This monthly update highlights key regulatory developments, enforcement trends, and
compliance issues affecting health care providers across the continuum – from solo practices to hospitals and large physician groups. Each section includes practical action items to help you assess risk and prepare for upcoming obligations.
Regulatory Developments
HIPAA Claims Attachment Standards Become Effective
The U.S. Department of Health and Human Services has finalized new standards governing
health care claims attachments and related electronic signatures under the HIPAA Administrative Simplification framework, 45 C.F.R. Part 162.
The rule became effective on May 26, 2026, and covered entities must comply by May 26, 2028. The new standards are designed to support the secure electronic exchange of documentation used in claims processing and related transactions. The rule is expected to reduce reliance on manual processes, such as faxing and mailing, while improving consistency and efficiency in the exchange of clinical and administrative information between providers and health plans.
Organizations should use the implementation period to evaluate current workflows, vendor capabilities, and internal policies related to claims documentation and transmission.
Action Items:
- Identify claims attachment processes that rely on manual or nonstandard methods.
- Engage clearinghouses and vendors regarding implementation timelines and system
- readiness.
- Review internal policies governing documentation transmission and authentication.
- Begin planning for implementation activities leading up to the May 26, 2028 compliance deadline.
Contracting Focus
Vendor Agreements and Technology Governance
As reliance on third-party vendors continues to expand, healthcare organizations should
periodically evaluate whether existing agreements adequately reflect current operations and risk allocation.
Particular attention should be given to business associate responsibilities, cybersecurity
safeguards, incident response obligations, use of automated or AI-enabled tools, service-level
expectations, audit rights, and data governance provisions. Organizations should also consider whether vendor relationships create operational dependencies that could affect continuity of care or regulatory compliance.
A proactive contract review can help align legal risk with evolving operational realities.
Action Items:
- Review business associate agreements for consistency with current operations.
- Evaluate cybersecurity and incident response provisions in vendor contracts.
- Assess contractual responsibilities relating to AI-enabled tools and automated systems.
- Confirm that service-level, audit, and data governance provisions remain adequate.
Compliance Focus
Artificial Intelligence in Utilization Review and Governance
Iowa House File 2635, effective July 1, 2026, establishes new standards applicable to health
carriers and utilization review organizations, including guardrails on the use of artificial
intelligence in prior authorization processes.
The law permits the use of AI-based tools for initial review of prior authorization requests.
However, for determinations involving medical necessity, AI may not serve as the sole basis for a decision to deny, delay, or downgrade a request. Human clinical judgment must be incorporated into adverse determinations.
Although HF 2635 focuses on utilization review and prior authorization, it reflects broader
regulatory concerns regarding AI governance and accountability. Healthcare organizations
increasingly utilizing AI-enabled tools should evaluate whether appropriate oversight, validation, and documentation processes are in place.
Action Items:
- Inventory current AI-enabled tools across clinical, administrative, and operational functions.
- Define where human oversight is required and how it will be documented.
- Ensure policies, training, and governance frameworks reflect actual use of automated tools.
- Evaluate vendor contracts to confirm accountability for AI-enabled products and services.
Litigation and Risk Management Trends
Cybersecurity and Third-Party Risk Remain Enforcement Priorities
Federal regulators continue to emphasize cybersecurity compliance, particularly in connection with risk assessments, incident response planning, and oversight of third-party vendors. Recent enforcement activity demonstrates that organizations may face significant exposure arising from vendor vulnerabilities and insufficient monitoring of business associates.
Healthcare organizations should ensure that cybersecurity planning extends beyond internal
systems and addresses vendors, contractors, and other external partners that have access to
protected health information or critical operational systems.
Action Items:
- Review and update cybersecurity risk assessments.
- Evaluate third-party vendor security practices and contractual obligations.
- Conduct tabletop exercises involving cybersecurity incidents and vendor-related disruptions.
- Confirm incident response plans remain current and operational.
FAQ of the Month
Do We Need a Formal AI Policy?
A standalone AI policy is not required in all circumstances. Many organizations address AI-
related risks through a combination of compliance, information security, privacy, and operational policies.
However, organizations using AI-enabled tools should ensure they maintain a documented
governance framework addressing permitted and prohibited uses, required human oversight,
documentation and validation expectations, vendor accountability, and workforce training.
The form of the framework may vary, but expectations should be clear, operational, and aligned with actual practice.
Upcoming Deadlines & Reminders
- HIPAA Claims Attachment Standards – Effective Date: May 26, 2026.
- HIPAA Claims Attachment Standards – Compliance Deadline: May 26, 2028.
- Section 504 Accessibility Compliance Deadline: May 11, 2027, for covered entities with 15 or more employees.
- Iowa HF 2635 – Effective Date: July 1, 2026.
- Monthly OIG Exclusion Screening: Conduct monthly exclusion screening using the OIG List of Excluded Individuals and Entities (LEIE).
- Medicare Revalidation (Rolling Deadlines): Monitor CMS notices and published revalidation deadlines.
Disclaimer: The information provided here is for general informational purposes only and does not constitute legal advice. No attorney-client relationship is created by this communication. Parties should consult with their own qualified attorney for advice regarding their specific legal situation.
For questions or assistance, contact Paul A. Drey or Emily E. Reiners of the Brick Gentry P.C. Healthcare & Regulatory Team.
