HIPAA & Compliance

The AI Model Card in Your EHR: What HTI-5 Would Delete, and How to Read Yours First

Since January 2025, every certified EHR has had to publish a plain-language disclosure of what its built-in AI was trained on, how it was validated, and what it should never be used for — free, at a public link. ASTP/ONC has proposed deleting that requirement. Here is how to find yours before it goes, and why your standalone AI scribe was never covered by it in the first place.

By MedAI Directory · September 21, 2026

Somewhere on your EHR vendor's website there is a document that says, in plain language, what every AI model built into your chart was trained on, who validated it, how well it performed, what it should never be used for, and how often anyone checks whether it still works.

Your vendor is legally required to publish it. It has to be reachable by a public link, with no login, no sales call, and no NDA. It has been required since January 1, 2025.

Almost nobody in a small practice has ever opened one. And on December 29, 2025, the federal agency that created the requirement proposed deleting it.

Here is what that document is, how to find yours, what the proposed rule would remove, and — the part most coverage skips — why the AI tool you probably use most was never covered by any of it.

The rule: § 170.315(b)(11), the closest thing to an AI nutrition label

In January 2024, ONC (now ASTP/ONC, the Assistant Secretary for Technology Policy) finalized the HTI-1 rule. Buried in a regulation mostly about interoperability was the federal government's first real attempt to regulate clinical AI outside the FDA's device pathway.

It works through the certification program rather than through you. Certified EHRs must meet a criterion at 45 CFR § 170.315(b)(11), "Decision support interventions." The old clinical decision support criterion, § 170.315(a)(9), expired from the program on January 1, 2025, and (b)(11) took its slot in the Base EHR definition — which means if your system counts as certified EHR technology at all, it is certified to (b)(11).

The criterion splits decision support into two kinds:

  • Evidence-based DSIs — the ordinary rules-and-guidelines kind. Thirteen disclosure fields: citation, developer, funding source, release and revision dates, and whether the logic uses race, ethnicity, language, sexual orientation, gender identity, sex, date of birth, social determinants, or health status assessments.
  • Predictive DSIs — defined in § 170.102 as "technology that supports decision-making based on algorithms or models that derive relationships from training data and then produces an output that results in prediction, classification, recommendation, evaluation, or analysis." That definition is broad enough to cover essentially every machine-learning feature a vendor ships. These require 31 disclosure fields.

Those 31 fields are what people mean by "model card." Grouped, they cover:

  • Details and output — who made it, who funded it, what it outputs and in what form
  • Purpose — intended use, intended patient population, intended users, and the role it is meant to play in a decision
  • Cautioned out-of-scope use — the tasks and situations it should not be used for, and known risks
  • Development details — what the training data was, how representative it was, how relevant it is to your population
  • Fairness approach — how bias was managed during development
  • External validation — who tested it on what data, and how representative that data was
  • Quantitative performance — validity and fairness measures on internal and external data
  • Ongoing maintenance — how often validity and fairness are monitored, including against local data
  • Update schedule — how often it is revised and how performance problems get corrected

ASTP/ONC's stated purpose was to let a clinician judge whether a model is FAVES — fair, appropriate, valid, effective, and safe — before trusting its output.

There is a second half that gets even less attention. Under § 170.315(b)(11)(vi), a developer must apply intervention risk management to every predictive DSI it supplies: a risk analysis covering "validity, reliability, robustness, fairness, intelligibility, safety, security, and privacy," the mitigation practices it applies, and its governance over how data is acquired, managed, and used. Proprietary internals — code, hyperparameters, model tuning — are explicitly not required.

And then the provision that makes all of this usable by a two-provider clinic. § 170.523(f)(1)(xxi) requires that the risk-management summary be submitted

"via publicly accessible hyperlink that allows any person to access the summary information directly without any preconditions or additional steps."

No preconditions. No additional steps. Epic, for instance, publishes its predictive-DSI risk management summary at epic.com/predictive. Your vendor has one too, and its link is listed on the Certified Health IT Product List at chpl.healthit.gov — search your product, open the listing, and look under the (b)(11) criterion. Developers have had to keep the source attributes and risk-management practices current on an ongoing basis since January 1, 2025, under § 170.402(b)(4).

That is a real, free, vendor-neutral disclosure sitting one click away from most practices that have never used it.

The catch: your scribe was probably never covered

Here is the part that gets lost in the "federal AI transparency rules" framing, and it matters more to a solo or small practice than anything else in this post.

The criterion only reaches supplied DSIs — ones the certified health IT developer "authored, developed, or explicitly offered" to its customers as part of the certified product. ASTP/ONC's own test method is blunt about the boundary: a developer is not responsible for source attributes on a predictive DSI it does not supply, "even if the customer leverages data from the Certified Health IT developer's Health IT Module and even if the output from another party's Predictive DSI is delivered to or through a Health IT Module."

