HTI-2: What Was Finalised, What Was Withdrawn, and What It Means
Health Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement (TEFCA) final rule, 89 FR 101772
Last updated
Free tool
Twelve factual questions on data access, governance and change capacity.
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callRegulator
Assistant Secretary for Technology Policy and Office of the National Coordinator for Health Information Technology (ASTP/ONC)
Who it applies to
- Qualified Health Information Networks and their participants operating under the Trusted Exchange Framework and Common Agreement, now governed by 45 CFR Part 172
- Developers of certified health IT, for the certification criteria finalised through HTI-4 covering electronic prescribing, real-time prescription benefit and electronic prior authorisation
- Information blocking actors as defined by the Cures Act: health care providers, health IT developers of certified health IT, and health information networks and health information exchanges
- Provider organisations indirectly, through the exchange capabilities their certified health IT is required to support and through their own information blocking exposure
- Not third party AI vendors as such, unless they operate as a health information network or exchange, which is a question about what the vendor actually does rather than what it calls itself
Penalties
Nothing in the HTI-2 final rule creates a new penalty. Enforcement in this area runs through two separate channels. Certification program non-conformities are handled by ONC direct review under 45 CFR 170.580, with corrective action and possible suspension or termination of a certification. Information blocking is handled separately: health IT developers of certified health IT and health information networks and exchanges face civil money penalties referred through the HHS Office of Inspector General, while health care providers found by OIG to have committed information blocking face disincentives established under section 4004 of the 21st Century Cures Act, applied through CMS programs rather than as fines.
Deadlines
Dates that already bind, and dates still ahead.
| Date | What happens |
|---|---|
| HTI-2 proposed rule published at 89 FR 63498 under the title Patient Engagement, Information Sharing, and Public Health Interoperability. Comments closed October 4, 2024. | |
| HTI-2 final rule published at 89 FR 101772, covering TEFCA only. | |
| HTI-3, Protecting Care Access, published at 89 FR 102512 and effective the same day. It finalised the information blocking provisions from the HTI-2 proposal. | |
| HTI-2 final rule effective date. | |
| HTI-4 effective. It finalised the electronic prescribing, real-time prescription benefit and electronic prior authorisation certification criteria from the HTI-2 proposal, published inside the FY2026 CMS IPPS final rule at 90 FR 36536. | |
| ASTP/ONC withdrew the remaining unfinalised HTI-2 proposals at 90 FR 60602, and published the HTI-5 proposed rule at 90 FR 60970. | |
| HTI-5 comment period closed at 5:00 pm ET. No final rule had been published as of early August 2026. |
What changed in 2026
Movement by year, newest first. Where nothing in the text moved, that is recorded too.
2026
The HTI-2 proposed rule is formally dead as a vehicle. Its withdrawal took effect on December 29, 2025 and nothing further has been finalised from it. Attention moved to HTI-5, whose comment period closed on February 27, 2026 and which had not been finalised as of early August 2026.
On the standards side, ASTP/ONC announced on July 31, 2026 that it had finalised the adoption of certain health IT standards through the FY2027 CMS IPPS final rule, published August 4, 2026 at 91 FR 49570 with an October 1, 2026 effective date. ONC also ran a request for information on diagnostic imaging interoperability standards and certification, published January 30, 2026 at 91 FR 4054, with comments closing March 16, 2026. Both point the same way: the agency is using standards adoption and payment rules rather than large certification rulemakings.
2025
The HTI-2 final rule took effect on January 15, 2025. HTI-4 followed on October 1, 2025 as part of the FY2026 IPPS final rule, bringing the first federal certification criteria for electronic prior authorisation, which is the piece most directly relevant to anyone automating prior authorisation workflows.
In December, ASTP/ONC withdrew the remaining HTI-2 proposals and published HTI-5, a deregulatory rule that would reset the certification program's scope and, in the agency's words, advance a new foundation of AI-enabled interoperability solutions through modernised standards and certification. The direction of travel is fewer criteria and more emphasis on FHIR based APIs.
2024
ASTP/ONC proposed HTI-2 on August 5, 2024 as a single large rule covering patient engagement, information sharing and public health interoperability. It was then finalised in pieces. The TEFCA provisions became the HTI-2 final rule on December 16. The information blocking provisions became HTI-3 on December 17, adding a definition of reproductive health care at 45 CFR 171.102, revising the Privacy and Infeasibility exceptions, and creating a new Protecting Care Access Exception at 45 CFR 171.206.
