CMS Releases CY2027 Medicare PFS Proposed Rule. The Centers for Medicare & Medicaid Services (CMS) released the Calendar Year (CY) 2027 Medicare Physician Fee Schedule (PFS) proposed rule. In addition to the physician payment proposals, other proposals address value-based care programs and Medicare accountable care organizations (ACOs). Proposed improvements to the Medicare Shared Savings Program (MSSP) aim to support continued participation and growth in ACOs, while strengthening incentives for high-quality, coordinated care. CMS is also proposing to sunset traditional Merit-based Incentive Payment System (MIPS) reporting in 2029 and transition clinicians toward specialty-focused MIPS Value Pathways. Also included are requests for information (RFIs), including one on the future transition to Fast Healthcare Interoperability Resources (FHIR)-based digital quality reporting for the Quality Payment Program. A CMS webinar on an overview of the 2027 Quality Payment Program proposed updates will be held on July 29. CMS fact sheets are available on the QPP, PFS, and MSSP proposed changes. Comments on the proposed rule are due by September 14.
CMS Releases Report on ACO REACH, Outlines Improved Care Quality and Cost Savings. The CMS Innovation Center released the third annual evaluation report for the ACO REACH model showing it improved care quality and reduced gross spending during its first four performance years. The model served over two million beneficiaries through 132 participating ACOs, with half of aligned beneficiaries new to the model in Program Year 2023. Over 70% of ACOs reported prioritizing initiatives to reduce avoidable hospital utilization, increase primary care touchpoints, and manage care for patients with complex needs. With ACO REACH ending this year, lessons-learned will help inform the next generation of ACO models, including the Long-term Enhanced ACO Design Model, which launches in January 2027.
OIG Audit Finds Issues in Medicaid Managed Care Provider Directories. The Office of Inspector General released its findings of an audit of Medicaid managed care maternal health providers in provider directories in five states. The results from the audit found issues with providers in directories who were not in-network, in-network providers who were not included in the directory, and inaccurate contact information. OIG recommended that CMS take steps to support states in the accuracy of their online provider directories.
Homeland Security Announces Establishment of ANCHOR-CI. The Department of Homeland Security (DHS), through the Cybersecurity & Infrastructure Security Agency (CISA), announced plans to establish the Alliance of National Councils for Homeland Operational Resilience—Critical Infrastructure (ANCHOR-CI). ANCHOR-CI will be an advisory body made up of critical infrastructure sector, cross-sector, regional, and industry councils. It will provide group advice and recommendations to the DHS Secretary, through the CISA Director, to ensure a coordinated national response to critical infrastructure and cybersecurity threats. Members of ANCHOR-CI will be approved by the CISA Director and represent: (i) critical infrastructure owners and operators, including their representative trade associations or equivalent organizations; (ii) governmental entities at the federal, state, local, tribal, and territorial levels; (iii) organizations with direct responsibility for cybersecurity and critical infrastructure security and resilience activities; and (iv) other private sector entities as deemed appropriate by the CISA Director.
White House Launches Cybersecurity Vulnerability Coordination Initiative. The White House launched “GOLD EAGLE,” an artificial intelligence (AI) innovation that provides a clearinghouse to enable cybersecurity vulnerability coordination. Built by open-source software partners and critical infrastructure companies, the coordinated system will receive and patch cyber vulnerabilities across critical infrastructure sectors using existing authorities and resources of the federal government. The project was a collaboration between the White House, Department of the Treasury, DHS through CISA, and Department of Defense and industry partners. GOLD EAGLE is in response to Executive Order “Promoting Advanced Artificial Intelligence Innovation and Security” (EO 14409) and represents a new operational model for cyber defense.
CISA Calls for Improved Router Hygiene to Protect Against Russian State-Sponsored Targeting. CISA, along with the National Security Agency, Federal Bureau of Investigation (FBI), Defense Cyber Crime Center, and international partners, released a joint cybersecurity advisory, “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,” addressing ongoing exploitation of vulnerable networking devices by Russian cyber threat actors. The advisory follows up on the FBI’s August 2025 public service announcement, providing updated information about Russian cyber threat actors. These actors continue to target critical infrastructure, including the Health Care and Public Health sector, by exploiting poorly configured routers and network devices. The advisory provides practical steps organizations can take to harden their networks against exploitation.
TEFCA™ RCE Publishes Directory Requirements SOP for Public Review. The Sequoia Project, the Trusted Exchange Framework and Common Agreement™ (TEFCA™) Recognized Coordinating Entity® (RCE®), along with the Office of the National Coordinator for Health Information Technology published the RCE Directory Service (Directory) Requirements Policy Standard Operating Procedure (SOP) Version 1.2 on the TEFCA Topics in Change Management webpage for review. This SOP describes Directory policy requirements that Qualified Health Information Networks (QHINs) must follow when maintaining Directory Entries, in addition to the specifications set forth in the Framework Agreements, QHIN Technical Framework, RCE Directory Service Implementation Guide, and applicable SOPs. Feedback on the draft SOP is due on July 28.
X12 to Hold Second Webinar on HIPAA Version 008060 270/271 Transaction. The Standards Development Organization X12 will hold a webinar July 23 at 2 pm ET as part of its 008060 education and information series. on. The session will focus on the 008060 version of the Health Care Eligibility and Benefit Inquiry and Information Response (270/271). X12 will continue to share webinars and additional content to better assist industry stakeholders understand the enhancements in the 008060 versions of standards already mandated under HIPAA. Registration is now open. Additional webinars and on-demand presentations for previous educational sessions will be offered in the future. Questions about the 008060 education and information series can be submitted via the X12 feedback form.
