What It Is

The program answers one question: is this software capable of supporting compliance? It does not answer whether your organization is compliant.

Certification is voluntary for developers - but effectively mandatory in practice, because CMS programs such as Promoting Interoperability and MIPS require providers to use certified EHR technology. That is the actual mechanism behind "certification enables participation in federal programs."

The division of responsibility is the part organizations miss. The vendor certifies the capability. You own the configuration, the access decisions, the monitoring, and the operations.

What Information Is Regulated

ONC-certified systems handle electronic protected health information (ePHI) and related healthcare data, including:

  • Patient medical records
  • Clinical notes and diagnoses
  • Prescriptions and medication data
  • Lab results and imaging data
  • Patient demographics and identifiers
  • Care coordination and interoperability data

Because these systems store and transmit sensitive health data, security and privacy controls are central to the certification criteria.

IT Requirements

The security expectations trace to real certification criteria at 45 CFR 170.315(d).

Access controls and identity management:

  • Authentication and access control: criterion (d)(1) - unique user identification and authorization.
  • Multi-factor authentication: criterion (d)(13) - developers attest whether the module supports MFA.
  • Emergency access and automatic time-out: criteria (d)(6) and (d)(5).

Audit logging and monitoring:

  • Auditable events and tamper-resistance: criterion (d)(2) - system activity is recorded and protected.
  • Audit reports: criterion (d)(3) - the log data can be turned into reviewable reports that support incident investigation.

Data protection and encryption:

  • End-user device encryption: criterion (d)(7).
  • Encrypted authentication credentials and trusted connections: criteria (d)(12) and (d)(9) - protecting data and credentials in transit.

Interoperability and secure data exchange:

  • Standards-based data sharing: secure interfaces and APIs between systems, with controls to prevent unauthorized access during exchange.

Configuration and operational responsibility:

  • The criteria certify capability, not operation. Certification assumes systems are configured securely, access is reviewed regularly, security features are enabled and monitored, and staff are trained. Certification does not protect you if those steps are skipped.

How It Fits Into Cyber Risk Management

ONC-certified technology is one layer of a healthcare security program, not the program itself. The certified capabilities only reduce risk when your operations activate them: access reviews, log monitoring, incident procedures, and vendor oversight.

A cyber risk management program treats the EHR as its most critical asset - and verifies the certified controls are configured, enabled, and producing evidence.

How We Help With ONC Certification Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates how your ONC-certified systems are actually configured - which certified security capabilities are enabled, monitored, and producing the evidence HIPAA and HITECH expect.

How to Prepare

  1. Confirm which systems are ONC-certified

    Document the EHR and health IT platforms in use, their certification status and scope, and the security features available within each system.

  2. Review system configuration and access controls

    Ensure role-based access is enforced, MFA is enabled where the platform supports it, administrative access is limited, and user access is reviewed regularly.

  3. Validate logging, monitoring, and audit readiness

    Confirm audit logs are enabled, logs are retained appropriately, monitoring processes exist, and incidents can be investigated effectively.

  4. Assess data exchange and interoperability security

    Review interfaces with external systems, API access controls, data-sharing agreements, and vendor responsibilities.

  5. Align ONC technology with HIPAA and HITECH requirements

    Certified systems should support the Security Rule safeguards, HITECH breach-response expectations, and your risk assessments and documentation. Technology enables compliance - operations complete it.

Official source

Official source: ASTP/ONC, HHS - ONC Health IT Certification Program

Secondary source: eCFR - 45 CFR Part 170

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25