What is the HTI-2 final rule, and what does it actually cover?
Most people searching for HTI-2 are looking for the August 2024 proposed rule, which was a sprawling document covering patient engagement, information sharing, public health interoperability, electronic prior authorisation and much else. That is not what was finalised.
The HTI-2 final rule, published December 16, 2024 at 89 FR 101772 and effective January 15, 2025, finalises only the Trusted Exchange Framework and Common Agreement provisions. Specifically it creates a new part of the Code of Federal Regulations for TEFCA at 45 CFR Part 172, implementing section 3001(c)(9) of the Public Health Service Act as added by the Cures Act, adopts the TEFCA related definitions as proposed, and amends the information blocking regulations to include definitions tied to the TEFCA Manner Exception. ASTP/ONC has been explicit that it made no changes to the TEFCA Manner Exception itself at 45 CFR 171.403.
If you came here expecting the patient engagement or public health provisions, they are not in this rule. Some became HTI-3 and HTI-4. The rest were withdrawn. The next section maps it.
What happened to the rest of the HTI-2 proposed rule?
ASTP/ONC broke the proposal apart and finalised it in fragments across three vehicles, then withdrew the remainder. Here is the whole HTI series as it stands in 2026.
| Rule | Subject | Status and key date | Why it matters for AI deployments |
|---|---|---|---|
| HTI-1 | Certification program updates, algorithm transparency, information sharing | Final. 89 FR 1192, published January 9, 2024, effective February 8, 2024 | The predictive model transparency requirements, including the 31 source attributes, live here |
| HTI-2 | Trusted Exchange Framework and Common Agreement | Final. 89 FR 101772, published December 16, 2024, effective January 15, 2025 | Governs a nationwide exchange route your agents may draw data from, but imposes nothing on the agent itself |
| HTI-3 | Protecting Care Access | Final. 89 FR 102512, published and effective December 17, 2024 | New information blocking exception at 45 CFR 171.206 plus revisions to the Privacy and Infeasibility exceptions. Relevant to any agent that decides what to release |
| HTI-4 | Electronic prescribing, real-time prescription benefit, electronic prior authorisation | Final. Published inside the FY2026 IPPS final rule at 90 FR 36536, effective October 1, 2025 | First federal certification criteria for electronic prior authorisation. Pairs with the CMS prior authorisation rule on the payer side |
| HTI-2 remainder | Patient engagement, public health interoperability and other proposals | Withdrawn. 90 FR 60602, December 29, 2025 | Do not plan against anything in the 2024 proposal that is not listed above |
| HTI-5 | ASTP/ONC deregulatory actions | Proposed. 90 FR 60970, December 29, 2025. Comments closed February 27, 2026, not final as of August 2026 | Would shrink the certification program and, per ASTP/ONC, remove the AI model card requirements from the DSI criterion |
The pattern is worth naming because it will repeat. Health IT policy is increasingly finalised inside CMS payment rules rather than standalone ONC rulemakings, and it is increasingly deregulatory. If your compliance calendar only watches for rules with ONC on the masthead, you will miss things.
How does HTI-2 differ from HTI-1?
They regulate different objects. HTI-1 regulates what a certified product must disclose and do, including the algorithm transparency requirements that are the main reason a health system's AI committee cares about the HTI series at all. HTI-2 regulates the rules of a network, TEFCA, and the definitions that surround it.
Put concretely: HTI-1 is the rule that lets a clinical informatics lead demand 31 structured attributes about a sepsis model shipped inside their EHR. HTI-2 is the rule that formalises how a Qualified Health Information Network operates and what the associated information blocking definitions mean. Nothing in HTI-2 says anything about a model, a prediction or an AI agent.
That distinction matters at procurement. Vendors occasionally describe themselves as HTI compliant without saying which rule. There is no such thing as being compliant with the HTI series as a whole. Ask which criterion, in which rule, and whether the product is listed on the Certified Health IT Product List. If the answer is vague, it usually means the product is not certified to anything and does not need to be, which is a legitimate position that should simply be stated plainly.
