The Centers for Medicare and Medicaid (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) have issued a final rule update to the standards that Electronic Health Record (EHR) applications must meet to be considered Certified Electronic Health Record Technology (CEHRT). These regulations consolidate previous certification standards and cover the full scope of the Health Information Technology (HIT) program.
Key Components of the Updated EHR Certification Standards
This update includes definitions related to certified EHR systems, technical specifications, and compliance requirements for health IT developers. It also sets conditions for maintaining certification and updates regulations for the ONC Health IT Certification Program.
- Definitions related to certified EHR systems,
- Standards and implementation specifications related to health information technology,
- Certification criteria for health information technology,
- Conditions and Maintenance of Certification Requirements for Health IT Developers, and
- Regulations covering the ONC Health IT Certification Program.
The Rationale for Using or Developing Certified EHR Technology
The reason for healthcare providers participating in Medicare to adopt certified electronic health records systems remains the same: maximizing Medicare reimbursement. In the early years of the development of electronic health records, Eligible Professionals (EP) and Eligible Hospitals (EH) who certified to meaningful use of CEHRT could receive incentive payments. EPs could receive as much as $44,000 if they certified to meaningful use over the years 2011-2015. EHs could receive incentive payments of at least $2m, prorated by their Medicare patient days as a percentage of total patient days.
Of course, the often-mentioned other major benefit of implementing electronic health records was the ability to make patient records and patient health data much more available for patient care coordination.
EXPERT GUIDANCE
Get Expert Help with EHR Certification
Ensure compliance and streamline the certification process with our consulting services.
Payment Adjustments for Eligible Hospitals Not Using Certified Electronic Health Records
Alas, the days of EHR incentive programs have been replaced with penalties for health care providers who do not implement certified EHR technology. The most recent iteration of penalties is the Medicare Promoting Interoperability Program. Under this program, CMS utilizes a performance-based scoring methodology for EHs and Critical Access Hospitals that attest to completing the scoring requirements. The scoring requirements for 2024 include:
- Use CEHRT certified to the ONC certification criteria, with or without the CURES update;
- Answer affirmatively to three requirements:
- Took no action to limit or restrict the compatibility or interoperability programs CEHRT attestation Direct Review Attestation;
- Performed a Security Risk Analysis – an analysis of the EH’s ability to maintain the confidentiality of protected health information.
- Reviewed the nine Safety Assurance Factors (SAFER) for EHR Resilience.
- Report on 3 self-selected Clinical Quality Measures (eCQM) and the Safe Use of Opioids, plus the Severe Obstetric Complications eCQM; and the Cesarean Birth eCQM.
- Several other criteria measuring the use of electronic health records, e.g., to support electronic prescribing, to provide access for patients to their health information, to report to immunization registries, etc.
So while the first requirement is to use ONC CEHRT, there is more to avoiding the disincentives than just utilizing certified electronic health records.
Payment Adjustments for Eligible Clinicians not using Certified Electronic Health Records.
The payment adjustments for physicians and clinicians are part of the Quality Payment Program implemented by Medicare six years ago. Eligible clinicians, including EPs, can participate in MIPS, the Merit-based Incentive Payment System. One component (25% of the score) of MIPS is “Promoting Interoperability”, which addresses promotion of patient engagement and electronic exchange of patient health data using CEHRT. Scoring requirements for the Promoting Interoperability portion of MIPS include:
- Using ONC CEHRT,
- Submitting data on the required Clinical Quality measures,
- providing your EHR’s CMS identification code from the Certified Health IT Product List (CHPL), and
- Answering affirmatively to four attestation statements:
- Took no Actions to Limit or Restrict Compatibility or Interoperability of CEHRT (previously named the Prevention of Information Blocking) Attestation.
- The ONC Direct Review Attestation.
- The Security Risk Analysis Measure.
- The Safety Assurance Factors for EHR Resilience (SAFER) Guides Measure.
Definitions Related to Certified EHR Systems
The Definitions in the latest certification criteria update are numerous, to say the least. Among the more important are:
- Base EHR. This is the list of features an EHR application must be capable of so EPs and EHs can certify they are meaningful utilizing CEHRT. Some of these certification criteria include:
- Patient demographics and clinical health information, e.g., medical history and problem lists;
- Capacity to support Clinical Decision Support, physician order entry, information on healthcare quality and communication with health information exchanges;
- Common Clinical Data Set. This is a long list of the standards defining clinical patient and demographic data. It includes everything from the standards for recording sex to vital signs and procedures.Note that almost everything on these lists are defined in specific certification criteria. This is necessary to ensure that patient data content such as medical history and treatment plans can be exchanged electronically.
Standards and Implementation Specifications Related to Health Information Technology
These standards are technical requirements for HIT. They cover issues like:
- Transport standards for secure transmission of medical records.
