The user wants me to review and correct time-sensitive claims in the provided article. Here’s a breakdown of the claims and my findings: 1. “The recent ONC HTI-2 Final Rule…”
- Finding: There are multiple ONC HTI rules. The “HTI-1 Final Rule” (Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing) was published in December 2023 and became effective in February 2024. This rule does introduce AI transparency requirements. There is also an “HTI-2 Final Rule” (Health Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement (TEFCA)) that was published in December 2024 and became effective in January 2025. This rule focuses on TEFCA and interoperability, not primarily AI transparency. Given the article’s focus on “AI transparency requirements,” it is highly likely it is referring to the HTI-1 Final Rule, which specifically addresses this. The naming “HTI-2” in the context of AI transparency is incorrect.
- Correction: Change “ONC HTI-2 Final Rule” to “ONC HTI-1 Final Rule” where it refers to AI transparency. 2. “…articulated by figures like Karen DeSalvo during her tenure…”
- Finding: Karen DeSalvo served as National Coordinator for Health Information Technology from January 2014 to August 2016. She also served as Acting Assistant Secretary for Health from October 2014 to January 2017. The phrase “during her tenure” accurately reflects a past period.
- Correction: No change needed. 3. “Companies like Epic and Cerner…”
- Finding: Oracle acquired Cerner in June 2022. Cerner is now known as Oracle Cerner.
- Correction: Change “Cerner” to “Oracle Cerner”. 4. “Christine Bechtel, a prominent advocate for patient data access and digital health…”
- Finding: Christine Bechtel is a consumer advocate and co-founder of X4 Health, focusing on patient engagement and digital health, and has consistently advocated for patient data access and transparency. This description remains accurate.
- Correction: No change needed. Based on these findings, I will proceed with the corrections.
I need to replace all instances of “ONC HTI-2 Final Rule” with “ONC HTI-1 Final Rule” and “Cerner” with “Oracle Cerner”.The burgeoning integration of artificial intelligence into healthcare promises transformative efficiencies and diagnostic precision. Yet, for Health IT Professionals and Health Plan Executives, this innovation arrives tethered to a critical question: how do these advanced tools align with the stringent regulatory landscape governing protected health information? The recent ONC HTI-1 Final Rule marks a pivotal shift, introducing new AI transparency requirements for certified health IT vendors, fundamentally reshaping the procurement calculus for AI-driven health solutions. This rule, published by the ONC, directly impacts how organizations assess the compliance posture of major players in the AI health space, from established EHR providers to specialized AI platforms.
The ONC HTI-1 Final Rule: Elevating AI Transparency as a Procurement Mandate
The ONC HTI-1 Final Rule significantly elevates the bar for AI transparency within certified health IT. For Health IT Professionals, this means moving beyond general assurances to demand specific, verifiable details about an AI’s development, validation, and performance. For Health Plan Executives, it introduces a crucial filter in vendor selection, ensuring that adopted technologies not only deliver clinical value but also meet a new standard of explicability and safety. This rule directly impacts the risk profile associated with AI health apps and platforms, pushing compliance to the forefront of enterprise procurement. The ONC’s intent, as articulated by figures like Karen DeSalvo during her tenure, has consistently emphasized patient safety and data integrity as foundational to health IT adoption. ONC HTI-2 Final Rule official text Consider the landscape of major health IT vendors. Companies like Epic and Oracle Cerner, dominant in the electronic health record (EHR) space, are rapidly integrating AI capabilities into their platforms. Their existing certifications under ONC programs will now necessitate adherence to these new AI transparency requirements. This implies a need for detailed disclosures on the AI models embedded within their systems, including data sources, model biases, and performance metrics. Similarly, specialized AI firms such as Tempus AI, which leverages vast genomic and clinical data for precision medicine, will face heightened scrutiny. Their offerings, while potentially revolutionary, must now demonstrate a transparent methodology that aligns with HTI-1 to secure contracts with large health systems and payers. The implications extend to other key players in the health tech ecosystem. Veeva Systems, a cloud-based software provider for the life sciences industry, and IQVIA, a global provider of advanced analytics, technology solutions, and clinical research services, often deal with sensitive health data. While their primary focus might differ from direct patient care applications, their data management and analytical tools, if incorporating AI for clinical or operational insights, will need to conform to the transparency demands if they seek ONC certification or interact with certified health IT. Even compliance management platforms like OneTrust, which helps organizations manage privacy, security, and governance, will need to evolve their offerings to help clients track and report on these new AI transparency mandates. Christine Bechtel, a prominent advocate for patient data access and digital health, has consistently highlighted the need for greater transparency in how health data is used, a sentiment that resonates deeply with the ONC’s latest directive.
