The Conditions and Maintenance of Certification are the ongoing obligations a health IT developer takes on when its product is certified under the ONC Health IT Certification Program at 45 CFR Part 170: semiannual attestations, Real World Testing plans and results, and 10-year record retention among them. They apply to health IT developers maintaining certified products, from initial certification onward. Integral Healthcare Solutions (IHS) maps your certification conditions to owners and drafts the attestation and change-control procedures; your engineers own product conformity.
What are the ONC Conditions and Maintenance of Certification?
ONC describes its program as “a voluntary certification program established by the ONC to provide for the certification of health IT” that “is run as a third-party product conformity assessment scheme for health information technology (health IT) based on the principles of the International Standards Organization (ISO) and International Electrotechnical Commission (IEC) framework” (ONC, About the Certification Program).
The governing text is 45 CFR Part 170. ONC's certification process page tells developers to “refer to a developer's ONC-ACB or the regulation outlined in 45 CFR Part 170 for further details.” The Conditions and Maintenance of Certification were set by the 21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program Final Rule, as amended. ONC's Conditions and Maintenance of Certification page explains the source: “The 21st Century Cures Act (Section 4002) requires the Secretary of Health and Human Services (HHS) to establish Conditions and Maintenance of Certification requirements for the ONC Health IT Certification Program.” Each Condition of Certification carries Maintenance of Certification requirements. Information blocking rules sit separately at 45 CFR Part 171.
Several obligations on that page set dates and periods a developer has to run to:
- Attestations: “A health IT developer must submit their attestations every six months as of the first attestation window beginning on April 1, 2022.”
- Records: “For a period of 10 years beginning from the date of certification, retain all records and information necessary that demonstrate initial and ongoing compliance with the requirements of the ONC Health IT Certification Program.”
- Real World Testing plan: “Submit its Real World Testing plan to its ONC-Authorized Certification Body (ONC-ACB) by a date that enables the ONC-ACB to publish the plan on the Certified Health IT Products List (CHPL) no later than December 15 of each calendar year.”
- Real World Testing results: “Report its Real World Testing results to its ONC-ACB by a date that enables the ONC-ACB to publish the results on the CHPL no later than March 15 of each calendar year.”
Who needs it and what triggers it
Any developer that certifies a product takes these obligations on. ONC's process page states: “Developers must register with an ONC-ACB and ONC-ATL to test and assess conformance to the requirements of the Certification Program.” The usual triggers are:
- Initial certification of a product, which starts the 10-year record retention clock and the attestation cycle.
- An attestation window or a Real World Testing deadline coming due without a documented process behind it.
- Customer demand. Although the program is voluntary, ONC notes that providers use certified products “to meet incentive program requirements, such as CMS's Promoting Interoperability program” (certification process page).
- Growth: new certified products, new releases or new staff that leave condition ownership unclear.
How IHS helps
IHS works on the organizational side of certification. The work runs in this order:
- A gap assessment of your organizational obligations against the Conditions and Maintenance of Certification.
- A responsibility map that ties each condition to an owner in engineering, security or regulatory.
- Drafting: attestation and change-control procedures, issue escalation, maintenance evidence files that support the 10-year record retention, and a review calendar tied to the attestation windows and the December 15 and March 15 Real World Testing dates.
- A mock review of the attestation file, read the way a reviewer would read it.
- Drafted attestation text for your organization to review and submit.
You supply your certified product list, current procedures, prior attestations, and the engineering, security and regulatory staff who own the work.
The limit: product conformity and testing are technical work for your engineers, your ONC-ATL and your ONC-ACB. IHS does not test software or certify conformance.
What to have ready
Each item ties to 45 CFR Part 170 as ONC describes it on its Conditions and Maintenance of Certification page and certification process page.
- A list of your certified products and the ONC-ACB and ONC-ATL each is registered with (process page).
- Your prior attestations and the dates of each attestation window you have met since your product's certification (six-month attestation requirement).
- Where your certification records are stored and how long they are kept, measured against the 10-year retention requirement.
