What Is ONC Health IT Certification and Why It Matters

ONC Health IT Certification refers to the ONC Health IT Certification Program, a U.S. federal program that certifies health IT - including electronic health record (EHR) technology - against national standards. In 2024, HHS renamed its health IT office the Assistant Secretary for Technology Policy (ASTP/ONC); the program keeps its ONC branding.

Certification is designed to ensure health IT products meet national standards for security, privacy, interoperability, data exchange, and auditability. Since the 2015 Edition, products are certified as Health IT Modules against specific criteria, through ONC-Authorized Certification Bodies.

While certification applies to software products, it has significant implications for the organizations that implement, configure, and rely on those systems. In practice, it sets the baseline expectation for how health data should be protected and managed.

What It Is

The program answers one question: is this software capable of supporting compliance? It does not answer whether your organization is compliant.

Certification is voluntary for developers - but effectively mandatory in practice, because CMS programs such as Promoting Interoperability and MIPS require providers to use certified EHR technology. That is the actual mechanism behind "certification enables participation in federal programs."

The division of responsibility is the part organizations miss. The vendor certifies the capability. You own the configuration, the access decisions, the monitoring, and the operations.

Who It Applies To

ONC certification is most relevant for two groups.

Health IT vendors:

  • EHR and EMR vendors
  • Patient engagement platforms
  • Health information exchange (HIE) solutions
  • Clinical data and interoperability platforms
  • Health data analytics and reporting tools

Healthcare organizations using certified technology:

  • Clinics and physician practices
  • Hospitals and health systems
  • Behavioral health and specialty providers
  • Organizations participating in federal healthcare programs
  • Entities subject to HIPAA and HITECH

Even if you are not the software vendor, how you configure and operate ONC-certified systems directly impacts compliance, security, and audit readiness.

What Information Is Regulated

ONC-certified systems handle electronic protected health information (ePHI) and related healthcare data, including:

  • Patient medical records
  • Clinical notes and diagnoses
  • Prescriptions and medication data
  • Lab results and imaging data
  • Patient demographics and identifiers
  • Care coordination and interoperability data

Because these systems store and transmit sensitive health data, security and privacy controls are central to the certification criteria.

Relation to Other Frameworks

ONC certification does not replace HIPAA or HITECH. The three fit together:

  • HIPAA defines privacy and security requirements for PHI.
  • HITECH strengthens enforcement and breach accountability.
  • ONC certification ensures the technology itself supports those requirements.

Using ONC-certified software does not automatically make an organization HIPAA compliant. It does ensure the platform includes capabilities such as audit logging, access controls, secure authentication, encryption, and interoperability safeguards. Organizations remain responsible for proper configuration, access management, and operational security.

IT Requirements

The security expectations trace to real certification criteria at 45 CFR 170.315(d).

Access controls and identity management:

  • Authentication and access control: criterion (d)(1) - unique user identification and authorization.
  • Multi-factor authentication: criterion (d)(13) - developers attest whether the module supports MFA.
  • Emergency access and automatic time-out: criteria (d)(6) and (d)(5).

Audit logging and monitoring:

  • Auditable events and tamper-resistance: criterion (d)(2) - system activity is recorded and protected.
  • Audit reports: criterion (d)(3) - the log data can be turned into reviewable reports that support incident investigation.

Data protection and encryption:

  • End-user device encryption: criterion (d)(7).
  • Encrypted authentication credentials and trusted connections: criteria (d)(12) and (d)(9) - protecting data and credentials in transit.

Interoperability and secure data exchange:

  • Standards-based data sharing: secure interfaces and APIs between systems, with controls to prevent unauthorized access during exchange.

Configuration and operational responsibility:

  • The criteria certify capability, not operation. Certification assumes systems are configured securely, access is reviewed regularly, security features are enabled and monitored, and staff are trained. Certification does not protect you if those steps are skipped.

