Certification Companion Guide:
§ 170.404 Application Programming Interfaces

Updated on 09-30-2025

This Certification Companion Guide (CCG) is an informative document designed to assist with health IT product certification. The CCG is not a substitute for the requirements outlined in regulation and related ONC final rules. It extracts key portions of ONC final rules’ preambles and includes subsequent clarifying interpretations. To access the full context of regulatory intent please consult the Certification Program Regulations page for links to all final rules or consult other regulatory references as noted. The CCG is for public use and should not be sold or redistributed.

On this page

Attestation Requirements

Outlined below is a summary of the attestation requirements for the Condition and Maintenance of Certification for § 170.404 Application Programming Interfaces. For additional details related to the requirements please refer to the latest certification standards and regulations.

  • The health IT developer provides certified API technology to an API Information Source on terms that are no less favorable than it provides to itself and its own customers. The terms on which we provided certified API technology were based on objective and verifiable criteria that are uniformly applied to all substantially similar or similarly situated classes of persons and requests.
  • The health IT developer charges fees for the use of the certified API technology described in detailed, plain language. The description of the fees includes all material information, including but not limited to: the persons or classes of persons to whom the fee applies; the circumstances in which the fee applies; and the amount of the fee, which for variable fees must include the specific variable(s) and methodology(ies) that will be used to calculate the fee.
  • The health IT developer does not charge fees for the following: costs associated with intangible assets other than actual development or acquisition costs of such assets; opportunity costs unrelated to the access, exchange, or use of electronic health information; and any costs that led to the creation of intellectual property if the actor charged a royalty for that intellectual property pursuant to § 171.303 and that royalty included the development costs for the creation of the intellectual property.
  • The health IT developer keeps for inspection detailed records of any fees charged with respect to the certified API technology, the methodology(ies) used to calculate such fees, and the specific costs to which such fees are attributed.
  • The health IT developer does not condition the receipt of the rights described in paragraph (a)(4)(ii)(A) of this section.
  • All fees related to certified API technology not otherwise permitted by this section are prohibited from being imposed by the health IT developer. The permitted fees in paragraphs (a)(3)(ii) and (a)(3)(iv) of this section may include fees that result in a reasonable profit margin in accordance with § 171.302.
  • The health IT developer provides all support and other services reasonably necessary to enable the effective development and use of certified API technology by API Information Sources and API Users in production environments.
  • The health IT developer makes reasonable efforts to maintain the compatibility of its certified API technology and to otherwise avoid disrupting the use of certified API technology in production environments.
  • The health IT developer institutes a process to verify the authenticity of API Users that is objective and the same for all API Users and completed within 10 business days of receipt of an API User’s request to register its software application for use with its Health IT Module certified to § 170.315(g)(10).
  • The health IT developer registers and enables all applications for production use within five business days of completing its verification of an API User’s authenticity, pursuant to paragraph (b)(1)(i) of this section.
  • By December 31, 2024, the health IT developer publishes the service base URLs and related organization details in a standardized FHIR® format for all Health IT Modules certified to § 170.315(g)(10) that can be used by patients to access their electronic health information.
  • The health IT developer with certified API technology previously certified to the certification criterion in § 170.315(g)(8), provides all API Information Sources with such certified API technology deployed with certified API technology certified to the certification criterion in § 170.315(g)(10) no later than December 31, 2022.
  • A health IT developer with Health IT Module(s) certified to the certification criteria in § 170.315(g)(7), (8), or (9) complies with paragraph (a) of this section, including revisions to its existing business and technical API documentation and makes such documentation available via a publicly accessible hyperlink that allows any person to directly access the information without any preconditions or additional steps no later than April 5, 2021.

Certification Requirements

Applicability: Health IT Modules certified to any one or more certification criteria in § 170.315 (g)(7) through (10)

Condition Explanations and Clarifications