When you shop for EHR software you will frequently see the phrase “certified EHR technology,” often abbreviated CEHRT. Certification is a formal process run under the federal Health IT Certification Program, and it has real consequences for practices that participate in certain federal programs.
What certification means
Health IT certification is administered by the Assistant Secretary for Technology Policy/Office of the National Coordinator for Health IT (ASTP/ONC). Products are tested by independent, accredited testing labs and certified by ONC-Authorized Certification Bodies against a defined set of criteria. Certification confirms that the technology meets specific functional and technical requirements — it is not an endorsement of overall quality or usability.
The certification criteria
The criteria are defined in federal regulation and cover capabilities such as clinical data capture, e-prescribing, clinical decision support, security, and the ability to export and exchange data using standardized formats. More recent editions place strong emphasis on application programming interfaces (APIs) using the HL7 FHIR standard so that patients and apps can access data.
Why it matters
Certification is most relevant if your practice participates in federal incentive or quality programs. For example, clinicians in the Merit-based Incentive Payment System (MIPS) Promoting Interoperability performance category must use certified technology to earn credit. Certification also signals that a product supports modern data-exchange standards, which is increasingly important regardless of incentive programs.
What certification does not guarantee
- It does not mean the software is easy to use for your specialty.
- It does not guarantee a smooth implementation or strong support.
- It does not lock in pricing or contract terms.
- It does not mean every optional feature is present — check which criteria the specific product version meets.
Practical takeaways
Treat certification as a baseline filter, not a final answer. Confirm the product and version on CHPL, ask the vendor which certified criteria apply to the edition you will actually run, and then evaluate usability, support, and fit through demos and reference checks. Certification tells you a product can do certain things in a test environment; it does not tell you how well it will work in your exam rooms.
How certification editions evolve
The certification criteria are not static. They are updated through federal rulemaking to keep pace with new standards and policy goals — for example, strengthening API requirements, advancing data-exchange standards, and adding capabilities such as those relevant to pediatric care. Because of this, two products can both be "certified" yet meet different sets of criteria from different rule editions. When you compare products, ask which criteria and which edition apply, and check whether the vendor's roadmap keeps the product current as requirements change.
Real-world testing and transparency
Recent program requirements emphasize transparency and real-world performance, not just one-time lab testing. Developers of certified health IT have obligations around disclosing limitations and supporting standardized data export. As a buyer, you can ask a vendor to walk you through their certification listing on CHPL, point to the specific criteria your workflows depend on, and explain how they handle updates when criteria change. A vendor that is comfortable doing this is generally a better long-term partner than one that simply waves the word "certified."
A quick buyer's checklist
- Look up the exact product and version on CHPL and read its certified criteria.
- Confirm the criteria you rely on (e-prescribing, API access, quality measures) are present.
- Ask how the vendor handles criteria updates and re-certification over time.
- Remember certification is a floor, not a ceiling — usability and support still decide success.