Written and maintained by CASRAI Editorial Board
Last updated
The Medicare Promoting Interoperability (PI) Program is a scored, pass/fail attestation, not a checklist of nice-to-haves — a hospital that does not clear the point threshold for its EHR reporting period is not a “meaningful EHR user,” and that status change carries a real Medicare payment consequence. For a patient-safety officer, quality director, or risk manager who owns part of this attestation but isn’t the one configuring the EHR, the practical question is narrower than “what is Promoting Interoperability”: which objectives and measures currently apply, what counts as compliant certified technology, and which specific actions — the security risk analysis chief among them — are the ones that actually determine whether the hospital avoids the penalty. This guide answers that, current as of the 2026 reporting year, with citations to the actual regulation rather than a vendor’s summary of it.
Written for hospital patient-safety officers, quality directors, risk managers, and infection preventionists who co-own PI compliance alongside health information management and IT — not for the EHR analysts building the measures themselves.
What the Promoting Interoperability Program Actually Scores
Promoting Interoperability (the successor name to the “meaningful use” EHR Incentive Program) is codified for eligible hospitals and critical access hospitals (CAHs) at 42 CFR 495.24. The paragraph structure matters and is a common source of confusion in secondary guidance: paragraph (c) sets out the Stage 3 objective list; paragraph (e) governed hospitals attesting to CMS for 2019 through 2022; paragraph (f) is the one that governs a hospital attesting to CMS for 2023 and all subsequent years — which is every hospital reading this today. Citing (c) or (e) as the current rule, which a surprising amount of secondary coverage still does, is citing an outdated version.
Paragraph (f) does something unusual: it does not itself enumerate the objectives or measures. It requires only that a hospital “meet all objectives and associated measures selected by CMS under section 1886(n)(3) of the [Social Security] Act for an EHR reporting period.” The actual measure set, point values, and any exclusions for the current year are published in that year’s IPPS/LTCH PPS final rule and CMS’s annual PI specification sheets — not in the CFR text itself. That’s why a hospital’s compliance officer needs to re-check the current-year specification sheet every reporting period rather than treating any single year’s summary as evergreen.
The Objective Categories
The base structure CMS’s current specification sheets are still organized around traces back to the codified Stage 3 objective list at 495.24(c)/(e):
- Protect Patient Health Information — the security risk analysis measure, covered in detail below.
- Electronic Prescribing — the share of permissible prescriptions generated and transmitted electronically, plus (in recent years’ specification sheets) a query-of-a-prescription-drug-monitoring-program measure in a subset of states.
- Health Information Exchange — sending, receiving, and reconciling patient records with other providers/settings across a transition of care.
- Provider to Patient Exchange — what the original Stage 3 list split into two objectives (Patient Electronic Access to Health Information, and Coordination of Care Through Patient Engagement) is grouped under this single heading in current CMS materials: patients (or their representatives) can view, download, or transmit their health information, and at least one patient uses a certified API-based method to access it during the reporting period.
- Public Health and Clinical Data Exchange — active engagement with public health agencies and clinical data registries. Six measures are currently required (Immunization Registry Reporting, Syndromic Surveillance Reporting, Electronic Case Reporting, Electronic Laboratory Reporting, Antimicrobial Use Surveillance, and Antimicrobial Resistance Surveillance), plus optional bonus measures — see the dedicated breakdown below.
Every required measure in every objective must be attested (a numerator/denominator ratio, a yes/no attestation, or an approved exclusion) for the hospital to be scored at all — a missing required measure, not just a low score on it, is treated differently from a low-scoring optional one and can zero out the objective.
Certified EHR Technology: the Edition That Actually Counts
495.4 defines certified EHR technology (CEHRT) for 2019 and subsequent years as EHR technology certified under the ONC Health IT Certification Program that meets the 2015 Edition Base EHR definition, or a subsequent Base EHR definition — there is no separate “2019 Edition” or “2021 Edition” the regulation names; ONC has instead updated the 2015 Edition’s own certification criteria (at 45 CFR 170.315) in place, most substantially through the 21st Century Cures Act (“Cures Update”) rulemaking and ONC’s subsequent HTI-series rules. In practice, this means the compliance question for a hospital’s HIM/IT team isn’t “which numbered edition do we have” — it’s whether the specific 170.315 criteria each PI measure relies on are the ones the hospital’s certified technology currently holds a valid certification for, since ONC periodically retires and replaces individual criteria rather than the whole edition at once. For the clinical quality measure criteria specifically, certification to 170.315(c)(2) and (c)(3)(i)–(ii) is what supports a conformant submission — certification to (c)(1) alone is not sufficient.
