Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callWhat actually changed in the last twelve months?
More than most compliance calendars caught. Between August 2025 and August 2026, Colorado replaced its AI act outright, Texas turned on a statewide AI law with a healthcare specific disclosure duty, the federal certification program went from expansion to proposed contraction, and the CMS prior authorization rule crossed its first operational deadline while its harder deadline moved closer.
None of that is visible if you track regulation by reading vendor emails. It is visible if you keep a short list of rules, an owner for each, and a date you revisit them. The maintained version of that list is the regulations index, which carries a page per rule with its own review date and its own primary sources. This post is the year in review that sits on top of it: what moved, when it moved, and what a provider organisation is supposed to do about it. It was checked on August 5, 2026.
The organising point is simple. Federal rules in this space mostly bind your EHR vendor and your payers rather than you directly, and you feel them as product changes and contract terms. State rules mostly bind you directly, as a licensed entity, and you feel them as disclosure duties and liability. Those two streams need different owners inside your organisation, and confusing them is the most common failure we see.
Which rules do you actually have to track?
Nine of them, for a US provider organisation deploying AI agents. Everything else is commentary on these.
| Rule | Who it binds | Next date that matters | Status, August 2026 |
|---|---|---|---|
| HIPAA Privacy and Security Rules | Covered entities and business associates, including AI vendors | Continuous | In force. The baseline every other rule sits on top of |
| HTI-1 certification criteria | Certified health IT developers, felt by providers as product changes | Passed. Enforcement discretion ended March 1, 2026 | In force |
| The HTI-2 package | Certified health IT developers | Rolling, by criterion | Finalised in parts |
| HTI-4 certification criteria | Certified health IT developers | Effective October 1, 2025 | In force |
| HTI-5 deregulatory proposal | Certified health IT developers | Comments closed February 27, 2026 | Proposed, not final |
| CMS-0057-F prior authorization rule | Medicare Advantage, Medicaid and CHIP plans, QHP issuers on the exchanges | January 1, 2027 for the four FHIR APIs | Operational provisions live since January 1, 2026 |
| FDA AI-enabled device software guidance | Manufacturers of AI functions that meet the device definition | No finalisation date announced | Draft since January 7, 2025 |
| Colorado SB 26-189 | Developers and deployers of automated decision-making technology | January 1, 2027 for developer duties | Signed May 14, 2026, replacing SB 24-205 |
| Texas HB 149 (TRAIGA) | Licensed healthcare providers using AI in treatment, among others | Passed. Effective January 1, 2026 | In force |
California and Utah sit outside the table because their healthcare AI duties predate this window and have not moved. They are covered in the state section below, and in full on the California page and the Utah page.
What is happening to the ONC certification program?
It is being cut back, and the direction reversed inside a single year.
HTI-1 added the decision support intervention criterion at 45 CFR 170.315(b)(11), which requires certified health IT to surface a defined set of source attributes for both evidence-based and predictive decision support. That is the criterion that made model transparency a product feature rather than a request. A lapse in appropriations from October to November 2025 disrupted testing access, and ASTP/ONC issued an enforcement discretion notice on November 24, 2025 covering fifteen criteria with a January 1, 2026 compliance date. The discretion ran from January 1 to February 28, 2026 and expired on March 1, 2026.
HTI-4 was finalised as part of the FY2026 Hospital Inpatient Prospective Payment System final rule and took effect on October 1, 2025. It adds certification criteria for electronic prior authorization, electronic prescribing and real-time prescription benefit information, which is the certification side of the same prior authorization push CMS is running on the payer side.
Then the direction changed. On December 29, 2025, ASTP/ONC published a proposed rule titled Health Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions to Unleash Prosperity, known as HTI-5. It proposes eliminating 34 of the roughly 60 existing certification criteria and revising seven more, alongside changes to information blocking exceptions. Comments closed on February 27, 2026. As of August 2026 it has not been finalised.
What this means operationally: do not build a governance programme that depends on a certification criterion staying in place. Build it on what you need to be able to evidence, then treat certification as one convenient source of that evidence. The same reasoning applies when you assess a vendor against our HIPAA-compliant AI tools shortlist.
What does the CMS prior authorization rule require, and when?
