Clarifications:
- There is no standard required for this certification criterion.
- This criterion replaces the § 170.314(a)(17) Advance directives and applies to various patient health information documents. [see also 80 FR 62661]
- We encourage health IT developers to develop innovative and efficient ways to meet this criterion and simultaneously support providers accepting health information from patient. [see also 80 FR 62662]
- Although the privacy and security requirements described above do not require that a privacy and security certification criterion must be explicitly tested with this functionality at § 170.315(e)(3), Health IT Module developers should perform their own security risk assessment to determine if additional security protections are necessary. For example, if a Health IT Module requires that a user first save a patient-supplied document to their end-user device before capturing the information, developers should consider adding end-user device encryption to protect this data. However, this functionality is not required to meet the privacy and security requirements for certification but is strongly recommended.