Read that against how small practices actually buy AI. If you licensed Freed, Heidi, Abridge, Suki, or Nabla directly and it writes into your chart through an integration, that is a third-party DSI at most. No model card was ever required for it. The transparency regime everyone is now arguing about never applied to the single most widely adopted category of clinical AI in ambulatory care.

What is covered is the AI your EHR vendor ships: sepsis and deterioration scores, readmission and no-show risk models, coding and HCC suggestions generated inside the certified module, imaging triage delivered as part of the product, and clinical decision support generally.

The line is about who supplies it, not what it does. An ambient scribe built into a certified EHR can land inside the criterion: ModMed announced on January 2, 2025 that its EMA platform had certified to the predictive DSI criterion, with its ambient ModMed Scribe central to the certification. The same functional tool, bought standalone, carries no such obligation. We walk through the broader trade-offs of that choice in Epic's AI charting vs. standalone scribes.

If you use a standalone AI medical scribe, the federal transparency rule being repealed is not your rule. It never was. That is an argument for reading the questions below more carefully, not less.

HTI-5: what the proposal would remove

On December 29, 2025, ASTP/ONC published "Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity" — HTI-5, RIN 0955-AA09, Federal Register document 2025-23896. Comments closed at 5 p.m. Eastern on February 27, 2026.

The rule is a large cleanup. Of the 60 certification criteria in the program, ASTP/ONC proposed to remove 34 and revise 7, leaving roughly 19 — retiring CDA-based document exchange criteria, legacy Direct transport, and thirteen privacy and security criteria, while pushing the program toward FHIR APIs. It also proposes dropping real-world testing plans and narrowing Insights reporting from seven measures to one. The agency estimated the package would save developers up to 4,000 compliance hours each in the first year — about 1.4 million hours industry-wide.

For AI, one sentence in the preamble does the work. ASTP/ONC wrote that among the proposed revisions, one

"would reduce the scope of the 'decision support interventions' certification criterion to fully remove the artificial intelligence (AI) 'model card' requirements."

In practice that means the 31 predictive source attributes and the intervention-risk-management obligations for predictive DSIs both go. The agency's rationale, as reported by Healthcare Dive when the rule dropped, was that it had no publicly available evidence the transparency requirements had produced positive effects on patient care — no evidence, for instance, that they had led anyone to remove a deficient or untested algorithm, or to test a deployed algorithm against local data.

The DSI criterion itself is not deleted. The rule's own table lists (b)(11) as revised, effective on the effective date of a final rule.

Hospitals pushed back hard. The American Hospital Association, in a comment letter dated February 27, 2026 signed by Senior Vice President Ashley Thompson, asked ASTP/ONC to keep the criterion as it stands, calling it

"one of the few examples of transparency standards providing information on AI to help inform procurement"

and noting that it "provides information on how a predictive or generative AI application was designed, developed, tested, evaluated and should be used." The AHA argued the disclosures address the black-box problem that slows adoption, and are "critical to foster trust in AI tools and ensure patient safety."

Status as of September 21, 2026: there is no final rule. Comments closed seven months ago and nothing has published in the Federal Register. The requirement is still on the books today, and your vendor still owes you the disclosure.

Meanwhile, federal adoption is accelerating

The timing is worth noticing. While the transparency requirement sits in limbo, the largest integrated health system in the country is scaling ambient AI fast.

Nextgov/FCW reported on September 14, 2026 that the VA is expanding ambient scribes beyond pilots to all Patient Aligned Care Team primary care providers, behavioral health interdisciplinary program practitioners, physical medicine and rehabilitation practitioners, and medical and surgical specialists, with an enterprise contract planned. The VA first deployed the technology at 10 medical centers in October 2025. More than 986,000 VA primary care appointments have now used an ambient scribe, and veterans declined the technology less than 1% of the time. A three-month Kansas City pilot reported 95.8% veteran satisfaction. Abridge and Knowtex are the two vendors named.

Deployment at that scale, with the disclosure rule for embedded AI under active proposal to be withdrawn, is the shape of the current moment: adoption running well ahead of the paperwork.

What is filling the gap

Nothing federal replaces (b)(11) for EHR-embedded AI. Three other things are doing some of the work.

The Joint Commission's certification. On June 1, 2026, the Joint Commission launched Responsible Use of AI in Healthcare (RUAIH) certification, built on guidance it issued with the Coalition for Health AI (CHAI) in September 2025. It is organized around five areas: governance; effective data management; risk and bias reduction; monitoring, evaluating and validating safety, performance, effectiveness and responsible use; and transparency, education and training. Organizations do not need Joint Commission accreditation to apply.

Two caveats matter for this audience. It certifies organizations, not products — it explicitly does not evaluate individual AI tools. And it is aimed at hospitals, critical access hospitals, and health systems, not at a three-physician clinic.

CHAI's governance playbooks. More useful if you are small. On May 27, 2026, CHAI released open-source governance playbooks built with more than 150 leaders from 100-plus healthcare organizations, structured around eight elements: organizational AI policy, organizational structure, organizational resources, responsible AI lifecycle management, risk and impact assessments, responsible data management and use, third-party management, and education, training and feedback. They are free, they map to the Joint Commission certification, and they are explicitly written to scale down to resource-constrained clinics.

