CMS Posts Materials from Listening Session on Advancing Adoption of X12 Version 008060. The Centers for Medicare & Medicaid Services (CMS) posted materials from the agency’s July 1 Listening Session on advancing the adoption of X12’s Version 008060 administrative transactions. WEDI and the six Designated Standards Maintenance Organizations (Dental Content Committee, Health Level 7, National Council for Prescription Drug Program, National Uniform Billing Committee, National Uniform Claim Committee, and X12) presented at the Listening Session. The materials from the session are now available on the CMS Administrative Simplification Events and Latest News webpage and include a summary of the event, slide presentations, audio recording, and appendix with additional stakeholder materials and related resources.
CMS Finalizes Addition of UDI Performance Measure in IPPS Final Rule. CMS finalized the addition of a performance measure in the FY 2027 Hospital Inpatient Prospective Payment System (IPPS) and Long-Term Care Hospital Prospective Payment System Final Rule for reporting Unique Device Identifiers (UDIs). The new measure, “Unique Device Identifiers for Implantable Medical Devices,” is part of the Public Health and Clinical Data Exchange objective beginning with the electronic health record (EHR) reporting period in Calendar Year 2027. The measure requires eligible hospitals or critical access hospitals to attest that they used a certified EHR during the reporting period to electronically capture and store the complete UDI for each implantable medical device subject to UDI requirements used for patient care delivery. The intent of integrating a UDI-focused measure into the Medicare Promoting Interoperability Program is to foster consistent workflows for capturing device data as discrete EHR elements and strengthen the ability of eligible facilities and public health agencies to use interoperable health information to improve outcomes, manage risk, and respond rapidly to device-related safety concerns.
CMS Shares First Look at 2026 Qualifying APM Participant Status and APM Participation Data. CMS updated its Quality Payment Program (QPP) Participation Status Tool to share a first look at the 2026 Alternative Payment Model (APM) data, including data from Medicare Part B claims with dates of service between January 1 and March 31, 2026. The tool includes the 2026 Qualifying APM Participant (QP) status and Merit-based Incentive Payment System (MIPS) APM participation status. Participating providers can log in to view their QP or APM participation status. Additional information is available on the QPP webpage.
GAO Releases Report on Cybersecurity Regulations, Calls for Harmonization. The Government Accountability Office (GAO) released a report on current cybersecurity regulations that finds multiple industry sectors, including health care, are subject to duplicative reporting requirements and calls for harmonization. Per the report, multiple cybersecurity regulations add administrative burden through conflicting guidance, inconsistencies, increased compliance costs, and redundancies. GAO contends that harmonizing regulations has the potential to bring consistency to the assessment, reporting, and auditing activities related to cybersecurity requirements. The report includes GAO’s review of federal cybersecurity regulations by department and agency and identifies opportunities for regulatory harmonization.
CISA Releases Cybersecurity Advisory on Gunra Ransomware. The Cybersecurity and Infrastructure Security Agency (CISA), with the Federal Bureau of Investigation and in collaboration with other U.S. government and international partners, released a joint Cybersecurity Advisory, #Stopransomware: Gunra Ransomware. This advisory is part of an ongoing series detailing ransomware variants and threat actors and provides technical details on the Gunra ransomware, along with detection and mitigation guidance to help protect at-risk organizations. Of note, Gunra actors have demonstrated the ability to disable backup features, and in one instance, prevented restoration by deleting backup and archived data stored at both a primary data center and disaster recovery center. CISA urges organizations to implement the advisory’s mitigation strategy.
U.S. House Bill Calls for AI Kill Switch. Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan “AI Kill Switch Act” that would require developers of artificial intelligence (AI) systems to maintain a shutdown-capability standard and graduated deployment-corrections framework with respect to certain technology. The act would authorize the Secretary of the Department of Homeland Security, in consultation with the Secretary of Commerce and the Director of National Intelligence, to order a slowdown or shutdown of an AI system that can cause catastrophic harm. The bill was introduced to address recent incidents in which two AI models went rogue. The Act would require incident reporting and preserve forensic records to learn from any failures, adding additional safeguards for AI deployment.
OCR Holding HIPAA Security Conference September 2-3. The Department of Health and Human Services Office for Civil Rights (OCR) and the National Institute for Standards and Technology (NIST) Information Technology Laboratory are holding the “Safeguarding Health Information: Building Assurance Through HIPAA Security 2026 Conference” on September 2-3 at the NIST Gaithersburg, Maryland Campus. There is also a virtual option for attendees. The conference will include panels and presentations addressing a variety of topics including practical strategies, tips, and techniques for implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, managing cybersecurity risk, implementing practical cybersecurity solutions, and understanding current cybersecurity threats. Federal agencies will also provide updates on cybersecurity considerations when adopting new technologies. Registration for the event is now open on the event web page.
X12 Announces Webinar on HIPAA Version 008060 834 and 820 Transactions. The Standards Development Organization X12 announced that its next webinar on the Version 008060 transactions will be on the 834 Benefit Enrollment and Maintenance and the 820 Payroll Deducted and Other Group Premium Payment for Insurance Products guides. The webinar will take place on Wednesday, August 19 at 1:30 pm ET. Registration is now open.
X12 will continue to share webinars and additional content to better assist industry stakeholders understand the enhancements in the 008060 versions of standards already mandated under HIPAA. Additional webinars and on-demand presentations for previous educational sessions will be offered in the future. Questions about the 008060 education and information series can be submitted via the X12 feedback form.
