ONC Certification & Disclaimer

Last Updated: September 11, 2026

ONC Certification

Our platform is compliant with the ONC Certification Criteria for Health IT and has been certified by an ONC-ACB in accordance with the applicable certification criteria adopted by the Secretary of Health and Human Services. This certification does not represent an endorsement by the U.S. Department of Health and Human Services.

ONC Disclosure

Certified Product Information

Developer subQdocs Co.
Product subQdocs
Version 5
Unique certification number (CHPL ID) To be issued upon certification by Drummond
Date certified To be issued upon certification by Drummond

Certified Criteria

subQdocs has been certified to the following ONC Certification Criteria for Health IT (45 CFR § 170.315). Criterion codes are included for clarity; the capability names are the plain-language descriptions.

  • Electronic Health Information (EHI) export — § 170.315(b)(10). Authorized users can export a single patient’s electronic health information, or the organization’s full patient population, as a machine-readable ZIP archive. Format documentation: subQdocs EHI Export.
  • Encrypt authentication credentials — § 170.315(d)(12). User passwords and stored integration credentials are encrypted or hashed using industry-recognized algorithms.
  • Multi-factor authentication — § 170.315(d)(13). Clinicians and practice staff can be required to complete a second authentication factor after password sign-in. Supported use cases: subQdocs Multi-Factor Authentication.
  • Quality management system — § 170.315(g)(4). subQdocs maintains a documented quality management system for the certified Health IT Module.
  • Accessibility-centered design — § 170.315(g)(5). Accessibility was considered in the design of the certified Health IT Module.

Clinical Quality Measures (CQMs)

subQdocs is not certified to any Clinical Quality Measures (CQMs). CQM certification is not included in the current scope.

Additional software required

The following third-party software and services are relied upon to demonstrate certified capabilities. Customers do not separately license these components; they are operated by subQdocs as part of the product.

Software / service Developer Purpose
Twilio Programmable Messaging Twilio, Inc. Delivers SMS one-time passcodes for multi-factor authentication (§ 170.315(d)(13)).
Amazon S3 Amazon Web Services, Inc. Stores generated EHI export archives for authorized download (§ 170.315(b)(10)).
archiver Open-source library (Node.js) Streams the ZIP archive used for EHI export (§ 170.315(b)(10)).

No additional software must be purchased by the customer to enable the certified capabilities listed above.

Costs of Certified Capabilities

There are no additional costs or fees to purchase, license, implement, maintain, upgrade, use, or otherwise enable and support any of the certified capabilities listed above, beyond subQdocs’ standard subscription.

Limitations

Known limitations that can affect how a user implements or uses certified capabilities:

  • Multi-factor authentication. The second factor is an SMS one-time passcode or a single-use backup code. Authenticator-app (TOTP) MFA is not currently offered. MFA applies to users of the Health IT Module (clinicians and practice staff); it is not a patient-portal login factor. Details: subQdocs Multi-Factor Authentication.
  • EHI export. Visit audio recordings are not included in the export (the transcript is). A full unsplit multi-patient fax PDF is not exported, because it can contain other patients’ information; the patient’s own split pages are included. Files stored only as an external URL are not fetched; the export records the pointer instead. Details: subQdocs EHI Export.

If additional limitations are identified, this page will be updated and Drummond will be notified of the change.

Related public documentation

×