Does TEFCA matter when you are deploying an AI agent?
Usually not directly, and occasionally a great deal. TEFCA is a nationwide framework for exchanging electronic health information between networks. Your agent almost certainly does not join it. What TEFCA affects is the quality and breadth of the record your agent reads from.
Two situations make it operationally relevant. The first is care coordination and referral workflows where an agent is assembling an external record before a visit. If your organisation participates in a Qualified Health Information Network, the agent sees more history, and the completeness of what it sees becomes a clinical safety question rather than an IT one. The second is any agent that responds to an external request for information. The HTI-2 final rule added information blocking definitions tied to the TEFCA Manner Exception, so how a request arrives can affect how you are permitted to respond to it.
Neither situation puts an obligation on the AI vendor. Both put one on you. If an agent is in the path of a data release decision, the information blocking analysis is yours, and it is not a decision to automate without a documented policy behind it. That is a governance question, and we treat it as one in the deployment roadmap.
How do the information blocking rules affect an agent deployment?
Information blocking is a practice by an actor that is likely to interfere with the access, exchange or use of electronic health information, except as required by law or covered by an exception in 45 CFR Part 171. The Cures Act applies it to health care providers, health IT developers of certified health IT, and health information networks and exchanges. Exceptions are voluntary safe harbours: meeting one means the practice is not information blocking, and failing to meet one does not automatically mean it is, since practices are assessed case by case.
Three failure modes show up in real agent deployments.
- Delay dressed as workflow. An agent that queues a records request for human review, indefinitely, is a delay. Whether it is information blocking depends on the reason and whether an exception applies. Design a service level into the workflow and record it.
- Over-broad withholding. An agent applying a blanket rule to sensitive categories may be reaching further than the Privacy Exception at 45 CFR 171.202 supports. HTI-3 revised that exception and the Infeasibility Exception at 171.204, and added a Protecting Care Access Exception at 171.206 with a definition of reproductive health care at 171.102. If your suppression logic predates December 2024, it predates the current text.
- Silent failures. An agent that drops requests it cannot parse, without alerting anyone, produces interference nobody chose. Log every declined or unhandled request and review the log.
None of this is exotic. It is the ordinary discipline of writing down what the automation does and why, which is the same discipline HIPAA already asks for.
Which API and certification provisions actually matter for agents?
Set the TEFCA material aside and the practically useful part of this rulemaking cluster is the certification criteria your EHR has to support, because those are what your agent integrates against.
Standardised API for patient and population services, 45 CFR 170.315(g)(10). This is the FHIR based API criterion that most third party integrations depend on, and it was one of the fifteen criteria with a revised version due on January 1, 2026, softened by enforcement discretion to February 28, 2026. When a vendor tells you an integration is not yet available, the useful follow up is which version of (g)(10) their EHR is currently certified to.
Electronic prior authorisation criteria from HTI-4. Effective October 1, 2025, these are the first federal certification criteria covering electronic prior authorisation, along with related API criteria and standards adopted for HHS use to support exchange of clinical and administrative information with payers. They are the provider side counterpart to the payer side obligations in the CMS prior authorisation rule, and they matter a great deal to anyone building prior authorisation automation or denial management workflows.
USCDI version 3. It became the certification program baseline on January 1, 2026. If an agent depends on data elements that only exist in a later USCDI version, that is a gap to confirm rather than assume, and it is worth checking against your specific product on the Certified Health IT Product List rather than against the vendor's marketing page.
What would HTI-5 change, and should you plan for it?
HTI-5 was published on December 29, 2025 at 90 FR 60970 as Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity, framed against Executive Order 14192 on deregulation and Executive Order 14267 on anti-competitive regulatory barriers. ASTP/ONC describes three aims: reduce burden by removing redundant certification requirements, revise definitions so that patient access to data is not blocked, and advance a foundation of AI-enabled interoperability through modernised standards and certification. It would also reset the program's regulatory scope to make room for future FHIR based API requirements.
The provision most relevant to AI programmes is the proposed reduction in scope of the decision support interventions criterion, which ASTP/ONC's own materials describe as removing the AI model card requirements. If finalised as proposed, the structured transparency that HTI-1 currently forces out of EHR vendors would become voluntary.
