Video Preview
🎧 Part I Podcast free on Apple Podcasts and Spotify.
🎧 Part II Podcast episode for paid subscribers only. Also available on Apple Podcasts and Spotify.
To listen to paid episodes in Apple or Spotify, link your Substack subscription via the show settings on those platforms (instructions inside the Substack app under Subscriptions → Podcast).
Table of Contents
What HTI-5 actually does, in plain English
The certification bonfire and who gets warm
Bots are now people (for info blocking purposes)
The modification use loophole closes
What quietly died with the HTI-2 withdrawal
Company shapes worth building
Where this goes wrong
Scorecard
Abstract
HTI-5 is the ASTP/ONC proposed rule dropped in late December 2025 under the banner of deregulation, with comments closed at the end of February 2026 and a final rule expected any week now.
It proposes removing 34 and revising 7 of the 60 certification criteria in the ONC Health IT Certification Program, keeps 19 untouched, and reanchors the whole program on FHIR APIs.
It kills the model card and predictive DSI risk management requirements, drops most C-CDA centric and privacy/security criteria, descopes real world testing, and limits Insights reporting to FHIR usage.
ONC pegs the savings at up to 4,000 compliance hours per developer in year one, roughly 1.4 million hours industry wide.
On the info blocking side it clarifies that access and use explicitly include automated means, including autonomous AI systems, and it removes the infeasibility condition that let actors decline third party modification use requests.
Practical read: the certification moat around EHRs just got shallower, and the legal cover for stonewalling bots got thinner. Both of those are startup fuel.
Best company shapes: agent native FHIR read/write layers, info blocking complaint and enforcement tooling, certification-lite specialty EHRs, and a governance layer that replaces the federal AI transparency requirements that just got deleted.
Biggest risks: the final rule softens, vendors migrate to other exceptions, and OIG enforcement stays as sleepy as it has been.
What HTI-5 actually does, in plain English
Quick refresher for anyone who has spent the last decade pretending the HTI rules were someone else’s problem. ONC (now wearing the ASTP hat) runs the certification program that decides which EHRs are allowed to participate in the Medicare and Medicaid incentive and reporting ecosystem. If your EHR isn’t certified, your hospital customers can’t use it to satisfy Promoting Interoperability, MIPS, and a pile of downstream program requirements, so certification is effectively a license to sell to anyone taking federal money. The criteria list grew for fifteen years, from the original meaningful use stuff through HTI-1 (algorithm transparency, insights reporting), HTI-2 (mostly withdrawn, more on that later), HTI-3 (the info blocking exception fixes), and HTI-4 (electronic prior auth and real time prescription benefit, bundled into the FY2026 IPPS rule).
HTI-5 is the administration taking a chainsaw to that list. The proposed rule was released right before Christmas 2025, published in the Federal Register on December 29, and framed explicitly around the executive orders on deregulation and anti-competitive regulatory barriers. Comment period closed February 27, 2026. As of this writing the final rule has not dropped, and the smart money says it lands before the end of the year with most of the proposed cuts intact, because there is not a natural constituency lobbying to keep C-CDA transmission criteria alive. The AI transparency piece is the one area where consumer groups pushed back hard, so that section is the most likely to get tweaked.
The headline numbers: 60 existing certification criteria, 34 proposed for removal, 7 revised, 19 kept as-is. The 19 keepers include the HTI-4 stuff (ePA, RTPB, e-prescribing updates) and the FHIR API criteria. What survives is basically a FHIR API program with a few compliance attestations bolted on. What dies is everything that assumed the EHR was a monolithic clinical application that needed to prove it could do clinical functions in a specific way.
The second half of the rule is the info blocking part, which is smaller in page count but arguably bigger in commercial impact. Two changes matter. First, the definitions of access and use now explicitly cover automated means, with the rule using the phrase autonomous AI systems in the text. Second, the infeasibility exception loses the condition that let actors deny requests seeking modification use of EHI by third parties. There is also a request for comment on revising the definition of exchange to match.
So: fewer rules for building an EHR, fewer excuses for refusing to share data with software that isn’t a human clicking a mouse. That combination is the whole story.
The certification bonfire and who gets warm
The list of what is proposed for removal reads like an obituary for the 2010s. Clinical decision support certification criteria, including the HTI-1 decision support intervention requirements that made developers publish source attribute information for predictive models (the thing everyone called model cards). C-CDA centric criteria for transitions of care and data export. Privacy and security certification criteria that were largely duplicative of HIPAA. Various design and performance obligations, including a chunk of the safety-enhanced design and user-centered design documentation. Real world testing gets descoped in favor of voluntary approaches. Insights reporting, which HTI-1 expanded to seven performance measures, collapses to FHIR usage only.