The EHR Reporting Period
For eligible hospitals and CAHs, 495.4 currently defines the EHR reporting period as any continuous 180-day period within the calendar year — the minimum shifted up from 90 days starting with CY 2024 and has carried forward since. A hospital does not need to report on the full calendar year, but it does need 180 continuous days of data within it, and the period it selects has to be the same period across every objective and measure in that year’s attestation — a hospital cannot mix a 180-day window for one objective with a different window for another.
The Security Risk Analysis Measure — the One That Actually Determines the Penalty Most Often
Under the Protect Patient Health Information objective, the measure’s operative text (495.24(c), carried forward in substance through subsequent years’ specification sheets since it’s built from standing HIPAA Security Rule citations rather than PI-specific language) reads:
“Conduct or review a security risk analysis in accordance with the requirements under 45 CFR 164.308(a)(1), including addressing the security (including encryption) of data created or maintained by CEHRT in accordance with requirements under 45 CFR 164.312(a)(2)(iv) and 45 CFR 164.306(d)(3), implement security updates as necessary, and correct identified security deficiencies as part of the provider’s risk management process.”
Three details make this measure the one compliance teams most often get wrong:
- It is required, not optional, and it is scored pass/fail — but failing it doesn’t just cost points, it can fail the whole attestation. Because it sits under a required objective, a hospital that cannot truthfully attest “yes” to having conducted or reviewed the analysis during the EHR reporting period is not a meaningful EHR user for that period, regardless of how it scored on every other measure.
- “Conduct or review” is a real distinction. A hospital does not need a brand-new risk analysis every reporting period if a prior one is still current — but it does need to actively review it against what changed: new systems, new interfaces, new locations data is created or stored, newly identified vulnerabilities — and document that review, not just point to an old PDF.
- SAFER Guides self-assessment has been part of this measure since CY 2022. CMS added a requirement (495.24(e)(7), governing hospitals attesting to CMS 2019 through 2022) that hospitals conduct an annual self-assessment using all nine ONC SAFER Guides at some point during the reporting period. Because paragraph (f) doesn’t itself re-enumerate the measure for 2023 and later years, this specific sub-requirement is not something you can point to in the current CFR text — but CMS’s annual PI specification sheets have kept the SAFER Guides self-assessment as a required sub-element of the Security Risk Analysis measure in the years since. Treat this as the one line item worth confirming against the current-year specification sheet directly rather than trusting any single year’s summary (this guide’s) to still be accurate next reporting period.
Public Health and Clinical Data Exchange: the CY 2026 Measure Set
This objective is where most hospitals’ Promoting Interoperability work overlaps directly with the infection-prevention and public-health-reporting functions patient-safety and quality teams already own. For the CY 2026 EHR reporting period, CMS finalized eight measures under this objective: six required (Immunization Registry Reporting, Syndromic Surveillance Reporting, Electronic Case Reporting, Electronic Laboratory Reporting, Antimicrobial Use Surveillance, and Antimicrobial Resistance Surveillance) and two optional bonus measures (Public Health Registry Reporting and Clinical Data Registry Reporting), plus a third optional bonus measure new for CY 2026 — Public Health Reporting Using TEFCA — available to a hospital that is a signed TEFCA Framework Agreement participant, is not suspended, is submitting data to a public health agency via TEFCA consistent with one or more of its objective measures, is at “Active Engagement Option 2: Validated Data Production” for at least one of those measures, and is using CEHRT functions for the exchange. Bonus points across all optional measures cap at 5 total, regardless of how many a hospital claims.
For the mechanics of any one of these six required measures — what registration and “active engagement” status actually means, and how a specific feed (an emergency-department syndromic surveillance interface, for example) gets onboarded to a public health agency — see our dedicated guide to syndromic surveillance reporting for hospitals, which covers the active-engagement option structure and NSSP onboarding sequence in depth rather than restating it here.
Clearing the Score: Point Thresholds and What Happens Below Them
495.24(f)(1)(i) sets the scoring bar a hospital must clear across all its objectives and measures combined to be a meaningful EHR user for an EHR reporting period: at least 60 points in 2023 and 2024, 70 points in 2025, and 80 points in 2026 and subsequent years — the bar has been rising each year. Two mechanics worth knowing:
- Exclusions redistribute points, they don’t remove them from the total. If a hospital qualifies for an exclusion on a measure, the points that measure would have carried are redistributed to another measure as CMS specifies — the maximum achievable score stays 100 points, an exclusion just changes where the points come from.
- CMS can suppress a measure entirely, beginning with the CY 2026 reporting period. Under 495.24(f)(3) — added by a November 2025 final rule — CMS has discretion to suppress a measure it finds affected by factors like out-of-date technical standards or a required partner’s operational capacity, allocating a hospital either maximum points if it still reported the measure, or excluding the measure from the meaningful-EHR-user determination if it did not.
