ONC Certification & Disclaimer
Last Updated: September 11, 2026
ONC Certification
Our platform is compliant with the ONC Certification Criteria for Health IT and has been certified by an ONC-ACB in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services. This certification does not represent an endorsement by the U.S. Department of Health and Human Services.
ONC Disclosure
Certified Product Information
| Developer | subQdocs Co. |
|---|---|
| Product | subQdocs |
| Version | 5 |
| Unique certification number (CHPL ID) | To be issued upon certification by Drummond |
| Date certified | To be issued upon certification by Drummond |
Certified Criteria
subQdocs has been certified to the following ONC Certification Criteria for Health IT (45 CFR § 170.315). Criterion codes are included for clarity; the capability names are the plain-language descriptions.
- Electronic Health Information (EHI) export — § 170.315(b)(10). Authorized users can export a single patient’s electronic health information, or the organization’s full patient population, as a machine-readable ZIP archive. Format documentation: subQdocs EHI Export.
- Encrypt authentication credentials — § 170.315(d)(12). User passwords and stored integration credentials are encrypted or hashed using industry-recognized algorithms.
- Multi-factor authentication — § 170.315(d)(13). Clinicians and practice staff can be required to complete a second authentication factor after password sign-in. Supported use cases: subQdocs Multi-Factor Authentication.
- Quality management system — § 170.315(g)(4). subQdocs maintains a documented quality management system for the certified Health IT Module.
- Accessibility-centered design — § 170.315(g)(5). Accessibility was considered in the design of the certified Health IT Module.
Clinical Quality Measures (CQMs)
subQdocs is not certified to any Clinical Quality Measures (CQMs). CQM certification is not included in the current scope.
Additional software required
The following third-party software and services are relied upon to demonstrate certified capabilities. Customers do not separately license these components; they are operated by subQdocs as part of the product.
| Software / service | Developer | Purpose |
|---|---|---|
| Twilio Programmable Messaging | Twilio, Inc. | Delivers SMS one-time passcodes for multi-factor authentication (§ 170.315(d)(13)). |
| Amazon S3 | Amazon Web Services, Inc. | Stores generated EHI export archives for authorized download (§ 170.315(b)(10)). |
| archiver | Open-source library (Node.js) | Streams the ZIP archive used for EHI export (§ 170.315(b)(10)). |
No additional software must be purchased by the customer to enable the certified capabilities listed above.
Costs of Certified Capabilities
There are no additional costs or fees to purchase, license, implement, maintain, upgrade, use, or otherwise enable and support any of the certified capabilities listed above, beyond subQdocs’ standard subscription.
Limitations
Known limitations that can affect how a user implements or uses certified capabilities:
- Multi-factor authentication. The second factor is an SMS one-time passcode or a single-use backup code. Authenticator-app (TOTP) MFA is not currently offered. MFA applies to users of the Health IT Module (clinicians and practice staff); it is not a patient-portal login factor. Details: subQdocs Multi-Factor Authentication.
- EHI export. Visit audio recordings are not included in the export (the transcript is). A full unsplit multi-patient fax PDF is not exported, because it can contain other patients’ information; the patient’s own split pages are included. Files stored only as an external URL are not fetched; the export records the pointer instead. Details: subQdocs EHI Export.
If additional limitations are identified, this page will be updated and Drummond will be notified of the change.
Related public documentation
- EHI export format and data dictionary (§ 170.315(b)(10))
- Multi-factor authentication use cases (§ 170.315(d)(13))