ONC’s own math says a certified developer saves up to 4,000 compliance hours in the first year. Across the industry that is about 1.4 million hours, which sounds like a lot until you remember Epic alone probably burns that many hours arguing about MyChart color palettes. But the real value isn’t the hours saved by incumbents. It is the hours never spent by new entrants.
Certification has been the quiet moat around the EHR business. Not the only moat, obviously. Data gravity, switching costs, the fact that a health system CIO who rips out Epic gets fired, those are all bigger. But certification was the moat that hit smallest players hardest. A three person team building a specialty EHR for, say, wound care clinics or mobile IV therapy had to either eat the certification cost (a year plus and several hundred thousand dollars in a good scenario) or bolt onto a certified partner and pay rent forever. A lot of point solutions in ambulatory specialty markets exist as modules inside a certified system precisely because standalone certification was too expensive.
Post HTI-5, the certification bar is something like: expose a US Core compliant FHIR API, do ePA and RTPB if you prescribe, do e-prescribing correctly, attest to some conditions of certification, report FHIR usage. That is a fundamentally different engineering problem. A competent team with a modern stack can hit a FHIR US Core profile in months, not years. The CDS, C-CDA, and UCD documentation burdens that ate the most non-engineering time are just gone.
Who benefits, ranked roughly by how excited they should be. Specialty EHR upstarts, especially in cash pay adjacent or hybrid markets (aesthetics, longevity, behavioral health, fertility, PT) where the customer base is fragmented and the incumbents are twenty years old. AI native clinical documentation companies that have been flirting with becoming the system of record and now have a much shorter path to say yes. FHIR infrastructure vendors, since the whole program now points at their product. And weirdly, the big EHRs, because they get to reallocate compliance headcount to product and because a leaner certification program is easier to dominate on pure API performance.
Who does not benefit: certification consultants, ONC-Authorized Certification Bodies whose revenue was proportional to the criteria count, and the compliance software vendors that sold checklist tooling against HTI-1. Also, anyone who built a business on the model card requirement, which brings us to the governance gap discussed later.
Bots are now people (for info blocking purposes)
The information blocking rule from the Cures Act says actors (providers, developers of certified health IT, HIEs and HINs) can’t interfere with access, exchange, or use of EHI unless an exception applies. The rule always technically covered automated access, since nothing in it limited access to humans, but in practice EHR vendors have spent five years treating API calls from third party software as a different category with a different set of hoops. Rate limits that mysteriously appear when a request pattern looks scripted. Terms of service that prohibit automated retrieval. App registration processes that take nine months and require a business justification that somehow never satisfies anyone. Bulk FHIR endpoints that exist on paper and time out in production.
HTI-5 removes the ambiguity. Access and use include automated means, and the rule says so using the phrase autonomous AI systems. So when an agent running on behalf of a patient, a payer, a downstream provider, or a records requester hits an API, and the actor throttles it or blocks it or demands a human do it instead, that is now squarely in scope for an info blocking complaint unless the actor can name the exception it is relying on.
The obvious first order effect is on release of information and record retrieval. ROI has been a fax and portal scraping business for decades with a thin FHIR layer on top for the last few years. An enormous share of the cost structure is humans logging into portals, downloading PDFs, and re-uploading them somewhere else. Every vendor in that space has been building agentic retrieval and every vendor has hit the wall of EHR vendors and health systems saying that automated access to a portal violates the terms of service. That objection just got much weaker. If the retrieval is on behalf of a patient exercising their right of access or a legitimate requester with proper authorization, the actor’s refusal to serve a bot is presumptively info blocking.
Second order effect is on payers. The CMS-0057-F provider access, payer to payer, and prior auth FHIR APIs come due January 2027 for MA, Medicaid, CHIP, and federal exchange QHPs. Payers have been quietly hoping the provider side would be slow to consume those APIs. Now provider side agents can consume them at scale, and provider side agents hitting payer APIs also count as access and use, so a payer throttling provider agents has the same problem. The whole prior auth automation thesis, which has been mostly stuck at the payer side, suddenly has a provider side with legal teeth.
