Part of a standard readiness conversation has always leaned on a simple fact: ONC certification requires certain things, so a client’s system either meets them or it doesn’t. That framing gets shakier under a proposal that would remove more than half of the requirements it rests on. HTI-5 hasn’t been finalized, and treating it as settled would be a mistake in the other direction. But the conversation a consultant has with a client today, in an active engagement or a new proposal, should already sound different than it did a year ago, before anyone outside ONC’s own rulemaking staff had reason to expect a rollback this large.

What does HTI-5 actually propose to remove?

The scale is worth stating plainly, because it’s easy to undersell. ONC’s own HTI-5 fact sheet confirms that, of 60 certification criteria currently within the ONC Health IT Certification Program, the agency proposes removing 34 entirely and revising an additional seven. That’s not a trim around the edges. The proposed rule text published in the Federal Register states the same numbers directly and frames the goal as reducing burden and offering flexibility to developers and providers, on the reasoning that many current criteria no longer meaningfully advance interoperability and instead impede innovation and market entry.

34 Standards Fading

Why is ONC proposing to cut CDA-based document exchange criteria specifically?

Among the criteria proposed for removal are several governing CDA-based document exchange, the certification requirements a client’s C-CDA export capability has likely been measured against for years. ONC’s stated reasoning is that these requirements are largely superseded by growing adoption of FHIR-based interoperability approaches, essentially arguing that the market has moved past the point where a certification mandate is still doing useful work.

That’s a defensible argument in the direction FHIR adoption is heading. It’s also exactly the kind of change that matters most to a consultant’s talking points, since C-CDA quality checks have likely been part of every readiness audit built around what certification currently requires. If the requirement disappears, the client’s system doesn’t automatically get worse. What disappears is the guarantee that anyone outside the client’s own team is checking.

Is HTI-5 final, and how should that change what you tell a client today?

It is not final. ONC’s own fact sheet describes HTI-5 as a proposed rule, and the public comment period closed February 27, 2026 without a final rule issued as of this writing. That matters for exactly one reason: nothing in HTI-5 currently changes what a client’s certified health IT is required to do. A consultant telling a client that specific certification criteria are gone today would be wrong. A consultant telling a client that specific criteria are proposed for removal, with a defined rationale and an uncertain timeline, is giving them something they can actually plan around.

The practical shift is in emphasis, not in facts. A year ago, the honest answer to “do we need to meet this certification criterion” was close to a simple yes or no. Today the honest answer has a second sentence: yes, for now, and here’s what ONC has proposed changing about that, and here’s roughly when a final rule might land.

Pending Deregulatory Rule

What does 'no longer certification-required' actually mean for a client's system?

This is the distinction worth making explicit in every client conversation about HTI-5, because it’s the one most likely to get flattened into an oversimplified takeaway. A certification requirement disappearing doesn’t mean the underlying capability stops mattering. It means the federal guarantee that a vendor built it correctly goes away, and independent verification becomes the client’s own responsibility, or their consultant’s.

Under current certification requirements Under HTI-5 as proposed
CDA-based document exchange is a certification criterion, tested and attested to CDA-based document exchange certification would be removed, on the reasoning that FHIR adoption has superseded it
A client can point to certification as external proof a capability works A client’s proof shifts to voluntary standards adoption and independent verification
An auditor’s baseline includes checking certification status An auditor’s baseline needs to include checking actual output, since certification status alone may say less than it used to

How do you update your own playbook without overreacting to a proposal?

The safest move is to separate two things that are easy to conflate: what HTI-5 proposes, which is real and worth explaining accurately, and what’s actually true about a specific client’s system today, which HTI-5 hasn’t changed yet. A readiness audit built around current certification criteria is still accurate. What needs updating is the framing around it, so a client understands which parts of that baseline are stable and which parts are sitting in a comment period.

  • Flag, in every relevant engagement, which certification criteria a client’s compliance posture currently depends on that HTI-5 proposes to remove or revise.
  • Keep the current certification requirements as the operative standard until a final rule changes that, regardless of how likely the proposal seems to pass.
  • Start verifying document and data output directly, independent of certification status, since that habit holds up whether HTI-5 finalizes as proposed, gets revised, or stalls.
  • Revisit the client conversation once a final rule is issued, rather than updating guidance based on the proposal alone.

That third point is the one worth building into a standing practice now rather than waiting for a final rule to force it. Hgear’s free FHIR Viewer and C-CDA to FHIR Converter let a consultant inspect a client’s actual document and data output directly, using synthetic or de-identified samples, independent of whatever certification currently requires or eventually stops requiring. A verification habit built on looking at real output rather than a certification checkbox doesn’t need to be rebuilt every time the regulatory baseline shifts.

How does this affect what goes into a current audit deliverable?

A readiness audit report written today benefits from a short, explicit note wherever it references a certification criterion that HTI-5 proposes to remove or revise: current status, what’s proposed, and where the comment period and rulemaking stand as of the report date. That’s a small addition, but it protects both the consultant and the client from a report that reads as settled fact six months later when the regulatory picture has moved.

It also changes what a finding actually recommends. An audit finding tied to a certification criterion HTI-5 proposes to remove shouldn’t tell a client to stop investing in that capability. It should separate the compliance argument, which is currently intact, from the underlying data-quality argument, which holds regardless of what ONC eventually decides. A client’s C-CDA export quality matters to their actual interoperability, independent of whether a federal certification criterion is still the mechanism enforcing it. Losing sight of that distinction is how a client ends up deprioritizing real work because a headline made a proposed rollback sound further along than it is.

Want to verify a client's actual output instead of relying on certification status alone?

Hgear’s free FHIR Viewer and C-CDA to FHIR Converter let a consultant inspect what a client’s system actually produces, using synthetic or de-identified samples, so the verification habit doesn’t depend on which certification criteria happen to be in effect this year.

FAQs

HTI-5, formally the Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity Proposed Rule, would remove 34 of the 60 current certification criteria in the ONC Health IT Certification Program and revise an additional seven, according to ONC's own published fact sheet and the proposed rule text in the Federal Register.

No. As of this writing, HTI-5 remains a proposed rule. The public comment period closed February 27, 2026, and ONC has not issued a final rule. Current certification requirements remain in effect until a final rule changes them.

ONC's stated reasoning is that these requirements are largely superseded by the growing adoption of FHIR-based interoperability approaches, meaning the agency views the certification mandate as less necessary given how far FHIR adoption has already progressed in the market.

No. Removing a certification criterion removes the federal requirement that a vendor be tested and attest to that capability. It doesn't mean the capability stops being useful or necessary; it means independent verification of it becomes the client's or consultant's responsibility rather than something certification guarantees.

Current certification requirements should be treated as the operative standard until a final rule says otherwise. Clients benefit from understanding what HTI-5 proposes and its rationale, but a consultant should avoid advising a client to stop meeting a requirement that is still legally in effect.

Hgear's free FHIR Viewer and C-CDA to FHIR Converter allow a consultant to inspect a client's actual document and data output using synthetic or de-identified samples, which provides a verification method that doesn't depend on which certification criteria are currently required.

ISO 27001:2022 Certified

Aigilx health specializes in developing Interoperability solutions to create a healthcare ecosystem and aids in the delivery of efficient, patient-centric and population-focused healthcare.

Graphics

Follow Us

Email: contact@aigilxhealth.com