Posted on
Feb 9, 2025
Posted on
Aug 23, 2026
Learn how CMIOs can meet ONC HTI-2 Evidence-Based Transparency rules for AI scribes with element-level FHIR Provenance and human-verification audit trails.
TL;DR: The 2026 ONC HTI-2 Final Rule mandates Evidence-Based Transparency (EBT) for predictive and generative clinical AI. Most AI scribe vendors document what the model produced but cannot prove which specific elements a clinician verified or changed. Scribing.io closes this gap with a Human-Verification Audit Trail that binds each provider-edited token to element-level FHIR Provenance and AuditEvent records—hashing every edit and mapping it to the exact EHR DOM selector and audio timestamp. The result is a machine-readable HTI-2 EBT bundle that survives payer DRG audits and ONC surveillance. See it applied to a live sepsis coding scenario below.
What HTI-2 EBT Requires
Defending a Sepsis DRG
Element-Level FHIR Provenance
ICD-10 Documentation Standards
Implementation Workflow
What ONC HTI-2 Evidence-Based Transparency Actually Requires of AI Scribes
CLINICAL UPDATE 2026: Revised for new CMS CPT G2211 standards, SB 1120 compliance, and FHIR interoperability.
For Clinical Operations Directors, HTI-2 is not a documentation nicety—it is a data-integrity obligation. The rule extends the transparency principles introduced in HTI-1's DSI (Decision Support Intervention) requirements. It applies Evidence-Based Transparency (EBT) to predictive and generative AI touching the clinical record.
Where earlier frameworks help you procure an AI tool via "nutrition label" model cards, HTI-2 EBT governs what happens after deployment. Scribing.io is engineered to prove, on demand, that a human clinician verified the AI's clinical assertions.
The core EBT expectation for an ambient AI scribe breaks down into four provable claims. Each must survive both payer and federal scrutiny.
HTI-2 EBT Provability Requirements vs. Typical Vendor Capability | ||
EBT Requirement | What Must Be Proven | Typical Vendor State |
|---|---|---|
Source attribution | Which audio/context produced each clinical element | Session-level only |
Human verification | Which elements a provider accepted, edited, or removed | Not element-level |
Model identity | Model ID/version that generated each draft field | Aggregated logs |
Tamper evidence | Integrity of the edit record over time | Rarely hashed |
Directors evaluating vendors across service lines should map these requirements against every specialty in use. Our Clinical Specialties Directory details how EBT obligations shift between emergency, inpatient, and ambulatory workflows.
Scribing.io Clinical Logic: Defending a Sepsis DRG Under HTI-2 EBT
This is the scenario that separates a compliant audit trail from a marketing claim. Consider a real inpatient workflow that stresses every EBT requirement simultaneously.
During a sepsis admission, the AI draft marked "severe sepsis" and auto-filled a lactate of 2.1 mmol/L at 18:42. In review, the hospitalist corrected the MAP values and removed the severe sepsis label—an appropriate downgrade to unspecified sepsis.
Weeks later, a payer audit challenges the DRG, and ONC surveillance separately requests AI provenance under HTI-2 EBT. Two threats converge on the same encounter.
The stakes are a $6,800 DRG downgrade risk plus a federal data-integrity inquiry. Without element-level provenance, the organization cannot prove the "severe sepsis" label was a machine draft the clinician correctly rejected—it reads as an unexplained discrepancy.
What Scribing.io Exports for This Case
Element-Level Human-Verification Audit Trail for the Sepsis Encounter | |||||
Clinical Element | AI Draft | Clinician Action | DOM Selector | Audio Timestamp (Hashed) | Attestation |
|---|---|---|---|---|---|
Severe sepsis label | R65.20 asserted | Removed | #dx-problem-list[3] | 18:42:07 → SHA-256 | FHIR Provenance |
Lactate 2.1 mmol/L | Auto-filled | Accepted | #labs-lactate-val | 18:42:11 → SHA-256 | AuditEvent |
MAP values | Draft value | Corrected | #vitals-map | 18:43:02 → SHA-256 | FHIR Provenance |
Sepsis dx (final) | A41.9 candidate | Confirmed | #dx-primary | 18:43:20 → SHA-256 | AuditEvent |
The exported EBT bundle demonstrates, field by field, exactly what the clinician did:
Per-field edit history with hashed audio segments proving the source of each draft assertion.
