New US rules make certified health records reveal how their AI was built
A federal rule now requires certified electronic health records to publish a standard set of facts about each predictive algorithm they ship, including how it was validated and whether it was tested for fairness.
A federal rule that took effect in 2024 requires the software behind most US electronic health records to disclose how its predictive algorithms were built, validated and checked for bias — the first time such transparency has been mandated for the artificial intelligence baked into certified health IT [s1][s3]. From 31 December 2024, a certified system has to expose a standard set of facts, called "source attributes," about each predictive tool it supplies, or lose the certification that hospitals need to qualify for certain federal programmes [s2].
What the rule is
The rule is HTI-1 — "Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing" — published by the Office of the National Coordinator for Health Information Technology, part of the Department of Health and Human Services, on 9 January 2024 and effective 8 February 2024 [s1]. It replaces the certification program's old Clinical Decision Support criterion with a new "Decision Support Interventions" (DSI) criterion, the first substantial revision to those requirements since 2012, and separately adopts a newer clinical-data standard, USCDI version 3 [s1][s2].
The DSI criterion draws a line the older rules did not. It defines a "Predictive DSI" as "technology that supports decision-making based on algorithms or models that derive relationships from training data and then produce an output that results in prediction, classification, recommendation, evaluation, or analysis" [s2] — that is, machine-learning tools, as distinct from the older evidence-based rules-and-alerts that make up traditional decision support.
What must be disclosed
The mechanism is transparency, not a performance test. A certified system must supply 13 source attributes for evidence-based DSIs and 31 source attributes for Predictive DSIs [s2]. Those 31 span nine categories: what the tool does and outputs; its purpose and the decision-making role it was designed for; cautioned out-of-scope uses; the development details and input features, including the inclusion and exclusion criteria that shaped the training data; the process used to ensure fairness; the external validation process; quantitative measures of validity and fairness in both internal and external data; ongoing maintenance; and the schedule for revalidation [s2]. Developers must also implement risk-management practices for the predictive tools they supply, covering risk analysis, risk mitigation and governance, and keep the disclosed information current over time [s2].
The stated goal is to give hospitals and clinicians enough to judge whether a tool is "fair, appropriate, valid, effective, and safe" — the rule's FAVES shorthand [s2]. The agency describes the package as "first of its kind transparency requirements for the artificial intelligence (AI) and other predictive algorithms that are part of certified health IT" [s3].
What it does — and does not — do
The distinction that matters for a reader is that HTI-1 mandates disclosure, not quality. It does not require a predictive algorithm to be accurate, and it does not require it to be unbiased; it requires the developer to publish how the algorithm was tested and let the buyer read the answer [s2]. A hospital can still choose a weakly validated model — it just can no longer install a black box inside a certified record system with no paper trail behind it.
The rule's reach is also bounded. It applies to predictive tools supplied as part of certified health IT, and holds developers responsible only for the predictive interventions they themselves supply [s2]. It is not the same regime as the FDA's oversight of software as a medical device, and a standalone AI product a hospital buys separately is not automatically covered. Transparency inside the EHR is the lever here, not pre-market approval.
The timeline
The compliance clock is already past its first mark. Developers had to update health IT certified to the old CDS criterion to meet the DSI criterion and get it to customers by 31 December 2024 [s2]. From 1 January 2025 the older CDS criterion (at 170.315(a)(9)) is no longer part of the base definition of a certified record system, and the DSI criterion is what a provider needs to hold "Certified EHR Technology" for the purposes of certain Centers for Medicare & Medicaid Services programmes [s2]. In practice, that ties the transparency requirement to the certification hospitals rely on for federal incentive and reporting programmes.
What to watch
Whether the disclosures are complete and honest in practice, rather than boilerplate; whether clinicians and procurement teams actually read the source attributes and let them change purchasing; and whether later rulemaking extends the same transparency to the growing category of predictive tools that sit outside certified health IT entirely. The rule sets a floor for what buyers can see [s2]; it does not, on its own, guarantee the models above that floor are any good.
Sources
- [s1] Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1) Final Rule — Federal Register (HHS/ONC), 2024-01-09
- [s2] Decision Support Interventions (DSI) Fact Sheet — HTI-1 Final Rule — Office of the National Coordinator for Health Information Technology, 2023-12-14
- [s3] Health Data, Technology, and Interoperability Certification Program (HTI-1) — Algorithm Transparency — Office of the National Coordinator for Health Information Technology, 2024-01-09
Related coverage: the two questions US regulators keep asking about medical AI, the FDA's clinical decision support guidance, and why fairness metrics for clinical prediction are contested.
Sources
- Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing (HTI-1) Final Rule — Federal Register (HHS/ONC) , January 9, 2024
- Decision Support Interventions (DSI) Fact Sheet — HTI-1 Final Rule — Office of the National Coordinator for Health Information Technology , December 14, 2023
- Health Data, Technology, and Interoperability Certification Program (HTI-1) — Algorithm Transparency — Office of the National Coordinator for Health Information Technology , January 9, 2024
The FDA's blueprint for AI medical devices: what a maker must show, cradle to grave
A January 2025 draft guidance lays out the documentation the agency expects across an AI device's whole life, including bias checks across demographic groups and postmarket monitoring. It is not yet binding.
The EU AI Act makes most medical AI 'high-risk.' The hard part starts in 2027
Under Article 6, AI that is or sits inside a device already needing an independent safety check counts as high-risk. A 70-study review finds the trouble is overlap with existing device law.
Nearly 99% of drug-allergy alerts get overridden. Most were never a real match
A year of alerts at one hospital shows the safety pop-ups clinicians dismiss almost automatically — and why the field still cannot agree on how to measure the problem.
How the FDA lets an AI device update itself without a new clearance
A predetermined change control plan is the FDA's answer to a model that keeps learning: pre-approve a bounded set of future changes, and the manufacturer can ship them without returning for a fresh review.