Key Prior Authorization Policies Finalized in FY2027 CMS IPPS Final Rule. The Centers for Medicare & Medicaid Services (CMS) and Office of the National Coordinator for Health Information Technology (ONC) partnered to finalize key Fast Healthcare Interoperability Resources (FHIR®) electronic prior authorization policies impacting the 2024 CMS Promoting Interoperability and Advancing Prior Authorization Final Rule (CMS-0057-F). The policies were outlined in the CMS FY 2027 Hospital Inpatient Prospective Payment System (IPPS) final rule (CMS-1849-F) and finalized policies to:
- Adopt for the ONC certification program the following standards: (i) HL7 FHIR® Da Vinci—Coverage Requirements Discovery IG, Version 2.2.1 - STU 2.2; (ii) HL7 FHIR® Da Vinci—Documentation Templates and Rules Implementation Guide, Version 2.2.0 - STU 2.2; (iii) HL7 FHIR® Da Vinci Prior Authorization Support (PAS) FHIR Implementation Guide, Version 2.2.1 - STU 2.2; (iv) HL7 FHIR® CARIN Consumer Directed Payer Data Exchange (CARIN IG for Blue Button®), Version 2.2.0 - STU 2.2; (v) HL7 FHIR® Da Vinci Payer Data Exchange (PDex) US Drug Formulary Implementation Guide, Version 2.1.0 - STU 2.1; (vi) HL7 FHIR® Da Vinci Payer PDex Plan Net Implementation Guide, Version 1.2.0 - STU 1.2; and (vii) HL7 FHIR® Da Vinci Clinical Data Exchange (CDex) IG, Version 2.1.0 - STU 2.1. These finalized standards were included in the 2026 CMS Interoperability Standards and Prior Authorization for Drugs (CMS-0062) Proposed Rule and are effective on October 1, 2026.
- Modify the CMS Electronic Prior Authorization measure, established in CMS-0057-F, as an optional bonus measure for the electronic health record (EHR) reporting period in Calendar Year (CY) 2027 and mandatory beginning with the EHR reporting period in CY 2028.
Additional provisions in the IPPS Final Rule include:
- Removing ONC Direct Review and ONC-Authorized Certification Body Surveillance attestations beginning with the EHR reporting period in CY 2026.
- Removing, with modification to delay removal an additional year, the Support Electronic Referral Loops by Sending Health Information and Support Electronic Referral Loops by Receiving and Reconciling Health Information measures beginning with the EHR reporting period in CY 2029.
- Adding the Unique Device Identifiers for Implantable Medical Devices measure to the Public Health and Clinical Data Exchange objective beginning with the EHR reporting period in CY 2027.
- Permitting impacted hospitals
Access the CMS Fact Sheet to learn more about the IPPS Final Rule.
OCR Settles Ransomware Investigation with Health Care System. The Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with an Illinois and Michigan regional health system for potential violations of the Health Insurance Portability and Accountability Act of (HIPAA) Privacy, Security, and Breach Notification Rules. The settlement resolves an investigation that OCR initiated after the health system filed a breach report in October 2021. This settlement is the agency’s 21st ransomware enforcement action.
The breach was the result of the health system’s files being infected with ransomware in April 2021. The protected health information (PHI) of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR’s investigation found that the health system’s potential violations included failing to conduct an accurate and thorough risk analysis and providing timely breach notification to the affected individuals and HHS. The provider resolved the enforcement action with a settlement agreement and agreed to a payment of $552,250 to OCR.
CMS Celebrates Health Tech Ecosystem and Announces New Initiatives. CMS celebrated one year of its Health Tech Ecosystem initiative and the progress to date. The event included HHS Secretary Robert F. Kennedy, Jr., CMS Administrator Mehmet Oz, MD and CMS Deputy Administrator and Chief Product Officer Amy Gleason. CMS launched a new solution in its Kill the Clipboard Health Tech Ecosystem initiative. The solution involves the patient maintaining their health and insurance information in an application (“app”) that generates a QR code and the provider’s office scanning the QR code to transfer the patient’s information into their practice’s EHR. The technology is SMART Health Link, which is a national, open standard for sharing health information securely. Using this technology ends the burdensome paperwork patients fill out at every visit and staff rekey into their system. It can also close information gaps that may be the cause of preventable medical errors. CMS also announced other new initiatives under the ecosystem that will focus on price transparency, “ditch the disk” for diagnostic imaging, patient scheduling, clinical trials, and others.
