HIT Policy Committee endorses recommendations on certification
The Health IT Policy Committee has adopted and endorsed recommendations from two workgroups on certification and privacy concerning the notice of proposed rulemaking (NPRM) of health IT certification bodies.
On March 10, the Department of Health and Human Services (HHS) proposed a rule regarding the establishment of two certification programs for purposes of testing and certifying health IT. The first proposal would create a temporary certification program and the second proposal would establish a permanent certification program to replace the temporary program.
The Privacy and Security Workgroup stated that it endorses a default rule that each EMR module must meet all privacy and security certification criteria when the module is being used as intended.
“However, the workgroup does not believe the NPRM appropriately recognizes that the security functionality that any specific EMR module needs to provide will vary depending upon the environment in which it is intended to be used,” the workgroup stated.
In addition to recommending that HHS provide specific examples of “technical infeasibility,” the workgroup recommended that each EHR module submitted for certification provide as part of certification:
The Adoption-Certification Workgroup had a list of 12 recommendations to HHS, including that the surveillance process contain compliance with testing criteria, certification criteria as well as a labeling requirement “established for Complete EHRs and EHR modules that provide instructions for reporting certification and testing violations or concerns.”
The workgroup also recommended that a website be maintained by the Office of the National Coordinator for Health IT (ONC) and by each ONC-Authorized Certification Body that clearly identifies the names of vendors and the vendor version numbers that have received certification and shows which meaningful use stage has been tested and certified.
For future flexibility, the workgroup recommended that other health IT systems, such as personal health records, should be certified. “This flexibility should be used," the workgroup concluded, "to the extent that it is needed to support the stated certification objectives, which are:
On March 10, the Department of Health and Human Services (HHS) proposed a rule regarding the establishment of two certification programs for purposes of testing and certifying health IT. The first proposal would create a temporary certification program and the second proposal would establish a permanent certification program to replace the temporary program.
The Privacy and Security Workgroup stated that it endorses a default rule that each EMR module must meet all privacy and security certification criteria when the module is being used as intended.
“However, the workgroup does not believe the NPRM appropriately recognizes that the security functionality that any specific EMR module needs to provide will vary depending upon the environment in which it is intended to be used,” the workgroup stated.
In addition to recommending that HHS provide specific examples of “technical infeasibility,” the workgroup recommended that each EHR module submitted for certification provide as part of certification:
- A complete description of the environment within which the module is intended to operate;
- Which of the privacy and security certification criteria are accomplished by the EHR module and which are not; and
- If the product is designed to perform a specific privacy and security capability, a specification of the interface through which the security and/or privacy services will be provided to other EHR modules.
The Adoption-Certification Workgroup had a list of 12 recommendations to HHS, including that the surveillance process contain compliance with testing criteria, certification criteria as well as a labeling requirement “established for Complete EHRs and EHR modules that provide instructions for reporting certification and testing violations or concerns.”
The workgroup also recommended that a website be maintained by the Office of the National Coordinator for Health IT (ONC) and by each ONC-Authorized Certification Body that clearly identifies the names of vendors and the vendor version numbers that have received certification and shows which meaningful use stage has been tested and certified.
For future flexibility, the workgroup recommended that other health IT systems, such as personal health records, should be certified. “This flexibility should be used," the workgroup concluded, "to the extent that it is needed to support the stated certification objectives, which are:
- Focus certification on meaningful use requirements; and
- Leverage the certification process to improve progress on privacy, security and interoperability."