Skip to main content
Category: Regulatory Framework

ONC Health IT Certification Program

Also known as: ONC Certification Program, Health IT Certification Program
Simply put

The ONC Health IT Certification Program is a voluntary federal program run by the Office of the National Coordinator for Health Information Technology (ONC) that certifies health information technology products. Certification checks that health IT products meet established criteria for functionality, security, interoperability, and patient access. Participation is voluntary and is separate from HIPAA compliance, so certification under this program does not by itself establish compliance with HIPAA rules.

Formal definition

The ONC Health IT Certification Program is a voluntary certification program established by the Office of the National Coordinator for Health Information Technology (ONC) to provide for the certification of health IT. The program defines certification criteria that developers of health IT modules must meet, addressing standards for functionality, security, interoperability, and patient access. Health IT certified under the program must conform to the full scope of the product's required capabilities, including applicable regulatory and conformance requirements. This program is administered by ONC and is distinct from HIPAA, which is enforced by HHS OCR; achieving certification under the program does not by itself demonstrate HIPAA compliance and does not replace obligations under the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. Readers should verify the current program requirements, applicable certification criteria, and ONC's current organizational placement within HHS against current official guidance, as program details and organizational structure may change over time.

Why it matters

The ONC Health IT Certification Program shapes the technology landscape that most covered entities and business associates rely on every day. When a health IT product such as an electronic health record system is certified, it has been tested against established criteria for functionality, security, interoperability, and patient access. For compliance professionals, this provides a degree of assurance that certified products incorporate standardized capabilities, which can support broader organizational goals around information sharing and patient access to their own health information.

At the same time, the program's voluntary and functionally scoped nature is a common source of confusion. Certification under this program is administered by ONC and is separate from HIPAA, which is enforced by HHS OCR. Deploying a certified health IT product does not by itself demonstrate compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. A covered entity that adopts certified technology still bears independent obligations, such as conducting a risk analysis, implementing administrative, physical, and technical safeguards, and executing business associate agreements where required. Certification is best understood as evidence that a product meets defined technical and security criteria, not as a substitute for an organization's own compliance program.

Because program details, certification criteria, and ONC's organizational placement within HHS can change over time, professionals should treat any specific requirement as something to confirm against current official ONC guidance rather than assume permanence.

Who it's relevant to

Health IT Developers
Developers of health IT modules are the direct participants in the program. They must have their products tested against the applicable certification criteria and ensure the product conforms to the full scope of its required capabilities. Developers should confirm current criteria against official ONC guidance, since program requirements evolve over time.
Privacy and Security Officers
Privacy and security officers should understand that certification addresses defined criteria including security and patient access, but does not by itself establish HIPAA compliance. Independent obligations under the HIPAA Privacy and Security Rules, including risk analysis and implementation of administrative, physical, and technical safeguards, still apply regardless of a product's certification status.
Compliance and Procurement Teams
Teams evaluating or purchasing health IT can use certification as one factor indicating that a product meets established functionality, security, and interoperability criteria. However, they should not treat certification as a guarantee of HIPAA compliance and should still address business associate agreements and other regulatory obligations separately.
Healthcare Providers and Covered Entities
Covered entities that adopt certified health IT benefit from standardized capabilities supporting interoperability and patient access, but retain full responsibility for their own HIPAA compliance obligations, which are enforced by HHS OCR and are separate from the certification program.

Inside ONC Health IT Certification Program

Voluntary Certification Program
The ONC Health IT Certification Program is a voluntary program administered by the Office of the National Coordinator for Health Information Technology (ONC) that establishes standards, implementation specifications, and certification criteria for health information technology, particularly electronic health record (EHR) systems. Participation is generally voluntary, though certification may be tied to eligibility for certain federal incentive or reporting programs.
Certification Criteria
The program defines technical and functional criteria that health IT modules must meet to become certified. These criteria address capabilities such as interoperability, data exchange, security features, and clinical functionality. Criteria are updated periodically, and readers should verify the current criteria against ONC's published rules rather than relying on any single snapshot.
ONC-Authorized Certification Bodies (ONC-ACBs) and Testing Laboratories (ONC-ATLs)
Certification and testing are carried out through ONC-authorized third parties. Testing laboratories evaluate whether health IT meets the applicable criteria, and certification bodies issue the certifications, operating under ONC oversight.
Certified Health IT Products List (CHPL)
ONC maintains a publicly accessible list of certified health IT products and modules, allowing purchasers and users to identify which products have been certified against specified criteria.
Relationship to HIPAA
The ONC Health IT Certification Program is a distinct federal program and is not the same as HIPAA. Certification of a health IT product under this program does not by itself establish HIPAA compliance. A covered entity or business associate remains independently responsible for meeting HIPAA Privacy, Security, and Breach Notification Rule obligations, which are enforced by HHS OCR rather than through health IT certification.

