Amid growing interest in the integration of health and social care to improve outcomes, communities across the United States have explored development of Community Information Exchanges (CIEs). A CIE is a community governed infrastructure that enables critical health and social information to be responsibly shared among partner organizations in support of holistic coordination of care. The development and use of a CIE give rise to a host of legal and policy challenges. Use and disclosure of data through a CIE are governed by a patchwork of different legal requirements, at times distinct and at times overlapping. Development of a legal framework for a CIE requires attention to clearly articulated data flows, detailed use cases, strong legal agreements and policy considerations. CIEs typically rely on an individual’s express consent to share their information, requiring careful evaluation of applicable laws and regulations and promotion of community trust and equity. And because many participants in a CIE are HIPAA covered entities, functions of the CIE must fit within HIPAA’s regulatory framework. This article examines in depth two components of a sound legal framework—consent models and HIPAA compliance—identifying considerations and lessons learned to support lawful and ethical information sharing through a CIE.