ONC to Scale Back Oversight of EHRs With Updates to Health IT Certification

Sept. 21, 2017
The Office of the National Coordinator for Health Information Technology (ONC) on Thursday announced two major changes to the ONC Health IT Certification program that signals it will relax its oversight of how well electronic health records (EHRs) meet government standards.

The Office of the National Coordinator for Health Information Technology (ONC) on Thursday announced two major changes to the ONC Health IT Certification program that signals it will relax its oversight of how well electronic health records (EHRs) meet government standards.

ONC officials stated that the changes are intended to improve the program’s efficiency and reduce burden on health IT developers and users. Through these two changes, ONC will allow self-declaration for certain certification criteria and will exercise discretion in randomized surveillance requirements.

In an ONC Health IT Buzz blog post, Elise Sweeney Anthony, director of ONC’s Office of Policy, and Steven Posnack, director of ONC’s Office of Standards and Technology, said the changes entail approving more than 50 percent of test procedures to be self-declaration and exercising discretion for randomized surveillance of certified health IT products.

These changes were recently issued to ONC-Authorized Certification Bodies (ONC-ACBs) and ONC-Authorized Testing Laboratories (ONC-ATLs), Anthony and Posnack said.

The first change entails ONC revising the ONC-approved test procedures for 30 out of the 55 certification criteria that were adopted to, in part, support the Centers for Medicare & Medicaid Services’ (CMS) Quality Payment Programs. Those 30 certification criteria are now “self-declaration only.”

“This means that health IT developers will self-declare their product’s conformance to these criteria without having to spend valuable time testing with an ONC-ATL. This testing typically included either a visual demonstration of the product’s functionality or submission of documentation confirming the required functionality,” Anthony and Posnack wrote.

The ONC officials note that self-declaration is not a new approach and is used among other industry testing programs. In evaluating the Certification Program’s potential burdens, ONC determined that this industry approach would best meet its efficiency goals while maintaining overall integrity, Anthony and Posnack wrote.

The test procedures for health IT products now designated as “self-declaration” are for functionality-based certification criteria.

“By making this change, ONC enables ONC-ATLs and health IT developers to devote more of their resources and focus on the remaining interoperability-oriented criteria, aligning with the tenets of the 21st Century Cures Act,” Anthony and Posnack wrote. “In addition, health IT developers are still required to meet certification criteria requirements and maintain their products’ conformance to the full scope of the criteria. Any non-conformity complaints received and associated with these certification criteria would continue to be reviewed and investigated by ONC-ACBs.”

The second change ONC announced on Thursday relates to exercising enforcement discretion when it comes to ONC-ACBs conducting randomized surveillance. ONC-ACBs are required to conduct randomized surveillance for, at a minimum, two percent of the health IT certifications they issue.

ONC will not, until further notice, audit ONC-ACBs for compliance with randomized surveillance requirements or otherwise take administrative or other action to enforce such requirements against ONC-ACBs, Anthony and Posnack wrote.

“In addition, we will not consider lack of implementation of these requirements by an ONC-ACB to be a violation of an ONC-ACB’s compliance requirements under the Principles of Proper Conduct, nor will it impact an ONC-ACB’s good standing under the Certification Program,” the ONC officials stated.

This change will permit ONC-ACBs to prioritize complaint driven, or reactive, surveillance and allow them to devote their resources to certifying health IT to the 2015 Edition, Anthony and Posnack stated. “These new actions we are announcing today will support greater availability of certified health IT for providers participating in the CMS’ Quality Payment Program,” the ONC officials wrote.

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...