Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

ONC Health IT Certification Program

The ONC Health IT Certification Program is the US voluntary-but-effectively-mandatory program under which health IT is certified against federal criteria. Its Cures Act Final Rule 'Standardized API for patient and population services' criterion — commonly cited as (g)(10) — requires certified systems to expose HL7 FHIR (US Core), SMART App Launch, SMART Backend Services, and Bulk Data, with published service base URLs and transparent, non-discriminatory business terms. It defines what a compliant healthcare API must technically contain.

The ONC Health IT Certification Program is where the Cures Act’s ‘standardized API’ promise becomes a concrete checklist. Certification is nominally voluntary, but because it gates participation in federal programs it is effectively mandatory — and its (g)(10) criterion is the precise definition of what a compliant EHR FHIR API has to be.

  • The (g)(10) ‘Standardized API’ criterion - Certified systems must expose HL7 FHIR with US Core profiles, SMART App Launch, SMART Backend Services, and Bulk Data.
  • Transparency conditions - Published service base URLs and transparent, non-discriminatory business and technical terms — an attempt to stop malicious compliance.
  • The USCDI data floor - The API must carry the current USCDI data classes.

I catalogue the certification program because it is the rare mandate that reached past ‘have an API’ toward ‘have a specified one’ — it names the standards, which is more than most regulators do. And yet my scoring shows the limit of even a well-specified rule: a certified (g)(10) endpoint at an incumbent is real and gated, a compliance interface rather than a developer product. Specifying the standard is necessary and not sufficient; the examples, discovery documents, consent surface, and self-serve access that make it usable are still left to the vendor’s discretion, and mostly left unbuilt.

Referenced in API Evangelist papers

This regulation shows up in my published research. These reports read the machine-readable evidence provider by provider — and put this regulation in the context of a real sector.

The State of US Healthcare APIs

The certification program whose (g)(10) criterion defines what a compliant EHR FHIR API must actually contain.

Implemented by these standards

A regulation is the law; a standard is the machine-readable contract that makes it real. These are the technical standards that implement this regulation, catalogued at standards.apievangelist.com.

SMART on FHIR

The (g)(10) criterion requires SMART App Launch and SMART Backend Services.

US Core

Certified APIs must expose US Core profiles.

USCDI

The data classes certified health IT must support.