CMS Launches QualTech to Identify Innovative Technology Solutions. The Centers for Medicare & Medicaid Services (CMS), through the Center for Clinical Standards and Quality (CCSQ), launched QualTech, an industry initiative designed to identify innovative technology solutions aligned to quality-related priorities and advance better health outcomes. CMS is inviting organizations with technology solutions or capabilities aligned to CMS quality priorities to submit proposals. Following review of submissions, finalists will be invited to participate in the QualTech Event and present their proposed technology solutions to CMS and CCSQ leadership. Following the QualTech Event, CMS may pursue continued engagement with select organizations. Additional information and the submission process are available on the QualTech website.
CMS Requests Billing Information for Unpaid 2026 APM Participants. CMS announced a request for billing information for providers who have not received their 2026 Alternative Payment Model (APM) incentive payments for the 2024 performance period. The request is based on CMS identifying eligible clinicians who attained Qualifying APM Participant (QP) status for the 2024 performance period but lacked a taxpayer identification number (TIN) for CMS to process their incentive payment for the 2026 payment year. CMS has compiled a list of QPs for whom it could not identify an associated TIN. These QPs, as well as others who anticipated receiving an APM incentive payment but have not, should provide CMS with updated Medicare billing information and all required documentation by October 13. After that date, claims for a 2026 APM incentive payment based on QP status for the 2024 performance period will be forfeited, and CMS will not accept requests for additional payment review or reprocessing.
CISA Updates Cybersecurity Advisory on Medusa Ransomware. The Cybersecurity & Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, and Department of Health and Human Services released an update to the joint Cybersecurity Advisory #StopRansomware: Medusa Ransomware. The advisory provides technical details on Medusa ransomware activity, including how Medusa actors gain initial access through brokers, phishing, and exploitation of unpatched internet-facing vulnerabilities, along with detection and mitigation guidance to help protect at-risk organizations. Medusa is a ransomware-as-a-service variant that has impacted more than 500 victims across multiple critical infrastructure sectors, including health care and public health. The advisory urges organizations to implement steps to mitigate known vulnerabilities by: (i) Ensuring operating systems, software, and firmware are patched and up to date within a risk-informed timeframe; (ii) Segmenting networks to restrict lateral movement from initially infected devices to other devices in the organization; and (iii) Filtering network traffic by preventing unknown or untrusted origins from accessing remote services on internal systems.
FDA Seeks Public Feedback on Generative AI-Enabled Medical Devices. The U.S. Food and Drug Administration (FDA) issued a discussion paper on considerations for the regulation of generative artificial intelligence (GenAI)-enabled medical devices and is seeking feedback on risk assessment, premarket evaluation, postmarket monitoring, and other topics relevant to the regulation of GenAI-enabled medical devices. The discussion paper outlines: (i) A framework for risk assessment that could be used to inform regulatory expectations; (ii) A potential approach to premarket evaluation; (iii) Several potential approaches to risk-proportionate postmarket monitoring; (iv) Considerations around foundation models and agentic AI systems. The FDA poses targeted questions intended to inform development of a regulatory framework for the novel capabilities of GenAI-enabled medical devices. Comments are to be submitted under the docket FDA-2026-N-7874 on Regulations.gov by October 19.
NIST Releases Concept Paper on Human-Centered Technologies. NIST’s Human-Centered Technologies team released a concept paper titled “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” on human-centered technologies (HCC) and is requesting public feedback on it. Their goal is to build a shared understanding of what HCC means and develop practical guidelines and resources that organizations can use to: (i) Clarify whether HCC is an approach or outcome; (ii) Communicate the relationship between HCC and existing NIST cybersecurity guidelines and frameworks; and (iii) Assist organizations in implementing and enhancing HCC within their cybersecurity programs. Feedback can be submitted via human-cybersec@nist.gov by September 30.
The Sequoia Project Awarded Extension as TEFCA RCE. The Sequoia Project announced it was awarded a contract extension and will continue its role as the Recognized Coordinating Entity® (RCE®) supporting the implementation of the Trusted Exchange Framework and Common Agreement™ (TEFCA®). The extension is part of an existing contract with the Office of the National Coordinator for Health Information Technology (ONC) and includes a more than 15% increase in funding. Since December 2023, TEFCA has supported the exchange of more than 1.5 billion documents with over 100,000 sites nationwide sharing patient data under explicit, approved exchange purposes.
TEFCA™ RCE Releases RCE® Directory Service Requirements SOP. The Sequoia Project, the TEFCA™ RCE®, along with ONC released the RCE® Directory Service (Directory) Requirements Policy Standard Operating Procedure (SOP). This SOP describes Directory policy requirements that Qualified Health Information Networks (QHIN) must follow when maintaining Directory Entries, in addition to the specifications set forth in the Framework Agreements, QHIN Technical Framework, RCE Directory Service Implementation Guide, and applicable SOPs. The SOP becomes effective September 14, 2026.
CHAI Launches Health AI Cybersecurity Work Group. The Coalition for Health AI (CHAI) launched the Health AI Cybersecurity Work Group with plans to develop real-world, peer-developed guidance on cyber risk and readiness. The Work Group consists of a leadership council and work group members. The intent is to develop playbooks and risk assessment tools that will address how health systems, payers, and health tech companies can respond to frontier model threats, both preventing potential attacks and using frontier models for defense. Registration for the Work Group is available here