Common questions

Answers to the questions practitioners most commonly ask about ONC Health IT Certification Program.

Does using ONC-certified health IT mean my organization is HIPAA compliant?
No. ONC Health IT certification and HIPAA compliance are separate matters. The ONC Health IT Certification Program evaluates whether health IT products (such as certified electronic health record technology) meet defined functional and interoperability criteria; it does not assess or establish an organization's compliance with the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule. HIPAA compliance depends on how a covered entity or business associate implements administrative, physical, and technical safeguards, conducts risk analysis, and manages PHI in all forms. Deploying a certified product may support certain safeguards, but it does not by itself satisfy HIPAA obligations, which are enforced by HHS OCR. Verify your compliance posture independently of any product certification.
Is ONC health IT certification a legal requirement for healthcare providers?
Generally, no. Certification is a program that applies to health IT developers and their products, not a direct legal mandate on every provider. In most cases, providers encounter certification indirectly, because participation in certain federal incentive or reporting programs may require use of certified health IT. Certification itself is voluntary for developers and distinct from HIPAA, which is a separate regulatory framework. Whether your organization must use certified technology depends on the specific programs you participate in; confirm current requirements against the applicable program rules.
How does adopting certified health IT relate to our HIPAA Security Rule obligations?
Certified health IT may include features that help support Security Rule safeguards, such as access controls, audit logging, or encryption capabilities. However, the Security Rule applies only to electronic protected health information (ePHI) and requires covered entities and business associates to implement safeguards based on their own risk analysis. A product's certified capabilities do not automatically fulfill required or addressable implementation specifications; your organization must still configure, use, and document these controls appropriately. Treat certified features as tools that may assist compliance rather than as evidence of compliance.
Where can I confirm the current certification criteria and organizational details before relying on them?
Because certification criteria and the administering office's structure can change over time, you should verify current details against official HHS and ONC sources rather than secondary summaries. The specific criteria a product must meet, along with any updates, are published through the program's official channels. As of the applicable regulatory text, confirm the current criteria, program version, and administering authority directly before making implementation or procurement decisions.
Does a vendor's certified health IT product change our HIPAA obligations toward that vendor?
Not by itself. If a health IT vendor creates, receives, maintains, or transmits PHI on behalf of your organization, that vendor is generally a business associate, and the associated HIPAA obligations flow through a business associate agreement regardless of whether the product is certified. Certification addresses product functionality, not the contractual and compliance relationship. In most cases you should still execute an appropriate business associate agreement and ensure obligations are defined through that relationship.
Can we rely solely on certified health IT to prevent breaches of ePHI?
No measure, including use of certified health IT, guarantees prevention of all breaches. Certified capabilities may reduce certain risks, but breach prevention depends on your organization's overall implementation of safeguards, workforce practices, configuration, and ongoing risk management. The Breach Notification Rule obligations, enforced by HHS OCR, apply based on how PHI is actually handled and protected. Additionally, state laws and the HITECH Act may impose further requirements. Certification should be viewed as one component of a broader compliance and security program, not a standalone safeguard.

Common misconceptions

Using ONC-certified health IT means an organization is HIPAA compliant.
Certification under the ONC program addresses whether a product meets defined technical and functional criteria; it does not by itself establish HIPAA compliance. HIPAA obligations, including implementation of administrative, physical, and technical safeguards under the Security Rule, apply to the covered entity or business associate regardless of a product's certification status, and are enforced separately by HHS OCR.
The ONC Health IT Certification Program and the HIPAA Security Rule are the same set of requirements.
They are distinct. The HIPAA Security Rule governs the protection of electronic protected health information (ePHI) by covered entities and business associates. The ONC program sets certification criteria for health IT products. Meeting one does not automatically satisfy the other, and organizations should treat them as separate compliance obligations.
Participation in the ONC Health IT Certification Program is legally mandatory for all health IT.
The program is generally voluntary. However, certification may be a practical prerequisite for participating in certain federal programs. Whether certification is effectively required in a given context depends on the specific program requirements, which readers should verify against current guidance.

Best practices

Do not treat ONC certification of a health IT product as evidence of HIPAA compliance; conduct and document your own HIPAA Security Rule risk analysis and safeguard implementation independently.
Verify a product's certification status and the specific criteria it was certified against using the Certified Health IT Products List (CHPL) rather than relying on vendor marketing claims.
Confirm the current certification criteria and program requirements against ONC's published materials, since criteria are updated periodically and any single reference may be out of date.
Maintain business associate agreements with health IT vendors where they create, receive, maintain, or transmit ePHI on your behalf, recognizing that certification does not substitute for these contractual obligations.
Assess whether state law or the HITECH Act imposes requirements beyond both HIPAA and the ONC program, and account for those in your overall compliance approach.
When relying on any statement about ONC's organizational placement or authority, confirm the current structure directly with HHS, as agency organization has changed over time.