As for things like the App Orchard and Epic on FHIR https://fhir.epic.com/ : Epic is smart enough to realize that their future lies as the platform of the health system IT stack, in the Ben Thompson sense of a platform / aggregator.
The hospitals are scared of open access, and Epic always does what's in the best interest of their customers, so they push against open access.
At times it feels like it would be better to just get data straight from the database, as custom Epic implementation times are insanely long and costly.
Getting data straight from an EHR's underlying database is risky. The vendors generally don't document or support this, and the schema could change at any time.
The P in HIPAA stands for portability, of course.
Interoperability is really driven by either state/federal reporting requirements, or billing. And there is no incentive for EHR vendors or their client hospital systems to go beyond the exact minimum to get paid.
I've worked with non-health system healthcare companies that have tried to work with Epic on interoperability. They are outright hostile to anyone being able to access any data in their systems unless it's the hospital customer (and even then they're not exactly helpful).
Vendor hostility is only an issue if you actually need to work directly with the vendor. Most of them have no incentive to help other developers who aren't their customers. Why would they? If you're doing something new that requires active Epic cooperation then it's best to partner with a major Epic customer, and put a formal legal agreement in place.