Health Officials Promise Better Cybersecurity Accessibility and AI Safety Standards
HHS officials discussed the 405(d) program changes and ONC leaders discussed how the HTI-1 Final Rule will affect AI in health care.

ORLANDO โ Officials from the Department of Health and Human Services (HHS) and the National Coordinator for Health IT (ONC) outlined changes to cybersecurity standards and electronic health records interoperability at the HIMSS conference in Orlando, Florida, Tuesday.
New Additions to HHS 405(d) Program
Officials from HHS announced a Spanish language page, as well as a new health care and public health sector (HPH) cybersecurity gateway as the latest updates to the 405(d) program, a collaboration of the Health Sector Coordinating Council and the federal government to align security practices. The gateway, released in December, provides voluntary cybersecurity performance goals and serves as a โconsistently evolving, comprehensive and accessible hubโ for health organizations.
โThis is the beginning of how we, at HHS, plan to expand our resources into the sector and underserved communities,โ Nick Rodriguez, HHS 405(d) program manager, said. โEveryone plays a critical role in cybersecurity, and we are excited to help and reach that loop across organizations.โ
In addition to the recent updates, Rodriguez also noted the importance of the updates announced during the 2023 HIMSS conference, which included the first hospital cyber resiliency landscape analysis, publishing and using the health industry cybersecurity practices (HICP) and providing free cybersecurity trainings and resources for health organizations. Rodriguez said HHS plans to release an annual landscape analysis and HICP.
New Requirements for the HTI-1 Final Rule
Following the recent release of the HTI-1 final rule, officials from ONC discussed why transparency is crucial for the use of AI in health care. The HTI-1 final rule, or Health Data, Technology, and Interoperability: Certification Program Updates, Algorithm Transparency, and Information Sharing, is an addition to the ONC Health IT Certification Program establishing transparency requirements for AI and other algorithms used in health care settings. With requirement updates, ONC aims to improve transparency and interoperability in health IT settings.
Following its proposal in April 2023, the HTI-1 final rule went into effect on February 8. The new requirements amend the information blocking regulations previously enacted by the ONC under the 21st Century Cures Act. The HTI-1 final rule also:
- Raises the United States Core Data for Interoperability (USCDI) Version 3, a standard for health data classes, from version 1
- Sets new requirements for standardized application programming interface (API)
- Facilitate interoperability with the standardization of health information and functionality
At HIMSS, Deputy Director of ONCโs Certification and Testing Division Jeffery Smith outlined the updated requirements for developers who supply predictive decision support interventions (DSI) to health care organizations. Developers must include 13 source attributes for evidence-based data sets and 31 for predictive data sets, which will create a baseline for the future. Smith said developers donโt need to provide DSIs to their customers, but they do need to โenable their users to select a predictive DSI.โ
โThat may not sound like a terribly different way of looking at things but itโs really important to know the developer doesnโt have to have a predictive DSI,โ Smith said. โBut, they do have to enable their users to select a particular site. Weโd also note here that the developer is not responsible for content that might get modified by the users.โ
Smith reiterated the timeline developers who provide DSIs are required to follow: all certified technology must be updated by December 31, 2024, to โsupport the capabilities for DSIs.โ He also noted that health care organizations arenโt required to use DSIs by that date, but will have access to them.
The Challenges of Regulating AI in Health Care
The need for data quality, equity and ethical requirements is important as officials and federal agencies weigh the idea of implementing artificial intelligence and machine learning. AI technology is changing quickly, reinforcing the need to standardize ethical AI practices. Without standards, regulations or best practices, health professionals run the risk of contributing to differential treatment, medical errors and inequitable results of treatment.
โWhen we talk about the challenges of regulation, itโs hard because the field of AI like most emerging technologies, continues to evolve at a rapid pace and government doesnโt always evolve at [that pace],โ ONC Senior Advisor to the Deputy National Coordinator Stephen Konya III said.
Konya discussed the challenge of regulating AI, as it needs to allow innovation while ensuring cybersecurity and safety. Konya referenced other agencies within HHS, like the Food and Drug Administration and its clinical decision support tools, which allows evolving guides and toolkits for accurate training.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Modernizing Critical Infrastructure in the Face of Global Threats
Officials are expanding the latest strategies in boosting defense infrastructure, including securing satellite communications, upgrading enterprise-wide technology, optimizing data management.
20m watch -
DOD Accelerates Software Modernization with Agile DevSecOps Push
The Pentagon's software implementation plan tackles cultural hurdles and integrates security early to deliver critical capabilities faster.
6m read -
VA's Platform One Powers Rapid Innovation to Bolster Digital Services
VA's Platform One accelerates software development timelines from weeks to hours, ultimately enhancing digital services for veterans.
5m read -
VA CIO Targets Modern IT and Smarter Workforce Alignment
Agency leaders told lawmakers they are focused on trimming legacy systems and restructuring its workforce to streamline operations.
3m read -
The Next AI Wave Requires Stronger Cyber Defenses, Data Management
IT officials warn of new vulnerabilities posed by AI as agencies continue to leverage the tech to boost operational efficiency.
5m read -
Federal CIOs Push for ROI-Focused Modernization to Advance Mission Goals
CIOs focus on return on investment, data governance and application modernization to drive mission outcomes as agencies adopt new tech tools.
4m read -
Trump Executive Order Boosts HBCUs Role in Building Federal Tech Workforce
The executive order empowers HBCUs to develop tech talent pipelines and expand access to federal workforce opportunities.
3m read -
DOD Can No Longer Assume Superiority in Digital Warfare, Officials Warn
The DOD must make concerted efforts to address cyber vulnerabilities to maintain the tactical edge, military leaders said at HammerCon 2025.
4m read -
Tracking CIOs in Trump's Second Term
Stay informed on the latest shifts in federal technology leadership as new CIOs are appointed and President Trump's second term takes shape.
6m read -
IHS Prepares to Deploy PATH EHR at Pilot Sites in 2026
IHS targets PATH EHR pilot in 2026, emphasizing governance, collaboration and interoperability as key pillars of the modernization strategy.
4m read -
Inside Oak Ridge National Labโs Pioneer Approach to AI
Energy Departmentโs Oak Ridge National Lab transforms AI vulnerabilities into strategic opportunities for national defense.
22m listen -
FEHRM CTO Targets Two-Year Cloud Migration for Federal EHR
Lance Scott touts new EHR tech advancements, including cloud migration, expanded data exchange and AI integration to improve care delivery.
4m read