Our advice is unchanged by the uncertainty, which is rather the point. Write the model documentation you need into vendor contracts, keep your own inventory, and do not treat a certification criterion as a substitute for either. Organisations that did that are indifferent to the outcome. Organisations that relied on the criterion are exposed to it. The governance and compliance engagement exists precisely to move an organisation from the second position to the first.
What should you do, and by when?
There is no HTI-2 compliance deadline for a provider organisation. There is a short list of things worth confirming.
- Stop planning against the 2024 proposal. Anything in the HTI-2 proposed rule that is not in HTI-2, HTI-3 or HTI-4 was withdrawn on December 29, 2025.
- Confirm which (g)(10) version your EHR is certified to and whether the January 2026 update landed. Ask for the Certified Health IT Product List entry, not a verbal assurance.
- Check whether your EHR is certified to the HTI-4 electronic prior authorisation criteria. If you are building payer facing automation, this determines what you can do natively and what needs a workaround.
- Review your information blocking policies against the post-HTI-3 text. The Privacy and Infeasibility exceptions were revised and the Protecting Care Access Exception was added in December 2024.
- Map every agent that sits in a release-of-information path and give each one an owner, a logged decline path and a service level.
- Watch HTI-5. It was still pending as of early August 2026 and would change what your vendor has to disclose about its models.
Steps two to five are the ones that surface real problems, and they usually surface them in a hospital or group practice as a mismatch between what the workflow does and what the written policy says it does. If you would rather find that in an assessment than in an audit, that is what the AI readiness audit is for.
Official sources
Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.
- ONCHTI-2 Final Rule, ASTP/ONC (opens in a new tab)
- ONCHealth Data, Technology, and Interoperability: Trusted Exchange Framework and Common Agreement (TEFCA), 89 FR 101772 (opens in a new tab)
- ONCHTI-3 Final Rule, Protecting Care Access, ASTP/ONC (opens in a new tab)
- ONCHTI-4 Final Rule, Electronic Prescribing, Real-Time Prescription Benefit, and Electronic Prior Authorization, ASTP/ONC (opens in a new tab)
- ONCInformation Blocking, ASTP/ONC (opens in a new tab)
- ONCHTI-5 Proposed Rule, ASTP/ONC (opens in a new tab)
- ONCCertification of Health IT, ASTP/ONC (opens in a new tab)
Questions we get asked
Was the HTI-2 rule ever finalised?
Yes, but only in part. The HTI-2 final rule published December 16, 2024 finalises the TEFCA provisions and nothing else. The information blocking provisions from the same proposal became HTI-3, the electronic prior authorisation and prescribing criteria became HTI-4, and ASTP/ONC withdrew everything else on December 29, 2025.
Does HTI-2 impose any requirement on AI vendors?
No. HTI-2 governs TEFCA and the definitions around it. It says nothing about models, predictions or AI agents. The rule in the series that does address predictive models is HTI-1, and it binds developers of certified health IT rather than standalone AI vendors.
What is the difference between HTI-2, HTI-3 and HTI-4?
They are three separate final rules carved out of one proposal. HTI-2 covers TEFCA. HTI-3, Protecting Care Access, covers information blocking, adding a new exception at 45 CFR 171.206 and revising the Privacy and Infeasibility exceptions. HTI-4 covers electronic prescribing, real-time prescription benefit and electronic prior authorisation certification criteria, and was published inside the FY2026 CMS IPPS final rule.
Can an AI agent cause an information blocking violation?
An agent cannot be an actor, but you can. If automation delays, restricts or silently drops requests for electronic health information, the practice is attributed to the health care provider, developer or network that deployed it. Design agents in a release-of-information path with a defined service level, a logged decline route and a policy that names the exception being relied on.
Do we need to join TEFCA to deploy AI agents?
No. TEFCA participation is a separate strategic decision about nationwide data exchange and has no bearing on whether you can deploy an agent. It affects how complete the record your agent reads from is likely to be, which is a clinical safety consideration rather than a compliance requirement.
Is HTI-5 final yet?
Not as of early August 2026. HTI-5 was published as a proposed rule on December 29, 2025 at 90 FR 60970 and its comment period closed on February 27, 2026. If finalised as proposed it would substantially shrink the certification program and remove the AI model card requirements from the decision support interventions criterion.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion