WHAT WE FOUND
ONC’s oversight of the ATCBs did not fully ensure that test procedures and standards could adequately secure and protect electronic patient information contained in EHRs. Specifically, ONC did not ensure that the ATCBs:
- developed procedures to periodically evaluate whether certified EHRs continued to meet Federal standards and
- developed a training program to ensure that their personnel were competent to test and certify EHRs and to secure proprietary or sensitive EHR information.
The ATCBs’ standards and procedures for testing and certifying EHRs met all NIST test procedure requirements that ONC approved. However, those NIST test procedures were not sufficient to ensure that EHRs would adequately secure and protect patient health information; in particular, the procedures allowed ATCBs to certify EHRs that demonstrated the use of a single-character password during testing. In addition, the NIST test procedures did not address common security issues, such as, but not limited to, password complexity and/or logging emergency access or user privilege changes.
WHAT WE RECOMMEND
To ensure that each patient’s health information in EHRs is secure and protected, we recommend that ONC require the ATCBs to:
- develop procedures to periodically evaluate whether certified EHRs continue to meet Federal standards and
- develop a training program to ensure that their personnel are competent to test and certify EHRs and to secure proprietary or sensitive EHR information.
We also recommend that ONC work with NIST to strengthen EHR test procedure requirements so that ATCBs can ensure during testing that EHR vendors incorporate a baseline set of security and privacy features into the development of EHRs to address common security issues.
Press Releases

Timeless Medical Systems® appoints Mike Antonelli as VP of Technology to drive next-generation platform innovation

Luma acquires Tonic to support 1,000+ health systems and 100M patients

HealthTree adds Flatiron Health and CareSpace EHR connections

DSS Wins CTM Plus Contract from U.S. Department of Veterans Affairs
Research Papers
Events Calendar
Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
12:00 AM - Heart Care and Diseases 2021
12:00 AM - Gastroenterology and Digestive Disorders
12:00 AM - Dermatology, Cosmetology and Plastic Surgery
6
7
12:00 AM - Euro Metabolomics & Systems Biology
9
10
11
12
13
14
16
+
12:00 AM - Food Science and Food Safety
12:00 AM - Traditional and Alternative Medicine
12:00 AM - Carbon and Advanced Energy Materials
18
19
20
21
22
+
12:00 AM - Herbal Medicine and Acupuncture 2021
12:00 AM - Hospital Management and Health Care
12:00 AM - Hematology and Infectious Diseases
23
24
+
12:00 AM - Aquaculture & Marine Biology
12:00 AM - Artificial Intelligence & Robotics 2021
12:00 AM - Tissue Engineering & Regenerative Medicine
12:00 AM - Nursing Research and Evidence Based Practice
26
+
12:00 AM - Earth & Environmental Science 2021
12:00 AM - Earth & Environmental Science 2021
12:00 AM - Nanomaterials and Nanotechnology
27
28
29
+
12:00 AM - Smart Materials and Nanotechnology
12:00 AM - World Nanotechnology Congress 2021
12:00 AM - Nanomedicine and Nanomaterials 2021
12:00 AM - Hepatology 2021
31
1
2
3
4
Events
Aug 08 : OIG Finds Privacy and Security Risks with ONC EHR Certification Process
August 8, 2014
















