Healthcare Compliance News

Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act

A bipartisan bill that seeks to improve healthcare cybersecurity and resilience has been unanimously passed by the U.S. Senate. The bill – The Health Care Cybersecurity and Resiliency Act (S.B. 3315) – calls for healthcare providers to implement cybersecurity best practices and key cybersecurity measures, and authorizes grants for rural hospitals and under-resourced healthcare providers to help them make the necessary cybersecurity improvements.

The Health Care Cybersecurity and Resiliency Act was initially proposed in 2025 by Senator Bill Cassidy (R-LA) and is co-sponsored by Senators Mark Warner (D-VA), John Cornyn (R-TX), and Maggie Hassan (D-NH). The bill was introduced following the ransomware attack on Change Healthcare, which caused massive disruption across the U.S. healthcare system, and seeks to strengthen cyber defenses, improve threat-sharing, establish workforce development and employee cybersecurity training programs, and provide better cybersecurity-related resources to help rural and low-resource healthcare providers bolster their defenses.

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has already proposed an update to the HIPAA Security Rule that includes extensive cybersecurity requirements for HIPAA-regulated entities; however, the final rule has been pushed back until at least July 2027, and it may not even progress to a final rule. A final decision has yet to be made by the Trump Administration about whether a final rule will be published.

The Health Care Cybersecurity and Resiliency Act requires certain cybersecurity measures to be adopted, such as encryption of electronic protected health information, implementation of multifactor authentication, ongoing monitoring for cyber events, and penetration tests. The bill also requires the adoption of cybersecurity best practices in line with national cybersecurity frameworks such as the NIST Cybersecurity Framework.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The bill requires the HHS to develop a cybersecurity incident response plan and designates the Administration for Strategic Preparedness and Response as the Sector Risk Management Agency. The bill recognizes the importance of adopting recognized security practices and requires more transparency about data breaches. The public would be able to see, via updated fields on the OCR breach portal, whether the reporting entity had implemented recognized security practices prior to a data breach occurring, and whether any corrective action was taken by OCR against a regulated entity in response to a data breach.

The Senate Health, Education, Labor, and Pensions (HELP) Committee voted 22-1 in favor to advance the bill, and on October 1, 2026, the full U.S. Senate unanimously passed the bill. It will now head to the U.S. House of Representatives for consideration. While the bill proposes a grant program to help low-resource healthcare organizations make the necessary cybersecurity changes, the bill does not stipulate how much will be made available. That will be a matter for the House and Senate Appropriations Committees to decide.

“My bipartisan bill, the Health Care Cybersecurity and Resiliency Act, would ensure health institutions can safeguard Americans’ health data against increasing attacks,” said Sen. Cassidy. “At a time when cyberattacks not only put patients’ sensitive health data at risk but can delay lifesaving care, we need to do more to provide support.”

The post Senate Unanimously Passes the Health Care Cybersecurity and Resiliency Act appeared first on The HIPAA Journal.

CISA Sends CIRCIA Final Rule for White House Review

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has penned a final rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, which has been sent to the White House for review. CIRCIA requires CISA to develop and implement regulations for critical infrastructure entities concerning the reporting of cybersecurity incidents and ransomware payments to CISA. CISA worked with the Sector Risk Management Agencies for each of the 16 critical infrastructure sectors, the Department of Justice, other appropriate federal agencies, and the DHS-chaired Cyber Incident Reporting Council when developing the rule.

CIRCIA covers 16 critical infrastructure sectors, including healthcare and public health (HPH), and will apply to businesses, government entities, contractors, and other entities. The key requirements are for critical infrastructure entities to report cyber incidents to CISA within 72 hours of a determination that a substantial incident has occurred. In the event of a ransomware attack where a ransom is paid, CISA must be notified within 24 hours of the payment being made.

There are thresholds for reporting, which are generally based on company size and annual revenue, although they vary from sector to sector. An estimated 316,000 entities will need to comply with the reporting requirements. For the healthcare sector, they include hospitals with 100 or more beds, any critical access hospital regardless of size, any HPH sector entity that exceeds the Small Business Administration size standards, as well as manufacturers of regulated drugs and medical devices. The reporting requirements will be in addition to the reporting requirements under HIPAA.

CISA currently encourages all critical infrastructure entities to voluntarily report cyber incidents and ransom payments; however, mandatory reporting is necessary to allow CISA to effectively track cyber trends across critical infrastructure sectors, deploy resources to assist victims, and warn other entities about attacks and techniques in time for them to take action to prevent attacks or mitigate harm from a successful attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

CISA’s Notice of Proposed Rulemaking (NPRM) was published on April 4, 2024, followed by a 30-day comment period that was extended in response to comments from industry groups due to the length and complexity of the rule. CISA received a significant volume of comments from stakeholders and the public on the proposed rule, including substantial criticism due to its broad scope and overlap with existing reporting requirements.

While the initial target was an October 2025 release of a final rule, the release date was extended to May 2026, and again to September 2026. CISA has held town hall meetings, and the final rule has now been sent to the Office of Management and Budget for review. A final rule is expected to be published before the end of the year.

The post CISA Sends CIRCIA Final Rule for White House Review appeared first on The HIPAA Journal.

OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued guidance for state Medicaid Agencies clarifying when the Part 2 regulations permit Medicaid applicants’ or beneficiaries’ SUD records to be used to verify an exclusion from the community engagement requirement for Medicaid eligibility.

The Confidentiality of Substance Use Disorder (SUD) Patient Records regulation, 42 CFR part 2 (Part 2), generally applies to federally assisted programs that provide SUD diagnosis, treatment, or referral for treatment, as well as organizations that receive Part 2-covered records such as health plans that pay for SUD treatment and government benefit programs such as Medicaid.

Under the Medicaid program, adult beneficiaries (aged 19-64) are generally required to engage in work, community service, or other activities for 80 hours per month, or be in at least half-time in education, as a condition of eligibility. There are certain exceptions to these requirements, such as individuals with special medical needs, which may include certain individuals with SUD or those participating in SUD treatment programs.

Under federal law, state Medicaid agencies are required to use reliable and available information to verify an applicant’s or beneficiary’s compliance or exclusion, where possible, without requiring the individual to submit additional information. The Centers for Medicaid and Medicare Services (CMS) has been working with OCR, which is responsible for administering and enforcing the Part 2 regulations, to produce technical assistance for state Medicaid agencies on the use of Part 2 records for verification of exclusion from the community engagement requirement.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“This OCR guidance will help state Medicaid agencies use information they already have to identify individuals who are excluded from the community engagement requirement, while continuing to protect the confidentiality of SUD patient records as required by Part 2,” said OCR Director Paula M. Stannard. “This new guidance helps ensure that state Medicaid agencies comply with Part 2 while also meeting their obligations to verify Medicaid eligibility — and without imposing unnecessary documentation burdens on eligible applicants and beneficiaries.”

The post OCR Clarifies When SUD Records Can be Used to Verify Medicaid Community Engagement Exclusions appeared first on The HIPAA Journal.

California Seeks to Implement AI Guardrails for Mental Health Treatment

A bill has been unanimously passed by the California Senate that seeks to establish common-sense guardrails for artificial intelligence (AI) use in mental health treatment. The bill, SB-903 Mental health professionals: artificial intelligence, was authored by Senator Steve Padilla and seeks to protect individuals seeking therapy or psychotherapy services in the state of California. The bill was passed by the Assembly with a vote of 71-4, and now awaits the signature of the state governor.

AI tools are being rapidly adopted by healthcare providers to automate routine clinical and administrative tasks and improve operational efficiency. The Trump administration is keen to expand its use further and is pressing ahead with plans to integrate AI more fully into medical care, including deploying AI agents for conducting therapy sessions and prescribing medications to patients under Medicare.

While the capabilities of AI have advanced considerably in recent years, mental health experts have voiced concerns about patient safety. AI algorithms may be able to accurately diagnose a mental health condition, but they are still capable of error, and in mental health, errors can have grave consequences. The bill seeks to ensure patient safety by requiring oversight by licensed mental health professionals and requiring patients to consent to the use of AI tools.

“Thousands of the professionals caring for patients across California are all urging Governor Newsom with one voice, “Sign this bill’,” said Senator Padilla. “The Trump administration is listening to tech companies who want to put unlicensed chatbots in front of vulnerable patients to make a profit. California should be listening to the licensed clinicians who spent years training to do this work safely.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

If signed into law by Governor Gavin Newsom, individuals, corporations, or entities that provide or facilitate psychotherapy services may only use AI tools to assist in providing administrative support services or supplementary support for psychotherapy services. AI tools or systems may not be used to conduct therapy sessions. If AI tools are used for making therapeutic decisions, therapeutic recommendations, assessment results, diagnoses, or treatment plans; detecting emotional states or mental stress; performing triage or screening; or directly interacting with patients or clients in any form of psychotherapeutic communication (unless FDA-approved and compliant with HIPAA), their output must be reviewed and approved by a licensed professional.

The bill prohibits advertising or otherwise purporting to offer psychotherapy services when they are provided through the use of companion chatbots, including claiming that a companion chatbot is a therapist or provides therapy. If AI tools are used to record or transcribe psychotherapeutic communications, psychotherapy sessions, or triage or screening, then the patient or their legally authorized representative must be informed about the specific purpose for which AI is being used, and must provide (revocable) consent.

The post California Seeks to Implement AI Guardrails for Mental Health Treatment appeared first on The HIPAA Journal.

Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act

On September 17, 2026, two Democratic Senators reintroduced the Health Infrastructure Security and Accountability Act, which seeks to improve cybersecurity standards for the U.S. healthcare system and make funds available to help rural and underserved hospitals invest in essential cybersecurity measures.

The bill was reintroduced by Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR), following its initial introduction in the 118th Congress 2D Session on September 25, 2024. When the bill was first introduced, 394 large hacking-related healthcare data breaches had been reported to the Department of Health and Human Services Office for Civil Rights (OCR), involving the protected health information of 43 million Americans.

At the time, the senators explained that cyberattacks are delaying and disrupting patient care, harming patient health and national security, and putting Americans at risk of identity theft and fraud. “These hacks are entirely preventable and are the direct result of lax cybersecurity practices by health care providers and their business partners,” explained the Senators.

The situation has only worsened in the two years since the bill was first introduced. The OCR breach portal lists year-to-date figures (Jan 1 – Aug 31) of 426 hacking-related breaches, involving the protected health information of 73 million Americans. That’s an 8% increase in hacking-related data breaches and a 70% increase in affected individuals.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

On January 24, 2024, OCR published two sets of voluntary cybersecurity performance goals (CPGs) for the healthcare and public health (HPH) sector – Essential and Enhanced – that consist of high-impact measures that should be adopted by healthcare organizations to strengthen and mature their cybersecurity programs. As predicted by OCR at the time, voluntary goals alone would not be enough to drive the behavioral changes needed across the sector to improve cybersecurity.

The CPGs were followed by a proposed update to the HIPAA Security Rule, which mandates significant additional cybersecurity requirements. The proposed update has proven hugely unpopular, with industry groups and health systems calling for the proposed rule to be scrapped. A final rule has been delayed until July 2027, although a final decision about whether a final rule will actually be released has yet to be made by the Trump administration. Part of the problem, especially for rural and other low-resource healthcare providers, is a lack of funding to make the necessary cybersecurity improvements, which is something that the Health Infrastructure Security and Accountability Act seeks to address.

“As cybercriminals ramp up their attacks on hospitals and health care providers, it’s becoming increasingly clear that voluntary standards are not enough to protect Americans’ health, safety, and privacy,” explained Sen. Warner. “This legislation would establish strong, commonsense cybersecurity protocols for health care entities, while also getting resources to rural and underserved hospitals to strengthen their defenses and protect the patients who depend on them.”

As the Senators explained, the U.S. health care system is particularly at risk for cyberattacks due to its size, technological dependence, collection of sensitive personal information, and unique vulnerability to disruptions. Healthcare organizations are viewed as low-hanging fruit, and attacks can be highly profitable for cybercriminals. “The frequency and sophistication of cyberattacks has dramatically increased in every part of the health care system, and will only grow,” said Sen. Wyden. “Our bill creates national cybersecurity standards for health care providers and devotes resources, especially in rural and underserved areas, to ensure every American’s medical information is secure. Congress cannot wait to act until another catastrophic cyberattack compromises the safety and privacy of American families’ most personal information.”