- Your most recent Real World Testing plan and the date your ONC-ACB published it on the CHPL (December 15 requirement).
- Your most recent Real World Testing results and their CHPL publication date (March 15 requirement).
- Your change-control records for certified functionality, since retained records must show “initial and ongoing compliance”.
- The names of the engineering, security and regulatory leads who will own each condition.
- Customer contract or RFP language that requires certified products, including any reference to the Promoting Interoperability program (process page).
Bring what you have to the introductory call; the responsibility map starts from it.
How it compares
| Option | What it is | Source |
|---|---|---|
| ONC certification with Conditions and Maintenance of Certification | Product certification under 45 CFR Part 170, with ongoing attestation, testing and record obligations | ONC |
| Not certifying | The program is “voluntary”; providers use certified products to meet incentive program requirements such as Promoting Interoperability | ONC, ONC |
| DirectTrust organizational accreditation | Accreditation of the organization rather than the product; for example, DirectTrust's Practice Management System program “provides a comprehensive review of Practice Management System vendors in the areas of privacy, security, mandated standards, and operating rules, as well as key operational functions” | DirectTrust |
Product certification and organizational accreditation answer different customer questions. Which one your customers ask for is in their contracts and RFPs.
What it costs
ONC does not publish a fee schedule on the pages we reviewed; fees depend on scope. We did not review ONC-ACB or ONC-ATL fee pages for this page. IHS scopes each engagement after a free introductory call.
What this is not
- It is not legal advice, including on information blocking under 45 CFR Part 171. Those questions go to your counsel.
- It is not testing or certification. IHS does not act as, or replace, an ONC-ATL or ONC-ACB.
- IHS does not submit attestations or deal with ONC or your ONC-ACB for you. IHS drafts; your organization submits.
Frequently asked questions
What are the ONC Conditions and Maintenance of Certification?
They are ongoing requirements for health IT developers with products certified under the ONC Health IT Certification Program. ONC states that Section 4002 of the 21st Century Cures Act requires HHS to establish them. Each Condition of Certification has accompanying Maintenance of Certification requirements, set out in 45 CFR Part 170.
Is ONC health IT certification voluntary, and why do customers require it?
ONC describes the program as voluntary. ONC also notes that providers use certified products to meet incentive program requirements, such as CMS's Promoting Interoperability program. Whether a customer requires certification is set by its contract or RFP.
How often must a certified health IT developer submit attestations?
Every six months. ONC states that a health IT developer must submit its attestations every six months as of the first attestation window, which began on April 1, 2022.
What are the Real World Testing plan and results deadlines?
The developer submits its Real World Testing plan to its ONC-ACB in time for the ONC-ACB to publish it on the CHPL no later than December 15 of each calendar year. Results go to the ONC-ACB in time for publication on the CHPL no later than March 15 of each calendar year.
What records must a developer keep, and for how long?
For 10 years beginning from the date of certification, the developer retains all records and information necessary to demonstrate initial and ongoing compliance with the Certification Program. IHS drafts the evidence file structure and retention procedure; your team keeps the records.
What is the role of an ONC-ACB vs an ONC-ATL?
ONC states that developers must register with an ONC-ACB and an ONC-ATL to test and assess conformance to the program requirements. The ONC-ACB also publishes the developer's Real World Testing plan and results on the CHPL. ONC refers developers to their ONC-ACB or to 45 CFR Part 170 for details.
What does the information blocking condition require of a developer?
The information blocking rules are in 45 CFR Part 171, with the definition at section 171.103. Whether a specific practice is information blocking is a legal question for your counsel. IHS can assign an owner to the condition and draft the escalation procedure your team uses when a question comes up.
What does a developer need in place before its first attestation window?
At minimum, a named owner for each condition, a record retention process that covers 10 years from certification, and a calendar for the six-month attestation cycle and the December 15 and March 15 Real World Testing dates. IHS drafts these procedures and a mock review of the attestation file before the window opens.
