ONC Health IT Certification Program
The ONC Health IT Certification Program is a voluntary federal program run by the Office of the National Coordinator for Health Information Technology (ONC) that certifies health information technology products. Certification checks that health IT products meet established criteria for functionality, security, interoperability, and patient access. Participation is voluntary and is separate from HIPAA compliance, so certification under this program does not by itself establish compliance with HIPAA rules.
The ONC Health IT Certification Program is a voluntary certification program established by the Office of the National Coordinator for Health Information Technology (ONC) to provide for the certification of health IT. The program defines certification criteria that developers of health IT modules must meet, addressing standards for functionality, security, interoperability, and patient access. Health IT certified under the program must conform to the full scope of the product's required capabilities, including applicable regulatory and conformance requirements. This program is administered by ONC and is distinct from HIPAA, which is enforced by HHS OCR; achieving certification under the program does not by itself demonstrate HIPAA compliance and does not replace obligations under the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. Readers should verify the current program requirements, applicable certification criteria, and ONC's current organizational placement within HHS against current official guidance, as program details and organizational structure may change over time.
Why it matters
The ONC Health IT Certification Program shapes the technology landscape that most covered entities and business associates rely on every day. When a health IT product such as an electronic health record system is certified, it has been tested against established criteria for functionality, security, interoperability, and patient access. For compliance professionals, this provides a degree of assurance that certified products incorporate standardized capabilities, which can support broader organizational goals around information sharing and patient access to their own health information.
At the same time, the program's voluntary and functionally scoped nature is a common source of confusion. Certification under this program is administered by ONC and is separate from HIPAA, which is enforced by HHS OCR. Deploying a certified health IT product does not by itself demonstrate compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules. A covered entity that adopts certified technology still bears independent obligations, such as conducting a risk analysis, implementing administrative, physical, and technical safeguards, and executing business associate agreements where required. Certification is best understood as evidence that a product meets defined technical and security criteria, not as a substitute for an organization's own compliance program.
Because program details, certification criteria, and ONC's organizational placement within HHS can change over time, professionals should treat any specific requirement as something to confirm against current official ONC guidance rather than assume permanence.
Who it's relevant to
Inside ONC Health IT Certification Program
Common questions
Answers to the questions practitioners most commonly ask about ONC Health IT Certification Program.