

For most of the last decade, EHR compliance had a comfortable rhythm. A product earned its certification, an organization attested to a handful of measures, and everyone moved on until the next reporting cycle. Certification was the finish line. As of mid-2026, that finish line has quietly moved—and a surprising number of organizations haven’t noticed yet.
The rules governing electronic health records have entered a distinctly operational phase. Interoperability requirements are maturing, information blocking enforcement is live, new certification expectations are in effect, and TEFCA has grown into a genuine national exchange framework. None of this is theoretical anymore. It now reaches directly into reimbursement, data exchange, and enterprise risk. And the question regulators are increasingly asking has changed in a way that should reshape how every health IT leader plans.
The question is no longer “Was your system certified?” It is “How is your system actually performing in the real world?”
There was no single sweeping rule that announced this shift. It emerged from the accumulation of several frameworks landing at once. The ONC HTI-1 Final Rule updated the Health IT Certification Program and made USCDI Version 3 the baseline data standard as of January 1, 2026. That expands the core data EHRs are expected to capture and exchange—including additional patient characteristics and public health data—pushing systems toward more complete, standardized, and equity-supportive records.
HTI-1 did two other things worth pausing on. It introduced algorithm transparency requirements for the predictive and AI models embedded in certified health IT, giving clinical users a baseline set of information to judge fairness, validity, and safety. And it strengthened expectations that certified EHRs support electronic export of EHI in computable form—so that organizations can actually retrieve, move, and reuse their data when they switch systems, close a practice, or share more broadly. Together, these signals indicate that an EHR is no longer just a system of record. It is a system expected to perform.
If there is one area where the operational stakes are clearest, it is information blocking. The framework applies to providers, developers of certified health IT, HIEs, and HINs, and it prohibits practices likely to interfere with the access, exchange, or use of EHI unless a recognized exception applies. What makes it consequential is that HHS OIG now holds active enforcement authority, with civil monetary penalties of up to $1 million per violation for applicable non-provider actors.
The trap is that information blocking rarely looks like a deliberate refusal to share data. It looks like portal release delays, API restrictions, avoidable process barriers, contractual limitations, improper fees, or design choices that make access harder than it needs to be. In other words, the risk lives inside everyday workflow and configuration decisions—which is precisely why it can no longer be treated as a legal abstraction owned by counsel alone.
Information blocking compliance is now inseparable from EHR workflow design and governance.
TEFCA has matured from concept into a working national “network of networks,” supporting exchange for treatment, payment, healthcare operations, public health, benefits determination, and individual access. The practical message for EHR strategy is that systems can no longer be designed solely around internal workflows and local interfaces. They increasingly need to participate in a broader national exchange fabric, whether directly or through connected partners.
The patient-access expectations point in the same direction. ONC’s Cures Act framework continues to require standardized APIs so patients can access their information through smartphone apps and third-party tools, and it reinforces that patients must be able to access all of their EHI—structured and unstructured—at no cost. That has direct implications for portal strategy, API maturity, and every patient-facing digital access model.
Nothing captures the shift better than ONC’s Insights Condition, a quieter but strategically important development. It requires developers of certified health IT to report real-world metrics on how their products are actually used—such as individuals’ access to EHI, applications supported through certified health IT, use of FHIR in apps, and immunization-related exchange. Data collection for some Year 1 measures begins January 1, 2026, with reporting beginning in 2027.
Read alongside the CMS payment programs—where Promoting Interoperability still depends on certified technology under 45 CFR 170.315, at least 180 continuous days of data, a current CMS EHR Certification ID, an annual Security Risk Analysis, and the SAFER Guide self-assessment attestation—the trajectory is unmistakable. Certification alone is becoming table stakes. Measurable, real-world performance is becoming the standard.
Two developments round out the picture. First, the proposed modernization of the HIPAA Security Rule would raise expectations around multi-factor authentication, encryption of ePHI, technical safeguards, and formalized risk management—all of which land squarely on the EHR, typically the most critical regulated application in the environment. EHR compliance and cybersecurity maturity are converging into a single discipline.
Second, AI regulation in healthcare is emerging even though no single rulebook exists yet. HTI-1’s transparency requirements are already in force, the FDA continues to advance its digital health and AI agenda, and the HTI-5 Proposed Rule—published in late 2025—points toward a more FHIR-based, AI-enabled, and less legacy-burdened certification model. The lesson is not to wait. Governance, transparency, validation, and clinical oversight are already becoming the expected features of responsible deployment.
A compact view of what is in effect, what is being measured, and what is on the near horizon:
| Requirement | What it means | Timing |
| USCDI v3 | Expanded baseline data standard within the Certification Program | In effect, Jan 1, 2026 |
| MIPS Promoting Interoperability | Certified EHR technology + 180 continuous days of data, plus required attestations | 2026 performance year |
| Information blocking | Active OIG enforcement; CMPs up to $1M per violation for applicable actors | Now |
| ONC Insights Condition | Developers report real-world use metrics for certified health IT | Collection begins Jan 1, 2026; reporting in 2027 |
| HIPAA Security Rule modernization | Stronger MFA, encryption, and formalized risk management | Proposed; near horizon |
| HTI-5 Proposed Rule | Streamlined certification; foundation for FHIR-based APIs and AI-enabled exchange | Proposed (late 2025) |
The organizations that thrive in this phase won’t be the ones that simply hold a certificate. They’ll be the ones that can prove, in the real world, that their EHR performs. Contact Med Tech Solutions for more information.
All references below are primary federal materials from HHS, ASTP/ONC, the HHS Office of Inspector General, and CMS. Two items—the HIPAA Security Rule update and HTI-5—remain proposed as of mid-2026 and may be modified, delayed, or withdrawn before finalization. Federal Register citations are provided where applicable.