WEDI Holds MPA on CMS QHP Directory Pilot. WEDI held a Member Position Advisory (MPA) event on Wednesday August 26 to solicit member feedback on the Centers for Medicare & Medicaid Services (CMS) Qualified Health Plans Directory Pilot currently ongoing in Oklahoma. The MPA was held at the request of CMS to obtain broad industry input on data accuracy, data exchange, consumer value, user experience, provider burden, and scalability of provider directories. WEDI will compile the perspectives and recommendations offered by the MPA facilitators and attendees into a report that it will submit to CMS. CMS has signaled that it will use this feedback in its future work on national provider directory initiatives. WEDI appreciates and thanks CMS, the facilitators, and attendees for participating in the MPA and sharing their expertise and viewpoints on provider directories.
OCR Announces HIPAA Right of Access Settlement with Provider. The Department of Health and Human Services Office for Civil Rights (OCR) announced a settlement with a California-based vision provider for a potential violation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The settlement resolves an investigation of a complaint alleging a failure to provide an individual with timely access to their protected health information (PHI). OCR’s investigation determined that the provider failed to deliver the individual’s PHI within 30 days. This settlement is the 55th enforcement action in OCR’s Right of Access Enforcement Initiative.
The complaint was filed in April 2023 when the individual failed to receive their PHI that was requested in January 2023. OCR’s investigation found that the provider potentially failed to take timely action in response to the individual’s right of access requests in accordance with the HIPAA Privacy Rule’s right of access standard. Under the terms of the resolution agreement, the provider agreed to implement a corrective action plan and agreed to pay OCR $50,000.
DEA Submits to OMB Final Rule on Telehealth Prescribing of Controlled Substances. The Drug Enforcement Agency (DEA) submitted to the Office of Management and Budget (OMB) for review the “Special Registrations for Telemedicine and Limited State Telemedicine Registrations” final rule on the allowance of telehealth prescribing of controlled substances. The final rule follows the proposed rule that was published on January 15, 2025. This regulation is addressing the current restrictions by the “Ryan Haight Online Pharmacy Consumer Protection Act of 2008” that requires an in-person medical evaluation as a prerequisite to prescribing or otherwise dispensing controlled substances via the internet, which therefore prohibits telehealth prescribing. The proposed rule outlined a framework for a special registration for telehealth that would authorize practitioners to prescribe controlled substances via telehealth if specific conditions are met. OMB typically has up to 90 days to review the final rule.
ONC Releases US Quality Core Test Kit on Inferno. The Office of the National Coordinator for Health Information Technology (ONC) released the companion Inferno Test Kit for the 2026 US Quality Core FHIR Implementation Guide (IG) v0.5.0 at Inferno on HealthIT.gov. The US Quality Core IG builds on US Core and aligns with existing HL7 quality standards to implement USCDI+ Quality v1 data elements in support of standardized quality data exchange. The companion test kit validates both server and client implementations against the IG, so implementers can test conformance for either the producing or consuming side of quality data exchange.
CMS Publishes B1 2026 HCPCS Decisions. CMS published the first biannual (B1) 2026 Healthcare Common Procedure Coding System (HCPCS) Level II application summaries and coding recommendations for non-drug and non-biological items and services. Each summary includes the topic, summary of the request as written by the applicant, CMS’ preliminary recommendation, summary of public feedback, and final coding determination. Final coding actions are effective October 1, 2026, unless otherwise indicated, and will also be included in the October 2026 HCPCS Quarterly Update. Additional information is available on the HCPCS Level II Coding Decisions webpage.
CMS Opens 2027 Self-Nomination Period for QCDRs and Qualified Registries. CMS opened the 2027 Self-Nomination period for Qualified Clinical Data Registries (QCDRs) and Qualified Registries on July 1, 2026. The QCDRs and Qualified Registries are the CMS-approved intermediaries that collect clinical data on behalf of clinicians for data submission. Only intermediaries that want to participate as a QCDR or Qualified Registry need to complete the Self-Nomination form. The Self-Nomination form is available on the Quality Payment Program (QPP) website and organizations must log in by 8 p.m. ET on September 1, 2026. The 2027 Self-Nomination Toolkit for QCDRs and Qualified Registries provides additional information about the Self-Nomination process.
CMS’ EHR Certification IDs Available through CHPL Starting Sept. 1. The CMS Electronic Health Record (EHR) Certification Identifiers (IDs) will be available through the Certified Health IT Product List (CHPL) beginning on September 1. The IDs will reflect the 2026 CMS program reporting year with a year-based prefix of "2026C." Users who still need a 2025C ID for the 2025 reporting year will continue to be able to generate one through December 31, 2026. During this overlap period, the CHPL CMS ID Creator will allow users to select either the 2025 or 2026 reporting year when generating an ID. For more information, see the CMS EHR Certification ID Quick Reference.
CISA Releases Vulnerability Review for Organizations to Address Software Vulnerabilities. The Cybersecurity & Infrastructure Security Agency (CISA) released the CISA Vulnerability Review for fiscal years 2024 and 2025 analyzing software vulnerabilities. The review gives a baseline understanding of the current threats, emphasizes the importance of Secure by Design principles, and provides best practices that organizations can employ to address potential areas that threat actors could exploit. High risk areas identified within organizations include: (i) Simple, known vulnerabilities rather than advanced techniques; (ii) Improper input validation and memory safety vulnerabilities; (iii) Outdated software and continued use of end-of-support technology; and (iv) Use of emerging technology, such as AI. Organizations are encouraged to address these issues proactively.
