Ten months after proposing it, the Office of the National Coordinator for Health Information Technology (ONC) — now operating as the Assistant Secretary for Technology Policy (ASTP/ONC) — finalized the rule that turns AI transparency in electronic health records from a proposal into a certification requirement. Published in the Federal Register on January 9, 2024, “Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing” — known throughout the industry by its shorthand, the HTI-1 final rule — locks in a new decision support intervention (DSI) certification criterion, adopts USCDI version 3 as the baseline interoperability standard, creates a new “Insights Condition” reporting requirement, and revises several information-blocking definitions. A separate but closely related rule finalized later in 2024 attaches real financial consequences for providers found to have committed information blocking.

This is a regulatory summary intended to help health IT and health system audiences track what changed and when, not legal advice. Compliance timelines below reflect ONC’s published dates as of this writing; organizations making certification, procurement, or compliance decisions should verify current requirements against primary sources and consult qualified regulatory counsel, since ONC has in the past adjusted enforcement discretion on specific dates.

From Proposal to Final Rule: What Changed

HTI-1 was proposed in April 2023 and drew substantial public comment, particularly on the scope of predictive algorithm disclosures and the compressed timeline for compliance. The final rule kept the core architecture of the proposal — a new DSI certification criterion replacing the older Clinical Decision Support (CDS) criterion, expanded transparency for predictive tools, USCDI v3 adoption, and information-blocking revisions — while adjusting some of the specifics, including the number and grouping of disclosure elements developers must supply and the sequencing of compliance dates.

The rule implements provisions of the 21st Century Cures Act of 2016, continuing the build-out that began with the 2020 ONC Cures Act Final Rule, which first established information-blocking regulations and the current ONC Health IT Certification Program. HTI-1 is the first in ASTP/ONC’s newer, more frequent “HTI” rulemaking series, replacing the prior pattern of periodic, large “edition” updates to certification criteria.

Decision Support Interventions Replace Clinical Decision Support

The final rule retires the long-standing Clinical Decision Support certification criterion (formerly at §170.315(a)(9)) in favor of a broader “decision support interventions” (DSI) criterion at §170.315(b)(11). ONC’s stated rationale is that “intervention” better captures the range of tools involved — alerts, order sets, dashboards, patient lists, documentation forms, reference information, reminders, and similar functions — including tools whose logic is derived from statistical or machine-learning models rather than clinician-authored rules alone.

Within the DSI category, the rule draws a specific line for predictive DSI: decision support in which the underlying logic was produced, in whole or in part, by training a model on data, as distinct from decision support built entirely from expert-authored rules. That distinction matters because predictive DSIs carry additional disclosure and risk-management obligations that evidence-based (non-predictive) DSIs do not.

Predictive-DSI Source Attribute Transparency

The most closely watched piece of the final rule is its transparency requirement for predictive algorithms embedded in certified health IT. ONC finalized a defined set of “source attributes” — informational disclosures — that certified health IT must make available to end users, organized into several categories covering the intervention’s purpose, its development, the data used to build and validate it, its performance characteristics, and how it is monitored and maintained over time. Developer commentary and ONC’s own fact sheets describe roughly a dozen source attributes required for all DSIs, with a substantially larger set — commentary has put the total near 30 individual attributes — applicable specifically to predictive DSIs.

ONC frames the purpose of this disclosure using the shorthand FAVES: the information is meant to let clinicians, informaticists, and health system leaders judge for themselves whether a given predictive tool is fair, appropriate, valid, effective, and safe. Categories of required disclosure include, in general terms:

  • A description of the intervention’s purpose and intended use
  • Information about the data used to develop and/or validate the underlying model
  • Quantitative measures of the intervention’s performance
  • How and when the intervention was evaluated for validity, including bias assessment
  • Ongoing maintenance practices and the developer’s schedule for revalidation or fairness reassessment

Critically, ONC’s role here is disclosure standardization, not algorithm approval. Certification confirms that a developer makes the required information available in a consistent, accessible format — it is not an ONC determination that any specific predictive model is accurate or free of bias. That judgment remains with the health systems and clinicians deploying the tool.

