Certification Companion Guide:
§ 170.402 Assurances

Updated on 03-11-2024

This Certification Companion Guide (CCG) is an informative document designed to assist with health IT product certification. The CCG is not a substitute for the requirements outlined in regulation and related ONC final rules. It extracts key portions of ONC final rules’ preambles and includes subsequent clarifying interpretations. To access the full context of regulatory intent please consult the ONC Regulatory Activities page for links to all final rules or consult other regulatory references as noted. The CCG is for public use and should not be sold or redistributed.

On this page

Attestation Requirements

Outlined below is a summary of the attestation requirements for the Assurances Condition and Maintenance of Certification (45 CFR § 170.402). This attestation is a part of the Attestations Condition and Maintenance of Certification requirements and will be available for developers to attest alongside the other attestation requirements in 45 CFR § 170.406 beginning on April 1, 2022, and semiannually thereafter. For additional details related to the attestation requirements please refer to the Attestations Condition and Maintenance of Certification CCG.

  • The health IT developer provides assurances satisfactory to the Secretary that the health IT developer will not take any action that constitutes information blocking on and after April 5, 2021, unless for legitimate purposes as specified by the Secretary; or any other action that may inhibit the appropriate exchange, access, and use of electronic health information (EHI).
  • The health IT developer ensures full compliance and unrestricted implementation of certification criteria capabilities.
  • The health IT developer did not take any action to interfere with a user’s ability to access or use certified capabilities.
  • The health IT developer of a certified Health IT Module that is part of a health IT product that electronically stores EHI is certified to the certification criterion in § 170.315(b)(10).
  • The health IT developer retains all records and information necessary that demonstrate initial and ongoing compliance with the requirements of the ONC Health IT Certification Program for a period of 10 years beginning from the date of certification or, if for a shorter period of time, a period of three years from the effective date that removes all of the certification criteria from the Code of Federal Regulations.
  • Within, on, and after, December 31, 2023, a health IT developer that meets applicable requirements must provide all customers of its certified health IT with the health IT certified to the certification criterion in § 170.315(b)(10).
  • The health IT developer updates to all applicable revised certification criteria, including the most recently adopted capabilities and standards included in the revised criterion.
  • The health IT developer provides all Health IT Modules certified to a revised certification criterion, including the most recently adopted capabilities and standards included in the revised certification criterion, to its customers of such certified health IT.
  • The health IT developer updates and provides these updates to its customers consistent with the timeframes specified in § 170.406(b)(3)(iii).
  • For developers of Health IT Modules certified to § 170.315(b)(11), starting January 1, 2025, and on an ongoing basis thereafter, the health IT developer reviews and updates as necessary source attribute information in § 170.315(b)(11)(iv)(A) and (B), intervention risk management practices described in § 170.315(b)(11)(vi), and summary information provided through § 170.523(f)(1)(xxi).

Certification Requirements

Applicability of Conditions: Sections 170.402 (a)(1)-(3) and (a)(5) apply to all Certified Health IT Developers. Section 170.402 (a)(4) applies to all developers of certified health IT, which electronically stores EHI and must certify to § 170.315(b)(10). Sections 170.402 (b)(1) and (b)(3) apply to all Certified Health IT Developers. Section 170.402 (b)(2) applies to all Certified Health IT Developers certified to § 170.315(b)(10). Section 170.402(b)(4) applies to all health IT developers of certified health IT certified to § 170.315(b)(11). 

Condition Explanations and Clarifications