on click brings up contact window
Compliance and RegulatoryEHR

Certified Is No Longer the Finish Line for EHRs

Dr. Gary Wietecha

June 26, 2026

Why mid-2026 is the moment EHR compliance stopped being about paper and started being about performance.

For most of the last decade, EHR compliance had a comfortable rhythm. A product earned its certification, an organization attested to a handful of measures, and everyone moved on until the next reporting cycle. Certification was the finish line. As of mid-2026, that finish line has quietly moved—and a surprising number of organizations haven’t noticed yet.

The rules governing electronic health records have entered a distinctly operational phase. Interoperability requirements are maturing, information blocking enforcement is live, new certification expectations are in effect, and TEFCA has grown into a genuine national exchange framework. None of this is theoretical anymore. It now reaches directly into reimbursement, data exchange, and enterprise risk. And the question regulators are increasingly asking has changed in a way that should reshape how every health IT leader plans.


The question is no longer “Was your system certified?” It is “How is your system actually performing in the real world?”


The change that arrived without a headline

There was no single sweeping rule that announced this shift. It emerged from the accumulation of several frameworks landing at once. The ONC HTI-1 Final Rule updated the Health IT Certification Program and made USCDI Version 3 the baseline data standard as of January 1, 2026. That expands the core data EHRs are expected to capture and exchange—including additional patient characteristics and public health data—pushing systems toward more complete, standardized, and equity-supportive records.

HTI-1 did two other things worth pausing on. It introduced algorithm transparency requirements for the predictive and AI models embedded in certified health IT, giving clinical users a baseline set of information to judge fairness, validity, and safety. And it strengthened expectations that certified EHRs support electronic export of EHI in computable form—so that organizations can actually retrieve, move, and reuse their data when they switch systems, close a practice, or share more broadly. Together, these signals indicate that an EHR is no longer just a system of record. It is a system expected to perform.


Where the real risk now lives: information blocking

If there is one area where the operational stakes are clearest, it is information blocking. The framework applies to providers, developers of certified health IT, HIEs, and HINs, and it prohibits practices likely to interfere with the access, exchange, or use of EHI unless a recognized exception applies. What makes it consequential is that HHS OIG now holds active enforcement authority, with civil monetary penalties of up to $1 million per violation for applicable non-provider actors.

The trap is that information blocking rarely looks like a deliberate refusal to share data. It looks like portal release delays, API restrictions, avoidable process barriers, contractual limitations, improper fees, or design choices that make access harder than it needs to be. In other words, the risk lives inside everyday workflow and configuration decisions—which is precisely why it can no longer be treated as a legal abstraction owned by counsel alone.


Information blocking compliance is now inseparable from EHR workflow design and governance.


Interoperability is now infrastructure, not aspiration

TEFCA has matured from concept into a working national “network of networks,” supporting exchange for treatment, payment, healthcare operations, public health, benefits determination, and individual access. The practical message for EHR strategy is that systems can no longer be designed solely around internal workflows and local interfaces. They increasingly need to participate in a broader national exchange fabric, whether directly or through connected partners.

The patient-access expectations point in the same direction. ONC’s Cures Act framework continues to require standardized APIs so patients can access their information through smartphone apps and third-party tools, and it reinforces that patients must be able to access all of their EHI—structured and unstructured—at no cost. That has direct implications for portal strategy, API maturity, and every patient-facing digital access model.


The new federal question: how is it actually performing?

Nothing captures the shift better than ONC’s Insights Condition, a quieter but strategically important development. It requires developers of certified health IT to report real-world metrics on how their products are actually used—such as individuals’ access to EHI, applications supported through certified health IT, use of FHIR in apps, and immunization-related exchange. Data collection for some Year 1 measures begins January 1, 2026, with reporting beginning in 2027.

Read alongside the CMS payment programs—where Promoting Interoperability still depends on certified technology under 45 CFR 170.315, at least 180 continuous days of data, a current CMS EHR Certification ID, an annual Security Risk Analysis, and the SAFER Guide self-assessment attestation—the trajectory is unmistakable. Certification alone is becoming table stakes. Measurable, real-world performance is becoming the standard.


Security and AI: two fronts you can’t defer

Two developments round out the picture. First, the proposed modernization of the HIPAA Security Rule would raise expectations around multi-factor authentication, encryption of ePHI, technical safeguards, and formalized risk management—all of which land squarely on the EHR, typically the most critical regulated application in the environment. EHR compliance and cybersecurity maturity are converging into a single discipline.

Second, AI regulation in healthcare is emerging even though no single rulebook exists yet. HTI-1’s transparency requirements are already in force, the FDA continues to advance its digital health and AI agenda, and the HTI-5 Proposed Rule—published in late 2025—points toward a more FHIR-based, AI-enabled, and less legacy-burdened certification model. The lesson is not to wait. Governance, transparency, validation, and clinical oversight are already becoming the expected features of responsible deployment.


