Guides

The SAFER Guides: An EHR Safety Self-Assessment for Practices

The SAFER Guides are free, ONC-published self-assessment checklists that let a practice grade its own EHR setup against recommended safety practices — things like whether your downtime plan works, whether test results reliably reach the ordering clinician, and whether two patients with the same name can be confused in your system. The 2025 edition consists of eight guides organized into three groups, and ONC publishes them as interactive PDFs you can download and complete locally. They are voluntary as tools. They are not entirely optional in practice, because CMS attaches a SAFER Guides measure to the Medicare Promoting Interoperability Program and to the Promoting Interoperability performance category of MIPS.

What the SAFER Guides are

SAFER stands for Safety Assurance Factors for EHR Resilience. Each guide is a set of recommended practices with a self-assessment worksheet: for each practice you record whether you have fully implemented it, partially implemented it, or not implemented it, and you note the evidence and the owner. It is deliberately not an audit. Nobody submits it to ONC. The output is a picture of your own risk that you can act on.

ONC's framing for the 2025 revision is worth quoting in spirit: the guides were updated and streamlined to focus on the highest-risk, most commonly occurring issues that can be addressed through technology or practice changes, in order to build system resilience. In other words, they are a triage list, not a completeness exercise.

The 2025 SAFER Guides

GroupGuideWhat it covers
FoundationalHigh Priority Practices16 recommendations pulled from the other seven guides, selected for their relevance and importance for practicing clinicians. Start here.
Organizational ResponsibilitiesThe activities, processes and tasks that optimize safe EHR use — with new content on AI-enabled systems and EHRs with enhanced AI features
InfrastructureContingency PlanningPlanned and unplanned EHR unavailability — what happens when clinicians cannot reach all or part of the record
System ManagementConfiguration, validation and maintenance of EHR hardware, software and system-to-system APIs, including the physical environment and testing of complex components
Clinical ProcessPatient IdentificationReliably matching the information on screen to the human in the room
Computerized Provider Order Entry with Decision SupportOrder structure, mapping, libraries, alerts and warnings clinicians rely on during care
Test Results Reporting and Follow-UpElectronic communication and management of test results — the classic missed-result failure mode
Clinician CommunicationMessaging among clinicians, care teams and patients, including care transitions and portal communication

The Organizational Responsibilities guide is the one that changed most in 2025: it now addresses AI-enabled systems and EHRs with enhanced AI features or functions used in administration, diagnosis, treatment and management of patient care. If your vendor has shipped ambient documentation or AI-assisted triage into your workflow, that guide is the closest thing to a public-sector checklist for governing it.

How CMS ties them to Promoting Interoperability

This is where practices get tripped up by version confusion, so be precise. Per ONC, the previous versions of the SAFER Guides, published in 2016, continue to be applicable for the SAFER Guides measures included in the Medicare Promoting Interoperability Program for eligible hospitals and critical access hospitals, and the Promoting Interoperability performance category of the Merit-based Incentive Payment System (MIPS).

CMS places the SAFER Guides measure under the Protect Patient Health Information objective, and the requirement is not the same for clinicians and hospitals. Per CMS's SAFER Guides infographic:

WhoWhat the measure asks
MIPS eligible clinicians (PI performance category)Report "yes" or "no" to completing an annual self-assessment using only the High Priority Practices SAFER Guide
Eligible hospitals and CAHs (Medicare PI Program)Attest "yes" or "no" to completing an annual self-assessment using all nine SAFER Guides

Two details worth knowing. The self-assessment must be completed by the last day of the performance period, and it can be done outside the 90-day reporting window that governs the category's other requirements. And — counterintuitively — both answers are acceptable. Reporting "no" is a valid response. Leaving the measure blank is what scores zero.

Two versions are in play, on purpose. Use the 2025 guides for actual safety improvement — current, streamlined, AI-aware. Use whatever CMS specifies for the reporting measure, which is presently keyed to the 2016 versions. Do not assume completing the 2025 self-assessment automatically satisfies a CMS measure, and verify the requirement for the performance year you are reporting rather than last year's memory.

Why a small practice should bother

The honest answer is not the CMS measure. It is that the failure modes these guides describe are the ones that actually hurt patients in small practices, and they are all quiet:

  • The result that came back abnormal and nobody saw it, because the ordering provider was out and the routing rule sent it to an inbox nobody covers.
  • The two patients with the same last name and birth year, one of whom now has the other's allergy list.
  • The downtime nobody had rehearsed, where the practice discovered at 8:05 a.m. that the paper downtime packet was a folder of blank forms and a phone number that had changed.
  • The alert everyone clicks through, because 40 fire every visit and 39 are noise.