State law. This is the layer that actually binds a small practice, and it moved in the opposite direction from Washington this year. Rhode Island, Louisiana, Texas, Maine, Colorado and others now impose disclosure, consent, accuracy-review, and scope-of-practice duties that no federal deregulatory action touches. We covered the full 2026 map in State Healthcare AI Laws vs. Federal Preemption.

And the FDA line has not moved: an ambient scribe that documents is not a device, but a tool that renders a diagnostic or treatment recommendation a clinician cannot independently review may be. See FDA's 2026 clinical decision support guidance.

What to do about it

While the requirement still exists:

  • Pull your EHR's model cards this quarter. Search your product on CHPL, open the (b)(11) criterion, and follow the public risk-management link. It costs nothing and takes minutes. If a final rule lands, vendors have no obligation to keep it posted.
  • Read the "cautioned out-of-scope use" field first. It is the single most useful of the 31 fields and the one your vendor's sales deck will never contain.
  • Check the external validation and maintenance fields against your panel. A no-show model validated on an urban academic population may behave differently in a rural small clinic. The criterion requires the developer to say how representative the validation data was — use it.
  • Save a copy. A dated PDF of what your vendor disclosed in 2026 is worth having if a model's behavior is ever questioned.

For standalone tools, which were never covered:

  • Ask for the same nine categories in writing. Intended use, out-of-scope use, training data, validation, performance, fairness, monitoring cadence, update schedule, and who is accountable. A vendor that cannot answer is telling you something.
  • Ask what changes when the model changes. Silent model swaps are the norm in this category. Ask whether you are notified, and whether performance is re-measured.
  • Keep your own accuracy check. Federal transparency was never a substitute for reading the note. The research on scribe error rates is in Can You Trust AI Scribe Notes?.
  • Watch coding-adjacent AI most closely. Suggestion engines that nudge code selection carry audit exposure regardless of who supplied them — see AI scribes and coding intensity.

If you are building governance from scratch: start with the CHAI playbooks rather than the Joint Commission standards. Same architecture, no survey, no fee.

The throughline

The federal government built exactly one mechanism that forced AI vendors to hand clinicians a structured, plain-language account of what their models do — and attached it to the certification program rather than to the tools most ambulatory practices actually buy. Now it has proposed removing the mechanism, on the stated grounds that nobody was using it.

That reasoning is partly circular and partly correct. The disclosures went largely unread. But they went unread because almost no one in a small practice knew they existed, not because they had nothing in them.

Until a final rule publishes, they do exist, they are free, and they are one link away. After that, the questions in them are still the right questions — you will just have to ask your vendor yourself.

Browse AI tools by category, compare options for your specialty, or start with what HIPAA compliance actually means for AI tools and how to choose an AI scribe.


This article is for general information only and is not legal or medical advice. Federal rulemaking is ongoing and the status of HTI-5 may have changed since publication — verify the current text of 45 CFR part 170 and the Federal Register before relying on any rule described here, and consult qualified counsel. Always confirm a vendor's disclosures and compliance posture directly with the vendor.

Tags
hti-5astp-oncai-transparencymodel-cardsdecision-support-interventionsehr-certificationai-governancejoint-commissionchaicompliance2026
Keep reading

Related articles

Industry News

FDA's Generative AI Device Paper: What It Means for the AI Tools Your Practice Uses (Comments Due Oct. 19)

On August 18, 2026, FDA published its first detailed sketch of how it might regulate generative AI medical devices: a two-axis risk map, clinician-style competency testing, and more postmarket monitoring. It is not guidance and binds no one yet. Here is what it says, where scribes, CDS, patient chatbots and imaging tools land, what the first 'patient-facing LLM' clearance actually covered, and which of the 26 questions clinicians should answer before the October 19 deadline.

HIPAA & Compliance

Your AI Scribe Is Changing How You Bill. Your Payer’s Algorithm Already Noticed.

The 2026 research shows coding intensity rises after ambient AI adoption — and payers have started downcoding in response. What the Trilliant, BCBSA, and UCSF data actually says, why an AI scribe can move an E/M level at all, and the audit checklist every practice should be running.

HIPAA & Compliance

FDA Just Moved the Line Between a Clinical Tool and a Regulated Device

In January 2026, the FDA rewrote its clinical decision support guidance and pushed more AI software outside its oversight. Single recommendations are now allowed, documentation tools got clearer footing, and generative AI got almost no framework at all. Here is what changed — and why 'no FDA clearance needed' tells you nothing about whether a tool works.

HIPAA & Compliance

Can You Trust AI Scribe Notes? What the Research Actually Says About Accuracy and Hallucinations

AI scribes save time, but modern ambient scribes still report overall error rates around 1-3% — and in healthcare, even rare errors matter. We dug into the research on AI scribe accuracy, the real failure modes clinicians report, and a practical review workflow that catches errors before they reach the chart.