Must read
CMS
HL7
FHIR
Medicare Advantage, Medicaid, CHIP, and Marketplace payers must deploy four new FHIR APIs and compress prior authorization timelines by 2026–2027, reshaping payer-provider-patient data exchange across the industry. CMS has finalized the Interoperability and Prior Authorization rule (CMS-0057-F),...
Must read
FDA
Other
A high-severity server-side request forgery vulnerability in the widely deployed OHIF open-source DICOM viewer can expose authenticated clinicians' OIDC Bearer tokens to attackers — patch to v3.12.2 immediately. CISA issued ICS Medical Advisory ICSMA-26-176-02 on June 25, 2026, disclosing...
Must read
CMS
HHS
A sweeping 231-page final rule mandates FHIR-based APIs for patient access, provider access, and payer-to-payer data exchange — and sets hard new timelines for electronic prior authorization across Medicare Advantage, Medicaid, CHIP, and FFE health plans. Published February 8, 2024 and effective...
High
ONC/ASTP
CMS
With HTI-4 finalized on August 4, 2025, ONC has now closed out four major rulemakings that together reshape certification criteria, information blocking, TEFCA, and prescription workflows. ONC's certification program regulations page now reflects a completed four-rule cycle stretching from early...
High
HHS
ONC/ASTP
TEFCA
A new HHS action extends TEFCA's reach to give patients more direct, secure access to their own health records — a concrete step toward the network's individual-access ambitions. HHS announced an expansion of secure health record access through TEFCA, the Trusted Exchange Framework and Common...
High
Other
Industry
A VA OIG review found staff using publicly accessible generative AI chat tools without adequate safeguards, exposing sensitive veteran patient data and creating unmitigated clinical risk. The Department of Veterans Affairs Office of Inspector General has published a review finding that VA staff...
Notable
CMS
Early results from Medicare's AI prior-authorization trial show a pattern of errors and delays that are straining care delivery, even as CMS defends the program as a fraud and cost-control tool. CMS is piloting the use of artificial intelligence to automate prior-authorization decisions for a set...