The 2026 Health Infrastructure Security and Accountability Act remains largely unchanged from the 2024 version, other than shifting the timeline forward by two years. The key requirements of the bill are:

  • Mandatory minimum cybersecurity standards for covered entities and business associates, established, enforced, and updated by the HHS. Updates are required at least every two years.
  • Heightened cybersecurity standards for systemically important entities and entities critical to national security.
  • Continuity/recovery plans for all covered entities for technical failures, disruptive cyber events, and natural disasters, and stress tests to evaluate whether the entity has the capabilities to recover essential functions.
  • Written annual statements signed by the chief executive officer and chief information security officer attesting that the company is compliant with applicable security standards.
  • Mandatory annual security risk analyses, including specific assessments of the extent to which the entity is exposed to risk through its business associates.
  • Independent audits of covered entities’ security measures to assess compliance with the HHS’s CPGs.
  • Annual HHS audits of at least 20 HIPAA-regulated entities to assess data security practices, focused on those of systemic importance.
  • Increased financial penalties under HIPAA for failing to meet security requirements – A minimum $500 penalty for no knowledge; $5,000 for reasonable cause; $50,000 for willful neglect (corrected); and $250,000 for willful neglect (uncorrected).
  • A government investment of $1.3 billion to help hospitals strengthen cybersecurity: $800 million in up-front investment for hospitals in rural and underserved urban communities to adopt the essential cybersecurity goals, and $500 million in incentives available to all hospitals to adopt the enhanced CPGs.
  • Medicare accelerated and advanced payments in response to cybersecurity incidents.

The post Democratic Senators Reintroduce the Health Infrastructure Security and Accountability Act appeared first on The HIPAA Journal.

House Subcommittee on Health Examines Healthcare Cybersecurity Proposals

On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare cybersecurity, reform Medicare provider payments, and other healthcare matters. At the hearing, titled Examining Legislative Proposals to Reform Medicare Provider Payment and Bolster Health Care Cybersecurity, the subcommittee discussed two bills that seek to improve healthcare cybersecurity – the Rural Hospital Cybersecurity Enhancement Act and the Healthcare Cybersecurity and Resiliency Act of 2026.

Healthcare data breaches have increased significantly in recent years. For the past five years, more than 700 data breaches affecting 500 or more individuals have been reported to the HHS’ Office for Civil Rights (OCR), and a new record was set in 2025, with 804 large data breaches currently listed on the OCR data breach portal. As of August 30, 2026, 496 large data breaches have been reported to OCR, indicating that 2026 will be another 700+ data breach year. So far this year, more than 74.6 million individuals have had their protected health information exposed. Last year, 140.5 million individuals were affected by large healthcare data breaches.

The increase in data breaches is largely driven by hacking and other IT incidents. Out of this year’s 496 large data breaches, 426 breaches are due to hacking and other IT incidents. That’s 86% of this year’s total, and accounts for 97.8% of the individuals whose protected health information has been breached this year. Healthcare organizations are required to comply with the HIPAA Rules, but with data breaches occurring at the current rate, it suggests either widespread noncompliance or ineffective regulations.

Healthcare breaches not only violate Americans’ privacy and put them at risk of identity theft and fraud; hacking incidents, especially ransomware attacks, cause massive operational disruption that affects the ability of healthcare providers to provide care. All too often, cyberattacks result in cancelled appointments, rescheduled surgeries, and delays to emergency care, which affect patient outcomes.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

An update to the HIPAA Security Rule has been proposed that includes a raft of new security requirements to improve healthcare cybersecurity; however, the proposed rule was heavily criticized by industry groups, health systems, and hospitals. The final rule has been delayed until at least July 2027, although a decision has yet to be made about whether a final rule will be issued. Even if it is, the requirements will not need to be implemented until at least early 2028.

