What Is HTI-5? The Proposed Reset of US Health IT Certification, Explained
CTO & Co-Founder
CTO & Co-Founder at Nirmitee.io. Architects healthcare integrations across FHIR, SMART on FHIR, ABDM and NHCX, writing from production experience taking hospital software from sandbox to go-live.

HTI-5 is a proposed US rule that would remove 34 of the 60 criteria health IT software must meet for federal certification, revise 7 more, and widen information blocking rules so automated tools, including AI, clearly count as legitimate users of health data.[1][3] Its full name is "Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity", and ASTP/ONC (the federal health IT office, formerly called ONC) published it in the Federal Register on 29 December 2025.[1]
This guide explains HTI-5 from a business point of view: why it exists, what it changes, who wins and who carries new risk, and what it means for companies that build or connect health software.
Where HTI-5 Stands
HTI-5 is still a proposed rule. The comment period closed on 27 February 2026.[2] As of 10 October 2026 no final rule has been published. A WEDI update dated 10 August 2026 reported that the final rule was under review at the White House Office of Management and Budget, which is usually the last step before publication.[10] The final rule may change what is described below.
Why HTI-5 Exists
To sell to US providers who take part in federal programs, EHR software has to be certified under the ONC Health IT Certification Program. Over the years that program grew to 60 criteria, many of which test specific features rather than how well systems share data. HTI-5 aims to cut that burden and "reset" the program so it prioritizes FHIR-based APIs over "functionality-oriented criteria".[4]
ASTP/ONC estimates the changes would save certified developers up to 4,000 hours each in the first year, about 1.4 million hours across the industry.[6] Those are the agency's own estimates, not measured savings.
A Short History
- 2009, HITECH Act: the federal government starts paying providers to adopt certified EHRs.
- 2016, 21st Century Cures Act: requires open APIs and prohibits information blocking.
- January 2024, HTI-1: adopts USCDI v3 and US Core 6.1.0 and adds transparency requirements for decision support tools.[12]
- July 2025, HTI-4: adds e-prescribing and prior authorization requirements.[11]
- December 2025: ASTP/ONC withdraws the remaining HTI-2 proposals[13] and proposes HTI-5.[1]
What HTI-5 Changes in Certification
The official ASTP/ONC chart lists 41 affected criteria: 34 removed and 7 revised.[3]
| Group | Proposed change | Proposed timing |
|---|---|---|
| Privacy and security, (d)(1) to (d)(13) | All 13 removed, including multi-factor authentication | Final rule effective date |
| Design and quality, (g)(3) to (g)(6) | Safety-enhanced design, quality management system, accessibility-centered design and C-CDA creation performance removed | Final rule effective date |
| Direct Project, (h)(1) and (h)(2) | Removed | Final rule effective date |
| Clinical, (a)(9), (a)(14), (b)(7) to (b)(9) | Clinical decision support, implantable device list, security tags and care plan removed | Final rule effective date |
| Measures and reporting | CQM filter, automated numerator recording, automated measure calculation, cancer registries and health care surveys removed | 1 January 2027 |
| Clinical and patient | Family health history, clinical information reconciliation and patient health information capture removed | 1 January 2027 |
| Older API criteria, (g)(7) and (g)(9) | Patient selection and all-data request removed | 1 January 2027 |
| Revised | Demographics, decision support interventions, CQM report, view/download/transmit, electronic case reporting, antimicrobial reporting | Final rule effective date |
| Revised | Transitions of care, (b)(1) | 1 January 2027 |
For C-CDA, the document most referrals use, see our C-CDA business guide; the transitions of care criterion is revised, not removed.[3]
What HTI-5 Changes in Information Blocking
Information blocking rules stop organizations from unreasonably preventing access to patient data. HTI-5 proposes to:[4][5]
- State that "access" and "use" include automated means, which commentators read as covering AI agents.
- Remove the TEFCA Manner Exception, which let an organization point a requester to TEFCA instead of the format the requester asked for. ASTP/ONC says the exception is no longer needed to encourage TEFCA participation.
- Revise the "manner requested" condition of the Manner Exception and remove or revise conditions in the Infeasibility Exception.
