HTI-5 removes 34 of 60 certification criteria and moves AI testing to every buyer

The HTI-5 proposed rule, Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity, published at 90 FR 60970 on December 29, 2025, would remove 34 of the 60 certification criteria in the ONC Health IT Certification Program, delete all 13 privacy and security criteria, and end the AI model card requirements adopted under HTI-1. The 2026 Unified Agenda targets a final rule for August 2026. Every obligation behind those criteria stays in force under HIPAA, ACA Section 1557, and state law. Verification of them moves to each buying organization.

What HTI-5 removes from certification

ASTP/ONC proposes to retain 19 criteria, revise seven, and remove 34, according to the agency’s HTI-5 fact sheet. The rule is framed as an implementation of Executive Order 14192, Unleashing Prosperity Through Deregulation. Twenty-four of the removals would take effect on the final rule’s publication date and the rest on January 1, 2027.

Area Proposed change
Certification criteria 34 of 60 removed, seven revised, 19 retained
Privacy and security, § 170.315(d) All 13 criteria removed, from authentication and access control at (d)(1) through multifactor authentication at (d)(13), along with the Privacy and Security Certification Framework
Decision support interventions, § 170.315(b)(11) Descoped to remove the AI model card requirements: the 31 source attributes for predictive DSIs and the predictive DSI risk management provisions
Real world testing, § 170.405 Testing plans and results descoped, with reliance on the voluntary Standards Version Advancement Process
Insights reporting, § 170.407 Reduced to a single measure, use of FHIR in apps through certified health IT
Information blocking, 45 CFR 171.102 “Access” and “use” redefined to include automated means, and conditions under the Infeasibility and Manner exceptions narrowed or removed

Other criteria on the removal list include clinical decision support at § 170.315(a)(9), family health history, audit reports, safety-enhanced design, accessibility-centered design, and the C-CDA-based document exchange criteria.

ASTP/ONC estimates the package saves certified health IT developers up to 4,000 compliance hours each in the first year and about 1.4 million hours across the industry. The regulatory impact analysis puts cost savings at a present value of $1.53 billion in 2024 dollars, discounted at 7% and running from 2027 in perpetuity, and states that the agency does not expect costs to be associated with the deregulatory proposals. The only cost it quantifies is $284,132 for the 644 developers and medical associations expected to read the rule. The docket drew 6,459 comments.

Information blocking moves in the opposite direction. The proposal would revise the definitions of “access” and “use” so they cover automated means, including, without limitation, autonomous AI systems, and ASTP/ONC issued FAQs confirming that interference with robotic process automation and agentic AI can trigger the rule. Certification narrows. The set of requests a health system cannot refuse widens.

When the final rule takes effect

The comment period closed February 27, 2026. The 2026 Unified Agenda lists the HTI-5 final rule for August 2026 and an HTI-6 proposed rule on API standards for November 2026. Unified Agenda dates are planning statements with no legal force, and agencies miss them routinely.

Twenty-four criteria disappear on the publication date itself. Organizations that begin planning when the notice appears will be planning after the change has taken effect.

Why fewer rules means more testing

Federal certification is a one-to-many test. A developer certifies a module once, and every buyer in the market relies on that single result. Remove the criterion and the obligation survives in HIPAA, Section 1557, state law, and tort. The shared test is what disappears.

The comparison to FDA review is imperfect. ONC certification verified conformance, that a module could perform a defined function in a defined way, and it never tested clinical effectiveness the way a drug trial does. The two arrangements share one property: a single evaluation whose result the whole market consumes. A hospital pharmacy stocks metformin without running its own trial for the same reason.

Removing the criterion changes who performs the evaluation and how many times it happens. The American Hospital Association represents nearly 5,000 member hospitals and health systems. Add physician practices, payers, and digital health companies, and the same module gets evaluated thousands of times by teams with less product-security capacity than the developer that built it.

The security criteria show the pattern

ASTP/ONC’s stated rationale for deleting the § 170.315(d) criteria is that these capabilities are widely adopted and independently required under the HIPAA Privacy and Security Rules. The rule bases its wide-adoption finding on 2021 survey data showing 96% of hospitals and 78% of office-based physicians reported having a certified EHR. That reasoning is correct on the requirement and silent on the verification.

Encryption stays required. Audit logging stays required. Access control stays required. No federal body checks whether the module you just bought implements any of them before it connects to your network.