Third order effect is on the data aggregators and HIEs. A lot of state HIEs and national networks have participation agreements that restrict automated querying to specific use cases. Those agreements are going to get relitigated. TEFCA’s QHIN framework already has a purpose of use taxonomy, and the QHINs are going to face pressure to define what an agent acting for a treatment or individual access purpose can do. Expect a year of very boring but very important governance fights.
One thing worth flagging for the analysts in the room: the rule does not say actors have to serve unlimited automated traffic. The security exception, the fees exception, and the manner exception all still exist, and ONC was careful to note that reasonable, non-discriminatory rate limiting and legitimate security controls remain fine. The change is about burden of proof and default posture. Before, a vendor could plausibly claim bots weren’t covered users. After, the vendor has to show the specific exception and apply it consistently to human and automated requests. That is a much harder position to defend when your rate limit applies to competitors’ agents but not your own.
The modification use loophole closes
This is the wonky part that matters most for anyone building write-back functionality. The infeasibility exception at 171.204 has (had) a condition at (a)(3) that let an actor decline a request for access, exchange, or use if the request was for the third party to modify EHI. The original theory was that letting random apps write into the chart was a patient safety risk and the EHR vendor should be allowed to just say no. In practice it became the universal shrug. Want to write an ambient note back into the encounter? Modification use, infeasible. Want an AI to update a problem list? Modification, infeasible. Want to close a care gap by posting a result? Modification, infeasible, please use our proprietary marketplace program, here is the pricing sheet.
HTI-5 proposes to delete (a)(3) entirely. The stated reasoning is that two way interoperability methods have matured enough (FHIR write operations, SMART on FHIR scopes, the argonaut write work) that categorically refusing modification requests is no longer reasonable without exploring alternative manners under the manner exception. ONC’s market assessment basically says the vendors’ own products prove that safe write-back is feasible, so they can’t claim otherwise when a third party asks.
Two things follow. First, the manner exception now does the work. An actor facing a modification request has to either fulfill it in the requested manner or negotiate an alternative manner in good faith. The negotiation has to be documented, and refusing to negotiate is itself a problem. That creates a paper trail, and paper trails create enforcement opportunities. Second, the remaining infeasibility conditions (uncontrollable events, segmentation, infeasible under the circumstances) are narrower and require the actor to respond in writing within ten business days explaining why. Ten business days is a very short fuse for a health system legal team.
Commercially, this is the change that converts a bunch of read-only AI companies into read-write companies. Every ambient scribe, every care gap closure vendor, every coding assistant, every clinical trial matching tool has been living with the constraint that the last mile into the chart runs through the EHR vendor’s app program and its economics. The (a)(3) deletion doesn’t nuke those programs, but it removes their legal justification as the only path. A vendor that gets told to use the marketplace or nothing now has a complaint to file, and the EHR vendor has to explain to OIG why the marketplace is the only feasible manner.
Do not expect Epic and Oracle to fold. Expect them to reprice. The fees exception permits recovering costs reasonably incurred, and the argument over what counts as reasonable for a write API is going to be the next five years of this fight. But the negotiating table just got a new chair, and the people who used to stand outside now get to sit in it.
What quietly died with the HTI-2 withdrawal
Alongside HTI-5, ONC formally withdrew the parts of the HTI-2 proposed rule that never got finalized. This is the graveyard section. USCDI version 4 adoption as the certification baseline is withdrawn, so USCDI v3 stays the floor for the foreseeable future. The imaging exchange criteria are gone. The public health interoperability expansions are gone. The proposed patient engagement criteria are gone. Several privacy and security enhancements inside the certification framework are gone. The stated reasons: comment feedback, the deregulation priority, and the observation that newer standards and AI have moved faster than the rulemaking cycle.
For founders this is a mixed bag. On the downside, anyone who built roadmap around mandated USCDI v4 elements (the expanded lab, medication, and clinical test data, plus the health status assessments and some of the SDOH fields) loses the regulatory forcing function. Vendors will still adopt v4 and beyond voluntarily, especially the big ones, but the long tail will not, and the long tail is where the data gaps live. Imaging exchange in particular was the one place where federal mandate would have actually moved a stuck market, and it is now back to being a bilateral negotiation between PACS vendors and everyone else.
On the upside, the withdrawal cements the FHIR-first posture. There is no longer a parallel track of document based exchange criteria being expanded. If you are building anything that assumes the future is FHIR resources and not C-CDA blobs, the regulatory environment just agreed with you. It also means the certification program is not going to keep moving the goalposts every eighteen months, which is the thing that made planning a certified product miserable.