- Functional standards such as the use of HL-7 Version 3®.
- Content standards for exchanging electronic health information. These include standards for describing prescription medications, laboratory testing results and clinical quality measures, to name just a few.
- Vocabulary standards such as SNOMED CT® for medical terminology used in a Problem List, LOINC® for laboratory testing and RxNorm for medications. There are also vocabularies for Race and Ethnicity, preferred languages, units of measure and sex/sexual orientation and gender information, provider type and patient insurance.
- Standards to protect electronic health information. These cover issues such as encryption and decryption, audit logs of access to each electronic health record, audit log content.
- United States Core Data for Interoperability. This set of standards is designed to facilitate interoperable health information exchanges.
- Application Programming Interface (API) Standards. These standards again mention HL7®, and include bulk data access standards (FHIR®) and API authentication, security and privacy (Open ID Connect Core 1.0).
Finally, there is a long list of standards maintained or published by other agencies that are incorporated by reference into the standards covered by this section of the regulations.
Health IT Developers should note that while the Base EHR definition is fairly brief, the standards for Health IT are also part of the certification process.
Certification Criteria for Health Information Technology
This section of the updated regulations covers the details of the certification criteria for Health IT. These are the criteria previously covered in the 2014 and 2015 Editions of the criteria for CEHRT. These certification requirements specify the patient data and other functionality that certified EHRs must be capable of creating, storing, transmitting, and displaying.
To meet these criteria, EHR systems must support structured data capture, ensure secure interoperability, and facilitate real-time clinical decision support. Additionally, certified EHRs must integrate with external health information exchanges, comply with standardized terminology for diagnoses and medications, and support reporting for regulatory and quality improvement programs.
IT developers can look to this section for requirements for virtually all certification criteria applicable to compliance for certified EHRs. These standards are designed to promote consistent data exchange, enhanced patient safety, and greater transparency in how health information is managed across different platforms and providers.
Conditions and Maintenance of Certification Requirements for Health IT Developers
The EHR certification process has changed dramatically since the early days of the certification exam. Health IT developers now certify they are in compliance with many of the certification standards, vs. demonstrating the capability of their application during a certification exam. The ONC has added assurances on a long list of requirements that IT developers must attest to as conditions of initial certification and ongoing maintenance of certification requirements. Some of these assurances include:
- Not taking any action that constitutes information blocking.
- Affirming that its Health IT certified under the ONC Health IT Certification program conforms to the full extent of the certification criteria.
- Maintaining all records and information necessary to demonstrate initial and ongoing compliance with the requirements of the certification program.
- Updating its Health IT modules whenever new certification criteria are adopted.
- Not prohibiting communication regarding the usability, interoperability, security or user experiences of others utilizing its Health IT.
- Publishing APIs and allow electronic information from such technology to be accessed, exchanged and used without special effort.
- Completing real world testing of modules for interoperability.
Regulations Covering the ONC Health IT Certification Program
This section of the updated regulations covers the applicability, definitions and authorization for an ONC authorized certification body (ACB). It covers, in part:
- Principles of proper conduct for ONC-ACBs, including its certified health product listing (CPHL).
- Surveillance of CEHRT, including an annual surveillance plan submitted to the National Coordinator.
- Principles of proper conduct for ONC authorized testing Laboratories (ATLs).
- Procedures for accepting and reviewing applications from ONC-ACBs and ONC ATLs.
- Procedures for Health IT Module Certification.
- Certification to newer versions of certain standards.
- Procedures for a certification ban and reinstatement.
What To Do Now?
This has been a high-level overview of the EHR certification program based upon consolidated regulations governing the program. Health IT developers are encouraged to download a copy of the regulations to ensure they are keeping up with the latest requirements for new certifications and maintaining existing certifications. For expert guidance on meeting certification requirements and navigating compliance challenges, learn more about our EHR Certification Consulting services. Current or potential adopters of EHR technology are also encouraged to review the regulations to make sure they can properly evaluate systems they may be considering purchasing, or are certifying they are using.
The stakes are high. A major vendor of office-based certified electronic health records was fined over $155m as far back as 2017 because it took shortcuts in its programming to mislead the ONC-ATL and ONC-ACB. Shortcuts like preprogramming the test data in the testing procedures was a major concern of the ONC when the testing and certification process was first implemented.
And healthcare users like hospitals have also been penalized for falsely claiming meaningful use of CEHRT to win incentive payments or avoid penalties for not utilizing CEHRT. In the case of providers, these actions could lead to false claims allegations. That’s where real penalties for providers kick in!
Finally, there are regulations pending on penalties for information blocking that are also on the horizon. This is a situation where you need to take a long, detailed look before you leap!