CMS-0057-F, the Advancing Interoperability and Improving Prior Authorization Processes final rule, was published in the Federal Register on February 8, 2024 and became effective on April 8, 2024. Its obligations phase in over three years, and the phase you are in now is the quiet one before the hard deadline.
From January 1, 2026, impacted payers must send prior authorization decisions within 72 hours for expedited requests and seven calendar days for standard requests, must give a specific reason for denials, and must publicly report prior authorization metrics each year. Those provisions are live now.
From January 1, 2027, the same payers must operate four FHIR APIs: Patient Access, Provider Access, Payer-to-Payer, and a Prior Authorization API that carries requirements, submissions and status. That is the one that changes what an automation project can do, because it turns prior authorization from a portal and fax problem into an interface problem.
The rule binds payers, not you. But the published denial metrics are a negotiating asset, the seven day clock is a service level you can hold a payer to, and the 2027 APIs are the thing your automation roadmap should be pointed at. If you are scoping prior authorization automation, baseline your current cost per authorization first with the prior authorization cost calculator, because after the APIs arrive nobody will remember what the old number was.
Where does FDA sit on clinical AI right now?
In draft, and it has been for eighteen months.
On January 7, 2025, FDA issued draft guidance titled Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations. It is the agency's first attempt at total product lifecycle recommendations for AI-enabled devices, covering design, development, maintenance and documentation in one document. The comment period closed on April 7, 2025. As of August 2026 it has not been finalised.
Two practical consequences. First, the boundary that matters to most provider organisations is not whether a tool uses AI but whether its function meets the device definition. An ambient documentation agent that drafts what was said sits in a different position from one that proposes a diagnosis or an order, and that distinction is a question to put to a vendor in writing rather than infer from a demo. Second, draft guidance is not binding, so a vendor claiming compliance with it is telling you about its internal practice, not its regulatory status.
The list of AI-enabled devices FDA has authorised is public and worth checking against any vendor claim of clearance. Details, and the questions we use, are on the FDA page.
How bad is the state patchwork now?
Manageable if you deploy in one state, genuinely difficult if you deploy in four, and the difficulty is not volume but divergence: the four significant state regimes regulate different things.
| State | What it regulates | Effective date | Direction of travel |
|---|---|---|---|
| Colorado | Automated decision-making technology in consequential decisions, via notice, disclosure and human review rights | Developer duties from January 1, 2027 | Narrowed. SB 26-189 replaced SB 24-205 on May 14, 2026 |
| California | Generative AI in patient clinical communications (AB 3030) and AI in payer utilization review (SB 1120) | Both operative January 1, 2025 | Stable and in force |
| Texas | Disclosure that a patient is interacting with an AI system in healthcare services or treatment | January 1, 2026 | New and in force |
| Utah | Disclosure of generative AI use by regulated occupations, which includes licensed clinicians | SB 149 signed March 13, 2024, amended since | Amended repeatedly. Check the current text |
Colorado is the clearest illustration of why quarterly review beats annual review. SB 24-205 was due to bite on February 1, 2026. Amendments signed on August 28, 2025 pushed that to June 30, 2026. Then on May 14, 2026 the governor signed SB 26-189, which repealed and replaced the act with a narrower automated decision-making statute, dropped the mandatory risk management programme and annual impact assessments, centralised enforcement with the attorney general, and set developer obligations to begin on January 1, 2027. Anyone who built to the 2024 text spent a year building to a law that no longer exists.
Full treatments are on the Colorado, California, Utah and Texas pages. If you operate across several of them, the strategy question is covered separately in the multi-state compliance post.
Will federal preemption make the state rules go away?
Not yet, and not on a schedule you can plan around.
Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, was signed on December 11, 2025 and published in the Federal Register on December 16, 2025. It sets federal policy toward a single national approach to AI and directs federal attention at the state law patchwork. It is an executive order, not a statute, and it does not itself repeal a state law.
As of August 2026, every state law described above remains in force or on its stated schedule. Colorado's narrowing came from the Colorado legislature, not from Washington. Texas turned on as written.
The planning implication is unglamorous. Build your compliance posture on the strictest state you operate in, because that posture also satisfies the looser ones, and because a posture built for the strictest rule survives both preemption and further state legislation. It costs slightly more now and it is the only version that does not need rebuilding. We work through the mechanics of that in the AI governance and compliance engagement.
