Binding law — in force
Intervention risk management practices must be applied to each Predictive Decision Support Intervention the health IT developer supplies as part of its Health IT Module: analysis of potential risks and adverse impacts for validity, reliability, robustness, fairness, intelligibility, safety, security and privacy; practices to mitigate the risks identified; and policies and implemented controls for governance, including how data are acquired, managed and used (45 CFR 170.315(b)(11)(vi)(A)-(C)). The records are kept by the developer outside the code. Report a missing risk-management record as not verifiable from code.
us-onc-hti1-dsi.predictive-dsi-intervention-risk-management · 45 CFR 170.315(b)(11)(vi) · official source · jurisdictions: US
The guard to add, and how far to trust this rule
Binding law — in force
A Health IT Module certified to the decision support interventions criterion must support source attributes for Predictive Decision Support Interventions (technology based on algorithms or models that derive relationships from training data, 170.102): the developer and funding source, output type, intended use, population, users and decision role, cautioned out-of-scope uses and known risks, training-data inclusion and exclusion criteria, protected-characteristic inputs and demographic representativeness, the fairness approach, external validation, quantitative validity and fairness measures, ongoing monitoring and the update schedule (170.315(b)(11)(iv)(B)). A limited set of identified users must be able to access complete, up-to-date plain-language descriptions of them, see when information is not available, and record and change them (170.315(b)(11)(v)). Detect predictive decision support code with no source-attribute record.
us-onc-hti1-dsi.predictive-dsi-source-attributes · 45 CFR 170.315(b)(11)(iv)(B) · official source · jurisdictions: US
The guard to add, and how far to trust this rule