TwinEthos homeAPI access

Law

ONC HTI-1 decision support interventions criterion, 45 CFR 170.315(b)(11)

Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology (HHS) · United States (federal) (US) · 2 provisions encoded · verified against the official source as of 2026-10-04.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: www.ecfr.gov, www.federalregister.gov.

Trust and provenance 3 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 2 of 2 provisions audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 2
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 2 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 2.
Audit standard
2 of 2 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 2 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Apply risk analysis, risk mitigation and governance to every Predictive DSI a certified Health IT Module supplies (45 CFR 170.315(b)(11)(vi))

45 CFR 170.315(b)(11)(vi) · official text · In force: applies since 1 Jan 2025 · United States (federal) (US)

Intervention risk management practices must be applied to each Predictive Decision Support Intervention the health IT developer supplies as part of its Health IT Module: analysis of potential risks and adverse impacts for validity, reliability, robustness, fairness, intelligibility, safety, security and privacy; practices to mitigate the risks identified; and policies and implemented controls for governance, including how data are acquired, managed and used (45 CFR 170.315(b)(11)(vi)(A)-(C)). The records are kept by the developer outside the code. Report a missing risk-management record as not verifiable from code.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Jan 2025
Official source
45 CFR 170.315(b)(11)(vi) · captured 4 Oct 2026 · anchor hash (SHA-256) 458cb10d16f5… · 4 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 9 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Code cannot show this item: the evidence is a kept record or process.

Who it applies to

  • Duty falls on: developer
  • Sectors: healthcare
  • Health IT developers presenting a Health IT Module for certification to 45 CFR 170.315(b)(11), for each Predictive DSI they supply as part of the module, in the United States. HTI-1 is in force from 2024-02-08; (b)(11) is required for the Base EHR definition from 2025-01-01.
  • Not covered:
    • Health IT that is not presented for certification to 170.315(b)(11) under the ONC Health IT Certification Program (the criterion is a certification requirement, not a general duty)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Keep an AI risk register that identifies, analyses, evaluates, treats, and monitors each AI system's risks through its life cycle, including after deployment.

A written AI risk methodology (AI-specific risk sources such as data drift, bias, misuse, opacity, and third-party model changes; likelihood and impact criteria; risk acceptance thresholds) folded into the organization's existing risk process, plus a per-system register entry with owner, analysis, evaluation against tolerance, chosen treatment, residual risk, and the monitoring signal that would show the risk changing. The system owner keeps it, with the risk function, and updates it at design review, before release, and when monitoring or incidents show a change. Link register entries to the evals and production monitors that implement each treatment.

Where it goes: 12 repository artifacts, 13 tests and evals, 10 logs and telemetry.

What this provision adds:

  • Analyse each Predictive DSI for validity, reliability, robustness, fairness, intelligibility, safety, security and privacy; mitigate what the analysis finds; and govern how its data are acquired, managed and used.

Example (AI risk register (repo record)), before:

# risk-register.yaml
- system: loan-assistant
  risk: model might be biased

After:

# risk-register.yaml
- system: loan-assistant
  id: R-07
  source: training data under-represents applicants over 65
  analysis: {likelihood: medium, impact: high}
  evaluation: above tolerance
  treatment: reweighting + subgroup error-rate eval (evals/subgroups.py)
  residual: low
  owner: credit-ml-lead
  monitoring: dashboard approval-rate-by-age, alert at >5 point gap
  last_reviewed: 2026-09-15

Control: AI system managed without a documented AI-specific risk-management process. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id us-onc-hti1-dsi.predictive-dsi-intervention-risk-management · review status: primary source derived

Binding law — in force

Support, show and let users edit the source attributes of each Predictive DSI in a certified Health IT Module (45 CFR 170.315(b)(11)(iv)-(v))

45 CFR 170.315(b)(11)(iv)(B) · official text · In force: applies since 1 Jan 2025 · United States (federal) (US)

A Health IT Module certified to the decision support interventions criterion must support source attributes for Predictive Decision Support Interventions (technology based on algorithms or models that derive relationships from training data, 170.102): the developer and funding source, output type, intended use, population, users and decision role, cautioned out-of-scope uses and known risks, training-data inclusion and exclusion criteria, protected-characteristic inputs and demographic representativeness, the fairness approach, external validation, quantitative validity and fairness measures, ongoing monitoring and the update schedule (170.315(b)(11)(iv)(B)). A limited set of identified users must be able to access complete, up-to-date plain-language descriptions of them, see when information is not available, and record and change them (170.315(b)(11)(v)). Detect predictive decision support code with no source-attribute record.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 1 Jan 2025
Official source
45 CFR 170.315(b)(11)(iv)(B) · captured 4 Oct 2026 · anchor hash (SHA-256) 4c7b112d0aac… · 7 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Attributes kept in a database seeded outside the repository
  • Interventions supplied by a third party through a CDS Hooks service
  • Source attributes may be stored in a configuration or database table the module reads; confirm users can reach them for each intervention. Evidence-based (non-predictive) interventions have a shorter attribute list (iv)…

Who it applies to

  • Duty falls on: developer
  • Sectors: healthcare
  • Health IT developers presenting a Health IT Module for certification to 45 CFR 170.315(b)(11) under the ONC Health IT Certification Program, for each Predictive DSI they supply as part of the module, and for evidence-based and Predictive DSIs users configure; used by providers in the United States. HTI-1 is in force from 2024-02-08; (b)(11) is required for the Base EHR definition from 2025-01-01.
  • Not covered:
    • Health IT that is not presented for certification to 170.315(b)(11) under the ONC Health IT Certification Program (the criterion is a certification requirement, not a general duty)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Ship a deployer-facing model card or deployer guide with each ADMT release covering intended uses, training-data categories, limitations, and human-review instructions.

A deployer-facing documentation artifact versioned with the decision system, such as MODEL_CARD.md or docs/deployer-guide.md (or a Hugging Face model card README with Uses, Bias, Risks, and Limitations, and Training Data sections). It states what the system is for, the categories of data it was trained on, its known limitations and risks, and how a deployer should monitor it and carry out meaningful human review of its outputs. A CI or release step checks that the file exists, carries each of those sections, and names the version being shipped, so a release cannot go out with missing or stale documentation.

Where it goes: 12 repository artifacts, 14 user-facing text, 11 CI/CD pipeline.

What this provision adds:

  • Cover the 31 Predictive DSI source attributes of (b)(11)(iv)(B), show complete plain-language descriptions to a limited set of identified users, flag attributes not available, and let those users record and change them and add their own.

Example (MODEL_CARD.md), before:

# Tenant Screening Scorer
Install with `pip install screener` and call `score(applicant)`.

After:

# Tenant Screening Scorer
Version: 2.3.0  Developer: Example Analytics
## Intended uses
Ranks rental applications for a leasing agent to review. Not for automatic denial.
## Training data
Categories: rental payment history, income verification, eviction filings (personal data).
## Known limitations
Less accurate for applicants with thin credit files; not validated outside the US.
## Human review
Agents see the top factors per score and must review every score below 40 before acting.

Control: Covered ADMT without developer documentation to deployers. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id us-onc-hti1-dsi.predictive-dsi-source-attributes · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.