How do you review this every quarter without it becoming a project?
Ninety minutes, one owner, four questions. Put it in the calendar as a recurring meeting rather than a task, because tasks slip and meetings do not.
- Did any date on the table pass? If yes, what did we have to have done by then, and did we do it? This catches the CMS 2027 API date creeping up on a roadmap that was written in 2025.
- Did any rule change text? Colorado changed twice in nine months. Utah has been amended more than once. Read the state legislature page, not a summary of it.
- Did we deploy anything new into a regulated state? A new clinic in a new state can pull you into a disclosure regime you have never read. So can a telehealth licence.
- Did any vendor change its terms? Retention, subprocessors and training rights move quietly, and the notice usually arrives as an email nobody in compliance receives.
Keep the answers in one document with dates. The document is the artefact that lets you explain, eighteen months later, why you did what you did, and it is also what an auditor or a plaintiff's lawyer will ask for. The full regulations index is the checklist to run it against.
If nobody in your organisation owns that ninety minutes, the honest first step is not a policy document but an assessment of what you are actually exposed to. That is what an AI readiness audit produces, and it takes three weeks rather than a quarter.
Sources
Primary material behind the claims above. Read the source before acting on any summary of it.
- ONCHealth Data, Technology and Interoperability certification program (HTI) (opens in a new tab)
- ONCCertification criteria compliance dates enforcement discretion notice (opens in a new tab)
- ONCHealth Data, Technology, and Interoperability: ASTP/ONC Deregulatory Actions To Unleash Prosperity (HTI-5 proposed rule) (opens in a new tab)
- CMSCMS Interoperability and Prior Authorization Final Rule (CMS-0057-F) (opens in a new tab)
- FDAArtificial intelligence and machine learning in software as a medical device (opens in a new tab)
- StateSB26-189 Automated Decision-Making Technology (opens in a new tab)
- StateTexas HB 149, Responsible Artificial Intelligence Governance Act (opens in a new tab)
- OtherExecutive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence (opens in a new tab)
- HHSHIPAA for professionals, HHS (opens in a new tab)
Questions we get asked
Which healthcare AI regulation should I worry about first?
HIPAA, because it applies to every AI tool that touches patient information and it is the one an enforcement action will actually be brought under. Everything else on this page sits on top of it. After that, the state disclosure law where you practise, because it binds you directly rather than binding your vendor.
Does the CMS prior authorization rule apply to providers?
Not directly. CMS-0057-F binds Medicare Advantage organisations, Medicaid and CHIP plans, and qualified health plan issuers on the federally facilitated exchanges. Providers feel it through faster decision timeframes, more specific denial reasons and, from January 1, 2027, payer FHIR APIs that automation can actually call.
Is the Colorado AI Act still in effect?
SB 24-205 was repealed and replaced. Governor Polis signed SB 26-189, Automated Decision-Making Technology, on May 14, 2026. It narrows the original framework to notice, disclosure and human review obligations, drops the mandatory risk management programme and impact assessments, and sets developer duties to begin January 1, 2027.
Has FDA finalised its AI device guidance?
No. The draft guidance on AI-enabled device software functions was issued on January 7, 2025 and the comment period closed on April 7, 2025. As of August 2026 it remains draft, which means it is not binding on anyone. A vendor citing it is describing its own practice rather than a regulatory status.
How often should this be reviewed?
Quarterly. Three of the nine rules tracked here changed status within the last twelve months, and one of them changed twice. An annual review would have missed both Colorado amendments and the certification enforcement discretion window entirely.
Do these rules apply to an AI scribe that never leaves the exam room?
HIPAA does, in full, because audio of a clinical encounter is protected health information. State disclosure laws may, depending on how the tool is used and which state you are in. FDA device rules generally do not, provided the tool drafts what was said rather than recommending a diagnosis or an order.
Know what changed before your vendor tells you
A monthly regulatory and vendor intelligence note for people who have to sign off on this. What moved in HIPAA, ONC and state AI rules, and which vendor claims stopped being true.
Book an evaluation call at any point. No obligation.