Implementing more robust cybersecurity measures comes at a cost, and that is especially problematic for rural healthcare providers, many of whom are already facing significant financial challenges without having to commit additional funds to improving cybersecurity. Each dollar spent on cybersecurity improvements is a dollar lost to patient care. The relative lack of cybersecurity resources and personnel makes rural and other resource-constrained healthcare providers soft targets for hackers, and cyberattacks that disrupt patient care can result in dangerous delays to healthcare services, as alternative facilities may be hundreds of miles away.

The Rural Hospital Cybersecurity Enhancement Act, a bipartisan bill co-sponsored by Representatives Erin Houchin (R-IN) and Rep. Kim Schrier (D-WA), was introduced to better protect rural healthcare providers against cyber threats by improving the cybersecurity workforce and improving resources.  That includes mandates for the HHS to provide free instructional materials to help rural healthcare providers train existing staff, targeted educational criteria aimed at improving cybersecurity training in rural educational institutions, and a workforce development strategy to expand the rural healthcare IT workforce.

The other key healthcare cybersecurity bill under consideration is the bipartisan Health Care Cybersecurity and Resiliency Act of 2026, which was introduced by Senate Health, Education, Labor & Pensions (HELP) Committee Chair, Sen. Bill Cassidy (R-LA), and co-sponsored by Sens. Mark Warner (D-VA), Maggie Hassan (D-NH), and John Cornyn (R-TX). The aim of the bill is to better protect patient health data, improve coordination between the HHS and the Cybersecurity and Infrastructure Security Agency (CISA), and strengthen overall cybersecurity defenses within the healthcare and public health sector.

At the hearing, the subcommittee heard testimony from Greg Garcia, Executive Director for Cybersecurity at the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group, on the state of healthcare cybersecurity and the pending two healthcare cybersecurity bills. Garcia warned that the nation’s rural and resource-constrained healthcare providers are the most vulnerable in the sector and are unprepared to protect against evolving cyber threats and technological innovation, including beneficial and adversarial uses. He called for “a concerted, multi-pronged combination of government programs, assistance and funding with market-based mutual support and community defense.”

Garcia made several recommendations, including workforce training on cybersecurity, especially at rural and low-resourced healthcare providers where it is desperately needed. Garcia said it is essential that grants are made available to allow rural and resource-constrained healthcare providers to make the necessary upgrades to cybersecurity, such as replacing end-of-life medical devices that lack the capacity to be made secure. Garcia also recommended that the HHS official appointed as responsible for coordinating cybersecurity internally and across the sector should be designated at the deputy assistant secretary level or higher, and for that individual to have the authority to influence policy and program decisions.

He advised against implementing regulations that require specific security technologies such as encryption and multifactor authentication, such as the mandatory measures in the proposed update to the HIPAA Security Rule, as it will be far more effective to address risks through evolving industry cybersecurity frameworks. Garcia suggested that the proposed HIPAA Security Rule update should be reset or abandoned, as it “did not demonstrate sufficient insight to the complexities of achieving effective cybersecurity protections for the health sector, nor acknowledge the considerable work the sector and government partners have accomplished in good faith and urgency over the past 6 years to build a collective cyber defense.”

Garcia also requested that HSCC be involved in cybersecurity policy decisions and should be included in threat information sharing and incident response advisories, as it is the primary cross-sector healthcare advisory council focused exclusively on critical infrastructure cybersecurity

The post House Subcommittee on Health Examines Healthcare Cybersecurity Proposals appeared first on The HIPAA Journal.

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

In September 2021, the U.S. Federal Trade Commission (FTC) issued a policy statement extending the FTC Health Breach Notification Rule to cover health apps and other connected devices not covered by the Health Insurance Portability and Accountability Act (HIPAA). On September 9, 2026, the FTC withdrew that policy statement as it was considered to provide little benefit, having been superseded by rulemaking.

The Health Breach Notification Rule was issued in 2009 under the Health Information Technology for Economic and Clinical Health (HITECH) Act and applies to vendors of personal health records (PHRs) and related entities that are not subject to HIPAA. In 2021, the FTC determined that because health apps were mainstream and increasingly collected consumers’ sensitive health and personal information, the developers of the apps should have a responsibility to ensure that the data they collect is secured, protected against unauthorized access, and that consumer notifications are required when there is a breach of that information or an unauthorized disclosure.

