EHR software development: certification, interoperability and the case against building your own

Building clinical record software is one of the few software projects where the hardest constraints arrive before the first requirement is written. Certification criteria, interoperability standards and the HIPAA Security Rule all have opinions about your architecture, and each of them is a great deal cheaper to design for than to retrofit. Teams that discover this in year two rarely recover the schedule.

EHR system development: certification is a framework, and it shapes the build

Health IT standards, implementation specifications and certification criteria live in 45 CFR part 170, which also establishes the ONC Health IT Certification Program and the conditions and maintenance requirements that apply to developers seeking certification. Whether you need certified health IT depends on what your customers must attest to, so answer that question first. It determines which criteria your product must meet, and those criteria are requirements you inherit rather than choose.

Interoperability is the part of EHR development people under budget

A clinical system that cannot exchange data is a liability, and the exchange work is consistently the most underestimated line in these projects. Standards based interfaces, terminology mapping between local codes and standard vocabularies, patient matching across systems that disagree about identity, and the operational job of keeping all of it working as partners change versions are each substantial. Ask a bidder what its patient matching strategy is. It is the question that most reliably separates clinical teams from general ones.

The Security Rule is architecture, not a checklist

The HIPAA Security Rule's technical safeguards at 45 CFR 164.312 require access control, audit controls, integrity controls, authentication of the person or entity seeking access, and transmission security. Audit controls in particular are architectural: recording who looked at which record, when, in a way that cannot be quietly altered, is difficult to add to a system that was not designed for it. Require the audit model in the design documents rather than in a security review before launch.

Remote patient monitoring software development, portals and the case against building a record system

Patient portal development and remote patient monitoring software development are usually sensible custom projects, because they are experiences layered on a record system you already have. Building the record system itself rarely is. A custom hospital software development company can genuinely help you with workflow, integration and the surfaces your clinicians use, while replacing a certified core with bespoke code takes on certification, interoperability and safety obligations permanently. Scope the layer, not the foundation.

Questions people ask about ehr software development

Should we build our own EHR?

Almost never. The certification criteria in 45 CFR part 170, the interoperability obligations and the Security Rule apply to you permanently once you own the core. Building portals, integrations, analytics and workflow on top of a certified system gets you the differentiation without the permanent regulatory ownership.

What does certification require of an EMR software development company?

It depends which criteria apply to your customers' attestations. 45 CFR part 170 sets out the standards, implementation specifications and certification criteria, and establishes the ONC certification program along with conditions and maintenance requirements for developers. Decide which criteria are in scope before you take quotes.

What do EHR and EMR software developers most often underestimate?

Interoperability and patient matching. Terminology mapping and identity resolution across systems that disagree are ongoing operational work, not a one time integration, and they are rarely priced that way in a fixed bid.

Does patient portal development need the same controls as the record system?

It handles protected health information, so the technical safeguards at 45 CFR 164.312 apply, including audit controls and transmission security. It does not necessarily need certification, which is why portals are a much more reasonable custom project than a record system.

Sources

Related answers

Get your agency shortlistDescribe your project