Skip to content
914126

OCR and ONC Release Updated Security Risk Assessment Tool. The Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator of Health Information Technology (ONC) released version 3.7 of the Security Risk Assessment (SRA) Tool for small and medium physician practices. In addition, OCR and ONC will co-host live webinars on September 15 at 12:00 pm ET and September 16 at 3:00 pm ET. During the sessions, experts will demonstrate the new features of the SRA Tool, walk through reports, and answer questions. Version 3.7 includes revised content and other important updates, such as: (i) Assessment coverage and scope questions and education; (ii) Remote access and telework questions and education; (iii) System activity logging revised language and education; (iv) Expanded asset examples to include newer technology; (v) Updated software libraries for bug and vulnerability fixes; and (vi) Report revisions to capture additional details and comments.

ONC Participating in Upcoming HL7 FHIR Connectathon in US Quality Core Track. ONC announced it will participate in the upcoming Health Level Seven (HL7) Fast Healthcare Interoperability Resources® (FHIR®) Connectathon on the U.S. Quality Core track. Attendees of the Connectathon will get hands-on experience with the U.S. Quality Core FHIR Implementation Guide (IG) and the Inferno Test Kit. The IG is designed to standardize how health care quality data is captured and exchanged across the industry. Participants will get an early look at newly released resources, including both the v0.5 and v1-ballot versions of the US Quality Core IG and the US Quality Core Inferno Test Kit. This work supports ONC’s efforts to reduce provider reporting burden, improve consistency across quality programs, and advance interoperable, digital quality measurement aligned with HL7 FHIR and USCDI+ Quality.

CMS Announces Fall 2026 ICD-10 Coordination and Maintenance Committee Meeting Details. The Centers for Medicare & Medicaid Services (CMS) announced details for the Fall 2026 ICD-10 Coordination and Maintenance Committee meeting. Proposals for diagnosis code topics will be presented virtually by the Centers for Disease Control and Prevention’s (CDC) National Center for Health Statistics and are scheduled for September 15-16. The final agenda and meeting materials for will be posted on the CDC website. Registration for the meeting is required.

The Fall 2026 ICD-10 procedure code topic materials and related documents will be made available on the CMS website. Additionally, CMS will post a question-and-answer document to address any clinical or coding questions that members of the public may have submitted by the designated deadlines.

The deadline to submit comments for procedure code topics to be considered for the April 1, 2027, implementation is October 16 and the deadline to submit comments for procedure code topics to be considered for the October 1, 2027, implementation is November 13. Comments are to be submitted to the related to the CMS mailbox at: ICDProcedureCodeRequest@cms.hhs.gov by the respective deadlines.

CMS Announces Timeline for 2025 MIPS Final Scores and Targeted Review. CMS announced the timeline for publication of the Merit-based Incentive Payment System (MIPS) final scores for the 2025 performance year. The Targeted Review period will open in October, along with requests for reviews. MIPS payment adjustments for the 2027 payment year will be released approximately one month after the release of final scores. The Targeted Review period will close 30 days after the MIPS payment adjustments are released. Performance period benchmarks are part of final scoring and will become available only once final scores are released. Announcement of the 2025 final scores will be released through the Quality Payment Program (QPP) listserv. Eligible providers can use the QPP Participation Status tool or sign in to the QPP website for additional information.

CMS Opens 2026 MIPS MVPs Registration. CMS opened the MIPS Value Pathways (MVPs) registration window for the 2026 performance year. Individuals, groups, subgroups, and Alternative Payment Model (APM) Entities have until November 30 to register through the QPP website to report an MVP. Additional information on the available MVPs for the 2026 performance period is available at Explore MVPs.

CISA Releases Guidance on Effective Communication During Service Outages. The Cybersecurity & Infrastructure Agency (CISA), in collaboration with the Federal Bureau of Investigation and international partners, released joint guidance Communicating Under Pressure: Best Practices for Service Providers for organizations to use in establishing effective communication strategies for service outages impacting information technology and operational technology systems. The guidance describes how service providers can prepare and deliver clear and timely messaging that provides necessary information. Actions highlighted for communicating during service outages include: (i) Focusing on facts, scope, and affected systems; (ii) Providing frequent updates tailored to audiences; (iii) Explaining operational impact and any customer actions; (iv) Avoiding vague language, speculation, and inconsistent messages; and (v) Aligning messaging with legal, regulatory, and law enforcement requirements. 

CISA Releases Call to Action for Post-Quantum Cryptography. CISA, in partnership with the Group of Seven Cyber Security Working Group members released “Preparing for the Post-Quantum Era: A Call to Action.” The document highlights the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data and critical assets from emerging quantum computing threats. Quantum computers use quantum bits or “qubits” that make it possible for quantum computers to problem-solve faster than traditional computers. As quantum computing advances, these computers will be able to break public-key cryptography widely used to protect sensitive data and communications. Malicious cyber threat actors are currently intercepting and storing public-key encrypted data that they can use in the future with PQC to compromise equipment and access confidential data. CISA’s call to action urges organizations to prioritize PQC migration and begin identifying critical assets, mapping dependencies, and developing phased transition plans aligned with their national cybersecurity authorities. Visit CISA’s Post-Quantum Cryptography Initiative for additional information.

House Bill Aims to Keep AI from Making Health Care Decisions. The bipartisan “Doctors Not AI” bill was introduced in the U.S. House of Representatives by Reps. Greg Landsman (D-OH), Buddy Carter (R-GA), Kim Schrier, MD (D-WA), and Tom Barrett (R-MI). The legislation aims to prevent artificial intelligence (AI) from making health care decisions that should be made by qualified health care professionals. If enacted, it would ensure medical decisions are made by a health professional, and not AI. The bill calls for: (i) AI to only be used in a supporting role; (ii) Protection of independent clinical judgment; (iii) Increased transparency; and (iv) Protection of access to mental health care.

 

Scroll To Top