ONC Certification Support
ONC certification is something I execute, not just advise on.
I joined Drummond Group at the start of the ONC CEHRT program and have worked all three sides of certification: the Test Proctor who runs the test, the Technical Reviewer inside the Certification Body who approves it, and, more recently on the developer side, the regulatory analyst who has to get a product through it. I have tested more Health IT products than most people working in the certification bodies today.
Most developers heading toward certification don’t need a strategist. They need someone who has run the process from every seat to run it with them.
Certification execution services
Getting certified
- Certification readiness. I embed with your developers, product managers, and QA. Interpret ONC criteria against the implementation guides, write or proof test procedures and acceptance criteria, and support test-tool runs and debugging before a test is ever scheduled.
- Mock proctored testing. I run a full practice test the way a Drummond proctor runs the real one. Failures surface on your schedule, not in front of the ACB.
- Test event support. I monitor your live proctored test, anticipate the proctor’s findings, and keep the event on track.
- Self-test and attestation execution. For self-attested criteria, I run the test, verify results, capture the evidence, and complete the attestation documentation for ACB submission.
- Post-event documentation. I finalize the documentation that closes out certification and assemble an audit-ready artifact trail.
Staying certified
- CEHRT maintenance design and automation. I design and help implement your ongoing obligations: quarterly ONC-ACB attestations, Real World Testing plans and annual reporting, Conditions of Certification, and Information Blocking and API maintenance. Then I automate them so your own staff can run maintenance each cycle without relearning it.
Defending the certification
- Surveillance, complaint, and audit defense. I respond to ONC complaints, ACB surveillance, and OIG and CMS Corporate Integrity Agreement situations. I led test-lab surveillance at Drummond and worked the high-profile vendors operating under Corporate Integrity Agreements, so I know what triggers a review and how it resolves.
Building continuous certification
For developer teams that want to stop treating certification as an event and start treating it as a build-time signal.
- ONC test tools as continuous integration. Inferno, the Edge Testing Tool, Cypress, and the ONC-published FHIR reference implementations all expose command-line entry points and APIs. Integrated into a CI/CD pipeline, they surface certification conformance the same way unit tests surface functional regressions. A test fails on a pull request, not in front of an ACB proctor six months later.
- Attestation evidence collection, automated. Real World Testing data, quarterly ONC-ACB attestation inputs, and Conditions of Certification artifacts are all downstream of production telemetry. Build evidence pipelines that collect them continuously against a defined schema instead of scrambling to reconstruct them at attestation deadlines.
- HTI-4 / CMS-0057 ePA API monitoring. Payer-facing FHIR APIs are subject to CMS-0057 compliance dates and ongoing operational reporting. Continuous monitoring on the endpoints (uptime, response conformance, USCDI element coverage) sits inside the same observability stack your engineering team already operates.
This is the same “compliance as engineering discipline” pattern that HITRUST QA and SOC 2 continuous monitoring have adopted. ONC has been slower to shift, largely because the test tools were designed for point-in-time proctored testing rather than automation. Vendors that build the automation layer first have a durable roadmap advantage.
Regulatory advisory
Execution is the core of the work. The strategy layer underneath it, for when you need to see what is coming:
- HTI-5 deregulation. Map the proposed HTI-5 changes to your certified criteria and CHPL listing, assess customer and contractual impact before removing anything, and document the rationale and transition plan for ONC-ACB review.
- FHIR and the API future. Position § 170.315(g)(10) as a foundation rather than a checkbox, plan the SVAP path and the USCDI v3 to vNext transition, and prepare for HTI-5 API scope changes and follow-on rulemaking.
- Electronic prior authorization (CMS-0057 + HTI-4). CMS-0057-F and HTI-4 together move prior authorization to FHIR-based APIs. Map HTI-4 certification criteria to the product roadmap and coordinate against the CMS-0057 compliance dates: operational and reporting requirements by January 1, 2026; the Patient Access, Provider Access, Payer-to-Payer, and Prior Authorization APIs by January 1, 2027.
- Predictive DSI § 170.315(b)(11). Source attribute documentation, Intervention Risk Management and FAVES evaluation, cross-mapped to NIST AI RMF and ISO/IEC 42001 so AI governance work satisfies multiple obligations at once. The AI governance page covers this in depth.
What’s at stake
When this works. Certification stops being the slow lane on your roadmap. Test events pass on the first attempt because the failures were caught in a mock run. Attestations submit on time without sprint disruption. Maintenance runs on a system your own staff can sustain.
When this doesn’t get done. A test event fails in front of the ACB and the certification slips a quarter. CEHRT status lapses and hospital sales freeze. A missed quarterly attestation triggers a Conditions of Certification review. An artifact trail nobody assembled becomes a problem when a complaint or surveillance request arrives.
Background
I joined Drummond Group in 2010, at the start of the ONC CEHRT program, and spent 14 years inside the ONC-Authorized Test Lab and Certification Body. Drummond certifies the large majority of CEHRT product listings; many developers simply call the process “Drummond Certification.” I worked across every facet of it:
- Health IT Test Proctor (2010 to 2018). Ran functional certification tests on Health IT products across the 2011, 2014, and 2015 editions of Meaningful Use.
- Technical Review Manager, Certification Body (2019 to 2020). Reviewed quarterly attestations and post-certification submissions, evaluated whether product changes triggered re-test, and led surveillance testing for high-profile vendors operating under OIG and CMS Corporate Integrity Agreements.
- Senior Program Engineer (2022 to 2024). Led research and growth strategy for emerging certification programs, including the Pediatric Health IT Certification program and FHIR Client Applications.
More recently I have worked on the developer side, inside a Health IT vendor’s regulatory function. That keeps the work current: I know what FHIR API implementation and ONC compliance look like in production and on a product roadmap, not only in regulatory text.
I also helped launch Drummond’s HITRUST service line and worked there as a Senior Cybersecurity Assessor.
Other credentials and affiliations:
- Member of the Coalition for Health AI and the NIST AI Safety Consortium working groups
- Credited contributor to the CHAI Responsible AI Guide (Privacy and Cybersecurity Profile)
Related practice areas
ONC work rarely lives alone. If your certified product uses AI features under § 170.315(b)(11), the AI governance page covers ISO/IEC 42001 and NIST AI RMF readiness. If customers are asking for HITRUST attestations alongside CEHRT, the HITRUST advisory page covers e1, i1, and r2 readiness.
Get started
Most engagements begin with a short scoping call to find where you are in the certification lifecycle and which of the services above fits. From there we agree on scope: a single test event, a full readiness-through-certification engagement, or ongoing maintenance support.
Get in touch to discuss your certification timeline.