Intervention Risk Management

Alongside source attributes, developers of certified health IT that supply predictive DSIs must implement and disclose summary information about their Intervention Risk Management (IRM) practices — addressing risk analysis, risk mitigation, and governance for those predictive tools — and make a summary of those practices available via a publicly accessible hyperlink through their ONC-Authorized Certification Body (ONC-ACB).

Compliance Timeline for DSI: What to Watch

ONC structured DSI compliance in stages rather than a single cutover date, and organizations should treat the dates below as ONC’s published targets rather than settled history, since ASTP/ONC has exercised enforcement discretion on specific HTI-1 dates in subsequent guidance:

  • Health IT developers seeking to maintain Base EHR definition certification, or continuity for customers on the old Clinical Decision Support criterion, were expected to certify Health IT Modules to the new DSI criterion by December 31, 2024.
  • Developers with a Health IT Module certified to DSI were expected to publish summary Intervention Risk Management information via their ONC-ACB by the same December 31, 2024 date.
  • From January 1, 2025 forward, the DSI criterion — not the older CDS criterion — is what counts toward the Base EHR definition, and predictive-DSI-specific source attributes and risk-management obligations apply on an ongoing basis to predictive DSIs the developer supplies.

Because ASTP/ONC has periodically revisited compliance-date enforcement for HTI-1 provisions since finalization, readers should confirm current expectations against the HealthIT.gov HTI-1 final rule page rather than treating any single date as immovable.

USCDI Version 3 Becomes the Certification Baseline

Separately from the AI-transparency provisions, HTI-1 finalizes United States Core Data for Interoperability (USCDI) version 3 as the new baseline data standard within the ONC Health IT Certification Program, with the older USCDI v1 baseline set to expire on the compliance date ONC has specified for full USCDI v3 adoption. USCDI v3 is a materially larger data set than prior versions, adding data classes such as:

  • Sexual orientation and gender identity
  • Functional status, disability status, and mental/cognitive status
  • Social determinants of health elements, including housing, food, and transportation needs

The practical effect is that certified EHRs and related health IT need to be able to structure, store, and exchange a wider range of data relevant to health equity and whole-person care than earlier USCDI baselines required — data many organizations previously captured inconsistently or only as unstructured text.

The New Insights Condition

HTI-1 also implements a Cures Act requirement establishing an “Insights Condition” of certification: a new obligation for developers of certified health IT to report standardized metrics about how their certified products are actually used in care delivery, such as measures related to patient access to electronic health information, FHIR API usage, and other utilization indicators. ONC has described a phased rollout of specific Insights Condition measures across multiple reporting cycles rather than a single reporting requirement taking effect all at once, so organizations should track ASTP/ONC guidance for the specific measures and reporting cadence that apply to their reporting period.

Information Blocking Definition Updates

The final rule also revises several information-blocking definitions and exceptions originally established in the 2020 Cures Act Final Rule. Notably, ONC updated the definition of “information blocking” to remove language tied to the USCDI v1-limited definition of electronic health information (EHI) that applied during the initial information-blocking compliance period, which ended October 5, 2023 — after that date, the information-blocking definition already applied to EHI more broadly, and HTI-1’s revision cleans up rule text to reflect that. HTI-1 also modifies certain information-blocking exceptions and adds a new exception intended to encourage secure, standards-based exchange consistent with the Trusted Exchange Framework and Common Agreement (TEFCA).

These are technical, definitional changes rather than a wholesale rewrite of the information-blocking framework — but they matter because information blocking, once identified, now carries direct financial consequences for a wide range of Medicare-participating providers under a separate 2024 final rule.

