Clarifications:
- There is no standard required for this certification criterion.
- This criterion focuses on users that would be able to access electronic health information in the technology and not on external users that may make requests for access to health information contained in the technology for the purpose of electronic health information exchange. The latter case could require a different/additional security approach(es). [see also 77 FR 54249]
- While this criterion does not specify a level of assurance, one-factor authentication would be minimally needed to satisfy this criterion. The developer has the discretion to satisfy this criterion above and beyond one-factor authentication. [see also 77 FR 54249]
- A user could be a healthcare professional or office staff, someone who might interact directly with the technology, or be a software program or service. [see also 75 FR 44598]