The public health piece is the quiet tragedy. The pandemic showed exactly how bad public health data exchange is, HTI-2 tried to fix it inside the certification program, and now it is nobody’s mandate again. If a state or a philanthropic funder wanted to build a company around public health reporting infrastructure, the tailwind is gone and the headwind (fifty different state systems with no federal glue) is back. Worth noting for the investors: sometimes the withdrawal of a rule is the market signal, not the rule itself.
Company shapes worth building
Now the part everybody skipped ahead to. Five shapes, ordered by how directly they ride the rule.
Shape one: the agent native FHIR read and write layer. Not another integration platform. There are a dozen of those and they are all fine. This is specifically a layer that sits between autonomous agents and the certified APIs, handles SMART scopes and consent for non-human actors, logs every request in a format that doubles as info blocking evidence, negotiates manner alternatives automatically when an endpoint refuses, and exposes a write path that satisfies the safety controls health systems will insist on even after (a)(3) dies. The customers are AI application companies that do not want to build this themselves, and the pricing is per transaction with a floor. The moat is the evidence log, because whoever holds the record of which actors refused what and when becomes the default source for complaints and, eventually, for the plaintiffs’ bar. The risk is that the big integration platforms add this as a feature. The counter is that they are structurally allied with the EHR vendors whose behavior you are documenting, and customers notice that.
Shape two: info blocking enforcement tooling, aka compliance as a weapon. OIG can hit developers and HIEs with up to a million dollars per violation, and the provider disincentives (MIPS score zeroing, hospital PI failure, ACO exclusion) have been on the books since 2024. Enforcement has been anemic because complaints are hard to file well. The complaint process requires specific facts, the exception analysis is technical, and the complainant has to be willing to name a partner they still need to work with. A company that productizes the complaint (evidence collection, exception mapping, drafting, submission, tracking) for third party developers and for health systems fighting their own vendors has a real business, and HTI-5 doubles the addressable behavior by making automated access disputes and modification refusals clearly cognizable. The sneaky version of this is a data product: an index of actor behavior across endpoints, sold to app developers choosing which health systems to sell into and to investors pricing interoperability risk. The regulatory arbitrage is that ONC and OIG want complaints, so this company is aligned with the enforcer, which is a comfortable place to be.
Shape three: certification-lite specialty EHRs. With the criteria count down to something a small team can hit, the calculus for building a full system of record in a fragmented specialty flips. The playbook is: pick a specialty where the incumbents are pre-cloud and the buyers are independent (dermatology, ophthalmology, PT, behavioral health, med spa and longevity clinics, urgent care independents), build AI native from day one so documentation and coding are the product rather than a bolt-on, hit the slim certification bar so customers can still report to programs that require it, and use the FHIR-first posture to be more interoperable than the incumbent rather than less. The trap is thinking certification was the only barrier. Distribution, billing edge cases, and the sheer volume of specialty workflow nuance are still hard. But the timeline to a certified product just dropped from something like eighteen months to something like six, which changes what a seed round can buy.
Shape four: the governance layer that replaces what HTI-5 deleted. The model card and predictive DSI risk management requirements were thin, but they were the only federal AI transparency requirements aimed at clinical software. They are gone. Health systems still need to answer questions about what models are running in their environment, what data they were trained on, and how performance is monitored, because state laws (Colorado’s AI act, California’s health AI disclosure requirements, Texas’s TRAIGA, a growing list) and payer contracts and malpractice carriers are all asking. The federal government just handed that requirement to the market. A company that becomes the registry, monitoring, and attestation layer for clinical AI, sold to health systems and eventually required by their insurers, fills a hole the government just dug. The interesting twist is that HTI-5’s FHIR-first orientation means these tools can pull model usage data straight from the API logs rather than from vendor questionnaires. The risk is that this becomes a feature of the big governance platforms already selling to CIOs. The counter is that those platforms do not understand clinical validation and the buyers know it.
Shape five: payer facing agent readiness. The 2027 CMS-0057-F API deadlines plus the automated access clarification mean payers are about to get hit by provider side agents at volume. Most payers are building the APIs to the letter of the rule with no plan for what happens when ten thousand practices point retrieval agents at them in the same week. A company that sells payers the throttling, consent, audit, and manner negotiation infrastructure that keeps them out of info blocking trouble (payers are not actors under the rule, but their downstream provider partners are, and the political optics of a MA plan stonewalling provider agents while WISeR uses AI to deny FFS claims are not great) has a defined buyer with a defined deadline. Boring, lucrative, and the kind of thing the payer IT shops will not build well themselves.
