The Department of Health and Human Services this week published a sweeping health-information-technology rule that creates the federal government’s first specific transparency requirements for artificial intelligence and other predictive algorithms embedded in certified health IT, placing new obligations on technology that supports care across most U.S. hospitals and physician practices.

The Office of the National Coordinator for Health Information Technology’s HTI-1 final rule appeared in the Federal Register on January 9. The final rule revises the ONC Health IT Certification Program, updates interoperability standards, changes information-blocking provisions and creates a new certification framework for “decision support interventions,” including predictive models that learn relationships from training data.

ONC describes the algorithm provisions as first-of-their-kind transparency requirements. The reach is potentially broad: ONC-certified health IT supports care delivered by more than 96% of U.S. hospitals and 78% of office-based physicians, according to the agency.

The rule focuses on visibility rather than federal approval of algorithms

HTI-1 does not create an FDA-style premarket approval system for every clinical algorithm. Instead, it requires certified health IT to make baseline information available so users can understand how predictive decision-support interventions were designed, developed, trained and evaluated.

The rule defines a predictive DSI broadly as technology that supports decision-making through algorithms or models that derive relationships from training data and produce a prediction, classification, recommendation, evaluation or analysis. The definition is intended to reach methods ranging from conventional statistical models to machine learning and more complex artificial-intelligence systems when they operate through certified health IT.

A January 9 HIPAA Journal analysis says the transparency requirements are designed to help clinical users assess whether algorithms are fair, appropriate, valid, effective and safe. That framework addresses a recurring problem in healthcare AI: a model may influence a patient’s care even when the clinician using it has limited information about its training population, validation, intended use or known limitations.

Developers must expose source attributes and risk-management information

The new certification criteria require health IT developers to support access to specified “source attributes” for decision-support interventions. These can include information about the intervention’s purpose, intended users, development and validation, datasets, performance and other characteristics relevant to judging how the model should be used.

The rule also requires developers of certified health IT supporting predictive DSIs to engage in risk-management practices and make information about those practices publicly accessible. The Federal Register text identifies areas including validity, reliability, robustness, fairness, intelligibility, safety, security and privacy.

Law firm Mintz said in a contemporaneous analysis that the rule represents the first substantial change to ONC’s clinical decision-support certification requirements since 2012. The objective is not to guarantee that every model is high quality, but to make enough consistent information available for healthcare organizations and clinicians to make more informed judgments.

The rule arrives as generative AI accelerates healthcare deployment

The timing is notable. Hospitals, electronic health record vendors and technology companies are rapidly adding machine-learning and generative-AI capabilities to clinical and administrative workflows. Those tools can summarize records, prioritize patients, predict outcomes or recommend actions, but their performance can vary when applied to populations different from those used for development.

Akin Gump described HTI-1 as a significant federal step into AI regulation through ONC’s existing authority over certified health IT. The rule uses certification leverage rather than attempting to regulate every healthcare algorithm directly.

That distinction also defines the rule’s limits. An algorithm outside the certified-health-IT ecosystem may not be reached by these particular certification criteria. Hospitals and clinicians also retain their own responsibilities for governance, local validation and deciding whether model outputs are appropriate for individual patients.

Interoperability changes accompany the AI provisions

HTI-1 is broader than algorithm transparency. It adopts United States Core Data for Interoperability Version 3 as a future certification baseline, adding and refining data elements intended to support public health, health equity and more standardized exchange. The rule also updates electronic case reporting and application programming interface requirements.

It modifies information-blocking regulations and creates changes intended to facilitate secure exchange under the Trusted Exchange Framework and Common Agreement. Healthcare Finance News reported that HHS expects the combination of interoperability and transparency policies to improve clinicians’ ability to understand algorithmic tools while continuing broader data-sharing reforms under the 21st Century Cures Act.

Healthcare organizations therefore face overlapping implementation questions: what their EHR vendors must disclose, how predictive tools are inventoried, how local model governance will use the new information and how updated interoperability standards affect existing interfaces and workflows.

Transparency is becoming part of clinical safety infrastructure

The rule reflects a policy judgment that algorithmic opacity is itself a healthcare risk. A model may produce a numerical risk score or recommendation that appears precise while hiding important facts about who was represented in its training data, how often it fails or whether performance differs across patient groups.

Hooper Lundy noted that providers will need to understand the new AI transparency provisions even though the certification obligations fall principally on health IT developers. Clinical users are ultimately responsible for how decision-support information is incorporated into care.

The Federal Register publication listed February 8 as the rule’s effective date, while individual certification and standards provisions have their own compliance timelines extending beyond that date. The transition is therefore not a single switch but a staged set of changes across certified products and developers.

HTI-1 does not resolve the broader debate over how artificial intelligence should be regulated in medicine. It does, however, establish a concrete national requirement in one of healthcare’s most pervasive technology channels. For a certified EHR ecosystem used by nearly every hospital in the country, predictive algorithms can no longer be treated solely as invisible proprietary functions. The federal certification framework now expects clinicians and organizations to receive enough information to begin asking whether those algorithms are fair, appropriate, valid, effective and safe.