The 2026 landscape at a glance

A compact view of what is in effect, what is being measured, and what is on the near horizon:

Requirement What it means Timing
USCDI v3 Expanded baseline data standard within the Certification Program In effect, Jan 1, 2026
MIPS Promoting Interoperability Certified EHR technology + 180 continuous days of data, plus required attestations 2026 performance year
Information blocking Active OIG enforcement; CMPs up to $1M per violation for applicable actors Now
ONC Insights Condition Developers report real-world use metrics for certified health IT Collection begins Jan 1, 2026; reporting in 2027
HIPAA Security Rule modernization Stronger MFA, encryption, and formalized risk management Proposed; near horizon
HTI-5 Proposed Rule Streamlined certification; foundation for FHIR-based APIs and AI-enabled exchange Proposed (late 2025)

What this means for leaders

  • EHR regulation in 2026 is real, specific, and operational. HTI-1, CEHRT requirements, information blocking, TEFCA, and API expectations all shape how your EHR must actually function.
  • Interoperability is infrastructure. National policy is steadily aligning reimbursement, access, and compliance around standardized exchange.
  • Information blocking is a design problem, not just a legal one. The highest-risk decisions are happening in workflow and configuration.
  • Security and compliance are converging. As HIPAA modernization advances, access control and encryption around the EHR matter more than ever.
  • Performance is the new bar. Certification is no longer enough; real-world access, exchange, transparency, and usability are what get measured.

Five moves worth making now

  • Validate EHR certification and 2026 CEHRT readiness, including the CMS reporting and attestation support you’ll rely on.
  • Assess HTI-1 impacts on USCDI v3 readiness, algorithm transparency obligations, and EHI export capability.
  • Run an information blocking operational review of record release, APIs, data-request workflows, fees, and policy barriers.
  • Pressure-test your TEFCA and exchange strategy, especially if you still depend on fragmented or nonstandard interfaces.
  • Get ahead of strengthened security expectations by reviewing MFA, encryption, and EHR-adjacent access controls now—before final rulemaking forces the timeline.

The organizations that thrive in this phase won’t be the ones that simply hold a certificate. They’ll be the ones that can prove, in the real world, that their EHR performs. Contact Med Tech Solutions for more information. 


Sources & Further Reading

All references below are primary federal materials from HHS, ASTP/ONC, the HHS Office of Inspector General, and CMS. Two items—the HIPAA Security Rule update and HTI-5—remain proposed as of mid-2026 and may be modified, delayed, or withdrawn before finalization. Federal Register citations are provided where applicable.

  1. ASTP/ONC — HTI-1 Final Rule: Certification Program Updates, Algorithm Transparency, and Information Sharing. Establishes USCDI v3 as the certification baseline (effective Jan. 1, 2026), algorithm transparency requirements for predictive interventions, the Insights Condition, and enhanced information-sharing provisions. 89 FR 1192 (Jan. 9, 2024). https://www.healthit.gov/regulations/hti-rules/hti-1-final-rule/
  2. ASTP/ONC — 21st Century Cures Act Final Rule: Interoperability, Information Blocking, and the ONC Health IT Certification Program. Establishes standardized API requirements, patient access to all EHI (structured and unstructured) at no cost, and the information blocking framework and exceptions. 85 FR 25642 (May 1, 2020). https://www.healthit.gov/topic/oncs-cures-act-final-rule
  3. HHS Office of Inspector General & ASTP/ONC — Information Blocking Civil Monetary Penalties and Enforcement Alert. OIG final rule authorizes CMPs of up to $1 million per violation for applicable developers, HIEs, and HINs (effective Sept. 1, 2023; 42 CFR Part 1003). https://www.healthit.gov/topic/information-blocking/enforcement-alert
  4. ASTP/ONC — Trusted Exchange Framework and Common Agreement (TEFCA). National “network of networks” supporting exchange for treatment, payment, operations, public health, benefits determination, and individual access. https://www.healthit.gov/topic/interoperability/policy/trusted-exchange-framework-and-common-agreement-tefca
  5. CMS — Promoting Interoperability, Traditional MIPS (Quality Payment Program). Requires certified EHR technology under 45 CFR 170.315, at least 180 continuous days of data, the CMS EHR Certification ID, Security Risk Analysis, and SAFER Guide self-assessment attestation. https://qpp.cms.gov/reporting-requirements/ways-to-report/traditional-mips/promoting-interoperability
  6. HHS Office for Civil Rights — HIPAA Security Rule Notice of Proposed Rulemaking (NPRM). Proposes stronger safeguards for ePHI, including multi-factor authentication, encryption at rest and in transit, and formalized risk management. Issued Dec. 27, 2024; published Jan. 6, 2025. Proposed as of mid-2026. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
  7. ASTP/ONC — HTI-5 Proposed Rule: Deregulatory Actions to Unleash Prosperity. Proposes streamlining the Certification Program, revising information blocking definitions and exceptions, and building a foundation for FHIR-based APIs and AI-enabled interoperability. Published December 2025; proposed as of mid-2026. https://www.healthit.gov/topic/laws-regulation-and-policy/hti-5-proposed-rule-fact-sheet