OMB Reviewing Final Rules for HTI-5 and Transparency in Coverage. The Office of Management and Budget (OMB) is reviewing two final rules. The first regulation is the Office of the National Coordinator for Health Information Technology’s (ONC’s) “Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity” final rule, known as “HTI-5.” The proposed rule focused on deregulatory actions to reduce burden, offered flexibility to both developers and providers, and supported innovation through the removal and revisions of certain certification criteria and regulatory provisions. It was included in the recently released 2026 Unified Agenda with a targeted publication of August 2026.
OMB is also reviewing the Centers for Medicare & Medicaid Services’ (CMS’) “Transparency in Coverage” final rule. The proposed rule included provisions to amend the Transparency in Coverage final rule published November 12, 2020, to improve the quality, accessibility, usability, and transparency of health care price data. It was included in the recently released 2026 Unified Agenda with a targeted publication of July 2026. Review by OMB is typically the last step in the regulatory process before a final rule is published. OMB reviews are typically up to 90 days in length.
CMS Health Tech Ecosystem Expands New Pledge and Focus Areas. The CMS Health Tech Ecosystem expanded pledge initiatives and focus areas have been further identified. CMS announced the expansion during its one-year celebration of the initiative. The new topics include:
- Real-Time Benefits Pledge using APIs to improve patient knowledge of coverage and expected cost drugs and medical services.
- Advanced Scheduling Pledge using APIs to improve patients’ experience with scheduling and managing appointments.
- Clinical Trials Access to improve patients’ access to and participation in clinical research studies.
- Medical Media Shuttling to improve transmission of imaging files between providers.
- Electronic Prior Authorization to further reduce administrative burden and treatment delays.
- Patient-Facing App Library Expansion to further develop the Medicare App Library with patient-friendly tools.
- Digital Identity Validation to improve data access through the expansion of digital credentials.
- Ecosystem Adoption Work Group to promote adoption and use of technology needs identified in the ecosystem.
Additional information is expected to be provided on the CMS Health Tech Ecosystem website.
CMS Announces Nationwide Expansion of CJR-X Model. CMS announced it is expanding the Comprehensive Care for Joint Replacement Expanded (CJR-X) Model, which is an initiative to improve care coordination for hip, knee, and ankle replacements. The goal of the model is for providers to work together from pre-surgery education through post-op recovery to promote a seamless patient care experience and optimal health outcomes. Beginning in January 2028, most hospitals will be required to participate in the CJR-X model in accordance with the FY 2027 Inpatient and Long-Term Care Hospital Prospective Payment System Final Rule.
Senate HELP Committee Advances Privacy Bill. The Senate Committee on Health, Education, Labor, and Pensions (HELP) advanced S.3097 “Health Information Privacy Reform Act” introduced by Committee Chair Sen. Bill Cassidy, MD (R-LA). The bill, if enacted, would require the Secretary of Health and Human Services (HHS), in consultation with the Federal Trade Commission, to promulgate regulations setting privacy, security, and breach notifications standards for the processing of applicable health information by regulated entities and their service providers. The bill designates that the standards must provide protections that are equal to and aligned with the Health Insurance Portability and Accountability Act and Health Information Technology for Economic and Clinical Health Act requirements that apply to covered entities and business associates with respect to protected health information.
Bipartisan Legislation Introduced to Improve Patient Matching. Sens. Mark Warner (D-VA) and Jim Banks (R-IN) introduced the “Patient Matching and Transparency in Certified Health IT (MATCH IT) Act” that seeks to improve standardization of patients’ demographic data entered into certified health information technology (IT) products to help decrease patient misidentification, improve patient safety, and promote interoperability. The bill would require the development of uniform data standards and definitions for accurate and precise patient matching and require all Certified Electronic Health Record Technology systems to adopt these standards, among other provisions. A similar bill was previously introduced in the U.S. House of Representatives.
ONC Releases Dataset Updates on Hospital and Clinician Certified Health IT Adoption. ONC released two new datasets that link clinicians’ and hospitals’ reporting for Promoting Interoperability in 2024 with the certified health IT they use, making it easier for researchers and developers to examine certified health IT use across specialties, states, and other characteristics. For clinicians, these datasets provide a minimum set of data fields to further combine these data with the full CMS Quality Payment Program experience data, full Certified Health IT Product List (CHPL) dataset, and other datasets. For hospitals, these datasets provide a minimum set of data fields to further combine these data with CMS hospital datasets, the full (CHPL) dataset, and other datasets. The documentation and notes describe those data fields necessary for linking to other data.
CISA Publishes New Security Guidance Documents. The Cybersecurity & Infrastructure Security Agency (CISA) released the following guidance:
- “Open Source Software: Security Principles and Practices:” This guidance helps federal agencies and organizations use open source software (OSS) securely, manage supply chain risk, and engage constructively with open source communities. The guidance explains how to evaluate OSS components, highlights the importance of maintaining an accurate software inventory, describes how software producers can adopt a “default open source” approach, and addresses “open source” artificial intelligence systems. Recommendations in the guidance align with CISA’s Cybersecurity Performance Goals 2.0 and the National Institute of Standards and Technology’s Secure Software Development Framework.
- “Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers:” This joint guidance by CISA, the National Security Agency, and international partners contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with external security researchers that includes a clear vulnerability disclosure policy and process for triaging, remediating and assigning Common Vulnerabilities and Exposures identifiers to reported vulnerabilities. The guidance also provides considerations for leveraging third-party intermediaries, like CISA or other national computer security incident response teams, to substitute or supplement a CVD program.
- “CI Fortify – Advice for isolating vital systems:” This joint guidance by CISA, in collaboration with the Federal Bureau of Investigation and international partners, is part of CISA’s Critical Infrastructure (CI) Fortify initiative and is designed to help critical infrastructure owners in isolating operational technology to maintain essential operations during a significant cybersecurity incident or crisis. The joint guidance provides practical steps for isolating vital systems, such as identifying and mapping critical assets and connections, building effective separation points, and developing graduated isolation plans with regular testing.
CISA Releases Updated Minimum Elements for a Software Bill of Materials. CISA, in collaboration with the National Security Agency, Federal Bureau of Investigation, and international partners, released joint guidance titled “2026 Minimum Elements for a Software Bill of Materials (SBOM).” An SBOM is a formal record that serves as an “ingredients list” for software. Minimum elements are the baseline technologies and practices that an SBOM should include. The joint guidance builds on previous work and incorporates feedback from a 2025 public comment period. Additional resources are available on CISA’s SBOM webpage.