Our guide to TEFCA and information blocking explains the existing rules these changes build on.
What If HTI-5 Never Happened
- Every certified developer would keep testing against all 60 criteria.
- Data holders could keep sending requesters to TEFCA instead of the format they asked for.
- It would stay unclear whether automated and AI-driven access is covered by information blocking rules.
Pros and Cons for Business
| Pros | Cons |
|---|---|
| Lower cost to certify and maintain certification | Security is no longer tested at certification |
| Easier entry for new vendors | Certified products will behave less alike |
| Clearer rights for apps and AI tools to access data | Hospitals must check security and safety themselves |
| Focus shifts to FHIR APIs | Critics warn of patient safety risk[9] |
The American Hospital Association asked for a slower overhaul and for the transitions of care criterion to be kept.[7] The EHR Association broadly supports the direction but said it is hard to comment without knowing ASTP/ONC's later plans.[8]
Deadlines
- 27 February 2026: comment period closed.[2]
- Final rule effective date: 24 criteria removed and 6 revised, as proposed.[3]
- 1 January 2027: 10 more criteria removed and transitions of care revised, as proposed.[3]
All dates depend on the final rule.
Why HTI-5 Matters to Product and Integration Companies
- A certified label will tell you less. With fewer criteria, two certified EHRs can behave very differently, so every EHR integration needs real testing.
- AI agents get a stronger case for access. If automated access is clearly covered, EHRs and data holders face more requests from AI tools, which favors agent-ready FHIR APIs.
- More format conversion. Without the TEFCA Manner Exception, data holders must work harder to serve the format requested, which means more conversion between C-CDA, HL7 v2 and FHIR.
- More rules are coming. ASTP/ONC describes HTI-5 as a reset toward FHIR-based APIs that improve automation and go beyond read-only access, so vendors should plan their API roadmaps now.[4]
Who the Customer Is
| Customer | What changes for them |
|---|---|
| Certified EHR developers | Re-scope products and certification; plan for new FHIR criteria |
| Hospitals and provider groups | Check security, safety and integrations that certification no longer covers |
| Digital health and AI companies | Stronger footing to request data through APIs |
| HIEs and networks | Support more formats without the TEFCA exception |
Why, Why, Why: The Root Causes
- Why test every integration? Because certification would check less, so the label guarantees less.
- Why build agent-ready APIs? Because automated access would clearly count as access under information blocking rules.
- Why expect more conversion work? Because data holders could no longer point every requester to TEFCA.
- Why plan for FHIR now? Because ASTP/ONC says HTI-5 clears the ground for FHIR-based API requirements.
Planning for HTI-5, testing EHR integrations, or building FHIR APIs that AI agents can use? Explore our Healthcare Interoperability Solutions and healthcare AI agents. Talk to our team to get started.
Sources
- Federal Register: HTI-5 proposed rule, 90 FR 60970 (29 December 2025)
- ASTP/ONC HTI-5 Proposed Rule page
- ASTP/ONC HTI-5 Proposed Rule Chart
- Covington: HTI-5 changes to certification and information blocking (January 2026)
- McDermott Will & Emery: HTI-5 relaxes certification criteria while tightening information blocking exceptions
- Healthcare IT News: ASTP/ONC seeks relaxation of health IT certification criteria
- AHA comments on the HTI-5 proposed rule (27 February 2026)
- Healthcare IT News: AHA and EHRA support proposed HTI-5 deregulation, air concerns
- Health Affairs Forefront: HTI-5 must preserve core certification
- WEDI Federal Update, 10 August 2026
- ASTP/ONC HTI-4 Final Rule
- ASTP/ONC HTI-1 Final Rule
- Federal Register: withdrawal of non-finalized HTI-2 proposals (2025-23890)
Ready to scale?
Talk to our healthcare engineering team about building, integrating, and shipping faster.
Frequently Asked Questions
What is HTI-5?
Is HTI-5 final?
Which certification criteria does HTI-5 remove?
How does HTI-5 affect AI and information blocking?
What should EHR vendors and integration teams do about HTI-5?