The 2024 Information-Blocking Disincentives Rule

Where HTI-1 governs certified health IT developers, a companion rule from the Department of Health and Human Services (HHS) — finalized in mid-2024 — governs healthcare providers directly. That rule establishes the long-anticipated “disincentives” for providers determined by the HHS Office of Inspector General (OIG) to have committed information blocking, closing a gap that had existed since the original 2020 information-blocking regulations took effect without any provider-side penalty structure.

Under that rule, providers found to have engaged in information blocking face different consequences depending on their program participation:

  • Hospitals and critical access hospitals (CAHs) participating in the Medicare Promoting Interoperability Program become ineligible for a portion of the annual market-based payment increase tied to being a meaningful EHR user; CAHs specifically see a reduction in the cost-based reimbursement percentage they would otherwise receive.
  • MIPS-eligible clinicians who have committed information blocking are not treated as meaningful EHR users and receive a zero score in the Promoting Interoperability performance category of the Merit-based Incentive Payment System, a category that ordinarily represents a substantial share of a clinician’s total MIPS score.
  • Accountable Care Organizations (ACOs), and their participating providers or suppliers, may be deemed ineligible to participate in the Medicare Shared Savings Program for a period of not less than one year.

The disincentives applicable to Medicare Promoting Interoperability Program hospitals and MIPS clinicians became effective July 31, 2024, while the disincentive affecting Shared Savings Program ACO participation became effective January 1, 2025. Actual referrals for information-blocking determinations flow through OIG’s separate enforcement process, meaning the disincentive rule supplies the penalty structure while OIG investigations and findings determine when it is actually applied to a given provider.

Why This Pairing Matters

Taken together, HTI-1 and the disincentives rule complete a two-sided regulatory structure the Cures Act originally called for: standardized transparency obligations on the health IT developer side, so that predictive algorithms embedded in certified EHRs are no longer opaque to the clinicians and organizations using them, paired with enforceable financial consequences on the provider side for information blocking, which had previously been defined in regulation but left largely without teeth for providers specifically. Health IT developers, CIOs, compliance officers, and clinical informatics leaders each have distinct obligations to track as these provisions phase in, and given ASTP/ONC’s demonstrated willingness to revisit specific compliance dates after finalization, the most reliable practice is to check current guidance directly rather than rely on any single previously published date.

Frequently Asked Questions

What is the HTI-1 final rule?

The HTI-1 final rule is ASTP/ONC’s January 2024 regulation (“Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing”) that adds AI/predictive-algorithm transparency requirements, adopts USCDI v3, creates an Insights Condition, and updates information-blocking definitions within the ONC Health IT Certification Program.

What is a predictive DSI under HTI-1?

A predictive decision support intervention (DSI) is decision support functionality within certified health IT whose logic is derived, in whole or in part, from a model trained on data — such as a risk score or prediction — as opposed to decision support built solely from clinician-authored rules, which HTI-1 treats as evidence-based, non-predictive DSI.

Does HTI-1 mean ONC approves or certifies that an algorithm is accurate?

No. HTI-1 requires developers to disclose standardized source-attribute information about predictive DSIs so users can judge fairness, appropriateness, validity, effectiveness, and safety themselves; ONC certification confirms disclosure occurred, not that any specific algorithm’s outputs are accurate or unbiased.

How does HTI-1 relate to the 2024 information-blocking disincentives rule?

HTI-1 regulates certified health IT developers, while the separate HHS disincentives rule, finalized in mid-2024, penalizes healthcare providers who commit information blocking through reduced Medicare payments, MIPS scoring, or Shared Savings Program eligibility; together they implement both sides of the Cures Act’s information-blocking framework.

When did USCDI v3 become required under HTI-1?

HTI-1 finalizes USCDI version 3 as the new baseline data standard within the ONC Health IT Certification Program, with the prior USCDI v1 baseline set to expire on ONC’s specified compliance date; organizations should confirm the current applicable date on HealthIT.gov since ASTP/ONC has adjusted enforcement discretion on some HTI-1 dates since finalization.