The HIPAA baseline is also standing still. OCR moved its Security Rule overhaul from the final rule stage to long-term actions with a target of July 2027, after receiving 4,745 public comments and a letter from a CHIME-led coalition of more than 100 organizations urging withdrawal on cost grounds, with the government’s own first-year estimate near $9 billion. The 2013 Security Rule remains the operative standard.

Provider groups filed on the gap. CHIME told ASTP/ONC that removing § 170.315(d) authentication, access control, and authorization moves responsibility for HIPAA compliance and patient data protection onto providers. AHIMA’s comments point to human error as the top compromise vector cited by CISOs, with phishing and social engineering used to reach EHR accounts. Writing in Health Affairs, MedStar’s Raj Ratwani and co-authors connect the security criteria to patient safety rather than privacy alone, citing estimates that roughly 50 electronic notes per 100,000 are entered into the wrong patient record.

AHA and WEDI both recommended retaining the privacy, security, and DSI criteria in current form. AHA argued the removal would move risk and cost to providers, because developers would treat the dropped features as add-on services and charge for them, and it cited HHS Office for Civil Rights figures showing individuals affected by healthcare data breaches rising from 27 million in 2020 to 259 million in 2024. AHA also asked for at least 24 months to transition certification criteria and for C-CDA-based criteria to remain, since many rural providers still depend on that exchange path.

How HTI-5 reassigns risk and responsibility in healthcare AI

The HTI-1 final rule took effect March 11, 2024, and required developers supplying predictive decision support interventions through certified health IT to support 31 source attributes covering training data, validation, fairness assessment schedules, and update practices, alongside 13 source attributes for evidence-based DSIs. Developers also had to maintain risk analysis, risk mitigation, and governance practices for predictive DSIs, organized around fairness, appropriateness, validity, effectiveness, and safety.

HTI-5 removes both. ASTP/ONC’s justification is that it has “no publicly available evidence” that the existing transparency requirements produced demonstrated clinical utility.

These were the only federal AI transparency requirements that operated inside an EHR. The questions they were pointed at are unchanged.

Legal risk

ACA Section 1557 at 45 CFR § 92.210 requires covered entities, which include most hospitals, practices, and payers, to make reasonable efforts to identify patient care decision support tools that use input variables measuring race, color, national origin, sex, age, or disability, and to mitigate the resulting discrimination risk. The general prohibition took effect July 5, 2024 and the affirmative identification and mitigation duties on May 1, 2025. OCR guidance directs entities that do not know what a tool contains to consult public sources or request the information from the developer.

HTI-5 removes the rule requiring developers to publish that information. The deployer’s duty to obtain it and act on it stays where it is.

State law adds to the same duty. Colorado’s SB 26-189, signed May 14, 2026 and effective January 1, 2027, covers automated decision-making technology that materially influences consequential decisions in seven domains, healthcare among them, with pre-use notice, adverse-outcome explanation, and recordkeeping obligations. Enforcement timing remains unsettled following an April 2026 stay and pending rulemaking. Malpractice exposure was never a function of federal certification at all.

Clinical risk

Models drift, vendors ship updates, and performance varies by population. Pacific AI’s Guardian evaluation of frontier models in February 2026 found no model scoring above 0.74 on clinical fairness across 11 sociodemographic dimensions. A Gatekeeper run against the augmented 712-prompt Safe-Child-LLM suite in May 2026 measured a 14.6-point gap on Inappropriate Content between GPT-5.4 at 0.980 and Grok-4.2 at 0.834. Neither finding is visible from a source attribute field, and neither is created by removing one.

Financial risk

Local verification costs money that the $1.53 billion savings estimate assigns to developers, and that the regulatory impact analysis does not quantify on the provider side. Insurance underwriting adds a second cost line, covered below.

Under HTI-1, a developer populated 31 defined fields and every customer read the same structure. After HTI-5, each AI governance committee asks each vendor separately, in its own template, and receives whatever format the vendor chooses to supply.

Who sets the industry standard instead

Insurers

On January 1, 2026, Verisk’s ISO released three standard endorsements, CG 40 47, CG 40 48, and CG 35 08, allowing carriers to exclude generative AI exposure from commercial general liability policies. CG 40 47 removes coverage for bodily injury, property damage, and personal and advertising injury arising out of generative AI across Coverage A and Coverage B. W.R. Berkley filed an absolute AI exclusion across D&O, E&O, and fiduciary lines, and Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial filed to adopt the ISO forms or proprietary equivalents.