Per the 2021 policy statement, the FTC viewed the developers of health apps and other connected devices to be vendors of personal health records, if an app or device had the capability to draw data from multiple sources and was not covered by a similar rule issued by the Department of Health and Human Services. The change in position was contentious at the time, and while the policy statement received majority FTC backing, it was only approved with a 3-2 vote. Commissioners Noah Joshua Philips and Christin S. Wilson voted against the policy statement, with both believing that the FTC’s interpretation of applicability for the Health Breach Notification Rule stretched the statutory text beyond its terms.

In 2024, the FTC updated its Health Breach Notification Rule, significantly expanding its scope. The definition of health information was broadened to make it clear that the rule applies to data collected via health apps, connected devices, and any other technology that draws health inferences from user data. The update also clarified that breaches that trigger the notification requirements include cybersecurity incidents and unauthorized disclosures to third parties.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

In its September 9, 2026, statement, the FTC said the 2024 update the Health Breach Notification Rule rendered the policy statement unnecessary and that pursuant to an Executive Order by President Trump, agencies have been directed to eliminate obsolete guidance documents, policy statements, and unnecessary rules that provide no benefit to Americans, hence the decision to withdraw the policy statement.

The post FTC Rescinds 2021 Policy Statement on Health App Data Breaches appeared first on The HIPAA Journal.

FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices

The U.S. Food and Drug Administration (FDA) has issued a discussion paper on considerations for the regulation of Generative AI (GenAI)-enabled medical devices. As a regulator of all medical devices, the FDA is considering whether new regulations are required for GenAI-enabled medical devices to ensure patients are provided with timely access to safe and effective devices.

GenAI-enabled medical devices have the potential to transform patient care, yet the devices may introduce unique risks compared to traditional software and artificial intelligence (AI)-enabled medical devices. Current regulatory frameworks, such as those used for traditional medical devices, may not be appropriate for GenAI-enabled devices, which present unique challenges and risks.

The devices have unique characteristics and behaviours, including the capability to produce variable outputs, which change over time as the devices incorporate continuously learning systems. GenAI devices can accept open-ended inputs, and it is not feasible to test the full range of inputs and assess outputs using traditional premarket testing methodologies. The FDA notes that many devices are built on general-purpose foundation models, which have been developed by third parties that have varying levels of transparency into training data, architecture, and evaluation methods. As such, specific behaviors and errors are difficult to attribute to the underlying model used by the devices.

While GenAI-enabled devices offer a wide range of benefits over and above what can be gained from traditional and AI-enabled medical devices, the characteristics that provide those benefits also present unique risks. For instance, GenAI systems may misinterpret or distort data, filling in knowledge gaps with plausible but invented information (confabulations), such as associating a symptom with the wrong condition. There is also a risk of hallucinations – the generation of false facts – on which output is based and presented as fact. GenAI tools may provide outputs that are plausible and sound authentic to end users, which may be questionable at best and potentially dangerous to health.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The discussion paper, published by the FDA’s Center for Devices and Radiological Health (CDRH) –  Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback – delves into the challenges associated with premarket evaluation and postmarket monitoring of GenAI-enabled medical devices. The aim of the paper is to guide discussion and focus feedback ahead of the potential development of guidance and future regulations. No decision has been made about whether FDA regulation is required, or areas where guidance may be necessary.  The feedback obtained in response to the discussion paper will guide future FDA decisions, including new methodologies for premarket evaluation and the postmarket assessment of the performance of GenAI-enabled medical devices to ensure they remain safe and effective throughout the entire product lifecycle.

The paper discusses the possibility of competency-based testing of GenAI-enabled medical devices for premarket evaluations, using an approach modelled on medical training, licensure examinations, supervised practice, periodic reevaluation, and public reporting, and device benchmarking to assess whether a device demonstrates the necessary clinical knowledge, analytic capabilities, safety behavior, communication, and generalizability to support reasonable assurance of safety and effectiveness of the device for its intended use. Potentially, clinical confirmation will be required, as a competency-based approach may not fully assess performance in a clinical setting.