Where this goes wrong
Honest accounting of the ways the thesis breaks, because the audience for this can smell a pitch deck.
The final rule could soften. The AI provisions drew the most heat in comments, from both directions. Consumer advocates want the model card stuff back. Some vendors want the autonomous AI language narrowed to exclude what they call unauthenticated scraping. It is entirely possible the final rule keeps the certification cuts (nobody fights those) and hedges the info blocking changes with new conditions. If the automated access language gets qualified with something like reasonable identity verification of the automated actor, that becomes its own new gate, and the vendors will run through it.
Vendors will migrate to other exceptions. Deleting (a)(3) does not delete the security exception, the privacy exception, or the fees exception. Expect a wave of security policies that just happen to classify agent traffic as a threat pattern, and a wave of fee schedules for write access that recover costs reasonably incurred at rates that make the marketplace look cheap. The rule anticipates this and requires consistency and non-discrimination, but consistency is a litigation standard, not a product standard, and it takes years to enforce.
Scorecard
This is the part where we admit that none of this is guaranteed and put some numbers on it anyway.
Certification cuts landing mostly intact: 8/10. There is broad consensus that the old criteria list was bloated, and almost nobody is burning political capital to save C-CDA export.
Automated access language surviving without being gutted: 6/10. The administration clearly wants to plant a flag for AI-enabled interoperability, but the pushback on bots and scraping is real, and some narrowing is likely.
(a)(3) deletion changing real-world write-back economics within three years: 7/10. EHR vendors will fight, but the combination of documented manner negotiations, shorter response timelines, and pent-up demand from AI vendors creates pressure.
New companies successfully using info blocking enforcement as a go-to-market wedge: 5/10. The opportunity is there; the question is whether founders want to live in a quasi-legal business and whether customers are willing to escalate.
Health systems buying a dedicated AI governance layer instead of assuming their existing GRC stack can handle HTI-5’s gap: 6/10. Early adopters will move; everyone else waits for their insurer or state regulator to force the issue.
Payers investing meaningfully in agent-readiness rather than treating CMS-0057-F as another checkbox: 4/10. Deadlines concentrate the mind, but payer IT has a long history of doing the minimum viable compliance.
OIG enforcement could stay sleepy. The disincentive framework has been live for two years and the enforcement docket is thin. Info blocking is a complaint driven regime, and the people best positioned to complain are the ones with the most to lose commercially from doing so. Shape two above only works if the complaint volume rises, and complaint volume is a collective action problem.
The FHIR-first bet might overshoot. FHIR is great for what it covers and terrible at the edges, and the edges (scanned documents, images, unstructured notes, the eighty percent of historical records that exist as PDFs) are where a lot of the value sits. A certification program that only cares about FHIR usage stops caring about the messy stuff, and the messy stuff does not go away because a rule stopped mentioning it. Anyone building the agent layer needs a plan for non-FHIR content or the agent will be very good at pulling structured vitals and useless at the actual chart.
And the deregulation itself could be its own headwind in a subtle way. Certification, for all its cost, was a quality signal that buyers used as shorthand. When the bar drops, the signal weakens, and a health system evaluating a new specialty EHR has to do more diligence itself. That raises sales cycle length for exactly the upstarts the rule was supposed to help. The winners will be the ones who build their own trust signals (public API performance, third party security attestations, published clinical validation) rather than relying on a certification badge that now means less.
Net net, HTI-5 is the most founder friendly health IT rule in a decade, with the caveat that founder friendly and patient friendly are not always the same thing and the AI transparency rollback is a real loss. The certification cuts lower the cost of entry for systems of record in a way that will show up in seed round math within a year. The automated access clarification and the modification use deletion together change the default legal posture from stonewall to negotiate, which is the thing every read-only AI company has been waiting for. The HTI-2 withdrawal removes some tailwinds (imaging, public health, USCDI v4) but locks in the FHIR-first direction that most modern builders already bet on.
The plays, for the cheap seats: build the agent facing read/write layer and own the evidence log, productize the complaint, build specialty systems of record while the bar is low, replace the federal AI governance the rule deleted, and get payers ready for the agent traffic they have no plan for. Watch for the final rule text on the autonomous AI language and the fees exception, because those two paragraphs decide whether this is a big shift or a medium one. Either way, the era of an EHR vendor being able to say sorry, our terms of service do not allow robots is closing, and the people who move first get the best seats
.