Underwriting questions moved with the forms. Carriers now ask for AI system inventories including shadow AI, human oversight for agentic systems, documented red-teaming, and risk assessments mapped to NIST AI RMF or ISO/IEC 42001. Application answers become warranties, and a control an organization attested to but cannot evidence is a rescission argument at claim time. No statute requires NIST AI RMF in healthcare. Underwriters treat it as the benchmark, which produces the same operational result faster than rulemaking.

Standards bodies

NIST AI RMF is the precedent: a voluntary framework nobody was required to adopt, now cited in insurance filings, procurement templates, and state guidance.

Healthcare’s equivalent is the Coalition for Health AI, a network of more than 3,000 organizations. CHAI operates a model card registry launched with Providence, Cleveland Clinic, and Kaiser Permanente, publishes an applied model card format built for procurement committees, and released governance playbooks on May 27, 2026 developed through workshops with more than 100 healthcare organizations and 150-plus health AI leaders. The Joint Commission’s Responsible Use of AI in Healthcare certification, announced June 1, 2026 and co-developed with CHAI, applies the same expectations to deployers across five standard areas and is open to more than 22,000 organizations. Pacific AI is a CHAI-certified Assurance Resource Provider and wrote about sustaining that certification in June.

CHAI’s January 2026 patient survey, conducted by NORC at the University of Chicago, found more than 80% of patients would trust healthcare more with clear accountability measures in place.

Procurement contracts

What was a condition of certification becomes a negotiated term: model card delivery on a defined schedule, performance warranties by subpopulation, notice of material model changes, right to test and re-test, and indemnification for algorithmic discrimination claims. Large health systems will obtain these terms. Smaller ones will sign the vendor’s paper.

Each mechanism produces the evaluation the certification program used to produce, on a timetable set by whichever party carries the bargaining power.

The case for HTI-5

ASTP/ONC’s argument concerns what the removed requirements bought. HTI-1’s source attributes were plain-language descriptions supplied by the developer, and no federal body verified their accuracy. A test confirming that a field is populated is not evidence that a model is fair, valid, or safe. ASTP director Michael Lipinski has rejected the characterization that the proposal guts the program, describing the removals as reasoned decisions about criteria that no longer advance interoperability, and citing C-CDA exchange certification in a FHIR-first market as an example.

Developer burden was measurable. EHRA chair Leigh Burchell has argued that maintaining legacy certification requirements diverted engineering capacity from work customers need. ASTP/ONC put that burden at up to 4,000 hours per developer in year one.

A model card was never a substitute for local validation. Knowing a sepsis model’s training cohort tells a health system nothing about its calibration on that system’s patients. Any organization treating federal certification as its AI assurance strategy was exposed before HTI-5.

The evaluation continues under either reading. Its cost moves from certified developers to several thousand provider organizations, and AHA, CHIME, AHIMA, WEDI, and the American College of Physicians filed comments objecting to that redistribution rather than to modernization itself.

What to do before the final rule

  1. Build the inventory. Every AI system, including models embedded in products already licensed and tools clinicians adopted without review.
  2. Stop treating certification status as evidence for anything on the removal list. Decide what replaces each check: your own test, a vendor attestation you can verify, or an independent third-party result.
  3. Rewrite procurement templates now. Model card delivery, subpopulation performance data, change notification, right to test, and indemnification cost less at signature than in a renegotiation.
  4. Choose one reference framework and apply it consistently. NIST AI RMF, ISO/IEC 42001, CHAI, or the Joint Commission standards. Underwriters, surveyors, and opposing counsel all ask which one you used.
  5. Date your evidence. A validation performed at go-live and never repeated describes a system that has since drifted or been updated.
  6. Budget the verification work as an operating cost. The savings HTI-5 projects accrue to developers.

How Pacific AI lowers the cost

The failure mode in a decertified market is redundancy: the same model evaluated thousands of times by teams that cannot each afford to do it well. Automating the evaluation makes it cheap enough to do properly and structured enough to reuse.

For deployers, Governor builds the AI registry, reads vendor SOC 2 reports and AI disclosures into scored risk assessments with written justifications, drafts model cards from available documentation, and proposes risk tiers and mitigating controls. Gatekeeper runs pre-release testing for bias, safety, and robustness and gates releases inside CI/CD, drawing on 60-plus healthcare-specific test suites, 50-plus medical red teaming categories, and the open-source MedHELM and LangTest libraries. Guardian monitors production continuously for accuracy, bias, safety, and drift. The AI Policy Suite tracks 250-plus regulations, standards, and frameworks with quarterly updates and maps to healthcare-specific ones including CHAI, the RUAIH standards, ACA Section 1557, and HHS HTI-1.

For developers, the economics run the other way and reach further. If every customer will evaluate the product independently, arriving with structured, current, independently produced test results shortens every sales cycle. As a CHAI-certified Assurance Resource Provider, Pacific AI produces validation evidence a developer generates once and every buyer can consume, which restores part of the one-to-many structure that certification provided.

This is governance automation rather than governance theater, purpose-built for healthcare. Document-and-workflow tools issue blank templates and reminder schedules. An automation layer reads the source material and produces the assessment for a person to review and approve, which is what the regulation requires in any case.

Platform Core is $0 forever, with unlimited users, systems, vendors, policies, tests, monitors, documents, and audit trails, and deploys into your own AWS or Azure tenant in about 10 minutes, with governance data, model cards, and test results never leaving your VPC. You pay only for credits consumed by AI-enabled features. Point Governor at your first vendor contracts and draft model cards and risk tiers arrive the same day. Install from the AWS or Azure Marketplace, or explore advisory services to stand up the full program, controls, tooling, and operating model in a 6- or 12-week engagement.

This is not legal advice

This article describes the HTI-5 proposed rule, ACA Section 1557, Colorado SB 26-189, and related frameworks, and how the Pacific AI platform supports organizations in meeting their requirements. It is not legal advice. HTI-5 is a proposed rule that may change materially before it is finalized, or may not be finalized. Criteria counts, effective dates, and information blocking provisions described here reflect the proposal as published on December 29, 2025. Using the Pacific AI platform supports compliance and does not by itself produce legal compliance with any law, regulation, or standard. Organizations should consult their own compliance counsel to determine what these rules require for their specific systems and operations.

FAQ

Is HTI-5 final?

No. ASTP/ONC published it as a proposed rule on December 29, 2025, and the comment period closed February 27, 2026. The 2026 Unified Agenda targets a final rule for August 2026, though agenda dates carry no legal force.

How much of the certification program would HTI-5 cut?

34 of 60 criteria removed and seven revised, leaving 19, including all 13 privacy and security criteria at § 170.315(d). Twenty-four removals would take effect on the final rule’s publication date and the remainder on January 1, 2027.

Does HTI-5 mean encryption and access controls are no longer required?

No. It means the federal certification program stops testing for them. HIPAA Security Rule obligations are unchanged, which is ASTP/ONC’s own stated rationale for the removal. OCR has also delayed its Security Rule overhaul to a July 2027 target, so the 2013 rule remains operative.

What happens to AI model cards under HTI-5?

The decision support interventions criterion at § 170.315(b)(11) is descoped to remove them entirely: the 31 source attributes for predictive DSIs and the associated risk management provisions. Developers supplying predictive DSIs through certified health IT would no longer publish them as a condition of certification.

If federal model card requirements end, is clinical AI transparency still required?

Yes, through other channels. ACA Section 1557 § 92.210 requires covered entities to identify and mitigate discrimination risk in patient care decision support tools, and OCR guidance directs them to request information from developers. State law, insurance underwriting, the Joint Commission’s RUAIH certification, CHAI’s model card registry, and procurement contracts request the same information.

How does HTI-5 treat AI agents accessing health data?

It would revise the definitions of “access” and “use” in 45 CFR 171.102 to cover automated means including autonomous AI systems, and narrow conditions under the Infeasibility and Manner exceptions. Interference with robotic process automation or agentic AI could constitute information blocking.

What should a health system do first?

Build the AI and vendor inventory, then decide what replaces each removed certification check. Testing, contracts, monitoring, and insurance evidence all depend on knowing which systems are in production and who supplied them.

Reliable and verified information compiled by our editorial and professional team. Pacific AI Editorial Policy.

HealthBench Professional in Gatekeeper: what 525 physician-authored tasks do and don’t measure

HealthBench Professional is now available in Pacific AI Gatekeeper. It is an open benchmark from OpenAI built on 525 physician-authored tasks, and it measures one thing well: how usefully a...