ONC Health IT Certification refers to the ONC Health IT Certification Program, a U.S. federal program that certifies health IT - including electronic health record (EHR) technology - against national standards. In 2024, HHS renamed its health IT office the Assistant Secretary for Technology Policy (ASTP/ONC); the program keeps its ONC branding.
Certification is designed to ensure health IT products meet national standards for security, privacy, interoperability, data exchange, and auditability. Since the 2015 Edition, products are certified as Health IT Modules against specific criteria, through ONC-Authorized Certification Bodies.
While certification applies to software products, it has significant implications for the organizations that implement, configure, and rely on those systems. In practice, it sets the baseline expectation for how health data should be protected and managed.
The program answers one question: is this software capable of supporting compliance? It does not answer whether your organization is compliant.
Certification is voluntary for developers - but effectively mandatory in practice, because CMS programs such as Promoting Interoperability and MIPS require providers to use certified EHR technology. That is the actual mechanism behind "certification enables participation in federal programs."
The division of responsibility is the part organizations miss. The vendor certifies the capability. You own the configuration, the access decisions, the monitoring, and the operations.
ONC certification is most relevant for two groups.
Health IT vendors:
Healthcare organizations using certified technology:
Even if you are not the software vendor, how you configure and operate ONC-certified systems directly impacts compliance, security, and audit readiness.
ONC-certified systems handle electronic protected health information (ePHI) and related healthcare data, including:
Because these systems store and transmit sensitive health data, security and privacy controls are central to the certification criteria.
ONC certification does not replace HIPAA or HITECH. The three fit together:
Using ONC-certified software does not automatically make an organization HIPAA compliant. It does ensure the platform includes capabilities such as audit logging, access controls, secure authentication, encryption, and interoperability safeguards. Organizations remain responsible for proper configuration, access management, and operational security.
The security expectations trace to real certification criteria at 45 CFR 170.315(d).
Access controls and identity management:
Audit logging and monitoring:
Data protection and encryption:
Interoperability and secure data exchange:
Configuration and operational responsibility:
For small and mid-sized healthcare organizations, ONC certification often:
Many SMBs mistakenly assume that using certified software equals compliance. In reality, most problems arise from poor access management, disabled security features, inadequate logging or monitoring, weak vendor oversight, and a lack of documented processes.
ONC-certified technology is one layer of a healthcare security program, not the program itself. The certified capabilities only reduce risk when your operations activate them: access reviews, log monitoring, incident procedures, and vendor oversight.
A cyber risk management program treats the EHR as its most critical asset - and verifies the certified controls are configured, enabled, and producing evidence.
Here's the key point most organizations miss: ONC certification ensures the tool is capable of supporting compliance - not that your organization is compliant.
Security, privacy, and compliance depend on how systems are configured, who has access, how data is monitored, how incidents are handled, and how vendors are managed.
That responsibility always stays with the organization.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment evaluates how your ONC-certified systems are actually configured - which certified security capabilities are enabled, monitored, and producing the evidence HIPAA and HITECH expect.
Document the EHR and health IT platforms in use, their certification status and scope, and the security features available within each system.
Ensure role-based access is enforced, MFA is enabled where the platform supports it, administrative access is limited, and user access is reviewed regularly.
Confirm audit logs are enabled, logs are retained appropriately, monitoring processes exist, and incidents can be investigated effectively.
Review interfaces with external systems, API access controls, data-sharing agreements, and vendor responsibilities.
Certified systems should support the Security Rule safeguards, HITECH breach-response expectations, and your risk assessments and documentation. Technology enables compliance - operations complete it.
If you build health IT, certification is your gateway to the market - CMS programs require your customers to use certified technology. If you're a provider, the certification obligation sits with your vendor, but the operational responsibility for configuring and running that system securely sits with you.
Using non-certified technology can disqualify you from CMS programs like Promoting Interoperability and MIPS, which carries direct payment consequences. Misconfiguring a certified system is the quieter risk: HIPAA and HITECH enforcement lands on your operations regardless of what the software was capable of.
A configuration and evidence review of an existing certified EHR typically fits inside our standard 2 to 4 week assessment. Remediation - enabling logging, tightening access, documenting processes - is then scheduled by priority, and most items are configuration work rather than new purchases.
It depends on how many systems you run and what the review finds. You get a firm quote after the assessment; the conversation costs nothing.
Your IT provider keeps the EHR running. The question certification raises is different: are the certified security capabilities enabled, monitored, and documented? That review benefits from independent eyes - the team assessing your controls shouldn't be the team that configured them.
ONC certification is about the software: it proves the product is capable of supporting compliance. HIPAA compliance is about your organization: configuration, access, monitoring, and documentation. Certified software with disabled features fails you on the second while passing the first.
If your team knows the platform's security settings and can produce the documentation, much of it is achievable in-house. The common blind spot is assuming defaults are safe - certified systems often ship with capabilities off. Our DIY-with-support tier pairs your team with executive guidance on exactly these decisions.
Start with an inventory: which systems are certified, which security capabilities exist, and which are actually turned on. Our Cyber Risk & Compliance Gap Assessment builds that picture and maps it to HIPAA and HITECH expectations. No pressure. No jargon. Just clear insights and your best next steps.
Official source: ASTP/ONC, HHS - ONC Health IT Certification Program
Secondary source: eCFR - 45 CFR Part 170
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25