Skip to Main Content
09/29/2025|5 minute read

Key Takeaways:

  • HHS indicates that information blocking enforcement is a priority and on the horizon.
  • Permanent Medicare telehealth flexibilities remain elusive.
  • Part 2 compliance obligations loom, with OCR as the new enforcement sheriff in town.
  • State laws may impact compliance with information blocking and artificial intelligence regulations.

Information Blocking Crackdown

Earlier this month, the U.S. Department of Health and Human Services (HHS) published a press release announcing a “crackdown on health data blocking” as the HHS Secretary had directed HHS to “increase resources dedicated toward curbing the harmful practice of information blocking.” As discussed in our previous client alert, the Information Blocking Rule (IBR) prohibits certain entities (including healthcare providers and developers of certified health IT) from blocking the access, exchange or use of electronic health information Notably, the fines for information blocking can be steep, ranging to $1 million per violation for certified health IT developers, or hefty disincentives for healthcare providers.

According to the HHS announcement, “unblocking the flow of health information is critical to unleashing health IT innovation and transforming our healthcare ecosystem.” The announcement made clear that HHS had already begun reviewing reports of information blocking against developers of certified health IT and was working with the HHS Office of the Inspector General to investigate these claims. The HHS announcement also included a link for patients to submit information blocking concerns. In light of the anticipated crackdown, it is prudent for industry stakeholders to review and update workflows, policies and procedures that were put in place to comply with the IBR.

State law must also be taken into consideration when developing an IBR compliance plan. Texas is the latest state to join the likes of California and Kentucky with its new law requiring that sensitive pathology and radiology test results not be disclosed to the patient via electronic means (such as through a patient portal) until three days after the results are finalized. It is conceivable that additional state legislation could be forthcoming in light of the proposed HHS crackdown.

The Telehealth Cliffhanger*

As we previously analyzed, after more than five years of kicking the proverbial legislative can down the road, permanent federal telehealth flexibilities remain elusive. Instead, the industry continues to be forced to rely on the temporary telehealth waivers enacted during the COVID-19 pandemic that leave the industry on a perpetual cliff whenever the waivers are slated to expire. Presently, these temporary telehealth flexibilities are set to expire on Sept. 30. However, there are several pending bills that the health care industry is closely monitoring, which would either extend the telehealth flexibilities until mid-November or permanently establish telehealth flexibilities for Medicare beneficiaries. As of this writing, no legislation to extend the telehealth flexibilities has been passed. If Congress fails to act to extend or make these flexibilities permanent before Sept. 30, the consequences could be devastating for Medicare beneficiaries who rely on telehealth, as they will generally no longer be able to receive telehealth in their home. While there is bipartisan support for permanently enabling the use of telehealth, as with the previous telehealth cliffs, industry stakeholders should continue to prepare yet again for the scenario in which the waivers may not be extended in a timely manner or at all.

Part 2 Enforcement

HHS recently delegated the authority to enforce the Confidentiality of Substance Use Disorder Patient Records regulations (Part 2 regulations) to the HHS Office for Civil Rights (OCR). As part of this authority, OCR can now:

  • Impose civil money penalties for failure to comply with Part 2;
  • Enter into resolution agreements, monetary settlements and corrective action plans, to resolve indications of noncompliance with Part 2; and
  • Issue subpoenas related to a Part 2 investigation.

Part 2 has been subject to several updates in recent years, and the  finalized changes to Part 2 require updates to patient consents, penalties, the notice of privacy practices, and breach notification requirements for Part 2 records by Feb. 16, 2026. It is advisable for stakeholders to review their Part 2 materials to ensure compliance with the new requirements.

DOJ Bulk Data Final Rule

As previously analyzed by our colleagues, a wide-reaching rule (Bulk Data Rule) aimed at addressing threats to national security was issued by the Department of Justice (DOJ) and prohibits access to U.S. bulk sensitive personal data by “countries of concern,” which are defined as China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia and Venezuela, or “covered persons” who are affiliated with the countries of concern. Because the regulations specifically apply to “personal health data”, biometric identifiers and genomic data (among other types of data), careful review of the Bulk Data Rule and its requirements is advisable for health care industry stakeholders.  Notably, the definition of “personal health data”  under the Bulk Data Rule is much broader than the definition of “health information” under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) that much of the health care industry is accustomed to.  The definition of “personal health data” is not limited to data collected and held by providers and health plans, but instead applies to any data related to the past, present or future physical or mental health condition of an individual, and the provision of healthcare or payment for such provision of health care.  According to DOJ guidance regarding the Bulk Data Rule, the definition of personal health data even includes logs of exercise habits that are collected by fitness apps.  Industry stakeholders should also be aware that the definition of bulk U.S. sensitive personal data includes the data in any format regardless of whether the data is anonymized, pseudonymized, de-identified or encrypted, which is also a significant departure from HIPAA.  Finally, there are some notable exceptions to the Bulk Data Rule that are relevant to the health care industry, including exceptions related to data that is transmitted for certain clinical research or as part of transactions related to particular drugs, biological products and medical device authorizations that may need to be taken into consideration as well.

Artificial Intelligence

On Sept. 17, Joint Commission partnered with the Coalition for Health AI to release best practices guidance on the responsible use of artificial intelligence (AI) by the U.S. healthcare system. Joint Commission noted in its press release that it intends to develop playbooks, tools and a new voluntary AI certification program. The guidance focused on several key elements that Joint Commission highlighted as necessary to ensure the responsible use of AI in healthcare, including (a) establishing AI policies and governance structures to manage responsible use of AI, (b) developing policies and safeguards to ensure patient privacy and transparency when AI tools are used, (c) promoting data security and data use protections when using AI, (d) utilizing ongoing quality monitoring to evaluate safe performance of AI tools, (e) creating a process for voluntary, blinded reporting of AI safety-related events, (f) identifying and addressing risks and bias in the AI tools, and (g) providing workforce education and training on the use of AI. With the current lack of cohesive federal oversight of AI in the healthcare industry, Joint Commission’s guidance and future playbooks could fill a much-needed gap in assisting healthcare providers with the safe and responsible deployment of AI tools within their organization. At the same time, however, a significant amount of legislation continues to be introduced at the state level that seeks to regulate the use of AI in healthcare. While many of these laws are aimed at limiting any unfair use of AI by insurers, other laws are geared toward regulating the use of chatbots and increasing transparency in the use of AI.

CMS Health Technology Ecosystem Initiative

The HHS Centers for Medicare & Medicaid Services (CMS) recently announced a new Health Technology Ecosystem initiative aimed at unlocking innovation and modernizing the data flows within the healthcare industry, including among data networks, EHR systems, health app developers, providers and innovators. As part of the initiative, CMS stated that it had secured commitments from 60 companies, including Amazon, Apple, Google and OpenAI, to “lay the foundation for the next-generation digital health ecosystem aimed at improving patient outcomes, reducing provider burden and driving value.” Two main focus areas of the initiative include promoting a CMS Interoperability Framework that will enable sharing information between patients and providers and increasing personalized tools to give  patients more access to the information they need to make healthcare decisions.


*After the publication of this article, the Medicare telehealth flexibilities expired; please see our updated telehealth analysis here.


Featured Insights