Navigating the Regulatory Context: HIPAA, ONC, and HHS OCR
The ONC HTI-1 Final Rule does not exist in a vacuum; it builds upon and reinforces existing regulatory frameworks, primarily the HIPAA Privacy Rule and the HIPAA Security Rule. For Health IT Professionals, this means understanding that AI transparency is now an integral component of a broader compliance strategy. The HIPAA Privacy Rule dictates how protected health information (PHI) can be used and disclosed, while the HIPAA Security Rule sets national standards for protecting electronic PHI. Any AI health app or platform that processes PHI must already adhere to these rules, ensuring data confidentiality, integrity, and availability. The HTI-1 rule adds a layer of accountability, demanding clarity on how AI models are processing that PHI, particularly concerning their inputs, outputs, and any potential for bias or error. The ONC, as the principal federal entity coordinating nationwide efforts to implement and use advanced health information technology, is the architect of the HTI-1 rule. Their focus is on ensuring that certified health IT promotes interoperability, patient safety, and data integrity. Concurrently, the HHS Office for Civil Rights (HHS OCR) remains the primary enforcement agency for HIPAA. While the ONC sets the certification standards, HHS OCR would investigate any privacy or security breaches arising from opaque or poorly managed AI systems. This dual oversight creates a powerful incentive for vendors to prioritize robust transparency and compliance. Organizations procuring AI health tools must now incorporate HTI-1 compliance into their vendor evaluation frameworks, alongside traditional HIPAA compliance checklists. HHS OCR HIPAA guidance The new requirements compel vendors to provide information on the characteristics and capabilities of their AI, including its intended uses, known limitations, and potential risks. This level of detail is critical for Health Plan Executives who are responsible for mitigating organizational risk and ensuring that third-party tools do not introduce new vulnerabilities or compliance gaps. The procurement filter for AI health tools now explicitly includes a deep dive into the AI’s “black box,” demanding explanations of its internal workings to an unprecedented degree.
Key Takeaways for Enterprise Procurement of AI Health Solutions
The ONC HTI-1 Final Rule fundamentally reshapes the landscape for AI health apps and platforms, transforming AI transparency from a desirable feature into a mandatory compliance requirement for certified health IT. For Health IT Professionals, this means updating vendor evaluation frameworks to include detailed AI transparency checklists. Questions about training data provenance, bias mitigation strategies, model validation methodologies, and performance monitoring capabilities must become standard practice. Relying solely on general HIPAA attestations is no longer sufficient. For Health Plan Executives, the rule serves as a critical reminder that AI innovation must be balanced with robust governance and oversight. The ability of a vendor like Epic, Oracle Cerner, Veeva Systems, IQVIA, Tempus AI, or OneTrust to clearly articulate and demonstrate compliance with HTI-1 will increasingly become a decisive factor in securing large employer and health-plan contracts. Failure to meet these new transparency standards will likely disqualify AI health apps from consideration, regardless of their purported clinical efficacy. The ultimate implication is a more mature and accountable AI health ecosystem, where trust is built not just on outcomes, but on verifiable, transparent processes. ONC health IT certification program details
Frequently Asked Questions
What is the primary impact of the ONC HTI-1 Final Rule on AI in healthcare?
The ONC HTI-1 Final Rule introduces new AI transparency requirements for certified health IT vendors. This rule mandates detailed disclosures about an AI’s development, validation, and performance, fundamentally reshaping how AI-driven health solutions are procured and assessed for compliance. It elevates patient safety and data integrity as foundational to health IT adoption.
Which specific ONC rule addresses AI transparency requirements?
The ONC HTI-1 Final Rule, published in December 2023 and effective in February 2024, specifically introduces AI transparency requirements. The article clarifies that while an ‘HTI-2 Final Rule’ exists, it focuses on TEFCA and interoperability, not primarily AI transparency, making HTI-1 the relevant rule for this context.
How does this rule affect major EHR vendors like Epic and Oracle Cerner?
Major EHR vendors like Epic and Oracle Cerner, who are dominant in the electronic health record space and integrate AI capabilities, will now need to adhere to these new AI transparency requirements. Their existing certifications under ONC programs will necessitate detailed disclosures on the AI models embedded within their systems, including data sources, model biases, and performance metrics.
What kind of information will AI transparency requirements demand from vendors?
The AI transparency requirements will demand specific, verifiable details about an AI’s development, validation, and performance. This includes disclosures on data sources used for training, potential model biases, and performance metrics of the AI models embedded within their systems.