A hospital that does not reach the applicable point threshold is not a meaningful EHR user for that period. That status feeds directly into the payment mechanism below — it is not merely a quality-reporting shortfall, it is the trigger for the payment adjustment.
How Falling Short Becomes a Payment Penalty
Section 1886(b)(3)(B)(ix) of the Social Security Act is the statutory basis for the payment consequence: a subsection (d) hospital that is not a meaningful EHR user for the applicable reporting period has three-quarters of its otherwise-applicable annual payment update reduced for the corresponding fiscal year — the hospital still gets an update, but only one-quarter of what it would have received had it met the requirement. This is a downward adjustment to the annual market-basket update, not a flat penalty amount, so its dollar value scales with the hospital’s own payment base and that year’s applicable update percentage; there’s no single dollar figure that applies uniformly across hospitals. The mechanic runs on the same calendar-year-reporting-period-to-fiscal-year-payment-determination structure as Hospital IQR and the other CMS hospital pay-for-performance programs (see our guides to the Hospital VBP Total Performance Score and the HAC Reduction Program for how those two adjust payment on a different basis).
What This Program Is Not
Two adjacent CMS requirements get folded into “Promoting Interoperability” in casual conversation but are legally and operationally distinct:
- eCQM reporting. Electronic clinical quality measures are required by the Medicare PI Program, but they are not one of the objectives or measures scored under 495.24(f) — the eCQM duty sits in the separate definition of “meaningful EHR user” at 495.4(1)(iv). A hospital can score above threshold on every PI objective and still fail meaningful-EHR-user status on eCQM submission alone. See our eCQM reporting guide for how that requirement actually works and why it’s frequently mis-cited as a PI objective.
- Hospital IQR. IQR is a separate program under a separate statutory provision (section 1886(b)(3)(B)(viii)) with its own penalty mechanism, even though CMS has deliberately aligned the two programs’ eCQM measure counts and reporting calendars in recent rulemaking.
A Practical Compliance Sequence
For a patient-safety or quality team coordinating its piece of the attestation alongside HIM and IT:
- Confirm the current-year CMS specification sheet for every objective before the reporting period starts — don’t rely on last year’s measure set or point values, both change by annual rulemaking.
- Confirm or refresh the security risk analysis, with documented review of what’s changed since the last one, and confirm the SAFER Guides self-assessment is scheduled and documented within the reporting period.
- Confirm the certified technology’s current 170.315 certifications actually cover the specific criteria each measure the hospital plans to report on relies on — a certification that lapsed or was retired on one criterion doesn’t invalidate the whole platform, but it does invalidate that one measure’s submission.
- Select and lock in the single continuous 180-day reporting period across every objective before data collection starts, so no measure ends up reported against a different window than the rest.
- Track progress against the current year’s point threshold continuously, not at submission time — a shortfall discovered after the reporting period closes can’t be fixed by adding data.
Frequently Asked Questions
Is Promoting Interoperability the same program as “meaningful use”?
Yes in lineage — Promoting Interoperability is the renamed, restructured successor to the Medicare and Medicaid EHR Incentive Programs (widely known as “meaningful use”). CMS renamed the hospital program in 2018 and has revised its objectives and scoring structure multiple times since; the current codified structure sits at 42 CFR 495.24(f) for hospitals attesting to CMS in 2023 and later years.
Does the eCQM measure count toward the Promoting Interoperability score?
No. eCQM submission is a separate requirement under the definition of “meaningful EHR user” at 42 CFR 495.4, not one of the objectives or measures scored under 495.24(f). A hospital must satisfy both independently.
What edition of certified EHR technology is currently required?
The 2015 Edition Base EHR definition, or a subsequent Base EHR definition, under 42 CFR 495.4 — ONC has updated the underlying 45 CFR 170.315 certification criteria in place (notably through the Cures Act “Cures Update” and later HTI rulemaking) rather than issuing a new numbered edition, so the practical question is whether a hospital’s certification covers the specific criteria each measure it reports relies on.
Is the SAFER Guides self-assessment still required?
CMS added it as a required sub-element of the Security Risk Analysis measure starting with the CY 2022 reporting period, and it has continued in the years since as part of CMS’s annual specification sheet for that measure, even though the current governing CFR paragraph (495.24(f)) doesn’t itself re-enumerate it. Confirm against the current-year specification sheet before attesting.
What actually happens if a hospital doesn’t hit the point threshold?
It is not a meaningful EHR user for that reporting period, which under section 1886(b)(3)(B)(ix) of the Social Security Act triggers a reduction of three-quarters of the hospital’s otherwise-applicable annual payment update for the corresponding fiscal year — the hospital keeps roughly a quarter of the update it would otherwise have received.








