EXPLAINER

New US rules make certified health records reveal how their AI was built

A federal rule now requires certified electronic health records to publish a standard set of facts about each predictive algorithm they ship, including how it was validated and whether it was tested for fairness.

A federal rule that took effect in 2024 requires the software behind most US electronic health records to disclose how its predictive algorithms were built, validated and checked for bias — the first time such transparency has been mandated for the artificial intelligence baked into certified health IT [s1][s3]. From 31 December 2024, a certified system has to expose a standard set of facts, called "source attributes," about each predictive tool it supplies, or lose the certification that hospitals need to qualify for certain federal programmes [s2].

What the rule is

The rule is HTI-1 — "Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing" — published by the Office of the National Coordinator for Health Information Technology, part of the Department of Health and Human Services, on 9 January 2024 and effective 8 February 2024 [s1]. It replaces the certification program's old Clinical Decision Support criterion with a new "Decision Support Interventions" (DSI) criterion, the first substantial revision to those requirements since 2012, and separately adopts a newer clinical-data standard, USCDI version 3 [s1][s2].

The DSI criterion draws a line the older rules did not. It defines a "Predictive DSI" as "technology that supports decision-making based on algorithms or models that derive relationships from training data and then produce an output that results in prediction, classification, recommendation, evaluation, or analysis" [s2] — that is, machine-learning tools, as distinct from the older evidence-based rules-and-alerts that make up traditional decision support.

What must be disclosed

The mechanism is transparency, not a performance test. A certified system must supply 13 source attributes for evidence-based DSIs and 31 source attributes for Predictive DSIs [s2]. Those 31 span nine categories: what the tool does and outputs; its purpose and the decision-making role it was designed for; cautioned out-of-scope uses; the development details and input features, including the inclusion and exclusion criteria that shaped the training data; the process used to ensure fairness; the external validation process; quantitative measures of validity and fairness in both internal and external data; ongoing maintenance; and the schedule for revalidation [s2]. Developers must also implement risk-management practices for the predictive tools they supply, covering risk analysis, risk mitigation and governance, and keep the disclosed information current over time [s2].

The stated goal is to give hospitals and clinicians enough to judge whether a tool is "fair, appropriate, valid, effective, and safe" — the rule's FAVES shorthand [s2]. The agency describes the package as "first of its kind transparency requirements for the artificial intelligence (AI) and other predictive algorithms that are part of certified health IT" [s3].

What it does — and does not — do

The distinction that matters for a reader is that HTI-1 mandates disclosure, not quality. It does not require a predictive algorithm to be accurate, and it does not require it to be unbiased; it requires the developer to publish how the algorithm was tested and let the buyer read the answer [s2]. A hospital can still choose a weakly validated model — it just can no longer install a black box inside a certified record system with no paper trail behind it.

The rule's reach is also bounded. It applies to predictive tools supplied as part of certified health IT, and holds developers responsible only for the predictive interventions they themselves supply [s2]. It is not the same regime as the FDA's oversight of software as a medical device, and a standalone AI product a hospital buys separately is not automatically covered. Transparency inside the EHR is the lever here, not pre-market approval.

The timeline

The compliance clock is already past its first mark. Developers had to update health IT certified to the old CDS criterion to meet the DSI criterion and get it to customers by 31 December 2024 [s2]. From 1 January 2025 the older CDS criterion (at 170.315(a)(9)) is no longer part of the base definition of a certified record system, and the DSI criterion is what a provider needs to hold "Certified EHR Technology" for the purposes of certain Centers for Medicare & Medicaid Services programmes [s2]. In practice, that ties the transparency requirement to the certification hospitals rely on for federal incentive and reporting programmes.

What to watch

Whether the disclosures are complete and honest in practice, rather than boilerplate; whether clinicians and procurement teams actually read the source attributes and let them change purchasing; and whether later rulemaking extends the same transparency to the growing category of predictive tools that sit outside certified health IT entirely. The rule sets a floor for what buyers can see [s2]; it does not, on its own, guarantee the models above that floor are any good.

Sources

Related coverage: the two questions US regulators keep asking about medical AI, the FDA's clinical decision support guidance, and why fairness metrics for clinical prediction are contested.

Sources

  1. Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1) Final Rule — Federal Register (HHS/ONC) , January 9, 2024
  2. Decision Support Interventions (DSI) Fact Sheet — HTI-1 Final Rule — Office of the National Coordinator for Health Information Technology , December 14, 2023
  3. Health Data, Technology, and Interoperability Certification Program (HTI-1) — Algorithm Transparency — Office of the National Coordinator for Health Information Technology , January 9, 2024
Related coverage