Definition
Health IT Surveillance
Health IT surveillance is the ongoing oversight of certified health IT by ONC-Authorized Certification Bodies and through ASTP/ONC direct review, to confirm that products keep meeting certification requirements after certification and in real use.
2 min readReviewed September 14, 2026
Also known as: ONC-ACB surveillance, ONC direct review, Certified health IT surveillance, Health IT non-conformity
Key facts
- Routine surveillance
- ONC-Authorized Certification Bodies (ONC-ACBs)
- Direct review
- ASTP/ONC, under authority set by a 2016 final rule
- Regulations
- 45 CFR Part 170, including 170.556 and 170.580
- Public record
- Surveillance and non-conformities shown in CHPL listings
- Possible outcomes
- Corrective action plan, suspension or termination of certification
What is health IT surveillance?
Certification under the ONC Health IT Certification Program is based on testing a product in a controlled setting. Surveillance checks whether the product still conforms after developers release updates and customers use it in clinical settings, and whether developers keep meeting program requirements such as cost and limitation disclosures.
There are two tracks. ONC-Authorized Certification Bodies (ONC-ACBs) surveil the products they certified. The Assistant Secretary for Technology Policy and Office of the National Coordinator for Health IT (ASTP/ONC), formerly ONC, can also review certified health IT directly.
How surveillance and direct review work
Oversight follows a defined sequence of findings and remedies:
- Reactive surveillance: an ONC-ACB investigates when complaints or other information suggest a product may not conform.
- Randomized surveillance: ONC-ACBs may also select products at random for in-the-field review, which ONC made optional rather than required.
- Non-conformities: when a product fails a requirement, the developer must submit a corrective action plan, which the ONC-ACB approves and monitors.
- Direct review: ASTP/ONC can review products where a non-conformity may pose a serious risk to public health or safety, where issues exceed what an ONC-ACB can practically address, and for Conditions and Maintenance of Certification.
- Enforcement: ONC-ACBs can suspend or withdraw a certification, ASTP/ONC can suspend or terminate one, and affected developers can face a ban on new certifications until issues are resolved.
Why health IT surveillance matters
Surveillance records are a public compliance trail for certified products:
- Health IT buyers: CHPL surveillance history, open non-conformities and corrective action plans are due diligence signals when choosing or valuing a developer.
- Providers: a terminated or withdrawn certification can leave users without Certified EHR Technology (CEHRT) for CMS programs, and CMS has offered hardship relief in those cases.
- Hospital reporting: the Medicare Promoting Interoperability Program asks hospitals to attest that they will cooperate with ONC direct review of their certified health IT.
- Analysts: counts of non-conformities by developer and criterion show where certified capabilities most often fall short.