A hospital inpatient payment rule is an odd place to find the technical specifications your EHR vendor will be certifying against next year. Yet that is exactly where they landed. The FY2027 Hospital Inpatient Prospective Payment System final rule — CMS-1849-F — carries both a set of certified health IT changes for the Medicare Promoting Interoperability Program and, alongside them, the Office of the National Coordinator’s adoption of seven updated FHIR implementation guides. Payment policy and standards policy arrived in the same document.

That packaging matters more than it might appear. Health IT standards are normally adopted through ONC’s own rulemaking — the HTI series — and hospital payment rules normally leave the technical specifications alone. When the two merge, the practical effect is that compliance calendars that used to run on separate tracks now share a single effective date, and health IT teams who do not read payment rules can miss requirements that apply to them.

What the rule actually adopts

ONC finalized adoption of seven FHIR-based implementation guides, effective October 1, 2026:

  • HL7 FHIR Da Vinci — Coverage Requirements Discovery (CRD) IG, version 2.2.1
  • HL7 FHIR Da Vinci — Documentation Templates and Rules (DTR) IG, version 2.2.0
  • HL7 FHIR Da Vinci — Prior Authorization Support (PAS) IG, version 2.2.1
  • HL7 FHIR CARIN Consumer Directed Payer Data Exchange IG, version 2.2.0
  • HL7 FHIR Da Vinci PDex US Drug Formulary IG, version 2.1.0
  • HL7 FHIR Da Vinci PDex Plan Net IG, version 1.2.0
  • HL7 FHIR Da Vinci Clinical Data Exchange (CDex) IG, version 2.1.0

None of these are new standards in the sense of appearing from nowhere. All were previously adopted in the HTI-4 final rule of July 2025; what the IPPS rule does is move them to newer versions. The functional areas they cover are electronic prior authorization, payer-to-provider exchange of administrative and clinical data, payer drug formulary publication, and payer provider-directory publication (ONC).

The version increments are small-numbered and easy to wave past. They are not trivial for anyone maintaining a certified product. A move from CRD 2.2.0 to 2.2.1 is still a recertification event if the criteria reference the specific version, and the three Da Vinci prior-authorization guides are referenced by the certification criteria at 45 CFR 170.315(g)(31)–(33).

What it removes

Running in the other direction, CMS finalized the removal and revision of certification criteria required for the Medicare Promoting Interoperability Program, aligned with proposals in the HTI-5 proposed rule — formally titled Health Data, Technology, and Interoperability: Assistant Secretary for Technology Policy (ASTP)/ONC Deregulatory Actions to Unleash Prosperity.

The most concrete removal: ONC Direct Review and ONC-Authorized Certification Body (ONC-ACB) Surveillance attestations disappear beginning with the EHR reporting period in CY 2026. Hospitals attesting for the Promoting Interoperability Program have been affirming that they cooperate with ONC direct review and ACB surveillance activities. That attestation requirement goes away.

Read the two halves together and the shape of the rule is clear enough: more standards, less oversight attestation. The technical surface a certified product must implement expands, while the administrative surface a hospital must attest to contracts. Whether that trade is favourable depends on where your organization’s costs actually sit. For a hospital, dropping two attestations is a genuine if modest reduction in reporting burden. For a health IT developer, seven implementation-guide version bumps are the more consequential half of the document.

The electronic prior authorization clock

The single most schedule-relevant item is the status of the electronic prior authorization measure. Under this rule, it becomes an optional bonus measure for CY 2027, then mandatory in CY 2028.

That is a genuine reprieve, and it is also the last one. Organizations that treated electronic prior authorization as a future problem now have a fixed date and one intervening year in which participation earns points rather than avoiding penalties. The bonus year is the implementation window, not a pause. Hospitals that use CY 2027 to stand up and exercise the CRD/DTR/PAS chain against real payer endpoints will enter CY 2028 with a working integration; those that wait will be implementing a mandatory measure with no margin.

It is worth being precise about what “mandatory in CY 2028” does and does not mean. It binds hospitals participating in the Medicare Promoting Interoperability Program. It does not by itself compel payers who are outside CMS’s interoperability rules, and the value of an electronic prior authorization capability to a hospital is a function of how many of its payers are on the other end of the transaction. Provider-side readiness is necessary and not sufficient.

A note on who issued this

Anyone searching the source documents will encounter the office under at least two names, and the inconsistency is real rather than sloppy citation. The Office of the National Coordinator for Health Information Technology was renamed the Assistant Secretary for Technology Policy/Office of the National Coordinator (ASTP/ONC) in July 2024, with an expanded remit covering HHS internal technology, data and AI functions. On March 31, 2026, HHS reversed that reorganization: the dual title ended, the office reverted to ONC, and the internal-technology and some cybersecurity functions moved back under the HHS chief information officer (Healthcare IT News).

The practical consequence for anyone doing compliance research: documents from mid-2024 through early 2026 say ASTP/ONC, documents before and after say ONC, and the HTI-5 proposed rule carries the ASTP/ONC name in its own title because it predates the reversal. Same office, same certification program, three naming conventions in the citation trail.

What to do with this

Three actions follow directly from the rule’s contents.

Confirm your vendor’s version roadmap against the October 1, 2026 effective date. Ask specifically which of the seven implementation guides your certified product touches and when the updated versions will be available in a production release — not a roadmap slide. The recertification burden is the vendor’s; the deployment burden is yours.

Treat CY 2027 as the electronic prior authorization build year. Identify which payers you exchange with, which of them expose CRD/DTR/PAS endpoints, and where the gaps are. The gaps are the project.

Re-read your Promoting Interoperability attestation checklist. Two items are coming off it starting with the CY 2026 reporting period. Removing them from an internal compliance checklist that nobody has revised in three years is a small win, but it is the kind that only happens if someone goes looking.

The FY2027 IPPS rule is not a dramatic document for health IT. It is a maintenance release with one hard deadline buried in it. The deadline is CY 2028, the preparation window is CY 2027, and the version numbers land on October 1, 2026.

Sources: CMS FY2027 IPPS/LTCH PPS Final Rule fact sheet (CMS-1849-F) · ONC, “ONC Finalizes the Adoption of Certain Health IT Standards in the FY2027 CMS IPPS Final Rule” · Federal Register, FY2027 IPPS proposed rule