Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: 2025 Safer Guides for EHRs

Understanding the 2025 SAFER Guides for Electronic Health Records

The Assistant Secretary for Technology Policy (ASTP) with the Office of the National Coordinator (ONC) released the 2025 SAFER Guides aiming to improve health systems’ adherence to Electronic Health Record (EHR) best practices. The 2025 SAFER Guides have been updated and streamlined to focus on the highest risk, most commonly occurring issues that can be addressed through technology, or practice changes to build system resilience.

TL;DR – 2025 SAFER Guides for EHRs:

  • Released by ONC to improve EHR best practices and safety
  • Updated to focus on highest risk, most common issues
  • New: AI for clinical care, cybersecurity, FDA device data integration
  • Three guide categories: Foundational, Infrastructure, Clinical Process
  • Includes 21st Century CURES Act updates and software testing procedures
  • Self-assessment tools to optimize EHR safety and safe use

What’s New in the 2025 SAFER Guides

Additionally, revisions related to the 21st Century CURES Act include the use of artificial intelligence (AI) for clinical care, cybersecurity and integration of U.S. Food and Drug Administration (FDA) approved medical device data into EHRs, and software testing procedures.

The Three Categories of SAFER Guides

There are three Guides within the 2025 SAFER Guides for self-assessment:

Foundational Guides

High Priority Practices and Organizational Responsibilities

Infrastructure Guides

Contingency Planning and System Management

Clinical Process Guides

Patient Identification, Computerized Provider Order Entry with Decision Support, Test Results Reporting and Follow-Up, and Clinician Communication

The guides identify recommended practices to optimize the safety and safe use of EHRs.

2025 SAFER Guides

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.