Why It Matters

For small and mid-sized healthcare organizations, ONC certification often:

  • Enables participation in federal programs: CMS incentive and reporting programs require certified EHR technology.
  • Supports payer and partner requirements: certified platforms are the expected baseline.
  • Reduces friction during audits and assessments: the capabilities auditors ask about are built in.
  • Improves security and operational consistency: when the features are actually enabled.

Many SMBs mistakenly assume that using certified software equals compliance. In reality, most problems arise from poor access management, disabled security features, inadequate logging or monitoring, weak vendor oversight, and a lack of documented processes.

How It Fits Into Cyber Risk Management

ONC-certified technology is one layer of a healthcare security program, not the program itself. The certified capabilities only reduce risk when your operations activate them: access reviews, log monitoring, incident procedures, and vendor oversight.

A cyber risk management program treats the EHR as its most critical asset - and verifies the certified controls are configured, enabled, and producing evidence.

How We Help With ONC Certification Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment evaluates how your ONC-certified systems are actually configured - which certified security capabilities are enabled, monitored, and producing the evidence HIPAA and HITECH expect.

How to Prepare

  1. 01Confirm which systems are ONC-certified

    Document the EHR and health IT platforms in use, their certification status and scope, and the security features available within each system.

  2. 02Review system configuration and access controls

    Ensure role-based access is enforced, MFA is enabled where the platform supports it, administrative access is limited, and user access is reviewed regularly.

  3. 03Validate logging, monitoring, and audit readiness

    Confirm audit logs are enabled, logs are retained appropriately, monitoring processes exist, and incidents can be investigated effectively.

  4. 04Assess data exchange and interoperability security

    Review interfaces with external systems, API access controls, data-sharing agreements, and vendor responsibilities.

  5. 05Align ONC technology with HIPAA and HITECH requirements

    Certified systems should support the Security Rule safeguards, HITECH breach-response expectations, and your risk assessments and documentation. Technology enables compliance - operations complete it.

Frequently Asked Questions

Does ONC certification apply to my business?

If you build health IT, certification is your gateway to the market - CMS programs require your customers to use certified technology. If you're a provider, the certification obligation sits with your vendor, but the operational responsibility for configuring and running that system securely sits with you.

What happens if our EHR isn't certified, or we misuse a certified one?

Using non-certified technology can disqualify you from CMS programs like Promoting Interoperability and MIPS, which carries direct payment consequences. Misconfiguring a certified system is the quieter risk: HIPAA and HITECH enforcement lands on your operations regardless of what the software was capable of.

How long does it take to get our EHR environment audit-ready?

A configuration and evidence review of an existing certified EHR typically fits inside our standard 2 to 4 week assessment. Remediation - enabling logging, tightening access, documenting processes - is then scheduled by priority, and most items are configuration work rather than new purchases.

What does this cost?

It depends on how many systems you run and what the review finds. You get a firm quote after the assessment; the conversation costs nothing.

We already have an IT provider. Do we still need this?

Your IT provider keeps the EHR running. The question certification raises is different: are the certified security capabilities enabled, monitored, and documented? That review benefits from independent eyes - the team assessing your controls shouldn't be the team that configured them.

What's the difference between ONC certification and HIPAA compliance?

ONC certification is about the software: it proves the product is capable of supporting compliance. HIPAA compliance is about your organization: configuration, access, monitoring, and documentation. Certified software with disabled features fails you on the second while passing the first.

Can we handle this ourselves?

If your team knows the platform's security settings and can produce the documentation, much of it is achievable in-house. The common blind spot is assuming defaults are safe - certified systems often ship with capabilities off. Our DIY-with-support tier pairs your team with executive guidance on exactly these decisions.

Where do we start?

Start with an inventory: which systems are certified, which security capabilities exist, and which are actually turned on. Our Cyber Risk & Compliance Gap Assessment builds that picture and maps it to HIPAA and HITECH expectations. No pressure. No jargon. Just clear insights and your best next steps.

Official source

Official source: ASTP/ONC, HHS - ONC Health IT Certification Program

Secondary source: eCFR - 45 CFR Part 170

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25