Updated SAFER Guide Requirement for 2026 MIPS
The Centers for Medicare and Medicaid Services (CMS) finalized many changes to the MIPS Promoting Interoperability (PI) category for the 2026 performance year. One of these is required use of the updated 2025 High Priority Practices SAFER Guide, rather than the 2016 version that was previously required.
In this blog, we cover the SAFER Guide requirement for the MIPS PI category, how to determine your best course of action, and an overview of the updated 2025 High Priority SAFER Guide.
Why Is the SAFER Guide Attestation Required?
Since 2018, cyberattacks on the U.S. healthcare system have more than doubled. Over the last several years, hacking incidents targeted at outpatient facilities and specialty clinics increased dramatically (by 41% in 2021 compared to 2020). The FBI reported 249 ransomware attacks against healthcare and public health organizations in 2023. In short, cybercriminals are focused on the healthcare sector and have been shifting their focus away from major hospitals and toward outpatient offices.
Cyberattacks cost the U.S. healthcare system over $20 billion a year and have compromised the data of over 45 million people. Unfortunately, this growing trend of cyberattacks on healthcare does not seem to be ending anytime soon.
Over the past few years, these attacks have also grown more sophisticated, with more than a 16% increase in the average cost to recover each patient record in 2020 over 2019. The average healthcare ransomware payment is $131,304. Of those who pay the ransom, 69% do not recover their data.
The possibility of loss of data, extended downtime due to lack of access, and violation of privacy for patients make the resiliency of EHR systems vitally important to healthcare providers. This has been exemplified by the recent Change Healthcare cyberattack. The SAFER guide attestation helps organizations to actively prepare for cybersecurity breaches and attacks.
Who Is Required to Complete the SAFER Guide Attestation?
Anyone who reports MIPS PI or who participates in the Medicare Promoting Interoperability Program (PIP) for eligible hospitals and Critical Access Hospitals (CAHs) is required to complete this attestation. (Medicare PIP participants must attest to completing all eight SAFER Guides, not just the High Priority Practices Guide that is required for MIPS.)
Even if you receive a PI hardship, consider performing this annual review anyway to avoid some of the staggering costs associated with cyberattacks.
Beginning with the 2026 performance year: You must attest “yes” to completing the 2025 High Priority Practices SAFER Guide self-assessment.
What Is Required to Attest “Yes”?
You must complete the self-assessment portion of the 2025 High Priority Practices SAFER Guide. This does not require you or your organization to immediately implement all of the recommended practices mentioned in the guide. It does require that you complete the High Priority Practices SAFER Guide self-assessment checklist, that your organization’s practices have been evaluated, and that any potential practical and beneficial changes are known and documented.
Important Note: The SAFER Guide requirement is separate from the requirement to conduct an annual Security Risk Analysis (SRA) and implement security measures to address identified vulnerabilities. The SAFER Guide does not fulfill the HIPAA SRA requirement.
How Do I Complete the High Priority SAFER Guide?
To satisfy the High Priority Practices SAFER Guide requirement, you must complete a checklist indicating how aligned your organization is with high priority recommended practices using the following scale:
- 0% (Not Implemented)
- 1 – 30% (Making Progress)
- 31 – 60% (Halfway There)
- 61 – 90% (Substantial Progress)
- 91 – 100% (Fully Implemented)
Each recommended practice has an associated worksheet for notetaking and for identifying any actions you may need to take to make your practice more secure. These worksheets also include examples of what the implementation of the recommended practices might require.
While this might at first seem like a daunting task, as there are sixteen “recommended practices,” the guide is actually well laid out and fairly straightforward.
The documents are downloadable and shareable, meaning that your team can collaborate on these documents easily and on their own time.
The guide assesses many general areas of readiness. As a result, not every example in the SAFER Guide for recommended practices will be relevant to every practice or provider. You are only required to assess those recommended practices and dimensions relevant to you or your organization. The intent of this requirement is for MIPS eligible clinicians to regularly assess their progress and status on important facets of patient safety.
Domain 1: Safe Health IT
The first domain will likely require collaboration with your EHR vendor. One way to do this is by emailing these questions to your contact at your EHR vendor and asking for an update on their utilization of these recommended practices. Make sure to check the worksheets associated with the recommended practices for any additional detail you may need.
Note that the 2025 updated guide includes a new practice in this domain focused on safety in artificial intelligence (AI).
Domain 2: Using Health IT Safely
This domain requires you to evaluate how you use the health IT in your office. To complete the worksheets for this domain, you will have to communicate with all members of your practice who use the EHR and/or other health IT, or have those practice members fill out this portion based on their own personal use and experience.
Domain 3: Monitoring Safety
This domain consists of evaluating policies, practices and procedures. The person who completes the HIPAA SRA can complete this on their own. If someone else is responsible for completing this SAFER Guide, they will likely need to complete this section in collaboration with your practice’s HIPAA security officer.
If you are unsure about the implementation of a recommended practice, simply check the worksheet for that recommended practice and look for “Suggested Sources of Input” in the upper righthand corner. This outlines who in your organization might know more.
Next Steps
- Share this information with your colleagues.
- Subscribe to our blog to get alerts on this and other important issues. You can subscribe using the field in our website footer below.
- If you are an Anatomy IT client, contact your MIPS Expert if you have any questions.
- If you are not an Anatomy IT client, contact us to learn more about our MIPS Success Plan and to reap the rewards of our combined decades of experience.
Written By: Sarrah Hakim, MHSA
About the Author: Sarrah is the Director of Health Policy at Anatomy IT.