ONC Releases USCDI v7. ONC released the U.S. Core Data for Interoperability Version 7 (USCDI v7). USCDI v7 incorporates 30 new data elements and one significantly revised data element (Tobacco and Nicotine Product Use, an evolution of the Smoking Status data element) for a total of 31 overall new data elements across multiple data classes. The new version seeks to strengthen support for patient safety, nutrition care, and administrative burden reduction. USCDI v7 also includes input submitted through the ONC New Data Element and Class system, which enables the public to propose new data elements. ONC publishes new versions of the USCDI annually, with a draft version typically released for comment in January and a final version released in July.
CMS Releases Guidance on Use of CARCs and RARCs for NSA. CMS released guidance on the use of Claim Adjustment Reason Codes (CARCs) and Remittance Advice Remark Codes (RARCs) for the No Surprises Act (NSA). The guidance is in response to the June 2026 final rules aimed at improving the functioning of the Federal Independent Dispute Resolution (IDR) process established under the NSA. The rules establish new requirements regarding use of the CARCs and RARCs. The regulations are intended to improve communication between parties by including information relevant to adjudication of claims, including information used to determine whether a payment dispute is eligible for the Federal IDR process. The guidance also states the government will continue to assess existing RARCs related to the NSA and make recommendations to the RARC Committee to remove existing RARCs or approve new RARCs should it determine that doing so will improve communications related to the NSA between plans or issuers and providers, facilities, or providers of air ambulance services. These regulations are effective as of August 3, 2026.
ONC Releases US Quality Core Test Kit on Inferno. ONC released the companion Inferno Test Kit for the 2026 US Quality Core FHIR Implementation Guide (IG) v0.5.0 on Inferno on HealthIT.gov. The US Quality Core IG builds on US Core and aligns with existing HL7 quality standards to implement USCDI+ Quality v1 data elements in support of standardized quality data exchange. The companion test kit validates both server and client implementations against the IG, so implementers can test conformance for either the producing or consuming side of quality data exchange. The US Quality Core Test Kit validates server and client implementations against the US Quality Core Implementation Guide v0.5.0. The test kit is open source and freely available. The scope of this test kit is intended to match the conformance scope defined by US Quality Core v0.5.0.
CMS Updates HCPCS on Master List. CMS published updates in the Federal Register to the Healthcare Common Procedure Coding System (HCPCS) codes on the Master List, Required Face-to-Face Encounter and Written Order Prior to Delivery List, and the Required Prior Authorization List. The Master List serves as a library of items identified as potential vulnerabilities to the Trust Fund based on criteria outlined in federal statute. Only items that are selected and announced via Federal Register notice are subject to the regulatory conditions of payment. Implementation of the updates, excluding upper limb orthoses, will be effective October 28, 2026. According to the notice, the prior authorization requirements for the upper limb orthoses will be implemented in three phases.
CISA Issues Warning of SharePoint Vulnerabilities. The Cybersecurity & Infrastructure Security Agency (CISA) issued a warning of active exploitation of vulnerabilities that allow cyber threat actors to gain unauthorized access to on-premises SharePoint Servers. These vulnerabilities affect all supported on-premises SharePoint Server versions and involve establishing remote code execution and post-exploitation activities to gain access and deploy malware. Organizations should monitor affected SharePoint Servers for any signs of exploitation or unusual activity and remediate any potential compromise.
X12 to Hold Webinar on HIPAA Version 008060 837 and 275 Transactions. The Standards Development Organization X12 will hold a webinar on Wednesday, August 5 at 2 pm ET on the three 837 claims HIPAA Version 008060 guides and the 006020/008060 275 attachments guide. This webinar is part of X12’s continuing education series and focuses on the Health Care Claim: Professional, Institutional, and Dental guides (837s) as well as the Additional Information to Support a Health Care Claim or Encounter (275) guide. Registration is now open. Questions about the Version 008060 education