The FDA anticipates a risk-based approach will be necessary for regulation, taking into consideration the intended use and device characteristics. For instance, certain action-directing functions may be classed as higher risk than functions that provide non-directive information, as well as agentic AI systems capable of autonomous actions.

The FDA said it wishes to work collaboratively with the full range of stakeholders to develop efficient, scientifically sound, and least burdensome approaches to the premarket evaluation and postmarket monitoring of GenAI-enabled devices. Feedback on the discussion draft is requested from medical device manufacturers, clinicians, researchers, and the general public by October 19, 2026.

The post FDA Seeks Feedback on Potential Regulation of GenAI Medical Devices appeared first on The HIPAA Journal.

Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations

The Department of Health and Human Services Office of Inspector General (HHS-OIG) has announced that two settlements have been agreed to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA).

EMTALA was enacted by Congress in 1986 to ensure public access to emergency medical services. EMTALA requires Medicare-participating hospitals that offer emergency services to provide a medical screening examination (MSE) to patients who present to their emergency department requesting an examination or treatment for an emergency medical condition, regardless of the patient’s ability to pay.

A patient must be provided with stabilizing treatment if the MSE determines that they have an emergency medical condition. If the hospital lacks the capability to provide stabilizing treatment, or if requested by the patient, they must initiate an appropriate transfer.  The receiving hospital must have the available space and qualified personnel and must agree to accept the transfer. The transferring hospital must send all medical records related to the emergency condition that are available at the time of the transfer, and send all other records as soon as is practicable. Hospitals that violate EMTALA can face heavy civil monetary penalties, and individuals harmed may pursue legal action for EMTALA violations.

Merit Health Central Hospital

Merit Health Central Hospital in Jackson, Mississippi, formerly known as Central Mississippi Medical Center, has agreed to settle alleged EMTALA violations with HHS-OIG and will pay a $350,000 financial penalty. Unusually, the case relates to patients who presented at the hospital emergency room more than a decade ago. The delay in issuing the penalty was due to a False Claims Act lawsuit related to the alleged EMTALA violations that was working its way through the legal system. HHS-OIG’s investigation determined that the hospital failed to provide an adequate MSE and stabilizing treatment to fourteen patients who presented to its emergency room between January 2013 and April 2015 requesting an examination or treatment for a medical condition.

Out of the fourteen individuals, nine had emergency medical conditions and were transferred to another hospital between January 2013 and May 2013 without providing an appropriate MSE and treatment to stabilize the patients to minimize the risk of transfer, despite having staff within its facilities or available as on-call physicians who could have provided the necessary stabilizing treatment. In six cases, the transfers were based on its application of Central MS Trauma Region Trauma Activation Criteria and Destination Guidelines for the transfer of individuals with penetrating trauma to another hospital. Several of the patients had presented with gunshot wounds.

Four patients presented to the emergency room between March 2015 and April 2015 with a psychiatric emergency medical condition and were not provided with an appropriate MSE within the capabilities of the hospital or stabilizing treatment. The four individuals were transferred by taxi in an unstable condition to a homeless day shelter. One patient presented to the emergency room in March 2015 for treatment related to end-stage renal disease and had an emergency medical condition requiring dialysis, yet stabilizing treatment was not provided even though it was within the hospital’s capabilities.

NorthShore University Health System

NorthShore University Health System in Evanston, Illinois, agreed to settle alleged an EMTALA violation concerning a patient who presented to its emergency room in February 2025 complaining of leg pain and nausea.

The 64-year-old man presented to the emergency department at 10:53 a.m. and was triaged at 11:15 a.m. During triage, the patient’s vitals were taken. He had a heart rate of 126 bpm and was assigned an emergency severity index (ESI) level of 2 – high risk. The patient was placed in a wheelchair in a waiting room but was not reassessed, and his vitals were not rechecked. The patient was found slumped over and unresponsive in the wheelchair at 8:55 p.m – more than 9 hours after he was triaged. The patient was determined to be in cardiac arrest, and CPR was quickly initiated. HHS-OIG’s investigation determined that Northshore failed to provide an appropriate MSE. The case was settled with a $105,000 financial penalty.

The post Merit Health Central Hospital & NorthShore University Health System Settle EMTALA Violations appeared first on The HIPAA Journal.