HTI-1 is an ONC final rule that updates the ONC Health IT Certification Program to address algorithm transparency. It replaces the prior Clinical Decision Support criterion with a broader Decision Support Intervention (DSI) criterion covering both evidence-based and predictive, AI-driven decision support tools. For predictive DSIs, certified health IT developers must disclose defined source attributes describing development, data, intended use, and risk management practices, giving clinical users information to evaluate validity and appropriateness before relying on outputs.
What Is HTI-1? Decision Support Intervention Requirements Explained
HTI-1 is an ONC final rule that updates the ONC Health IT Certification Program to address algorithm transparency. It replaces the prior Clinical Decision Support criterion with a broader Decision Support Intervention (DSI) criterion covering both evidence-based and predictive, AI-driven decision support tools. For predictive DSIs, certified health IT developers must disclose defined source attributes describing development, data, intended use, and risk management practices, giving clinical users information to evaluate validity and appropriateness before relying on outputs.
HTI-1 at a Glance
| Issuing Body | Office of the National Coordinator for Health Information Technology (ONC), HHS |
|---|---|
| Legal Basis | Amends 45 CFR Part 170, the ONC Health IT Certification Program regulations |
| Core Change | Replaces the Clinical Decision Support criterion with a broader Decision Support Intervention (DSI) criterion |
| Key Obligation | Source attribute disclosures for predictive, algorithm-based DSIs |
Source Attribute Categories Required for Predictive DSIs
Certified health IT developers must disclose the following categories of information alongside a predictive DSI so clinical users can evaluate its validity before relying on its output.
- Identification and developer details for the predictive intervention
- Intended use, including the clinical context the DSI is designed to support
- Funding source associated with the development of the DSI
- Characteristics of the data used to train and develop the model
- Validation methods and evidence supporting the DSI's performance claims
- Risk management and bias mitigation practices applied during development
What HTI-1 Is and Why It Applies to Predictive Health IT
HTI-1, formally titled Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing, is a final rule from ONC that was finalized in December 2023 and published in the Federal Register in early 2024. It amends the ONC Health IT Certification Program regulations at 45 CFR Part 170. The rule's central shift is a move away from treating decision support as a static, rules-based feature and toward recognizing that certified health IT increasingly incorporates predictive, algorithm- or AI/ML-based tools that generate risk scores, alerts, or recommendations. HTI-1 addresses this by requiring transparency into how those tools were built and validated, rather than dictating specific model architectures or algorithms.
What Qualifies as a Decision Support Intervention
HTI-1 replaces the prior Clinical Decision Support certification criterion with a new Decision Support Intervention (DSI) criterion. The DSI definition is intentionally broader, encompassing both evidence-based decision support and predictive decision support tools driven by algorithms or machine learning models. A DSI is distinguished from general software functionality by its role in producing outputs, such as risk stratification scores or clinical recommendations, that inform user decisions. It is important to note that the DSI certification criterion applies to health IT modules seeking or maintaining ONC certification. It does not extend automatically to every predictive or analytic tool an enterprise deploys internally, which means organizations need to determine which of their tools sit within certified health IT versus outside its scope.
How Source Attribute Disclosures Function
Source attribute disclosures are structured metadata that certified health IT developers must make available to users, not free-form vendor marketing documentation. ONC frames this requirement as a way to let clinicians and organizations assess fairness, validity, and appropriateness before relying on a predictive DSI's output, rather than accepting a model's recommendation at face value. In practice, this means the disclosure needs to be accessible alongside the DSI within the certified system, tied to a specific version of the model, and updated when that model is retrained or materially modified. Systems that surface predictive DSIs therefore need a way to store, version, and present this metadata consistently rather than treating it as a one-time compliance artifact.
Compliance Timeline and Certification Pathway
HTI-1 establishes phased compliance dates across its various certification criteria rather than a single effective date for the entire rule. Organizations evaluating a specific health IT product should confirm the applicable effective date for the DSI criterion relevant to that product, since timelines can differ by criterion. Compliance is enforced through the ONC Health IT Certification Program itself. Developers whose certified products fail to meet DSI requirements risk having their certification status affected, which in turn has downstream implications for healthcare organizations that rely on that certification for procurement, interoperability, or regulatory reporting purposes. This structure means enterprise compliance is partly dependent on vendor certification status, not solely on internal enterprise controls.
Operationalizing DSI Compliance Beyond Certification
- Confirm whether purchased or deployed health IT products are ONC-certified and whether their DSI functionality falls under HTI-1's criteria
- Request complete source attribute documentation from vendors as part of procurement due diligence, not after deployment
- Maintain an inventory of predictive DSIs in use, distinguishing certification-linked tools from internally built analytics
- Establish an audit trail linking specific DSI versions to the source attribute disclosures in effect at time of use
- Assign internal ownership for periodically reassessing DSI risk management disclosures rather than treating them as static
Where HTI-1 Connects to Broader AI Governance
HTI-1's disclosure-based approach parallels wider AI governance expectations around transparency, documentation, and explainability for algorithmic tools, including practices reflected in federal AI risk management guidance discussed around the same period. However, source attribute disclosure should be treated as a compliance floor, not a substitute for independent internal risk assessment. Vendor-provided documentation describes a model as built and validated at a point in time, but it does not by itself confirm how that model behaves in production or whether its outputs are being used within approved boundaries.
Where governance responsibility begins
Organizations need visibility into which agents or tools are invoking predictive DSIs, enforcement of permissions around how those outputs are used, and audit logging that ties specific decisions back to the model version and disclosure in effect at the time. Trussed AI provides runtime governance and security controls, including runtime policy enforcement, agent permissions, and audit logging, that support this kind of ongoing oversight for AI agents interacting with predictive tools, complementing rather than replacing the certification-based disclosures HTI-1 requires.
Frequently Asked Questions
Does HTI-1 apply to every predictive tool used in a healthcare enterprise?
No. The DSI certification criterion applies to health IT modules seeking or maintaining ONC certification. Internally built or non-certified predictive tools are not automatically covered, though enterprises should still apply comparable governance to them.
What happens if a vendor's product fails to meet DSI requirements?
Compliance is enforced through the ONC Health IT Certification Program. A product that fails to meet DSI criteria risks losing certification status, which can affect a purchasing organization's own regulatory and interoperability position.
Are source attribute disclosures the same as full risk management documentation?
They are a defined, structured set of disclosures intended to support user evaluation, not a comprehensive risk assessment. Organizations should treat them as a starting point for their own internal review.
Understand Where DSI Compliance Ends and Governance Begins
HTI-1 establishes disclosure requirements for predictive Decision Support Interventions, but ongoing oversight of how those tools are used in production is a separate governance responsibility.
Explore Runtime Governance