Certification Companion Guide:
§ 170.403 Communications

Updated on 03-11-2024

This Certification Companion Guide (CCG) is an informative document designed to assist with health IT product certification. The CCG is not a substitute for the requirements outlined in regulation and related ONC final rules. It extracts key portions of ONC final rules’ preambles and includes subsequent clarifying interpretations. To access the full context of regulatory intent please consult the ONC Regulatory Activities page for links to all ONC final rules or consult other regulatory references as noted. The CCG is for public use and should not be sold or redistributed.

On this page

Attestation Requirements

Outlined below is a summary of the attestation requirements for the Communications Condition and Maintenance of Certification (45 CFR § 170.403). This attestation is a part of the Attestations Condition and Maintenance of Certification requirements and will be available for developers to attest alongside the other attestation requirements in 45 CFR § 170.406 beginning on April 1, 2022, and semiannually thereafter. For additional details related to the attestation requirements please refer to the Attestations Condition and Maintenance of Certification CCG.

  • The health IT developer does not prohibit or restrict any communication regarding usability, interoperability, security, user experiences, business practices related to exchanging EHI, and how a user of the health IT used such technology unless such prohibition or restriction was permitted under § 170.403(a)(2)(ii).
  • The health IT developer does not prohibit communication of any information whatsoever when the communication is about one or more of the subject matters listed in § 170.403(a)(1) and is made for any of the following purposes:
    • Making a disclosure required by law;
    • Communicating information about adverse events, hazards, and other unsafe conditions to government agencies, health care accreditation organizations, and patient safety organizations;
    • Communicating information about cybersecurity threats and incidents to government agencies;
    • Communicating information about information blocking and other unlawful practices to government agencies; or
    • Communicating information about a health IT developer’s failure to comply with a Condition of Certification requirement, or with any other requirement of this part, to ONC or an ONC-ACB.
  • The health IT developer notifies all customers annually starting in 2021 that any communication or contract/agreement provision that violates the Communications Condition of Certification will not be enforced by the health IT developer.
  • The health IT developer notifies all customers annually up to and until the health IT developer amends any contract or agreement that violates the Communications Condition of Certification to remove or void the contravening contractual provisions.

Certification Requirements

Applicability: Applies to all Certified Health IT Developers. 

Condition Explanations and Clarifications