Exact DOM-mapped fields the clinician changed—not a vague session summary.
Model ID/version attached to the "severe sepsis" draft, isolating it as a machine suggestion.
FHIR
ProvenanceandAuditEventrecords linking each change to clinician attestation.
Outcome: the system proves human verification, the removal of the severe sepsis label stands as documented clinical judgment. The DRG holds against the payer challenge, and the encounter clears HTI-2 EBT review.
The audit resolves in the provider's favor because the evidence is machine-readable and tamper-evident. Quantify what this defensibility is worth across your census with the AI Medical Scribe ROI Calculator.
The Information Gain Pillar: Binding Edits to Element-Level FHIR Provenance
Most transparency frameworks stop at the tool level: Is this model transparent about its training data and limitations? That is a necessary procurement question. It is not sufficient for HTI-2 EBT.
HTI-2 EBT demands transparency at the moment of clinical action, not just at procurement. Here is the gap competitors miss, and what Scribing.io does about it.
Scribing.io binds its Human-Verification Audit Trail to element-level FHIR Provenance and AuditEvent records. Each provider-edited token is hashed and mapped to three anchors:
The exact EHR DOM selector where the edit occurred.
The precise audio timestamp that sourced the underlying assertion.
The model ID/version that produced the original draft.
This yields a machine-readable HTI-2 EBT bundle—not a PDF summary, but structured FHIR resources a surveyor's system can parse and validate against federal data-integrity requirements.
Model-Card Transparency vs. Element-Level EBT Provenance | ||
Dimension | Model Card Transparency | Scribing.io Element-Level EBT |
|---|---|---|
Granularity | Tool-level disclosure | Per-token, per-field |
Timing | Pre-deployment | Live at point of edit |
Format | Human-readable document | Machine-readable FHIR bundle |
Human verification | Assumed / policy-based | Cryptographically logged |
Audit response | Manual reconstruction | On-demand export |
The distinction matters operationally: a model card tells an auditor the tool could be safe. The EBT bundle proves a specific clinician made it safe in a specific encounter.
Binding these records requires deep EHR field mapping across every vendor system in your environment. Our EHR Integration Library documents the DOM-selector coverage for each supported platform.
Technical Reference: ICD-10 Documentation Standards for Sepsis
The sepsis scenario above turns on the correct sequencing and support of two codes. Precise documentation of the AI-versus-clinician distinction directly affects which code survives audit.
ICD-10-CM Codes Relevant to the Sepsis EBT Scenario | |||
Code | Description | Documentation Requirement | Reference |
|---|---|---|---|
A41.9 | Sepsis, unspecified organism | Clinician-confirmed final diagnosis after severe label removal | |
R65.20 | Severe sepsis without septic shock | Requires organ dysfunction; correctly removed by hospitalist here |
The audit hinges on proving R65.20 was a machine draft, not a clinician assertion. The EBT bundle timestamps the removal at 18:42:07, binding it to provider attestation rather than an unexplained record edit.
Coding integrity under HTI-2 requires that every AI-suggested code carry its own provenance chain. This prevents both upcoding exposure and downgrade losses during utilization review.
Implementation Workflow for Clinical Operations Directors
Deploying an HTI-2 defensible workflow is a phased operational task, not a single toggle. The sequence below reflects how Scribing.io integrates into an existing inpatient documentation pipeline.
HTI-2 EBT Deployment Phases and Owner Responsibilities | |||
Phase | Action | Owner | EBT Output |
|---|---|---|---|
1. Field mapping | Map EHR DOM selectors to FHIR resources | Integration team | Selector registry |
2. Model registration | Log model ID/version per draft field | Vendor + IT | Model manifest |
3. Edit capture | Hash each provider edit at point of care | Automated | SHA-256 edit log |
4. Attestation binding | Link edits to clinician sign-off | Clinician | FHIR Provenance |
5. Audit export | Generate EBT bundle on demand | Compliance | Machine-readable FHIR |
Directors should confirm each phase against their compliance calendar before payer audit season. The registry from Phase 1 becomes the backbone of every downstream provenance record.
Review deployment tiers and audit-export capabilities against your census volume at Scribing.io Pricing & Plans. Match the retention window to your longest payer look-back period.
Ambient Clinical Intelligence only defends revenue when its evidence is element-level and tamper-evident. Clinical-Grade Scribing that logs sessions alone will not survive a 2026 HTI-2 EBT surveillance request.


