meilynx

Framework · ONC HTI-1

Transparency evidence for the predictive tools you deploy.

ONC HTI-1's decision support interventions criterion, 45 CFR 170.315(b)(11), binds certified health IT developers: source attributes for every intervention and risk-management practices for predictive ones, in the certification program since January 2025. A deploying organization still has to know which predictive tools it runs and keep their attributes on file. Meilynx evidences that deployer side. The HTI-5 proposal that would narrow the criterion is tracked as a watch item, never cited as an obligation.

What the criterion expects

Interaction, configuration, source attributes, risk management.

Six sub-paragraphs bind the developer. A deployer mirrors four of them in its own evidence.

  • Interaction and configuration: authorized users can interact with, configure, and give feedback on decision support interventions (170.315(b)(11)(i)–(ii)).
  • Source attributes for evidence-based and predictive interventions: intended use and populations, cautioned uses, development data, fairness process, external validation, performance, and update schedule (170.315(b)(11)(iv)–(v)).
  • Intervention risk management for predictive interventions: analysis, mitigation, governance, with a public summary (170.315(b)(11)(vi)).
  • HTI-5 would remove the source-attribute requirements. Its comment period closed on 27 February 2026 and nothing changes until a final rule is published.
How Meilynx maps

Runtime expectations, to runtime evidence.

A specific Meilynx control for each expectation the proxy can substantiate, and the artifact it produces. Everything else is attested in the package, and the package says which is which.

45 CFR 170.315(b)(11) → Meilynx controls (deployer, AI-traffic slice)

Know which predictive interventions are in use

HTI-1 · 170.315(b)(11)(iii)

Maps to · The inventory of AI decision support tools is derived from live traffic and enforced by runtime model allow-listing. Which observed tools are predictive interventions under the criterion is your determination.

Examination artifact · Predictive intervention inventory, generated from traffic

Control configuration changes to interventions

HTI-1 · 170.315(b)(11)(ii)

Maps to · Prompt-drift and tool-grant-drift detection flag unapproved changes to proxy-routed interventions against approved baselines.

Examination artifact · Drift findings against approved baselines

Keep the interaction record

HTI-1 · 170.315(b)(11)(i)

Maps to · Each interaction with a proxy-routed intervention is sealed into a hash-chained record: which interventions clinicians used and what they returned.

Examination artifact · Hash-chained interaction record

Keep source attributes on file and reachable

HTI-1 · 170.315(b)(11)(iv) · (v)

Maps to · The developer supplies the attributes; you keep them on file per tool. The package carries them as a structured attestation with a completeness flag per intervention.

Examination artifact · Source-attribute attestations per predictive tool

Evidence risk management and feedback

HTI-1 · 170.315(b)(11)(vi) · (ii)

Maps to · Risk analysis, mitigations, a named governance owner, and the feedback export cadence are your practices, attested in the package.

Examination artifact · Intervention risk-management and feedback attestations

The evidence

What a deployer can show.

A readiness-shaped transparency package: deployer posture stated up front, the inventory and change evidence proxy-verified, attributes and risk management attested.

In the package

  • Predictive intervention inventory, with the deployer-side determination per tool.
  • Source-attribute attestations with a completeness flag per intervention.
  • Configuration change evidence and the interaction record.
  • Intervention risk management and feedback monitoring attestations.
  • Obligation timeline: developer dates, Insights reporting from 2026, HTI-5 as a proposed watch item, the §1557 pointer.
FAQ

ONC HTI-1 and the proxy.

We are not a certified developer. Why does HTI-1 apply?

The certification criterion binds developers, not deployers, and the package says so. What a deployer owes its patients and its regulators is knowing which predictive tools it runs and having their attributes on hand. The preset evidences that, and nothing on the page asserts certification.

What does HTI-5 change?

Nothing yet. HTI-5 is a proposed rule whose comment period closed on 27 February 2026. It would narrow the decision support criterion and remove the source-attribute requirements. The package lists it as a watch item and cites it nowhere as an obligation.

Where do source attributes come from?

From the developer, through the certified health IT. The preset does not generate them; it records that they are on file, complete or not, per tool.

Examination package

See exactly what an examiner receives

Download a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.