Every one of those is a checklist item in a SAFER guide. None of them show up in a vendor demo. A practice that has actually worked through the High Priority Practices guide has a materially better answer to "could that happen here?" than one that has not.

How to actually run a self-assessment

  1. Start with High Priority Practices. Sixteen recommendations, drawn from the other guides. If you do nothing else, do this one.
  2. Do it as a group, not as a form. Put a physician, the practice manager, the person who actually handles results, and whoever owns your IT in the same room for ninety minutes. The value is in the disagreement about whether something is really implemented.
  3. Be honest about "partially." The temptation to mark everything fully implemented defeats the entire exercise. "Partially" is the most useful answer on the form, because it is where the work is.
  4. Record the evidence, not the intention. "We have a downtime procedure" is an intention. "Downtime procedure last tested 2026-03-14; packet verified; contact list current" is evidence.
  5. Assign an owner and a date to every gap before anyone leaves the room. A self-assessment with no owners is a document, not a program.
  6. Re-run it annually, and after any major EHR upgrade or workflow change. Upgrades routinely change alert behavior and result routing.

What to do with the findings

  • Split the list into three buckets: things you can fix in configuration this week; things that need a vendor; things that need a workflow change. The middle bucket is the one that stalls, so raise it with the vendor in writing and reference the specific SAFER recommendation.
  • Feed the results into your existing programs. Contingency Planning findings belong in your business continuity plan and overlap directly with the HIPAA Security Rule's contingency plan requirements. System Management findings belong in your patching and change-control process.
  • Keep the completed worksheets. They are evidence of a functioning safety program, and they are the fastest way to brief a new practice manager or a new physician partner on where the bodies are buried.
  • Bring the gaps to your next vendor conversation. A renewal negotiation is a good moment to ask a vendor to fix a documented safety gap.

Common questions

What are the SAFER Guides?

They are free self-assessment guides published by ONC that identify recommended practices for the safety and safe use of EHRs. The 2025 edition has eight guides in three groups — Foundational, Infrastructure, and Clinical Process — and is available as interactive PDFs that an organization completes locally to assess its own conformance with the recommended practices.

Are the SAFER Guides required?

The guides themselves are voluntary self-assessment tools, but CMS includes a SAFER Guides measure under the Protect Patient Health Information objective. Per CMS, MIPS eligible clinicians report "yes" or "no" to completing an annual self-assessment using only the High Priority Practices guide; eligible hospitals and CAHs attest across all nine guides. Both answers are acceptable — leaving the measure blank is what scores zero. Verify the requirement for your performance year.

Which version should we use — 2025 or 2016?

Both, for different reasons. ONC says the 2016 versions continue to be applicable for the SAFER Guides measures in the Medicare Promoting Interoperability Program and the MIPS Promoting Interoperability performance category. The 2025 versions are the current guidance for actually improving EHR safety, streamlined around the highest-risk issues and updated to address AI-enabled systems.

Where should a small practice start?

The High Priority Practices guide. It contains sixteen recommendations selected from the other seven guides specifically because of their relevance and importance for practicing clinicians. It is the shortest path from zero to a real list of things to fix.

Common questions

What are the SAFER Guides?

Free self-assessment guides published by ONC that identify recommended practices for the safety and safe use of EHRs. The 2025 edition consists of eight guides in three groups — Foundational, Infrastructure and Clinical Process — published as interactive PDFs an organization completes locally to assess its own conformance.

Are the SAFER Guides required?

The guides themselves are voluntary self-assessment tools, but CMS includes a SAFER Guides measure under the Protect Patient Health Information objective. Per CMS, MIPS eligible clinicians report yes or no to completing an annual self-assessment using only the High Priority Practices guide, while eligible hospitals and CAHs attest across all nine guides. Both answers are acceptable — leaving the measure blank is what scores zero. Verify the requirement for your performance year.

Should we use the 2025 or the 2016 SAFER Guides?

Both, for different purposes. ONC states the 2016 versions continue to be applicable for the SAFER Guides measures in the Medicare Promoting Interoperability Program and the MIPS Promoting Interoperability performance category. The 2025 versions are the current safety guidance — streamlined to the highest-risk issues and updated to address AI-enabled systems.

Where should a small practice start with the SAFER Guides?

The High Priority Practices guide. It contains sixteen recommendations drawn from the other seven guides, selected for their relevance and importance to practicing clinicians. It is the shortest path from nothing to a concrete list of safety gaps to fix.