts most projects. Are you in formal Cures Act certification? Bring in Inferno early. Are you in day-to-day development? Use the HL7 Validator continuously. Are you exposing bulk export? Test against the reference implementations against real-shape data. Are you iterating on profiles? Pin a specific US Core version and stay there until the team is ready to roll forward.
Cures Act work rewards consistent tooling over clever tooling. Pick the standard reference tools, wire them into your pipeline, and keep them running.
Sources
- ONC Cures Act Final Rule (canonical regulatory anchor, evergreen) - HealthIT.gov
- Inferno conformance testing tool home (evergreen) - HealthIT.gov
- Inferno Redesigned (ONC, evergreen / recent) - HealthIT.gov blog



